Showing posts with label Cyberlaw. Show all posts
Showing posts with label Cyberlaw. Show all posts

Saturday, April 07, 2018

Monitoring of smartphones and by CCTV in the workplace


I recently participated in an interdisciplinary seminar at UCC on 'Electronic Monitoring in Ireland: Shaping what we do and who we are'.

The title of my talk was 'Monitoring of smartphones and by CCTV in the workplace'. 

I discussed the legal implications of (a) use of smartphones and (b) monitoring by CCTV in the workplace.

Smartphones allow receipt of emails on a 24/7 basis, even when the employee is in theory off duty.  Employees’ locations may also be monitored.  The implications for employees’ mental health and compliance with the Working Time Directive were considered.  CCTV monitoring also raises significant issues, for example regarding the purposes of monitoring and the relationship between data protection law and employment law.

My presentation:
http://bit.ly/monitoring-law

A podcast interview:
"Listen to Dr Darius Whelan (@dariuswirl) speak with Jane Mulcahy (@janehmul) about the monitoring of smartphones in the workplace and the use of CCTV by employers"
https://itunes.apple.com/ie/podcast/dr-darius-whelan-shares-his-thoughts-on-electronic/id1288572014?i=1000408249932

[UCC School of Law Podcast]     If you don't have iTunes, the file is here.

The organisers of the seminar were Dr. Eleanor Bantry-White, Applied Social Studies; Dr. Katharina Swirak, Criminology; Dr. Debora Jeske, Applied Psychology; Dr. Fiona Donson, Law.

Speakers included
Professor Mike Nellis, Emeritus Professor of Criminal and Community Justice in the Law School, University of Strathclyde
Dr. Ciaran McCullagh, Associate Professor, University of Limerick
Gerry McNally, President of the Confederation of European Probation (CEP) and Assistant Director, Irish Probation Service
Professor Frederic Adam, Business Information Systems, UCC
Dr. Eleanor Bantry White, UCC School of Applied Social Studies
Dr. Orla O’Donovan, UCC School of Applied Social Studies

Some tweets may be found at #EMIreland

Case-law referred to in my presentation includes:

UPC Ireland v UNITE and SIPTU (2015)  LCR20938
https://www.workplacerelations.ie/en/Cases/2015/March/LCR20938.html

O'Connor v Galen Ltd (UD 1514/2009)

Köpke v. Germany (2010)
http://hudoc.echr.coe.int/eng?i=001-101536 

López Ribalda v Spain (2018)
http://www.bailii.org/eu/cases/ECHR/2018/14.html

Ali v First Quench (2001)
www.bailii.org/ew/cases/EWCA/Civ/2001/446.html

McGowan v Scottish Water (2004)
www.bailii.org/uk/cases/UKEAT/2004/0007_04_2309.html

Gresham Hotel (Case Study 6 of 2007)
https://www.dataprotection.ie/docs/Case-Studies-2008/c/732.htm#6

Westwood Swimming (2011)
https://www.dataprotection.ie/docs/Case-Studies-2011/1212.htm#9

Employee v Employer (Supermarket Restaurant) UD893/2010 (2012)
https://www.workplacerelations.ie/en/Cases/2012/September/UD893_2010_MN848_2010.html




Tuesday, July 14, 2015

IT Law Clinic at University College Cork

From September 2015, the School of Law at University College Cork will open an IT Law Clinic.

UCC law students will provide information to businesses in the IT sector on issues such as copyright law, web domain names, electronic commerce law and data protection law. 

Clinic activities will include training on provision of legal information, meetings with IT businesses, guest seminars and engagement in proposals for law reform.

The development of the IT law Clinic builds on UCC’s membership of iLINC, the EU network of ICT Law Incubators (see www.ilincnetwork.eu).

For more information on Intellectual Property and E Law at UCC see www.ucc.ie/law/lawonline/elaw/.

The IT Law Clinic module will be a 5-credit semester 1 LLM module (LW6612).  Students will be admitted  by means of application form and interview. 

For more information contact Dr Darius Whelan (d.whelan@ucc.ie) and Professor Maeve McDonagh (m.mcdonagh@ucc.ie)

www.ucc.ie/en/lawsite/currentstudents/it-law-clinic/

Thursday, August 14, 2014

World Intermediary Liability Map - Ireland Entry

I have contributed the Irish entry to the new World Intermediary Liability Map (WILMap) at Stanford Law School Center for Internet and Society (CIS).

The WILMap educates the public about evolving Internet regulation affecting freedom of expression and user rights worldwide. It is managed by Giancarlo Frosio, the Intermediary Liability Fellow at CIS.
The map is a detailed English-language resource comprised of case law, statutes, and proposed laws related to intermediary liability worldwide. It allows visitors to the CIS website to select information on any country of interest through a graphical user interface.

The full entry on Ireland which I contributed is Creative Commons licensed and is available here.

An edited version appears below:

WILMAP: IRELAND



LEGISLATION

[A report by an expert committee on reform of copyright law, including a draft Bill. Includes proposals concerning intermediaries, e.g.  (1) that a “marshalling” exception be introduced for sites which index, syndicate, aggregate or curate online content and (2) that certain sections of the Copyright and Related Rights Act 2000 concerning transient and incidental copies be amended to come more closely into line with the CJEU’s approach to interpretation of the Information Society Directive.] 
[The Privacy Bill was published by the previous Government in 2006 but has not been enacted.  In 2012, the Minister for Justice stated that he was considering re-introducing a version of this Bill.]  

DECISIONS

SUPERIOR COURTS

Supreme Court, EMI v Data Protection Commissioner [2013] IESC 34 
[copyright, privacy, data protection, graduated response]
[A settlement had been reached between record companies and a large ISP, Eircom, instituting a Graduated Response Protocol under which Eircom would issue copyright infringement notices to customers.  The Data Protection Commissioner believed that this Protocol breached EU and Irish data protection law and issued an enforcement notice requiring Eircom to cease its operation of the Protocol. The Supreme Court found that the enforcement notice was invalid because of the absence of reasons.]

LOWER COURTS

High Court, Schrems v Data Protection Commissioner [2014] IEHC 310 
[privacy, data protection, Facebook, transfers of personal data to USA]
[(1) The Data Protection Act 1988 as amended prohibits transfers of personal data outside the state unless adequate privacy protections are in place.  In 2000, the European Commission had decided that the USA ensured an adequate level of privacy protection for data.  A Safe Harbour framework had been put in place between Europe and the USA regarding transfers of personal data.
(2) In light of the Snowden revelations, Mr Schrems, an Austrian lawyer who runs the “Europe v Facebook” group, made a complaint to the Data Protection Commissioner arguing that the Commissioner should direct that transfers of personal data from Facebook Ireland to Facebook in the USA should cease.  Facebook Ireland is responsible for millions of Facebook users outside the USA and Canada.
(3) The Commissioner decided that the request was unsustainable in law.  Mr Schrems sought Judicial Review of the Commissioner’s decision.  
(4) In the High Court, Hogan J. said that much had changed since 2000, including for example the entry into force of the EU Charter of Fundamental Rights.  As a result, he referred questions of EU law to the Court of Justice of the EU (CJEU).  He also noted that mass and indiscriminate surveillance of communications as shown by the Snowden revelations would, as a matter of Irish law, be unconstitutional, but that Irish law on this matter had effectively been pre-empted by EU law.]  
High Court, Schrems v Data Protection Commissioner (No.2) [2014] IEHC 351
[privacy, data protection, Facebook, transfers of personal data to USA, amicus curiae]
[The High Court ordered that Digital Rights Ireland (DRI) be added as amicus curiae in the proceedings, which will now proceed to the CJEU.  DRI had stated that it would not adopt a position of partisanship. Hogan J. distinguished this case from the case of EMI v UPC [2013] IEHC 204, where DRI was not added as amicus curiae. The court also noted DRI’s successful case before the CJEU – Case 293-12, Digital Rights Ireland v Minister for Communications ECLI:EU:C:2014:238. The court did not permit DRI as amicus to alter the nature of the questions which it had already proposed should be transmitted to the CJEU.] 
High Court, Cummins v Twitter, February 2014 
[defamation, libel, hosting provider, Twitter]
[The High Court ordered that Twitter remove defamatory posts concerning the mayor of Waterford.  The order was made under s.33 of the Defamation Act 2009.]  
High Court, EMI v UPC [2013] IEHC 274
[copyright, access provider, ISP, torrent, ThePirateBay, blocking order]
[Record companies successfully applied for an order against various ISPs blocking access to the Pirate Bay website, based on the amended s.40 of the Copyright and Related Rights Act 2000. Later in 2013, the record companies successfully applied to the High Court for Kickass Torrents to be blocked.]
High Court, EMI v UPC [2013] IEHC 204
[copyright, access provider, ISP, torrent, ThePirateBay, blocking order, amicus curiae]
[Record companies had instituted proceedings seeking an order against various ISPs blocking access to the Pirate Bay website.  Digital Rights Ireland (DRI) applied to be added as an amicus curiae.  The Court refused to add DRI to the case.  Considering Irish cases on criteria for joining an amicus curiae, the court found that this case did not involve novel principles and DRI was not a neutral party.]  
High Court, Tansey v Gill [2012] IEHC 42
[defamation, hosting provider, preliminary injunction, interlocutory order]
[The plaintiff claimed he had been defamed on the website www.rate-your-solicitor.com.  He successfully sought interlocutory orders under s.33 of the Defamation Act 2009 against certain defendants prohibiting publication of the defamatory statements.  The court noted that, since the arrival of the internet, judicial hesitation in granting interlocutory orders of this type should be eased. One of the defendants was the host of the website, Dotster, located in the USA.  Dotster had not made an appearance in the case and the court made a final order in default of appearance.]   
High Court, McKeogh v Doe [2012] IEHC 95 
[defamation, privacy, right to good name, video removal, Norwich Pharmacal orders.]
[The plaintiff had wrongly been identified as the taxi fare evader shown in a video posted on various websites.  The judgment primarily concerns the issue of whether the plaintiff could be named on newspaper websites reporting the court case and the court ordered that he could be named.  The court noted that it had earlier granted interim orders that social media sites such as YouTube and Google should remove the video and provide the identities of web users who had defamed the plaintiff.  The orders regarding identities of web users were granted applying the UK tort case of Norwich Pharmacal v Customs & Excise [1973] UKHL 6. According to media reports, there have been further developments in this case in 2013 and 2014.] 
High Court, EMI v UPC [2010] IEHC 377 
[copyright, access provider, mere conduit, ThePirateBay, E-Commerce Directive]
[Record companies sought orders (1) restraining UPC, an ISP, from making available to the public copies of sound recordings which breach copyright and (2) requiring UPC to block access to the Pirate Bay site. The court found that s.40(4) of the Copyright and Related Rights Act 2000 only covered “removal” of infringing material and therefore an injunction could not be granted.  Charleton J. also reconsidered his previous decision in EMI v Eircom [2009] IEHC 411 (see below), in which he granted an order requiring an ISP to block access to the Pirate Bay, and stated that his previous decision in that case had been incorrect. Following this case, s.40 of the 2000 Act was amended by Statutory Instrument in 2012 (see above).] 
[privacy, data protection, data retention, access providers, ISP, telephony providers, Directive 2006/24/EC, referral, ECJ, invalidity]
[This litigation concerned the validity of the data retention requirements imposed on ISPs and telephony providers. This case led to a decision by the CJEU (Grand Chamber) that the Data Retention Directive (Directive 2006/24/EC) was invalid, Case 293-12, Digital Rights Ireland v Minister for Communications ECLI:EU:C:2014:238.]
High Court, EMI v Eircom [2010] IEHC 108  
[copyright, data protection, graduated response]
[Record companies had reached a settlement with a large ISP (Eircom) instituting a graduated response system.  Charleton J. held that the settlement did not breach data protection laws as IP addresses in the hands of the record companies which do not identify subscribers are not “personal data”. He said that copyright is flagrantly violated by music theft and the sanction of terminating access is not excessive. Eircom’s terms and conditions stated that copyright must not be infringed and subscribers have agreed to these terms.]
High Court:  Irish Red Cross v UPC and Google (Unreported, 2010) [see news coverage here and here]
[confidentiality, breach, privacy, disclosure, alleged infringer, hosting provider, blog, liability of blog host]
[According to website reports, it appears that the High Court ordered that UPC and Google reveal the name of an anonymous blogger who allegedly breached confidentiality on the Blogger website.  Originally Google Ireland was named as defendant but the court permitted Google Inc to be substituted.] 
High Court, EMI v Eircom [2009] IEHC 411
[copyright, access provider, ISP, torrent, ThePirateBay, website blocking order, graduated response]
[Record companies had reached a settlement with a large ISP (Eircom) instituting a graduated response system. The court ordered, on application by the record companies, that Eircom should block access to the Pirate Bay website. The court based its decision on s.40(4) of the Copyright and Related Rights Act 2000 and the Information Society Directive 2001.]  
High Court, Mulvaney v Sporting Exchange trading as Betfair [2009] IEHC 133 
[defamation, libel, hosting provider, gambling, chatroom, forum, E-Commerce Directive, hosting defence]
[Betfair was a gambling site which also operated internet forums (chatrooms) where users could discuss sports events and other issues. The plaintiffs alleged defamation by forum users. As a preliminary issue, Betfair successfully relied on the hosting defence in the E-Commerce Directive as implemented by the 2003 Regulations. The court found that the gambling exception to the Directive and Regulations did not apply as the forums were not directly connected to the gambling part of the site.] 
High Court, Ryanair v Johnston, 2005/514P, July 12, 2006 
[bullying, intimidation, privacy, hosting provider, bulletin board, website operator, moderator, members, liability, disclosure, identities, alleged infringers, Norwich Pharmacal order]
[This was an action against the operators and moderator of an internet site and bulletin board set up to facilitate discussions by Ryanair pilots.  Ryanair alleged that bullying and intimidation of pilots was taking place on the site and sought ‘Norwich Pharmacal’ orders to disclose the identities of certain users of the bulletin board. On reviewing the evidence, Smyth J. found that there was no evidence of bullying or intimidation or that Ryanair had suffered loss. He distinguished this case from EMI v Eircom, 2005 (see below) and the English case of Totalise v Motley Fool [2001] EWCA Civ 1897.  He also stated that a balance needed to be struck between justice and privacy.]   
High Court, EMI v Eircom [2005] IEHC 233 
[copyright, privacy, confidentiality, access provider, disclosure, identities, alleged infringers, Norwich Pharmacal order]
[Record companies requested Eircom, a large ISP, to provide identities of 17 customers who were allegedly infringing copyright. The High Court ordered that customers’ identities should be passed to the ISP, based on the UK tort case of Norwich Pharmacal v Customs & Excise [1973] UKHL 6. The court also relied on the Canadian case of BMG Canada v Doe 2004 FC 488.] 

OTHER RESOURCES

A Guide to the European Communities (Directive 2000/31/EC) Regulations 2003, http://www.djei.ie/publications/trade/2003/ecommercedirectiveguide.doc
Data Protection Commissioner, www.dataprotection.ie
Data Protection Commissioner, Final report of Audit of Facebook Ireland (2011) and Facebook Ireland Audit Review Report (2012), http://dataprotection.ie/docs/Facbook-Audit/1290.htm 
Digital Rights Ireland, http://www.digitalrights.ie
Information Technology Law in Ireland – Denis Kelleher and Karen Murray, http://ictlaw.com
Information Technology Law in Ireland – TJ McIntyre Blog, http://www.tjmcintyre.com
Internet Content Governance Advisiory Group, Report of the Internet Content Governance Advisory Group (2014), http://www.dcenr.gov.ie/NR/rdonlyres/0BCE1511-508E-4E97-B1A9-23A6BE9124A...
Internet Hotline, www.hotline.ie  
Joint Committee on Transport and Communications, Addressing the Growth of Social Media and Tackling Cyberbullying (2013), www.oireachtas.ie/parliament/media/Report-on-Social-Media-July-2013-Webs...
Office for Internet Safety, http://www.internetsafety.ie

CONTRIBUTORS

Darius Whelan
Lecturer in Law, University College Cork  
Email: d.whelan@ucc.ie 







Friday, November 01, 2013

The Internet at 40: Reflections on Cyberspace

John Naughton - CC BY SA - Sebastiaan ter Burg 
We had a very interesting symposium this morning here in UCC on "The Internet at 40".  It followed two lectures by Professor John Naughton which he had given yesterday on the topic.  John's lectures developed themes from earlier lectures such as this one from March on 'Our Networked Future.'  He also drew on his recent book From Gutenberg to Zuckerberg: What You Really Need to Know About the Internet.  

The symposium was chaired by Professor Cormac Sreenan, and panellists were Karlin Lillington, Theresa Reidy, Alfred Moore and myself.  There were really interesting contributions from the audience as well.  It was organised by Ionad Bairre and Bettie Higgs, the Interim Vice President for Teaching and Learning.

Some of my thoughts were as follows (based on rudimentary notes I made in advance):

I wonder are some people now “pacified” by the web?  Is it the new opium of the people?  Has it replaced religion? What are the key “values” people seek online?  Maybe people look for “coolness” as a value.  “That’s a cool site; that’s a cool video”.  Slickness; humour; entertainment; shopping are all “values”.  All of this masks the fact that code is not neutral (as Lawrence Lessig has said).  Search results are not neutral.  The order of items on your Facebook timeline is not neutral.

However, there are exceptions to corporatisation, e.g. Wikipedia.  Also, activists can fight back on the “coolness” front – e.g. the recent video “Stop Watching  Us” which included Maggie Gyllenhaal, Oliver Stone, John Cusack and  Lawrence Lessig .  The video was produced by a coalition of 100 organisations including the ACLU, EFF and EPIC.  Tim Berners Lee supports the coalition and the video has had 1 million views.  Stop SOPA campaigns were also positive example of activism.  Wikipedia went dark for a day.  

John Naughton speaks of permissionless innovation online, which can be good or bad.  My input on this:  Copyright law can stifle innovation.   History shows the extent of copyright protection has continuously been extended – both in what it covers and in duration.  We now have extremely long durations of copyright such as 70 years after the death of the author.  We have absurd scenarios such as an eBook of Alice in Wonderland with a note in the settings saying “The book cannot be read aloud”.  You cannot easily give your ebook to your partner, child or friend.  It’s not clear how your family will inherit your ebooks when you die.  More absurdity: Ebook vendors can possibly “rescind”  a book from your ebook reader even weeks after you've downloaded it.  Ironically, "1984" by George Orwell  was  rescinded from people’s ebooks in 2009.  

David Cameron said that Google might not have started in the UK.  Fair use in the USA is broader than in Europe.  We need to raise awareness of the limitations of copyright law, and variations between national laws. 

John Naughton refers to the generativity of the internet, as highlighted by Jonathan Zittrain.  My example to flesh this out:  Creative Commons is in a way an example of generativity.  (If you're not familiar with Creative Commons, see www.creativecommons.org.)  People can use Creative Commons licensed works to publicise their work, but still charge for commercial use of their work.  

Important reforms of copyright law have been proposed in the recent report of the Copyright Review Committee - Modernising Copyright.  Unfortunately, the committee is somewhat restrained by EU law in the area, and there's only so much it can do within the confines of EU law.  It is worrying that intellectual property was elevated to the level of a fundamental right in the EU Charter of Fundamental Rights (see Article 17(2)).  Hopefully this will be interpreted in a benign manner by the courts but we can't be sure.  Don't get me wrong - I am not opposed to copyright but I'm concerned about maximalist application of copyright without due regard to rights of users and consumers.

A flavour of thoughts from other speakers (roughly paraphrased):

Alfred Moore:
Recently, there has been a neoliberal rejection of democracy altogether, an emphasis on the free market and the consumer.  There is a disdain for democracy, but we need democratic principles to be to the forefront.

Karlin Lillington:
Data retention laws allow a shocking level of surveillance, akin to giving the keys to your house to the Gardaí.  For human rights defenders (e.g. in Pakistan), anonymity is crucial.  See www.bytesforall.pk.
Engineers and scientists need to learn how to code for human rights and code for society.  There's now a Tech Defenders Network.

Theresa Reidy:
Social media has had a transformative effect on politics, but we need more research on its effects.  Can it be a force for citizen engagement?  Can it challenge the dominance of elites?  Twitter has transformed the dynamic of politics, with the possibility of public two-way conversations between politicians and voters.

John Naughton:
A lot of the surveillance of the web stems from 9/11.  The Snowden revelations have had a huge impact - will they lead to a crisis or merely a scandal?  Engineers need to know about ethics.  Engineers and architects designed the concentration camps in the second world war, but what of the ethical dimension?
Recommended books:  Tim Wu, The Master Switch and Dave Eggers, The Circle.

General Discussion:
How do we raise awareness of these issues?  Can they be included in secondary school curriculum, e.g. in Civic, Social and Personal Education?  At university level, can we ensure that ethical issues are considered?  One way of doing this is to find a staff member in a Department who is passionate on these issues.  Then, they can include technical activities in a module (not necessarily a specific module on ethics) which raise awareness, e.g. set students a task to investigate privacy breaches by apps.
Historical perspectives are vital - people need to be able to see what happened with previous new technologies; previous abuses of power; previous political developments.
Literature and arts shine a light on these areas, e.g. E.M. Forster's 'The Machine Stops' (1909).
























Monday, November 05, 2012

Regulating Cloud Computing: Clear Skies Ahead? - Cork, 16 Nov. 2012





We're organising a conference here in UCC Faculty of Law on Friday 16 November:


Regulating Cloud Computing: Clear Skies Ahead?


Presented in association with UCC’s LLM in Intellectual Property and E Law

Friday 16 November, 2012, 2.00 p.m. to 5.15 p.m.

Room G10, Brookfield Health Sciences Complex, UCC, College Road, Cork

Cloud computing - internet-based delivery of IT services – is a growth industry and many Irish businesses are operating as either cloud providers or cloud clients.  This conference, presented in association with UCC’s LLM in Intellectual Property and E Law, will discuss regulation of  cloud computing, including questions such as the following:


  • What legal issues need to be considered by businesses in contracting for the provision or use of cloud computing services?
  • Can an appropriate regulatory balance be struck between cloud provider and cloud client interests?
  • What are the legal consequences of security breaches regarding data held in the cloud?
  • What are the implications of storage of data in Europe, the USA and other jurisdictions?
  • What is the relevance of the EU / US safe harbour arrangements for cloud computing?
  • What are the implications of the EU’s draft General Data Protection Regulation?
  • Are concerns about the USA’s Patriot Act and Mutual Legal Assistance Treaties in cloud computing justified?
  • How are intellectual property law issues dealt with in a cloud environment?


Speakers: 


  • Professor Ian Walden, Centre for Commercial Law Studies, Queen Mary, University of London and member of the Cloud Legal Project.
  • Mr John O'Connor, Head of the Technology and Commercial Contracts Group at Matheson Ormsby Prentice, Solicitors.
  • Ms Síofra Flood, COO and General Counsel at Swrve, leading provider of in-application testing and analytics, California and Dublin.   

Supported by the UCC Dean of Law’s Strategic Fund

Conference Convenors:
Dr Darius Whelan, Professor Maeve McDonagh and Dr Louise Crowley

Advance Registration is essential.
Conference Registration: €40, to be paid by post in advance.
Students:  No Fee.

Continuing Professional Development: 3 hours General CPD

Conference Administrator:  Ms Noreen Delea, Faculty of Law, UCC.
Email n.delea@ucc.ie.    Phone +353-21-490 3220.

Please book by post and pay in advance.
Please use the Booking Form available here.

Students may book by email.

For information on UCC’s LLM on Intellectual Property and E law, see
www.ucc.ie/en/lawsite/StudyLaw/postgrad/.

Update - December 2012: 
Slides and videos from this conference are available at