ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

ISPs revolt against data retention law

Matt Loney ZDNet.co.uk

Published: 23 Oct 2002 17:08 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

UK ISPs are poised to ignore a Home Office voluntary code of practice addressing retention of Internet data unless big changes are made to the wording.

The code of practice lays out the obligations of ISPs under the Anti-Terrorism, Crime and Security Act, which was rushed through parliament in the wake of the 11 September terrorist attacks. It obliges ISPs to retain communications data for law enforcement purposes, but, a year since the first draft was released, the Home Office has failed to explain how ISPs will be reimbursed for retaining the data, or how they can comply with the code without breaking numerous other laws.

The proposals have already been knocked back by European data protection commissioners.

In a letter to the ISP Association's members, ISPA general secretary Nicholas Lansman said he could not "recommend to members that they voluntarily comply with the proposed code of practice." According to the letter, which was seen and first reported by The Guardian, the industry had not been convinced that extending the length of time companies hold on to customer logs was necessary for the fight against terrorism and serious crime.

An ISPA spokesman confirmed the contents of the letter to ZDNet UK, but played down the significance, saying that it merely restates a position that ISPA has held for "many months". Furthermore, he said, if the ISP community refuses to abide by the voluntary code of practice then it will be forced upon them. "The government has said that if after a year the voluntary code of practice is seen, in the eyes of the home secretary, not to have worked then they will make it mandatory and so communications service providers will not have any option. It will be law," said the spokesman.

Nevertheless, ISPs say they still have many concerns about the code of practice, not least of which is the worry that by complying with it, ISPs may be forced to break other laws. "The ACTS law and code of practice has to reconciled with the Regulation of Investigatory Powers Act (RIPA), the Data Protection Act, the Human Rights Act, and the Police and Criminal Intelligence Act. ISPs need to know their legal position," said the spokesman. It's a concern that the ISP community and others have been voicing to the Home Office for more than a year now -- with no response.

ISPA is not alone is voicing such concerns. Shortly after the first draft was published last year a joint parliamentary committee warned it was likely to break European human rights legislation. The House of Lords and House of Commons Joint Committee on Human Rights said the code appeared to be incompatible with the European Convention on Human Rights (ECHR), and said safeguards are needed to prevent the government from compiling a stockpile of communications data on innocent citizens.

"We consider that measures should be put in place to ensure that the Code of Practice and any directions are compatible with the right to respect for private and family life, home and correspondence under Article 8 of the ECHR, and that those measures should be specified, so far as practicable, on the face of the legislation," the Committee concluded.

Even if the legal issues are sorted out, the costs of implementing the measures are likely to be high. "There is the initial set up," said the ISPA spokesman. "Then there are costs associated with management processes, storage and storage management, human resources, and then ISPs will also have to deal with requests from the data subjects themselves. There are so many problems that need to be resolved."

The spokesman said that ISPs are keen to work with law enforcement, but the Home Office must reply to the concerns of industry. "We need to know what the terms of the cost recovery process will be. We want to help, but law enforcement is not our job so we shouldn't have to pay for it."


For everything Internet-related, from the latest legal and policy-related news, to domain name updates, see ZDNet UK's Internet News Section.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
61 out of 115 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Business Analyst / Oracle SCM Business Analyst / Business Analy

After an impressive H1, coupled with above average Q3 results, they have decided to progress forward to phase 2 of their aggressive ERP Oracle ...

SAP HR Payroll Consultant - SAP HR Consultant SAP

SAP HR Payroll Consultant SAP HR Consultant SAP Reach out for a permanent position as SAP HR Payroll Consultant within ADP GlobalView ADP GlobalView ...

Technical Support Services Consultant

As the quality of support offered by ISPs continues to vary greatly, at Zen Internet we pride ourselves on having one of the best technical support ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains