Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Wednesday, April 01, 2026

Policing with drones in Ireland

 The Irish Times reports today that a Garda Drone Unit has been created for various policing purposes:

[Drones] look set to be deployed initially to pursue offenders, including those in vehicles, and for rapid dispatch to the scenes of major emergencies to provide “eye in the sky” intelligence for gardaí.

The drones are also expected to be used during major public order incidents, including riots, to record footage for identifying and prosecuting suspects.

And they could be dispatched to the scenes of planned operations, including co-ordinated searches against organised crime gangs, to provide intelligence.

The legal basis for the use of drones is the Garda Síochána (Recording Devices) Act 2023. I've written about this for the Irish Current Law Statutes Annotated - here's a short and lightly edited excerpt from that annotation on some legal issues that arise around police use of drones:

This Act provides a general basis for recording devices, very broadly defined to include any visual and sound recording devices. Recording devices in this context include hand-held devices, devices fixed to structures or vehicles (dashcams), carried by an animal, or remotely operated on an unmanned aerial vehicle (drones). 

Recording devices can be used in public places and any other place where a garda has the right to be present or is present for the performance of their functions. This includes private dwellings, subject only to the additional requirement that the occupants be notified of the use of the devices.

Where a recording device is used on a drone, there is no limitation on the places where the drone may be used or may observe. For example, this would permit a drone to be flown over a private garden, or to look into a private garden, and there is no notification requirement.

Recording devices can be used for essentially any policing purpose: for the prevention, investigation, etc. of any criminal offence – not just serious or arrestable offences – as well as for public security, public safety, and public order, state security, and execution of criminal penalties. The only limitation is that the use should be “necessary and proportionate” for a particular purpose. The Act provides examples of particular uses (for example, where “the member believes on reasonable grounds that a breach of the peace or a public order offence is occurring or may have occurred”) but these are without prejudice to the generality of the provision.

The breadth of these provisions raises concerns about the necessity and proportionality of the use of recording devices, and the ICCL has noted that these are particularly concerning in relation to the right to public assembly – especially if later paired with facial recognition technology (Irish Council for Civil Liberties, ‘Submissions on Digital Recording Bill’, accessed 2 December 2024, https://www.iccl.ie/wp-content/uploads/2022/09/210813-FINAL-ICCL-Submission-Digitial-Recording-Bill-2.pdf, p.25).

The main safeguard in relation to these devices is that their use should (as far as practicable) be overt, with body worn cameras to be visible with a visible indicator showing when they are being operated. There is no other requirement for e.g. signage to show that recording devices are being used or that a garda be in uniform when using the device.

The Act does not provide for retention periods regarding data obtained using recording devices, leaving this to the code of practice to be established under Part 8. The Act provides that data obtained using recording devices may be processed for any of the policing purposes already mentioned – leaving open the possibility of data being used for a different purpose other than the one for which it was obtained.


Friday, March 27, 2026

Legitimate interest in practice: EDPB report on one stop shop decisions applying legitimate interest


Last year the European Data Protection Board commissioned me to write a report on legitimate interest as part of the series of One Stop Shop thematic digests and I'm delighted that this has now been published. The report surveys every publicly available OSS decision applying legitimate interest as a legal basis, finding a significant number of interesting decisions applying this concept in areas such as consumer credit, fraud prevention, and regulating user behaviour on online services. One aspect I found surprising was how legitimate interest can diverge between member states, creating what are effectively choice of law issues for supervisory authorities who must decide how far to take into account national law and social norms in different states.

The EDPB register of final OSS decisions is a valuable resource for research, teaching and practice, particularly for jurisdictions like Ireland which do not systematically publish decisions of the supervisory authorities, and I hope that the report will help to promote awareness of the register.


Friday, May 03, 2024

Irish state spyware and the law

In 2022 the European Parliament PEGA committee adopted a damning report on the use of spyware across the EU, following growing evidence of countries such as Spain, Poland, Greece and Hungary abusing spyware to spy on opposition politicians, the media, and civil society.

Ireland featured in that report, but only incidentally as the home of several spyware businesses which had set up shop in Dublin for tax advantages. Consequently the report leaves unanswered the questions of whether the Irish state is using spyware and if so what legal justifications it is using to do so.

Let's have a quick look at those questions.

There's not a lot of direct evidence here - there is no Irish law specifically governing state spyware and the state refuses to comment on its use - but I obtained an interesting document under FOI which might shed some light on this.

This is the Department of Justice's response to a questionnaire from the European Commission looking for "information from all Member States about the use of spyware by national authorities and the legal framework governing such use". (Cianan Brennan had a good summary of the response in the Examiner.)

The letter to the Commission is careful not to confirm or deny that the Garda Síochána or other state agencies agencies use spyware. In fact, it doesn't even mention the word. However, it does suggest that state agencies do. (Unsurprisingly: as far back as 2015 the Defence Forces were in discussion with Hacking Team about purchasing their products.)

Why? The key point is that the letter mentions two separate powers - interception of communications under the Interception of Postal Packets and Telecommunications Messages (Regulation) Act 1993 and use of surveillance devices under the Criminal Justice (Surveillance) Act 2009.

Neither of these individually allows state malware - the 1993 Act permits interception only, and does not give power to tamper with devices, while the 2009 Act authorises use of surveillance devices, including access to premises to plant the devices, but does not give any express power to interfere with computer systems and specifically excludes anything (such as monitoring of email traffic) that would constitute an interception under the 1993 Act. Consequently neither power on its own would permit the use of spyware.

However by referring to both powers the letter suggests that spyware is being authorised using both of these powers - possibly combining a warrant from the Minister for Justice under the 1993 Act with a District Court authorisation under the 2009 Act in some cases to provide a (shaky) legal foundation for spyware.

If so, this is a major scandal in itself. The 2009 Act was never put forward as authorising spyware and in fact it is drafted in terms which make it clear that it is intended to apply to physical surveillance tools. The key term "surveillance device" is defined as "an apparatus designed or adapted for use in surveillance" - i.e. a physical device rather than software. Judges may authorise "enter[ing] ... any place" for the purposes of surveillance, but aren't empowered to authorise hacking into a computer.

In March 2024 the Irish government signed up to the US-led Joint Statement on Efforts to Counter the Proliferation and Misuse of Commercial Spyware. That statement re-commits Ireland to the principle that "Governments should ensure transparency on the applicable general legal framework supporting the use of surveillance technologies. Governments should clearly define the legal basis for using surveillance technology with transparency on the safeguards in place to prevent abuse or discriminatory uses." It is the height of hypocrisy for the Irish government to lecture the world about transparency, when denying it at home.

Data retention in Ireland: When European law meets national recalcitrance


I've just finished writing a chapter on data retention law in Ireland for a forthcoming collection edited by Eleni Kosta and Irene Kamara. It examines how, from the judgment in Digital Rights Ireland onwards, the Irish state has fought a rearguard action against compliance with EU fundamental rights.

Abstract:

This chapter examines the development of data retention in Ireland following the CJEU judgments in Digital Rights Ireland and Tele2 Sverige. It describes how the Irish State continued to enforce national data retention law for six years after Tele2 Sverige confirmed its illegality, attempted to re-litigate the legality of indiscriminate data retention before the national courts, and reformed domestic law only when forced to act by the CJEU decision in GD v Commissioner of An Garda Síochána. It assesses how national oversight mechanisms largely failed to address this illegality and argues that the data retention saga has highlighted significant weaknesses in the criminal justice system, the ‘designated judge’ model of supervising surveillance, and the accountability of the executive to parliament.

Full text on SSRN

Friday, November 10, 2023

The "essence" of the fundamental rights to privacy and data protection in the context of state surveillance

The EDPS has just published a comprehensive study by Prof. Gloria González Fuster on the essence of the fundamental rights to privacy and to protection of personal data, and marked the publication of the study with a one day seminar on the issue earlier this week. As the event wasn't public I won't summarise what the other panellists said, though I'm sure they won't object if I refer to some of their excellent prior work either directly on the topic or touching on it (Prof. Takis TridimasProf. Cecilia RizcallahProf. Maria Grazia PorceddaProf. Kathleen Gutman; Prof. Herke Kranenborg (paywalled); Prof. Nóra Ní Loideáin; Prof. Hielke Hijmans).

For my part, I offered some practical thoughts on applying these concepts to state surveillance which I've summarised below.

To set the scene: identifying the "essence" of these fundamental rights is significant because of Article 52(1) of the Charter of Fundamental Rights which provides that "Any limitation on the exercise of the rights and freedoms recognised by this Charter must be provided for by law and respect the essence of those rights and freedoms". As the President of the CJEU, Koen Lenaerts, has explained:

Respect for the essence of fundamental rights is laid down in Article 52(1) of the Charter of Fundamental Rights of the European Union, as one of the conditions that must be fulfilled in order for a limitation on the exercise of a fundamental right to be justified. Accordingly, where an EU measure fails to take due account of the essence of a fundamental right, that measure is incompatible with the Charter and must be annulled or declared invalid. Similarly, where a national measure implementing EU law—within the meaning of Article 51(1) of the Charter—fails to respect the essence of a fundamental right, that measure is to be set aside.

While generally fundamental rights can be restricted if a limitation is a necessary and proportionate measure to achieve an objective of general interest or to protect the rights and freedoms of others, a measure which trenches on the essence of the right cannot be justified in this way. As President Lenaerts puts it:

Once it is established that the essence of a fundamental right has been compromised, the measure in question is incompatible with the Charter. This is so without it being necessary to engage in a balancing exercise of competing interests. As the Schrems I judgment shows, a measure that compromises the essence of a fundamental right is automatically disproportionate.

The caselaw on the "essence" of fundamental rights is, however, notoriously terse in its reasoning, especially in relation to state surveillance. That said, we can pick out four key findings:

First, the caselaw recognises a content/metadata distinction: In Digital Rights Ireland legislation requiring telecommunications companies to indiscriminately retain traffic and location data on all users was held not to violate the essence of the right to privacy under Article 7 of the Charter on the basis that "the directive does not permit the acquisition of knowledge of the content of the electronic communications as such". (Tele2 restates this point.) Conversely in Schrems I the CJEU held (regarding US law) that "legislation permitting the public authorities to have access on a generalised basis to the content of electronic communications must be regarded as compromising the essence of the fundamental right to respect for private life, as guaranteed by Article 7 of the Charter".

Second, it seems clear that the caselaw requires an individual legal remedy for wrongful surveillance to include deletion of illegally obtained surveillance material; in Schrems I the CJEU held that: "legislation not providing for any possibility for an individual to pursue legal remedies in order to have access to personal data relating to him, or to obtain the rectification or erasure of such data, does not respect the essence of the fundamental right to effective judicial protection, as enshrined in Article 47 of the Charter". (Schrems II makes a similar finding in relation to the Privacy Shield ombudsman mechanism without explicitly addressing the point.)

Third, the CJEU seems to have implicitly accepted that indiscriminate state access to metadata would not violate the essence of the fundamental rights to privacy and data protection: in Privacy International the Court assessed UK bulk collection of communications data on a proportionality basis without mentioning the question of whether bulk collection violated the essence of these rights.

Fourth, the caselaw accepts (in the two PNR cases) that indiscriminate state access to travel data does not in itself violate the essence of the fundamental rights to privacy and data protection, at least so long as that data is "limited to certain aspects of that private life" and does not "allow for a full overview of the private life of a person" (Opinion 1/15; Ligue des droits humains).

Overall, therefore, the notion of the essence of rights has played a limited role in relation to EU and Member State surveillance measures, and the CJEU has been unwilling to hold that even what it describes as "very far-reaching [and] particularly serious" interference with these rights (indiscriminate telecommunications data retention) constitutes an interference with the essence. While there are many cases invalidating EU/Member State surveillance measures on proportionality grounds, there are none which find that such measures violate the essence of the rights to privacy or data protection.

Why this reluctance? It may be that preserving institutional capital plays a role: a finding that a particular form of surveillance violates the essence of a right would be very difficult to walk back in the case of Member State pushback, while a finding of disproportionality is more easily finessed in future cases. The one area where the CJEU has found a surveillance tactic to violate the essence of a right - generalised state access to the contents of communications - is precisely the area which has not presented a significant clash with Member States, as their bulk interception activities have largely been shielded from scrutiny by the CJEU by the general exclusion of national security measures from the scope of EU law. Instead, direct Member State activities in this area have generally been assessed by the more lenient standards of the ECHR, under which the ECtHR has held that bulk interception is in principle compatible with Article 8 (Big Brother WatchCentrum För Rättvisa).

My sense is that this position - in which the CJEU has not had to confront wider issues around the essence of the rights to privacy and data retention, particularly in relation to bulk interception - is about to come to an end.

Multiple current controversies are set to put issues about the essence of these rights in front of national courts and ultimately the CJEU. The Encrochat and SkyECC investigations are already presenting significant issues about the legality of bulk collection of communications from all users of particular services. The proposed CSAM Regulation would mandate indiscriminate examination of all communications on particular services and is certain to be challenged on that basis. The fallout from state use of spyware such as Pegasus across Europe continues. (Indeed, the EDPS has already described such spyware as threatening the essence of the right to privacy.) The EDPB has also described growing use of widescale facial recognition in public places as likely to violate the essence of the right to data protection.

What these situations have in common (with a possible exception in relation to state spyware, depending on the exact context) is that they are certainly within the scope of EU law and therefore do not benefit from the national security cloak of invisibility. It may be that some of these cases can be dealt with solely under the Law Enforcement Directive, the e-Privacy Directive, the forthcoming AI Act, or other relevant legislative measures, but it seems inevitable that the CJEU will ultimately have to address whether these types of large scale surveillance are compatible with the "essence" of the Charter rights to privacy and data retention.

Finally, I should mention an issue about procedural approaches to identifying the essence of these rights in the context of state surveillance. Some of the caselaw (such as Digital Rights Ireland and the PNR decisions) suggests that there is no breach of the essence of the right to data protection provided that the law provides some data protection safeguards, albeit that those safeguards might not be adequate. Other judgments (particularly Schrems I and II) place particular focus on the right to effective judicial protection under Article 47 of the Charter. However it seems to me that to concentrate on procedural safeguards risks conflating assessing the essence of the right with assessing the legality of the interference with the right. Article 52(1) of the Charter already provides that limitations on rights must be "provided for by law". This closely resembles Article 8(1) ECHR which provides that restrictions on the right to privacy must be "in accordance with the law" - a formula which has been used by the ECtHR in cases from Klass v. Germany onwards to read in safeguards such as independent oversight of surveillance as essential components of legality of surveillance systems. If the legality assessment already requires some procedural safeguards, then is it redundant to treat those safeguards as also making up (part of) the essence of these rights? To put it another way, what are the additional procedural or oversight elements that comprise the essence of these rights which are not required by the principle of legality?

Thursday, June 17, 2021

Issues with the new Garda Powers Bill

I have a piece in today's Irish Times which identifies some serious concerns with the new Garda Powers Bill. Here's an excerpt:

The sensitivity of your phone means that this week’s proposal from the Department of Justice for a new Garda Síochána Powers Bill requires close scrutiny. That proposal would introduce a new power for gardaí, when carrying out search warrants, to demand your password or PIN and require you to biometrically unlock your phone (or tablet, or computer) using your fingerprint or face.

As well as taking a copy of everything on the device itself, gardaí could also use the device to access any other service you use – such as your webmail, cloud storage, or online banking – and then take a copy of that data also.

The way in which the searches would be carried out is concerning. Failure to comply with the demand there and then (with no right to consult a solicitor) would be an offence exposing you to immediate arrest, punishable by imprisonment for up to five years and a fine of up to €30,000. This power would also apply to the devices of “any person present at the place where the search is carried out”, including for example the parents or siblings of a suspect or someone who shares a house with them.

Full text

Saturday, February 08, 2020

The GAA and the GDPR

I have a piece in the Irish Times today discussing the kerfuffle about GAA clubs using WhatsApp to communicate with members. It may be the first time the phrase "dick pics" has appeared on the opinion pages of the paper of record. Here's an excerpt:
Facebook is not providing WhatsApp for philanthropic purposes, and information about who you communicate with, how and when is immensely valuable. When it bought WhatsApp, Facebook attempted to combine that information with individuals’ Facebook activity – to build up a complete picture of your activity, public and private – despite stating to the European Commission that it would not do so. Facebook was eventually stopped by data protection authorities, and in 2017 it was fined €110 million by the European Commission for its deceptive statements during the merger. 
Nevertheless, it has stated that it still aims to use WhatsApp information for Facebook advertising, and presumably will also use your WhatsApp activity for ad targeting as it rolls out advertising on WhatsApp in 2020. 
Given the commercial value of this personal information, clubs and other groups who communicate through WhatsApp are still paying for a service – it’s just that they’re shifting the cost to their members, who pay with their privacy.

Full text

Thursday, September 28, 2017

Ireland must learn from UK data protection and ID disasters

I have a piece in today's Irish Times on the approach of the Irish state to privacy. In short: there's a lot of room for improvement. Text below with added links.

Ireland must learn from UK data protection and ID disasters

The growth of the public services card as a de facto national ID card has attracted a lot of media attention recently, with special credit due to Elaine Edwards of this newspaper for her persistence in excavating the facts on which most of the later reporting has been based.

The issue continues to rumble on, and the Data Protection Commissioner has asked the Department of Social Protection to explain the legal basis for the claim that the card is mandatory. One month later, despite repeated promises, the department has not yet done so.

More could be written about the public services card, and the varying and sometimes contradictory claims put forward to support it. But if we focus on the card we risk missing the wider picture, which is that the card is not an aberration but exemplifies a systematic disregard for privacy and data protection throughout the State.

Consider the Department of Health. In a remarkable statement to the Dáil earlier this month, Minister for Health Simon Harris admitted that Ireland “remains in breach of both European Union and national data protection legislation” by keeping a database of blood samples from newborn children without the consent of their parents. Following a complaint in 2009, the Data Protection Commissioner ordered that these samples be destroyed. However, the Department of Health has failed to comply and is instead proceeding with plans to retain the database and to open it up for research and possible other uses.

This defiance of the law raises significant questions for the independence of the Data Protection Commissioner, who has taken no enforcement action against this challenge to her statutory authority. The message to the State is that it can ignore data protection law with impunity.

Since 2014, the Department of Health has also been involved in developing health identification numbers and electronic health records schemes, which present significant issues of privacy and confidentiality. For example, by requiring the use of health identification numbers these schemes tie together potentially leak-sensitive information about an individual’s medical history, despite an earlier promise that use of these numbers would be voluntary. It is hard to trust assurances from the department on this issue given that it is already, by its own admission, in deliberate breach of data protection law.

We see the same picture elsewhere.

In 2014, An Garda Síochána started using body-worn cameras in an ad hoc way, without any legislation or formal safeguards. The Garda five-year modernisation plan says that the Garda will start taking video feeds from the National Roads Authority, local authorities and private car park operators to run automatic number plate recognition systems – creating a national database of people’s travel to be stored for an unspecified period.

That plan also says that, from 2017, the Garda will start using “face-in-the-crowd and shape-in-the-crowd biometrics” to identify people on CCTV systems. Again, all of this is to take place without any legal basis, in a manner that appears to be contrary to data protection law. It seems the Garda has not learned any institutional lessons from the 2014 scandal around the recording of calls to and from Garda stations, nor from the ongoing concerns about abuse of the Pulse system.

The common pattern in these cases is that fundamental rights are viewed as inconvenient obstacles. This is a paternalistic view, in which the institution knows best and public concern can be disregarded. However, this approach merely stores up problems for the future. There are lessons for Ireland from the UK, where many of these issues have already been played out.

In 2002, the UK government launched a National Health Service-wide electronic health records system which failed to adequately address patient confidentiality. This was eventually scrapped in 2011, in large part due to concerns about privacy, and replaced with systems which guarantee that patients can opt out of data sharing. The ultimate cost was in the region of £10 billion.

The public services card has a parallel in the UK, where ID cards and a National Identity Register were introduced by legislation in 2006, only to be abandoned and the data destroyed in 2011 following extensive public opposition. Similar to the public services card, the UK ID card had no clear rationale and was ultimately rejected by the Tory/Lib Dem coalition government as “wasteful, bureaucratic and intrusive”, at an eventual cost of about £5 billion.

The increasing Garda use of CCTV, facial recognition and number-plate recognition also echoes the UK, where both the information commissioner and the independent surveillance camera commissioner have described similar practices by UK police forces as intrusive, disproportionate and illegal.

The message from these UK examples is clear. While state authorities may push ahead with plans which ignore concerns about privacy and data protection, the law will eventually catch up with them, usually at significant cost to the taxpayer. Fundamental rights are factors which must be taken into account at the outset, not reluctantly considered when a scheme is already being implemented.

As the Data Protection Commissioner put it in her most recent annual report: “Public-sector bodies and Government departments are in many cases slow to adjust to the reality that data-protection rights cannot simply be legislated away without sufficient necessity and proportionality analysis and prejudice tests being applied.”

The failure of the State to accept these points has already squandered public trust in areas such as the public services card, and seems likely to do so in other areas such as electronic health records.

Dr TJ McIntyre is a lecturer in the UCD Sutherland School of Law, a solicitor with FP Logue Solicitors and the chair of Digital Rights Ireland

Saturday, August 26, 2017

Letter regarding the Public Services Card

I'm very grateful to my colleagues who have signed a letter expressing concern at the growing use of the (supposedly optional) public services card as a mandatory requirement for essentials as passports and social welfare, creating a de facto national ID card or Ireland without public debate.

The full text of the letter and the signatories are below.

Wednesday, April 06, 2016

Search warrants and privacy in Ireland - CRH, Irish Cement & Lynch v. CCPC

The High Court gave a very important judgment yesterday (Independent.ie story) on the issues raised by the use of a search warrant to seize an entire email account where many of the emails in the account were not caught by the terms of the warrant. To grossly simplify a complicated decision, Barrett J. held that where the Competition and Consumer Protection Commission (CCPC) had seized an entire email account it was not itself entitled to carry out a "sifting" exercise to determine which emails fell within the scope of the warrant - instead, this had to be done by some impartial vetting process. In the lack of a suitable statutory mechanism, this could be done by agreement between the parties.

The full decision isn't yet on the courts.ie site, but courtesy of the CCPC I've uploaded a scanned copy to Scribd. The full decision will need careful consideration, but at first glance it's a very privacy protective decision which may have far reaching consequences in other areas of criminal procedure. Notably, it cites with approval the 2013 Canadian Supreme Court decision in R. v. Vu on the special privacy issues presented by searches of computers. (And, I'm glad to see, the Digital Rights Ireland litigation.) By requiring specificity in what is seized and how that material is then examined, it puts a question mark over other search powers - such as those under s.48 of the Criminal Justice (Theft and Fraud Offences) Act, 2001 - which are generally used so as to seize an entire computer and not merely specific records.

Tuesday, October 13, 2015

Law Society Annual Human Rights Conference

I spoke at the Law Society's 2015 Annual Human Rights Conference last Saturday about privacy and surveillance online in light of recent CJEU decisions - a particularly topical area following the decision in Schrems. I was joined on my panel by Karlin Lillington, the journalist whose advocacy was responsible for data retention being treated as a civil liberties issue in Ireland, and the session was chaired by Michael McDowell who as Minister for Justice was responsible for introducing data retention in Ireland in 2005 and was one of the main proponents behind data retention at a European level. As you would expect with this range of views, there was a full and interesting discussion of privacy generally and the specific area of state surveillance. Unfortunately there's no recording of the conference, but I've embedded my own slides below.



The Law Society will be making available other slides/papers from the conference - including hopefully the very interesting papers from Olivia O'Kane on privacy and the media and Judge Michael O'Reilly on prisoners' rights - and I'll link to those once they are put up.

Tuesday, September 15, 2015

Whitewashing your internet profile: political edition

Irish politicians are getting nervous. Although the government still insists it will serve out its full term, insiders are muttering about the possibility of a post-budget snap election. It's no coincidence, therefore, that they are now looking to clean up their online presence and two stories from this week are particularly telling.

First Alan Kinsella, of the invaluable Irish Election Literature website, tweets:

Second, an anonymous user from an Oireachtas IP address attempted a systematic (but ultimately unsuccessful) whitewashing of the Wikipedia entry for Senator Jim Walsh, deleting all reference to various gaffes by him through the years.

There's nothing new about attempts to suppress unfavourable information about Irish politicians - and the current stories are nowhere near the seriousness of the recent incident in which the aide to Derek Keating TD dumped several thousand copies of a local freesheet containing a critical story about his boss. But these examples still raise interesting issues for lawyers. In the case of the Irish Election Literature website - should politicians be able to invoke what would presumably be a copyright argument in order to conceal their past promises? In the case of Wikipedia, should edits made by TDs, Senators or their staff about themselves be disclosed? (Wikipedia certainly thinks so.) More generally, how should Irish law deal with sites such as Politwoops which archive deleted tweets from politicians? Is Twitter correct in saying that politicians should be able to delete their ill thought out tweets without that fact being highlighted - or should we accept that what politicians say is inherently newsworthy?

The Irish courts have yet to confront most of these issues - but it will be interesting to see what happens in an ongoing case brought by a Dublin election candidate who has invoked the "right to be forgotten" against online discussion of his election literature. Hopefully this will result in a judicial statement affirming the strong public interest in political discussion.

Tuesday, September 16, 2014

United States v. Microsoft (and Ireland)

I have a short piece in today's Irish Independent on the remarkable legal battle between Microsoft and US prosecutors over access to data on non-US users which is stored in Ireland, which has now resulted in a finding that Microsoft is in contempt of court.

The Irish Independent doesn't allow inline links to resources in stories, so for background here are:
In the piece I suggest that Microsoft might commit a criminal offence under Irish law if it discloses user emails without an Irish court order or other Irish law entitlement to do so. The relevant provision is section 21(2) of the Data Protection Acts which makes it an offence for any data processor to knowingly disclose personal data without the prior authority of the data controller on whose behalf the data were processed.

This does, of course, assume that Microsoft would be a data processor rather than a data controller in respect of the contents of user emails. While there is some debate as to when a cloud service operator should be treated as a data controller rather than a data processor, guidance from the Article 29 Working Party (Opinion 1/2010 on the concepts of "controller" and "processor", p.11) strongly suggests that Microsoft should be treated as a data controller only in relation to content (such as traffic data) which it generates - in relation to the emails themselves Microsoft would be treated as a data processor and would therefore be exposed to criminal liability.

Thursday, August 21, 2014

"State must be more mindful of your private data"

I've waited a while to quote Fr. Dougal McGuire in the national press, but finally got my chance in the Independent:
Last week the Irish Independent revealed further abuses of private files in the Department of Social Protection. The abuses ranged from private investigators illegally accessing personal information, to one male employee who spent up to two hours per day looking up information on women and their partners... The response of the department - that it constantly reviews its internal controls - is reminiscent of Father Dougal McGuire's promise: "As I said last time, it won't happen again".
 Full text.

Saturday, May 25, 2013

Will Irish courts take phone hacking seriously?

There's a remarkable story in today's Irish Independent about a woman whose criminal charges were struck out - without even a conviction - despite having been found guilty of listening to her former supervisor's voicemails. From the article:
A CIVIL servant who was found guilty of spying on her former supervisor by hacking into her mobile phone's voicemail messages has escaped punishment.

Dublin City Council employee Severine Doyle (39) had pleaded not guilty to 11 charges under the Postal and Telecommunication Act. However, following a hearing last June, she was found guilty of intercepting voice messages on a phone used by Teresa Conlon, Dublin City Council's head of housing allocation.

Dublin District Court heard that Ms Conlon's voicemail messages had been intercepted over a five-week period, from January 8 until February 11, 2010.

Doyle's sentencing had been adjourned until yesterday. Judge Eamon O'Brien told defence solicitor Declan Fahy: "I will strike it out with liberty to re-enter. I am giving her a chance, the ball is in her court."

During the trial on June 28 last year, Ms Conlon told the judge she found out that some city councillors had said they had listened to tapes of messages left on her phone.
This is an unusual outcome. The offences established carry a possible sentence of 5 years if prosecuted on indictment or 12 months otherwise. There were multiple incidents of phone hacking over an extended period. There was no guilty plea. The offences were aggravated by dissemination of the recorded material to councillors. Despite all this, the case was struck out. This may not have been a case for a custodial sentence, but I see no reason why a conviction shouldn't have been registered to mark the gravity of the offence. While there may be more to the matter than emerges from the media coverage, on the face of it this is a case where the court has failed to give adequate weight to the right to privacy in communications.

Thursday, May 16, 2013

Defamatory material on Facebook and YouTube: McKeogh v. Doe and others

The High Court today gave a significant decision in McKeogh v. Doe and others concerning defamatory material posted through Facebook and YouTube. The background to the case is well summarised by the Daily Mail. As I have a professional involvement I'll refrain from any comment except to explain that this is an interlocutory judgment (i.e. pending a final hearing of the action) in which Peart J. held that a mandatory injunction should be granted against Facebook and the Google defendants requiring them to take down material defaming the plaintiff until the full trial can take place. The judgment did not itself grant an injunction - instead, the details of the injunction will be determined following a meeting to take place between experts for the plaintiff and the defendants. After this meeting the experts must report back to the court with either an agreed report or separate reports regarding the technical steps which can be taken to remove the defamatory material as far as reasonably possible.

Full text of the judgment:

Thursday, March 21, 2013

Microsoft joins the transparency movement (with an important Irish dimension)

Kudos to Microsoft for today publishing their first annual Transparency Report setting out details of how often national police forces seek to read customer content (such as emails) or to access other information on customers. This is done as part of their commitment as a member of the Global Network Initiative and it's striking, but alas not surprising, that this makes Microsoft considerably more transparent than the Irish government which refuses to reveal even this basic statistical information.

On to the data. In 2012, in relation to Microsoft products generally (Hotmail, Outlook.com, Messenger, etc.) Gardaí sought information in 72 different requests, relating to 222 different accounts. Of these requests, 5 resulted in user content being revealed (such as the actual contents of emails), 46 resulted in non-content user information being revealed (such as the IP address last used), 19 resulted in no data being found and 2 were rejected for not meeting legal requirements.

Skype, which Microsoft now owns, was treated separately. In relation to Skype Gardaí made 4 requests relating to 7 different accounts and there was no data disclosed in relation to any of those requests. (This mostly seems to be due to no data being found but records aren't available for the entire year.). Also, in 2 cases the Skype support team provided general guidance to Gardaí regarding the procedures for accessing customer data.

There's an interesting comparison here with Google's Transparency Report. The overall numbers of requests by Gardaí to Microsoft and Google are very close (76 total for Microsoft for all of 2012; 34 for Google for the first six months of 2012). However the numbers of requests which result in information being provided are very different. In the case of Google data was provided in reply to just 2 of 34 requests (6%), while Microsoft provided data in response to 51 of 76 requests (67%). It's impossible to know without more information why that is and the low Google response rate might be just a blip for the particular six month period - nevertheless the difference is striking.

Significantly, Ireland was one of only four countries other than the US where user content was disclosed, the others being Brazil, Canada and New Zealand. The report doesn't make it clear why this is, but the FAQs imply that this may be due to Hotmail and Outlook.com accounts being hosted in Ireland and therefore being subject to local law.

The report also glosses over a question which has long interested me - what's the legal basis on which Microsoft will provide the contents of emails to Gardaí? Here's what the FAQs have to say:

What laws apply to Microsoft and Skype customer records and content? 

Irish law and European Union directives apply to the Hotmail and Outlook.com accounts hosted in Ireland...

How does Microsoft and Skype determine what law enforcement entities are able to request data? 

Microsoft must produce data in response to valid legal requests from U.S. and Irish law enforcement entities because we are headquartered in those jurisdictions or because we host data in those countries. Microsoft may disclose non-content data pursuant to a law enforcement request after it is validated locally and transmitted to our compliance teams in the U.S. and Ireland...
So - what exactly is a "valid legal request"? Irish law on interception doesn't seem to extend to webmail, suggesting that Microsoft are simply acting in response to non-statutory Garda requests rather than requiring a Ministerial warrant as would be required for telephone tapping. If so, the relevant law would be s.8 of the Data Protection Acts 1988 and 2003, which allows (but doesn't require) voluntary disclosures of user information in the context of criminal investigations. This would, however, be worrying if true as it would allow Garda access to email contents without any outside scrutiny (no Ministerial warrant or court order required) and without the other safeguards which would apply to telephone tapping - so no judicial oversight after the fact and no complaints mechanism available.

If this is the case then it would also put Ireland in breach of our obligations under Article 8 of the European Convention on Human Rights, which states that interferences with private communications must be "in accordance with the law", requiring that there should be a clear legal basis along with adequate mechanisms in place to oversee and guard against abuses of surveillance. (See in particular Klass v. Germany and Malone v. UK.)

More clarity on this point is required, and as soon as possible the law should be changed to ensure that emails enjoy the same protections as telephone calls.

Monday, December 03, 2012

Irish mobile phone companies: still spammy

Last year, following a complaint to the Data Protection Commissioner, I finally received an apology from Carphone Warehouse for multiple spam text messages sent to my phone. It seems that they didn't get the message then. From today's Irish Times:
Carphone Warehouse was fined €1,250 on each of two charges relating to the sending of an unsolicited email marketing messages. The court heard the company had previously been warned in relation to similar breaches, although it had no previous convictions.

Meteor was also prosecuted over the sending of an unsolicited marketing email. The customer who complained to the Data Protection Commissioner had previously gone to "some lengths" to ensure he would not be contacted by the company, the court heard. While the customer was the only one who complained, the message had been sent to between 11,000 and 18,500 people who should not have received it, the court heard. Counsel for the Data Protection Commissioner agreed that while Meteor had no previous convictions for such offences, it had previously had the benefit of the Probation Act. Judge O'Neill said that if the company paid €5,000 to Temple Street children's hospital by December 17th, he would strike out the charge. If the money was not paid by that date he would convict and impose a fine of €5,000.

Hutchison 3G, trading as Three, was prosecuted on three counts - one of sending an unsolicited email, one in relation to an unsolicited phone call, and a third in relation to an unsolicited marketing text message sent to deputy data protection commissioner Gary Davis.

Judge O'Neill asked the company to pay €2,500 to Crumlin children's hospital by December 17th. He said if such payment was made he would strike out the charge. He took two of the three charges into account.
Pro tip: if you're going to spam, try not to spam the Data Protection Commissioner's Director of Investigations.

Monday, November 26, 2012

High Court confirms standard of review in data protection appeals

The recent decision in Nowak v. Data Protection Commissioner will be essential reading for all data protection practitioners as in it the High Court finally confirms the test to be used in hearing appeals against decisions of the Data Protection Commissioner, along with providing some interesting observations regarding examination scripts as personal data and the meaning of "frivolous and vexatious" complaints to the DPC.

Under s.26 of the Data Protection Acts 1988 and 2003 there is a general right of appeal to the Circuit Court against decisions of the DPC - that section does not, however, specify the standard which the court should take in hearing appeals. In particular, it left open the question of whether an appeal should be treated as a full rehearing of the matter, an appeal on the merits, an appeal limited to a point of law, or some other approach falling short of a hearing de novo. In practice, the Circuit Court has generally followed the decision in Ulster Bank v. Financial Services Ombudsman which is deferential towards the decision maker and requires the appellant to show a serious and significant error in the decision. However, given the scarcity of written judgments at Circuit Court level and the lack of any High Court precedent the matter remained open until now.

In this case, Mr. Nowak was an unsuccessful student with Chartered Accountants Ireland (CAI) and sought access to information held by CAI including a copy of his examination script. While other information was provided to him, the examination script was withheld on the basis that it did not constitute personal data. Mr. Nowak complained to the DPC, who ultimately declined to investigate his complaint on the basis that the complaint was frivolous or vexatious.

Mr. Nowak then brought an appeal to the Circuit Court under s.26, where Judge Linnane held that the court had no jurisdiction to hear the appeal where the DPC had declined to investigate the complaint on this basis. On subsequent appeal the High Court (Birmingham J.) agreed, ruling that:

I find myself in respectful agreement with Judge Linnane that the jurisdiction of the Circuit Court is to hear an appeal against a decision that has been arrived at after there has been an investigation. I share her view that absent investigation of the complaint and a decision in relation to the investigation, that the Circuit Court has no jurisdiction. The entitlement of an aggrieved party in the first place to submit an appeal and then of the Court to hear and determine an appeal arises only where there has been a decision of the Commissioner in relation to a complaint under section 10(1)(a). However, the Commissioner reaches a decision in relation to a complaint only if, not having decided that the matter is frivolous and vexatious, he proceeds to investigate the complaint and reaches a decision in relation thereto.

More importantly, however, Birmingham J. nevertheless went on to consider the substantive issue raised by the appellant and held that:
15. Had an appeal been possible, it would then have been necessary to consider how a court should approach the hearing of an appeal from a body such as the Data Protection Commissioner. How a court should approach an appeal from a statutory body was addressed by Finnegan P. in the case of Ulster Bank v. Financial Services Ombudsman [2006] IEHC 323 (Unreported, High Court, Finnegan P., 1st November, 2006). In the course of his judgment he commented:

"To succeed on this appeal the Plaintiff must establish as a matter of probability that, taking the adjudicative process as a whole, the decision reached was vitiated by a serious and significant error or a series of such errors. In applying the test the Court will have regard to the degree of expertise and specialist knowledge of the Defendant. The deferential standard is that applied by Keane C.J. in Orange v The Director of Telecommunications Regulation & Anor and not that in The State (Keegan) v Stardust Compensation Tribunal."...

17. I am satisfied that the approach identified by Finnegan P. is the one that would have been appropriate to apply had an appeal been available. In particular, it seems to me that it would have been appropriate for the court to have regard to what Finnegan P. referred to as the deferential standard, when deciding whether to substitute its own view for that of the Data Protection Commissioner on the issue of whether an examination script constituted personal data. The Data Protection Commissioner is concerned with issues involving data protection on a daily basis. He is required to be in regular contact with his colleagues in other EU member states and is likely to be fully au fait with developments internationally. Pointing to the expertise of the Data Protection Commissioner does not mean that a court will abdicate its responsibilities and there may be cases where decisions of the Commissioner will be set aside, but if that happens, the decision to set aside the decision of the Commissioner will have been taken by a court that is conscious of the experience and expertise of the Commissioner. [Emphasis added.]
Applying this standard, Birmingham J. went on to hold that examination scripts did not, per se, amount to personal data and that the DPC was entitled to find that the examination scripts in this case did not contain personal information. He also held that the DPC was entitled to find the complaint frivolous or vexatious on the basis that:
Th[e] section refers to complaints that are frivolous or vexatious. However, I do not understand these terms to be necessarily pejorative. Frivolous, in this context does not mean only foolish or silly, but rather a complaint that was futile, or misconceived or hopeless in the sense that it was incapable of achieving the desired outcome...
The decision of the Circuit Court was therefore affirmed.

While the points raised regarding examination scripts and frivolous and vexatious complaints are significant in their own right, for me the most important part of the decision is its clear statement that the courts should be slow to set aside decisions of the DPC. The standard applied - that of a serious and significant error - sets the bar quite high for any challenges.

Thursday, September 13, 2012

Hillsborough: using police databases to smear the dead

Yesterday saw the publication of the Report of the Hillsborough Independent Panel which confirmed many of the criticisms made by the families of those killed in the disaster. One of the most shocking points in that report for me was the revelation that criminal record checks were carried out on some of the dead, with a view to smearing them and deflecting criticism of police handling of the event. This illustrates an important point that privacy campaigners have been making for a long time: centralised databases of this type can and will be abused, and the power to trawl databases for information on individuals - in effect, to manufacture a case against them - is a dangerous one. It's not hard to imagine how data retention records might be abused in a similar way in future. With that in mind, here's an excerpt from the Report setting out what was done:
Criminal record checks on the deceased

2.5.111 A solicitor involved in the Hillsborough inquests disclosed a document to the Panel showing that criminal record checks were conducted selectively on some of the deceased who had recorded blood alcohol levels. To protect the privacy of the deceased the Panel has decided not to make public the document but to describe the process through which an attempt was made to establish links between blood alcohol levels and previous criminal convictions.

2.5.112 The document indicates that a Police National Computer (PNC) check was conducted on all who died at Hillsborough for whom a blood alcohol reading above zero was recorded. It includes a handwritten list of the names, dates of birth, blood alcohol readings and home addresses of 51 of the deceased and provides screen-prints apparently drawn from the PNC. A summary of the results appears on the front page, establishing the number ‘with cons’ (convictions).

2.5.113 The document was not formally part of the West Midlands or South Yorkshire Police inquiries and there is no record in the documents provided by either force or by the Coroner. There is no record of who conducted the checks or precisely when the checks occurred. The National Policing Improvement Agency, the organisation responsible for the PNC, confirmed to the Panel that information has not been retained within the PNC.

2.5.114 It is the Panel’s view that criminal record checks were carried out on those of the deceased with recorded blood alcohol levels in an attempt to impugn personal reputations. There is, however, no evidence to suggest that this inappropriate – and possibly unlawful – exercise was used in the investigations, inquiries or inquests.