Παρασκευή 20 Μαρτίου 2015

The French Government's Drift on Surveillance

The information shared today by Le Figaro regarding the upcoming French Bill on Intelligence, ahead of its presentation before the Council of ministers on Thursday 19 March, only confirms earlier concerns. While this new law was announced as an important overhaul aimed at protecting fundamental rights, the securitarian instrumentalisation of the deadly events of January is bound to lead to an incredible drift in state surveillance practices. La Quadrature du Net calls on citizens and their elected representatives to oppose this bill.
Behavioural surveillance of all users by all sorts of technical intermediates in order to detect suspicious behaviours, real time access to connection data, access to the content of emails and key loggers etc.: the reach of the new powers to be given to law enforcement agencies (police, border-police, etc.) without any judiciary supervision is of an unprecedented scale.
Without drawing any lessons from the case law of the European Union Court of Justice (Digital Rights Ireland Ltd etc., C-293/12, 594/12), which condemns the overly long and broad retention of citizen's personal data, the bill will propose to rise up to five years of the retention of the data by intelligence services.
To control the dangerous restrictions of the fundamental right to privacy by surveillance and profiling, the government only plans a consultative commission with limited powers. Citizens will only be able to resort to a a posteriori procedure with no substantial due process guarantee.
While waiting on the formal adoption of the bill by the government, La Quadrature du Net already urges the members of the French parliament to do their duty of controlling, reasoning and of defending the civil rights of citizens against this dangerous bill, and calls citizens to mobilise against it.
While studies show that everywhere in the world mass surveillance does not lower the risk of violent crimes, the path taken by the French government is bound to establish a new era of general suspicion, marking historical drawback for the separation of powers and for fundamental rights. If the French parliament accept to pass these measures, the conditions for a correct exercise of democracy in France will not be met anymore.


Source: https://www.laquadrature.net/en/intelligence-reform-the-french-governments-disastrous-drift-on-surveillance

VIDÉO - «Une loi qui s'adapte à la menace terroriste», explique Sébastien Pietrasanta, député PS et rapporteur du projet de loi sur le renforcement de la lutte contre le terrorisme http://bcove.me/rib82alh






Κυριακή 15 Μαρτίου 2015

Review of EU Data Protection Law: A Future with a Past



On 15 September 2014 the European Data Protection Supervisor (EDPS) has made available the thourough data protection review article entitled "EU Data Protection Law: The Review of Directive 95/46/EC and the Proposed General Data Protection Regulation" by Peter Hustinx which is based on a course given at the European University Institute's Academy of European Law in July 2013.

The article reminds the reader of the origins of data protection which were about the rights and interests of individuals and not mainly about the data relating to those individuals and then not only takes stock of where EU data protection law currently is but also takes a closer look at some of the key data protection issues.

EU Data Protection Authorities: Guidelines for Global Implementation of "Right to be Forgotten"




Art. 29 Data Protection Working Party, WP 225, adopted on 26 November 2014



On 26 November 2014, the European data protection authorities assembled in the Article 29 Working Party (WP29) have adopted guidelines on the implementation of the judgment of the Court of Justice of European Union (CJEU) of 13 May 2014 in Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González (C-131/12), CRi 2014, p. 77 with remarks from US perspective by Spelman/Towle, p. 85, and remarks from an Irish perspective by Tobin, p. 87. These Guidelines contain the common interpretation of the ruling as well as the common criteria to be used by the data protection authorities when addressing complaints. The Guidelines request effective implementation of the CJEU's judgment on a global scale including all relevant ".com" domains which makes it all the more interesting to realise how such "right to be forgotten" constitutes a challenge to free speech rights recognized by the Constitution of the United States(see Brown, "The Right to be Forgotten: U.S. Rulings on Free Speech Won’t Let Google Forget", CRi 6/2014, pp. 161).


Background


The CJEU's judgment in Google Spain SL and Google Inc. v AEPD and Mario Costeja González (C-131/12)sets a milestone for EU data protection in respect of search engines and, more generally, in the online world. It grants the possibility to data subjects to request to search engines, under certain conditions, the de-listing of links appearing in the search results based on a person’s name.


WP29 Guidelines
Applicability of Data Protection Directive to Search Engines


The WP29 guidelines recall that the CJEU ruling confirmed the applicability of Directive 95/46/EC to a search engine insofar as the processing of personal data is carried out in the context of the activities of a subsidiary on the territory of a Member State, set up to promote and sell advertising space on its search engine in this Member State with the aim of making that service profitable.
Scope of "Right to be Forgotten"


The CJEU's judgment expressly states that the right only affects the results obtained from searches made on the basis of a person’s name and does not require deletion of the link from the indexes of the search engine altogether. That is, the original information will still be accessible using other search terms, or by direct access to the source.
Effective Implementation: National EU-Domains as well as All Relevant ".com"-Domains


The WP29 considers that in order to give full effect to the data subject’s rights as defined in the Court’s ruling, de-listing decisions must be implemented in such a way that they guarantee the effective and complete protection of data subjects’ rights and that EU law cannot be circumvented. In that sense, limiting de-listing to EU domains on the grounds that users tend to access search engines via theirnational domains cannot be considered a sufficient means to satisfactorily guarantee the rights of data subjects according to the ruling. In practice, this means that in any case de-listing should also be effective on all relevant .com domains.
Eligibility to "Right to be Forgotten"


Under EU law, everyone has a right to data protection. In practice, DPAs will focus on claims where there is a clear link between the data subject and the EU, for instance where the data subject is a citizen or resident of an EU Member State.
List of Common Criteria for Harmonised Handling of Complaints Against Search Engine's De-Listing Refusal


The guidelines also contain the list of common criteria which the data protection authorities will apply to handle the complaints filed with their national offices following refusals of de-listing by search engines. The list contains 13 main criteria and should be seen as a flexible working tool to help DPAs during the decision-making processes. Criteria will be applied on a case by case basis and in accordance with the relevant national legislations.


No single criterion is, in itself, determinative. Each of them has to be read in the light of the principles established by the CJEU and in particular in the light of the “the interest of the general public in having access to [the] information”.

Digital privacy: EU-wide logo and “data protection impact assessments” aim to boost the use of RFID systems

New EU-wide technical standards have been agreed that will help users of Radio Frequency Identification (RFID) smart chips and systems comply with EU Data Protection rules and the Commission’s 2009 recommendation on RFID. A “data protection impact assessment” process has also been agreed.
Practical effects of these new standards will include:

  • People using electronic travel passes, or buying clothes and supermarket items with RFID tags in the label, will know that smart chips are present thanks to the RFID sign (see right).
  • Retailers can use RFID technology to improve stock management and prevent theft, confident that they are respecting current EU data protection rules.
  • RFID application developers can rely on the Privacy Impact Assessment standards to ensure “data protection by design” within EU data protection rules.
In sectors such as healthcare and banking where RFID use is exploding, this rapid set of changes will take place in the legal mainstream rather than in a grey zone.
European Commission Vice President @NeelieKroesEU said: "Smart tags and systems are part of everyday life now, they simplify systems and boost our economy. But it is important to have standards in place which ensure those benefits do not come at a cost to data protection and security of personal data". According to reports, the global market for RFID applications is expected to grow to $9.2 billion in 2014. Consumers should not face surveillance from RFID chips, they should be deactivated by default immediately and free-of-charge at the point of sale.
Companies or public authorities using smart chips should:

  • give consumers clear and simple information so that they understand if their personal data will be used, the type of collected data (such as name, address or date of birth, for example when registering for a travel subscription card) and for what purpose.
  • provide clear labelling to identify the devices that 'read' the information stored in smart chips, and provide a contact point for citizens to obtain more information.
  • should conduct privacy and data protection impact assessments, reviewed by national data protection authorities, before using smart chips.
Retail associations and organisations should promote consumer awareness on products containing smart chips through the use of a common European sign.


Source: http://europa.eu/rapid/press-release_IP-14-889_en.htm

Παρασκευή 6 Μαρτίου 2015

ΒΙΒΛΙΟΠΑΡΟΥΣΙΑΣΗ: Άννα Τσιφτσόγλου, Δημόσια Ασφάλεια και Ιδιωτικότητα




Πρόλογος: Σπυρίδων Ι. Φλογαϊτης
Καθηγητής Νομικής Σχολής Παν/μιου Αθηνών


Οι αποκαλύψεις Snowden το 2013 σχετικά με τα σκάνδαλα μαζικής παρακολούθησης εκ μέρους της βρετανικής και αμερικανικής κυβέρνησης εξέθεσαν απροκάλυπτα δείγματα της νέας πραγματικότητας. Παγκόσμιο χαρακτηριστικό αυτής είναι η σταδιακή μετεξέλιξη του σύγχρονου κράτους σε κράτος παρακολούθησης. Παράλληλα, οι αποκαλύψεις έδειξαν πως το δίκαιο της ανάγκης που επικαλέστηκαν πολιτικοί και νομικοί μετά την 11η Σεπτεμβρίου έχασε μάλλον την παροδικότητά του. Απεναντίας, τα έκτακτα μέτρα έγιναν ο κανόνας παρά η εξαίρεση, η νέα δικαιϊκή νόρμα.

Η παρούσα μονογραφία εστιάζει στη σύγκρουση δημόσιας ασφάλειας και ιδιωτικότητας μέσα στη νέα πραγματικότητα του κράτους πρόληψης και παρακολούθησης. Η διελκυστίνδα αυτή εκφράζεται μέσα από σταθμίσεις νομοθετικές και δικαστικές, εντοπίζεται σε δύο κυρίως πεδία- τις ηλεκτρονικές επικοινωνίες και τις γενετικές πληροφορίες- και αναδεικνύει θεσμικές επιλογές κοινοβουλίων και δικαστηρίων σε εθνικό αλλά και υπερεθνικό επίπεδο. Παράλληλα, η σύγκρουση εξετάζεται και μέσα από ένα σώμα αποφάσεων των ελληνικών ανεξάρτητων διοικητικών αρχών, αντλώντας πολύτιμα στοιχεία και από το ευρωπαϊκό παράδειγμα, ανιχνεύοντας το θεσμικό τους ρόλο στην επίλυση της αξιακής σύγκρουσης.  

Μεθοδολογικά, ακολουθείται το σχήμα θέμα πράξη θεσμοί, δηλαδή η τριμερής (θεωρητική, πρακτική και θεσμική) προσέγγιση της θεματικής μας. Αξιοποιείται συγκριτικά πρωτογενές υλικό από τέσσερις τουλάχιστον έννομες τάξεις (Ελλάδα, ΗΠΑ, ΕΕ και ΕΣΔΑ), αλλά και επιστημονική βιβλιογραφία και ειδησεογραφία που καλύπτει τρεις τουλάχιστον γλώσσες (ελληνική, αγγλική και γαλλική).

Στόχος του έργου είναι τόσο η ανάδειξη όσο και η επαναδιαπραγμάτευση της σχέσης των δύο αντίπαλων αξιών μέσα από συγκριτική μελέτη μιας πληθώρας πηγών ιδίως σε περιόδους κρίσης, όπως η βιωθείσα παγκοσμίως κατά τη δεκαετία μετά από τις τρομοκρατικές επιθέσεις στις ΗΠΑ.  





Κυριακή 1 Μαρτίου 2015

Περιορισμοί στην πρόσβαση σε ιστοτόπους με παράνομο περιεχόμενο. Η απόφαση του ΔΕΕ στην υποθ. C-314/12 (UPC Telekabel)


Το Δικαστήριο της ΕΕ έκρινε στην απόφαση της 27.3.2014 σχετικά με την έννοια του διαμεσολαβητή κατά την οδηγία 2001/29 και εάν οι περιορισμοί στην πρόσβαση σε ιστοτόπους που παραβιάζουν δικαιώματα πνευματικής ιδιοκτησίας προσκρούουν στα θεμελιώδη δικαιώματα της Ένωσης.

Τα πραγματικά περιστατικά της υπόθεσης έχουν ως εξής: Η Constantin Film και η Wega, δύο εταιρίες παραγωγής κινηματογραφικών ταινιών, αφού διαπίστωσαν ότι ιστότοπος πρότεινε, χωρίς τη συγκατάθεσή τους, είτε την τηλεφόρτωση είτε την παρακολούθηση μέσω «streaming» [υπηρεσίας ροής δεδομένων] ορισμένων ταινιών παραγωγής τους, ζήτησαν από τον δικαστή ασφαλιστικών μέτρων την έκδοση διατάξεως απαγορεύουσας στην UPC Telekabel, φορέα παροχής προσβάσεως στο διαδίκτυο, να επιτρέπει την πρόσβαση των πελατών της στον επίμαχο ιστότοπο, καθόσον ο ιστότοπος αυτός θέτει στη διάθεση του κοινού, χωρίς τη συγκατάθεσή τους, κινηματογραφικά έργα επί των οποίων έχουν συγγενικό του δικαιώματος του δημιουργού δικαίωμα. Με διάταξη της 13ης Μαΐου 2011, το Handelsgericht Wien (Αυστρία) απαγόρευσε στην UPC Telekabel να παράσχει στους πελάτες της την πρόσβαση στον επίμαχο ιστότοπο, η δε απαγόρευση αυτή έπρεπε, μεταξύ άλλων, να πραγματοποιηθεί με τον αποκλεισμό του ονόματος χώρου και τη φραγή της ενεργού διευθύνσεως IP («Internet Protocol») του ιστότοπου αυτού καθώς και κάθε άλλη διεύθυνση IP του εν λόγω ιστότοπου, την οποία μπορεί να εντοπίσει η UPC Telekabel. Τον Ιούνιο του 2011 ο επίμαχος ιστότοπος διέκοψε τη λειτουργία του κατόπιν παρεμβάσεως των γερμανικών αστυνομικών αρχών εις βάρος των διαχειριστών του. Με διάταξη της 27ης Οκτωβρίου 2011, το Oberlandesgericht Wien (Αυστρία), δικάζον σε δεύτερο βαθμό, μεταρρύθμισε εν μέρει τη διάταξη του πρωτοβάθμιου δικαστηρίου καθόσον το πρωτοβάθμιο δικαστήριο, εσφαλμένως, προσδιόρισε τα μέτρα τα οποία πρέπει να εφαρμόσει η UPC Telekabel για να προβεί στον αποκλεισμό του επίμαχου ιστότοπου και, συνακολούθως, να εκτελέσει τη διάταξη. Στη συνέχεια, έκρινε ότι, παρέχοντας στους πελάτες της πρόσβαση σε περιεχόμενο που διατίθεται παρανόμως, η UPC Telekabel πρέπει να θεωρηθεί ως διαμεσολαβητής του οποίου οι υπηρεσίες χρησιμοποιούνται για την προσβολή συγγενικού προς το δικαίωμα του δημιουργού δικαίωμα, οπότε η Constantin Film και η Wega δικαιούνταν να ζητήσουν την έκδοση διατάξεως κατά της εταιρίας αυτής. Εντούτοις, όσον αφορά την προστασία του δικαιώματος του δημιουργού, το Oberlandesgericht Wien έκρινε ότι στην UPC Telekabel μπορούσε να επιβληθεί μόνον, υπό μορφή υποχρεώσεως επιτεύξεως αποτελέσματος, η απαγόρευση προσβάσεως των πελατών της στον επίμαχο ιστότοπο, αλλά η UPC Telekabel έπρεπε να έχει την ελεύθερη επιλογή των προς εφαρμογή μέσων. Η UPC Telekabel άσκησε αίτηση αναιρέσεως («Revision») ενώπιον του Oberster Gerichtshof. Προς στήριξη της αιτήσεώς της αναιρέσεως, η UPC Telekabel προβάλλει, μεταξύ άλλων, ότι δεν μπορεί να θεωρηθεί ότι οι υπηρεσίες της χρησιμοποιούνται για την προσβολή του δικαιώματος του δημιουργού ή συγγενικού δικαιώματος κατά το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29, διότι δεν διατηρεί καμία εμπορική σχέση με τους διαχειριστές του επίμαχου ιστότοπου και δεν αποδείχθηκε ότι οι πελάτες της ενήργησαν παρανόμως. Εν πάση περιπτώσει, η UPC Telekabel υποστηρίζει ότι τα διάφορα μέτρα αποκλεισμού τα οποία δύνανται να τεθούν σε εφαρμογή μπορούν όλα να καταστρατηγηθούν τεχνικώς και ορισμένα είναι εξαιρετικώς δαπανηρά.

Το αυστριακό Δικαστήριο υπέβαλε τα εξής προδικαστικά ερωτήματα προς το ΔΕΕ:

«1)      Πρέπει το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29 […] να ερμηνεύεται υπό την έννοια ότι πρόσωπο το οποίο διαθέτει προστατευόμενα αντικείμενα στο διαδίκτυο χωρίς τη συγκατάθεση του δικαιούχου (άρθρο 3, παράγραφος 2, της οδηγίας 2001/29) χρησιμοποιεί τις υπηρεσίες των φορέων παροχής προσβάσεως [στο διαδίκτυο], πελάτες των οποίων είναι τα πρόσωπα που αποκτούν πρόσβαση στα εν λόγω αντικείμενα;
Σε περίπτωση που δοθεί αρνητική απάντηση στο πρώτο ερώτημα:
2)      Επιτρέπονται η αναπαραγωγή για ιδιωτική χρήση (άρθρο 5, παράγραφος 2, στοιχείο β΄, της οδηγίας 2001/29) και η μεταβατική και παρεπόμενη αναπαραγωγή (άρθρο 5, παράγραφος 1, της οδηγίας 2001/29) μόνον όταν το πρωτότυπο της αναπαραγωγής έχει αναπαραχθεί, διανεμηθεί ή διατεθεί στο κοινό νομίμως;
Σε περίπτωση που δοθεί καταφατική απάντηση στο πρώτο ή στο δεύτερο ερώτημα με αποτέλεσμα να πρέπει να διαταχθεί, δυνάμει του άρθρου 8, παράγραφος 3, της οδηγίας 2001/29, η λήψη ασφαλιστικών μέτρων κατά του φορέα που παρέσχε πρόσβαση [στο διαδίκτυο] στον χρήστη:
3)      Συνάδει με το δίκαιο της Ένωσης, ιδίως στο πλαίσιο της αναγκαίας σταθμίσεως μεταξύ των θεμελιωδών δικαιωμάτων των εμπλεκομένων, η επιβολή στον φορέα παροχής προσβάσεως [στο διαδίκτυο] μιας γενικής απαγορεύσεως (δηλαδή, χωρίς διαταγή λήψης συγκεκριμένων μέτρων), ώστε να μην επιτρέπεται να καθιστά δυνατή την πρόσβαση των πελατών του σε συγκεκριμένο ιστότοπο στον οποίο διατίθεται αποκλειστικώς ή ως επί το πλείστον περιεχόμενο χωρίς τη συγκατάθεση των δικαιούχων του, εάν οι ποινές που προβλέπονται σε περίπτωση παραβιάσεως της εν λόγω απαγορεύσεως δεν επιβάλλονται στον φορέα παροχής προσβάσεως εφόσον αυτός αποδείξει ότι είχε λάβει ούτως ή άλλως κάθε εύλογο μέτρο;
Σε περίπτωση που δοθεί αρνητική απάντηση στο τρίτο ερώτημα:
4)      Συνάδει με το δίκαιο της Ένωσης, ιδίως στο πλαίσιο της αναγκαίας σταθμίσεως μεταξύ των θεμελιωδών δικαιωμάτων των εμπλεκομένων, η επιβολή στον φορέα παροχής προσβάσεως [στο διαδίκτυο] της υποχρεώσεως να λάβει συγκεκριμένα μέτρα προκειμένου να δυσχεράνει την πρόσβαση των πελατών του σε ιστότοπο με περιεχόμενο το οποίο διατίθεται παρανόμως, εφόσον τα μέτρα αυτά απαιτούν σημαντική δαπάνη, ενώ είναι δυνατόν να καταστρατηγηθούν χωρίς ιδιαίτερες τεχνικές γνώσεις;»
Ως προς το 1ο ερώτημα το ΔΕΕ δέχθηκε:

(32) Στη συνέχεια, δεδομένου ότι ο φορέας παροχής προσβάσεως στο διαδίκτυο, για κάθε διαδικτυακή μετάδοση προσβολής προστατευόμενου έργου, μεσολαβεί κατ’ ανάγκη μεταξύ ενός από τους πελάτες του και ενός τρίτου, εφόσον, παρέχοντας την πρόσβαση στο δίκτυο, καθιστά τη μετάδοση αυτή εφικτή (βλ., συναφώς, διάταξη της 19ης Φεβρουαρίου 2009, C‑557/07, LSG-Gesellschaft zur Wahrnehmung von Leistungsschutzrechten, Συλλογή 2009, σ. I‑1227, σκέψη 44), πρέπει να θεωρηθεί ότι ο φορέας παροχής προσβάσεως στο διαδίκτυο, όπως αυτός της κύριας δίκης, ο οποίος παρέχει στους πελάτες του τη δυνατότητα να έχουν πρόσβαση σε προστατευόμενα αντικείμενα που τίθενται στη διάθεση του κοινού στο διαδίκτυο από τρίτον, είναι διαμεσολαβητής οι υπηρεσίες του οποίου χρησιμοποιούνται για την προσβολή δικαιώματος του δημιουργού ή συγγενικό δικαίωμα κατά το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29.

Η απάντησή του, συμπερασματικά, ήταν ότι:

(40) Λαμβανομένων υπόψη των προηγουμένων, στο πρώτο ερώτημα πρέπει να δοθεί η απάντηση ότι το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29 έχει την έννοια ότι πρόσωπο το οποίο θέτει στη διάθεση του κοινού σε ιστότοπο προστατευόμενα αντικείμενα χωρίς τη συγκατάθεση του δικαιούχου, κατά το άρθρο 3, παράγραφος 2, της οδηγίας αυτής, χρησιμοποιεί τις υπηρεσίες φορέα παροχής διαδικτυακής προσβάσεως στα πρόσωπα που αποκτούν πρόσβαση στα αντικείμενα αυτά, ο οποίος πρέπει να θεωρηθεί ως διαμεσολαβητής κατά το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29.

Ακολούθως, δέχθηκε ότι δεδομένης της απαντήσεως που δόθηκε στο πρώτο ερώτημα, παρέλκει η απάντηση στο δεύτερο ερώτημα.


Ως προς το τρίτο ερώτημα, το Δικαστήριο έκανε ενδιαφέρουσες σκέψεις.

Συγκεκριμένα δέχθηκε ότι η διάταξη, όπως αυτή της κύριας δίκης που επιβάλλει στον αποδέκτη της περιορισμούς στην ελεύθερη χρήση των πόρων που διαθέτει, καθόσον τον υποχρεώνει να λάβει μέτρα τα οποία μπορεί να αντιπροσωπεύουν μεγάλο κόστος γι’ αυτόν, να έχουν σημαντικό αντίκτυπο στην οργάνωση των δραστηριοτήτων του ή να απαιτούν δυσχερείς και περίπλοκες τεχνικές λύσεις. Πάντως, τέτοιου είδους διάταξη δεν προσβάλλει προφανώς την ουσία του δικαιώματος της επιχειρηματικής ελευθερίας φορέα παροχής προσβάσεως στο διαδίκτυο, όπως αυτού της κύριας δίκης.

Ως προς τα μέτρα που λαμβάνει φορέας παροχής προσβάσεως στο διαδίκτυο, το ΔΕΕ έκρινε ότι όταν ο αποδέκτης διατάξεως, όπως αυτή της κύριας δίκης, επιλέγει τα προς λήψη μέτρα προκειμένου να συμμορφωθεί προς τη διάταξη αυτή, οφείλει να μεριμνά για την τήρηση του θεμελιώδους δικαιώματος της ελευθερίας πληροφορήσεως των χρηστών του διαδικτύου. Εν προκειμένω, όχι το ΔΕΕ, αλλά τα εθνικά δικαστήρια πρέπει να έχουν τη δυνατότητα να εξετάζουν αν πρόκειται περί αυτού.

Ωστόσο, στην περίπτωση διατάξεως, όπως αυτή της κύριας δίκης, επισημαίνεται ότι, αν ο φορέας παροχής προσβάσεως στο διαδίκτυο λαμβάνει μέτρα βάσει των οποίων μπορεί να εφαρμόζει την επιβληθείσα απαγόρευση, τα εθνικά δικαστήρια δεν έχουν τη δυνατότητα να προβούν στον έλεγχο αυτό στο στάδιο της εκτελεστικής διαδικασίας, εφόσον δεν υπάρχει αμφισβήτηση επ’ αυτού. Στη συνέχεια, για να μην προσκρούει η έκδοση διατάξεως, όπως αυτή της κύριας δίκης, στα αναγνωριζόμενα από το δίκαιο της Ένωσης θεμελιώδη δικαιώματα, απαιτείται οι εθνικοί δικονομικοί κανόνες να προβλέπουν τη δυνατότητα των χρηστών του διαδικτύου να προβάλλουν τα δικαιώματά τους ενώπιον του δικαστή, αφού γνωστοποιηθούν τα εκτελεστικά μέτρα που έλαβε ο φορέας παροχής προσβάσεως στο διαδίκτυο.

Ως προς το τέταρτο ερώτημα, το Δικαστήριο έκρινε ότι παρέλκει η εξέτασή του.

Εν τέλει, η απάντηση του Δικαστηρίου είναι ότι:

1)      Το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29/ΕΚ του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου, της 22ας Μαΐου 2001, για την εναρμόνιση ορισμένων πτυχών του δικαιώματος του δημιουργού και συγγενικών δικαιωμάτων στην κοινωνία της πληροφορίας, έχει την έννοια ότι πρόσωπο το οποίο θέτει στη διάθεση του κοινού σε ιστότοπο προστατευόμενα αντικείμενα χωρίς τη συγκατάθεση του δικαιούχου, κατά το άρθρο 3, παράγραφος 2, της οδηγίας αυτής, χρησιμοποιεί τις υπηρεσίες φορέα παροχής διαδικτυακής προσβάσεως σε πρόσωπα που αποκτούν πρόσβαση στα αντικείμενα αυτά, ο οποίος πρέπει να θεωρηθεί ως διαμεσολαβητής κατά το άρθρο 8, παράγραφος 3, της οδηγίας 2001/29.
2)      Τα αναγνωριζόμενα από το δίκαιο της Ένωσης θεμελιώδη δικαιώματα έχουν την έννοια ότι δεν αντιτίθενται σε επιβαλλόμενη με δικαστική διάταξη σε φορέα παροχής διαδικτυακής προσβάσεως απαγόρευση να παρέχει στους πελάτες του πρόσβαση σε ιστότοπο ο οποίος θέτει στο διαδίκτυο προστατευόμενα αντικείμενα χωρίς τη συγκατάθεση των δικαιούχων, όταν η διάταξη αυτή δεν διευκρινίζει τα μέτρα που πρέπει να λάβει ο φορέας αυτός, οι δε χρηματικές ποινές που προβλέπονται σε περίπτωση παραβιάσεως της εν λόγω απαγορεύσεως δεν επιβάλλονται στον εν λόγω φορέα εφόσον αυτός αποδείξει ότι έλαβε κάθε εύλογο μέτρο με σκοπό την εφαρμογή της απαγορεύσεως, υπό την προϋπόθεση πάντως ότι τα ληφθέντα μέτρα, αφενός, δεν στερούν ασκόπως από τους χρήστες του διαδικτύου τη δυνατότητα σύννομης προσβάσεως σε διαθέσιμες πληροφορίες και, αφετέρου, έχουν ως αποτέλεσμα να παρακωλύουν ή, τουλάχιστον, να δυσχεραίνουν τη μη εγκεκριμένη πρόσβαση σε προστατευόμενα αντικείμενα ή αποθαρρύνουν σοβαρώς την πρόσβαση των χρηστών του διαδικτύου, οι οποίοι χρησιμοποιούν τις υπηρεσίες του αποδέκτη της διατάξεως αυτής, στα εν λόγω αντικείμενα τα οποία τέθηκαν στη διάθεσή τους κατά παράβαση του θεμελιώδους αυτού δικαιώματος, όπερ απόκειται στις εθνικές αρχές και στα εθνικά δικαστήρια να εξακριβώσουν.


Πέμπτη 11 Δεκεμβρίου 2014

Video surveillance - CJEU decision



The Data Protection Directive (95/46/EEC) applies to a video recording made with a surveillance camera installed by a person on his family home and directed towards the public footpath. Nevertheless, under the Directive, a person has a legitimate interest in protecting the property, health and life of his family and himself.

Under the Data Protection Directive, it is not as a general rule permitted to process personal data unless the data subject has given his consent. However, the directive does not apply to the processing of data carried out by a natural person in the course of a purely personal or household activity.
Mr Ryneš and his family were subjected to a number of attacks by unknown persons, and on several occasions the windows of their house were broken. In response to those attacks, Mr Ryneš installed a surveillance camera on the family home, which filmed the entrance, public footpath and the entrance to the house opposite.

During the night of 6 to 7 October 2007, a window of the family home was broken by a shot from a catapult. The recordings made by the surveillance camera were handed over to the police and made it possible to identify two suspects, who were subsequently prosecuted before the criminal courts.
However, one of the suspects disputed before the Czech Office for the Protection of Personal Data the legality of the processing of the data recorded by Mr Ryneš’ surveillance camera. The Office found that Mr Ryneš had in fact infringed the personal data protection rules and fined him. In that connection, one of the points made by the Office was that the data on the suspect had been recorded without his consent while he was on the public footpath in front of M. Ryneš’ house.

The Nejvyšší správní soud (Supreme Administrative Court, Czech Republic), hearing the appeal in the dispute between Mr Ryneš and the Office, asks the Court of Justice whether the recording made by Mr Ryneš for the purposes of protecting the life, health and property of his family and himself (that is to say, the recording of personal data relating to the individuals launching an attack on his house from the public footpath) constitutes a category of data processing that is not covered by the directive, on the grounds that that recording was made by a natural person in the course of purely personal or household activities.

In this judgment, the Court states first of all that the term ‘personal data’ as used in the Directive encompasses any information relating to an identified or identifiable natural person. An identifiable person is anyone who can be identified, directly or indirectly, by reference to one or more factors specific to his physical identity. Consequently, the image of a person recorded by a camera constitutes personal data because it makes it possible to identify the person concerned.
Similarly, video surveillance involving the recording and storage of personal data falls within the scope of the Directive, since it constitutes automatic data processing.

Secondly, the Court finds that the exception provided for in the directive in the case of data processing carried out by a natural person in the course of purely personal or household activities must be narrowly construed. Accordingly, video surveillance which covers a public space and which is accordingly directed outwards from the private setting of the person processing the data cannot be regarded as an activity which is a ‘purely personal or household activity’.

In applying the Directive, the national court must, at the same time, bear in mind the fact that that directive makes it possible to take into account the legitimate interest of the person who has engaged in the processing of personal data (‘the controller’) in protecting the property, health and life of his family and himself.

Specifically, firstly, one of the situations in which personal data processing is permissible without the consent of the data subject is where it is necessary for the purposes of the legitimate interests pursued by the controller. Secondly, the data subject need not be told of the processing of his data where the provision of such information proves impossible or would involve a disproportionate effort. Thirdly, Member States may restrict the scope of the obligations and rights provided for under the Directive if such a restriction is necessary to safeguard the prevention, investigation, detection and prosecution of criminal offences, or the protection of the rights and freedoms of others.


Τρίτη 2 Δεκεμβρίου 2014

An Analysis of Directive 2013/40/EU – attacks against information systems


Amy Beales 

Student of the University of Groningen, the Netherlands
E-mail: amy.beales@googlemail.com





Developments in the area of Information Technology have unfortunately meant the development of new crimes in this area and therefore the need to create sanctions for these crimes, cybercrimes. Cybercrimes areborderless criminal acts, which are committed online by using electronic communications networks and information systems.[1] The internet is used as a platform for many day-to-day activities such as the exchange of information, money, social communication and research. The frequency of use and popularity of the internet means that there are increased risks when using it – there is always someone who could intervene in your activities and cause harm. 

The European Union (EU) has been making moves towards protecting people involved in the electronic sphere since 2001 with the Framework Decision on Combating Fraud and Counterfeiting of Non-Cash Means of Payment.[2] This initiative was considered to be successful in achieving its objectives and was signed and ratified by non Member States such as the USA, Canada and Japan,[3] which shows just how important the level of protection afforded to combating these issues was at the time. It meant that legislation was finally allocated to a growing issue and countries were forced to come to terms with the problems that ignorance may cause. 

The Decision was soon followed by the ePrivacyDirective in 2002[4], which provided for the obligation of providers of electronic communications services  to ensure the security of their services and maintain the confidentiality of client information; and the 2011 Directive on the Combating of Sexual Exploitation of Children Online and Adult Pornography,[5] which better addressed developments in the online environment, such as grooming. The newest Directive is the one which shall be the focus of this essay – the 2013 Directive on Attacks against Information Systems[6] (hereafter the Directive); this directive has the purpose of tackling large-scale cyber attacks by requiring that Member States strengthen their national cyber crime laws and introduce tougher criminal sanctions for breaches. This essay will assess the merits and drawbacks that come with the new Directive, the increase in the minimum penalties, as well as new malware advancements such as DDoS (Distributed Denial of Services) attacks and botnets.

Directive to replace Framework Decision
The Directive was first proposed in 2010 with the idea of it replacing the EU Council Framework Decision2005/222/JHA[7], which criminalised a number of acts relating to attacks against information systems. As already discussed, the fast paced nature of the development of the information technology systems meant that the change from a decision to a directive was essential. It is important to note here the differences between a decision and a directive: A decision refers to an issued statement which is binding only to those whom it is addressed and is directly applicable; a directive, on the other hand, is a legislative act which sets out a goal that all EU countries must achieve – how this is done is up to the individual countries. 

The move from one to the other in this case was based on Article 83(1)(a)[8] of the Treaty on the Functioning of the European Union (TFEU) which states that the European Parliament and Council may establish minimum rules concerning the definition of criminal offences and sanctions in the areas of particularly serious crime with a cross-border dimension when there is a need to combat them on a common basis. The Directive retains numerous provisions of the Framework Directive, as well as stating various offences relating to illegal access to information systems and interference with these systems and their data. However, the Directive’s build upon the Framework Decision was greatly welcomed and saw the introduction of the outlawing of ‘botnets’ and malicious software. 

Botnets are networks of computers which are infected with malicious software and controlled as a group without the owner’s knowledge, usually to send spam email messages, spread viruses, attack computer and servers, and commit other kinds of crime and fraud[9]. The Directive also mentions the illegality of the use of passwords obtained through unsavoury means.[10] The move towards the notion of a directive to cover this issue was important to create harmony between the Member States by binding them to implement legislation in their own national legal order, which would increase cooperation and the likelihood of criminals being caught and punished for their crimes. This notion, as well as what exactly a directive entails, will be discussed later in the essay.

Penalties and Sanctions
Prior to the Directive, it was generally left to the discretion of the Member States to decide how to sanction cyber crimes and any crime to do with the information technology sphere. However, the Directive is working to tackle this to make it more uniform. As well as the introduction of new offences, stricter penalties are introduced in the Directive. Penalties are to include a minimum sentence of two years for any attempt at a breach of an information system. Attacks by organised criminal groups and those which cause significant damage or affects key infrastructure networks [like power-plants, government institutions or transportation networks] can have even tougher sanctions of a minimum five years imprisonment. The use of Botnets also has a minimum sentence of three years if their use results in financial cost or loss of personal data.[11] 

We can also see penalties such as the exclusion from entitlement to public benefits and aid; temporary or permanent disqualification from the practice of commercial activities; placing under judicial supervision; judicial winding-up; temporary or permanent closure of establishments which have been used for committing the offence, as well as many others. The purpose of these penalties is to make them effective, proportionate and dissuasive to those who intentionally and illegally access information systems, launch illegal system interference or launch illegal data interference. This means that those who commit cyber crimes will not go unpunished and with one common set of rules, people will not be able to hide behind the national laws of their country, which was previously easy to do because of the transnational character of cybercrime [i.e. crimes that occur in one country, but have an affect on another, or many others.] The Directive also introduces the possibility of serving punishment on companies who breach obligations of supervision or control which allow a person under their authority to commit any offence listed in the Directive. [12]

EU Law
The directive on attacks against information systems was addressed to all 28 Member States and so all will have to take measures in order to implement the goals of the Directive within the national system. The aim of applying a directive in this manner is to increase the level of cooperation between the Member States and bringing national laws into line with each other, thus creating a united front in matters of conflict. At the moment, Denmark will not be bound by the Directive as they have neither signed nor ratified it, but the UK and Ireland, as well as the rest of the Member States, have decided to apply it; Member States have to take all necessary action to comply with the Directive by 4th September 2015. 

Following publication of the Directive in the Official Journal of the European Union, it shall enter into force twenty days following[14]. Two years later, by 4th September 2017, will see a report submitted to the European Parliament and the Council. It will assess what steps have been taken by the Member States in order to comply with the Directive and possible further legislation needed to make it more effective. At this stage, the Commission will also take into account further technical and legal developments in the field of cybercrime within the scope of the Directive.[15]

Similarities and Advancements
The Directive is similar to the Framework Decision in many ways and therefore does not require Member States to change a great deal of their existing legislation. The definition of cyber crime has remained the same, as well as rules governing liability of legal persons and jurisdiction. However, some of the additions of the Directive may prove slightly more difficult for Member States to initially identify, impose or maintain; the mention of botnets, identity theft and the need to respond urgently to requests from other member states, are but a few. There are discrepancies as to a few of the definitions of terms used – for example exactly how many systems are required to create a botnet – the Directive mentions a ‘significant number’[16] of computers, but of course this is ambiguous and notions of this definition would differ from person to person. There is also the question of what exactly constitutes prejudice to identity owners[17]

All these ambiguous definitions will be ironed out over time, but it is likely to cause some complications and misunderstandings within the first stages of implementation. The question of being able to respond to ‘urgent’ requests from other Member States within eight hours is also likely to cause a few problems and complications; however they again should be made a little clearer and easier as time goes on. With this there is the issue of what exactly is ‘urgent’, to which is it presumed with Member States will use their discretion, and also the fact that legal proceedings take a long time and eight hours may not be long enough to collect the relevant data needed to answer the question at hand. 

Although undisputed that Member States should respond within a reasonable time frame, eight hours seems a little unrealistic if information gathered is to be reliable and a viable source. Given many countries have already criminalised many of the offences mentioned in the Directive, the implementation of the Directive in all Member States will ensure cooperation between national authorities and also hopefully make fighting cybercrime easier and more effective. The idea is to bring Member States in line with each other and hopefully change the situation as it presently stands – there are presently countries who have signed the EU Convention on Cybercrime but still have not ratified it. With the internet playing such a predominant role in society, it is important that it is one of the top priorities in Europe.

Botnets and DDoS
As the Directive mainly focuses on Botnets and the malicious attacks associated with them, it also seems appropriate to mention DDoS attacks. As already mentioned, a Botnet is a group of maliciously infiltrated, internet connected computers without the knowledge of the computers owner. The most common reason for these takeovers is DDoS attacks, which are a subcategory of DoS attacks (Denial of Services). The distributed form of the attacks occur when distributed computers are used from different locations to attack a particular victim/server; the attacks are an attempt to make a server or a network unavailable to its users by temporarily interrupting or suspending services of the host,[18] usually through overwhelming it with traffic from multiple sources[19] which consume its resources, forcing target computers to reset or obstructing the communication media between the indeed users and the victim so they can no longer adequately communicate, rendering it unusable.[20]   The consequence of the server being unusable is loss of money and status of the organisation or website which is being attacked. When used in conjunction with Botnets, the individual controls the botnets remotely to allow for maximum protection and target the maximum number of computers or most effectively attack a specific target.[21] 

In simple terms DDoS attacks either crash services and/or flood services. It is also possible that DDoS attacks or botnet can be traded on the black market – a week long DDoS attack, capable of making a small company go offline, can cost as little as 100 Euros[22]. Systems may also be compromised by a trojan (malware programme which carries out actions determined by the malware causing loss/theft of data and system harm[23]) or hackers can break into systems using automatic tools. There are many different ways to hack into computer systems and cause damage to these platforms, which were intended for a good purpose. As attackers get more knowledgeable about the ways around protection services and firewalls, the next logical step is, of course, legal protection. There have been many cases in recent times where these advances can be demonstrated.

Case Law
If we look at case law, the protection of people on the internet has been long awaited and is essential if the internet is to develop further. In 2005, Jeanson James Ancheta became the first person to be charged for controlling large numbers of hijacked computers (botnets). Although this is an American case, because of their involvement in the ratification of the Framework Directive, it is relevant to our understanding. A similar event occurred in 2009, where a Mr Schiefer was sentences to a 48 month prison sentence after he used botnets to steal the identity of thousands of people and wire tapping computers. These both being US cases, there is also relevant case law in Europe which backs up the need for a stricter stance on cyber crime.

July 2012 saw the shutdown of the Grum botnet, which was responsible for 18 billion emails ever day and 17.4% of global spam traffic. February 2013 saw Microsoft and Symantec put an end to the Bamital botnet, which redirected computer users to a website where they would cash in on the traffic and online advertising network, netted an estimated £640,000 while in operation.[24] 

December 2013, Greek police arrested two individuals who were connected with the spam botnet “Lecpetex” which used Facebook to target as many as 250,000 computers and use them to mine a Bitcoin-like currency called Litecoin.[25] The malware affected users in the UK, Europe and North and South America. This was the biggest case ever handled by the Greek Cyber Crime Unit at the time according to Greek news site, the “Greek Reporter”. A very prevalent case is that of Matjaz Skorjanc, who was arrested in Slovenia in 2010 after it was found he introduced the malware “Mariposa”, which hijacked 12.7 million computers from over 190 countries.[26] He received a 58 month prison sentence and ordered to pay a 4000 Euro fine, as well as forfeiting his home and car, which it was alleged he bought with the money received from the event. It should also be noted that many cases of cybercrime go unreported, especially when the victims have a reputation to uphold, this could include banks, as reporting such things may result in even greater reputational damage. Therefore although there is a large amount of case law on these subjects and it is likely that these are only a fraction of the real number of cases which occur.

Identity Theft
Although not covered as extensively as Botnets, identity theft is still a problem in the cyber sphere, and with the crime rate for this increasing it is important to demonstrate a united legislative front through way of implementation through the Directive. According to article 9(5) of the Directive, Member States are required to ‘take the necessary measures to ensure that when [..illegal system access or interference..] is committed by misusing the personal data of another person, with the aim of gaining the trust of a third party, thereby causing prejudice to the rightful identity owner... may be regarded as aggravated circumstances unless those circumstances are already covered by another offence, punishable under national law.’[27] 

In other words – identity theft: the misuse of personal data to gain the trust of a third party, and prejudice to the rightful identity owner. Prior to the Directive, many countries did not have existing legislation specifically tailored towards identity theft, but were left to fall under general criminal laws such as fraud prevention legislation. With identity theft, as with many criminal acts, there is an intention to cause some kind of harm and therefore it was considered that it should be given a clearer distinction for criminalisation.

Big Brother State?
From the above, we can see that there are many important decisions made by the courts which show how important it is to have case law and legislation to protect users of the internet. Case after case can be found on the use of Botnets and the damage they cause to individuals and companies alike. However, some may argue that the protection on the internet is too much and may actually infringe rights of users in an attempt to keep them out of harms way. The recent case of Edward Snowden brings to light the fact that it is not just civilians who are accessing computer information of unsuspecting members of the public, it also happens on a regular basis by government officials. The US, UK, Sweden, France and Germany all have the means to tap into the main internet cables of their country and collect all the traffic which occurs at any given time – this is done by lawful interception facilities and standardised interfaces[28]

Although considered lawful, it has raised questions as to the ethics of security and surveillance technologies, and how far the Directive has gone in order to protect citizens. The New Directive allows those party to it to use their discretion and take “necessary action to ensure” various things such as the protection of the nation and its people. The problem itself lies not with the directive, as this explicitly states that it is not for ‘minor’ acts, but more for large scale problems – however the definition of minor acts itself is open to interpretation by each government, making it a bit arbitrary and open to abuse. 

The problem is the amount of power that the government processes and the possibility of the abuse of that power. Having access to the central servers and databases of the internet, and the ability to tap computers could potentially lead to the abuse of this to obtain information or statistics that would not otherwise be readily given up. The monitoring of internet use is one step closer towards total surveillance and the feared ‘big brother’ or ‘nanny’ state and the removal of basic protection against misuse of information.[29] It has already been reported that a number of countries, including the US and UK, are already monitoring e-mails (looking out for key ‘trigger’ words, friends of suspects or those from unsavoury backgrounds) and data traffic from many unsuspecting civilians computers, but the directive affords a little more discretion and flexibility to countries, causing an arguable expansion in their already seemly unregulated power. The states often argue that pre-emptive surveillance is there for protection but in fact it infringes the right of the people to have the government not interfere in family and private life.

Increased Co-operation
 The effect of the EU Directive worldwide should also be considered. As previously discussed, the Directive hopes to make it so perpetrators of these kinds of cybercrimes cannot use the national laws of less developed Member States to avoid prosecution. However, many people who are responsible for attacks in recent times reside outside of the EU, and so the Directive will have little or no effect on their activities. This then becomes an issue of international law and jurisdiction, which makes it more complex to arrest and sanction those responsible. If a criminal hides in a country which is not a Member State, it becomes a question of whether that country will allow EU officials to detain and question the suspect – something which is unlikely to occur.

This can be seen in the example of the previously mentioned Edward Snowden case, -who sought refuge in Russia, a Non Member-State, who did not give permission for European Officials to enter the territory to arrest Snowden. Of course there may also be questions of jurisdiction between Member States – as it stands, each Member State has jurisdiction for offences committed on its territory or by one of its nationals. Where several Member States have jurisdictional rights over the same matter, cooperation is essential in deciding which State will conduct proceedings[30] against the perpetrator. 

The Directive introduces the importance of the exchange of information, with regards to the exchange of information, obligations remain the same in the Directive, but a response time is added: eight hours to reply to urgent requests from other Member States. There are some reservations held about this time limit though, although eight hours may be feasible for a reply, this reply was unlikely to be substantive or useful because of lack of time for proper investigations and compilations of information.[31] With many different task delegations afforded to cybercrime and information technology, eight hours would more likely result in fragmented bits of incomplete information – a more realistic time frame would be around twenty-four hours, according to most Member States.[32]

To conclude, the new Directive is set to replace the existing Framework Decision of 2005. It has come at an appropriate time as, although the Framework Decision is not old, rapid advancement in the area of information technology means that the legislation must also match this rapid development. Recent times have seen the increasing problems which are caused by malware such as botnets and large scale cyber attacks which threaten to cripple key information infrastructures of many countries, possibly at the same time. The unity that the Directive hopes to create will mean a more rapid response time and a greater level of compliance and cooperation between Member States who have signed and ratified the agreement. By 4th September 2015 the new Directive will be implemented in the national systems of all Member States (with the exception of Denmark), but it is inevitable that new provisions will be needed by this time already. 

The review in 2017 will act as a forum to propose new developments in the legislation and it will hopefully be the case that advances will keep up to date with the problems posed by technology and malicious software. The law will realistically always struggle to keep up with those who abuse the freedom granted by the internet, but as long as legislation acts as some form of deterrent by imposing tough sanctions on those who do take advantage, then it can be considered a success. 

The introduction of Directive 2013/40/EU is a positive thing that will increase safety and security on the internet, both for the individual and nations as a whole. It seems that the main aim of this Directive, as with any directive, is unanimity between the Member States. This can be seen through all Member States being addressees (and thus must implement the directive within their national legal order), the tougher, uniform penalties imposed for such offences, and the overall cohesion it hopes to create between the Members. This Directive is another step towards uniform laws throughout Europe due to the globalised nature of modern society.






[1] European Commission, 'Cybercrime' (Europa 2014) accessed 15th November 2014
[2] Council Framework Decision (EC) e.g. 961/2010 combating fraud and counterfeiting of non-cash means of payment [2001] OJ L149/2001
[3] Hans Graux, 'New Directive on Attacks against Information Systems' (Time Lex 2013) accessed 15th November 2014
[4] European Directive (EC) 2009/136/EC amending Directive 2002/22/EC on universal service and users’ rights relating to electronic communications networks and services, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector and Regulation (EC) No  2006/2004 on cooperation between national authorities responsible for the enforcement of consumer protection laws [2009] OJ L337/11
[5] European Directive (EC) 2011/92/EU on combating the sexual abuse and sexual exploitation of children and child pornography, and replacing Council Framework Decision 2004/68/JHA [2011] OJ L335/1
[6] European Directive (EC) 2013/40/EU on attacks against information systems and replacing Council Framework Decision 2005/222/JHA [2013] OJ L218/8
[7] Council Framework Decision (EC) 2005/222/JHA on attacks against information systems [2005] OJ L69/67
[8] e.g. Council Regulation (EC) 2012 Consolidated versions of the Treaty on European Union and the Treaty on the Functioning of the European Union [2012] Art 83(1)(a) OJ C 326/01
[9] Microsoft, 'What is a Botnet?' (Microsoft e.g. 2005) accessed 15th November 2014
[10] Mark Turner, Nick Pantlin, Loretta Pugh and Christine Young, 'EU Cyber Crime Directive takes a tougher stance against attacks on information systems' (Lexology 2013) accessed 15th November 2014
[11] Brid-Aine Parnell, 'EU crackdown will see tougher sentences for stupid cyber-badhats' (The Register 2013) accessed 15th November 2014
[12]Ibid. 11
[13] European Commission, 'Directives - Definition' (Europa 2012) accessed 15th November 2014
[14] Ibid. 6. Article 18.
[15] Ibid. 6. Article 17
[16] Ibid. 6 Preamble 5
[17] Ibid. 6 Article 9(5)
[18] 'Botnet DDoS Attacks' (Incapsula ) accessed 15th November 2014
[19]What is a DDoS Attack?' (Digital Attack Map 2013) accessed 15th November 2014
[20] http://en.wikipedia.org/wiki/Denial-of-service_attack
[21] Ibid. 19
[22] Ibid. 17
[24] Katie Collins, 'European Union agrees tougher jail sentences for cybercriminals' (Wierd 2013) accessed 15th November 2014
[25] Matthew Sparkes, 'Arrests as Facebook spam botnet is shut down' (Telegraph 2014) accessed 15th November 2014
[26] 'Mariposa botnet 'mastermind' jailed in Slovenia' (BBC News 2013) accessed 15th November 2014
[27] Ibid. 6. Article 9(5)
[28] C.f. the secret room 641A at the AT&T switching facility in San Francisco, see Whistle-Blower's Evidence, Uncut, Wired, 22.5.2006, http://www.wired.com/science/discoveries/news/2006/05/70944;  the GCHQ Tempora programme, see GCHQ taps fibre-optic cables for secret access to world's communications, The Guardian,21.6.2013,http://www.theguardian.com/uk/2013/jun/21/gchq-cables-secret-world-communications-nsa; the German Telecommunications Surveillance Regulation of 2005. The European Telecommunications Standards Institute (ETSI) has a “Lawful Interception Seminar” responsible for defining such standards.

[29] http://www.independent.co.uk/news/uk/politics/the-big-brother-state-ndash-by-stealth-1050576.html
[30] 'Attacks against information systems' (Europa 2008) accessed 15th November 2014
[31] European Union Agency for Network and Information Security ‘The Directive on Attacks Against Information Systems’ Version 1.5, 2013
[32] Ibid. 31.