Advertisement
Promo

Security management Toolkit

America debates data retention

Declan McCullagh CNET News

Published: 18 Apr 2006 18:00 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The explosive idea of forcing ISPs to record their customers' online activities for future police access is gaining ground in US state capitols and in Washington DC.

Top Bush administration officials have endorsed the concept, and some members of the US Congress have said federal legislation is needed to aid law enforcement investigations into child pornography. A bill is already pending in the Colorado State Senate.

Mandatory data retention requirements worry privacy advocates because they permit police to obtain records of email chatter, Web browsing or chat-room activity that normally would have been discarded after a few months. And some proposals would require providers to retain data that ordinarily never would have been kept at all.

ZDNet UK sister site CNET News.com was the first to report last June that the US Department of Justice was quietly shopping around the idea of legally required data retention. But it was the European Parliament's vote in December for a data retention requirement that seems to have attracted broader interest inside the United States.

At a hearing last week, Congressman Ed Whitfield, a Kentucky Republican who heads a House oversight and investigations subcommittee, suggested that data retention laws would be useful to police investigating crimes against children.

"I absolutely think that that is an idea that is worth pursuing," an aide to Whitfield said in an interview on Thursday. "If those files were retained for a longer period of time, it would help in the uncovering and prosecution of these crimes." Another hearing is planned for 27 April.

Internet providers generally offer three reasons why they are sceptical of mandatory data retention: first, it is not clear who will be able to access records of someone's online behaviour; second, it's not clear who will pay for the data warehouses to be constructed; and third, it's not clear that police are hindered by current law as long as they move swiftly in investigations.

"What we haven't seen is any evidence where the data would have been helpful, where the problem was not caused by law enforcement taking too long when they knew a problem existed," said Dave McClure, president of the US Internet Industry Association, which SMEs.

McClure said that while data retention aficionados cite child pornography, the stored data would be open to any type of investigation — including, for instance, those focused on drug crimes, tax fraud, or terrorism prosecutions. "The agenda behind this doesn't appear to be legitimate," he said.

Proposals for mandatory data retention tend to adhere to one of two models: Address storage or some kind of content storage. In the first model, businesses must record only which Internet address is assigned to a customer at a specific time. In the second, which is closer to what Europe adopted, more types of information must be retained — including telephone numbers dialled, contents of Web pages visited, recipients of email messages and so on.

Without saying what model he favoured, Homeland Security secretary Michael Chertoff broadly endorsed data retention at a meeting of a departmental privacy panel last month. In response to a question, Chertoff said that federal police should be permitted to run queries against data repositories created and maintained by businesses for a set time.

"That might be a model for some kind of data retention issue," Chertoff said. "It might be one that would say the government, instead of holding the data itself, will allow it to remain in the private sector, provided the private sector retains it for a period of time so we can ping against it."

FBI director Robert Mueller was more blunt. He was quoted by the Financial Times  in January as saying: "There can be standardised regulations and rules relating to data retention and secondly a mechanism for the swift exchange of information." The remarks, made at...

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
206 out of 485 people found this useful


Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters