SlideShare a Scribd company logo
Investigatory Powers Act
introduction
Graham Smith
SCL Annual Conference
8 June 2017
Background to the Act
Multiple sources -
two main ones
● Bulk interception under RIPA
● Equipment interference (CNE)
2013 - Snowden
2012
Communications
Data Retention
2014
● Digital Rights Ireland (CJEU)
● Data Retention and Investigatory Powers Act
(DRIPA)
2015
"RIPA, obscure since its inception, has been
patched up so many times as to make it
incomprehensible to all but a tiny band of initiates"
"comprehensive and
comprehensible"
Page 8
Overview of #IPAct powers
Overview of #IPAct powers
300 page Act
● Interception warrants
• Bulk, targeted, thematic; Content and ‘secondary’ data
● Equipment interference (hacking) warrants
• Bulk, targeted, thematic; Content and ‘equipment’ data
● Communications data acquisition and disclosure
• Bulk warrants, targeted notices + request filter
● Mandatory communications data retention notices
• Browsing histories (Internet Connection Records)
● Technical capability notices
• E2E encryption
● National security notices
● Bulk personal dataset warrants
Page 10
What? How? Who to? Enforce? Secret?
Warrant
(SoS + JC)
TelOp Crim +
Civ
Crim
Warrant
(SoS [some
LE] + JC)
TelOp UKpers
only, Civ
Crim
Notice
(SoS + JC)
TelOp UKpers
only, Civ
Civ
Notice
(various
authorities)
TelOp Civ Crim
Warrant
(SoS + JC)
TelOp UKpers
only, Civ
Crim
Notice
(SoS + JC)
TelOp
(inc
prospective)
As per
substantive
powers
Yes
Notice
(SoS + JC)
UK
TelOp
UKpers
only, Civ
Yes
Overview of #IPAct powers
Comms Data
Retention
(inc ICRs)
Comms Data
Acquisition
(targeted)(?)
Equipment
interference
(targeted,
thematic)
Encryption
removal
Equipment
interference
(bulk)
Request
filter
(comms data)
Technical
capability
notices
Comms Data
Acquisition
(bulk)
Interception
(targeted,
thematic)
Interception
(bulk)
Interception
(secondary
data)
Equipment
interference
(equipment
data)
National
security
notices
Page 11
What? How? Who by? Purposes?
Warrant
(SoS + JC)
MI5, SIS, GCHQ, MoD, 5 LE bodies,
MLAT
National security;
prevent/detect serious
crime; UK economic well-
being (nat sec-related,
non-BI persons)
Warrant
(SoS + JC)
MI5, SIS, GCHQ; MoD (nat sec only)
Warrant
(LE head + JC)
Police (various), National
Crime Agency
Prevent/detect serious crime,
prevent death, prevent or
mitigate injury/damage to
physical/mental health
Immigration, Revenue/Customs,
Competition/Markets, Police investigations
Prevent/detect serious crime
Warrant
(SoS + JC)
MI5, SIS, GCHQ (overseas-
related main purpose)
National security; national
security and prevent/detect
serious crime, UK economic
well-being (non-BI persons)
Warrant
(SoS + JC)
MI5, SIS, GCHQ
Notice (plus
court order for
local authorities)
Numerous authorities 11 different purposes
Notice (+ JC)
(up to 12 mths)
Secretary of State
Notice
(+ JC)
Secretary of State National security
Warrants, comms data
acquisition notices
Overview of #IPAct powers
Equipment
interference
(targeted,
thematic)
Equipment
interference
(bulk)
Comms Data
Acquisition
(bulk)
Interception
(targeted,
thematic)
Interception
(bulk)
National
security
notices
Technical
capability notices
(inc decryption)
Comms Data
Acquisition
(targeted)(?)
Request
filter
(comms data)
Comms Data
Retention
(inc ICRs)
Page 12
What has changed?
New or not new?
● Explicit powers re-enacted
● Semi-explicit powers (scale of use
hidden) now made explicit
● Opaque powers now made explicit
● Opaque powers still (arguably)
opaque
Interception
(targeted)
Comms Data
Acquisition
(bulk)
Equipment
interference
(targeted,
thematic)
Encryption
removal
Interception
(bulk)
Interception
(thematic)
Equipment
interference
(bulk)
Interception
(related
communications
data)
Page 14
New and extended
Authorisation and oversight – new safeguards
● Judicial Commissioner approval of most warrants and notices
• Except targeted communications data acquisition
- But Watson.
Extended mandatory data retention powers
● Extended to all kinds of communications data
• including Internet Connection Records (site level browsing histories)
● Extended to all kinds of communication (background, IoT)
● Extended to include generation and obtaining data for
retention
● Abolition of 'processed within UK' limitation
● Extended to include private telecommunications operators
Page 15
New and extended
Content-derived metadata
● Interception, equipment interference, BPD warrants.
• Targeted, thematic, bulk
● New power to extract some information from content and
treat as metadata
Page 16
New and extended
Technical capability notices
● Permanent technical capability to assist with warrants and
communications data acquisition notices
● Extended from interception (RIPA) to most powers (IPAct)
● Extended to include private telecommunications operators
• Subject to any limitations in regulations
Draft regulations
● No minimum threshold for communications data acquisition
● Black boxes (communications data acquisition)
● Hacking back door
● End to end encryption?
Page 17
New and extended
New non-disclosure obligations on warrant/notice
recipients
● Criminal (targeted and bulk)
• Interception warrants (59(1), 156(2))
• Equipment interference warrants (134(1), 197)
• Bulk communications data acquisition warrants (174(1))
• Targeted communications data acquisition notices (82(1))
● Civil
• Data retention notices (95(2))
● Indeterminate
• Technical capability notices (255(8))
• National security notices (255(8))
Page 18
Tweaks
● Extraterritoriality
● Content v metadata
● Categories of metadata
● Journalists, MPs, legal privilege
● Interception offence
● etc
Page 19
Timetable
● Data retention partially in force 30 December 2016
• Existing notices continue for max 6 mths
● The rest of the Act?
• New oversight regime
• New warrantry procedures
• ‘Some time … timetable in due course’
Page 20
Graham Smith
graham.smith@twobirds.com
@cyberleagle
Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses.
Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number OC340318 and is authorised and regulated by the
Solicitors Regulation Authority. Its registered office and principal place of business is at 15 Fetter Lane, London EC4A 1JP. A list of members of Bird & Bird LLP and
of any non-members who are designated as partners, and of their respective professional qualifications, is open to inspection at that address.
twobirds.com
Thank you

More Related Content

Similar to SCL Conference 8 June 2017 - Investigatory Powers Act

Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
Dione McBride, CISSP, CIPP/E
 
NIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government ContractorsNIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government Contractors
Unanet
 
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
IBM Security
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year On
Symantec
 
Information Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric VanderburgInformation Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric Vanderburg
Eric Vanderburg
 
Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016
Graham Smith
 
Isaca new delhi india privacy and big data
Isaca new delhi india   privacy and big dataIsaca new delhi india   privacy and big data
Isaca new delhi india privacy and big data
Ulf Mattsson
 
Ip bill issues
Ip bill issuesIp bill issues
Ip bill issues
rcorrigan
 
Understanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: WebinarUnderstanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: Webinar
CipherCloud
 
Protect the Unexpected
Protect the UnexpectedProtect the Unexpected
Protect the Unexpected
Charles Mok
 
Ignyte - US Sovereign Cloud Computing
Ignyte - US Sovereign Cloud ComputingIgnyte - US Sovereign Cloud Computing
Ignyte - US Sovereign Cloud Computing
Ignyte Assurance Platform
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
SecurityScorecard
 
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz PatrickDigital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Tealium
 
Chapter2
Chapter2Chapter2
Chapter2
Pibi Lu
 
Isaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big dataIsaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big data
Ulf Mattsson
 
ISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloud
Ulf Mattsson
 
Legal and privacy implications of IoT
Legal and privacy implications of IoTLegal and privacy implications of IoT
Legal and privacy implications of IoT
Andres Guadamuz
 
Cross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataCross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive data
Ulf Mattsson
 
Infosec Law (Feb 2006)
Infosec Law (Feb 2006)Infosec Law (Feb 2006)
Infosec Law (Feb 2006)
Lance Michalson
 
Jul 16 isaca london data protection, security and privacy risks - on premis...
Jul 16 isaca london   data protection, security and privacy risks - on premis...Jul 16 isaca london   data protection, security and privacy risks - on premis...
Jul 16 isaca london data protection, security and privacy risks - on premis...
Ulf Mattsson
 

Similar to SCL Conference 8 June 2017 - Investigatory Powers Act (20)

Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1Data Privacy for Information Security Professionals Part 1
Data Privacy for Information Security Professionals Part 1
 
NIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government ContractorsNIST Cybersecurity Requirements for Government Contractors
NIST Cybersecurity Requirements for Government Contractors
 
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
Encryption and Key Management: Ensuring Compliance, Privacy, and Minimizing t...
 
Symantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year OnSymantec Webinar: GDPR 1 Year On
Symantec Webinar: GDPR 1 Year On
 
Information Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric VanderburgInformation Security Lesson 1 - Eric Vanderburg
Information Security Lesson 1 - Eric Vanderburg
 
Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016Internet and eCommerce Law Review 2016
Internet and eCommerce Law Review 2016
 
Isaca new delhi india privacy and big data
Isaca new delhi india   privacy and big dataIsaca new delhi india   privacy and big data
Isaca new delhi india privacy and big data
 
Ip bill issues
Ip bill issuesIp bill issues
Ip bill issues
 
Understanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: WebinarUnderstanding Global Data Protection Laws: Webinar
Understanding Global Data Protection Laws: Webinar
 
Protect the Unexpected
Protect the UnexpectedProtect the Unexpected
Protect the Unexpected
 
Ignyte - US Sovereign Cloud Computing
Ignyte - US Sovereign Cloud ComputingIgnyte - US Sovereign Cloud Computing
Ignyte - US Sovereign Cloud Computing
 
GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready? GDPR Enforcement is here. Are you ready?
GDPR Enforcement is here. Are you ready?
 
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz PatrickDigital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
Digital Velocity London 2017 - Data Privacy and Sovereignty, Sheila Fitz Patrick
 
Chapter2
Chapter2Chapter2
Chapter2
 
Isaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big dataIsaca new delhi india - privacy and big data
Isaca new delhi india - privacy and big data
 
ISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloudISSA Atlanta - Emerging application and data protection for multi cloud
ISSA Atlanta - Emerging application and data protection for multi cloud
 
Legal and privacy implications of IoT
Legal and privacy implications of IoTLegal and privacy implications of IoT
Legal and privacy implications of IoT
 
Cross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataCross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive data
 
Infosec Law (Feb 2006)
Infosec Law (Feb 2006)Infosec Law (Feb 2006)
Infosec Law (Feb 2006)
 
Jul 16 isaca london data protection, security and privacy risks - on premis...
Jul 16 isaca london   data protection, security and privacy risks - on premis...Jul 16 isaca london   data protection, security and privacy risks - on premis...
Jul 16 isaca london data protection, security and privacy risks - on premis...
 

More from Graham Smith

BBW v UK - IP Act implications
BBW v UK - IP Act implicationsBBW v UK - IP Act implications
BBW v UK - IP Act implications
Graham Smith
 
Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018
Graham Smith
 
Investigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection AdequacyInvestigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection Adequacy
Graham Smith
 
Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith
 
Data Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers ActData Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers Act
Graham Smith
 
Internet Jurisdiction Primer
Internet Jurisdiction PrimerInternet Jurisdiction Primer
Internet Jurisdiction Primer
Graham Smith
 
Geoblocking in context
Geoblocking in contextGeoblocking in context
Geoblocking in context
Graham Smith
 
IPBillOversightInsight
IPBillOversightInsightIPBillOversightInsight
IPBillOversightInsight
Graham Smith
 
Future-proofing the IPBill
Future-proofing the IPBillFuture-proofing the IPBill
Future-proofing the IPBill
Graham Smith
 
Draft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal ViewDraft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal View
Graham Smith
 
Communications Privacy and the State
Communications Privacy and the StateCommunications Privacy and the State
Communications Privacy and the State
Graham Smith
 
2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review
Graham Smith
 
Right to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-finalRight to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-final
Graham Smith
 
Communications Data Retention by Intermediaries
Communications Data Retention by IntermediariesCommunications Data Retention by Intermediaries
Communications Data Retention by Intermediaries
Graham Smith
 
2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update
Graham Smith
 
Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?
Graham Smith
 
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Graham Smith
 
Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?
Graham Smith
 
Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?
Graham Smith
 

More from Graham Smith (19)

BBW v UK - IP Act implications
BBW v UK - IP Act implicationsBBW v UK - IP Act implications
BBW v UK - IP Act implications
 
Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018Internet and eCommerce Law Review 2018
Internet and eCommerce Law Review 2018
 
Investigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection AdequacyInvestigatory Powers Act and Data Protection Adequacy
Investigatory Powers Act and Data Protection Adequacy
 
Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017Graham Smith - Internet and eCommerce Law Review 2017
Graham Smith - Internet and eCommerce Law Review 2017
 
Data Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers ActData Protection Adequacy and the Investigatory Powers Act
Data Protection Adequacy and the Investigatory Powers Act
 
Internet Jurisdiction Primer
Internet Jurisdiction PrimerInternet Jurisdiction Primer
Internet Jurisdiction Primer
 
Geoblocking in context
Geoblocking in contextGeoblocking in context
Geoblocking in context
 
IPBillOversightInsight
IPBillOversightInsightIPBillOversightInsight
IPBillOversightInsight
 
Future-proofing the IPBill
Future-proofing the IPBillFuture-proofing the IPBill
Future-proofing the IPBill
 
Draft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal ViewDraft Investigatory Powers Bill - Legal View
Draft Investigatory Powers Bill - Legal View
 
Communications Privacy and the State
Communications Privacy and the StateCommunications Privacy and the State
Communications Privacy and the State
 
2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review2015 Internet and ECommerce Law Review
2015 Internet and ECommerce Law Review
 
Right to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-finalRight to Privacy in the Digital Age-final
Right to Privacy in the Digital Age-final
 
Communications Data Retention by Intermediaries
Communications Data Retention by IntermediariesCommunications Data Retention by Intermediaries
Communications Data Retention by Intermediaries
 
2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update2014 Internet and ECommerce Law Update
2014 Internet and ECommerce Law Update
 
Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?Data Retention - Dead or Merely Stunned?
Data Retention - Dead or Merely Stunned?
 
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
Are Moral Rights Human Rights? Presentation to BLACA/IPKat seminar 12 Februar...
 
Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?Are techlaw principles in the ascendancy?
Are techlaw principles in the ascendancy?
 
Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?Who wins when copyright and free speech clash?
Who wins when copyright and free speech clash?
 

Recently uploaded

Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
ssuser559494
 
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdfV.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
bhavenpr
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
osenwakm
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
lawyersonia
 
Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
MasoudZamani13
 
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
CIkumparan
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Syed Muhammad Humza Hussain
 
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
bhavenpr
 
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence LawyersDefending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
HarpreetSaini48
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
osenwakm
 
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
SKshi
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
ssusera97a2f
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
PelayoGilbert
 
Tax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th semTax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th sem
azizurrahaman17
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Massimo Talia
 
fnaf lore.pptx ...................................
fnaf lore.pptx ...................................fnaf lore.pptx ...................................
fnaf lore.pptx ...................................
20jcoello
 
Energizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining FuturesEnergizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining Futures
USDAReapgrants.com
 
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
gjsma0ep
 
Lifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point PresentationLifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point Presentation
seri bangash
 
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee
 

Recently uploaded (20)

Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptxPatenting_Innovations_in_3D_Printing_Prosthetics.pptx
Patenting_Innovations_in_3D_Printing_Prosthetics.pptx
 
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdfV.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
V.-SENTHIL-BALAJI-SLP-C-8939-8940-2023-SC-Judgment-07-August-2023.pdf
 
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
在线办理(SU毕业证书)美国雪城大学毕业证成绩单一模一样
 
What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...What are the common challenges faced by women lawyers working in the legal pr...
What are the common challenges faced by women lawyers working in the legal pr...
 
Genocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptxGenocide in International Criminal Law.pptx
Genocide in International Criminal Law.pptx
 
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
2015pmkemenhub163.pdf. 2015pmkemenhub163.pdf
 
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
Synopsis On Annual General Meeting/Extra Ordinary General Meeting With Ordina...
 
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdfXYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
XYZ-v.-state-of-Maharashtra-Bombay-HC-Writ-Petition-6340-2023.pdf
 
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence LawyersDefending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
Defending Weapons Offence Charges: Role of Mississauga Criminal Defence Lawyers
 
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
原版制作(PSU毕业证书)宾州州立大学公园分校毕业证学历证书一模一样
 
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
Presentation (1).pptx Human rights of LGBTQ people in India, constitutional a...
 
From Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal EnvironmentsFrom Promise to Practice. Implementing AI in Legal Environments
From Promise to Practice. Implementing AI in Legal Environments
 
Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976Ease of Paying Tax Law Republic Act 11976
Ease of Paying Tax Law Republic Act 11976
 
Tax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th semTax Law Notes on taxation law tax law for 10th sem
Tax Law Notes on taxation law tax law for 10th sem
 
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
Guide on the use of Artificial Intelligence-based tools by lawyers and law fi...
 
fnaf lore.pptx ...................................
fnaf lore.pptx ...................................fnaf lore.pptx ...................................
fnaf lore.pptx ...................................
 
Energizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining FuturesEnergizing Communities, Fostering Growth, Sustaining Futures
Energizing Communities, Fostering Growth, Sustaining Futures
 
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
一比一原版(Lincoln毕业证)新西兰林肯大学毕业证如何办理
 
Lifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point PresentationLifting the Corporate Veil. Power Point Presentation
Lifting the Corporate Veil. Power Point Presentation
 
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
Sangyun Lee, 'Why Korea's Merger Control Occasionally Fails: A Public Choice ...
 

SCL Conference 8 June 2017 - Investigatory Powers Act

  • 1. Investigatory Powers Act introduction Graham Smith SCL Annual Conference 8 June 2017
  • 4. ● Bulk interception under RIPA ● Equipment interference (CNE) 2013 - Snowden
  • 6. 2014 ● Digital Rights Ireland (CJEU) ● Data Retention and Investigatory Powers Act (DRIPA)
  • 8. "RIPA, obscure since its inception, has been patched up so many times as to make it incomprehensible to all but a tiny band of initiates" "comprehensive and comprehensible" Page 8
  • 10. Overview of #IPAct powers 300 page Act ● Interception warrants • Bulk, targeted, thematic; Content and ‘secondary’ data ● Equipment interference (hacking) warrants • Bulk, targeted, thematic; Content and ‘equipment’ data ● Communications data acquisition and disclosure • Bulk warrants, targeted notices + request filter ● Mandatory communications data retention notices • Browsing histories (Internet Connection Records) ● Technical capability notices • E2E encryption ● National security notices ● Bulk personal dataset warrants Page 10
  • 11. What? How? Who to? Enforce? Secret? Warrant (SoS + JC) TelOp Crim + Civ Crim Warrant (SoS [some LE] + JC) TelOp UKpers only, Civ Crim Notice (SoS + JC) TelOp UKpers only, Civ Civ Notice (various authorities) TelOp Civ Crim Warrant (SoS + JC) TelOp UKpers only, Civ Crim Notice (SoS + JC) TelOp (inc prospective) As per substantive powers Yes Notice (SoS + JC) UK TelOp UKpers only, Civ Yes Overview of #IPAct powers Comms Data Retention (inc ICRs) Comms Data Acquisition (targeted)(?) Equipment interference (targeted, thematic) Encryption removal Equipment interference (bulk) Request filter (comms data) Technical capability notices Comms Data Acquisition (bulk) Interception (targeted, thematic) Interception (bulk) Interception (secondary data) Equipment interference (equipment data) National security notices Page 11
  • 12. What? How? Who by? Purposes? Warrant (SoS + JC) MI5, SIS, GCHQ, MoD, 5 LE bodies, MLAT National security; prevent/detect serious crime; UK economic well- being (nat sec-related, non-BI persons) Warrant (SoS + JC) MI5, SIS, GCHQ; MoD (nat sec only) Warrant (LE head + JC) Police (various), National Crime Agency Prevent/detect serious crime, prevent death, prevent or mitigate injury/damage to physical/mental health Immigration, Revenue/Customs, Competition/Markets, Police investigations Prevent/detect serious crime Warrant (SoS + JC) MI5, SIS, GCHQ (overseas- related main purpose) National security; national security and prevent/detect serious crime, UK economic well-being (non-BI persons) Warrant (SoS + JC) MI5, SIS, GCHQ Notice (plus court order for local authorities) Numerous authorities 11 different purposes Notice (+ JC) (up to 12 mths) Secretary of State Notice (+ JC) Secretary of State National security Warrants, comms data acquisition notices Overview of #IPAct powers Equipment interference (targeted, thematic) Equipment interference (bulk) Comms Data Acquisition (bulk) Interception (targeted, thematic) Interception (bulk) National security notices Technical capability notices (inc decryption) Comms Data Acquisition (targeted)(?) Request filter (comms data) Comms Data Retention (inc ICRs) Page 12
  • 14. New or not new? ● Explicit powers re-enacted ● Semi-explicit powers (scale of use hidden) now made explicit ● Opaque powers now made explicit ● Opaque powers still (arguably) opaque Interception (targeted) Comms Data Acquisition (bulk) Equipment interference (targeted, thematic) Encryption removal Interception (bulk) Interception (thematic) Equipment interference (bulk) Interception (related communications data) Page 14
  • 15. New and extended Authorisation and oversight – new safeguards ● Judicial Commissioner approval of most warrants and notices • Except targeted communications data acquisition - But Watson. Extended mandatory data retention powers ● Extended to all kinds of communications data • including Internet Connection Records (site level browsing histories) ● Extended to all kinds of communication (background, IoT) ● Extended to include generation and obtaining data for retention ● Abolition of 'processed within UK' limitation ● Extended to include private telecommunications operators Page 15
  • 16. New and extended Content-derived metadata ● Interception, equipment interference, BPD warrants. • Targeted, thematic, bulk ● New power to extract some information from content and treat as metadata Page 16
  • 17. New and extended Technical capability notices ● Permanent technical capability to assist with warrants and communications data acquisition notices ● Extended from interception (RIPA) to most powers (IPAct) ● Extended to include private telecommunications operators • Subject to any limitations in regulations Draft regulations ● No minimum threshold for communications data acquisition ● Black boxes (communications data acquisition) ● Hacking back door ● End to end encryption? Page 17
  • 18. New and extended New non-disclosure obligations on warrant/notice recipients ● Criminal (targeted and bulk) • Interception warrants (59(1), 156(2)) • Equipment interference warrants (134(1), 197) • Bulk communications data acquisition warrants (174(1)) • Targeted communications data acquisition notices (82(1)) ● Civil • Data retention notices (95(2)) ● Indeterminate • Technical capability notices (255(8)) • National security notices (255(8)) Page 18
  • 19. Tweaks ● Extraterritoriality ● Content v metadata ● Categories of metadata ● Journalists, MPs, legal privilege ● Interception offence ● etc Page 19
  • 20. Timetable ● Data retention partially in force 30 December 2016 • Existing notices continue for max 6 mths ● The rest of the Act? • New oversight regime • New warrantry procedures • ‘Some time … timetable in due course’ Page 20
  • 21. Graham Smith graham.smith@twobirds.com @cyberleagle Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses. Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number OC340318 and is authorised and regulated by the Solicitors Regulation Authority. Its registered office and principal place of business is at 15 Fetter Lane, London EC4A 1JP. A list of members of Bird & Bird LLP and of any non-members who are designated as partners, and of their respective professional qualifications, is open to inspection at that address. twobirds.com Thank you