Tuesday, March 07, 2017

Side Effect: Snoopers Charter [Part 3]

Last month I was curious about the effects of recent legislation on my internet usage. Since then I've had some conversation tennis with support teams at my ISP but no traction or movement.

Up until this morning I'd suspected that nothing was being done - I'd send an email from an account I use tracking systems with, get a response back within a few hours telling me that email address wasn't authorised for the support ticket, then I'd send a reply from the original email address authorising the second email address with the ISP... and then getting nothing in reply.

Twice.

I know the emails were opened in India and read twice each time within a few hours of sending. All other responses or communications were simply being swallowed up into a black hole.

This morning I tried using the live chat on the ISPs website and got a far better response (even if it wasn't what I wanted to hear).

Despite repeated requests to get status or answer any outstanding queries I've had nothing. The live chat support person, Linda, was able to tell me that the original recipient of the request fobbed me off onto the wrong department then closed the support ticket. And it's been that way ever since the 19th of January. 

Not really surprised but I pushed Linda to forward the request onto either their legal or compliance team. A bit of confusion - it sounds like their usual section 7 requests are for case notes, not ICR data - easily clarified. Now although Linda refused to re-open the support ticket she did promise to forward the request onto legal after I explained that the ISPs legal team would have had to review & sign-off the Snoopers Charter implications. This would involve them understanding the request and its terms.

However we're now over the 40 day limit for a SAR and there is no response other than acknowledgements that the ISP have received the request - it's going to be interesting to see how they respond from this point. Recent legal updates have included a major setback to the Investigatory Powers Act at ECJ level and some inevitable challenges to it's implementation; especially relating to the requirement to implement 'back doors' in all CSP platforms. Note emphasis there on CSP platforms, not anti-virus software or encryption software.

Whether or not this will really affect peoples daily lives or not is another matter, but I'd be concerned that local councils, HMRC, the Dept. for Education and other similar level government departments will inevitably use this type of information for purposes other than 'detection of a crime'.

'Detection' will easily slip into 'Prevention', and then we're in the tin-foil hat territory akin to Minority Report. I don't have government-level actors trying to hack my devices but if there is a method of access available, criminals will find it - and that's enough of a cause for concern for me. Just a quick glance at how busy ICO are with government departments and you begin to understand the scale of the data-protection problem: Here's a list of decision notices - when this article went live they were all councils on the receiving end of complaints.

Click to see larger image

Monday, February 06, 2017

Side Effect: Snoopers Charter [Part 2]

Last month I sent a rather well-known international internet provider a subject access request (SAR) - since that post (which you can recap on here) I've had some rather less entertaining communiques with them.

I'm not going to name the ISP just yet for security reasons but suffice to say that the following are true:

  1. They ask that a cheque is sent in the post to them for £10 as part of the SAR process; yet do not accept cheques as a form of payment for any of their services
  2. They do not advertise the email details for any legal department inbox, nor do they extend their current online issue registration capabilities to include SAR or similar filings
  3. This is a company who sell themselves on high technological value (and do so on multiple continents) yet fail to provide a simple means for lodging a SAR - which is an individuals right under the law here in the UK [and EU]
After the last post I had received an assurance from the member of staff that she would contact the original member of staff to find out why it was [erroneously] passed to her department, and that she would call me back within 2 hours.

I've heard nothing since the 19th and 20th of January.

I've sent two follow-up emails to the ISP to which they have failed to reply within 48 hours - which is their SLA for business customers. I sent another further update request from an email address embedded within a tracking system.

This email got a response within 3 hours saying that the update request was "...not sent from the email address you used in your initial enquiry", and that "...for security reasons, we cannot provide an update unless you use the same email address that you originally used to contact us".

Actually I'm happy with that response as it's a verification of identity - the tracking system uses a completely separate domain and I'd be asking for the same verification from any of my customers too. So I sent back a message from the original email address used to the effect that yes - it was me, and that they should enact this second email address with the appropriate authorisation to deal with this issue.

That was the 2nd of February and there's been no further communication since.

So I repeated the latter part of the exercise and got the same response today - also read and responded to within 3 hours of being sent.

So what is clear is that the ISP are receiving the requests for update and essentially refusing to provide an update. As I've had adequate responses directly from the ISP staff they have received and acknowledged the request, and I've asked specifically how I can pay the £10 SAR fee without a cheque book.

As they're refusing to respond does that mean they're waiving it? Forgetting the fact that the fee was designed in the 1980's to cover the cost of postage of the potentially large printed documents to answer the SAR, I'm not sure how relevant that price is versus the cost of doing business - which the all businesses must acknowledge if they conform to the Data Protection Act.

I can show that each of the requests for information have been received, opened and read (all in India), yet have little to show in terms of meaningful response. I found another part of the same ISP - well it's a law firm that says it's part of this ISP and I'm going to send them a copy of these posts as well as the original request.

Expect another post in coming weeks as the time limit on the SAR (40 days) means the statutory limit expires on the 28th of February. At that point the ISP will be in breach of the DPA.