Monday, June 13, 2011

Ireland to extradite "Boards.ie hacker"?

Continuing our series of "interesting stories lost behind the Sunday Times paywall", John Mooney and Mark Tighe reveal that the DPP has directed the extradition of a Latvian man suspected of involvement in the January 2010 hacking of Boards.ie [subscription only].

According to that article:
Gardai from the force's computer crimes unit quickly traced the hacker to Latvia but it is only in recent weeks that the Director of Public Prosecutions (DPP) has ordered the suspect to be extradited. The DPP has directed that there is enough evidence to secure a conviction...

Legal sources said it may be possible for the boards.ie suspect to be charged with theft or fraud: some of the passwords obtained in the hack appear to have been used to steal money from people's Paypal accounts... The hacker is suspected of downloading a number of databases to order.
Background on the attack on Boards.ie: 1|2.

Sunday, June 12, 2011

The first Irish case on defamation via autocomplete

Another story lost behind the Sunday Times paywall last week was Mark Tighe's piece on what seems to be the first Irish case alleging defamation via Google's autocomplete system:
Hotel Fury over Google

A FAMILY-OWNED hotel in Louth is suing Google because it says the search engine giant gives web surfers the mistaken impression it is bust. The four-star Ballymascanlon House hotel, located outside Dundalk, has applied for a High Court injunction to prevent the Google search engine from suggesting it is in receivership.

Ballymascanlon is not in receivership and the Quinn family, who have run the hotel for 70 years, say it is trading successfully.

Google declined to comment on the legal action.

When search engine users type the first seven letters of the hotel's name into Google, the website's automatic prompting service, Google Instant, throws up the suggestion "Ballymascanlon hotel receivership".

The hotel, one of the most popular wedding venues in the northeast, says it has been contacted by brides who had booked weddings there and were "in tears" after seeing the Google prompt.
Mark Collier has an excellent post setting out the background to this case and more details, from which I've borrowed the following image showing the offending search terms:

This isn't the first time Google has been sued over autocomplete suggestions - it recently lost similar cases in France and Italy - and the case raises a fundamental issue as to whether Google should be treated as responsible for the suggestions which it claims merely reflect the most popular user queries. Undoubtedly (if the case makes it to trial) Google will rely heavily on the recent English judgment in Metropolitan International Schools v. Designtechnica, in which it was found not to be the publisher of defamatory snippets in search results on the basis that:
When a snippet is thrown up on the user's screen in response to his search, it points him in the direction of an entry somewhere on the web that corresponds, to a greater or lesser extent, to the search terms he has typed in ... it is for him to access or not, as he chooses. [Google] has merely, by the provision of its search service, played the role of a facilitator.
In this case, however, it may be that Google will face difficulties in running that defence. Looking at both Metropolitan International Schools and the recent Italian judgment, three factors seem likely to be important. First, unlike the case of search results, autocomplete suggestions do not merely reflect what is elsewhere on the web but are created by Google (albeit by algorithm). Second, as Google actively censors the autocomplete system it makes it harder to argue that there is no "human input" into the results - a factor which was critical in Metropolitan International Schools. Third (although the judgment isn't entirely clear on this point) the court in Metropolitan International Schools found it signficant that Google could not block all searches against particular terms without also blocking a great deal of unrelated material. In this case, however, it would seem quite simple to remove a particular autocomplete result for this hotel, ruling out any argument based on practicability or collateral damage.

Incidentally, I see from the High Court search that the action is listed as QUINN [SENIOR] & ORS -V- GOOGLE IRELAND LIMITED 2011/4784 P. I was surprised to see Google Ireland named as a defendant, as I understand that Google's search functions are run by Google Inc., California - a distinction which tripped up the Red Cross in their action seeking to identify a blogger hosted on Google's blogspot. In that case the Red Cross eventually had to seek the permission of the court to substitute Google Inc. as the defendant, and I'll be interested to see whether this happens in this case also.

Saturday, June 11, 2011

Data Protection Commissioner investigating Eircom's "three strikes" system

Between the bank holiday weekend and the Sunday Times paywall Mark Tighe's story last week revealing that the Data Protection Commissioner is investigating the Eircom / IRMA three strikes system didn't receive the attention it deserved. However the investigation has the potential to entirely derail the system and needs to be considered further.

First, the background. I'm disappointed but not surprised to find that my 2009 prediction - that Eircom would end up falsely accusing innocent users - has come to pass in relation to 300 users:
THE "three strikes" scheme to prevent music piracy, which is operated by Eircom at the behest of record companies, is being investigated by the data protection commissioner (DPC) after customers said they were sent warning letters in error. The investigation began after an Eircom customer complained that he had wrongly received a "first strike" letter. The company has admitted it incorrectly issued such warnings to a "limited number" of customers.
So why did Eircom falsely accuse users?
This was due to a software failure caused when the clocks went back last October, it said.
Far from being a technical sounding "software failure", this appears to show up ineptitude in relation to a very basic aspect of network management - i.e. making sure that the server clock reflects daylight savings time. As a result, it seems that users found themselves being accused on the basis of what somebody else did from the same IP address either an hour earlier or an hour later. Consequently, the users who were wrongfully accused should consider themselves lucky that this incompetence did not lead to their being accused of a serious crime - for example, being arrested and having their homes searched due to the wrong time being used (as happened to these Indian users).

The significance of this case goes beyond simple technical failings, however, as the complaint to the Data Protection Commissioner has triggered a wider investigation of the legality of the entire three strikes system:
The DPC said it was investigating the complaint "including whether the subject matter gives rise to any questions as to the proportionality of the graduated response system operated by Eircom and the music industry".
This is unsurprising - when the Eircom / IRMA three strikes settlement was being agreed the Data Protection Commissioner identified significant data protection problems with it. These problems remain, notwithstanding the deeply flawed High Court judgment which approved of the system - a judgment which, for example, decided on the question of whether or not IP addresses are personal data without once considering the views of the Article 29 Working Party. It is not surprising that the Data Protection Commissioner was not convinced by that judgment (the judgment was problematic at least in part because the Commissioner was not represented - the only parties before the court had a vested interest in the system being implemented). However, until a concrete complaint arose no further action could be taken.

The complaint in this case has now triggered that action, and it seems likely that the Commissioner will reach a decision reflecting his previous views that using IP addresses to cut off customers' internet connections is disproportionate and does not constitute "fair use" of personal information. If so, the Commissioner has the power and indeed the duty to issue an enforcement notice which would prevent Eircom from using personal data for this purpose - which would ultimately seem likely to put the matter back before the courts. Watch this space.

Saturday, May 14, 2011

Impact of the Criminal Justice Bill on the investigation of cybercrime

The Minister for Justice yesterday published the Criminal Justice Bill 2011 (pdf) which is primarily aimed at white collar crime and unsurprisingly aims to facilitate the investigation of banking and financial crimes in particular (press release | Irish Times). It will, however, also have a significant impact on the investigation and prosecution of cybercrime.

Under section 3, the Bill applies to “relevant offences” which, as set out in Schedule 2, includes the offence of dishonest use of a computer. In addition, the Bill allows the Minister to add crimes to the list of "relevant offences" including "criminal acts involving the use of electronic communications networks and information systems or against such networks or systems or both". Consequently, assuming the Minister uses this power, the majority of computer crimes are likely to be subject to the provisions of this Bill.

As summarised in the press release, the key parts of the Bill are:
• A new system to make more effective use of detention periods. This will allow persons arrested and detained for questioning by the Gardaí to be released and their detention suspended so that further investigations can be conducted during the suspension period.

• New powers for the Garda Síochána to apply to court for an order to require any person with relevant information to produce documents, answer questions and provide information for the purposes of the investigation of relevant offences. Failure to comply with such an order will be an offence.

• Measures relating to how documents are to be produced to the Gardaí. These measures are aimed at reducing the delays associated with the production of large volumes of poorly ordered and uncategorised documents to the Gardaí in the course of their investigations.

• Measures to prevent unnecessary delays in investigations arising from claims of legal privilege.

• The creation of a new offence, similar to the former misprision of felony offence, which relates to the failure to report information to the Gardaí.
Also, though not mentioned in the press release, s.18 of the Bill will make the admission of documentary and electronic evidence in criminal trials significantly easier by establishing new presumptions regarding the creation, ownership and receipt of documents.

These provisions would dramatically change the rules governing the investigation and prosecution of computer crime in Ireland. Take two examples. The proposed offence of failing to report information would create a positive duty to report computer crimes to the Gardaí - with failure to do so carrying a term of imprisonment of up to five years. One wonders whether this is workable and what effect it might have on the work of computer security researchers. Similarly, the new power to order the production of documents includes a requirement that such documents be provided in decrypted form or that a password be provided (s.15(6)), which appears to address the gap in the law revealed by the encrypted Anglo Irish Bank files.

This is certainly one to watch for anyone with an interest in cybercrime in Ireland, and I'll be coming back to it as it progresses through the Oireachtas.

Thursday, May 12, 2011

ALAI comes to Dublin

There's a very good IPR conference coming up in Dublin shortly as the Association littéraire et artistique internationale will hold its bi-annual Study Days on the 30th June and 1st July, hosted by the Copyright Association of Ireland. Readers of this blog may be particularly interested to see that speakers include the president of HADOPI, solicitor Helen Sheehy (who has represented the Plaintiffs in all Irish filesharing litigation) and Judge Peter Charleton (who heard both the Eircom and UPC filesharing cases). Full details at www.alaidublin2011.org.

Monday, April 11, 2011

The curious case of internet filtering in Ireland

[Reblogged from the new website MediaLaws.eu, where I will be contributing updates from Ireland.]

One of the most important developments for freedom of expression online has been the growth of internet filtering systems, which have rapidly been adopted by national governments as the “solution” to various forms of internet wrongdoing. Ireland is no exception to this trend, and last month it was revealed that the Garda Síochána (the national police force) is now attempting to introduce a system whereby ISPs would block access to websites alleged to host child abuse images.

It is somewhat ironic that this news becomes public just as both Germany and the Netherlands have decided to abandon similar systems, having found that they are ineffective as a means of tackling child abuse images. Even leaving aside considerations of effectiveness, however, the proposed Irish system still presents a number of significant concerns.

A fundamental principle under Article 10 of the European Convention on Human Rights is that measures which have the effect of restricting freedom of expression must be “prescribed by law”. In this case, however, the Irish system would not have any legal basis whatsoever, much less any judicial oversight or control. Instead, it would involve the police in telling ISPs what domains to block on a “self-regulatory” basis. Consequently, it would seem on the face of it that the proposed system would violate Article 10. The European Commission recently reached the same conclusion about self-regulatory blocking systems (p.30) as did a government study which was decisive in causing the Dutch blocking system to be abandoned.

A further problem relates to the secret manner in which the government and the police have attempted to introduce this system. There has been no public consultation or debate of any kind regarding blocking – instead, information has only dripped out in response to freedom of information requests and leaks from ISPs. This is particularly worrying given that (as Lessig points out) internet filtering is an inherently opaque process, which is prone to operating in an unaccountable way and to being extended beyond its original purposes. In the Irish context, the secrecy surrounding the introduction of filtering doesn’t bode well for the future.

The nature of the proposed blocking is also worrying. What Irish police have suggested is based on the CIRCAMP model, which attempts to block material by using DNS tampering. In short, the police would notify ISPs to block http://example.com or http://subdomain.example.com and the ISP would then configure their DNS servers to redirect all attempts to visit any material hosted on those (sub)domains. The effect would be massive overblocking, where users would be unable to visit any page hosted on a particular domain, irrespective of whether it had any connection whatsoever with the blocked material. Last February, a similar approach in the United States saw over 84,000 innocent websites being wrongfully blocked, and there is no reason to think that the Irish approach would be any more precise.

Finally, one particularly unusual aspect of the proposals is the way in which police seek to introduce monitoring of users. According to the proposals, where a user attempts to view a blocked domain name, police would “obtain details of other websites visited by the user, along with other technical details, in order that [they] can identify any new websites that require blocking”. This in effect seeks the full browsing history of users – whether or not there has been any attempt on their part to view child pornography! (Bearing in mind that DNS tampering results in massive overblocking, it is quite likely that a user may have their browsing history disclosed due to an attempt to visit http://example.com/innocent_content when the entirety of example.com has been blocked due to a single image or page elsewhere in the site.) This raises fundamental privacy and data protection concerns, particularly given that a user can often be identified by viewing their browsing history (e.g.), and has therefore been referred to the Data Protection Commissioner for investigation.

Given these problems, it must be hoped that these proposals are abandoned. But quite apart from these particular proposals, it is now also time to look at the other systems of internet filtering in Ireland that have developed on an ad hoc basis. In particular, Irish mobile phone companies have been engaged in self-regulatory blocking for some time (1|2), in a manner which often affects innocent users due to crude DNS systems. Similarly, the largest Irish broadband provider Eircom recently settled an action brought by the music industry by (amongst other things) agreeing to block access to The Pirate Bay and “related domain names”. These systems have developed without any real public scrutiny or oversight and it is time to consider the effect which they have on users, whether they are subject to adequate transparency and oversight mechanisms and whether or not they are effective at achieving their goals.

Thursday, April 07, 2011

Data breach law in Ireland - the current state of play

I had a very interesting morning at McCann Fitzgerald who were kind enough to invite me in to give a legal update on data breaches - here's a copy of the handout I provided:Lessons from laptop loss: Legal consequences where organisations lose personal data

Saturday, April 02, 2011

Irish Press Council now taking online only sites as members

The Press Council published its annual report for 2010 yesterday. It details some interesting cases (1|2) involving reporting which reuses material from social networking sites and blogs, but more importantly for Irish websites the launch also revealed that the Press Council is now taking online only media as members.

From the Irish Times:
With the increase in news gathering and reporting increasing on the internet, chairman of the Press Council Daithí Ó Ceallaigh said web-based organisations or publications could benefit by joining its independent regulatory regime.

“When this happens – and at least one new web-based organisation has already been accepted as one of the recent new members of the council – we are ready to play a positive role in light of our own experience in support of the highest possible journalistic standards.”
This is a significant development. Membership of the Press Council and adherence to its Code of Practice offers periodicals a significant benefit in establishing a defence of fair and reasonable publication on a matter of public interest. The narrow definition of "periodical" in the Defamation Act 2009, however, created doubt as to whether an online-only publication would qualify for membership.

Eoin O'Dell took the view that it wouldn't (a view which I shared) though the last Minister for Justice later took a contrary view, claiming that:
The question of whether publications existing "on-line" only, either now or in the future, wish to come under the umbrella of the Press Council - and abide by its code of practice - is a matter for those publications. Nothing in the Defamation Act precludes this. Neither have I noticed any express limitation of jurisdiction in the Articles of Association of the Press Council on membership by on-line publications. Some recent commentary from media experts seems to have missed this point.
The Press Council itself has now clearly taken the position that online-only periodicals are eligible for membership, which will certainly cause a number of Irish websites to consider joining.

One note of caution, however: it will ultimately be for a court to determine whether an online-only site is a "periodical" for the purposes of the defence of fair and reasonable publication. The views of the Press Council on this point will be relevant but certainly not conclusive.

Monday, March 28, 2011

Consultation on implementation of Telecoms Reform Package

There are just a few days left if you wish to comment on the Department of Communications proposals for implementation of the Telecoms Reform Package.

While there's quite a lot contained in the five sets of proposed regulations, the portions of most interest to me are the proposals regarding the revised E-Privacy Directive (.doc) which will implement a requirement for data breach notification along with new rules regarding cookies.

Curiously enough, there hasn't been much public debate in Ireland about the impact of the new rules regarding cookies - unlike the UK, where a similar implementation (which essentially copies and pastes text directly from the Directive) has been particularly controversial. This may be because the proposed Irish text is more business friendly in explicitly stating that browser settings can be used to show that users consent to cookies. However, it's still not entirely clear from the draft regulations whether this means that the technically unsavvy user will be taken to have consented where they fail to adjust their browser settings from what is (usually) the default "accept all cookies" option. (The Article 29 Working Party, for example, have taken the view that failure to adjust default settings does not amount to an affirmative consent.)

Update: The Department has now confirmed that it has extended the deadline for submissions to 15 April.

Friday, March 25, 2011

Analysis of the new Data Retention Act

Ronan Lupton (barrister and also chair of Irish telecom industry body ALTO) has written a particularly useful and well informed analysis of the impact of the new Data Retention Act on Irish law and has been kind enough to allow me to mirror it here:

The Internet in Society: Empowering or Censoring Citizens?

This video by RSA Animate is a superb visualisation of Evgeny Morozov's recent book The Net Delusion on cyber-utopianism and the impact of the internet on fundamental freedoms. While I don't agree with his overall conclusions, his cyber-realist argument is certainly a welcome corrective to a media tendency to believe in technological determinism and the inevitable spread of freedom via Facebook. His pessimistic views on the crowd-sourcing of surveillance and censorship are particularly insightful and present an interesting challenge for advocates of free speech online.

Monday, March 07, 2011

Impact of the Programme for Government

Daithi MacSithigh has written an excellent post on the new Programme for Government and what it means for technology law and policy in Ireland. There are some particularly interesting commitments on broadband, fair use and cloud computing, while filesharing gets a mention but without any detail as to what the new government plans to do.

Friday, February 25, 2011

Subject access requests up by 25% as employees seek to see HR files

Elaine Edwards has an interesting report from the Irish Computer Society Annual Data Protection Conference:
THE NUMBER of complaints from people seeking access to personal information held on them increased last year due to the economic downturn, with many people concerned about potential or actual dismissal from their jobs.

Data Protection Commissioner Billy Hawkes said yesterday the top item for complaints to his office in 2010 was about failure to respond adequately to requests for access to personal data.

Individuals have a right under the Data Protection Acts to be given this data. “In past years, the top spot was always occupied by unsolicited direct marketing,” Mr Hawkes said. “I think with the economic downturn we are currently suffering, we’ve seen increasing use of the right of access by people who are fearful that they are going to lose their jobs or, who sometimes may have lost them.

“They are using the right of access to see what exactly is going on in relation to them within a particular organisation, or to see was it justified that they should have been picked out for dismissal from the company.”
Daragh O'Brien has also put up a screencast of his presentation at that conference.

Update: Elaine Edwards has more from the conference here, discussing the need for reform of data breach reporting.

Sunday, February 20, 2011

Judge's report reveals allegations that Garda used phone records to spy on her ex

Mark Tighe has an important story in today's Sunday Times about apparent abuse by a garda of the data retention system. Unfortunately it's behind a paywall, but I've taken the liberty of scanning the hardcopy and placing it here as it raises a number of fundamental questions about the safeguards which are in place against abuse and the likelihood of further abuse now that the 2011 Act has extended data retention to internet use also.
Garda accused of bugging her ex-boyfriend

Mark Tighe

A FEMALE garda suspected of obtaining the phone records of her ex-boyfriend has been reported as the first person who may have breached phone-tapping rules introduced in legislation in 1993.

The case is highlighted in a report prepared by Iarfhlaith O'Neill, a High Court judge designated to monitor the state's phone-tapping activities.

Security sources say that the case involves a garda who was stationed in the force's crime and security division, which carries out spying and intelligence services. The garda is accused of obtaining phone records of her former boyfriend to track his movements and activities after they separated. The man became suspicious and complained to gardai because his ex-girlfriend allegedly knew s details of calls he had made.

In a report to the Oireachtas earlier this month, O'Neill said that he investigated a number of alleged breaches of Section 64(2) of the Criminal Justice (Terrorist Offences) Act 2005. Under Section 64(2) no garda below the rank of chief superintendent can request an individual's phone records from a service provider to aid investigations of criminal offences.

O'Neill said: "These breaches are alleged to have been committed by a member of An Garda Siochana."

"As a result of my investigations, I was concerned that these breaches may have occurred. These alleged breaches are now the subject matter of a criminal investigation and also disciplinary proceedings under the garda disciplinary code."

O'Neill said that the extent of the alleged non-compliance with the 2005 Act had been "rigorously investigated and fully understood". He said all appropriate steps had been taken to ensure future compliance with the act.

The rest of O'Neill's report states that on November 18 last year he attended garda headquarters, then army headquarters in McKee Barracks and later the Depart¬ment of Justice offices on St Stephen's Green.

In each location he reviewed documents relating to phone tapping and phone records and spoke to people involved in the operation of the act. He said that all his queries were answered to his satisfaction.

"As a result of the forgoing, I am satisfied that there is, as of the date of this report (November 26, 2010) full compliance with the provisions of the above acts," he said.

A spokesman for the Data Protection Commissioner (DPC) said that gardai had informed it of the apparent data breach last June.

Gardai refused to comment on the case.

Gardai and the Department of Justice have refused to release details of how many requests for phone records or how many phone taps are authorised each year. They say that such information is sensitive.

The Labour party has called for a review of the powers given to gardai to access personal records and said they should only be used in exceptional circumstances.

In 2007 the DPC said that, based on audits of phone companies, it estimated gardai were making 10,000 requests for citizens' phone records each year. Security sources say the figure is now likely to be closer to 15,000 as gardai regularly seek phone records to aid investigations.

Despite its resistance to publishing details about requests to access the phone records of private citizens, Ireland may be forced to do so by a 2009 European Council directive.

The directive requires member countries to legislate to provide their data protection commissioners with the number of requests made for phone records and the legal justification invoked.
Some quick thoughts:

The references to bugging and phone-tapping are misleading - what is alleged here (as I understand it) is that the garda accessed the phone records of her ex rather than actually listened to the contents of telephone calls.

There are, unhelpfully, no details given in the report as to how the abuse came to light or what changes will be made in future to prevent further abuses. (Continuing a fine tradition of opacity.) But a number of questions spring to mind.

When did the alleged abuse take place, and how long did it take before it was uncovered? Was the abuse discovered purely by chance? Is there an adequate internal audit trail of requests which are made? If so, who is responsible for reviewing that trail? Does the designated judge access a sample of requests from the preceding year to ensure that the surveillance was appropriate? If the designated judge will not provide this level of detail in the annual report then the Minister for Justice must do so to the Oireachtas if the public are to have confidence in this system. While the particular details of this case cannot be discussed until any criminal trial is concluded, it is remarkable that there is absolutely no discussion of the systems-level controls which are (or are not) in place.

Finally, when data breach notification is finally introduced as a legal obligation (whether under the revised e-Privacy Directive or the Data Protection Commissioner's Code of Practice) will it include a right to be notified of this type of breach also? Note that the Directive appears to impose a notification obligation on telcos only.

For more background on the allegations behind this story, see this Mail on Sunday piece from last year.

Friday, February 18, 2011

Irish local government says open source software not just for "sandal-wearers"

According to today's Irish Times, the Local Government Computer Services Board is moving towards open source software:
THE LOCAL Government Computer Service Board, a flagship Microsoft client, is moving to open-source software after nearly 10 years of allegiance.

The public sector body provides shared ICT services to local government and was a pioneering exponent of SharePoint, the Microsoft web-based product that is used as an intranet by many of the country’s 33 councils.

In 2001, the board signed a landmark €10 million contract with Microsoft, licensing end-to-end software from desktop to database for use across local government. It was renewed in 2005, but only after assistant director Tim Willoughby looked at the open-source alternatives.

At the time he expressed a reluctance to entrust local government IT platforms to a “sandal-wearing” community, preferring the level of support offered by Microsoft.

A number of factors have convinced Willoughby that the time is right to make the move, not least the fact that the computer service board has seen a 15-20 per cent cut in its IT spend and must make funds go further.
Interestingly, Willoughby also states that data portability was a factor in the decision - "we don’t want our data to be stuck in old infrastructure where we have to pay somebody to get it out".

The relevant request for information is available on eTenders.

The Local Government Computer Services also has a blog on open source software, which includes presentations from a recent local authority forum discussing issues associated with a move to open source.

For background on the relatively slow takeup of open source within the Irish government see this 2008 article from Pearse Ryan and Andy Harbison (PDF).

Monday, February 14, 2011

Importation and sale of mobile phone jammers now an offence

Comreg watchers will be interested to learn that it has today issued the catchily-titled Prohibition of Sale, Letting on Hire, Manufacture, and Importation of Wireless Telegraphy Interference Apparatus Order 2011. The statutory instrument does what it says on the tin, and makes it a criminal offence to import, sell, etc. jamming devices - in particular mobile phone jammers.

I'm not sure what prompted this action now (growing numbers of cheap jammers being imported via Hong Kong sites?) though it does plug a gap which was recognised as far back as 2004 when a Comreg consultation on mobile phone interceptors pointed out that the use but not the sale, etc. of jammers was illegal (Consultation Document | Response to Consultation).

Incidentally, there is an overlap here with offences under the European Communities (Electromagnetic Compatibility) Regulations also, as by their nature jammers cause excessive electromagnetic interference and so could not be lawfully put on the market.

(h/t Ronan Lupton)

Want to know how much your neighbour owes on his credit card? Try the Companies Registration Office

Edited 21/2/11: The story behind this post has since been removed from the Sunday Business Post from its site and a clarification printed:
In an article published on February 13 under the headline "Debtors’ personal details posted online by debt collection firm", we said that Cash Flow Services (CFS) had made personal details of almost 1,100 credit card holders available on the internet, through the Companies Registration Office.

We have been asked to point out, and are happy to clarify, that neither CFS nor any party acting on its behalf listed the names or outstanding debts of MBNA customers in any documents filed in the Companies Registration Office, nor did CFS post any debtors’ personal details online.

The Sunday Business Post apologises to CFS and its directors for any misunderstanding or confusion caused.

Saturday, January 29, 2011

The ISPAI are looking for a legal intern

This looks like an interesting job for a newly-minted law graduate:
ISPAI – The Internet Service Providers Association of Ireland Limited

ISPAI is the Industry Association that represents businesses operating in Ireland that provide publicly available Internet infrastructural and electronic services to customers both in Ireland and abroad. The Association deals with regulatory and legal issues which potentially impact the ISP business environment and affect all our members (see: www.ispai.ie). As part of this, ISPAI coordinates ISP industry self-regulation, administers the industry code of practice and ethics and runs the Hotline.ie service which supports ISPAI members to comply with Irish/EU law to respond to notices of illegal content and to assist international cooperation in this area.

ISPAI offers an intern opportunity for a post-graduate legal student who has a specific interest in the area of telecommunications and digital media law. This is a highly dynamic area with many new initiatives emerging as legislators, law enforcement and various lobbying groups realise the ubiquitous nature of the Internet and its role in shaping modern society. This is a unique opportunity to gain experience and to work with leading companies in the industry. It is strongly recommended for those intending to practise in this area.

It is intended that the selected Intern will follow proposed measures, draft legislation and other issues potentially affecting the ISP industry which are being developed at EU and national level. They will be expected to liaise with the EuroISPA secretariat in Brussels (see: www.euroispa.org) and ISP organisations. The internship will entail European travel to selected meetings or conferences

The Intern will be expected to undertake research on the issues they will be assigned to monitor and write briefings for the internal information of ISPAI secretariat and members. They will also work closely with ISPAI staff to promote our views through our websites and develop press releases.

The internship will be of at least 9 months duration. It will be based in our offices located opposite the Sandyford Luas station in South Dublin. Working within the small ISPAI team, the Intern will report to the ISPAI General Manager. They will be expected to work at least three days per week. The position offers good opportunities for self-development and interaction with international counterparts.

The successful applicant must demonstrate:

• A reasonable knowledge of using various Internet services (web, peer to peer, etc.) and methods used in web based services and be proficient using Microsoft Office products such as Word, Powerpoint and Excel.
• Familiarity with the legal issues surrounding the internet in Ireland, such as the E-Commerce Directive, online defamation and/or "three strikes" and similar systems. The successful applicant must have a law degree and is likely to have taken at least one module covering related issues.
• Good verbal, presentation and writing skills which are essential. Proficiency in a major European language in addition to English would be an advantage.
• A diligent and accurate approach to completing tasks and an ability to work to deadlines with minimal supervision.

Training on technical principles of Internet communications and digital content distribution will be given. Please note: this internship will involve possible exposure to information relating to assessments of potentially illegal pornographic imagery and other content, within the context of ISPAI Hotline.ie operations. This is indemnified under strict procedures agreed with Government and overseen by the Department of Justice and Law Reform, Office for Internet Safety (www.internetsafety.ie) and approved by An Garda Síochána.

Expenses will be given for travel, accommodation and subsistence for approved work-related activities outside the office and a nominal stipend will be available.

Please provide by email to legalintern2011@ispai.ie, your CV and a covering letter of no more than one A4 page explaining why you should be awarded the Internship.

Closing date for applications: Tuesday 15th February 2011.

Saturday, January 22, 2011

Finance Bill taxes internet betting sites - will this lead to blocking of offshore sites?

In my last post I looked at the possible implications of the Finance Bill for Irish computer crime and data protection laws. I missed, however, another important aspect of the Bill, which is that it will extend betting duty to internet betting sites. (In my defence, I didn't read all 223 pages of the Bill and don't plan to do so any time soon. The relevant provision is s.46, at p.186.)

According to the Taoiseach, this extension of duty will be matched by a new requirement that offshore providers obtain a licence to offer their services in Ireland:
The Government will introduce legislation to ensure that overseas betting providers comply with a licensing regime that will permit them to sell their products into our jurisdiction.
So what happens if the offshore providers decide not to play ball? It might not be a coincidence that the Department of Justice has been considering the introduction of internet filtering for some time now - and officials in the Department's Gaming Control section have been taking part in this discussion (PDF released under FOI - see item 49). I can't help but suspect that there will be calls for ISPs to block access to offshore sites which don't pay this new tax - and there have been some European developments in this direction already.

Watch this space.

Friday, January 21, 2011

Finance Bill 2011 - impact on Irish data protection and computer crime law

I'm indebted to Rossa McMahon and Daragh O'Brien for pointing out (via Twitter) two interesting provisions in the Finance Bill 2011 (PDF).

Section 71 creates a new revenue offence of possessing or using computer tools for the purpose of evading tax:
71.—Section 1078 of the Principal Act is amended in subsection (2), by inserting the following after paragraph (b): "(ba) knowingly or wilfully possesses or uses, for the purpose of evading tax, a computer programme or electronic component which modifies, corrects, deletes, cancels, conceals or otherwise alters any record stored or preserved by means of any electronic device without preserving the original data and its subsequent modification, correction, cancellation, concealment or alteration,
(bb) provides or makes available, for the purpose of evading tax, a computer programme or electronic component which modifies, corrects, deletes, cancels, conceals or otherwise alters any record stored or preserved by means of any electronic device without preserving the original data and its subsequent modification, correction, cancellation, concealment or alteration,".
This would appear to cover a wide range of software and hardware, including encryption and steganography software and secure deletion tools. (Though not the encryption of the Anglo files, unless it could be shown that those files were encrypted for the purpose of evading tax.)

Section 73, meanwhile, creates what is in effect a parallel data protection system for the Revenue. Although too long to quote in full, an interesting aspect is that it creates a new offence of unauthorised disclosure of information:
(2) All taxpayer information held by the Revenue Commissioners or a Revenue officer is confidential and may only be disclosed in accordance with this section or as is otherwise provided for by any other statutory provision.

(3) Except as authorised by this section, any Revenue officer who knowingly—
(a) provides to any person any taxpayer information,
(b) allows to be provided to any person any taxpayer information,
(c) allows any person to have access to any taxpayer information, or
(d) uses any taxpayer information otherwise than in the course of administering or enforcing the Acts,

shall be guilty of an offence and shall be liable —
(i) on summary conviction to a fine of €3,000, and
(ii) on conviction on indictment to a fine of €10,000.
I wonder whether this amendment may have been prompted by the publicity attached to these recent examples of wrongdoing by Revenue staff.