privacy

The right to privacy is a crucial element of our personal security, for free speech and for democratic participation. It is a fundamental right in the primary law of the European Union and is recognised in numerous international legal instruments. Digital technologies have generated a new environment of potential benefits and threats to this fundamental right. As a result, defending our right to privacy is at the centre of EDRi’s priorities.

07 Nov 2018

NGOs urge Austrian Council Presidency to finalise e-Privacy reform

By Epicenter.works

EDRi member epicenter.works, together with 20 NGOs, is urging the Austrian Presidency of the Council of the European Union to take action towards ensuring the finalisation of the e-Privacy reform. The group, counting the biggest civil society organisations in Austria such as Amnesty International and two labour unions, demands in an open letter sent on 6 November 2018 an end to the apparently never-ending deliberations between the EU member states.

----------------------------------------------------------------- Support our work - make a recurrent donation! https://edri.org/supporters/ -----------------------------------------------------------------

It is today 666 days since the European Commission launched its proposal. The e-Privacy regulation is an essential aspect for the future of Europe’s digital strategy and a necessity for the protection of modern democracies from ubiquitous surveillance networks. Echoing European citizens rightful demands for protections of their online privacy, the organisations ask the Austrian Presidency to lead the way into a new privacy era by concluding the e-Privacy dossier by 2019.

The letter comes in a context in which a parliamentary inquiry from the Austrian Social Democratic party tries to shed light on the lobby connections of the Austrian government regarding the hampering of secure communications for its citizens. Right now, the Austrian government’s position is closely aligned with the interests of internet giants like Facebook and Google, big telecom companies and the advertisement industry.

The Austrian government has recently fast-tracked negotiations on the controversial e-evidence proposal, which would weaken the rule of law and foster further surveillance of citizens’ online behaviour. This is a stark contrast to the meager effort Austrian representatives put into negotiations around legislative proposals that aim to protect the fundamental right to privacy – a topic missing from the Austrian Council Presidency agenda.

In order to ensure that e-Privacy laws will not be used as excuse for the establishment of new repressive instruments, epicenter.works demands a clear commitment to the prohibition of data retention. Data retention has been found unconstitutional in different European countries, while epicenter.works was plaintiff in the 2014 proceedings of the European Court of Justice (ECJ) annulling the data retention directive. A circumvention of the ECJ’s ban through the e-Privacy regulation could expose EU citizens to indiscriminate mass-surveillance and severely undermine trust in EU institutions.

Open Letter sent to Austrian Government (in German only, 06.11.2018)
https://epicenter.works/content/offener-brief-wir-brauchen-eprivacy

Parliamentary inquiry from the Austrian Social Democratic Party (in German only, 29.10.2018)
https://www.parlament.gv.at/PAKT/VHG/XXVI/J/J_02174/index.shtml

Council continues limbo dance with the ePrivacy standards (24.10.2018)
https://edri.org/council-continues-limbo-dance-with-the-eprivacy-standards/

ePrivacy: Public benefit or private surveillance? (24.10.2018)
https://edri.org/eprivacy-public-benefit-or-private-surveillance/

ECJ: Data retention directive contravenes European law (09.04.2014)
https://edri.org/ecj-data-retention-directive-contravenes-european-law/

(Contribution by Thomas Lohninger, EDRi member epicenter.works)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
24 Oct 2018

CJEU introduces new criteria for law enforcement to access to data

By IT-Pol and EDRi

On 2 October 2018, the Court of Justice of the European Union (CJEU) delivered a new ruling in the “Ministerio Fiscal” case on access to data retained by electronic communications service providers under the scope the ePrivacy Directive.

----------------------------------------------------------------- Support our work - make a recurrent donation! https://edri.org/supporters/ -----------------------------------------------------------------

While investigating the robbery and theft of a mobile phone, the Spanish police asked an investigating magistrate to order various providers of electronic communications services to disclose the telephone numbers that had been activated during a twelve-day period with the International Mobile Equipment Identity (IMEI) code of the stolen mobile device, as well as the names and addresses of the subscribers for the SIM cards used for this activation. The request was denied by the magistrate on grounds that the criminal offence did not fulfill the requirements for serious offences in the Spanish Law 25/2007 on the retention of data relating to electronic communications and to public communication networks. On appeal by the prosecutor, a Spanish court referred the case to the CJEU.

The CJEU ruled that access to retained data for the purpose of determining the owners of the SIM cards used for activation of a mobile device entails an interference with the owners’ fundamental rights to privacy and personal data protection. However, the CJEU clarified that if the purpose for accessing the retained data is solely to obtain the subscriber identity, Article 15(1) of ePrivacy Directive allows restrictions of the rights provided for by the Directive for the prevention, investigation, detection, and prosecution of criminal offences – not just serious criminal offences.

What is interesting about this ruling is that in its previous Tele2/Watson judgment, the CJEU had ruled that access to the retained data is limited to cases involving serious crime. To reconcile the two rulings, the CJEU explains that this is because the objective pursued by the access must be proportionate to the seriousness of the interference with the fundamental rights that the access entails. The Tele2 case is concerned with access to retained data which, taken as a whole, allows precise conclusions to be drawn regarding the private lives of the persons concerned. Such access constitutes a serious interference with fundamental rights and can be justified only by the objective of fighting serious crime. If, however, the access to retained data is a non-serious interference, as in the present case involving access to the subscriber’s identity, access can be justified by the objective of fighting criminal offences generally.

The question that immediately comes to mind is whether this new case in any way departs from the strict conditions for access to retained data set forth in the Tele2/Watson judgment, and, in particular, whether the Ministerio Fiscal case waters down some of these conditions, thus allowing for access to retained data by law enforcement authorities in a greater number of scenarios.

First and foremost, it is important to note that the overlap between the two judgments is fairly small since they are concerned with very different questions:

The object of the Tele2/Watson case is the retention of data which, taken as a whole, is liable to allow very precise conclusions to be drawn concerning the private lives of the persons whose data has been retained (first part of the judgment) and access to such data retained by electronic communications service providers (second part).

In contrast, the Ministerio Fiscal case is concerned with the presumably very narrow situation where accessing data does not constitute a serious interference. This includes obtaining a subscriber identity. However, the CJEU confirms that access to retained data which reveals the date, time, duration and recipients of the communications, or the locations where the communications took place, must be regarded as a serious interference since that data allows precise conclusions to be drawn about the private lives of the persons concerned (cf. paragraph 60 of the ruling). In these situations, access to the retained data must be limited to cases involving serious crimes, as in the Tele2 case.

There is, however, one scenario where the new judgment may add some confusion to the interpretation of the Tele2 judgment. According to paragraphs 108-111 of the Tele2 judgment, targeted data retention requirements for the purpose of fighting serious crime are compatible with EU law (unlike general and undifferentiated data retention which is illegal under EU law). Moreover, it would be natural to read paragraph 115 of the Tele2 judgment as always limiting the access to such retained data to cases involving serious crime because the targeted data retention requirement in itself constitutes a serious interference with fundamental rights that can only be justified by the objective of fighting serious crime. Allowing access to the retained data in cases not involving serious crime would arguably undermine the purpose limitation at the retention stage.

The CJEU did not define what can constitute a serious crime. Similarly, the Ministerio Fiscal ruling does not clearly refer to why the data was retained in the first place or whether that should affect the conditions for access to the retained data.

Because there is no apparent connection to why the data is retained, the CJEU now seems to say in paragraphs 54-61 of the Ministerio Fiscal ruling that if access is only sought to minor parts of the retained data, for example only for the purpose of obtaining the subscriber identity, accessing that data does not constitute a serious interference, even if the data is only available in the first place because of a (targeted) data retention order that can only be justified by the objective of fighting serious crime. This situation could arise in practice if the data retention order includes all data items in the (annulled) Data Retention Directive for a targeted group of persons, but access to the retained data is only requested for the purpose of determining the identity of a subscriber who has been assigned a specific dynamic IP address.

Leaving aside this potential weakening of the strict Tele2 conditions for access to retained data, there are three main positive aspects of the new judgment from a digital rights perspective:

  1. The judgment clarifies that traffic data under the ePrivacy Directive includes the subscriber name and the IMEI address of the mobile device (cf. paragraphs 40-42). This implies that access to such data falls within the scope and safeguards of the ePrivacy Directive, and that the ePrivacy Directive cannot be circumvented by attempts to expand to definition of subscriber data.
  2. The judgment notes in paragraph 51 with reference to the Court’s Opinion on the EU-Canada Passenger Name Records (PNR) agreement that access to any retained data, including subscriber identity, constitutes an interference with the fundamental right to the protection of personal data. Therefore, the CJEU requires substantive and procedural conditions based on objective criteria for the access to the retained PNR data, and the access must be subject to prior review by a court or an independent administrative body. In the Ministerio Fiscal case, the CJEU was not asked to consider substantive and procedural conditions for access. Nonetheless, paragraph 51 of the judgment has potential implications for other parts of EU law, most notably the proposed e-Evidence Regulation, which allows for access to not just subscriber data, but also so-called access data (data necessary to identify the user of a service) for all criminal offences and without any requirements of prior review by a court (a prosecutor’s approval can be sufficient) or an independent administrative body.
  3. In paragraphs 34-37 of the Ministerio Fiscal judgment, the CJEU reiterates what it said in the Tele2/Watson judgment – that national legislation permitting access by competent authorities to personal data retained by electronic communications service providers cannot be regarded as activities of the state that fall outside the scope of Article 15(1) of the ePrivacy Regulation, since the access by competent authorities necessarily presupposes processing of personal data by the electronic communications service providers.

CJEU judgment in case C-207/16 Ministerio Fiscal (02.10.2018)
http://curia.europa.eu/juris/document/document.jsf?docid=206332&mode=req&pageIndex=1&dir=&occ=first&part=1&text=&doclang=EN&cid=252986

CJEU judgment in joined Cases C‑203/15 and C‑698/15 (Tele2/Watson)
http://curia.europa.eu/juris/document/document.jsf?text=&docid=186492&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=2525180

(Contribution by Jesper Lund, IT-Pol, Denmark, and Maryant Fernández Pérez, EDRi)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
26 Sep 2018

UK counter-terrorism law would restrict freedom of expression

By Guest author

Freedom of expression campaigners, human rights groups and legal experts are raising concerns that proposed new counter-terrorism legislation in the United Kingdom would restrict freedom of expression and limit access to information online.

----------------------------------------------------------------- Support our work with a one-off-donation! https://edri.org/donate/ -----------------------------------------------------------------

The UK Parliament is currently considering the Counter-Terrorism and Border Security Bill, which could become law within a few months. The government aims to build on existing laws to fill gaps and close perceived loopholes. However, in doing so, the bill goes very far, including restricting online activity, which undermines fundamental rights to freedom of expression.

For example, the bill would make it a crime to view online content that is likely to be useful for terrorism, even if you have no terrorist intent (and even if you are watching over someone else’s shoulder). The crime would carry a prison sentence of up to 15 years. It would make the work of investigative journalists and academic researchers difficult and risky – as mistakenly landing on an offending page could have major consequences. The first version of this clause required a person to access the wrong content three times, but the government has amended this to become a “one-click rule” rather than the original “three-click rule”.

The bill would criminalise publishing (for example, posting on social media) a picture or video clip of clothes or a flag in a way that raises “reasonable suspicion” that the person doing it is a member or supporter of a terrorist organisation. Parliament’s Joint Committee on Human Rights recommended that this clause be withdrawn or amended because it “risks a huge swathe of publications being caught, including historical images and journalistic articles” and because of its potentially very wide reach and interference with Article 10 of the European Convention on Human Rights. The government has not taken this recommendation into account.

United Nations special rapporteur Professor Fionnuala Ní Aoláin has expressed concerns that the proposed clause “runs the risk of criminalizing a broad range of legitimate behaviour, including reporting by journalists, civil society organizations or human rights activists as well as academic and other research activity”. She has expressed concerns about several parts of the bill and emphasised that it should be brought in line with the UK’s obligations under international human rights law.

EDRi member Index on Censorship believes that the bill is not fit for purpose and should go back to the drawing board. It would significantly impact freedom of expression online, damage journalism and academic research, and signal the wrong direction for future online regulation in the UK.

Counter-Terrorism and Border Security Bill 2017-19
https://services.parliament.uk/Bills/2017-19/counterterrorismandbordersecurity.html

“Reckless” counter-terror bill a threat to academic research (17.09.2018)
https://www.indexoncensorship.org/2018/09/reckless-counter-terror-bill-a-threat-to-academic-research/

Joint Committee on Human Rights Legislative Scrutiny: Counter-Terrorism and Border Security Bill – Ninth Report of Session 2017–19
https://publications.parliament.uk/pa/jt201719/jtselect/jtrights/1208/1208.pdf

Mandate of the Special Rapporteur on the promotion and protection of human rights and
fundamental freedoms while countering terrorism (17.07.2018)
https://www.ohchr.org/Documents/Issues/Terrorism/SR/OL-GBR-7-2018.pdf

Counter-Terrorism and Border Security Bill not fit for purpose (10.09.2018)
https://www.indexoncensorship.org/2018/09/counter-terrorism-and-border-security-bill-not-fit-for-purpose/

(Contribution by Joy Hyvarinen, EDRi observer Index on Censorship, the United Kingdom)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
11 Jul 2018

Danish High Court ruling on data retention use and file sharing cases

By IT-Pol

On 7 May 2018, the Eastern High Court in Denmark delivered a ruling that internet service providers (ISPs) are not required to disclose subscriber information in file sharing cases. This represents a major change of the previous legal practice in Denmark, where rightsholders were routinely granted access to subscriber information for alleged file sharers, even if the identification required access to retained data from mandatory data retention.

----------------------------------------------------------------- Support our work - make a recurrent donation! https://edri.org/supporters/ -----------------------------------------------------------------

Two Danish law firms have specialised in legal action against file sharers in cooperation with the German file sharing monitoring company MaverickEye UG, which is well known from similar activities in other European countries. MaverickEye monitors BitTorrent file sharing networks and collects IP addresses of the participants in the BitTorrent swarm. In order to verify that the copyrighted work is made available from the IP address in question, a small piece of the file is downloaded using a modified BitTorrent client. For each copyrighted work, MaverickEye provides information about IP addresses and timestamps to the relevant rightsholders or, in most cases, the specialised law firms that represents them. The next step is to seek a court order requiring the ISPs to identify the actual subscribers that have used the IP addresses at the specific time. This is the critical step and legal practice varies among EU Member States.

If the subscriber names and addresses can be obtained from the ISPs, the law firm can either file a lawsuit demanding compensation for copyright infringement or send a letter to the subscriber with a proposed settlement for the case. The latter is generally the preferred option since lawsuits are expensive, and the alleged copyright infringement using BitTorrent is often limited to a single film or TV-series episode/season. In Denmark, the settlement offer from the law firm has typically been a payment of 200 to 300 euros for a single film. Only a handful of lawsuits have been filed with Danish courts, so most claims have either been settled or dropped if the subscriber denies having taken part in the alleged file sharing activity.

Based on Danish case law for three file sharing cases at the two High Courts around 2008, the subscriber does not automatically become legally responsible for file sharing from the IP address. The rightsholder must prove who has committed the file sharing act in order to obtain compensation. This burden of proof can be very difficult to meet if the subscriber for instance has an open WiFi network, has allowed guests to use his/her internet connection, or if there are several persons in the household. Most subscribers are probably not aware of this, so it is quite likely that many cases have been settled by paying the offered settlement amount of 200 to 300 euros.

The current wave of legal action started in 2014, and according to information from the recent High Court ruling of 7 May 2018, the two Danish law firms have obtained subscriber information for some 200,000 IP addresses. This shows the massive scale of the monitoring operation of file sharing networks by MaverickEye. Access to subscriber information for a large number of IP addresses has also been reported in Sweden by TorrentFreak, incidentally involving the same Danish law firm as the present case.

Each court application for subscriber identification consists of a large number of IP addresses, for example 4000 IP addresses in the case ruled by the High Court on 7 May 2018. Because of the Danish data retention law, ISPs hold information about assignment of dynamic IP addresses for 12 months, so there is no urgent need for the law firm to quickly seek a court order for subscriber identification when information about the file sharing activity has been received from MaverickEye. A large batch of IP addresses from the same ISP can be collected before seeking the court order for subscriber identification from that ISP.

Until recently, this assembly-line strategy by the two law firms to send letters to alleged file sharers did not meet any legal challenges. In most cases, Danish ISPs do not object to a court application for subscriber information, and there is no court hearing for the application. The sole purpose of the court order, which is granted without any objections, is to provide a legal basis for the ISP to disclose the personal data (subscriber information) to the rightsholder.

However, between 2016 and 2017 the large Danish ISPs finally changed their response strategy and started to object to the court applications for subscriber information. Besides the administrative cost of handling the large number of requests for subscriber information and the increasing news media reporting of ISP customers complaining about file sharing allegations based on information obtained by law firms from their own ISP, the Tele2 data retention judgment (joined cases C-203/15 and C-698/15) of the Court of Justice of the European Union (CJEU) also played a major role.

According to the Tele2 judgment, general and undifferentiated (blanket) data retention is illegal under EU law. Moreover, access to the retained data, whether from (illegal) blanket data retention or targeted data retention, must be limited to what is strictly necessary. For criminal offences, the Tele2 judgment specifically states that access can only be granted for serious crime. Paragraph 115 of the Tele2 does not completely rule out that access to the retained data can be granted for civil claims, as there is an indirect reference to the Promusicae case C-275/06. However, when access to the retained data for criminal offences is strictly limited to serious crime, it does not seem to be proportionate to grant access to the retained data in civil proceedings involving only a minor copyright infringement, such as file sharing of a single film or TV series.

In a case involving Telenor and TeliaSonera, the District Court of Frederiksberg considered the data protection issues (noting that it was unclear whether this had been done in previous cases), but followed the established practice of ruling in favour of the rightsholder on 24 October 2017, that is ordering the disclosure of subscriber information. The ISPs appealed the court decision to the Eastern High Court. The ruling from the High Court on 7 May 2018, which reverses the ruling from the District Court and blocks disclosure of the subscriber information, is mainly based on an interpretation of the e-Privacy Directive 2002/58/EU and case law of the CJEU in Tele2, Promusicae and Bonnier C-461/10.

The e-Privacy Directive imposes an obligation of confidentiality on ISPs with respect the subscribers’ use of the internet. ISPs must delete traffic data, such as assignment of dynamic IP addresses, when it is no longer needed for the purpose of the transmission of a communication. According to statements to the High Court given by Telenor, TeliaSonera and a third ISP not involved in the case (TDC), information about assignment of dynamic IP addresses to individual subscribers is retained for at most 3-4 weeks for operational purposes. Therefore, the necessary information is only available in a special system for law enforcement access because of the Danish data retention law which has a mandatory 12-month retention period.

The High Court then considers the case law of Promusicae and Bonnier, and notes that the e-Privacy Directive does not preclude national legislation which requires disclosure of subscriber information in civil proceedings on copyright infringement, but that it must be possible to consider the opposing interests in an application for disclosure.

In the present case, the High Court finds that there are compelling reasons against disclosure. The information needed to identify the subscribers is only available because of the data retention obligation, and the sole purpose of the data retention provisions is to enable the police to obtain access to retained data for the purpose of investigation and prosecution of criminal offences. The Court is aware that the civil claims cannot be pursued without access to subscriber information, and that it is likely that there has been a substantial copyright infringement. After balancing the opposing interests, the Court finds that this does not outweigh the confidentiality of communication for the subscribers under the e-Privacy Directive. Therefore, the request for disclosure of subscriber information is denied. The decisive factor in the High Court ruling is the Danish data retention law which limits access to the retained data for the purpose of investigation and prosecution of criminal offences.

Read more:

Denmark: Our data retention law is illegal, but we keep it for now, EDRi (08.03.2017)
https://edri.org/denmark-our-data-retention-law-is-illegal-but-we-keep-it-for-now/

ISPs Win Landmark Case to Protect Privacy of Alleged Pirates, TorrentFreak (08.05.2018)
https://torrentfreak.com/isps-win-landmark-case-protect-privacy-alleged-pirates-180508

Copyright Trolls Hit Thousands of Swedish ‘Pirates’ With $550 ‘Fines’ (23.10.2017)
https://torrentfreak.com/copyright-trolls-hit-thousands-of-swedish-pirates-with-550-fines-171023/

(Contribution by Jesper Lund, IT – Pol, EDRi member, Denmark)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
27 Jun 2018

Restoring freedom of expression in Spain: end the “gag law”

By Maria Roson

Spain has been one of the countries of the European Union that has most shamefully stood out for its government’s attitude against freedom of expression and information. During the government of former President Mariano Rajoy, the Spanish parliament passed the controversial “gag law”- as it was popularly known – which entered into force on 1 July 2015. This law amended the Spanish penal code by, among other things, reinforcing the penalties of “glorification of terrorism” and “humiliation of the victims of terrorism” and introducing limitations on protests and imposing administrative sanctions against demonstrators.

----------------------------------------------------------------- Support our work - make a recurrent donation! https://edri.org/supporters/ -----------------------------------------------------------------

One of the most obvious consequences that this law has had for freedom of expression and information online have been the criminal cases against many political activists, artists, and politicians because of their tweets. In its last report “Tweet…if you dare: How counter-terrorism laws restrict Freedom of Expression in Spain”, Amnesty International denounces the lack of legitimate purpose of the law, considering it too broad and too vague and with an evident purpose of targeting those expressing dissident opinions against the Spanish political system.

Among the limitations that this law has imposed on online activity are:

Arbitrarily restricting access to websites that promote or advocate “terrorism”

The text is written with such an ambiguous wording that it condemns not only the dissemination of criminal content but also simple access to it. This implies that accessing these websites is, itself, a crime, regardless of whether the person simply wanted to be informed or whether they are actually involved in a terrorist activity.

“Seriously disturbing the public order”

Without any definition of what the law considers to be “seriously disturbing the public order”. This ambiguity has lead to arbitrary fines to journalists when they were covering a public event.

Organizing online protests

The gag law punishes “unauthorised protest” which could be fined between 30,000 and 600,000 euro if the protest takes part near institutions such as the Spanish parliament, which happened with the protest organised by the “7N against gender violence”.

Posting pictures of police officers which imply a “danger for their personal of family security”

The doubt is of course what does “danger” mean. How exactly will the law measure “danger”? Again, it is not defined. The result is freedom of expression is curtailed, with fines ranging from 600 to 30,000 euro, and with such extreme consequences as fining a women for posting a picture of a police car parked illegally in a parking spot reserved for people with disabilities.

Penalising content sharing platforms

Platforms such as the sport streaming website “Rojadirecta”. Despite the legitimate intent to limit copyright infringements, the consequences of this measure will be creating legal uncertainty for hundreds of small businesses that have nothing to do with infringements.

Restriction of online protests

The “gag rule” punishes with criminal penalties the dissemination of messages on the internet which may be considered as “glorification or justification” of terrorism or “the dissemination of slogans” which may incite others to commit offences. This has undoubtedly been the most controversial part of the law and the most arbitrarily applied. Under the pretext of committing “glorification of terrorism”, an extremely abusive interpretation of this offence has been used. As a consequence, rappers, professional puppeteers and visual artists have been charged or prosecuted by the Spanish justice because of the politically content of their lyrics, plays or even the meaning of their artistic pieces.

The other battlefield has been Twitter where, since 2014, four coordinated police operations – called the “Spider Operations” – led to a big number of people arrested for posting messages and jokes on social media platforms referring, among other topics, to ETA’s terrorist attacks addressed to members of the Franco dictatorship. One of the most famous cases was the conviction of the rapper “Strawberry” for tweeting about ETA’s terrorist attacks. Although most of the people accused were released without charges or were not imprisoned , there are particularly worrying cases such as the recent convictions of rappers Pablo Hassel and Valtonyc, the latter currently on the run.

After almost 3 years since this law was approved, one of the first tasks of the new Spanish government is to take down the “gag law”. The idea of fixing the law by making amendments within the law, as the Socialist party has pointed out, is not enough. As associations such as the Platform for the Defence of Freedom of Information (Plataforma en Defensa de la Libertad de Información), Amnesty International, Rights International Spain and Spanish EDRi member X-Net have expressed, the only solution is to call for the repeal of the law.

Read more:

Amnesty International Report: “Tweet…if you dare. How counter-terrorism laws restrict Freedom of Expression in Spain” (13.03.2018)
https://www.amnesty.org/download/Documents/EUR4179242018ENGLISH.PDF

UN Rapporteur demands respect for freedom of expression online (14.06.2017)
https://edri.org/un-rapporteur-demands-respect-for-freedom-of-expression-online/

Xnet: Legislation that restricts freedom of expression of action and organization in the Spanish State (available only in Spanish) (01.12.2015)
https://xnet-x.net/leyes-coartan-libertad-expresion-accion-organizacion/

Spanish Citizens’ Security law: There is still some hope (21.06.2015)
https://edri.org/spanish-citizens-security-law-hope-not-lost/

Spanish Citizens’ Security Bill: Many restrictions, few freedoms (28.01.2015)
https://edri.org/spanish-citizens-security-bill-many-restrictions-few-freedoms/

(Contribution by Maria Roson, EDRi intern)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
21 Jun 2018

ENAR and EDRi join forces for diligent and restorative solutions to illegal content online

By Maryant Fernández Pérez

The European Network Against Racism (ENAR) and European Digital Rights (EDRi) joined forces to draw up some core principles in the fight against illegal content online. Our position paper springs both from the perspective of victims of racism and that of free speech and privacy protection.

The European Commission has so far not been successful in tackling illegal content in a way that provides a redress mechanism for victims. In fact, the European Commission has been way too long focused on a “public relations regime” on how quickly and how many online posts have been deleted, while not having a diligent approach for addressing the deeper problems behind the removed content. Indeed, the European Commission has been continuously promoting rather superficial “solutions” that are not dealing with the problems faced by victims of illegal activity in a meaningful way.

At the same time, the European Commission’s approach is undermining people’s rights to privacy and freedom of expression by urging and pressuring internet giants to take over privatised law enforcement functions. As a consequence, ENAR and EDRi have agreed a joint position paper following our commitment to ensure fundamental rights for all.

Our joint position paper relies on four basic principles:

1. No place for arbitrary restrictions – Any measure that is implemented must be predictable and subject to real accountability.

2. Diligent review processes – Any measure must be implemented on the basis of neutral assessment, rather than being left entirely to private parties, particularly as they may have significant conflicts of interest.

3. Learning lessons – Any measure implemented must be subject to thorough evidence-gathering and review processes.

4. Different solutions for different problems – No superficial measure in relation to incitement to violence or hatred should be implemented without clear obligations on all relevant stakeholders to play their role in dealing with the content in a comprehensive manner. Illegal racist content inciting to violence or discrimination should be referred to competent and properly resourced law enforcement authorities for adequate sanctions if they meet the criminal threshold. States must also ensure that laws on racism and incitement to violence are based on solid evidence and respect international human rights law.

This paper follows cooperation between the two organisations over the past few years to bring the digital rights community and the anti-racist movement together in a more comprehensive way. The common initiative comes at a time where the European Commission is consulting stakeholders and individuals to provide their opinion on how to tackle illegal content online by 25 June 2018. EDRi has developed an answering guide for individuals that consider that the European Union should take a diligent, long-term approach that protects for the victims of illegal content, such as racism online, and victims of free speech restrictions.

(Contribution by Maryant Fernández Pérez, EDRi Senior Policy Advisor)

Read more:

ENAR-EDRi Joint position paper: Tackling illegal content online – principles for efficient and restorative solutions (20.06.2018)
https://edri.org/files/enar-edri_illegalcontentposition_final_20180620.pdf

EDRi Answering guide to EU Commission’s “illegal” content “consultation” (13.06.2018)
https://edri.org/answering-guide-eu-commission-illegal-content-consultation/

Commission’s position on tackling illegal content online is contradictory and dangerous for free speech (28.09.2017)
https://edri.org/commissions-position-tackling-illegal-content-online-contradictory-dangerous-free-speech/

EU Commission’s Recommendation: Let’s put internet giants in charge of censoring Europe (28.09.2017)
https://edri.org/eu-commissions-recommendation-lets-put-internet-giants-in-charge-of-censoring-europe/

close
02 May 2018

EU Member States fight to retain data retention in place despite CJEU rulings

By IT-Pol

EU Member States are still working to adopt their position on the ePrivacy Regulation proposed by the European Commission in January 2017. A number of draft compromise texts have been published by the Council Presidency before discussions in the Working Party on Telecommunications and Information Society (WP TELE).

----------------------------------------------------------------- Support our work with a one-off-donation! https://edri.org/donate/ -----------------------------------------------------------------

Unfortunately, the Council transparency in publishing those documents does not extend to the part of the ePrivacy Regulation that concerns data retention. This means mainly Article 11, which allows Member States to restrict the rights to data protection and confidentiality of electronic communication under certain conditions, in a similar way to Article 15(1) of the current ePrivacy Directive. This part of the ePrivacy Regulation is being discussed jointly by WP TELE and the Working Party on Information Exchange and Data Protection – Friends of the Presidency on Data Retention (DAPIX FoP), which is also tasked with analysing the implications of the Tele2 judgment (joined cases C-203/15 and C-698/15) from the Court of Justice of the European Union (CJEU).

Documents from these discussions are marked “LIMITE” and therefore not generally available to the public. An incomplete picture of the work is available through a combination of Freedom of Information (FOI) requests and leaked documents. It is known that DAPIX FoP has developed the concept of ”restricted data retention” which is a deliberately crafted attempt to circumvent the Tele2 ruling of the highest court of the European Union (the CJEU) with a data retention scheme that is, in reality, general and undifferentiated (and therefore illegal) while officially claiming not to be.

Recently, the working document WK 11127/2017 of 10 October 2017 was released in full through a FOI request by Corporate Europe Observatory. This document provides another piece of the puzzle regarding the secret data retention discussions in Council working groups by outlining two different strategies for storage of electronic communications metadata for law enforcement purposes.

The first strategy is based on data retained by providers of Electronic Communication Services (ECS) for business purposes. Article 6(2)(b) of the Commission proposal for the ePrivacy Regulation allows ECS providers to process electronic communications metadata for purposes of billing, calculating interconnection payments as well as stopping fraudulent or abusive use of ECS. The working document proposes to expand Article 6(2)(b) to include ”illicit use” of ECS, which would allow processing for a broader purpose than abuse or fraudulent use of the communications service itself. Potentially, ”illicit use” could include any crime or illegal behaviour committed by the subscriber with the assistance of the electronic communications service, even if the ECS provider is not the victim of the offence (such as through fraudulent use of the service). The working document further proposes a minimum six month retention period for electronic communications data processed under the broadened purposes of Article 6(2)(b).

In effect, this is mandatory blanket data retention disguised as storage of communications data processed for voluntary business purposes, like billing. When ECS providers process communications data for business purposes, the processing, and in particular any storage of personal data, should be limited to the duration necessary for this purpose. Setting a minimum mandatory retention period for communications data processed under Article 6(2)(b) will mean weakening the level of protection guaranteed under the General Data Protection Regulation (GDPR), which is not only unacceptable but also contradictory to the ePrivacy Regulation being lex specialis to the GDPR. If Member States want to “ensure” the availability of electronic communications data for law enforcement, this should be done by appropriately restricting the rights to data protection and confidentiality of communications in accordance with Article 11 of the ePrivacy Regulation and, in particular, in accordance with the CJEU case law which prescribes targeted data retention rather than blanket data retention.

The second consideration in working document WK 11127/2017 is to exclude processing for law enforcement purposes from the scope of the ePrivacy Regulation in Article 2(2). Under the current ePrivacy Directive, both the retention of electronic communications data and access to retained data by competent authorities is within the scope of the Directive. The working document suggests that excluding processing for law enforcement purposes from the scope of the ePrivacy Regulation could ”bring more clarity to the legal context of data retention”. This would put national legislation for mandatory data retention outside the scope of the ePrivacy Regulation and possibly even outside the scope of EU law, which would be very dangerous for fundamental rights. It could also be considered that it does not put this activity outside the scope of EU law (or at least not fully), as data retention could be considered an exception to the GDPR. So much for “clarity”.

The current ePrivacy Directive provides legal clarity for the retention of electronic communications data and access to the retained data since both types of processing are covered by Article 15(1) of the Directive. Furthermore, CJEU case law provides specific conditions for retention and access to electronic communications data, which ensure appropriate safeguards for fundamental rights. Excluding processing for law enforcement purposes from the scope of the ePrivacy Regulation would bring less legal clarity, not more. In addition, a Regulation aimed at protecting personal data and confidentiality of electronic communications would be deprived of its purpose if certain types of processing (such as “processing for law enforcement purposes”) are completely excluded from its scope. This was also noted by the CJEU in paragraph 73 of the Tele2 judgment.

On 25 April 2018, EDRi member Statewatch published a recent document from the Bulgarian Council Presidency on data retention. Working document WK 3974/2018 looks at the “renewable retention warrant” (RRW). The intention is that competent authorities can issue data retention orders (warrants) to ECS providers under certain conditions. The legal basis for issuing RRWs will have to be national law as no EU legal basis currently exists. It is suggested by the Presidency that ECS providers could appeal the warrant, which would give private companies the job of safeguarding citizens’ fundamental rights. Even though the data retention requirements for RRWs could differ among ECS providers, the Presidency notes that the RRW would be rendered ineffective for law enforcement purposes if not all providers are covered. This will make the RRW approach identical to blanket data retention for all practical purposes and, therefore, a clear circumvention of CJEU rulings.

The patchwork of Council documents (only some of which are available) from DAPIX FoP on data retention shows that some Member States governments are exploring every possible option to uphold their current data retention requirements, despite two very clear CJEU rulings in 2014 and 2016 that blanket data retention is illegal under EU law. These efforts often take place behind closed doors in Council working groups, and the discussions only receive input from Member States’ governments and EU institutions in the law enforcement area, such as Europol and the EU Counter-Terrorism Coordinator. The European public, civil society organisations and data protection authorities are excluded from most of the critical discussions around data retention. In the past, this approach has repeatedly produced legislation such as the Data Retention Directive which was later overturned by the CJEU.

After working document WK 11127/2017 was published in full, European Digital Rights and EDRi members Access Now, Privacy International and IT-Pol Denmark, sent an open letter to EU Member States on the ePrivacy reform. The letter calls upon EU Member States to ensure privacy and reject data retention.

ePrivacy: Civil society letter calls to ensure privacy and reject data retention (24.04.2018)
https://edri.org/eprivacy-civil-society-letter-calls-to-ensure-privacy-and-reject-data-retention/

Freedom of Information request by CEO for WP TELE ePrivacy documents (17.04.2018)
https://www.asktheeu.org/en/request/updated_discussions_in_telecommu#incoming-16851

“Renewable retention warrants”: a new concept in the data retention debate, Statewatch (25.04.2018)
http://www.statewatch.org/news/2018/apr/eu-data-retention-renewable.htm

EU Member States plan to ignore EU Court data retention rulings (29.11.2017)
https://edri.org/eu-member-states-plan-to-ignore-eu-court-data-retention-rulings/

(Contribution by Jesper Lund, EDRi member IT-Pol, Denmark)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
24 Apr 2018

ePrivacy: Civil society letter calls to ensure privacy and reject data retention

By EDRi

On 23 April 2017, EDRi, together with other civil society organisations, sent a follow up to our previous open letter to the permanent representations of EU Member States in Brussels. The letter highlighted the importance of the ongoing reform of Europe’s ePrivacy legislation for strengthening individuals’ rights to privacy and freedom of expression and for rebuilding trust in online services, in particular in the light of the revelations of the Cambridge Analytica scandal.


Open letter to European member states on the ePrivacy reform

23 April 2018

Dear Minister,
Dear Member of the WP TELE,

We, the undersigned organisations, support the ongoing and much-needed efforts to reform Europe’s ePrivacy legislation. As we mentioned in our recent open letter, the reform is essential in order to strengthen individuals’ rights to privacy and freedom of expression across the EU and to rebuild trust in online services, in particular given the revelations of the Cambridge Analytica scandal.1

Despite the urgent need to protect the confidentiality of communications, we are aware of the political difficulties that were met during debates in Council and at Working Party level, specifically regarding Article 11 of the proposed ePrivacy Regulation.

Given these difficulties and following the recent publication of the full document WK 11127/2017,2 we would like to highlight a number of legal points that may help move the discussion forward:

– The Court of Justice of the European Union (CJEU) clarified, in two different judgements (Digital Rights Ireland – joined cases 293/12 and 594/12 and Tele2-Watson, joined cases C-203/15 and C-698/15), that mandatory bulk retention of communications data breaches the Charter of Fundamental rights. Any attempt to subvert CJEU case law by adding “clarity to the legal context” without a legal basis that respects the Charter is a direct attack on the most basic foundations of the European Union and should be dismissed. In fact, the current legal framework (the e-Privacy Directive, Directive 2002/58) provides legal clarity since mandatory retention of metadata for the purpose of prevention, investigation, detection or prosecution of criminal offences, as well as access to retained metadata for this purpose, is regulated in its Article 15(1).

– A Regulation aimed at protecting personal data and confidentiality of electronic communications would be deprived of its purpose if certain types of processing (“processing for law enforcement purposes”) are completely excluded from its scope. This was also noted by the Court of Justice in paragraph 73 of the Tele2-Watson judgment. Furthermore, such processing requires specific safeguards defined by the Court and must be necessary and proportionate.

– Finally, we have also noted certain attempts by a number of delegations to introduce a minimum storage period (of 6 months) for all categories of data processed under Article 6(2)(b). If approved, this would impose indiscriminate retention of personal data in a way that has already been ruled as unlawful by the Court of Justice of the European Union in Tele2/Watson. If Article 6(2)(b) establishes a legal basis for processing communications data in order to maintain or restore security of electronic communications networks and services, or to detect errors, attacks and abuse of these networks/services, the processing should still be limited to the duration necessary for this purpose. On top of this, the general principles of GDPR Article 5 should apply, e.g. storage limitation in Article 5(1)(e). If the technical purpose can be achieved with anonymised data, this is no justification for processing data for identified or identifiable end-users. Setting a minimum mandatory retention period for communications data processed under Article 6(2)(b) will mean weakening the level of protection guaranteed under the GDPR, which is not only unacceptable but also contradictory to the concept of lex specialis.

We are aware of the political difficulties raised in Council around the issue of data retention, however the clarity provided by the CJEU in two landmark rulings on that matter can not and must not simply be ignored. We strongly encourage you to keep in mind all of the legal points above in the ongoing debates. We count on the Council to swiftly conclude a general approach on the ePrivacy Regulation, which should include a legally sound Article 11 rooted in respect for the EU Charter and the CJEU case law, to provide law enforcement authorities with the legal certainty needed to accomplish their duties.3

Yours faithfully,


European Digital Rights

 


AccessNow

 


Privacy International

 


IT-Political Association of Denmark

 


https://edri.org/files/eprivacy/20180327-ePrivacy-openletter-final.pdf and https://edri.org/cambridge-analytica-access-to-facebook-messages-a-privacy-violation

https://www.asktheeu.org/en/request/updated_discussions_in_telecommu#incoming-16851

https://edri.org/eprivacy-reform-open-letter-to-eu-member-states/

Twitter_tweet_and_follow_banner

close
18 Apr 2018

Hermes Center demands investigation of NAT-related data retention

By Hermes Center

On 27 March 2018, EDRi member Hermes Center for Transparency and Digital Human Rights filed a request with the Italian Data Protection Authority (DPA) to investigate on the widespread practice of logging Network Address Translations (NAT) by most of the telecommunication operators.

To better understand the issue, we must first study, from a technical point of view, the operation and allocation of IP addresses by telecommunications companies, in particular, the practice of Carrier-Grade NAT (CGN), an approach used by telecommunications companies – and especially mobile operators – to manage the allocation of IPv4 addresses. Due to the shortage of available IPv4 addresses, it has become necessary to assign private IP addresses to customers, and then translate them into public IP addresses through a NAT procedure performed by devices connected to the internet operator network. In this way, a single public IP address can shield several private IP addresses: the direct identification of the unequivocal user that on “that day and at that time” was assigned to that internet identifier — similar to telephone numbers identification — is more difficult.

According to the statements of law enforcement authorities (LEA), this practice complicates the operations of identification of those who commit crimes because, given a public IP address, there may be dozens of different users. A practice widely used by telecommunication operators to deal with requests for identification by the judicial authority is that of recording and storing all NAT operations between private IP addresses of its customers and public IP addresses: like this, all the connections of the various IP addresses to the internet are recorded.

The Hermes Center demanded that the Italian Data Protection Authority perform a timely verification and inspection of all the main mobile and fixed operators in relation to the practices of data collection of internet traffic, publicly reporting the results, to verify which is the information collected for the purpose of providing compulsory services to the judicial authorities.

----------------------------------------------------------------- Support our work - make a recurrent donation! https://edri.org/supporters/ -----------------------------------------------------------------

A recently introduced Italian law on data retention has extended the retention time period by telecoms providers by up to six years. This data retention concerns both phone traffic and internet connections and clearly goes against the European data retention principles.

On 13 October 2017, Europol and the Estonian Presidency of Council of European Union organised a workshop with 35 policy-makers and law enforcement officials from all around Europe, in order to discuss the “increasing problem of non-crime attribution associated with the widespread use of Carrier Grade Network Address Translation (CGN) technologies by companies that provide access to the internet”.

The Hermes Center filed a Freedom of Information (FOI) request to Europol and the documents are available here: https://www.documentcloud.org/public/search/projectid:37909-Carrier-Grade-NAT-workshop-by-EUROPOL. In Italy, the Hermes Center has appealed to the Data Protection Authority, asking for inspection across all telecommunication operators in order to verify in great details which are the exact information elements logged to comply with data retention laws.

Italy extends data retention to six years (29.11.2017)
https://edri.org/italy-extends-data-retention-to-six-years/

Europol’s FOIA on data retention with carrier grade NAT (22.01.2018)
https://www.hermescenter.org/europols-foia-data-retention-carrier-grade-nat/

Documents related to the Hermes Center’s FOI request to Europol
https://www.documentcloud.org/public/search/projectid:37909-Carrier-Grade-NAT-workshop-by-EUROPOL

(Contribution by Riccardo Coluccini, EDRi-member Hermes Center for Transparency and Digital Human Rights, Italy)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close
27 Mar 2018

Europol: Delete criminals’ data, but keep watch on the innocent

By Joe McNamee

It is almost impossible to believe, but the European Union Agency for Law Enforcement Cooperation (Europol) simultaneously:

  1. has policies that lead to evidence related to possible crimes being deleted (a data indifference regime) and
  2. supports laws requiring the data of innocent people to be stored (a data retention regime).

Worse still, most of this is not necessarily Europol’s fault. The contradiction is supported, or more precisely demanded, by the European Commission and some EU Member States.

1. Data indifference regime

Under the Europol Regulation, the agency must “support Member States’ actions in preventing and combating forms of crime” such as terrorism and racism. However, much of the criminality that Europol works on is not harmonised on a EU level. Indeed, Member States have little interest in actually enforcing much of the relevant law. For the sake of being seen to be doing “something”, the EU has given Europol the job of putting pressure on internet companies to delete content that may or may not be illegal. In the absence of an accusation that a crime was committed, everyone can quietly look the other way.

Under the Regulation, Europol is given the task of referring “internet content, by which […] forms of crime are facilitated, promoted or committed, to the online service providers concerned for their voluntary consideration of the compatibility of the referred internet content with their own terms and conditions”. (emphasis added)

Once Europol identifies and refers illegal content associated with serious crime or terrorism to the relevant internet service providers, how many times does this lead to investigations?

The answer is unknown. Neither Europol nor the European Commission knows if any reports are referred to national law enforcement or judicial authorities nor if there are any investigations.

If there are actual investigations, what happens to the evidence associated with the content? Well, when referring content to service providers, Europol confirmed to EDRi in an e-mail that they give no instructions whatsoever to the internet companies as to whether data should be retained for law enforcement purposes. However, they consider whether the associated personal data can be considered to be “sensitive data” from a legal perspective and treat it accordingly. This assessment is not shared with the providers. If the providers feel that it is “sensitive data”, then they would normally be expected to delete all data not needed for business purposes. Indeed, one of the major social media platforms told us that, when they delete accounts on the basis of referrals, all associated data are deleted after 30 days.

That needs to be said again: in the absence of any instructions whatsoever from Europol, data that is allegedly associated with serious crime or terrorism is deleted.

----------------------------------------------------------------- Support our work - make a recurrent donation! https://edri.org/supporters/ -----------------------------------------------------------------

2. Data retention regime

While data related to content where Europol has acted due to potential serious crime or terrorism is not considered interesting, it is busy supporting measures to require the storage to data related to perfectly innocent people. “We don’t want to use the data we have, but we want more” appears to be the message.

They want more data, even if the mandatory storage of the data has already been deemed illegal by the Court of Justice of the European Union (CJEU) . In addition, numerous EU Member States have laws requiring communications companies to store communications data related to every individual within their territory. They have these laws despite two CJEU rulings against this activity. The European Commission failed and continues to fail to take court action against those countries, in breach of its legal obligation to uphold the treaties of the European Union.

Worse still, the European Commission, Member States (represented in the Council of the EU) and Europol are engaged in a “reflection process” that is seeking to implement new mandatory communications data retention rules. The institutions are attempting to bypass the CJEU rulings through exercises of legal sophistry to exploit imaginary loopholes. Europol even prepared a presentation to support this effort to break the law in the name of ostensibly enforcing the law.

In short, Europol, the Commission and Member States are promoting action by private companies with no obligations for their own law enforcement authorities. The European Commission keeps publishing press releases boasting increasingly restrictive demands on what action internet companies can take to prevent and act on crimes. All of this is done, no doubt, in order to give the impression that somebody is doing something, without actually doing what needs to be done.

A good European Commission would confront law enforcement agencies on their failure to cooperate and start looking into solutions to address this. At the very least it would demand that Member States and Europol to publish consistent and reliable statistics. Right now this Commission is acting against its own mandate by hiding unpleasant facts and actively promoting practices that have repeatedly been found in violation of the Charter of Fundamental Rights of the European Union, of which the Commission supposedly is a Guardian.

(Contribution by Joe McNamee, EDRi)

EDRi-gram_subscribe_banner

Twitter_tweet_and_follow_banner

close