Showing posts with label right to privacy. Show all posts
Showing posts with label right to privacy. Show all posts

Thursday, 11 July 2024

Mass hacking and fundamental rights: a missed opportunity for the CJEU?



Hugo Partouche, Attorney-at-law (avocat) at the Paris Bar, and Chloé Berthélémy, Senior Policy Advisor, EDRi

 

Photo credit: hacker-silhoutte, via Wikimedia commons

 

*A first version of this article was published in French by Actualité Juridique (AJ) Pénal, Dalloz Revues here.

 

On 30 April 2024, the Court of Justice of the European Union (CJEU) published its decision in the ‘EncroChat’ case.

 

The case emerged from recent European police cooperation operations against organised crime, involving the mass interception of encrypted communications by means of spyware (‘hacking’). They enabled the collection, for EncroChat alone, of millions of messages associated with 32,000 users in 122 countries, including nearly 4,600 in Germany, and leading to more than 6,500 arrests and 3,800 legal proceedings in the Union.[1]

 

The Berlin Regional Court (the ‘Berlin court’) referred questions to the CJEU, asking whether a German European Investigation Order (‘EIO’) concerning the transmission of data collected by French investigators using hacking techniques was compatible with fundamental rights.

 

The Court's response is based primarily on the principle of mutual trust, which guarantees the effectiveness of European judicial cooperation.[2] Unfortunately, it carefully avoids linking this decision to its case law on the rights to privacy and data protection in criminal matters developed since the entry into force of the EU Charter of Fundamental Rights (the ‘Charter’).

 

Thus, the Court considers that EU law is of very little assistance to the fundamental rights issues at stake, since the transmission of data between two Member States in the context of an EIO is subject only to the rules applicable to a similar procedure within the issuing State (here, Germany). Similarly, the proportionality of an EIO is analysed solely in light of the law of the issuing State, particularly with regard to the evidence that should be considered sufficient to order such a measure. This question is considered to be distinct from the debate on the integrity of the data before the court hearing the case, which alone is capable of assessing whether the defence is able to comment effectively on the evidence – which is an ability that EU law prescribes.[3]

 

    1. The EncroChat investigation

 

‘EncroChat’ was a closed network of encrypted communications using modified telephones, used for organised crime, whose servers were in France. In April 2020, the French authorities set up a joint investigation team with the Netherlands, under the aegis of Eurojust, with the support of Europol, and obtained a judicial authorisation to install Trojan horse software on the servers and then directly on the terminals (the phones). The investigators informally announced via Europol's messaging system (SIENA) that they were going to intercept data located beyond their own territory. The German criminal police (BKA) expressed an interest in the data.

 

On the basis of this information, the Berlin court took the view that the investigation should be seen as a single European project with the aim of dismantling the EncroChat service and enabling criminal proceedings to be brought against all European users in their respective countries. It supports this analysis using a variety of indicators: the cooperation between France and the Netherlands starting in 2018, the support of Eurojust and Europol, the development of a complex interception technique, the prior knowledge of the German authorities that the interception would extend over its territory and, above all, the opening in 2020 of an ‘empty shell’ procedure by the Frankfurt public prosecutor's office, intended to receive information on German users, who would then be prosecuted in separate procedures on the basis of information accessed from Europol’s servers.

 

Furthermore, the technical characteristics of the hacking[4] are not known because the method used is classified as a French national defence secret.[5] A large part of the file is also being kept confidential by the German public prosecutor's office, which refused to inform the Berlin court of what information had actually been shared between national authorities before the interception measure was launched.[6] Lastly, numerous errors have been identified in the data (message senders, time stamps, etc.).[7]

 

2. The limited added value of the judgment on the data protection jurisprudence

 

According to the Berlin court, the course of the investigation suggests that the transmission of the data motivated the collection and not vice versa. With concerns, the referring court suggested that the EIO Directive could not, in such circumstances, separate collection and transmission and that only an independent court could review the proportionality of the latter. However, in the Court's view, the distinction between transmission and collection is clear and the EIO Directive is to be interpreted literally in that it subjects the admissibility of an EIO for the purposes of transmission solely to the law of the issuing State (§92), so that a German public prosecutor may be regarded as competent (§77).

 

The Court did not take the opportunity offered to draw on its own case law relating to Directive 2002/58, known as the ‘ePrivacy’ Directive, interpreted in the light of the Charter (in the context of mass data retention). (See, for example, the judgments in Prokuratuur and La Quadrature du Net and others). Indeed, the retention of and access to telecommunications data are both data processing operations involving serious interference with the fundamental rights to respect for private life and to the protection of personal data. This means that they are subject to EU law criteria, independently of national rules, in particular with regards to the control of proportionality and to the competent authority.

 

The Berlin court noted that the infringement of rights was even more serious in the EncroChat case because of the collection of the content of communications, which is considered sensitive, the long collection period, the massive and indiscriminate nature of the targeting without any specific and individualised suspicion and the immediate collection by law enforcement authorities without any action on the part of the service provider.

 

However, the CJEU refuses to follow this reasoning and to transpose its own criteria in the data protection field to a transfer of data between law enforcement authorities. For the Court, the logic of European judicial cooperation takes precedence over the protection of privacy when the competent authority is dealing with another judicial authority and not with a telecommunications operator.[8] As a result, there is a risk of a significant disparity between the levels of protection and guarantees afforded to different data processing operations during a cross-border telecommunications interception operation.

 

The laundering of EncroChat data from its original controversial method of collection is of importance in the current debate at EU level on the (illegal) use by several Member States of spyware such as Pegasus and Predator, and their compliance with EU law. The technical characteristics and practical impact on privacy of the Trojan Horse software used to target EncroChat bear many similarities to these contentious spywares. The European Data Protection Supervisor is even of the view that they threaten the very essence of the right to privacy and would therefore be contrary to EU law. As modern state hacking techniques became ever more intrusive, the adequacy of current European instruments for police and judicial cooperation to preserve fundamental rights can be reasonably put into question.

 

It is also regrettable that the conditions under which EncroChat data is stored by the national authorities and by Europol are not mentioned. Such storage constitutes an autonomous infringement of fundamental rights. This question is all the more relevant as the 2022 reform of Europol's mandate allows the agency to derogate exceptionally from its own data protection rules to process large datasets (e.g. data collected in bulk) and authorises the long-term storage of investigative data. This enables Europol and investigating authorities to regularly draw on databases without, however, having to demonstrate the existence of concrete evidence of individualised suspicions, or to comply with the requirements of necessity and proportionality.

 

3. Minimum review of proportionality and right to a fair trial

 

To assess the proportionality of the EIO measure, the Berlin court asks the CJEU to assess the related infringements of procedural rights.[9]

 

With regard to the right to privacy, the Berlin court held that in order for an EIO ordering the transmission of data to satisfy the conditions of necessity and proportionality set out in the EIO Directive, it is not sufficient to have evidence of multiple offences committed by unidentified persons.

 

The Court replied that: ‘By using the terms “under the same conditions” and “in the context of a similar national procedure”, Article 6(1)(b) of Directive 2014/41 [the EIO Directive] makes the determination of the precise conditions required for the issuing of a European investigation order depend solely on the law of the issuing State’. It concludes that, if the law of the issuing State makes the transmission of data subject to the existence of concrete indications that the person being prosecuted has committed serious offences or to the admissibility of the evidence, the adoption of an EIO is subject to those same conditions. It can be inferred from the request for preliminary ruling that the Berlin court holds that very position, whereas other German courts don’t.

 

With regard to the right to a fair trial, the Berlin court asked the Court of Justice whether the principle of proportionality precluded the issuing of an EIO where the integrity of the data obtained could not be verified because of the confidentiality of the technical bases, and the defence might not, for that reason, be able to comment effectively on that data in subsequent criminal proceedings. The Court replied that it follows from Article 4 of the EIO Directive that the necessity and proportionality of the measure are to be assessed in the light of the law of the issuing State. The Court explains that if the transmission of evidence were to appear either disproportionate or not in conformity with the framework of the ‘similar’ national proceedings, the consequences would be those of national law (§103).

 

However, and it may be one of the most important contributions of this judgment to the many ongoing EncroChat proceedings across Europe, the Court reasserts that if a party ‘is unable effectively to comment on evidence which is capable of having a preponderant influence on the assessment of the facts, that court must find that there has been a breach of the right to a fair hearing and exclude that evidence in order to avoid such a breach.’ (§105).

 

Unfortunately, the CJEU refuses to outline an enhanced control, whether substantive or procedural (§89), in the area of technically complex cross-border investigative measures. It limits the control on this point to the question of judicial review of compliance with fundamental rights provided for in Article 14 of the EIO (§§101 et seq.).

 

However, the Berlin court’s questions seemed particularly relevant on two fronts. First, it follows from the Court's case-law that the practical ease of an interference is not sufficient to make it proportionate.[10] Secondly, the limitation of a Charter right, while presumed proportionate, ‘may prove to be disproportionate if the criteria governing it are imprecisely drafted and if they do not lay down genuinely objective and controllable conditions’.[11] These concepts are not used in the judgment.

 

The Court's reasoning, however unsatisfactory in its minimalism, is not surprising: it seizes every opportunity to defend the principle of mutual trust rather than to seek in the Charter the elements for a full review of the implementation of judicial cooperation tools. And for good reason: that is the inherent logic of these tools.

 

However, the complexity of the EncroChat investigation had given the opportunity to the Court to develop its case law. The Court started applying in the Aranyosi and Caldararu case what some commentators have described as the principle of acquired mutual trust rather than blind mutual trust,[12] particularly with regard to the risk of forum shopping.

 

4. Wilful blindness to the risk of forum shopping?

 

In the Court's view, the singular structure of the investigative measures does not present any particularity of relevance to the EIO Directive.

 

Although it acknowledges that the data was collected on behalf of Germany and on its territory, the Court does not explain why it completely rules out the risk that Germany might have opportunistically subcontracted the collection to France where data interception is less regulated. In the Court's view, the EIO Directive does not take into account the location of the data collection (§98). This allows the Court to not assess the risk of forum shopping, that implies taking advantage of the difference in rules between collection and transmission in the State where the data are collected (here, Germany).

 

In those circumstances, it is particularly surprising that the judgment states, without giving any reasons, that ‘in the present case, it does not appear that the purpose or effect of the collection and transmission, by means of a European Investigation Order, of the evidence thus collected was such circumvention, which it is for the referring court to ascertain’ (§97). The Court is ruling on a point that it considers to be outside its purview.

 

However, the Berlin Court was rather clear about the genuine risk of circumvention, particularly since it would have been more logical for an EIO to have been issued prior to collection and, in such a case, the authorisation of an independent court would have been required under German law (on the basis of the CJEU judgment of 16 December 2021, Spetsializirana prokuratura (Traffic and location data)). The referring court therefore finds itself on the receiving end of a paradoxical answer to its question.

 

The Court's ambivalence stems from its overreliance on the principle of mutual recognition in this context. This principle, which is itself based on mutual trust, justifies that the referring court is not authorised to review the validity of the procedure by which an EIO was issues to the executing State for the purpose of transmission (§§99-100). This was the Advocate General's position, according to whom the ‘interception took place independently of the EIOs at issue’ (paras 15-16 of the opinion).

 

As said, however, it was specifically questioned in cases where mutual trust, instead of merely facilitating cooperation between two States, serves as a screen for opaque police strategies. No control over such strategies and their impact on fundamental rights would therefore come directly from EU law, despite the fact that EU law has been able to act as a bulwark against the protection of privacy in relation to new technologies.

 

Could it be that the Court has missed its appointment with complex and new technical issues destined to change the economics of European judicial cooperation?



[1]https://www.europarl.europa.eu/RegData/etudes/ATAG/2022/739268/EPRS_ATA(2022)739268_EN.pdf  The spyware made it possible to intercept their traffic and location data, as well as the content of communications, including those stored on the devices prior to the operation. Given the massive scale of the data extraction, many lawyers have publicly questioned the lawfulness of the data interception measures, as well as the reliability and admissibility of the resulting evidence: https://www.computerweekly.com/news/252526497/Dutch-lawyers-raise-human-rights-concerns-over-hacked-cryptophone-data

       https://www.fairtrials.org/articles/news/encrochat-hack-fair-trials-denounces-lack-of-transparency-and-oversight/

[2]The Court has vigorously defended this principle because of its role in European integration, allowing only exceptional circumstances to derogate from it. See also: https://www.eurojust.europa.eu/20-years-of-eurojust/recent-jurisprudence-cjeu-judicial-independence-and-european-arrest-warrant

[3]Note D. Berlin, La Semaine Juridique Edition Générale n° 19, 13 May 2024, act. 606.

       Note V. Barbault, Lexis « EncroChat : précisions de la CJUE sur la transmission et l'utilisation de preuves dans les affaires pénales transfrontalières »

[4]But also the storage, allocation and filtering of data by the French authorities or by Europol.

[5]French law provides minimal control over hacking measures, as demonstrated by Decision no. 2022-987 QPC of April 8, 2022 (M. Saïd Z. ), dealing in particular with the provisions of article 706-102-1 of the French Code of Criminal Procedure, and a ruling by the French Supreme Court (Cour de cassation) on the nullity of interception and capture operations carried out on the basis of this same text, as well as on the failure to include the master procedure in the proceedings (Crim. October 11, 2022, no. 21-85.148).

[6]The Berlin Court explains that this opacity explains a divergent decision by the Federal Court of Justice on March 2, 2022.

[7]For a technical analysis of the practical impossibility of effectively commenting on the data and possible errors: V. R. Stoykova, Encrochat: The hacker with a warrant and fair trials?, Forensic Science International: Digital Investigation 46 (2023) 301602

[8]H. Christodoulou, Issuance of a European investigation order for the transmission of telecommunications data possessed by the executing State: sufficiency of the prosecutor's control, CJEU Apr. 30, 2024, aff. C-670/22, Dalloz Actualité, 31 May 2024

[9]It is regrettable that the Berlin Regional Court did not use Article 52(1) of the Charter, which is intended to verify that the infringement of a fundamental right does not affect the essence of that right, which in principle takes precedence over the examination of the necessity and proportionality of the interference.

[10] P. Gilliaux, Droit général des droits fondamentaux de l’Union européenne, Bruylant, 2024, §770

[11]Ibid. §784.  In this respect, by submitting such a complex investigative technique to the Court for the first time, the Encrochat case could have provided an opportunity to reinforce the standard of equality of arms by abandoning the idea that it is sufficient for the defendant to be able to "comment" on information from investigations carried out by foreign authorities.

[12] V. Mitsilegas, Trust (2020) German Law Review 69. This consideration is not, however, absent from the decision, which recalls that the presumption of respect for fundamental rights in the executing State is rebuttable (§99).

Saturday, 20 April 2024

Podchasov v. Russia: the European Court of Human Rights emphasizes the importance of encryption

 

 


 

Mattis van ’t Schip & Frederik Zuiderveen Borgesius*

*Both authors work at the iHub and the Institute for Computing and Information Sciences, Radboud University, The Netherlands - mattis.vantschip[at]ru.nl & frederikzb[at]cs.ru.nl

Photo credit: Gzen92, on wikimedia commons 

 

In a judgment from February 2024 in the case Podchasov v. Russia, the European Court of Human Rights emphasised the role of encryption in protecting the right to privacy. The judgment comes at a time where encryption is central to many legal debates across the world. In this blog post, we summarise the main findings of the Court and add some reflections.

Summary

Podchasov, the applicant in the case, is a user of Telegram. Russia listed Telegram as an ‘internet communication organiser’ in 2017. This registration meant that Telegram, according to Russian law, had to store all its communications data for one year, and the contents of communication data for six months. The obligation concerns all electronic communications (e.g., textual, video, sound) received, transmitted, or processed by internet users. Law enforcement authorities could request access to that data, including access to the decryption key in case communications are encrypted (para 6 of the judgment).

Telegram is a messaging app that users often employ because of its end-to-end encrypted messaging. For instance, Telegram is an important communication channel for Ukrainians to receive updates about the current war. End-to-end encryption means, roughly summarised, that only the sender and the intended recipient can access the content of the encrypted data, in this case Telegram messages.

In July 2017, the Russian Federal Security Service (FSB) required Telegram to disclose data that would allow the FSB to decrypt messages of suspects of ‘terrorism-related’ activities (para 7 of the judgment). Telegram refused. Telegram said that it was impossible to allow the FSB to access encrypted messages without creating a backdoor to their encryption that malicious actors might also use. Because of Telegram’s refusal, a District Court in Moscow ordered the nation-wide blocking of Telegram in Russia. The applicants challenged the disclosure order, but their challenge was dismissed across several Moscow courts. Meanwhile, Telegram remains operational in Russia today. Finally, the applicants lodged their complaint with the European Court of Human Rights. They complained that Russia violated their right to private life in Article 8 of the European Convention on Human Rights (ECHR).

Russia is not a member of the Council of Europe anymore. The Council of Europe stopped Russia’s membership in March 2022, in response to Russia’s invasion of parts of Ukraine. Six months later, on 16 September 2022, Russia ceased to be party to the European Convention on Human Rights. Nevertheless, the Court gives this judgment. The Court says that it has jurisdiction over this case, as the alleged violations occurred before the date that Russia ceased to be a party to the Convention.

The Court quotes several documents that are not directly related to the ECHR, including surveillance case law of the Court of Justice of the European Union, a report on the right to privacy in the digital age by the Office of the United Nations High Commissioner for Human Rights, a statement by Europol and the European Union Agency for Cybersecurity, and an Opinion of the European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB).

The surveillance scheme before the European Court of Human Rights resembles earlier Russian surveillance schemes, which the Court held as a violation of providing adequate and sufficient safeguards to protect against indiscriminate breaches of the right to private life in Article 8 ECHR. Earlier holdings thus also apply in the underlying case. Unlike in previous judgments about surveillance in Russia, the Court discusses the role of encryption in protecting the right to private life.

On encryption, the Court holds that the underlying case only concerns the encryption scheme of ‘secret chats’. Telegram offers ‘cloud chats’ by default with ‘custom-built server-client encryption’, but users can also decide to activate ‘secret chats’ which are end-to-end encrypted (para 5 of the judgment). The Court explicitly excludes any considerations of so-called ‘cloud chats’ in the case, as the complaints only concern the ‘secret chats’. The scope of the Court’s holdings is therefore limited to only end-to-end encryption as used for secret chats.

The applicants and several privacy-related civil organisations say that decryption of end-to-end encrypted messages would concern all users of that system, in this case Telegram, as technical experts can never create an encryption backdoor for a specific instance, case, or user. The Russian government did not refute these statements. The Court therefore holds that the Russian authorities interfered with right to private life of Article 8 ECHR. The Court then investigates whether the Russian authorities can justify this violation, for instance because the violation is necessary in a democratic society. The Court analyses encryption in this light.

The Court emphases that encryption contributes to ensuring the enjoyment of the right to private life and other fundamental rights, such as freedom of expression:

[T]he Court observes that international bodies have argued that encryption provides strong technical safeguards against unlawful access to the content of communications and has therefore been widely used as a means of protecting the right to respect for private life and for the privacy of correspondence online. In the digital age, technical solutions for securing and protecting the privacy of electronic communications, including measures for encryption, contribute to ensuring the enjoyment of other fundamental rights, such as freedom of expression (…) (para 76).

The Court adds that encryption is important to secure one’s data and communications:

Encryption, moreover, appears to help citizens and businesses to defend themselves against abuses of information technologies, such as hacking, identity and personal data theft, fraud and the improper disclosure of confidential information. This should be given due consideration when assessing measures which may weaken encryption. (para 76)

The Court observes that legal decryption obligations cannot be specific or limited to certain circumstances: once a messaging provider creates a backdoor, there is a backdoor to all communications on the messaging platform:

Weakening encryption by creating backdoors would apparently make it technically possible to perform routine, general and indiscriminate surveillance of personal electronic communications. Backdoors may also be exploited by criminal networks and would seriously compromise the security of all users’ electronic communications. The Court takes note of the dangers of restricting encryption described by many experts in the field. (par 77)

Based on the above-mentioned arguments, the Court holds that the requirement to decrypt communication messages cannot be ‘regarded as necessary in a democratic society.’ (para 80 of the judgment) The Court concludes that Russia breached the right to private life, protected in article 8 ECHR.

Comments

The Podchasov case follows a long debate about the value of end-to-end encryption in democratic societies globally. As the Court mentions, end-to-end encryption is valuable for privacy as it enables people to communicate in such a way that third parties cannot access the communication. In this context, experts herald end-to-end encryption for its capacity to support, for instance, journalists in performing their work safely, or historically marginalised groups to express themselves freely.

At the same time, some law enforcement agencies consider end-to-end encryption a threat to public safety, as malicious actors can benefit from the privacy provided by secure messaging and similar methods, such as data encryption, too.

For instance, the FBI is in a long battle with Apple over the encryption of iPhones, which several suspects employed to keep their phone information and data private. On each occasion, Apple refused to offer decryption keys or software to the FBI, citing security concerns that can stem from enabling such backdoors.

The battle between security and privacy is, of course, long-standing. Encryption is now central to this debate. The EU Commission recently joined the debate with a proposal for a Child Sexual Abuse Material Regulation (CSAM proposal). Roughly summarised, the proposal would require communication providers (such as Telegram or WhatsApp) to analyse people’s communications to find, block, and report child sexual abuse materials, such as inappropriate pictures. Experts agree that communication providers can only do so if they do not encrypt communications, if they include a type of backdoor, or if they analyse communications on people’s devices before they are encrypted. Experts warn that such on-device analysis can be seen as a kind of backdoor of encrypted communications too. Many civil organisations, technical experts, and academics oppose the CSAM proposal. Opponents of the CSAM proposal can be expected to cite his judgment. 

The European Court of Human Rights is clear about the role of end-to-end encryption for the right to private life. In one paragraph, the Court states that end-to-end encryption is vital to privacy. The Court bases its reasoning partly on an opinion of the European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB) which discusses encryption in the context of the above-mentioned CSAM proposal. The Court also refers to responses from civil society organisations, who can present their views to the Court as amici curiae. The Court follows the reasoning of the EDPS, the EDPB, and privacy organisations regarding the conclusion that once encryption is broken, the entire system is no longer secure for its users.

The Court also mentions that encryption is vital to security of users. Consider, for instance, the importance of data protection in the current privacy context. Without adequate data encryption, people cannot be sure that the data they store in, for instance, cloud storage, is accessible to only them. Encryption therefore also helps against hacking, identity fraud, and data theft (para 76 of the judgment).

The Podchasov case is straight-forward: encryption is vital to the protection of the right to privacy. The Court’s clear statements will influence ongoing encryption debates, but the end of the debate is not in sight.

Tuesday, 14 December 2021

Is the Passenger Name Record Directive Valid? Opinion on the pending CJEU case

 



Douwe Korff, comparative and international lawyer specialising in human rights and data protection


In Case-817/19, Belgium’s Constitutional Court has asked the EU Court of Justice whether the PNR Directive (2016/681) is compatible with the Charter of Fundamental Rights. An Advocate-General’s opinion in this case is expected in the New Year.

In my opinion, the appropriate tests to be applied to mass surveillance measures such as are carried out under the PNR Directive (and were carried out under the Data Retention Directive, and are still carried out under the national data retention laws of the EU Member States that continue to apply in spite of the CJEU case-law) are:

Have the entities that apply the mass surveillance measure – i.e., in the case of the PNR Directive (and the DRD), the European Commission and the EU Member States — produced reliable, verifiable evidence:

-          that those measures have actually, demonstrably contributed significantly to the stated purpose of the measures, i.e., in relation to the PNR Directive, to the fight against PNR-relevant crimes (and in relation the DRD, to the fight against “serious crime as defined by national law”); and

-          that those measures have demonstrably not seriously negatively affected the interests and fundamental rights of the persons to whom they were applied?

If the mass surveillance measures do not demonstrably pass both these tests, they are fundamentally incompatible with European human rights and fundamental rights law and the Charter of Fundamental Rights; this means the measures must be justified, by the entities that apply them, on the basis of hard, verifiable, peer-reviewable data.

The conclusion reached by the European Commission and Dutch Minister of Justice: that overall, the PNR Directive, respectively the Dutch PNR law, had been “effective” because the EU Member States said so (Commission) or because PNR data were quite widely used and the competent authorities said so (Dutch Minister) is fundamentally flawed, given that this conclusion was reached in the absence of any real supporting data. Rather, my analyses show that:

-          Full PNR data are disproportionate to the purpose of basic identity checks;

-          The necessity of the PNR checks against Interpol’s Stolen and Lost Travel Document database is questionable;

-          The matches against unspecified national databases and “repositories” are not based on foreseeable legal rules and are therefore not based on “law”;

-          The necessity and proportionality of matches against various simple, supposedly “suspicious” elements (tickets bought from a “suspicious” travel agent; “suspicious” travel route; etc.) is highly questionable; and

-          The matches against more complex “pre-determined criteria” and profiles are inherently and irredeemably flawed and lead to tens, perhaps hundreds of thousands of innocent travellers wrongly being labelled to be a person who “may be” involved in terrorism or serious crime, and are therefore unsuited (D: ungeeignet) to the purpose of fighting terrorism and serious crime.

The hope must be that the Court will stand up for the rights of individuals, enforce the Charter of Fundamental Rights, and declare the PNR Directive (like the Data Retention Directive) to be fundamentally in breach of the Charter.

For my full 149-page opinion, and an executive summary of it, see here.

 

Reblogged from the Data Protection and Digital Competition blog

Photo credit: Konstantin von Wedelstaedt, via wikicommons




Wednesday, 7 October 2020

When is mass surveillance justified? The CJEU clarifies the law in Privacy International and other cases


 

 


 

Lorna Woods, Professor of Internet Law, University of Essex

 

Background

 

This case concerns the collection of bulk communications data (BCD) from network operators by the security and intelligence agencies (SIAs).  It formed part of an action brought by Privacy International challenging the SIAs’ acquisition, use, retention, disclosure, storage and deletion of bulk personal datasets (BPDs) and BCD which started in 2015 before the Investigatory Powers Tribunal (IPT).  Privacy International’s claim is based on its understanding of the safeguards required by the Court of Justice in Tele2/Watson – a 2016 CJEU judgment on UK data retention law, discussed here.

 

In Tele2/Watson the Court of Justice held that any data retention obligation must be targeted and limited to what is strictly necessary in terms of the persons affected, the sorts of data retained and the length of retention.  It also suggested that access to retained data should be subject to prior review by an independent body and that parties affected should be informed of the processing (unless this would compromise the investigations); and that the data should be retained within the EU.  The authorities must take steps to protect against misuse of data and any unlawful access to them.  Privacy International argued that the safeguards provided by British law are insufficient. The British government claimed that the SIAs’ activities fell outside the scope of EU law and that the rules were compliant with Article 8 ECHR. It argued that providing the safeguards as required by Tele2/Watson would undermine the ability of the SIAs.  The IPT referred two questions – but only in relation to BCD not BPD - to the Court of Justice.  This was the basis for the Court’s judgment handed down yesterday.

 

Questions in Issue

 

The two questions referred were:

 

-          whether the activities of the SIAs fall within the scope of EU law bearing in mind Art 4 TEU and Art 1(3) of Directive 2002/58 (ePrivacy Directive);

-          if the answer is that the situation falls within EU law, do any of the “Watson Requirements” (as above) (or any other requirements) apply?

 

The Court of Justice decided to deal with this case with two other cases that had been referred to it: Joined cases C-511/18 and C-512/18 La Quadrature du Net & Ors and Case C-520/18 Ordre des barreaux francophones et germanphone & Ors, which were also the subject of a separate judgment yesterday. The cases also dealt with the bulk collection of communications data but in addition the court in La Quadrature du Net also asked whether real-time measures for the collection of the traffic and location data of specified individuals, which, whilst affecting the rights and obligations of the providers of an electronic communications service, do not however require them to comply with a specific obligation to retain their data are permissible. It also asked whether the Charter required persons concerned by surveillance to be informed once such information is no longer liable to jeopardise the investigations being undertaken by the competent authorities, or may other existing procedural guarantees which ensure that there is a right to a remedy suffice?   Ordre des barreaux francophones et germanphone & Ors raised the question of whether a general obligation might be justified to identify perpetrators of secual abuse of minors. If national law has not usfficiently guaranteed human rights may the effects of that law be temporarily retained in the interests of certainty and to achieve the objectives set down in the law.

 

The Advocate General handed down separate opinions on each of the cases (see here, here and here) but all on the same day (15 January 2020) to similar effect, that:

 

-          the e-privacy directive (and EU law in general) applies in this situation because of the required co-operation of private parties;

-          limitations on the obligation to guarantee the confidentiality of communications must be interpreted narrowly and with regard to the rights in the EU Charter on Fundamental Rights;

-          the case law in Tele2/Watson (summarised above) should be upheld: general and indiscriminate retention of traffic and location data of all subscribers is an interference with the fundamental rights enshrined in the Charter but real-time collection of traffic and location data of individuals suspected of being connected to a specific terrorist threat could be permissible provided it down not impose a requirement on communications service providers to retain additional data beyond that which is required for billing/marketing purposes; and that the use of such data for purposes less serious than the fight against terrorism and serious crime was incompatible with EU law.

 

Note that there are two more cases pending Case C-746/18 H.K. v Prokurator (Opinion handed down by AG Pitruzzella 21 Jan 2020) as well as references from Germany from 2019 and Ireland from 2020. 

 

Summary of Judgment

 

Privacy International

 

In its Grand Chamber judgment, the Court confirmed that requirements on communications service providers to retain data fell within the scope of EU law and specifically the e-Privacy Directive. The Court argued that the exclusion in Article 1(3) e-Privacy Directive related to “activities of the State or of State authorities and are unrelated to fields in which individuals are active” (para 35, citing Case C-207/16 Ministerio Fiscal, discussed here, para 32), whereas Art 3 makes clear that it regulates the activities of communications service providers. As held in Ministerio Fiscal, the scope of that directive extends not only to a legislative measure that requires providers of electronic communications services to retain traffic data and location data, but also to a legislative measure requiring them to grant the competent national authorities access to that data.

 

The legislative measures, permissible as a derogation under Article 15, “necessarily involve the processing, by those providers, of the data and cannot, to the extent that they regulate the activities of those providers, be regarded as activities characteristic of States” (para 39). given the breadth of the meaning of ‘processing’ under the GDPR, the directions made under s 94 Telecommunications Act fall within the scope of the ePrivacy Directive. The Court re-affirmed (para 43) the approach of its Advocate General in this case (and in La Quadrature du Net) that ‘activities’ in the sense of Art 1(3) cannot be interpreted as covering legislative measures under the derogation provision; to hold otherwise would deprive article 15 of any effect (following reasoning in Tele2/Watson) and Article 4(2) TEU does not disturb that conclusion (despite the Court’s reasoning in the first PNR case (Cases C-317/04 and C-318/04, paras 56 to 59).  For the e-Privacy Directive (by contrast to the former Data Protection Directive in issue in the PNR case), what is important is who does the processing; it is the communications providers. The Court took the opportunity to confirm that the GDPR should not be interpreted the same way as the Data Protection Directive but in parallel with the e-Privacy Directive.

 

As regards the second question, the Court re-stated the scope of s. 94 orders thus (paras 51-52):

 

That data includes traffic data and location data, as well as information relating to the services used, pursuant to section 21(4) and (6) of the RIPA. That provision covers, inter alia, the data necessary to (i) identify the source and destination of a communication, (ii) determine the date, time, length and type of communication, (iii) identify the hardware used, and (iv) locate the terminal equipment and the communications. That data includes, inter alia, the name and address of the user, the telephone number of the person making the call and the number called by that person, the IP addresses of the source and addressee of the communication and the addresses of the websites visited.

 

Such a disclosure of data by transmission concerns all users of means of electronic communication, without its being specified whether that transmission must take place in real-time or subsequently. Once transmitted, that data is, according to the information set out in the request for a preliminary ruling, retained by the security and intelligence agencies and remains available to those agencies for the purposes of their activities, as with the other databases maintained by those agencies. In particular, the data thus acquired, which is subject to bulk automated processing and analysis, may be cross-checked with other databases containing different categories of bulk personal data or be disclosed outside those agencies and to third countries. Lastly, those operations do not require prior authorisation from a court or independent administrative authority and do not involve notifying the persons concerned in any way.

 

The Court stated that the purpose of the e-Privacy Directive was to protect users from threats to their privacy arising from new technologies. It ‘gave concrete expression to the rights enshrined in Articles 7 and 8 of the Charter’ (para 57) and the exceptions thereto under Article 15(1), ie necessary, appropriate and proportionate in the interests of purposes listed in Art 15(1): national security, defence and public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system. The exceptions cannot permit this exception to become the rule (citing Tele2/Watson, but also the ruling in La Quadrature du Net). Restrictions must also comply with the Charter. This is the same whether the legislation requires retention of the transmission of data to third parties (citing EU-Canada PNR Agreement, discussed here, paras 122-123). Drawing on Schrems II, discussed here, the Court held:

 

“any limitation on the exercise of fundamental rights must be provided for by law implies that the legal basis which permits the interference with those rights must itself define the scope of the limitation on the exercise of the right concerned ” (para 65).

 

It also re-iterated that derogations from the protection of personal data any restriction on  confidentiality of communications and traffic data may apply only in so far as is strictly necessary and “by properly balancing the objective of general interest against the rights at issue’ (para 67). Proportionality also requires the legislation to lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards, to protect effectively against the risk of abuse. The legislation must set down conditions for the application of the measures so as to restrict them to those ‘strictly necessary’; the legislation must be binding. Automated processing gives rise to greater risks. These considerations are the more pressing in the context of sensitive data.

 

The Court noted that the transmission of data to SIAs constituted a breach of confidentiality in a general and indiscriminate way and thus

 

has the effect of making the exception to the obligation of principle to ensure the confidentiality of data the rule, whereas the system established by Directive 2002/58 requires that that exception remain an exception (para 69).

it also constitutes an interference with Articles 7 and 8 of the Charter, no matter how the data are subsequently used. Re-iterating its approach in EU-Canada PNR Opinion, the Court stated that

 

it does not matter whether the information in question relating to persons’ private lives is sensitive or whether the persons concerned have been inconvenienced in any way on account of that interference (para 70).

 

Here, given the potential to create a personal profile of individuals the intrusions was particularly serious and “no less sensitive than the actual content of communications” (para 71). The court also emphasised the impact of the feeling of being under constant surveillance, following its reasoning in Digital Rights Ireland (discussed here) and Tele2/Watson. Such surveillance may have an impact on freedom of expression, especially where users are subject to professional secrecy rules or are whistleblowers. The Court also note that given the quantity of data in issue, their “mere retention” entails a risk of abuse and unlawful access (para 73).

 

The Court distinguished between ‘national security’ understood in the light of Article 4(2) TEU and ‘public security’ and matters within Article 15 ePrivacy Directive.  While measures safeguarding national security must still comply with Art 52(1) of the Charter, given the seriousness of threats comprised in ‘national security’ in principle the objective of safeguarding national security is capable of justifying more intrusive measures that those would could be justified by other objectives (cross referring to its reasoning in La Quadrature du Net). 

 

Even in relation to national security, the underlying national legislation must also lay down the substantive and procedural conditions governing use of the data and not just provide for access. National legislation must rely on objective criteria in order to define the circumstances and conditions under which the competent national authorities are to be granted access to the data at issue. Here, the national legislation requiring providers of electronic communications services to disclose traffic data and location data to the security and intelligence agencies by means of general and indiscriminate transmission exceeds the limits of what is strictly necessary and cannot be considered to be justified, within a democratic society even in the interests of protecting national security.

 

La Quadrature du Net/Ordre des barreaux francophones et germanophone

 

The Court’s approach to Article 15 and the sorts of activities in the service of which surveillance may be undertaken by contrast with Article 3(1) was, unsurprisingly, the same as can be seen in Privacy International, as was its approach to interpreting the directive – emphasising the confidentiality of communications as well as Articles 7 and 8 EU Charter. Again, the Court took the approach that the exception to communications confidentiality should not become the rule and that exceptions must be strictly necessary and proportionate to their objectives. Retention of communications data is a serious interference with fundamental rights – including freedom of expression. The retention of the data constitutes such an interference whether or not the data are sensitive or whether the user was inconvenienced.

 

In similar terms to Privacy International, the Court again came to the conclusion that the general and indiscriminate retention of data was impermissible under the Charter and Article 15. The Court also re-stated the limitations on derogating measures made under Art 15. The point of difference in this analysis is that the Court recognised the conflicting rights that might need to be reconciled – particularly with regard to crimes against minors and the State’s positive obligation to protect them. This does not mean that the limits as regards necessity and proportionality may be overlooked.

 

The Court then considered the meaning of national security – approaching the matter in the same terms as it did in Privacy International.  This higher threshold meant that neither the directive nor the Charter precludes recourse to an order requiring providers of electronic communications services to retain, generally and indiscriminately, traffic data and location data. This however is only so when the Member State concerned is facing a sufficiently serious threat to national security (which includes matters more serious than those listed in Art 15), a threat that is genuine and actual or foreseeable. In such a case retention can only be for a period of time limited to that which is strictly necessary. If any such order is to be renewed it must be for a specified length of time. The retained data must be protected by strict safeguards against the risk of abuse. The decision must be  subject  to effective  review by  an  independent body (court or administrative), whose  decision  is  binding, in  order  to  verify  that  such a situation exists and that the conditions and safeguards laid down are observed.

 

The Court observed that general and indiscriminate surveillance refers to that which covers virtually all the population. The Court recognised the duties of the State under positive obligations and the need to balance potentially conflicting rights. It then held that in situations such as those described at paras 135-6 of its judgment, that is those falling in Article 4(2) TEU, the e-Privacy Directive and the Charter do not preclude measures for targeted retention of traffic and location data. Such measures must be limited in time to what is strictly necessary, and focused on categories of persons identified on the basis of objective and non-discriminatory factors, or by using geographical criteria.  It then relied on similar reasoning in relation to the fight against crime and the protection of public safety.

 

Similarly, IP addresses may be retained in a general and indiscriminate manner subject to a requirement of strict necessity. Further, the directive also does not preclude the retention of data beyond statutory data retention periods when strictly necessary to shed light on serious criminal offences or attacks on national security, when the offences or attacks have already been established, or if their existence may reasonably be suspected.  Real-time data may also be used when it is limited to people in respect of whom there is a valid reason to suppose that they are involved in terrorist activities. Such use of data must be subject to prior review by an independent body to ensure that real-time collection is limited to what is strictly necessary. The Court notes that in urgent cases that the review should take place promptly (presumably rather than after the event).

 

Finally, a national court may not apply a provision of national law empowering it to limit the temporal effects of a declaration of illegality which declaration the national court must make in respect of national legislation due to incompatibility with the e-Privacy Directive, and evidence obtained illegally should not be relied on in court.

 

Comment

 

The common theme across the cases was the acceptability of the retention and analysis of communications data generally. The Court has re-iterated its general approach, unsurprisingly linking – as the Advocate General also did – between the Privacy International ruling and that in La Quadrature du Net.  In its approach, the Court relied generously on its previous rulings, which demonstrates that there is quite a thick rope of cases, all to broadly the same effect. While the Court based its ruling on the ePrivacy directive (which is specific to communications and communications data), it also based its ruling more generally on Articles 7 and 8 of the Charter.  It is noteworthy that the Court did not just refer to its case law on communications data but also to the Canada PNR opinion, underlining that there is a similar approach no matter the type of data in issue.  The Court also relied on Schrems II, implicitly confirming aspects of its approach there and embedding that decision in its jurisprudence. The underlying concern in Schrems II was the same as here: that is, data collected by private actors are accessed by state actors.  In sum, even in the interests of national security, general and indiscriminate surveillance does not satisfy the test of strict necessity and proportionality.  While its general approach might be similar to what has gone before, there are still some points of interest and new ground covered.

 

The IPT seems to have been the only court amongst those making references that still has not accepted that the retention of data falls within the scope of the e-Privacy Directive, relying on the reasoning of the Court on the Data Protection Directive in relation to passenger name records in an early case.  In addition to re-establishing the well-trodden principles regarding the impact of requiring electronic service providers to retain data bringing the entire scheme within scope of the e-Privacy Directive, and different functions of Article 1(3) (scope of directive) and Art 15 (derogation from directive), the Court took the opportunity to say something about the scope of the GDPR, the successor legislation to the Data Protection Directive. In effect, the Court has stopped the line of reasoning found in that early PNR judgment – it cannot be used to determine the scope of the GDPR which should be understood in line with Art 1(3) of the e-Privacy Directive.

 

The Court has emphasised a couple of aspects of the legal regime surrounding surveillance that are worth a second look. Firstly, while the Court says nothing about the form of law on which a surveillance may be based, in its analysis of Article 52(1) Charter it does say that the same law must contain the constraints. The principle then has wider application than just communications data. This raises questions about forms of surveillance rolled out by the police based on broad common law powers, or – as in the recent Bridges decision – in a mix of legislation, common law and code. These sorts of surveillance – although in public – may also give rise to a feeling of being subject to constant surveillance, though the Court’s jurisprudence on video-surveillance under the GDPR has not yet grappled with this issue. It may be, however, that the Court would take a different view on the extent to which ‘private life’ would be engaged in such circumstances.  It is also worth noting that the views of the independent body must be binding on the SIAs; this reiterates the point that in principle approval must be sought in advance.

 

The Court also made clear that the rights in issue are not just privacy and data protection; it specifically referred here to freedom of expression and flagged the distinctive of those under professional duties of confidentiality (doctors, lawyers) and whistleblowers. It did not, however, consider whether any infringement was justified in this context. The list of possible rights affected is not limited to freedom of expression: in Schrems II the Court highlighted the right to a remedy. It is not inconceivable that the right to association could also be affected.  Presumably the same points of analysis apply – that general and indiscriminate monitoring cannot be justified even in the interests of national security.  The Court also recognised, in La Quadrature du Net, the positive obligations on the State in relation to Article 3 and 8 ECHR and the corresponding article in the Charter – Articles 4 and 7. The balancing of these positive obligations provided the framework for the Court’s analysis of types of surveillance that did not immediately fall foul of its prohibition of of general and indiscriminate data retention. In this context, it might almost be said that the Court is reformulating public interest objectives (such as national security or the fight against sexual abuse of children) as positive obligations and thus bringing them in a rights balancing framework.

 

The Court’s reasoning in both cases also gave us some insight into the meaning of national security. It is distinct from and covers more serious issues that the objectives listed in Art 15.  While this in principle seems to allow more intrusive measures to be justified, it seems that the Court has limited the circumstances of when it can be used.  It does not overlap seemingly with those grounds in Article 15 e Privacy Directive. So, even might be argued reading this part of the judgments that serious crime cannot be blurred with national security.  The devil will be in the detail here, a tricky one for any independent body to patrol – and in terms of permitted surveillance it is not clear what the consequences in practice would be.

 

The headline news, however, must be the ruling of the Court relating to measures that do not fall within the prohibition as general and indiscriminate measures.  This on one level is not totally novel; it is implied, for example, in Tele2/Watson, para 106.  The questions relate to what level of generality of surveillance would be permissible, and in relation to what sort of objective? Para 137 seems to limit targeted retention of communications data to matters of national security (including terrorism), but the Court then wheels out the same reasoning in relation to serious crime and public safety, and seems to envisage similar safeguards in both cases.  This then means that the test of ‘strict necessity’ is doing a lot of work in distinguishing between the legitimate and illegitimate use of surveillance measures. The Court has historically not been particularly strong on what it requires of a necessity test – let alone one requiring strict necessity – in other cases involving the interference with Charter rights.

 

The final point relates to the procedural questions. The Court was clear that striking down incompatible law cannot have suspended effect. Yet, that is precisely what the English court did in Watson when allowing the UK government several months to get its house in order. The Court of Justice also held here that illegally obtained evidence cannot be used in court, relying on the need to ensure that the rights granted by EU law are effective.  While the status of EU law in the British courts may currently be uncertain on the face of it this might mean that convictions based on data between the handing down of Tele2/Watson, or at latest its application by the English courts, until the revision of the regime might be open to challenge whatever the domestic rules on evidence might say. Of course, even if we did not have to deal with the jurisprudential consequences of Brexit, the Court of Appeal, in its approach to Tele2/Watson ignored the aspects of the judgment directed at Tele2 referring court despite the fact that element of the judgment was an interpretation of EU law having general application, so it is to be assumed that still more would it ignore a ruling in a different case altogether.

 

Barnard & Peers: chapter 9

Photo credit: Internet of Business