ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Privacy comes under attack

Wendy McAuliffe ZDNet.co.uk

Published: 30 Mar 2002 07:31 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The events of 11 September provoked a new urgency in the need for powers that would allow law enforcement officers to retain traffic data for anti-terrorist investigations. Within a matter of weeks, the privacy rights of British citizens had been hugely compromised by emergency legislation, which allowed the automated surveillance of all electronic communications.

Now at the start of 2002, British surveillance laws are at risk of infringing what are seen by some as basic human rights. Huge demands have been placed on Internet Service Providers (ISPs) to stockpile traffic data on customers under the new Anti-Terrorism, Crime and Security Bill (ATCS), and the Information Commissioner has characterised the requirements as "disproportionate general surveillance".

Traffic data collected under the voluntary Code of Practice within the ATCS would provide a "complete map of a person's private life" according to the Foundation for Information Policy Research (FIRP). Records will include an individual's geographical location determined through their mobile phone, the sender and recipient information from emails, a complete log of a person's Internet sessions including their IP address, and the address of all Web sites visited.

The Data Protection Act 1998 states that a communications provider must only retain traffic data for the length of time necessary for legitimate billing purposes. But contained within the Act is a provision for cases of national security, where personal data may be stored for longer periods of time in order to assist in the prevention or detection of crime.

In her scrutiny of the ATCS, Elizabeth France, information commissioner, warned that the Act might pose difficulties for data protection and human rights compliance. "Although recent events have prompted these measures to be brought forward," she said, "law enforcement agencies will make use of them on a day-to-day basis for a variety of matters. Careful consideration must be given to ensure that the provisions are appropriate to addressing these more routine needs."

Before the publication of ATCS, the home secretary, David Blunkett, stated that traffic data obtained under the new arrangements would be used "strictly in the case of a criminal investigation against suspected terrorists." This promise was broken within the Act's report stage, when part 11 endorsed the stockpiling of traffic data for minor criminal investigations. But Blunkett u-turned his decision a matter of hours before the Act received royal assent, and accepted a proposal tabled by the Liberal Democrats to separate out data that is relevant to terrorists, as opposed to organised criminals. The Code of Practice now makes the ambiguous requirement that in order for surveillance powers to apply, the investigation must relate "directly or indirectly to national security."

Data retention powers included in ATCS will be regulated under the terms of the Regulation of Investigatory Powers Act (RIPA). This Act allows access to traffic data for broader reasons than national security, including public order, minor crime, health and safety and tax. Any ISP can be required to install a "black box" capable of relaying intercepts back to a central monitoring facility at MI5. Content and traffic data can be directly collected by the black boxes, without the need for a content warrant or traffic notice on the ISP. A superintendent is able to request access to all traffic data stored by an ISP, and a single interception officer has sole responsibility for overseeing all interceptions conducted under RIPA.

Chapter II of Part I of RIPA, which makes it possible for law enforcement to access traffic data without a court order is still to come into force. The Home Office has set no date for its passage, but hopes that it will become law "shortly".


Who's watching you? Get the latest on spy networks such as Echelon and Carnivore, as well as privacy issues for companies and individuals alike, at ZDNet UK's Privacy News Section.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
56 out of 97 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

VB.NET Developer Andover, Hampshire up to 40k

They combined the experience of first hand experts with criminal and fraud investigation, combined with top level compliance officers and private ...

SQL Server Developer - London

Previous experience in a telecommunications or ISP background is highly desirable. Solid experience of MS SQL Server 2005, DTS, SSIS, and complex ...

ISP Network & Infrastructure Manager

We are able to retain our reputable and unrivalled position with the ISP market due to our dedicated work force that is committed to providing the ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains