Feeds

EU data retention laws 'too costly' for telcos

Flack over anti-terror tax

Business security measures using SSL

EU laws that mean service providers will need to retain communications data for the purposes of possible criminal investigation will place a huge burden on carriers, market watchers warn.

The controversial measures, enacted to aid the fight against terrorism, would compel telecom firms to keep customer email logs, details of internet usage and phone call records for up to two years.

The content of messages isn't covered by the directive, which is designed to harmonise European laws. EU member states have until September 2007 to apply the directive into national laws.

Opposition to the measures has thus far centered on privacy concerns. Critics argue that existing voluntary data retention provisions are sufficient.

But cost, and who pays, is also a factor. The directive doesn't oblige member states to reimburse telecom companies for additional costs incurred in servicing law enforcement requests, a factor highlighted by market analysts Frost & Sullivan in a recent report on the impact of the directive on the telecoms sector.

Service providers and operators need to adapt their systems by the time various national governments implement the European provisions on data retention as law. For example, call detail record (CDR) systems will need to be revamped to cope with the increase in communication and traffic data to be stored and managed. Importantly service providers not previously obligated to retain data will now be governed by the EU Directive stipulations, Frost & Sullivan notes.

"Implementing solutions compliant with the EU Directive on Data Retention will result in an onerous burden on communications service providers and operators," said Frost & Sullivan senior industry analyst Fernando Elizalde. "The provisions of the EU Directive will apply not just to mobile and fixed telephony, but also to Internet telephony, e-mail services and messaging services."

Service providers will be obliged to respond to lawful requests from law enforcement agencies "without undue delay", however the legislation fails to clarify what this might mean in practice.

"The EU Directive introduces the idea of 'without undue delay' as a criterion to measure service providers' responsiveness to requests from law enforcement agencies. However, it is not clear how long the delay can be- interpretations of this criterion vary from minutes to a few hours," Elizalde added.

Marie-Charlotte Patterson, vice president of corporate marketing at records compliance management firm AXS-One, said the need to keep records of millions of private emails or phone calls is hardly a new concept. Although the directive goes much further than keeping records purely for billing purposes, careful planning should help carriers to make the project as painless as possible. There might even be the possibility of using the data to market new services to customers, she added.

"Telecommunication companies need to approach the new legislation in the right manner to ensure that the project meets the new regulatory directives, but also provides some potential value-add to both the customer and carrier. Key to this is, understanding that accurate and timely access of historical records and the ability to securely destroy records at the end of their retention period are as important as retention. So only considering the retention and storage aspects of the requirements are not sufficient," she said. ®

Business security measures using SSL

More from The Register

next story
Brit telcos warn Scots that voting Yes could lead to HEFTY bills
BT and Co: Independence vote likely to mean 'increased costs'
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
Radio hams can encrypt, in emergencies, says Ofcom
Consultation promises new spectrum and hints at relaxed licence conditions
Google+ GOING, GOING ... ? Newbie Gmailers no longer forced into mandatory ID slurp
Mountain View distances itself from lame 'network thingy'
ISPs' post-net-neutrality world is built on 'bribes' says Tim Berners-Lee
Father of the worldwide web is extremely peeved over pay-per-packet-type plans
Vodafone to buy 140 Phones 4u stores from stricken retailer
887 jobs 'preserved' in the process, says administrator PwC
Bonking with Apple has POUNDED mobe operators' wallets
... into submission. Weve squeals, ditches payment plans
Drag queens: Oh, don't be so bitchy, Facebook! Let us use our stage names
Handbags at dawn over free content ad network's ID policy
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.