Showing posts with label data retention. Show all posts
Showing posts with label data retention. Show all posts

Friday, May 03, 2024

Data retention in Ireland: When European law meets national recalcitrance


I've just finished writing a chapter on data retention law in Ireland for a forthcoming collection edited by Eleni Kosta and Irene Kamara. It examines how, from the judgment in Digital Rights Ireland onwards, the Irish state has fought a rearguard action against compliance with EU fundamental rights.

Abstract:

This chapter examines the development of data retention in Ireland following the CJEU judgments in Digital Rights Ireland and Tele2 Sverige. It describes how the Irish State continued to enforce national data retention law for six years after Tele2 Sverige confirmed its illegality, attempted to re-litigate the legality of indiscriminate data retention before the national courts, and reformed domestic law only when forced to act by the CJEU decision in GD v Commissioner of An Garda Síochána. It assesses how national oversight mechanisms largely failed to address this illegality and argues that the data retention saga has highlighted significant weaknesses in the criminal justice system, the ‘designated judge’ model of supervising surveillance, and the accountability of the executive to parliament.

Full text on SSRN

Tuesday, October 13, 2015

Law Society Annual Human Rights Conference

I spoke at the Law Society's 2015 Annual Human Rights Conference last Saturday about privacy and surveillance online in light of recent CJEU decisions - a particularly topical area following the decision in Schrems. I was joined on my panel by Karlin Lillington, the journalist whose advocacy was responsible for data retention being treated as a civil liberties issue in Ireland, and the session was chaired by Michael McDowell who as Minister for Justice was responsible for introducing data retention in Ireland in 2005 and was one of the main proponents behind data retention at a European level. As you would expect with this range of views, there was a full and interesting discussion of privacy generally and the specific area of state surveillance. Unfortunately there's no recording of the conference, but I've embedded my own slides below.



The Law Society will be making available other slides/papers from the conference - including hopefully the very interesting papers from Olivia O'Kane on privacy and the media and Judge Michael O'Reilly on prisoners' rights - and I'll link to those once they are put up.

Monday, March 30, 2015

Two data retention cases pose questions for three Ministers for Justice

Two cases have now been brought in Ireland seeking to take advantage of the Digital Rights Ireland decision from the European Court of Justice in order to exclude evidence in criminal trials. First, a case stated in the prosecution of a detective garda alleged to have given false information to GSOC; second, a challenge brought by convicted murderer Graham Dwyer - commenced in January but made public only on his conviction last week.

Given how central internet and phone evidence is to many prosecutions, the only surprise is that it's taken this long for these challenges to be brought and no doubt more will come. Unfortunately it is possible that at least some convictions will be overturned as a result - and the blame for this will lie squarely with the Department of Justice and successive ministers.

Ministers Dermot Ahern, Alan Shatter and Frances Fitzgerald in particular have questions to answer.

Dermot Ahern knew in 2011 that data retention was on very shaky ground. By then data retention laws had been struck down in Bulgaria (2008), Romania (2009) and Germany (2010) - and the Irish challenge was pending before the High Court which had decided that the case raised "important constitutional questions". At this point the Irish law should have been reformed to provide for data preservation and include adequate safeguards identified by those cases, such as a requirement for a judge to approve access to data. Instead the law adopted in 2011 was equally flawed.

Alan Shatter and Frances Fitzgerald are equally if not more at fault. It was clear from the Advocate General's opinion in December 2013 that the Data Retention Directive would be struck down. But instead of replacing the 2011 law implementing the Directive both ministers adopted the ostrich position. There has been nothing but radio silence from the Minister for Justice since the Data Retention Directive was invalidated just under a year ago. It may be that she hopes by ignoring the problem it will go away. But by doing so she is only ensuring that many more prosecutions and convictions will be put at risk. As I previously predicted, "by continuing to keep its head in the sand the State is only storing up problems for the future".

Thursday, January 22, 2015

Mobile phone records as evidence in Irish courts

Just before Christmas a murder trial collapsed when the prosecution failed to lay the correct evidential basis for admitting mobile phone records against the accused. There's no written judgment but according to media reports:
The State entered a nolle prosequi in the case after Judge Catherine Murphy ruled that telephone records held on a mainframe computer could not be relied on as evidence because there was no evidence that the computer was operating correctly at the relevant time... 
In her ruling at Dublin Circuit Criminal Court Judge Murphy said there must be evidence of the function and operation of the main frame computer, on which the call records are held. She said: “This must include information that the computer was operating correctly at the relevant time”. 
The ruling relies on a 1992 judgement from the UK appeal courts which held that the prosecution must provide evidence of the function and operation of the mainframe computer used to store the records. The Cochrane ruling, which has been upheld by the Irish courts, noted that “the problem of proving transactions of this type must now arise frequently and it should be possible… to devise a standard form of evidence to deal with it.” 
Judge Murphy had earlier ruled that the evidence of the records held on the Meteor mainframe server was not admissible under the 1992 Criminal Evidence Act because the act does not cover automatically held records. 
The evidence in this case was that the records were held, automatically, on the Meteor mainframe server. The prosecution then submitted to the Court that the records could be admitted under Common Law. Judge Murphy ruled against them on this and noted that the UK judgement states there must be evidence “that the computer was operating correctly at the relevant time”. 
The UK judgement states that the prosecution must provide “authoritative evidence about the operation of the relevant machines”. Judge Murphy noted that an engineer from Meteor gave evidence for the prosecution that he had working knowledge of the Meteor computer system but not of the mainframe computer from on the records were held.
Today it seems that another trial has collapsed on the same basis. According to the Irish Times:
The legal argument centred on whether records from mobile phone masts could be relied on to link the phones to the robbery by placing them at relevant times and places. Detectives have developed the network of phones out of a single call allegedly made from the Dublin Mountains to the Richardson family home during the kidnapping. Mrs Richardson testified that the gang had allowed her to call her husband from the mountains. In ruling on the defence application, made in the absence of the jury, Judge Ring said that none of the three mobile phone network experts called by the prosecution could say that the relevant networks were fully operational and functioning on a given day or whether any particular cell sites are out of operation on those relevant dates. She said there was evidence that calls could be routed through another mast if the nearest mast was not operational at the time or if it was busy.
The Cochrane judgment referred to in these reports is R v. Cochrane [1993] Crim LR 98, which was applied in Ireland in relation to mobile phone records by People (DPP) v. Colm Murphy [2005] IECCA 1. It's a little surprising, therefore, that admissibility has become such a contentious issue nearly a decade later. As far as I can tell from the newspaper reports, what has happened is that trial judges have become more familiar with the technology and have become more strict in insisting that the prosecution witnesses can testify to the operation of the system as a whole and not just particular components such as the masts. In the short term this is going to require prosecutors to put forward more technical witnesses from the mobile operators; longer term I wouldn't be surprised to see legislation rushed forward to provide a statutory basis for admitting these records (probably on the basis of certificate evidence).

Incidentally, this is certainly not limited to the case of mobile phone records - the same logic would apply to evidence of IP address allocation and use and other computer evidence. Expect these arguments to be played out soon in other cases involving computers.

Friday, April 11, 2014

ECJ finds data retention unacceptable in a democratic society

My preliminary thoughts on our data retention victory, in yesterday's Irish Independent:

This is a significant decision for Irish law. The Digital Rights Ireland case will now return to the High Court in Dublin which will decide whether Irish data retention law is unconstitutional in light of the European Court of Justice ruling.

It is difficult to see how the national law implementing the directive can stand up to challenge now that the directive itself has been held invalid. Consequently it is very likely that new Irish legislation will be proposed.

More generally the judgment will have fundamental implications both throughout Europe and worldwide. The decision itself is effective throughout all 28 member states and will provide greater privacy protection for over half a billion EU citizens.

It will almost certainly be followed by more cases in other member states by national civil rights groups challenging local data retention laws. It also comes at a time when data protection law throughout Europe is under review and will help to establish high standards for any new law.

Finally, this is the first major ruling on surveillance following the Edward Snowden revelations and is clearly influenced by the abuses which he exposed. The judgment will be of central importance to other cases, pending against the UK government, challenging internet surveillance by the British intelligence service GCHQ. In effect, the European Court of Justice has set out a position which directly rejects the type of indiscriminate mass surveillance carried out by the US and UK governments as being unacceptable in a democratic society.
Full text.

Friday, June 07, 2013

Quote of the day

The way things are supposed to work is that we're supposed to know virtually everything about what they do: that's why they're called public servants. They're supposed to know virtually nothing about what we do: that's why we're called private individuals.
Glenn Greenwald nails it.
 

Thursday, September 13, 2012

Hillsborough: using police databases to smear the dead

Yesterday saw the publication of the Report of the Hillsborough Independent Panel which confirmed many of the criticisms made by the families of those killed in the disaster. One of the most shocking points in that report for me was the revelation that criminal record checks were carried out on some of the dead, with a view to smearing them and deflecting criticism of police handling of the event. This illustrates an important point that privacy campaigners have been making for a long time: centralised databases of this type can and will be abused, and the power to trawl databases for information on individuals - in effect, to manufacture a case against them - is a dangerous one. It's not hard to imagine how data retention records might be abused in a similar way in future. With that in mind, here's an excerpt from the Report setting out what was done:
Criminal record checks on the deceased

2.5.111 A solicitor involved in the Hillsborough inquests disclosed a document to the Panel showing that criminal record checks were conducted selectively on some of the deceased who had recorded blood alcohol levels. To protect the privacy of the deceased the Panel has decided not to make public the document but to describe the process through which an attempt was made to establish links between blood alcohol levels and previous criminal convictions.

2.5.112 The document indicates that a Police National Computer (PNC) check was conducted on all who died at Hillsborough for whom a blood alcohol reading above zero was recorded. It includes a handwritten list of the names, dates of birth, blood alcohol readings and home addresses of 51 of the deceased and provides screen-prints apparently drawn from the PNC. A summary of the results appears on the front page, establishing the number ‘with cons’ (convictions).

2.5.113 The document was not formally part of the West Midlands or South Yorkshire Police inquiries and there is no record in the documents provided by either force or by the Coroner. There is no record of who conducted the checks or precisely when the checks occurred. The National Policing Improvement Agency, the organisation responsible for the PNC, confirmed to the Panel that information has not been retained within the PNC.

2.5.114 It is the Panel’s view that criminal record checks were carried out on those of the deceased with recorded blood alcohol levels in an attempt to impugn personal reputations. There is, however, no evidence to suggest that this inappropriate – and possibly unlawful – exercise was used in the investigations, inquiries or inquests.

Monday, November 21, 2011

Will the ECJ stymie attempts to identify internet users?

PHILIPS SHP1900 Headphones


This time last year I blogged about Bonnier Audio v. Perfect Communication, the Swedish case which questioned whether data retained under the Data Retention Directive could be used in litigation to identify users accused of infringing copyright. In that case five audiobook companies brought an action against Perfect Communication, an ISP, seeking the details of a user who was said to be sharing many popular audiobooks. The ISP, however, resisted the application and argued (in essence) that data retained under the Data Retention Directive could only be used for the purposes of that Directive and not for unrelated purposes such as civil litigation. In a preliminary reference, the Swedish court asked the ECJ the following questions:
* Whether the Data Retention Directive prevents the application of a national rule based on the EU IP Rights Enforcement Directive (2004/48/EC), which provides that an ISP in a civil case can be ordered to provide a copyright owner or a rights holder with information on which subscriber holds a specific IP address assigned by the ISP, from which address the infringement is alleged to have taken place.

* Whether the answer to the first question is affected by the fact that the state has not yet implemented the Data Retention Directive, although the deadline for implementation has passed.
As I said at the time, this has the potential to be a very important case - one in which a ruling against the copyright plaintiffs might well force a revision of the entire approach which Irish and English law takes to identifying internet users. I am surprised therefore that there hasn't yet been much reaction to the Advocate General's opinion, issued last Thursday, which comes down largely on the side of the ISP.

While there's no official English translation yet, the key part of the decision appears to be in paragraphs 60-62 which build on Promusicae to hold that (irrespective of the Data Retention Directive) the disclosure of information about internet users in civil proceedings is only permissible in accordance with the provisions of Article 15 of the e-Privacy Directive - that is, only where there are "legislative measures" in place which are "necessary, appropriate and proportionate... within a democratic society". Pending the official translation, the following is an auto-translated version, tidied up slightly by myself:
60. EU law requires that before the disclosure of personal data is possible, a retention obligation must be provided for by national legislation which sets out the categories of data to be kept, the purpose for which it may be kept, the retention period and those who can access the data. It would contradict the rules governing personal data protection principles to draw on data sets that have been collected for purposes other than those set by the legislature.

61. Therefore, for the preservation and transmission of personal data to be consistent with Article 15 of Directive 2002/58, in a situation such as that described in the main proceedings, national legislation should include, at advance and in detail, the limitations on the scope of rights and obligations under Articles 5, 6, 8, paragraphs 1 to 4, and 9 of the Directive (20). A limitation so established must be a necessary, appropriate and proportionate. However, a disclosure obligation, imposed on Internet service provider and relating to personal data kept for another purpose, is not sufficient to meet these requirements.

62. In conclusion, it should be noted that the human rights protection of personal data and privacy on the one hand, as well as protection of intellectual property on the other, shall enjoy equal protection. There is no reason to favor the owners of intellectual property rights by allowing them to use personal data that have been lawfully obtained or retained for purposes unrelated to the protection of their rights. The collection and use such data for such purposes in compliance with EU law on the protection of personal data would require the prior adoption by the national legislature, of detailed provisions, in accordance with Article 15 of Directive 2002/58. (Emphasis added.)
The Advocate General's approach, if followed by the ECJ, will undoubtedly be extremely significant on a number of fronts. From my perspective, the most significant aspect would be the requirement that identification of users requires "legislative measures". Under the existing Norwich Pharmacal jurisdiction as applied to the internet in Ireland (EMI v. Eircom) and England and Wales (Totalise v. Motley Fool) there are no such legislative measures - instead the courts are relying on an inherent equitable jurisdiction which has been developed through caselaw. This would be thrown into disarray by the Bonnier Audio reasoning. Some litigants might not be too badly affected - for example, many intellectual property litigants could fall back on their rights under the various implementations of the IPR Enforcement Directive (e.g. SI 360/2006 in Ireland) - but this result would be fatal to other cases such as online defamation claims. (One example being the current litigation against RateYourSolicitor.)

I'll be watching with interest to see whether the ECJ follows the AG's opinion - if it does, expect the cat to be put among the pigeons at national level.

Friday, June 24, 2011

Irish documents on interception of communications and surveillance

I've uploaded a few documents recently which might be useful to anyone interested in issues of surveillance and interception of communications in Ireland.

First is the 2009/10 report of the Designated Judge responsible for monitoring the interception of communications and data retention:
Interception and Data Retention Annual Report 2009/10

Second is the 2009/10 report of the (different) Designated Judge responsible for monitoring covert surveillance:
Covert Surveillance Report 2009-10

Third is the Revenue manual setting out their understanding of their powers and duties in relation to covert surveillance, following the enactment of the Criminal Justice (Surveillance) Act 2009:
Revenue Surveillance Manual

(Many thanks to Mark Tighe for copies of the two judges' reports.)

Friday, March 25, 2011

Analysis of the new Data Retention Act

Ronan Lupton (barrister and also chair of Irish telecom industry body ALTO) has written a particularly useful and well informed analysis of the impact of the new Data Retention Act on Irish law and has been kind enough to allow me to mirror it here:

Sunday, February 20, 2011

Judge's report reveals allegations that Garda used phone records to spy on her ex

Mark Tighe has an important story in today's Sunday Times about apparent abuse by a garda of the data retention system. Unfortunately it's behind a paywall, but I've taken the liberty of scanning the hardcopy and placing it here as it raises a number of fundamental questions about the safeguards which are in place against abuse and the likelihood of further abuse now that the 2011 Act has extended data retention to internet use also.
Garda accused of bugging her ex-boyfriend

Mark Tighe

A FEMALE garda suspected of obtaining the phone records of her ex-boyfriend has been reported as the first person who may have breached phone-tapping rules introduced in legislation in 1993.

The case is highlighted in a report prepared by Iarfhlaith O'Neill, a High Court judge designated to monitor the state's phone-tapping activities.

Security sources say that the case involves a garda who was stationed in the force's crime and security division, which carries out spying and intelligence services. The garda is accused of obtaining phone records of her former boyfriend to track his movements and activities after they separated. The man became suspicious and complained to gardai because his ex-girlfriend allegedly knew s details of calls he had made.

In a report to the Oireachtas earlier this month, O'Neill said that he investigated a number of alleged breaches of Section 64(2) of the Criminal Justice (Terrorist Offences) Act 2005. Under Section 64(2) no garda below the rank of chief superintendent can request an individual's phone records from a service provider to aid investigations of criminal offences.

O'Neill said: "These breaches are alleged to have been committed by a member of An Garda Siochana."

"As a result of my investigations, I was concerned that these breaches may have occurred. These alleged breaches are now the subject matter of a criminal investigation and also disciplinary proceedings under the garda disciplinary code."

O'Neill said that the extent of the alleged non-compliance with the 2005 Act had been "rigorously investigated and fully understood". He said all appropriate steps had been taken to ensure future compliance with the act.

The rest of O'Neill's report states that on November 18 last year he attended garda headquarters, then army headquarters in McKee Barracks and later the Depart¬ment of Justice offices on St Stephen's Green.

In each location he reviewed documents relating to phone tapping and phone records and spoke to people involved in the operation of the act. He said that all his queries were answered to his satisfaction.

"As a result of the forgoing, I am satisfied that there is, as of the date of this report (November 26, 2010) full compliance with the provisions of the above acts," he said.

A spokesman for the Data Protection Commissioner (DPC) said that gardai had informed it of the apparent data breach last June.

Gardai refused to comment on the case.

Gardai and the Department of Justice have refused to release details of how many requests for phone records or how many phone taps are authorised each year. They say that such information is sensitive.

The Labour party has called for a review of the powers given to gardai to access personal records and said they should only be used in exceptional circumstances.

In 2007 the DPC said that, based on audits of phone companies, it estimated gardai were making 10,000 requests for citizens' phone records each year. Security sources say the figure is now likely to be closer to 15,000 as gardai regularly seek phone records to aid investigations.

Despite its resistance to publishing details about requests to access the phone records of private citizens, Ireland may be forced to do so by a 2009 European Council directive.

The directive requires member countries to legislate to provide their data protection commissioners with the number of requests made for phone records and the legal justification invoked.
Some quick thoughts:

The references to bugging and phone-tapping are misleading - what is alleged here (as I understand it) is that the garda accessed the phone records of her ex rather than actually listened to the contents of telephone calls.

There are, unhelpfully, no details given in the report as to how the abuse came to light or what changes will be made in future to prevent further abuses. (Continuing a fine tradition of opacity.) But a number of questions spring to mind.

When did the alleged abuse take place, and how long did it take before it was uncovered? Was the abuse discovered purely by chance? Is there an adequate internal audit trail of requests which are made? If so, who is responsible for reviewing that trail? Does the designated judge access a sample of requests from the preceding year to ensure that the surveillance was appropriate? If the designated judge will not provide this level of detail in the annual report then the Minister for Justice must do so to the Oireachtas if the public are to have confidence in this system. While the particular details of this case cannot be discussed until any criminal trial is concluded, it is remarkable that there is absolutely no discussion of the systems-level controls which are (or are not) in place.

Finally, when data breach notification is finally introduced as a legal obligation (whether under the revised e-Privacy Directive or the Data Protection Commissioner's Code of Practice) will it include a right to be notified of this type of breach also? Note that the Directive appears to impose a notification obligation on telcos only.

For more background on the allegations behind this story, see this Mail on Sunday piece from last year.

Tuesday, November 09, 2010

Are Norwich Pharmacal orders compatible with the Data Retention Directive?

Interesting news from Sweden, where a court has made a preliminary reference to the ECJ which calls into question the use of information held under the Data Retention Directive to identify users accused of copyright infringement. According to a report in Intellectual Asset Management:
The request for a preliminary ruling was made by the Supreme Court in a copyright litigation case between five audiobook publishers, and Perfect Communication AB, an ISP. Before the case reached the Supreme Court, the audiobook companies had requested the district court to order Perfect Communication to reveal information regarding the name and address of the registered user of a certain IP address, who was suspected of infringing copyrights in a large number of popular audiobooks...

On 25th August 2010 the Supreme Court requested a preliminary ruling from the ECJ on two questions:

* Whether the Data Retention Directive prevents the application of a national rule based on the EU IP Rights Enforcement Directive (2004/48/EC), which provides that an ISP in a civil case can be ordered to provide a copyright owner or a rights holder with information on which subscriber holds a specific IP address assigned by the ISP, from which address the infringement is alleged to have taken place.
* Whether the answer to the first question is affected by the fact that the state has not yet implemented the Data Retention Directive, although the deadline for implementation has passed.
While the full text of the reference isn't available, the ISP's case seems to be based on the interaction between the ePrivacy Directive and the Data Retention Directive. In particular it appears to argue that data stored under the Data Retention Directive should only be made available to national authorities for the purposes of that Directive - not for other, unrelated purposes (such as civil actions against filesharing). If successful, the implications would be far reaching and would at the very least require the Irish and UK courts to revisit cases such as EMI v. Eircom which deal with Norwich Pharmacal orders identifying internet users.


(My thanks to Niall Handy for pointing out this case.)

Tuesday, September 21, 2010

Google Transparency Report launched


The New York Times has a story today about Google's new Transparency Report. The Report - which expands on an earlier initiative - tracks government intervention on the internet and shares internal data from Google in three broad categories:

* Government inquiries for information about users;
* Government requests to remove content (both hosted content and search results); and
* Traffic flows.

In each case the data is broken down by country. In relation to the UK, for example, the map shows that for the period January-June 2010 there were:

1343 data requests
48 removal requests, for a total of 232 items; and
62.5% of removal requests were fully or partially complied with

Blogger
o 1 court order to remove content
o 1 item requested to be removed

Video
o 3 court orders to remove content
o 32 items requested to be removed

Groups
o 1 court order to remove content
o 1 items requested to be removed

Web Search
o 8 court orders to remove content
o 144 items requested to be removed

YouTube
o 6 court orders to remove content
o 29 non-court order requests to remove content
o 54 items requested to be removed
There's no data given for Ireland for the same period. This may mean one of two things - either there were no Irish requests to take down information or access user information during that period, or else (probably more likely) there were so few Irish requests that Google has chosen not to reveal the statistics. For what it's worth, during the previous six month period Google indicates that there were fewer than 10 Irish government requests to remove content, of which 50% were complied with.

The traffic flow portion of the report is new and particularly interesting - by visualising the amount of data flowing to a particular country it graphically illustrates government attempts to block access to particular sites. Here, for example, is a graph of YouTube traffic to Turkey from March 2010 onwards. The abrupt drops in traffic appear to coincide with the Turkish government's ongoing attempts to block users from viewing YouTube and other Google services.

Google must be congratulated for providing this information - along with Herdict and Chilling Effects (which is also supported by Google) the information provided will be invaluable in tracking attempts to control the flow of information on the net. However, as Lilian Edwards and Christopher Soghoian have pointed out this is still only a start - greater detail as to the types of content being targeted and the legal basis for requests is necessary to make sense of the raw numbers. Perhaps in the next revision?

Tuesday, February 10, 2009

ECJ upholds Data Retention Directive

The big news of the day is that the European Court of Justice has upheld the Data Retention Directive against the challenge by the Irish Government in Ireland v. Parliament and Council where it was claimed that it was adopted on the wrong legal basis. The decision doesn't consider whether the Directive is in breach of fundamental rights, and the Digital Rights Ireland action on that basis will continue. More once I've had a chance to read the full decision.

Wednesday, February 04, 2009

ECHR expands scope of privacy rights?

OUT-LAW has details of a recent European Court of Human Rights decision which may push out the boundaries of privacy rights - in particular by finding a violation based on the taking of a photograph alone (without any publication). The facts in Reklos and Davourlis v. Greece were:
The applicants, Dimitrios Reklos and Vassiliki Davourli, are Greek nationals who were born in 1964 and 1967 respectively and live in Athens. They are the parents of Anastasios Reklos, who was born on 31 March 1997 in a private clinic. Immediately after birth, the baby was placed in a sterile unit to which only medical staff had access.

As part of the photography service offered to clients, two photographs of the new-born baby, viewed face on, were taken by a professional photographer. The parents objected to this intrusion into the sterile environment without their prior consent.

On 25 August 1997, following the clinic’s refusal to hand over the negatives of the photographs to them, the applicants brought an action for damages before the Athens Court of First Instance. The court dismissed the action as unfounded.

In September 1998 the child’s parents appealed unsuccessfully against that decision. In August 2002 they lodged an appeal on points of law, submitting that the court rulings had infringed the right “to dignity” and “to protection of private life”, and stressing the potential dangers for disabled children.

On 8 July 2004 the Court of Cassation dismissed the appeal on points of law on the ground that it was too vague. (Facts taken from the ECHR press release - judgment in English not yet available.)
The ECHR agreed with the parents, holding:
The Court reiterated that the concept of private life was a broad one which encompassed the right to identity. It stressed that a person’s image revealed his or her unique characteristics and constituted one of the chief attributes of his or her personality. The Court added that effective protection of the right to control one’s image presupposed, in the present circumstances, obtaining the consent of the person concerned when the picture was being taken and not just when it came to possible publication.

The Court observed that, since he was a minor, Anastasios’s right to protection of his image had been in the hands of his parents. Their consent had not been sought at any point, not even with regard to the keeping of the negatives, to which they objected. The Court noted that the negatives could have been used at a later date against the wishes of those concerned.

The Court concluded that the Greek courts had not taken sufficient steps to guarantee Anastasios’s right to protection of his private life, in breach of Article 8. (Emphasis added.)
The portions in bold are significant: unlike earlier caselaw on photography / CCTV (such as von Hannover v. Germany or Peck v. United Kingdom) the Court identified the taking of the photograph itself as a violation irrespective of whether it was subsequently published or otherwise made public. This is - as Rosemary Jay points out in the OUT-LAW post - consistent with the approach taken in the UK DNA Database case last December (S and Marper v. United Kingdom) where the focus was on the gathering and storage of personal information rather than its subsequent use. As such, it is potentially important for the argument that data retention is itself a violation of Article 8, whether or not any further use is made of the retained data.