Saturday, 12 July 2014

Dissecting DRIP - the emergency Data Retention and Investigatory Powers Bill

[Update: DRIP became law on Thursday 17 July 2014. The Act is available here. Post-Act analysis here.]

Three months after the EU Court of Justice invalidated the EU Data Retention Directive, the UK government has burst into feverish action with emergency legislation to replace the 2009 Data Retention Regulations.  Those Regulations, made under the European Communities Act, are nominally still in place but highly vulnerable to judicial review following the demise of the Directive.

What does DRIP (the inevitable acronym with which the Data Retention and Investigatory Powers draft Bill has been saddled) do? With so much material appearing at such short notice, considered analysis is difficult.  Here are some first impressions.
DRIP, now with its accompanying provisional draft regulations which appeared on the Home Office website yesterday afternoon, has to square a circle.  Ideally it should make a plausible attempt to address the 15 or so fundamental rights grounds on which the ECJ held that the Data Retention Directive was invalid.  But at the same time DRIP has to deliver on Theresa May’s 10 July statement to the House of Commons that it maintains the status quo until 31 December 2016, when the sunset clause kicks in.

In reality DRIP cannot square the circle. Indeed the newly published Impact Assessment recognises that the legislation does not overcome all the ECJ stumbling blocks, claiming only to address the ECJ judgment “where possible” and “to the extent practicable”.  It also acknowledges the “Risk of being perceived as ignoring the ECJ judgment”.

[Update: The Home Office Human Rights Memorandum published by the Joint Committee on Human Rights on 16 July 2014 says in paragraph 33 (p. 8) that the Bill, together with existing domestic legislation, addresses "the majority of the criticisms of the Directive set out in the ECJ's judgment". The Committee has written to the Home Secretary asking her to provide the Committee with "a further detailed memorandum setting out in full the Government's analysis of precisely how UK law satisfies, or will satisfy, each of the requirements set out in paras 54 to 68 of the CJEU's judgment.]

We can frame two simple questions.
  1. Does DRIP merely maintain the status quo?
  2. If so, how far is maintaining the status quo permissible in the light of the ECJ decision?
First, however, we should recognise that DRIP does far more than replace the 2009 Data Retention Regulations.  It makes substantive changes to the interception warrants, interception capability and communications data access provisions of the Regulation of Investigatory Powers Act (RIPA).  The Home Secretary has justified these amendments on a different basis from the data retention legislation: an urgent need to clarify, in particular, the territorial scope of RIPA's interception and communications data acquisition provisions.
These are the non-data retention aspects of DRIP.
  • Clause 4 addresses the government’s concern that it should be able to apply RIPA to non-UK companies that provide communications services to the UK public.
  • Clause 5 broadens the RIPA definition of telecommunications services. The Explanatory Note says this is so that webmail providers are clearly caught.  The change will also have implications for data retention because of crossover into DRIP.
  • Clause 3 places a further restriction on the general purposes for which interception warrants and communications data acquisition notices can be issued.  This will bring RIPA into line with the existing codes of practice.
Whatever the merits of the non-data retention amendments (more on that below), it is debatable why any of them requires emergency legislation to be fast-tracked through Parliament at such breakneck speed.  They seem to be taking a piggy-back ride on the government’s urgent need for primary legislation in the wake of the ECJ’s data retention decision.

In relation to data retention, does DRIP merely maintain the status quo?
Putting Clauses 3 to 5 aside, let us focus on the claim that for data retention DRIP merely maintains the status quo.  This splits into three questions:
  • Are the same providers as before required to retain data?  
  • Are they required to retain the same data?
  • Are the retention periods the same?
Are the same providers as before required to retain data?
This is difficult to answer, as the government is shifting from one existing set of definitions to another and then amending them for good measure.  Conspiracy theorists will smell a rat. Even the more generous may chalk up another example of the obscurantist law-making for which this field is notorious.

The 2009 Data Retention Regulations were based on EU definitions of publicly available electronic communications services and networks in the EU communications Framework Directive, implemented in the UK by the Communications Act 2003.
DRIP, however, abandons those EU definitions and instead adopts the homegrown RIPA definitions of public telecommunications systems and service.  It then amends the latter, which has been in place for 14 years.

Why, if the intention is to continue the status quo, does DRIP not simply continue to use the definitions in the Communications Act 2003?  The Explanatory Note (para 53) says that this is to "ensure uniform definitions across access and retention regimes".  

It is anyone's guess at this stage whether these changes will cast a wider net than the existing 2009 Regulations.  That would require detailed comparison of the two sets of definitions and a truckload of hypotheticals.  What is quite clear, however, is that they broaden the RIPA definitions.
The existing RIPA definition of telecommunication service is framed in terms of a service consisting in the “provision of access to, and of facilities for making use of, a telecommunications system”: two discrete elements related to the telecommunications system. 
DRIP Clause 5 says that the RIPA definition is now to cover a service that “consists in or includes facilitating the creation, management or storage of communications transmitted, or that may be transmitted, by means of such a system.”

The Explanatory Note (para 71) says that this is in order to ensure that companies who provide internet-based services, such as webmail, are caught.  Although para 18 of the Explanatory Note says that the amendment is “for the purposes of communications data and interception requests”, it also applies to the new mandatory data retention regime under DRIP.  
On the face of it the amendment could apply not just to webmail, but to any remote storage service (bearing in mind that the meaning of “communication” under RIPA is effectively anything capable of being transmitted). The word “facilitating” is a red flag for broad interpretation.  There is obvious potential for this to cover a very broad spectrum of activities.  It is exactly the type of provision that deserves the fullest Parliamentary scrutiny. 

The Home Office is reported in the Sunday Times (13 July 2014, subscription) as saying, in relation to this amendment to RIPA: "The bill clarifies how the current definition should be interpreted, but this cannot change or extend the meaning of the definition in RIPA to capture new services." This is twaddle.  In effect the amendment says "A shall be taken to include B." To the extent that B covers anything not within A, new services are captured.  Even if different views might exist on whether B does in fact cover things not within A, to suggest that the amendment 'cannot' capture new services is nonsense.  
Are they required to retain the same data?
The Explanatory Notes stress that a DRIP notice (i.e. a notice by the Secretary of State to a public telecommunications operator) cannot require retention of data types additional to those specified in the existing legislation. This is achieved by defining 'relevant communications data' by reference to the Schedule to the 2009 Regulations, which sets out the specific types of communications data that a CP could be required to retain.

The definition also carries through the important qualification that such data is caught only so far as it is generated or processed in the UK by public telecommunications operators in the process of supplying the telecommunications services concerned.  In other words, a PTO  cannot be required to create data if it does not generate or process it in the course of supplying those services. 
Generally, this appears faithfully to replicate the 2009 Regulations.  However the adoption and amendment of the RIPA definitions of telecommunications services and systems (see above) could conceivably affect the scope of data falling within "relevant communications data".

Are the retention periods the same?
The existing 2009 Regulations mandate retention for 12 months. DRIP (subject to an apparent drafting defect) provides for a maximum retention period of 12 months, while enabling shorter periods to be specified for different purposes. 

The defect is that if no regulations were in place specifying a maximum retention period under S1(4)(b), then the Secretary of State could apparently issue a notice under S1(2)(c) requiring retention for longer than 12 months. It is hard to believe that the government intends this to be a possibility.  The provisional draft regulations do specify a maximum period of 12 months.
Is maintaining the status quo for data retention permissible after the ECJ judgment?
The extent to which the government will in the new legislation address the grounds on which the ECJ invalidated the Data Retention Directive was initially unclear, since much is to be implemented through secondary legislation requiring affirmative resolutions of the Commons and the Lords.  DRIP and the now published provisional draft regulations go some way to addressing the ECJ judgment, although it was always difficult to see how any form of general mandatory data retention could comply with some of the more fundamental issues identified in the ECJ judgment. 

There may be room for debate about whether the ECJ intended to lay down that every objection identified in the judgment is a self-standing issue that has to be overcome independently in national legislation; and if so how each one should be overcome.  It does have to be remembered that:
  • The ECJ was assessing the compatibility of EU legislation with the EU Charter of Fundamental Rights and Liberties.
  • The question of whether national legislation also has to comply with the EU Charter was not before the Court (although following the subsequent Pfleger decision of the ECJ it is very likely that national legislation does have to comply with the Charter, for reasons explained by Professor Steve Peers here).
  • National legislatures may have a certain degree of latitude (margin of appreciation) in how they comply with the Charter.
  • The ECJ judgment may in some respects have applied stricter standards under the Charter than the European Court of Human Rights in Strasbourg has done in respect of the Convention.  If so, that could open up the possibility that a Minister might certify DRIP compliance with the European Convention on Human Rights while not complying with all aspects of the ECJ judgment.
In any event the main Impact Assessment now makes tolerably clear that the government has not tried to comply with the full implications of the ECJ judgment. 

With all this in mind, it is instructive to list the ECJ's specific grounds for invalidating the Data Retention Directive and consider how DRIP does and does not address them. [Update: the government has now published a Note making its own comparison.]

Issue [paragraph number in ECJ judgment]
National legislation
Generality
●          Applies to all means of electronic communication (use widespread and of growing importance in people’s everyday lives) [56]
●          All subscribers and registered users [56]
●          Interference with fundamental rights of practically the entire European population [56]
●          All persons, all means of electronic communication without any differentiation, limitation or exception [57]
The ECJ's comments on generality referred specifically to the datatypes listed in Article 5 of the Directive.  Those were replicated in the Schedule to the 2009 Regulations.
 
No change in DRIP, which replicates the 2009 Schedule/Article 5 list.  
Suspicionless
●          Applies even to persons for whom no evidence capable of suggesting a link, even indirect or remote, with serious crime [58]
●          No relationship required between data retained and a threat to public security: not restricted to:
•         data pertaining to:
-           particular time period
-           particular geographical zone
-           circle of particular persons likely to be involved in serious crime [59]
•         persons whose data for other reasons could contribute to prevention, detection or prosecution of serious offences [59]
These objections all go to the very heart of a requirement on communication service providers to retain communications data of all users.  It is difficult to see how DRIP could address these (as a matter of retention, rather than access) without fundamentally altering the nature of the retention to something targeted at specific categories of communications relating to likely suspects and associates.

Not addressed.
Specific rights
●      Applies to persons whose communications are subject to professional secrecy [58]
Again, it is difficult to see how this could be addressed (as a matter of retention) without moving to some kind of targeted scheme.

Not addressed [Update: Not addressed as a matter of retention. Intention is that Communications Data Code of Practice will be amended regarding access (See Comms Data Factsheet)].
Access and use
●      No objective criterion to determine limits of access to data and subsequent use for prevention, detection or prosecution of sufficiently serious offences [60]
●      Leaves serious crime definition to national law [60]
●      No substantive and procedural conditions relating to access and subsequent use
•         Left to member States to define procedures and conditions in accordance with necessity and proportionality [61]
•         In particular no objective criteria re restriction of number of persons authorised to access and subsequently use to that strictly necessary [62]
Should be capable of being addressed in national legislation. 

The government is relying in part on the provisions of RIPA governing access to communications data to satisfy these requirements. 
RIPA is not the only legislation that can be used to require access to communications data.  The use of other powers is discouraged in the Communications Data Code of Practice, but not forbidden. The government addresses this under DRIP S1(6) by limiting access to mandatorily retained data to RIPA authorisations and notices, court orders or other judicial authorisation or warrant, or regulations under DRIP. (See 'Joining DRIP to RIPA', below)
Independent supervision
●      Above all, access not dependent on prior review by court or independent administrative body following a reasoned request
•         No obligation on MS to establish such limits [62]
Capable of being addressed in national legislation.

But this requirement for prior review by a court or independent body is contrary to the scheme of RIPA, whose communications data acquisition notices are not (save for local authorities) subject to any such requirement.  Nothing in DRIP or the provisional draft regulations addresses this objection. The government may perhaps seek to suggest that the ECJ has set a higher threshold than applies under the European Convention on Human Rights.
Retention period
●      No distinction between categories of data on basis of:
•         possible usefulness
•         persons concerned [63]
●      No objective criteria limited to strict necessity on which to base determination of retention period [64]
Capable of being addressed in national legislation.

The government's intention appears to be to leave this aspect to the terms of individual retention notices issued by the Secretary of State, who is required in general terms to act in a way that he considers to be necessary and proportionate.  DRIP itself and the provisional draft regulations do no more than set an overall maximum 12 months retention period.
Data protection issues
Various issues raised by the ECJ concerning matters such as data security and destruction of data are addressed in the provisional draft regulations, which also introduce oversight of these aspects by the Information Commissioner.

Joining DRIP to RIPA
The government is relying on the necessity, proportionality and safeguards provisions of RIPA that govern access to communications data in order to address some of the implications of the ECJ judgment. 

However, RIPA is not the only legislation that can be used to access retained communications data.  Other powers exist which do not enjoy RIPA's safeguards. The use of other non-specific powers is deprecated in the Communications Data Code of Practice (para 1.3), but not forbidden.
The draft Communications Data Bill proposed in 2012 would have prevented such powers being used to acquire communications data.  The draft Explanatory Note to Clause 24 stated:

"123. This clause introduces Schedule 2 to the Bill which contains repeals of certain general information powers so far as they enable public authorities to secure the disclosure by a telecommunications operator of communications data without the consent of the operator. Clause 24 therefore ensures that operators are not required by law to obtain and disclose communications data other than in cases where the relevant statutory framework expressly guarantees the substantive protections of Article 8 and Directive 2002/58/EC (Directive on privacy and electronic communications)."
The powers specifically earmarked for abolition were under the Trade Descriptions Act 1968, The Health and Safety at Work Act 1974, the Criminal Justice Act 1987, the Consumer Protections Act 1987, the Environmental Protection Act 1990, the Social Security Administration Act 1992, the Competition Act 1998, the Financial Services and Markets Act 2000 and the Enterprise Act 2002.

The argument that in assessing compliance with the ECJ judgment DRIP should be read together with RIPA’s safeguards is difficult to maintain if other powers exist that may not have similar safeguards.  DRIP therefore addresses this in S1(6) by limiting access to mandatorily retained data to RIPA authorisations and notices, court orders or other judicial authorisation or warrant, or regulations under DRIP.  Part 3 of the provisional draft regulations also applies this limitation to data retained voluntarily under S.102 ACSA 2001.
DRIP's RIPA provisions

The new provisions in DRIP include Clauses 4 and 5, outlined briefly above. According to the Explanatory Note, these measures are only intended to clarify the intent of the current legislation and therefore were subject to Parliamentary scrutiny when RIPA was enacted in 2000. 
RIPA extra-territoriality
Clause 4 attempts to address the government’s concern that it should be able to apply RIPA interception capability notices, interception warrants and communications data acquisition notices to non-UK companies that provide communications services to the UK public.

18 months ago this issue was addressed in some detail, as regards communications data notices, in the report of the Joint Committee on the draft Communications Data Bill (paras 230 to 243) published in December 2012.

The DRIP clarification has two distinct aspects. One is whether, as a matter of interpretation, the warrantry and communications data acquisition provisions of RIPA can apply to conduct outside the UK. The second is how a RIPA warrant or a notice can be served on an entity outside the UK and the entity made subject to the relevant duty under RIPA.  This is important since no-one is obliged to do anything under these RIPA provisions unless they are served with or given the appropriate warrant or notice.

As to the first aspect, none of the existing RIPA provisions contain any clear territorial limitation on the location of conduct that can be authorised or required under a warrant or communications data notice.  That contrasts with the criminal offence of unauthorised interception which is explicitly confined to conduct within the United Kingdom.
However location of conduct is only part of the issue.  A person located outside the UK may engage in conduct within the UK.  A person located within the UK may engage in conduct outside the UK; and a person located outside the UK may engage in conduct outside the UK.  How these different scenarios map onto the different aspects of RIPA is, and always has been, fearfully difficult to understand.
The Joint Committee said:
"The terms in which RIPA is drafted appear to impose no limits on the telecommunications operators which may be required to disclose communications data, as long as they operate in the United Kingdom i[t] does not matter where they may be based."
As to location of conduct, now DRIP states explicitly that a warrant, a capability maintenance notice and a communications data acquisition notice may each relate to conduct outside the UK.

DRIP then provides that the duties to comply with such warrants and notices apply whether or not the person is within the United Kingdom. In the case of interception warrants knowing failure to comply with the duty can give rise to criminal liability under RIPA S11(7).

DRIP then goes to great lengths to devise ways of serving warrants and notices within the UK on non-UK entities.  For communications data acquisition notices this can even include oral notification.  Whether this elaboration is simply a question of practicality or perhaps reflects a deeper concern that serving government warrants and notices outside the UK might be regarded as executive acts violating the territorial sovereignty of another State is a matter for speculation. 
As for data retention notices, DRIP provides that they can be given to an operator (or description of operators) by giving or publishing it in such manner as the Secretary of State considers appropriate for bringing it to the attention of the operator or description of operators to whom it relates.
Telecommunications services
As explained above, the amended definition of telecommunications services under DRIP Clause 5 applies both to data retention under DRIP and to RIPA. 

[Updated with minor amendments 21.40 12 July 2014, 10.50 13 July 2014; and 12.17 13 July 2014 to take account of Home Office statement on telecommunications services reported in The Sunday Times; 14:42 15 July 2014 regarding professional secrecy. Further updated 23:11 16 July 2014 to take account of Home Office Human Rights Memorandum; and 09:48 22 July 2014 to include the government's point by point Note on compliance with the ECJ judgment and a reference to the enacted legislation.]

Saturday, 24 May 2014

This tweet is a Section 127 offence

Section 127 of the Communications Act 2003 is a notorious blot on the statute book, epitomised by the ultimately unsuccessful prosecution of Paul Chambers (the Twitter Joke Trial) under the first limb of the section.  That concerns messages of a grossly offensive, indecent, obscene or menacing character sent by means of a public communications network.

The section is such a mess that the Director of Public Prosecutions had to devise a set of social media prosecution guidelines in attempt to avoid criminalising a substantial proportion of the population.

The less well known second limb of Section 127 is also extraordinarily broad.  It catches anyone who sends – again by means of a public communications network - a message that he knows to be false for the purpose of causing annoyance, inconvenience or needless anxiety to another.

The second limb was originally designed in the 1930s to catch a particularly unpleasant type of hoaxer who would send telegrams to people informing them that a relative was seriously ill (see Hansard).  Now, like the first limb, it can catch tweets.  (Tweets qualify because they are sent across public telecommunications networks.)

Putting aside the potential for the second limb to catch all sorts of harmless pranks, we can have some fun with it.

Consider the tweet that forms the title of this post: “This tweet is a Section 127 offence.” Could that tweet fall (however theoretically) within the second limb of Section 127?

The first requirement is that the message be false.  If the tweet is not an offence under Section 127, its message is false.  But if it is false, then Section 127 can bite.  But if that means the tweet is an offence, then the message is true and the tweet cannot be an offence. (For self-referential paradoxes, see here)  

Is the tweet sent for the purpose of annoying another?  Hardly (and indeed ‘another’ may suggest something targeted at a particular person). However a substantial section of the population detests logical puzzles and paradoxes and may conceivably be annoyed to discover that they have been lured into such a maddening game by following the link to this post in the tweet.

Finally, S.127 requires that the sender knows the message to be false. The tweet’s assertion that it is an offence under Section 127 is both preposterous and, by virtue of that falsity, potentially caught by S.127; and so (putting annoyance on one side) in turn possibly true.  I’ll leave to the philosophers whether I know to be false a message that I believe to be false, yet which endlessly loops through truth and falsity.


Thursday, 22 May 2014

Everyman and the data inspector

Everyman is dreaming of a future.

Data Inspector: Good morning, citizen. We have reason to believe you have data in this house.

Everyman: Who told you that?

DI: Someone who knows.

Everyman: It would be a strange house that didn’t have data in it, wouldn’t it?

DI: All the same, we have to act on reports received.

Everyman: At dawn?

DI: You heard us. We require entry to inspect the data on these premises. We suspect it may be inaccurate, incomplete or irrelevant to the purposes for which it was collected or further processed.

Everyman: This is my private house. It’s my personal information.

DI: Your personal information? We’ve heard it names other people. That makes it their information.

Everyman: It’s still my private house.

DI: From which you run a little business on eBay.  No household exception for you.

Everyman: I don’t have to answer your questions.

DI: Ah, but you do.  How else can we perform our duty to the public?

Everyman: What about my privacy?

DI: Privacy begins at home. So that's where we start.

Everyman: By invading my privacy?

DI: We protect privacy, we don’t invade it.

Everyman: You seem to be about to invade my home.

DI: Sometimes you have to sacrifice privacy to preserve privacy.

Everyman: So what do you want to know?

DI: Who is the data controller in this house?

Everyman: How should I know that?

DI: You are required to know that. The data controller should have notified us.

Everyman: Well you’ve got me there, haven’t you?

DI: When did you last clean your data?

Everyman: Clean?

DI: Scrub it - remove excessive, irrelevant or out of date data. We like to see hygienic data practices, citizen.  Dirty data is a menace.

Everyman: Sounds like the last public health campaign.

DI: Exactly.  Unclean data spreads.  We could have a national data contamination crisis on our hands.  You know our motto: “Healthy data makes a healthy mind”.

Everyman: So you think I’ve got a secret store of mouldy old data hidden away here, do you? 

DI: I’m sure of it.  We have a duty to discharge and you’re starting to be obstructive.

Everyman: What else do you want?

DI: Do all your appliances conform to privacy design standards?

Everyman: And if they don’t?

DI: You’ll be put on our list.

Everyman: What list is that?

DI: The privacy offenders register. Everyone should know who can and can’t be trusted with their data.

Everyman: How long would I be on it?

DI: Permanently.

Everyman: No right to be forgotten, then?

DI: Not where privacy breaches are concerned, my friend. Far too serious.

Everyman: Well, thank you for your interest. Now please leave.

DI: Not that simple, citizen.  Sledgehammer, please.

Everyman: (wakes up).


[Now dedicated to the memory of John Blundell, who died on 22 July 2014. Find out the connection here.]




Tuesday, 18 February 2014

Svensson - free to link or link at your risk?

[Updated 5 July 2014]
Last week's CJEU Svensson v Retriever decision has established some important points about the legality of linking under EU copyright law:
  1. A clickable direct link to a copyright work made freely available on the internet with the authority of the copyright holder does not infringe. 
  2. It makes no difference to that if a user clicking on the link is given the impression that the work is on the linking site.
  3. However, it appears that a clickable link will (unless saved by any applicable copyright exceptions) infringe if the copyright holder has not itself authorised the work to be made freely available on the internet (see further discussion below; [the UK Intellectual Property Office has adopted this interpretation in its Copyright Notice on Digital Images, Photographs and the Internet.]).
  4. If the work is initially made available on the internet with restrictions so that only the site’s subscribers can access it, then a link that circumvents those restrictions will infringe (again subject to any applicable exceptions and further discussion below).
  5. The same is true where the work is no longer available on the site on which it was initially communicated, or where it was initially freely available and subsequently restricted, while being accessible on another site without the copyright holder’s authorisation.
It seems to follow, although this is not very clear in the judgment, that a link to an infringing copy does not infringe if, and for so long as, a copy of the same work is freely available somewhere on the internet with the authority of the copyright holder. (“How could I possibly know that?” you ask.  More on that theme below.)  But this would not exempt links to infringing copies of works that are not legitimately available on the internet at all, or which have only been legitimately made available on the internet under restrictions.

In practical terms the Court has made a valiant attempt to balance the competing considerations of protecting rightsholders’ content without restricting reasonable user behaviour.  However among the commentators (see here, here, here and here - hat tip to these for some of the questions raised below) some are already suggesting that the CJEU’s reasoning – giving a very wide meaning to an act of communication, then reining back the scope according to whether the link makes the work available to a ‘new public’ compared with that contemplated by the copyright holder – may store up trouble for the future.

Open questions

Before delving into that, let’s mention some areas that Svensson may have left open for future decisions (such as, possibly, the pending references in C More Entertainment and Bestwater).

  1.  The Court draws a distinction between freely available content and, on the other hand, restricted content where a link circumvents the restrictions. Are those intended to be the only two possible categories, so that if a copyright work is not ‘restricted’ it is necessarily ‘freely available’? Or are they two ends of a spectrum, the middle of which has yet to be explored? What, for instance, would be the position if the copyright holder has authorised a licensee to make the content freely available on the internet, but the licensee makes it available only on a restricted basis?
  2. Does ‘restricted’ refer only to technical restrictions (and how sophisticated?), or does it also encompass licence or contractual restrictions?
  3. The judgment refers only to clickable links.  What about other varieties of link, or analogous technologies? The logic of the judgment would seem to apply to inline links where, rather than awaiting the user’s click, the linked-to content is served up automatically to the user when the web page is requested.
  4. The judgment refers to links ‘to’ copyright works, affording ‘direct’ access to those works. Does the link have to be to the actual work itself in order to make it available, or does a link to a page containing the work suffice? So applying the Svensson reasoning a clickable link to the URL of a news page makes available the HTML text of that page. Does it also make available a photograph which loads automatically as part of the news page, but which is nevertheless a separate copyright work with its own URL capable of being separately linked to? What about a playable video within the page, or a PDF downloadable from that page? Each of those is a separate copyright work requiring a further click by the user to access it.  Might they be regarded as indirectly, rather than directly, accessible from a link to the news page containing them?
  5. Does the reservation for subsequently removed or restricted works apply only to new links created after the initially freely available work was withdrawn or restricted, or do existing links to unauthorised copies automatically become infringing?
  6.  What is the position where initially the work was lawfully made freely available on the internet under an exception to copyright, such as fair dealing? Is that different from when it was done with the authorisation of the copyright holder?  On the face of it the Svensson version of the 'new public' test would not of itself legitimise linking in the former situation.
It is also important to understand that the Court's decision only concerns whether a link can amount to 'communication to the public' for the purposes of harmonised EU copyright law. It does not deal with other ways in which linking might infringe, for instance by authorising infringement or joint liability for someone else's infringement.  Nor does it say anything about non-copyright issues such as passing off or unfair competition.


Authorising the initial internet communication

The most significant aspect of the Svensson judgment is, oddly, not mentioned in the operative part of the decision (in which the Court provides its definitive answer to the question posed by the referring national court). The operative part says:

“…the provision on a website of clickable links to works freely available on another website does not constitute an ‘act of communication to the public' … .”

Taken at its face, that could suggest that a link to any freely available work does not infringe, regardless of whether the copyright holder initially authorised the work to be made freely available on the internet. That would broadly legitimise most links. But if that is right it is difficult to understand the numerous references in the judgment to whether the copyright holders authorised the initial communication to the public on the internet, and the potential audience contemplated when they did so.  It is likely that the operative part should instead be understood to mean:

“…the provision on a website of clickable links to works freely available on another website, in circumstances where the copyright holder has authorised such works to be made freely available at [that]/ [an] internet location, does not constitute an ‘act of communication to the public' … .”

The alternatives ‘that’/‘an’ reflect the possible uncertainty about the effect of the judgment on links to unauthorised copies where the copyright holder has authorised the work to be freely available at some other location on the internet. 

The curious case of the freelance journalist

The significance of the copyright holder’s authorisation of the initial internet communication is well illustrated by the facts of Svensson itself. According to the CJEU judgment the Swedish proceedings were between four journalists, Mr Svensson, Mr Sjögren, Ms Sahlman and Ms Gadd, who sued Retriever Sverige AB for compensation resulting from Retriever’s inclusion on its website of clickable links to press articles in which the journalists held the copyright.

The Court said:
“[The journalists] wrote press articles that were published in the Göteborgs-Posten newspaper and on the Göteborgs-Posten website. Retriever Sverige operates a website that provides its clients, according to their needs, with lists of clickable Internet links to articles published by other websites. It is common ground between the parties that those articles were freely accessible on the Göteborgs-Posten newspaper site. …”
The journalists claimed that by linking to the articles on the newspaper website Retriever was making their articles available to its clients without their consent. When the CJEU discussed ‘new public’ it said:

“a communication, such as that at issue in the [Swedish] proceedings, concerning the same works as those covered by the initial communication and made, as in the case of the initial communication, on the Internet, and therefore by the same technical means, must also be directed at a new public, that is to say, at a public that was not taken into account by the copyright holders when they authorised the initial communication to the public ….
… it must be held that, where all the users of another site to whom the works at issue have been communicated by means of a clickable link could access those works directly on the site on which they were initially communicated, without the involvement of the manager of that other site, the users of the site managed by the latter must be deemed to be potential recipients of the initial communication and, therefore, as being part of the public taken into account by the copyright holders when they authorised the initial communication.
Therefore, since there is no new public, the authorisation of the copyright holders is not required for a communication to the public such as that in the main proceedings.” (emphasis added)
The assumption of the Court in coming to this conclusion on the facts appears to be that the four copyright holder journalists all authorised the newspaper to make the articles freely available on the newspaper website - the site on which the initial communication on the internet was made and to which Retriever linked.  

But what if the journalists had authorised publication only in the print newspaper and not on the newspaper website? It then seems inescapable that since the initial communication on the internet would not have been authorised by the journalists, a public link to the newspaper website article would be caught, even though the article was freely available on the newspaper website and not subject to any restriction.

Curiously, that scenario may have some relevance to the Svensson case itself. In his judgment in Paramount Home Entertainment v BSkyB, Mr Justice Arnold summarised the facts of Svensson based on English translations of the Swedish judgments provided by Paramount. He said this:

“14.The claimants were four journalists who between them had written 13 articles published by the Göteborgs-Posten newspaper. Three of the journalists were employed by the newspaper, while one was freelance. All of the articles had all been published not only in print, but also online on the newspaper's website. In the case of one of the articles, which was written by the freelance author, the online publication by the newspaper was not licensed by the author.” (emphasis added)

If that is right, then for one of the 13 articles the copyright holding journalist who wrote it did not authorise initial communication to the public on the internet. For that article (assuming that the journalist had not authorised freely available publication elsewhere on the internet) the CJEU’s conclusion that the link did not amount to a communication to a new public would be thrown into doubt (unless it is wrong to read the 'authorisation of initial communication' qualification into the operative part, as discussed above).

Does Svensson pass the 'reasonable internet user' test?

Whatever the precise facts of Svensson may be, this example illustrates a fundamental difficulty with the CJEU's judgment, assuming that the 'authorisation of initial communication' reading is correct.  Ordinary internet users are put in the position of publicly linking at their risk to any freely available content on the internet, however reputable the site may be, because they cannot be certain and have no practicable way of finding out whether the site owns copyright in its material, or has properly licensed it in, or whether a third party copyright owner has authorised the same material to be made freely available elsewhere on the internet.

A good test when evaluating copyright judgments that directly affect the general public, especially internet users, is this: 
  1. Can I explain to a user with confidence exactly what rules s/he has to follow?
  2. Will a reasonable internet user think those rules are sensible?
  3. In any given situation can the user readily ascertain whether what s/he wants to do will infringe?
Svensson just about passes the first question, probably fails the second and certainly fails the third.

The third point is especially significant since, at least in the UK, civil liability for primary copyright infringement is strict. You can infringe by accident, in situations where you are blameless. It is no excuse that you did everything you could to avoid infringement, or that you had no reason to think you were infringing.

That has always been the case in the UK for primary infringement (reproduction, communication to the public and some other types of restricted act).  It is a hangover from the hard copy days when copyright was almost entirely a commercial matter and hardly impinged on end users. It was reasonable to expect commercial publishers and broadcasters to clear rights first. Even then dealers, such as commercial distributors, were subject only to secondary infringement: they did not infringe copyright unless they had reason to believe they were handling an infringing copy.

Now, thanks to the long reach of digital copyright (which Svensson's interpretation of 'making available' has arguably extended even further) primary copyright infringement impinges directly on end users.

End users are in no position to clear rights before, for instance, posting links to public discussion forums or on social media platforms. We make decisions to send public tweets, including links, in a matter of seconds.  If we are retweeting, we may not even visit the location to which the original tweet links.  If we are expected to embark on some investigation to satisfy ourselves that our link won’t infringe, for instance because someone’s unlicensed copyright might be lurking behind a reputable site – worse still if there is no practicable investigation that we can make - then we have a regime that risks chilling freedom of expression. 

It is no answer to suggest that if the links are harmless no-one will ever complain.  That would repeat the UK format-shifting episode, where the gap between copyright principle and reality has been so great as to bring copyright into disrepute.  Nor is it an answer to say that you don’t have to tweet links.  That is exactly the kind of chilling effect that copyright law should avoid.

Of course copyright law does contain some built-in freedom of expression accommodation.  Many linking tweets may find refuge in, say, the UK fair dealing exceptions for criticism, review and news reporting.  However these contain their own technicalities and limitations. For instance the UK news reporting exception does not apply to photographs. And the exceptions vary from one country to another, even within the EU. That is problematic for a user given the inherently cross-border nature of the internet. Is a tweeter expected to consider which countries her tweet may be thought to be targeting before tweeting a link?

Whatever happened to Article 10?

Again on the point of chilling freedom of expression, the CJEU judgment contains a surprising omission. Notwithstanding that it has adopted an interpretation of ‘making available’ of such breadth that it must engage Article 10 ECHR/Article 11 EU Charter, the Court conducted no proportionality assessment. In fact there is no mention of Article 10/11 at all; this after SABAM v Scarlet and Donald Ashby, in which the CJEU and European Court of Human Rights respectively have held that copyright has to be balanced against other fundamental rights.

What could the CJEU have done differently?

The CJEU could have avoided these problems had it adopted a narrower view of “making available”. It could have restricted it to material intervention in the actual or putative transmission, so that but for the intervention no transmission would take place.  In most previous CJEU communication to the public cases the defendant was an actual or putative transmitter. In Airfield the defendant was not, but supplied encryption keys and decoder cards without which the transmission could not take place. Thus there was a material intervention (in effect a participation) in the transmission. 

In its first communication to the public case, Rafael Hoteles, the CJEU treated the ‘without which’ transmission requirement as forming part of the test for an ‘act of communication to the public’.   In Airfield the ‘without which’ test became mixed up with ‘new public’.  Now, in Svensson, the process is complete. ‘Act of communication’ has been completely decoupled from transmission.  ‘New public’ is everything.  One has to wonder whether this is a wise progression.

[Thanks to @twobirds colleagues for looking over a draft, especially Jerker and Benoit for insightful comments. However they bear no responsibility for this final version.]

[Updated 10.50 am 19 February 2014 to clarify Open Question 6 and cross refer to Open Questions in initial paragraph.] [Further tweaking 12.45pm 20 February 2014 and 5 July 2014.]