Wednesday, April 04, 2007
UK Interim data retention measures published
The Register reports that the Home Office has published draft regulations to require data retention for the interim period before the data retention directive must be implemented. As with the current Irish law this will cover details of all calls made or texts sent, and also location data in the case of mobile phones. The Home Office proposes a twelve month retention period with discretionary cost reimbursement for affected telcos.
The telescreen: coming soon to a street near you
The Telegraph reports that:
Britain is already one of the most watched nations on earth and now "talking” CCTV cameras are to be installed in 20 areas across the country.As usual, Eric Blair was well ahead of Tony Blair:
The loudspeakers will allow CCTV operators to bark orders at people committing anti-social behaviour.
'Smith!' screamed the shrewish voice from the telescreen. '6079 Smith W.! Yes, you! Bend lower, please! You can do better than that. You're not trying. Lower, please! That's better, comrade. Now stand at ease, the whole squad, and watch me.'
Monday, April 02, 2007
Eric Blair watched by Tony Blair
This is London takes a look at the pervasive surveillance surrounding George Orwell's former home:
According to the latest studies, Britain has a staggering 4.2million CCTV cameras - one for every 14 people in the country - and 20 per cent of cameras globally. It has been calculated that each person is caught on camera an average of 300 times daily.
Use of spy cameras in modern-day Britain is now a chilling mirror image of Orwell's fictional world, created in the post-war Forties in a fourth-floor flat overlooking Canonbury Square in Islington, North London.
On the wall outside his former residence - flat number 27B - where Orwell lived until his death in 1950, an historical plaque commemorates the anti-authoritarian author. And within 200 yards of the flat, there are 32 CCTV cameras, scanning every move.
Orwell's view of the tree-filled gardens outside the flat is under 24-hour surveillance from two cameras perched on traffic lights.
The flat's rear windows are constantly viewed from two more security cameras outside a conference centre in Canonbury Place.
In a lane, just off the square, close to Orwell's favourite pub, the Compton Arms, a camera at the rear of a car dealership records every person entering or leaving the pub.
Within a 200-yard radius of the flat, there are another 28 CCTV cameras, together with hundreds of private, remote-controlled security cameras used to scrutinise visitors to homes, shops and offices.
The message is reminiscent of a 1949 poster to mark the launch of Orwell's 1984: 'Big Brother is Watching You'.
Saturday, March 31, 2007
Zooomr - Free pro photo hosting for bloggers
Zooomr are offering a free pro account to bloggers who host their images with them.
The only condition - you must host one of your blog photos with them. This is mine.
I'm very interested to see how Zooomr stacks up against Flickr. Unfortunately both have an annoying problem - try giving the url to somebody who isn't already familiar with the fun world of Web 2.0 naming. Chances are they'll end up at flicker.com, zoomr.com or zoomer.com - all of which are (now very valuable because of all the misdirected traffic) parked domains. In effect, Flickr and Zooomr have a self-inflicted typosquatting problem.
The only condition - you must host one of your blog photos with them. This is mine.
I'm very interested to see how Zooomr stacks up against Flickr. Unfortunately both have an annoying problem - try giving the url to somebody who isn't already familiar with the fun world of Web 2.0 naming. Chances are they'll end up at flicker.com, zoomr.com or zoomer.com - all of which are (now very valuable because of all the misdirected traffic) parked domains. In effect, Flickr and Zooomr have a self-inflicted typosquatting problem.
Wednesday, March 28, 2007
Blogger beware: Blog libel and privacy action settled for £150,000
The Guardian reports that an action by Martin Sorrell and Daniela Weber for libel and breach of privacy by way of email and blog has settled without admission of liability for a total of £150,000 - £120,000 to him, £30,000 to her. The level of the settlement (which included a nominal sum for the plaintiffs' costs) appears to reflect the plaintiffs' difficulty in linking the anonymous material to the defendants.
Background to the case:
Background to the case:
Two former business partners of advertising boss Sir Martin Sorrell launched a "vicious" campaign against him on blogs and emails, a court heard today.
One of his former associates referred in a private email to the WPP boss as a "mad dwarf" and described the company's former chief operating officer in Italy as a "nympho schizo", the High Court in London was told.
Marco Benatti, WPP's former manager in Italy, and his lieutenant Marco Tinelli, were spurred to publish defamatory remarks after Sir Martin sacked Mr Benatti over allegations of financial irregularities at WPP's Italian business, Sir Martin's barrister said.
Opening his case at a libel and invasion of privacy trial, Desmond Browne QC said the two men had taken "countermeasures" against Sir Martin and WPP's chief operating officer in Italy, Daniela Weber. ...
The "counter-measures" against Sir Martin included a blog that appeared in March last year containing a "host of libels" against the WPP boss, Mr Browne said.
Although the blog was taken down after three days, another one appeared a month later, he said.
"The day that Sir Martin managed to get the blog taken down, Mr Benatti emailed his friends saying that blogs were like mushrooms, they sometimes pop up again the next time it rains," Mr Browne said.
"What could be a stronger pointer to Mr Benatti's knowledge of what was going on and his being the architect of the whole exercise than that email shortly after the blogs had been taken down suggested that blogs were like mushrooms?"
Mr Browne said the other "countermeasure" was a series of emails that included a "vicious Jpeg image grossly intruding into the privacy of Sir Martin and Ms Weber".
"Naturally it would be to intrude further to even start to describe them. We say Mr Tinelli was directly involved in the dissemination of that vicious image.
"There is no doubt that he felt just as bitterly towards Sir Martin and Ms Weber as did his boss, Mr Benatti. I say 'no doubt' because on the very morning of the day the images were sent out by email he referred to them as the mad dwarf and the nympho schizo."
Mr Browne said that the two men had taken "elaborate steps to cover their tracks" but that computer evidence implicated them.
Friday, March 23, 2007
Data Protection Commissioner Guidance on CCTV in the Workplace and Biometrics in Schools
The Data Protection Commissioner has given two important guidance notes on the use of cctv in business premises and the use of biometrics in schools. In both case the guidance is very protective of privacy rights.
Significantly, the biometrics guidance takes a different approach to that recently adopted in England. The English approach has been to accept that once a minor is mature enough to give an informed consent to the use of biometrics in schools, parental consent is no longer required. Under this guidance, however, parental consent will always be necessary in the case of a minor, and if the minor is aged twelve or above they must also consent:
The Register has a good discussion of the biometrics guidance note here. I've previously blogged about this issue here.
Significantly, the biometrics guidance takes a different approach to that recently adopted in England. The English approach has been to accept that once a minor is mature enough to give an informed consent to the use of biometrics in schools, parental consent is no longer required. Under this guidance, however, parental consent will always be necessary in the case of a minor, and if the minor is aged twelve or above they must also consent:
In the context of students attending a place of education, the Data Protection Commissioner would stipulate that the obtaining of consent is of paramount importance when consideration is being given to the introduction of a biometric system. It is the Commissioner’s view that when dealing with personal data relating to minors, the standards of fairness in the obtaining and use of data, required by the Data Protection Acts, are much more onerous than when dealing with adults. Section 2A(1)(a) of the Data Protection Acts states that personal data shall not be processed by a data controller unless the data subject has given his/her consent to the processing, or if the data subject by reason of his/her physical or mental incapacity or age, is or is likely to be unable to appreciate the nature and effect of such consent, it is given by a parent or guardian etc. While the Data Protection Acts are not specific on what age a subject will be able to consent on their own behalf, it would be prudent to interpret the Acts in accordance with the Constitution. As a matter of Constitutional and family law a parent has rights and duties in relation to a child. The Commissioner considers that use of a minor’s personal data cannot be legitimate unless accompanied by the clear signed consent of the child and of the child’s parents or guardian.Two aspects of this guidance may be significant in the future - in requiring a double lock (both parental and child consent) is there a possibility of a knock on effect in the area of marketing to children? (Where previously the consent of a child mature enough to give an informed consent would have sufficed.) Also, in imposing a strict test for determining when the use of biometrics is proportionate or necessary in education, will there be an impact on the use of biometrics in other sectors?
As a general guide, a student aged eighteen or older should give consent themselves. A student aged from twelve up to and including seventeen should give consent themselves and, in addition, consent should also be obtained from the student’s parent or guardian. In the case of children under the age of twelve, consent of a parent or guardian will suffice. All students (and/or their parents or guardians as set out above) should, therefore, be given a clear and unambiguous right to opt out of a biometric system without penalty. Furthermore, provision must be made for the withdrawal of consent which had previously been given.
The Register has a good discussion of the biometrics guidance note here. I've previously blogged about this issue here.
Thursday, March 22, 2007
Blogger beware - legal issues facing Irish bloggers
Many thanks to the IIA and Fleishman-Hillard for hosting a session on Blogging, New Media, Business and the Law. My presentation on issues such as defamation, contempt of court, copyright and privacy (ppt file) is available here and Brian Greene has podcast the event here. Tom Murphy gave a very interesting presentation on online marketing, and he's blogged about the event here.
Tuesday, February 27, 2007
Function creep in action: Mobiles may be checked after crashes
The Telegraph reports that the English government proposes to use data retention to enforce the ban on mobile phones while driving:
Motorists face having their mobile phone records checked after a routine accident, under proposals unveiled by the Government yesterday...Remember - data retention was sold on the basis that it was necessary to prevent terrorism and serious crime.
In the review the Department for Transport paper says: "We will look at ways to make it easier for the police to be able to follow the process of investigating whether mobile phone use was a contributory factor in an accident and thus prosecute more offenders."
According to police sources this would entail lowering the seniority of both the officer who can check the records and the threshold of the severity of the accident.
Where the use of a phone is suspected to have been a cause in the accident, it is straightforward to check when calls were received or made, irrespective of whether the call was made on a hands-free or hand-held device.
If the phone were destroyed, police would, under the proposals, be able to use call records.
Data Retention in Ireland - stealth, bad faith, and contempt for the democratic process
I've written a brief article for Data Protection Law and Policy on the development of data retention in Ireland. As you'll guess from the following excerpt, I'm not impressed with the way in which it's been passed into law.
"The history of data retention law in Ireland has been marked by stealth, bad faith, and a shocking contempt for the democratic process. The 2002 Direction in particular stands out as an attempt to make law in secret, by the abuse of an unrelated statutory power, and then to stymie any judicial review by directing the recipients of the Direction to remain silent as to its existence. Moreover, when finally forced by the Data Protection Commissioner to proceed by primary legislation, the Department of Justice did so in 2005 without notice, in a way calculated to exclude any public scrutiny, and ignoring earlier assurances that draft legislation would be published and debated."PDF of the article here.
Thursday, February 15, 2007
.ie Domain Disputes Multiply
The amusingly named I squatted your .EU mentions some recent .ie domain decisions from WIPO, including the adidas.ie, and buy-sell.ie decisions.
There have been 10 complaints lodged with WIPO under the .ie Dispute Resolution Policy to date - resulting in four decisions transferring the domain to the complainant, three complaints which were terminated before decision (presumably because the respondent decided to voluntarily relinquish the domain), and just two complaints denied. Not a bad batting average for complainants.
There have been 10 complaints lodged with WIPO under the .ie Dispute Resolution Policy to date - resulting in four decisions transferring the domain to the complainant, three complaints which were terminated before decision (presumably because the respondent decided to voluntarily relinquish the domain), and just two complaints denied. Not a bad batting average for complainants.
More filesharing litigation coming to Ireland?
Last time it was the music industry. This time Hollywood? John Collins posts:
my home phone rang this morning with a little surprise for me. it was a representative of bt who asked me to confirm that i have a broadband service with them. when i said he did, he told me they had been contacted by paramount movies (as far as i can see there is no entity of this name, but who am i to split hairs) to say i was sharing a movie of theirs, an inconvenient truth. he asked me to remove it from my pc because if they didn't they could take further action.
Tuesday, February 13, 2007
Commission to make life easier for online businesses by streamlining consumer law
From The Register:
The European Commission will overhaul European contract law to make internet selling easier, more reliable and more efficient.Hopefully this will also review the areas of overlap between these directives and the E-Commerce Directive.
The commission has opened consultation on proposed changes that will affect eight EU Directives.
Recognising that e-commerce is hampered by a mass of conflicting national laws, the commission has proposed changes to Directives which it hopes will, when transferred into national laws, bring the law into line with technological developments.
'There is an urgent need for action, the world is moving so fast and Europe risks lagging behind', said Meglena Kuneva, the new EU Commissioner for Consumer Affairs, in her first press conference in Brussels. 'We need a root and branch review of consumer rules. At the moment, consumers are not getting a fair deal online, and complex rules are holding back the next generation of bright business ideas. We must find new solutions to new challenges.'
The commission believes that online businesses would benefit significantly if doubts about the legal implications of cross-border trading were removed.
'Consumer confidence is a key factor determining how and when consumers spend their money in different sectors of the economy,' said a Commission statement. 'All the evidence is that consumers are not yet comfortable enough in the digital and online world to seize its full potential. Only a tiny fraction – six per cent of EU consumers – are currently shopping online cross border.'
The commission will review all consumer contract law, which will involve a review of eight directives. They are: the Unfair Contract Terms Directive and the Directive on Sale of Consumer Goods and Guarantees; the Distance Selling Directive; the Doorstep Selling Directive; the Package Travel Directive; the Timeshare Directive; the Directive on Injunctions; and the Price Indication Directive.
Tuesday, January 30, 2007
NTR Deal introduces number plate surveillance
'Invisible' toll part of €600m deal to buy out West-Link bridge - Irish Independent:
It is understood that NTR will be operating the toll on behalf of the State, which will effectively become the new landlord. This will involve photographing the registration of every vehicle and billing them unless they have a prepaid arrangement... Drivers are only tolled now if they cross the West-Link bridge. Under the new deal, everyone using the M50 will be charged.Expect this to be used to justify the roll out of number plate recognition and the monitoring of all car journeys.
Wednesday, January 17, 2007
Garda leaks and the right to privacy
RTÉ News reports:
It does, however, represent an interesting application of the Hanahoe v. Hussey principle that public bodies may owe you a duty of care to keep certain information confidential. It also reflects Hanahoe v. Hussey in that it shows a judicial willingness to impose vicarious liability in respect of unauthorised garda disclosures.
Update: Eoin O'Dell links to the full decision here with an interesting discussion of the issues involved.
A family who were forced to leave their new home in Kerry because of the leaking of confidential information by gardaà to journalists have been awarded €70,000 in the High Court.This case follows the 1997 decision in Hanahoe v. Hussey where gardaà tipped off the media to the fact that a solictor's office would be searched under a search warrant, leading to a "media circus" when gardaà arrived with damage to the reputation of the firm, and ultimately resulting in an award of £100,000 in damages. In that case, the basis for the decision was that the wrongful and negligent disclosure of this information amounted to negligence under the principles in Ward v. McMaster. It's not clear from the media coverage whether the decision in this case goes further, or whether data protection principles were also considered. (Compare section 7 of the Data Protection Acts, 1988-2003, creating a duty of care in respect of the handling of personal data.)
Alan and Phyllis Gray and their son Francis are originally from Blanchardstown in Co Dublin but moved to Ballybunion under the Rural Resettlement Programme.
They sued the Minister for Justice for breach of privacy.
They say they had to leave their home after gardaà leaked to the media that Mr Gray's nephew, who had served a sentence for rape, was staying with them.
It does, however, represent an interesting application of the Hanahoe v. Hussey principle that public bodies may owe you a duty of care to keep certain information confidential. It also reflects Hanahoe v. Hussey in that it shows a judicial willingness to impose vicarious liability in respect of unauthorised garda disclosures.
Update: Eoin O'Dell links to the full decision here with an interesting discussion of the issues involved.
Wednesday, January 10, 2007
Bar Camp talk - Who owns software?
Does your employer own software that you write on your own time at home? Can a client who commissions you to write software prevent you from reusing portions of that code for a different project? Are you entitled to modify software developed for you by an outside programmer? If you don't own copyright, will you have an implied licence to use software? Will an implied licence limit you to using software in a particular market sector or a particular jurisdiction? Does it matter how much you've paid for the software? Does it matter whether you've given / been given the source code? What about databases you commission from a third party?
Come to Bar Camp South East and find out. I'll be talking on the topic of "Who owns software?" - taking a practical look at the problems of determining who owns copyright and other rights in software and giving tips as to how you can protect your position.
[edited to add] I've since published an article dealing with these topics in more detail.
Come to Bar Camp South East and find out. I'll be talking on the topic of "Who owns software?" - taking a practical look at the problems of determining who owns copyright and other rights in software and giving tips as to how you can protect your position.
[edited to add] I've since published an article dealing with these topics in more detail.
Tuesday, December 12, 2006
From "the innocent have nothing to fear" files - mortgage brokers selling financial information on buyers to estate agents
Unless you've been living on Mars recently, you'll have heard of the RTÉ Prime Time exposé of dodgy dealings in the property market. Amongst other things, that program revealed that estate agents are (illegally) buying information from mortgage brokers about prospective purchasers: how much they have to spend, how much they've received in mortgage approval, how much they might have from other sources (such as parental gifts). Unsurprisingly, they are using this to extract every last penny from purchasers.
Hopefully we'll remember this the next time somebody tries to tell us that if you've done nothing wrong, you've nothing to fear.
Hopefully we'll remember this the next time somebody tries to tell us that if you've done nothing wrong, you've nothing to fear.
Wednesday, December 06, 2006
From "the innocent have nothing to fear" files - police kept record of beautiful women
Cops kept record of beautiful women - Peculiar Postings - MSNBC.com:
STOCKHOLM, Sweden - Two Swedish border control officers risk disciplinary action for keeping a photo collection of 'exceptionally beautiful' women who passed through their checkpoint, police officials said Tuesday.
The officers, who were working at a ferry terminal near Stockholm, made photocopies of the women's passport photos and placed them in a binder. They also noted the date of birth next to each entry, the Stockholm police department said.
The binder contained instructions on how to compile the collection, and orders to make backup copies in case the binder would go missing or be confiscated by 'evil-minded bores,' police said.
Friday, December 01, 2006
Irish law on metatags and keywords
I've written (together with Paul Lambert of Merrion Legal solicitors) a piece on the legal issues involved where businesses find their trademarks being used by competitors as metatags or keywords. The full article (with the kind permission of Thomson Roundhall) is available here. Excerpt:
As cybersquatting declines we find that trade mark owners now have to defend their names in a different context. As search engines become more sophisticated, users are tending to rely on them as their primary means of navigation. Rather than type in a domain name directly (or rely on a bookmark), many users will simply enter a term—such as a company name or product – into a search engine, expecting the site they are looking for to appear high in the list of results. Consequently, the importance of domain names is diminished and search engines take on a new prominence. As Nielsen puts it:
“Web users are growing ever-more search dominant. Search is how people discover new websites and find individual pages within websites and intranets. Unless you're listed on the first search engine results page … you might as well not exist.”
This poses a new problem for trade mark holders—what happens when a competitor uses their trade mark in such a way that a person searching for the term will be shown a competing site in the list of results, or will be shown an advertisement for the competitor? ...
At first glance the unauthorised use of trade marks as metatags or keywords might seem to be a clear infringement of the mark in question. The trade mark holder will certainly argue that the metatag or keyword improperly takes advantage of the goodwill in the trademarked term and confuses the user into believing that there is some link between the trade mark and the search results or advertisements displayed in response. It can also be argued that the search engine is itself guilty of infringement by selling the trademarked term as a keyword. In addition, the tort of passing-off may be available.
However, look more closely and the position becomes more complicated. Trade mark law was not drafted with metatags or keywords in mind, making it difficult to bring these situations within the legislative language. There will be some situations where the trade mark use is legitimate, for example, a company which manufactures spare parts for BMW cars might be entitled to use “spare parts suitable for BMW” in its metatags.
The likelihood of consumer confusion may also be less in metatag / keyword cases as the trade mark is being used “invisibly” — that is, in a way which is not directly visible to the user, reducing the likelihood that the user will associate the search result or the advertisement with the trade mark. If a search engine faces liability for selling trademarked keywords, it may be hard to determine whether that liability is direct or merely contributory. (Some cases suggest that the search engine should not be liable for the keywords chosen by its clients.)
In addition, some would argue that provided users are not confused, presenting advertisements for competing goods alongside search results is no more objectionable than a shop placing similar products in the same aisle.
Friday, November 03, 2006
Your personal information is for sale: Bank worker uses information to stalk model
From BreakingNews.ie:
A 27-year-old former bank official who harassed Irish model Glenda Gilson and her family has been given a three month suspended sentence and ordered to stay 100 yards from the victims.Despite Judge McMahon's comments, I suspect that it will take many more cases like this before people realise the dangers of their private information being open to abuse.
Daniel Rooney, of Castleknock Cottages, Castleknock, pleaded guilty at Dublin Circuit Criminal Court, to harassment of the Gilson family by persistently communicating with Glenda Gilson and her parents Noel and Aileen Gilson by e-mail and telephone at various locations on dates between November 12, 2004 and March 21, 2005.
Defence counsel Mr Luigi Rea BL, said Rooney was underachieving at that time in his life and he had became "jealous and obsessed" about Miss Gilsons progress in her modelling career. He had used his computer skills to "obtain telephone numbers he should not have".
Judge Bryan McMahon said one should not under estimate the "sinister impact these calls from a unknown quarter" can have on their victims but said he would take the mitigating factors into account and treat this as an "aberration".
He said this case was a "a feature of modern technology and mobile phones and the access to people on these phones" and that it was "indicative of the personal data of all citizens" which corporations hold.
Garda Deirdre Conway told Mr Paul Carroll BL, prosecuting, that there had been 49 calls to the family over the five month period. She said the harassment began on November 12, 2004, when Miss Gilsons model agency, Assets, received a call and an e-mail purporting to be from a friend.
It soon became evident that the caller was using a false name as he started shouting abuse about Miss Gilson and her career. Miss Gilson later received abusive calls on the land line at her parents home and also on her mobile. Many of the calls made to Miss Gilson’s home were answered by her parents...
Mr Rooney worked for AIB at the time and had been able to access the phone numbers though his work.
Friday, October 27, 2006
Your personal information is for sale: Call centre edition
The BBC reports that
One in 10 of Glasgow's financial call centres has been infiltrated by criminal gangs, police believe.Expect data retention to be a goldmine for criminals.
The scam works by planting staff inside offices or by forcing current employees to provide sensitive customer details.
The information is then used to steal identities and fraudulently set up accounts or transfer money...
Det Ch Insp Derek Robertson of Strathclyde Police told the BBC's Newsnight Scotland programme that there were a large number of call centres in the Glasgow area...
"I would say approximately 10% have been infiltrated in the past and we are working very hard to reduce that number."
Detectives believe that criminal crews are sent out to recruit volunteers to work in the centres.
Once they agree, they are asked to supply financial information in return for a fee.
Another tactic is to identify pubs where call centre workers visit and intimidate the employees to pass on the details.
Det Ch Insp Robertson said: "There are a number of different ways to do it.
"We know of organised crime groups who are placing people within the call centres so that they can steal customers' data and carry out fraud and money laundering.
"We also know of employees leaving the call centres and being approached and coerced, whether physically, violently or by being encouraged to make some extra money.
"And of course you have the disgruntled employee who may turn their hand to fraud just to benefit themselves."
Subscribe to:
Posts (Atom)