ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Government's data retention back-pedal fails to impress

Matt Loney ZDNet.co.uk

Published: 11 Mar 2003 14:39 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The government is scaling down its data retention plans in a renewed effort to quell public and industry disquiet, but even the toned-down policy has met a mixed response, with one prominent think-tank already labelling it a "sham".

On Tuesday, the government launched two consultation papers: one addressing data retention, and the other addressing who has access to communications data and how they can access it. It is the first of these -- the consultation paper on a Code of Practice for Voluntary Retention of Communications Data, which is required under the Terrorism Act -- that appears to have drawn the most flak.

Among the paper's concessions to concerns from industry and the public are reduced terms for how long ISPs and communications providers will have to retain data: 12 months maximum for subscriber information and telephony data, compared to the seven years that the government originally called for. Subscriber information includes the telephone number of an individual, their email address, log-in names for dial-up Internet accounts and other data (including the MAC addresses of network cards where held) that can be used to identify users. Telephony data typically covers numbers called, and location of mobile phones when those calls were placed.

Under the draft code of conduct, which is now open to public consultation, SMS and MMS data, along with details of where emails were sent to and received from, would be kept for six months, and details of Web sites visited would be kept for four months.

It is this consultation that has drawn the most ire, with Ian Brown, director of the Foundation for Information Policy Research, calling it "disingenuous". Brown criticised the Home Office for not addressing in the draft the concerns expressed by the information commissioner, the communications industry or by the parliamentary All Party Internet Group (APIG), which published a critical report earlier this year. Industry had called for the code of practice to be made mandatory, so that ISPs would be protected from legal action under the Human Rights Act and the Data Protection Act when complying with the measures in the code of practice.

Under the new draft code of practice, said Brown, companies will still be breaking the law by retaining data for anti-terrorist purposes and then making it available for access for other purposes, whether they are criminal investigations or civil lawsuits.

Furthermore, he said, the Home Office seems to be avoiding the issue of cost. ISPs say that retaining all the data will cost huge amounts.

"The data retention consultation is a sham," said Brown. "The Home Office has failed to address any of the well-known substantive issues and is merely going through the motions so it can come back with a compulsory scheme." But, he said, the compulsory scheme is also likely to be unlawful and will also be incredibly expensive: "The Home Office needs to drop data retention and start again, perhaps with a targeted preservation scheme such as seems to be successful in the USA."

The consultation on access to communications data under RIPA is a second attempt to regulate who should be able to access communications data: the first, last summer, drew widespread public concern when it became apparent just how many agencies would have access to communications data, and how easily they would have access.

New proposals contained in the revised consultation paper introduce the idea of vetting by the Information Commission of each request to access communications data. Introducing the consultation documents, Bob Ainsworth MP, parliamentary undersecretary of state at the Home Office, said a "double lock" would be applied to make sure that requests are proportional.

Under this idea, access would be restricted by purpose and by type of data. "Agencies would have to satisfy the Information Commission that their systems are suitable, and then they would have to seek prior approval from the Information Commission for access to the data," said Ainsworth. However, he could not say whether the Information Commission would have enough resources to deal with the expected flood of requests.


Who's watching you? Get the latest on spy networks such as Echelon and Carnivore, as well as privacy issues for companies and individuals alike, at ZDNet UK's Privacy News Section.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
54 out of 99 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Jobs

Quality Lead - Unilever - Level C-00055185

Perform security-communications across the unit (e.g.during comms events) Report board-level status/progress Unit Processes: Act as single point of ...

Security/Quality Analyst-00055189

Maintain open a communication channel with the corporate risk management team regarding requests for audit assistance and wide risk management ...

EXCELLENT SAN ROLE!

My Client based in Glasgow requests a candidate with In-depth knowledge of the following: Fibre architecture and Protocol Design, implementation, ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains