Wednesday, May 16, 2007

Just how public should public information be?

There is a conflict between requirements that some personal information should be made public (such as the contents of electoral registers) and the data protection principle that the disclosure of personal information should be minimised. This conflict becomes acute when public files which were previously hard to access are put online. Is there a qualitative difference between personal information available on paper in a local authority office and that same information coming up as the result of a Google search? Does technology disrupt the balance between the competing interests of publicity and privacy?

This issue was dealt with in the Data Protection Commissioner's 2006 Annual Report
Local Authority: Minutes of council meetings
I received a complaint from a member of the public concerning the publication on a local authority's website of the minutes of the Council's monthly meeting. The complainant informed me that his name and address had appeared in the minutes of the meeting in the context of the sale of lands and properties under the Affordable Housing and Shared Housing Schemes. He expressed concern at the publication of his personal data in this way on a local authority website as well as the ensuing exposure of his personal data on search engines.

My Office contacted the local authority on this matter. We pointed to the important principle outlined in the Annual Report in 2003 that, even where there is legislation providing that information must be made available to the public, this may not always mean that it is appropriate to place such information on a website. On foot of my Office's intervention, the local authority took swift remedial action. It removed the document containing the personal data and edited it in such a way that all names and addresses included on it in respect of the Affordable Housing and Shared Housing Schemes were removed. The local authority also contacted one particular search engine that the complainant was concerned about and sought the deletion of the record from its cache. Finally, the Authority undertook to ensure that the website version of its minutes would, in future, be edited to prevent the disclosure of personal data.
This appears to be a sensible compromise in the individual case, but it leaves several issues open for the future. Strictly speaking, the Data Protection Acts have no application in this situation. (Section 1(4)(b) provides that "This Act does not apply to ... personal data consisting of information that the person keeping the data is required by law to make available to the public".) Consequently one might ask - if legislation requires that certain information be made public, is it appropriate that it should only be made public in a way which is particularly difficult to access? Will this create an unfair disparity in access? More sophisticated searchers will still be able to find the information they seek in person, while the general public who don't know of the availability of this information may be cut off. Should the law recognise different degrees of "publicity" in public information? Is there a parallel with developments in the European Court of Human Rights, where in cases such as Peck the Court is increasingly looking at the extent of the disclosure of personal information to see whether there has been an Article 8 violation?

For an interesting take on these issues in a US context, see Givens, Public Records on the Internet: The Privacy Dilemma.

Data Protection Commissioner 2006 Report Published

The Data Protection Commissioner has now published his 2006 Annual Report (Full text (PDF), summary).

There are several very important issues raised in that Report (including direct marketing by email, personal information which must be made public by law, and application of data protection law to the media) and I'll look at some of these in follow up posts.

Thursday, May 10, 2007

A good day to bury bad news - Labour attempts to bury spiralling cost of ID cards

BBC News:
ID card cost rises above £5bn

The official cost of the ID card scheme has risen by £400m to £5.31bn, the Home Office says.

The figure was released as Tony Blair announced his departure, leading to claims from the opposition that the government was "burying bad news".

The Tories also say that the actual rise in costs, when expressed in 2007/08 prices, is £640m.

The Home Office say that figure is 'concocted' and the increase was due to staff and anti-fraud expenditure.

Amid the row about the actual rise in the cost of the scheme, the Tories and Lib Dems also say that the Home Office broke the law by releasing the updated costings a month later than they should have.

Under the Identity Card Act, the government must give an update on the costs of the scheme twice a year. The latest update was due on 9 April.
Hopefully the fiasco of UK identity cards will deter attempts to introduce them in Ireland.

Wednesday, May 09, 2007

"Mumsnet" case shows problems with forum liability for member comments

The Telegraph reports:
The controversial childcare expert Gina Ford today dropped her threat to sue the parenting website Mumsnet after a year-long dispute was settled out of court.

Lawyers for Ms Ford, author of The Contented Little Baby Book, agreed to halt legal action after the popular website agreed to pay a contribution of her costs and prevent “personal attacks” on the site.

The agreement brings to an end a bitter dispute that began more than a year ago.

Some of Mumsnets’ 60,000 members used messageboards to attack Miss Ford’s famously rigorous childcare methods.

A sarcastic comment last August accused her of “strapping babies to rockets and firing them in to south Lebanon”.

Ms Ford, 52, a strong advocate of routine, said the remarks amounted to “serious and offensive libel” and caused her huge distress.

She began legal proceedings against the site, which receives up to 15,000 internet posts a day.

Justine Roberts, the founder of Mumsnet, in turn accused Miss Ford of conducting a “menacing” campaign to stifle negative comment, which Ms Ford strongly denied.

But after a series of legal letters and an eight-week mediation period, both parties announced today that the dispute had been settled.

The exact terms of the agreement are confidential, but it is understood that Mumsnet has apologised and made a contribution to Gina Ford’s substantial legal costs to protect its individual members from legal action.

It has also agreed to abide by its own “personal abuse” policy, preventing members from making unnecessary attacks on individuals. The ban on discussing Miss Ford’s methods has also been lifted.
Cases such as this highlight the draconian nature of English (and Irish!) libel laws, which in effect require bulletin boards and other social sites to police the actions of their users or risk being crippled by the costs (let alone the damages) of a libel action. This is difficult enough on a low-traffic site, let alone one which receives 15,000 posts a day. Quite apart from the chilling effect on freedom of expression, this also presents a competitiveness problem - why set up operations in Dublin or London when you can avail of a much more publisher friendly jurisdiction in the United States?

[Update] The Mumsnet site has now put up its own perspective on these issues:
Like many other website publishers, we have long maintained that libel law has not caught up with the digital age with the result that freedom of expression is being unacceptably curtailed. Now that we have settled our long running dispute with Gina Ford, we intend to campaign energetically for a review of how libel legislation applies to the internet.

Put crudely, the current legal situation is the rough equivalent of trying to use a set of railway signals to control the air traffic over Heathrow – the principles may be fine but different forms of communication, just like different forms of transport, require a different approach. Currently the law regards a bulletin board just as it does a newspaper or a book.

In fact the Law Commission, the body which advises the government on legislation, recognized this problem in 2002, warning that a rethink of defamation law was needed to protect freedom of speech online. At the time Hugh Beale QC, one of the law commissioners, warned: "When a website carries material to which someone objects - rightly or wrongly - it is often easier to complain to the ISP than to the author. The problem is that the law puts ISPs under pressure to remove sites as soon as they are told that the material on them may be defamatory. There is a possible conflict between the pressure to remove material, even if true, and the emphasis placed on freedom of expression by the European Convention of Human Rights."

Since then, however, no changes have been made to the law governing defamation on the internet and we believe website publishers running bulletin boards now find themselves in a similar position to that described by Mr Beale. Faced with any complaint about a bulletin board posting, website publishers, frequently small businesses or individuals with limited resources, find themselves with little choice but to remove the posting, with obvious consequences for freedom of speech.

Mumsnet has this week written to the Department of Constitutional Affairs urging the government to reconsider this area in its forthcoming consultation on defamation.

In particular we have asked to government to address these points:

1. Does holding websites liable for postings by users on their bulletin boards have the effect of unacceptably curtailing freedom of expression?
2. Is a website which swiftly removes material following a complaint protected from liability for the posting? And how swift is swift?
3. Should the different nature of bulletin board communication be taken into account in assessing whether a complainant has been defamed? For instance if a single poster makes a defamatory comment but is immediately rebutted by a large number of users should the resulting thread be considered as defamatory? Or should there be a requirement to consider bulletin board conversations in the whole?

We would stress that we accept that individuals have a right to protect their reputations. However this right always has to be balanced against the rights of others to freedom of expression. At present we believe that this balance is not struck in the right place.
The E-Commerce Directive was intended to make online business easier by removing some of these liability fears. Unfortunately, it was drafted narrowly to apply to mere conduits (telecommunications providers), caching and hosting only. This appears to leave other online intermediaries (such as search engines, bulletin boards and content aggregators) out in the cold, unless they can bring themselves within the hosting defence. Might a bulletin board be able to rely on the hosting defence in respect of user posts? I have been unable to track down any discussion of this precise issue, but Lillian Edwards analyses a related issue in respect of eBay liability for user advertisements here.

Wednesday, April 04, 2007

UK Interim data retention measures published

The Register reports that the Home Office has published draft regulations to require data retention for the interim period before the data retention directive must be implemented. As with the current Irish law this will cover details of all calls made or texts sent, and also location data in the case of mobile phones. The Home Office proposes a twelve month retention period with discretionary cost reimbursement for affected telcos.

The telescreen: coming soon to a street near you

The Telegraph reports that:
Britain is already one of the most watched nations on earth and now "talking” CCTV cameras are to be installed in 20 areas across the country.

The loudspeakers will allow CCTV operators to bark orders at people committing anti-social behaviour.
As usual, Eric Blair was well ahead of Tony Blair:
'Smith!' screamed the shrewish voice from the telescreen. '6079 Smith W.! Yes, you! Bend lower, please! You can do better than that. You're not trying. Lower, please! That's better, comrade. Now stand at ease, the whole squad, and watch me.'

Monday, April 02, 2007

Eric Blair watched by Tony Blair



This is London takes a look at the pervasive surveillance surrounding George Orwell's former home:
According to the latest studies, Britain has a staggering 4.2million CCTV cameras - one for every 14 people in the country - and 20 per cent of cameras globally. It has been calculated that each person is caught on camera an average of 300 times daily.

Use of spy cameras in modern-day Britain is now a chilling mirror image of Orwell's fictional world, created in the post-war Forties in a fourth-floor flat overlooking Canonbury Square in Islington, North London.

On the wall outside his former residence - flat number 27B - where Orwell lived until his death in 1950, an historical plaque commemorates the anti-authoritarian author. And within 200 yards of the flat, there are 32 CCTV cameras, scanning every move.

Orwell's view of the tree-filled gardens outside the flat is under 24-hour surveillance from two cameras perched on traffic lights.

The flat's rear windows are constantly viewed from two more security cameras outside a conference centre in Canonbury Place.

In a lane, just off the square, close to Orwell's favourite pub, the Compton Arms, a camera at the rear of a car dealership records every person entering or leaving the pub.

Within a 200-yard radius of the flat, there are another 28 CCTV cameras, together with hundreds of private, remote-controlled security cameras used to scrutinise visitors to homes, shops and offices.

The message is reminiscent of a 1949 poster to mark the launch of Orwell's 1984: 'Big Brother is Watching You'.

Saturday, March 31, 2007

Zooomr - Free pro photo hosting for bloggers

Zooomr are offering a free pro account to bloggers who host their images with them.

The only condition - you must host one of your blog photos with them. This is mine.

Up up and awayUp up and away Hosted on Zooomr


I'm very interested to see how Zooomr stacks up against Flickr. Unfortunately both have an annoying problem - try giving the url to somebody who isn't already familiar with the fun world of Web 2.0 naming. Chances are they'll end up at flicker.com, zoomr.com or zoomer.com - all of which are (now very valuable because of all the misdirected traffic) parked domains. In effect, Flickr and Zooomr have a self-inflicted typosquatting problem.

Wednesday, March 28, 2007

Blogger beware: Blog libel and privacy action settled for £150,000

The Guardian reports that an action by Martin Sorrell and Daniela Weber for libel and breach of privacy by way of email and blog has settled without admission of liability for a total of £150,000 - £120,000 to him, £30,000 to her. The level of the settlement (which included a nominal sum for the plaintiffs' costs) appears to reflect the plaintiffs' difficulty in linking the anonymous material to the defendants.

Background to the case:
Two former business partners of advertising boss Sir Martin Sorrell launched a "vicious" campaign against him on blogs and emails, a court heard today.

One of his former associates referred in a private email to the WPP boss as a "mad dwarf" and described the company's former chief operating officer in Italy as a "nympho schizo", the High Court in London was told.

Marco Benatti, WPP's former manager in Italy, and his lieutenant Marco Tinelli, were spurred to publish defamatory remarks after Sir Martin sacked Mr Benatti over allegations of financial irregularities at WPP's Italian business, Sir Martin's barrister said.

Opening his case at a libel and invasion of privacy trial, Desmond Browne QC said the two men had taken "countermeasures" against Sir Martin and WPP's chief operating officer in Italy, Daniela Weber. ...

The "counter-measures" against Sir Martin included a blog that appeared in March last year containing a "host of libels" against the WPP boss, Mr Browne said.

Although the blog was taken down after three days, another one appeared a month later, he said.

"The day that Sir Martin managed to get the blog taken down, Mr Benatti emailed his friends saying that blogs were like mushrooms, they sometimes pop up again the next time it rains," Mr Browne said.

"What could be a stronger pointer to Mr Benatti's knowledge of what was going on and his being the architect of the whole exercise than that email shortly after the blogs had been taken down suggested that blogs were like mushrooms?"

Mr Browne said the other "countermeasure" was a series of emails that included a "vicious Jpeg image grossly intruding into the privacy of Sir Martin and Ms Weber".

"Naturally it would be to intrude further to even start to describe them. We say Mr Tinelli was directly involved in the dissemination of that vicious image.

"There is no doubt that he felt just as bitterly towards Sir Martin and Ms Weber as did his boss, Mr Benatti. I say 'no doubt' because on the very morning of the day the images were sent out by email he referred to them as the mad dwarf and the nympho schizo."

Mr Browne said that the two men had taken "elaborate steps to cover their tracks" but that computer evidence implicated them.

Friday, March 23, 2007

Data Protection Commissioner Guidance on CCTV in the Workplace and Biometrics in Schools

The Data Protection Commissioner has given two important guidance notes on the use of cctv in business premises and the use of biometrics in schools. In both case the guidance is very protective of privacy rights.

Significantly, the biometrics guidance takes a different approach to that recently adopted in England. The English approach has been to accept that once a minor is mature enough to give an informed consent to the use of biometrics in schools, parental consent is no longer required. Under this guidance, however, parental consent will always be necessary in the case of a minor, and if the minor is aged twelve or above they must also consent:
In the context of students attending a place of education, the Data Protection Commissioner would stipulate that the obtaining of consent is of paramount importance when consideration is being given to the introduction of a biometric system. It is the Commissioner’s view that when dealing with personal data relating to minors, the standards of fairness in the obtaining and use of data, required by the Data Protection Acts, are much more onerous than when dealing with adults. Section 2A(1)(a) of the Data Protection Acts states that personal data shall not be processed by a data controller unless the data subject has given his/her consent to the processing, or if the data subject by reason of his/her physical or mental incapacity or age, is or is likely to be unable to appreciate the nature and effect of such consent, it is given by a parent or guardian etc. While the Data Protection Acts are not specific on what age a subject will be able to consent on their own behalf, it would be prudent to interpret the Acts in accordance with the Constitution. As a matter of Constitutional and family law a parent has rights and duties in relation to a child. The Commissioner considers that use of a minor’s personal data cannot be legitimate unless accompanied by the clear signed consent of the child and of the child’s parents or guardian.

As a general guide, a student aged eighteen or older should give consent themselves. A student aged from twelve up to and including seventeen should give consent themselves and, in addition, consent should also be obtained from the student’s parent or guardian. In the case of children under the age of twelve, consent of a parent or guardian will suffice. All students (and/or their parents or guardians as set out above) should, therefore, be given a clear and unambiguous right to opt out of a biometric system without penalty. Furthermore, provision must be made for the withdrawal of consent which had previously been given.
Two aspects of this guidance may be significant in the future - in requiring a double lock (both parental and child consent) is there a possibility of a knock on effect in the area of marketing to children? (Where previously the consent of a child mature enough to give an informed consent would have sufficed.) Also, in imposing a strict test for determining when the use of biometrics is proportionate or necessary in education, will there be an impact on the use of biometrics in other sectors?

The Register has a good discussion of the biometrics guidance note here. I've previously blogged about this issue here.

Thursday, March 22, 2007

Blogger beware - legal issues facing Irish bloggers

Many thanks to the IIA and Fleishman-Hillard for hosting a session on Blogging, New Media, Business and the Law. My presentation on issues such as defamation, contempt of court, copyright and privacy (ppt file) is available here and Brian Greene has podcast the event here. Tom Murphy gave a very interesting presentation on online marketing, and he's blogged about the event here.

Tuesday, February 27, 2007

Function creep in action: Mobiles may be checked after crashes

The Telegraph reports that the English government proposes to use data retention to enforce the ban on mobile phones while driving:
Motorists face having their mobile phone records checked after a routine accident, under proposals unveiled by the Government yesterday...

In the review the Department for Transport paper says: "We will look at ways to make it easier for the police to be able to follow the process of investigating whether mobile phone use was a contributory factor in an accident and thus prosecute more offenders."

According to police sources this would entail lowering the seniority of both the officer who can check the records and the threshold of the severity of the accident.

Where the use of a phone is suspected to have been a cause in the accident, it is straightforward to check when calls were received or made, irrespective of whether the call was made on a hands-free or hand-held device.

If the phone were destroyed, police would, under the proposals, be able to use call records.
Remember - data retention was sold on the basis that it was necessary to prevent terrorism and serious crime.

Data Retention in Ireland - stealth, bad faith, and contempt for the democratic process

I've written a brief article for Data Protection Law and Policy on the development of data retention in Ireland. As you'll guess from the following excerpt, I'm not impressed with the way in which it's been passed into law.
"The history of data retention law in Ireland has been marked by stealth, bad faith, and a shocking contempt for the democratic process. The 2002 Direction in particular stands out as an attempt to make law in secret, by the abuse of an unrelated statutory power, and then to stymie any judicial review by directing the recipients of the Direction to remain silent as to its existence. Moreover, when finally forced by the Data Protection Commissioner to proceed by primary legislation, the Department of Justice did so in 2005 without notice, in a way calculated to exclude any public scrutiny, and ignoring earlier assurances that draft legislation would be published and debated."
PDF of the article here.

Thursday, February 15, 2007

.ie Domain Disputes Multiply

The amusingly named I squatted your .EU mentions some recent .ie domain decisions from WIPO, including the adidas.ie, and buy-sell.ie decisions.

There have been 10 complaints lodged with WIPO under the .ie Dispute Resolution Policy to date - resulting in four decisions transferring the domain to the complainant, three complaints which were terminated before decision (presumably because the respondent decided to voluntarily relinquish the domain), and just two complaints denied. Not a bad batting average for complainants.

More filesharing litigation coming to Ireland?

Last time it was the music industry. This time Hollywood? John Collins posts:
my home phone rang this morning with a little surprise for me. it was a representative of bt who asked me to confirm that i have a broadband service with them. when i said he did, he told me they had been contacted by paramount movies (as far as i can see there is no entity of this name, but who am i to split hairs) to say i was sharing a movie of theirs, an inconvenient truth. he asked me to remove it from my pc because if they didn't they could take further action.

Tuesday, February 13, 2007

Commission to make life easier for online businesses by streamlining consumer law

From The Register:
The European Commission will overhaul European contract law to make internet selling easier, more reliable and more efficient.

The commission has opened consultation on proposed changes that will affect eight EU Directives.

Recognising that e-commerce is hampered by a mass of conflicting national laws, the commission has proposed changes to Directives which it hopes will, when transferred into national laws, bring the law into line with technological developments.

'There is an urgent need for action, the world is moving so fast and Europe risks lagging behind', said Meglena Kuneva, the new EU Commissioner for Consumer Affairs, in her first press conference in Brussels. 'We need a root and branch review of consumer rules. At the moment, consumers are not getting a fair deal online, and complex rules are holding back the next generation of bright business ideas. We must find new solutions to new challenges.'

The commission believes that online businesses would benefit significantly if doubts about the legal implications of cross-border trading were removed.

'Consumer confidence is a key factor determining how and when consumers spend their money in different sectors of the economy,' said a Commission statement. 'All the evidence is that consumers are not yet comfortable enough in the digital and online world to seize its full potential. Only a tiny fraction – six per cent of EU consumers – are currently shopping online cross border.'

The commission will review all consumer contract law, which will involve a review of eight directives. They are: the Unfair Contract Terms Directive and the Directive on Sale of Consumer Goods and Guarantees; the Distance Selling Directive; the Doorstep Selling Directive; the Package Travel Directive; the Timeshare Directive; the Directive on Injunctions; and the Price Indication Directive.
Hopefully this will also review the areas of overlap between these directives and the E-Commerce Directive.

Tuesday, January 30, 2007

NTR Deal introduces number plate surveillance

'Invisible' toll part of €600m deal to buy out West-Link bridge - Irish Independent:
It is understood that NTR will be operating the toll on behalf of the State, which will effectively become the new landlord. This will involve photographing the registration of every vehicle and billing them unless they have a prepaid arrangement... Drivers are only tolled now if they cross the West-Link bridge. Under the new deal, everyone using the M50 will be charged.
Expect this to be used to justify the roll out of number plate recognition and the monitoring of all car journeys.

Wednesday, January 17, 2007

Garda leaks and the right to privacy

RTÉ News reports:
A family who were forced to leave their new home in Kerry because of the leaking of confidential information by gardaí to journalists have been awarded €70,000 in the High Court.

Alan and Phyllis Gray and their son Francis are originally from Blanchardstown in Co Dublin but moved to Ballybunion under the Rural Resettlement Programme.

They sued the Minister for Justice for breach of privacy.

They say they had to leave their home after gardaí leaked to the media that Mr Gray's nephew, who had served a sentence for rape, was staying with them.
This case follows the 1997 decision in Hanahoe v. Hussey where gardaí tipped off the media to the fact that a solictor's office would be searched under a search warrant, leading to a "media circus" when gardaí arrived with damage to the reputation of the firm, and ultimately resulting in an award of £100,000 in damages. In that case, the basis for the decision was that the wrongful and negligent disclosure of this information amounted to negligence under the principles in Ward v. McMaster. It's not clear from the media coverage whether the decision in this case goes further, or whether data protection principles were also considered. (Compare section 7 of the Data Protection Acts, 1988-2003, creating a duty of care in respect of the handling of personal data.)

It does, however, represent an interesting application of the Hanahoe v. Hussey principle that public bodies may owe you a duty of care to keep certain information confidential. It also reflects Hanahoe v. Hussey in that it shows a judicial willingness to impose vicarious liability in respect of unauthorised garda disclosures.

Update: Eoin O'Dell links to the full decision here with an interesting discussion of the issues involved.

Wednesday, January 10, 2007

Bar Camp talk - Who owns software?

Does your employer own software that you write on your own time at home? Can a client who commissions you to write software prevent you from reusing portions of that code for a different project? Are you entitled to modify software developed for you by an outside programmer? If you don't own copyright, will you have an implied licence to use software? Will an implied licence limit you to using software in a particular market sector or a particular jurisdiction? Does it matter how much you've paid for the software? Does it matter whether you've given / been given the source code? What about databases you commission from a third party?

Come to Bar Camp South East and find out. I'll be talking on the topic of "Who owns software?" - taking a practical look at the problems of determining who owns copyright and other rights in software and giving tips as to how you can protect your position.

[edited to add] I've since published an article dealing with these topics in more detail.

Tuesday, December 12, 2006

From "the innocent have nothing to fear" files - mortgage brokers selling financial information on buyers to estate agents

Unless you've been living on Mars recently, you'll have heard of the RTÉ Prime Time exposé of dodgy dealings in the property market. Amongst other things, that program revealed that estate agents are (illegally) buying information from mortgage brokers about prospective purchasers: how much they have to spend, how much they've received in mortgage approval, how much they might have from other sources (such as parental gifts). Unsurprisingly, they are using this to extract every last penny from purchasers.

Hopefully we'll remember this the next time somebody tries to tell us that if you've done nothing wrong, you've nothing to fear.