Site icon Inforrm's Blog

Case Law: Privacy International v Secretary of State for Foreign and Commonwealth Affairs: Collection of bulk personal datasets was unlawful – Sophie Stalla-Bourdillon

On 17 October 2016, the investigatory Powers Tribunal (IPT) delivered its judgment in the case Privacy International v. Secretary of State for Foreign and Commonwealth Affairs et al. The skeleton arguments for the claimants and respondents can be accessed here.

In a nutshell:

“The proceedings were brought on 5th June 2015 relating to the SIAs [Security and Intelligence Agencies]’ acquisition, use, retention, disclosure, storage and deletion of Bulk Personal Datasets (“BPDs”), whose existence was publicly acknowledged in March 2015 by the Respondents in evidence to, and then in a Report by, the Intelligence Security Committee of Parliament (“ISC”). The proceedings were amended in September 2015 to add claims in relation to the use of s.94 of the Telecommunications Act 1984 (“s.94” and “the 1984 Act”) by the Home and Foreign Secretaries to give directions to Public Electronic Communications Networks (“PECNs”) to transfer bulk communications data to GCHQ and MI5 (“BCD”).” [3]

A few dates are worth mentioning:

The IPT is faced with 4 issues:

“a) Issue 1: Section 94 TA under domestic law: Is it lawful as a matter of domestic law to use section 94 TA to obtain BCD? [Independently of the law of the EU and the ECHR]

(b) Issue 2: Is the section 94 TA regime in accordance with the law? This issue is to be considered in three time periods. First, prior to the avowal of the use of section 94 to obtain BCD [4th November 2015]. Secondly, from avowal to the date of hearing. Thirdly, as at the date of hearing.

c) Issue 3: Is the BPD regime in accordance with the law? This issue is to be considered in four time periods. First, prior to the avowal of the holding of BPDs [March 2015]. Secondly, from avowal to the publication of the BPD handling arrangements. Thirdly, from publication to the date of the hearing. Finally, as at the date of hearing.

d) Issue 4: Are the section 94 regime and the BPD regime proportionate?”

The IPT ruled:

  1. “[I]t is lawful at domestic law to use s 94 to obtain BCD.” [The IPT refused to conceive both RIPA and DRIPA as constituting a comprehensive framework necessarily excluding alternatives or trapdoors. In fact the IPT rejected the very term of trapdoors as a way to describe the effects of s.94 the Telecommunications Act 1984].
  2. Accordingly, our conclusion is, in respect of Issues 2 and 3, that, subject to the issue of transfer of data, and to resolution of Issue 4 below, the s.94 BCD [Bulk Communications Data] regime did not comply with Article 8 until November 4 2015 and thereafter complies, and that the BPD [Bulk Personal Data] regime did not comply with Article 8 until 12 March 2015 and thereafter complies. We so decide.”
  3. “Since the hearing, Mr. Anderson QC has published, as referred to in paragraph 21 above, his Bulk Powers Review. It is plainly highly relevant to this issue, and we propose to grant both parties the opportunity to make submissions upon it before reaching our conclusions in respect of this issue, which we consequently adjourn, to come on to be heard at the same time as the EU law issues.”

So the question that is on many lips is whether this new IPT’s decision actually means that the Investigatory Powers Bill (IPB) should actually be welcome.

As Alison Knight explained it in her previous post, the IPB is an attempt, among other things, to legalise the practice of transfer, storage and use of bulk personal datasets as well as bulk acquisition of communications data.  Chapter 2 of Part 6 regulates the power to issue bulk acquisition warrants “in the interests of national security,” “for the purpose of preventing or detecting serious crime,” or “in the interests of the economic well-being of the United Kingdom” (“so far as those interests are also relevant to the interests of national security”). Importantly while a bulk acquisition warrant is meant to target communications data, the telecommunications operator specified in the warrant can be required “to obtain any communications data specified in the warrant which is not in the possession of the operator but which the operator is capable of obtaining.” S. 147(8) besides adds that “A bulk acquisition warrant may relate to data whether or not in existence at the time of the issuing of the warrant.” Notably, a judicial commissioner must review the Secretary of State’s conclusions of its decision to issue a bulk acquisition warrant.

Chapter 7 of the IBP regulates the power to retain a bulk personal dataset. The decision is taken by the Secretary of State after an application is made by or on behalf of the head of an intelligence service. Once again the conclusions of the Secretary of State must be reviewed by a judicial commissioner.

To come back to the IPT, it applies the rulings in the judgement by the European Court of Human Right in Weber & Saravia v Germany [2008] and Kennedy v United Kingdom [2011] to solve issues 2 and 3 (Mention is also made of R E v United Kingdom [2016] and Szabo & Vissy v Hungary). It insists at para. 61“it is not for this Tribunal to lay down new requirements.”

But the IPT (simply) reformulates the high-level test to be found in Weber: “As noted above, Issues 2 and 3 are framed by reference to the “in accordance with law” requirement in Article 8. That requirement is generally stated to comprise (a) that the measures under review should have a basis in domestic law, and (b) that the laws in question should be compatible with the rule of law, in being generally accessible, foreseeable and contain adequate safeguards against arbitrary use.” [59]. [without assessing all the safeguards identified by the European Court of Human Rights (ECtHR) in Weber].

The IPT states that:

Ultimately the IPT seems to welcome the IPB when it states at para. 86: Further, just as the fact that there have been improvements [with the present IP Bill] does not necessarily mean that the previous system prior to the improvements was non-compliant (paragraph 62 above), similarly the fact that there could be further improvements does not mean of itself that the present system is non-compliant.”

What will the additional consideration of EU law bring? And by the reference to EU law here, one should understand, Digital Rights Ireland of 2015 and Tele2 Sverige AB, which has not been decided yet. Does EU law go beyond the law of the ECHR (for some earlier considerations on this point, see my previous post here)?

Finally, it is worth remembering that this is the second major breach by the SIAs upheld by the IPT (see Alison’s post here). Will the IP Bill put a definitive end to these “unprecedented judgements”?

This post originally appeared on the Peep Beep! blog and is reproduced with permission and thanks

Exit mobile version