Data Retention in the EU
Total Page:16
File Type:pdf, Size:1020Kb
Evidence for necessity of data retention in the EU Table of Contents 1. Introduction ................................................................................................................................. 2 2. Context ........................................................................................................................................ 2 3. How communications data are used ............................................................................................ 3 4. Overview of types of cases in which data are important ............................................................. 4 5. Consequences of absence of data retention ................................................................................. 5 6. Cross-border aspects of data retention......................................................................................... 6 7. Statistics and quantitative data .................................................................................................... 7 Article 10 ......................................................................................................................................... 7 Available statistics ........................................................................................................................... 7 Limitations of quantitative data ....................................................................................................... 8 Conceptual and methodological issues ............................................................................................ 8 8. Qualitative data ........................................................................................................................ 9 Terrorism ......................................................................................................................................... 9 Murder and manslaughter .............................................................................................................. 11 Serious sexual offences and child abuse ....................................................................................... 15 Buying or offering online child pornography ................................................................................ 18 Drugs trafficking ........................................................................................................................... 19 Armed robbery .............................................................................................................................. 21 Burglary, theft and organised trafficking ...................................................................................... 22 Cybercrime .................................................................................................................................... 26 Fraud .............................................................................................................................................. 27 1 1. Introduction This document draws together evidence which has been supplied by Member States and Europol in order to demonstrate the value to criminal investigation and prosecution of communications data retained under the Directive 2006/24/EC (the Data Retention Directive or 'DRD'). It contains some general context on the role of historical data in various types of investigations, some observations on the available statistics, and a selection of individual case studies which have been provided by Member States. It is intended to provide further information on the question of the necessity of data retention; readers should also consult the evaluation report for the Commission's general evaluation of the DRD,1 which included (section 5.4) a number of the arguments which are developed in this document, along with a few illustrative examples, and other statements including replies to questions from the European Parliament2 concerning the role of communications data in the investigation and prosecution of the most serious crimes. 2. Context Crime in the EU3 is increasingly characterised by highly mobile and flexible groups operating in multiple jurisdictions and criminal sectors, and aided, in particular, by widespread illicit use of the internet. These groups focus their activities where they perceive the risks of detection to be low, like credit fraud and counterfeiting, which along with trafficking in weapons, drugs and human beings are also extensively used to finance terrorist activities. The EU furthermore is a key target for cybercrime, and the prevalence of internet technology has created a market for child abuse material. Criminal exploitation of communications technologies mirrors general trends in consumer behaviour. In the 1990s a typical user might make 10-20 fixed line or mobile calls a day and send two or three SMS over a few networks; in the 2000s with increased volume and network coverage, a typical user might make 15-25 calls and send 5-15 emails and SMS, and also use online chat, browsing and 'voice over the internet' services.4 Internet protocol (IP) traffic volumes were estimated to have more than trebled between 2007 and 2010,5 and in the current decade the internet is the primary source of communication. Criminals attempt to evade detection through the use of false identities or anonymous communications services. Investigators therefore need not only to be able to access traffic and location data and associated identification details, but also to be confident that these data cannot be fabricated or falsified. The access by and exchange between law enforcement authorities of these communications data is essential to the successful disruption of organised criminal networks. 1 COM(2011)225, 'Evaluation Report on the Data Retention Directive (Directive 2006/24/EC)' http://ec.europa.eu/commission_2010-2014/malmstrom/archive/20110418_data_retention_evaluation_en.pdf 2 E.g. E-004636/2012 3 See Commission Communication 'First Annual Report on the implementation of the EU Internal Security Strategy', COM(2011) 790 Internal Security Report; Europol: Organised Crime Threat Assessment (OCTA) 2011. 4 Analysys Mason, Europe's Digital Deficit: Revitalising the Market in Electronic Communications, 3 March 2010. 5 Source: Cisco Visual Networking Index. 2 Communications data which do not concern the ‘content’ (e.g. the conversation during the telephone call, the message in the email) but rather the 'envelope' or 'metadata', consist of information on the identity of subscribers or clients (i.e. service-associated information e.g. IP addresses), traffic data (i.e. communication-associated information e.g. logs of calls received and made), and data on the location of the user at the time of the communication.6 Such non- content data were used before the adoption of the DRD in high-profile investigations including the murder of Irish journalist Veronica Guerin in 1996, the uncovering of a massive international drug trafficking ring centred around the 'Ndrangheta mafia organisation (known as operation IBISCO), the murder in 1998 of Corsican police prefect Claude Erignac, and the 2004 Madrid bombings. The DRD was adopted on 15 March 2006 with the aim of ensuring that such data be retained for between six months and two years and be available for the purpose of the investigation, detection and prosecution of serious crime. It is in force in most Member States.7 The Commission’s evaluation report, published in April 2011,8 concluded that, given the objectives of the Internal Security Strategy9 and the Digital Agenda,10 the EU should continue to support and regulate the storage of, access to and use of communications data, but should improve EU rules to prevent the different types of operators facing unfair obstacles in the Internal Market and to ensure that high levels of respect for privacy and the protection of personal data are applied consistently. 3. How communications data are used During criminal investigations requests for communications data usually proceed - and often result in – the arrest of suspects, bringing of charges or the exclusion of people from investigation. Fewer data are used during prosecution proceedings in court. This may be because prosecuting authorities are unlikely to use information about individuals who have been investigated and then deemed to be of no further interest to the investigation, or because accused parties when confronted with evidence provided through communications data decide to enter guilty pleas which thus remove the need for the communications evidence to be adduced in court. Communications data are used to corroborate other evidence like witness statements and evidence of the association of suspects and location and chronology of event. Some crimes may be dealt with through administrative means (e.g. a caution), and certain investigations may be unable to progress for various reasons. Consequently, more data tend to be acquired initially by the investigator than is later relied on in court. Defence counsel also obtain access to these data: one UK authority reported that there had been 204 such requests between April 2009 and March 2010. 6 These types of data are reflected in Article 5(1) of the DRD i.e. from whom (sub-article a)) and to whom (b) the communication was sent, when it was sent and how long it lasted (c), what sort of communication (d), how the communication was sent i.e. what equipment was used (e) and where the communication was sent (f). For definitions see ETSI Technical Standard 101 331. 7 The deadline for transposition