Showing posts with label surveillance. Show all posts
Showing posts with label surveillance. Show all posts

Wednesday, 29 November 2023

Live Facial Recognition for Law Enforcement: The European Union’s Regulatory Approach Should be Informed by UK Police’s Practice

 




 

Asress Adimi Gikay (PhD)

Senior Lecturer in AI, Disruptive Innovation, and Law at Brunel University London

Photo credit: Dirk Ingo Franke, via Wikimedia Commons

 

Divergent Approaches to Regulating Live Facial Recognition

In what is characterised as an 'Orwellian Nightmare', UK’s Minister of Crime, Rt Hon Chris Philp  MP recently suggested the opportunity for the UK police to search national passport database using facial recognition technology to tackle shoplifting crimes. This occurred as preparations were underway for the AI Safety Summit, an event that took place in London. It has some irony, to the surveillance anxious participants who gathered to discuss AI Safety as London is one of the cities with the largest number of CCTV cameras; but importantly where the police frequently use live facial recognition (LFR) in public spaces. 

Since South Wales Police made the first arrest using LFR over six years ago, UK Police use the technology to locate criminal suspects from crowds. In  LFR, the artificial intelligence(AI) software compares, in real-time, biometric facial images captured by a camera with existing facial templates of persons of interest  in a police-created database known as ‘watchlist’. This is contrasted with retrospective facial recognition system where the facial recognition takes place in the absence of the person of interest based on a video or still image taken from a source (also known as post-system). The UK government has called up on police force to expand the use of the technology, amidst growing concerns that the technology could endanger civil liberties.

By contrast, the European Union’s (EU) upcoming AI Act, in the Parliament’s Compromise Amendments categorically bans the use of LFR. However, the ‘trialogue negotiations’ seem to have led to a compromise where the use of the technology is permitted for specifically listed crimes punishable by at least five years. The EU’s restrictive position seems  intended primarily to appease civil society organisations, 12 of which wrote a letter to the EU Council in 2022 reiterating the need to prohibit the technology in categorical terms. Meanwhile, despite the recent call from 61 MPs and 31 civil society organisations demanding the immediate cessation of the use of the technology by UK police and private companies, efforts to stop the technology have remained unsuccessful in the UK.

In this post, explain why the UK’s approach should inform the regulation of LFR in the EU, by using evidences from the use of the technology by the UK police. I also introduce the theory of incrementalism, a normative framework for regulating novel technologies posing evolving risks whose magnitudes are yet to be known, in my forthcoming Cambridge Law Journal Article—‘Regulating Use by Law Enforcement Authorities of Live Facial Recognition Technology in Public Spaces: An Incremental Approach.’ 

Why the EU’S Approach Should Take an Incremental Approach

Incrementalism calls for regulating the use of the LFR technology by the police, and by extension similar technologies with novel advantages and risks, through progressive adjustment of the existing legal framework in the light of the potential risks and evidence of actual harm. This is different from a regulatory framework that responds to the risk of harm assessed in abstract terms, without considering the context of actual application of the technology, existing safeguards as well as the overall benefit of the technology.

I propose this theory to incorporate four main ingredients: sectoralism; reliance on existing legal frameworks; evidence-based regulation; and flexibility. This post will only explain evidence-based regulation as one of the important elements of the theory. The UK’s prevailing approach to regulating LFR and AI in general reflects certain elements of incrementalism. A measured regulation of facial recognition technology in the EU requires adopting this theory in its entirety or partially.   

Evidence-Based Regulation

The position of the EU on LFR does not appear to be based on thorough assessment of the benefits and risks of the harm of the technology as well as public support and the ability of law enforcement authorities to use it in proportionate manner.  Indeed, these are important factors in choosing the appropriate response to a new regulatory phenomenon. The experience in the UK provides an excellent insight into understanding the issue.

Evidence of Public Support and Benefits of the Technology

In a 2019 UK national survey conducted by Ada Lovelace Institute, 70% of respondents thought police should be permitted to use facial recognition in criminal investigation, with 71% supporting its use on public spaces, if it helps reduce crime. This positive public view aligns with the existing evidence of the effectiveness of the technology in tackling crimes. In 2020 and 2022, the London Metropolitan Police Service identified nine suspects in eight live facial recognition deployments. Earlier in 2018, the technology assisted South Wales Police in, reportedly,  making 450 arrests.  Several deployments in the UK have recently shown the effectiveness of the technology in helping arresting people suspected of committing violent crimes.

In October 2023, the Metropolitan Police identified 149 suspects of retail crimes using retrospective facial recognition. They compared hundreds of CCTV still images provided by retail businesses of their ‘prolific retail offenders’ against custody images. The result is significant as retail business are crucial to the UK economy creating a job for one in ten Londoners. Additionally, these crimes lead to the loss of estimated £1.9 billion in revenue whilst involving rampant abuse of retail workers. 

With the technology garnering some public support, campaigners struggle to present a persuasive evidence of harm of using it to back their push for blanket prohibition or suspension in the UK. As EU members states have not allowed the technology to be used, it is impossible to understand if the technology actually causes harm.  Generally, advocacy groups  highlight the inaccuracy of face recognition systems, especially in identifying women of colour, with Big Brother Watch claiming that Met and South Wales Police facial recognition systems are over 89% inaccurate. However the National Physical Laboratory independently tested two facial recognition systems used by the UK police in 2022. The result showed the software underperformed the most on Black-Female faces, but the discrepancy in accuracy rates across demographics was found to be statistically insignificant. Equally importantly, the inaccuracy of the technology does not inevitably translate into harm due to the existing legal safeguards the UK police adhere to, safeguards that exist or can be implemented in the EU.

Evidence of Safe and Proportionate Use

Despite the technology seeming to be unquestionably inaccurate, there is no reported case of serious harm resulting from the use of the technology in the UK because the UK police use it safely and proportionately. This can be contrasted with the US, where troubling incidents of wrongful arrests using facial recognition systems have been documented. For instance, Nijeer Parks, a Black American misidentified by facial recognition was wrongfully incarcerated for ten days. According to a civil complaint against the Director of Woodridge Police and others, Nijeer Parks voluntarily visited the police station to clear his name upon learning of an arrest warrant issued for him, in what he believed to be a case of mistaken identity. The police subjected him to coercive interrogations and solitary confinement, to secure his confession, whilst ignoring his alibi and the mismatch between DNA and fingerprints found at the crime scene with those of Nijeer Parks’.

These kinds of incidents seem to reflect more of police misconduct than the inherent challenge posed by the technology. Despite the concerns in the US,  in 2021, not less than seventeen state legislatures rejected bills to ban facial recognition. Some states including New Orleans and Virginia, that had previously banned facial recognition have now reversed course, to allow its regulated use.  Legislatures seem to want legal frameworks that strike a balance between benefits of the technology and addressing its risks.

Such a legal framework largely exists in the UK and the EU, as the two jurisdictions have similar human rights regimes. The UK police are obligated to use facial recognition technology in compliance with the Human Rights Act and the Equality Act, the latter imposing equality impact assessment obligation. Equality impact assessment requires the police to proactively tackle the potential discriminatory impact of the technology on specific groups and implement risk mitigation measures. These measures are supplemented by privacy law under the European Human Rights Convention and data protection rules under the Law Enforcement Directive (applicable both in the EU and the UK).

In the UK, the police also adhere to a national document prescribing detailed procedures for deploying live facial recognition technology known as the authorised professional practice. This national code of practice has a binding force. As a result of these comprehensive safety frameworks, the UK police have used facial recognition technology for seven-years without a single instance of wrongful arrest or abuse. As the European Union has advanced legal frameworks on human rights, privacy, data protection, and rule of law in general, it is inconceivable that the result of using facial recognition technology in the EU would be different from that of the UK.

Advocacy groups also highlight privacy intrusion and the expansion of surveillance as further concerns in relation to the use of LFR in public spaces. Nevertheless, these are addressed by legally limiting the duration, purpose and context of the use of the technology in the UK. The police are required to  assess the proportionality of using the technology, especially in places where it could have serious privacy implications such as hospitals and schools. This is mainly because article 8 of the European Human Rights Convention, similarly to its EU counterparts, articles 7, and 52 of the Charter of Fundamental Rights allow interference with privacy right based on the assessment of proportionality and necessity.  The existing legal framework in the UK does not permit surveillance at will. Things are not different in the EU, and in any event, a  loophole that creates a room for excessive surveillance could be addressed by a legislation.

Additionally, the face recognition software used by the police does not retain biometric data of individuals unless  positively matched, and personal data generated during its use is automatically deleted within a short span of time. These are intentionally built-in features of the software aimed at lessening the privacy and data protection impacts of the technology. Last, LFR is currently used in public spaces where people are unlikely to engage in private activities that should outweigh the public's interest in tackling violent crimes, although again, specific deployments need to observe the requirements of necessity and proportionality. 

Academics and advocacy groups often express doubt about the clarity of the legal basis for using facial recognition or the existence of mechanisms for redress for harms caused by the use of the technology. But this is not based on sound legal analysis. The current law does allow the police to gather information for fighting crimes including using new technological tools.  Furthermore, the police can be liable to pay compensation for harms, if they wrongfully detain or interrogate someone following misidentification using facial recognition technology under civil liability law. This is not to suggest that the existing law is without any loophole, but that addressing any legal gap requires delicate balancing rather than unnecessarily restrictive measures.

The Need to Reverse Course in the EU

The EU Commission’s Initial Draft of the AI Act permitted the limited use of LFR for law enforcement purpose.  First, by way of exception it allowed the use of the technology for narrowly defined, specific, and legitimate purposes [Art. 5(1)(d)]. These purposes are:

(i) the targeted searches for specific potential victims of crime, including missing children;

(ii) the prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a terrorist attack; and

(iii) the detection, localisation, identification or prosecution of a perpetrator or suspect of a crime with a maximum sentence of at least three years that would allow for issuing a European Arrest Warrant. 

Second, the relevant law enforcement authority must demonstrate that the use of the technology is justifiable against (a) the seriousness, probability and scale of the harm caused in the absence of the use of the technology;(b) the seriousness, probability and scale of consequences of the use of the technology for the rights and freedoms of all persons concerned; and (c) the compliance of the technology's use with necessary and proportionate safeguards and conditions in relation to the temporal, geographic and personal limitations[Art. 5(2)-3]. The authority proposing to use the technology bears the burden of justification.

Third, the relevant law enforcement authority must obtain prior express authorisation from a judicial or a recognised independent administrative body of the Member State in which the technology is to be used, issued upon a reasoned request. If duly justified by urgency, the police may apply for authorisation during or after use [Art. 5(3)].

The Parliament’s Compromise Amendments categorically banned LFR used either by private companies or law enforcement authorities.  As this post has demonstrated, the evidence in the UK as well the recent reversal of bans in the US clearly indicate that the EU’s position is not based on concrete evidence. As mentioned earlier, the ‘trialogue negotiations’ seem to have led to a compromise where the use of the technology is permitted for specific crimes punishable by at least five years. This is unnecessarily restrictive as host of crimes including money laundering, financial fraud and other offences are not envisioned to be among the crimes for which the technology can be used.

A Call for Measured Regulation

The thinking behind the EU’s approach seems to be highly influenced by campaigners who depict the use of the technology as 'Orwellian' to induce public  fear, regardless of the context in which it is used. It appears to be a knee-jerk reaction, rather than an evidence-based response. The UK’s current practice and legal framework certainly have some loopholes to close. For instance, the technology could potentially be used for all crimes today, regardless of the seriousness of the crimes in question. But addressing these kinds of details does not entail suspending the use of the technology or entirely prohibiting it. Neither does it requires unnecessarily restricting it. Any legislative effort that aims to strike a delicate balance between the societal benefits and risks of the technology should take an incremental approach, that allows for timely response to evolving risk based on actual evidence of harm than conjecture. Starting with the strictest regulatory framework, uninformed by evidence could needlessly deny society of the benefits of the technology.

 

Friday, 28 October 2022

Should the EU Ban the Real-Time Use of Remote Biometric Identification Systems for Law Enforcement Purposes?

 




Asress Adimi Gikay (PhD)

Senior Lecturer in AI, Disruptive Innovation, and Law

Brunel Law School & Brunel Centre for AI(London, UK)

Twitter: @DrAsressGikay

Photo credit: Irbsas, via Wikimedia commons

 

The Call for Ban on Real-Time Remote Biometric Identification System

It has been around two years since the European Commission introduced its Draft Artificial Intelligence Act ("EU-AIA), which aims to provide an overarching AI safety regulation in the region. The EU-AIA's risk-based approach has been severely criticised mainly for failing to take a fundamental rights approach to regulate AI systems. This post focuses on the EU-AIA's position on the use of Real-Time Remote Biometric Identification Systems (RT-RBIS) by law enforcement authorities in public spaces, which continues to cause the most controversy.  

The EU-AIA defines RT-RBIS as a "system whereby the capturing of biometric data, the comparison and the identification all occur without a significant delay" [EU-AIA Art. 3(37)]. The regulation covers the real-time processing of a person's biological or physical characteristics, including facial and bodily features, living traits, and physiological and behavioural characteristics, through a digitally connected surveillance device. The most commonly known RT-RBIS is facial recognition technology (FRT)—a process by which an AI software identifies or recognises a person using their facial image or video. The software compares the individual's digital image captured by a camera to an existing biometric image to estimate the degree of similarity between two facial templates and identifies a match. In the case of real-time systems, capturing and comparing images occur almost instantaneously.   

As EU institutions, Member States, and stakeholders continue to discuss the EU-AIA, there is growing dissent against the use of RT-RBIS for law enforcement purposes in publicly accessible spaces. In 2021, the European Parliament invited the Commission to consider a moratorium on the use of this technology by public authorities on premises meant for education and healthcare. In response to the EU Council's latest proposed revision of the EU-AIA, on October 17, 2022, 12 NGOs wrote a letter to the EU Council reiterating the need to prohibit the technology unconditionally.  

  

The Risk Posed by the Technology

RT-RBIS poses multiple risks that might jeopardise individual rights and citizens’ overall welfare.

As the technology is still evolving, there remains the risk of inaccurate analysis and decisions made by the system. In the United States, police have used FRT to apprehend individuals suspected of a crime where multiple instances of mistaken identification led to wrongful arrests and pre-trial incarcerations. In one example, a Black American wrongly identified by a Non-Real Time FRT for suspicion of shoplifting, resisting an arrest and attempting to hit a police officer with a car spent eleven days in jail in New Jersey. Between January 2019 and April 2021, 228 wrongful arrests were reportedly made based on FRT in the State of New Jersey. 

The deployment of RT-RBIS in public spaces could cause more significant harms compared to Non-Real time biometric identifications systems. These harms include missing flights, false arrests, and prolonged and distressing police interrogations that have adverse socio-economic and psychological effects on law-abiding members of society. 

RT-RBIS could also be applied discriminatorily, disproportionately targeting specific groups. In a 2019 study, researchers have found that FRT falsely identifies "Black and Asian faces 10 to 100 times more often than white faces." False positives were found to be between "2 and 5 times higher for women than men." Whilst an ethical and inclusive machine learning programme could alleviate this, the potential for discriminatory application of the technology cannot be ignored. In the UK, the existing policing practice has been criticised for subjecting ethnic minorities to disproportionate stops and searches. Indeed, the police should not be allowed to use technology to maintain similar stereotypical practices.

Lastly, RT-RBIS could continue to normalise surveillance culture and increase the infrastructure for it. Public spaces such as airports, train stations, and parking lots could be equipped with cameras that law enforcement authorities could activate for live biometric identification in case of necessity. This could expose the public to the risk of state surveillance. The use of FRT to crack down on the exercise of democratic rights by authoritarian governments is becoming a common practice.  Currently, there is an ongoing legal challenge against Russia before the European Human Rights Court for mass surveillance of protests using FRT.

The risks highlighted above must be addressed seriously and comprehensively. However, is a complete ban on the use of the technology a reasonable solution? 

Qualified Prohibition and Fundamental Rights Approach under the EU AI Act

Due to the high risk to fundamental rights  posed by some AI systems, scholars have argued that the EU-AIA should take a fundamental rights approach in regulating these AI systems. As fundamental rights are given strong legal protection, any measure that interferes with them should meet three legal requirements:

Interference  with derogable rights is allowed for a narrowly defined, specific and legitimate purposes prescribed by law, and subject to the tests of necessity and proportionality.

The burden of proving the necessity and proportionality of interfering with fundamental rights lies with the authority seeking to interfere with such rights.

A court or a similar independent body determines whether the authority has met the threshold of its burden of justification.

These requirements involve a careful judicial balancing act. The EU-AIA's qualified prohibition of using RT-RBIS effectively adopts the same approach. 

First, the EU-AIA permits, by way of exception, the use of the technology for narrowly defined, specific, and legitimate purposes [EU-AIA Art. 5(1)(d)]. These purposes are, (i) the targeted searches for specific potential victims of crime, including missing children; (ii) the prevention of a specific, substantial and imminent threat to the life or physical safety of natural persons or a terrorist attack; and (iii) the detection, localisation, identification or prosecution of a perpetrator or suspect of a crime with a maximum sentence of at least three years that would allow for issuing a European Arrest Warrant. These are specific and legitimate purposes for restricting fundamental rights, depending on the context. 

Second, the relevant law enforcement authority must demonstrate that the use of the technology is justifiable against: (a) the seriousness, probability and scale of the harm caused in the absence of the use of the technology; (b) the seriousness, probability and scale of consequences of the use of the technology for the rights and freedoms of all persons concerned; and (c) the compliance of the technology's use with necessary and proportionate safeguards and conditions in relation to the temporal, geographic and personal limitations[EU-AIA Art. 5(2)-3]. The authority proposing to use the technology bears the burden of justification.

Third, the relevant law enforcement authority must obtain prior express authorisation from a judicial or a recognised independent administrative body of the Member State in which the technology is to be used, issued upon a reasoned request. If duly justified by urgency, the police may apply for authorisation during or after use [EU-AIA Art. 5(3)].

The preceding analysis demonstrates that the EU-AIA does not give a blank cheque to the police to conduct spatially, temporally, and contextually unlimited surveillance. Despite the EU-AIA not explicitly employing fundamental rights language in the relevant provision, it entails a balancing act by courts, that must determine whether the use of RT-RBIS is necessary and proportionate to the purpose in question by considering multiple factors, including human rights. 

 

The Call for Categorical Prohibition is Unsound

The fear of increasing surveillance is one of the grounds for the heightened call for the complete prohibition of RT-RBIS. Nevertheless, viewed within the overall context, the envisioned use of the RT-RBIS under the EU-AIA does not significantly change the existing surveillance culture or infrastructure.   

 

Amid Corporate Surveillance Capitalism

Contemporary societies now live in massive corporate surveillance capitalism. Big Tech companies such as Facebook, Google, Twitter, Apple, Instagram, and many other businesses access our personal data effortlessly. They know almost everything about us— our location, addresses, phone numbers, private email conversations and messages, food preferences, financial conditions and other information we would prefer to keep confidential. Surveillance is the rule rather than the exception, and we have limited tools to protect ourselves from pervasive privacy intrusions. 

Whilst surveillance, if employed by law enforcement, is used at least in theory to enhance public welfare, such as prosecuting criminals and delivering justice, Big Tech uses it to target us with advertisements or behavioural analysis. The fear of law enforcement's use of RT-RBIS in limited instances is inconsistent with our tolerance for Big Tech corporate surveillance. This does not mean we must sink further into surveillance culture, but we should not apply inconsistent policies and societal standards, detrimental to the beneficial use of the technology.  

 

Minimal Change in Surveillance Infrastructure

 The deployment of RT-RBIS as envisioned by the EU-AIA is unlikely to change the current surveillance infrastructure significantly, where Closed-Circuit Television (CCTV) cameras are pervasively present. In Germany, in 2021, there were an estimated 5.2 million CCTV Cameras, most facing publicly accessible spaces. In the UK, there are over five million surveillance cameras, over 691 000 of which are in London. On average, a London resident could be caught  300 times on CCTV cameras daily

The police can access these data during the crime investigation, probably without needing a search warrant in practice. It is improbable that private CCTV camera owners refuse to provide access footage to the police due to a lack of a search warrant, unless they are involved in the crime or protecting others. At the same time, footage from these cameras play an instrumental role in solving serious crimes. However, the overall picture surveillance infrastructure would not significantly change; if it does, it is for a better public good.

 

Ethical Development and Use Guideline

The potential biases or disproportionate use of the technology against certain groups could be tackled by designing ethical standards for the development, deployment and use of AI systems. These guidelines include ensuring that the AI systems are bias-free before deployment and requiring law enforcement authorities to have clear, transparent and auditable ethical standards. The EU-AIA itself has several provisions to ensure this.

 

Maintaining the EU-AIA's Provisions on RT-RBIS

The use of RT-RBIS, as envisioned under the EU-AIA, does not fundamentally change the existing surveillance culture and infrastructure. Nor does it unreasonably increase the surveillance power of the state. On the contrary, a categorical ban would impede beneficial limited use. Therefore, the provisions of the EU-AIA governing the limited use of RT-RBIS by law enforcement authorities in publicly accessible spaces must be maintained. Stakeholders should resist the temptation to implement radical solutions that will harm societal interest, and focus on developing ethical guidelines for development, deployment and use of the technology. 

Thursday, 17 June 2021

Big Brother Watch v UK: the ECtHR Grand Chamber rules on mass surveillance


 


 

Lorna Woods, Professor of Internet Law, University of Essex

 

Introduction

 

This is the Grand Chamber’s take on a challenge to the UK’s RIPA regime originally decided by a chamber (judgment 13 September 2018). It is the culmination of a long series of challenges to the UK regime, following the publication of information revealing that the UK (and other Governments) had engaged in bulk surveillance of people’s communications as well as in intelligence sharing. The judgment arose from three applications originally filed before the Strasbourg Court: Big Brother Watch and Others v. the United Kingdom (App no. 58170/13); Bureau of Investigative Journalism and Alice Ross v. the United Kingdom (App no. 62322/14); and 10 Human Rights Organisations and Others v. the United Kingdom (App no. 24960/15) (and on which I commented).  Similar questions were also in issue in Centrum för Rättvisa v. Sweden (App no. 35252/08), another Grand Chamber judgment handed down on the same day but based in a longstanding challenge to Swedish surveillance laws from 2008 which had been found by a chamber of the court not to violate Article 8 ECHR (the right to privacy). 

 

It raises questions about the extent to which such surveillance is permissible and under what conditions – and is about the extent to which the safeguards identified before digitization and which were generally applied in relation to interception of communications can apply to intelligence gathering based on data analytics, where issues of meta data are directly considered as well as concerns about the content of communications. The particular problem is that surveillance has historically been considered from the perspective of individual surveillance, where a person may be the subject of surveillance when there are reasonable grounds for suspicion. The very nature of bulk data acquisition and intelligence gathering means that there is no such suspicion.

 

As many commentators have remarked, it is the first mass electronic surveillance case to be decided against the UK after the Edward Snowden revelations and, significantly, it also considered meta data (communications data) as well as content. While the Court found the UK government to be in violation of Article 8 on some points, it is not a complete ‘win’ for privacy activists. Notably, this judgment and that in Centrum för Rättvisa, sets the conditions for bulk collection of data; in so doing, has it – as the Court of Justice of the EU apparently has following La Quadrature du Net (Case C-511/18) -accepted the possibility the principle of mass survellance, with the loss of anonymity not just online but – with smart homes, cars and cities – potentially everywhere?

 

Facts

 

The UK Government Communications Headquarters (GCHQ) was running three surveillance systems:

 

-          bulk interception of (foreign) communications (which was then winnowed down through automated means to sets of information that would be analysed by the security services);

-          intelligence sharing among the ‘Five Eyes’ (the United States, Canada, Australia, New Zealand as well as the UK), specifically in collaboration with the PRISM and Upstream programs run by the American NSA; and

-          acquisition of communications data from internet service providers.

 

The regime at that time was based on the Regulation of Investigatory Powers Act 2000 (RIPA), which has now been replaced by the Investigatory Powers Act 2016 (IPA); the Court decided matters on the basis of the law as was and not in the light of the IPA (though the IPA shares some features with the RIPA regime). In addition to statutory provisions, RIPA envisaged that codes of practice would provide more detail as to actual practice. As regards the sharing of intelligence, the Counter Terrorism Act 2008 allowed for the disclosure of information to each arm to exercise any of their functions, subject to any limitations imposed by virtue of the Data Protection Act 1998 (now itself replaced by the Data Protection Act 2018) and the Human Rights Act. The Official Secrets Act also applies.  The U.K.-U.S. Communication Intelligence Agreement governs the exchange of intelligence information relating to “foreign” communications between the UK and the US, with the code of practice containing more detail as to treatment of foreign intelligence.

 

The applications – which included journalists and human rights organisations and which might be understood to be particularly affected by the threat of surveillance -were heard together. The 10 Human Rights Organisations had started their action in the IPT; the other applicants claimed there was no effective remedy.  The Chamber decision found a violation of Article 8 and Article 10 in relation to the bulk interception regime in s 8(4) RIPA, and the regime for obtaining communications data, but found no violation as regards the information sharing.

 

 

Judgment

 

There are three aspects to the judgment regarding Article 8. The consideration  of the bulk interception (and the possibility of analysing associated communications data); the receipt of data from foreign intelligence services; and the acquisition of communications data from service providers. These also gave rise to claims under Article 10.

 

Bulk Intercept

 

The analysis of the bulk communications involves a number of stages, each one narrowing the dataset but at the same time, intensifying the level of scrutiny on that information. The Court identified the following stages (para 325):

 

-          the interception and initial retention  of communications and related communications data;

-          the application of specific ‘selectors’ (whether stong selectors – eg an email address - or complex queries);

-          the examination of the resulting selected communications and communications data and retention of data;

-          use of ‘final product’, including sharing that information.

 

While the mere holding of such information by the State in and of itself has long been held to be an intrusion into Article 8 rights, the Court portrayed the four stages as a process in which the degree of interference increases as the analysis progresses (paras 330-331). While bulk surveillance was not per se prohibited by the ECHR, the entire process must be subject to “end-to-end safeguards”.

 

The Court considered whether there was a need to develop the case law given the developments in technology.  In Weber and Saravia and Liberty & Ors the Court had applied the principles developed in relation to targeted interception – targeted interception, however, has a much narrower impact that bulk surveillance.  The Court identified a number of differences between targeted and bulk interception:

 

-          bulk interception was predominantly directed towards international communications (para 244);

-          bulk interception was predominantly aimed at intelligence gathering (rather than investigating crime) (para 345);

-          insofar as individuals were targeted, there devices were not monitored but rather ‘strong selectors’ were used to fish out their communications from the mass of communications intercepted (para 346).

 

This meant that the safeguards already in place, although they provide a useful framework, should be adapted. Specifically, rules that envisaged a particular person or group of persons would not work here – eg the  requirement  to  define  clearly  in  domestic  law  the  categories  of  people  liable  to  have  their  communications  intercepted  and  the  nature  of  offences  which  might  give  rise  to  such  an order or the requirement to have “reasonable suspicion” of the persons put under surveillance (para 348). Nonetheless, domestic law should still set out with sufficient clarity and detail the grounds upon which bulk interception might be authorised and any circumstances in which an individual’s communications might be intercepted. Supervision and review become more important (para 349). The domestic regime should ensure that an assessment of necessity and proportionality is made at each stage of the measures being taken; that bulk interception should be subject to independent authorisation at the outset, when the object and scope of the bulk operation are being defined; and that the operation at each stage should be subject to supervision and independent ex post facto review (para 350). Affected individuals should have access to an effective remedy. When assessing a regime, the Court would take into account its operation in practice including instances of actual abuse (para 360).

 

Note that the Court was not persuaded that the acquisition of related communications data through bulk interception was necessarily less intrusive than the acquisition of content. The same safeguards should therefore be used to assessed bulk collection and analysis of communications data as content.

 

The starting point for analysis is the typical three stage test (lawful, legitimate aim and necessary in a democratic society), but the Court blends the lawful and necessity questions together which it claims is established (citing Roman Zakharov – a Grand Chamber decision discussed here - and Kennedy). The Court produced a framework that was wider -in the assessment of the Court - than the six Weber criteria (para 361):

 

-          the grounds on which bulk interception may be authorised;

-          circumstances in which an individual’s communications may be intercepted;

-          the procedure for granting authorisation;

-          procedures for selecting, examining and using intercept material;

-          precautions when communicating material to other parties;

-          limits on duration of interception, storage of intercept material and circumstances in which that material must be erased/destroyed;

-          supervision by an independent authority (with powers to address non-compliance);

-          independent ex post review.

 

The Court also took the opportunity to provide more detail on data sharing. Any data shared must have been collected and stored in a Convention compliant manner. Additional safeguards relating to the transfer must be in place: the circumstances in which data are to be shared should be set out in domestic law; the receiving state should have safeguards in place capable of preventing abuse, including secure storage and restriction on onward disclosure. Heightened safeguards are required as regards material requiring special confidentiality (eg journalistic material). In principle the same tests apply to communications data, which it viewed as no less intrusive as content, though the safeguards need not be exactly the same given the different way content and communications data were likely to be analysed.

 

The UK regime did not provide sufficient “end to end” safeguards. In assessing the safeguards, the Court took into account the breadth of the grounds on which surveillance could take place; the UK’s rules ‘were formulated in relatively broad terms’ (para 371). The Court specifically focussed on the absence of independent authorisation, the failure to include the categories of selectors in the application for a warrant (which had implications for the necessity assessment), and the failure to subject selectors linked to an individual to prior internal authorisation both as regards content but also related communications data. Although the Court assessed the oversight provided by the Commissioner and the IPT as effective and robust respectively, these did not compensate for the shortcomings.

 

Note that in the parallel Swedish case, the Court applied a similar framework to find that the Swedish regime was also deficient. So, it found ‘the absence of a clear rule on destroying intercepted material which does not contain personal data, the absence of a requirement in the Signals Intelligence Act or other relevant legislation that, when making a decision to transmit intelligence material to foreign partners, consideration is given to the privacy interests of individuals; and the absence of an effective ex post facto review’ (Centrum för Rättvisa, para 369).

 

The complaint under Article 10 was considered separately, with the Court’s starting point being the importance of journalism. It emphasised the detrimental impact of compelled source disclosure, as well as the more serious intrusion of searching of journalists’ homes and workplaces. Safeguards must ‘be attended with the right to protection of journalistic sources must be attended with legal procedural safeguards commensurate with the importance of the principle at stake’, referring back to its decision in Sanoma Uitgevers (para 444). Crucially, independent review must take place prior to disclosure. In the older case of Weber, the interference with the journalist’s expression rights had not been seen as particularly serious; the journalists had not been targeted by the surveillance. The court determined that confidential journalistic material could have been accessed by the intelligence services either intentionally, through the deliberate use of selectors or search terms connected to a journalist or news organisation, or unintentionally, as a “bycatch” of the bulk interception operation. While the former category must be authorised in accordance with the approach in Sanoma Uitgevers, for the latter category because interference with journalistic material was not intended, it could not be predicted and therefore ex ante authorisation would not be possible.

 

The Court noted the technological developments since Weber, finding that the intrusion now would be more significant than at the time of Weber. Robust safeguards are therefore required so that when it becomes apparent that confidential journalistic material is in issue, that material could only continue to be stored and examined by an analyst if authorised by a judge or other independent and impartial decision‑making body with the power to determine whether its continued storage and examination was “justified by an overriding requirement in the public interest” (para 450). In both aspects, despite specific provisions in the relevant code of practice, the UK regime was deficient.

 

Data-sharing

 

The complaint was considered from the perspective of solicited intercept material from the NSA. The applicants did not challenge the Chamber’s decision as regards the effectiveness of the IPT. Avoiding questions about Article 1 ECHR and the issue of a State’s jurisdiction, the Court focused on the initial request and subsequent receipt of intercept material, together with any subsequent use thereof. The Court noted the risk of States seeking to circumvent controls; there must be a clear basis in domestic law for such requests (found in the Code), and guarantees against the risk of abuse specifically relating to examination, use and storage, any onward transmission as well as erasure/destruction.  The Grand Chamber found that, since the treatment of foreign intelligence was essentially the same as the treatment accorded to domestically generated material, the United Kingdom had in place adequate safeguards for the examination, use and storage of the content and communications data received from intelligence partners, as well as for the onward transmission of this material and for its erasure and destruction. It also noted the extra layer of protection provided by the Commissioner and the IPT. It found no violation of Article 8. The claims under Article 10 were likewise dismissed.

 

Communications Data

 

The Chamber’s finding that a regime which suffers the same flaws as a regime accepted to be incompatible with EU law, then having priority over domestic law, must also fail the in accordance with the law test was not challenged as regards Article 8. The Grand Chamber also agreed with this reasoning. An Article 10 challenged had also been brought against the regime. This was also considered not to be in accordance with the law; again the Grand Chamber followed this reasoning to find a violation of Article 10.

 

Dissent

 

While the findings of violation were unanimous, the Court was not unanimous as regards to the finding of no violation being split by 12 votes to 5. Three judges shared a partly concurring opinion; judge Pinto De Albuquerque wrote a partly concurring but partly dissenting opinion and  Judges Lemmens, Vehabovic, Ranzoni and Bosnjak produced a partly dissenting opinion.

 

Comment

 

Most of the commentary has focussed understandably on the fact that the Court did not state that the bulk interception of communications was in itself contrary to Article 8 and on the safeguards.  These are – obviously – important points, but there is a prior issue regarding the lawfulness test, which relates to the complexity and availability of domestic law. The Grand Chamber followed the Chamber in accepting that the Codes of Practice satisfied this requirement. While Codes are now public documents, this assessment does not fully take into account that for a considerable period much now in those codes were “below the waterline” and information was only forthcoming as a result of litigation.

 

Another question is the extent to which the judgment takes into the impact of digitalization. The Chamber judgment has suggested the different rules applied in different contexts, and that not all data would have the same impact. The Grand Chamber recognised that some updating of the analytical framework from Weber would be required (which turns out to be both a good and bad thing), and specifically notes the impact of meta data (probably a good thing).  It is open at least to argument to state however that the negative consequences of the revision of Weber outweighed the good.

 

Looking at the good, it is indubitably true that some recognition of the change in techniques of state surveillance facilitated by changes in technology and computing power is an important prerequisite for ensuring effective protection of individuals’ rights.  There is some way to go however before we can state confidently that the Court has appreciated the ramifications of the digitalisation of life and particularly data profiling. The key positive is that the Court does not think that meta data is less sensitive than content (para 363). It emphasises that

 

any intrusion occasioned by the acquisition of related communications data will be magnified when they are obtained in bulk, since they are now capable of being analysed and interrogated so as to paint an intimate picture of a person through the mapping of social networks, location tracking, Internet browsing tracking, mapping of communications patterns, and insight into who a person interacted with (para 342)

In this, the Court joins the Court of Justice (see eg. Tele2/Watson, para 99).  While the Court goes someway to recognise the always-on aspect of digital surveillance (para 341), and certainly does not go down the route of the Chamber in suggesting some data are less impactful than others, it does not acknowledge the possibility of combining communications data with data from other sources. The range of data available is wide, especially given the range of smart devices. These include for example, biometric data from fitness trackers, biometric based systems proposed for cars note the driver’s blood pressure, heart rate and other vital to detect, if the driver is impaired in any way. At home detail from smart energy meters could be shared. Nor does it question the basis on which those analyses and interrogations take place. While in its safeguards it does suggest oversight over the circumstances in which data are chosen, it seems to take the tools as given.  This is worrying given the emphasis that has previously been placed on the need for special safeguards in related to automated tools and processing techniques, a point the Court of Justice of the EU has also made (e.g Digital Rights Ireland, para 55).

 

While the emphasis on the significance of meta data is good, it should not be forgotten that the first part of the case concerned bulk interception – so interference with content. Against this context, the Court’s assessment that the first stage of the surveillance process – the data gathering stage – does not constitute a particularly serious interference is worrying (and arguably not in line with previous case law). It certainly underplays the threat to privacy that is implicit in the acquiring and holding of data (and Judges Lemmens, Vehabovic and Bosnjak discuss this in their concurring opinion, paras  3-8).  A further question arises in relation to other forms of surveillance; what if smart city devices (eg lampposts) can record our conversations as we pass by (UK installation of microphones have apparently not been for this purpose but to detect aggression). How comfortable are we about data acquisition then? This reasoning may be the top of the slippery slope. 

 

Within the EU context it should be remembered that the Court of Justice has repeatedly emphasised that “access on a generalised basis to the content of electronic communications” undermined the essence of the relevant EU Charter right (article 7) and could not be therefore be justified (see e.g. Schrems I, para 94). This then suggests a difference in approach between the two European courts. It would be unfortunate if the recognition of the impact of meta data led to a lowering of standards as regards content. 

 

The more problematic development is the approach to reasonable suspicion. The Court acknowledges that these surveillance practices do something different from other more traditional forms of surveillance, which tend to be reactive (ie somebody has done something bad) and more focussed (as opposed to diffuse), most likely based on existing evidence which suggests suspicion of specific individuals. This mass surveillance is about intelligence gathering, and about predicting – thus severing the link between an individual’s choices and actions and the likelihood of that person being the subject of surveillance. Rather than assess the surveillance by reference to existing standards – for example, the presumption of innocence and the impact of a State carrying out surveillance (which is recognised through the case law on the mere storing of data), the Court abandons these standards as part of its updating in order to fit round state choices. In so doing, it gives some legitimacy to the idea that the State may carry out surveillance on individuals without any grounds related to that person (para 317, 348).

 

This is based on the Court’s deference to the State’s assessment that these are necessary for national security reasons – though this assessment is not really critically examined. Indeed, when it re-emphasised that the choice of adopting certain surveillance techniques fell to the States, it emphasised the valuable nature of the technique (para 386, emphasis added). Judge Pinto De Albuquerque writes critically of the Court’s “self-imposed evidential and adjudicatory limitation” which “leads the Court to assume the inevitability of bulk interception and, even more so, that of a blanket, non-targeted, suspicion-less interception regime (Opinion, para 5). He also points to the fact that previous cases – including Zakharov – have involved bulk intercept of communications and yet still sought to apply the first two Weber criteria that the Court here has abandoned.

 

 

While of course a State may be free to make these choices about approaches to surveillance in principle they should be assessed to ensure that they are lawful and necessary in a democratic society.  The test of lawfulness and the proportionality test implied in the ‘necessary in a democratic society’ actually ask different questions – but blending them together, as the Court has done here, dilutes the protective nature of the proportionality test. Rather than ask whether this is disproportionate and should not be done, the question becomes how to put oversight in place, which accepts the fact of the interference with the right in the first place. This criticism has been levelled at the Court’s approach before; the Court here (in referring to Zakharov and Kennedy to justify this approach) implies that this blurring of the three part test is both well-established and non-problematic. The Court has in some previous cases suggested that a test of “strict necessity” should be used for mass surveillance (Szabo and Vissy v. Hungary, para 73) – that sort of reasoning is not evident here.

 

As regards the safeguards themselves, it is unclear which grounds justify bulk surveillance (and contrast the position here with the EU position). It should be noted that that prior judicial authorisation is not a prerequisite for such surveillance, even if it might be best practice (para 320). The Court cites authorities to suggest that ex post oversight compensates for lack of ex ante control; this is like saying it is all right to drop an egg on the floor provided you have bucket and mop to clean up afterwards. The end result is not the same (and Judges Lemmens, Vehabovic and Bosnjak remind the Court of the significant harms that may eventuate from a lack of protection in their partly concurring opinion). Significantly, it seems that despite calling these various safeguards fundamental, a global assessment may be made, suggesting that some regimes may be weaker on some issues (perhaps not deal with them at all?) than others (para 370).

 

The approach to the sharing of data is also worrying. On the one hand, the Court recognises the threat posed by intelligence sharing, and the risk that safeguards may be circumvented. Yet, it seems to imply that a lesser standard of safeguards is acceptable in this context, and in so doing accepts the practice as well as the lower standards applicable (contrast viewpoint of Judge Koskelo joined by Judge Turković in the chamber judgment).  It should be noted that the Court only considers one aspect of intelligence sharing – the receipt by the UK security and intelligence services of information. The issue of proportionality is dealt with relatively briefly. Notably, the Court states that the requirement for safeguards:

 

“... does not necessarily mean that the receiving State must have comparable protection to that of the transferring State; nor does it necessarily require that an assurance is given prior to every transfer” (para 362).

 

How oversight is supposed to function against what seems to be a highly flexible framework is uncertain. It is also questionable whether or to what extent this fits with the EU’s approach – admittedly relating to the export rather than as here import of data – under the GDPR and Articles 7 and 8 of the Charter.  Judges Lemmens, Vehabovic, Ranzoni and Bosnjak suggested that the same “end-to-end” safeguards should apply here.

 

In sum, the outcome of this case while certainly restraining some of the potential excesses of the RIPA regime (and possibly therefore its younger sibling, IPA), it is by no means an unqualified victory for privacy activists.

 


Photo credit: Adrian Drycuk, via Wikimedia Commons







Tuesday, 26 May 2015

Open letter to UK MPs: Ensuring democratic scrutiny of UK surveillance law changes




Steve Peers

Due to my concern about inadequate democratic scrutiny of changes to UK law (often linked to EU law) affecting privacy rights, I am one of the signatories to today's letter to MPs on this issue, published in the Guardian and elsewhere. Thanks to Andrew Murray and Paul Bernal for taking this initiative.


An open letter to all members of the House of Commons,

 

Dear Parliamentarian,

 

Ensuring the Rule of Law and the democratic process is respected as UK surveillance law is revised

 

Actions Taken Under the Previous Government

 

During the past two years, the United Kingdom’s surveillance laws and policies have come under scrutiny as the increasingly expansive and intrusive powers of the state have been revealed and questioned in the media. Such introspection is healthy for any democracy. However, despite a need for transparency in all areas of lawmaking, and in particular in areas of controversy, the previous Government repeatedly resisted calls for an open and transparent assessment and critique of UK surveillance powers. Instead, in response to legal challenges, it extended the powers of the state in the guise of draft Codes of Practice and “clarifying amendments.” As we welcome a new Government we expect another round of revisions to UK surveillance laws, with the likelihood that the Queen’s Speech will signal a revival of the Communications Data Bill. At this time we call on the new Government, and the members of the House, to ensure that any changes in the law, and especially any expansions of power, are fully and transparently vetted by Parliament, and open to consultation from the public and all relevant stakeholders.

 

Last year, in response to the introduction of the Data Retention and Investigatory Powers Bill (“DRIP”), a number of leading academics in the field – including many of the signatories to this letter – called for full and proper parliamentary scrutiny of the Bill to ensure Parliamentarians were not misled as to what powers it truly contained. Our concern emanated from the Home Secretary’s attempt to characterize the Bill, which substantially expanded investigatory powers, as merely a re-affirmation of the pre-existing data retention regime.[1]

 

Since that letter was written, it has become apparent that the introduction of the DRIP Bill was not the only time an expansion of surveillance powers was presented in a way seemingly designed to stifle robust democratic consideration. In February 2015, the Home Office published the draft Equipment Interference Code of Practice.[2] The draft Code was the first time the intelligence services openly sought specific authorisation to hack computers both within and outside the UK. Hacking is a much more intrusive form of surveillance than any previously authorised by Parliament. It also threatens the security of all internet services as the tools intelligence services use to hack can create or maintain security vulnerabilities that may be used by criminals to commit criminal acts and other governments to invade our privacy. The Government, though, sought to authorise its hacking, not through primary legislation and full Parliamentary consideration, but via a Code of Practice.

 

The previous Government also introduced an amendment via the Serious Crimes Act 2015, described in the explanatory notes to the Bill as a ‘clarifying amendment’.[3] The amendment effectively exempts the police and intelligence services from criminal liability for hacking. This has had an immediate impact on the ongoing litigation of several organisations who are suing the Government based in part on the law amended, the Computer Misuse Act 1990.[4]

 

The Way Ahead

 

The new Conservative Government has announced its intention to propose new surveillance powers through a resurrection of the Communications Data Bill. This will require internet and mobile phone companies to keep records of customers’ browsing activity, social media use, emails, voice calls, online gaming and text messages for a year, and to make that information available to the government and security services. We also anticipate this Parliament will see a review of the Regulation of Investigatory Powers Act 2000, which currently regulates much of the Government’s surveillance powers. The Independent Reviewer of Terrorism Legislation, David Anderson QC, has conducted an independent review of the operation and regulation of investigatory powers, with specific reference to the interception of communications and communications data. The report of that review has been submitted to the Prime Minister, but has yet to be made public: when it is made public, parliamentary scrutiny of the report and any recommendations made following it will be essential.

 

As the law requires that surveillance powers must be employed proportionate to any harm to privacy caused (as required by Article 8 of the European Convention on Human Rights and Article 12 of the Universal Declaration of Human Rights) we believe that any expansion or change to the UK’s surveillance powers should be proposed in primary legislation and clearly and accurately described in the explanatory notes of any Bill. The Bill and its consequences must then be fully and frankly debated in Parliament. When reaching an assessment of the proportionality, of any measure that restricts rights, both our domestic courts and the European Court of Human Rights place great stock on the degree and quality of Parliamentary involvement prior to any measure being adopted. If the matter ever came to before the courts one issue examined would be the nature of any “exacting review” undertaken by MPs into the necessity of extending these powers. The Government should not be permitted to surreptitiously change the law whenever it so desires, especially where such changes put our privacy and security at risk.

 

This letter has been prepared and signed by 35 academic researchers. We are comprised of people from both sides of this issue - those who believe that increased powers are a reasonable response to an emerging threat, and those who think them an unjustified extension of state interference. Our common goal is to see the Rule of Law applied and Parliamentary oversight reasserted. We are calling on all members of the House of Commons, new and returning, and of all political persuasions to support us in this by ensuring Parliamentary scrutiny is applied to all developments in UK surveillance laws and powers as proposed by the current Government.  

 

Signatories

 

Andrew Murray (contact signatory)
Paul Bernal (contact signatory)
Professor of Law
London School of Economics
Lecturer in Information Technology, Intellectual Property and Media Law University of East Anglia
 
Subhajit Basu
Associate Professor
University of Leeds
 
Sally Broughton Micova
Deputy Director LSE Media Policy Project, Department of Media and Communications
London School of Economics and Political Science
 
Abbe E.L. Brown
Senior Lecturer
School of Law
University of Aberdeen
 
Ian Brown
Professor of Information Security and Privacy
Oxford Internet Institute
Ray Corrigan
Senior Lecturer in Maths, Computing and Technology
Open University
 
Angela Daly
Postdoctoral Research Fellow
Swinburne Institute for Social Research
Swinburne University of Technology
Richard Danbury
Postdoctoral Research Fellow
Faculty of Law
University of Cambridge
 
Catherine Easton
Lancaster University School of Law
 
Lilian Edwards
Professor of E-Governance
Strathclyde University
Andres Guadamuz
Senior Lecturer in Intellectual Property Law
University of Sussex
 
Edina Harbinja
Lecturer in Law
University of Hertfordshire
 
Julia Hörnle
Professor in Internet Law
Queen Mary University of London
Theodore Konstadinides
Senior Lecturer in Law
University of Surrey
 
Douwe Korff
Professor of International Law
London Metropolitan University
 
Mark Leiser
Postgraduate Researcher
Strathclyde University
 
Orla Lynskey
Assistant Professor of Law
London School of Economics
 
 
 
David Mead
Professor of UK Human Rights Law
UEA Law School
University of East Anglia
 
Robin Mansell
Professor, Department of Media and Communication
London School of Economics
 
Chris Marsden
Professor of Law
University of Sussex
 
Steve Peers
Professor of Law
University of Essex
 
Gavin Phillipson
Professor, Law School
University of Durham
Julia Powels
Researcher
Faculty of Law
University of Cambridge
 
Andrew Puddephatt
Executive Director
Global Partners Digital
Judith Rauhofer
Lecturer in IT Law
University of Edinburgh
 
Chris Reed
Professor of Electronic Commerce Law
Queen Mary University of London
 
Burkhard Schafer
Professor of Computational Legal Theory
University of Edinburgh
 
Joseph Savirimuthu
Senior Lecturer in Law
University of Liverpool
 
Andrew Scott
Associate Professor of Law
London School of Economics
 
Peter Sommer
Visiting Professor
Cyber Security Centre, De Montfort University
 
Gavin Sutter
Senior Lecturer in Media Law
Queen Mary University of London
 
Judith Townend
Director of the Centre for Law and Information Policy
Institute of Advanced Legal Studies
University of London
 
Asma Vranaki
Post-Doctoral Researcher in Cloud Computing
Queen Mary University of London
 
Lorna Woods
Professor of Law
University of Essex