Showing posts with label Digital Rights Ireland. Show all posts
Showing posts with label Digital Rights Ireland. Show all posts

Monday, July 01, 2019

From Alan Turing to the mass surveillance machine that is the internet

I gave a talk, on Saturday last, at the 9th Tensions of Europe Conference in Luxembourg. Draft of my remarks below. They are relatively brief and as a result somewhat over-simplified.


From Alan Turing to the mass surveillance machine that is the internet

In November 1942, English code breaker, Alan Turing, arrived in the US on a four-month intelligence sharing visit. He was met by three immigration officers and very nearly denied entry and dispatched to Ellis Island immigration detention centre, due to anomalies in his documentation. Two of the three eventually agreed he should be admitted.

There followed an intense period of work with the US Navy’s intelligence service in Washington DC and Bell Labs in New York. This was partially hampered by bureaucratic issues with his security clearances, and Turing’s unofficial instructions from British intelligence to reveal as little as possible to their US counterparts. The British were distrustful of the US government and vice versa.[i]

It became clear that the absence of trust and cooperation was impairing the war effort and shortly after Turning’s visit, US Intelligence officials Colonel Alfred McCormack, Lieutenant Colonel Telford Taylor, and Lieutenant Colonel William Friedman travelled to Britain to work with the head of Bletchley Park, Edward Travis. Friedman played a key role in the cracking of the Japanese Purple code and Taylor went on to become the chief US prosecutor at the Nuremberg trials. The parlay between Travis and the US delegation led to the 1943 BRUSA Agreement (Britain–United States of America agreement) to share intelligence.

BRUSA in turn spawned the UKUSA Agreement in 1946 to share signals intelligence (sigint) and communications security (comsec, the security of the processes, infrastructure and products of that sigint).

By 1956 Canada, Australia and New Zealand became parties to the agreement and it became known as the Five Eyes (FVEY). This FVEY agreement (or now collection of agreements) forms the basis of intelligence cooperation between these countries to this day.



[Norway, Denmark, and West Germany became secondary associates in the 1950s.]

At this point I’m going to have to fast forward through decades and significant parts of the story.*
To the FYEV intelligence & security services in the 1990s. The Cold war was supposedly over. They were suffering what they considered to be underinvestment and lack of appreciation. The Internet & WWW were going global and there were serious concerns in the agencies about keeping up.

ECHELON, the satellite centred surveillance system, developed by FVEY in the late 60s to early 70s, intended to collect communications of Soviet leaders, military personnel and diplomats, had already been turned to spying on FVEY allies like Germany and France; and the surveillance of individuals and commerce, facilitating industrial espionage.

That’s not my conclusion btw, that comes from a 2001European Parliament report on ECHELON at a time when the FVEY alliance was refusing to confirm or deny ECHELON officially existed. The report said there was no longer any doubt – it exists but all the EU could do is ask the FYEY, nicely, to stop spying on us. Some members of the committee disavowed the report as too soft and declaring that the deployment of ECHELON constituted a blatant breach of European law and the EU Charter of Fundamental Rights. It did conclude, however,

“However extensive the resources and capabilities for the interception of communications may be, the extremely high volume of traffic makes exhaustive, detailed monitoring of all communications impossible in practice.”

So even those who were deeply critical of the surveillance activities of FVEY accepted that these organisations were being snowed under with electronic data.

9/11 to 7/7

When the September 11, 2001 attacks on the US happened with the tragic loss of thousands of lives, everything changed. The US & UK now had a new demon to replace the Soviet Union – terrorism. So began the US orchestrated war on terror and huge resources were poured into recruitment and mass surveillance technology. Much of it was wasted e.g. Trailblazer and, if we take the word of NSA whistleblowers such as Thomas Drake or William Binney, fraudulently so.

Military action in Afghanistan began within weeks and followed in Iraq about 18 months later.[ii]

The action in Iraq & Afghanistan stretched GCHQ operationally.

On 11/3/2004 the Madrid train bombings, the biggest terrorist attack in Spain in history, killed 191 and injured more than 2000 people.

The following year. The 7/7/2005 London attacks led to 56 deaths and nearly 800 were injured.

The Data retention directive, an intimate part of the mass surveillance story in Europe

In the wake of the 2005 London attacks there was a reinforced urgency in government about doing something about terrorism. In the UK the Blair government obsessively pursued mass data retention and all manner of other privacy decimating policies, regulations and processes, culminating in the EU Data Retention Directive 2006. Government ministers were drilled to chant the poisonous & deceitful but powerful ‘nothing to hide, nothing to fear’ sound bite, at every conceivable opportunity.  One of the things, incidentally, UK governments are going to miss after Brexit is the policy laundering they pursued so successfully through the EU.

Mass communications data retention was later found unlawful in multiple high courts around Europe - Romania (2009), Germany (2010), Bulgaria (2010), the Czech Republic (2011) and Cyprus (2011) have all declared the data retention directive unconstitutional and/or a disproportionate unjustified interference with the fundamental right to privacy, free speech and confidentiality of communications.

In 2006 GCHQ began their ‘SIGMod Initiative’ (signals intelligence modernisation programme) on gathering, processing, analysing, assessing, storing, distributing and sharing communications data. The government proposed an Intercept Modernisation Programme (IMP) 2008 involving the spending of £12 Billion + passing a proposed new law, the Communications Data Bill. A small number of NGOs, notably the Open Rights Group, Liberty and Privacy International, managed to get the attention of the media and a few politicians, noting the proposals were a terrible idea and labelling the whole thing a‘Snoopers’ charter.’ And with the financial crash of 2007/’08 and an election imminent it was officially shelved but the government and security & intelligence services implemented it in secret anyway.
 
Snowden 2013

Meanwhile stateside, an insider at the NSA, Edward Snowden, decided that the activities of the FVEY had reached the point of unchecked intrusion into the lives of ordinary people to a degree that was unconscionable and indefensible. In June 2013 Snowden chose to smuggledocumentary evidence of these activities to Hong Kong where he handed them over to journalists Glenn Greenwald, Laura Poitras and Ewan MacAskill.[iii]

What was revealed was a spectacular array of FVEY resources, technical capabilities and activities, with a very limited degree of legal or political oversight, checks or balances. Mass surveillance was not only being conducted by the commercial behemoths of Silicon Valley and every economic actor with a Web presence but by governments of the FVEY alliance. And these security services, like Silicon Valley, had their processes and technologies[iv] targeted at entire populations.

One of the surprises for informed security and intelligence analysts that came out of the Snowden revelations was that GCHQ and the NSA had got these large-scale systems working. The history of government deployments of large-scale information age IT projects had not previously been promising.

Circumventing & breaking law

According to the Snowden documents, one of the effects of the FVEY agreement was that NSA shared intelligence with GCHQ to circumvent UK law and vice versa. The documents quote US intelligence services staff considering that their UK equivalents had no real legal restrictions to abide by. The UK end of the operation likewise talked of their light regulatory regime as being a ‘selling point’ in soliciting funds from the NSA, amounting to $100 million between 2010 and 2013. So, if there were technical legal restrictions on the NSA’s activities – e.g. not being permitted to target US citizens, they could just get the British to do the surveillance for them. Officially this was denied. 

Even where to request the information would be a technical legal breach, it could be circumvented by the transatlantic sharing of information, under FVEY, without the need for a formal request.

Snowden changed things in Europe, if not the UK. EU allies were angry at the scale and reach of FVEY surveillance resources, targeted at their populations, policymakers (including tapping Angela Merkel’s phone) and economic actors. The European Court of Human Rights and the Court of Justice of the European Union became sensitised to mass surveillance and issued a series of decisions declaring the activities unlawful.

The European Court of Justice in the Digital Rights Ireland case in 2014 declared the data retention directive so bad it should never have existed and abolished it.

DRIPA 2014 – the UK’s let’s pretend the data retention directive didn’t get abolished Act.

The UK government decided to ignore the ruling. UK chief police officers issued an edict to their police forces to continue retaining data. When the government couldn't ignore it any more because they were being sued and the press were about to start paying attention to it, they passed a new law, the Data Retention and Investigatory Powers Act 2014.

This contained 8 sections and was rushed through parliament in record time with no scrutiny, by means of a very rarely used parliamentary process, just as MPs were about to go on their summer holidays. [The party briefings instructing MPs what to say about this law in public were longer than the law and both the parties of the coalition government - the Tories and Lib Dems - and the Labour party were all in favour.]

UK Investigatory Powers Act 2016 [v]

Far from reigning in surveillance and other activities revealed by Snowden in 2013, and those previously known and found by high courts all round Europe to be in breach of fundamental human rights, the UK passed the Investigatory Powers Act 2016, to legalise them. Whereas the US made some effort to be seen to be engaging in at least cosmetic reforms to that nation’s surveillance laws, the UK government denied there was an issue, trotted out tropes about national security and “nothing to hide, nothing to fear”, issued gagging orders, ritually destroyed the Guardian’s computers and reinforced and expanded the scope of intelligence gathering activities permitted.  Providing this legal infrastructure, with extraterritorial reach, to enable and facilitate the exploitation of modern digital technologies and networks, nominally for security and intelligence purposes and, with arguably limited checks and balances, has profound implications for democracy, all around Europe.

It remains also, however, the long standing FYEY intelligence sharing operation between the US, UK, Canada, Australia and New Zealand, that now deploys the considerable resources made available by the respective governments to exploit the infrastructure of the internet to engage in mass surveillance around the globe. This is not about FYEY being old and dated. The UN Declaration of Human Rights and the European Convention on Human Rights both stem from the same period and stand strong; as do multiple other historic documents like the US Constitution and Bill of Rights. However, the FVEY sigint agreement, as an arrangement emerging from the devastation of WWII and the ‘Second Red Scare’ and designed primarily to facilitate the collection of intelligence on the Soviet Union, China and their allies, in the modern context now reaches deeply into the lives and homes of ordinary people.

Liberty and others have taken the battle over the Investigatory Powers Act 2016 bulk surveillance provisions back to the courts. In April 2018 the UK High Court ruled that the data retention elements of the Act were unlawful.[vi] On 11 June 2019 it emerged that, even with the extra permissions of the Act, MI5 had been acting so far outside the scope of the legislation, in relation to their data management practices, that documents compelled to be revealed to the court showed that the independent ‘Investigatory Powers Commissioner’ (IPC) declared the agency’s bulk surveillance data management practices “undoubtedly unlawful”.[vii] [The Investigatory Powers Commissioner was a new office, set up under the Investigatory Powers Act, charged with dual oversight, along with the relevant Secretary of State, of the activities subject to the Act.] 

MI5 had effectively been caught out unlawfully retaining innocent people’s data for years, failing to give the IPCO (IPC's Office) accurate information about repeated breaches of its duty to delete bulk surveillance data, and mishandling sensitive legally privileged material. Even if this can be chalked up to normal bureaucratic failings on the part of a government service, this must be concerning.

The reality of FVEY is significantly more complex than I have the time to cover here. It has not, in practice, facilitated blanket, open, totally frictionless sharing of intelligence between the US, UK and other FYEY partners. Just because they agreed to share intelligence and not spy on each other, did not mean they stuck to that agreement or collection of agreements. Intelligence and security services, even within national boundaries, tend to be complex Faustian ecologies of competing institutions, individuals, agendas, bureaucracy and politics, wrapped up in an evolutionary internecine game of the survival of the fittest, surfing on the cause of protecting national security.

We should take infinitely more care in building and continuing to expand the legal, technical & organisational infrastructure of mass surveillance. Such complex systems fail naturally - systems fail, people make mistakes, staff under pressure circumvent the systems to get the job done and the temptation to hide those failures is organisationally irresistible. It will always be so & that's before you start factoring in malign actors because complex systems can also be made to fail by internal and external attackers with nefarious intent. Create these systems and the failures will come. We know this because they have failed and there is not a computer scientist or security specialist anywhere in the world who can secure them and make them water-tightly safe in practice.


The internet has become a huge surveillance machine.

It is possible, as the Net is an entirely artificially designed and constructed entity, to wrestle/retrofit it into something useful that is not a mass surveillance machine. However, it will be difficult to do, in practice, as all the most powerful governmental and commercial economic actors, as well as us the masses of the bread & circuses distracted unwashed users, caught in the headlights of seductive surveillance, are addicted to that architecture of surveillance. 

The critical question is how. How do we cultivate, energise, harness, direct and sustain sufficiently powerful socio-economic, political, commercial, cultural, environmental, social and technical forces to transforming the internet into something with a human rights respecting architecture, at an individual, community, district, national, transnational and global level?


As Carl Sagan said, science and technology heap a new and awesome responsibility on the shoulders of scientists, technologists, policymakers and Jo Public, to pay more attention to the hazards and long-term consequences of advances, from individual, communities, regional, global & multi-generational perspectives, avoiding appeals to simplistic claptrap and the nationalism, chauvinism and hate mongering so prevalent in modern politics & media.


[i] The British worried about the rivalry between US navy and army potentially leading to leaks. The US were equally distrustful of the British and frustrated, given the 500+ US ships sunk by U-boats in the previous year, that they were so unwilling to share information.
[ii] {Katherine Gun GCHQ whistleblower case – UN second resolution, NSA memo 31 Jan 2003 requiring UK to spy on world leaders in the hope of blackmailing them into supporting war. This came about a week after GCHQ staff, deeply concerned about the legitimacy of the impending conflict, had been officially assured they would not be required to engage in illegal activity. Gun, a 28-year-old analyst, admitted passing the NSA memo to the Observer newspaper which printed it in full on its front page in early March, having spent a month confirming its provenance. AG equivocal legal advice on war led to Gun’s prosecution being dropped in February 2004}
 [iii] Unlike Wikileaks who tended to put everything openly on the internet, Snowden decided the documents should be curated by respected news organisations, like The Guardian and The Washington Post newspapers, with revelations to be made public selected purely based on the public interest and the avoidance of exposure of intelligence services personnel to risk.
[iv] [of what the UK end of the business now calls “bulk” interception, acquisition, equipment interference and personal dataset warrants]
My evidence to Joint Committee on Investigatory Powers Bill https://b2fxxx.blogspot.com/2016/01/evidence-to-joint-committee-on.html
‘S253 Technical capability notices
(1)     The Secretary of State may give a relevant operator a technical capability notice…’
Operators have multiple dutes to assist with implementation of IPAct measures.
[vi] [Since ministers were empowered by the Act to issue data retention orders without independent review and authorisation – and for reasons which have nothing to do with investigating serious crime – it was a breach of fundamental rights.] 
[vii] [He also said that he has effectively put them in special measures after discovering they were misleading the Investigatory Powers Commissioner’s Office (IPCO).
“Without seeking to be emotive, I consider that MI5’s use of warranted data... is currently, in effect, in ‘special measures’ and the historical lack of compliance... is of such gravity that IPCO will need to be satisfied to a greater degree than usual that it is ‘fit for purpose'".]
*Including the cold war & evolution of sigint processes and technology, establishment of Menwith Hill and other sigint infrastructure, the Korean war, the development of the ARPANET, ECHELON, the emergence of the WWII sigint story, the Pentagon papers, Watergate, Nixon, the FISA court, the ABC trials, the accidental but happy coincidence of technology and regulation that enabled the early internet to be built on the back of telephone networks, with an end to end architecture – the ‘intelligence’ was not built into the network but rather the devices that connected to it – enabling anyone to innovate, Reagan’s Executive Order 12333, Duncan Campbell’s 1988 revelation of ECHELON (it was an extension of the UKUSA Agreement; He also detailed how Echelon worked), Tim Berners Lee’s creation of the WWW protocols, the WWW & Net going mainstream, the cryptowars, the internet’s midwifery of today’s big 5 tech giants, the West’s military adventures, RIPA, 9/11, the US Patriot Act, the ‘war on terror’, Total Information Awareness, Trailblazer, NSA whistleblowers Bill Binney (ThinThread) & Thomas Drake, National Security Letters, Blair government architects of the data retention directive 2006 and national identity cards and a blizzard of serious crime and anti-terrorism regulations expanding powers of law enforcement, intelligence & security services, US FISA Amendment Act 2008 Act – guilty of being a foreigner – Caspar Bowden & Microsoft, NSA violation of FISA court orders, Bush & Blair establishment and Obama and Con-Dem coalition consolidation and expansion of architecture and resources of mass surveillance conducted by FYEY. Some of Snowden's revelations
PRISM – targeted intelligence, this had some justification and defensible due process overseen by the FISA Court
Tempora – GCHQ hardwire tap of UK backbone cables (UK connected to 57 countries by fibre optic cables; US is connected to 63)
Upstream - BLARNEY, FAIRVIEW, OAKSTAR and STORMBREW NSA interception tools
Boundless Informant – metadata engine, data analysis and data visualisation tool
Blanket open-ended court orders for Verizon phone records
XKeyscore – the NSA’s Google, for collection of "almost anything done on the internet" (Snowden claimed he could wiretap anyone anywhere with it and indeed Angela Merkle’s and other world leaders’ phones were tapped; Angela Merkel's phone communications were monitored by the Special Collection Service, part of the STATEROOM program)
OpticNerve
Mainway - NSA mass phone tapping
Bullrun (NSA) & EdgeHill (GCHQ) to crack encryption
MUSCULAR (mainly GCHQ run) secretly tapped Yahoo! & Google data centres
NSA black budget to pay commercial organisations for secret access to their networks
Spied on gaming sites, charities, commercial enterprises like Brazil’s biggest oil company, dozens of world leaders including Merkle
TURBINE – malware
Tailored Access Operations (TAO) – NSA’s cyberwar sigint operation
QUANTUM suite of attacking facilities e.g. compromising routers, interception, duplication & compromising of traffic
Tapping phones of world leaders including Germany’s Angela Merkel
GCHQ’s Smurf Suite for hacking mobile phones
NSA & GCHQ tapping fibre optic cables to Google and Yahoo data hubs
NSA allowed to surveillance connections three hops from identified targets
UK operating a surveillance system where “anything goes”
If you want to know how some of this data collection and processing works one of the single most useful Snowden documents is the “HIMR Data Mining Research Problem Book
And even that lot is a wholly incomplete OTTOMH list but then there has been a lot of activity in this arena since WWII.

Monday, December 01, 2014

Email to MP re Counter Terrorism and Security Bill

The 2nd reading of Counter Terrorism and Security Bill is due in the House of Commons tomorrow.

Prompted by the Open Rights Group I've written to my MP, Nicola Blackwood, about it. Copy of my email below. Some of ORG's concerns are outlined in their briefing on the Bill.
Dear Nicola,

The latest government proposal, the Counter Terrorism and Security Bill, gives me cause for significant concern.

The ill-judged Data Retention and Investigatory Powers Act was, as you know, rushed through as emergency legislation without proper parliamentary scrutiny in the summer, the week before MPs went on holiday.  The use of the murder of Fusilier Lee Rigby as an excuse for introducing these new measures, expanding DRIPA and the further expansion of additional surveillance powers, is unconscionable.

With an election round the corner, we should hardly be surprised that party managers might be encouraging senior figures to ramp up their “tough on terrorism” rhetoric. However, Lee Rigby, who dedicated his life to defending the freedoms we enjoy in the UK, deserves better from our political leaders.

The UK survived two world wars, the cold war, multiple other military adventures and domestic bombing and violence orchestrated by groups like the IRA. Yet in the face of small numbers of violent religious extremists, successive UK governments, in the past 15 years, have normalised mass surveillance and done more damage to the legal infrastructure protecting our fundamental freedoms than any collection of deranged vicious clowns with access to dangerous weapons could do in a lifetime.

The Counter Terrorism and Security Bill is unfortunately building further on that trend.

1.       It introduces an obligation on public bodies including universities, schools, nurseries and councils to prevent terrorism. I've read this section 21 provision of the Bill repeatedly in the hope of making some sense of it. Yet the truth is, as a university educator with an interest in law and technology, I have genuinely no idea of what it is going to mean in practice.
   
2.       It expands the kind of meta-data that ISPs are being required to hold onto to help identify our IP addresses. This fundamentally misses the subtlety that an IP address denotes a device, not a human being.

3.       Mobile Phone companies do not currently log IP addresses because of differences in the technology to mainline broadband providers. They have been told they have to find a way. This will cost the taxpayer £100m over 10 years.

4.       The problems with the Bill are much wider than digital rights concerns. It also includes temporary exclusion orders, banning suspects from Britain for two years, even if they are British citizens.

5.       We are not currently facing a national emergency, so Parliament should not rush through this kind of legislation. We need proper scrutiny by MPs, Peers and civil society.

6.       The European Court of Justice (in the Digital Rights Ireland case this year) ruled that blanket data retention was incompatible with of articles 7, 8 and 52(1) of the Charter of Fundamental Rights of the EU. New laws should comply with that judgment. Neither DRIPA nor this proposed new Bill do so.

7.       The ECJ said that there should be a relationship between the data being retained and a threat to public security. However there are no restrictions to time, place or people in this Bill.

8.       DRIPA is even now the subject of a legal challenge, brought by the Open Rights Group and Liberty challenge. It may well be found illegal, while these new provisions are still being paid for.

Could I recommend for your review, the same Open Rights Group's analysis of the proposals in this Bill, available at https://www.openrightsgroup.org/ourwork/reports/briefing-on-counter-terrorism-and-security-bill  

Again you will not be surprised, given our previous correspondence, that I'm of the view that existing mass surveillance activities and powers need reigning in not expansion. Indeed the coalition government came to power on a promise of cracking down of the worst excesses of the previous government's database state. Rather than fulfilling that promise the current government has normalised and expanded these operations and powers. I hope when history comes to be written it will not judge the coalition's performance favourably on that score. Only then will we be sure that fundamental freedoms, under sustained attack by comparatively tiny numbers of terrorists and the bulk of the current, often well-intentioned but scientifically, mathematically and technically illiterate mainstream political classes, have survived intact.

Regards,

Ray

Wednesday, April 30, 2014

ECJ invalidate data retention directive

ECJ Invalidates data retention

On 8 April2014 the Grand Chamber of the European Court of Justice, (ECJ) in joined cases C-293/12 and C-594/12, issued a landmark decision declaring the 2006 data retention directive invalid.

The data retention directive was the instrument through which the EU required communications service providers, both fixed line and mobile, to store details of everything everyone does on the telephone or internet; for a period of between 6 months and two years. The details of what was required to be collected were laid out in article 5 of the directive and the only thing not permitted was recording of the content of calls or messages.

The ECJ decided that mass indiscriminate data retention interferes disproportionately and in a particularly serious manner with the fundamental rights to privacy and the protection of personal data.

The challengers

Digital Rights Ireland (DRI) and 11,130 Austrian citizens whose case was joined to that of DRI challenged the directive, ostensibly arguing it constituted an unlawful and unacceptable interference with fundamental rights to privacy and free speech. The Court focused on the effects of the data retention directive on articles 7 and 8 of the Charter of Fundamental Rights of the European Union - respect for private and family life and protection of personal data.

The Grand Chamber of the court proceeded to declare the directive invalid and effectively condemned pre-emptive, suspicionless, warrantless mass surveillance and consequent "interference with the fundamental rights of practically the entire European population".

Introduction and legal context

The Court opens by explaining Digital Rights Ireland challenged the implementation of the data retention directive into Irish law and the Austrian Constitutional Court, Verfassungsgerichtshof, was asked to consider the constitutionality of the Austrian implementation of the directive. They then set out the legal context.

The objective of the data protection directive, directive 95/46/EC, is to protect people's privacy. The aim of the directive on privacy and electronic communications, directive 2002/58/EC, is to harmonise privacy rights and allow sharing of data within and across the EU. Both these directives require appropriate technical and organisational measures to protect the security of personal data.  The 2002 directive prohibits surveillance without user consent, in theory. It has,however, the enormous loophole of article 15 which states any necessary, appropriate and proportionate measure can be used to bypass obligations to respect fundamental rights, when those measures are for national security or crime fighting reasons. Article 15 also specifically appears to approve of the retention of data.

The data retention directive itself obliged communications service providers to retain data. Under article 3, EU member state were required to adopt measures mandating data retention of categories of data specified in article 5. (Take a look at the list of information retained. It's almost unbelievable). Under article 4, access to this retained data would only be available to "competent national authorities" in specific cases and in accordance with national law. Article 6 specified the data should be retained for between 6 months and 2 years. Article 11 basically says when it comes to data retention the need to respect a basic level of fundamental rights theoretically noted in article 1 of the 2002 e-privacy directive could be ignored.

DRI and Austrian cases

The Court then outlines the Digital Rights Ireland and Austrian cases in paragraphs 17 to 22. DRI argued the directive constituted a disproportionate interference with fundamental rights to respect for privacy and family life, data protection and freedom of expression & information, guaranteed under articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union. Austrian citizens Mr Seitlinger, Mr Tschol et al sought the annulment of the Austrian law implementing data retention. The Austrian Court, took the view that data retention, because of the indiscriminate nature and scale of it, almost exclusively affects innocent people. The Verfassungsgerichtshof also felt data retention could not achieve its objectives and was disproportionate, so they also asked the European Court of Justice to review whether data retention constituted a disproportionate interference with fundamental rights guaranteed under articles 7, 8 and 11 of the Charter of Fundamental Rights of the European Union. Additionally the Verfassungsgerichtshof suggested the data protection directive and articles 52 and 53 of the Charter of Fundamental Rights presented barriers or at least limitations to data retention.

Next the ECJ considers the substance of the questions before them. They acknowledge (para 27) that the data mandated for retention taken as a whole provides a very rich picture of people's lives. Also that people might well adjust their behaviour and self censor due to the chilling effect of the knowledge of the mass data gathering (para 28). So there is a clear acceptance by the ECJ that freedom of expression protected by article 11 of the Charter could be on the line. They do not however pursue this to any solid conclusion and focus instead of matters of privacy and data protection, relating to articles 7 & 8 of the Charter.

Interference with privacy and data protection

The heavy lifting in the decision is then laid out from paragraph 32 to 71.
"32. ... Directive 2006/24... derogates from the system of protection of the right to privacy established by Directives 95/46 and 2002/58"
The data collected does not have to be sensitive or to inconvenience people in any way to establish the existence of an interference with the fundamental right to privacy. (Para 33). Data retention
"constitutes in itself an interference with the rights guaranteed by Article 7 of the Charter." (para 34). Access to the data retained by competent national authorities is an interference with the rights guaranteed by Article 7 of the Charter. (para 35). Likewise because the directive provides for the processing of personal data it is an interference with the fundamental right to data protection covered by article 8 of the Charter. (para 36). Paragraph 37 merits quotation in full:
"37.  It must be stated that the interference caused by Directive 2006/24 with the fundamental rights laid down in Articles 7 and 8 of the Charter is, as the Advocate General has also pointed out, in particular, in paragraphs 77 and 80 of his Opinion, wide-ranging, and it must be considered to be particularly serious. Furthermore, as the Advocate General has pointed out in paragraphs 52 and 72 of his Opinion, the fact that data are retained and subsequently used without the subscriber or registered user being informed is likely to generate in the minds of the persons concerned the feeling that their private lives are the subject of constant surveillance."
Justification for interference with fundamental rights

Having declared the interference with the fundamental rights to privacy and data protection particularly serious, the Court then must look at the justification for and proportionality of this interference. It finds the 2006 directive wanting on both counts.

Article 52(1) of the Charter of Fundamental Rights of the EU states that any circumvention of those rights must be proportionate, strictly limited and necessary to meet objectives of general interest or to protect the freedoms of others.

In paragraphs 39 and 40, the Court then makes a rather fuzzy attempt to step back from the absolutist stance it appears to have be shaping up to take against data retention.
"39... it must be held that, even though the retention of data required by Directive 2006/24 constitutes a particularly serious interference with those rights, it is not such as to adversely affect the essence of those rights given that, as follows from Article 1(2) of the directive, the directive does not permit the acquisition of knowledge of the content of the electronic communications as such."
This does not sit logically with the earlier acceptance in paragraphs 27 & 28 that metadata provides a very comprehensive picture of peoples' lives which could have a chilling affect on freedom of expression. It also seems something of a non sequitur - how must it be held that data retention constitutes a particularly serious interference with fundamental rights, yet not be such as to adversely affect the essence of those rights?

Paragraph 40 says the essence of article 8 data protection rights are not adversely affected because the text of data retention directive includes a note that says data protection must be respected. On that basis you could stick a token 'respect data protection' clause in every liberty bashing regulatory instrument and not "adversely affect" data protection.

The object of the the data retention is to fight serious crime and article 6 of the Charter of rights lays down the fundamental right to security. So fighting serious crime is a legitimate 'objective of general interest.' And communications technology is an important crime fighting tool. So
"44.  It must therefore be held that the retention of data for the purpose of allowing the competent national authorities to have possible access to those data, as required by Directive 2006/24, genuinely satisfies an objective of general interest."
Disproportionate nature of the data retention directive

The objective of data retention is acceptable. But is data retention a proportionate way to achieve that crime fighting objective? Proportionality requires acts of EU institutions to "not exceed the limits of what is appropriate and necessary in order to achieve" the objective in hand, in this case fighting serious crime.

The ECJ takes guidance from the European Court of Human Rights decision in 2008, S and Marper v UK, on the retention of DNA and fingerprints.
"47. ... the EU legislature’s discretion may prove to be limited, depending on a number of factors, including, in particular, the area concerned, the nature of the right at issue guaranteed by the Charter, the nature and seriousness of the interference and the object pursued by the interference (see, by analogy, as regards Article 8 of the ECHR, Eur. Court H.R., S. and Marper v. the United Kingdom [GC], nos. 30562/04 and 30566/04, § 102, ECHR 2008-V)."
Privacy and data protection are fundamental and so the discretion of EU legislature to interfere with them is reduced and any review of that discretion should be strict. (para 48). Data retention may be appropriate for crime fighting. (Para 49). The fight against serious crime requires modern techniques but that doesn't mean the kind of mass data retention required by the directive is necessary. (Para 51). Data protection is especially important for privacy.
"54. Consequently, the EU legislation in question must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards so that the persons whose data have been retained have sufficient guarantees to effectively protect their personal data against the risk of abuse and against any unlawful access and use of that data (see, by analogy, as regards Article 8 of the ECHR, Eur. Court H.R., Liberty and Others v. the United Kingdom, 1 July 2008, no. 58243/00, § 62 and 63; Rotaru v. Romania, § 57 to 59, and S. and Marper v. the United Kingdom, § 99)."
Data retention should have clear rule on scope and application and minimum safeguards against unlawful access. The unstated critique is that the directive fails on all counts.
"55.  The need for such safeguards is all the greater where, as laid down in Directive 2006/24, personal data are subjected to automatic processing and where there is a significant risk of unlawful access to those data (see, by analogy, as regards Article 8 of the ECHR, S. and Marper v. the United Kingdom, § 103, and M. K. v. France, 18 April 2013, no. 19522/09, § 35)."
Safeguards are particularly important with respect to the automatic large scale processing of data. Again the 2006 directive fails.
56. ... Directive 2006/24... entails an interference with the fundamental rights of practically the entire European population. [My emphasis]
"57.   In this respect, it must be noted, first, that Directive 2006/24 covers, in a generalised manner, all persons and all means of electronic communication as well as all traffic data without any differentiation, limitation or exception being made in the light of the objective of fighting against serious crime.." [My emphasis]
Paragraph 58 goes on to criticise Directive 2006/24's mandate to engage in the mass surveillance of innocent people not remotely connected to serious crime. Additionally it circumvents rules protecting privileged communications.

Then in recognition of the need for targeted rather than mass surveillance they state:
"59.  Moreover, whilst seeking to contribute to the fight against serious crime, Directive 2006/24 does not require any relationship between the data whose retention is provided for and a threat to public security and, in particular, it is not restricted to a retention in relation (i) to data pertaining to a particular time period and/or a particular geographical zone and/or to a circle of particular persons likely to be involved, in one way or another, in a serious crime, or (ii) to persons who could, for other reasons, contribute, by the retention of their data, to the prevention, detection or prosecution of serious offences."
That paragraph alone could be interpreted as a serious judicial uppercut to the UK government's mass surveillance practices revealed by Edward Snowden. At the risk of being boring I'm going to repeat my old mantra here.  It is unnecessary and completely disproportionate, not to mention dangerously ineffective, to collect innocent communications in order to find serious criminals. Finding a terrorist or serious criminal is a needle in a haystack problem – you can’t find the needle by throwing infinitely more needle-less electronic hay on the stack.  Law enforcement, intelligence and security services have to be able to move with the times. They need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion. That is not, however, the same as building an infrastructure of mass surveillance or facilitating the same through the legal architecture of directives like 2006/24 on data retention.

The ECJ follows up this mass surveillance critique with a clear declaration in paragraph 60 that the data retention directive has no limits on access to and use of retained data to the purpose of fighting serious crime and no criteria for determining such limits. In a way paragraphs 60 to 68 provide a blueprint for the Commission and particularly rabid surveillance addicted governments to re-write the data retention directive in a way that might be acceptable to the ECJ. Since these paragraphs spell out what is missing from the directive and might be read as suggesting 'make a token effort with these things next time and you'll be ok.'

Para 61 criticises Directive 2006/24's lack of procedures on determining access to data or its use or even limiting these to crime fighting. Para 62 notes the directive does not limit the number of people with access to the retained data to those strictly necessary. Nor does it subject access to the data to the prior review or oversight of a court, in order to limit access to that which is strictly necessary. Nor are member states obliged to set down such procedures.

Para 63 complains that the blanket data retention mandated doesn't make any distinction between categories of data. Para 64 says there is not even an attempt to justify the arbitrary period of retention chosen of between 6 months and 2 years.

Then comes the clincher.
"65.  It follows from the above that Directive 2006/24 does not lay down clear and precise rules governing the extent of the interference with the fundamental rights enshrined in Articles 7 and 8 of the Charter. It must therefore be held that Directive 2006/24 entails a wide-ranging and particularly serious interference with those fundamental rights in the legal order of the EU, without such an interference being precisely circumscribed by provisions to ensure that it is actually limited to what is strictly necessary." [My emphasis]
"66.   Moreover, as far as concerns the rules relating to the security and protection of data retained by providers of publicly available electronic communications services or of public communications networks, it must be held that Directive 2006/24 does not provide for sufficient safeguards, as required by Article 8 of the Charter, to ensure effective protection of the data retained against the risk of abuse and against any unlawful access and use of that data. In the first place, Article 7 of Directive 2006/24 does not lay down rules which are specific and adapted to (i) the vast quantity of data whose retention is required by that directive, (ii) the sensitive nature of that data and (iii) the risk of unlawful access to that data, rules which would serve, in particular, to govern the protection and security of the data in question in a clear and strict manner in order to ensure their full integrity and confidentiality. Furthermore, a specific obligation on Member States to establish such rules has also not been laid down." [My emphasis]
Para 67 says the 2006 directive doesn't specify a high enough data security threshold and doesn't require the irreversible destruction of data at the end of the retention period. Then in 68 the ECJ has serious concerns that the data retention directive does not require data to be retained within the borders of the EU. So control by independent authority of data protection and access to the retained data cannot be fully ensured. Such control is an essential corner stone of EU data protection law.

And that's the ballgame

They conclude:
"69. Having regard to all the foregoing considerations, it must be held that, by adopting Directive 2006/24, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality in the light of Articles 7, 8 and 52(1) of the Charter.
70. In those circumstances, there is no need to examine the validity of Directive 2006/24 in the light of Article 11 of the Charter.
71.  Consequently... Directive 2006/24 is invalid."
In short, the data retention directive presents a disproportionate interference with the fundamental rights to respect for private and family life and the protection of personal data. Consequently the directive is invalid, null and void. And because it is invalid on privacy grounds the ECJ don't see the need to pursue the question of whether it also might be invalid on the grounds of Article 11 of the Charter of Fundamental Rights relating to freedom of expression.

If the Charter of Fundamental Rights proves to have staying power as the legislative architecture protecting the rights of EU citizens into the distant future, then this ECJ decision could well prove to be historic. On a par with the civil rights cases of the US Supreme Court such as Brown v the Board of Education or the NYT v Sullivan. Only time will tell whether it achieves that fame or notoriety but it was certainly a welcome development in the battle to avoid a mass surveilled future.

Congratulations and thanks to TJ McIntyre, Simon McGarr and Digital Rights Ireland and to Mr Seitlinger, Mr Tschol et al and the Austrian Constitutional Court the Verfassungsgerichtshof in what was a long and difficult battle and a hard fought but very welcome victory in the end.