Showing posts with label surveillance. Show all posts
Showing posts with label surveillance. Show all posts

Wednesday, April 01, 2026

Policing with drones in Ireland

 The Irish Times reports today that a Garda Drone Unit has been created for various policing purposes:

[Drones] look set to be deployed initially to pursue offenders, including those in vehicles, and for rapid dispatch to the scenes of major emergencies to provide “eye in the sky” intelligence for gardaí.

The drones are also expected to be used during major public order incidents, including riots, to record footage for identifying and prosecuting suspects.

And they could be dispatched to the scenes of planned operations, including co-ordinated searches against organised crime gangs, to provide intelligence.

The legal basis for the use of drones is the Garda Síochána (Recording Devices) Act 2023. I've written about this for the Irish Current Law Statutes Annotated - here's a short and lightly edited excerpt from that annotation on some legal issues that arise around police use of drones:

This Act provides a general basis for recording devices, very broadly defined to include any visual and sound recording devices. Recording devices in this context include hand-held devices, devices fixed to structures or vehicles (dashcams), carried by an animal, or remotely operated on an unmanned aerial vehicle (drones). 

Recording devices can be used in public places and any other place where a garda has the right to be present or is present for the performance of their functions. This includes private dwellings, subject only to the additional requirement that the occupants be notified of the use of the devices.

Where a recording device is used on a drone, there is no limitation on the places where the drone may be used or may observe. For example, this would permit a drone to be flown over a private garden, or to look into a private garden, and there is no notification requirement.

Recording devices can be used for essentially any policing purpose: for the prevention, investigation, etc. of any criminal offence – not just serious or arrestable offences – as well as for public security, public safety, and public order, state security, and execution of criminal penalties. The only limitation is that the use should be “necessary and proportionate” for a particular purpose. The Act provides examples of particular uses (for example, where “the member believes on reasonable grounds that a breach of the peace or a public order offence is occurring or may have occurred”) but these are without prejudice to the generality of the provision.

The breadth of these provisions raises concerns about the necessity and proportionality of the use of recording devices, and the ICCL has noted that these are particularly concerning in relation to the right to public assembly – especially if later paired with facial recognition technology (Irish Council for Civil Liberties, ‘Submissions on Digital Recording Bill’, accessed 2 December 2024, https://www.iccl.ie/wp-content/uploads/2022/09/210813-FINAL-ICCL-Submission-Digitial-Recording-Bill-2.pdf, p.25).

The main safeguard in relation to these devices is that their use should (as far as practicable) be overt, with body worn cameras to be visible with a visible indicator showing when they are being operated. There is no other requirement for e.g. signage to show that recording devices are being used or that a garda be in uniform when using the device.

The Act does not provide for retention periods regarding data obtained using recording devices, leaving this to the code of practice to be established under Part 8. The Act provides that data obtained using recording devices may be processed for any of the policing purposes already mentioned – leaving open the possibility of data being used for a different purpose other than the one for which it was obtained.


Friday, May 03, 2024

Irish state spyware and the law

In 2022 the European Parliament PEGA committee adopted a damning report on the use of spyware across the EU, following growing evidence of countries such as Spain, Poland, Greece and Hungary abusing spyware to spy on opposition politicians, the media, and civil society.

Ireland featured in that report, but only incidentally as the home of several spyware businesses which had set up shop in Dublin for tax advantages. Consequently the report leaves unanswered the questions of whether the Irish state is using spyware and if so what legal justifications it is using to do so.

Let's have a quick look at those questions.

There's not a lot of direct evidence here - there is no Irish law specifically governing state spyware and the state refuses to comment on its use - but I obtained an interesting document under FOI which might shed some light on this.

This is the Department of Justice's response to a questionnaire from the European Commission looking for "information from all Member States about the use of spyware by national authorities and the legal framework governing such use". (Cianan Brennan had a good summary of the response in the Examiner.)

The letter to the Commission is careful not to confirm or deny that the Garda Síochána or other state agencies agencies use spyware. In fact, it doesn't even mention the word. However, it does suggest that state agencies do. (Unsurprisingly: as far back as 2015 the Defence Forces were in discussion with Hacking Team about purchasing their products.)

Why? The key point is that the letter mentions two separate powers - interception of communications under the Interception of Postal Packets and Telecommunications Messages (Regulation) Act 1993 and use of surveillance devices under the Criminal Justice (Surveillance) Act 2009.

Neither of these individually allows state malware - the 1993 Act permits interception only, and does not give power to tamper with devices, while the 2009 Act authorises use of surveillance devices, including access to premises to plant the devices, but does not give any express power to interfere with computer systems and specifically excludes anything (such as monitoring of email traffic) that would constitute an interception under the 1993 Act. Consequently neither power on its own would permit the use of spyware.

However by referring to both powers the letter suggests that spyware is being authorised using both of these powers - possibly combining a warrant from the Minister for Justice under the 1993 Act with a District Court authorisation under the 2009 Act in some cases to provide a (shaky) legal foundation for spyware.

If so, this is a major scandal in itself. The 2009 Act was never put forward as authorising spyware and in fact it is drafted in terms which make it clear that it is intended to apply to physical surveillance tools. The key term "surveillance device" is defined as "an apparatus designed or adapted for use in surveillance" - i.e. a physical device rather than software. Judges may authorise "enter[ing] ... any place" for the purposes of surveillance, but aren't empowered to authorise hacking into a computer.

In March 2024 the Irish government signed up to the US-led Joint Statement on Efforts to Counter the Proliferation and Misuse of Commercial Spyware. That statement re-commits Ireland to the principle that "Governments should ensure transparency on the applicable general legal framework supporting the use of surveillance technologies. Governments should clearly define the legal basis for using surveillance technology with transparency on the safeguards in place to prevent abuse or discriminatory uses." It is the height of hypocrisy for the Irish government to lecture the world about transparency, when denying it at home.

Data retention in Ireland: When European law meets national recalcitrance


I've just finished writing a chapter on data retention law in Ireland for a forthcoming collection edited by Eleni Kosta and Irene Kamara. It examines how, from the judgment in Digital Rights Ireland onwards, the Irish state has fought a rearguard action against compliance with EU fundamental rights.

Abstract:

This chapter examines the development of data retention in Ireland following the CJEU judgments in Digital Rights Ireland and Tele2 Sverige. It describes how the Irish State continued to enforce national data retention law for six years after Tele2 Sverige confirmed its illegality, attempted to re-litigate the legality of indiscriminate data retention before the national courts, and reformed domestic law only when forced to act by the CJEU decision in GD v Commissioner of An Garda Síochána. It assesses how national oversight mechanisms largely failed to address this illegality and argues that the data retention saga has highlighted significant weaknesses in the criminal justice system, the ‘designated judge’ model of supervising surveillance, and the accountability of the executive to parliament.

Full text on SSRN

Monday, May 15, 2017

Oversight of phone tapping in Ireland: still inadequate

Following allegations of abuse of phone tapping by Irish police, I have an opinion piece in today's Irish Independent explaining why oversight mechanisms in this area are ineffective. Here's a flavour:
The reaction of the Department of Justice and An Garda Síochána to the latest phone-tapping scandal has been a predictable circling of the wagons. As usual, those bodies have refused to address the details of the allegations. We have seen generic statements, asserting that there is a legal basis for phone tapping and that it is subject to judicial oversight. 
The problem with that response is simple: it is clear that both the Irish law on phone tapping and the way it is implemented fail to meet fundamental international standards. 
Take the most basic starting point: who decides whether a phone tap should take place? International human rights law requires that interception of communications be authorised by a judge or an equivalent independent body. In Ireland, however, this power is given to the Justice Minister - leaving it open to allegations of political motivation. 
Irish law also falls down on the question of who can have their phones tapped. Contrary to international standards, there are no safeguards on phone tapping targeting lawyers, journalists or parliamentarians. 
Unusually for a Western democracy, Ireland does not have separate security and police agencies. Instead, both roles are combined in An Garda Síochána. The result is a blurring of the boundaries between the two functions which means that all surveillance ends up being concealed in unnecessary secrecy. 
The Irish oversight system is also out of line with international practice. In almost all EU member states, there are parliamentary committees which can oversee surveillance by security agencies. Ireland is one of only four EU states which does not make its security agency accountable to parliament. Instead, in security matters the Garda Commissioner answers only to the Justice Minister - the same person who is responsible for decisions to tap phones in the first place.
I've written more about the issue in the chapter "Judicial Oversight of Surveillance: The Case of Ireland in Comparative Perspective" (2016), full text online at the UCD research repository.


Tuesday, October 13, 2015

Law Society Annual Human Rights Conference

I spoke at the Law Society's 2015 Annual Human Rights Conference last Saturday about privacy and surveillance online in light of recent CJEU decisions - a particularly topical area following the decision in Schrems. I was joined on my panel by Karlin Lillington, the journalist whose advocacy was responsible for data retention being treated as a civil liberties issue in Ireland, and the session was chaired by Michael McDowell who as Minister for Justice was responsible for introducing data retention in Ireland in 2005 and was one of the main proponents behind data retention at a European level. As you would expect with this range of views, there was a full and interesting discussion of privacy generally and the specific area of state surveillance. Unfortunately there's no recording of the conference, but I've embedded my own slides below.



The Law Society will be making available other slides/papers from the conference - including hopefully the very interesting papers from Olivia O'Kane on privacy and the media and Judge Michael O'Reilly on prisoners' rights - and I'll link to those once they are put up.

Tuesday, June 16, 2015

Downloading or accessing certain material could constitute a criminal offence

Poster put up in London internet cafes from 2010 onwards
Background:
It's not about asking owners to spy on their customers, it's about raising awareness," a police spokesman said, speaking anonymously in line with force policy. "We don't ask them to pass on data for us."Still, he said, police were "encouraging people to check on hard drives." He did not elaborate, saying it would be up to cafe owners to decide if or how to monitor what customers left on their computers.

Tuesday, October 21, 2014

Garda body cameras: quis custodiet ipsos custodes?

Garda body worn camera - screencap from Dublin Says No protest video.
I had a piece in Saturday's Irish Independent on the implications of the new Garda body worn cameras being used at protests against water charges. There wasn't enough room in 750 words to tackle all the issues involved so here are some thoughts that didn't make it into the finished piece:

* While there is almost no transparency around the use of the cameras, for the moment it looks as though they are only being used at protests. This is a relatively straightforward case - public protests are the best case scenario for the use of cameras as situations where there is a limited privacy interest on both sides and a likelihood of confrontation - but isn't at all representative of the problems that would be faced if cameras were rolled out to ordinary policing. For example, would cameras be turned off when gardaí are in private homes? In hospitals?

* In particular, there is a real risk that the use of cameras in day to day policing will lead to a more wary relationship with the public. Will people be deterred from talking to gardaí for fear that their casual conversations may be recorded and reviewed?

* The main financial cost lies not in the cameras themselves but in the management of the recordings they generate. Video requires lots of storage and systems in place to deal with transfer of material from device to server, deletion of material once the retention period is up, flagging of particular recordings to be stored, search and retrieval of material which might be spread across a number of different stations, backups and archiving, ensuring that older file formats can still be read, responding to subject access requests, etc. Have these points have been taken into account in garda planning? Or will we end up with another case of garda tapes being stored randomly in cardboard boxes and covered in mould?

* At the moment garda management are saying very little about these new cameras. In a few months the Freedom of Information Act 2014 will be extended to An Garda Síochána - but in the meantime anyone who has been videoed at a protest can find out more by making a (free) request under s.3 of the Data Protection Acts to determine what data from the cameras are being held and the purposes for which they are being kept.

Wednesday, March 26, 2014

Recording of calls to and from Garda stations

I have a piece in today's Irish Independent on the revelation that there was widespread recording of calls to and from garda stations over a number of years. Excerpt:
The revelation that telephone calls to and from garda stations have been systematically recorded since the 1980s raises many fundamental issues for the Garda Siochana and for the wider criminal justice system.

The most grave issue is that each recording likely amounted to a serious criminal offence. Under Irish law, the recording of a telephone conversation on a public network without the consent of at least one party to the call amounts to an "interception", a criminal offence carrying a possible term of imprisonment of up to five years.

Interceptions can only be authorised by a warrant signed by the Minister for Justice, but such warrants are restricted to specific cases involving serious offences and are limited to three-month periods. There is no suggestion that any such warrant was issued in relation to this system, and it is clear that the system as a whole fell well outside the bounds of any possible warrant.

Consequently, unless gardai were notified that their calls might be recorded then a large number of criminal offences are likely to have been committed by and within the Garda Siochana itself.
Full text.

Thursday, March 20, 2014

Yahoo moves from London to Dublin; scuppers UK spies

It's surprising to see Ireland as a privacy haven, but by comparison with the UK we look good. The arrogance of the Home Office is astonishing - it genuinely appears to believe it should be able to dictate where a company runs its business so as to allow it to engage in mass surveillance.
Theresa May summoned the internet giant Yahoo for an urgent meeting on Thursday to raise security concerns after the company announced plans to move to Dublin where it is beyond the reach of Britain's surveillance laws.  By making the Irish capital rather than London the centre of its European, Middle East and Africa operations, Yahoo cannot be forced to hand over information demanded by Scotland Yard and the intelligence agencies through "warrants" issued under Britain's controversial anti-terror laws...

The home secretary called the meeting with Yahoo to express the fears of Britain's counter-terrorism investigators. They can force companies based in the UK to provide information on their servers by seeking warrants under the Regulation of Investigatory Powers Act, 2000 (Ripa).  The law, now under review by a parliamentary committee, has been widely criticised for giving police and the intelligence agencies too much access to material such as current emails and internet searches, as well as anything held on company records...

"There are concerns in the Home Office about how Ripa will apply to Yahoo once it has moved its headquarters to Dublin," said a Whitehall source. "The home secretary asked to see officials from Yahoo because in Dublin they don't have equivalent laws to Ripa. This could particularly affect investigations led by Scotland Yard and the national crime agency. They regard this as a very serious issue."

Saturday, March 08, 2014

Oliver Connolly is wrong – Sgt McCabe broke no laws with his secret recording

I have a piece in today's Irish Independent on Oliver Connolly's claim that his rights were infringed by secret recording of his comments. To put it mildly, I'm not convinced. Here's the piece with added links:

Oliver Connolly is wrong – Sgt McCabe broke no laws with his secret recording

SECRET recordings by a party to a conversation can be powerful things. When somebody does not know they are being recorded, they are more candid in their comments. They are often prepared to reveal things they would never repeat publicly. The recording then becomes important evidence to expose inconsistencies between public positions and private admissions.

Unsurprisingly, those who are recorded often feel threatened by this. A common response in many jurisdictions – not just Ireland – is to claim that secret recording is illegal or in breach of the right to privacy.

The former Garda Confidential Recipient, Oliver Connolly, has now taken that approach, asserting that his "constitutional right to privacy" was infringed and that garda whistleblower Sgt Maurice McCabe acted "in breach of confidence" by secretly recording and publishing details of a meeting with him. He has also said that politicians, by repeating excerpts under parliamentary privilege, have further violated his constitutional rights.

These, however, are not correct statements of the law. The starting point is that Irish law generally requires only "single party consent" for the recording of conversations – whether on the phone or in person.

Unlike some other countries, where legislation expressly requires that all parties should consent to a recording, in Ireland any one party can record the conversation. Other parties need not agree – or even be informed.

There are exceptions to this general rule. In some situations, data protection law imposes higher duties on businesses, employers and other "data controllers".

But those duties do not apply to information that an individual keeps only for their "personal affairs" – meaning Sgt McCabe's covert recording would not be covered by data protection rules.

Mr Connolly correctly states that Irish law recognises a constitutional right to privacy – and it is true that this right could apply to recordings if they related to his personal life. The carrying out of his public functions is quite another matter. There is no basis for saying that senior public officials enjoy a right to privacy in the way they carry out their duties. Public officials act on behalf of the people – not in any private capacity – and are open to scrutiny about what they do in our name.

In any event, the claim of privacy is misguided where a person voluntarily reveals information in the course of their duty. There can be no reasonable expectation of privacy in information that has been deliberately disclosed in this way, however much a person might later regret the disclosure.

Mr Connolly might superficially appear to have a better case as regards confidentiality. His former title – Confidential Recipient – reflects duties in the 2007 regulations establishing that role to "take all practicable steps to ensure that the identity of the confidential reporter is not disclosed".

But those duties are imposed to protect the identity of the whistleblower. They apply to the Confidential Recipient, the Garda Commissioner, the Minister for Justice and Equality, GSOC, and the Chief Inspector of the Garda Inspectorate – in short, to everyone other than the whistleblower himself. The confidentiality belongs to the whistleblower and can be waived by him.

In any event, even if a duty of confidentiality did apply, it would be defeated by a countervailing public interest that favours disclosure.

In this case, it is clear that there is such a public interest. Mr Connolly is alleged to have said: "If Shatter thinks you're screwing him, you're finished" and: "If Shatter thinks it's you, or if he thinks that it is told by the commissioner or the gardai, here's this guy again trying another route to put you under pressure, he'll go after you."

Such comments about the minister by the person designated to receive complaints of garda wrongdoing can only give rise to very significant concern. They would certainly be a matter of genuine interest and importance to the general public which would override any obligation of confidentiality.

One more law should be mentioned. Sgt McCabe is also subject to the Garda Siochana Act 2005, which prohibits disclosures of information which are "likely to have a harmful effect". But "harmful effect" is defined very narrowly by the legislation to mean only particularly serious and direct harms such as "facilitating the commission of an offence". The information revealed by Sgt McCabe would not come within the terms of this prohibition.

In short, there does not appear to be any support for Mr Connolly's claim that Sgt McCabe made an "unlawful recording". Rather than attempting to shift the focus to the actions of Sgt McCabe, Mr Connolly might do better to consider how he can help resolve the significant public concerns which have been raised by this episode.

TJ McIntyre is a lecturer in the UCD Sutherland School of Law

Friday, June 07, 2013

Quote of the day

The way things are supposed to work is that we're supposed to know virtually everything about what they do: that's why they're called public servants. They're supposed to know virtually nothing about what we do: that's why we're called private individuals.
Glenn Greenwald nails it.
 

Saturday, May 25, 2013

Will Irish courts take phone hacking seriously?

There's a remarkable story in today's Irish Independent about a woman whose criminal charges were struck out - without even a conviction - despite having been found guilty of listening to her former supervisor's voicemails. From the article:
A CIVIL servant who was found guilty of spying on her former supervisor by hacking into her mobile phone's voicemail messages has escaped punishment.

Dublin City Council employee Severine Doyle (39) had pleaded not guilty to 11 charges under the Postal and Telecommunication Act. However, following a hearing last June, she was found guilty of intercepting voice messages on a phone used by Teresa Conlon, Dublin City Council's head of housing allocation.

Dublin District Court heard that Ms Conlon's voicemail messages had been intercepted over a five-week period, from January 8 until February 11, 2010.

Doyle's sentencing had been adjourned until yesterday. Judge Eamon O'Brien told defence solicitor Declan Fahy: "I will strike it out with liberty to re-enter. I am giving her a chance, the ball is in her court."

During the trial on June 28 last year, Ms Conlon told the judge she found out that some city councillors had said they had listened to tapes of messages left on her phone.
This is an unusual outcome. The offences established carry a possible sentence of 5 years if prosecuted on indictment or 12 months otherwise. There were multiple incidents of phone hacking over an extended period. There was no guilty plea. The offences were aggravated by dissemination of the recorded material to councillors. Despite all this, the case was struck out. This may not have been a case for a custodial sentence, but I see no reason why a conviction shouldn't have been registered to mark the gravity of the offence. While there may be more to the matter than emerges from the media coverage, on the face of it this is a case where the court has failed to give adequate weight to the right to privacy in communications.

Thursday, March 21, 2013

Microsoft joins the transparency movement (with an important Irish dimension)

Kudos to Microsoft for today publishing their first annual Transparency Report setting out details of how often national police forces seek to read customer content (such as emails) or to access other information on customers. This is done as part of their commitment as a member of the Global Network Initiative and it's striking, but alas not surprising, that this makes Microsoft considerably more transparent than the Irish government which refuses to reveal even this basic statistical information.

On to the data. In 2012, in relation to Microsoft products generally (Hotmail, Outlook.com, Messenger, etc.) Gardaí sought information in 72 different requests, relating to 222 different accounts. Of these requests, 5 resulted in user content being revealed (such as the actual contents of emails), 46 resulted in non-content user information being revealed (such as the IP address last used), 19 resulted in no data being found and 2 were rejected for not meeting legal requirements.

Skype, which Microsoft now owns, was treated separately. In relation to Skype Gardaí made 4 requests relating to 7 different accounts and there was no data disclosed in relation to any of those requests. (This mostly seems to be due to no data being found but records aren't available for the entire year.). Also, in 2 cases the Skype support team provided general guidance to Gardaí regarding the procedures for accessing customer data.

There's an interesting comparison here with Google's Transparency Report. The overall numbers of requests by Gardaí to Microsoft and Google are very close (76 total for Microsoft for all of 2012; 34 for Google for the first six months of 2012). However the numbers of requests which result in information being provided are very different. In the case of Google data was provided in reply to just 2 of 34 requests (6%), while Microsoft provided data in response to 51 of 76 requests (67%). It's impossible to know without more information why that is and the low Google response rate might be just a blip for the particular six month period - nevertheless the difference is striking.

Significantly, Ireland was one of only four countries other than the US where user content was disclosed, the others being Brazil, Canada and New Zealand. The report doesn't make it clear why this is, but the FAQs imply that this may be due to Hotmail and Outlook.com accounts being hosted in Ireland and therefore being subject to local law.

The report also glosses over a question which has long interested me - what's the legal basis on which Microsoft will provide the contents of emails to Gardaí? Here's what the FAQs have to say:

What laws apply to Microsoft and Skype customer records and content? 

Irish law and European Union directives apply to the Hotmail and Outlook.com accounts hosted in Ireland...

How does Microsoft and Skype determine what law enforcement entities are able to request data? 

Microsoft must produce data in response to valid legal requests from U.S. and Irish law enforcement entities because we are headquartered in those jurisdictions or because we host data in those countries. Microsoft may disclose non-content data pursuant to a law enforcement request after it is validated locally and transmitted to our compliance teams in the U.S. and Ireland...
So - what exactly is a "valid legal request"? Irish law on interception doesn't seem to extend to webmail, suggesting that Microsoft are simply acting in response to non-statutory Garda requests rather than requiring a Ministerial warrant as would be required for telephone tapping. If so, the relevant law would be s.8 of the Data Protection Acts 1988 and 2003, which allows (but doesn't require) voluntary disclosures of user information in the context of criminal investigations. This would, however, be worrying if true as it would allow Garda access to email contents without any outside scrutiny (no Ministerial warrant or court order required) and without the other safeguards which would apply to telephone tapping - so no judicial oversight after the fact and no complaints mechanism available.

If this is the case then it would also put Ireland in breach of our obligations under Article 8 of the European Convention on Human Rights, which states that interferences with private communications must be "in accordance with the law", requiring that there should be a clear legal basis along with adequate mechanisms in place to oversee and guard against abuses of surveillance. (See in particular Klass v. Germany and Malone v. UK.)

More clarity on this point is required, and as soon as possible the law should be changed to ensure that emails enjoy the same protections as telephone calls.

Wednesday, December 19, 2012

Cloud surveillance in Ireland: coming soon to a server near you?

There's an excellent article by Peter Swire in the current International Data Privacy Law journal titled "From real-time intercepts to stored records: why encryption drives the government to seek access to the cloud". The core argument is relatively familiar though particularly well articulated - with the move away from conventional telephony and towards the use of VOIP, webmail and encrypted web connections over SSL there are growing problems for national governments in using traditional surveillance powers. Instead governments are increasingly attempting to access stored communications after the fact, where these are held in cloud services.

An important implication is that this divides up countries into "haves" (where cloud services are based and can be compelled to cooperate) and "have nots" (who will lack leverage over foreign companies). Consequently, as he puts it:
the 'have nots' become increasingly dependent, for access to communications, on cooperation from the 'have' jurisdictions... This technical possibility to respond to process leads to an important, specific split between the ‘haves’ and ‘have nots’. Some jurisdictions will have the cloud server in their jurisdiction, with relatively straightforward access to the stored records under local law. Other jurisdictions will not have such access. They will have to use a Mutual Legal Assistance Treaty (MLAT) or other mechanism to gain access to the holder of the records. These ‘have not’ jurisdictions may well face added expense and delay in gaining access to the records. In some (or perhaps many) cases they will not be able to access records that they consider important for law enforcement or national security purposes. Conversely, cloud providers and other holders of records are likely to face an increasing number of lawful access requests, from a potentially bewildering array of jurisdictions.
So what does this mean for Ireland? Think about these recent headlines: "Dropbox to establish Irish office", "Twitter ramps up hiring in Dublin", "Facebook is liking Ireland more and more". Add Google and other companies with Dublin HQs and suddenly Ireland becomes - in Swire's analysis - one of the "have" jurisdictions when it comes to internet surveillance.* Better yet, it's a jurisdiction with antiquated laws on surveillance, where oversight of police activities continues to be inadequate. Consequently we can expect both domestic and international interest in accessing the contents of these cloud services - with the added advantage that the out of date Irish law might allow the more stringent requirements of US law to be evaded in the case of providers with their main base in the US. Watch this space.

--

*There is one possible caveat - some US providers appear to be basing only e.g. sales and marketing functions here, leaving actual data hosting in the hands of a different (US) corporate entity and therefore theoretically outside the scope of the Irish authorities. It remains to be seen though whether this will be effective.

Sunday, April 08, 2012

Surveillance up, but bugs being discovered by targets

Smoke alarm claimed to have been bugged by gardaí
John Mooney and Mark Tighe have an detailed piece in today's Sunday Times arising out of the latest report of the designated judge under the Criminal Justice (Surveillance) Act 2009. Some highlights:
AN INCREASING number of requests by gardai for permission to spy on alleged criminals and terrorists are being rejected because the operations were premature, excessive or contained inadequate information. A report on the state's covert surveillance operations by Kevin Feeney, a High Court judge appointed to audit spying activities by gardai, Customs and the military, found a small increase in the number of cases where gardai were refused permission to plant eavesdropping devices and tiny cameras to spy on people suspected of involvement in paramilitary groups and organised crime.

In one case, a chief superintendent who asked to use an audio transmitter was refused permission because the surveillance was not proportionate to the identified objectives of the operation. Applications by garda officers for surveillance warrants were turned down on the basis that the premises where the device was to be located had not been confirmed as available or appropriate.

The 2009 Surveillance Act allows gardai, the Defence Forces and Revenue Commissioners to break into homes and cars to plant recording devices and tiny cameras to record private conversations. The "product" can be used as evidence in prosecutions. Permission for the surveillance, which can last up to three months, must be granted by a district court judge.

Feeney said the number of cases where gardai obtained district court authorisation to plant devices was "a small double-figure number". The number of authorisations that were declined was fewer than 10, but up on the previous year.

The report, obtained by The Sunday Times, also noted that surveillance and countersurveillance devices can be bought by the public. The judge said the availability of such equipment was brought to his attention when gardai found a device that had been installed by an unknown third party to monitor a person they were spying on. The report makes no reference to the discovery of such equipment by people being spied upon. Security sources say several devices have been detected recently...
I'll upload a copy of the latest report as soon as I have it. In the meantime, the 2009/2010 report is available here.

Friday, February 24, 2012

Self-service search warrants after Damache v. DPP

A peculiar feature of Irish law for many outside observers is the fact that search warrants are treated as being an executive rather than judicial function (PDF, ch.4). As a result a number of statutes give police the power to themselves issue such warrants on a "self-service" basis. Yesterday's Supreme Court decision in Damache v. DPP, however, cuts back the scope of these powers somewhat.

In this case Damache was suspected of involvement in a conspiracy to murder Lars Vilks, one of a number of cartoonists said to have insulted Islam by drawing Mohummad. On foot of this suspicion, a senior garda issued a search warrant in relation to his home by under s. 29(1) of the Offences Against the State Act 1939 (as inserted by s. 5 of the Criminal Law Act 1976). That section is exceptionally wide and in essence allows a senior garda to issue a search warrant in any terrorist related case in respect of any location without any special circumstances having to be shown:
Where a member of the Garda Síochána not below the rank of superintendent is satisfied that there is reasonable ground for believing that evidence of or relating to the commission or intended commission of an offence under this Act or the Criminal Law Act, 1976, or an offence which is for the time being a scheduled offence for the purposes of Part V of this Act, or evidence relating to the commission or intended commission of treason, is to be found in any building or part of a building or in any vehicle, vessel, aircraft or hovercraft or in any other place whatsoever, he may issue to a member of the Garda Síochána not below the rank of sergeant a search warrant under this section in relation to such place.
Crucially, the garda in question had been centrally involved in the investigation and there were no circumstances of urgency or time pressure in the case. Was the legislation valid insofar as it allowed a warrant to be issued in these circumstances?

Initially, the High Court held that it was. In a disappointing decision which relied on the fallacy that "modern terrorism is different" Kearns P. held that a search warrant was merely a step in the investigative process which did not have to be issued by an independent authority and that in any event the section would be justified on the basis that:
the security demands of countering international terrorism are of a quite different order to those which apply in what might be described as routine criminal offences. Serious injury and harm can be unleashed at any point in the globe by terrorists who can avail of modern technology to devastating effect. That fact was amply borne out by the attack on the World Trade Centre on 11th September, 2001, and many other terrorist acts before and since. The international terrorism of the modern age is a sophisticated, computerised and fast moving process where crucial evidence may be lost in minutes or seconds in the absence of speedy and effective action by police authorities.
On appeal, however, the Supreme Court took an entirely different approach. Building on earlier Irish authorities and applying the ECtHR decision in Camenzind v. Switzerland and the Canadian Supreme Court decision in Hunter v. Southam Inc the court devloped the principle that search warrants should generally only be issued by an independent person:
For the process in obtaining a search warrant to be meaningful, it is necessary for the person authorising the search to be able to assess the conflicting interests of the State and the individual in an impartial manner. Thus, the person should be independent of the issue and act judicially.
Applying this, the court found that the section was invalid insofar as it allowed for search warrants to be granted in respect of any location by a garda involved in the investigation without there being any special circumstances justifying a departure from this rule:
54. This case is decided on its own circumstances. These circumstances include the fact that the warrant was issued by a member of a Garda Síochána investigating team which was investigating the matters. A member of An Garda Síochána who is part of an investigating team is not independent on matters related to the investigation. In the process of obtaining a search warrant, the person authorising the search is required to be able to assess the conflicting interests of the State and the individual person, such as the appellant. In this case the person authorising the warrant was not independent. In the circumstances of this case a person issuing the search warrant should be independent of the Garda Síochána, to provide effective independence.

55. The circumstances of the appellant’s case also includes the fact that the place for which the search warrant was issued, and which was searched, was the appellant’s dwelling house. The Constitution in Article 40.5 expressly provides that the dwelling is inviolable and shall not be forcibly entered, save in accordance with law, which means without stooping to methods which ignore the fundamental norms of the legal order postulated by the Constitution. Entry into a home is at the core of potential State interference with the inviolability of the dwelling.

56. These two circumstances are at the kernel of the Court’s decision.

57. No issue of urgency arose in this case, and the Court has not considered or addressed situations of urgency.

58. The Court points out that it is best practice to keep a record of the basis upon which a search warrant is granted.

59. This Court would grant a declaration that s. 29(1) of the Offences against the State Act, 1939 (as inserted by s. 5 of the Criminal Law Act, 1976) and referred to as s. 29(1) of the Act of 1939, is repugnant to the Constitution as it permitted a search of the appellant’s home contrary to the Constitution, on foot of a warrant which was not issued by an independent person.
This is in some ways quite a narrow decision. The court placed great stress on the fact that the search related to a dwellinghouse - suggesting that powers of search relating to business premises might be treated differently. Similarly, the court noted that the decision didn't relate to cases of urgency which would seem to leave intact a number of garda powers to issue search warrants in situations where "circumstances of urgency giving rise to the need for the immediate issue of the search warrant would render it impracticable to apply to a judge of the District Court or a Peace Commissioner".

Significantly, however,  the court clearly flags a preference for search warrants to be issued judicially in future. Rather than simply requiring that a search warrant be issued by a garda who was not personally involved in the investigation, the court holds that "in the circumstances of this case a person issuing the search warrant should be independent of the Garda Síochána, to provide effective independence". This would seem to require that any power to issue search warrants in respect of the home should only be exercised by an outside authority (presumably a district court judge) except in cases of urgency.

At the very least this will force a reevaluation of garda practice in this area - and should also require reconsideration of the procedures in related areas such as GPS tracking or access to telephone and internet data where authorisations are granted internally within the Garda.

Thursday, February 23, 2012

Checking the PULSE

We've known for some time now that there's been significant abuse of the Garda PULSE database - whether this takes the form of gardaí checking up on daughters' boyfriends or more seriously information being sold to armed robbers. This abuse was one of the factors which led the Data Protection Commissioner in 2007 to adopt a Garda Code of Practice on Data Protection. While quite far-reaching, that document also dealt specifically with the PULSE database and provides:
The standard of security expected of all employees of An Garda Síochána includes the following:
* access to the information restricted to authorised staff on a "need-to- know" basis in accordance with a defined policy,
* computer systems password protected,
* information on computer screens and manual files kept hidden from callers to offices,
* back-up procedures in operation for computer held data, including off-site back-up,
* all waste papers, printouts, etc. disposed of carefully by shredding,
* all employees must log off from PULSE and other computers on each occasion when they leave the workstation,
* personal security passwords must not be disclosed to any other employee of An Garda Síochána,
* all Garda premises to be secure when unoccupied,
* a designated person will be responsible for all the above within An Garda Síochána with periodic reviews of the measures and practices in place.

Every contact on PULSE leaves a trace and every employee should be acutely aware that all activity under their registered number and password on PULSE is recorded. During an Audit or Investigation procedure they may be asked to account for the reasons they accessed a particular individual's data at any given time and what they did with it afterwards. An Garda Síochána will ensure that appropriate data protection and confidentiality clauses are in place with any processors of personal information on its behalf...

6. AUDITS OF DATA PROTECTION PROCEDURES WITHIN AN GARDA SÍOCHÁNA

To ensure the quality of data retained by An Garda Síochána, and that access to and usage of such data is appropriate within the terms of this Code, each District Officer will, as part of his/her quarterly inspection and audits in line with the Garda Commissioner's policy, examine data under the headings of Quality Control; Data Accuracy; Access to Data; and Usage of Data.

In addition to this, the Garda Professional Standards Unit will conduct examinations and reviews of Data Protection procedures as part of their ongoing examination and review process.
Unfortunately, it seems that the 2007 Code of Practice has been neglected. In particular, there has been a failure to implement the agreed monitoring of the use of the PULSE system and in his 2010 Annual Report the Data Protection Commissioner stated that:
It is disappointing to report that, despite our repeated engagements on this issue, the monitoring of access by members of An Garda Síochána to Pulse falls short of the standards we expect. We wish to see significant progress by the Gardaí in pro-actively monitoring Pulse access in 2011 and will be carrying out an audit to satisfy ourselves of this progress.
Today's Irish Times brings the story up to date, and reveals that a Garda system to monitor access to PULSE has now been put in place (four years after it was first promised) while the Data Protection Commissioner's audit will proceed in the next three months. I look forward with interest to the results - particularly if the audit goes beyond PULSE to also examine the weak controls over Garda surveillance powers which have led to at least one serious case of abuse.

Sunday, February 05, 2012

Your personal information for sale: Irish Rail edition

A Winter Commute
Today's Sunday Independent reveals that a private investigator acting for Irish Rail illegally accessed staff bank accounts, while the company also monitored staff email and placed a GPS tracking device on the car of an individual working for a contractor:
A statement issued by the Data Protection Commissioner's office this weekend said Irish Rail "acknowledged" the "unacceptable level of surveillance" on employees: "It was apparent to the investigation that one senior manager at Irish Rail authorised the surveillance and accessing of bank accounts without the knowledge or approval of management."

The investigation found "that the private bank accounts of nine employees or former employees of Irish Rail were inappropriately accessed in 2007. The bank accounts were held in four different financial institutions".

Because of the passage of time, the investigation was unable to identify "precisely how or when" employee bank accounts had been accessed. "In one case, however, the investigation did find evidence of an unsuccessful attempt by an individual by means of a telephone call to obtain bank statement information in respect of one of the bank accounts concerned," the statement said.

"The investigation was satisfied that this attempt to inappropriately access bank account information was made by an individual phoning from outside of the State."

The statement continued: "It also emerged that the individual who played the key role in accessing information from the bank accounts was operating from outside of this jurisdiction and that he is since deceased."

The investigation was also told how a GPS tracking device was fitted on the car of an employee of a contractor of Irish Rail, and the emails of 35 employees were monitored.

The investigation into the data protection breach at Irish Rail remains "open".
There's some background to the case in this earlier Sunday Independent piece.

Tuesday, July 19, 2011

The Internet of Elsewhere

I've just finished reading a review copy of Cyrus Farivar's impressive new book The Internet of Elsewhere. Like many books, it traces the development and mass takeup of the internet - unlike most, however, it is not US-centric and instead gives equal space to case studies from four countries: South Korea, Senegal, Estonia and Iran. In doing so, it provides a wealth of detail for many developments (the 2003 Iranian crackdown on bloggers, the Seoul "Dog Poop Girl", the Estonian takeup of wifi) which are often cited but seldom put into their wider social context. The author makes a particular point of describing the factors such as demographics, literacy and cost which have driven the use of the internet in each country - or, in the case of Senegal, have kept much of the population offline. A particular highlight for anyone interested in civil liberties online is the description of Iranian control of the internet, which goes back to early measures in 2000 and describes the various state tactics since then which have resulted in many prominent bloggers being forced to leave the country. The book also succeeds in being an easy read - while it is well researched and sourced it is also journalistic in its tone and describes each country through the stories of individuals. I would recommend this to anyone with an interest in the takeup of the internet and the social changes it prompts.

Friday, June 24, 2011

Irish documents on interception of communications and surveillance

I've uploaded a few documents recently which might be useful to anyone interested in issues of surveillance and interception of communications in Ireland.

First is the 2009/10 report of the Designated Judge responsible for monitoring the interception of communications and data retention:
Interception and Data Retention Annual Report 2009/10

Second is the 2009/10 report of the (different) Designated Judge responsible for monitoring covert surveillance:
Covert Surveillance Report 2009-10

Third is the Revenue manual setting out their understanding of their powers and duties in relation to covert surveillance, following the enactment of the Criminal Justice (Surveillance) Act 2009:
Revenue Surveillance Manual

(Many thanks to Mark Tighe for copies of the two judges' reports.)