Friday, July 31, 2009
Big news for small print: Court of Appeal gives the thumbs up for website disclaimers
Struan Robertson, editor of OUT-LAW.COM has a frank and useful discussion of what the decision means for online businesses.
Tuesday, July 28, 2009
Sutherland Institute v. Continuative: Is it time to take the U out of UDRP?
OUT-LAW has a good report of the WIPO panel decision in Sutherland Institute v. Continuative LLC - a decision which by focusing on the location of the parties makes me wonder whether it's misleading to describe the UDRP as a "Uniform" Dispute Resolution Policy.
On the face of it this was a relatively straightforward case. The complainant was a right wing Utah think thank hosted at SutherlandInstitute.org while the respondent set up a parody site at SutherlandInstitute.com. A screengrab of a portion of both pages shows the difference:

Despite the fact that the respondent did not defend the proceedings, the panelist found in their favour, holding that it had not been established that they had registered and used the domain "in bad faith" as required by the UDRP. This isn't of itself a surprising outcome, but it's the reasoning underpinning this conclusion which I find interesting. The key passage is this:
Gerald Levine has more, including an interesting discussion of an alternative choice of law approach under the UDRP.
On the face of it this was a relatively straightforward case. The complainant was a right wing Utah think thank hosted at SutherlandInstitute.org while the respondent set up a parody site at SutherlandInstitute.com. A screengrab of a portion of both pages shows the difference:
Despite the fact that the respondent did not defend the proceedings, the panelist found in their favour, holding that it had not been established that they had registered and used the domain "in bad faith" as required by the UDRP. This isn't of itself a surprising outcome, but it's the reasoning underpinning this conclusion which I find interesting. The key passage is this:
Because this proceeding involves political speech that is strongly protected under the U.S. Constitution, the Panel will not in these proceedings involving two U.S. parties attempt to identify bad faith elements that are not specifically enumerated in the Policy. If the right of political speech is to be interfered with based upon Complainant’s service mark incorporated in Respondent’s disputed domain name, it is preferable that a federal or state court make that application of the concept of “bad faith”.This passage relies on the fact that the parties are both US based to apply US law. As such it takes advantage of rule 15(a) of the UDRP which gives a panel a remarkably wide discretion to decide claims based on "any rules and principles of law that it deems applicable". This has often been used by panelists to apply domestic rules of law where the parties are both from the same jurisdiction - to the extent that the Berkman Center's excellent Analysis of UDRP Issues assumes this to be the norm. Indeed, this practice is supported by paragraph 176 of the WIPO Final Report which led up to the adoption of the UDRP, which states:
In applying the definition of abusive registration given above in the administrative procedure, the panel of decision-makers appointed in the procedure shall, to the extent necessary, make reference to the law or rules of law that it determines to be applicable in view of the circumstances of the case. Thus, for example, if the parties to the procedure were resident in one country, the domain name was registered through a registrar in that country and the evidence of the bad faith registration and use of the domain name related to activity in the same country, it would be appropriate for the decision-maker to refer to the law of the country concerned in applying the definition.Against this, however, is a strong body of opinion which argues that national law should not be imported into the UDRP - that to do so will lead to a lack of uniformity and to inconsistent outcomes. For example, in McMullan Bros & Maxol v. Web Names, the panelist ruled that:
5.10 Paragraph 15(a) of the Rules requires a Panel to make its decision "in accordance with the Policy, these Rules and any rules and principles of law that it deems applicable." This might justify applying the without prejudice doctrine in this case, but the Panel is unconvinced. The Policy provides an international procedure for international application by a panel comprising panelists who may come from a jurisdiction unconnected with either party. To import a national rule simply because both parties come from the same jurisdiction may result in similar cases being decided in a different manner dependant upon geographical accident. This is a conclusion that this Panel finds inherently unattractive. At times resort to national law may be unavoidable (for example when determining the existence of a trademark recognised by the Policy), but the Panel sees no reason for doing so in this case.Similarly Wotherspoon & Cameron argue that:
The UDRP was developed by reference to the status of national laws and international treaties. In our view, it already reflects a somewhat harmonized version of these laws. The practice of referring to territorial laws undermines a central purpose of the UDRP — to provide a uniform mechanism for resolution of domain name disputes in the face of the borderless nature of the Internet. By continuing to refer to national laws, Panels will reinforce jurisdiction specific intellectual property rights and undermine the goal of a global uniformity in resolving domain name disputes.This clash of views highlights an unresolved tension within the UDRP as to how to deal with choice of law issues. There is an obvious attraction in the use of national law where a matter is very closely connected with one jurisdiction. But doing so - even if permitted by the UDRP - does run the risk of eroding its "uniform" nature. Also, this growing practice adds an extra layer of complexity to UDRP proceedings - forcing parties to address choice of law issues as well as the substance of any claim - and may also result in registrants and trademark holders gaming the system by choosing to establish themselves in the jurisdictions which they see as most friendly to their side.
Gerald Levine has more, including an interesting discussion of an alternative choice of law approach under the UDRP.
Friday, July 17, 2009
Bill published to transfer RegTel premium rate functions to Comreg
That legislation has now emerged, in the form of the Communications Regulation (Premium Rate Services) Bill 2009. According to the explanatory memorandum, the purpose of the Bill is to provide for:
• the transfer of the function of regulating premium rate services to the Commission for Communications Regulation, hereinafter called the Commission.Key elements here are the introduction of a licence to provide premium rate services and the creation of a range of criminal offences including acting without a licence and overcharging / charging for services which were not requested.
• the licensing of premium rate services by the Commission.
• offences, penalties and rights of appeal in relation to the regulation of premium rate services.
• the funding of expenses incurred by the Commission in exercise of its regulatory functions.
• the transfer of staff and responsibility for certain legal proceedings, respectively, from Regtel to the Commission.
• compliance by the Commission with the same obligations in relation to Ministerial directions, reporting and accountability responsibilities in respect of premium rate services as it has in respect of electronic communications and postal services.
More from the Irish Times | Siliconrepublic.
(I'm a bit late blogging this story - I lost sight of this Bill in the flurry of legislative activity during the run up to the summer vacation, particularly the rushing through of the Criminal Justice (Surveillance) Act 2009 and the introduction of the Communications (Retention of Data) Bill 2009. More on these anon.)
Wednesday, July 08, 2009
Eircom hacking shows flaws in Irish computer crime law
Today's Irish Times has a report of an apparent denial of service attack against Eircom:
Here's an excerpt from a chapter I wrote in Reich (ed.), Cybercrime and Security discussing the uncertain Irish law on denial of service attacks:
MANY OF Eircom’s 500,000 internet subscribers have been left offline or experienced delays in web browsing at times this week because of a suspected attack by hackers.I've said it before but it's worth repeating: Irish law does not adequately deal with computer crime at the moment (with denial of service attacks being one of many areas left without adequate sanctions) and legislation to implement the Cybercrime Convention and the Framework Decision on Attacks Against Information Systems is now long overdue.
Some customers who tried to connect to popular sites such as RTÉ, Facebook or Bebo were redirected to incorrect websites, often displaying images of advertising or scantily clad women.
The company blamed the problems on “an unusual and irregular volume of internet traffic” directed at its website, which affected the systems and servers that provide access to the internet for its customers.
Internet discussion groups speculated that the problems were caused by a hacker accessing Eircom’s domain name server (DNS) system through a denial-of-service attack.
This involves a target site being saturated with messages and requests to the point it can no longer function properly.
Here's an excerpt from a chapter I wrote in Reich (ed.), Cybercrime and Security discussing the uncertain Irish law on denial of service attacks:
Whether or not such an attack would amount to an offence under Irish law will vary depending on the precise structure of the attack.
For example, suppose that A sets out to harm B by sending several million emails to B’s server. The effect is not only to use up B’s bandwidth but also to use his disk capacity. In this case, it might be possible to charge A with criminal damage under section 2 of the Criminal Damage Act 1991, on the basis that A has damaged B’s data within the meaning of section 1 by adding to it without lawful excuse.
This result is supported by the English decision in DPP v. Lennon. In that case the defendant was a 16 year old who took umbrage at the circumstances of his dismissal and sent five million emails to his former employer with the expressed intention of “causing a bit of a mess up”. He was charged with unauthorised modification to a computer system with intent to impair the operation of the computer, contrary to section 3(1) of the Computer Misuse Act 1990 (the equivalent provision to section 2 of the Criminal Damage Act 1991). His defence was that the company had implicitly consented to receiving emails and as such he had not made unauthorised modifications. Although the trial judge accepted this argument, on appeal the Divisional Court held that any implied consent did not extend to emails sent for the purpose of disrupting the system. Per Jack J.:“I agree, and it is not in dispute, that the owner of a computer which is able to receive emails is ordinarily to be taken as consenting to the sending of emails to the computer. His consent is to be implied from his conduct in relation to the computer. Some analogy can be drawn with consent by a householder to members of the public to walk up the path to his door when they have a legitimate reason for doing so, and also with the use of a private letter box. But that implied consent given by a computer owner is not without limit. The point can be illustrated by the same analogies. The householder does not consent to a burglar coming up his path. Nor does he consent to having his letter box choked with rubbish. That second example seems to me to be very much to the point here. I do not think that it is necessary for the decision in this case to try to define the limits of the consent which a computer owner impliedly gives to the sending of emails. It is enough to say that it plainly does not cover emails which are not sent for the purpose of communication with the owner, but are sent for the purpose of interrupting the proper operation and use of his system.”However, if the facts of a denial of service attack are varied slightly then criminal damage may no longer be an appropriate charge. Suppose for example that C sets out to hinder access to D’s publicly available website, and does so by programming several computers to repeatedly download large pages from the site. The result is to use up D’s bandwidth and ensure that other users cannot get through to the site, though the server itself continues to function. What crime, if any, has been committed?
In this case C would not have damaged D’s data (assuming that C downloaded data only and did not make any modifications to the data on the server). It might be argued that C has committed criminal damage to the server itself given the extended definition of “damage” under section 1, which includes situations where a person “whether temporarily or otherwise, render[s] inoperable or unfit for use or prevent[s] or impair[s] the operation of” property.
Such a charge would, however, prevent some difficulties. It might be successful if the effect of a denial of service attack was to cause the server to crash – that temporary inoperability would certainly seem to constitute damage within the meaning of section 1. In the hypothetical above, however, C has not rendered the server inoperable but merely inaccessible – which would seem to fall outside the scope of the criminal damage offence.
On the other hand, using the reasoning in DPP v. Lennon it might be possible to characterise the attack as unauthorised access contrary to section 5 of the Criminal Damage Act 1991. The argument could be made that while public websites carry with them an implied permission to access the site, this permission does not (to use the words of Jack J.) cover visits which are “the purpose of interrupting the proper operation and use of [the] system”, so that such a visit would constitute operation of the server with intent to access data without lawful excuse.
Friday, July 03, 2009
Search engines and safe harbours
Danny O'Brien has a strong piece in today's Irish Times arguing that Irish and European law is holding back development of online businesses by imposing excessive liabilities on search engines. Here's an excerpt:
In the US, the law specifically carves out a protection against liability for "information location tools" - search engines, in other words.I'm in agreement with Danny and would go one step further - rather than limit a new immunity to search engines, we should extend it to other online intermediaries such as content aggregators. This 2006 report from the UK Department of Trade and Industry is a good starting point for understanding how content aggregators and others are deterred by possible liability.
It is the same sort of "safe harbour" that protects web hosting services from being sued over their customers' content and internet service providers and mobile phone companies from being penalised for making temporary caches of websites to cut down connection costs and speed up connections.
No such protection exists in Europe for search engines. However the very fact that these US search engine companies are so large and, moreover, have large subsidiaries in Europe and beyond, gives them a little more protection from midnight raids than start-ups like SurfTheChannel.
It also provides them with something of an economic advantage over any upstart European search engine.
When Bing, the new Microsoft search engine, was launched, only a few noted that its "video search" effectively embedded copyrighted content on to Microsoft's own website (try typing The Office into its video search and see what happens).
If that had been a European search engine launched by a plucky new start-up, you can bet that its lawyers would have warned them off such a feature.
This effectively means that one of the biggest selling points of Microsoft's Google competitor is out of bounds for any European contender...
Perhaps the best solution would be for individual countries in the EU to make themselves more business friendly.
The e-commerce directive already allows individual nations to carve out wider exceptions than those listed.
Countries like Spain, Portugal and Austria have all included some protection to search engines, as well as anyone providing a weblink to another website.
Perhaps Ireland could create its own "safe harbour" in national law for new internet start-ups.
That way, we could draw investment from other countries who want the benefit of being able to find what we need on the internet but are scared to alienate the vested interests who would rather choke it. (emphasis added)
Thursday, July 02, 2009
The Music Industry v. ISPs - Round 2 - UPC and BT vow to fight
UPC
The company is now preparing its defence and intends to vigorously defend its position in Court...BT are more laconic:
UPC has made its position clear from the outset -- it will not agree to a request that goes beyond what is currently provided under existing legislation. There is no basis under Irish law requiring ISPs to control, access or block the internet content its users download. In addition, the rights holders' proposal gives rise to serious concerns for data privacy and consumer contract law.
Irish and European law maintains a careful balance between the rights and obligations of copyright owners, internet users and ISPs. The three strikes policy that was agreed in private with eircom as part of the settlement, and any attempt to impose in upon the industry generally, seriously undermines that balance.
It is unfortunate that the rightsholders did not take up UPC's suggestion that it convene a stakeholder forum in which their concerns could be addressed. UPC indicated that it would be willing to participate in such a forum provided all relevant parties that have a vested interest in this matter were included (eg ISPs, the Data Protection Commission, the National Consumer Agency and relevant Departments of the Government). (Emphasis added)
BT Ireland believes there is no legal basis for such a claim and the proceedings will accordingly be strongly defended.
Tuesday, June 30, 2009
Quote of the day
Beware the Four Horsemen of the Information Apocalypse: terrorists, drug dealers, kidnappers, and child pornographers. Seems like you can scare any public into allowing the government to do anything with those four.- Bruce Schneier
Thursday, June 25, 2009
Bord Gais Laptop Loss
I wrote an opinion piece for the Sunday Business Post on the recent Bord Gais laptop loss - using it as a jumping off point to argue for a data breach notification law in Ireland. Here's an excerpt:
It hasn’t been a good week for personal information. Last Tuesday, the HSE admitted that it had lost an unencrypted laptop containing sensitive information, including particular social work case notes on nine families.More from the Digital Rights Ireland perspective here. What Irish bloggers have been saying about the Bord Gais scandal here.
Remarkably, the HSE had not reported this loss to the Data Protection Commissioner, who learned of the incident from media reports. The HSE incident was eclipsed the following day when Bord Gáis revealed that it had lost an unencrypted laptop with account details - including bank and credit card information - on 75,000 customers, exposing them to the risk of identity theft.
Unfortunately, these are not isolated incidents. In the last year alone, multiple cases have come to light: notably Bank of Ireland, which lost personal data on more than 30,000 life assurance customers; the Office of the Comptroller and Auditor General, which lost information on 380,000 social welfare recipients; and Airtricity which posted the financial details of 1,200 customers on its website for six weeks.
Why have Irish organisations been so slipshod with the information we have entrusted to them? One problem is that the bodies that hold the data suffer little direct damage if the data is lost - it is the individual, not the company, who suffers the harm. Consequently, there is little financial incentive for them to take adequate measures to protect our data.
This is compounded by a lack of transparency. Under Irish law, there is no express obligation for a company that has lost customer data to notify anyone - neither the customer nor the Data Protection Commissioner.
The result is that organisations try to cover up data breaches to save face. Consequently, if your details are leaked, it is entirely possible that the first you will know of it is when you discover that your fraudulent alter ego has enjoyed a spending spree on your credit card or run up huge debts in your name. By then, it’s too late.
Thursday, June 18, 2009
The Music Industry v. ISPs - Round 2
After their inconclusive action against Eircom, this time the music industry is suing UPC and BT. Proceedings were issued on Tuesday according to the (stupidly not hot-linkable) search facility on courts.ie. Expect the cat to be put among the pigeons shortly.
I believe that litigation demanding that ISPs monitor what their users do and/or disconnect users based on three unproven allegations is unjustified - for the reasons why, see the Digital Rights Ireland site in relation to user monitoring and three strikes.
Digital Britain and the Internet Watch Foundation
But one aspect of the report which has received less attention (with the notable exception of the Register) is its discussion of the Internet Watch Foundation (pp. 202-203). This is relatively short so it's worth posting in full:
Criminal Material on the InternetWhat to make of this discussion? First, it's noticeably uncritical. For example, the claim that the "IWF model ... is a success and is admired internationally" simply ignores the criticisms that have been voiced of the IWF model by observers such as Lilian Edwards, Frank Fisher, Richard Clayton (pdf) and others.
64. The Internet Watch Foundation, based in Cambridge and with just 15 employees, is tasked with minimising the availability of criminal content – specifically, child sexual abuse content hosted anywhere in the world and criminally obscene and incitement to racial hatred content hosted in the UK. It works with law enforcement agencies worldwide and operates a "notice and take down" procedure in relation to content on UK sites and a list of international child abuse sites that ISPs can block at the network level. The vast majority of UK networks use this list and discussions are under way to ensure that relevant consumer networks are comprehensively covered.
65. As a result of the partnership approach adopted by the IWF, less than 1% of child sexual abuse content, known to the IWF, has been hosted in the UK since 2003, down from 18% in 1997. The IWF’s work remains invaluable to every part of the value chain in the UK’s Internet industry. And, in a world of universal availability, increasing take-up and enhanced services on the network the work of the IWF will become more and more important.
66. IWF’s current income includes a contribution from the EU Safer Internet Action Plan with the bulk being derived from voluntary membership subscriptions. Its current income equates to some £1m per annum. This voluntary structure means that there is no certainty that the level of funding received now from the EU or from its membership will continue at this level in the future. In the current economic climate a voluntary funding base carries with it increased uncertainty over funding. Whereas having secure funding would allow the IWF to consider expanding its internal skill base, especially with regard to hiring additional technical expertise and raising greater awareness amongst Internet users about their role and remit. The IWF model of self-regulation is a success and is admired internationally, but if the regulation of criminal content is not adequately funded by industry, Government would need to consider statutory intervention. We therefore call on the IWF membership to propose a more secure funding model for the future.
67. The IWF has also been a model for international hotlines for reporting child abuse material, especially across the EU. Some operators already use its list of illegal sites internationally. Since most child abuse material originates outside the EU, there is a case for its operations to cover at least the whole of the EU. We will therefore explore with the IWF and the European Commission the scope for a pan-European model with commensurate funding.
In part, this flows from a second problem with the report - it doesn't differentiate between the role of the IWF in dealing with illegal material hosted in the UK (which is generally regarded as successful) with its role in providing a blacklist against which ISPs can/must filter (a much more controversial and ineffective endeavour). By conflating the two it attempts to use the success of the hosting remit to justify expansion of the very different filtering remit.
Third, the report - by referring to exploring "a pan-European model" - appears to be unaware of the fact that there are already proposals at an EU level for internet filtering. In fact, far from exporting the IWF model to Europe those proposals - by requiring the involvement of "judicial or police authorities" and "adequate safeguards ... to ensure that the blocking is limited to what is necessary, that users are informed of the reason for the blocking and that content providers are informed of the possibility of challenging it" - would if adopted require the IWF model to be entirely rebuilt.
Overall, therefore, the report's analysis of the IWF is quite flawed - undermining the recommendations it makes in respect of funding. It will be interesting to see how IWF members respond.
Incidentally, it's also been a busy week elsewhere in Europe in relation to internet filtering as proposed German legislation to require blocking of child pornography appears to be agreed between the main parties.
Monday, June 15, 2009
A must see - Tony Bunyan comes to Dublin
Tony Bunyan is one of the stalwarts of the civil liberties movement in the UK and Europe. As a journalist, writer and founder of Statewatch he's been at the very forefront of monitoring what governments and the European Union have been doing in our name (but without our knowledge). The Irish Council for Civil Liberties is bringing him to Dublin next Saturday (20th June) to talk about his new report, "The Shape of Things to Come" - and I can't recommend this event highly enough to anyone interested in law, technology and civil liberties. It will be held in The Blue Room, Law Society of Ireland, Blackhall Place, Dublin 7 (map) at 3.30pm. The talk is free but spaces are limited so if you'd like to go, contact Joanne Garvey (Tel: 01-7994504 or E-mail: info@iccl.ie) to ensure a place.
Update: The Irish Times has a report from the talk.
Update: The Irish Times has a report from the talk.
Monday, June 08, 2009
Surveillance Bill "will fail to tackle gangs"
John O'Brien - a former Detective Chief Superintendent - has an interesting opinion piece in the Irish Times arguing that the Surveillance Bill is likely to be inadequate. Here's an excerpt where he summarises his objections:
1. It adopts a generalist approach by seeking to apply this law to the entire population and not directly to criminal organisations as defined in the Criminal Justice Act 2006.
2. The threats emanate from specific and defined sources, criminal gangs and subversive organisations. The threats do not emanate from the population as a whole and arguably the population as a whole should not be subjected to these measures.
3. The definition of surveillance data is far too wide.
4. It can be construed to include all surveillance activity, including intelligence and evidential material.
5. The material received from foreign agencies could be disclosable and electronic devices fitted by them to assist Irish authorities could be rendered inadmissible.
6. There may be a loss of confidence at international level in the Irish systems which may inhibit the flow of intelligence and subsequently of evidence.
7. The rules on disclosure are unclear.
8. It is not clear if telephones and electronic mail are covered. Some of the measures may have the effect of neutralising current surveillance practices, particularly in relation to telephone intercepts and electronic mail.
9. Placing authorisations at the District Court level is unnecessarily indulgent and it exposes a greater number to possible threats from the criminal elements.
10. The authorisation process is rigid at the operational level and lacks operational reality.
11. The rules on privilege are also unclear.
12. Surveillance officers may be compromised in terms of personal safety and their identities may become known to the criminal gangs.
13. Their operational effectiveness may be impaired and, of course, they will spend much more time dealing with bureaucracy.
14. It is not clear whether individual surveillance actions will have to be authorised on a piecemeal basis and the thrust of the Bill seems to suggest that approach. This would hamstring fast flowing dynamic operations.
15. The Bill seems to miss the point that surveillance activity is, by its very definition, a secret activity and its efficiency depends on the practitioners maintaining a high level of security for their own safety and that of others.
Tuesday, June 02, 2009
Computers, Freedom & Privacy 2009
I'm lucky enough to be at Computers Freedom & Privacy 2009, which has just started in George Washington University with a opening talk from Susan Crawford. She's been appointed as Special Assistant to the President for Science, Technology, and Innovation Policy, and her talk (and the hosting of CFP in Washington this year) reflects a buzz of excitement here about the new administration and the possibility for change in technology and privacy policy.
Video of most of the conference proceedings is being streamed live online. There's also a twitter feed at #cfp09 and an event blog.
Video of most of the conference proceedings is being streamed live online. There's also a twitter feed at #cfp09 and an event blog.
Tuesday, May 26, 2009
Mulvaney v. Betfair - High Court holds that hosting defence is available to chatroom operators
Can a chatroom operator rely on the hosting defence under the E-Commerce Directive? In the first Irish case to consider the scope of the Directive and the Irish implementing Regulations the High Court has held that the answer is yes - an answer which may have significant implications for Irish sites hosting other types of user generated content.
The case - Mulvaney v. The Sporting Exchange (trading as Betfair) - involved plaintiffs who claimed to have been defamed by material posted on a Betfair chatroom by Betfair clients. The plaintiffs brought proceedings against the posters themselves and also against Betfair as the operator of the chatroom, claiming that Betfair was therefore liable as a publisher of the defamatory statements.
Betfair sought to rely on the hosting defence in Article 14 of the E-Commerce Directive as implemented by Regulation 18 of the implementing Regulations. Two issues therefore arose: whether Betfair could rely on this defence notwithstanding the gambling exclusion in the Directive / Regulations, and whether in relation to the chatroom Betfair could be said to be a host.
As regards the gambling issue, the court took the view that whether or not Betfair's main function (as a betting exchange) was covered by the exclusion, the chatroom was not directly connected with that activity and as such it could be treated as a distinct activity for the purposes of the Directive.
The court then considered whether Betfair could be considered to be a host in respect of the chatroom, or more precisely whether it was an "intermediary service provider who provides a relevant service consisting of the storage of information provided by a recipient of the service". Here the court relied on Bunt v. Tilley to hold that Betfair was an "intermediary service provider" and, in a remarkably short ruling, held that it fell within the hosting defence:
There's no discussion, for example, of the fact that the chatroom was subject to terms of use and was (apparently) moderated by Betfair - a surprising oversight, considering that it might have been the basis for an argument that the posters were acting under the control of Betfair which, if successful, would have ruled out the hosting defence. (See e.g. the analysis of Lilian Edwards in respect of eBay's "control" over its users.)
Equally, there's no reference to the related argument that the hosting defence is intended to cover purely technical (and essentially passive) storage of information, and is lost when a provider exercises a greater degree of control over the information which users provide. Goldstone and Gill, for example, suggest that:
Finally, there's no reference to the cases in other jurisdictions which have challenged the scope of the Article 14 hosting immunity. (Lilian Edwards has some examples here and more recently here.)
Consequently, although this decision will give some comfort to Irish chatroom operators, it shouldn't be given too much weight and is unlikely to be the last word on the scope of the hosting defence in Ireland. We may have to wait for a more fully reasoned judgment (or guidance from the ECJ) before we can definitively say what rules apply to Irish sites which host user generated content.
For more on this decision see A&L Goodbody | Olswang | Sunday Business Post.
The case - Mulvaney v. The Sporting Exchange (trading as Betfair) - involved plaintiffs who claimed to have been defamed by material posted on a Betfair chatroom by Betfair clients. The plaintiffs brought proceedings against the posters themselves and also against Betfair as the operator of the chatroom, claiming that Betfair was therefore liable as a publisher of the defamatory statements.
Betfair sought to rely on the hosting defence in Article 14 of the E-Commerce Directive as implemented by Regulation 18 of the implementing Regulations. Two issues therefore arose: whether Betfair could rely on this defence notwithstanding the gambling exclusion in the Directive / Regulations, and whether in relation to the chatroom Betfair could be said to be a host.
As regards the gambling issue, the court took the view that whether or not Betfair's main function (as a betting exchange) was covered by the exclusion, the chatroom was not directly connected with that activity and as such it could be treated as a distinct activity for the purposes of the Directive.
The court then considered whether Betfair could be considered to be a host in respect of the chatroom, or more precisely whether it was an "intermediary service provider who provides a relevant service consisting of the storage of information provided by a recipient of the service". Here the court relied on Bunt v. Tilley to hold that Betfair was an "intermediary service provider" and, in a remarkably short ruling, held that it fell within the hosting defence:
5.10 Betfair submitted that, in the present case, it is the third parties who provided the information in question, i.e. the allegedly defamatory comments, and that Betfair stored this information on its servers that hosted the Chatroom. Betfair submitted that this service was provided at a distance by electronic means and at the individual request of the recipient of the service. It is submitted by Betfair that it, therefore, acted as "hosts" of that information for the purposes of Regulation 18 of the 2003 Regulations.This conclusion - that chatroom operators are hosts as regards user comments - appears to me to be correct, but the underlying reasoning is rather scanty. (I should say that this is not a criticism of the judge, who can only decide on the arguments raised by the parties.)
5.11 At Recital 20, the E-Commerce Directive states that:-“The definition of 'recipient of a service' covers all types of usage of information society services, both by persons who provide information to open networks such as the Internet and by persons who seek information on the Internet for private of professional reasons.”
5.12 It seems to me that this provision clearly covers such use of the services provided by the defendant as was made by the third parties in these proceedings. Furthermore, at Recital 18 of the E-Commerce Directive, it is provided, inter alia, that:-"Information society services span a wide range of economic activities which take place on-line; these activities can, in particular, consists of selling goods on-line; activities such as the delivery of goods as such or the provision of service off-line are not covered; information society services are not solely restricted to services giving rise to on-line contracting but also, in so far as they represent an economic activity , extend to services which are not remunerated by those who receive them, such as those offering on-line information or commercial communications, or those providing tools allowing for search, access and retrieval of data; information society services also include services consisting of the transmission of information via a communication network, in providing access to a communication network or in hosting information provided by a recipient of the service."5.13 There is no case law dealing directly with the question of whether Regulation 18 covers the provision of Chatroom facilities. However the E-Commerce Directive appears to apply to chatrooms if they are hosting information provided by a recipient of the service and available to other users of the service. In addition, the corresponding Article to Regulation 18 (i.e. Article 14), has been recognised in the Report from the Commission to the European Parliament on the application of the E-Commerce Directive, where at page 12 , it states:-"In particular, the limitation on liability for hosting in Article 14 covered different scenarios in which third party content is stored apart from the hosting of websites, for example, also bulletin boards or 'chatrooms'."5.14 As the service provided by Betfair, through its Chatroom, clearly falls within the meaning of "relevant service" as defined by the 2003 Regulations, it follows that Betfair, in providing this service, is a "relevant service provider" and so an "intermediary service provider" within the meaning of the 2003 Regulations. Betfair is, therefore, entitled to the benefits of Regulations 15 and 18 of the 2003 Regulations.
6. Conclusions
6.1 ... For the reasons which I have just sought to analyse, I am also satisfied that the provision of a chatroom service comes within the definition of an intermediary service provider contained in the 2003 Regulations, and that the provision of that service to its subscribers by Betfair constitutes the provision of a relevant service consisting of the storage of information provided by a recipient of the service within the meaning of the same Regulations.
6.2 If follows that Betfair are, in principle, entitled to the protection of the E-Commerce Directive in these proceedings. In order to be able, successfully, to defend the proceedings on that basis it is, of course, also necessary that Betfair be able to establish, as a matter of fact, in each individual case, that the conditions concerning knowledge and expeditious action set out in subparas (a) and (b) of Article 14 of the E-Commerce Directive are met. Whether that can be established on the facts of this case is a matter which did not arise on this preliminary hearing and will fall to be determined at the trial.
There's no discussion, for example, of the fact that the chatroom was subject to terms of use and was (apparently) moderated by Betfair - a surprising oversight, considering that it might have been the basis for an argument that the posters were acting under the control of Betfair which, if successful, would have ruled out the hosting defence. (See e.g. the analysis of Lilian Edwards in respect of eBay's "control" over its users.)
Equally, there's no reference to the related argument that the hosting defence is intended to cover purely technical (and essentially passive) storage of information, and is lost when a provider exercises a greater degree of control over the information which users provide. Goldstone and Gill, for example, suggest that:
The recitals to the Directive are narrow in scope and state, for example, that the activities to which the exemptions apply are 'limited to the technical process of operating and giving access to a communication network' and are of a 'mere technical, automatic and passive nature'. The recitals do not suggest that the Directive intended the hosting defence also to apply to storage of information by Web site operators such as UGC Web sites.Whether correct or not, it is remarkable that this argument doesn't appear to have been made in this case.
Finally, there's no reference to the cases in other jurisdictions which have challenged the scope of the Article 14 hosting immunity. (Lilian Edwards has some examples here and more recently here.)
Consequently, although this decision will give some comfort to Irish chatroom operators, it shouldn't be given too much weight and is unlikely to be the last word on the scope of the hosting defence in Ireland. We may have to wait for a more fully reasoned judgment (or guidance from the ECJ) before we can definitively say what rules apply to Irish sites which host user generated content.
For more on this decision see A&L Goodbody | Olswang | Sunday Business Post.
Friday, May 15, 2009
Transparency in overseeing state surveillance: How not to do it
Under Irish law a designated High Court judge (currently Mr. Justice Iarfhlaith O'Neill) is assigned to oversee the operation of telephone tapping and data retention. Unfortunately, the annual reports of the designated judges are not exactly models of transparency. Here's the most recent example - all three paragraphs of it:

I'll be writing more about Irish law in this area shortly: stay tuned. (Or should I say "keep listening"?)
Edited to add: The Sunday Times has now picked up on this issue.
I'll be writing more about Irish law in this area shortly: stay tuned. (Or should I say "keep listening"?)
Edited to add: The Sunday Times has now picked up on this issue.
Tuesday, May 05, 2009
UCD Launches MSc In Digital Investigation
Shameless plug ahead - I'm happy to say that I will be teaching next year on a new course offered by the UCD School of Computer Science and Informatics, the MSc in Digital Investigation. This is essentially a civilian counterpart to the successful MSc in Forensic Computing and Cybercrime which is restricted to police officers. Full details on the course site, but here's a brief outline:
This programme is aimed at information security professionals who need to acquire skills for investigation of computer-related incidents. It introduces the concepts, principles, and professional practice in digital investigation. The programme is delivered in cooperation with the leading Irish experts in the field.
Programme Structure
This is a two-year part-time course. The first three semesters of the course, are made up of six examinable modules, which cover all areas of investigative expertise from legislation and forensic analysis techniques to presentation of investigation results in the court of law:
* Computer Forensics Foundations
* Law for IT Investigators
* Application Forensics
* Investigative Techniques
* Corporate Investigations
* Information Security
The fourth semester of the course comprises an individual research project on a real-world topic in digital investigation.
Friday, May 01, 2009
IWF Annual Report: Wikipedia blocking and more
The Internet Watch Foundation has just issued its 2008 Annual Report (PDF) where it offers this defence of its role in the Wikipedia blocking saga, along with an indication that it will review its procedures in light of this case:
Incidentally, the annual report is also interesting in that it signals a move towards tackling child pornography by targeting a new type of intermediaries - by seeking to have domain name registries delist domain names involved in the sale of child pornography. This follows a trend I've noted before - towards domain name registrars / registries becoming the new points of control for regulators.
Wikipedia on the IWF listMy take? The Wikipedia debacle created a number of fundamental challenges for the IWF in relation to its reputation, procedures and legitimacy, as well as undermining the technical claims for the efficacy of internet filtering. This IWF response offers the possibility that they will address these issues - but it remains to be seen whether the outcome will be (possibly modified) business as usual or whether there will be a fundamental rethink of the IWF's role in internet filtering.
In December our hotline received a report regarding an indecent image of a pre-pubescent girl on a Wikipedia page. The image was assessed according to current UK legislation, in accordance with the UK Sentencing Guidelines Council thresholds (see page 8, Figure 5) and was considered to be potentially illegal.
Our procedures require us to pass details of every URL considered to be in breach of UK legislation to law enforcement and hotline associates around the world for further investigation, in accordance with the laws in the hosting country. If the URL is hosted outside the UK, it is also added to our URL list which is provided to companies in the online sector that have voluntarily committed to blocking access to these URLs to help protect their customers from inadvertent exposure to indecent images of children online.
These procedures and policies are approved by our Board of Trustees and Funding Council, and our hotline systems, security and processes, including the handling of the URL list, are periodically audited by external independent inspectors, including forensic, academic and law enforcement professionals identified by our Board.
In this particular case there was an unforeseen technical side-effect of blocking access to the Wikipedia page in question. Due to the way some ISPs block, users accessing Wikipedia from these ISPs appeared to be using the same IP address. This undermined the way Wikipedia controls vandalism therefore anonymous UK Wikipedia users were blocked from editing.
Following representations from Wikipedia the IWF invoked its Appeals Procedure. This entails a review of the original decision with law enforcement officers. They confirmed the original assessment and this information was conveyed to Wikipedia. Due to the public interest in this matter our Board closely monitored the situation and, once the appeals process was complete, they convened to consider the contextual issues involved in this specific case. IWF’s overriding objective is to minimise the availability of indecent images of children on the internet, however, on this occasion our efforts had the opposite effect so the Board decided that the webpage should be removed from the URL list.
As a learning organisation we are committed to improving our services so issues raised by this incident will be addressed, in collaboration with our industry partners, in the year ahead. (p.9)
Incidentally, the annual report is also interesting in that it signals a move towards tackling child pornography by targeting a new type of intermediaries - by seeking to have domain name registries delist domain names involved in the sale of child pornography. This follows a trend I've noted before - towards domain name registrars / registries becoming the new points of control for regulators.
Sunday, April 26, 2009
Realm Communications backs down from RegTel challenge
Remember the High Court challenge brought by Realm Communications (of Irish Psychics Live fame) against industry self-regulatory body RegTel? (Full details in this earlier post, but in short Realm were found to have been overcharging customers in breach of the Regtel Code of Practice and were banned from sending premium texts for twelve months.) In an apparent victory for RegTel, Realm has now agreed to abandon that action, to revise its services and to pay refunds in respect of customer complaints - though it seems that the twelve month ban has been waived. (Irish Times | Statement from Regtel)
The significance of this result? Although the result has no precedential value, it should strengthen the hand of Regtel in taking action against persistent breaches by removing a lingering threat about the scope of its authority. Perhaps more importantly from their perspective, it may also support the argument that premium rate services should be controlled by self-regulation via Regtel rather than (as the Minister has previously proposed) by statutory regulation giving new powers to ComReg.
The significance of this result? Although the result has no precedential value, it should strengthen the hand of Regtel in taking action against persistent breaches by removing a lingering threat about the scope of its authority. Perhaps more importantly from their perspective, it may also support the argument that premium rate services should be controlled by self-regulation via Regtel rather than (as the Minister has previously proposed) by statutory regulation giving new powers to ComReg.
Sunday, April 19, 2009
Thoughts on the new Surveillance Bill
I've a piece in today's Sunday Business Post on the Department of Justice's new Surveillance Bill. For some reason it's not online, so here's the full text:
Operation Observation Comes to IrelandEdited to add: It's now available here.
This week the Department of Justice published a Surveillance Bill which, if enacted, will allow Gardaà to break into private property to place covert video cameras and audio bugs, to plant tracking devices on cars and to use evidence gathered in this way in criminal prosecutions. The Bill – which was already on the legislative programme but was rushed forward after the murders in Limerick of Shane Geoghegan and Roy Collins – is intended to place existing Garda practices on a statutory basis in line with Ireland’s obligations under the European Convention on Human Rights.
Currently, due to the lack of statutory controls, material gathered in this way –such as transcripts of conversations – can be used for intelligence purposes but would not be admissible in criminal trials. The Bill aims to remedy this by providing that Gardaà will generally have to obtain permission from a District Court judge before this type of surveillance can be carried out (except for tracking devices and urgent cases, where internal permission will suffice) and that a designated judge of the High Court will keep the overall operation of the system under review. In addition, these methods can only be used in respect of crimes carrying a possible sentence of at least five years imprisonment and where the surveillance is, in all the circumstances, proportionate.
The Bill promises to regularise the law in this area and to that extent must be welcomed. It is unfortunate, however, that it took a number of high profile and tragic killings before this was given priority. As far back as 1996 the Law Reform Commission in a consultation paper identified a need for reform and in a 1998 report it recommended that there should be a legal basis for Garda surveillance of this type. Successive Ministers for Justice have, however, largely ignored this recommendation, most notably in 2006 when the Privacy Bill introduced by then Minister for Justice Michael McDowell targeted surveillance by the media – but entirely excluded Garda surveillance from its scope. In light of over a decade of government inactivity, the Bill is long overdue.
The timing of the Bill aside, its provisions generally represent a substantial step forward. It has clearly been influenced by the constitutional guarantee of the inviolability of the dwelling and the safeguards which it provides are more robust than those recommended in 1998 by the Law Reform Commission. It introduces for the first time in Irish law the principle that judicial approval should be required before surveillance is carried out. Unlike other forms of surveillance such as data retention – which currently can be used in respect of even the most minor crimes – the Bill is limited to genuinely serious offences and also introduces a requirement that the surveillance must be proportionate having regard to the impact on the rights of innocent third parties.
There are of course some aspects of the Bill which could be improved. For example, the procedure to deal with cases of exceptional urgency is too lax. Under the Bill as it stands those cases would bypass the judicial process entirely, so that surveillance could take place for up to 3 days without any authorisation. There must be a question mark as to whether this provision would be constitutional if it was used to break into and bug a dwelling. Instead, it would be preferable to deal with cases of urgency by permitting Gardaà to commence surveillance without a judicial authorisation but then requiring that an application be made to the District Court for retrospective approval and/or permission to continue the surveillance. There must also be a question mark over the proposal to allow the use of tracking devices on vehicles – for up to four months – without any judicial approval.
Also, while the Bill is generally good as far as it goes, there is a strong argument to be made that it doesn’t go nearly far enough.
Despite its broad title – the Criminal Justice (Surveillance) Bill 2009 – it seems to be intended to deal with one narrow form of surveillance: covert surveillance by devices which are physically planted in certain locations. Many other forms of surveillance – such as the use of long lenses to observe locations from a distance and live monitoring of internet activity – will still be entirely unregulated. As a result there will continue to be doubt as to whether Gardaà have the power to use these types of surveillance and as to whether the resulting evidence can be used in criminal prosecutions. It is likely that there will be criminal cases in the future which fail as a result.
Meanwhile, although there is some legislation regulating other forms of surveillance such as the interception of communications, data retention and Garda use of CCTV, that legislation has developed on an ad hoc and reactive basis with few consistent principles applying to its use or oversight. Much of it is also out of date, most notably the 1993 interception of communications legislation. That law was designed with voice telephony and faxes in mind but due to technological changes no longer adequately protects email and other internet communications. For example, the law does not cover interception of internet telephone calls using services such as Skype, nor does it protect users of webmail services such as Gmail or Hotmail. In addition, Irish law currently protects messages only as they are “being transmitted”, making it likely that the stored contents of a person’s inbox would not be protected.
This ad hoc legislative framework also suffers from weak oversight mechanisms. Although the legislation provides for a designated judge to oversee interception, data retention and now covert surveillance, the annual reports of that judge have consisted of no more than a single page stating that the operation of the law has been kept under review and its provisions are being complied with. Compared with the UK system, for example, Irish law has little public accountability in relation to matters such as the volume of surveillance being carried out; whether individual files are reviewed to ensure correct procedures were followed; or whether mistakes were made such as the targeting of the wrong individual or number and what steps were taken to safeguard against such mistakes in future.
Considered as a whole, therefore, the wider Irish law is inadequate. Given that many of these issues were flagged by the Law Reform Commission in 1998, it is hard to see any justification for the failure to address them to date. Although this Bill does provide for some improvements, it is at best a piecemeal response which will not address similar problems with other forms of surveillance. It is clear that the time has come for comprehensive reform of the overall law relating to surveillance. This Bill is a good first step towards that reform. But it is only a first step, and it would be regrettable if the government were to continue to ignore this area until forced to act by another highly visible crime.
TJ McIntyre is a solicitor, Lecturer in Law in UCD and Chairman of Digital Rights Ireland
Wednesday, April 15, 2009
Perspectives on internet filtering
In light of recent EU moves towards internet filtering now might be a good time to point to a paper by Colin Scott and myself where we argue that filtering risks jeopardising values we associate with freedom of expression - in particular legitimacy, transparency and accountability. It's available on SSRN here. If you find that paper interesting you might also enjoy the collection of essays from which it was taken - Brownsword and Yeung (eds.), Regulating Technologies.
Subscribe to:
Posts (Atom)