My take on last week's Privacy International and La Quadrature decisions, and implications for UK data protection adequacy. cyberleagle.com/2020/10/hard-q…
Thread summary of some central points follows. (The post is a long read and covers much more.)
The cases concern more than compelled retention of communications data. They include legislation mandating service providers to conduct automated analysis of communications data to detect terrorism, and to provide real-time feeds to security and intelligence authorities. 1/16
The CJEU draws a line between activity on the service provider side (retention and analysis) and transfer of data to the authorities. In limited circumstances, or for some kinds of data, the former may permissibly be general and indiscriminate; the latter not. 2/16
The distinction between legislation directly imposing blanket obligations on all service providers, and that conferring discretionary powers to require individual service providers to engage in stipulated activities, is also becoming more significant. 3/16
Legislation imposing general and indiscriminate communications data retention obligations is generally speaking incompatible with EU law, other than for source IP addresses and user identity data. 4/16
However, an instruction for general and indiscriminate retention of communications data, and mandated general and indiscriminate automated analysis to detect a terrorist threat, are permissible (subject to safeguards) while a serious threat to national security exists. 5/16
Targeted retention (for instance according to categories of person or geographic criteria objectively connected to the purpose of combating serious crime) is permissible for limited purposes and subject to safeguards. 6/16
A blanket legislative requirement imposed on all providers is readily characterised as general and indiscriminate. But how to determine whether a discretionary power mandates general and indiscriminate, or targeted, activities? 7/16
The CJEU reiterates that legislation must lay down clear and precise rules, and indicate the circumstances and conditions in which a measure can be adopted. It adds that the legal basis permitting the interference must itself define its scope. 8/16
Does a Member State have to list in its own legislation a set of substantive conditions, such as according to category of person or geographic criteria, constraining the exercise of a discretionary power? 9/16
Or is it sufficient for the legislation to require observance of necessity and proportionality and to lay down factors to be taken into account when exercising the power, accompanied by safeguards? 10/16
Under the IP Act the Secretary of State must consider it necessary and proportionate to exercise her data retention power, and is required to take into account specified factors. Her decision is subject to Judicial Commissioner approval. 11/16
In April 2018 the High Court in the Liberty case said that sufficed. It was not necessary, and would be impractical, to list conditions in the legislation. Also, it could not be said that the legislation permitted general and indiscriminate retention of communications data. 12/16
As to whether an approach more reliant on safeguards than limitations is sufficient, these CJEU decisions appear to lean further towards requiring substantive conditions to be spelled out in binding legislative instruments. 13/16
The potential impact of that is heightened by the distinctions that the CJEU has now made between different kinds of service provider activity and access by the authorities, which are made subject to differing conditions and are permissible for differing purposes. 14/16
An avowedly bulk power such as the IP Act communications data acquisition warrant, which while requiring necessity and proportionality does not make such differentiations on the face of the legislation, now appears less likely to pass muster. 15/16
Overall, the IP Act powers should be evaluated from two perspectives: acceptability of soft versus hard limitations, and compliance with the substantive limits applicable to different categories of data retention and transmission power now articulated by the CJEU. 16/16

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Graham Smith

Graham Smith Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @cyberleagle

8 Apr 19
The "initial" list of online harms. "...by design, neither exhaustive nor fixed. A static list could prevent swift regulatory action to address new forms of online harm, new technologies, content and new online activities." #onlineharms
Guess they haven't been reading the right blogs. cyberleagle.com/2019/03/a-ten-…
And to think I warned of this 7 years ago... scl.org/articles/2626-…
Read 4 tweets
15 Sep 18
Some predictions of possible consequences of the Strasbourg Big Brother Watch judgment for the Investigatory Powers Act. #IPAct 1/6
1. Oversight of entire bulk interception selection process from start (bearer selection) through middle (selectors etc) to end (analyst searches etc).

Public description of nature and granularity of oversight at each stage. Perhaps doable within current #IPAct framework. 2/6
2. Selection of related communications data (secondary data in #IPAct terms) for purposes other than ascertaining whether someone is currently within the British Islands.

#IPAct amendment. May sound technical, but this is potentially a significant issue. 3/6
Read 6 tweets
26 Nov 17
This commentary on the European Commission’s Communication ‘Tackling Illegal Content Online’ has just entered my top 10 all time posts. At 8,500 words admittedly it’s on the long side. So here goes a threaded summary. cyberleagle.com/2017/10/toward…
1/20 The EU Council Freedom of Expression Guidelines stress the importance of “protecting intermediaries from the obligation of blocking Internet content without prior due process.”
2/20 ‘Tackling Illegal Content Online’ institutionalises the opposite: prior restraint instead of prior due process. Small wonder they deleted a previously leaked draft’s reference to the Guidelines.
Read 21 tweets
28 Jun 17
1/7 At the heart of the end to end encryption debate is this.
2/7 If you take technical steps to make the internet unsafe for terrorists and criminals, you make it unsafe for the rest of us.
3/7 No amount of Silicon Valley tech wizardry can change that.
Read 7 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!