Feeds

EU Data retention directive 'flawed, unlawful'

Lib Dem and digital rights group have privacy gripes

Choosing a cloud hosting partner with confidence

European state powers to retain data about customers’ telecommunications are set to come in for a kicking with the release of an offical report from the European Commission.

The report, due out this afternoon, is expected to evaluate and gently prod the Commission towards taking further steps to harmonising existing legislation (pdf) in this area and ensuring that it does not clash with the basic human right to privacy.

Others, including digital civil rights organisation EDRI and the Lib Dems Home Affairs spokeswoman in the European Parliament Baroness Ludford, are more critical.

According to the official report, which The Register has seen in leaked form only, privacy rights may be subject to limitation where such limitation is "proportionate to the general interest". It is right, the report says, that European states should retain data on telecommunications between their citizens, both as a means to break down barriers to trade and as a proportionate response to international terrorism and serious crime.

The directive as currently agreed applies to the fields of fixed network telephony, mobile telephony, internet access, email and internet telephony. Categories of data that may be retained include the source, destination, date and time of communication, as well as details on the type of equipment used.

The volume of data access requests has been steadily rising, with around two million data access requests made by the 19 European member states in 2008/9. The report notes significant variance between states, with just 100 requests made in Cyprus, against one million – or approximately half of all requests – originating in Poland.

The report concludes that the measures are working fairly well, but that there needs to be further harmonisation, particularly in terms of what is defined as serious crime. It also calls for greater transparency, a reduction in the number of authorities allowed to access data as well as fewer categories retained, and the reimbursement of costs for ISPs and telecoms operators.

EDRI is less sympathetic to the current situation. It has published a shadow report to the Commission evaluation, which takes the view that "over the past five years, the Data Retention Directive has proved to be an unnecessary and unprecedented violation of the fundamental rights of 500 million Europeans".

It adds: "According to the European Data Protection Supervisor, the Directive constitutes "the most privacy invasive instrument ever adopted by the EU."

EDRI, too, recognises the need for greater harmonisation and a broader agreement of what categories of activity might need to be under review. However, they are otherwise unimpressed by the report, accusing the Commission of never having investigated seriously the issues that this directive raises in respect of personal privacy – and of having further ignored key rulings in this area. In particular, it cites the Schecke ruling by the European Court of Justice, which held that "derogations and limitations in relation to the protection of personal data must apply only in so far as is 'strictly necessary'".

Data retention, it concludes, is an "unprecedented violation" of the fundamental rights of European citizens and is "unnecessary" to the fight against crime. It has been imposed on a flawed legal basis – and insufficient safeguards have been instituted in several states.

Closer to home, Liberal Democrat European justice and human rights spokeswoman and London MEP Sarah Ludford told us: "I opposed this directive from the very start, when the then Labour Home Secretary Charles Clarke managed to push it through, ostensibly in the name of counterterrorism. It gave the green light for mass surveillance and possible profiling of the general public.

"The constitutional courts of Germany, the Czech Republic and Romania have all ruled that the national laws implementing the directive were unconstitutional as they breached privacy protection."

"The law needs to be tightened up so that searches can only be conducted for the purpose of combating terrorism and other really serious criminality, and the current maximum data storage period of two years must be significantly reduced." ®

Security for virtualized datacentres

More from The Register

next story
Ex-US Navy fighter pilot MIT prof: Drones beat humans - I should know
'Missy' Cummings on UAVs, smartcars and dying from boredom
Facebook, Apple: LADIES! Why not FREEZE your EGGS? It's on the company!
No biological clockwatching when you work in Silicon Valley
The 'fun-nification' of computer education – good idea?
Compulsory code schools, luvvies love it, but what about Maths and Physics?
Doctor Who's Flatline: Cool monsters, yes, but utterly limp subplots
We know what the Doctor does, stop going on about it already
'Cowardly, venomous trolls' threatened with TWO-YEAR sentences for menacing posts
UK government: 'Taking a stand against a baying cyber-mob'
Happiness economics is bollocks. Oh, UK.gov just adopted it? Er ...
Opportunity doesn't knock; it costs us instead
Sysadmin with EBOLA? Gartner's issued advice to debug your biz
Start hoarding cleaning supplies, analyst firm says, and assume your team will scatter
Don't bother telling people if you lose their data, say Euro bods
You read that right – with the proviso that it's encrypted
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.