Friday, January 08, 2016

Evidence to Joint Committee on Investigatory Powers Bill

The Joint Committee on the Investigatory Powers Bill yesterday published all of the written evidence it received. Over 120 submissions were received, in spite of the incredibly tight timetable. My evidence is available on the website and, as promised, I include a copy below. Apologies for the occasional typographical errors.

Strangely, my opening note about working for The Open University but submitting the evidence in a personal capacity got truncated from the version the committee published.
To the members of the Draft Investigatory Powers Bill Joint Committee,

Thank you for the opportunity to make a submission to your inquiry the Draft Investigatory Powers Bill.

My name is Ray Corrigan. I’m a Senior Lecturer in the Maths, Computing & Technology Faculty of The Open University, though I write to you in a personal capacity.

Summary

The Joint Committee is being required to analyse the long and complex Draft Investigatory Powers Bill in an unreasonably short timescale.

This submission to your inquiry is divided into 6 sections covering:

·         Bulk collection & retention of personal data by computers
·         Privacy
·         Legality of bulk collection and retention
·         ICRs and relevant communications data
·         The base rate fallacy and the lack of efficacy of bulk data collection
·         Complex system security and equipment interference

The first section challenges a fundamental misunderstanding – the idea that collecting and retaining bulk personal data is acceptable as long as most of the data is only “seen” by computers and not human beings. This is a line that has been promoted by successive governments for some years and seems to be widely accepted. Yet it is seriously flawed.

Next I suggest a simplified version of US scholar Daniel Solove’s model of privacy, to help provide a framework for thinking about information and data processing, in the context of communications surveillance.

Then the April 2014 European Court of Justice Digital Rights Ireland decision, invalidating the Data Retention Directive, is reviewed. Viewed carefully, the decision could be considered an aid to framing surveillance legislation. The draft Investigatory Powers Bill in its current form would be unlikely to meet the tests, laid down in the case, regarding compatibility with privacy and data protection rights, guaranteed by articles 7 and 8 of the EU Charter of Fundamental Rights.

The fourth section examines the tangled web of “internet connection records” and “relevant communications data”. Technology law expert, Graham Smith, has identified and mapped 14 different interlinked definitions in the Bill that are connected to “relevant communications data”. It is difficult to see how the bulk retention of data under the broad and dynamic scope of “relevant communications data” or “internet connection records” could meet the tests of necessity or proportionality laid down in the Digital Rights Ireland case.

The penultimate section looks at the base rate fallacy, a statistical concept that policy makers must familiarise themselves with if intending to approve the indiscriminate bulk collection, retention and processing of personal data. Finding a terrorist is a needle in a haystack problem. You don’t make it easier to find him/her by throwing industrial scale levels of the personal data, of mostly innocent people, on your data haystack. Section 150 of the Bill, Bulk personal datasets: interpretation, states “the majority of the individuals are not, and are unlikely to become, of interest to the intelligence service in the exercise of its functions”. Explicit recognition innocent people would be subject to indiscriminate surveillance under proposed powers.

The final section discusses security in general and the inadvisability of giving government agencies the powers to engage in bulk hacking of the internet. It is advocated that targeted surveillance practices are more effective than mass surveillance approaches and recommended that Part 6, Chapter 3 of the draft Bill be removed in its entirety.

I conclude with an appeal to frame surveillance laws within the rule of law, rather than attempting to shape the law to accommodate expansive, costly, ineffective and damaging population-wide surveillance practices. 
Bulk collection & retention of personal data by computers

1.       To begin I would just like to note that it is a mammoth task to expect parliamentarians to analyse this long and complex Bill in the short timescale you have been given.

2.        I would also like to tackle a fundamental misunderstanding at large in Westminster – the idea that collecting and retaining bulk personal data is acceptable as long as most of the data is only “seen” by computers and not human beings; and it will only be looked at by persons with the requisite authority if it is considered necessary.  This is a line that has been promoted by successive governments for some years and seems to be widely accepted. Yet it is seriously flawed.

3.       The logical extension of such an argument is that we should place multiple sophisticated electronic audio, video and data acquisition recording devices in every corner of every inhabited or potentially inhabited space; thereby assembling data mountains capable of being mined to extract detailed digital dossiers on the intimate personal lives of the entire population. They won’t be viewed by real people unless it becomes considered necessary.

4.       Indeed with computers and tablets in many rooms in many homes, consumer health and fitness monitoring devices, interactive Barbie dolls, fridges, cars and the internet of things lining up every conceivable physical object or service to be tagged with internet connectivity, we may not be too far away from such a world already.[1]

5.       The Home Office, on 16 December 2015, rejected a freedom of information request[2] asking for the “metadata of all emails sent to and from the Home Secretary for the period 1st January 2015 - 31st January 2015 inclusive.” They rejected the request on the grounds that the request “is vexatious because it places an unreasonable burden on the department, because it has adopted a scattergun approach and seems solely designed for the purpose of ‘fishing’ for information without any idea of what might be revealed.”

6.       Yet the same Home Office considers it acceptable to have powers, in the Investigatory Powers Bill, to engage in bulk data collection, retention and equipment interference, to assemble information about every member of the population, in the hope of conducting contemporaneous and/or post hoc ‘fishing’ activities to look for evidence of misbehaviour.

7.       I would contend that this approach is unnecessary, disproportionate and incompatible with the rule of law. It is additionally very costly and technically, mathematically and operationally ineffective. If all that was not bad enough, it risks undermining the security of our already frail and insecure communications infrastructure.


Privacy

8.       Individual and collective privacy underpins a healthy society but privacy is hard to define. We understand the conceptual protection of a person’s home being their castle and what is behind closed doors being private. But privacy was the default state in the pre-internet world and we didn’t think too hard about its subtleties.  With mass personal data processing, however, we need a better understanding of privacy. US scholar Daniel Solove has helpfully characterised privacy as a collection of problems.[3] Privacy harm, Solove argues, is triggered by –

·         Information collection
·         Information processing
·         Information dissemination/sharing
·         Privacy invasion and erosion

9.       We now teach a simplified model of Solove’s taxonomy to our 3rd level information systems students at The Open University a visual depiction of which I include below.


10.    One of the key issues clarified by Solove’s model is that the initial privacy harm originates at the point of collection of personal data, whether that collection is done by a computer, other device or a person. In the context of investigatory powers it can be helpful to ask whether the specifics under consideration relate to information collection (& retention), information processing, information dissemination or privacy invasion. Whichever of these processes are at issue their collective effect is the stripping bear of the digital persona of anyone who comes into contact with devices connected to the internet.

11.    Information collection is the surveillance done by commerce, governments and other agents, such as criminal gangs. Solove suggests it also covers the interrogation of the information collected.

12.    Commerce, governments and others are involved in information processing – the storage, use (or misuse), analysis and aggregation of lots of data, secondary use of data, the exclusion of the data subject from knowledge of how information about them is being used and exclusion from being able to correct errors. Solove expresses particularly concern about bureaucracy. Surveillance bureaucracy makes life-changing decisions based on secret information, while denying the subject/s of the data the ability to inform, see or challenge the information used. The privacy problem here is all about information. The privacy harms are bureaucratic – powerlessness for the subject, indifference to them, error, lack of transparency and accountability.

13.    On that front, when giant data mountains are conveniently sitting around, there is not a safeguard in existence that will prevent (possibly even well-intentioned) future incarnations of a bureaucracy from tapping that data for secondary uses not originally envisaged by those behind the IP Bill. A related case in point is the expansive interpretation of s7(4) of the Intelligence Services Act 1994 and the Equipment Interference Code of Practice 2015 to justify the equipment interference activities currently undertaken by the security and intelligence services (SIS). Provisions for equipment interference and bulk equipment interference included in part 5 and 6 of the IP Bill present serious economic wellbeing and security risks.

14.    Information dissemination – Data viewed out of context can paint a distorted picture. The novelist researching criminal behaviour might be flagged for buying too many of the wrong kinds of books from an online bookshop. In the UK collection of information ‘of a kind likely to be useful to a person committing or preparing an act of terrorism’ is a criminal offence, under Section 58 of the Terrorism Act 2000. We might expect an analyst to recognise a known novelist but processing purely by algorithm may lead to distortion and faulty inference. We also get dissemination through leaking and misappropriation through stealing of personal information, which can lead to exposure to identity theft, fraud, blackmail, and further distortion.

15.    Privacy invasion is about the information activities and their aggregation mentioned above but also amounts to intrusion into the personal sphere. Overt surveillance, direct interrogation, junk mail, unsolicited phone calls are all disruptive intrusions and cause harm. But there can be a decision making element to this intrusion too. For example someone may be reluctant to consult a doctor if current plans on the sharing of health data through the ill-considered care.data scheme progress further. Innocents may be inhibited from using the internet if they feel under constant surveillance.

16.    Whether or not mass indiscriminate personal data collection and retention is only “seen” by computers it remains mass indiscriminate personal data collection and retention, repeatedly found unlawful by the Court of Justice of the European Union [Digital Rights Ireland, 2014; Schrems 2015], the European Court of Human Rights [Zakharov, 2015] and multiple high courts including Romania (2009), Germany (2010), Bulgaria (2010), the Czech Republic (2011) and Cyprus (2011). Mass indiscriminate personal data collection and retention has been variously described by these courts as unconstitutional and/or a disproportionate unjustified interference with the fundamental right to privacy, free speech and confidentiality of communications.

Legality of bulk collection and retention

17.    On 8 April2014 the Grand Chamber of the European Court of Justice, (ECJ) in joined cases C-293/12 and C-594/12, issued a landmark decision declaring the 2006 data retention directive invalid. The Grand Chamber of the Court effectively condemned pre-emptive, suspicionless, bulk collection and retention of personal data and consequent "interference with the fundamental rights of practically the entire European population". The Paragraph 37 of the judgment noted the interference with articles 7 (data protection) and 8 (privacy) of the EU Charter of Fundamental Rights caused by mass data retention “must be considered to be particularly serious.”

18.    Paragraph 58 of the decision criticises the mass surveillance of innocent people not remotely connected to serious crime. Then in recognition of the need for targeted rather than mass surveillance the Court states:

"59.  Moreover, whilst seeking to contribute to the fight against serious crime, Directive 2006/24 does not require any relationship between the data whose retention is provided for and a threat to public security and, in particular, it is not restricted to a retention in relation (i) to data pertaining to a particular time period and/or a particular geographical zone and/or to a circle of particular persons likely to be involved, in one way or another, in a serious crime, or (ii) to persons who could, for other reasons, contribute, by the retention of their data, to the prevention, detection or prosecution of serious offences."

So the Court considers it unnecessary and disproportionate to engage in bulk collection of innocent communications in order to find serious criminals.

19.    Finding a terrorist or serious criminal is a needle in a haystack problem – you can’t find the needle by throwing infinitely more needle-less electronic hay on the stack.  Law enforcement, intelligence and security services need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass indiscriminate data collection, retention and equipment interference proposed in the Investigatory Powers Bill – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion. That is not, however, the same as building an infrastructure of mass surveillance or facilitating the same through the legal architecture proposed in the Bill.

20.    The ECJ follows up this mass surveillance critique with a clear declaration in paragraph 60 that the data retention directive had no limits on access to and use of retained data to the purpose of fighting serious crime and no criteria for determining such limits. Paragraphs 60 to 68 could be read as a lesson on how to write a data retention law in a way that might be acceptable to the Court. The data retention directive declared invalid by the Court did not –

·         include procedures on determining access to data or its use or even limiting these to crime fighting
·         limit the number of people with access to the retained data to those strictly necessary
·         subject access to the data to the prior review or oversight of a court, in order to limit access to that which is strictly necessary
·         oblige member states to set down such procedures.
·         make any distinction between categories of data
·         attempt to justify the arbitrary period of retention chosen of between 6 months and 2 years
·         lay down clear and precise rules governing the extent of the interference with the fundamental rights to privacy and data protection
·         provide for sufficient safeguards to ensure effective protection of the data retained against the risk of abuse
·         provide for sufficient safeguards to ensure against any unlawful access and use of that data
·         specify a high enough data security threshold
·         require the irreversible destruction of data at the end of the retention period
·         require data to be retained within the borders of the EU
·         ensure control of data protection and access to the retained data by independent authority

21.    Big and complex as the Investigatory Powers Bill is, it too falls at many of these hurdles in relation to the bulk data collection and retention powers proposed. IT fundamentally fails to take into account data protection principles, in particular data minimisation.[4] Not only does the IP Bill eschew data protection principles, it promises to offer its own version of data processing rules to deal with bulk data which will appear as a code of practice. A guide to what this code of practice will look like is included in Schedule 6, section 3 of the Bill.

22.    The Court concluded:
"69. Having regard to all the foregoing considerations, it must be held that, by adopting Directive 2006/24, the EU legislature has exceeded the limits imposed by compliance with the principle of proportionality in the light of Articles 7, 8 and 52(1) of the Charter.
70. In those circumstances, there is no need to examine the validity of Directive 2006/24 in the light of Article 11 of the Charter.
71.  Consequently... Directive 2006/24 is invalid."
23.    In short, the data retention directive presented a disproportionate interference with the fundamental rights to respect for private and family life and the protection of personal data. Consequently the directive was invalid, null and void. And because it was invalid on privacy grounds the Court didn't see the need to pursue the question of whether it also might be invalid on the grounds of Article 11 of the Charter of Fundamental Rights relating to freedom of expression.

Internet connection records and relevant communications data
24.    The Home Office appear to have briefed the Joint Committee that the retention of “internet connection records” is the only new power in the Bill.  As far as I can tell the phrase “internet connection records” is mentioned only in section 47 of the Bill (“Addition restriction on grant of authorisations”) which does not deal with data retention.  Section 71 (Powers to require retention of certain data) deals with data retention and uses the term “relevant communications data” rather than internet connection records.

25.    “Relevant communications data” has a six part definition in s71(9)(a)-(e) relating to the purposes of section 71. “Internet connection record” has a two part definition in s49(6)(a)-(b) relating to that section. The components of the “relevant communications data” definition them acquire different meanings or definitions depending on what part of the Bill they appear in.

26.    Graham Smith has done a remarkable job of tracking these down. In a blogpost on Sunday, 29 November 2015, Never mind Internet Connection Records, what about Relevant Communications Data[5], he identified and mapped 14 different interlinked definitions in the Bill that are connected to “relevant communications data”.

27.    It is hardly surprising therefore that industry representatives, such as BT’s Mark Hughes, have testified to the joint committee that the definitions in the Bill are unclear.

28.    Relating “relevant communications data” back to the Solove model (at the beginning of my submission) implicates it variously in data collection, retention, processing and dissemination. Unfortunately even that doesn’t help identify exactly what “relevant communications data” is going to mean in practice.

29.    Government representatives have told the joint committee that definitions of ICRs and relevant communications data are “clear” and industry have insisted they are unclear in the Bill. It appears that what they really mean in practice will be worked out in private discussions through the “very good relationship” the government maintains with industry.

30.    Does the joint committee get to oversee these discussions? So who gets the final say on who gets to program the computers for surveillances and what are the specific 'selectors'/filters? Who decides what the selectors should be? Who decides who decides what the selectors should be? With the best will in the world most parliamentarians are not technical experts, so how can the committee effectively or Home Secretary or judicial commissioners scrutinise the technical aspects of this work? How do you measure the efficacy of these filters given it is widely known in the tech community how ineffective electronic filters can be? How, when someone is tagged as suspicious via these secret algorithms applied to bulk datasets, does the information on that individual then get further processed? What happens when someone is wrongly tagged and how do they retrieve their innocence and clean bill of electronic health?

31.    It is difficult to see how the bulk retention of data under the broad and dynamic scope of “relevant communications data”, or “internet connection records” if that is to be the common phrase to be alluded to regardless of its definition in the Bill, could meet the tests of necessity or proportionality laid down by the Court of Justice of the European Union in the Digital Rights Ireland case in 2014. Given that the final text of the EU’s new General Data Protection Regulations (GDPR) just been agreed, it will further complicate the committee’s efforts in trying to understand the implications of the proposed IP Bill.

32.    One last note on this section on the differences of opinion over the clarity or otherwise of the Bill. The drafters of the Bill have gone to some length to try to distinguish communications data (or meta data) from content. Paul Bernal and others have explained to the joint committee why there is no simple way to distinguish the two, given the complex overlapping nature of both e.g. does an email address mentioned in the main text of a document constitute content or communications data. Could I, on this point, just commend to you the presentation of your special adviser, Peter Sommer, from the 2012 Scrambling for Safety conference, Can we separate “comms data” and “content”– and what will it cost?[6]

Base rate fallacy
33.    The whole Investigatory Powers Bill approach to signals intelligence – giant magic computerised terrorist catching machine that watches everyone and identifies the bad guys – is flawed from a mathematical as well as operational perspective.
34.    Time and again from the dreadful attacks on the US on the 11th September 2001 through to the recent attacks in Paris the perpetrators were previously known to the security services but they lost track of them in the ocean of data noise they were then[7] and are now[8] drowning in.
35.    Even if an IP Bill mandated magic terrorist catching machine, watching the entire population of the world, was 99% reliable, it would flag too many innocents for the security services to investigate and swamp the services in unproductive activity.
36.    But it is not even as simple as that mathematically. Is your machine 99% reliable at identifying a terrorist, given they are a terrorist? Or is it 99% reliable at identifying an innocent, supposing they are truly innocent? In general your machine will have two failure rates

·         A false positive where it identifies an innocent as a terrorist
·         A false negative where it identifies a terrorist as an innocent

37.    The reliability of your identification further depends on the actual number of terrorists in the population as a whole – the base rate. The problem is particularly acute when the base rate is low. Let’s stick with the 99% reliability for both failure rates (though they will rarely be the same – if you adjust your machine to catch more terrorists, it will falsely accuse more innocents; and if you adjust it to catch less innocents it will let more terrorists go). So assume both a false positive and false negative rate of 1%. Suppose also there are 100 terrorists in every collection of 1 million people.[9] Your terrorist catching machine, watching these 1 million, will flag 99 of the 100 terrorists, giving one a free pass; but it also flags 1% of the remaining 999,900 innocents i.e. 9,999 innocent people get tagged as terrorists. So the 99% reliable machine flags 99 + 9999 = 10,098 people for suspicion. Only 99 of these 10,098 are real terrorists, giving your magic machine a hit rate of 99/10098 = 0.0098 approximately. Your 99% reliable machine is not 99% reliable but less than 1% effective at identifying terrorists.

38.    The numbers underlying this base rate fallacy[10] – the tendency to ignore known base rate statistical data (e.g. the low probability someone is a terrorist in a large population) in favour of an interpretation of specific data (my magic machine is 99% accurate) that seems as though it might be right – are slightly counter intuitive but need to be understood if you purport to deploy techniques involving the surveillance of entire populations.

39.    Denmark, following 7 years of ineffective bulk collection of data equivalent to the IP Bills internet connection records, in 2014 repealed the law requiring the collection and retention of these records.[11] Because of the base rate fallacy and the fact that terrorists are relatively few in number compared to the population as a whole, mass data collection, retention and mining systems, such as those proposed in the IP Bill, always lead to the swamping of investigators with false positives, when dealing with a large population. Law enforcement authorities end up investigating and alienating large numbers of innocent people. That’s no good for the innocents, for the investigators or for society. In Denmark, over half a million records per citizen were retained in 2013 but the system proved an ineffective tool for law enforcement and security and intelligence services.

40.    If the government has £175 million over ten years (about equivalent to Wayne Rooney’s wages and as industry and others have pointed out to the joint committee, this will not come close to paying for what the IP Bill requires) to invest in terrorism prevention, then it would be better spent on more security services people not magic terrorist catching computer systems. You need more human intelligence and better targeted and managed signals intelligence.

Complex system security and equipment interference
41.    Our communications infrastructure is complex, fragile and insecure.  Large and complex systems like the internet are extremely difficult if not impossible to secure.  Security is hard and complexity kills it. When you make any changes to complex systems, they produce unintended emergent effects. But it is a really bad idea to undermine the security of an already fragile and insecure communications infrastructure deliberately, by giving government the power to undermine that security directly, through the equipment interference measures in the IP Bill.

42.    There may be a case [though it has not been made] for carefully targeted and judicially supervised and controlled, necessary and proportionate equipment interference, to pursue known suspects, about whom the intelligence or law enforcement services have reasonable cause to harbour suspicion. That applies generally to the bulk data collection and retention and equipment interference regime of the IP Bill. The requisite authorities need to use modern digital technologies intelligently in their work and through targeted data preservation regimes – not the mass surveillance regime they are currently operating and the government is proposing to expand under the draft IP Bill – engage in technological surveillance of individuals about whom they have reasonable cause to harbour suspicion.

43.    Targeted equipment interference does however, compromise digital forensic evidence that may be used in law enforcement cases.

44.    Although equipment interference better known as hacking was avowed by the government with the publication of the draft Equipment Interference Code of Practice early in 2015, government legal representatives at the recent Privacy International Investigatory Powers Tribunal hearing denied that the government had yet admitted engaging in bulk equipment interference.

45.    The justification for bulk equipment interference appears to be based on stretching interpretations of the Anderson and Intelligence & Security Committee reports, and the Intelligence Services Act 1994 and the Police Act 1997, beyond breaking point. Anderson, in what I consider one of the few weak/evidence-light parts of his otherwise thorough and impressive report,[12] approved of bulk collection and retention of communications data.  In no part of the Anderson report is there expressed or implicit approval for bulk equipment interference.

46.    Government are claiming bulk equipment interference (mass hacking of the internet) is their attempt to "build on recommendations made by David Anderson QC and the ISC".  Generally speaking giving the government the power to hack the internet is really bad security hygiene, undermining communications infrastructure for everyone. Professor Mark Ryan of Birmingham University informed the Joint Committee that equipment interference is “a huge power” which would result in innocent people being targeted. Professor Ryan also described it is an "extremely dangerous game".

47.    Numerous other computer scientists and security experts, including Jon Crowcroft at Cambridge University, have described the Bill as a hacker charter, a description recognisable in part 5 and part 6, chapter 3 of the Bill. The 2015 Equipment Interference Code of Practice appears to have stretched the meaning of s7(4)(a) of the 1994 Intelligence Services Act's "acts of a description specified in the authorisation" to mean it covers bulk hacking. Section 7.11 of the Code of Practice claims s7(4)(a) "may relate to a broad class of operations" i.e. anything? Part 6 Chapter 3 would appear to be aimed at codifying this in the new law.

48.    There is no case for the open ended bulk equipment interference powers outlined in part 6, chapter 3 of the Bill. These powers seem to be aimed at facilitating the hacking of overseas communications data and equipment. But wherever bulk hacking is aimed it has no place in the toolbox of government authorities. Following an investigation into the Edward Snowden leaks in 2013, President Obama’s Review Group on Intelligence and Communications Technologies recommended that intelligence agencies should focus on defending rather that engaging in attacks on network and computer security.[13]

49.    Part 6 Chapter 3 should be removed in its entirety from the Bill. Part 5 needs significant amendment if it is to remain.

50.    Securing systems of the magnitude of those used by security agencies and industry, and effectively proposed in the IP Bill, from external hackers or the multitude of insiders who have access to these databases (850,000 including Edward Snowden in the case of the NSA), is incredibly difficult. The joint committee will be familiar with the recent TalkTalk hack compromising the personal data of 157,000 customers.[14] You may be familiar with the even more serious and potentially life threatening compromise of the systems of US government’s Office of Personnel Management.[15] The complete dossiers of tens of millions of US federal employees, their families and others who had applied for government jobs were stolen.

51.    When you create large and valuable databases they attract attackers. Whereas, in addition to respecting data protection principles, minimising the collection and processing of personal data to that required for the specified purpose, is also good security practice.

52.    Security experts like Ross Anderson, Bruce Schneier, Peter Neumann and others have written extensively about this.  And to understand the problem of securing these systems you need to think about how such systems can fail - how they fail naturally, through technical problems and errors (a universal problem with computers), and how they can be made to fail by attackers (insiders and outsiders) with malign intentions. And sometimes, like the case of Edward Snowden, one of 850,000 security cleared people with access to NSA secrets, those insiders or outsiders may have, what they believe to be, benign intent. Snowden’s stated intention was to disclose unconstitutional and/or illegal government agency practices. Whatever an attacker’s intent, no information to which nearly a million people have access, as a routine part of their job, is secure.

53.    The mood amongst western governments has been leaning towards deliberate mandates to undermine communications infrastructure security, providing security vulnerabilities for law enforcement and intelligence services to exploit. Anderson, Schneier, Neumann and other world renowned security experts recently published Keys Under Doormats: Mandating insecurity by requiring government access to all data and communications.[16] The paper explains, in commendably accessible detail, why this is a bad idea.

54.    From their conclusion: “Even as citizens need law enforcement to protect themselves in the digital world, all policy-makers, companies, researchers, individuals, and law enforcement have an obligation to work to make our global information infrastructure more secure, trustworthy, and resilient. This report’s analysis of law enforcement demands for exceptional access to private communications and data shows that such access will open doors through which criminals and malicious nation-states can attack the very individuals law enforcement seeks to defend. The costs would be substantial, the damage to innovation severe, and the consequences to economic growth difficult to predict. The costs to developed countries’ soft power and to our moral authority would also be considerable. Policy-makers need to be clear-eyed in evaluating the likely costs and benefits.”


Conclusion

55.    The government has the right to intercept, retain and analyse personal information, when someone is suspected of a serious crime. However, current operations and the powers and processes proposed in the draft IP Bill involve collection of personal data indiscrimately, in bulk and without suspicion, in addition to network security decimating equipment interference. This is, in effect, mass surveillance.

56.    Due process requires that surveillance of a real suspected criminal be based on much more than general, loose, and vague allegations, or on suspicion, surmise, or vague guesses. To operate the mass data collection and analysis systems proposed in the IP Bill, thereby giving the entire population less protection than a hitherto genuine suspected criminal, based on a standard of reasonable suspicion, is indefensible.

57.    250 years ago, Lord Chief Justice Camden decided that government agents are not allowed to break your door down and ransack your house and papers in an effort to find some evidence to incriminate you (the case of Entick v Carrington (1765) 19 Howell’s State Trials 1029, 2 Wils 275, 95 ER 807, Court of Common Pleas).
58.    The good judge also declared personal papers to be one’s “dearest property”. It is not unreasonable to suspect he might view personal data likewise in the internet age. I understand Lord Camden's reasoning in Entick became the inspiration behind the 4th Amendment to the US Constitution which offers protection from unreasonable searches and seizures. The 4th Amendment itself underpins the 46 recommendations of the Report of President Obama’s Review Group on Intelligence and Communications Technologies. For a quarter of a millennium, fishing expeditions, of the type that are proposed in the IP Bill but at a scale and scope which Lord Chief Justice Camden could barely have imagined, have been considered to fundamentally undermine the rule of law. It's time Parliament brought these modern costly, ineffective and damaging surveillance practices into line with that rule of law rather than, as with the IP Bill, attempting to shape the law to facilitate and expand them in scale and scope.











[1] Executive Office of the President President’s Council of Advisors on Science and Technology Report to the President, [May, 2014], Big Data and Privacy: A Technological Perspective
[2] https://www.whatdotheyknow.com/request/300685/response/745953/attach/html/3/FOI%2037410%20Response.pdf.html
[3] Solove, DJ, [2006], A Taxonomy of Privacy, University of Pennsylvania Law Review, Vol.154 No.3
[4] https://ico.org.uk/for-organisations/guide-to-data-protection/principle-3-adequacy/
[5] http://cyberleagle.blogspot.co.uk/2015/11/never-mind-internet-connection-records.html
[6] http://www.pmsommer.com/sf2012_sommer_commsdata_content.pdf
[7] The NSA’s Call Record Program, a 9/11 Hijacker, and the Failure of Bulk Collection https://www.eff.org/deeplinks/2015/04/nsas-call-record-program-911-hijacker-and-failure-bulk-collection
[8] Intelligence and Security Committee Report on the intelligence relating to the murder of Fusilier Lee Rigby http://isc.independent.gov.uk/committee-reports/special-reports
[9] Various spokespersons of successive UK governments have referred to 6000 dangerous people at large in the UK, so I’ve chosen 100 per million as equivalent to 6000 in 60 million.
[10] For a fuller description of the base rate fallacy see  Richards J. Heuer, Jr., Psychology of Intelligence Analysis,
Chapter 12 Biases in Estimating Probabilities, available at https://www.cia.gov/library/center-for-the-study-of-intelligence/csi-publications/books-and-monographs/psychology-of-intelligence-analysis/art15.html
[11] Details available from http://itpol.dk/consultations/written-evicence-ipbill-scitech-committee IP-Pol submission to the Science and Technology Committee inquiry into the Investigatory Powers Bill.
[12] A Question of Trust: Report of the Investigatory Powers Review by David Anderson Q.C., June 2015
[13] Richard A. Clarke, Michael J. Morell, Geoffrey R. Stone, Cass R. Sunstein, Peter Swire [13 December 2013] Liberty and Security in a Changing World: Report and Recommendations of The President’s Review Group on Intelligence and Communications Technologies
[14] http://www.bbc.co.uk/news/business-34743185
[15] https://www.opm.gov/cybersecurity/cybersecurity-incidents/
[16] https://dspace.mit.edu/bitstream/handle/1721.1/97690/MIT-CSAIL-TR-2015-026.pdf

Monday, December 21, 2015

Better that a thousand innocents suffer than one guilty person go free...?

The Universal Declaration of Human Rights (UDHR), Article 11 states:
Everyone charged with a penal offence has the right to be presumed innocent until proved guilty according to law in a public trial at which he has had all the guarantees necessary for his defence.
The EU Charter of Fundamental Rights article 48 states:
Everyone who has been charged shall be presumed innocent until proved guilty according to law.
The presumption of innocence has been a cornerstone of English law for centuries. William Blackstone put it thus:
"the law holds it better that ten guilty persons escape, than that one innocent party suffer"
Benjamin Franklin was even more emphatic:
"it is better 100 guilty Persons should escape than that one innocent Person should suffer" 
Otto von Bismark, Pol Pot and Dick Cheney took the opposite view. It was better for them that innocents suffer than one guilty person escape.

The deadline for submitting your thoughts to the Joint Committee on the Draft Investigatory Powers Bill is today. This is probably the single most important piece of prospective legislation in a generation and the committee have been given an unconscionably short period to analyse and review this large and complex Bill.

I sent my thoughts to the Committee Friday evening last and will publish them here as soon as I'm able to do so.

In the meantime, though, I wanted to highlight something that doesn't appear to have been discussed in the context of the Bill anywhere that I'm aware of - the Bill's implicit reversal of the presumption of innocence.

The Investigatory Powers Bill is an attempt to codify permissions in law for the UK government to run a gigantic computerised multi systems communications surveillance apparatus. An apparatus that we know from the Snowden documents they have been running for some years. It also expands the scope and scale of those operations and the powers facilitating them. It is mass surveillance by any other name - collecting, retaining, processing and analysing the electronic communications of the entire population and as many of those overseas they can access.

The government is essentially creating intimate digital dossiers of every connected resident of the UK amongst others. We may decide as a society that is something we wish to accept - I don't - but there most certainly must be open, informed public debate about the direction of travel.

One of the key justifications for this mass surveillance is to find terrorists. As regular readers will be sick of hearing me say, finding a terrorist is a needle in a haystack problem and you can't find the needle by throwing infinitely more needle free hay on the stack.

The government have a stated belief that this is not mass surveillance because most of the collected data is only seen and analysed by computers not human beings. Every time I hear this mass surveillance defended or excused, I get a picture of the National Lottery's giant magic promotional hand emerging from the government's giant magic computerised terrorist catching machine, with a booming voice-over saying "it's you" as it points out the bad guys.

Now let's give them the benefit of the doubt and assume their machine could work. Assume it is 99% effective at pointing out a terrorist if the person it is watching at the time really is a terrorist. A 1% false negative rate is a pretty good hit rate. Ok so one gets away but you've found 99 baddies out of a hundred.

Unfortunately, your 99% catch-a-terrorist effectiveness has a down side. It will also show false positive results some of the time. So sometimes it will identify innocents as terrorists. The false positive rate won't necessarily (or even often) be the same as the false negative rate. If you calibrate your machine to identify 999 terrorists out of 1000 (instead of 99 from 100) it will also tend to falsely identify more innocents as terrorists.

However, to keep matters simple, lets assume the false positive rate is also 1%. So for every innocent person it looks at there is a 99% chance it correctly identifies them as innocent. One innocent is wrongly tagged but that may, to you, even if not to Ben Franklin, be an acceptable risk.

Except that again things are no so simple as they seem. When your magic machine is watching 60 million people in the UK and you don't know which comparative few are terrorists, life gets more complicated. How effective your magic machine is depends on how many terrorists and innocents there are relative to each other in the surveilled population.

I've periodically heard ministers and spokespersons for multiple successive governments over the past 15 years refer to 6,000 dangerous individuals in the UK. Let's assume that's the terrorist base rate. I don't know whether it is and we don't have enough empirical evidence to judge it but take the governments' claims at face value to give us some numbers to work with.

[Note: More generally it is to be recommended not to take claims about statistics at face value but to examine the detailed evidence critically]

6,000 out of 60 million means the population contains 0.1% terrorists, or 1 in a 1,000. Now the question is, given 1 terrorist per 1,000, how reliable or useful is your 99% reliable terrorist catching machine?

The answer which many people find surprising is: not very.

Your machine, when watching the 6,000 terrorists, will identify 5,994 of them as terrorists. (Assuming 1% false negative rate)

Your machine when watching the remaining 59,994,000 innocents (60 million minus 6,000) will identify 599,940 of these innocents as terrorists. (Assuming a 1% false positive rate)

Your 99% reliable giant computerised magic terrorist catching machine catches 5,994 terrorists but falsely accuses 599,940 innocents.

So, roughly speaking, your 99% "reliable" giant computerised magic terrorist catching machine accuses about a 100* innocents, in order to find one real terrorist. The 99% effective machine is really only 1% effective.

And even then 6 terrorists get away to perpetrate the next attack that will draw calls for even bigger more powerful magic computerised terrorist catching machines...

We have not even begun to consider here the security and law enforcement resource implications of having to investigate such a disproportionate number of innocent people; let alone the target-infested, cost-cutting cultures visited by government upon dedicated security and law enforcement services personnel, creating pressures to "get results".

I would ask you to consider one question, before getting onto the parliamentary website and sharing your views of the Draft Investigatory Powers Bill:

Do you want to live in a society where the default operational state of the security, intelligence and law enforcement services is: that it is better that a thousand innocents suffer than that one guilty person go free?

[... And... er... some terrorists will still slip through the net... shhhh...]

That reversal of the presumption of innocence is a central, if unspoken and somewhat unnoticed, tenet of the Draft Investigatory Powers Bill and the operations it seeks to protect and expand within its legal framework.

Don't be silent on something that really matters. Offer the Joint Committee your views.

Update: I made a decimal point error in original calculation, now corrected.

Saturday, December 19, 2015

Deadline for submitting evidence to IP Bill Joint Committee imminent

With the deadline for submitting evidence to the Draft Investigatory Powers Bill Joint Committee looming on Monday, it's worth considering Privacy International's short video (3m54s) explaining what communications surveillance is and why they are calling for an end to mass communications surveillance.



The Committee's call for evidence is available here. Given this is probably the single most important piece of legislation in a generation, I would urge anyone with a few spare moments, who has not yet done so, to express their opinion on the Bill.

The following conditions attach to providing written evidence to the committee:
"Evidence which is accepted by the Committee may be published online at any stage; when it is so published it becomes subject to parliamentary copyright and is protected by parliamentary privilege. Submissions which have been previously published will not be accepted as evidence. Once you have received acknowledgement that the evidence has been accepted you will receive a further email, and at this point you may publicise or publish your evidence yourself. In doing so you must indicate that it was prepared for the Committee, and you should be aware that your publication or re-publication of your evidence may not be protected by parliamentary privilege"
I sent in a submission yesterday evening and will publish it here in due course. 

Friday, December 04, 2015

Nothing to hide, nothing to fear: a short response

Ruth Coustick-Deal at the Open Rights Group has done a really useful blogpost on responding to the "nothing to hide, nothing to fear" mantra.

Frankly, every journalist worthy of the name should blast this seductive, toxic little soundbite and all its derivatives into discredited oblivion, immediately and every time a talking head tries to use it to rig a discussion on surveillance or other privacy issues.

Expose it for what it is. Laugh at it, if that works.

Don't accept the demonstrably false premise that privacy is exclusively sought or needed by evil people wanting to hide nefarious deeds and intentions. It is not.

Don't accept the demonstrably false premise that destroying privacy will solve the complex socio-technical-economic-environmental-justice-immigration-terrorism-[choose your issue] problem/mess du jour. It has not and will not.

By all means, list the collection of types of people for whom privacy is not only about dignity and humanity but about risk to life and limb.

By all means quote Snowden and Schneier, Applebaum, Greenwald and others, most especially Daniel Solove. Solove's Nothing to Hide: The False Tradeoff between Privacy and Security is, by a street, the best book-length argument, exclusively devoted to debunking the vicious, sleazy, lazy, ignorant, sophistic but powerful debating trick that is the 'nothing to hide' meme.

But start by saying you do not and cannot accept the false assertion that privacy is only about bad people hiding bad things.

Start by saying you do not and cannot accept the false assertion that destroying privacy (or "giving up a little individual privacy for collective security", as it is often deceitfully wielded) will fix terrorism/fraud/immigration/[issue of choice].

Never, ever accept "nothing to hide..." as the basis for framing a debate.

People who use it innocently or ignorantly need to be educated about its false underpinning assumptions.

People who use it with a deliberate privacy destroying or power grabbing agenda need to be reigned in.

Privacy, individual and collective, is at the foundation of a health society.

Be wary of anybody who seeks to destroy or undermine it, brandishing the malignant 'nothing to hide' slogan, whatever their motives.

Saturday, November 21, 2015

The poisonous seduction of the demonising of whole classes of people

This is no time for people who oppose Senator McCarthy's methods to keep silent.



Politicians, journalists and their paymasters would do well to heed Edward R. Murrow, who repeatedly inveighed against the extremism of Congressional McCarthyism.

The demonisation of Muslims, Syrians, refugees, [pick a categorisation for your discrimination of choice] is poisonous and destructive.

Wednesday, November 11, 2015

Science and Technology Committee IP Bill hearings

Some day when you find yourself with a couple of hours free, sit down in front of your computer and watch a debate in parliament on something you know a little about. I couldn’t spare a couple of hours but nevertheless couldn’t resist the Science and Technology Select Committee’s hearings on the draft Investigatory Powers Bill published by the government last week.

My very own MP, Nicola Blackwood, the recently installed Chair of the committee, opened proceedings with a briefing from the Home Office. She assured us that the Home Office had assured her that there were no plans for new powers to ban encryption deployed by overseas companies. I assume that was rushed to Ms Blackwood in advance of the briefing, following Apple chief Tim Cook’s dim view of the Bill headlining the front page of the Telegraph that morning. The only new power in the bill, Nicola assured us, was the facilitation of access to internet connection records. Given the amount of public relations there has been in the run up to the publication of the bill, I was assured that Nicola was assured and that MPs had been assured that all was ok and they need not worry too much about what that bill actually says.

One problem with watching parliamentary proceedings on the Internet, however, is that no, not that the spies/police might be watching when the IP Bill passes, but that the Parliamentlive streaming service can be decidedly flaky. I spent a fair and irritating chunk of my couple of hours watching a buffering circle on my screen.

First up in the witness chairs were Matthew Hare, Chief Executive Officer, Gigaclear, John Shaw, Vice President, Product Management, Sophos, and James Blessing, Chair, Internet Services Providers' Association. All three tried valiantly to enlighten but separating an MP in thrall to a party briefing from a clear view of the world is a bit like trying to separate a toddler from a beloved comfort blanket.

Witnesses:
  • High speed internet connections could result in an annual storage requirement of 15 terrabytes of data, just relating to a single home
  • The amount of data the IP bill requires service providers to collect, indiscriminately, is huge and costly and will not meet the aims of the bill
  • Serious criminals are already using strong encryption the IP Bill won’t address
  • Keeping massive stores of data safe and secure is really difficult... cough… TalkTalk cough…
  • Definitions in the bill are ridiculously broad – not even clear what a service or a service provider is
  • The Bill disadvantages UK companies which appear obliged to hand over data overseas companies do not
  • Internet protocol data networks are not run the same way as telephony networks and assuming they do is a fundamental error
  • Engaging in a population wide data dragnet in order to engage in a historical data fishing expedition at some point in the future is inappropriate
  • What is being proposed in the IP Bill is what has already been done in China
  • With port mirroring everything delivered to a customer can be delivered to 3rd party (MPs eyes glazing over)
  • It’s going to cost taxpayers a lot of money
  • Targeted rather than mass surveillance is a more effective, efficient and practical approach to the aims of the bill. If service providers get a request to intercept traffic to a particular IP address they can and do do that today.
  • The removal of electronic protection aka nobble encryption clause is a baaaaad idea
  • The Bill talks about 3 layers of data – communications data, content and one or the other. Unfortunately, once you capture comms data it becomes content, when you analyse it, it becomes information. (MPs glazing over again)
  • The IP Bill, as it stands, potentially makes it a criminal offense for service providers to share information about security vulnerabilities
In summary their evidence amounted to – the Bill is technically complicated and unclear what it really means in practice; it'll cost a fortune, fail to catch terrorists and other serious criminals, damage business, undermine everyone’s security and result in large numbers of innocent people being inappropriately dragged into the net of suspicion.

MPs:
  • But, but, but…
  • We’re already paying to be spied on – that’s how we fund the secret services
  • It’s ok to have a dragnet for the internet because we have a dragnet for phones and it’s just the same
  • Stella Creasy enthusiastically jumped in to share her knowledge of IPv6 which would fix everything by allowing the “spearfishing” of the baddies’ data from giant data stores and thereby making everything ok with bulk personal data collection. Unfortunately, as the techies heroically tried to explain, IPv6 generates vastly more data and makes everything more not less complicated technically
  • But, but, but…
  • It’s ok because we don’t intend to do all those things you’re complaining about
In summary, but, but but…

Just as the ever excellent Professor Ross Anderson of Cambridge opened for the second collection of witnesses of the day, my dreaded buffering circle kicked in again… The second group also included Professor Mike Jackson, Birmingham City Business School, Dr Joss Wright, Oxford Internet Institute, and Professor Sir David Omand, King's College London.

My feed came back online just in time to hear Nicola Blackwood emphatically declaring that there was no place for ethics in the hearing. The committee was here to be educated purely on the technology issues.  Prof Omand open by profoundly disagreeing with everything Prof Anderson had just said.

Ah shucks. What did I miss?

As far as Prof Omand was concerned the questions underpinning the bill were not ethical in nature but empirical. Unfortunate though the revelations of former NSA contractor, Edward Snowden, were, they demonstrated, empirically and without question, that the intelligence authorities were very good at handling large quantities of data.

Prof Omand went on to explain that in his opinion the main “fuzziness” in the bill was in the distinction between communications data and content. It was, however, a fuzziness with minimal practical relevance. The bill was as close as you can get to clear on the distinction between the two. The word "clear" did draw some sharp intakes of breath in the room but he ploughed on. The real significance was in the authorisation process for intercepting or accessing the data; and since that could be worked out by the insiders with the appropriate expertise, there was nothing to be concerned about.

Joss Wight respectfully disagreed with the good Prof about there being a clear practical line between metadata and content. His main opening concern was with mass retention or “bulk” retention which the government likes to call it. Dr Wight would want to see some respect for proportionality. Prof Omand was a little irritated with this and noted that the mistake the Home Office made in last 5 years was to not update interception and surveillance codes of practice. If the public had known there were secret codes of practice governing everything, all would have been ok and then the Snowden wouldn't have been such a shock.

Prof Anderson was invited back into proceedings again and decided it was time to ground all this abstract stuff in something the MPs might understand – their Google calendars – Google calendar data relating to who they were meeting with, where and when would be within the scope of what the Bill would consider content. Prof Omand jumped in insisting that this was not intended and accusing critics of the bill of using “worst case” examples to undermine it. Theoretically, the Infinite Power (sic) Bill could be abused but trust us, it won’t be.

Dr Wight noted a fundamental misunderstanding underpinning the bill being the assumption that metadata (or communications data) is less sensitive than content. Prof Omand was, metaphorically at least, on his feet again – the authors of the bill (by this stage observers must have been wondering if he was one) were not disagreeing that communications data might be sensitive but "most of the time" it is not.

Dr Wight insisted that comparing web communications data to telephony data is ridiculous. A better analogy is to real life - what shop, home, workplace, place of leisure you visit are all captured. That provides a much more intrusive picture of life than telephone billing records. Content data is not more sensitive than communications data. It is merely differently sensitive.

An MP ventured a really good question (that was not of the variety ‘can you confirm how clever I am’) – how do we frame this kind of surveillance legislation so it is practical now and future proof? 

Prof Anderson bluntly explained you can't. The technology is changing too quickly and parliament will have to continually revisit access to personal data issues for the foreseeable future. Technology and policy are inextricably interlinked and guess what? The internet of things is about to hit us. Also whether we like it or not, the networks are international in nature and Prof Anderson strongly encouraged international cooperation in their regulation.

Dr Wight then pointed out that from an investigatory perspective a targeted approach to surveillance was more effective and more practical. Though he understood the seductive attractions of creating a time machine with which to explore, at some future point, the intimate details of anyone’s past life, it was somewhat unethical. 

Prof Anderson agreed. There may be information gold in them there communications data hills but that didn’t make it ethical to build them. 

Prof Jackson confirmed that even as you continue to construct these data mountains you’ll find only a tiny amount of the data is useful. This is mass surveillance.

Nicola Blackwood was now getting tired of reminding these techies that the panel was here to discuss technology not ethics.

And Prof Omand was having none of it from his fellow witnesses. The British government simply does not and would not indulge in mass surveillance. It’s not the done thing. Mass surveillance is the persistent surveillance of all or large part of population. And since it is only computers that are engaged in the persistent recording, storage and analysis of the intimate details of everyone's lives, that’s perfectly fine. Human beings only look at a small amount of the data you see. [By which measure, incidentally, you could make an argument for installing the most sophisticated modern video cameras, filming 24/7 in every corner of every room and space in the country - it will be ok if nobody looks at it].

Prof Jackson pointed out that when mass databases exist that opens the personal data to the post hoc (rather than real time) equivalent of mass surveillance. Dr Wight agreed – proponets of the IPbill might be claiming there is no mass surveillance going on because human beings only see a small proportion of the data but computers can do a phenomenal amount with mass data before humans ever get involved in the loop. We also need to be cognisant of the clear and empirically measured chilling effects of a population’s awareness of constant surveillance.

Ms Blackwood: No ethics please, we’re here to discuss technological issues!

Profs Anderson, Jackson & and Dr Wight: The elephant in the room here is the destruction of privacy and you cannot deal with this bill without discussing it.

Prof Anderson tried again to bring the discussion back to something the MPs would understand. There are, he noted, significant sensitivities around medical records for example. Likewise bank records – did the MPs want police or other public services trawling through people’s bank records?

Prof Omand was in no doubt that of course we do – it was perfectly reasonable. It was perfectly unreasonable for Prof Anderson to be attempting to scare people witless about abuse of these powers with worst case scenarios. It won’t happen because we will now have stronger oversight including the involvement of judicial oversight. We listened to our US cousins on that one.

Dr Wight, at this point, disputed the notion that the IP Bill was not expanding existing powers. It would additionally lead to a reluctance on the part of commerce to do business in the UK and people seeking to subvert what the bill is trying to do would simply use services overseas.

Prof Anderson again noted that if we’re to get a handle on the regulation of these technologies we have to have international cooperation. Something along the lines of an international cyber evidence convention is called for.

Prof Omand: The security of the internet is the number one priority. The policy in the bill is extremely clear. You simply cannot remove the right of the authorities to deal with pedophiles and the IP bill might give the police and security services a chance to catch them. We do note, however, that the judicial commissioners involved in the oversight processes will need a lot of technical expertise.

Prof Anderson: Yes and the problem with the proposed set up is that the experts on the advisory board will have representatives from police, security services and service providers. No one from civil society or academia is entitled to even a look in – no representatives, in short, for Jo Public. Given big data is manna from heaven for government and commerce, that appears somewhat unbalanced.

Nicola Blackwood watching the clock, with relief, summed up: We’re out of time. We need to give the security services what they need. We need to insure proportionality in the deployment of these powers. She also thanked the witnesses for their heated advice. [Actually it was all reasonably civilised even though there was a split in opinions on the panel]

So, in summary where did we actually get to?

Profs Anderson, Jackson and Dr Wight: The government are collecting digital dossiers on the intimate details of the personal lives of the entire population.  Whatever you choose to call it that is mass surveillance

MPs: But, but, but…

Prof Omand: No it isn’t and it is irritating that people keep saying so

MPs: Ah that’s a relief... and they vacated the room, party briefing comfort blankets still tightly clenched.

Update: The Science and Technology Committee has invited written submissions on the Investigatory Powers Bill by Friday 27 November. As Nicola Blackwood repeatedly reminded her witnesses, they are looking for submissions that focus on technology issues, including:
  • The technical feasibility and costs of meeting the obligations imposed by the Bill 
  • The impact on communications service providers and related businesses 
  • The likely consequences for citizen/consumer use of ICT services
You can submit your thoughts via the UK Parliament website.

Update 2:  A full official transcript of the hearings is now available.

Thursday, October 15, 2015

Tuesday, October 06, 2015

CJEU Schrems, The Irish Data Protection Commissioner and Facebook

The Court of Justice of the European Union has today declared the EU-US Safe Harbour agreement, which  facilitates the transfer of personal data from the EU to the US, invalid.

The Court opens by highlighting the provisions of the 1995 Data Protection Directive
Object of the Directive
1. In accordance with this directive, Member States shall protect the fundamental rights and freedoms of natural persons, and in particular their right to privacy with respect to the processing of personal data.
Article 25 of the directive lays down the principles under which it may be permitted to transfer personal data to countries outside the EU, "a third country" (or countries), primarily that the 3rd country offer "an adequate level" of data protection. The European Commission has the power to declare 3rd countries compliant with EU standards but are obliged to engage in due diligence in accordance with procedures outlined in article 31 of the directive, to ensure the requisite checks and balances are in place.

Under article 26, EU member states can sanction personal data transfers to third countries not yet in possession of the Commission's seal of approval under a specific set of circumstances e.g. if the person whose data is to be transferred agrees to it.

From an initial scan of the decision, it seems that the Safe Harbour agreement of 2000, declaring the US a safe 3rd country for EU personal data transfers, has been declared invalid by the Court because the EU were not careful enough in checking out the US; and because untrammeled US mass surveillance practices would appear to make it an unsafe third country.

From paragraph 5, the Court outlines the Commission's Safe Harbour Decision 2000/520 (including principles and US organisations' self certification and dispute resolution processes) declaring the US a safe third country for personal data transfers. The agreement allowed for US law to override Safe Harbour obligations. So if US law explicitly imposes an obligation on US organisations to process or transfer data in ways that would breach the Safe Harbour principles it is ok for them to do so. The idea being to give US companies an exit when caught between complying with conflicting legal obligations.

At the time, privacy advocates were unhappy with the Safe Harbour decision, accusing EU negotiators of folding in the face of US demands. Several reviews of the agreement, including this one by a group of internationally renowned scholars, in the summer of 2007, have noted that the Safe Harbour scheme does not meet the requirements of the 1995 data protection directive or EU privacy standards. Documentary evidence, released to journalists by NSA whistleblower Edward Snowden in 2013, on the mass surveillance practices of the US and UK governments, have given weight to those conclusions.

The CJEU get to the Snowden revelations and the EU's response to these in paragraph 11 to 25 of the Schrems decision. In a kind of an 'ooops, oh dear, those nice US Safe Harbour compliant companies are doing things they shouldn't be with EU data; but let's not upset them because it's the government's fault' realisation, the Commission issued Communication COM(2013) 846 final and Communication COM(2013) 847 final; noting US mass surveillance (though they didn't call it that) "raises serious questions".

As our US cousins might say, you're darn tootin' it raises serious questions.

Paragraph's 26 to 36 deal with the Schems complaint about Facebook to the Irish Data Protection Commissioner and the Irish High Court.

Schrems asserted that Facebook's data transfers to the US undermined his fundamental rights to privacy and the protection of his personal data, guaranteed by articles 7 and 8 the Charter of Fundamental Rights of the European Union.

The Irish Data Protection Commissioner said not my job guv, get lost but even if it was, there was no specific evidence that the NSA had been playing with Mr Schrems's data.

Judge Hogan in the Irish High Court took a different view. Whilst accepting that electronic surveillance and interception "serve necessary and indispensable objectives in the public interest... the revelations made by Edward Snowden had demonstrated a ‘significant over-reach’ on the part of the NSA and other federal agencies." [para 30 Schrems] Judge Hogan also noted that EU citizens have no effective right to be heard in relation to the "indiscriminate surveillance and interception" carried out on them on a large scale by US federal agencies like the FBI and NSA. Protections for privacy, fundamental rights and freedoms guaranteed by the Irish Constitution were essentially being undermined by indiscriminate and disproportionate mass surveillance by US authorities. On the basis of Irish law alone, the Irish Data Protection Commissioner was wrong to reject Mr Schrems complaint.

Judge Hogan's view, that then brings the Commission's Safe Harbour decision of 2000 into play. Does that decision, certifying the US as a safe place for EU personal data, bind member states, obliging them to accept that certification; or can a data protection authority of a Member State, independently examine the claim of a person concerning a breach of their rights by a third country, when the law and practices in the third country do not ensure an adequate level of protection? Additionally, given what we know from Snowden, Judge Hogan believes the Safe Harbour decision itself to be invalid - as the fundamental right to privacy would be rendered meaningless if "State authorities were authorised to access electronic communications on a casual and generalised basis without any objective justification based on considerations of national security or the prevention of crime that are specific to the individual concerned and without those practices being accompanied by appropriate and verifiable safeguards."

The Court's deliberations play out in paragraphs 37 to 107.

The fundamental rights to privacy and data protection have been affirmed and re-affirmed in the Court time and again (Österreichischer Rundfunk and Others, Google Spain and Google, Ryneš, Rijkeboer, Digital Rights Ireland and Others). The independence of national supervisory authorities is an important element in protecting those rights in practice. They are obliged, however, to balance those rights with the interests of those requiring free movement of data and have no power relating to the processing of data, once it is transferred to another country. They do have an obligation, under articles 25, 26 and 28 of the 1995 directive, to monitor the transfer of data to a third country and ensure it complies with EU standards. Transfers may only be effected where the country the data is being sent to offers an "adequate level of protection".

Member states or the Commission may assess and determine whether protections offered by a third country are adequate. When the Commission makes a decision that a third country provides adequate protections it is binding on member states, until it is declared invalid by the CJEU. But that Commission decision cannot prevent EU citizens from pursuing a claim through the national supervisory authorities and, if necessary, national courts, if they have reason to be concerned that their fundamental rights are being undermined by the transfer to and processing of their personal data in a third country. If the national courts consider the complaint well founded, as did Judge Hogan in the Schrems case, they must refer it to the CJEU.

Bottom line - even if the Commission white-lists a country like the US, it does not prevent national data protection authorities investigating and national courts hearing an individual's complaint. And if an individual, like Mr Schrems, has a legitimate complaint, then it may be referred to the CJEU and the Commission's decision approving the US as a privacy respecting jurisdiction, may itself be reviewed [exclusively] by the Court of Justice.
"66 Having regard to the foregoing considerations, the answer to the questions referred is that Article 25(6) of Directive 95/46, read in the light of Articles 7, 8 and 47 of the Charter, must be interpreted as meaning that a decision adopted pursuant to that provision, such as Decision 2000/520, by which the Commission finds that a third country ensures an adequate level of protection, does not prevent a supervisory authority of a Member State, within the meaning of Article 28 of that directive, from examining the claim of a person concerning the protection of his rights and freedoms in regard to the processing of personal data relating to him which has been transferred from a Member State to that third country when that person contends that the law and practices in force in the third country do not ensure an adequate level of protection."
Paragraphs 67 to 106 review the validity of the Commission's Safe Harbour decision and constitute another CJEU warning over US and UK mass surveillance practices and the tepid European Commission response to these, following in the tradition of the Google Spain and Digital Rights Ireland cases from 2014.

Short version: the Commission failed totally, in its obligation to ensure that the laws and international obligations of the US actively respected the privacy rights of EU citizens, when approving the US as a trusted data protection nation, in their Safe Harbour decision of 2000. US organisations were permitted approval under a Safe Harbour self certification scheme which had no effective US public authority or legislative oversight (the US Federal Trade Commission's oversight being restricted to commercial disputes relating to unfair or deceptive practices in or affecting commerce and not the legality of interference with fundamental rights) and no remedies for individuals concerned about the potential abuse or misuse of their personal data. Not only did it fail, the Commission didn't even bother to check but eventually did get round to admitting, once the Snowden revelations emerged, that there might be "serious questions" over the Safe Harbour agreement.

Additionally the Commission, in the Safe Harbour decision, exceeded its authority in attempting to nullify national data protection authorities' powers to enable individuals to raise concerns about the processing of data in Commission approved third countries like the US.
86 ... Decision 2000/520 lays down that ‘national security, public interest, or law enforcement requirements’ have primacy over the safe harbour principles, primacy pursuant to which self-certified United States organisations receiving personal data from the European Union are bound to disregard those principles without limitation where they conflict with those requirements and therefore prove incompatible with them. ...
88 In addition, Decision 2000/520 does not contain any finding regarding the existence, in the United States, of rules adopted by the State intended to limit any interference with the fundamental rights of the persons whose data is transferred from the European Union to the United States, interference which the State entities of that country would be authorised to engage in when they pursue legitimate objectives, such as national security.
89 Nor does Decision 2000/520 refer to the existence of effective legal protection against interference of that kind...
92 Furthermore and above all, protection of the fundamental right to respect for private life at EU level requires derogations and limitations in relation to the protection of personal data to apply only in so far as is strictly necessary (judgment in Digital Rights Ireland and Others, C‑293/12 and C‑594/12, EU:C:2014:238, paragraph 52 and the case-law cited).
93 Legislation is not limited to what is strictly necessary where it authorises, on a generalised basis, storage of all the personal data of all the persons whose data has been transferred from the European Union to the United States without any differentiation, limitation or exception being made in the light of the objective pursued and without an objective criterion being laid down by which to determine the limits of the access of the public authorities to the data, and of its subsequent use, for purposes which are specific, strictly restricted and capable of justifying the interference which both access to that data and its use entail ...
94 In particular, legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life, as guaranteed by Article 7 of the Charter (see, to this effect, judgment in Digital Rights Ireland and Others, C‑293/12 and C‑594/12, EU:C:2014:238, paragraph 39).
95 Likewise, legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter...
96 As has been found in particular in paragraphs 71, 73 and 74 of the present judgment, in order for the Commission to adopt a decision pursuant to Article 25(6) of Directive 95/46, it must find, duly stating reasons, that the third country concerned in fact ensures, by reason of its domestic law or its international commitments, a level of protection of fundamental rights essentially equivalent to that guaranteed in the EU legal order, a level that is apparent in particular from the preceding paragraphs of the present judgment.
97 However, the Commission did not state, in Decision 2000/520, that the United States in fact ‘ensures’ an adequate level of protection by reason of its domestic law or its international commitments. 98 Consequently, without there being any need to examine the content of the safe harbour principles, it is to be concluded that Article 1 of Decision 2000/520 fails to comply with the requirements laid down in Article 25(6) of Directive 95/46, read in the light of the Charter, and that it is accordingly invalid... 
99      ... national supervisory authorities must be able to examine, with complete independence, any claim concerning the protection of a person’s rights and freedoms in regard to the processing of personal data relating to him. That is in particular the case where, in bringing such a claim, that person raises questions regarding the compatibility of a Commission decision adopted pursuant to Article 25(6) of that directive with the protection of the privacy and of the fundamental rights and freedoms of individuals...  
102 The first subparagraph of Article 3(1) of Decision 2000/520 must ... be understood as denying the national supervisory authorities the powers which they derive from Article 28 of Directive 95/46, where a person, in bringing a claim under that provision, puts forward matters that may call into question whether a Commission decision that has found, on the basis of Article 25(6) of the directive, that a third country ensures an adequate level of protection is compatible with the protection of the privacy and of the fundamental rights and freedoms of individuals.
103 The implementing power granted by the EU legislature to the Commission in Article 25(6) of Directive 95/46 does not confer upon it competence to restrict the national supervisory authorities’ powers referred to in the previous paragraph of the present judgment.
104 That being so, it must be held that, in adopting Article 3 of Decision 2000/520, the Commission exceeded the power which is conferred upon it in Article 25(6) of Directive 95/46, read in the light of the Charter, and that Article 3 of the decision is therefore invalid.
105 As Articles 1 and 3 of Decision 2000/520 are inseparable from Articles 2 and 4 of that decision and the annexes thereto, their invalidity affects the validity of the decision in its entirety. 106 Having regard to all the foregoing considerations, it is to be concluded that Decision 2000/520 is invalid."
The Court concludes that the Safe Harbour Decision 2000/520 is invalid.

I would just repeat paragraph 93 for emphasis: "Legislation is not limited to what is strictly necessary where it authorises, on a generalised basis, storage of all the personal data of all the persons whose data has been transferred from the European Union to the United States without any differentiation, limitation or exception being made in the light of the objective pursued and without an objective criterion being laid down by which to determine the limits of the access of the public authorities to the data, and of its subsequent use, for purposes which are specific, strictly restricted and capable of justifying the interference which both access to that data and its use entail"

So, in summary, national data protection authorities and national courts can review claims of abuse of personal data by third countries and the Safe Harbour EU-US agreement, Decision 2000/520 is invalid.
"On those grounds, the Court (Grand Chamber) hereby rules: 1. Article 25(6) of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data as amended by Regulation (EC) No 1882/2003 of the European Parliament and of the Council of 29 September 2003, read in the light of Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that a decision adopted pursuant to that provision, such as Commission Decision 2000/520/EC of 26 July 2000 pursuant to Directive 95/46 on the adequacy of the protection provided by the safe harbour privacy principles and related frequently asked questions issued by the US Department of Commerce, by which the European Commission finds that a third country ensures an adequate level of protection, does not prevent a supervisory authority of a Member State, within the meaning of Article 28 of that directive as amended, from examining the claim of a person concerning the protection of his rights and freedoms in regard to the processing of personal data relating to him which has been transferred from a Member State to that third country when that person contends that the law and practices in force in the third country do not ensure an adequate level of protection.
2. Decision 2000/520 is invalid."

Update: Peter Swire who was one of the US expert negotiators when the Safe Harbour provisions were agreed, yesterday criticised CJEU AG's opinion in the case, as suffering from particular inaccuracies concerning the law and practice of U.S. foreign intelligence law, notably the PRISM program. He particularly emphasises changes to US law since the original Snowden revelations notes with approval the PRISM program is governed by Section 702 of the law enacted in 2008 to amend the Foreign Intelligence Surveillance Act. I suspect, given s702's 'guilty of being a foreigner' provisions Caspar Bowden would have had a few words to say on the subject.

The full court don't get into the intricacies of PRISM but it does hint strongly that Kafkaesque mass surveillance, without remedy available to those affected, undermines the rule of law.

Update 2: Daniel Solove does a really accessible analysis of the Court's decision and its possible implications. I suspect he over-estimates the likely impact of the coming revisions to EU data protection laws, given the giant privacy avoidance loopholes built into the draft general data protection regulations. But it is still essential reading.

Update 3: I also highly recommend Andres Guadamuz's analysis of the case.

Update 4: Some typos plus one error relating to FTC corrected. There follow links to EU Commission/Parliament reviews of Safe Harbour in 2002, 2004 and the post Snowden reviews of 2013 COM(2013) 846 final Rebuilding Trust in EU-US Data Flows and COM(2013) 847 final on the Functioning of the Safe Harbour from the Perspective of EU Citizens and Companies Established in the EU