Saturday, January 29, 2011

The ISPAI are looking for a legal intern

This looks like an interesting job for a newly-minted law graduate:
ISPAI – The Internet Service Providers Association of Ireland Limited

ISPAI is the Industry Association that represents businesses operating in Ireland that provide publicly available Internet infrastructural and electronic services to customers both in Ireland and abroad. The Association deals with regulatory and legal issues which potentially impact the ISP business environment and affect all our members (see: www.ispai.ie). As part of this, ISPAI coordinates ISP industry self-regulation, administers the industry code of practice and ethics and runs the Hotline.ie service which supports ISPAI members to comply with Irish/EU law to respond to notices of illegal content and to assist international cooperation in this area.

ISPAI offers an intern opportunity for a post-graduate legal student who has a specific interest in the area of telecommunications and digital media law. This is a highly dynamic area with many new initiatives emerging as legislators, law enforcement and various lobbying groups realise the ubiquitous nature of the Internet and its role in shaping modern society. This is a unique opportunity to gain experience and to work with leading companies in the industry. It is strongly recommended for those intending to practise in this area.

It is intended that the selected Intern will follow proposed measures, draft legislation and other issues potentially affecting the ISP industry which are being developed at EU and national level. They will be expected to liaise with the EuroISPA secretariat in Brussels (see: www.euroispa.org) and ISP organisations. The internship will entail European travel to selected meetings or conferences

The Intern will be expected to undertake research on the issues they will be assigned to monitor and write briefings for the internal information of ISPAI secretariat and members. They will also work closely with ISPAI staff to promote our views through our websites and develop press releases.

The internship will be of at least 9 months duration. It will be based in our offices located opposite the Sandyford Luas station in South Dublin. Working within the small ISPAI team, the Intern will report to the ISPAI General Manager. They will be expected to work at least three days per week. The position offers good opportunities for self-development and interaction with international counterparts.

The successful applicant must demonstrate:

• A reasonable knowledge of using various Internet services (web, peer to peer, etc.) and methods used in web based services and be proficient using Microsoft Office products such as Word, Powerpoint and Excel.
• Familiarity with the legal issues surrounding the internet in Ireland, such as the E-Commerce Directive, online defamation and/or "three strikes" and similar systems. The successful applicant must have a law degree and is likely to have taken at least one module covering related issues.
• Good verbal, presentation and writing skills which are essential. Proficiency in a major European language in addition to English would be an advantage.
• A diligent and accurate approach to completing tasks and an ability to work to deadlines with minimal supervision.

Training on technical principles of Internet communications and digital content distribution will be given. Please note: this internship will involve possible exposure to information relating to assessments of potentially illegal pornographic imagery and other content, within the context of ISPAI Hotline.ie operations. This is indemnified under strict procedures agreed with Government and overseen by the Department of Justice and Law Reform, Office for Internet Safety (www.internetsafety.ie) and approved by An Garda Síochána.

Expenses will be given for travel, accommodation and subsistence for approved work-related activities outside the office and a nominal stipend will be available.

Please provide by email to legalintern2011@ispai.ie, your CV and a covering letter of no more than one A4 page explaining why you should be awarded the Internship.

Closing date for applications: Tuesday 15th February 2011.

Saturday, January 22, 2011

Finance Bill taxes internet betting sites - will this lead to blocking of offshore sites?

In my last post I looked at the possible implications of the Finance Bill for Irish computer crime and data protection laws. I missed, however, another important aspect of the Bill, which is that it will extend betting duty to internet betting sites. (In my defence, I didn't read all 223 pages of the Bill and don't plan to do so any time soon. The relevant provision is s.46, at p.186.)

According to the Taoiseach, this extension of duty will be matched by a new requirement that offshore providers obtain a licence to offer their services in Ireland:
The Government will introduce legislation to ensure that overseas betting providers comply with a licensing regime that will permit them to sell their products into our jurisdiction.
So what happens if the offshore providers decide not to play ball? It might not be a coincidence that the Department of Justice has been considering the introduction of internet filtering for some time now - and officials in the Department's Gaming Control section have been taking part in this discussion (PDF released under FOI - see item 49). I can't help but suspect that there will be calls for ISPs to block access to offshore sites which don't pay this new tax - and there have been some European developments in this direction already.

Watch this space.

Friday, January 21, 2011

Finance Bill 2011 - impact on Irish data protection and computer crime law

I'm indebted to Rossa McMahon and Daragh O'Brien for pointing out (via Twitter) two interesting provisions in the Finance Bill 2011 (PDF).

Section 71 creates a new revenue offence of possessing or using computer tools for the purpose of evading tax:
71.—Section 1078 of the Principal Act is amended in subsection (2), by inserting the following after paragraph (b): "(ba) knowingly or wilfully possesses or uses, for the purpose of evading tax, a computer programme or electronic component which modifies, corrects, deletes, cancels, conceals or otherwise alters any record stored or preserved by means of any electronic device without preserving the original data and its subsequent modification, correction, cancellation, concealment or alteration,
(bb) provides or makes available, for the purpose of evading tax, a computer programme or electronic component which modifies, corrects, deletes, cancels, conceals or otherwise alters any record stored or preserved by means of any electronic device without preserving the original data and its subsequent modification, correction, cancellation, concealment or alteration,".
This would appear to cover a wide range of software and hardware, including encryption and steganography software and secure deletion tools. (Though not the encryption of the Anglo files, unless it could be shown that those files were encrypted for the purpose of evading tax.)

Section 73, meanwhile, creates what is in effect a parallel data protection system for the Revenue. Although too long to quote in full, an interesting aspect is that it creates a new offence of unauthorised disclosure of information:
(2) All taxpayer information held by the Revenue Commissioners or a Revenue officer is confidential and may only be disclosed in accordance with this section or as is otherwise provided for by any other statutory provision.

(3) Except as authorised by this section, any Revenue officer who knowingly—
(a) provides to any person any taxpayer information,
(b) allows to be provided to any person any taxpayer information,
(c) allows any person to have access to any taxpayer information, or
(d) uses any taxpayer information otherwise than in the course of administering or enforcing the Acts,

shall be guilty of an offence and shall be liable —
(i) on summary conviction to a fine of €3,000, and
(ii) on conviction on indictment to a fine of €10,000.
I wonder whether this amendment may have been prompted by the publicity attached to these recent examples of wrongdoing by Revenue staff.

Wednesday, January 19, 2011

Cloud computing complications costing Celtic companies

The lack of an appropriate regulatory environment, standard due-diligence checklists, and standard SLAs are an economic barrier to vibrant young technology companies providing cloud-based technology solutions to enterprises that need a greater level of protection than is currently on offer. The costs of developing such offerings and dealing with due-diligence queries and contract negotiations may be beyond the financial resources of a start-up.

Professional service providers who wish to avail of the efficiencies of cloud services may decide that they are not equipped to conduct due diligence or agree SLAs without the help of specialist consultants. This is an impediment to Irish businesses reducing their costs and increasing their competitiveness through the adoption of cloud technologies.
Reamonn Smith (solicitor and member of the Law Society's Technology Committee) argues for "a clearer regulatory and legal environment" in relation to cloud computing in the Law Society Gazette (PDF, p.24).

Friday, January 14, 2011

Data breach notification - ENISA study released

ENISA - the European Network and Information Security Agency - has just published a study (PDF) on data breach notification. The research was carried out as part of the process of implementing the notification requirement in the revised e-Privacy Directive, and aims to develop consistent guidelines throughout Europe for the technical and procedural issues surrounding breach notification. Some highlights from the summary (text in [brackets] is my own interlineation):
[Views of telecoms operators]

The telecommunications sector recognises that data breach notifications have an important role in the overall framework of data protection and privacy. Nevertheless, operators are seeking support and guidance on an EU and local level over a number of issues, which if clarified, would better enable European service providers to comply effectively with data breach notification requirements. Key concerns raised by telecom operators include the following:

● Risk prioritisation – The seriousness of a breach should determine the level of response. In order to prevent ‘notification fatigue’ for both the operator and the data subjects, breaches should be categorised according to specific risk levels.

● Communication channels – Operators want assurances that notification requirements will not negatively impact their brands. It is important for operators to maintain control of communications with relevant data subjects, as much as possible, to ensure that operators can effectively manage any impact on brand perception brought about by the data breach and subsequent notification.

[If operators want to avoid negative impact on their brands it might be more productive to avoid data breaches in the first place.]

● Support – In preparation for mandatory notification requirements, operators are looking for support in terms of guidance on procedures. In particular, guidance should provide a methodology for categorising types of private data and combinations of private data, as well as how to proceed with notifications based on the level of risk attributed to each breach.

[Views of Data Protection Authorities]


Data protection authorities (DPAs) take varied approaches to enforcing data protection and privacy. Some follow EC Directives closely, while others take on additional responsibilities beyond those outlined in the Directives. Although there are exceptions, the majority of DPAs surveyed in this study support mandatory notifications for telecom operators. Those that did not support mandatory notifications mostly indicated that budgetary limitations were a key factor in influencing their opinion. As notifications are not yet mandatory in most countries, regulatory authorities have little experience in handling notifications. Since regulatory authorities have a number of responsibilities, there are concerns that additional duties must not interfere with pre-existing responsibilities. Notifications are not viewed as a number one priority for most authorities. A smooth transition to mandatory notifications will consequently depend on a resolution to a number of factors, outlined here:

● Resources – Budgetary allocations for regulatory authorities should reflect new regulatory responsibilities. Concern has been raised that resources at some regulatory authorities are already occupied with other priorities. Bandwidth for additional responsibilities is limited.

● Enforcement – DPAs indicated that sanctioning authority enables them to better enforce regulations. Data controllers will be less incentivised to comply with regulations if regulatory authorities do not have sufficient sanctioning powers. Some authorities indicated that financial penalties are seen as the most effective tool for pressuring data controllers to comply, while others indicated that public criticism and black lists could be effective too.

● Relevant authorities – Local legislation will determine who the relevant authority is for regulating data breach notifications in the telecommunications sector, when mandatory notification requirements are transposed into local legislation. Although many data protection authorities indicated they are communicating effectively with other authorities already, it is important for legislation to clearly delineate relevant responsibilities, in order to mitigate or prevent potential conflicts.

● Technical expertise – In some cases, businesses have a high level of technical sophistication, which allows them potentially to conceal valuable information regarding breaches from regulatory authorities, which do not have comparable resources and expertise. Hiring new staff with relevant expertise is important in order for regulatory authorities to remain effective.

● Awareness raising – A high public profile is an important element in demonstrating the influence of regulatory authorities. A common strategy in communicating the importance of data protection to the public could be useful in better educating data subjects about their privacy rights, and the role of notifications in the overall framework of data protection.

[Areas of conflict]


Smooth implementation of data breach notification procedures requires close cooperation between data controllers at the service providers and the relevant regulatory authorities. While most operators and regulatory bodies surveyed recognise the importance of notifications, there are a number of issues where interests of the parties involved might conflict.

● Undue delay – Regulatory authorities want to see a short deadline for reporting breaches to authorities and data subjects, in order to prevent controllers from concealing evidence and also to give data subjects ample time to protect themselves. Service providers, however, want their resources to be focused on identifying if the problem is serious and solving the problem, instead of spending time reporting details, often prematurely, to regulatory authorities.

[This is an important point which is sometimes overlooked. In some breaches - such as those of credit card details - it will be essential that individuals be notified immediately so that they can e.g. cancel cards. Other breaches - such as those of healthcare information - may be just as serious but aren't likely to be as time sensitive. However, the fact that the affected individuals may not need to be notified immediately must not become an excuse for failure to notify the relevant DPA as soon as possible.]

● Traffic monitoring – Private data belonging to employees or customers running over a corporate network remain a challenging issue for both regulatory authorities and operators. Telecom operators are often requested to monitor and analyse traffic data on behalf of their customers, particularly in cases where companies want to monitor the actions of their employees. In this context, regulatory authorities see traffic monitoring as a privacy risk, due to the fact that employers may be exchanging private information on the corporate network, to which the employers would then have access.

● Content of notifications – The content of the notifications can have a direct impact on customer relations and retention. Operators want to make sure that the content of the notifications does not impact negatively on customer relations. Regulatory authorities, however, want to see that the notifications provide the necessary information and guidance in line with the rights of the data subjects.

● Audits – One service provider indicated that it performed its own security audits internally, with the aim of detecting and solving any potential vulnerabilities that could result in data breaches. The operator believed that its internal expertise were sufficient to ensure it was using the latest techniques for securing data and compliance with regulations, suggesting its expertise surpassed that of the national regulatory authorities. Regulatory authorities, however, indicated that their ability to perform audits and spot checks provides the authority necessary to enforce compliance.

[Extension of notification to other sectors]


While the recent telecoms reforms make notifications mandatory for telecom operators, there remains ongoing debate about extending mandatory notifications to other sectors.

● Telecommunications operators: In comparison to other sectors, regulatory authorities indicated that telecommunications operators ranked high in terms of their security measures and ability to limit data breaches.

Telecom operators have at their disposal some of the top networking, communications and security experts. But this is true mostly for the larger operators. Smaller alternative operators and local ISPs do not necessarily have resources comparable to the large international companies and incumbent operators.

● Finance sector: Finance institutions are considered to be at great risk, due to the sensitive nature of the data they possess. Nonetheless, financial institutions are already subject to regulations across Europe, with regulations being enforced by various bodies, including central banks. Consequently, extending data breach requirements to financial institutions would require careful coordination with other responsible authorities, which may already require incidents of data breaches to be reported.

● Healthcare: Data protection authorities regularly pointed to the healthcare sector as an area of high risk. Due to the large amount of very sensitive private data stored on doctors’ and nurses’ laptops, which are often unencrypted, there is high risk for exposure or leaks.

● Small businesses: Small businesses pose a major challenge. Collectively, they have a lot of personal data, but individually they do not have resources or know-how to secure their data. Due to the sheer number of small businesses, regulation would prove challenging. Educating and making businesses aware would require significant efforts and resources. As more and more small businesses develop online strategies, the risk for exposure is increasing.

Thursday, January 13, 2011

Job opportunity: Privacy and surveillance

I received a very interesting job opportunity in my inbox this morning, which might be of interest to some readers of this blog:
Senior Research Analyst

Trilateral Research & Consulting, a London-based consultancy, specialising in research and the provision of strategic, policy and regulatory advice on new technologies, privacy, trust, surveillance, risk and security issues is seeking to engage a Senior Research Analyst to work on one or more new projects. Specific duties of the position include:

  • Performing research work related to current projects, writing reports or sections of reports and developing other deliverables as required to fulfil contractual obligations.
  • Researching and writing content for grant proposals and tender submissions.
  • Writing content for peer-reviewed journal articles and book chapters, as part of projects, or as an outgrowth from projects.
  • Attending and/or presenting at some project-related meetings, involving some level of travel outside the UK.

 Preferred candidates will be based in the UK, will have English as their native language and will have recently completed a PhD in an area of study related to security, privacy, data protection, surveillance or a related field.

Contact:
David Wright
Managing Partner
Trilateral Research & Consulting
www.trilateralresearch.com
david.wright@trilateralresearch.com

or

Kush Wadhwa
Senior Partner
Kush.wadhwa@trilateralresearch.com

Friday, December 17, 2010

Firms hampered by failure to keep law up to date with internet age

I have an opinion piece in today's Irish Times arguing that the Taoiseach's recent comments about reform of copyright law create an opportunity for wider reform. Unfortunately, the Irish Times doesn't allow inline links, so here's a version with relevant links included:
Firms hampered by failure to keep law up to date with internet age

Much of the Irish law governing the internet is archaic, restrictive and hampers growth, writes TJ McIntyre

IN A speech this week, the Taoiseach announced support for a review of European and Irish copyright law, stating “it is time to review our copyright legislation, and examine the balance between the rights holder and the consumer, to ensure that our innovative companies operating in the digital environment are not disadvantaged against competitors”.

This is a welcome development for the Irish internet industry, which has argued for some time that copyright reform would be desirable.

It follows a seminar last month, hosted by Digital Rights Ireland, Google and the Institute of International and European Affairs, where speakers from businesses such as Boards.ie, UPC and Google pointed out the practical problems copyright laws can create.

In particular, one of the reasons why the US has been so successful at encouraging internet innovation is that US copyright law includes a doctrine known as fair use. This permits the use of portions of a copyrighted work so long as the normal economic exploitation of the work is not undermined.

Irish law, by comparison, has no equivalent to the flexible doctrine of fair use.

Instead, there is a finite and restrictive list of exceptions to copyright, hampering the ability of Irish businesses to develop new forms of internet services.

Reform of the law – if it addresses this and similar issues – will help promote the growth of new businesses in this area and avoid the loss of jobs to more internet-friendly jurisdictions, such as the US.

However, this is not a uniquely Irish development. It follows action at European Union level and in other countries such as Britain. Last month, David Cameron said UK copyright laws were out of date and needed to be reviewed to “make them fit for the internet age”.

The Irish Government will have to move quickly to avoid falling behind Britain and other European bodies that have taken the initiative in this area.

It will also be important that copyright not be considered in isolation, as it is just one of a number of areas where Irish businesses have been hampered by a failure to keep the law up to date with the internet.

After a flurry of activity leading up to the Electronic Commerce Act 2000, there has been relatively little reform since.

Consequently, much of the Irish law governing the internet is now a decade old – an eternity in the online world – and is no longer suited for current conditions.

One of the most important areas in need of reform is defamation. A significant risk faced by Irish internet companies is that of being sued for what users say. Under the law as it stands, businesses such as online forums, auction sites and even search engines face a real likelihood of legal action being brought against them, even though they were in no way responsible for what was said and behaved reasonably.

European law does recognise the injustice of this, and provides some protection for these intermediaries. Ireland, however, has adopted a very limited implementation of this European law, so Irish online businesses are much more exposed than those in other jurisdictions.

Remarkably the Defamation Act 2009 ignored proposals for reform of the law in this area.

If the Taoiseach is to succeed in his stated aim of ensuring that Irish businesses are not disadvantaged against competitors, then it will be important to tackle online defamation also.

Wednesday, November 24, 2010

EU Internal Security Strategy Published

The Commission has just published an internal security strategy document setting out a four year plan for European level action on the issues of "fighting and preventing serious and organised crime, terrorism and cybercrime, strengthening the management of our external borders and building resilience to natural and man-made disasters."

While the entire plan is likely to be controversial (and the sections on border control have already been criticised), I'd like to focus on the section on cybercrime and to offer a few thoughts:
Action 1: Build capacity in law enforcement and the judiciary

By 2013, the EU will establish, within existing structures, a cybercrime centre, through which Member States and EU institutions will be able to build operational and analytical capacity for investigations and cooperation with international partners. The centre will improve evaluation and monitoring of existing preventive and investigative measures, support the development of training and awareness-raising for law enforcement and judiciary, establish cooperation with the European Network and Information Security Agency (ENISA) and interface with a network of national/governmental Computer Emergency Response Teams (CERTs). The cybercrime centre should become the focal point in Europe's fight against cybercrime.

At national level, Member States should ensure common standards among police, judges, prosecutors and forensic investigators in investigating and prosecuting cybercrime offences. In liaison with Eurojust, CEPOL and Europol, Member States are encouraged by 2013 to develop their national cybercrime awareness and training capabilities, and set up centres of excellence at national level or in partnership with other Member States. These centres should work closely with academia and industry.
The recommendations for action at EU level are welcome, but unfortunately Ireland has a long way to go to meet the recommendations for action at national level. I've written about the failings in the Irish response to cybercrime recently in the Sunday Business Post.
Action 2: Work with industry to empower and protect citizens

All Member States should ensure that people can easily report cybercrime incidents. This information, once evaluated, would feed into national and, if appropriate, the European cybercrime alert platform. Building on the valuable work under the Safer Internet Programme, Member States should also ensure that citizens have easy access to guidance on cyber threats and the basic precautions that need to be taken. This guidance should include how people can protect their privacy online, detect and report grooming, equip their computers with basic anti-virus software and firewalls, manage passwords, and detect phishing, pharming, or other attacks. The Commission will in 2013 set up a real-time central pool of shared resources and best practices among Member States and the industry.

Cooperation between the public and private sector must also be strengthened on a European level through the European Public-Private Partnership for Resilience (EP3R). It should further develop innovative measures and instruments to improve security, including that of critical infrastructure, and resilience of network and information infrastructure. EP3R should also engage with international partners to strengthen the global risk management of IT networks.

The handling of illegal internet content – including incitement to terrorism – should be tackled through guidelines on cooperation, based on authorised notice and take-down procedures, which the Commission intends to develop with internet service providers, law enforcement authorities and non-profit organisations by 2011. To encourage contact and interaction between these stakeholders, the Commission will promote the use of an internet based platform called the Contact Initiative against Cybercrime for Industry and Law Enforcement.
Much of this is uncontentious, but the references to handling illegal internet content require careful scrutiny. The "guidelines on cooperation" and "notice and takedown procedures" reflect a worrying trend at EU level towards bringing about internet censorship by means of self-regulation. The result is that decisions about legality are being made in a way which doesn't have a legislative basis and excludes judicial oversight. This trend can already be seen in relation to internet filtering but this strategy, if implemented, would seem to extend it significantly further. It is hard to see how this proposal could be compatible with Article 10 of the European Convention on Fundamental Rights.
Action 3: Improve capability for dealing with cyber attacks

A number of steps must be taken to improve prevention, detection and fast reaction in the event of cyber attacks or cyber disruption. Firstly, every Member State, and the EU institutions themselves should have, by 2012, a well-functioning CERT. It is important that, once they are set up, all CERTs and law enforcement authorities cooperate in prevention and response. Secondly, Member States should network together their national/governmental CERTs by 2012 to enhance Europe's preparedness. This activity will also be instrumental in developing, with the support of the Commission and ENISA, a European Information Sharing and Alert System (EISAS) to the wider public by 2013 and in establishing a network of contact points between relevant bodies and Member States. Thirdly, Member States together with ENISA should develop national contingency plans and undertake regular national and European exercises in incident response and disaster recovery. Overall, ENISA will provide support to these actions with the aim of raising standards of CERTs in Europe.
The Irish CERT body (IRISS) does not have any state funding at present - will this recommendation encourage the Irish government to provide funding?

Wednesday, November 17, 2010

Legal issues for mobile marketing

Peppe Santoro of Eversheds O'Donnell Sweeney has just placed a very comprehensive and useful presentation on this topic on Slideshare:
Strongly recommended.

Friday, November 12, 2010

More developments on defence access to breathalyser source code

I've blogged before about whether a defendant in a drink driving charge is entitled to examine the source code to the breath testing machine, and there's been a High Court decision on this point since then, but this issue has recently cropped up yet again in the form of an interesting decision of the Information Commissioner.

In Case 080260 - Mr. W & The Medical Bureau of Road Safety (MBRS) the applicant sought to use a FOI request to the Medical Bureau of Road Safety to obtain (amongst other things) the source code relating to a "Lion Intoxilyzer 6000 IRL". The decision of the Information Commissioner addressed a number of important issues - including whether FOI could be used to "provide a parallel system whereby the defence could obtain what is in effect disclosure in a criminal case" - but in relation to the source code the Commissioner had this to say:
It is my understanding that the term "source code" refers to high level code, the disclosure of which would allow the development of competing products. I therefore accept that the source code at issue in this case qualifies as a trade secret within the meaning of section 27(1)(a) of the FOI Act. I also consider that, on balance, the public interest would not favour release, particularly if the testing, maintenance and repair records are made available. As Ms. Campbell stated, court procedures must be considered adequate to ensure the fairness of any criminal proceedings under the Road Traffic Acts.

I also accept that a duty of confidence would be owed to Lion Laboratories in the circumstances. Moreover, I note that evidence was submitted in the case stated by Judge Mary Devins in DPP v. O'Malley [2008] IEHC 117 to show that the MBRS is contractually prohibited from disclosing the source code to any third party. In the circumstances, I am satisfied that the source code is exempt under section 26(1)(b) as well as section 27(1)(a) of the FOI Act.
While this may be the correct result in the context of FOI, when taken together with the decision in DPP v. O'Malley it seems to leave defendants in drink driving cases with no effective means of challenging the inner workings of the machines used to convict them, and may potentially lead to an injustice. As a fundamental principle of law, if a person is to be convicted based on the "testimony" of a machine then that person should have the right to challenge the process by which the machine generates that "testimony" - something which may require inspection of the source code. As things stand however it seems that there's no route in Irish law for that to be done.

Wednesday, November 10, 2010

Advertising standards, the internet and "ghost and entity removal"

There was some publicity recently about the fact that the UK Advertising Standards Authority is to extend its remit to cover online advertising also. Surprisingly, however, there appeared to be very little awareness of the fact that the Advertising Standards Authority of Ireland has explicitly covered internet advertising since 2001. (Rather than 2009, as the Sunday Business Post suggested.)

To honour this long record of regulating internet advertising, I thought I'd share a recent ASAI decision on internet advertising- one which considered amongst other things "Shamanic Healing", "Angel Therapy" and - best of all - "Ghost and Entity Removal". The complaint related to an Irish website Seventh Heaven Healing and the variety of "spiritual" services it offered. According to the decision, "the complainant challenged all the claims in relation to distant healing and medical advice from the spirit world. He questioned the ability to arrange for divine intervention and requested that proof be provided for all claims."

Perhaps unsurprisingly, the ASAI wasn't persuaded by the website owner's claims that she could not prove her "claims on healing an individual without disclosing personal information about the people in question" and that "as a medical intuitive she uses her mediumship ability to help individuals remove energy blocks on an energetic scale". Consequently it ordered that "the advertisement must not run in its current format again".

As to how effective that ruling has been, judge for yourself at seventhheavenhealing.net. (Warning - autoplay saccharine music.) Or, if you're in a hurry, jump straight to the "Ghost and Entity Removal" page.

For a related ASAI ruling on "powerful energy over the phone" and "healing" in relation to cancer and "sick babies" see this decision.

Police access to encrypted files: Does the Anglo case show up a gap in the legislation?


According to today's Irish Independent the Anglo investigation is being held up by encrypted files:
Gardai are unable to examine more than 100 key files in their investigation into Anglo Irish Bank because former senior executives have not handed over the computer passwords.

Former Anglo staff hold passwords to about 200 documents vital to the inquiries being carried out jointly by the Garda Fraud Bureau and the Director of Corporate Enforcement.

The passwords for around a third of the encrypted documents have been produced so far by the bank. But Anglo admitted it has been unable up to now to secure the rest.

Among the former employees being contacted by Anglo to establish if they have knowledge of the missing passwords is its ex-chairman Sean FitzPatrick.

Gardai are using state-of-the-art technology to crack the password puzzle and are confident they will be able to gain access to all of the key documents.

But they indicated yesterday that the absence of the passwords was one of the factors which have delayed the completion of their inquiries.
In light of this story it might be worth considering the legal position governing police access to such files and whether or not the former bank officials mentioned might be compelled to assist in decrypting them.

Background

Irish law generally doesn't require disclosure of passwords or private keys to police - see e.g. section 28 of the Electronic Commerce Act 2000. (This is in contrast to the position in the UK, where there is a wide power to order key disclosure and it is an offence to fail to disclose - see here for an example of such an order.)

However, there are specific Garda powers under the Criminal Justice (Theft and Fraud Offences) Act 2001 which are relevant. Will they apply to the facts of this particular case?

Search warrants

The first power is contained in section 48 of the Act, which deals with search warrants and provides that:
A member of the Garda Síochána acting under the authority of a warrant under this section may—

(a) operate any computer at the place which is being searched or cause any such computer to be operated by a person accompanying the member for that purpose, and
(b) require any person at that place who appears to the member to have lawful access to the information in any such computer—

(i) to give to the member any password necessary to operate it,
(ii) otherwise to enable the member to examine the information accessible by the computer in a form in which the information is visible and legible, or
(iii) to produce the information in a form in which it can be removed and in which it is, or can be made, visible and legible.
Consequently search warrants under this section can have the effect of requiring individuals to provide passwords or to decrypt information (to provide it in a "visible and legible" form). However, this power wouldn't apply in the context of the Anglo investigation insofar as it only applies to any "person at the place which is being searched". Former bank employees who are sipping brandy at home can't be required to assist in the decryption process.

Evidence orders

At first glance, the section 52 power would appear to be more promising. That section provides that:
(2) A judge of the District Court, on hearing evidence on oath given by a member of the Garda Síochána, may, if he or she is satisfied that—

(a) the Garda Síochána are investigating an offence to which this section applies,
(b) a person has possession or control of particular material or material of a particular description, and
(c) there are reasonable grounds for suspecting that the material constitutes evidence of or relating to the commission of the offence,

order that the person shall—

(i) produce the material to a member of the Garda Síochána for the member to take away, or
(ii) give such a member access to it,

either immediately or within such period as the order may specify.

(3) Where the material consists of or includes information contained in a computer, the order shall have effect as an order to produce the information, or to give access to it, in a form in which it is visible and legible and in which it can be taken away.
As with the section 48 power, this includes a power to require a person to decrypt information (though not to require a person to provide a password or key). Again, however, it wouldn't seem to apply to former bank officials. The order to produce and/or decrypt evidential material applies where a person has certain material in their "possession or control". This wouldn't seem to stretch to the situation where the material - the file - is located on bank premises and as such isn't in the possession or control of the former bank official.

Other statutory powers?

Sections 48 and 52 of the 2001 Act are not the only statutory powers to provide for passwords to be handed over or information to be decrypted. Similar powers are contained in section 16 of the Proceeds of Crime Act 1996 (as amended by the Proceeds of Crime (Amendment) Act 2005) and several other pieces of legislation. However, these powers all appear to be modelled on the 2001 Act and consequently would fall foul of the same problems if applied to a person who is not at the scene or does not have possession or control of the material in question.

Conclusion

If this analysis is correct then there would seem to be a gap in the 2001 Act powers to require decryption - while a person can be compelled to decrypt material so long as they remain in employment in a particular organisation it would seem that once they leave then they are no longer subject to these powers.

Tuesday, November 09, 2010

Are Norwich Pharmacal orders compatible with the Data Retention Directive?

Interesting news from Sweden, where a court has made a preliminary reference to the ECJ which calls into question the use of information held under the Data Retention Directive to identify users accused of copyright infringement. According to a report in Intellectual Asset Management:
The request for a preliminary ruling was made by the Supreme Court in a copyright litigation case between five audiobook publishers, and Perfect Communication AB, an ISP. Before the case reached the Supreme Court, the audiobook companies had requested the district court to order Perfect Communication to reveal information regarding the name and address of the registered user of a certain IP address, who was suspected of infringing copyrights in a large number of popular audiobooks...

On 25th August 2010 the Supreme Court requested a preliminary ruling from the ECJ on two questions:

* Whether the Data Retention Directive prevents the application of a national rule based on the EU IP Rights Enforcement Directive (2004/48/EC), which provides that an ISP in a civil case can be ordered to provide a copyright owner or a rights holder with information on which subscriber holds a specific IP address assigned by the ISP, from which address the infringement is alleged to have taken place.
* Whether the answer to the first question is affected by the fact that the state has not yet implemented the Data Retention Directive, although the deadline for implementation has passed.
While the full text of the reference isn't available, the ISP's case seems to be based on the interaction between the ePrivacy Directive and the Data Retention Directive. In particular it appears to argue that data stored under the Data Retention Directive should only be made available to national authorities for the purposes of that Directive - not for other, unrelated purposes (such as civil actions against filesharing). If successful, the implications would be far reaching and would at the very least require the Irish and UK courts to revisit cases such as EMI v. Eircom which deal with Norwich Pharmacal orders identifying internet users.


(My thanks to Niall Handy for pointing out this case.)

Monday, October 11, 2010

EMI v. UPC - Full judgment now available

It's been a busy few days for copyright law in Ireland. First the important decision in Koger v. HWM, and now the landmark decision in EMI v. UPC (RTÉ | Irish Times), which derailed music industry plans to compel ISPs to introduce "three strikes" in Ireland.

I'm still digesting the 82 pages of the judgment, but in the meantime here's the full text for your delectation:

EMI v. UPC                                                            

Tuesday, September 21, 2010

Google Transparency Report launched


The New York Times has a story today about Google's new Transparency Report. The Report - which expands on an earlier initiative - tracks government intervention on the internet and shares internal data from Google in three broad categories:

* Government inquiries for information about users;
* Government requests to remove content (both hosted content and search results); and
* Traffic flows.

In each case the data is broken down by country. In relation to the UK, for example, the map shows that for the period January-June 2010 there were:

1343 data requests
48 removal requests, for a total of 232 items; and
62.5% of removal requests were fully or partially complied with

Blogger
o 1 court order to remove content
o 1 item requested to be removed

Video
o 3 court orders to remove content
o 32 items requested to be removed

Groups
o 1 court order to remove content
o 1 items requested to be removed

Web Search
o 8 court orders to remove content
o 144 items requested to be removed

YouTube
o 6 court orders to remove content
o 29 non-court order requests to remove content
o 54 items requested to be removed
There's no data given for Ireland for the same period. This may mean one of two things - either there were no Irish requests to take down information or access user information during that period, or else (probably more likely) there were so few Irish requests that Google has chosen not to reveal the statistics. For what it's worth, during the previous six month period Google indicates that there were fewer than 10 Irish government requests to remove content, of which 50% were complied with.

The traffic flow portion of the report is new and particularly interesting - by visualising the amount of data flowing to a particular country it graphically illustrates government attempts to block access to particular sites. Here, for example, is a graph of YouTube traffic to Turkey from March 2010 onwards. The abrupt drops in traffic appear to coincide with the Turkish government's ongoing attempts to block users from viewing YouTube and other Google services.

Google must be congratulated for providing this information - along with Herdict and Chilling Effects (which is also supported by Google) the information provided will be invaluable in tracking attempts to control the flow of information on the net. However, as Lilian Edwards and Christopher Soghoian have pointed out this is still only a start - greater detail as to the types of content being targeted and the legal basis for requests is necessary to make sense of the raw numbers. Perhaps in the next revision?

Friday, September 10, 2010

Monitoring online radicalisation

I was at the fascinating Terrorism and New Media conference in DCU yesterday taking part in a panel discussion "Monitoring the Internet for Violent Radicalisation: Ethical and Legal Issues", along with Mina al Lami (LSE), Paul Durrant (ISPAI) and Sadhbh McCarthy (Centre for Irish and European Security).

The discussion was under the Chatham House Rule so I won't be putting names to views, but the other panelists and the audience had some interesting perspectives which I thought worth jotting down.

There was a definite concern that anti-terror laws (especially in the UK) may make criminals of researchers. Cases such as the recent University of Nottingham arrests have made academics increasingly nervous and uncertain as to whether they can carry out their work in a way which is compliant with the law. From a purely practical perspective (at a conference where the majority of participants were from outside Ireland) there is a fear that the contents of one's laptop might be legal in country A but not in country B.

On a related point researchers were worried as to their legal and ethical responsibilities if they find material which might provide evidence of a crime or indications that a crime might be committed in the future. For Irish researchers section 9 of the Offences Against the State Act 1998 presents particular problems, making failure to volunteer certain information to Gardaí punishable by up to five years' imprisonment unless the researcher has a "reasonable excuse" for that failure. There seems to be a relatively low level of awareness of this and other reporting obligations.

The source material for studies in this area - jihadi forums, bulletin boards, chatrooms, etc. also presented difficulties for researchers. What ethical standards apply to the use of material deliberately published for a global audience? Does it matter whether individuals have used their real name or a pseudonym? Does it matter whether material is on an open forum or requires registration? Are researchers justified in deceit as to their identity or institutional affiliation in signing up to these forums? While there has been a good deal written on these issues (well summarised here) it seemed that these points still trouble researchers.

Finally, there was a substantial consensus that existing EU practice doesn't provide adequate ethical review of research in this area. When funding decisions are being made, there is a narrow focus on legality - asking "will researchers be breaking the law?" - rather than on wider ethical questions such as "is it desirable to develop particular tools of censorship or mass surveillance?" The INDECT project was cited as a prime example of inadequate ethical review, which (perhaps not surprisingly) has led to widespread media criticism.

Tuesday, August 10, 2010

Putting the "Entertainment" into Media and Entertainment Law

Ever wondered what a letter from Lindsay Lohan's lawyers would look like? Perhaps you wanted to know how Britney Spears and Kevin Federline agreed to enter into a fake marriage? Or maybe you wanted to see how contestants in American Idol sign their rights away on entering the show? If so, look no further. US law professor Eric Johnson has put together an excellent compendium of materials on media and entertainment law for his courses. Unlike traditional materials, however, his compendium includes not just the (relatively staid) decisions of the courts but also dressing room requirements, the bluff and bluster of correspondence, and more. As he explains:
I'm a strong believer in assigning readings other than judicial opinions. So my compendium includes contracts, demand letters, and various litigation pleadings. These documents are especially valuable reading in entertainment law and media law, where industry custom, intimidation tactics, creative lawyering, ignorance, bullying, and fear all combine to play a role that rivals that of the law itself.

Wednesday, July 14, 2010

Access controlled


The new book Access Controlled from the OpenNet Initiative is now available for free download to read free online. The sequel to the superb Access Denied, it describes a system of state control of the internet which is developing rapidly - from the relatively crude first generation of controls based on filtering and blocking towards a more sophisticated next-generation system which adds features such as built-in surveillance, control of users by contractual terms of use, and authority delegated to private bodies to oversee the net. As the introduction puts it:
States no longer fear pariah status by openly declaring their intent to regulate and control cyberspace. The convenient rubric of terrorism, child pornography, and cyber security has contributed to a growing expectation that states should enforce order in cyberspace, including policing unwanted content... Internet censorship is becoming a global norm.
As with Access Denied, the book is divided into two parts: opening with analytical chapters examining developments from data retention to the Global Network Initiative and followed by individual country and regional profiles. The latter are extremely useful overviews of the state of play worldwide - for me, however, the real strength of the book lies in the first six chapters in which a strong line up of authors consider international developments. Colin Maclay's chapter Protecting Privacy and Expression Online: Can the Global Network Initiative Embrace the Character of the Net? was a particular highlight, shining a light on a promising but as yet immature and relatively unexamined development.

Strongly recommended.

Friday, July 02, 2010

Hotline.ie 2009 Annual Report

Hotline.ie has just published its annual report for 2009 which makes for interesting reading. 2009 marks the 10th anniversary of the Hotline, which started operations in November 1999.

By way of background, Hotline.ie is an industry self-regulatory body (or perhaps co-regulatory: the boundaries are fluid) run by the ISPAI using funding from members and from the European Commission. The role of the Hotline is to receive complaints from the public about illegal content online and to act as a filter for those complaints - for example, if illegal material is found to be hosted in Ireland it will be notified to the Garda Síochána and/or the ISP; if hosted abroad it will be notified to the local authorities via either the INHOPE network or the Garda Síochána. Although it deals with reports of illegal content generally the primary focus of the Hotline is on preventing the distribution of child pornography.

Key statistics from the report:
* 2117 total number of reports processed by the Hotline.
* 284 of the above were determined as illegal under Irish law.
* 9 of the 284 proved to be duplicate reports, resulting in,
* 275 unique illegal reports. Of these:
* 9 were other issues (such as racism, threats of violence against individuals and financial scams that had an Irish connection).
* 267 were assessed as child sexual abuse and were forwarded for action through INHOPE or to An Garda Síochána for national investigation or forwarding via Interpol to other jurisdictions. One of these reports was of child grooming, all others were cases of child pornography.
Although the number of complaints had increased, the number of child pornography images reported was significantly reduced:
the reports assessed as illegal under Irish law numbered 536 in 2008 compared with 284 in 2009, a very significant drop of 252. Analysis of the figures suggests that the decline reflects that the public simply do not encounter illegal content with the same frequency as in previous years. Similar observations have been reported by other INHOPE hotlines. This could be a turning point reflecting some degree of success due to the sustained worldwide effort to counter child abuse images on the Internet.
One complaint related to child pornography on the web hosted in Ireland (the first time this had been detected):
The problem of weak log-on/password security was highlighted last October when the Hotline had its first absolutely confirmed report of a child pornography website in Ireland. The Garda investigation discovered that because of weak log-on/passwords the site had been hacked by criminals based outside the jurisdiction. The CSAM had been placed in a separate directory which was not navigatable from the shop website. However, clicking on the link in the banner site which held the full URL led directly to the planted directory. This contained PHP routines which created a pay-site portal with preview images pulled in from hosts in other countries.

The UK hotline, the International Watch Foundation (IWF), received a report about a banner site advertising a wide range of different child pornography sources. One of the banners linked to an IP address in Ireland. The IWF forwarded the report to Hotline.ie. Our content analysts verified that the content was indeed illegal under Irish law and confirmed the trace. The ISP was a major data centre in Dublin but we discovered that the IP was in fact sub-leased to a web developer/small hosting service in Co. Cork who had created and maintained the website on behalf of the client, a small retail business.
The complaints, as in previous years, overwhelmingly related to images hosted on the web and via spam emails, with complaints relating to p2p and Usenet being a vanishingly small proportion of the total:

(This statistic, however, appears to reflect the passive role of the Hotline, which is limited to receiving complaints from members of the public - it has no proactive role to actively search out child pornography. Recent media coverage of Irish p2p users downloading and uploading child pornography suggests that a significant number of Irish users may be sharing child pornography via p2p but that this is not registering on the Hotline radar.)

One particularly interesting part of the report was its analysis of those countries where child pornography is most often found to be hosted. Until recently the US and Russia were generally regarded as the worst offenders in this regard - recently, however, Russia appears to have improved its enforcement somewhat. Although the US continues to head this list, there has been a striking fall in the number of child pornography websites detected there, which may suggest that US procedures for taking down these sites are becoming more effective:

Friday, June 25, 2010

Technology, privacy and domestic violence

Privacy advocacy in Ireland faces a number of challenges. Often it's met with the old canard "if you've nothing to hide you've nothing to fear" - implying that privacy is something for wrongdoers and criminals. A related problem has been a lack of wider public concern about privacy issues: while occasional issues (such as the recent series of data breaches) trigger public interest, more often issues such as data retention tend to be seen as rather esoteric and remote from people's day to day lives.

This makes a recent story on domestic violence charity Women's Aid all the more significant in showing that privacy issues should be of much wider concern:
In its annual report for 2009, to be released today, the charity has noted an increase in disclosures of women being abused, controlled and stalked through technology.

Director of the charity Margaret Martin said it was very concerned at the development.

She said callers disclosed that current or former boyfriends, husbands and partners were using many forms of technology to control, coerce and intimidate them.

Women had disclosed that home and mobile phone calls were monitored, as well as their texts. Some women also found cameras secretly installed to monitor them in their own homes.

Abusers tracked and scrutinised online use and demanded access to private e-mail and social networking accounts.

Some women said their partners and ex-partners had placed lies about them on internet sites. Others had been photographed and filmed without their consent, sometimes having sex, and the images were uploaded to the internet...

“Quite often it prevents women from seeking help as they fear their partner will see that they have rung a helpline, looked at a domestic violence website or spoken of the abuse to their friends, family or colleagues in an e-mail or text.”
This story also reflects a significant wider trend not just in online privacy but in digital rights generally - slowly but surely these rights are being recognised as important by mainstream civil society groups. For example, earlier this week in the UK the National Union of Journalists agreed to support legal challenges to the Digital Economy Act while in Europe the consumers' group BEUC recently adopted a specific strategy on consumer rights in the digital environment. This trend is important in that it promises to enlist greater support for digital rights - but presents a new challenge for digital rights groups to liaise with and educate other civil society groups.

Friday, June 18, 2010

May newspapers publish the whereabouts of released rapists? Murray v. Newsgroup Newspapers interlocutory decision handed down

The High Court (Irvine J.) today gave an interlocutory judgment in the important case of convicted rapist Michael Murray who is seeking to restrain newspapers from publishing his photograph or details of his whereabouts. The case follows extensive publicity given to him post-release (e.g.) which he claims is threatening his safety and jeopardising his rehabilitation.

Today's judgment refuses to grant an interlocutory injunction which would restrain the newspapers pending a full trial - significantly noting that there is a "public interest in being informed of the identity and whereabouts of a convicted criminal who may pose a risk to the community" (p.59). The Northern Irish decision in the similar case of Callaghan v. Independent News and Media was distinguished as involving a criminal who posed a lesser threat to the community and who faced a greater risk of being physically attacked once his identity was known.

Full text of judgment:

Murray v. Newsgroup Newspapers and others

Monday, May 17, 2010

Book review: Bound by Law

I've written a short review of the superb Bound by Law? Tales from the Public Domain for the film studies journal Scope. Here's an excerpt:
You seldom find lawyers writing comic books. It's not that we have anything against them. We're happy to litigate about them (as fans of Alan Moore's Watchmen can testify, having seen Zack Snyder's film adaptation delayed by litigation between Twentieth Century Fox and Warner Brothers). We're even sometimes their subject (just consider the central role of Harvey Dent / Two-Face in the Batman canon). But writing comic books? What might the clients think? Or the tenure committee? And how might a profession known for its verbosity cope with the tight constraints of the speech bubble?

This makes Bound by Law? a rare beast indeed – a comic book written (and drawn) by lawyers which also manages to be a clear and entertaining introduction to the legal issues faced by filmmakers in the minefield that is intellectual property law. The authors are academics at UC Davis School of Law (Aoki) and Duke University Law School (Boyle and Jenkins) with a track record of innovative research at the point where law, creativity and the public domain intersect. In this book they set out to look at the position of documentary makers and how intellectual property law constrains what they do, with a view to illustrating the wider argument that the law has become imbalanced and is in need of reform.

The focus of their work is neatly set out by this example:

A cell phone happened to ring during the filming of Marilyn Agrelo and Amy Sewell's Mad Hot Ballroom, a documentary about New York City kids in a ballroom dancing competition. The ring tone was the Rocky theme song … EMI, which owns the rights to the Rocky song asked for – guess how much? $10,000. In another scene, they were filming a foosball game and one of the players spontaneously yelled "Everybody dance now" – a line from the C&C Music Factory hit. Warner Chappell demanded $5,000 for the use of the line (14).

This demonstrates an ongoing problem for documentary film makers -- the problem of documenting the world when certain aspects of the world (music playing in the background, artwork on the walls, even trademarks appearing on products) may be off limits. This book is full of examples of situations where documentary makers have found their work stifled as a result. But how did we arrive at a situation where rights holders demand payment of large sums for transient and incidental excerpts of their works? And what should we do about it?
Full review.

Saturday, May 01, 2010

For a safer and cleaner internet

I was extremely impressed with this cynical but accurate video about EU internet blocking proposals. Enjoy:



For more, see the Cleanternet website.

Tuesday, April 27, 2010

Music Industry says "Child Pornography is Great"

”Child pornography is great,” the speaker at the podium declared enthusiastically. ”It is great because politicians understand child pornography. By playing that card, we can get them to act, and start blocking sites. And once they have done that, we can get them to start blocking file sharing sites”.

The venue was a seminar organized by the American Chamber of Commerce in Stockholm on May 27, 2007, under the title ”Sweden — A Safe Haven for Pirates?”. The speaker was Johan Schlüter from the Danish Anti-Piracy Group, a lobby organization for the music and film industry associations, like IFPI and others...

”One day we will have a giant filter that we develop in close cooperation with IFPI and MPA. We continuously monitor the child porn on the net, to show the politicians that filtering works. Child porn is an issue they understand,” Johan Schlüter said with a grin, his whole being radiating pride and enthusiasm from the podium.

And seen from the perspective of IFPI and the rest of the copyright lobby, he of course had every reason to feel both proud and enthusiastic, after the success he had had with this strategy in Denmark.

Today, the file sharing site The Pirate Bay is blocked by all major Internet service providers in Denmark. The strategy explained by Mr. Schlüter worked like clockwork.
Christian Engström MEP has more.

Sunday, March 21, 2010

Update on Eircom, IRMA and "three strikes" in Ireland

In all the excitement surrounding St. Patrick's day this week the fact that Eircom and the music industry were back in court on Tuesday didn't really receive the attention it deserves.

The background to Tuesday's hearing lies in last January's settlement under which Eircom agreed to introduce a "three strikes" system to disconnect users accused of filesharing by the music industry. Under that agreement (which has never been made public, but details of which have leaked) the record companies seem to have been required to show that they - and Eircom - would be acting in compliance with data protection law.

The Data Protection Commissioner, however, threw a spanner in the works, as summarised by the Sunday Times:
As part of the agreement, Irma said it would use piracy-tracking software to trace IP addresses, which can identify the location of an internet user, and pass this information to Eircom. The company would then use the details to identify its customer, and take action.

But the office of the Data Protection Commissioner (DPC) has indicated that using customers’ IP addresses to cut off their internet connection as a punishment for illegal downloading [presumably this should be uploading] does not constitute "fair use" of personal information. Irma and Eircom have asked the High Court to rule on whether these data-protection concerns mean the 2009 settlement cannot be enforced...

The Eircom case was reopened in the High Court last month and Judge Peter Charleton will hear submissions from both sides on March 16. The record companies asked for the DPC to be joined to the High Court action, but it refused on the basis that no one would guarantee to pay its legal costs.

Charleton will first have to decide whether an IP address constitutes "personal information" under data protection law. If it does, then data controllers are required to "get and use the data fairly". They are also required to use that data for "only one or more clearly stated purposes". The DPC does not think this includes cutting off their internet service.

"The EU telecoms directive indicated people have a fundamental right to an internet connection," said a source involved in the case. "So the judge must decide whether processing a person’s IP address to cut them off is a proportionate response to discovering they have downloaded pirated music."
Consequently, arguments on these issues were heard on Tuesday, throwing up some interesting new information. (It emerged for example that Eircom has agreed to throttle user traffic after strike two, and that Eircom will have three staff devoted to running the three strikes procedure.)

Unfortunately, that hearing seems to have been something of a case of Hamlet without the Prince. With the Data Protection Commissioner not represented, the court was hearing only from parties with a vested interest in the three strikes procedure and was deprived of an independent and impartial perspective.

I don't yet have a full transcript of the hearing, but I understand that the court was asked to rule on three broad questions:

1. Do IP addresses (in the hands of the music industry) constitute personal data?
2. Is the settlement agreement itself compatible with the Data Protection Acts?
3. If IP addresses are personal data, are they "sensitive personal data" in a context where they might reveal the commission of a criminal offence?

Other issues that arose included the fundamental rights implications of disconnecting users, whether users waived those rights by agreeing to Eircom's terms of use, and whether the Eircom/IRMA agreement was compatible with the new Telecoms Package rules on disconnecting users in relation to proportionality, necessity and procedural safeguards (including judicial review). Judgment is expected next week.

Friday, March 05, 2010

Cloud computing controversy won't clear

It seems as though the controversy caused by the Chief State Solicitor's advice about purchasing cloud computing just won't go away. John Collins has an update in today's Irish Times. Here's an excerpt:
ON A Thursday afternoon early last month an e-mail with the subject line "eTenders – Cloud Computing Warning" began to arrive in the inbox of public servants.

Sent by the National Public Procurement Operations Unit, which operates the Government’s electronic tendering website, eTenders, the brief communication said the Chief State Solicitor’s Office had advised "that issues such as data protection, confidentiality and security and liability are not necessarily dealt with in a manner that would be necessary for public-sector responsibilities" by cloud services.

The e-mail was quickly forwarded around Ireland’s technology industry. Not only are companies such as Microsoft, IBM and HP investing millions into research centres and data centres here to support the new model of delivering software and other services over the internet, but Minister for Communications Eamon Ryan last year identified cloud computing as one of six "pillars" that would drive the creation of a smart economy.

In fact, Ryan is understood to have been extremely annoyed at the message being sent out, and his advisers have moved to soothe the nerves of some of the major technology multinationals based here.

While not renowned for its technology expertise, one of the roles of the Chief State Solicitor’s Office is to review commercial agreements for public bodies before they sign them.

"They must have reviewed a contract which wasn’t up to scratch and now they have concluded all cloud contracts are like this," says Philip Nolan, a partner in legal firm Mason Hayes + Curran who specialises in technology contracts. "It’s a totally disproportionate reaction and the IT industry is recoiling in shock."

Nolan equates the advice given by the Chief State Solicitor’s Office to someone saying 12 years ago "don’t buy anything using e-commerce because it’s not secure".

Describing the e-mail as "damaging", Ed Byrne, general manager of Hosting365, a local firm that provides a platform to support cloud computing, says eTenders should have instead "outlined the questions that need to be asked before buying a cloud service".

According to Byrne, this would have included questions such as where is the service based, who is the supplier, how much money can it save and what levels of support can be expected.
Previously on this blog: 1|2

Tuesday, March 02, 2010

Ryanair v. Billigfluege.de - Full decision now available

I've just received a copy of the decision of Hanna J. in Ryanair v. Billigfluege.de and uploaded it to Scribd. At first glance it appears to represent a significant win for site owners who wish to control screenscraping, indexing and other uses of their content:

Ryanair v. Billigfluege.de