EC may sue Great Britain to stop a sweeping data interception law

By Scott M. Fulton, III | Published April 14, 2009, 3:44 PM

"Do you want the Internet to turn into a jungle?" asked European Commissioner for the Information Society and Media Viviane Reding, to open her weekly English-language address this morning. "This could happen, you know, if we can't control the use of our personal information online."

Comm. Reding's message accompanied an announcement that the EC has launched the first stage in what could be a long, drawn-out series of proceedings against one of its own member nations, the United Kingdom. At issue is the UK's handling of online privacy laws, under the nearly two-year-old administration of Prime Minister Gordon Brown. The surface issue is what made news in the UK, at least in the general press: The EC has been concerned that the behavioral advertising service Phorm, a service built in association with leading UK carrier BT, may be enabling data collection policies that go beyond the limits mandated by EC directives.

But if the EC's problem was with Phorm, it could have made its complaint to BT, which hasn't been even partly state-owned since the early 1990s. No, the EC's complaint against Britain itself runs somewhat deeper than that, although this morning Comm. Reding was only willing to show the proverbial knife with the blade withdrawn. A paragraph deep down in this morning's announcement from the Brussels government shows how even the EC can bury the lede:

"Under UK law, which is enforced by the UK police, it is an offence to unlawfully intercept communications. However, the scope of this offence is limited to 'intentional' interception only," reads the EC statement. "Moreover, according to this law, interception is also considered to be lawful when the interceptor has 'reasonable grounds for believing' that consent to interception has been given. The Commission is also concerned that the UK does not have an independent national supervisory authority dealing with such interceptions."

Although the EC's concern may have been triggered by an investigation into the Phorm matter, as the announcement suggests, nothing about Phorm's behavioral advertising scheme has anything to do with government interception of private messages. British subjects will readily point out that the "interception" language more likely points to a sweeping new extension to existing law proposed last March 16 by Security and Counter-terrorism Minister Vernon Coaker, in a presentation to a key parliamentary committee. That extension is part of what was introduced last year as the Intercept Modernization Programme.

Under the UK's interpretation of the IMP, the new law would force ISPs in the UK to submit communications data regarding its users to a central database maintained by the government. As MP Coaker explains it, the IMP is necessary in order to carry out the EC's directives, which mandate that communications data regarding who speaks with whom, be kept on file for as much as two years. Coaker calls the creation of the IMP a "transposition" of EU law to the UK, as well as an extension of existing UK law regarding telephone traffic to Internet traffic.

The purpose of a centralized database, MP Coaker explained to committee, would be to cut through all the red tape: "To minimize the bureaucratic burden on businesses, particularly small businesses, we want to avoid four or five different communications service providers retaining the same data. So, in discussions with the communications service providers, we will look at who has the various data sets and we will specify through the notice who is required to retain what."

In his speech, MP Coaker suggested that the UK would only need to retain communications data for as little as 12 months. ISPs would only need to retain data in instances where they were specifically requested by government to do so, he said, although it seems impossible for a business to be able to present any data to authorities over a period of time if it had not been retaining that data to begin with.

What some ministers are concerned about is whether the law would extend to communications traffic over social networks, like MySpace or Facebook. Coaker stated that might step beyond the boundaries of the "transposition," though in this particular case, he left the door open, saying he'd welcome working with other ministers in perhaps extending the transposition in that direction.

European Commissioner for the Information Society Viviane Reding, in a weekly address April 14, 2009.Comm. Reding addressed one aspect of the social networking data problem in her address this morning: "Social networking has a strong potential for a new form of communication and for bringing people together, no matter where they are. But is every social networker really aware that technically, all pictures and information uploaded on social networking profiles can be accessed and used by anyone on the Web? Do we not cross the border of the acceptable when, for example, the pictures of the Winnenden school shooting victims in Germany are used by commercial publications just to increase sales? Privacy must in my view be a high priority for social networking providers and for their users."

But this morning's statement from the EC bolsters Reding's comments with some principles that could be used in a pre-emptive proceeding against the UK. Specifically, it alludes to the possibility that if the centralized database created through the IMP revealed something about a person "unintentionally," perhaps by tying together that person's contacts across different media, that information may be justified by law enforcement officials the same way "plain sight" information in the US is deemed admissible in court without a warrant. And if the data behind such a revelation was compiled by someone or something outside of law enforcement entirely...say, a behavioral advertising service, then authorities could give themselves plausible deniability.

"European privacy rules are crystal clear: A person's information can only be used with their prior consent," stated Comm. Reding. "We cannot give up this basic principle, and have all our exchanges monitored, surveyed and stored in exchange for a promise of 'more relevant' advertising! I will not shy away from taking action where an EU country falls short of this duty."

Today's action against the UK marks the first stage of infringement proceedings. The government has two months to respond, after which the EC may issue a formal opinion. If that opinion is challenged or let stand, a formal court case may begin in the European Court of Justice.

Comments

View comments by with a score of at least

We give the powers that be control over our lives and in turn they use these remits 'against' us. Greatly heralded technological advances blended with human trepidation and distrust of others has a certain price. Add to this the spectre of political intrigue and gain and uncertainty replaces security. This is nothing new. All civilisations have had their equivalents of this cycle and probably always will. The nature of Man is one of suspicion and doubt.

Pat Regan
Southport
Author of ‘Dirty Politics’ and other titles

Score: 0

|

Woah. The EC are actually doing something good! That makes a lovely change.
It'll be ignored anyway though.

Score: 0

|

It's good that the EU is standing up for us, but it's disheartening that they need to.

Maybe what some people see as the ultra-liberal Brussels government is just what we need in this time of government-propagated fear and wholesale surrender of civil liberties.

If it was between Westminster and Brussels, I know who I'd choose.

Score: 1

|

If the choice was between a different Westminster (pretty much anyone but Labour) I'd stick with Westminster any day. That'll definitely be the case by next summer.

Joining the EU fully would be terrible for this country.

Score: 0

|

It is most likely that large International Companies, are becoming increasingly aware that all of their Business Transmissions through the UK are at risk, and important contracts may well be in jeopardy due to interception.

There is also the fact that ‘UK’s Big Brother’ may find he has an even ‘Bigger Brother’ watching him. This surveillance and Data Collection Technology may already be being used by Counter Intelligence Services from other counties.

As already disclosed many times via the media, the Data the Government does have is very loosely guarded. Laptops left in public places, CD discs and DVD Discs left in public places.

To cap it all they still want to store more of our private and personal data. British National Security is becoming a bad joke at our expense.

Signed
Carl Barron
Chairman of agpcuk
Action Group for the Protection of Communities UK

Score: 0

|

I don't know what they taught you at school but the fact is that the UK is a 'full' member of the EU.....and in fact most of those embracing parts some seem to feel are too much were signed up to by the British conservative party, Labour's biggest treaty to date has been the so-called 'Social Chapter' which merely guaranteed British workers certain working minimum rights.

Score: 0

|

After telling US to mind its own business, Kroes slaps caps on Rambus royalties

The holder of many patents worldwide pertaining to DDR memory offered to reduce its royalty stake in that technology, and today the EU said yes.

Why Apple succeeds, and always will

The company consistently plays by different rules, literally like David did in his battle against Goliath.

EC's Kroes to US senators: Mind your own business on Oracle + Sun

UPDATED The EU's antitrust chief told the United States Senate Tuesday that any merger that takes place in the world is more her affair than theirs.

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

In a peace offering to newspapers, Google offers a new news format

It's probably not a solution to the woes of major news publishers, but Living Stories may gather a few of those publishers together in search of one.

Google Maps doesn't prevent car accidents, only search accidents

This week, Google updated Maps for Android 3.3.1, adding topography, nearby points of interest, and error reporting.

DOJ: Microsoft interop docs are now 'substantially complete'

A major milestone in the US Government's oversight of Microsoft is passed, as the Justice Dept. is now saying the company's protocol documents make sense.

The $1 DVD rental debate: LA group says Redbox will lose movie makers $1B

A report from the Los Angeles Economic Development Corporation says cheap Redbox DVD rentals could seriously damage the movie business.

First impressions of Droid: Easy, breezy, friendly, if a little fat

Though it's not quite as well-polished as Apple's iPhone OS, the version of Android that Motorola's Droid phone sports is still a breeze to use.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.