Friday, October 24, 2014

Discovery of encrypted documents

Today's Irish Times has a story arising out of the Quinn litigation against the state which raises important issues around access to encrypted documents:
The family of Seán Quinn is demanding access to three letters sent between former minister for finance Brian Lenihan and then chairman of Anglo Irish Bank Donal O’Connor as part its €2.34 billion claim against the state.  This correspondence relates to late January 2009 and early February 2009, just after the state took the decision to nationalise Anglo as it tottered on the brink of collapse. The family also wants efforts to be made to crack a password-protected email sent by the bank’s chief executive David Drumm to Matt Moran, a close lieutenant, in the midst of the financial crisis in April 2008, according to documents filed in relation to their legal battle...

Legal advisers to the liquidators of IBRC, who are now in charge of Anglo, are refusing to release about 168 documents which they claim are legally privileged, with the exception of the email from Mr Drumm to Mr Moran which they cannot access... [The Quinns] have asked the liquidators of IBRC to instruct IT experts to crack the encoded email or give it to the family so that they can try to do so.

I've already looked at the encrypted Anglo files from a criminal law perspective, considering when police can demand that files be decrypted or that individuals hand over passwords. This case presents parallel civil law issues - when can a party in litigation demand that potentially relevant files be decrypted as part of the discovery process, when the other party does not have the relevant passwords?

This will be the first time this is considered by the Irish courts. There doesn't appear to be any case law on the topic, and it's not explicitly addressed in the Rules of the Superior Courts. It's also not considered in the Law Reform Commission's (rather disappointing) 2009 Consultation Paper on Documentary and Electronic Evidence. The closest Irish material is the 2013 Good Practice Guide to Electronic Discovery in Ireland which suggests that parties making discovery should if necessary attempt to break the protection on encrypted or password protected files (PDF, p.23).

I look forward to seeing the decision on this point.

Tuesday, October 21, 2014

Garda body cameras: quis custodiet ipsos custodes?

Garda body worn camera - screencap from Dublin Says No protest video.
I had a piece in Saturday's Irish Independent on the implications of the new Garda body worn cameras being used at protests against water charges. There wasn't enough room in 750 words to tackle all the issues involved so here are some thoughts that didn't make it into the finished piece:

* While there is almost no transparency around the use of the cameras, for the moment it looks as though they are only being used at protests. This is a relatively straightforward case - public protests are the best case scenario for the use of cameras as situations where there is a limited privacy interest on both sides and a likelihood of confrontation - but isn't at all representative of the problems that would be faced if cameras were rolled out to ordinary policing. For example, would cameras be turned off when gardaí are in private homes? In hospitals?

* In particular, there is a real risk that the use of cameras in day to day policing will lead to a more wary relationship with the public. Will people be deterred from talking to gardaí for fear that their casual conversations may be recorded and reviewed?

* The main financial cost lies not in the cameras themselves but in the management of the recordings they generate. Video requires lots of storage and systems in place to deal with transfer of material from device to server, deletion of material once the retention period is up, flagging of particular recordings to be stored, search and retrieval of material which might be spread across a number of different stations, backups and archiving, ensuring that older file formats can still be read, responding to subject access requests, etc. Have these points have been taken into account in garda planning? Or will we end up with another case of garda tapes being stored randomly in cardboard boxes and covered in mould?

* At the moment garda management are saying very little about these new cameras. In a few months the Freedom of Information Act 2014 will be extended to An Garda Síochána - but in the meantime anyone who has been videoed at a protest can find out more by making a (free) request under s.3 of the Data Protection Acts to determine what data from the cameras are being held and the purposes for which they are being kept.

Thursday, October 02, 2014

Watering down data protection

© P L Chadwick CC-BY-SA-2.0.
It was never likely that people would be happy about paying directly for their water. But public resentment has been stoked further by the invasive questions on the Irish Water application forms, which demand PPS numbers for the householder and all children before the free allowances are granted.
That resentment was only exacerbated when people looked at the data protection notice on the website to discover that Irish Water claims the right to use our personal information to market to us via unsolicited text messages, emails, junk mail and telephone calls and even to send salesmen to “contact the customer… in person”.

What do they propose to sell us? The website says that Irish Water or its agents may contact us about “water related products or services”, whatever those might be. Bathtubs? Swimming lessons? Boats? Perhaps we should expect phone calls at dinnertime which begin “Hi there. I’m calling you today because your body is 66% water.”

Irish Water also claims the right to send our information outside of Europe, which would allow outsourcing of their operations (for example, call centres or IT support) to a low cost location such as India. As originally drafted, their website also stated that information would be disclosed if Irish Water was bought by a third party – though they have since deleted this last point, no doubt because it is too close to the political hot potato that is privatisation of the water system.

Are Irish Water entitled to do these things with our information?

Let’s start with PPS numbers. There has been some talk of the criminal offence of requesting a PPS number without legal authority, but that is a red herring: since July Irish Water has been a specified body entitled to use PPS numbers.

However, the fact that they are seeking PPS numbers at all points to a flawed system

For example, Irish Water tell us that they need PPS numbers of children to confirm their eligibility for a water allowance. Yet the Department of Social Protection already holds this information in relation to child benefit. Rather than create an additional bureaucracy within Irish Water it would have been preferable to leave this within the existing state agency – for example, by simply adding the relevant amount to the child benefit payment. This is already being done for the household benefit, which will be increased by an additional €100 each year towards water bills without any need for anyone in Irish Water to know who is on household benefit.

(Using PPS numbers also creates a fresh problem. Many residents in Ireland - such as foreign students and foreign pensioners - will not have PPS numbers. What is to happen to their allowances?)

Quite apart from the initial request for PPS numbers there is also a problem with ongoing storage. While Irish Water may need PPS numbers to verify water allowances initially, that is no reason to continue storing them once this is done. It is a fundamental rule that personal information should not be stored for longer than necessary – especially in cases such as this, where Irish Water would end up holding a vast database which would be vulnerable to both corrupt insiders and outside attackers. Their apparent intention to store PPS numbers in this way is likely to breach data protection law - particularly if Irish Water follow through on what appears to be a half-baked plan to use PPS numbers to track down tenants for non-payment. Such a use would clearly be incompatible with the purpose for which they claim to be collecting the information.

The situation is no better in relation to marketing. For example, the assertion that Irish Water can send us unsolicited text messages and emails unless we object is wrong. Positive, opt-in consent is required by law before this can be done. Similarly, Irish Water is lacking in the mechanisms it provides to opt-out of marketing. The website makes opt-out excessively difficult by providing only a postal address and telephone number and (because it is not a freephone number) violating the requirement that opt-out should be free of charge. Indeed, it has since emerged that Irish Water staff answering that telephone number are actually unable to register opt-outs in the way promised by the privacy statement.

In relation to transferring our information outside Europe, Irish Water fails again. The website claims that “by submitting data to Irish Water” you agree to such transfers. However the fiction that you consent by filling out the registration form is unsustainable – as Irish Water is a monopoly and there is no choice but to fill out the form then any supposed consent would not be “freely given” as required by European law. Any transfer outside Europe would have to be justified in some other way.

The beleaguered head of PR has appeared on Morning Ireland attempting to extricate Irish Water from this quagmire - stating for example that Irish Water would only be direct marketing via postal inserts with bills, not by phone calls or emails. However her ad hoc assurances are meaningless while the data protection statement still claims much wider rights.

These are fundamental failures to meet basic requirements of data protection law and have already resulted in one change to the privacy statement. The Data Protection Commissioner is now also involved, and it is safe to say that her office will also insist on further changes. However it is astonishing that it is only at this late stage that the privacy issues involved are being given the attention which should have been there from the start.

For more see this excellent series of posts from Daragh O'Brien, who has been on top of the issue from the start: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10.

Tuesday, September 16, 2014

United States v. Microsoft (and Ireland)

I have a short piece in today's Irish Independent on the remarkable legal battle between Microsoft and US prosecutors over access to data on non-US users which is stored in Ireland, which has now resulted in a finding that Microsoft is in contempt of court.

The Irish Independent doesn't allow inline links to resources in stories, so for background here are:
In the piece I suggest that Microsoft might commit a criminal offence under Irish law if it discloses user emails without an Irish court order or other Irish law entitlement to do so. The relevant provision is section 21(2) of the Data Protection Acts which makes it an offence for any data processor to knowingly disclose personal data without the prior authority of the data controller on whose behalf the data were processed.

This does, of course, assume that Microsoft would be a data processor rather than a data controller in respect of the contents of user emails. While there is some debate as to when a cloud service operator should be treated as a data controller rather than a data processor, guidance from the Article 29 Working Party (Opinion 1/2010 on the concepts of "controller" and "processor", p.11) strongly suggests that Microsoft should be treated as a data controller only in relation to content (such as traffic data) which it generates - in relation to the emails themselves Microsoft would be treated as a data processor and would therefore be exposed to criminal liability.

Thursday, August 21, 2014

"State must be more mindful of your private data"

I've waited a while to quote Fr. Dougal McGuire in the national press, but finally got my chance in the Independent:
Last week the Irish Independent revealed further abuses of private files in the Department of Social Protection. The abuses ranged from private investigators illegally accessing personal information, to one male employee who spent up to two hours per day looking up information on women and their partners... The response of the department - that it constantly reviews its internal controls - is reminiscent of Father Dougal McGuire's promise: "As I said last time, it won't happen again".
 Full text.

Sunday, July 20, 2014

"Significant gaps" in Department of Justice IT security

You might think that the Department of Justice and Equality - which is responsible for data protection law in Ireland - would have adequate security in place for its own systems. Apparently not. Here's an excerpt from briefing materials for the new Minister, Frances Fitzgerald:
Significant gaps have been found in levels of IT security in use to protect our systems and data. The systems have become out of date as investment (as with infrastructure) has not been applied to maintaining levels at what would be deemed adequate. A security consultant has been retained and a dedicated security manager has been taken on to review and remediate this deficiency. This will require significant investment and resource to bring us to a suitable level of protection and awareness. (p.82)
Proving the point, the briefing material was released as a PDF with crude redaction, easily defeated by the time honoured method of copying and pasting the blacked out material. While the department hurriedly pulled the material from its own site the entire brief remains available in Google cache.

Wednesday, July 16, 2014

July 2014 updates

Blogging here has been light with most material going on Twitter or DigitalRights.ie instead but I should jot down a few updates you might not otherwise have seen.
  • I've put together a surveillance library on the DRI site which brings together in one place the key sources on state surveillance in Ireland. It is, as far as I know, the first time this has been done and the process of pulling together all the documents highlighted to me just how opaque and fragmented the Irish surveillance systems are.
  • DRI has succeeded in its application for amicus status in Max Schrems' challenge to the transfer of personal data to the US under Safe Harbour. Following the decisions in Digital Rights Ireland and Google Spain it is clear that the ECJ is prepared to adopt strong positions on privacy issues and I look forward to being able to contribute to their continued development of the law.
  • The Internet Content Governance Advisory Group published its report in June. The report is a sensible and balanced assessment which focuses on education and parental empowerment rather than legislative responses. I do have a concern about the recommendation that internet messages should be brought within the scope of the existing law on "grossly offensive, indecent, obscene or menacing" messages - while the recommendation itself is quite nuanced there is a risk that a clumsy implementation could jeopardise free expression online in the way that Fergal and I outlined before the Oireachtas social media hearings last year.
  • In a peculiar case, an Irish man was convicted of criminal damage for posting a Facebook update purporting to be from his ex-girlfriend. He was fined €2,000 for posting a status update from her phone stating that she was a "whore" who "would take any offers". This was the first time that the offence of criminal damage to data was used in relation to social media and it is notable in that the sentence imposed was based not on the damage itself but on the reputational harm the damage caused.
  • The "right to be forgotten" is beginning to have an impact on Irish newspapers.
  • Revenue and Social Welfare staff continue to misuse personal data.
  • Finally, the Irish courts have seen regular convictions for online harassment, using the existing provisions of the Offences Against the Person Act 1997, raising the question whether the Content Advisory Group recommendation for change is genuinely necessary.

Friday, April 11, 2014

ECJ finds data retention unacceptable in a democratic society

My preliminary thoughts on our data retention victory, in yesterday's Irish Independent:

This is a significant decision for Irish law. The Digital Rights Ireland case will now return to the High Court in Dublin which will decide whether Irish data retention law is unconstitutional in light of the European Court of Justice ruling.

It is difficult to see how the national law implementing the directive can stand up to challenge now that the directive itself has been held invalid. Consequently it is very likely that new Irish legislation will be proposed.

More generally the judgment will have fundamental implications both throughout Europe and worldwide. The decision itself is effective throughout all 28 member states and will provide greater privacy protection for over half a billion EU citizens.

It will almost certainly be followed by more cases in other member states by national civil rights groups challenging local data retention laws. It also comes at a time when data protection law throughout Europe is under review and will help to establish high standards for any new law.

Finally, this is the first major ruling on surveillance following the Edward Snowden revelations and is clearly influenced by the abuses which he exposed. The judgment will be of central importance to other cases, pending against the UK government, challenging internet surveillance by the British intelligence service GCHQ. In effect, the European Court of Justice has set out a position which directly rejects the type of indiscriminate mass surveillance carried out by the US and UK governments as being unacceptable in a democratic society.
Full text.

Wednesday, March 26, 2014

Recording of calls to and from Garda stations

I have a piece in today's Irish Independent on the revelation that there was widespread recording of calls to and from garda stations over a number of years. Excerpt:
The revelation that telephone calls to and from garda stations have been systematically recorded since the 1980s raises many fundamental issues for the Garda Siochana and for the wider criminal justice system.

The most grave issue is that each recording likely amounted to a serious criminal offence. Under Irish law, the recording of a telephone conversation on a public network without the consent of at least one party to the call amounts to an "interception", a criminal offence carrying a possible term of imprisonment of up to five years.

Interceptions can only be authorised by a warrant signed by the Minister for Justice, but such warrants are restricted to specific cases involving serious offences and are limited to three-month periods. There is no suggestion that any such warrant was issued in relation to this system, and it is clear that the system as a whole fell well outside the bounds of any possible warrant.

Consequently, unless gardai were notified that their calls might be recorded then a large number of criminal offences are likely to have been committed by and within the Garda Siochana itself.
Full text.

Thursday, March 20, 2014

Yahoo moves from London to Dublin; scuppers UK spies

It's surprising to see Ireland as a privacy haven, but by comparison with the UK we look good. The arrogance of the Home Office is astonishing - it genuinely appears to believe it should be able to dictate where a company runs its business so as to allow it to engage in mass surveillance.
Theresa May summoned the internet giant Yahoo for an urgent meeting on Thursday to raise security concerns after the company announced plans to move to Dublin where it is beyond the reach of Britain's surveillance laws.  By making the Irish capital rather than London the centre of its European, Middle East and Africa operations, Yahoo cannot be forced to hand over information demanded by Scotland Yard and the intelligence agencies through "warrants" issued under Britain's controversial anti-terror laws...

The home secretary called the meeting with Yahoo to express the fears of Britain's counter-terrorism investigators. They can force companies based in the UK to provide information on their servers by seeking warrants under the Regulation of Investigatory Powers Act, 2000 (Ripa).  The law, now under review by a parliamentary committee, has been widely criticised for giving police and the intelligence agencies too much access to material such as current emails and internet searches, as well as anything held on company records...

"There are concerns in the Home Office about how Ripa will apply to Yahoo once it has moved its headquarters to Dublin," said a Whitehall source. "The home secretary asked to see officials from Yahoo because in Dublin they don't have equivalent laws to Ripa. This could particularly affect investigations led by Scotland Yard and the national crime agency. They regard this as a very serious issue."

Saturday, March 08, 2014

Oliver Connolly is wrong – Sgt McCabe broke no laws with his secret recording

I have a piece in today's Irish Independent on Oliver Connolly's claim that his rights were infringed by secret recording of his comments. To put it mildly, I'm not convinced. Here's the piece with added links:

Oliver Connolly is wrong – Sgt McCabe broke no laws with his secret recording

SECRET recordings by a party to a conversation can be powerful things. When somebody does not know they are being recorded, they are more candid in their comments. They are often prepared to reveal things they would never repeat publicly. The recording then becomes important evidence to expose inconsistencies between public positions and private admissions.

Unsurprisingly, those who are recorded often feel threatened by this. A common response in many jurisdictions – not just Ireland – is to claim that secret recording is illegal or in breach of the right to privacy.

The former Garda Confidential Recipient, Oliver Connolly, has now taken that approach, asserting that his "constitutional right to privacy" was infringed and that garda whistleblower Sgt Maurice McCabe acted "in breach of confidence" by secretly recording and publishing details of a meeting with him. He has also said that politicians, by repeating excerpts under parliamentary privilege, have further violated his constitutional rights.

These, however, are not correct statements of the law. The starting point is that Irish law generally requires only "single party consent" for the recording of conversations – whether on the phone or in person.

Unlike some other countries, where legislation expressly requires that all parties should consent to a recording, in Ireland any one party can record the conversation. Other parties need not agree – or even be informed.

There are exceptions to this general rule. In some situations, data protection law imposes higher duties on businesses, employers and other "data controllers".

But those duties do not apply to information that an individual keeps only for their "personal affairs" – meaning Sgt McCabe's covert recording would not be covered by data protection rules.

Mr Connolly correctly states that Irish law recognises a constitutional right to privacy – and it is true that this right could apply to recordings if they related to his personal life. The carrying out of his public functions is quite another matter. There is no basis for saying that senior public officials enjoy a right to privacy in the way they carry out their duties. Public officials act on behalf of the people – not in any private capacity – and are open to scrutiny about what they do in our name.

In any event, the claim of privacy is misguided where a person voluntarily reveals information in the course of their duty. There can be no reasonable expectation of privacy in information that has been deliberately disclosed in this way, however much a person might later regret the disclosure.

Mr Connolly might superficially appear to have a better case as regards confidentiality. His former title – Confidential Recipient – reflects duties in the 2007 regulations establishing that role to "take all practicable steps to ensure that the identity of the confidential reporter is not disclosed".

But those duties are imposed to protect the identity of the whistleblower. They apply to the Confidential Recipient, the Garda Commissioner, the Minister for Justice and Equality, GSOC, and the Chief Inspector of the Garda Inspectorate – in short, to everyone other than the whistleblower himself. The confidentiality belongs to the whistleblower and can be waived by him.

In any event, even if a duty of confidentiality did apply, it would be defeated by a countervailing public interest that favours disclosure.

In this case, it is clear that there is such a public interest. Mr Connolly is alleged to have said: "If Shatter thinks you're screwing him, you're finished" and: "If Shatter thinks it's you, or if he thinks that it is told by the commissioner or the gardai, here's this guy again trying another route to put you under pressure, he'll go after you."

Such comments about the minister by the person designated to receive complaints of garda wrongdoing can only give rise to very significant concern. They would certainly be a matter of genuine interest and importance to the general public which would override any obligation of confidentiality.

One more law should be mentioned. Sgt McCabe is also subject to the Garda Siochana Act 2005, which prohibits disclosures of information which are "likely to have a harmful effect". But "harmful effect" is defined very narrowly by the legislation to mean only particularly serious and direct harms such as "facilitating the commission of an offence". The information revealed by Sgt McCabe would not come within the terms of this prohibition.

In short, there does not appear to be any support for Mr Connolly's claim that Sgt McCabe made an "unlawful recording". Rather than attempting to shift the focus to the actions of Sgt McCabe, Mr Connolly might do better to consider how he can help resolve the significant public concerns which have been raised by this episode.

TJ McIntyre is a lecturer in the UCD Sutherland School of Law

Saturday, August 31, 2013

What would Turkey like to hide from its citizens?

Internet censorship in Turkey is a prime example of why democracies should not attempt to filter the internet. I've blogged before about the blocking of Richard Dawkin's website by the Turkish authorities so I was fascinated to learn that a full list of sites which have been blocked by Turkey is available. The information has been compiled by EngelliWeb.com which identifies 31,694 sites as having been blocked, roughly doubled from last year. You can also view all blocked sites as a single page.

Highlights of the blocking list? In addition to Kurdish news sites, it includes the entirety of:

Blogger
Blogspot
Dailymotion
Google Groups
Google Sites
Shoutcast
Ustream.tv
Vimeo
Wordpress
YouTube

One important caveat - not everything on the list is currently blocked. Turkey has flipflopped on many of these sites with on again/off again bans at different times for different reasons. Some sites - such as YouTube - have also been unblocked after caving in to Turkish government pressure and agreeing to censor for Turkish users.

More on Turkish blocking from the excellent Reporters Without Borders site. The Guardian has a recent piece on how Turkish internet users are getting around this censorship.

Friday, June 07, 2013

Quote of the day

The way things are supposed to work is that we're supposed to know virtually everything about what they do: that's why they're called public servants. They're supposed to know virtually nothing about what we do: that's why we're called private individuals.
Glenn Greenwald nails it.
 

Saturday, May 25, 2013

Will Irish courts take phone hacking seriously?

There's a remarkable story in today's Irish Independent about a woman whose criminal charges were struck out - without even a conviction - despite having been found guilty of listening to her former supervisor's voicemails. From the article:
A CIVIL servant who was found guilty of spying on her former supervisor by hacking into her mobile phone's voicemail messages has escaped punishment.

Dublin City Council employee Severine Doyle (39) had pleaded not guilty to 11 charges under the Postal and Telecommunication Act. However, following a hearing last June, she was found guilty of intercepting voice messages on a phone used by Teresa Conlon, Dublin City Council's head of housing allocation.

Dublin District Court heard that Ms Conlon's voicemail messages had been intercepted over a five-week period, from January 8 until February 11, 2010.

Doyle's sentencing had been adjourned until yesterday. Judge Eamon O'Brien told defence solicitor Declan Fahy: "I will strike it out with liberty to re-enter. I am giving her a chance, the ball is in her court."

During the trial on June 28 last year, Ms Conlon told the judge she found out that some city councillors had said they had listened to tapes of messages left on her phone.
This is an unusual outcome. The offences established carry a possible sentence of 5 years if prosecuted on indictment or 12 months otherwise. There were multiple incidents of phone hacking over an extended period. There was no guilty plea. The offences were aggravated by dissemination of the recorded material to councillors. Despite all this, the case was struck out. This may not have been a case for a custodial sentence, but I see no reason why a conviction shouldn't have been registered to mark the gravity of the offence. While there may be more to the matter than emerges from the media coverage, on the face of it this is a case where the court has failed to give adequate weight to the right to privacy in communications.

Thursday, May 16, 2013

"Anyone who uses Facebook does so at his or her peril"

Lawyers: Angry that former clients are suing you over failed investments? Apparently the correct response is not to post on Facebook "They thought they knocked me down, now they will see the full scale of my reaction. F*** them, just f*** them. They will be left with nothing."

Turns out that Facebook posts are not automatically confidential, and will be admissible in evidence against you in proceedings to stop you dissipating the money you owe. Whodathunkit?

The key passage is at para. 4 of the judgment and neatly summarises why very few posts will attract a duty of confidence:
[A]nyone who uses Facebook  does so at his or her peril. There is no guarantee that any comments posted to be viewed by friends will only be seen by those friends. Furthermore it is difficult to see how information can remain confidential if a Facebook user shares it with all his friends and yet no control is placed on the further dissemination of that information by those friends. No evidence was adduced as to how many friends the defendant had and what his relationship was with each of them. It was certainly not suggested that those friends were in anyway restricted as to how they used any information given to them by the defendant. For the avoidance of doubt, I do not consider that any of the friends viewing that information would necessarily have concluded that the information was confidential and could not be disclosed. I have received no evidence as to why those friends were in any way restricted as to how they can use information received from the defendant and why they would have known this information was confidential or private

Defamatory material on Facebook and YouTube: McKeogh v. Doe and others

The High Court today gave a significant decision in McKeogh v. Doe and others concerning defamatory material posted through Facebook and YouTube. The background to the case is well summarised by the Daily Mail. As I have a professional involvement I'll refrain from any comment except to explain that this is an interlocutory judgment (i.e. pending a final hearing of the action) in which Peart J. held that a mandatory injunction should be granted against Facebook and the Google defendants requiring them to take down material defaming the plaintiff until the full trial can take place. The judgment did not itself grant an injunction - instead, the details of the injunction will be determined following a meeting to take place between experts for the plaintiff and the defendants. After this meeting the experts must report back to the court with either an agreed report or separate reports regarding the technical steps which can be taken to remove the defamatory material as far as reasonably possible.

Full text of the judgment:

Thursday, March 21, 2013

Microsoft joins the transparency movement (with an important Irish dimension)

Kudos to Microsoft for today publishing their first annual Transparency Report setting out details of how often national police forces seek to read customer content (such as emails) or to access other information on customers. This is done as part of their commitment as a member of the Global Network Initiative and it's striking, but alas not surprising, that this makes Microsoft considerably more transparent than the Irish government which refuses to reveal even this basic statistical information.

On to the data. In 2012, in relation to Microsoft products generally (Hotmail, Outlook.com, Messenger, etc.) Gardaí sought information in 72 different requests, relating to 222 different accounts. Of these requests, 5 resulted in user content being revealed (such as the actual contents of emails), 46 resulted in non-content user information being revealed (such as the IP address last used), 19 resulted in no data being found and 2 were rejected for not meeting legal requirements.

Skype, which Microsoft now owns, was treated separately. In relation to Skype Gardaí made 4 requests relating to 7 different accounts and there was no data disclosed in relation to any of those requests. (This mostly seems to be due to no data being found but records aren't available for the entire year.). Also, in 2 cases the Skype support team provided general guidance to Gardaí regarding the procedures for accessing customer data.

There's an interesting comparison here with Google's Transparency Report. The overall numbers of requests by Gardaí to Microsoft and Google are very close (76 total for Microsoft for all of 2012; 34 for Google for the first six months of 2012). However the numbers of requests which result in information being provided are very different. In the case of Google data was provided in reply to just 2 of 34 requests (6%), while Microsoft provided data in response to 51 of 76 requests (67%). It's impossible to know without more information why that is and the low Google response rate might be just a blip for the particular six month period - nevertheless the difference is striking.

Significantly, Ireland was one of only four countries other than the US where user content was disclosed, the others being Brazil, Canada and New Zealand. The report doesn't make it clear why this is, but the FAQs imply that this may be due to Hotmail and Outlook.com accounts being hosted in Ireland and therefore being subject to local law.

The report also glosses over a question which has long interested me - what's the legal basis on which Microsoft will provide the contents of emails to Gardaí? Here's what the FAQs have to say:

What laws apply to Microsoft and Skype customer records and content? 

Irish law and European Union directives apply to the Hotmail and Outlook.com accounts hosted in Ireland...

How does Microsoft and Skype determine what law enforcement entities are able to request data? 

Microsoft must produce data in response to valid legal requests from U.S. and Irish law enforcement entities because we are headquartered in those jurisdictions or because we host data in those countries. Microsoft may disclose non-content data pursuant to a law enforcement request after it is validated locally and transmitted to our compliance teams in the U.S. and Ireland...
So - what exactly is a "valid legal request"? Irish law on interception doesn't seem to extend to webmail, suggesting that Microsoft are simply acting in response to non-statutory Garda requests rather than requiring a Ministerial warrant as would be required for telephone tapping. If so, the relevant law would be s.8 of the Data Protection Acts 1988 and 2003, which allows (but doesn't require) voluntary disclosures of user information in the context of criminal investigations. This would, however, be worrying if true as it would allow Garda access to email contents without any outside scrutiny (no Ministerial warrant or court order required) and without the other safeguards which would apply to telephone tapping - so no judicial oversight after the fact and no complaints mechanism available.

If this is the case then it would also put Ireland in breach of our obligations under Article 8 of the European Convention on Human Rights, which states that interferences with private communications must be "in accordance with the law", requiring that there should be a clear legal basis along with adequate mechanisms in place to oversee and guard against abuses of surveillance. (See in particular Klass v. Germany and Malone v. UK.)

More clarity on this point is required, and as soon as possible the law should be changed to ensure that emails enjoy the same protections as telephone calls.

Wednesday, March 20, 2013

Testifying before the Oireachtas Social Media Hearings

Leinster House, Kildare Street
I appeared today along with my colleague Fergal Crehan on behalf of Digital Rights Ireland before the Oireachtas Joint Committee on Transport and Communications which is currently holding a series of hearings on "Social Media Ethics and Regulation". There's a good summary of the proceedings in the Irish Times but the masochistic amongst you can watch the whole thing here. Our slides and Fergal's very comprehensive written submissions are embedded below.

I won't rehash here the substance of the discussion, but I should say that we got a very fair hearing from the Committee whose members - following four separate sessions on the topic - are now very familiar with the issues (previous sessions: 1|2|3). They were quite receptive to the argument that greater resources are needed for the Data Protection Commissioner and the Garda Computer Crime Investigation Unit, and I suspect that they were as shocked as I was to discover that there is currently a three year backlog for that unit to investigate child pornography cases.

The hearings as a whole were also useful in highlighting current practice in sites such as YouTube and shedding some light on the otherwise rather opaque Office for Internet Safety in the Department of Justice. I was disappointed though that there was no evidence from domestic social networking sites such as Boards.ie - the larger international players such as Facebook, Twitter and YouTube operate in a very different environment, not least in the resources they have, and it would be unfortunate if the Committee were given the impression that they were typical of social media sites generally. I don't know whether the domestic absence is because local sites didn't seek to be heard, or whether they weren't given time - but either way it seems to me that these sites would benefit from joining forces and possibly setting up a group to represent their views. In any event I look forward to seeing the Committee's report.


Tuesday, March 05, 2013

Irish court allows reporters into family law case (but bars tweeting)

The High Court gave a landmark judgment on surrogacy earlier today, holding that the biological mother of twins born to a surrogate (her sister) was entitled to be recorded as their mother on their birth certificates. I'll leave the family law side of this to the experts, but I was struck by how the court handled the issue of media coverage. In particular, in exercising its discretion to allow certain designated journalists to report on the proceedings the court did so subject to a number of conditions one of which was that: "no contemporaneous social media reporting e.g. by Twitter shall be carried out by the designated reporters."

This seems to be the first time that an Irish court has positively restricted the tweeting or live blogging of court proceedings, though that's not to say that the issue hasn't been considered.

In 2009 Abigail Rieley - then working as a court reporter - could still say that the issue hadn't yet reached the judicial consciousness. In 2011 it was reported that a judicial committee would consider the issues of jurors' use of the internet and might also consider the issue of courtroom reporting on social media. (I'm not aware that anything public ever emerged from this - if you know better please let me know.) Still again, in 2012 the media relations advisor to the Courts Service published an interesting article on social media and the courts (PDF) which amongst other things suggested that there was a need for judicial guidance along the lines of the current English rules regarding tweeting from court.

Meanwhile, despite these concerns the use of Twitter in court has simply become a part of day to day reality. Today's judgment is the first time it has butted up against judicial resistance - and that only in the particularly difficult and private context of a family law matter. I suspect, though, that it won't be the last.

Thursday, February 28, 2013

Illegally obtained digital evidence: Mind your Ps and Qs

"While the law provides for court orders to be made for the preservation and obtaining of evidence for the purpose of future legal proceedings, claimants, or potential claimants, sometimes resort to measures of self help, by copying, seizing, or attempting to access digital copies of documents" - Tugendhat J. in L v. L. (2007)

Those words from the English High Court are equally true in Ireland. Particularly in family law cases it can be very easy for a litigant to (illegally) access the laptop, webmail or other electronic information of the other side to collect ammunition for use at trial. This presents interesting legal issues as to when such evidence will be admissible, despite the way in which it was obtained.

The High Court gave a recent judgment in the family law case P v. Q [2012] IEHC 593 which offers some guidance. In this case the applicant (the husband) sought a judicial separation and attempted to introduce evidence relating to the respondent's (wife's) sexual activities since the breakup of their marriage, including details of material on her laptop and posted by her to certain websites. The respondent gave evidence that the passwords for her laptop and the access codes for the sites were kept in a locked safe which the applicant must have accessed illegally. Consequently she sought to ensure that the information obtained by the applicant was not used in the proceedings and in particular was not used as the basis to obtain an order for discovery against her.

On appeal from the Circuit Court, the High Court held that in the ordinary course of events this information would be inadmissible on the basis that it was obtained illegally and in breach of the constitutional right to privacy of the respondent. In this case, however, given that child welfare issues also arose the court took the view that the constitutional rights of the child took precedence over the manner in which the evidence was obtained so that the information could be admitted in relation to the child welfare issues only. The relevant parts of the judgment are at para. 33 onwards:
33. The issue for the court to determine is complicated by the allegation that the respondent’s privacy was breached illegally when the codes and passwords of her personal laptop were accessed, at a time subsequent to the commencement of family law proceedings Although disputed by the applicant, the evidence before this court heard on affidavit would indicate that the passwords and access codes to these particular websites were retained by the respondent in a locked safe. There are many occasions and opportunities in family law proceedings, where parties to the proceedings access information which the other party regards as private, but which has not been obtained illegally. In this case the acquisition of the codes is tainted by illegality.

34. I accept the submissions on behalf of the respondent, that there is a broad principle of constitutional law, that evidence which is obtained by invasion of a constitutional personal right such as a right of privacy must be excluded unless the Court is satisfied that the breach was committed unintentionally or accidentally (which could not be the case here) or is satisfied that there were extraordinary excusing circumstances which justify the admission of the evidence in its discretion”. It is respectfully submitted that there are no extraordinary excusing circumstances in this appeal. I would accept that principle as applying to a criminal prosecution, in order to protect the absolute right to a fair trial.

35. Where different constitutional rights have to be balanced, different principles apply.

36. A court should always be reluctant to admit evidence or approve discovery, which is tainted with illegality, but that is not to say that on all occasions where illegality is suspected or found, that the evidence so obtained is not admissible. This is particularly so when dealing with the welfare of a child.

37. If the court were only dealing with issues between the parties and not the welfare of the child, the court would have taken into consideration the sexual history of the marriage, and on balance would not make the order for discovery sought..

39. The alleged sexual activity of the respondent has a direct bearing on the welfare of the child of the marriage...

41. While the proceedings touching on the welfare of the child are adversarial in nature, there is an inquisitorial aspect to that portion of the proceedings dealing with his custody. Balancing the different constitutional rights and responsibilities the welfare of the child would take precedence over illegally gathered information touching on the child’s welfare.

42. In addition the constitutional right to privacy of the respondent is protected in “in camera” proceedings, as the information disclosed is confined to the parties, their legal representatives and the court. The respondent’s rights can be further protected by the addition of further conditions.

43. The court affirms the order of the Circuit Court with the following additional conditions:-

(1) The material furnished can only be used for the purposes of determining the welfare of the child of the marriage and not for the purposes of s. 16(2)(i) of the Act in respect of the behaviour of the respondent.
(2) Any material discovered which does not impinge on the child’s welfare, should be furnished but returned to the respondent, and not relied on by the court.
(3) In the event of any dispute the presiding judge of the Circuit Court should consider the material and decide on relevance
While this decision allowed the use of this information on the particular facts of the case for a limited purpose, overall it adopts an approach which will mean that in most future cases such evidence will be inadmissible. The judgment isn't entirely clear on the distinction between illegally and unconstitutionally obtained evidence but appears to accept the proposition that wrongful access to a laptop or an online account will amount to an invasion of the constitutional right to privacy - not merely an illegality. In this, it extends the principle previously established in PMcG v. AF in relation to hardcopy (a diary in that case) to digital information also.