Feeds

Busting net neutrality may amount to spying, says EU

Eurocrat warns of 'massive, real-time inspection of comms'

Top three mobile application threats

Gather data only for 'explicit and legitimate' purposes

Under the EU's Data Protection Directive organisations must ensure that they process personal data fairly and lawfully, and that it is collected for "specified, explicit and legitimate purposes" that are "adequate, relevant and not excessive in relation to the purposes".

Organisations must also ensure that any personal information they keep is "kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed," the Data Protection Directive states.

Hustinx said that regulatory guidance was needed and that it should determine "the inspection practices that are legitimate to ensure the smooth flow of traffic which may not require users' consent, such as, for example, the fight against spam.

"In addition to the intrusiveness of the monitoring applied, aspects such as, for example, the level of disturbance to the smooth flow of traffic that would otherwise occur, are relevant," he said.

Hustinx said the guidance should also explain to ISPs "which inspection techniques can be carried out for security purposes, which may not require users' consent" and explain "when monitoring requires individual's consent, notably the consent of all the users concerned, and the permissible technical parameters to ensure that the inspection technique does not entail processing of data that is not proportionate vis-à-vis its intended purposes".

Hustinx said that ISPs may need users' freely given, explicit, informed consent to conduct some inspection of their personal data when conducting some traffic management on their services, such as "to monitor and filter the communications of individuals for the purposes of limiting (or allowing) access to certain applications and services such as [file-sharing] and VoIP".

This consent can only be considered to be given if users take "affirmative action" to give it, Hustinx said.

"Consent must be free, explicit and informed. It should be indicated through an affirmative action," Hustinx said.

'Meaningful' consent

"These requirements put strong emphasis on the need to step up the efforts to ensure that individuals are properly informed, in a way that is direct, understandable and specific so that they can assess the effects of the practices and ultimately make an informed decision," he said. "Given the complexity of these techniques, giving meaningful prior information to users is one of the main challenges to obtain valid consent. Besides, there should be no detrimental consequences (including financial costs) towards users who do not consent to any monitoring."

ISPs must also consider whether it is proportionate to view personal information for the purposes of traffic management, Hustinx said.

"The proportionality principle plays a crucial role when ISPs engage in traffic management policies, whatever the legal ground for processing and the purpose: delivering the service, avoiding congestion or providing targeted subscriptions with or without access to certain services and applications," Hustinx said.

"This principle limits ISPs ability to engage in monitoring of the content of individual's communications that entail processing of excessive information or accruing benefits for ISPs only. What can logistically be performed by ISPs will depend on the level of intrusion of the techniques, the results required (for which they may accrue benefits) and the specific privacy and data protection safeguards applied. Prior to deploying inspection techniques, ISPs must engage in an assessment of whether these comply with the proportionality principle," he said.

Copyright © 2011, OUT-LAW.com

OUT-LAW.COM is part of international law firm Pinsent Masons.

Securing Web Applications Made Simple and Scalable

More from The Register

next story
Yorkshire cops fail to grasp principle behind BT Fon Wi-Fi network
'Prevent people that are passing by to hook up to your network', pleads plod
Major problems beset UK ISP filth filters: But it's OK, nobody uses them
It's almost as though pr0n was actually rather popular
Microsoft unsheathes cheap Android-killer: Behold, the Lumia 530
Say it with us: I'm King of the Landfill-ill-ill-ill
All those new '5G standards'? Here's the science they rely on
Radio professor tells us how wireless will get faster in the real world
Apple orders huge MOUNTAIN of 80 MILLION 'Air' iPhone 6s
Bigger, harder trouser bulges foretold for fanbois
US freemium mobile network eyes up Europe
FreedomPop touts 'free' calls, texts and data
'Two-speed internet' storm turns FCC.gov into zero-speed website
Deadline for comments on net neutrality shake-up extended to Friday
Oh girl, you jus' didn't: Level 3 slaps Verizon in Netflix throttle blowup
Just hook us up to more 10Gbps ports, backbone biz yells in tit-for-tat spat
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.