Saturday, June 16, 2012

Help ORG stop the snoopers' charter

The Open Rights Group needs your help to fight the Communications Data Bill. The announcement on the Bill was slipped out on Thursday when David Cameron was giving evidence before the Leveson inquiry. At least £1.8 billion is to be spent on mass surveillance technology at the same time as sacking police officers and military personnel.



As ORG say,
"Your communications via Google, Facebook or Skype will now be open to what may be a large number of government officials. We want to see the powers to collect and access communications data tightened up, not extended ever further."
And they're offering training sessions to help you get involved in educating people and MPs about these dangerous proposals -
"a series of events to get the campaigning going at the grassroots, and help people working with their MPs.



You don't need any previous knowledge of the issues or experience talking with your MP. 

Each training event will last for around four hours. They will cover a background briefing on the issues and an overview of the campaigns followed by some practical training on how to speak to your MP. 

The sessions will be sociable and entertaining as well as extremely informative.  And if you wonder whether it is worth an evening of your time just remember that you cannot protect democracy by building state infrastructure of mass surveillance. Bruce Schneier put it more accessibly, "technology shouldn't give big brother a head start... it's bad civic hygiene to build technologies that could someday be used to facilitate a police state."

Monday, June 11, 2012

Congratulations Dr Doctorow

Congratulations to the prolific Cory Doctorow who fittingly, on Friday last, 8 June 2012, was awarded an honorary doctorate by the Open University.

(Image via Matt Locke).

Professor Marian Petre made the presentation explaining why Cory had been honoured.
"Cory Doctorow is a science fiction novelist, blogger and civil rights activist. He is the co-editor of the hugely popular weblog Boing Boing (boingboing.net), and is a regular columnist for The Guardian, Wired, Popular Science, Make, The New York Times, and many other newspapers, magazines and websites. He was formerly Director of European Affairs for the Electronic Frontier Foundation (eff.org) and was a founder of the UK-based Open Rights Group, both non-profit civil liberties organizations that defend freedom in technology law, policy, standards and treaties. He has worked at the UN, with standards bodies, governments, industry, universities and other non-profit organizations promoting a balanced approach to intellectual property law, a policy area of special educational concern to the Open University. In 2007, he served as the Fulbright Chair at the Annenberg Center for Public Diplomacy at the University of Southern California.
His internationally-renowned science fiction novels are simultaneously published by Tor Books and released on the Internet under Creative Commons licenses that encourage their re-use and sharing, a demonstration of his philosophy on open publication. He has won the Locus and Sunburst Awards, and been nominated for the Hugo, Nebula and British Science Fiction Awards. Entertainment Weekly has called Doctorow "The William Gibson of his generation."
At a time when technological developments and associated regulations are transforming our society, including our concepts of privacy and freedom of expression, Doctorow has been a tireless campaigner for the free flow of ideas, educating the press, policymakers, OU students and the general public alike about civil liberties issues related to technology and intellectual property law.
In IP law in recent years, far removed from the attention of most ordinary people, there has been a dramatic expansion in government-granted monopolies over broad swathes of knowledge – patents on human genes or ways of doing business, repeated extensions of the term of copyright – which present a clear and present danger to the mission of the Open University to promote ‘educational opportunity and social justice by providing high-quality university education to all who wish to realise their ambitions and fulfil their potential.' Through his campaigning, his writings, his multitude of accessible and entertaining talks, all freely available on the Internet, Cory Doctorow has told this complex story, in a way we can all understand, of the largely successful lobbying of IP industries as they struggle to protect and extend their knowledge-based monopolies in the face of developments in technology. His boundless energy and advocacy of innovative business models and the removal of barriers to achievement does a service, not just to the OU and the general public, but the entertainment industries themselves which, even as they succeed in getting more and more draconian copyright laws and locked-down technologies, continue to experience a shrinking turnover of their products.
In addition to this wide-ranging contribution in areas of special educational concern to the OU, Doctorow has made his specific unique contributions to OU courses like TU100 (My Digital Life).
Doctorow was named one of Forbes magazine's 2007/8 Web Celebrities, and one of the World Economic Forum's Young Global Leaders for 2007. Doctorow co-founded the open source peer-to-peer software company OpenCola, sold to OpenText, Inc in 2003. He serves on the boards and advisory boards of a variety of cultural and charitable foundations and civil rights organisations such as the Participatory Culture Foundation, the MetaBrainz Foundation, Technorati, Inc, the Organization for Transformative Works, Areae, the Annenberg Center for the Study of Online Communities, and Onion Networks, Inc.
In summary, we nominate Cory Doctorow for an honorary Open University DUni, in recognition of his tireless endeavours and recognised international standing in areas of special educational concern to the University – technology law, policy and standards and the free flow of ideas – and our mission to ‘promote educational opportunity and social justice by providing high-quality university education to all who wish to realise their ambitions and fulfil their potential.’"

Friday, June 01, 2012

Oracle v Google ruling a win for Google

Judge Alsup has issued an Order re Copyrightability of certain replicated elements of the Java Application Programming Interface. I like the way he opens, describing the case as "the first of the so-called “smartphone war” cases tried to a jury."

An interesting element of the case, evident in his summary of the ruling and the substance of the decision, is that the judge actually learnt some java to help him come to a decision. A technically literate judge - that's something of a rarity. It would be nice if policymakers and the courts generally made such efforts in relation to technology.
"SUMMARY OF RULING
So long as the specific code used to implement a method is different, anyone is free
under the Copyright Act to write his or her own code to carry out exactly the same function
or specification of any methods used in the Java API. It does not matter that the declaration or
method header lines are identical. Under the rules of Java, they must be identical to declare a
method specifying the same functionality — even when the implementation is different.
When there is only one way to express an idea or function, then everyone is free to do so and
no one can monopolize that expression. And, while the Android method and class names could
have been different from the names of their counterparts in Java and still have worked,
copyright protection never extends to names or short phrases as a matter of law.
It is true that the very same functionality could have been offered in Android
without duplicating the exact command structure used in Java. This could have been done by
re-arranging the various methods under different groupings among the various classes and
packages (even if the same names had been used). In this sense, there were many ways to group
the methods yet still duplicate the same range of functionality.
But the names are more than just names — they are symbols in a command structure
wherein the commands take the form
java.package.Class.method()
Each command calls into action a pre-assigned function. The overall name tree, of course, has
creative elements but it is also a precise command structure — a utilitarian and functional set
of symbols, each to carry out a pre-assigned function. This command structure is a system or
method of operation under Section 102(b) of the Copyright Act and, therefore, cannot be
copyrighted. Duplication of the command structure is necessary for interoperability.
I wonder if the comment that
"copyright protection never extends to names or short phrases as a matter of law"

is a dig at the 2005 Bridgeport music decision where the US Court of Appeals for the 6th Circuit ruled that a 2 second sampling of 3 notes constituted copyright infringement.

And how about this on APIs:
"An API is like a library. Each package is like a bookshelf in the library. Each class is
like a book on the shelf. Each method is like a how-to-do-it chapter in a book. Go to the right
shelf, select the right book, and open it to the chapter that covers the work you need. As to the
37 packages, the Java and Android libraries are organized in the same basic way but all of the
chapters in Android have been written with implementations different from Java but solving the
same problems and providing the same functions. Every method and class is specified to carry
out precise desired functions and, thus, the “declaration” (or “header”) line of code stating the
specifications must be identical to carry out the given function."
 Mark Lemley at Stanford (and owner/coordinator of the excellent Cyberprof list) gets a mention.
 "the number of software patents in force in the United States has dramatically increased from
barely a thousand in 1980 to hundreds of thousands today...This has caused at least one noted commentator to observe:
As software patents gain increasingly broad protection, whatever
reasons there once were for broad copyright protection of
computer programs disappear. Much of what has been considered
the copyrightable “structure, sequence and organization” of a
computer program will become a mere incident to the patentable
idea of the program or of one of its potentially patentable
subroutines.
Mark Lemley, Convergence in the Law of Software Copyright?, 10 HIGH TECHNOLOGY LAW JOURNAL 1, 26–27 (1995)."
Whereas it's true copyright causes all sorts of problems for programming I remain as unconvinced as Donald Knuth was in 1994 that software should be subject to proprietary patent rights.  I find the idea that software is mathematics too convincing for that.

Most notably in this case, though, Judge Alsup is pretty scathing about Oracle's claims in concluding:
"In closing, it is important to step back and take in the breadth of Oracle’s claim. Of the
166 Java packages, 129 were not violated in any way. Of the 37 accused, 97 percent of the
Android lines were new from Google and the remaining three percent were freely replicable
under the merger and names doctrines. Oracle must resort, therefore, to claiming that it owns,
by copyright, the exclusive right to any and all possible implementations of the taxonomy-like
command structure for the 166 packages and/or any subpart thereof — even though it 
copyrighted only one implementation. To accept Oracle’s claim would be to allow anyone
to copyright one version of code to carry out a system of commands and thereby bar all others
from writing their own different versions to carry out all or part of the same commands.
No holding has ever endorsed such a sweeping proposition.
CONCLUSION
This order does not hold that Java API packages are free for all to use without license.
It does not hold that the structure, sequence and organization of all computer programs may be
stolen. Rather, it holds on the specific facts of this case, the particular elements replicated by
Google were free for all to use under the Copyright Act. Therefore, Oracle’s claim based on
Google’s copying of the 37 API packages, including their structure, sequence and organization
is DISMISSED. To the extent stated herein, Google’s Rule 50 motions regarding copyrightability
are GRANTED (Dkt. Nos. 984, 1007). Google’s motion for a new trial on copyright infringement
is DENIED AS MOOT (Dkt. No. 1105)."
It's a 2-1 win for Google on the merits of the case which, given a jury recently decided Google didn't infringe Oracle's claimed patents, is a killer blow to Oracle's bid to extract multiple truckloads of cash from Google's coffers.

Apologies for the formatting issues with the extracts from the ruling.

Monday, May 28, 2012

The universality of organisational stupidity

1.   Knowledge = Power [sic]

2.   Time = Money [sic ditto]

3.   Power = Work/Time [Science]

Substitute 1. into 3. to give:

4.   Knowledge = Work/Time

Substituting 2. into 4. demonstrates:

5.    Knowledge = Work/Money

Re-arranging 5. leads to the conclusion that

6.     Money = Work/Knowledge

Hence we derive and/or demonstrate the universal nature of organisational stupidity. I was thinking of using this in opening my book on the convergent evolution towards insanity of large organisations.  But insanity, at least in a legal sense, is to do with a person's capacity to be responsible for their actions in the context of a loss of contact with reality. Stupidity is a feature of the insanity of large organisations but I'm wondering if it is a sufficiently important feature or emergent property of the insanity to merit inclusion in the introduction? Answers on a postcard (or electronic equivalent) please...

Friday, May 25, 2012

A Global reality: don't put your data in the cloud, Mrs Worthington

Hogan Lovells have produced a very practical and succinct white paper, A Global Reality: Governmental Access to Data in the Cloud.

The authors examine government access to personal data in the cloud across ten jurisdictions and conclude that we're kidding ourselves if we believe controls on government access are tighter in the EU than the US.
"Businesses often assume knowledge of the laws regulating
governmental access to data in their home jurisdictions, and
they make further assumptions about the legal regimes
abroad where Cloud service providers may be located."
The authors mention the PATRIOT Act as a particular bogey man for critics of the US in this regard. Whereas the PATRIOT Act does give governmental authorities wide ranging powers equivalent anti- terrorism laws in other jurisdictions mean
"Every single country ... examined vests authority in the
government to require a Cloud service provider to disclose
customer data in certain situations, and in most instances
this authority enables the government to access data
physically stored outside the country’s borders, provided
there is some jurisdictional hook."
The result is that:
"Some erroneously believe the best way to limit governmental
access to data is to use Cloud service providers present only
in “safe” jurisdictions – places where data are thought to be
free from troublesome governmental access."
But even when particular jurisdictions don't seem to have nominally permissive access regimes,
"The existence of Mutual Legal Assistance Treaties greatly
diminishes any argument that data stored in one jurisdiction
is immune from access by governmental authorities in
another jurisdiction." 
Just as civil rights activists have been explaining for years, you can drive a coach and horses through the loopholes in the statutory protections for privacy in the EU.

The report points out that in terms of protection the EU could, by virtue of the existence of the data retention directive (Directive 2006/24/EC) be structurally weaker on personal data protection in theory than the US.
"a law that perpetuates the existence of data that might not otherwise be available to governmental authorities (because it would have been deleted) is a factor to be considered in evaluating the favorability of one jurisdiction over another as a service provider location."
Being a short overview of 10 jurisdictions the Hogan Lovells report doesn't have the capacity to go into the practical application of the various legal regimes. They clearly and succinctly outline the situation in each jurisdiction - the US, Canada, Australia, Denmark, France, Germany, Ireland, Japan, Spain and the UK and also note that "Proposals for reform of privacy rules in the EU do not contemplate altering the current environment in which law enforcement has significant access to data in the Cloud."  In the UK, for example,
"The government may intercept communications if doing so is
“necessary” in the interests of national security; for the
prevention or detection of a serious crime; to safeguard the
economic well-being of the UK; or in response to a request
under an international mutual legal assistance agreement.
There is no need for court approval and the details of such
an “interception warrant” must be kept secret."
The table at the end of the paper provides a neat summary indicating you can barely slip a cigarette paper between the access regimes across all 10 jurisdictions reviewed. The lesson?

For the foreseeable future, if you want to protect your data from essentially unrestrained government access, (without even thinking about private sector and criminal access and sharing), don't put your data in the cloud, Mrs Worthington.

Report authors, Winston Maxwell and Christopher Wolf, should be commended for condensing a complex subject in such an accessible way.

Update: One of the smartest thinkers/practitioners around on privacy and the Net, Caspar Bowden, has pointed out that the over-simplification in the report, as simplification often does, distorts the real story here. The claim that the EU might be structurally weaker than the US on privacy regulations, for example, does not stand up to any kind of close scrutiny. Caspar draws particular attention to the DOJ's belief that the PATRIOT Act is subject to secret government interpretation and additionally that such claims are unsustainable when the details of the PATRIOT Act and the FISA (Foreign Intelligence Surveillance Act) Amendment Act 2008 (s.1881a) are examined and compared to EU regulations.

Update 2

Caspar Bowden says:
"This paper, and several others of its kind over past few years, manage to avoid mentioning ... :

- the FISA Amendment Act 2008 s.1881a, which created a new power targeted only at non-US persons outside the US, to intercept communications and access "remote computing services" (i..e Cloud computing) from any company subject to US jurisdiction, which compels access, without any warrant, to...

- ...information which merely "relate" to "the conduct of the foreign affairs of the United States" or "with respect to" a "foreign territory" or "a foreign-based political organization". Isn't is strange how all US accounts of US laws seem to omit these limbs of the (enormous and rambling) definitions?

- s.215 of the Patriot Act, which is being interpreted according to some secret doctrine that is (possibly/probably) about grabbing arbitrary data stored on disk under powers designed for library records, thus avoiding a warrant. This will likely be worse if you are outside the US, because you will have no chance at all to get standing in a US court (assuming you ever found out about it).

All this is quite illegal in ECHR territories, which grant universal rights irrespective of nationality (within the jurisdiction of the 50 signatory states), with laws that are precise and foreseeable in their effect, for purposes which cannot include spying on ordinary lawful democratic political activities and beliefs"
He goes on to comment specifically on some of the detail:
"pp1. "As one observer put it, France's anti-terrorism laws make the Patriot Act look "namby-pamby" by comparison."
- following the footnotes, that 'observer' is one Gary Schmitt, former staff director of the US Senate Select Committee on Intelligence

pp2. - "it is incorrect to assume that the United States government’s access to data in the Cloud is greater than that of other advanced economies"
- Untrue: FISA explicitly discriminates both the protections and allowed purposes by nationality, given inferior (or zero) protection to foreigners, especially outside US

pp.2 - Kennard: "In a number of critical areas, the U.S. provides more restrictions to the access of personal data than do European Member States."
- Untrue: under no Cloud-relevant circumstances will the data of a European in Europe receive greater protection under US law than under European law

pp.2 - "Despite the procedural hurdles that may exist to request and obtain information pursuant to MLATs..."
Misleading - euphemism for fact EU law enforcement authorities may have to wait 6 months while their MLAT requests stack up in the US Department of Justice (thus discouraging sending very many)

pp2. - "The existence of Mutual Legal Assistance Treaties greatly diminishes any argument that data stored in one jurisdiction is immune from access by governmental authorities in another jurisdiction."
Wrong - unless the US wants to do any political spying (e.g. on the European Commission where apparently use of US cloud apps is rife for preparing official documents)

pp.4 - "The reality is that most of the investigatory methods in the Patriot Act were available long before it was enacted. And those investigative tools had, and still have, limitations imposed by the United States Constitution and by statute"
Misleading: - although the US Constitution is silent on the matter, the US mostly doesn't recognize (ask John Yoo) foreigners as having Constitutional rights, even those physically within US territory. Which is sort of the point in Cloud computing.

pp.4 "Under the ECPA, if a government body seeks disclosure of customer data from a Cloud service provider, it can only do so if a judge issues a search warrant or special ECPA court order, or if the government issues a valid subpoena to the provider"
Omission - which is why the secret interpretation malarkey of Patriot 215 is important, because it by-passes this law and then some (no probable cause, or reasonable grounds to believe etc.)

pp5. "FISA Orders and NSLs were available to the United States government even before the Patriot Act was enacted. The Patriot Act merely expanded some of the
provisions of these access methods. For example, it added “gag order” provisions"
- here's what that merely amounted to for one small ISP owner

pp.5 "A Cloud service provider also may petition the court to overturn the “gag order.”"
- only took Nick Merrill six years of life

pp5. "...relevant to the concerns of foreign countries about their nationals’ data, a recent ruling by a United States appeals court one level below the Supreme Court confirmed that statutory protections are extended to non-United States citizens for data physically maintained in the United States and stored in the Cloud"
Misleading & wrong: - there's no reference given, but they plainly mean the Suzlon case, which only applies to ECPA (Electronic Communications Privacy Act) not ways of getting at data under FISA or Patriot or relying on 4th Amendment protection, and isn't a Supreme Court decision anyhow. But well done Microsoft for litigating hard anyway, even if it is self-serving to reassure your foreign customers.
====

[...]

====
pp.12 "In short, the proposals for reform of privacy rules in the EU do not contemplate altering the current environment in which law enforcement has significant access to data in the Cloud."
Sadly true but also misleading: the draft of the proposed new EU DP Regulation which leaked in Dec 2011 contained an Article (42) which would have required Cloud providers to get the approval of data protection authorities before responding to direct US law enforcement authorities' requests (e.g. under Patriot/FISA), on pain of severe fines, and to notify the individual. Presumably after heavy lobbying, this Article was removed in the published proposal, replaced with a pathetically weak Recital 132 which says if the Commission finds out something naughty is going on they should jolly well do something about it quickly""
Caspar would be grateful for comments, corrections and refinements. Thanks to Caspar and to Peter Sommer who originally drew my attention to the report via the excellent FIPR alerts.


Monday, March 19, 2012

The $8 (or maybe $6) billion iPod

Rob Reid, founder of the Rhapsody online music subscription service has being doing some copyright Maths at TED.



He suggests we put aside the emotive debates about copyright and associated monsters like SOPA and ACTA and look at the numbers.  The MPAA, for example, claim the internet is costing the US economy $58 billion a year "due to content theft".  $58 billion which if you had it laid out in pennies would stretch all the way to Mars. It's also equivalent to the entire US corn crop failing, along with all fruit, wheat, cotton, rice and a number of other crops.

Music revenues are down about $8 billion a year since Napster's early days according to the music labels.  Movie and cable TV along with publishing revenues are up so where's the missing $50 billion, once the $8 billion drop in music sales is accounted for? With copyright revenues up in most sectors the missing $50 billion must be "foregone growth in a market that has no historic norms", i.e. a market that didn't previously exist.  His tongue in cheek answer to the missing link is "the insidious cost of ringtone piracy."

The MPAA also tell us the economy loses 373,000 jobs to content theft. Interesting given that in 1998 the US Bureau of Labour Statistics showed the entertainment companies were employing 270,000 people.

He goes on to talk about the $150,000 statutory damages available in the US for copyright infringement, (hence the notorious excessive damages in the Jammie Thomas and Joel Tenenbaum cases).  He claims the original MP3 player the Rio could store 10 songs i.e. $1.5 million worth of songs. In an iPod with a 40,000 song capacity this runs to $6 billion "worth of stolen media." It's a pity he got his sums wrong here, as he actually says "$8 billion worth of stolen media or about 75,000 jobs."  Maybe the error is deliberate and he's making a subtle point about the normal rules of mathematics being ignored in copyright debates and policy?  His conclusion that you might find copyright math strange is an understatement.  The five minute talk is nevertheless worth a look.

Update: Rob Reid explains his $8 billion calculation:
"In determining a given device’s maximum capacity for infringing material, I assumed an average song length of three minutes, and an encoding rate of 128 kilobits/second. I went with 128 kbps because using the AAC codec,[25] this is the rate at which music achieves “hi-fi transparency[26] — which is to say, it becomes indistinguishable from CD quality in most listening environments. This rounds very closely to 1 megabyte of data per minute of music.[27] At 32 megabytes, the Rio (1999’s Christmas hit) therefore had room for about 10 songs, which, if pirated, could represent up to $1.5MM in liabilities under US law. Today’s iPod classic, with its 160GB capacity, can hold 53,333 songs, which at $150,000 a pop is precisely $8 billion. Incidentally, Apple markets the iPod classic as having room for just 40,000 songs, but by my math, that’s selling it short. I meant to note this in the presentation, but I was running way over time by then, and spared everyone the convoluted math (so if the leap from 40,000 songs to an $8 billion liability confused anyone, I apologize — I had meant to take a quick detour through that 53,333 figure!)."
That's a really helpful clarification.  The problem with simplifying  is you end up losing precision to the point of getting it wrong. I hesitate to extend the pedantry but 53,333 songs at at $150,000 a pop is precisely $7,999,950,000 not $8 billion. Another 1/3 of a song at $50,000 is needed to reach the magic $8 billion.  Of course the odd $50k in the copyright wars is barely discernible small change...

Wednesday, March 14, 2012

Pictfor: Harvgreaves, consumer & creator rights

Consumer Focus and the Parliamentary Group on Internet Communications and Technology (Pictfor) had another panel discussion about the Hargreaves review yesterday evening in the Grand Committee room in Westminster Hall at the Houses of Parliament.  The speakers were Mike Holderness, Chair of the Creators’ Rights Alliance, Gwen Thomas, Consultant to the Association of Photographers, Saskia Walzel, Senior Policy Advocate at Consumer Focus, and Simon Indelicate of the UK band the Indelicates.

The event was chaired by Alun Michael MP, who opened proceedings opining that finding common ground was a more productive process to the usual situation where vested interests get together in their own silos and reinforce their own views. Stakeholders getting together, listening to each other and working out a way forward was much better than leaving it to government which has a huge capacity to get things wrong. So stakeholders should work out what needs to be done and get the law to underpin that with principles. He also mentioned that the panel event was a follow up to a Consumer Focus and creators rights day long event which had explored:
  • Copyright exceptions
  • Orphan works
  • How to smooth the flow of money from consumers to creators
- and associated issues. Then introduced the speakers, inviting Saskia Walzel of Consumer Focus to go first. Saskia opened by explaining Consumer Focus is the statutory watchdog for consumers. They work on copyright licensing, exceptions and enforcement.  The work on licensing grew out of their initial work on enforcement.

Consumer Focus are keen for licencing reform and the facilitation of the licensing of legal services in a timely manner. They have found that consumers are broadly supportive of copyright as a framework to ensure creators get a fair share of the revenues flowing from their work.  But equally consumers are bewildered by the complexity of copyright and for example the illegality of format shifting.

Historically consumers were not big stakeholders in the detailed archaic rules of copyright. It was relatively difficult for them to engage in infringement, so they didn't need to understand the rules. In the modern world though where the use of a computer connected to the internet results in de facto copyright infringement consumers need to understand and buy into copyright regulations.  So Consumer Focus strongly support Hargreaves recommendation for a limited private copying exception.

Saskia said the last major copyright law update in the UK was in 1988 in the time of tape recording machines. Ancient times and therefore unsuitable for the internet age. Consumers expect private copying to be legal. But also accept unlawful copying via peer to peer networks to be controlled.

In a digital age many exceptions intended to benefit creators are now used by consumers e.g. reporting and commenting done by bloggers. So exceptions need to work for consumers as well as creators. Consumers are users of copyrighted materials and share creator needs.

Consumer Focus argue there is a desperate need for a small claims court for copyright disputes.  The UK Intellectual Property Office hope to introduce such a system later this year. The cost of litigation under the current system is way beyond the means of most individual consumers and creators. The current system was created for commercial entities, the assumption being they would have the necessary funds to go to court if and when necessary.

Hargreaves conclusions were quite similar to those of the Gowers review in 2006. The primary difference was the Hargreaves concentrated on well functioning markets to support growth and therefore focused on licencing. Consumers and creators are large stakeholders in this. We need to ensure the fruits of consumer spending get back to creators. Creators in the UK often get a very small slice of the pie if any at all.  In a bid to address this creator groups have periodically called for levies on consumer technology like ipods. The thinking is that an extra revenue stream can be generated which creators could benefit from.  But the flaw in the plan is that it does not address the key problem of the money being soaked up by intermediary commercial agents like the big music labels. Nearly £800 million was spent on recorded music in 2011. Commercial companies and wealthy artists got the lion's share of it.

Saskia also noted that Hargreaves did not properly consider creators' rights. Though moral rights do get mentioned.

There is an underlying false assumption behind a lot of the public debate on copyright that creators' rights are coincident with commercial entities interests.  The Monopolies and Mergers Commission as far back as the mid 1980s found that the big music labels were engaged in monopolistic practices; and that they used their monopoly position to impose unfair contract terms on creators.  Yet they concluded that this was not against the public interest.

The interests of creators and commercial intermediaries are not the same. So how do we construct a copyright system where intermediaries do get paid but creators get a better share of the spoils?

The next speaker was Mike Holderness, Chair of the Creators’ Rights Alliance (CRA). He explained that the CRA has about 100,000 members, many of whom are sole traders. The CRA are concerned about how we will get growth.

He asked the question: what do? And then answered by stating it involved overwhelmingly the work of sole traders. These individuals have very little bargaining power in dealing with the commercial intermediaries.  Mike Holderness himself is a science writer.

Technological changes create massive possibilities e.g. to reach a worldwide audience but most of these possibilities are only theoretical.  The changes and the possibilities provided to sole traders by disintermediation are welcome.  But the problem is taking advantage of the changes because people trust big name brands.

Hargreaves concentrated too much on re-users and intermediaries (e.g. big search engines) as far as the CRA is concerned. It is hard to make a living as a professional creator. Wikipedia is a great example of what people will do for free but it's not reliable.  We have to have reliable information produced by people who dedicate their working lives to doing it.

There has been a lot of controversy around the phone hacking scandal and we need to get journalists to take responsibility for their work.  Yet they often have no control over how it is presented.  The journalist researches and writes a story.  It is then mangled by the editorial process at the newspaper where the first three paragraphs are rewritten to trot out the paper's editorial line. To get the story as it was intended to be conveyed you have some chance only if you start reading at the fourth paragraph. There are numerous examples of newspapers and magazines altering photographs e.g. Time Magazine's alteration of a photo of O.J.Simpson around the time of his arrest as a murder suspect making his skin look darker. An unaltered copy of the photo appeared simultaneously in Newsweek. The original photographer had no control over any of this. The president of the CRA herself had an article she wrote on gay marriage grossly distorted and misrpresented when published in the Gulf.

Publishers often have a standard creator rights waiver which writers are obliged to sign if they want their work published. So creators need an enforceable right to be named/accredited as happens in France. The UK has failed creators in the area of moral rights. Moral rights support the careers of individual creators.

These laws are not made for agents.  Every kid in the country will be a published author, holding copyright in their contributions to Facebook, before they can vote.  We therefore need to level the playing field in terms of relative bargaining power between individuals and large commercial services like Facebook.

As he then got the nod from the chair that his time was up, Mr Holderness concluded with a rapid "Libraries are a very wonderful thing!"

The third speaker was Gwen Thomas, Consultant to the Association of Photographers. Ms Thomas opened directly with a critique of the Hargreaves review suggesting it missed two key areas - contracts and moral rights.  The Association of Photographers did a survey in 2007 of about 2500 members. 50% of respondents said that their bargaining power had diminished in the previous ten years. 40% had been forced into signing moral rights waivers and 24% had seen decline in attribution over the same period. 31% said the decline was getting worse.

So they believe we need to strengthen moral rights and equalise bargaining power of commissioners, creators and users.

When the Copyright Designs and Patents Act (CDPA), introducing extra protection for photographs, came into force on 1 August 1989 it was a mixed blessing.  Nice in theory but that same day nearly all photographers got a letter from the big publishers including a contract to waive moral rights. They were obliged to assign the copyright in their photos to the publisher and waive their moral rights into the bargain. For every photographer refusing to assign copyright there is a queue of people prepared to do it.

Unlike for European colleagues UK law treats copyright like a property right. Therefore as property it is something you can give or sign away.

The UK needs to strengthen the Unfair Contract Terms Act 1977 which does not apply to intellectual property.

Moral rights are hugely important to photographers because derogatory treatment of their work is rife.  Most professionals are aware of moral rights but not that they need asserting. Everyone is a photographer but most are not aware of their rights under the law.

There is a lot of talk about orphaned works but images become orphaned unintentionally.  The original photographer knows they are not orphaned. Photographers can avail themselves of the economic benefits of lending rights when there is no name on the image.

Moral rights are incredibly important for reputations.  The moral right to object to the derogatory treatment is hugely important (this applies equally to digital artists and illustrators).  Images can be and are widely copied and mutilated on the internet and this can damage the career of a photographer.  Misuse, distortion and doctoring of images of people can damage the people in those photos.

We need stronger moral rights.  If we don't get them the UK photographic community will decline.

The problem with digital images is that the embedded metadata can be removed.  Photographers use the internet to sell themselves but images are constantly lifted.  The Association of Photographers calls for "effective sanctions against those who deliberately extract metadata."  When I asked later if they were asking for specific new anti-circumvention provisions in law to cover metadata in digital photographs Ms Thomas indicated with a nod that yes that was what they were interested in.

Simon Indelicate of the Indelicates band was the final speaker. He began by explaining he found the idea of copyright weird and then proceeded to outline the genealogy of one of his own songs, Savages, from the album Songs for Swinging Lovers. He described the song as being one of his favourite creations which he would hate to see mistreated.  The song draws inspiration from -
  • Ode to my Family by the Cranberries - chords
  • Orchestration from someone else
  • Beat - "used in every dance track since 1985 and every indie song since 2003"
  • The savage from Huxley's Brave New World, a title stolen from Shakespeare
  • Paraphrased line from West Side Story
  • The phrase "sweat of the brow" as used in a particular video game
  • A section stolen from a poet who stole it from another poet which ended up sounding like something from The NeverEnding Story.
  • Samples from recordings made by a violinist
None of the parts were done by corporates.  They were created by him being inspired by other creators. But he believes the resultant song is uniquely his and certainly uniquely important to him and his wife. Good art communicates and for that we need to be able to freely refer to our culture. Just like Milton freely referred to the Bible and Shakespeare. Creators need to be able to consume and use copyrighted materials.

He wants people to pay him for his creations but we need to recognise that our culture does not have the division between creators and consumers there used to be.  Creation needs constant access - free and open access - and also a chain of recognition.

At this point the chairman, Alun Michael, called for questions from the floor, with an opportunity for the panel to respond at the end. The 'questions' mostly turned out to be statements rather than questions.

Q1.  New technology is changing at an astonishing speed. Everyone has become a creator. Who needs to change fastest, intermediaries or legislators? (That, in fairness, was a question)

Q2. Could Gwen Thomas from the Photographers Association elaborate on how to draw the line between original work and what users can do with it? (Also a question. Pity Alun Michael didn't let the panelists respond at this stage.  It might have set the tone for a dialogue.)

Q3. David Hammerstein of the TransAtlantic Consumer Dialogue (TACD) said copyright is not in harmony. Citizens violate copyright massively. Therefore we need to adjust the law to fit reality. He finds though he is almost reluctant to describe it as such a "luddite" resistance to this change. So at the point when we have the ability to digitise orphan works we get the EU constructing a law to prevent it.  Copyright is almost absurd today. It is absurd that we need an international treaty to give blind and partially sighted people access to copyrighted works. 1.5 million Braille works can't be sent from the UK to India because it is illegal.  It's very important to release orphan works and facilitate easy access for those with visual disabilities.

Q4. Paul Ellis, co-founder of Stop43, who successfully lobbied against photography provisions in the Digital Economy Act, said orphan works are only orphans as far as the discoverer is concerned. A photographer knows his own work is not orphaned. Calling the copying of orphaned works a victimless crime is nonsense. Copyright is a human right under Article 27 of the Universal Declaration of Human Rights. Creators have to be allowed to make money from the work we create.  We can only do that through copyright.

Q5. A representative from the Open Rights Group asked Gwen Thomas if she could clarify whether it was moral rights or economic rights the Photographers Association was most concerned about. (Another question!)

Q6. A representative of the UK IPO mentioned they were working on a current government proposal that photographers should be equitably remunerated.

Q7.  James Firth of Open Digital asked how the panel viewed the global jurisdiction issue particularly in the light of the two recent copyright extradition cases. (Note the Home Secretary, in the latest stage of the UK TVShack case, decided yesterday that student Richard O'Dwyer should be extradited to the US).

Q8. I asked Gwen Thomas if she was calling for a specific new anti-circumvention provision in law to cover meta data in digital photographs.  She nodded.

Q9. Three or four (if EMI doesn't get rolled into Universal) music companies own 95%+ of the world's recorded music of the past 50 years.  These middlemen are standing in the way of consumer money getting to creators.  Transparency is important. We need clear audit trails of the cash flows.

Q10. Guy Fletcher of the Performing Rights Society (PRS) said they represent 75,000 writers and 5000 publishers.  In answer to the point made by one of the speakers about the Monopolies and Mergers Commission, they also investigated the PRS and found them to be effective.  About 60,000 of their writers don't make a living.  Those 60k need the collective bargaining strength of the PRS.  The Monopolies and Mergers Commission decided they were a necessary and benign monopoly.  The PRS Board is run by creators and publishers.  He welcomed the moral rights language in the 1988 copyright legislation.  However the writing community suffer like the photographers.  They bend to pressure and sign waivers.

Q11.  A former MP and representative of the CRA asked Saskia Walzel of Consumer Focus when the interests of consumers should override those of creators.  (Finished on a high with a question).

The panel then got the chance to respond in reverse order.

Simon Indelicate went first. He said the collecting agencies presented an interesting problem. When his band plays in small clubs in Germany those clubs pay large fees to the German collecting agency. As a result those clubs are barely financially viable. Yet his band never sees even a small proportion of the fees paid to the collecting society because they are too far down the food chain.

He believes we can improve the system with the aid of modern technology.  The collecting agency system is too monolithic at the moment - everyone loses apart from Bono.  On the points raised by Stop43 on unintended orphan works and moral rights, they are legitimate but all creators including Shakespeare stand on the shoulders of giants.  Copyright's purpose is to ensure more culture is made.  More culture is good for society and the Net is great at facilitating the creation of more culture.  He doesn't like the idea of the law making the creation of culture more difficult.

He also has a problem with the claim that he has a right to make money doing what he does.  As far as culture is concerned supply has exploded but demand has not kept pace.  Yes photographers should get paid but they don't have a right to make a living from photography.

His final contribution addressed the first question - he didn't care if corporations (i.e. intermediaries) changed because their business models were already causing them to fail.

Whilst making his points he was subject to some heckling by Labour MP, Jim Dowd, who had originally been scheduled to be on the panel in his place. He responded to Mr Dowd robustly and was cheerfully supported in that endeavour by the chair, Alun Michael.

Next up was Gwen Thomas from the Photographers Association.
She was particularly keen to address the question from the Open Rights Group representative about whether they were primarily concerned about moral or economic rights. Moral rights were pre-eminent.  The primary focus was integrity not money.  But the building of reputation through the protection of moral rights enabled photographers to derive income from their work.

Mike Holderness from the Creators' Rights Alliance was next.
He has a problem with the corporation that scanned all the world's books without permission and put them online. A creator should have the right to object to the distortion of their work in a way which damages their reputation.  He is pleased there is a sensible draft of a WIPO Treaty for an Improved Access for Blind, Visually-Impaired and Other Reading Disabled Persons. There were delays there because a lot of vested interests were trying to include crazy exceptions on the back of it.
Most importantly to round off Mr Holderness was emphatic about the need to level the playing field in terms of the relative bargaining power between individual creators and the corporations they do business with.

Saskia Walzel from Consumer Focus finished up the session for the panel.
She outlined some history explaining copyright was originally supposed to cover books and the law has been changed in response to changes in technology.  In the UK we have had big changes in copyright law in 1911, 1956 and 1988. So it is not unusual that it gets changed to cope with new technology. It is the current rate of change of the technology that is the problem.

It takes about 3 years to update primary legislation. So we should make copyright legislation more technology neutral.

Creators should always be attributed as has been the case in most European countries since the beginning of the 20th century.  That principle has not changed.

In the UK the time-shifting exception in 1988 has stood the test of time. Lots of language in the 1988 Act was technology specific (e.g. photocopying).  Such language will not stand the test of time.

Creators are the first owners of copyright.  They get that privilege so they can bargain with publishers.  Shakespeare had no copyright but still made money.  Copyright developed country by country. That's why Charles Dickens had so many problems with the US where so many publishers copied, printed and sold his books without ever paying him a penny.  There was no mutual respect between countries or recognition of the copyrights of foreign authors until the Berne Convention was negotiated in the late 19th century.

We as a society have decided that rewarding creators is important.  Some people are making money out of the copyright system. Too often these beneficiaries are not the creators.  So we need to focus on reforming the contracts and licencing systems to ensure creators get a fairer share of the spoils.

Alun Michael then closed proceedings by expressing his admiration in principle for the notion of technology neutral laws.  His concern is that technology makes everything unpredictable. Also that too often parliament is concerned with legislating to deal with specific problems of the day, rather than laying down blueprints of more general principles.

A few of closing notes:

1.  Thanks to Consumer Focus for inviting me along.

 2. I've attempted to report what was said accurately at this stage, rather than comment (with the exception being the comment about the way questions were handled).  Regular readers will know I have a different perspective to a number of the views expressed.

3. It is irritating when the blogger spellchecker refuses to work on long posts - precisely when it is needed - and I have to cut and paste and check in an external word processor.  If I've missed any typos let me know and I'll correct them.

Monday, March 12, 2012

EDPS opinion on the data protection reform package

The European Data Protection Supervisor (EDPS), Peter Hustinx, last week issued his opinion on the European Commission's data protection reform package. The Commission announced proposed changes to EU data protection rules in January, including a proposal for a Directive covering data protection in law enforcement. He is impressed with the intent of the new general data protection rules and simultaneously "seriously disappointed" (code for "appalled") at the carving out of a special anything goes directive for law enforcement. There is a decent summary of the opinion in the associated press release.
"On the package, Peter Hustinx, EDPS, says: "The proposed Regulation constitutes a huge step forward for the right to data protection in Europe. However, we are unfortunately still far from a comprehensive set of data protection rules on national and EU level in all areas of EU policy. The proposals are disappointing in the law enforcement area, and they leave many existing EU data protection instruments untouched, such as the data protection rules for the EU institutions and bodies and also all the specific law enforcement instruments...
"The proposed rules for data protection in the law enforcement area are unacceptably weak. In many instances there is no justification whatsoever for departing from the rules provided in the proposed Regulation. The law enforcement area requires some specific rules, but not a general lowering of the level of data protection."
The EDPS is concerned in particular with regard to:
  • the lack of legal certainty about the further use of personal data by law enforcement authorities;
  • the lack of a general duty for law enforcement authorities to demonstrate compliance with data 
  • protection requirements; 
  • the weak conditions for transfers to third countries; 
  • the unduly limited powers of supervisory authorities. "
In relation to new general Regulation on data protection he also has some specific concerns on the details:
  • the possibilities for restricting basic principles and rights;
  • the possible derogation for transferring data to third countries;
  • the excessive powers granted to the Commission in the mechanism designed to ensure
  • consistency among supervisory authorities;
  • the new ground for exceptions to the purpose limitation principle.
As usual with Mr Hustinx it is a thoughtful comprehensive opinion and whereas I don't expect many but privacy anoraks to read and inwardly digest the full 85 pages, the two page executive summary should be compulsory reading for all EU citizens.  Expect the Commission to liberally use and abuse that description of the proposed regulation as "a huge step forward for data protection in Europe" whilst simultaneously ignoring and engaging significant energies to circumvent the serious concerns raised in the opinion.

Friday, March 09, 2012

BT, TalkTalk lose DEA appeal Part 2

I've been thinking further on the BT DEA Court of Appeal decision, BT Plc and TalkTalk Telecom Group Plc -v- Secretary of State for Culture, Olympics, Media and Sport and others on Tuesday. This post will focus primarily on the data protection element of the case.

In my previous post I mentioned the Court's questionable assumption of balance in the text of the legislation and the associated lack of understanding of the technology. The other thing that concerns me about the decision was the selective perspective on legislative histories of the relevant legal instruments.

Then Secretary of State for Business, Innovation and Skills Peter Mandelson's road to Damascus like revelation, following a holiday with some rich friends and including a meeting with a well known entertainment mogul, that the UK 'needed' a 3 strikes regime, quickly led to the ill thought out Digital Economy Bill. This got rushed through parliament in the wash up of legislation before the last election becoming the controversial Digital Economy Act (DEA). The possibility of balance in the final text of the statute was effectively blown out of the water by the unseemly, unprecedented haste with which it was rushed through, the almost complete lack of parliamentary scrutiny of the bill and the universal lack of understanding amongst parliamentary representatives about what it was all about.

Let's look at some of the detail of that in the context of the data protection element of the case. As previously mentioned BT and TalkTalk challenged the act on four grounds.  Firstly in relation to the technical standards directive and secondly the ecommerce directive. These aspects of the case I covered in my first post. Ground 3 of the challenge was based on the data protection directive and the privacy and electronic communications directive.

On the data protection directive the Court focuses on Article 8(1) and 8(2)(e)
"SPECIAL CATEGORIES OF PROCESSING
Article 8
The processing of special categories of data
1. Member States shall prohibit the processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, and the processing of data concerning health or sex life.
2. Paragraph 1 shall not apply where: ...
(e) the processing relates to data which are manifestly made public by the data subject or is necessary for the establishment, exercise or defence of legal claims. "
In High Court last year judge Parker originally concentrated his analysis of the data protection directive angle on the processing of personal data by copyright owners. As explained by Lord Justice Richards in the Court of Appeal decision this week:
"75. For reasons given at [152]-[157], the judge concentrated on the processing of data by the copyright owners, i.e. the processing involved in their identifying apparent infringements, together with relevant IP addresses and subscriber details, for the purpose of compiling copyright infringement reports: it was accepted that subsequent processing by the ISPs, including the sending of notifications and the completion of copyright infringement lists, would be compatible with the directive. The judge proceeded on the basis that the data processed by the copyright owners would be “personal data” and that, because of what might be revealed by the nature of the unlawfully copied digital material identified by the exercise, some of it would be special category data falling within Article 8(1). He held at [159]-[161], however, that such processing would fall within the exception in Article 8(2)(e). In particular:
“159. The Defendant and the Interested Parties rely on Article 8(2)(e) …: the processing is necessary for ‘the establishment, exercise or defence of legal claims’. That would appear to be the precise purpose of the contested provisions of the DEA: the copyright owner will be able, through the procedures under the DEA, to establish not only that there has been an infringement of copyright but also who is responsible for the infringement.”
So the judge bypassed the ISP processing of the personal data and concentrated on that done by copyright owners.  He then concluded the data at the heart of the case was covered by article 8(1) privacy protection provisions but that article 8(2)(e), the right to pursue legal claims, was an absolute get out clause which facilitates fishing expeditions to detect copyright infringement via mass invasion of privacy.  Contrary to European Court of Justice recommendations in the Promusicae case in 2008 (which I'll get to a little later in the context of the privacy and electronic communications directive) Judge Parker effectively decided that copyright protection trumps privacy.

BT argued that a substantial number of cases triggered by the DEA would not involve legal claims because it was estimated that 70% of ISP customers receiving warning letters would act to stop infringement associated with their account at that point.
"76. The appellants’ essential submission is that the judge lost sight of the fact that in a substantial proportion of cases the scheme established by the DEA 2010 is not intended to involve legal claims at all... assumption in the Government’s impact assessment for the statute that 70% of infringers would stop once and for all upon receiving a single notification from their ISP... if that is right, those cases will not get as far as inclusion in a copyright infringement list and there will be no prospect of a legal claim... “a principal aim of the measures is educational (so obviating legal action)”. In the light of those matters, Mr White submitted that the scheme would operate for the most part as an extra-judicial curtailment of copyright infringement, and he submitted that in those circumstances the processing could not be said to be necessary for the establishment, exercise or defence of legal claims and could not therefore fall within the exemption in Article 8(2)(e)."
Quite clever that - 70% of suspects will never get involved in legal proceedings so the personal data processing exception, article 8(2)(e) can't apply to these. The surveillance and processing of personal data in the case of the 70% cannot be considered to be necessary for the establishment, exercise or defence of legal claims.

Lord Richards sadly completely rejected that argument.  His explanation feels a bit like saying the ends justify the means:
"77. I do not accept that submission. In my view the processing is plainly necessary for the establishment, exercise or defence of legal claims even if the beneficial consequence of the sending of a notification by the ISP pursuant to a copyright information request will be that in the majority of cases the infringing activity ceases and no further action is required. As Mr Saini QC observed on behalf of the Interested Parties, the fact that the scheme seeks to educate users about the legal rights of copyright owners and to encourage them to desist without the need for legal action does not mean that the copyright owners are not establishing, exercising or defending their legal rights. It no more has that effect than does the sending of a letter before action to an infringer in the hope that he will desist. In my view, therefore, the judge was right to find that the processing in question in this case would fall within the exception in Article 8(2)(e)."
The mass processing, he suggests, is necessary and 8(2)(e) applies because it facilitates the sending of warnings equivalent to cease and desist letters. It's a defensible perspective but I think it avoids addressing the fishing expedition issue. I'm wondering if there is Supreme Court (doubtful) or ECJ guidance on the specific interpretation of 8(2)(e) in this kind of context that would help here?

Lord Richards then concludes his assessment of the data protection directive's impact on the case by mentioning the European Data Protection Supervisor's (EDPS) clear opinion (relating to ACTA negotiations) that mass personal data processing for 3 strikes regimes was disproportionate and in breach of EU data protection laws; but the noble Lord rounds off by stating that EDPS opinion is not binding on the Court so does not alter his view on article 8(2)(e).
"78. I should mention for completeness that the appellants placed reliance in this context on an Opinion dated 22 February 2010 of the European Data Protection Supervisor (“the EDPS”) on then current negotiations by the EU of an Anti-Counterfeiting Trade Agreement with third countries. We were told by Mr Saini that the Opinion was provided by the EDPS of his own motion and was based on the EDPS’s own understanding of what was then proposed. At paragraph 52 of the Opinion, in relation to the possible imposition on ISPs of a “three strikes internet disconnection policy”, the EDPS acknowledged that the collection of targeted, specific evidence, particularly in cases of serious infringements, might be necessary to establish and exercise a legal claim, but he cast doubt on the legitimacy of wide-scale investigations involving the processing of massive amounts of data of internet users. It is not clear that he had Article 8(2)(e) of the DPD specifically in mind, but if he did it is difficult to see why the applicability of that provision should depend on the scale of the operation. In any event the view expressed by the EDPS is not binding on us and it does not cause me to alter my own view that the processing in this case would fall within Article 8(2)(e)."
Whereas it is true that the EDPS's opinion is not binding on the UK, Lord Justice Richards casual dismissal of the scale factor here is rather worrying: "it is difficult to see why the applicability of that provision should depend on the scale of the operation". Seriously?  If the judiciary can’t understand that scale changes everything we have a potentially insurmountable problem. Yet I'm flummoxed on how to get that through to a distinguished judge in terms he would understand.

Possibly what we have here is a Court seeing a problem through the lens of the strongest possible contrast of the false privacy  v security dichotomy. When the problem is constructed as the balancing of the privacy of a single individual against the security of a whole nation or society, then the needs of the many outweigh the needs of the few.  In this case, the privacy of the individual (remember scale doesn't matter according to Lord Richards), especially a suspected pirate hiding his nefarious copyright infringing deeds and therefore unworthy of the rights of decent law abiding citizens, has to be weighed against the interests of an important industry. Do we want to protect the dirty pirate - the underlying unspoken assumption being that privacy is fundamentally about concealing bad behaviour - or the livelihoods of thousands of people dependent on that industry?  Again it's a no contest.  The greater good favours protecting the many by protecting the industry.  The abstract societal value of protecting the privacy of the individual is incalculable but nebulous. And the absence of evidence to the effect that this mass privacy invasion will help the industry is not even a factor that remotely touches the cognitive radar of the learned judge. Routine copyright warning notices or the 3 strikes regime almost inevitably bound to emerge from the DEA will not solve the industry's internet copyright infringement problem. Machines, transmission pipes and storage are getting faster, bigger and cheaper and copying is only going to increase in volume.

I got a little side-tracked there but the scale and the framing of the problem are critical when it comes to protecting privacy and finding sustainable business models for the >entertainment industry. Lord Richards took slightly less space to dispose of the BT challenge based on the privacy and electronic commerce directive than he did in the two pages of the decision dealing with the data protection directive.

The privacy and electronic commerce directive articles 5 and 6 impose obligations regarding the confidentiality of communications and traffic data.  Article 15(1) is the universal get out clause here and provides for bypassing confidentiality when it is:
"a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system, as referred to in Article 13(1) of Directive 95/46/EC. To this end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period justified on the grounds laid down in this paragraph."
Note that copyright protection is not included in that list of reasons to ignore privacy. However, in paragraph 80 of the judgment, Lord Richards uses the Promusicae decision from the European Court of Justice to conclude that protection of copyright can be used as an excuse to bypass privacy obligations imposed by the directive.  It is true that the ECJ in Promusicae said that article 15 could provide a route around privacy obligations when it involved "the protection of the rights and freedoms of others." The ECJ indeed clearly stated that music labels had the right to protect their copyrights. The fundamental foundation of the Promusicae decision, though, was that copyright owners rights must be balanced with the basic human rights of users of the Net. Having access to the Net is now a basic part of nearly everyone's life in the developed world and it relates to basic rights to
  • free expression
  • freedom of association
  • education
  • and employment
and the ECHR and every other serious international charter of rights says that if a law is not proportionate it is not legal.  Copyright does not trump privacy according to the ECJ.  Even with the legitimate aim of defending or protecting copyrights, the ECJ clearly instructed member state governments that they are not to endanger human rights or proportionality. Professor Lilian Edwards of Strathclyde University actually thinks that the Promusicae decision was a clear warning from the court aimed directly at the kind of 3 strikes notice and disconnect schemes the French have implemented and that might emerge from the DEA.  That Promusicae, therefore, should be used in defence of the position that protection of copyright does trump privacy is something of an anomaly.

BT's final shot on the privacy and electronic communications directive was that the the recent judgement of the European Court of Justice in Scarlet v SABAM (Case C-70/10, November 2011), negating the demand that the ISP install a copyright filtering system, supported their argument that article 15 could not be an excuse for copyright trumping privacy. Lord Richards simply responded that the Scarlet case was effectively not relevant here and rejected that argument.

I'm not going to spend a lot of time on the fourth and final ground on which BT brought the case, the Authorisation Directive, (2002/20/EC), save to say that both BT, the original judge made some fair points. Though I would question the semantic hair splitting of both sides in paragraph 97; and the concluding implicit value judgment in that same paragraph that the DEA strikes "a proportionate balance between the free market and the protection of copyright."

Now just three final points to note on the authorisation directive.  Firstly at paragraph 95, Lord Richards says:
"95...  the Commission’s comments on the French legislation which permits  measures to be taken against internet users who commit copyright infringement  online. In those comments the Commission recognised that copyright protection is a general interest objective of a kind referred to in Article 1(3). As to the  Commission’s comments on the draft Costs Order, the fact is that the United  Kingdom persisted in its reliance on Article 1(3) but the Commission took no further action, which is at least consistent with an acceptance by the Commission that Article 1(3) is applicable."
This sounds a little like deciding to take the legislative history of the directive into account when it supports the Court's perspective on the case but ignore it when it doesn't.

Secondly, Lord Richards does agree with BT's counsel, Mr White, that: "all costs and charges under the DEA regime, including “relevant costs”, are to be regarded as “administrative charges” within Article 12.
What matters is substance, not form:" So the ISPs had a partial win on the authorisation directive.

Thirdly, I predict that Lord Richards final paragraph on the authorisation directive where he says:
111... I do not think that anything material is added by recourse to the principle of  non-discrimination or the desirability of technological neutrality. "
will be repeatedly taken out of context.  I confess I can't resist the temptation to be the first to do so.  This statement on its own is a simple example of the learned judge's lack of understanding of the technology.

So there you have it.  The decision was predictable though questionable in the underlying assumption of balance in the text of the legislation.  It's disappointing that that judiciary continue to have a problem understanding the technology and the difference that the scale of surveillance and data processing has on this whole landscape. We techies have to get better at explaining it to them.

What we have here is a clash of values even more than of law or of vested economic actors like telcos and the entertainment companies.  Perhaps we need a modern day Samuel D. Warren or Louis D. Brandeis to create a navigation blueprint, internet constitutional framework or just a base level equivalent understanding of the impact of the technology of the information society on our fundamental right to privacy.

Wednesday, March 07, 2012

BT, TalkTalk lose DEA appeal

The Court of Appeal (Civil Division) issued its judgment in the case of BT Plc and TalkTalk Telecom Group Plc -v- Secretary of State for Culture, Olympics, Media and Sport and others yesterday.

They rejected BT's and TalkTalk's challenge of the Digital Economy Act (DEA), as did Justice Parker in the High Court last April.

In many ways it was a predictable outcome but nevertheless frustrating, both for the lack of understanding of the technology displayed by the Court and the underlying assumption of "balance" in the wording of the key legal instruments on display.

The contested provisions of the DEA impose "initial obligations on ISPs to notify (s124a) customers of copyright infringement reports (CIRs) received from copyright owners; and to provide (s124b) copyright infringement lists (CILs) to content owners if an "initial obligations code" is in force. The initial obligations code could be self regulatory (s124c) - worked out between the telcos and copyright owners - or imposed by Ofcom (s124d) in the event the relevant agents can't agree amongst themselves. S124e gives a fairly detailed list of the things that the initial obligations code is supposed to cover eg CIRs, CILs, what suspect identification has to be expedited, who pays what, administrative specifics, proportionality, transparency, non discrimination and other provisions. The DEA also empowers the Secretary of State to decide rules about the relative responsibilities for costs arising from the initial obligations code.

The DEA also allows the future introduction of blocking measures or a 3 strikes regime or, more accurately, future "technical obligations" on ISPs to police copyright infringement.  The case was not concerned with these technical obligations - only the initial obligations code and the relative costs provisions.

The ISPs are exorcised by the demands the DEA initial obligations code is imposing on them.  They appealed Justice Parker's rejection of their challenge on 4 grounds.

Firstly they content the obligations (sections 124 a to e of the DEA) should have been notified to the EU Commission under the requirements of article 8(1) of the Technical Standards Directive. Lord Justice Richards (in para 24 to 45 of the judgment) rejects the claim on the basis of European Court of Justice precedents (Case C-317/92 Commission v Germany 1994 and Case C-194/94 CIA Security SA v Signalson SA and Securitel SORL 1994) which suggest that the initial obligations code, once the details are worked out, will be notifiable to the Commission under the directive, but the primary legislation from which the code is derived is not notifiable, since it's not detailed enough to be a technical standard.

BT made some sound detailed arguments on this eg when (para 34) they suggest the original judge might have been mistaken in saying "that the ISP would not be liable to receive or take action on a copyright infringement report “unless” a code was in force: “unless” suggests that there might not be a code, whereas the statute requires there to be one." This is a very fair point but on the substance of the precedents they lost the overall argument on points in relation to the technical standards directive.

Secondly they challenged on the basis of a perceived twofold breach of the Electronic Commerce Directive.
"(1) that the effect of the contested provisions is to render ISPs potentially “liable for the information transmitted”, contrary to Article 12, and (2) that the contested provisions amount to restrictions on the freedom to provide information society services from other Member States, “for reasons falling within the coordinated field”, contrary to Article 3."
Lord Richards quotes liberally from the original High Court judgement of Justice Parker here.  Justice Parker basically liberally praised the balance of the legislation (eg. he explained he was concerned about "doing violence" to the language and thereby "upsetting the careful balance represented by the text"); whilst saying that making an ISP police copyright infringement is not the same as making them liable directly or vicariously for copyright infringement.  So forcing ISP into incurring costs of policing does not trigger making them liable as "mere conduits" and therefore article 12 of the directive doesn't apply. It's a defensible and possibly even clever position but the notion that it is "balanced" is too deferential to the legislature and a long way out of sync with such evidence as is available regarding the proportionality of the mass surveillance the DEA facilitates. Lord Richards uses paras 46 to 60 of the judgment to do little more than agree with that position.

The argument in relation to article 3 of the ecommerce directive, which excludes copyright from its scope, was slightly more convoluted. Basically BT argued that the DEA was not a copyright statute so therefore not excluded from section 3. The government argued and the judges agreed that it was a law related to copyright and therefore excluded. There was an argument too about whether the copyright and related rights directive provided an upper limit on what member states could do with copyright law (BT's position) or whether it was a baseline ("a minimum harmonising measure") and didn't prevent the enactment of more restrictive measures. BT lost that one too.
"70. At the time when the Electronic Commerce Directive was adopted, “copyright” in the Annex to the directive must in my view have had its normal meaning, encompassing all aspects of the law of copyright under national laws, and cannot have had the elaborate meaning attributed to it by the appellants. At that time there was no harmonising directive at the Community level in the field of copyright protection. It would be unrealistic to impute to the Community legislature, at least in the absence of clear, express language to this effect, an intention to give “copyright” a meaning related to provisions of a copyright directive that had not yet been adopted. But if “copyright” did not have the appellants’ meaning at the outset, I do not see how it can have come to acquire that meaning subsequently. The later adoption of the Copyright Directive cannot of itself have had the effect of changing the meaning of the expression. It would have needed an express amendment of the Electronic Commerce Directive to achieve that result, but no such amendment has ever been made.
71. In my judgment, that is sufficient to dispose of the appellants’ case under Article 3 of the Electronic Commerce Directive."
Ground three of the appeal was on the basis of the data protection directive and the privacy and electronic communications directive. My perspective on that central element of the case and ground 4 in relation to the authorisation directive will be the subject of a later post.

Wednesday, February 29, 2012

Do authors still need publishers?

I've been in touch with the publisher of my first book, Springer, about writing another one, this time on systems failures in regulating the internet.  I would like to release it under a creative commons licence and price it at less than £15.

Springer was one of the first big publishers to try open access publishing as far back as 2004, primarily with academic journals. They describe their perspective on open access thus:
Open access publishing makes articles published in a journal freely and permanently available online. Open access journals operate in the same way as traditional journals, including stringent and thorough peer-review. The only difference is the business model, whereby a fee is levied upon publication. Articles are then freely available and can be redistributed and reused as long as the article is correctly attributed.
And this short video gives a decent overview:



The company is fairly new to releasing books under creative commons licences but told me that if I wanted to go down that route there would be an initial fee and that the print version of the book would be priced at £44.95.

By coincidence I was reading Anthony Horowitz's article in yesterday's Guardian, Do we still need publishers? when the further details came through from Springer by email.  The fee would depend on the number of pages in the book.  The minimum fee would be €15,000 if the book was shorter than 200 pages; and €75 per page for longer books.  So a 312 page book (like my first) would cost €23,400.

On Springer's open access journals there appears to be a reliance on authors' academic institutions providing the up front publishing fee. So it was a natural question from Springer's perspective to ask whether the Open University would be interested in providing some funds for me to publish my book with them under a creative commons licence. The answer, given the funding squeeze on universities in the UK, is no.

There are a lot of very smart, hard working and dedicated people at Springer but, even if universities were not facing financially straitened circumstances, €20k+ up front for publishing a book is not a good business proposition.  Hopefully my friends at Springer will find a more viable and sustainable model for publishing creative commons and open access books.  Until then I'll have to look for another publisher if I want to CC my next book.

Anthony Horowitz, by the way, concluded we do need publishers and he values highly the important values and standards they bring to the table.
"I asked my own publisher, Jane Winterbotham, why I needed her and she came straight back with the reply. She said she'd call me next Tuesday...
Jane is a brilliant editor ... without Walker, Alex Rider would never have seen the light of day...
...my feeling is that in some indefinable way, having a publisher raises the bar...
Publishers do, I think, provide an imprimatur, a sort of quality control... I don't like being what Apple calls "talent". I'm an author. And I write books, not "content"...
... traditional publishers have less to fear from the digital revolution than they think... For me, the digital revolution offers fantastic opportunities – if you grab hold of them."
The outline of the book I sent to Springer was -

Systems failures in regulating the Net

1. Systems

  • What's a system?
  • The internet: a complex system
  • Our system of governance and regulation

2. Systems failures

  • ICT systems failures
  • Regulatory systems failures
  • Internet regulatory failures
  • A pattern emerges: Vaughan’s normalisation of deviance

3. Decision making on Net regulations

  • Garbage cans rule: technological ignorance of policymakers
  • The shift key circumvention tool
  • Rationality drought
  • Reactionary politics: "Events, my dear boy, events"
  • Think tanks and grand plans
  • Media, politics and the criminal justice system: a case study in phone hacking
  • Benjamin Franklin v hacking
  • Money - republic lost
--->      normalisation of deviance in the institutions of regulation

4. Copyright rehashed

  • The internet and piracy as progressive taxation
  • Innovation not lawsuits
  • BT v Secretary of State for Business on the Digital Economy Act
  • BBC HD DRM saga
  • Golan v Holder - Eldred all over again?
  • EU term extension 2011
  • Google book settlement
  • ECJ SABAM v Scarlett
  • Post SABAM web filtering alive and kicking
  • SOPA and PIPA: social network activism a temporary blip?
  • The economics of copyright
  • Robert Heinlein, 1939 thought for the day

5. Crime

  • The 24 hour news cycle and politicians
  • Cybercrime
  • Something must be done. 
  • We've done something.
  • Something has been done
  • EU stupid plans to mandate web blocking
  • Cybercrime booming business in economic hard times
  • McKinnon and O'Dwyer
  • Legislate in haste, repent at leisure

6. Erosion of liberty bit by bit, byte by byte

  • Privacy a thing of the past: the nothing to hide fallacy
  • Social networks: anti privacy architectures and norms
  • Stolen phones and consequences: AMP v Person's Unknown [2011] EWHC 3454 (TCC)
  • US Supreme Court and medical privacy: Sorrell v. IMS Health Inc.
  • Teaching hospitals and the Gordian knot of medical privacy
  • No data protection on NHS Choices
  • EDPS and the data retention directive
  • R v Commissioner of Police of the Metropolis on DNA and fingerprint retention
  • Free speech and the intermediaries as choke points
  • Net neutrality and/or co-regulation
  • Great firewall of China… + UK + US + …
  • How Islamophobia has become socially acceptable
  • Wikileaks and Bradley Manning: saint or sinner
  • Search & seizure: US v Jones on GPS tracking
  • School fingerprinting and the ASCL: convenience and deviance
  • UK, the Human Rights Act and the European Court of Human Rights
  • A patent on what?! IBM, Apple, Google, Amazon, Facebook, Intel, Microsoft and Turing
  • Judge Bonello’s last stand
  • A UK bill of rights or a constitution for cyberspace?

7. End runs and trade negotiations

  • GATT, WTO, TRIPS
  • WIPO treaties
  • Cybercrime treaty
  • EU Directives
  • ACTA: transparency lost & Commissioners at war

8. Avoiding normalised deviance in regulating the Net

  • Understand the technology and science
  • Fundamental principles of social regulation apply
  • Law and cyberspace
  • ---> Sagan's Demon Haunted World: Science as a Candle in the Dark