Showing posts with label internet service providers. Show all posts
Showing posts with label internet service providers. Show all posts

Saturday, August 29, 2015

Canadian Police Chiefs looking to resurrect warrant-less access to telecom users' data

The Canadian Association of Chiefs of Police, at their annual conference, just passed a resolution looking to resurrect the lawful access debate following R. v. Spencer.

I find it puzzling. They are looking for warrantless access to customer data (which they call BSI, or basic subscriber information) where there is no expectation of privacy, while the Supreme Court of Canada said that there is a reasonable expectation of privacy in basic subscriber information. Their resolution (reproduced below), refers to recent caselaw that follows old pre-Spencer decisions that say there is no expectation of privacy in customer name and address connected to a telephone number. The resolution also refers to options being considered by a federal, provincial and territorial cybercrime working group to provide warrantless access to BSI.

Let me get this straight: they want warrantless access to BSI where there is no expectation of privacy, while the Supreme Court has said there is an expectation of privacy in BSI. So what's left of the categories of BSI where there is no expectation of privacy?

A few things are clear to me, which make this resolution and the apparent efforts to circumvent the warrant process very problematic.

  • The Supreme Court said there is a reasonable expectation of privacy in BSI, at least in the internet context;
  • The CACP and law enforcement generally have consistently said -- contrary to what the Court found in Spencer -- that there is never an expectation of privacy in BSI;
  • You can't trust law enforcement to determine whether an expectation of privacy exists.

I recognize that BSI is often critical to investigations, but it can't be a free for all where the police get access to it without an impartial judicial officer determining, on sworn evidence, that the balance between privacy and public safety is in favour of public safety. The inexorable conclusion is that the only solution to this is to make the warrant and production order process more efficient and streamlined.

Justin Ling did a great article on this for the CBA's National Magazine: National | Accessing subscriber data: Working around the Spencer ruling.

Resolution #03 - 2015

REASONABLE LAW TO ADDRESS IMPACT OF SUPREME COURT OF CANADA DECISION R. v SPENCER, 2014, SCC 43

Submitted by the E-Crimes Committee

WHEREAS law enforcement requires real-time, or near real-time access to basic subscriber (customer name and address) information (BSI) as it relates to telecommunications’ customers for investigative reasons, and;

WHEREAS the Supreme Court of Canada, in their majority decision in R. v Spencer, 2014 SCC 43, did state that:

  • a reasonable expectation of privacy exists in the identity of an internet subscriber where there is an ability to link that identity to specific online activity;

  • the identity of a person linked to their use of the Internet must be recognized as giving rise to a privacy interest beyond that inherent in the person’s name address and telephone number found in the subscriber information;

  • absent an exigent circumstance, or authority from a reasonable law, such as authority from a judicial warrant or order, police do not have the power to conduct a search for basic subscriber information (BSI) when there exists a reasonable expectation of privacy in that information, and;

WHEREAS since the Spencer decision, the telecommunications companies refuse to provide any basic subscriber information (BSI) in the absence of an exigent circumstance, or a judicial warrant or order, even where there exists no reasonable expectation of privacy, and;

WHEREAS there exists no lawful authority designed specifically to require the provision of basic subscriber information, and the problems posed by this gap in the law are particularly acute where there exists no reasonable expectation of privacy in that information.

THEREFORE BE IT RESOLVED that the Canadian Association of Chiefs of Police supports the creation of a reasonable law designed to specifically provide law enforcement the ability to obtain, in real-time or near real-time, basic subscriber information (BSI) from telecommunications providers.

REASONABLE LAW TO ADDRESS IMPACT OF SUPREME COURT OF CANADA DECISION R. v SPENCER, 2014, SCC 43

Background

In June 2014, the Supreme Court of Canada issued a decision in the case of R v. Spencer - identifying that subscriber information that allows for the linking of the identity of a person with specific online activity in the context of a criminal investigation engages a high level of informational privacy. However, telecommunications and other service providers (e.g. financial institutions, rental companies) have interpreted the court's findings more broadly, and now demand judicial authorization (based on a reasonable grounds to believe threshold) for nearly all types of government requests for basic identifying information, extending beyond instances involving a person's substantive Internet activity.

The impact of the Spencer ruling and the broader response by telecommunications and other service providers is having a significant impact on law enforcement and criminal investigations. Basic identifying information is often required at the onset of an investigation where technology plays a role, but the judicial threshold required to obtain warrants and general production orders to access basic identifying information is difficult, and often impossible, to satisfy when an investigation is in its early stages.

Moreover, the impact of the Spencer ruling has caused substantial resource and workload challenges for law enforcement. For example, prior to the Spencer ruling, law enforcement agencies would generally complete a voluntary request to telecommunications service providers for basic identifying information in under an hour, and receive a response from service providers within the same day. Following the Spencer ruling, accessing the same information now often requires ten to twenty times the amount of administrative work and documentation, days of preparation to seek judicial authorization, and responses from service providers can take upwards of one month - sometimes exceeding a service provider's data retention schedule for the same information (meaning the information is no longer available).

Criminal investigations impacted by the Spencer ruling are now often delayed and in some cases, not pursued, due to judicial authorization or resource challenges. This impact applies to a range of investigative work, such as cases involving suspected online child sexual exploitation and abuse, fraud and other financially-motivated crimes, organized crime, requests for international law enforcement assistance, and national security matters involving suspected extremism and other threats to Canada - all of which may require basic identifying information from a telecommunications or other service provider to identify potential evidence for criminal investigations and prosecutions.

Transparency Guidelines

Transparency Reporting Guidelines were prepared by Industry Canada, in consultation with RCMP and other relevant Government of Canada partners, to help private organizations be open with their customers, regarding the management and sharing of their personal information with government, while respecting the work of law enforcement, national security agencies, and regulatory authorities. Specifically, the Guidelines cover categories of disclosures for reporting purposes and limitations to consider when reporting statistics. Of note, the Guidelines specify that there should be a six month delay in reporting timeframe to ensure that most active investigations have no possibility of being compromised. On June 30, 2015, the Transparency Reporting Guidelines were published on Industry Canada’s website:

http://www.ic.gc.ca/eic/site/smt-gst.nsf/eng/sf11057.html

Coordinating Committee of Senior Officials

Recently, a discussion paper, led by Justice, was presented to the Federal, Provincial and Territorial Coordinating Committee of Senior Officials, Cybercrime Working Group. The paper focuses on the impact of Spencer and legislative reform considerations.

Option 1: Create an administrative (non-judicial) scheme for access to Basic Subscriber Information (BSI).

Option 2: Create a new judicial order (production order) for basic subscriber information and/or add BSI to existing production orders.

Option 3: Create a specific production order for some types of basic subscriber information with a greater expectation of privacy, and create a specific administrative (non-judicial) authority for access to other types of basic subscriber information.

Recent Case Law

  • Since the Supreme Court of Canada released its decision in R. v. Spencer in June 2014, case law has started to emerge that applies the analysis in Spencer to other cases involving police requests for BSI.

  • The majority of relevant cases thus far are from Ontario and involve requests for BSI associated to a phone number. The cases have generally found that the privacy interests in BSI associated to a phone number are not the same as the privacy interests in BSI linked to an IP address, and distinguish Spencer on that basis. As such, the Ontario decisions have upheld warrantless requests for BSI associated to phone numbers as they found in the circumstances of each case that there was no expectation of privacy in such information. See: R. v. Morrison (unreported, Ontario Court of Justice, Reasons released on December 17, 2014); R. v. Khan (2014 ONSC 5664); R. v. Latiff (2015 ONSC 1580); R. v. Nurse and Plummer (2014 ONSC 6004).

  • The issue of whether there is a reasonable expectation of privacy in BSI associated to a phone number has also emerged in the context of transmission data recorders warrants (TDRW). These warrants provide judicial authorization to record incoming and outgoing dialed phone numbers. In Ontario, police/Crowns have argued before the Superior Court of Justice that an assistance order is the proper authorization to obtain in conjunction with a TDRW to compel a service provider to provide the BSI associated with the dialed numbers. However, Telus has argued that due to the privacy interests in BSI, as found in Spencer, a general warrant is the proper authorization. Nordheimer J. agreed with the police/Crown and held that Spencer was a decision dealing with the Internet and it did not find that there is always a reasonable expectation of privacy in BSI, but rather it will depend on the circumstances of each case. This is a very recent decision (June 19, 2015), and it will be interesting to see if other jurisdictions follow this reasoning. See H.M.Q. v. TELUS Communications Company, 2015 ONSC 3964.

REASONABLE LAW TO ADDRESS IMPACT OF SUPREME COURT OF CANADA DECISION R. v SPENCER, 2014, SCC 43

Action Plan

The CACP Law Amendments Committee will work with the E Crime Committee to develop new legislation that supports the creation of a reasonable law designed to specifically provide law enforcement the ability to obtain, in real-time or near real-time, BSI from telecommunications providers.

The Committee will keep abreast of the ongoing work of the F/P/T Coordinating Committee of Senior Officials, Cyber crime Working Group who is leading the policy development of legislative reform considerations; next meeting schedule in November, 2015.

Requirement to develop an overall government-wide approach to ensure law does not run counter to government objectives or would require major modifications in the future.

Saturday, February 18, 2012

Police "PIPEDA requests" for customer information

As a follow-up to my previous post 'Dealing with police "Letters of Request for Information"', I thought I'd discuss a particular species of request letters, commonly referred to as "PIPEDA Requests".

The names are a bit misleading, since in many cases the recipient is led to believe that the authority to obtain the information is found in PIPEDA (the Personal Information Protection and Electronic Documents Act).

Here is an example letter, taken from R. v. Ward, 2008 ONCJ 355:

I, Constable Jason Tree of the National Child Exploitation Coordination Centre, am a law enforcement officer with the Royal Canadian Mounted Police.

I am conducting an investigation in relation to child sexual exploitation offences under the Criminal Code and I am requesting account information pursuant only to that investigation.

I request this disclosure in accordance with s. 7(3)(c.1) of the Personal Information Protection Electronic Documents Act. My authority to request and obtain this information derives from the Royal Canadian Mounted Police Act and the Royal Canadian Mounted Police Regulations as well as common law.

I am requesting the last known customer name and address of the account holder associated with IP address [number] used [date and time].

Should you agree to this request, please provide the information in the section below and reply via e-mail to Jason.tree@rcmp-grc.gc.ca.

As I understand it, the form of letter was a result of the coordinated effort of law enforcement and a group of internet service providers who have agreed to provide warrantless access to customer account information in connection with child exploitation investigations. They are designed to satisfy the requirements of Section 7(3)(c.1)(ii) of PIPEDA which permits disclosures of personal information to the police where they have the "lawful authority" to obtain the information and the information relates to "enforcing any law of Canada, a province or a foreign jurisdiction, carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law".

While I generally have a dim view of disclosing customer information without a warrant, I can certainly understand why internet service providers have worked with law enforcement to address these particularly grim crimes.

Monday, November 07, 2011

ISP's terms of use allow disclosure of customer information to police

Once again, a Canadian trial court has determined that an internet service provider's "terms of use" mean that a customer does not have a reasonable expectation of privacy in their identity information when the police come knocking. R. v. Lo, 2011 ONSC 6527.

I can't help but wonder how many people have ever read the terms of use for the internet service provider and how you can really conclude that an expectation of privacy can be vitiated by something that the vast majority of people have never read.

I also note that the police had more than enough information to get a warrant or a production order, but didn't.

Saturday, November 05, 2011

Saskatchewan Court refuses to admit expert evidence on reasonable expectation of privacy for ISP customer information

The Saskatchewan Court of Queen's bench has just released a decision in which the Court refused the defendant's application to admit expert evidence to support the proposition that there exists a reasonable expectation of privacy in customer name and address information when the police request it from an ISP with only an IP address.

In R v Pinsky, 2011 SKQB 371, police were carrying out an investigation into alleged possession and distribution of child pornography. The police had an IP address and asked Shaw, an internet service provider, for the customer name and address connected to the IP address at the relevant time. The ISP handed it over without a warrant.

In the course of the trial, the defendant asserted that there is a reasonable expectation of privacy in such information and that the evidence obtained following this should be excluded. The defendant sought to have Dr. Sunny Handa qualified as an expert, but the Court declined on the basis that such evidence is not necessary.

The decision only deals with the question of whether expert evidence can be put forward for such an argument, not whether the reasonable expectation of privacy exists. It'll be interesting to see how the court decides on the ultimate question.

Friday, November 04, 2011

What's the justification for warrantless access to customer data in "lawful access"

The Public Safety Minister and various police folks are arguing that telecom operators should have to hand over any and all of the following information without a warrant and without an underlying criminal investigation: name, address, telephone number and electronic mail address, Internet protocol address, mobile identification number, electronic serial number, local service provider identifier, international mobile equipment identity number, international mobile subscriber identity number and subscriber identity module card number that are associated with the subscriber’s service and equipment.

None of them have come up with any shred of a justification for such measures, other than empty platitudes that come down to "think of the children" and broken analogies that liken the above information to what you'd find in a phone book. Since both of these supposed justifications are--on their face--worthless, let's speculate about what the real justification might be and whether they can be properly addressed.

  1. Police need this information to get bad guys but often can't convince a judge that they should get a search warrant or a production order for this information. - The answer is that if you can't convince a judge that the public interest in the police obtaining this information outweighs the individual right of privacy, then you should not be getting it. By definition, it would be an unconstitutional invasion of privacy.
  2. Police need this information to get bad guys but it takes too long to get a warrant or a production order. - This is a resources or a procedures issue. Frankly, I want it to take some time and effort on the part of the police to be able to pry into the private lives of Canadians. But if it really takes too long, streamline the processes and appoint more judges and justices of the peace. Don't sacrifice individual privacy on the altar of cost-cutting.
  3. Police URGENTLY need this information to get bad guys and there are lives hanging in the balance. - That's why we have telewarrants and exigent circumstances. Don't use a non-problem to justify stripping away individual rights from Canadians. Every Canadian telco I've spoken to on the topic tells me they will provide this information if a police officer says that the circumstances are exigent.

Maybe I'm missing something here and there is an adequate justification that I just haven't heard yet. If you've got one, leave it in the comments. I'd like to hear it.

Monday, October 31, 2011

Ontario Commissioner on lawful access (actually, "expanded surveillance")

In the National Post, Ontario's Information and Privacy Commissioner adds her strong voice to the call for increased scrutiny of any "lawful access" proposals:

Privacy Commissioner Ann Cavoukian: Privacy invasion shouldn’t be ‘lawful’ | Full Comment | National Post:

By Ann Cavoukian

I must add my voice to the growing dismay regarding the impact of impending “lawful access” legislation in this country. In my view, it is highly misleading to call it “lawful.” Let’s call it what it is — a system of expanded surveillance.

At issue is the anticipated re-introduction of a trio of federal bills that will provide police with much greater ability to access and track information, via the communications technologies we use every day, such as the Internet, smart phones and other mobile devices. I have no doubt that, collectively, the legislation will substantially diminish the privacy rights of Ontarians and Canadians as a whole.

Let’s take a brief look at the surveillance bills, which were introduced prior to the last election:

  • Bill C-50 would make it easier for the police to obtain judicial approval of multiple intercept and tracking warrants and production orders, to access and track e-communications.
  • Bill C-51 would give the police new powers to obtain court orders for remote live tracking, as well as suspicion-based orders requiring telecommunication service providers and other companies to preserve and turn over data of interest to the police.
  • Bill C-52 would require telecommunication service providers to build and maintain intercept capability into their networks for use by law enforcement, and gives the police warrantless power to access subscriber information.

I well understand the attraction for law enforcement officials — the increased ability to access and track our e-communications, with reduced judicial scrutiny, would put a treasure trove of new information at their fingertips.

However, we must be extremely careful not to allow the admitted investigative needs of police forces to interfere with or violate our constitutional right to be secure from unreasonable state surveillance. The proposed surveillance powers come at the expense of the necessary privacy safeguards guaranteed under the Charter of Rights and Freedoms. The federal government must be persuaded to acknowledge the sensitivity of traffic data, stored data and tracking data, and strongly urged to re-draft the bills. For a start, the proposal for warrantless access to subscriber information is untenable and should be withdrawn. If special access to subscriber information is considered to be absolutely necessary, it must take place under a court-supervised regime.

The government needs to step back and consider all of these implications. A comprehensive cost-benefit analysis should precede the entrenchment of so many significant public policy decisions. Public Parliamentary hearings must also be scheduled to ensure that civil society, as well as the telecom industry, has a full opportunity to provide input.

Canadians must press the federal government to publicly commit to enacting much-needed oversight legislation in tandem with any expansive surveillance measures. Intrusive proposals require, at the very least, matching legislative safeguards. The courts, affected individuals, future Parliaments and the public must be well informed about the scope, effectiveness and damaging negative effects of such intrusive powers.

We can, and must, have both greater security and privacy, in unison. It cannot be one at the expense of the other. The true value of privacy must be recognized in any effort to modernize law enforcement powers. Imposing a mandatory surveillance regime on the public and its telecom service providers must not go forward without strong safeguards to protect the future of our fundamental freedoms.

National Post

Ann Cavoukian is the Information Privacy Commissioner of Ontario.

Sunday, October 30, 2011

Why lawful access legislation should not be allowed

This is why lawful access legislation should not be allowed to pass.

The Guardian is reporting on equipment being used by London's Metropolitan Police to eavesdrop on cell phones: Met police using surveillance system to monitor mobile phones | UK news | The Guardian.

The last iteration of lawful access legislation that fell off the order paper with the last federal election would have allowed police to obtain any of the following information, without a warrant, without oversight, without justification and even without any active investigation:

  • name,
  • address,
  • telephone number and
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number that are associated with the subscriber’s service and equipment.

In the abstract, that may sound innocuous, but it's far from it.

The equipment described in the Guardian article allows police to scan the airwaves and pick out the unique identifiers for all cell phones in the area. With that identifier, they can get any of the above information, again without a warrant and without any justification. Such a device could be used to identify anyone at a lawful protest, regardless of whether they had done anything wrong. We expect to carry on our lawful lives free from police intrusion unless a judge can be persuaded that the police are justified in their intrusion into your life, including the fact that the intrusion relates to a lawful investigation into criminal wrongdoing. Lawful access would remove the only check and balance, allowing police the ability monitor citizens without any reason.

This is not the country we should aspire to live in.

Saturday, September 17, 2011

What lawful access is all about

Yesterday, I posted about three new public service announcements made by OpenMedia.ca, which are part of a campaign against "lawful access". (Canadian Privacy Law Blog: OpenMedia.ca launches "lawful access" PSAs).

The ads themselves will probably raise awareness about lawful access, but don't do a good job of really explaining what lawful access is. The ads suggest that police will be able to read your e-mail, intercept your calls and watch your online shopping without a warrant. That's not the case.

We don't really know what the Harper Government(TM) plans to put in the legislation when it is introduced later this year, but we can take a look at what has been put forward by the liberals and the conservatives over the past few years. In short, the police will be able to go to your ISP, your phone company or any other online service provider and get the following information about you:

  • name,
  • address,
  • telephone number and
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number that are associated with the subscriber’s service and equipment.

All they would need is one piece of that puzzle and the service provider has to provide all the other pieces. If they have your IP address, they get your address. If they have your name, they get your phone's built-in identifier.

So why does this matter? The Internet is not quite like the real world. When you go to a library, you don't have to provide ID or leave a record of what you looked at or that you were even there. When you step into a store in the real world, you don't necessarily leave a trace of what you perused and what you bought (if you paid cash). You can send an anonymous letter to the editor of your local newspaper to voice an unpopular opinion without giving your name or any other identifying information. (They probably will not publish it, but that's beside the point.) But the Internet doesn't work like that.

Every device on the network (phone, computer, etc) has an IP address. IP addresses can be tied to an individual computer or a range of computers sitting behind a firewall or a router. Every mobile device, such as a cell phone or a smart phone, has a number of unique identifiers that it chirps out to the network that it's attached to. Every interaction that you have online, you can assume is being logged in some fashion in connection with that IP address. Many e-mails you send include in the headers the IP address of the computer it was written on.

It's just the nature of how networks work. That IP can perhaps be traced to you, to your household or to your employer. In most cases, where residential internet accounts are concerned, they are connected to the name and address of the account holder. With phones, that identifier is connected to the individual who owns the phone.

In short: Everywhere you go on the internet or with your mobile phone, you leave digital footprints. That's the nature of the modern, networked world. So what protects your privacy when you do anything online? The fact that whoever allocated that IP address or provides your cell phone service has to keep it confidential unless a judge decides that the public interest (or the state interest) overrides your privacy interest. That's why we have a Charter of Rights and Freedoms in Canada and why we have an independent judiciary. There is no absolute anonymity online, but there is effective privacy by obscurity because anyone who can connect your IP address to an individual is bound to keep it confidential unless a judge says otherwise.

However, the Harper Government's lawful access bill proposed to take that important balance away. It would give police forces and national security folks virtually unfettered powers to connect those otherwise anonymous footprints to an actual person (or small group of persons).

That is inconsistent with your rights to privacy and is dangerous to the free and open internet. Whoever is elected needs to know that privacy is something that all Canadians value.

Thursday, May 19, 2011

Tories plan to ram internet surveillance law through Parliament

I've ranted about this many times before, but it appears that the newly-elected Conservative government will include the so-called "lawful access" provisions in the omnibus crime bill they plan to shepherd quickly through parliament.

I couldn't agree more with Michael Geist (see below) that doing so is extremely problematic. The proposed provisions would give police and national security agents vastly expanded access to information about customers of telecommunications companies and internet service providers (that's everyone in Canada) even in the absence of any sort of investigation. This needs serious debate and should not be tucked into and camouflaged by other legislative initiatives.

Check out Michael's most recent op-ed on this topic: Tories aim to heighten web-surveillance powers.

Monday, April 11, 2011

Canadian police state legislation needs closer examination

I try not to get too opinionated on this blog, but there are some things I feel strongly about. One thing is the ability of people to live their lives (online and off) free of state surveillance and intrusion unless an impartial judge decides that the balance needs to be shifted in favour of the state.

When the recent election was called, a bill fell off the order paper that would remove the impartial judge and put significant surveillance powers it the hands of the state. (In fairness, I have to say that this was originally conceived under the previous Liberal goverment, but is currently part of the Conservative Party's law and order platform that they say will be passed within 100 days if they win a majority (Conservative majority would pass lawful access [laws] within 100 days)). One Bill in particular needs a full airing and thorough debate. It was introduced in the last session and never made it past first reading. This means there was no debate and no scrutiny of any kind.

Here's why Bill C-52 - An Act regulating telecommunications facilities to support investigations needs much closer examination.

Section 16 of the Bill requires all telecommunication service providers to hand over enormous quantities of customer information to the police, CSIS or the competition cops. There is no limit on the amount of information to be provided and is only restricted to "duties" of the cops or intelligence agency.

The provisions, at least as they appeared in Bill C-52, read as follows:

OBLIGATIONS CONCERNING SUBSCRIBER INFORMATION

16. (1) Every telecommunications service provider must provide a person designated under subsection (3), on his or her written request, with any information in the service provider’s possession or control respecting the name, address, telephone number and electronic mail address of any subscriber to any of the service provider’s telecommunications services and the Internet protocol address, mobile identification number, electronic serial number, local service provider identifier, international mobile equipment identity number, international mobile subscriber identity number and subscriber identity module card number that are associated with the subscriber’s service and equipment.

(2) A designated person must ensure that he or she makes a request under subsection (1) only in performing, as the case may be, a duty or function

(a) of the Canadian Security Intelligence Service under the Canadian Security Intelligence Service Act;

(b) of a police service, including any related to the enforcement of any laws of Canada, of a province or of a foreign jurisdiction; or

(c) of the Commissioner of Competition under the Competition Act.

(3) The Commissioner of the Royal Canadian Mounted Police, the Director of the Canadian Security Intelligence Service, the Commissioner of Competition and the chief or head of a police service constituted under the laws of a province may designate for the purposes of this section any employee of his or her agency, or a class of such employees, whose duties are related to protecting national security or to law enforcement.

(4) The number of persons designated under subsection (3) in respect of a particular agency may not exceed the greater of five and the number that is equal to five per cent of the total number of employees of that agency.

(5) The Commissioner of the Royal Canadian Mounted Police and the Director of the Canadian Security Intelligence Service may delegate his or her power to designate persons under subsection (3) to, respectively, a member of a prescribed class of senior officers of the Royal Canadian Mounted Police or a member of a prescribed class of senior officials of the Canadian Security Intelligence Service.

17. (1) A police officer may request a telecommunications service provider to provide the officer with the information referred to in subsection 16(1) in the following circumstances:

(a) the officer believes on reasonable grounds that the urgency of the situation is such that the request cannot, with reasonable diligence, be made under that subsection;

(b) the officer believes on reasonable grounds that the information requested is immediately necessary to prevent an unlawful act that would cause serious harm to any person or to property; and

(c) the information directly concerns either the person who would perform the act that is likely to cause the harm or is the victim, or intended victim, of the harm.

The police officer must inform the telecommunications service provider of his or her name, rank, badge number and the agency in which he or she is employed and state that the request is being made in exceptional circumstances and under the authority of this subsection.

Let me break this down: Any designated police officer or CSIS agent can ask a telecommunications service provider to hand over any of the following information about a customer:

  • name,
  • address,
  • telephone number,
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number.

This goes well beyond the usual scenario of when the cops have an IP address of someone suspected of online child exploitation and want the customer name and address information. But the bill doesn't say that if the cops have X info, they can get Y subscriber data. Instead, it just says on request the telco has to hand over the entire laundry list of data on customers. This is without a warrant, without a production order and without any court oversight at all. Unlike wiretap laws where stats have to be released, there is no obligation on the part of the police or the ministers responsible to release information about how these powers are used and under what circumstances. The Privacy Commissioner gets to audit it, but I don't think this saves any of the problems with the Bill.

The Bill contained no limitation on what level of investigation was required. It isn't limited to serious crimes or even trivial crimes. It is not limited to criminal or national security investigations. All that's necessary is that it be connected with the cop's duties. Collecting parking tickets fit within that category.

Think about what this means, given the laundry list of data to be provided with no threshold of probable cause or even a real investigation. The police can scan the airwaves at a protest and identify the IMEIs of the mobile phones in the vicinity. One request to the telcos can get the names and addresses of virtually everyone who was there. I bet the Egyptian authorities would have loved to have done this in Tahrir Square. Next time there's a G-20 protest in Canada, the police can do this, too.

There is no limitation in the statute that would prevent the police from asking for all the above data for any subscribers who connected, for example, to any cell site in a particular neighbourhood at a particular time.

In Canada, we expect that we can generally live our lives free of government surveillance and intrusion, unless an independent judge says that the government interest in crime fighting outweighs our individual right to privacy. This legislation would remove this balance and tips the scales dramatically toward police state powers.

Monday, February 28, 2011

Tracking Internet miscreants

A growing portion of my practice is working with the litigators in my firm on cases of online torts, including defamation and harassment. This mainly involves working to track down people who do harmful things under a veil of supposed internet anonymity. This includes people who hide behind pseudonyms on chat boards and other internet fora while saying defamatory things in addition to the (apparently) growing problem of creating fake Facebook profiles in order to harass and bully others. We've dealt with similar situations involving online dating sites, where people have set up fake profiles in the names of the victims in order to harass them.

I'm not sure about the psychology behind this, but it certainly appears as though many people feel free to say things about others on the internet that they would never say in "public" or to the person's face. Others, bullies in particular, see the internet as a great place to extend their activities, often with very harmful results.

Some of the cases I've worked on have become well-publicized in this region, and I was asked by the Canadian Bar Association - New Brunswick Branch to present on the topic at their annual Mid-Winter Meeting. In case you're interested, below is a presentation on what sorts of tracks people leave online and how they can be assembled and used to try to identify otherwise unnamed defendants. In almost all cases, they involve applying to the court for Norwich orders, which is a form of order from the court to require a mostly uninvolved third-party to provide information that will lead to the identification of the actual defendant. The court, acting as the gatekeeper, needs to balance the interests of the plaintiff who is looking for a remedy against the interests of both the third party service provider and the unnamed defendant. In short, the court should not allow a fishing expedition, nor should it allow the disclosure if the claim is not reasonably well established. Only if the plaintiff is able to satisfy the following test will the court order disclosure:

(1) the applicant must establish a bona fide claim against the unknown alleged wrongdoer;

(2) the third party against whom discovery is sought must be in some way connected to or involved in the misconduct;

(3) the third party must be the only practical source of the information available to the applicant;

(4) the third party must be reasonably compensated for expenses and legal costs arising out of compliance with the discovery order; and

(5) the public interest in favour of disclosure must outweigh the legitimate privacy interests.

Here is the presentation I gave to the Canadian Bar Association New Brunswick's Mid-Winter Meeting:

https://docs.google.com/present/view?id=ddpx56cg_379fgxwmgd4&interval=60

Here are a couple of notable reported cases where we have been successful in obtaining information from third party service providers to identify defendants:

Saturday, January 15, 2011

Investigating and Preventing Criminal Electronic Communications Act bill one step closer to (warrantless) surveillance state

Want to know one reason why the Canadian government's proposed Bill C-52, referred to as the Investigating and Preventing Criminal Electronic Communications Act, is so horrible? Just look at what recently happened in Belarus. According to Boing Boing (Report: Belarusian mobile operators gave police list of demonstrators - Boing Boing), mobile operators in that country have cooperated with the secret police to identify people who were present at an anti-government demonstration. Shocking.

Bill C-52 gives the same tools to the Canadian secret and not-quite-secret police. Section 16 of Bill C-52 requires all telecommunciations service providers to hand over enormous quantities of customer information to the police, CSIS or the competition cops. There is no limit on the amount of information to be provided and is only restricted to "duties" of the cops or intelligence agency. In addition, the law just says that the following information has to be provided:

  • name,
  • address,
  • telephone number,
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number.

Usually, the cops say they need help chasing down a customer name and address when they have an IP address, but the bill doesn't say that if the cops have X info, they can get Y subscriber data. Instead, it just says on request the telco has to hand over the entire laundry list of data on customers. And this is without a warrant or any sworn justification of any kind. Unlike wiretap laws where stats have to be released, there is no obligation on the part of the police or the ministers responsible to release information about how these powers are used and under what circumstances.

If the police are able to scan the airwaves at a protest and pick out the IMEIs of all the phones present, telcos would have to hand over a list of all the names, addresses, etc of their customers upon request. I can't really see a limitation in the statute that would prevent the police from asking for all the above data for any subscribers who connected, for example, to any cell site in a particular neighbourhood at a particular time. How handy would that be to track down everyone who was present near the G-20 protests in Toronto.

If we're shocked at what repressive regimes are doing to their citizens, we shouldn't be giving our own governments tools to be repressive.

(The good news, if there is any, is that the Bill was introduced on November 1, 2010 and doesn't seem to be going anywhere fast. But don't count it out yet.)

Monday, November 01, 2010

Lawful access back before Parliament

Once again, the Government of Canada has put "lawful access" back before Parliament.

Notice that it again allows for the police and "national security agencies" to require the personal information of telecommunications customers without a warrant.

I will post a link to the bill itself as soon as I can get my hands on it, but in the meantime here's the press release from the Department of Justice:

Government of Canada Introduces Legislation to Fight Crime in Today’s High-Tech World

GOVERNMENT OF CANADA INTRODUCES LEGISLATION TO FIGHT CRIME IN TODAY’S HIGH-TECH WORLD

OTTAWA, November 1, 2010 – The Honourable Rob Nicholson, P.C., Q.C., M.P. for Niagara Falls, Minister of Justice and Attorney General of Canada, together with Dave MacKenzie, M.P. for Oxford and Parliamentary Secretary to the Minister of Public Safety, and Daniel Petit, M.P. for Charlesbourg–Haute-Saint-Charles and Parliamentary Secretary to the Minister of Justice, today re-introduced in the House of Commons two bills that would provide law enforcement and national security agencies with up-to-date tools to fight crimes such as gang- and terrorism-related offences and child sexual exploitation.

“New and evolving technologies provide new ways of committing crimes, making them harder to investigate,” said Minister Nicholson. “We must ensure that law enforcement has the means to bring to justice those who would break the law. Twenty-first-century technology demands twenty-first-century tools for police to effectively investigate crime.”

The proposed Investigative Powers for the 21st Century Act would provide law enforcement agencies with new, specialized investigative powers to help them take action against Internet child sexual exploitation, disrupt on-line organized crime activity and prevent terrorism by:

  • enabling police to identify all the network nodes and jurisdictions involved in the transmission of data and trace the communications back to a suspect. Judicial authorizations would be required to obtain transmission data, which provides information on the routing but does not include the content of a private communication;
  • requiring a telecommunications service provider to temporarily keep data so that it is not lost or deleted in the time it takes law enforcement agencies to return with a search warrant or production order to obtain it;
  • making it illegal to possess a computer virus for the purposes of committing an offence of mischief; and
  • enhancing international cooperation to help in investigating and prosecuting crime that goes beyond Canada’s borders.

“We are giving our police the tools they need to keep up with criminals who are increasingly using new technology in carrying out their crimes. High-tech criminals must be met by high-tech police,” said Mr. MacKenzie. “This announcement once again demonstrates our commitment to give our law enforcement agencies the tools they need to make our communities safer.”

The Investigating and Preventing Criminal Electronic Communications Act would address challenges posed by today’s technologies that did not exist when the legal framework for interception was last updated nearly 40 years ago. The Act would require service providers to include interception capability in their networks, thereby allowing law enforcement and national security agencies to execute authorizations for interception in a more timely and efficient manner with a warrant. The proposed Act also calls for service providers to supply basic subscriber information upon request to designated law enforcement, Competition Bureau and national security officials.

Requirements to obtain court orders to intercept communications will not be changed by this Act. This legislation will simply help ensure that, when warrants are issued, telecommunications companies have the technical ability required to intercept communications for the police and the Canadian Security Intelligence Service.

Other countries, such as the United Kingdom, the United States, Australia, New Zealand, Germany and Sweden, already have similar legislation in place.

“Both of these pieces of legislation will provide vital tools to allow law enforcement officers to trace serious computer crimes such as child pornography and hate crime,” said Mr. Petit. “Both acts help to address Canadians’ privacy concerns by including strict privacy safeguards which, in the case of the Investigative Powers for the 21st Century Act, includes heightened requirements for obtaining judicial authorization before police can obtain data relating to a suspect’s location.”

The Government carefully considered input provided by a broad range of stakeholders in developing these two pieces of legislation, including the telecommunications industry, civil liberties groups, victims’ advocates, police associations and provincial/territorial justice officials. As a result, the Government has ensured that the Investigative Powers for the 21st Century Act and the Investigating and Preventing Criminal Electronic Communications Act adopt a balanced approach, taking full account of the need to protect the safety and security of Canadians, the competitiveness of the telecommunications industry, and the privacy rights of Canadians.

An on-line version of the legislation will be available at www.parl.gc.ca.

Backgrounder: Investigative Powers for the 21st Century Act.

Monday, March 01, 2010

Drawing the curtain on ISP cooperation with law enforcement

My latest posting on slaw.ca:

Drawing the curtain on ISP cooperation with law enforcement – Slaw

I've been a faithful follower of Cryptome for quite some time. Cryptome has been posting very interesting and controversial content on the internet since 1996. It was the first WikiLeaks. Recent readers would note some publications that are very interesting for those who are interested a look at the level of cooperation of between internet service providers and law enforcement. Some of the reaction has been overblown, in my view. Nobody should be surprised that service providers hand over customer information in response to warrants and subpoenaes. Where the law requires it, banks do it, pharmacies do it, libraries do it and credit card companies do it. I think it would be shocking if service providers didn't have policies and procedures for this. What would be more troubling would be the extent to which service providers hand over information in the absence of a lawful requirement.

Most recently, Microsoft served a DMCA notice on Cryptome and its hosting provider, demanding that their Global Criminal Compliance Handbook be removed. Cryptome countered and Microsoft ultimately caved. My personal view is that service providers should make this information public so that customers really understand their digital footprints.

So if you want to see what Facebook, AOL, PayPal, MySpace, AOL and Skype will provide in response to a lawful demand, check out Cryptome.

And for lawyers, these documents will tell you what you can expect to get in response to a lawful demand.

Sunday, December 20, 2009

NB Court orders production of ISP data to litigant

Check out Dan Michaluk's summary of Carter v. Connors, 2009 NBQB 317, in which the New Brunswick Court of Queen's Bench ordered a litigant to obtain from her internet service provider a record of all her internet usage since the accident in issue to produce to the other side: Case Report – Another FaceBook production order made « All About Information.

I would be very surprised (shocked, actually) if the ISP kept a record of websites visited, going back five years.

From the first paragraph of the case:

[1] The Applicant-Defendant has brought a motion for an order that the Plaintiff, who is currently undergoing discovery examination by the Applicant’s counsel, provide an undertaking to have her Internet Service Provider, Bell-Aliant, disclose the history of her Internet use at her home from the date of a motor vehicle accident in 2004 until today. Included in that request is a specific ancillary request that, in the event the motion succeeds, the technician that assembles the Internet use record segregate as a discrete record, if possible, the time spent on the Internet social network site Facebook that may be disclosed in the Plaintiff’s Internet use account record. The Plaintiff has conceded in her examination that she also has an account on the social networking site Facebook. The motion is brought pursuant to Rule 33.12 of The Rules of Court but, practically speaking, under the auspices of Rule 32.06 and 33.08(3) of The Rules of Court.

Monday, October 26, 2009

The future of privacy on the internet

I was honoured to be one of the speakers at the Halifax Internet Town Hall hosted at Dalhousie University this evening, sponsored by the Chebucto Community Net and Dalhousie Student Union. My portion of the proceedings -- surprise -- was about privacy. I only had ten minutes, so needed to be short and sweet.

I decided to focus my presentation on the abomination that is Bill C-47, in particular the provision that allows law enforcement to have wholesale access to customer information without a warrant. It is frankly appalling and should not be allowed to pass.

Look at this provision:

16. (1) Every telecommunications service provider shall provide a person designated under subsection (3), on his or her written request, with any information in the service provider’s possession or control respecting the name, address, telephone number and electronic mail address of any subscriber to any of the service provider’s telecommunications services and the Internet protocol address, mobile identification number, electronic serial number, local service provider identifier, international mobile equipment identity number, international mobile subscriber identity number and subscriber identity module card number that are associated with the subscriber’s service and equipment.

You can disagree on the finer aspects of whether an ISP should be permitted to match an IP address provided by the cops with the customer name and address information in their files. That's a reasonable debate. But I do not see any limitation in Section 16. There's no oversight. There's no real accountability. There's no nuance. All ISPs will be required to provide any (or all) of the following:

  • name,
  • address,
  • telephone number,
  • electronic mail address,
  • Internet protocol address,
  • mobile identification number,
  • electronic serial number,
  • local service provider identifier,
  • international mobile equipment identity number,
  • international mobile subscriber identity number and
  • subscriber identity module card number

It doesn't have to be connected to a child exploitation investigation. Or a parking ticket. In fact, there's no requirement that there be an underlying lawful investigation. The police will be able to hand a list of names to the ISP and require all of the above information, for an unlimited number of targets.

This is appalling legislation and should not stand.

For other postings on this topic, check out my previous postings tagged Lawful Access.

Friday, October 09, 2009

The debate about warrantless access to ISP customer information

Just posted on slaw: The debate about warrantless access to ISP customer information >> Slaw

In the privacy community, there has been a debate over whether it is lawful, under PIPEDA, for a custodian of personal information to provide customer information when then police come knocking. The debate has been most heated in the arena of internet service providers customer names and addresses to the police when presented with an IP address. PIPEDA allows a number of disclosures of personal information without consent pursuant to Section 7(3) of the statute. One exception to the general rule relates directly to law enforcement requests:

Disclosure without knowledge or consent

(3) For the purpose of clause 4.3 of Schedule 1, and despite the note that accompanies that clause, an organization may disclose personal information without the knowledge or consent of the individual only if the disclosure is ...

(c.1) made to a government institution or part of a government institution that has made a request for the information, identified its lawful authority to obtain the information and indicated that
(i) it suspects that the information relates to national security, the defence of Canada or the conduct of international affairs,

(ii) the disclosure is requested for the purpose of enforcing any law of Canada, a province or a foreign jurisdiction, carrying out an investigation relating to the enforcement of any such law or gathering intelligence for the purpose of enforcing any such law, or

(iii) the disclosure is requested for the purpose of administering any law of Canada or a province; [emphasis added]

The debate has raged over differing interpretations of “lawful authority”, and there are conflicting decisions from the Courts over whether internet service providers can disclose customer name and address information to the police in response to a request.

For example, in Re S.C., 2006 ONCJ 343, the court set aside a search warrant that was based on information obtained from an ISP in response to a law enforcement request. In R. v. Kwok, the court found that the customer had a reasonable expectation of privacy in his name and address information and that the police should have obtained a warrant to get this information from the internet service provider. From paragraph 35 of that decision:

"The subscriber, in this case, in my view, and based on my reading of the authorities, has an expectation of privacy in respect of this personal information [name and address]. The investigation of these types of crimes is essential and important, but there must always be the proper balancing of the procedures used by the police and the right of citizens to be free from unreasonable search and seizure. Shortcuts, such as set out in s. 7(3)(c) of PIPEDA in the circumstances of this case must be used with great caution, given the notions of freedom and democracy we come to expect in our community. In my view, the police should have procured a warrant to obtain the subscriber information, that is the name and address of the Applicant, in this case, as I have found the name and address is information from which intimate personal details of lifestyle and choices can be obtained. I therefore find there has been a s. 8 violation."

More recently, in R. v. Ward, 2008 ONCJ 355 (CanLII), the court determined that the customer did not have a reasonable expectation of privacy with respect to this information because the service agreement imposed upon him by Bell’s Sympatico service reduced, if not destroyed, whatever expectation of privacy he might otherwise have had. Similarly, in R. v. Wilson, the court also found no reasonable expectation of privacy.

The pendulum may be swinging the other way. Last week, the Ontario Court of Justice released its decision in R. v. Cuttell. The Court concluded there is a reasonable expectation of privacy in customer account records, but this expectation can be destroyed by an ISP if their service agreement grants them wide latitude to hand over customer information. The judge accepted that a broadly-worded statement in Bell's contract with the customer might supplant the reasonable expectation of privacy but there was no proof brought by the police that the Bell contract applied to this customer. What is perhaps most interesting is that the Judge lamendted the fact that the increasing use of "we will disclose" language in ISP contracts tilt the balance of privacy away from individuals toward the police, without the ability of the Courts to impartially consider what is reasonable in the circumstances.

All of this may become moot (and then some!) thanks to currently pending legislation. Bill C-47, entitled Technical Assistance for Law Enforcement in the 21st Century Act, is about to come up for committee review in parliament. Introduced along with Bill C-46, Investigative Powers for the 21st Century Act, both bills represent a significant shift in the powers of law enforcement. Though marketed as updating current police powers to keep pace with technology, C-47 would give law enforcement virtually unfettered access to customer information from internet and telecommunications service providers without any judicial oversight. The particular provision is at Section 16:

Provision of subscriber information

16. (1) Every telecommunications service provider shall provide a person designated under subsection (3), on his or her written request, with any information in the service provider’s possession or control respecting the name, address, telephone number and electronic mail address of any subscriber to any of the service provider’s telecommunications services and the Internet protocol address, mobile identification number, electronic serial number, local service provider identifier, international mobile equipment identity number, international mobile subscriber identity number and subscriber identity module card number that are associated with the subscriber’s service and equipment.

I am of the view that there should be appropriate judicial oversight of any regime in which service providers are required to identify their users to law enforcement officials. (Subject to exceptions in exigent circumstances.) It is only with judicial oversight that society can be assured that the appropriate balance between privacy and public safety is maintained. The government’s proposal provides no oversight and the powers of law enforcement are completely unfettered. If the concern is that search warrants are too time consuming, then appropriate resources should be put in place to provide for rapid review by independent judicial officers. Removing all the stops from law enforcement powers it not appropriate in this case.

Currently there is a disparity of practices among telecommunication service providers and internet service providers across Canada when dealing with a request from a law enforcement agent to provide a customer name and address connected with a specific IP address. This is due to at least a measure of uncertainty in interpreting the service provider’s obligations under the Personal Information Protection and Electronic Documents Act. Most ISPs will provide customer name and address information if law enforcement officers make a written request in the course of investigation related to child exploitation. In other sorts of investigations, a search warrant is required. Other internet service providers require a search warrant in all circumstances to disclose this information.

For example, Clause 16 as drafted does much more than impose the obligation for service providers to carry out a “reverse look-up” to match one piece of information (such as an IP address) with customer billing information. Instead, it would require the service provider to give law enforcement a laundry list of information in response to any request. This sort of information would be IP address, mobile identification number, electronic serial number, phone number, equipment identifiers and others. This, on its face, goes beyond what law enforcement has been asking for, at least in public.

This power is not subject to meaningful review and is completely unfettered. There is no restriction on the circumstances under which these powers can be used. Currently, requests of this nature generally relate to child exploitation investigations or compelling national security/public safety matters. As drafted, law enforcement would be able to use these powers in connection with parking violations and very minor concerns. In fact, these powers could be used in the complete absence of a lawful investigation. In addition, there is no limitation whatsoever on the volume of these sorts of requests. It would be possible for a law enforcement agency to require the name, address, e-mail address and IP address of every single one of their customers. I think most would say this goes over the line.

It has been said before that a customer’s name and address is not “personal information” or if it is, it is not sensitive information. That misses the point. A customer’s name and address, when connected with an IP address or a mobile phone serial number, is never used in isolation. It is always connected with other information relating to that individual’s behaviours or activities. An individual citizen can carry on their “offline” life in relative anonymity without having to produce identification every time they visit a store or look at a particular book in a library. The realities of network communications mean that every activity undertaken by an individual on the internet, lawful or not, leaves a record of that individual’s IP address. The only protection for that individual’s anonymity is that the connection between the IP address and other identifiers can only be made by the telecommunications service provider. Connecting the identity of an individual to his or her online activities amounts to a collection of personal information that should only be done by law enforcement where the circumstances are sufficiently compelling to tilt the balance in favour of law enforcement/public safety. These provisions do not maintain the traditional balance as has developed in Canada under the Charter and in fact go dramatically and unreasonably in favour of law enforcement.

I've been surprised that discussion of this topic has mostly been contained within the privacy community and hope that the upcoming parliamentary hearings on C-46/C-47 will bring the debate into the wider community, where it belongs.

Thursday, October 08, 2009

New decision on warrantless access to ISP customer data

A friend just provided me with a copy of a recent decision of the Ontario Court of Justice considering the admissibility of information obtained without a warrant from the suspect's internet service provider, Bell. R. v. Cuttell is not on CanLii yet, but I've put a copy here.

The Court concluded there is a reasonable expectation of privacy in your account records, but this expectation can be destroyed by your ISP if their service agreement grants them wide latitude to hand over customer information. The judge accepts that a broadly-worded statement in Bell's contract with the customer might supplant the reasonable expectation of privacy. (I would also question whether a form contract that the customer likey has not read would be enough to mean that subjectively there is no reasonable expectation of privacy.)

In this case, there was no proof brought by the police that the Bell contract applied to this customer so a Charter breach was found.

The Court importantly notes that PIPEDA does not give the police the right to seek information and rejects every crown argument that the police may have had "lawful authority" in the circumstances.

But, in the end, the records were admissible as the police acted in good faith.

What is perhaps most interesting is that the Judge laments the fact that the increasing use of "we will disclose" language in ISP contracts tilt the balance of privacy away from individuals toward the police, without the ability of the Courts to impartially consider what is reasonable in the circumstances.

Thursday, June 18, 2009

Lawful access to ISP subscriber information reintroduced

The Minister of Justice is having a press conference as I type this, unveiling among other things, "lawful access" to telecommunications customers' idenfitying information without a warrant. Stay tuned for more details.


Update: Here's the media release from the government:

Government Of Canada Introduces Legislation To Fight Crime In The 21st Century

OTTAWA, June 18, 2009 – The Honourable Rob Nicholson, P.C., Q.C., M.P. for Niagara Falls, Minister of Justice and Attorney General of Canada, together with the Honourable Peter Van Loan, P.C., Q.C., M.P. for York-Simcoe, Minister of Public Safety, and Mr. Daniel Petit, M.P. for Charlesbourg-Haute-Saint-Charles, Parliamentary Secretary to the Minister of Justice today introduced in the House of Commons two separate pieces of legislation that will ensure law enforcement and national security agencies have the tools they need to fight crime and terrorism in today’s high-tech environment.

“Evolving communications technologies like the Internet, cell phones, and PDAs (personal digital assistants) clearly benefit Canadians in their day-to-day lives,” said Minister Nicholson. “Unfortunately, these technologies have also provided new ways of committing crimes such as distributing child pornography. We must ensure investigators have the necessary powers to trace and ultimately stop crimes.” While technology has advanced rapidly in the past two decades, law enforcement and national security agencies have faced increased difficulty in protecting the safety and security of Canadians. The Investigative Powers for the 21st Century (IP21C) Act will ensure that law enforcement officials have the tools they need to fight crime in today’s modern environment by updating certain existing offences as well as creating new investigative powers to effectively deal with crime in today’s computer and telecommunications environment.

“We must provide our law enforcement with the tools they need to keep our communities safe,” said Minister Van Loan. “High tech criminals will be met by high tech police. This is a great day for the victims and their families who have been long calling for these legislative changes, and those who work tirelessly every day to ensure that when there is a threat to safety police can intervene quickly.”

The Technical Assistance for Law Enforcement in the 21st Century Act will require service providers to include interception capability in their networks. Requirements to obtain court orders to intercept communications will not be changed by this Act, which will require service providers to supply basic subscriber information to law enforcement agencies and the Canadian Security Intelligence Service on request. Other countries, such as the United Kingdom, the United States, Australia, New Zealand, Germany and Sweden, already have similar legislation in place.

“The safety of our citizens, both in our communities and in cyberspace, is a responsibility that this Government takes very seriously,” said Mr. Petit. “The proposed legislation strikes an appropriate balance between the investigative powers used to protect public safety and the necessity to safeguard privacy and the rights and freedoms of Canadians.”

The Government carefully considered input provided by a broad range of stakeholders in developing these two pieces of legislation, including the telecommunications industry, civil liberties groups, victims’ advocates, police associations and provincial/territorial justice officials. As a result, the Government has ensured that the Investigative Powers for the 21st Century (IP21C) Act and theTechnical Assistance for Law Enforcement in the 21st Century Act strike an appropriate balance between the need to protect the safety and security of Canada, the competitiveness of the telecommunications industry, and the privacy rights of Canadians.

An online version of the legislation will be available at http://www.parl.gc.ca/.

See also:

Technical Assistance for Law Enforcement in the 21st Century Act

Investigative Powers for the 21st Century (IP21C) Act -->

Information:

Darren Eke Press Secretary Office of the Minister of Justice 613-992-4621

Media Relations Department of Justice 613-957-4207

Media Relations Public Safety Canada 613-991-0657

Here is the government's summary of the warrantless access to customer information provisions:

Technical Assistance for Law Enforcement in the 21st Century Act

Subscriber Information Component

Police forces and CSIS also require timely access to basic subscriber information as it is an essential tool for fighting crime and terrorism. Subscriber information refers to basic identifiers such as name, address, telephone number and Internet Protocol (IP) address, e-mail address, service provider identification and certain cell phone identifiers. These basic identifiers are often crucial in the early stages of an investigation, and without this basic information, police forces and CSIS often reach a dead-end as they are unable to obtain sufficient information to pursue an investigative lead or obtain a warrant.

Currently, there is no legislation specifically designed to require the provision of this information to police forces and CSIS in a timely fashion. As a result, the practices of releasing this information to police forces and CSIS vary across the country: some service providers release this information to law enforcement immediately upon request; others provide it at their convenience, often following considerable delays; while others insist on law enforcement obtaining search warrants before the information is disclosed. This lack of national consistency and clarity can delay or block investigations.

A consistent, balanced, well-regulated and accountable solution is needed for law enforcement and CSIS to obtain basic subscriber information in order to protect the public’s safety and security, while safeguarding individual privacy interests. The Act will accomplish this by compelling all service providers to release this information and creating an administrative model that provides for a reporting regime which ensures accountability by including consisting of a number of new, privacy-related safeguards. Safeguards include such things as the designation of a limited number of law enforcement and CSIS officials who can request information, record keeping, and both internal audits and external oversight.

This legislation provides law enforcement and CSIS with the updated tools needed in the face of rapidly changing technology, while providing maximum flexibility for industry, and creating rigorous safeguards to protect privacy. In doing so, this legislation strikes an appropriate balance between the needs of law enforcement and CSIS, the competitiveness of industry, and the privacy rights of Canadians.

Monday, April 06, 2009

European internet firms must start logging communications as of today

As of today, all internet service providers in Europe are required by law to retain information about every e-mail and VOIP call made by their users thanks to the European Data Retention Directive.

BBC NEWS Technology Net firms start storing user data

Details of user e-mails and net phone calls will be stored by internet service providers (ISPs) from Monday under an EU directive.

The plans were drawn up in the wake of the London bombings in 2005.

ISPs and telecoms firms have resisted the proposals while some countries in the EU are contesting the directive.

Jim Killock, executive director of the Open Rights Group, said it was a "crazy directive" with potentially dangerous repercussions for citizens.

All ISPs in the European Union will have to store the records for a year. An EU directive which requires telecoms firms to hold on to telephone records for 12 months is already in force.

The data stored does not include the content of e-mails or a recording of a net phone call, but is used to determine connections between individuals.

Authorities can get access to the stored records with a warrant.

Governments across the EU have now started to implement the directive into their own national legislation.

The UK Home Office, responsible for matters of policing and national security, said the measure had "effective safeguards" in place.

There is concern that access to our data is widening to include many public bodies ISPs across Europe have complained about the extra costs involved in maintaining the records. The UK government has agreed to reimburse ISPs for the cost of retaining the data.

Mr Killock said the directive was passed only by "stretching the law".

The EU passed it by "saying it was a commercial matter and not a police matter", he explained.

"Because of that they got it through on a simple vote, rather than needing unanimity, which is required for policing matters," he said.

Sense of shock

He added: "It was introduced in the wake of the London bombings when there was a sense of shock in Europe. It was used to push people in a particular direction."

Sweden has decided to ignore the directive completely while there is a challenge going through the German courts at present.

"Hopefully, we can see some sort of challenge to this directive," said Mr Killock.

Isabella Sankey, Policy Director at Liberty, said the directive formalised what had already been taking place under voluntary arrangement for years.

"The problem is that this regime allows not just police to access this information but hundreds of other public bodies."

In a statement, the Home Office said it was implementing the directive because it was the government's priority to "protect public safety and national security".

It added: "Communications data is the where and when of the communication and plays a vital part in a wide range of criminal investigations and prevention of terrorist attacks, as well as contributing to public safety more generally.

"Without communications data resolving crimes such as the Rhys Jones murder would be very difficult if not impossible.

"Access to communications data is governed by the Regulation of Investigatory Powers Act 2000 (Ripa) which ensures that effective safeguards are in place and that the data can only be accessed when it is necessary and proportionate to do so."

And, as an aside, I'm not sure many will find comfort in the idea that RIPA will act to protect privacy: RIPA surveillance may break human rights laws - ZDNet.co.uk.