Monday, March 26, 2012
Eircom admits user disconnection is illegal; wants other Irish ISPs to do it anyway
You couldn't make it up. Eircom, not content with shooting itself in the foot by agreeing to introduce a "three strikes" system which wasn't required by the law, now wants its rivals to do the same. Presumably that would be the same three strikes system which Eircom's head of public policy has admitted is in breach of European law.
Friday, March 16, 2012
Coleman v. MGN - jurisdiction in internet defamation cases
The Supreme Court yesterday gave a decision on internet defamation in Coleman v. Mirror Group Newspapers, where it held that the Irish courts had no jurisdiction in relation to a photograph said to have been published on the Mirror website in 2003. The judgment turns for the most part on deficiencies in pleading rather than on the substantive law so is of little precedential value, but it does highlight the fact that the courts will not rely on "presumed" publication in this jurisdiction - there must be evidence that online material was actually read by a person within the jurisdiction in order for a defamation claim to be brought:
First, there is no pleading that the publication alleged of the relevant articles is by internet publication of the relevant newspaper. Nor could such a pleading be inferred from the words of the Statement of Claim. Secondly, there is a need for evidence of publication to establish the tort of defamation. There is no evidence before the Court that the Daily Mirror was published on line in 2003. There is no evidence that the daily edition of the Daily Mirror was on the world wide web in 2003. Thirdly, there is no evidence of any hits on any such site in this jurisdiction. These are fatal flaws in the plaintiff’s case.Compare the similar decision in USA Rugby v. Calhoun.
Tuesday, March 13, 2012
User consent to privacy policies is a fiction - here's why
One simple answer to our privacy problems would be if everyone became maximally informed about how much data was being kept and sold about them. Logically, to do so, you'd have to read all the privacy policies on the websites you visit. A few years ago, two researchers, both then at Carnegie Mellon, decided to calculate how much time it would take to actually read every privacy policy you should.
First, Lorrie Faith Cranor and Aleecia McDonald needed a solid estimate for the average length of a privacy policy. The median length of a privacy policy from the top 75 websites turned out to be 2,514 words. A standard reading rate in the academic literature is about 250 words a minute, so each and every privacy policy costs each person 10 minutes to read.
Next, they had to figure out how many websites, each of which has a different privacy policy, the average American visits. Surprisingly, there was no really good estimate, but working from several sources including their own monthly tallies and other survey research, they came up with a range of between 1,354 and 1,518 with their best estimate sitting at 1,462.
So, each and every Internet user, were they to read every privacy policy on every website they visit would spend 25 days out of the year just reading privacy policies! If it was your job to read privacy policies for 8 hours per day, it would take you 76 work days to complete the task. Nationalized, that's 53.8 BILLION HOURS of time required to read privacy policies. [Emphasis added.]
From TheAtlantic.com. The full study (PDF) is well worth reading.
Wednesday, March 07, 2012
Witness comments on Facebook cause assault case to be dismissed
This may be the first time in Ireland that a case has been dismissed on the basis of Facebook comments. From the Mayo News:
A WOMAN who wrote comments on a Facebook page about an alleged assault was told her actions had ‘fatally compromised’ the assault case which was subsequently dismissed.Based on this report, it's difficult to see precisely why the charge was dismissed. There was no jury and therefore no real risk of the comments improperly influencing the decision maker. The mere fact that a witness has previously written about what they saw - even publicly - is not in itself a basis for dismissal of charges. In addition, there was no suggestion that the comments could influence other witnesses in the case. Most importantly, the equation of Facebook comments with newspaper coverage is simply incorrect and seems to reflect a misguided analogy with the law regarding contempt of court and the sub judice rule. While social media does present genuine challenges for the law, it would be unfortunate if judicial unfamiliarity with the internet were to lead to unnecessary problems for the criminal justice system.
Judge Mary Devins told last week’s sitting of Ballina District Court that in her view writing messages on Facebook was akin to writing in newspapers.
She made her ruling after hearing evidence from Maureen O’Malley from Westport, who explained that she posted two messages on Facebook about an alleged assault by the CEO of a Ballina laboratory against an animal rights protester.
Leonard Moran of Carrentrila, Ballina, was accused of assaulting Laura Broxon from Dublin. He was accused of punching her in the face while wielding a hammer when she was staging a protest outside the Ovagen and Charles River Laboratories, which are adjacent to Mr Moran’s house.
Mr Moran, who is a Director of Ovagen and who used to own the lab until it was sold to US company, Charles River in 2002, denied he punched her. Ms Broxon, who is the founder of the National Animal Rights Association, claimed that testing of animals takes place in the lab and during the protest accused Mr Moran of having ‘blood on your hands’...
Detective Garda Pat Ruane explained that two comments had been posted by Maureen O’Malley, who admitted posting them.
She told the court last week that she arrived at the scene after the incident had taken place and had spoken to Ms Broxon, who explained what she claimed happened. She said was shocked at what happened and posted the comments when she went home.
In the first comment, she posted that the CEO of Charles River had assaulted a protester, and in the second comment she asked why he would resort to physical violence and what he was capable of doing to ‘defenceless animals in his lab’.
Judge Devins said that even though she wrote the comments with good intentions, writing about something on Facebook can compromise a criminal prosecution. She said it was akin to a local or national newspaper giving their version of events and dismissed the case.
Saturday, March 03, 2012
Illegal blood sample database to be destroyed
Two years ago the Sunday Times broke the story that the Irish national children's hospital was illegally keeping blood samples from almost every Irish newborn since 1984, in what amounted to a de facto national DNA database. Two years later, the decision has finally been made to destroy these samples. From today's Irish Times:
MINISTER FOR Health Dr James Reilly has decided to have more than a million archived blood samples taken from newborns destroyed within the next four to six months.
Cardiologists have called on the Minister to reverse the decision, describing it as “appalling”. They say the samples could be particularly valuable in genetic tests for diagnosing sudden adult death syndrome.
Dr Reilly is to follow the recommendations of a Health Service Executive review group to destroy heel-prick screening cards that are more than 10 years old.
The department plans to give individuals and their families the chance to access the cards or have them returned. Most of those affected would now be aged between 10 and 28...
Until recently parents were not asked for consent to keep the samples. Parents have had the right to opt out of the test since a 2001 Supreme Court judgment.
Since July 2011 parents have been asked for consent to take the samples, with agreement to allow storage for 10 years with use only for tests to which they agree.
Action on the issue came about after the Data Protection Commissioner found in 2009 that the retention of the cards breached the law, following a complaint from a member of the public. The commissioner proposed that the retained samples be destroyed.
The HSE review group report seen by The Irish Times said that retaining samples without consent “clearly contravenes both EU and national data-protection legislation”. It is “extremely important” that the screening programme was “not undermined or compromised in any way”, it said.
Using the samples for research or another purpose “compounds only further that initial wrong”, it said.
The destruction of the old samples “serves to respect the autonomy of the individual”, the report concludes.
Wednesday, February 29, 2012
More Ryanair litigation against flight resellers - this time with a data protection twist
You might have noticed that Ryanair is busy with litigation against services which screenscrape flight details from its site or act as resellers of its flights. (Previously on this blog 1|2|3|4|5.)
Usually those cases have centered on arguments that this activity amounts to a breach of either Ryanair's intellectual property rights in their site or their terms of use. However Ryanair has now added an interesting data protection dimension to its claims in a fresh action against Club Travel. From today's Irish Times:
RYANAIR HAS claimed before the High Court that details about people who book its flights through a package holiday website can be seen by other travellers.
The airline is seeking an injunction stopping Club Travel from selling its flights on the grounds that it amounts to wrongful interference with its copyright and database. Club Travel denies the claims. Because of the way Club sells the flights, customers who book through it have access to information about other travellers’ flights and know when they will be out of the country, Ryanair alleges.
Club customers, it claims, are told not to input their own email address but a specific address which belongs to Club. As a result, Club customers may access details of other passengers who booked flights the same way, Martin Hayden SC, for Ryanair, argued.
This gives access to information about when other people who booked the flight are abroad and when their homes are unoccupied, counsel said.
Ryanair said it was also concerned that, for the cost of changing a name on a flight, a person who has such access can change the name, address and passport details on another traveller’s flight and obtain that person’s boarding card, he said.
These were serious data protection issues which could expose Ryanair to penalties, he said.
Friday, February 24, 2012
Self-service search warrants after Damache v. DPP
A peculiar feature of Irish law for many outside observers is the fact that search warrants are treated as being an executive rather than judicial function (PDF, ch.4). As a result a number of statutes give police the power to themselves issue such warrants on a "self-service" basis. Yesterday's Supreme Court decision in Damache v. DPP, however, cuts back the scope of these powers somewhat.
In this case Damache was suspected of involvement in a conspiracy to murder Lars Vilks, one of a number of cartoonists said to have insulted Islam by drawing Mohummad. On foot of this suspicion, a senior garda issued a search warrant in relation to his home by under s. 29(1) of the Offences Against the State Act 1939 (as inserted by s. 5 of the Criminal Law Act 1976). That section is exceptionally wide and in essence allows a senior garda to issue a search warrant in any terrorist related case in respect of any location without any special circumstances having to be shown:
Initially, the High Court held that it was. In a disappointing decision which relied on the fallacy that "modern terrorism is different" Kearns P. held that a search warrant was merely a step in the investigative process which did not have to be issued by an independent authority and that in any event the section would be justified on the basis that:
Significantly, however, the court clearly flags a preference for search warrants to be issued judicially in future. Rather than simply requiring that a search warrant be issued by a garda who was not personally involved in the investigation, the court holds that "in the circumstances of this case a person issuing the search warrant should be independent of the Garda Síochána, to provide effective independence". This would seem to require that any power to issue search warrants in respect of the home should only be exercised by an outside authority (presumably a district court judge) except in cases of urgency.
At the very least this will force a reevaluation of garda practice in this area - and should also require reconsideration of the procedures in related areas such as GPS tracking or access to telephone and internet data where authorisations are granted internally within the Garda.
In this case Damache was suspected of involvement in a conspiracy to murder Lars Vilks, one of a number of cartoonists said to have insulted Islam by drawing Mohummad. On foot of this suspicion, a senior garda issued a search warrant in relation to his home by under s. 29(1) of the Offences Against the State Act 1939 (as inserted by s. 5 of the Criminal Law Act 1976). That section is exceptionally wide and in essence allows a senior garda to issue a search warrant in any terrorist related case in respect of any location without any special circumstances having to be shown:
Where a member of the Garda Síochána not below the rank of superintendent is satisfied that there is reasonable ground for believing that evidence of or relating to the commission or intended commission of an offence under this Act or the Criminal Law Act, 1976, or an offence which is for the time being a scheduled offence for the purposes of Part V of this Act, or evidence relating to the commission or intended commission of treason, is to be found in any building or part of a building or in any vehicle, vessel, aircraft or hovercraft or in any other place whatsoever, he may issue to a member of the Garda Síochána not below the rank of sergeant a search warrant under this section in relation to such place.Crucially, the garda in question had been centrally involved in the investigation and there were no circumstances of urgency or time pressure in the case. Was the legislation valid insofar as it allowed a warrant to be issued in these circumstances?
Initially, the High Court held that it was. In a disappointing decision which relied on the fallacy that "modern terrorism is different" Kearns P. held that a search warrant was merely a step in the investigative process which did not have to be issued by an independent authority and that in any event the section would be justified on the basis that:
the security demands of countering international terrorism are of a quite different order to those which apply in what might be described as routine criminal offences. Serious injury and harm can be unleashed at any point in the globe by terrorists who can avail of modern technology to devastating effect. That fact was amply borne out by the attack on the World Trade Centre on 11th September, 2001, and many other terrorist acts before and since. The international terrorism of the modern age is a sophisticated, computerised and fast moving process where crucial evidence may be lost in minutes or seconds in the absence of speedy and effective action by police authorities.On appeal, however, the Supreme Court took an entirely different approach. Building on earlier Irish authorities and applying the ECtHR decision in Camenzind v. Switzerland and the Canadian Supreme Court decision in Hunter v. Southam Inc the court devloped the principle that search warrants should generally only be issued by an independent person:
For the process in obtaining a search warrant to be meaningful, it is necessary for the person authorising the search to be able to assess the conflicting interests of the State and the individual in an impartial manner. Thus, the person should be independent of the issue and act judicially.Applying this, the court found that the section was invalid insofar as it allowed for search warrants to be granted in respect of any location by a garda involved in the investigation without there being any special circumstances justifying a departure from this rule:
54. This case is decided on its own circumstances. These circumstances include the fact that the warrant was issued by a member of a Garda Síochána investigating team which was investigating the matters. A member of An Garda Síochána who is part of an investigating team is not independent on matters related to the investigation. In the process of obtaining a search warrant, the person authorising the search is required to be able to assess the conflicting interests of the State and the individual person, such as the appellant. In this case the person authorising the warrant was not independent. In the circumstances of this case a person issuing the search warrant should be independent of the Garda Síochána, to provide effective independence.This is in some ways quite a narrow decision. The court placed great stress on the fact that the search related to a dwellinghouse - suggesting that powers of search relating to business premises might be treated differently. Similarly, the court noted that the decision didn't relate to cases of urgency which would seem to leave intact a number of garda powers to issue search warrants in situations where "circumstances of urgency giving rise to the need for the immediate issue of the search warrant would render it impracticable to apply to a judge of the District Court or a Peace Commissioner".
55. The circumstances of the appellant’s case also includes the fact that the place for which the search warrant was issued, and which was searched, was the appellant’s dwelling house. The Constitution in Article 40.5 expressly provides that the dwelling is inviolable and shall not be forcibly entered, save in accordance with law, which means without stooping to methods which ignore the fundamental norms of the legal order postulated by the Constitution. Entry into a home is at the core of potential State interference with the inviolability of the dwelling.
56. These two circumstances are at the kernel of the Court’s decision.
57. No issue of urgency arose in this case, and the Court has not considered or addressed situations of urgency.
58. The Court points out that it is best practice to keep a record of the basis upon which a search warrant is granted.
59. This Court would grant a declaration that s. 29(1) of the Offences against the State Act, 1939 (as inserted by s. 5 of the Criminal Law Act, 1976) and referred to as s. 29(1) of the Act of 1939, is repugnant to the Constitution as it permitted a search of the appellant’s home contrary to the Constitution, on foot of a warrant which was not issued by an independent person.
Significantly, however, the court clearly flags a preference for search warrants to be issued judicially in future. Rather than simply requiring that a search warrant be issued by a garda who was not personally involved in the investigation, the court holds that "in the circumstances of this case a person issuing the search warrant should be independent of the Garda Síochána, to provide effective independence". This would seem to require that any power to issue search warrants in respect of the home should only be exercised by an outside authority (presumably a district court judge) except in cases of urgency.
At the very least this will force a reevaluation of garda practice in this area - and should also require reconsideration of the procedures in related areas such as GPS tracking or access to telephone and internet data where authorisations are granted internally within the Garda.
Thursday, February 23, 2012
Checking the PULSE
We've known for some time now that there's been significant abuse of the Garda PULSE database - whether this takes the form of gardaí checking up on daughters' boyfriends or more seriously information being sold to armed robbers. This abuse was one of the factors which led the Data Protection Commissioner in 2007 to adopt a Garda Code of Practice on Data Protection. While quite far-reaching, that document also dealt specifically with the PULSE database and provides:
The standard of security expected of all employees of An Garda Síochána includes the following:Unfortunately, it seems that the 2007 Code of Practice has been neglected. In particular, there has been a failure to implement the agreed monitoring of the use of the PULSE system and in his 2010 Annual Report the Data Protection Commissioner stated that:
* access to the information restricted to authorised staff on a "need-to- know" basis in accordance with a defined policy,
* computer systems password protected,
* information on computer screens and manual files kept hidden from callers to offices,
* back-up procedures in operation for computer held data, including off-site back-up,
* all waste papers, printouts, etc. disposed of carefully by shredding,
* all employees must log off from PULSE and other computers on each occasion when they leave the workstation,
* personal security passwords must not be disclosed to any other employee of An Garda Síochána,
* all Garda premises to be secure when unoccupied,
* a designated person will be responsible for all the above within An Garda Síochána with periodic reviews of the measures and practices in place.
Every contact on PULSE leaves a trace and every employee should be acutely aware that all activity under their registered number and password on PULSE is recorded. During an Audit or Investigation procedure they may be asked to account for the reasons they accessed a particular individual's data at any given time and what they did with it afterwards. An Garda Síochána will ensure that appropriate data protection and confidentiality clauses are in place with any processors of personal information on its behalf...
6. AUDITS OF DATA PROTECTION PROCEDURES WITHIN AN GARDA SÍOCHÁNA
To ensure the quality of data retained by An Garda Síochána, and that access to and usage of such data is appropriate within the terms of this Code, each District Officer will, as part of his/her quarterly inspection and audits in line with the Garda Commissioner's policy, examine data under the headings of Quality Control; Data Accuracy; Access to Data; and Usage of Data.
In addition to this, the Garda Professional Standards Unit will conduct examinations and reviews of Data Protection procedures as part of their ongoing examination and review process.
It is disappointing to report that, despite our repeated engagements on this issue, the monitoring of access by members of An Garda Síochána to Pulse falls short of the standards we expect. We wish to see significant progress by the Gardaí in pro-actively monitoring Pulse access in 2011 and will be carrying out an audit to satisfy ourselves of this progress.Today's Irish Times brings the story up to date, and reveals that a Garda system to monitor access to PULSE has now been put in place (four years after it was first promised) while the Data Protection Commissioner's audit will proceed in the next three months. I look forward with interest to the results - particularly if the audit goes beyond PULSE to also examine the weak controls over Garda surveillance powers which have led to at least one serious case of abuse.
Monday, February 20, 2012
Heads should roll. But, of course, they won't.
Justified outrage from Eamon Delaney in the Sunday Independent:
It is shocking but not surprising that not a single civil servant has been fired for an incredible bout of behaviour at the so-called Department of Social Protection.
It seems that almost 100 departmental employees accessed the personal files of the public and passed on highly sensitive information to insiders. They snooped on their friends, on colleagues and celebrities.
It is hardly of reassurance to know that this has not been going on for a few weeks but for more than seven years, and involved thousands of records being improperly interfered with. In short, it is a disgraceful breach of trust, which just shows the corrosion at the heart of our civil service, a once-pristine post-colonial inheritance.
And yet, not one member of staff has been sacked for their conduct. Not one. This is despite the offenders breaching both the Data Protection Act and the department's own internal rules. Instead, 87 staff members were 'sanctioned' for improperly accessing sensitive data...
And yet what is most amazing is how little outcry there has been about this, or comment from our otherwise vocal politicians, whose ambition is to actually be responsible for public servants. But then they are so immersed in the culture of the public service, and its indulgences and leniency, that they presumably don't see anything to get too alarmed about.
But you can be damn sure that if it was journalists doing this snooping, or bank officials leaking sensitive personal info, there would be an outcry and robust calls for enquiries and dismissals.
Wednesday, February 15, 2012
Is data misuse finally becoming a criminal matter?
There's a long and ignominious history in Ireland of personal data abuse by employees in the public sector and insurance industry. Sometimes it's a garda using phone records to spy on her ex, sometimes it's nosiness on the part of Revenue staff, and in still other cases it's systematic abuse of social welfare records by the insurance industry. Sadly, the full list is too long for this post. What these cases have in common is that historically no one has been prosecuted. In some cases staff have been dismissed - but more commonly an internal slap on the wrist was the most that could be feared.
Against this background, it's significant that two prosecutions have recently been taken over data misuse. The first, reported in December, involved a staff member in Revenue who leaked information on a number of individuals to contacts including a private investigator. That case was somewhat outside the data protection mainstream - it was detected to a large extent by accident and dealt with primarily by Gardai rather than the Data Protection Commissioner - but still held out hope for the greater use of criminal sanctions in appropriate cases. That hope has now been realised by a second successful prosecution - this time of three large insurance companies found to be receiving information unlawfully accessed by private investigators from the Department of Social Protection. While the case against the companies is now concluded, a related investigation is continuing into the insider in the Department who was responsible for passing on the information.
What should we make of these cases? In one way the prosecutions still represent only small steps towards more effective enforcement. The penalties are still derisory - in each case the Probation Act was applied so that the defendants escaped conviction on the basis that they made charitable donations. The substantive offences are also lacking - in the Social Protection case the prosecution was based on processing of data other than in accordance with registration rather than any more serious offence. (Sections 19(2)(a) and 19(2)(b) of the 1988 Act.)
From a wider perspective, however, the prosecutions represent an important step forward. The Revenue case seems to have been the very first prosecution under sections 21 and 22 of the Data Protection Acts 1988 and 2003, and certainly the first such prosecution on indictment. Similarly the Social Protection case is important in its own right in that it came out of ongoing work by the Data Protection Commissioner - dating back to 2007 and including a 2008 Code of Practice - and represents the first time that the insurance industry has been effectively held to account for systematic wrongdoing. Combined with recent amendments which create specific offences of leaking Revenue information these cases may finally begin to dislodge the culture of snooping within much of the public sector.
Against this background, it's significant that two prosecutions have recently been taken over data misuse. The first, reported in December, involved a staff member in Revenue who leaked information on a number of individuals to contacts including a private investigator. That case was somewhat outside the data protection mainstream - it was detected to a large extent by accident and dealt with primarily by Gardai rather than the Data Protection Commissioner - but still held out hope for the greater use of criminal sanctions in appropriate cases. That hope has now been realised by a second successful prosecution - this time of three large insurance companies found to be receiving information unlawfully accessed by private investigators from the Department of Social Protection. While the case against the companies is now concluded, a related investigation is continuing into the insider in the Department who was responsible for passing on the information.
What should we make of these cases? In one way the prosecutions still represent only small steps towards more effective enforcement. The penalties are still derisory - in each case the Probation Act was applied so that the defendants escaped conviction on the basis that they made charitable donations. The substantive offences are also lacking - in the Social Protection case the prosecution was based on processing of data other than in accordance with registration rather than any more serious offence. (Sections 19(2)(a) and 19(2)(b) of the 1988 Act.)
From a wider perspective, however, the prosecutions represent an important step forward. The Revenue case seems to have been the very first prosecution under sections 21 and 22 of the Data Protection Acts 1988 and 2003, and certainly the first such prosecution on indictment. Similarly the Social Protection case is important in its own right in that it came out of ongoing work by the Data Protection Commissioner - dating back to 2007 and including a 2008 Code of Practice - and represents the first time that the insurance industry has been effectively held to account for systematic wrongdoing. Combined with recent amendments which create specific offences of leaking Revenue information these cases may finally begin to dislodge the culture of snooping within much of the public sector.
Sunday, February 12, 2012
#SOPAIreland: where's the legal advice?
The main reason - effectively the only reason - given by Minister Sean Sherlock for pushing ahead with a deeply flawed statutory instrument is that he is acting on the advice of the Attorney General. However, he has not revealed the detail of that advice and we are being asked to take it on trust both that it is correct (a matter which is open to debate) and also that it compels this particular course of action.
Fortunately, I discovered during the week that the Labour Party has an explicit commitment as to what should be done in these circumstances. Here's an excerpt from their 2011 policy document "New Government, Better Government":
---
* A question might be raised as to whether publishing advice might prejudice the pending music industry litigation. It could be argued that advice about Ireland's obligations under the Infosoc Directive should not be released, though the Minister has already rather let the cat out of the bag by stating to the Dáil that the advice is that "the State is at risk of actions against it, which would probably result in substantial damages". However, even granting this point there is no reason not to publish the advice about the distinct issue of how to implement the Directive. For example, why was a SI considered appropriate and not primary legislation? How was the vague wording chosen? Why did the Minister reject the suggestions in the Technical Group's alternative draft SI? There is no possible prejudice in providing more clarity on these points.
Fortunately, I discovered during the week that the Labour Party has an explicit commitment as to what should be done in these circumstances. Here's an excerpt from their 2011 policy document "New Government, Better Government":
Attorney General’s AdviceI couldn't agree more, and look forward to this Labour policy being applied to the current statutory instrument.
50. In specific circumstances the Attorney General’s advice to government should be published. If the advice of the Attorney General is publicly relied upon as justifying or necessitating a particular course of action adopted by the Government or by a minister, privilege should not preclude the publication of a summary of the arguments as they relate to:
* the development of a legislative proposal by the government, a minister of the government or a minister of state, or by any other member of the Dáil or Seanad,
* the introduction of a Bill or resolution in either House of the Oireachtas or the passage, defeat or amendment of a Bill or resolution in either House,
* the making, revocation or amendment of a statutory instrument, or
* the development or amendment of a policy or programme of a public body, unless the advice is given in the course of litigation or in relation to pending or contemplated litigation.*
* Appropriate provision would be taken for the protection of commercially sensitive information and information to do with private individuals, national security, the detection and prosecution of crime, and so on.
---
* A question might be raised as to whether publishing advice might prejudice the pending music industry litigation. It could be argued that advice about Ireland's obligations under the Infosoc Directive should not be released, though the Minister has already rather let the cat out of the bag by stating to the Dáil that the advice is that "the State is at risk of actions against it, which would probably result in substantial damages". However, even granting this point there is no reason not to publish the advice about the distinct issue of how to implement the Directive. For example, why was a SI considered appropriate and not primary legislation? How was the vague wording chosen? Why did the Minister reject the suggestions in the Technical Group's alternative draft SI? There is no possible prejudice in providing more clarity on these points.
Monday, February 06, 2012
I thought I was writing a blog; turns out I'm a threat to humanity
We need to address the threat to humanity posed by the tsunami of unverifiable data, opinion, libel and vulgar abuse in new media. I know all the stuff about it being a tool of freedom and democracy, and I also know it has the capacity to destroy civil society and cause unimaginable suffering. Governments have a regulatory function in this regard, and they’re walking away from it because they’re afraid of appearing to be repressive.Ironically today's speech by Alan Crosbie at a conference on media diversity is itself full of such unverifiable data and opinion. For a man who makes much of the credibility and reliability of newspapers, it is unfortunate that he repeats the long since debunked claim that:
Those English riots, for example, were a new media generated phenomenon, a product of information going from pillar to post without mediation without being edited, without a quality check.Also worth noting is the cognitive dissonance between page 3 (complaining about political interference in RTE) and page 4 (seeking licence fee payments for newspapers also). Read the whole thing for an insight into the views of the man behind a substantial chunk of the Irish media industry.
Sunday, February 05, 2012
"The law should be predictable as to what is mandated and what is forbidden"
One of the strongest arguments against the proposed copyright statutory instrument is that it is so vague as to make it impossible to predict what it might require of internet intermediaries. The proposal is entirely silent in relation to the most basic issues where one might expect clarity. What type of injunction might be granted? Site blocking? Three strikes? Deep packet inspection? Hash value blocking? What types of intermediaries might be affected - ISPs, search engines, hosting providers, cloud computing providers? Who will have to pay the legal costs of applications for injunctions? Who will have to pay the ongoing cost of implementing any injunction?
Crucially, this vagueness is highlighted by comments of Charleton J., the very High Court judge whose ruling in EMI v. UPC has been relied upon by Sean Sherlock as justification for this statutory instrument. However, when examined closely neither his judgment in that case nor his later extrajudicial pronouncements support this claim. In particular, in a recent speech to the Fordham Intellectual Property Conference, he said:
Crucially, this vagueness is highlighted by comments of Charleton J., the very High Court judge whose ruling in EMI v. UPC has been relied upon by Sean Sherlock as justification for this statutory instrument. However, when examined closely neither his judgment in that case nor his later extrajudicial pronouncements support this claim. In particular, in a recent speech to the Fordham Intellectual Property Conference, he said:
Legislation such as the [UK Digital Economy] Act of 2010, has at least the predictability of express statement as to the objects to be achieved. In respect of each of the possible solutions of diversion, interruption, warning and cut-off, the British have OfCom looking at the appropriate technical machinery with which to achieve these ends. When this machinery is approved, then, in those circumstances, any court faced with these difficult cases will be in a position to fairly, if not precisely, predict what they can use as a technical solution with a view to granting or refusing to grant injunctions."The law should be predictable as to what is mandated and what is forbidden and enables a judge to also know what is expected in the judicial sphere in particular circumstances". Can the DJEI honestly claim that their proposed statutory instrument meets these criteria?
This strongly accords with the European law principle that the law should be predictable as to what is mandated and what is forbidden and enables a judge to also know what is expected in the judicial sphere in particular circumstances. As I said in another part of the judgment in EMI v. UPC, if any judge were merely to act on the basis of what the Court felt was right, without having a legislative basis, the Court would be putting itself back in the position of judges in the late 19th and 20th century who used the tort of conspiracy and the remedy of an injunction against the trade union movement and thereby caused public controversy, rendered uncertain the concept of the rule of law and undermined their own authority.
It may also be well for the judicial mind to observe that the separation of powers is a definite guiding principle against doing what might seem desirable, but which is not provided for in legislation.
Irish copyright regulations unnecessary
Senior Counsel John Gordon has a clear explanation as to why Sean Sherlock's proposed copyright regulations are unnecessary in today's Sunday Business Post. I've taken the liberty of reproducing the entire piece here:
Simplistic Internet regulations court troubleIt's worth noting, although not explicitly stated, that the effect of this opinion is the proposed statutory instrument would be ultra vires the power of the Minister and therefore would be struck down if challenged before the High Court. To date the government talking points have been to the effect that it would be "prudent" to introduce the SI. John Gordon's analysis shows why this is flawed - unless the SI is required by EU law then the Minister has no power to introduce it.
Amendments to copyright law for online infringements should be dealt with through primary legislation, writes John Gordon
There has been much debate in recent weeks about a draft statutory instrument (SI) that minister of state Sean Sherlock is about to bring into Irish law to deal with online copyright infringement. The SI is intended to fulfil Ireland's EU obligations by facilitating injunctions against internet service providers (ISPs). This follows the decision of Justice Charleton in 2010 in the unsuccessful action taken by Irish recording companies, EMI, Sony, Universal, Warner and Wea against UPC, in which I appeared on behalf of the defendant.
These recording companies last month issued proceedings against the state on the basis that it is liable to pay compensation for its failure to provide them with a remedy to fight online copyright infringement. This raises the question of how the state has failed in its obligations.
In Minister Sherlock's press release on January 26, accompanying a draft of the proposed SI, it was stated that the obligations contained in the relevant directive were clear.
Article 8(3) of the directive on the harmonisation of certain aspects of copyright and related rights in the information society, (2001/29/EC), which is referred to in the draft SI, provides that member states shall ensure copyright owners are in a position to apply for injunctions against intermediaries whose services are used by others to infringe copyright. The directive states that the conditions and modalities for such injunctions are at the discretion of member states.
Having taken into account these provisions, the state did in fact legislate to provide a remedy to rightsholders in respect of copyright infringements under the notify and takedown provisions of Section 40(4) of the Copyright and Related Rights Act 2000. In addition, rightsholders have been granted Norwich Pharmacal Orders under the common law, which obliges an ISP to identify subscribers who are shown to have infringed copyright on the ISPs network so the rightsholders can pursue such infringers directly. Such relief has historically been obtained by the recording companies that are now suing the state.
However, they consider it too expensive and ineffective. So what is now being sought is not the right to a remedy but an additional remedy under Irish law. There is no clear and unambiguous obligation on the state to implement this SI.
In the UPC case the reliefs sought included the possible implementation by ISPs of filtering and blocking technology on their network, and of a graduated response system, whereby after three warnings a person's internet subscription is suspended or terminated and/or the blocking of subscriber access by ISPs to certain websites alleged to facilitate copyright infringement.
A recent decision of the Court of Justice of the EU (Case C-70/10 SABAM) has confirmed, since the UPC case, that it is unlawful under EU law for an ISP to be ordered to implement blocking and filtering technology on its network to seek out copyright infringements.
In addition, Eircom's implementation of the graduated response, or three strikes, system, which is the subject of specific legislation in certain member states, is currently being challenged by the Data Protection Commissioner before the Irish Courts.
Given the progress of legislative and judicial thought in the EU, it is now even more clear that the type of remedy which rightsholders seem to expect as a result of the proposed SI will not be available to them.
As a result, the state cannot be liable to pay compensation for failing to provide these remedies under Irish law. The generality of the language in the proposed SI can only lead to confusion as to the precise remedies that can lawfully be obtained in the light of other express provisions of EU law. Such EU law is intended to cut down on the scope of the remedies available against ISPs.
Judges will have to approach any new legislation by reference to EU law and jurisprudence, which must take precedence over Irish domestic law where there is any inconsistency between the two.
If this whole debate is a matter of empowering the Irish courts to order the blocking of websites, as many commentators have stated in recent weeks and months, then the legislation should specifically address this and set out the relevant criteria in a manner consistent with EU law. The proposed SI introduces unwelcome uncertainty and will inevitably lead to further litigation.
Further, it is noteworthy that the Programme for Government stated that legislation in the area of online copyright infringement needed to be tackled — but went on to say that "the situation can no longer be tolerated where Irish ministers enact EU legislation by statutory instrument", where "the checks and balances of parliamentary democracy are bypassed". The proposed SI ignores this statement, in that it seeks, without the benefit of the normal legislative process, to amend the Copyright and Related Rights Act 2000, which itself was the subject of lengthy debate in both houses of the Oireachtas at the time.
Implementing this alarmingly simplistic SI will unfortunately not solve the problem of striking a fair balance between the interests of all involved, be they rightsholders, ISPs or internet users, but rather leave it to be teased out in the courts. Time should be taken to properly consider what changes need to be made to our copyright laws by means of primary legislation. In this context, assistance can be obtained from considering similar debates currently taking place in many other jurisdictions including the United States of America.
John Gordon is a senior counsel
Your personal information for sale: Irish Rail edition
Today's Sunday Independent reveals that a private investigator acting for Irish Rail illegally accessed staff bank accounts, while the company also monitored staff email and placed a GPS tracking device on the car of an individual working for a contractor:
A statement issued by the Data Protection Commissioner's office this weekend said Irish Rail "acknowledged" the "unacceptable level of surveillance" on employees: "It was apparent to the investigation that one senior manager at Irish Rail authorised the surveillance and accessing of bank accounts without the knowledge or approval of management."There's some background to the case in this earlier Sunday Independent piece.
The investigation found "that the private bank accounts of nine employees or former employees of Irish Rail were inappropriately accessed in 2007. The bank accounts were held in four different financial institutions".
Because of the passage of time, the investigation was unable to identify "precisely how or when" employee bank accounts had been accessed. "In one case, however, the investigation did find evidence of an unsuccessful attempt by an individual by means of a telephone call to obtain bank statement information in respect of one of the bank accounts concerned," the statement said.
"The investigation was satisfied that this attempt to inappropriately access bank account information was made by an individual phoning from outside of the State."
The statement continued: "It also emerged that the individual who played the key role in accessing information from the bank accounts was operating from outside of this jurisdiction and that he is since deceased."
The investigation was also told how a GPS tracking device was fitted on the car of an employee of a contractor of Irish Rail, and the emails of 35 employees were monitored.
The investigation into the data protection breach at Irish Rail remains "open".
Wednesday, February 01, 2012
Copyright proposals block innovation and free expression
I have an opinion piece in today's Irish Times arguing against current government proposals which would allow internet blocking and more. Here's an excerpt:
As currently drafted, the statutory instrument provides that the High Court may grant an injunction against an internet intermediary who is entirely innocent of any wrongdoing – but does not specify even the most basic details regarding how this power might be exercised.Full text
What type of injunction might be granted? On what criteria? Against what types of intermediary – internet service providers, discussion forums, search engines, social networking sites, video hosting sites? Who will bear the costs of these injunctions? Who will be responsible if, as often happens, an unrelated website is wrongfully blocked?
This lack of detail makes it impossible to predict how this law might be applied, and means that clarification will come only after repeated and expensive trips to the High Court.
The Internet Service Providers Association of Ireland (whose members include Google) has opposed the legislation, noting the proposal creates “business uncertainty for those running or considering establishing internet services from Ireland” in a way which may have “drastic consequences” for them: in short, it will act as a deterrent to the next generation of Irish internet businesses which may relocate to warmer legal climes. Significantly, the Department of Enterprise has not produced a Regulatory Impact Assessment of the measure.
Wednesday, January 25, 2012
Ireland's SOPA to permit three strikes; TDs asked to debate something they haven't seen
It's been a peculiar day in relation to Ireland's SOPA.
First of all, junior minister Sean Sherlock said on lunchtime radio that he intends to hold an emergency Dáil debate on the law - within 24 hours no less! - and is happy to meet with me and other representatives of StopSOPAIreland.com to discuss it. While I'm glad to see that he's softened his position, it's remarkable that he still hasn't published the text of his proposals and doesn't show any signs of doing so. Consequently, I'm not sure what there is to discuss or what he expects the Dáil to debate. Asking TDs to have a debate in the dark about a document they haven't seen doesn't show much respect for Parliament.
But let's leave that aside for the moment. Assume TDs are given the proposal at some point tomorrow. Pretend that despite the short notice they might have sufficient time to digest a complex area of law. Ignore the fact that citizens will be prejudiced by being denied the chance to adequately brief TDs. The point remains - a hurried debate on its own isn't sufficient.
Normally laws are made through a measured process where both the Dáil and the Seanad are given adequate time to scrutinise a Bill, identify weaknesses and pass amendments. It's clear that what Sean Sherlock proposes won't enable them to do that. Instead, TDs will be left impotent with the Dáil being treated as a talking shop, unable to make any changes to a document drafted behind closed doors.
(Incidentally, it also contradicts the minister's own Programme for Government which states that "The situation can no longer be tolerated where Irish Ministers enact EU legislation by statutory instrument. The checks and balances of parliamentary democracy are by-passed." I couldn't agree more.)
The need for greater transparency is obvious from a second remarkable development today. In a briefing note circulated to TDs and senators, Séan Sherlock has confirmed that his proposals go even further than we had thought, and respond to the music industry demands in the EMI v. UPC case:
If you're worried by these proposals and want to see an open and transparent discussion take place then please support the campaign at StopSOPAIreland.com.
First of all, junior minister Sean Sherlock said on lunchtime radio that he intends to hold an emergency Dáil debate on the law - within 24 hours no less! - and is happy to meet with me and other representatives of StopSOPAIreland.com to discuss it. While I'm glad to see that he's softened his position, it's remarkable that he still hasn't published the text of his proposals and doesn't show any signs of doing so. Consequently, I'm not sure what there is to discuss or what he expects the Dáil to debate. Asking TDs to have a debate in the dark about a document they haven't seen doesn't show much respect for Parliament.
But let's leave that aside for the moment. Assume TDs are given the proposal at some point tomorrow. Pretend that despite the short notice they might have sufficient time to digest a complex area of law. Ignore the fact that citizens will be prejudiced by being denied the chance to adequately brief TDs. The point remains - a hurried debate on its own isn't sufficient.
Normally laws are made through a measured process where both the Dáil and the Seanad are given adequate time to scrutinise a Bill, identify weaknesses and pass amendments. It's clear that what Sean Sherlock proposes won't enable them to do that. Instead, TDs will be left impotent with the Dáil being treated as a talking shop, unable to make any changes to a document drafted behind closed doors.
(Incidentally, it also contradicts the minister's own Programme for Government which states that "The situation can no longer be tolerated where Irish Ministers enact EU legislation by statutory instrument. The checks and balances of parliamentary democracy are by-passed." I couldn't agree more.)
The need for greater transparency is obvious from a second remarkable development today. In a briefing note circulated to TDs and senators, Séan Sherlock has confirmed that his proposals go even further than we had thought, and respond to the music industry demands in the EMI v. UPC case:
"to prevent infringement of the record companies’ sound recording copyright, through... internet “peer-to-peer” services, possibly involving a 'three strikes and you’re out' scenario. This is where the ISP sends three warnings of increasing severity and if the infringement continues, discontinues access to the Internet. It is sometimes referred to as a 'graduated response'."In short, the proposals aren't simply about website blocking, but could also allow courts to require ISPs to introduce three strikes systems. It's surprising and disappointing that this is happening now - after the Data Protection Commissioner has shown the unreliability of these systems by taking proceedings against Eircom for wrongly threatening innocent users with disconnection - and truly remarkable that the department seems content with the possibility for such systems to be introduced at the discretion of judges with no legislative controls.
If you're worried by these proposals and want to see an open and transparent discussion take place then please support the campaign at StopSOPAIreland.com.
Tuesday, January 24, 2012
Anonymous attacks on Ireland will hurt, not help the case against blocking
My heart sank when I saw this tweet a few minutes ago:
Until now the Irish campaign against internet blocking proposals has been remarkably effective at getting the issue onto the public and political agenda. With the help of the StopSOPAIreland site, the proposed law has shot from almost no public awareness to national prominence in just a few days, and has seen some Irish politicians genuinely engaging with our concerns. It also is giving many Irish netizens a grounding in political advocacy, something that will help as we confront more of these issues in future.
The Anonymous attacks, if they go ahead, will jeopardise this - making it easier for the music industry to spin critics as criminals, and giving unsympathetic politicians an easy, crowd pleasing reason to ignore the campaign. If the headlines shift from "New law threatens civil liberties" to "Hackers attack Irish government websites" then we will be on the back foot, jeopardising what's been achieved to date.
I don't think Anonymous tend to reconsider their targets once chosen. But if they do, now would be a good time to rethink the Irish attack.
Leave aside, for a moment, the inconvenience and disruption this will cause people trying to make use of government sites, the cost of responding and the controversial question whether denial of service attacks are legitimate as a type of civil disobedience. Quite apart from all these points, the action will do nothing to advance the Anonymous goals.Ireland has angered the hive, we will be reporting all attacks through this account | #OpIreland #OpMegaUpload
— Anonymous (@YourAnonNews) January 24, 2012
Until now the Irish campaign against internet blocking proposals has been remarkably effective at getting the issue onto the public and political agenda. With the help of the StopSOPAIreland site, the proposed law has shot from almost no public awareness to national prominence in just a few days, and has seen some Irish politicians genuinely engaging with our concerns. It also is giving many Irish netizens a grounding in political advocacy, something that will help as we confront more of these issues in future.
The Anonymous attacks, if they go ahead, will jeopardise this - making it easier for the music industry to spin critics as criminals, and giving unsympathetic politicians an easy, crowd pleasing reason to ignore the campaign. If the headlines shift from "New law threatens civil liberties" to "Hackers attack Irish government websites" then we will be on the back foot, jeopardising what's been achieved to date.
I don't think Anonymous tend to reconsider their targets once chosen. But if they do, now would be a good time to rethink the Irish attack.
Monday, January 23, 2012
Ireland's SOPA: A FAQ
What's this all about?
Long story short: the Irish government plans, before the end of January, to bring in a law which would allow Irish courts to block access to websites accused of infringing copyright (and possibly do other things as well).
Isn't that a short time for parliament to examine it?
The Irish parliament won't have a chance to debate it before it's passed. The law is to be brought in by a statutory instrument, something which requires only the stroke of a minister's pen.
Who's responsible?
The law is the responsibility of the Department for Jobs, Enterprise and Innovation where the key person is junior minister Sean Sherlock.
What will the law say?
We don't have a final text yet. But the key part is likely to be similar to a previous draft which said:
Certainly. This will give the Irish courts an open-ended power to grant orders against ISPs and other intermediaries who provide facilities which might be used to infringe copyright. This could include hosting providers, social networks, forums, video hosting sites - potentially most online services.
What will these intermediaries be required to do?
We don't know. At a minimum this will probably allow courts to require ISPs to block access to alleged infringing sites (such as The Pirate Bay). Over and above that it becomes impossible to say - the language is so vague it might, for example, allow a court to require an ISP to introduce a three strikes system or to block certain ports. However, once copyright plaintiffs get hold of this power you can expect it to be pushed to its absolute limit.
So who will pay for this?
We don't know. It is possible, under this draft, that the intermediaries will have to pay for both the legal costs of the court application and also the running costs of whatever they are ordered to do - for example, the staff costs of receiving and administering block lists. In that case, expect costs to be passed on to the end user.
Will the sites to be blocked have a right to be heard?
Maybe. The draft language does say that affected third parties might be given notice of applications to block them. On the other hand, in 2009 an Irish High Court judge was happy to allow Eircom to block The Pirate Bay without any notification or chance to be heard which doesn't bode well for the future.
What sort of standard will be used to decide if a site should be blocked?
Your guess is as good as mine - the draft is completely silent on this point.
Isn't this rather vague?
Yes. By failing to provide any real detail, the proposed law leaves the future of the Irish internet essentially in the discretion of Irish judges.
Could this harm Irish industry?
Yes - including the latest push to establish Ireland as a centre for cloud computing. Here's what tech journalist Adrian Weckler had to say:
Tumbleweed.
Would this vagueness breach the European Convention on Human Rights?
Quite possibly.
If nothing else will it at least stop illegal downloads and protect Bono's pocketbook?
No. Blocking is easily circumvented. But don't take my word for it - here's what UK regulator Ofcom had to say:
In a 2010 decision the High Court held that European law required Ireland to introduce blocking into domestic law, and that Ireland was in breach by failing to provide for court ordered blocking.
Doesn't that decision mean that blocking must be introduced?
Maybe. The law in this area is extremely complex, particularly since the European Court of Justice has given an important decision restricting the use of blocking in the meantime. That decision found that filtering would be impermissible if it undermined freedom of expression and blocked lawful communications - something that is inevitable if this proposal is adopted.
From a practical point of view, the European Commission - which monitors implementation of EU law - doesn't seem to think Ireland is in breach and hasn't taken any action against Ireland for failure to introduce blocking. Irish telecoms group ALTO have also put forward a different view arguing that this law is unnecessary.
However, even if we assume that EU law does require some form of blocking then it should not be introduced in a way which
If you live in Ireland and you want to stop this proposal then you should let Sean Sherlock (email) (twitter @seansherlocktd), the senior minister Richard Bruton (email) and your TDs what you think of it. Phone their offices if you can - one phone call will outweigh 20 emails.
StopSOPAIreland.com has more you can do.
If you live outside Ireland, you might still email Richard Bruton and Sean Sherlock to let them know the effect this will have on Ireland's reputation as a place to set up technology businesses.
One more thing - is it really true that the music industry wants the Irish taxpayer to pay for supposedly lost sales?
Yes. I hope you brought your wallet.
Long story short: the Irish government plans, before the end of January, to bring in a law which would allow Irish courts to block access to websites accused of infringing copyright (and possibly do other things as well).
Isn't that a short time for parliament to examine it?
The Irish parliament won't have a chance to debate it before it's passed. The law is to be brought in by a statutory instrument, something which requires only the stroke of a minister's pen.
Who's responsible?
The law is the responsibility of the Department for Jobs, Enterprise and Innovation where the key person is junior minister Sean Sherlock.
What will the law say?
We don't have a final text yet. But the key part is likely to be similar to a previous draft which said:
3. The Act of 2000 is hereby amended by the insertion of the following subsection after subsection (5) of section 40:
(5A)(a) without prejudice to subsections (3) and (4), the owner of the copyright in the work concerned may apply to the High Court for an injunction against a person who provides facilities referred to in subsection (3) where those facilities are being used by one or more third parties to infringe the copyright in that work.
Can we have that in English please?(b) In considering an application for an injunction under this subsection, the court shall have due regard to the rights of any third party likely to be affected and the court shall make such directions (including, where appropriate, a direction requiring a third party to be put on notice of the application) as the court may deem necessary or appropriate in all the circumstances.
Certainly. This will give the Irish courts an open-ended power to grant orders against ISPs and other intermediaries who provide facilities which might be used to infringe copyright. This could include hosting providers, social networks, forums, video hosting sites - potentially most online services.
What will these intermediaries be required to do?
We don't know. At a minimum this will probably allow courts to require ISPs to block access to alleged infringing sites (such as The Pirate Bay). Over and above that it becomes impossible to say - the language is so vague it might, for example, allow a court to require an ISP to introduce a three strikes system or to block certain ports. However, once copyright plaintiffs get hold of this power you can expect it to be pushed to its absolute limit.
So who will pay for this?
We don't know. It is possible, under this draft, that the intermediaries will have to pay for both the legal costs of the court application and also the running costs of whatever they are ordered to do - for example, the staff costs of receiving and administering block lists. In that case, expect costs to be passed on to the end user.
Will the sites to be blocked have a right to be heard?
Maybe. The draft language does say that affected third parties might be given notice of applications to block them. On the other hand, in 2009 an Irish High Court judge was happy to allow Eircom to block The Pirate Bay without any notification or chance to be heard which doesn't bode well for the future.
What sort of standard will be used to decide if a site should be blocked?
Your guess is as good as mine - the draft is completely silent on this point.
Isn't this rather vague?
Yes. By failing to provide any real detail, the proposed law leaves the future of the Irish internet essentially in the discretion of Irish judges.
Could this harm Irish industry?
Yes - including the latest push to establish Ireland as a centre for cloud computing. Here's what tech journalist Adrian Weckler had to say:
With their billions of users, YouTube, Facebook and Twitter inherently find some copyright protected material leaked onto their web services. The new law will give music and movie firms the legal footing to get ISPs blocking. That may not go down too well with Google and Facebook, which are two of Dublin's biggest employers. It probably won't sit easily, either, with the IDA, which may have to alter its pitch to large US social media firms who may have been thinking of setting up in Ireland. (That includes Twitter.)So where's the Regulatory Impact Assessment? Surely we need more detail about the impact this law will have?
Tumbleweed.
Would this vagueness breach the European Convention on Human Rights?
Quite possibly.
If nothing else will it at least stop illegal downloads and protect Bono's pocketbook?
No. Blocking is easily circumvented. But don't take my word for it - here's what UK regulator Ofcom had to say:
For all blocking methods circumvention by site operators and internet users is technically possible and would be relatively straightforward by determined users.So why is the government pushing this law now?
In a 2010 decision the High Court held that European law required Ireland to introduce blocking into domestic law, and that Ireland was in breach by failing to provide for court ordered blocking.
Doesn't that decision mean that blocking must be introduced?
Maybe. The law in this area is extremely complex, particularly since the European Court of Justice has given an important decision restricting the use of blocking in the meantime. That decision found that filtering would be impermissible if it undermined freedom of expression and blocked lawful communications - something that is inevitable if this proposal is adopted.
From a practical point of view, the European Commission - which monitors implementation of EU law - doesn't seem to think Ireland is in breach and hasn't taken any action against Ireland for failure to introduce blocking. Irish telecoms group ALTO have also put forward a different view arguing that this law is unnecessary.
However, even if we assume that EU law does require some form of blocking then it should not be introduced in a way which
- short circuits the democratic process and without proper scrutiny by the Irish parliament; and
- introduces intolerable uncertainty for Irish online businesses and fundamental rights.
If you live in Ireland and you want to stop this proposal then you should let Sean Sherlock (email) (twitter @seansherlocktd), the senior minister Richard Bruton (email) and your TDs what you think of it. Phone their offices if you can - one phone call will outweigh 20 emails.
StopSOPAIreland.com has more you can do.
If you live outside Ireland, you might still email Richard Bruton and Sean Sherlock to let them know the effect this will have on Ireland's reputation as a place to set up technology businesses.
One more thing - is it really true that the music industry wants the Irish taxpayer to pay for supposedly lost sales?
Yes. I hope you brought your wallet.
Sunday, January 22, 2012
"Ireland's SOPA" will be vague and open-ended
[23.01.12 Hello Redditors! Here's a FAQ with more information.]
Adrian Weckler has a worrying piece on government proposals for blocking legislation in today's Sunday Business Post (paywalled). I've taken the liberty of extracting some of the highlights:
This ambiguity - as well as jeopardising fundamental rights - will create intolerable uncertainty for businesses such as Google who might find themselves at risk of business threatening and unpredictable injunctions and will certainly deter others from setting up in Ireland.
Instead, any action should only take place by primary legislation which the Oireachtas would have a chance to scrutinise and debate. As I said previously in a letter on behalf of Digital Rights Ireland:
Adrian Weckler has a worrying piece on government proposals for blocking legislation in today's Sunday Business Post (paywalled). I've taken the liberty of extracting some of the highlights:
Is Ireland about to introduce a law that will allow music companies to order Internet service providers to block access to websites? I rang up the Minister of State at the department of Enterprise, Jobs and Innovation, Sean Sherlock, to find out. "The statutory instrument to be introduced is completely different to Sopa [Stop Online Piracy Act] in America" he told me. "We are simply addressing the High Court judgment handed down by Mr Justice Peter Charleton in relation to copyright law... I will introduce this imminently, by the end of January." That's a yes, then ...The clear implication from that interview with Sean Sherlock is that the proposed measures will be lacking in any real detail, leaving it entirely up to the judges as to what types of blocking might emerge. (Possibly going beyond web blocking to also target hosting and other services.)
The Irish governments new “statutory instrument” threatens to do some of the same things as Sopa, mainly introducing the power to force ISPs to block websites suspected of having copyrighted material on them.
While that means curtains for the Pirate Bay (which few people here will miss), it also leaves open the possibility for a judge to order ISPs to block YouTube, Facebook and Twitter.
Why? Because, with their billions of users, YouTube, Facebook and Twitter inherently find some copyright protected material leaked onto their web services. The new law will give music and movie firms the legal footing to get ISPs blocking. That may not go down too well with Google and Facebook, which are two of Dublin's biggest employers. It probably won't sit easily, either, with the IDA, which may have to alter its pitch to large US social media firms who may have been thinking of setting up in Ireland. (That includes Twitter.)
Given the seismic nature of the proposed change to Irish internet access, surely more detailed primary legislation would be in order here? For example, could there be a limit to enforcement of the injunctions? What defences might be available? Could there be exceptions? "We will probably need a test case to come before the courts before primary legislation such as that could be considered," said Sherlock. In other words: don't look at us, guv. We may be the government, but this kind of law-making is really a matter for judges. We don't really do that kind of thing ...
Politically, this is a no-win scenario. Even with the government about to open the legal doors for the music and movie companies to start directing ISPs' access policies, the content creation industry is frothing and fuming. Ironically, by taking a leave-it-to-m'lud approach, the government is also now attracting the anger of an increasing tranche of the technology and digital community. It is unusual to alienate both sides of a legislative argument ...
So this really is turning out to be a lose-lose episode for the government. Yet the issue wields vast significance for both sides of the debate (the music industry and the digital technology industry). It could also have profound, long-lasting consequences for Irish industry.
This ambiguity - as well as jeopardising fundamental rights - will create intolerable uncertainty for businesses such as Google who might find themselves at risk of business threatening and unpredictable injunctions and will certainly deter others from setting up in Ireland.
Instead, any action should only take place by primary legislation which the Oireachtas would have a chance to scrutinise and debate. As I said previously in a letter on behalf of Digital Rights Ireland:
It is significant that Charleton J. in EMI v. UPC [2010] IEHC 377 referred to any legislative intervention being properly a matter for the Oireachtas. The Opinion of the Advocate General in Scarlet (Extended) v. SABAM (Case C-70/10) similarly referred to a need for legislation in this area to be "democratically legitimised" (at para. 113).Although it's the 11th hour, it's not too late for the Irish government to see sense and abandon this proposal. If you agree then you should let Sean Sherlock and your TDs what you think of it.
It would be undesirable in any event for a matter dealing with fundamental rights to be disposed of by way of secondary legislation. It is all the more undesirable in this case, however, given the vague and open-ended nature of the powers involved. This is, in effect, a case of delegation heaped on delegation - rather than rules governing blocking and other remedies being made by primary legislation, or even secondary legislation, they are instead effectively being made by delegation to the judiciary.
Subscribe to:
Posts (Atom)
