Sunday, 9 December 2012

From Freiburg


I'm, along with Steve Saxby, in snowy Freiburg at the moment attending a very interesting conference on the future of the Council of  Europe Cybercrime Convention. It is advertised as a  meeting of experts (about 15 of us). Especially in the later sessions  I have the feeling that I am here under false pretences!

At first  the focus was on substantive law and the specific offences laid down in the Convention. There was a lot of discussion how the technology had moved on since the Convention was drafted. A couple of points which may be of interest. A lot of concern was expressed  that trying to tie criminal  provisions to telecommunications terminology no longer works. The notion of messages being in the course of communication (or not) is problematic. One issue which attract a lot of attention is when and to what extent emails are protected legally against interception? Generally once it has read by the recipient a message  is classed as being stored and ( at least in continental legal systems) gets a lot less protection than when it is being communicated. As one person commented, in the age of the cloud, storage is merely a slow form of communication. In a slightly different context, there is evidence that criminals/terrorists are using email systems such as google or yahoo. Member one can post a message in draft format n the mail server. If member 2 ( or 3 or 4 ...) can access the email box they can amend the message but in traditional terms there is no communication. But  there is communication!

We considered also the need to harmonise the provisions of data protection and computer crime legislation. A linked topic was the suggestion that we need to extend data protection laws to include commercial data (as happens to some extent under the Communications Privacy Directive. This might give criminal law protection to things like trade secrets without having to wrestle with the thorny topic whether data might be consider property. In the UK , and moving away  from Freiburg, there is a very interning High Court decision on the point - Fairstar v.Adkins ([2012] EWHC 2952).

A good deal of time was spent on the topic of copyright law. Perhaps surprisingly, there was little support from copyright owners attempts to involve the criminal law. We has a senior German policeman present and he indicated that the German police were not interested in acting against ordinary users. He recounted a tale of one copyright owner who, with the aid of dishonest lawyers, actually uploaded materials to a file sharing web site and then got the lawyer to demand money with menaces from individuals who had downloaded materials.

Day one saw a bit of momentum for (limited changes to the Convention), At the start of day 2 we heard from a senior Council of Europe person who spoke in some detail about the problems any attempt to make changes would be. What the Council are planning is to make more use of Guidance Notes. There were he considered ( and those of us from the UK will know the truth of his comments) too many misunderstandings by police, prosecutors and judges as to what the legislation means. The criminality  of denial of service attacks was an example he gave. In addition, there might be more protocols attached to the Convention although the basic instrument is likely to email unchanged. A number of new countries ( including Japan) have now ratified the Convention and more are in the pipeline.

The focus of the second day was on procedural issues and we started with a discussion about transborder issues. If police in England execute a search warrant and find a computer with a link to an email account in the United States, can they access it. he general consensus was that laws were rather vague but that law enforcement agencies would access data unless they knew that it was held outside their jurisdiction. A difficult test! There are tensions in the field. We talk much about cyber terrorism and it got publicity in the UK last week with the publication of a Ministerial statement on the working of the UK's cyber terrorism strategy. All countries need to build defences against such attacks but the danger or difficulty is that attempts to pre-empt attacks may involve accessing sites on foreign  territories. The analogy was drawn with sending troops into foreign territories to rescue citizens being held hostage. Politically risky if done without the knowledge and consent of the territory in question.

Perhaps not surprisingly but rather depressingly, there was little confidence in cross border cooperation between law enforcement agencies and aspects of the session had me first baffled by some of the technologies that scientific experts were talking about but also with the feeling that only clever criminals have any real expectation of privacy in the modern world. Encryption poses real challenges to law enforcement and the only real solution identified was to attack suspected computers at source - before data was encrypted for transmission. Again, arrangements for intercepting communications have become more complex in recent  years and again the point came over that there was too much reliance on telecommunications terminology. Can SKYPE be required to maintain a capability to intercept communications at the behest of law enforcement?

I have to say that I can only hope that I have given an accurate account of the procedural discussions. There were times when, although all the sessions were conducted in English, I could have benefited from simultaneous translation of the technologies.

All in all, a fascinating 2 and a half days ( and rather long days). I certainly learned a lot ( and also found an Irish pub to watch the Celtic Champions League game) but suspect we are still at the stage which does make IT law both fascinating and frustrating. We are increasingly aware that old models are not working but are not sure what can replace them. In a networked world we need global solutions but as we can see in the Euro crisis, this is not easy to achieve even at a regional level. The Council of Europe Convention is achieving success in being ratified but it is very general in its provisions, especially at the procedural level.

Hopefully I will be able to post more formal minutes of the meting in a month or so. In the meantime,  maybe this account will be f interest in showing the possible form of future developments.

Tuesday, 4 December 2012

"When in China, don't leave your laptop alone"

InfoWorld makes a very bold assertion: "If you travel to China or Russia, assume government or industry spooks will steal your data and install spyware."

Is this something which all companies need to be aware of, from a basic data protection point of view, if employees are traveling with laptops which have on them, or enables easy access to, customer data, to meet the requirement of "appropriate security"?

Friday, 30 November 2012

ICO's code of practice on anonymisation

The Information Commissioner's Office has released its code of practice on anonymisation, following a consultation period earlier in the year.

It's quite a lengthy document, but is worth a look —
  • it reaffirms that anonymising data is an act of processing in itself, but one which is likely to be permitted under the "legitimate use" basis, and thus does not require consent;
  • there's an interesting discussion about the disclosure of anonymous data, and the "motivated intruder" test for determining whether something should be treated as anonymous or not; and
  • the second case study, on mobile footfall analytics, is particularly pertinent to the course here — my view is that the overall privacy harm (and public perception of the activity) would seem to demand more user control over the activity than ICO has seemed to suggest here.
What do you think? Does it set the bar too low, or it is realistic?

Tuesday, 27 November 2012

Unleashing the Potential of Cloud Computing in Europe


I saw this report from the EU commission and thougth to share it. It gives an overview and status of the cloud computing within the EU.

http://ec.europa.eu/information_society/activities/cloudcomputing/docs/com/com_cloud.pdf


Cloud computing requires clarity and knowledge about the applicable legal framework,
by making it easier to signal and verify compliance with the legal framework (e.g. through
standards and certification) and by developing it further (e.g. through a forthcoming
legislative initiative on cyber security).

Monday, 19 November 2012

Judge: Your boss has no right to your emails held by a third party


"Staff emails can’t just be accessed by a company whenever it feels like it, a UK High Court Judge has ruled, in what could be a guiding case on email privacy."

"The only way that emails could belong to a firm is if they contained copyrighted material or confidential information or if the employee’s signed contract with the firm already said so."


This is new to me, having been employed for so long, and it has  always been the case that employees should be careful on how to use their e-mails becuase the company has the right for accessing it.


Full text here.

Friday, 16 November 2012

Businesses need more guidance on how to verify cloud providers' data protection compliance, says EU watchdog


Organisations need to be provided with further guidance over how to ensure that the cloud computing providers they wish to contract with deal with personal data in a manner that complies with EU data protection laws, a privacy watchdog has said.

Full text here.

Certainly, personal data protection covers storing and processing within the cloud, therefore compliance with EU data protection laws is required.

Monday, 8 October 2012

Welcome to Information Security


As we start work on the module I want to make a posting which is perhaps rather different from the norm. If you have had the chance to look back at previous postings you will realise that they normally relate to topical issues. Today, I’m going to say a bit about myself and throw out some opening thoughts about the module.

I live in Glasgow and that perhaps says a lot about the potential of the Internet. I’m teaching this course for the University of Southampton which is about 500 miles away. I visit Southampton maybe 3-4 times a year and do the rest of my work over the Internet.

I’ve taught in the field of Information Technology Law for about 25 years. It feels longer.  My book on IT law is now in its sixth edition and I have a new book on Telecommunications Law due out early next year. Its aimed at the practitioner market and is being sold at an eye watering £150.

I’m married to Moira – who you will also get to know on the course – and we have 2 sons, Thomas and James.  Apart from the family another love of my life is Glasgow Celtic Football Club. If you ever want to contact me to ask a favour, you might check to see how we fared in our latest matches. We are doing quite well at the moment.

On to legal aspects of information security. We will start by looking at notions of privacy and then put this into an IT context by looking at what we in Europe call data protection  - and the rest of the world know as privacy protection. We will look at substantive provisions – such as the data subject’s (you and me) right to obtain a copy of data about us which is held on a computer – and then the internationally contentious issue of regulation of international (Transborder) data flows. . We will then switch focus somewhat and look at the topic of computer crime.

A few thoughts about privacy.  It’s certainly seldom out of the news. I was teaching in Tanzania a few weeks ago when the controversy erupted about the publication of topless photos of the Duchess of Cambridge. Breach of privacy was the cry. Three comments – or maybe points for you to ponder. Would anyone have been interested if the photos had been of Katy Ordinary Person?  In many respects the doctrine I linked to publication which is likely to affect only a few people.  A second comment.  You cannot view  the photos in any UK publication. I set my Tanzanian students the task of finding copies on the Internet. Time taken, less than 10 seconds.  Third comment and perhaps related to the previous  one. Traditional media outlets do try (generally) to comply with the law  and can face sanctions if they fail. I have a lawyer friend who is employed by a newspaper to read the text of every issue before it is published to ensure that it does not contain anything which is defamatory. Blogs and web sites are seldom so scrupulous. Last year, a famous English footballer secured an injunction to prevent publication of details of his private life (an affair with his brother’s wife). The injunction prohibited publication of anything that might identify him. At least initially, the injunction  was observed by the mainstream media.  Again, you could go on to the Internet and a couple of Google searches later you had all the salacious details. By my reckoning, however, 3 other footballers were (presumably) falsely identified on different web sites. Power without responsibility?

Anyway, please respond to this posting with a little bit of data about yourself and your thoughts, either about the points I have made or your own take on privacy. What, if any, aspects of modern Internet related life worry you?