Tuesday, 8 June 2021

Big Brother Watch/Rättvisa – a multifactorial puzzle

The European Court of Human Rights Grand Chamber has now delivered its long awaited judgment in Big Brother Watch.  It always seemed a bit of a stretch that the Strasbourg Court would tell the UK to close down the bulk (so to speak) of GCHQ’s operations, especially since 15 years ago the Weber/Saravia decision had accepted the principle of bulk communications surveillance (albeit in a world in which digital communications were not yet ubiquitous). 

So it proved. The Court’s Big Brother Watch judgment (and its companion judgment in the Swedish Centrum för Rättvisa case) lay down a revised set of fundamental rights criteria by which to assess bulk surveillance regimes, but do not forbid them as such.

The Grand Chamber’s approach

The twin judgments are notable for advancing further down the path of assessing a surveillance regime not by drawing red lines that must not be crossed, but by applying a multifactorial evaluation of criteria that feed into a “global assessment” of the regime's compliance with the “provided by law” and “necessary in a democratic society” requirements of the Convention.

The “provided by law” Convention requirement is that a measure must have some basis in law, and also have the quality of law: be publicly accessible and sufficiently certain and precise so as to be foreseeable in its effects. The scope of any discretion to exercise a surveillance power must be indicated with sufficient clarity to provide adequate protection against arbitrary interference.  

The conundrum that faces a human rights court is how such traditional rule of law requirements – certainty of law, foreseeability of legal effects, accessibility of a legal regime – can be applied to the inherently secret and discretionary nature of communications surveillance. The answer has been to import the notion that safeguards (such as independent oversight) can compensate for lack of openness, so long as the kind of circumstances in which communications surveillance may take place are clearly set out in legislation, supplemented if necessary by instruments such as codes of practice. The ECtHR’s particular focus on the role of safeguards is facilitated by its policy of considering the “provided by law” test jointly with whether the interference constituted by a given regime is “necessary in a democratic society” (BBW [334], Rättvisa [248]).

It is not a straightforward task to decide at what point safeguards sufficiently compensate for the rule of law deficiencies presented by secret exercise of a discretionary power. The Grand Chamber describes the role of safeguards in bulk interception of digital communications as “pivotal and yet elusive” (BBW [322], Rättvisa [236]). 

It is hard to avoid the conclusion that the search for this will o’the wisp is ultimately a matter of impression – the more so, the further the evaluation strays from red lines that cannot be crossed towards an overall multifactorial assessment, the result of which depends on how much weight the court chooses to give to each factor.

Bulk interception not per se unlawful

The challenge that faces a party seeking to strike down a bulk interception regime is how to bring a substantive objection – that a bulk communications surveillance regime is inherently repugnant - within the framework of a “quality of law” and “necessity” challenge. The argument will be that the interference with privacy and (perhaps) freedom of expression entailed by bulk communications interception is so great that, although useful, bulk communications interception does not pass the “necessity” test. This is the kind of argument that succeeded in the Marper case on blanket retention of DNA, fingerprint and cellular samples.

In the BBW and Rättvisa  cases the Grand Chamber held that a decision to operate a bulk interception regime continues to fall within the competence (“margin of appreciation”) of a Contracting State.  Their freedom of choice in how to operate such a regime is, however, more constrained. (BBW [340, 347], Rättvisa [254, 261])

Another way of stating the objection to such a regime might be that, given the scale of the interference, no amount of safeguards can compensate for the lack of foreseeability inherent in the secret exercise of bulk communications surveillance powers. However, in reality once necessity is surmounted in principle, the examination moves on to whether the combination of accessibility, precision of rules and compensating safeguards embodied in the regime under challenge is sufficient for Convention compliance.

The Court’s decision on RIPA

In BBW the UK’s now superseded RIPA (Regulation of Investigatory Powers Act 2000) regime was under challenge. As in the Chamber judgment in 2018 the Grand Chamber found the UK regime wanting. But it did so in slightly different ways:

Chamber

Grand Chamber

Article 8

 

Bulk interception: lack of provision for sufficient oversight of the entire selection process, specifically search criteria and selectors [387, 388]

Lack of independent authorisation at the outset [377]

 

Lack of provision for oversight of categories of selectors at point of authorisation; lack of provision for enhanced safeguards for use of strong selectors linked to identifiable individuals [383]

 

Insufficiently precise nature of SoS certificate as to descriptions of material necessary to be examined [386, 387, 391]

 

All applicable to both content and RCD [416]

Bulk interception: examination of related communications data (RCD) exempted from all safeguards applicable to content, such as S.16(2) ‘British Islands’ restriction applicable to content. [357, 387, 388]

Lack of ‘British Islands’ restriction for RCD is not decisive in overall assessment [421]; different storage periods for RCD (“several months”) were not evident in the Interception Code. Should be included in legislative and/or other general measures [423]

Communications data acquisition: Violation of EU law meant that acquisition could not be in accordance with the law [467, 468]

Not contested [521, 522]

Article 10

 

Bulk interception: lack of protection for journalistic privilege at selection and examination stage (content and RCD) [493, 495, 500]

As per Art 8; additionally, no requirement for a judge or similar to decide whether use of selectors or search terms known to be connected to a journalist was justified by an overriding requirement in the public interest; or whether a less intrusive measure might have sufficed [456];

 

Nor provision for similar authorisation of continued storage and examination of confidential journalistic material once a connection to a journalist became known. [457]

Communications data acquisition: insufficiently broad journalistic privilege protections [499, 500]

Not contested [527, 528]

The main concrete point of difference from the Chamber judgment is probably the Grand Chamber's emphasis on prior independent authorisation. That, in the form of Judicial Commissioner approval of the Secretary of State’s decision to issue a warrant, is now a feature of the Investigatory Powers Act 2016 which has superseded RIPA.

It is difficult to predict specific implications of the two Grand Chamber judgments for the IP Act. This is due to the Court’s already noted holistic, multifactorial approach to fundamental rights compliance. Although in places the Grand Chamber speaks of ‘minimum requirements’ – which might suggest a cumulative set of threshold conditions – in others it speaks of ‘shortcomings’ that inform the overall assessment and may be compensated for by other features of the regime.

This approach is more prominent in the Rättvisa judgment, in which the Court held that while certain safeguards did compensate for identified shortcomings in the Swedish regime, they did not do so sufficiently. The BBW judgment, while also adopting the “global assessment” approach, is in substance a starker exercise in striking down the RIPA regime owing to lack of certain safeguards. 

The main reason for the difference between the two judgments is that the Swedish surveillance regime did provide for initial authorisation of bulk warrants by an independent Foreign Intelligence Court. It could not, therefore, be said (as it was for RIPA in BBW) that the regime lacked independent authorisation at the outset (a minimum requirement that the Court has now described as a “fundamental safeguard” that “should” be present ([377]).  The approach of the Court in Rättvisa was therefore of necessity more nuanced.

Hard versus soft limits

By contrast with the Grand Chamber’s holistic, multifactorial approach, the EU Court of Justice has moved in the direction of insisting on that the relevant legal instruments set out clear and precise hard limits on powers.

That contrast may to some extent reflect the different roles of the two courts. The CJEU’s task is to lay down the content of substantive, positive EU law, within the framework of the Charter of Fundamental Rights. The task of the ECtHR is not to harmonise or lay down positive law (although when it ventures into the territory of horizontal rights it comes perilously close to doing that), but to determine whether a potentially wide variety of  Contracting State laws has strayed beyond the boundaries of Convention compatibility.

Although even the CJEU must allow for some differences in Member State domestic laws, it is in principle able to be more prescriptive than the ECtHR. 

At any rate, the ECtHR (confirmed by the Grand Chamber in the BBW and Rättvisa cases) has taken a softer-edged approach, with greater stress on safeguards than on the need for clear and precise limits on powers (emphasised by the CJEU most recently in Privacy International/La Quadrature). Whether or not that ultimately means a substantively stricter outcome than the CJEU's approach, it certainly makes for one that is less predictable in terms of compliance with the Convention.

The ECtHR’s approach is exemplified by the set of compliance criteria articulated by the Grand Chamber in BBW and Rättvisa. It has laid down eight minimum criteria, compared with the six in Weber/Saravia, to be considered in deciding whether a surveillance regime passes the initial ‘in accordance with the law’ test.

The criteria are that the Court will examine whether the domestic framework clearly defines:

1. the grounds on which bulk interception may be authorised;

2. the circumstances in which an individual’s communications may be intercepted;

3. the procedure to be followed for granting authorisation;

4. the procedures to be followed for selecting, examining and using intercept material;

5. the precautions to be taken when communicating the material to other parties;

6. the limits on the duration of interception, the storage of intercept material and the circumstances in which such material must be erased and destroyed;

7. the procedures and modalities for supervision by an independent authority of compliance with the above safeguards and its powers to address non-compliance;

8. the procedures for independent ex post facto review of such compliance and the powers vested in the competent body in addressing instances of non-compliance.

These are framed as topic areas that have to be clearly addressed in domestic law. They also imply some degree of minimum requirement: for instance, domestic legislation that addressed the topic of limits on the duration of interception by stating clearly that it may be unlimited would not pass muster. Similarly, the factors connote some level of independent supervision and review.

However, what those implied minimum requirements might amount to in practice is not easy to tell. The eight topics appear to be as much – perhaps more so - criteria to be assessed, as a cumulative set of threshold conditions to be surmounted.  They may have elements of both. The Court referred in its judgment to its ‘overall assessment’ of the bulk interception regime, emphasising that shortcomings in some areas may be compensated by safeguards in others. The Court may also take into account factors beyond the eight minimum criteria, such as notification provisions.

In a separate Opinion Judge Pinto de Albuquerque pointed out the ambiguity in the Grand Chamber’s judgment as to whether it was laying down factors to be considered or mandatory requirements:

“On the one hand, it has used imperative language (“should be made”, “should be subject”, “should be authorised”, “should be informed”, “must be justified”, and “should be scrupulously recorded”, “should also be subject”, “it is imperative that the remedy should”) and has called them “fundamental safeguards” and even “minimum safeguards”. But on the other hand, it has diluted these safeguards in “a global assessment of the operation of the regime”, allowing for a trade-off among the safeguards. It seems that at the end of the day each individual safeguard is not mandatory, and the prescriptive language of the Court does not really correspond to non-negotiable features of the domestic system.”

That said, the Court went on to lay down what it described as the “fundamental safeguards” that would be the cornerstone of an Article 8-compliant bulk interception regime ([350]). This was articulated in the context of the particular model presented to the court (collection, filtering to discard unwanted material, automated application of selectors and search queries, manual queries by analysts, examination by analysts, subsequent retention and use), which the Court regarded as involving increasing interferences with privacy as the process progressed. ([325]) . This model already feels somewhat old-fashioned, given the more sophisticated pattern-matching and other techniques that could be applied to analysis of, in particular, bulk communications data.  

The Court's requirements are that the process must be subject to end-to-end safeguards, meaning that: 

  • At each stage of the process an assessment must be made of the necessity and proportionality of the measures being taken. [350]

  • Bulk interception should be subject to independent authorisation at the outset, when the object and scope of the operation are being defined [351]

  • The operation should be subject to supervision and independent ex post facto review [350]

The Court commented that the importance of supervision and review is amplified compared with targeted interception because of the inherent risk of abuse and the legitimate need for secrecy [349].

Drilling down further into those fundamental safeguards, the Court observed that:

  • The independent authorising body should be informed of both the purpose of the interception and the bearers or communication routes likely to be intercepted. [352]
  • Given that the choice of selectors and query terms determines which communications will be eligible for examination by an analyst, the authorisation should at the very least identify the types or categories of selectors to be used. The Court accepted that the inclusion of all selectors in the authorisation may not be feasible in practice. [354]
  • Enhanced safeguards should be in place for strong selectors linked to identifiable individuals. The use of every such selector must be justified by the intelligence services and that justification should be scrupulously recorded and be subject to a process of prior internal authorisation providing for separate and objective verification of whether the justification conforms to the principles of necessity and proportionality. [355]
  • Each stage of the bulk interception process – including the initial authorisation and any subsequent renewals, the selection of bearers, the choice and application of selectors and query terms, and the use, storage, onward transmission and deletion of the intercept material – should be subject to supervision by an independent authority. That supervision should be sufficiently robust to keep the interference with Art 8 rights to what is “necessary in a democratic society”. In order to facilitate supervision, detailed records should be kept by the intelligence services at each stage of the process. [356]
  • Finally, an effective remedy should be available to anyone who suspects that his or her communications have been intercepted by the intelligence services, either to challenge the lawfulness of the suspected interception or the Convention compliance of the interception regime. A remedy that does not depend on notification to the interception subject can be effective. But it is then imperative that the remedy should be before a body which, while not necessarily judicial, is independent of the executive and ensures the fairness of the proceedings, offering, in so far as possible, an adversarial process. The decisions of such authority shall be reasoned and legally binding with regard, inter alia, to the cessation of unlawful interception and the destruction of unlawfully obtained and/or stored intercept material. [357]

The court also provided guidance on sharing intercept material with agencies in other countries.

In the light of the above, the Court will determine whether a bulk interception regime is Convention compliant by conducting a global assessment of the operation of the regime. Such assessment will focus primarily on whether the domestic legal framework contains sufficient guarantees against abuse, and whether the process is subject to “end-to-end safeguards”. In doing so, the Court will have regard to the actual operation of the system of interception, including the checks and balances on the exercise of power, and the existence or absence of any evidence of actual abuse. [360]

The Court also observed that it was not persuaded that the acquisition of related communications data through bulk interception is necessarily less intrusive than the acquisition of content. It therefore considered that the interception, retention and searching of related communications data should be analysed by reference to the same safeguards as those applicable to content. [363]

That said, the Court observed that while the interception of related communications data would normally be authorised at the same time the interception of content is authorised, once obtained they could permissibly be treated differently by the intelligence services. 

In view of the different character of related communications data and the different ways in which they are used by the intelligence services, as long as the aforementioned safeguards were in place, the legal provisions governing their treatment did not necessarily have to be identical in every respect to those governing the treatment of content. [364]

Implications for the Investigatory Powers Act 2016

Where does this leave the 2016 Act? The Act ticks several important boxes, notably the “double lock” system of approval of bulk warrants by a Judicial Commissioner introduced after the end of the RIPA regime.

When considering the Convention compliance of the IP Act regime the Rättvisa decision is probably more factually relevant than the BBW decision, since it addresses a regime that featured initial authorisation by an independent court.

The IP Act in some respects provides stronger safeguards than those that fell short in Rättvisa – thus the UK IPT was held up as an example of what was possible in the area of ex post facto review.

On the other hand, the Swedish regime provided for mandatory presence of a privacy protection representative at Foreign Intelligence Court sessions. That was identified as a relevant safeguard to be weighed against the fact that the Court had never held a public hearing and that all its decisions were confidential.

There is no provision in the IP Act for a privacy protection representative to make submissions in the bulk warrant approval process. As to publicising bulk warrant approval decisions, in his April 2018 Advisory Notice the Investigatory Powers Commissioner said:

“The Judicial Commissioners will consider making any decisions on approvals public, subject to any statutory limitations and necessary redactions.”

It is noteworthy that the latest Annual Report of the Investigatory Powers Commissioner (for 2019) records that a Judicial Commissioner issued the first approvals of a communications data retention notice regarding internet connection records. It also describes a potential obstacle to approval of warrants posed by MI5's IT issues. Whilst this evinces a degree of openness, it does not go as far as (for instance) a practice of publishing Judicial Commissioner decisions on points of legal interpretation.

Given the multifactorial, trade-off-oriented approach of the Grand Chamber it is impossible to be categoric about whether this aspect of the IP Act regime presents Convention compliance problems. On the basis of Rättvisa we can expect, however, that it will be argued that either a privacy (and freedom of expression?) representative should be able to make submissions in the bulk warrant approval decision-making process, or the possibility of publishing elements of bulk warrant approval decisions should be explored further, or perhaps both.

As for the double-lock procedure itself, although the Secretary of State remains the primary decision-maker, and it is occasionally suggested that Judicial Commissioner approval, being based on judicial review principles, falls short of full scrutiny, it should not be forgotten that the Advisory Notice issued by the IPC in April 2018 stated that the Judicial Commissioners would not apply the relatively hands-off ‘Wednesbury reasonableness’ test, but instead the judicial review test applied by the domestic courts when considering interferences with fundamental rights. That would be taken into account in any assessment of the level of scrutiny applied to warrants.

Another area of the IP Act that is likely to attract attention is the IP Act's bulk communications data acquisition warrant. This is the successor to S.94 of the Telecommunications Act 1984, which the government admitted in November 2015 had been used for bulk acquisition of communications data from communications service providers.

Unlike bulk interception under RIPA (and now under the IP Act), the bulk communications acquisition warrant is not focused on foreign intelligence purposes. Given the various references in the BBW and Rättvisa judgments to bulk interception being primarily used for foreign intelligence, and the acknowledgment that bulk communications data should not be regarded as less sensitive than content, the Convention compliance of a domestic bulk acquisition regime may fall to be considered in the future.

A potential problem area, both for bulk interception and communications data acquisition, is journalistic privilege. Although the IP Act contains stronger protections for journalistic material than did RIPA, it may be questioned whether those, at least of themselves, are sufficient to meet the criticisms contained in the two ECtHR judgments.

Returning to the central theme of the Grand Chamber judgments, does the IP Act provide sufficient end-to-end safeguards over the bulk interception process? Following the Chamber judgment in 2018 I suggested that since the 2016 Act did not spell out whether end to end oversight was applied to all stages of the bulk interception process, more would need to be done to fill that gap (remembering that it is not enough for that simply to be done – it must be required to be done by means of clearly stated public rules.) That view is reinforced by the Grand Chamber judgment. I can do no better than repeat what I said then:

“Beyond that, under the IP Act the Judicial Commissioners have to consider at the warrant approval stage the necessity and proportionality of conduct authorised by a bulk warrant. Arguably that includes all four stages identified by the Strasbourg Court (see my submission to IPCO earlier this year). If that is right, the RIPA gap may have been partially filled.

However, the IP Act does not specify in terms that selectors and search criteria have to be reviewed. Moreover, focusing on those particular techniques already seems faintly old-fashioned. The Bulk Powers Review reveals the extent to which more sophisticated analytical techniques such as anomaly detection and pattern analysis are brought to bear on intercepted material, particularly communications data. Robust end to end oversight ought to cover these techniques as well as use of selectors and automated queries. 

The remainder of the gap could perhaps be filled by an explanation of how closely the Judicial Commissioners oversee the various selection, searching and other analytical processes.

Filling this gap may not necessarily require amendment of the IP Act, although it would be preferable if it were set out in black and white. It could perhaps be filled by an IPCO advisory notice: first as to its understanding of the relevant requirements of the Act; and second explaining how that translates into practical oversight, as part of bulk warrant approval or otherwise, of the end to end stages involved in bulk interception (and indeed the other bulk powers).”

The case for the gap to be filled formally is reinforced when we consider that the government has publicly referred to discussions that have been taking place with IPCO to strengthen end to end supervision in practice. The Grand Chamber judgment records the government’s argument that:

“Robust independent oversight of selectors and search criteria was therefore within the IC Commissioner’s powers: by the time of his 2014 report he had specifically put in place systems and processes to make sure that actually occurred, and, following the Chamber judgment, the Government had been working with the IC Commissioner’s Office to ensure that there would be enhanced oversight of selectors and search criteria under IPA.”

In his Annual Report for 2019 (published in December 2020) the Investigatory Powers Commissioner stated:

“Our oversight of bulk powers has evolved over the past year (see para 10.27). This reflected the European Court of Human Right’s judgment in the Big Brother Watch and others v UK case, and the Intelligence and Security Committee’s (ISC) Privacy and Security Report of March 2015.We reviewed our approach to inspecting bulk interception in 2019, considering the technically complex ways in which bulk interception is implemented and from 2020 our inspections will include a detailed examination of selectors and search criteria.”

Now that we have the Grand Chamber judgment the case appears to be stronger for the end to end oversight arrangements, and IPCO’s interpretation of the 2016 Act in that regard, to be spelled out publicly. That would also be well timed for the forthcoming review of the operation of the 2016 Act that is required to start in a year’s time.



Sunday, 16 May 2021

Harm Version 3.0: the draft Online Safety Bill

Two years on from the April 2019 Online Harms White Paper, the government has published its draft Online Safety Bill. It is a hefty beast: 133 pages and 141 sections. It raises a slew of questions, not least around press and journalistic material and the newly-coined “content of democratic importance”. Also, for the first time, the draft Bill spells out how the duty of care regime would apply to search engines, not just to user generated content sharing service providers.

This post offers first impressions of a central issue that started to take final shape in the government’s December 2020 Full Response to consultation: the apparent conflict between imposing content monitoring and removal obligations on the one hand, and the government’s oft-repeated commitment to freedom of expression on the other - now translated into express duties on service providers.

That issue overlaps with a question that has dogged the Online Harms project from the outset: what does it mean by safety and harm?  The answer shapes the potential impact of the legislation on freedom of expression. The broader and vaguer the notion of harm, the greater the subjectivity involved in complying with the duty of care, and the greater the consequent dangers for online users' legitimate speech. 

The draft Bill represents the government's third attempt at defining harm (if we include the White Paper, which set no limit). The scope of harm proposed in its second version (the Full Response) has now been significantly widened

For legal but harmful content the government apparently now means to set an overall backstop limitation of "physical or psychological harm", but whether the draft Bill achieves that is doubtful. In any event that would still be broader than the general definition of harm proposed in the Full Response: a “reasonably foreseeable risk of a significant adverse physical or psychological impact on individuals”. For illegal content the Full Response's general definition would not apply; and the new backstop definition would have only limited relevance.   

Moderation and filtering duties

If one provision can be said to lie at the heart of the draft Bill, it is section 9(3). This describes duties that will apply to all the estimated 24,000 in-scope service providers. It is notable that pre-Brexit, duties (a) to (c) would have fallen foul of the ECommerce Directive's Article 15 ban on imposing general monitoring obligations on hosting providers. Section 9(3) thus departs from 20 years of EU and UK policy aimed at protecting the freedom of expression and privacy of online users.  

Section 9(3) imposes: 

A duty to operate a service using proportionate systems and processes designed to—

(a) minimise the presence of priority illegal content;

(b) minimise the length of time for which priority illegal content is present;

(c) minimise the dissemination of priority illegal content;

(d) where the provider is alerted by a person to the presence of any illegal content, or becomes aware of it in any other way, swiftly take down such content.

Duty (d) approximately parallels the hosting liability shield in the ECommerce Directive, but cast in terms of a positive regulatory obligation to operate take down processes, rather than potential exposure to liability for a user's content should the shield be disapplied on gaining knowledge of its illegality. 

As is typical of regulatory legislation, the draft Bill is not a finished work. It is more like a preliminary drawing intended to be filled out later. For instance, the extent of the proactive moderation and filtering obligations implicit in Section 9(3) depends on what constitutes ‘priority illegal content’. That is not set out in the draft Bill, but would be designated in secondary legislation prepared by the Secretary of State. The same holds for ‘priority content that is harmful to adults’, and for a parallel category relating to children, which underpin other duties in the draft Bill. 

Since Section 9(3) and the other duties make no sense without the various kinds of priority content first being designated, regulations would presumably have to be made before the legislation can come into force.  The breadth of the Secretary of State's discretion in designating priority content is discussed below.

If secondary legislation is a layer of detail applied to the preliminary drawing a further layer, yet more detailed, will consist of codes of practice, guidance and risk profiles for different kinds of service, all issued by Ofcom.

This regulatory vessel would be pointed in the government's desired direction by a statement of strategic online safety priorities issued by the Secretary of State, to which Ofcom would be required to have regard. The statement could set out particular outcomes. The Secretary of State would first have to consult with Ofcom, then lay the draft before Parliament so as to give either House the opportunity to veto it.  

The moderation and filtering obligations implicit in Section 9(3) and elsewhere in the draft Bill would take the lion’s share – £1.7bn  of the £2.1bn that the government’s Impact Assessment reckons in-scope providers will have to spend on complying with the legislation over the first 10 years. Moderation is expected to be both technical and human:

“…it is expected that undertaking additional content moderation (through hiring additional content moderators or using automated moderation) will represent the largest compliance cost faced by in-scope businesses.” (Impact Assessment [166])

Additional moderation costs are expected to be incurred in greater proportion by the largest (Category 1) providers: 7.5% of revenue for Category 1 organisations and 1.9% for all other in-scope organisations (Impact Assessment [180]). That presumably reflects the obligations specific to Category 1 providers in relation to legal but 'harmful to adults’ content.

Collateral damage to legitimate speech

Imposition of moderation and filtering obligations, especially at scale, raises the twin spectres of interference with users’ privacy and collateral damage to legitimate speech. The danger to legitimate speech arises from misidentification of illegal or harmful content and lack of clarity about what is illegal or harmful. Incidence of collateral damage resulting from imposition of such duties is likely to be affected by:

  •     The proof threshold that triggers the duty. The lower the standard to which a service provider has to be satisfied of illegality or harm, the greater the likelihood of erroneous removal or inhibition.
  •     Scale. The greater the scale at which moderation or filtering is carried out, the less feasible it is to take account of individual context. Even for illegal content the assessment of illegality will, for many kinds of illegality, be context-sensitive.
  •     Subjectivity of the harm. If harm depends upon the subjective perception of the reader, a harm standard according to the most easily offended reader may develop.
  •     Vagueness. If the kind of harm is so vaguely defined that no sensible line can be drawn between identification and misidentification, then collateral damage is hard-wired into the regime.
  •     Scope of harm The broader the scope of harm to which a duty applies, the more likely that it will include subjective or vague harms.

Against these criteria, how does the draft Bill score on the collateral damage index?

Proof threshold S.41 defines illegal content as content where the service provider has reasonable grounds to believe that use or dissemination of the content amounts to a relevant criminal offence. Illegal content does not have to be definitely illegal in order for the section 9(3) duties to apply.

The scale of the required moderation and filtering is apparent from the Impact Assessment.

The scope of harm has swung back and forth. Version 1.0 was contained in the government’s April 2019 White Paper. It encompassed the vaguest and most subjective kinds of harm. Most kinds of illegality were within scope. For harmful but legal content there was no limiting definition of harm. Effectively, the proposed regulator (now Ofcom) could have deemed what is and is not harmful.

By the time of its Full Consultation Response in December 2020 the government had come round to the idea that the proposed duty of care should relate only to defined kinds of harm, whether they arose from illegal user content or user content that was legal but harmful [Full Response 2.24].

In this Version 2.0, harm would consist of a “reasonably foreseeable risk of a significant adverse physical or psychological impact on individuals”. A criminal offence would therefore be in scope of a provider’s duty of care only if the offence presented that kind of risk.

Although still problematic in retaining some elements of subjectivity through inclusion of psychological impact, the Full Response proposal significantly shifted the focus of the duty of care towards personal safety properly so-called. It was thus more closely aligned to the subject matter of comparable offline duties of care.

Version 3.0 The draft Bill states as a general definition that "harm" means "physical or psychological harm".  This is an attenuated version of the general definition proposed in the Full Response. However, the draft Bill does not stipulate that 'harmful' should be understood in the same limited way. The result of that omission, combined with other definitions, could be to give the Secretary of State regulation-making powers for legal but harmful content that are, on the face of them, not limited to physical or psychological harm. 

This may well not be the government's intention. When giving evidence to the Culture Media and Sport Commons Committee last week, Secretary of State Oliver Dowden stressed (14:57 onwards) that regulations would not go beyond physical or psychological harm. This could usefully be explored during pre-legislative scrutiny.  

For legal but harmful content the draft Bill does provide a more developed version of the Full Response’s general definition of harm, tied to impact on a hypothetical adult or child "of ordinary sensibilities". This is evidently an attempt to inject some objectivity into the assessment of harm. It then adds further layers addressing impact on members of particularly affected groups or particularly affected people with certain characteristics (neither specified), impact on a specific person about whom the service provider knows, and indirect impact. These provisions will undoubtedly attract close scrutiny.  

In any event, this complex definition of harm does not have universal application within the draft Bill. It governs only a residual category of content outside the Secretary of State’s designated descriptions of priority harmful content for adults and children. The longer the Secretary of State's lists of priority harmful content designated in secondary legislation, the less ground in principle would be covered by content to which the complex definition applies. The Secretary of State is not constrained by the complex definition when designating priority harmful content. 

Nor, on the face of it, is the Secretary of State limited to physical or psychological harm. However, as already flagged, that may well not represent the intention of the government. That omission would be all the more curious, given that Ofcom has a consultation and recommendation role in the regulation-making process, and the simple definition – physical or psychological harm - does constrain Ofcom’s recommendation remit. 

The Secretary of State has a parallel power to designate priority illegal content (which underpins the section 9(3) duties above) by secondary legislation. He cannot include offences relating to:

-        Infringement of intellectual property rights

-        Safety or quality of goods (as opposed to what kind of goods they are)

-        Performance of a service by a person not qualified to perform it

In considering whether to designate an offence the Secretary of State does have to take into account, among other things, the level of risk of harm being caused to individuals in the UK by the presence of content that amounts to the offence, and the severity of that harm. Harm here does mean physical or psychological harm.  

As with harmful content, illegal content includes a residual category designed to catch illegality neither specifically identified in the draft Bill (terrorism and CSEA offences) nor designated in secondary legislation as priority illegal content. This category consists of “Other offences of which the victim or intended victim is an individual (or individuals).” This, while confined to individuals, is not limited to physical or psychological harm. 

The first round of secondary legislation designating categories of priority illegal and harmful content would require affirmative resolutions of each House of Parliament. Subsequent regulations would be subject to negative resolution of either House.

To the extent that the government’s rowback from the general definition of harm contained in the Full Response enables more vague and subjective kinds of harm to be brought back into scope of service provider duties, the risk of collateral damage to legitimate speech would correspondingly increase.

Internal contradictions

The draft Bill lays down various risk assessments that in-scope providers must undertake, taking into account a ‘risk profile’ of that kind of service prepared by Ofcom and to be included in its guidance about risk assessments.

As well as the Section 9(3) moderation and filtering duties set out above, for illegal content a service provider would be under a duty to take proportionate steps to mitigate and effectively manage the risks of harm to individuals, as identified in the service’s most recent illegal content risk assessment.

In parallel to these duties, the service provider is placed under a duty to have regard to the importance of protecting users’ right to freedom of expression within the law when deciding on, and implementing, safety policies and procedures.

However, since the very duties imposed by the draft Bill create a risk of collateral damage to legitimate speech, a conflict between duties is inevitable. The potential for conflict increases with the scope of the duties and the breadth and subjectivity of their subject matter. 

The government has acknowledged the risk of collateral damage in the context of Category 1 services, which would be subject to duties in relation to lawful content harmful to adults in addition to the duties applicable to ordinary providers.

Category 1 service providers would have to prepare assessments of their impact on freedom of expression and (as interpreted by the government's launch announcement) demonstrate that they have taken steps to mitigate any adverse effects. The government commented:

“These measures remove the risk that online companies adopt restrictive measures or over-remove content in their efforts to meet their new online safety duties. An example of this could be AI moderation technologies falsely flagging innocuous content as harmful, such as satire.” (emphasis added)

This passage acknowledges the danger inherent in the legislation: that efforts to comply with the duties imposed by the legislation would carry a risk of collateral damage by over-removal.  That is true not only of ‘legal but harmful’ duties, but also of the moderation and filtering duties in relation to illegal content that would be imposed on all providers.

No obligation to conduct a freedom of expression risk assessment could remove the risk of collateral damage by over-removal. That smacks of faith in the existence of a tech magic wand. Moreover, it does not reflect the uncertainty and subjective judgement inherent in evaluating user content, however great the resources thrown at it. 

Internal conflicts between duties, underpinned by the Version 3.0 approach to the notion of harm, sit at the heart of the draft Bill. For that reason, despite the government’s protestations to the contrary, the draft Bill will inevitably continue to attract criticism as - to use the Secretary of State's words -  a censor’s charter. 

 


Tuesday, 6 April 2021

Seriously annoying tweets

The row over Section 59 of the Police, Crime, Sentencing and Courts Bill is reminiscent of a backwater pond that has lain undisturbed for years. Then someone decides to poke a stick in it and all manner of noxious fumes are released.

In this instance the pond is the common law offence of public nuisance. The stick that has disturbed it is the government’s proposal to replace the common law offence with a statutory codification. The noxious fume that has been released is the risk of criminalising legitimate public protest.

Section 59 would replace the common law public nuisance offence with a statutory equivalent. The new offence would consist of intentionally or recklessly causing serious harm, or a risk of serious harm, to the public or a section of the public. Such harm would include “serious distress, serious annoyance, serious inconvenience or serious loss of amenity”. There would be a defence of reasonable excuse. “Serious annoyance”, in particular, has been criticised as overly broad.

Section 59 is situated in the Public Order part of the Bill: a collection of provisions about policing public demonstrations. But Section 59 is not limited to behaviour in the street. In impeccably technology-neutral fashion it would apply to any "act". Posting a tweet is as much an "act" as gluing oneself to the road.

Criticism of Section 59 has focused on its potential for affecting street protests. Little attention has been paid to 
online communications. How would “serious annoyance” translate from street to tweet? Is a seriously annoying tweet the same kind of thing as a seriously annoying street protest? Is the potential impact of the Section 59 offence greater, less or no different in the online rather than the physical environment? Spoiler alert: it is at least the same and probably greater. How much greater we can only guess at – reason enough to send Section 59 back to the drawing board.

Origin of Section 59

The official response to concerns about Section 59 is that there is nothing to see here: it merely implements the Law Commission’s 2015 recommendations for codification of the common law public nuisance offence. The Secretary of State for Justice during the Second Reading of the Bill described concerns about “annoyance” as a “canard” (see further below).

It does appear that the Law Commission’s recommendations excited no public controversy at the time. Its consultation paper attracted a total of 10 responses on the public nuisance offence, none of which opposed its overall proposals.

However, for at least two reasons things are not that simple. First, the Law Commission did not discuss how the offence might apply to public online communications. (For that matter it barely touched on real world protest, even though the common law offence had been deployed against "sit-down" demonstrations in the 1960s.)  Second, in recommending “serious annoyance” as a criterion it reformulated the common law offence in terms that, although intended to keep the statutory offence within clear bounds, may have the opposite result when applied to
online speech. It is hard to avoid the impression that the question of what “serious annoyance” might mean when transposed from street to tweet was not on the Law Commission’s radar. 

Before delving into those issues, some context is helpful. 

The Law Commission’s June 2015 report was the first product of a larger project to simplify the criminal law. The report recommended that the common law public nuisance offence should be replaced with a statutory codification. The statutory offence would differ in some respects from the common law offence. The mental element would be set at intention or recklessness rather than negligence. The statutory offence would have to prescribe a maximum penalty. The Law Commission made no recommendation as to that, other than to observe that the maximum sentence should reflect that the offence was intended to address serious cases for which other offences were not adequate. The Policing Bill proposes a maximum custodial sentence of 10 years.

The Law Commission’s proposals sat on the shelf for the best part of six years. Why the government has chosen this moment to blow the dust off them and poke a stick in the pond is a matter of speculation. Whatever the reason, the government has done it and now people are reading the wording of Section 59. They see “serious annoyance” and question how that wording would apply to street demonstrations. Equally, we can ask how it would apply to online behaviour.

The Law Commission did not consider online communications

Neither the 2015 Law Commission Report nor its preceding consultation paper addressed how the codified offence, including the “serious annoyance” language, might apply to public online communications such as social media posts. The common law offence was certainly capable of doing so, as the Law Commission later acknowledged in its 2018 Scoping Report on Abusive and Offensive Online Communications.

This extract from the 2015 Report illustrates how far removed the Law Commission’s focus was from online speech:
“In our view, its proper use is to protect the rights of members of the public to enjoy public spaces and use public rights (such as rights of way) without danger, interference or annoyance.”
For whatever reason, the 2015 Report paid little attention to the possible effect of the public nuisance offence on freedom of expression, whether offline or online. It did note that its proposed reasonableness defence “would include cases where the defendant’s conduct is in exercise of a right under Article 10 (freedom of expression) or 11 (freedom of assembly and association) of the European Convention on Human Rights.”

But it added in a footnote: “It is somewhat difficult to imagine examples in which this point arises in connection with public nuisance.” This comment is not easy to understand in the online context, where any application of the offence to an online post is likely to engage Article 10. Use of the common law offence against sit-down demonstrations in the 1960s also seems pertinent.

Over-vigorous application of a statutory offence might be greeted in similar terms to those employed by the Lord Chief Justice in the Twitter Joke Trial case (Chambers v DPP), an appeal from conviction under s.127 of the Communications Act 2003:
“The 2003 Act did not create some newly minted interference with the first of President Roosevelt's essential freedoms – freedom of speech and expression. Satirical, or iconoclastic, or rude comment, the expression of unpopular or unfashionable opinion about serious or trivial matters, banter or humour, even if distasteful to some or painful to those subjected to it should and no doubt will continue at their customary level, quite undiminished by this legislation.”
But when we are considering conversion of public nuisance into a statutory offence, is it enough to hope that what on the face of it looks like overly broad language (with concomitant chilling effects on speech) would be rescued by the ECHR?

The Law Commission’s reformulation 

The common law offence, as endorsed in 2005 in the leading House of Lords case of Rimmington, is articulated in terms of "endangering the comfort of the public". The Law Commission described that terminology as "somewhat archaic", "wide and vague" in everyday language, which "could include very trivial reasons for displeasure". It proposed instead: "serious distress, annoyance, inconvenience or loss of amenity". In Section 59 this is rendered as “serious distress, serious annoyance, serious inconvenience or serious loss of amenity”.

The Law Commission evidently considered that by recommending a change in language from "endangering the comfort of the public" to "serious annoyance" it was narrowing the potential scope of the offence. It certainly intended to exclude the possibility of catching trivial displeasure.

Yet, when applied to pure speech, the reformulation seems less constraining than the original. "Comfort" could be taken to connote a physical or sensory element that is not a requirement for "annoyance": consider the disruptive effect on the public of a hoax bomb threat, compared with public reaction to the contents of an offensive tweet. 

Back to Blackstone?

If "annoyance" is a well understood term in relation to the common law offence, might that provide a basis on which to interpret Section 59 narrowly? 
Blackstone referred to "nuisances that are an annoyance to all the King’s subjects". 

In the 1700s public nuisance concerned environmental and public health misdeeds such as "noisome and offensive stinks and smells", polluting the Thames, or taking a child infected with smallpox through a public street. 

Whilst those readily fit the description of annoyances, how would that read across to speech? Can we even conceptualise a foul-smelling tweet? A noxious vapour and an obnoxious tweet are categorically different, one impinging on the senses and the other on the mind. Yet under Section 59 the courts would be asked to apply the same statutory language to both. The one context does not provide a guide to the other.

As the Law Commission observed in its 2015 Report, the common law offence has expanded from those roots to cover such diverse behaviour as plotting to switch off the lights at a football match, threatening suicide by jumping from bridges, hosting acid house parties, hanging from bridges, jumping into a river during a boat race, sniffing glue in public, lighting flares or fireworks at football matches, or recording videos threatening bombings – what it called "general public misbehaviour".

As the common law offence has developed since Blackstone to cover a greater variety of misbehaviour, correspondingly greater caution has to be exercised over the language used to characterise the elements of the offence.

Did the Law Commission mean to include online communications?

If the Law Commission did not in its 2015 Report specifically consider the impact of its recommendations on online communications, might that be because the statutory offence was not intended to apply to them?

As a largely technical exercise in codification, a proposed statutory offence would be expected to mirror the scope of the common law offence unless explicitly stated otherwise.

As to the common law offence, Lord Nicholls in Rimmington posed the example of a hoax message of the existence of a public danger, such as a bomb in a railway station, communicated by telephone. That, he said, even if communicated to one person alone, would be a public nuisance because it was intended to be passed on to users of the railway station. If a message communicated in that way can be a public nuisance, then all the more so a tweet published directly to the world.

If there were any doubt about that, the Law Commission acknowledged in its 2018 Scoping Report on Abusive and Offensive Online Communications that the common law offence is already capable of applying to public social media posts. The Law Commission identified overlap with, for instance, existing statutory harassment and communications offences.

The 2015 Law Commission Report discussed the Rimmington judgment in detail. It did not suggest that misbehaviour covered by its proposed statutory offence should exclude electronic communications. The technology-neutral approach of Section 59 is no accident, even if the consequences for social media and internet communications were not discussed.

Would Section 59 be used against online behaviour?

The 2018 Law Commission Scoping Report observed: “Given the wide array of statutory offences covering online harassment, it is difficult to see public nuisance being justifiably used in favour of these other offences in cases of online harassment and stalking.”

It noted that the common law offence was “very broad in scope”. While acknowledging that the public nuisance offence could cover online behaviour, the Law Commission said that it was not aware of any prosecution. Nor does 
the Crown Prosecution Service social media prosecution guidance mention public nuisance. 

None of that, however, means that the same would hold true once the public nuisance offence is given statutory force. 

The Law Commission’s observation about justifiability of prosecution of the common law offence rests on the primacy given to statutory offences. As the Law Commission explained in its 2015 Report, there is a presumption against using a common law offence where the same territory is covered by a statutory offence. That falls away once the public nuisance offence itself becomes statutory.

More fundamentally, there
 is nothing like a statutory codification to bring a common law offence back to full life and vigour. Language embedded in a statute gains strength from the fact that it represents the explicit will of the legislature. No longer is the court incrementally developing a common law offence within the bounds of reasonable foreseeability in order to accommodate changing activities. For a statutory offence its task is to interpret specific words to which Parliament has expressly agreed. Once written down in a statute, words tend to take on a life of their own. The broader they are, the greater the potential for them to do so. 

Prosecutorial guidance

The Law Commission suggested that the effect of removing the presumption could be mitigated by development of prosecutorial guidance, which could state that the offence should not be used when a more specific offence is available except for good reasons. Prosecutorial discretion, however, is no substitute for an appropriately drawn offence. Where speech is concerned, reliance on prosecutorial discretion is apt to produce the kind of uncertainty that gives rise to a chilling effect on freedom of expression.

Even if relying on prosecutorial discretion to mitigate an over-broad offence were an acceptable way of proceeding in the past, for online speech it now has harmful consequences that do not apply offline. Why so? Because when online intermediaries (such as web hosts, discussion forums and social media platforms) are incentivised (or even, come the proposed Online Safety Bill, obliged on pain of regulatory sanctions) to remove illegal content, the test of illegality is not whether a prosecutor would decide to bring charges. It is whether the content falls within the letter of the statute. It matters more than ever before that the language of a statute should clearly and precisely catch only what it ought to catch and nothing more.

The canard of annoyance

The Secretary of State for Justice Robert Buckland, during the Bill’s Commons Second Reading, suggested that concern about the term annoyance was a “canard”. He prayed in aid the authority of Lord Bingham:
“The law had been restated with reference to the use of the word “annoyance” by none other than the late and noble Lord Bingham when he was in the House of Lords. He set out the law very clearly. Clause 59 amounts to no more than a reiteration of the excellent work of the Law Commission. To say anything else is, frankly, once again a confection, a concoction and a twisting of the reality.”
This presumably was a reference to Lord Bingham’s speech in Rimmington. Lord Bingham concluded that the common law public nuisance offence, interpreted in the way that he specified, passed the legality test:
“A legal adviser asked to give his opinion in advance would ascertain whether the act or omission contemplated was likely to inflict significant injury on a substantial section of the public exercising their ordinary rights as such: if so, an obvious risk of causing a public nuisance would be apparent; if not, not."
Did Lord Bingham intend "significant injury" to include "serious annoyance"? The critical passage in his speech is at paragraph 36:
“I would for my part accept that the offence as defined by Stephen, as defined in Archbold (save for the reference to morals), as enacted in the Commonwealth codes quoted above and as applied in the cases (other than R v Soul 70 Cr App R 295) referred to in paras 13 to 22 above is clear, precise, adequately defined and based on a discernible rational principle.”
The offence as defined by Stephen was quoted by Lord Bingham at para 10 of his speech. It does not include "annoyance". In paragraphs 9 and 10 he quoted the offence as defined in different editions of Archbold. Again there is no mention of "annoyance". He went on in paragraph 11 to examine the Commonwealth codes of Canada, Queensland and Tasmania. None of those mentions "annoyance". At paragraphs 13 to 22 of his speech he reviews numerous cases. None of the passages from judgments that he quotes mentions "annoyance".

“Annoyance” was, however, mentioned in the two authorities that Lord Bingham quoted in paragraph 8 of his speech: Hawkins Pleas of the Crown (1716) Blackstone’s Commentaries (1768). Lord Bingham omitted both of those from the critical passage quoted above, endorsing only Stephen and Archbold.

That leaves the reference in paragraph 10 of Lord Bingham’s speech to Section 268 of the Indian Penal Code of 1860. That Commonwealth provision includes the phrase "common injury, danger or annoyance". Lord Bingham commented that it seemed likely that the draftsman of that provision intended to summarise the English common law on public nuisance "as then understood". 

Whatever may have been the position in 1860, today there is every reason to doubt whether the expression “serious annoyance” captures either the common law offence as it currently applies, or the statutory offence as it ought to apply, to public online communications.

[7 April 2021. Added “Commonwealth” to penultimate paragraph.] 



Sunday, 7 February 2021

Corrosion-proofing the UK’s intermediary liability protections

The UK having now cut its direct ties with EU law, what does its future hold for the intermediary liability protections in Articles 12 to 15 of the Electronic Commerce Directive?

Until recently, the government’s policy has been taken to be as stated in its 2019 “eCommerce Directive guidance for businesses if there’s no Brexit deal”:

“Immediately following the UK’s exit from the EU in a no deal scenario, the government will minimise disruption by prioritising continuity and stability. Therefore the UK’s policy approach will continue to align with the provisions contained in the Directive, including those on liability of intermediary service providers and general monitoring.”

Consistently with that, in October 2020 the government published post-transition guidance, stating that it "has no current plans to change the UK’s intermediary liability regime or its approach to prohibition on general monitoring requirements".

Articles 12 to 14 provide limitations on the liability of conduits, caches and hosts for unlawful user information. Article 15 prohibits EU member states from imposing general monitoring obligations on those intermediaries. Whether and how long the government’s commitment to Articles 12 to 15 would survive was an open question. With nothing said in the UK-EU Trade and Co-Operation Agreement about online intermediary liability, there appeared to be nothing to prevent the government – should it wish to depart from its previous policy – from legislating in future contrary to Articles 12 to 15 - subject always to the possibility of a legal objection on fundamental rights grounds.

There was a detectable drift away from the overt commitment to Article 15 with the publication of the government’s Full Consultation Response to the Online Harms White Paper, published on 15 December 2020. The Response strayed into proposing proactive monitoring obligations that could not readily be reconciled with that policy. That drift was also evident in the simultaneously published Interim Voluntary Codes of Practice on Terrorism, and Online Child Sexual Exploitation and Abuse, which are in effect a template for obligations likely to be imposed under the future Online Safety Bill. The Full Response was silent on the apparent conflict with Article 15.

Now, the government has dropped its commitment to maintain alignment with Article 15. A new version of its post-Brexit eCommerce Directive guidance, published on 18 January 2021, says this:

“The eCommerce Directive also contains provisions relating to intermediary liability and prohibitions against imposing general monitoring obligations.

The government is committed to upholding the liability protections now that the transition period has ended. For companies that host user-generated content on their online services, there will continue to be a ‘notice and take down’ regime where the platform must remove illegal content that they become aware of or risk incurring liability.

The government also intends to introduce a new Online Safety regulatory framework. This will require companies to take action to keep their users safe, including with regard to illegal content. Details on what this will mean for companies are set out in the Online Harms White Paper: Full government response to the consultation, and the government plans to introduce legislation to Parliament this year.”

Notably, although a commitment to preserving some kind of hosting protection remains, there is now silence on preserving the prohibition on general monitoring obligations. The significance of this omission can hardly be overstated.

Legislation that takes conscious bites out of the Directive’s protections is one thing. But there is also a more subtle threat. Active maintenance of the statute book will be needed if the liability protections to which the government appears to be committed are not to be corroded by simple neglect. The Article 12 to 14 protections for conduit, caching and hosting activities are potentially liable to erode over time as the statute book is augmented and amended.

The reason for this lies partly in the horizontal nature of the protections. They are not tailored specifically to copyright, to defamation, to obscenity, or to any of the other myriad kinds of criminal and civil liability that might be incurred online.  Articles 12 to 14 are shields that apply across the board, whatever the subject matter of the liability.

The risk of erosion lies in the way in which successive governments have gone about legislating those protections. When the ECommerce Directive was first implemented in UK law, the 2002 Regulations enacted the Art 12 to 14 liability protections across the board: they applied to all existing laws under which liability within scope of the Directive might be incurred (except for financial services, for which the protections were legislated separately).

But, crucially, the 2002 Regulations stated that they did not have prospective effect. This meant that they applied only to legislation in existence when they came into force. On every occasion thereafter that a new criminal offence or civil wrong was created, or an existing one amended, the protections required by Arts 12 to 14 had to be specifically enacted for that offence or civil wrong. Administrative Guidance on Consistency of Future Legislation issued at the time by the Department of Trade and Industry stated:

“Legislators will need to give careful consideration to the question of whether any new requirements - again, whether in primary, secondary or tertiary legislation and whether reserved or devolved- create any offences which (or the aiding or abetting of which) could possibly be committed by a mere conduit, cache or host within the meanings of Regulations 17-19. If so, they will need to ensure that they recognise these limitations on the liability of intermediary service providers. Similar considerations will apply to any form of civil liability created by any new requirements.”

In an ideal world, this would have been done within the primary legislation that created the new or amended liability. Sometimes that happened. We can, for instance, see the conduit, caching and hosting protections included in Schedule 1 of the Hate Crime and Public Order (Scotland) Bill currently making its way through the Scottish Parliament. Sometimes, however, it was overlooked and the omission had to be remedied separately. Since the protections were required by an EU Directive, the necessary provisions could be enacted pre-Brexit by secondary legislation under the European Communities Act 1972. This was done on around 15 occasions, in addition to regulations implementing the protections for the financial services sector.

The result is a veritable hodgepodge of primary and secondary legislation enacted over the best part of 20 years, implementing – not always using the same language – the intermediary protections required by Articles 12 to 14 of the Directive. At my last count, in addition to the 2002 Regulations themselves there were over 30 separate subject matter-specific implementations dotted around different primary and secondary legislation – and I may well not have found them all.

Post-Brexit, the option of plugging gaps via European Communities Act is no longer available. There will therefore be a greater premium on ensuring that, as in the Scottish Hate Crime Bill,  the protections are included in the relevant legislation itself. If active scrutiny and maintenance are neglected, and the requisite protections are omitted from future legislation that creates new offences and civil liability, there will be a slow accretion of liabilities and offences to which the Directive’s conduit, caching and hosting protections do not apply. 

If an omission has to be remedied, it would (unless some usable order-making power that I have not spotted is buried somewhere in the Brexit legislation) have to be done by further primary legislation. 

There [was, but is no longer] one potential qualification to this analysis. Could “Retained EU law” under the 2018 Withdrawal Act give the Directive itself a degree of post-Brexit prospective effect? If so, could the Directive’s liability protections be invoked against a future offence created by post-Brexit legislation which has omitted to address the liability position of conduits, hosts and caches? I do not pretend to know the answer to that, other than noting that the 2002 DTI Administrative Guidance was in no doubt that the liability provisions of the Directive had direct effect:

“If legislators fail to address such issues or fail to make proper provisions, the Directive will have direct effect in prohibiting them from imposing liability.”

However, any potential retention of direct effect would not offer any assistance in civil liability cases, since direct effect of Directives has been limited to the state, and not extended horizontally to affect rights as between private parties. For the Directive's intermediary liability protections the CJEU held as such in Papasavvas (C-291/13). [Moreover, direct effect now cannot be invoked for facts arising since enactment of the Retained EU Law (Revocation and Reform) Act 2023.]

[Amended 8 and 10 Feb 2021 to add reference to October 2020 government guidance; and 9 March 2021 to add reference to Papasavvas; and 19 June 2025 to add abolition of direct effect.]


Monday, 28 December 2020

Internet legal developments to look out for in 2021

Seven years ago I started to take an annual look at what the coming year might hold for internet law in the UK. This exercise has always, perforce, included EU law. With Brexit now fully upon us future developments in EU law will no longer form part of UK law. Nevertheless, they remain potentially influential: not least, because the 2018 EU Withdrawal Act provides that UK courts may have regard to anything relevant done by the CJEU, another EU entity or the EU after 31 December. In any case I am partial to a bit of comparative law. So this survey will continue to keep significant EU law developments on its radar.

What can we expect in 2021?

Copyright

Digital Single Market
EU Member States are due to implement the Digital Copyright Directive by 7 June 2021. This includes the so-called snippet tax (the press publishers’ right) and the Article 17 rules for online sharing service providers (OSSPs). The UK is not obliged to implement the Directive and has said that it has no plans to do so. Any future changes to the UK copyright framework will be “considered as part of the usual domestic policy process”.

The Polish government’s challenge to Article 17 (Poland v Parliament and Council, Case C-401/19) is pending. Poland argues that Article 17 makes it necessary for OSSPs, in order to avoid liability, to carry out prior automatic filtering of content uploaded online by users, and therefore to introduce preventive control mechanisms. It contends that such mechanisms undermine the essence of the right to freedom of expression and information and do not comply with the requirement that limitations imposed on that right be proportionate and necessary.

Linking and communication to the public The UK case of Warner Music/Sony Music v TuneIn is due to come before the Court of Appeal early in 2021.

Pending CJEU copyright cases Several copyright references are pending before the EU Court of Justice.

The YouTube and Uploaded cases (C-682/18 Peterson v YouTube and C-683/18 Elsevier v Cyando) referred from the German Federal Supreme Court include questions around the communication to the public right, as do C-392/19 VG Bild-Kunst v Preussischer Kulturbesitz (Germany, BGH), C-442/19 Brein v News Service Europe (Netherlands, Supreme Court) and C-597/19 Mircom v Telenet (Belgium). Advocate General Opinions have been delivered in YouTube/Cyando, VG Bildt-Kunst and Mircom.

YouTube/Cyando and Brein v News Service Europe also raise questions about copyright injunctions against intermediaries, as does C-500/19 Puls 4 TV.

Linking, search metadata and database right

C-762/19 CV-Online Latvia is a CJEU referral from Riga Regional Court concerning database right. The defendant search engine finds websites that publish job advertisements and uses hyperlinks to redirect users to the source websites, including that of the applicant. The defendant’s search results also include information - hyperlink, job, employer, geographical location of the job, and date – obtained from metatags on the applicant’s website published as Schema.org microdata. The questions for the CJEU are whether (a) the use of a hyperlink constitutes re-utilisation and (b) the use of the metatag data constitutes extraction, for the purposes of database right infringement.

Online intermediary liability

The UK government published its Full Consultation Response to the Online Harms White Paper on 15 December 2020, paving the way for a draft Online Safety Bill in 2021. The government has indicated that the draft Bill will be subject to pre-legislative scrutiny.

The German Federal Supreme Court has referred two cases (YouTube and Cyando – see above) to the CJEU asking questions about (among other things) the applicability of the ECommerce Directive hosting protections to UGC sharing sites. The Advocate General’s Opinion in these cases has been published.

Brein v News Service Europe and Puls 4 TV (see above for both) also ask questions around the Article 14 hosting protection, including whether it is precluded if communication to the public is found.

The European Commission published its proposals for a Digital Services Act and a Digital Markets Act on 15 December 2020. The proposed Digital Services Act includes replacements for Articles 12 to 15 of the ECommerce Directive.  The proposals will now proceed through the EU legislative process.

The European Commission’s Proposal for a Regulation on preventing the dissemination of terrorist content online is nearing the final stages of its legislative process, the Council and Parliament having reached political agreement on 10 December 2020. The proposed Regulation is notable for requiring one hour takedown response times and also for proactive monitoring obligations - potentially derogating from the ECommerce Directive Article 15 prohibition on imposing general monitoring obligations on conduits, caches and hosts.

The prospect of a post-Brexit UK-US trade agreement has prompted speculation that such an agreement might require the UK to adopt a provision equivalent to the US S.230 Communications Decency Act. However, if the US-Mexico-Canada Agreement precedent were adopted in such an agreement, that would appear not to follow (as explained here).

Cross-border 

The US and the UK signed a Data Access Agreement on 3 October 2019, providing domestic law comfort zones for service providers to respond to data access demands from authorities located in the other country. No announcement has yet been made that Agreement has entered into operation. The Agreement has potential relevance in the context of a post-Brexit UK data protection adequacy decision by the European Commission.

Discussions continue on a Second Protocol to the Cybercrime Convention, on evidence in the cloud.

State surveillance of communications


The kaleidoscopic mosaic of cases capable of affecting the UK’s 
Investigatory Powers Act 2016 (IP Act) continues to reshape itself. In this field CJEU judgments remain particularly relevant, since they form the backdrop to any data protection adequacy decision that the European Commission might adopt in respect of the UK post-Brexit. The recently agreed UK-EU Trade and Co-operation Agreement provides a period of up to 6 months for the Commission to propose and adopt an adequacy decision.

Relevant CJEU judgments now include, most recently, Privacy International (Case C-623/17), La Quadrature du Net (C-511/18 and C-512/18), and Ordre des barreaux francophones et germanophone (C-520/18) (see discussion here and here).

Domestically, Liberty has a pending judicial review of the IP Act bulk powers and data retention powers. Some EU law aspects (including bulk powers) were stayed pending the Privacy International reference to the CJEU. The Divisional Court rejected the claim that the IP Act data retention powers provide for the general and indiscriminate retention of traffic and location data, contrary to EU law. That point may in due course come before the Court of Appeal.

In the European Court of Human Rights, Big Brother Watch and various other NGOs challenged the pre-IP Act bulk interception regime under the Regulation of Investigatory Powers Act (RIPA). The ECtHR gave a Chamber judgment on 13 September 2018. That and the Swedish Rattvisa case were subsequently referred to the ECtHR Grand Chamber and await judgment. If the BBW Chamber judgment had become final it could have affected the IP Act in as many as three separate ways.

In response to one of the BBW findings the government has said that it will introduce ‘thematic’ certification by the Secretary of State of requests to examine bulk secondary data of individuals believed to be within the British Islands.

Software - goods or services?

Judgment is pending in the CJEU on a referral from the UK Supreme Court asking whether software supplied electronically as a download and not on any tangible medium constitutes goods and/or a sale for the purposes of the Commercial Agents Regulations (C-410/19 Computer Associates (UK) Ltd v The Software Incubator Ltd). The Advocate General’s Opinion was delivered on 17 December 2020.

Law Commission projects

The Law Commission has in train several projects that have the potential to affect online activity.

It is expected to make recommendations on reform of the criminal law relating to Harmful Online Communications in early 2021. The government has said that it will consider, where appropriate, implementing the Law Commission’s final recommendations through the forthcoming Online Safety Bill. The Law Commission issued a consultation paper in September 2020 (consultation closed 18 December 2020).

The Law Commission has also issued a Consultation Paper on Hate Crime Laws, which while not specifically focused on online behaviour inevitably includes it (consultation closed 24 December 2020).

It has recently launched a Call for Evidence on Smart Contracts (closing 31 March 2021) and is also in the early stages of a project on Digital Assets.

Electronic transactions

The pandemic has focused attention on legal obstacles to transacting electronically and remotely. Whilst uncommon in commercial transactions, some impediments do exist and, in a few cases, have been temporarily relaxed. That may pave the way for permanent changes in due course.

Although the question typically asked is whether electronic signatures can be used, the most significant obstacles tend to be presented by surrounding formalities rather than signature requirements themselves. A case in point is the physical presence requirement for witnessing deeds, which stands in the way of remote witnessing by video or screen-sharing. The Law Commission Report on Electronic Execution of Documents recommended that the government should set up an Industry Working Group to look at that and other issues.

Data Protection 

Traditionally this survey does not cover data protection (too big, and a dense specialism in its own right). On this occasion, however, the Lloyd v Google appeal pending in the UK Supreme Court should not pass without notice.

ePrivacy

EU Member States had to implement the Directive establishing the European Electronic Communications Code (EECD) by 21 December 2020. The Code brings ‘over the top’ messaging applications into the scope of ‘electronic communications services’ for the purpose of the EU telecommunications regulatory framework. As a result, the communications confidentiality provisions of the ePrivacy Directive also came into scope, affecting practices such as scanning to detect child abuse images. In order to enable such practices to continue, the European Commission proposed temporary legislation derogating from the ePrivacy Directive prohibitions. The proposed Regulation missed the 21 December deadline and continues through the EU legislative process.

Meanwhile there is as yet no conclusion to the long drawn out attempt to reach consensus on a proposed replacement for the ePrivacy Directive itself. 

[Updated 29 December 2020 to add sections on Data Protection and ePrivacy.]