ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

MPs say snooping laws need ring fence

Matt Loney ZDNet.co.uk

Published: 03 Feb 2003 17:41 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

MPs have warned that government agencies must stop using a range of laws to demand access to records of people's surfing activities if ISPs are not to be forced out of business.

In a report on its inquiry into data retention, the All-party Parliamentary Internet Group (APIG) said that government agencies must pay more heed to the spirit than the letter of the law when demanding communications data from ISPs.

Communications data means IP addresses of Web sites that people visit, and addresses of emails; it is distinct from content, although many in the industry believe it is just as invasive.

Rules designed to regulate access to communications data are contained in the Regulation of Investigatory Powers Act (RIPA), which contains provisions for the home secretary to allocate money to compensate ISPs for the costs of providing data to government agencies such as the police. But a wide range of government agencies can still access the data under different laws: Trading Standards officers have the power to demand records under Trading Standards Act, while Social Security officers have powers under the Social Security Act, and the Serious Fraud squad under separate powers, to name but a few. None of these are required to compensate ISPs for costs incurred during access demanded under these other laws instead of under RIPA.

ISPs already retain data for operational purposes -- in case a system fails and they have to restore it -- and they receive requests from various government agencies for this data.

But when the relevant part of the Anti-Terrorism Crime and Security Act (ATCS) comes into power later this year, and ISPs are forced to retain a whole year's worth of data, they are expecting a "flood" of requests from numerous agencies under numerous laws, and a corresponding rise in costs.

At Thus, costs are expected to be in the region of £5m, while AOL has estimated its costs at £30m to set up the systems and then a further £30m a year. The government is believed to have estimated the costs for data access under RIPA for the entire industry at £20m, but has no plans to address the costs incurred when agencies use other powers.

MPs say the only solution is legislation to ring-fence access to communications data so it can only be accessed by public authorities through the use of RIPA Part I Chapter II "and hence use of other legislation would be ineffective." This legislation would "prevent agencies from deliberately avoiding RIPA controls" by accessing communications data through a statutory gateway.

"We endorse the recommendation from (the UK ISP Association) that a memorandum of understanding be developed whereby those public authorities who currently access communications data would renounce use of their legacy powers," said APIG in its report. "We recommend that the Home Office bring forward legislation to prevent agencies from deliberately avoiding RIPA controls by accessing communications data through a statutory gateway."

The MPs also called for explicit criminal penalties in RIPA for those who use section data access notices without proper authorisation "or who deliberately abuse the system to obtain information to which they are not entitled."


Who's watching you? Get the latest on spy networks such as Echelon and Carnivore, as well as privacy issues for companies and individuals alike, at ZDNet UK's Privacy News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
62 out of 109 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Project Manager c.48k Credit Reference Agency Experience (desirable)

A financial services client in Northampton are looking to recruit a Project Delivery Manager to focus on the companys global usage of Credit ...

Site Systems Integration Manager

Assuring and managing the quality of the systems integration programme set up and execution, youll have a specific focus on: Build and integration ...

Quality Lead - Unilever - Level C-00055185

Support implementation coordination for agreed QPI, SOX and Security controls Manage one quality team member who will support these activities Main ...

Discussions

spartus4 spartus4

Internet connection?

Friday 4 July 2008, 4:30 AM

3 comments
roger andre roger andre

Beware Of Sneaky Services

Thursday 3 July 2008, 7:18 PM

5 comments
Moley Moley

Beware Of Sneaky Services

Thursday 3 July 2008, 7:02 PM

5 comments
roger andre roger andre

facebook lockdown

Thursday 3 July 2008, 1:47 PM

3 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal