Thursday, 24 October 2013

Digital after death: A grave concern

This is another area to consider, after death, what about what one has stored on the internet (photos, emails, information in the cloud and social medias,..etc)?

Interesting area that may require a uniform law, what do you think?

full text here. 

Tuesday, 10 September 2013

Edmondson: [2013] EWCA Crim 1026


If you have not already seen it, you might find this case interesting, as it advances the interpretation of what is considered to be “in the course of transmission”, for the purposes of RIPA. It’s a “voicemail hacking” case, focussing on whether the actions of Rebekah Brooks, Andy Coulson and others could fall within the ambit of unlawful interception of communications.

Focussing particularly on voicemail, although making some interesting comments about email too, the case holds that, where a communication is stored on the infrastructure of a communications provider, access to that stored communication is an act of interception even where it has already been accessed or collected by the intended recipient. In other words, it provides some clarity on where the endpoint of a communication is for a hosted message service, for interception purposes.

Thursday, 15 August 2013

New directive on attacks against information systems

The new directive against attacks on information systems was published in the Official Journal yesterday.

Not much of the content seems particularly new, especially in terms of the law in the UK at the moment.

The only area where I see some potential challenges, and the potential need for a sensible discussion between member states and industry relates to article 7 of the directive, “tools used for committing offences.” 

The drafting has clearly attempted to delineate that difficult boundary between a “hacking tool” and a tool which is useful testing the security of a network or computer system – which, in all likelihood, is the same software - and, to ensure that businesses and individuals remain able to test the security of their own infrastructure, implementing legislation must tread a fine line to ensure that this distinction is recognised.


Monday, 20 May 2013

Ofcom "Study into the Implications of Smartphone Operating System Security"

It's long, it's detailed, and it might just be up your street:
Goode Intelligence was commissioned by Ofcom to prepare an independent expert report into emerging risks to users of Smartphones and to further Ofcom's understanding of how these risks are addressed in this highly dynamic and nascent environment. 
 You can download all 130+ pages here.

Sunday, 19 May 2013

US politicians quiz Google on Glass privacy

This is another example on privacy/ data and identity protection implications, when Google Glass potentially  gather images, video and other data about almost anything a user sees.

Full text here.

Saturday, 18 May 2013

Tracking phones in shopping centres — how do you feel?

I was in a shopping centre in Reading today, and this notice caught my eye:

Despite the protestation that "no personal data is recorded," it's quite clear that information about me — or, perhaps, my phone — are being used to provide information to the shopping centre, and perhaps used in other ways.

It was a system I had heard of before, from a company called Path Intelligence. It does not work by using data from the mobile operators, but by careful monitoring of certain frequencies used by mobile phones, to detect phones as their users move around. There was quite some controversy around Path Intelligence in 2011, with the system being labelled as "secretly tracking" and "snooping," but it seems to have gone quiet since then.

I did come across this Freedom of Information Act request, made by Eric King at Privacy International, asking the Information Commissioner to produce any materials resulting from a discussion with Path Intelligence, and the results make for quite interesting reading.

How do you feel about this? Sufficiently invasive to be in need of regulatory attention, or a trivial and inherently harmless use of information gathered from the airwaves? Would it make a difference if you could opt out (something Path Intelligence does not offer)?

Saturday, 13 April 2013

"Google chief urges action to regulate mini-drones"

Computers, of course, stretch far beyond boxes sitting in your study or on your desk — but how do you feel about computers, or sensors attached to remote computers, in the sky? How would you feel about an unmanned aircraft hovering over you, watching your every move and reporting it back to some unknown base station? Or are drones — even mini-drones — a good idea?

The BBC has an interesting piece about Eric Schmidt's views on mini-drones: Schmidt, of course, might be seen as an odd person to give pro-privacy advice, particularly after Google's StreetView project.

Thursday, 14 March 2013

Data protection


Data protection issues have long been a source of controversy. The proliferation of global Internet companies such as Google, Facebook and Twitter have crystallised conflicts between the privacy interests of individuals and commercial aspirations.
 In 2012 the European Commission published a draft Regulation that, if adopted, will replace the current Data Protection Directive. The measure appears to  attracted both support and opposition. A group of European academicshttp://euobserver.com/justice/119365 have launched an on-line petition supporting the Commission’s proposals. The European Parliament’s Justice Committee has adopted a report which calls for the Commission’s proposals to be strengthened still further.
 This might be contrasted with the UK Parliament’s Justice Committee which has described some of the Commission’s proposals – including the so called ‘right to be forgotten’ as unworkable.  Concerns are shared by some data protection authorities  as this report in the Financial Times indicates. It is perhaps not surprising that the UK is mentioned. We abstained in the final vote on the existing  Directive on the basis that the measure went too far. More surprising is that we have been joined by countries such as Germany who 18 years ago were concerned that the Directive did not go far enough.
 The next year promises to be an interesting period for data protection. I suspect the saga still has a way to go.

Sunday, 24 February 2013

End of an Era

I've just been informed of the death of Alan Westin.

Professor Westin was one of the pioneers in the modern debate about privacy and the law and his writings certainly influenced much of my early academic work. His book, Privacy and Freedom was published in 1967 and is still worth reading. I doubt whether the same will be said of my books 50 years from now.

There is an obituary in the New York Times which you can link to from here

Ian

Friday, 8 February 2013

"EU Cybersecurity plan to protect open internet and online freedom and opportunity"

"The European Commission, together with the High Representative of the Union for Foreign Affairs and Security Policy, has published a cybersecurity strategy alongside a Commission proposed directive on network and information security (NIS).
The cybersecurity strategy – "An Open, Safe and Secure Cyberspace" - represents the EU's comprehensive vision on how best to prevent and respond to cyber disruptions and attacks. This is to further European values of freedom and democracy and ensure the digital economy can safely grow. Specific actions are aimed at enhancing cyber resilience of information systems, reducing cybercrime and strengthening EU international cyber-security policy and cyber defence."

The full press release is here, along with links to the proposed directive and to strategy documents.

From my perspective, this looks like a good thing, both for increasing the scope of what is considered to be critical national infrastructure in a digital age, and also to bring up the overall level of cybersecurity, and particularly to level the playing field: over the top communications providers should, I hope, be brought up to the same level as traditional telcos here.

Monday, 21 January 2013

Future Challenges to Identity


How will changes in the next ten years affect notions of identity?

This is the big question addressed by a new report today by the UK Department for Innovation, Business & Skills (BIS), which sets out set out to explore how changes in technology will affect our notions of identity.

The report identifies key challenges for effective policy-making and implementation in a rapidly changing, globalised, technology-rich, and densely networked society. Amongst other areas, it focuses on implications for crime prevention and criminal justice in a chapter called, ‘The Future Challenges of Identity Crime in the UK’ by Professor David Wall.

For more information, see: http://www.bis.gov.uk/foresight/our-work/policy-futures/identity/Copy%20of%20reports-documents and today’s introductory comment by the BBC: http://www.bbc.co.uk/news/technology-21084945.

If anyone has research interests touching on identity and law (for example, from a different cultural perspective than the UK), please feel free to email me: amk1g10@soton.ac.uk. It will be great to share ideas!

Best wishes,
Alison


 


Thursday, 10 January 2013

European Cybercrime Centre

Hello,

I'm a new member of your blog and a few others. I've just started a PhD in IT law (specially on legal issues surrounding digital identity) at Southampton. Thanks for letting me join!

Another one on cybercrime: today, the European Commissioner for Home Affairs  will present the European Cybercrime Centre to the media on 9 January 2013 after which the Centre will be officially inaugurated on 11 January 2013. In 2010, the European Council had tasked the Commission with verifying the feasibility of establishing a European Cybercrime Centre that would become Europe's focal point in the fight against cybercrime.
 
The establishment of the EC3 is a result of the Commission Communication, Tackling Crime in our Digital Age: Establishing a European Cybercrime Centre (EC3), which was adopted on 28 March 2012. This Communication stated that the fight against cybercrime, for which the main legal instrument is the Council of Europe Cybercrime Convention, continues to be a top priority for the EU.

The Centre will develop a common standard for cybercrime reporting so that serious cybercrime can be reported to national law enforcement authorities in a uniform way; respond to queries from and train cybercrime investigators, prosecutors and judges as well as the private sector on specific technical and forensic issues; and:
 
"assume the collective voice of European cybercrime investigators, providing a platform to develop common positions of Union law enforcement authorities on key issues, for example on Internet governance structures or in building trusted networks with the private sector and non-governmental organisations, and providing the natural interface for international initiatives to curb cybercrime, such as Interpol's work in this domain".

For more details, see:

Wednesday, 9 January 2013

Cyber Security

"The cyber threat is, like some other emerging threats, one which has the capacity to
evolve with almost unimaginable speed and with serious consequences for the
nation’s security. The Government needs to put in place – as it has not yet done –
mechanisms, people, education, skills, thinking and policies which take into account
both the opportunities and the vulnerabilities which cyber  presents. It is time the
Government approached this subject with vigour"

thus speaks the Defence Select Committee of the House of Commons. A PDF version of its report can be downloaded from this link. The report has received extensive publicity and you can find a BBC report here

Another Parliamentary Committee, the Home Appairs Select Committee is conducting an investigation into e-crime and you can find its ongoing work via this link

Monday, 31 December 2012

The Office of Communications v IC

The Information Rights Tribunal has ruled on an ongoing matter about disclosure of the precise location and other details of mobile operators' base stations under the Environmental Information Regulations 2004, holding that Ofcom must release the information supplied to it by mobile operators, including information about the TETRA network, which is used for emergency services communications.

The decision is EA/2006/0078.

The tribunal adopted much of the reasoning of the tribunal which originally heard the case, with some added discussion about the nature of the public interest test and its application, in determining certain qualified exemptions to the regulations.

The result of this case is that, in a few days, a lot of detailed information about cell site locations, power outputs and directions and the like will be released to the applicant in the case by Ofcom. It remains to be seen what the applicant will do with this information — the tribunal acknowledges that the operators' claims to database rights may well be valid, and that, whilst the claimant is entitled to receive these data, it does not get a licence for any act restricted by copyright — but I would have expected it to be posted online.

What do you think? Should this sort of information be made public? Or is it right that it should be kept confidential? Do you think there's a risk here that, if operators cannot trust their regulator to keep information private, they will stop providing information, potentially frustrating a regulator's ability to regulate?

Sunday, 9 December 2012

From Freiburg


I'm, along with Steve Saxby, in snowy Freiburg at the moment attending a very interesting conference on the future of the Council of  Europe Cybercrime Convention. It is advertised as a  meeting of experts (about 15 of us). Especially in the later sessions  I have the feeling that I am here under false pretences!

At first  the focus was on substantive law and the specific offences laid down in the Convention. There was a lot of discussion how the technology had moved on since the Convention was drafted. A couple of points which may be of interest. A lot of concern was expressed  that trying to tie criminal  provisions to telecommunications terminology no longer works. The notion of messages being in the course of communication (or not) is problematic. One issue which attract a lot of attention is when and to what extent emails are protected legally against interception? Generally once it has read by the recipient a message  is classed as being stored and ( at least in continental legal systems) gets a lot less protection than when it is being communicated. As one person commented, in the age of the cloud, storage is merely a slow form of communication. In a slightly different context, there is evidence that criminals/terrorists are using email systems such as google or yahoo. Member one can post a message in draft format n the mail server. If member 2 ( or 3 or 4 ...) can access the email box they can amend the message but in traditional terms there is no communication. But  there is communication!

We considered also the need to harmonise the provisions of data protection and computer crime legislation. A linked topic was the suggestion that we need to extend data protection laws to include commercial data (as happens to some extent under the Communications Privacy Directive. This might give criminal law protection to things like trade secrets without having to wrestle with the thorny topic whether data might be consider property. In the UK , and moving away  from Freiburg, there is a very interning High Court decision on the point - Fairstar v.Adkins ([2012] EWHC 2952).

A good deal of time was spent on the topic of copyright law. Perhaps surprisingly, there was little support from copyright owners attempts to involve the criminal law. We has a senior German policeman present and he indicated that the German police were not interested in acting against ordinary users. He recounted a tale of one copyright owner who, with the aid of dishonest lawyers, actually uploaded materials to a file sharing web site and then got the lawyer to demand money with menaces from individuals who had downloaded materials.

Day one saw a bit of momentum for (limited changes to the Convention), At the start of day 2 we heard from a senior Council of Europe person who spoke in some detail about the problems any attempt to make changes would be. What the Council are planning is to make more use of Guidance Notes. There were he considered ( and those of us from the UK will know the truth of his comments) too many misunderstandings by police, prosecutors and judges as to what the legislation means. The criminality  of denial of service attacks was an example he gave. In addition, there might be more protocols attached to the Convention although the basic instrument is likely to email unchanged. A number of new countries ( including Japan) have now ratified the Convention and more are in the pipeline.

The focus of the second day was on procedural issues and we started with a discussion about transborder issues. If police in England execute a search warrant and find a computer with a link to an email account in the United States, can they access it. he general consensus was that laws were rather vague but that law enforcement agencies would access data unless they knew that it was held outside their jurisdiction. A difficult test! There are tensions in the field. We talk much about cyber terrorism and it got publicity in the UK last week with the publication of a Ministerial statement on the working of the UK's cyber terrorism strategy. All countries need to build defences against such attacks but the danger or difficulty is that attempts to pre-empt attacks may involve accessing sites on foreign  territories. The analogy was drawn with sending troops into foreign territories to rescue citizens being held hostage. Politically risky if done without the knowledge and consent of the territory in question.

Perhaps not surprisingly but rather depressingly, there was little confidence in cross border cooperation between law enforcement agencies and aspects of the session had me first baffled by some of the technologies that scientific experts were talking about but also with the feeling that only clever criminals have any real expectation of privacy in the modern world. Encryption poses real challenges to law enforcement and the only real solution identified was to attack suspected computers at source - before data was encrypted for transmission. Again, arrangements for intercepting communications have become more complex in recent  years and again the point came over that there was too much reliance on telecommunications terminology. Can SKYPE be required to maintain a capability to intercept communications at the behest of law enforcement?

I have to say that I can only hope that I have given an accurate account of the procedural discussions. There were times when, although all the sessions were conducted in English, I could have benefited from simultaneous translation of the technologies.

All in all, a fascinating 2 and a half days ( and rather long days). I certainly learned a lot ( and also found an Irish pub to watch the Celtic Champions League game) but suspect we are still at the stage which does make IT law both fascinating and frustrating. We are increasingly aware that old models are not working but are not sure what can replace them. In a networked world we need global solutions but as we can see in the Euro crisis, this is not easy to achieve even at a regional level. The Council of Europe Convention is achieving success in being ratified but it is very general in its provisions, especially at the procedural level.

Hopefully I will be able to post more formal minutes of the meting in a month or so. In the meantime,  maybe this account will be f interest in showing the possible form of future developments.

Tuesday, 4 December 2012

"When in China, don't leave your laptop alone"

InfoWorld makes a very bold assertion: "If you travel to China or Russia, assume government or industry spooks will steal your data and install spyware."

Is this something which all companies need to be aware of, from a basic data protection point of view, if employees are traveling with laptops which have on them, or enables easy access to, customer data, to meet the requirement of "appropriate security"?

Friday, 30 November 2012

ICO's code of practice on anonymisation

The Information Commissioner's Office has released its code of practice on anonymisation, following a consultation period earlier in the year.

It's quite a lengthy document, but is worth a look —
  • it reaffirms that anonymising data is an act of processing in itself, but one which is likely to be permitted under the "legitimate use" basis, and thus does not require consent;
  • there's an interesting discussion about the disclosure of anonymous data, and the "motivated intruder" test for determining whether something should be treated as anonymous or not; and
  • the second case study, on mobile footfall analytics, is particularly pertinent to the course here — my view is that the overall privacy harm (and public perception of the activity) would seem to demand more user control over the activity than ICO has seemed to suggest here.
What do you think? Does it set the bar too low, or it is realistic?

Tuesday, 27 November 2012

Unleashing the Potential of Cloud Computing in Europe


I saw this report from the EU commission and thougth to share it. It gives an overview and status of the cloud computing within the EU.

http://ec.europa.eu/information_society/activities/cloudcomputing/docs/com/com_cloud.pdf


Cloud computing requires clarity and knowledge about the applicable legal framework,
by making it easier to signal and verify compliance with the legal framework (e.g. through
standards and certification) and by developing it further (e.g. through a forthcoming
legislative initiative on cyber security).

Monday, 19 November 2012

Judge: Your boss has no right to your emails held by a third party


"Staff emails can’t just be accessed by a company whenever it feels like it, a UK High Court Judge has ruled, in what could be a guiding case on email privacy."

"The only way that emails could belong to a firm is if they contained copyrighted material or confidential information or if the employee’s signed contract with the firm already said so."


This is new to me, having been employed for so long, and it has  always been the case that employees should be careful on how to use their e-mails becuase the company has the right for accessing it.


Full text here.

Friday, 16 November 2012

Businesses need more guidance on how to verify cloud providers' data protection compliance, says EU watchdog


Organisations need to be provided with further guidance over how to ensure that the cloud computing providers they wish to contract with deal with personal data in a manner that complies with EU data protection laws, a privacy watchdog has said.

Full text here.

Certainly, personal data protection covers storing and processing within the cloud, therefore compliance with EU data protection laws is required.