Privacy

UK surveillance bill’s controversial bulk powers to be reviewed

Comment

Image Credits: Harshil Shah (opens in a new window) / Flickr (opens in a new window) under a CC BY-ND 2.0 (opens in a new window) license.

The UK government has agreed to an independent review of so called “bulk collection” — aka mass surveillance — powers in proposed new surveillance legislation, one of the most controversial elements of the Investigatory Powers bill which is currently before parliament. It’s aiming to get the bill onto the statute books before the end of this year.

Bulk powers set out in the IP bill include a provision for ‘bulk equipment interference‘ — aka mass hacking — allowing the security and intelligence agencies to compromise multiple devices/services as part of their investigations.

A further provision relating to state hacking capabilities set out in a Code of Practice associated with the draft bill notes that communications service providers may be required to maintain a “technical capability” to enable their users’ data to be intercepted — including having user data harvested in bulk — a scenario that human rights group Privacy International described to TechCrunch as “the worst form of backdoor“.

The bulk powers review was one of the concessions called for by the opposition Labour Party’s Shadow Home Secretary, Andy Burnham, in April when the party abstained on a vote on the legislation. Burnham said substantial changes were needed before the party would consider supporting the bill.

Speaking about the latest developments in parliament yesterday, Burnham described Home Secretary Theresa May agreeing to an independent review of the case for bulk powers as “a major concession” and “something which will build trust in this process”.

He also said May’s letter clarified that state agencies cannot use surveillance powers to monitor legitimate trade union activity — another key concern for Labour.

Independent terrorism reviewer returns

The planned bulk powers review, due to report this summer, will be led by QC David Anderson — who previously played a key role for the government as it was drafting the IP bill, as its independent terrorism legislation reviewer.

In his letter to the Home Secretary back in April, Labour’s Burnham described it as “imperative” an independent review of bulk powers be set up, writing: “I would be open to a discussion about the various forms this independent review could take but it is imperative that we get it up and running. I will consider carefully the nature and extent of the bulk powers in this Bill in light of the review.”

Yesterday in parliament he said he was “pleased” the government had agreed to a review and approached Anderson to lead it. “We, on this side of the House, strongly welcome that development and we believe in the end it will build trust and support behind her Bill,” he added.

“There are other areas in which we wish to see significant movement and we will continue to work in a constructive spirit to achieve it. But this letter shows that the Home Secretary is listening and that bodes well for the rest of this Bill’s passage.”

A flagship recommendation from Anderson’s earlier report on this area of legislation was that government ministers should hand intercept warrant sign offs to the judiciary — a suggested change only partially reflected in the bill before parliament now, which has a so called ‘double lock’ sign off mechanism, involving both judiciary and senior ministers (although it also allows for the Home Secretary to solely authorize so called ’emergency warrants’ which are then retrospectively reviewed by a judge).

Anderson also considered bulk powers in his prior report which was generally supportive of security agencies being able to use the controversial capability — leading to criticism of the review by civil rights groups.

Liberty for example, which is challenging the legality of bulk collection/mass interception in the European Court of Human Rights, criticized the earlier report for offering only six Agency case studies as justification for bulk collection — arguing that this “vague and limited information” was not substantial enough to assess security outcomes had other more targeted surveillance methods been used.

That said, Anderson’s prior support for bulk powers was predicated upon there also being “strict additional safeguards” in the associated legislation — including: judicial authorization; tighter operational/mission definitions of the purposes for which bulk data is being sought; and bulk warrants being typically targeted at the communications of people believed to be outside the UK at the time of the sought for communications.

So it remains to be see whether Anderson will judge the IP bill includes enough of these safeguards to justify continued state used of mass interception powers. Since his prior report, multiple parliamentary committees have scrutinized the draft bill and been critical of its overly broad powers, a lack of clarity and not enough privacy safeguards.

It is also not clear whether the bulk powers review will include the IP bill’s web logging proposals — aka the Internet Connection Records (ISCs) that ISPs will be required to record and retain for 12 months, creating records of all the websites and services accessed by their users for the past year. A Home Office spokesman declined to specify whether ISCs will be included in Anderson’s forthcoming review.

Logging the digital activity of every UK citizen ‘just in case’ sounds very much like a bulk capability that sorely needs reviewing for proportionality so let’s hope so. Update: Burnham’s spokesman has now confirmed the review will not include ISCs but only focus on capabilities badged as “bulk” in the bill. So that’s a missed opportunity then.

In a statement a spokesman for the Home Office added: “The Home Secretary has always been clear she will listen to the constructive views of politicians from all sides of the House to ensure the passage of this important Bill. The Government will be bringing forward amendments at Report Stage.”

At the European level, EU mass surveillance legislation was overturned by the European Court of Justice, back in April 2014, which judged such bulk intercept powers as contravening fundamental privacy and human rights.

This post was updated with additional comment 

More TechCrunch

The Series C funding, which brings its total raise to around $95 million, will go toward mass production of the startup’s inaugural products

AI chip startup DEEPX secures $80M Series C at a $529M valuation 

A dust-up between Evolve Bank & Trust, Mercury and Synapse has led TabaPay to abandon its acquisition plans of troubled banking-as-a-service startup Synapse.

Infighting among fintech players has caused TabaPay to ‘pull out’ from buying bankrupt Synapse

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

The Twitter for Android client was “a demo app that Google had created and gave to us,” says Particle co-founder and ex-Twitter employee Sara Beykpour.

Google built some of the first social apps for Android, including Twitter and others

WhatsApp is updating its mobile apps for a fresh and more streamlined look, while also introducing a new “darker dark mode,” the company announced on Thursday. The messaging app says…

WhatsApp’s latest update streamlines navigation and adds a ‘darker dark mode’

Plinky lets you solve the problem of saving and organizing links from anywhere with a focus on simplicity and customization.

Plinky is an app for you to collect and organize links easily

The keynote kicks off at 10 a.m. PT on Tuesday and will offer glimpses into the latest versions of Android, Wear OS and Android TV.

Google I/O 2024: How to watch

For cancer patients, medicines administered in clinical trials can help save or extend lives. But despite thousands of trials in the United States each year, only 3% to 5% of…

Triomics raises $15M Series A to automate cancer clinical trials matching

Welcome back to TechCrunch Mobility — your central hub for news and insights on the future of transportation. Sign up here for free — just click TechCrunch Mobility! Tap, tap.…

Tesla drives Luminar lidar sales and Motional pauses robotaxi plans

The newly announced “Public Content Policy” will now join Reddit’s existing privacy policy and content policy to guide how Reddit’s data is being accessed and used by commercial entities and…

Reddit locks down its public data in new content policy, says use now requires a contract

Eva Ho plans to step away from her position as general partner at Fika Ventures, the Los Angeles-based seed firm she co-founded in 2016. Fika told LPs of Ho’s intention…

Fika Ventures co-founder Eva Ho will step back from the firm after its current fund is deployed

In a post on Werner Vogels’ personal blog, he details Distill, an open-source app he built to transcribe and summarize conference calls.

Amazon’s CTO built a meeting-summarizing app for some reason

Paris-based Mistral AI, a startup working on open source large language models — the building block for generative AI services — has been raising money at a $6 billion valuation,…

Sources: Mistral AI raising at a $6B valuation, SoftBank ‘not in’ but DST is

You can expect plenty of AI, but probably not a lot of hardware.

Google I/O 2024: What to expect

Dating apps and other social friend-finders are being put on notice: Dating app giant Bumble is looking to make more acquisitions.

Bumble says it’s looking to M&A to drive growth

When Class founder Michael Chasen was in college, he and a buddy came up with the idea for Blackboard, an online classroom organizational tool. His original company was acquired for…

Blackboard founder transforms Zoom add-on designed for teachers into business tool

Groww, an Indian investment app, has become one of the first startups from the country to shift its domicile back home.

Groww joins the first wave of Indian startups moving domiciles back home from US

Technology giant Dell notified customers on Thursday that it experienced a data breach involving customers’ names and physical addresses. In an email seen by TechCrunch and shared by several people…

Dell discloses data breach of customers’ physical addresses

Featured Article

Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

The Israeli startup has raised $5.5M for its platform that uses “statistical AI” to generate synthetic data that it says is as good as the real thing.

19 hours ago
Fairgen ‘boosts’ survey results using synthetic data and AI-generated responses

Hydrow, the at-home rowing machine maker, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI (unified payments interface) payments rail by one to two years, sources…

India likely to delay UPI market caps in win for PhonePe-Google Pay duopoly

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?