Original URL: http://www.theregister.co.uk/2008/04/17/ripa_phorm_shambles/
The government has refused to investigate BT's covert wiretapping of thousands of its customers in 2006 and 2007, despite its own expert's view that without consent Phorm's advertising targeting technology is a breach of criminal law.
Whitehall's willingness to turn a blind eye to the fact that tens of thousands of people were spied on by big business in order to serve up targeted marketing has angered web users. "I'm absolutely sickened and appalled," Pete John, who has tried to interest authorities, told The Register this week.
BT customers who have attempted to report the secret listening and profiling experiments to the police have been told to approach the Home Office. One was subsequently told over email by an official: "It is important to remember that private companies such as ISPs are allowed to do certain things under section 3 of [the Regulation of Investigatory Powers Act] that Law Enforcement Agencies cannot do without permission."
The Home Office advice to BT and Phorm meanwhile, written by civil servant Simon Watkin (http://cryptome.org/ho-phorm.htm), says a proposed Phorm deployment may be legal under RIPA only if consent is obtained.
BT and Phorm did not obtain any consent for either the autumn 2006 or the summer 2007 trial. The technical report on the earlier secret wiretap states: "The customers who participated in the trial were not made aware of this fact as one of the aims of the validation was not to affect their experience."
The pair claim the two trials were legal under UK law, but refuse to provide any explanation as to why. BT says it doesn't know which of its customers it co-opted into the system.
A Home Office spokesman told The Register yesterday that responsibility for infringements of the Regulation of Investigatory Powers Act 2000 (RIPA) lies with the the Investigatory Powers Tribunal (http://www.ipt-uk.com/default.asp).
However, the tribunal only has powers to investigate eavesdropping carried out on behalf of law enforcement, not commerce. Its website states (http://www.ipt-uk.com/default.asp?sectionID=2): "The tribunal has no jurisdiction to investigate complaints about private individuals or companies unless you believe they are acting on behalf of an intelligence agency, law enforcement body or other public authority covered by RIPA."
Liberal Democrat shadow culture, media and sport secretary Don Foster blasted the Home Office's brick wall stance today. "It is clear the government is completely confused over who has responsibility for this matter. The Information Commissioner's Office and the public have expressed considerable concerns and it is time for the Government to stop passing the buck and deal with the matter immediately," he said.
"The Home Office needs to step up to the plate and decide whether BT's secret technical tests were legal and, if not, decide what will be done about them."
Foster is meeting BT executives next week to question them on the trials.
The Information Commissioner's Office (ICO) is meanwhile investigating the tests for alleged breaches of the Data Protection Act and Privacy and Electronic Communications Regulations, but not the alleged criminal wiretap under RIPA. The ICO's work is based on a complaint from Stephen Mainwaring, the BT Business customer in Weston-super-Mare that we revealed (http://www.theregister.co.uk/2008/03/17/bt_phorm_lies/) was misled by his ISP over its involvement with Phorm last summer.
In its broad public statement on Phorm (http://www.ico.gov.uk/about_us/news_and_views/current_topics/phorm_webwise_and_oie.aspx), the ICO also referred the question of an illegal interception under RIPA to the Home Office. It wrote: "The Home Office is responsible for compliance with RIPA, and Phorm has approached the office directly and had a written response."
But as we've seen, that response referred to a proposed deployment, not historical secret interceptions. The internet legal think tank FIPR has described the RIPA case against the trials as "clear cut".
The Home Office's spokesman, however, disavowed any responsibility for holding the pair to account for eavesdropping on what is now known (http://www.theregister.co.uk/2008/04/14/bt_phorm_2007/) to be between 38,000 and 108,000 customers. "The tribunal is there for people who have a complaint," he said. We pointed out that the interception tribunal only has jurisdiction over law enforcement. The Home Office refused to say where people can go to report that they believe they have been illegally eavesdropped upon by a company.
The spokesman repeatedly said the Home Office "has made a statement and won't be adding to it".
Pete John raged: "BT and Phorm seem to be above the law. No one wants responsibility for enforcing complaints against ISPs. ICO say the Home Office. The Police say the Home Office. The Home Office say they have no investigative role." ®
UK.gov misses deadline on EU Phorm probe (12 August 2008)
http://www.theregister.co.uk/2008/08/12/eu_phorm_letter/
Phorm failed to mention 'illegal' trials at Home Office meeting in 2007 (18 June 2008)
http://www.theregister.co.uk/2008/06/18/home_office_phorm_meetings/
EU mulls intervention over BT's secret Phorm trials (10 June 2008)
http://www.theregister.co.uk/2008/06/10/eu_bt_phorm_trial/
Phorm opponents to picket BT shareholders (30 May 2008)
http://www.theregister.co.uk/2008/05/30/bt_agm_phorm_protest/
Activist coders aim to deafen Phorm with white noise (16 May 2008)
http://www.theregister.co.uk/2008/05/16/antiphormlite/
Union gears up for BT strike action this month (15 May 2008)
http://www.theregister.co.uk/2008/05/15/bt_connect_strike/
Virgin Media distances itself from Phorm 'adoption' claims (1 May 2008)
http://www.theregister.co.uk/2008/05/01/virgin_media_phorm_misleading/
Spy regs used against dogs, litterbugs (28 April 2008)
http://www.theregister.co.uk/2008/04/28/ripa_council_dog_fouling/
Anti-Spyware Coalition probes data pimping (25 April 2008)
http://www.theregister.co.uk/2008/04/25/apc_to_probe_behaviorial_ad_firms/
Home Office defends 'dangerously misleading' Phorm thumbs-up (24 April 2008)
http://www.theregister.co.uk/2008/04/24/home_office_phorm_fipr_bt/
Six months on from HMRC, data losses still rising, says ICO (22 April 2008)
http://www.theregister.co.uk/2008/04/22/ico_data_loss_rollcall/
BT's 'illegal' 2007 Phorm trial profiled tens of thousands (14 April 2008)
http://www.theregister.co.uk/2008/04/14/bt_phorm_2007/
American ISPs already sharing data with outside ad firms (10 April 2008)
http://www.theregister.co.uk/2008/04/10/american_isps_embrace_behavioral_ad_targeting/
Information Commissioner: Phorm must be opt-in only (9 April 2008)
http://www.theregister.co.uk/2008/04/09/ico_phorm_tougher/
Phorm admits 'over zealous' editing of Wikipedia article (8 April 2008)
http://www.theregister.co.uk/2008/04/08/phorm_censors_wikipedia/
FIPR: ICO gives BT 'green light for law breaking' with Phorm (7 April 2008)
http://www.theregister.co.uk/2008/04/07/bt_phorm_ico/
BT: 'We did not let anyone down over Phorm... it was not illegal' (3 April 2008)
http://www.theregister.co.uk/2008/04/03/bt_phorm_interview/
BT and Phorm secretly tracked 18,000 customers in 2006 (1 April 2008)
http://www.theregister.co.uk/2008/04/01/bt_phorm_2006_trial/
The Guardian ditches Phorm (26 March 2008)
http://www.theregister.co.uk/2008/03/26/guardian_phorm_uturn/
Phorm agrees to independent inspection of data pimping code (19 March 2008)
http://www.theregister.co.uk/2008/03/19/phorm_8020_pi/
Net think thank: Phorm is illegal (17 March 2008)
http://www.theregister.co.uk/2008/03/17/phorm_fipr_illegal/
BT admits misleading customers over Phorm experiments (17 March 2008)
http://www.theregister.co.uk/2008/03/17/bt_phorm_lies/
Top security firm: Phorm is adware (12 March 2008)
http://www.theregister.co.uk/2008/03/12/phorm_av_vendors/
Dear ISP, I am not a target market (10 March 2008)
http://www.theregister.co.uk/2008/03/10/isps_phorm_comment_target_market/
BT targets 10,000 data pimping guinea pigs (5 March 2008)
http://www.theregister.co.uk/2008/03/05/bt_phorm_trial/
The Phorm files (29 February 2008)
http://www.theregister.co.uk/2008/02/29/phorm_roundup/
How Phorm plans to tap your internet connection (29 February 2008)
http://www.theregister.co.uk/2008/02/29/phorm_documents/
BT pimped customer web data to advertisers last summer (27 February 2008)
http://www.theregister.co.uk/2008/02/27/bt_phorm_121media_summer_2007/
ISP data deal with former 'spyware' boss triggers privacy fears (25 February 2008)
http://www.theregister.co.uk/2008/02/25/phorm_isp_advertising/
© Copyright 2008