SlideShare une entreprise Scribd logo
1  sur  21
Investigatory Powers Act
introduction
Graham Smith
SCL Annual Conference
8 June 2017
Background to the Act
Multiple sources -
two main ones
● Bulk interception under RIPA
● Equipment interference (CNE)
2013 - Snowden
2012
Communications
Data Retention
2014
● Digital Rights Ireland (CJEU)
● Data Retention and Investigatory Powers Act
(DRIPA)
2015
"RIPA, obscure since its inception, has been
patched up so many times as to make it
incomprehensible to all but a tiny band of initiates"
"comprehensive and
comprehensible"
Page 8
Overview of #IPAct powers
Overview of #IPAct powers
300 page Act
● Interception warrants
• Bulk, targeted, thematic; Content and ‘secondary’ data
● Equipment interference (hacking) warrants
• Bulk, targeted, thematic; Content and ‘equipment’ data
● Communications data acquisition and disclosure
• Bulk warrants, targeted notices + request filter
● Mandatory communications data retention notices
• Browsing histories (Internet Connection Records)
● Technical capability notices
• E2E encryption
● National security notices
● Bulk personal dataset warrants
Page 10
What? How? Who to? Enforce? Secret?
Warrant
(SoS + JC)
TelOp Crim +
Civ
Crim
Warrant
(SoS [some
LE] + JC)
TelOp UKpers
only, Civ
Crim
Notice
(SoS + JC)
TelOp UKpers
only, Civ
Civ
Notice
(various
authorities)
TelOp Civ Crim
Warrant
(SoS + JC)
TelOp UKpers
only, Civ
Crim
Notice
(SoS + JC)
TelOp
(inc
prospective)
As per
substantive
powers
Yes
Notice
(SoS + JC)
UK
TelOp
UKpers
only, Civ
Yes
Overview of #IPAct powers
Comms Data
Retention
(inc ICRs)
Comms Data
Acquisition
(targeted)(?)
Equipment
interference
(targeted,
thematic)
Encryption
removal
Equipment
interference
(bulk)
Request
filter
(comms data)
Technical
capability
notices
Comms Data
Acquisition
(bulk)
Interception
(targeted,
thematic)
Interception
(bulk)
Interception
(secondary
data)
Equipment
interference
(equipment
data)
National
security
notices
Page 11
What? How? Who by? Purposes?
Warrant
(SoS + JC)
MI5, SIS, GCHQ, MoD, 5 LE bodies,
MLAT
National security;
prevent/detect serious
crime; UK economic well-
being (nat sec-related,
non-BI persons)
Warrant
(SoS + JC)
MI5, SIS, GCHQ; MoD (nat sec only)
Warrant
(LE head + JC)
Police (various), National
Crime Agency
Prevent/detect serious crime,
prevent death, prevent or
mitigate injury/damage to
physical/mental health
Immigration, Revenue/Customs,
Competition/Markets, Police investigations
Prevent/detect serious crime
Warrant
(SoS + JC)
MI5, SIS, GCHQ (overseas-
related main purpose)
National security; national
security and prevent/detect
serious crime, UK economic
well-being (non-BI persons)
Warrant
(SoS + JC)
MI5, SIS, GCHQ
Notice (plus
court order for
local authorities)
Numerous authorities 11 different purposes
Notice (+ JC)
(up to 12 mths)
Secretary of State
Notice
(+ JC)
Secretary of State National security
Warrants, comms data
acquisition notices
Overview of #IPAct powers
Equipment
interference
(targeted,
thematic)
Equipment
interference
(bulk)
Comms Data
Acquisition
(bulk)
Interception
(targeted,
thematic)
Interception
(bulk)
National
security
notices
Technical
capability notices
(inc decryption)
Comms Data
Acquisition
(targeted)(?)
Request
filter
(comms data)
Comms Data
Retention
(inc ICRs)
Page 12
What has changed?
New or not new?
● Explicit powers re-enacted
● Semi-explicit powers (scale of use
hidden) now made explicit
● Opaque powers now made explicit
● Opaque powers still (arguably)
opaque
Interception
(targeted)
Comms Data
Acquisition
(bulk)
Equipment
interference
(targeted,
thematic)
Encryption
removal
Interception
(bulk)
Interception
(thematic)
Equipment
interference
(bulk)
Interception
(related
communications
data)
Page 14
New and extended
Authorisation and oversight – new safeguards
● Judicial Commissioner approval of most warrants and notices
• Except targeted communications data acquisition
- But Watson.
Extended mandatory data retention powers
● Extended to all kinds of communications data
• including Internet Connection Records (site level browsing histories)
● Extended to all kinds of communication (background, IoT)
● Extended to include generation and obtaining data for
retention
● Abolition of 'processed within UK' limitation
● Extended to include private telecommunications operators
Page 15
New and extended
Content-derived metadata
● Interception, equipment interference, BPD warrants.
• Targeted, thematic, bulk
● New power to extract some information from content and
treat as metadata
Page 16
New and extended
Technical capability notices
● Permanent technical capability to assist with warrants and
communications data acquisition notices
● Extended from interception (RIPA) to most powers (IPAct)
● Extended to include private telecommunications operators
• Subject to any limitations in regulations
Draft regulations
● No minimum threshold for communications data acquisition
● Black boxes (communications data acquisition)
● Hacking back door
● End to end encryption?
Page 17
New and extended
New non-disclosure obligations on warrant/notice
recipients
● Criminal (targeted and bulk)
• Interception warrants (59(1), 156(2))
• Equipment interference warrants (134(1), 197)
• Bulk communications data acquisition warrants (174(1))
• Targeted communications data acquisition notices (82(1))
● Civil
• Data retention notices (95(2))
● Indeterminate
• Technical capability notices (255(8))
• National security notices (255(8))
Page 18
Tweaks
● Extraterritoriality
● Content v metadata
● Categories of metadata
● Journalists, MPs, legal privilege
● Interception offence
● etc
Page 19
Timetable
● Data retention partially in force 30 December 2016
• Existing notices continue for max 6 mths
● The rest of the Act?
• New oversight regime
• New warrantry procedures
• ‘Some time … timetable in due course’
Page 20
Graham Smith
graham.smith@twobirds.com
@cyberleagle
Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses.
Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number OC340318 and is authorised and regulated by the
Solicitors Regulation Authority. Its registered office and principal place of business is at 15 Fetter Lane, London EC4A 1JP. A list of members of Bird & Bird LLP and
of any non-members who are designated as partners, and of their respective professional qualifications, is open to inspection at that address.
twobirds.com
Thank you

Contenu connexe

Similaire à SCL Conference 8 June 2017 - Investigatory Powers Act

Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Dione McBride, CISSP, CIPP/E
 
NIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government ContractorsNIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government ContractorsUnanet
 
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...IBM Security
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec
 
Information Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric VanderburgInformation Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric VanderburgEric Vanderburg
 
Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016Graham Smith
 
Isaca new delhi india privacy and big data
Isaca new delhi india   privacy and big dataIsaca new delhi india   privacy and big data
Isaca new delhi india privacy and big dataUlf Mattsson
 
Ip bill issues
Ip bill issuesIp bill issues
Ip bill issuesrcorrigan
 
Understanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: WebinarUnderstanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: WebinarCipherCloud
 
Protect the Unexpected
Protect the UnexpectedProtect the Unexpected
Protect the UnexpectedCharles Mok
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? SecurityScorecard
 
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz PatrickDigital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz PatrickTealium
 
Chapter2
Chapter2Chapter2
Chapter2Pibi Lu
 
Isaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big dataIsaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big dataUlf Mattsson
 
ISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudUlf Mattsson
 
Legal and privacy implications of IoT
Legal and privacy implications of IoTLegal and privacy implications of IoT
Legal and privacy implications of IoTAndres Guadamuz
 
Cross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataCross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataUlf Mattsson
 
Jul 16 isaca london data protection, security and privacy risks - on premis...
Jul 16 isaca london   data protection, security and privacy risks - on premis...Jul 16 isaca london   data protection, security and privacy risks - on premis...
Jul 16 isaca london data protection, security and privacy risks - on premis...Ulf Mattsson
 

Similaire à SCL Conference 8 June 2017 - Investigatory Powers Act (20)

Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
 
NIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government ContractorsNIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government Contractors
 
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year On
 
Information Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric VanderburgInformation Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric Vanderburg
 
Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016
 
Isaca new delhi india privacy and big data
Isaca new delhi india   privacy and big dataIsaca new delhi india   privacy and big data
Isaca new delhi india privacy and big data
 
Ip bill issues
Ip bill issuesIp bill issues
Ip bill issues
 
Understanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: WebinarUnderstanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: Webinar
 
Protect the Unexpected
Protect the UnexpectedProtect the Unexpected
Protect the Unexpected
 
Ignyte - US Sovereign Cloud Computing
Ignyte - US Sovereign Cloud ComputingIgnyte - US Sovereign Cloud Computing
Ignyte - US Sovereign Cloud Computing
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz PatrickDigital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
 
Chapter2
Chapter2Chapter2
Chapter2
 
Isaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big dataIsaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big data
 
ISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloud
 
Legal and privacy implications of IoT
Legal and privacy implications of IoTLegal and privacy implications of IoT
Legal and privacy implications of IoT
 
Cross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataCross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive data
 
Infosec Law (Feb 2006)
Infosec Law (Feb 2006)Infosec Law (Feb 2006)
Infosec Law (Feb 2006)
 
Jul 16 isaca london data protection, security and privacy risks - on premis...
Jul 16 isaca london   data protection, security and privacy risks - on premis...Jul 16 isaca london   data protection, security and privacy risks - on premis...
Jul 16 isaca london data protection, security and privacy risks - on premis...
 

Plus de Graham Smith

BBW v UK - IP Act implications
BBW v UK - IP Act implicationsBBW v UK - IP Act implications
BBW v UK - IP Act implicationsGraham Smith
 
Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018Graham Smith
 
Investigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection AdequacyInvestigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection AdequacyGraham Smith
 
Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017Graham Smith
 
Data Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers ActData Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers ActGraham Smith
 
Internet Jurisdiction Primer
Internet Jurisdiction PrimerInternet Jurisdiction Primer
Internet Jurisdiction PrimerGraham Smith
 
Geoblocking in context
Geoblocking in contextGeoblocking in context
Geoblocking in contextGraham Smith
 
IPBillOversightInsight
IPBillOversightInsightIPBillOversightInsight
IPBillOversightInsightGraham Smith
 
Future-proofing the IPBill
Future-proofing the IPBillFuture-proofing the IPBill
Future-proofing the IPBillGraham Smith
 
Draft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal ViewDraft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal ViewGraham Smith
 
Communications Privacy and the State
Communications Privacy and the StateCommunications Privacy and the State
Communications Privacy and the StateGraham Smith
 
2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law ReviewGraham Smith
 
Right to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-finalRight to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-finalGraham Smith
 
Communications Data Retention by Intermediaries
Communications Data Retention by IntermediariesCommunications Data Retention by Intermediaries
Communications Data Retention by IntermediariesGraham Smith
 
2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law UpdateGraham Smith
 
Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?Graham Smith
 
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...Graham Smith
 
Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?Graham Smith
 
Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?Graham Smith
 

Plus de Graham Smith (19)

BBW v UK - IP Act implications
BBW v UK - IP Act implicationsBBW v UK - IP Act implications
BBW v UK - IP Act implications
 
Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018
 
Investigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection AdequacyInvestigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection Adequacy
 
Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017
 
Data Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers ActData Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers Act
 
Internet Jurisdiction Primer
Internet Jurisdiction PrimerInternet Jurisdiction Primer
Internet Jurisdiction Primer
 
Geoblocking in context
Geoblocking in contextGeoblocking in context
Geoblocking in context
 
IPBillOversightInsight
IPBillOversightInsightIPBillOversightInsight
IPBillOversightInsight
 
Future-proofing the IPBill
Future-proofing the IPBillFuture-proofing the IPBill
Future-proofing the IPBill
 
Draft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal ViewDraft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal View
 
Communications Privacy and the State
Communications Privacy and the StateCommunications Privacy and the State
Communications Privacy and the State
 
2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review
 
Right to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-finalRight to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-final
 
Communications Data Retention by Intermediaries
Communications Data Retention by IntermediariesCommunications Data Retention by Intermediaries
Communications Data Retention by Intermediaries
 
2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update
 
Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?
 
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
 
Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?
 
Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?
 

Dernier

Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksUnderstanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksFinlaw Associates
 
citizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicablecitizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicableSaraSantiago44
 
OMassmann - Investment into the grid and transmission system in Vietnam (2024...
OMassmann - Investment into the grid and transmission system in Vietnam (2024...OMassmann - Investment into the grid and transmission system in Vietnam (2024...
OMassmann - Investment into the grid and transmission system in Vietnam (2024...Dr. Oliver Massmann
 
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptxThe Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptxgurcharnsinghlecengl
 
Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...
Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...
Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...Rich Bergeron
 
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los AngelesAre There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los AngelesChesley Lawyer
 
Labour legislations in India and its history
Labour legislations in India and its historyLabour legislations in India and its history
Labour legislations in India and its historyprasannamurthy6
 
Illinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideIllinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideillinoisworknet11
 
Right to life and personal liberty under article 21
Right to life and personal liberty under article 21Right to life and personal liberty under article 21
Right to life and personal liberty under article 21vasanthakumarsk17
 
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxSarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxAnto Jebin
 
1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in Sales1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in SalesMelvinPernez2
 
Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...
Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...
Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...Rich Bergeron
 
Choosing the Right Business Structure for Your Small Business in Texas
Choosing the Right Business Structure for Your Small Business in TexasChoosing the Right Business Structure for Your Small Business in Texas
Choosing the Right Business Structure for Your Small Business in TexasBrandy Austin
 
ENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened to
ENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened toENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened to
ENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened toirenelavilla52178
 
Town of Haverhill's Summary Judgment Motion for Declaratory Judgment Case
Town of Haverhill's Summary Judgment Motion for Declaratory Judgment CaseTown of Haverhill's Summary Judgment Motion for Declaratory Judgment Case
Town of Haverhill's Summary Judgment Motion for Declaratory Judgment CaseRich Bergeron
 
Guide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docxGuide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docxjennysansano2
 
PPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training CenterPPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training Centerejlfernandez22
 
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdfWurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdfssuser3e15612
 
RA. 7432 and RA 9994 Senior Citizen .pptx
RA. 7432 and RA 9994 Senior Citizen .pptxRA. 7432 and RA 9994 Senior Citizen .pptx
RA. 7432 and RA 9994 Senior Citizen .pptxJFSB1
 
Hungarian legislation made by Robert Miklos
Hungarian legislation made by Robert MiklosHungarian legislation made by Robert Miklos
Hungarian legislation made by Robert Miklosbeduinpower135
 

Dernier (20)

Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal FrameworksUnderstanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
Understanding Cyber Crime Litigation: Key Concepts and Legal Frameworks
 
citizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicablecitizenship in the Philippines as to the laws applicable
citizenship in the Philippines as to the laws applicable
 
OMassmann - Investment into the grid and transmission system in Vietnam (2024...
OMassmann - Investment into the grid and transmission system in Vietnam (2024...OMassmann - Investment into the grid and transmission system in Vietnam (2024...
OMassmann - Investment into the grid and transmission system in Vietnam (2024...
 
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptxThe Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
The Punjab Land Reforms AcT 1972 HIRDEBIR.pptx
 
Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...
Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...
Town of Haverhill's Statement of Facts for Summary Judgment on Counterclaims ...
 
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los AngelesAre There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
Are There Any Alternatives To Jail Time For Sex Crime Convictions in Los Angeles
 
Labour legislations in India and its history
Labour legislations in India and its historyLabour legislations in India and its history
Labour legislations in India and its history
 
Illinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guideIllinois Department Of Corrections reentry guide
Illinois Department Of Corrections reentry guide
 
Right to life and personal liberty under article 21
Right to life and personal liberty under article 21Right to life and personal liberty under article 21
Right to life and personal liberty under article 21
 
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptxSarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
Sarvesh Raj IPS - A Journey of Dedication and Leadership.pptx
 
1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in Sales1990-2004 Bar Questions and Answers in Sales
1990-2004 Bar Questions and Answers in Sales
 
Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...
Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...
Town of Haverhill's Statement of Material Facts For Declaratory Judgment Moti...
 
Choosing the Right Business Structure for Your Small Business in Texas
Choosing the Right Business Structure for Your Small Business in TexasChoosing the Right Business Structure for Your Small Business in Texas
Choosing the Right Business Structure for Your Small Business in Texas
 
ENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened to
ENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened toENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened to
ENG7-Q4-MOD3. determine the worth of ideas mentioned in the text listened to
 
Town of Haverhill's Summary Judgment Motion for Declaratory Judgment Case
Town of Haverhill's Summary Judgment Motion for Declaratory Judgment CaseTown of Haverhill's Summary Judgment Motion for Declaratory Judgment Case
Town of Haverhill's Summary Judgment Motion for Declaratory Judgment Case
 
Guide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docxGuide for Drug Education and Vice Control.docx
Guide for Drug Education and Vice Control.docx
 
PPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training CenterPPT Template - Federal Law Enforcement Training Center
PPT Template - Federal Law Enforcement Training Center
 
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdfWurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
Wurz Financial - Wealth Counsel to Law Firm Owners Services Guide.pdf
 
RA. 7432 and RA 9994 Senior Citizen .pptx
RA. 7432 and RA 9994 Senior Citizen .pptxRA. 7432 and RA 9994 Senior Citizen .pptx
RA. 7432 and RA 9994 Senior Citizen .pptx
 
Hungarian legislation made by Robert Miklos
Hungarian legislation made by Robert MiklosHungarian legislation made by Robert Miklos
Hungarian legislation made by Robert Miklos
 

SCL Conference 8 June 2017 - Investigatory Powers Act

  • 1. Investigatory Powers Act introduction Graham Smith SCL Annual Conference 8 June 2017
  • 4. ● Bulk interception under RIPA ● Equipment interference (CNE) 2013 - Snowden
  • 6. 2014 ● Digital Rights Ireland (CJEU) ● Data Retention and Investigatory Powers Act (DRIPA)
  • 8. "RIPA, obscure since its inception, has been patched up so many times as to make it incomprehensible to all but a tiny band of initiates" "comprehensive and comprehensible" Page 8
  • 10. Overview of #IPAct powers 300 page Act ● Interception warrants • Bulk, targeted, thematic; Content and ‘secondary’ data ● Equipment interference (hacking) warrants • Bulk, targeted, thematic; Content and ‘equipment’ data ● Communications data acquisition and disclosure • Bulk warrants, targeted notices + request filter ● Mandatory communications data retention notices • Browsing histories (Internet Connection Records) ● Technical capability notices • E2E encryption ● National security notices ● Bulk personal dataset warrants Page 10
  • 11. What? How? Who to? Enforce? Secret? Warrant (SoS + JC) TelOp Crim + Civ Crim Warrant (SoS [some LE] + JC) TelOp UKpers only, Civ Crim Notice (SoS + JC) TelOp UKpers only, Civ Civ Notice (various authorities) TelOp Civ Crim Warrant (SoS + JC) TelOp UKpers only, Civ Crim Notice (SoS + JC) TelOp (inc prospective) As per substantive powers Yes Notice (SoS + JC) UK TelOp UKpers only, Civ Yes Overview of #IPAct powers Comms Data Retention (inc ICRs) Comms Data Acquisition (targeted)(?) Equipment interference (targeted, thematic) Encryption removal Equipment interference (bulk) Request filter (comms data) Technical capability notices Comms Data Acquisition (bulk) Interception (targeted, thematic) Interception (bulk) Interception (secondary data) Equipment interference (equipment data) National security notices Page 11
  • 12. What? How? Who by? Purposes? Warrant (SoS + JC) MI5, SIS, GCHQ, MoD, 5 LE bodies, MLAT National security; prevent/detect serious crime; UK economic well- being (nat sec-related, non-BI persons) Warrant (SoS + JC) MI5, SIS, GCHQ; MoD (nat sec only) Warrant (LE head + JC) Police (various), National Crime Agency Prevent/detect serious crime, prevent death, prevent or mitigate injury/damage to physical/mental health Immigration, Revenue/Customs, Competition/Markets, Police investigations Prevent/detect serious crime Warrant (SoS + JC) MI5, SIS, GCHQ (overseas- related main purpose) National security; national security and prevent/detect serious crime, UK economic well-being (non-BI persons) Warrant (SoS + JC) MI5, SIS, GCHQ Notice (plus court order for local authorities) Numerous authorities 11 different purposes Notice (+ JC) (up to 12 mths) Secretary of State Notice (+ JC) Secretary of State National security Warrants, comms data acquisition notices Overview of #IPAct powers Equipment interference (targeted, thematic) Equipment interference (bulk) Comms Data Acquisition (bulk) Interception (targeted, thematic) Interception (bulk) National security notices Technical capability notices (inc decryption) Comms Data Acquisition (targeted)(?) Request filter (comms data) Comms Data Retention (inc ICRs) Page 12
  • 14. New or not new? ● Explicit powers re-enacted ● Semi-explicit powers (scale of use hidden) now made explicit ● Opaque powers now made explicit ● Opaque powers still (arguably) opaque Interception (targeted) Comms Data Acquisition (bulk) Equipment interference (targeted, thematic) Encryption removal Interception (bulk) Interception (thematic) Equipment interference (bulk) Interception (related communications data) Page 14
  • 15. New and extended Authorisation and oversight – new safeguards ● Judicial Commissioner approval of most warrants and notices • Except targeted communications data acquisition - But Watson. Extended mandatory data retention powers ● Extended to all kinds of communications data • including Internet Connection Records (site level browsing histories) ● Extended to all kinds of communication (background, IoT) ● Extended to include generation and obtaining data for retention ● Abolition of 'processed within UK' limitation ● Extended to include private telecommunications operators Page 15
  • 16. New and extended Content-derived metadata ● Interception, equipment interference, BPD warrants. • Targeted, thematic, bulk ● New power to extract some information from content and treat as metadata Page 16
  • 17. New and extended Technical capability notices ● Permanent technical capability to assist with warrants and communications data acquisition notices ● Extended from interception (RIPA) to most powers (IPAct) ● Extended to include private telecommunications operators • Subject to any limitations in regulations Draft regulations ● No minimum threshold for communications data acquisition ● Black boxes (communications data acquisition) ● Hacking back door ● End to end encryption? Page 17
  • 18. New and extended New non-disclosure obligations on warrant/notice recipients ● Criminal (targeted and bulk) • Interception warrants (59(1), 156(2)) • Equipment interference warrants (134(1), 197) • Bulk communications data acquisition warrants (174(1)) • Targeted communications data acquisition notices (82(1)) ● Civil • Data retention notices (95(2)) ● Indeterminate • Technical capability notices (255(8)) • National security notices (255(8)) Page 18
  • 19. Tweaks ● Extraterritoriality ● Content v metadata ● Categories of metadata ● Journalists, MPs, legal privilege ● Interception offence ● etc Page 19
  • 20. Timetable ● Data retention partially in force 30 December 2016 • Existing notices continue for max 6 mths ● The rest of the Act? • New oversight regime • New warrantry procedures • ‘Some time … timetable in due course’ Page 20
  • 21. Graham Smith graham.smith@twobirds.com @cyberleagle Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses. Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number OC340318 and is authorised and regulated by the Solicitors Regulation Authority. Its registered office and principal place of business is at 15 Fetter Lane, London EC4A 1JP. A list of members of Bird & Bird LLP and of any non-members who are designated as partners, and of their respective professional qualifications, is open to inspection at that address. twobirds.com Thank you