HoC 85mm(Green).tif

Science and Technology Committee

Oral evidence: Investigatory Powers Bill: technology issues, HC 573
Tuesday 8 December 2015

Ordered by the House of Commons to be published on 8 December 2015.

Written evidence from witnesses:

       BT

       techUK

       Home Office

Watch the meeting

Members present: Nicola Blackwood (Chair); Victoria Borwick; Stella Creasy; Dr Tania Mathias; Carol Monaghan; Graham Stringer; Derek Thomas; Matt Warman

Questions 91-167

Witnesses: Mark Hughes, President, BT Security, and Antony Walker, Deputy Chief Executive Officer, techUK, gave evidence.

Q91   Chair: Good afternoon and welcome. Thank you for coming to our second session on the Investigatory Powers Bill. We are looking specifically at the technological aspects and feasibility of the Bill. Mr Walker, techUK has submitted some written evidence to our inquiry. In particular, you asked the Committee to consider the importance of clear definitions of terms such as “telecommunications service”, “relevant communications data”, “communications content”, “equipment interference” and so on. Could you explain to the Committee where your concerns lie in terms of definitions?

Antony Walker: Thank you and good afternoon, everybody. Clearly this is a very complicated and in many ways necessarily complex piece of legislation. It is putting some quite complicated technological issues in the context of a legal framework, which inevitably means that the translation of language can often be difficult. It means that often language used in the course of a technological discussion changes when it is used in a more legal context. Secondly, the core definitions in the document have an enormous impact on the interpretation of the measures and powers in the Bill, so issues like communications service, communications content, equipment interference, technical feasibility and reasonable practice all become central terms in the Bill and have significant implications.

Two aspects are a particular challenge, one in relation to the definition of relevant communications data. I think that Graham Smith, who provided written evidence to this Committee, very usefully mapped out the way in which that term relies upon interlinkages between 13 different definitions in the document. Trying to understand what relevant communications data really means in practice remains unclear. The industry view is that we could certainly benefit from perhaps examples or clearer suggestions as to what is and is not included.

The second issue is internet connection records—ICRs—where there appear to be inconsistent definitions in the text. Two definitions purport to explain what an ICR is in practice, but when you put together the various definitions and the uncertainties around them it means that the whole piece of legislation is open to quite a lot of interpretation. That is an uncomfortable place for the industry and also law enforcement to be. These are issues that we think need to be addressed.

 

Q92   Chair: Mr Hughes, do you share these concerns?

Mark Hughes: In part, yes. The specific definition of internet connection records that has already been mentioned is important. More definition is required around that. We have been consulting with the Home Office. There is more to be done to ensure that we get to a point where not only can we understand the purpose behind it, but that then leads us, more technically, into how we would be able to comply with internet connection records—a thrust of the Bill. There are further things about public and private networks. Definitionally, we think it is very important that a distinction is driven between what is a public and what is a private network. We think that the Bill and the law should apply where we provide public networks, not private ones. That is not clear.

We welcome the concept of traffic data in the Bill, which distinguishes between entity and event data and content. There are really three definitions around data. The Bill introduces a new concept and we think that is encouraging and good, but there is a need to work through the detailed definitions of exactly what that means. The principle to apply when it comes to definitions in the Bill is that we need to be very careful about the extent of intrusiveness around definitions that are driven by the type of data. Therefore, in terms of the intrusiveness that results from that definition one should always level up. One should always look to apply the most stringent safeguards to the appropriate level of intrusiveness. Where the definition of the data drives you to more intrusiveness you should level up the stringency of oversight.

 

Q93   Chair: Mr Walker, one of the definition questions you raise in your written evidence is about equipment. You say it is important for the Committee to consider exactly what the nature of the equipment could be, for example whether it could include even interference with an autonomous vehicle. Since you submitted this piece of evidence, have you received any further information in consultation with the Home Office, or any of your member organisations?

Antony Walker: No. At the moment we do not have any further clarity on that issue. The definition of equipment is hugely important in relation to the powers around equipment interference, in particular bulk equipment interference, because we are moving beyond a world that is just about telephony, accessing messaging services and so on. In an IOT—internet of things—type world the definitions that seem to apply to equipment seem to apply potentially to a huge range of devices that could be used for communications purposes and other purposes as well. The definition is quite clear that these can be devices that relay messages between non-human beings, as it were, so it can be machine-to-machine communication. In the context of the internet of things you have many types of connected devices, one of which is autonomous vehicles. A range of devices in the news recently in relation to a hack are toys with which children can interact. These devices may sit in a child’s bedroom, but they may be accessible. In theory, the manufacturer of the products could be subject to a warrant to enable equipment interference with those devices. The potential extent needs to be carefully considered by Parliament and this Committee when we think about not just the world today but the world in five or 10 years’ time as the internet of things becomes more real and pervasive.

 

Q94   Chair: Does techUK have a view as to what the definition should be?

Antony Walker: It requires careful thought about where the limits should be. We have not come up with a defined limit, but it needs to be the subject of further conversation and discussion with the Home Office and others to get it right. It needs proper debate rather than simply people trying to draw an arbitrary line.

 

Q95   Carol Monaghan: We know there are huge benefits to our economy from IT and telecommunications companies, for other people involved in terms of employment and in subsidiaries. There is a clear financial implication regarding compliance with the Bill in terms of the collection of ICRs. At this point are you satisfied with what the arrangements will be in terms of the financial help on the compliance costs that may be associated with this?

Mark Hughes: If you are asking whether we will be directly impacted by it, no, we are not at this stage. We have been consulted and we have gone through some lengthy consultations with the Home Office so far. For two key reasons we believe very strongly that it should be made expressly clear in the legislation that all eligible costs incurred by us as providers should be met by Government. First, we think that through the cost discussion in the consultation process a proportionality element is introduced, when considering how much a potential solution may cost. We believe that is quite important. In other words, if during that consultation process something is going to be exorbitantly expensive to achieve little impact, one could argue that proportionally it might not be an appropriate thing to do. We think that to capture the full costs is quite important in that context. At the moment the draft legislation does not make it clear that all eligible costs will be reimbursed to us.

The second reason why we think it important that that is the case is that the UK, the industry and citizens as a whole should not be burdened by this. It is something Government should pay for and they should reimburse us for it. At the end of the day, it is important for us to note that as a commercial business, where we are required to comply with the law, under current and future legislation, the intent is that we are reimbursed. We want to be reimbursed our costs. There is no profit. The profit for UK plc is diminished because we do not make any money by complying with the legislation; it is simply a cost reimbursement. We think the Bill is not clear and it needs to be clearer that in future we will be reimbursed for our costs.

 

Q96   Carol Monaghan: Mr Walker, you are nodding. I imagine you concur with Mr Hughes.

Antony Walker: Yes. First, the figure of £174 million is mentioned in the impact assessment document. Although that was based on some consultation, given the uncertainty about the extent of the powers and the implications of potentially a much broader range of communication service providers, at this stage it is quite difficult to determine whether or not that is an accurate figure. I have met very few people across business who currently would regard it as a properly robust figure. The point my colleague was making is absolutely right, in that, if Government are responsible for meeting the full costs, it is an important check to ensure that the powers the Government seek to implement are proportionate.

 

Q97   Carol Monaghan: If my understanding is correct, both of you are saying that the compliance costs should be met by the Government, not companies, and you are not entirely sure how the figure of £174 million that has been set aside is going to be allocated in order to meet compliance costs.

Mark Hughes: Let me be quite specific. We have done some lengthy consultation, and indeed a pamphlet has been issued to us about the potential costs, especially round internet connection records. We have already discussed the concept of internet connection records and the definition of them. We believe more work needs to be done to help define what they are, although the purposes for which they will be used are clear in the three scenarios given in the draft legislation.

Technical compliance with the intent of the Bill at the moment is not straightforward; it is quite complex. There are different ways of achieving different things with different levels of return. Therefore, the cost estimate at the moment—you mentioned the figure of £174 million—could apply in some senses, but on some of the assumptions we have worked through, based on information we have been in receipt of through consultation, we think it will cost our business alone a lot—many tens of millions. I cannot comment on what it may cost other businesses, but as a large communications provider in the UK we will incur significant cost if you implement the intent and assumptions behind the internet connection records part of this Bill.

 

Q98   Carol Monaghan: So that figure of £174 million is unrealistic.

Mark Hughes: I could not comment on its entirety. All I can say is that it would cost us a large part of that figure to be able to implement, looking over a period. When one looks at the internet connection records part of the Bill, the bandwidth appetite in our country is increasing very rapidly, so, clearly, assumptions have to be put in that take account of the fact that bandwidth will increase. Indeed, in the consultation some of that has been taken into account, but the core key technical aspect of the internet connection records part of this is the extent to which the sampling or 100% collection goes on within the networks for them then to be able to comply. Technically, there are many different options, depending upon what you come up with, so there is a definite range of possible costs.

 

Q99   Matt Warman: When the Data Communications Bill was considered in the previous Parliament a similar operation was going to cost a rather greater amount of money. Is it your understanding that the reason for the significant fall in the estimate is accompanied by a significant change in what you are being asked to do?

Mark Hughes: No. I cannot refer back to the previous draft legislation because it was some time ago. We are where we are. In looking at how we would comply with the intent in the Bill, technically there are many options in it. They range from the sampling of NetFlow traffic—quite a technical term, but it is one of them—up to and including full one-in-one capture of flow traffic, which is much more onerous in terms of both capture and storage. That is really the spectrum. If one was at one end of the spectrum it could be much more lightweight and the costs could be potentially more, but at the other end of the spectrum they might not be appropriate. It is difficult for me to comment specifically on whether they are right or wrong. We have been consulted, but we think there are more consultations and workings to go through.

 

Q100   Chair: The techUK consultation said it was unclear whether the £174 million would be able to be used for security measures to ensure that data were kept safely. Mr Hughes, in your consultation with the Government has that been made clear to you?

Mark Hughes: I think it is implied within it. We have to be clear that, specifically on internet connection records, this is new data that we do not generate for business purposes, so we would have to have an infrastructure that ensured it was secure.

 

Q101   Victoria Borwick: Continuing on that, do you think the ISP industry could move overseas to avoid being compelled to comply with the proposed measures? Could customers or ISP providers move overseas? What are the risks?

Mark Hughes: We have no intention of going anywhere. We make a significant contribution to the UK economy, and we are very proud of the fact that we are significant in the UK market. I do not see that as a risk for the large internet service providers, and certainly not in our case. On the general point of the question, anyone providing services in the UK will come under the Investigatory Powers Bill, wherever they are located, and should do according to the draft legislation. However, there could be issues associated with those who provide services in the UK but are not located in the UK. Clearly, jurisdictionally, getting them to comply if they are located overseas is a clear challenge; a request from the UK may conflict with local laws. As far as large ISPs are concerned, I do not see them locating overseas.

Antony Walker: This is perhaps where we ought to differentiate the different powers within the Bill. Different powers apply to different types of company. In terms of the impact of the draft Bill on businesses and business practices, it probably varies very much between different companies that play different roles in the value chain. They will have different assessments of the operational, technical, financial and also, frankly, reputational impact that the legislation may have on their operations. For some companies, the bulk equipment interference powers could have significant reputational impacts on their business, where they feel that it potentially undermines the security of their services, should they be subject to a warrant; indeed, the potential that they could be subject to a warrant, but are unable to tell anybody whether or not they have been, simply undermines their credibility. We are aware of some companies that said that makes them question where the right jurisdiction might be for them.

Interestingly, potentially there are significant problems for companies based fundamentally on an open source business model. I think you have had evidence from Mozilla in that regard, which I think is quite instructive. The very nature of its business, which is based on inputs from the open source community, means that a lot of its code has to be out in the open. Therefore, meeting any of the equipment interference requirements would be something it could not conceal from the people who provide the open source software. A company like that would face very real specific problems. It varies very much in terms of the different types of companies that could be subject to the powers set out in the draft Bill.

 

Q102   Graham Stringer: Is there anything in the draft Bill that could threaten the integrity of encryption?

Antony Walker: The issue of encryption has been much debated. In advance of publication of the Bill, the Government were at pains to say they did not seek to ban encryption or undermine its use at any point. However, the language around encryption remains a little opaque, and responses from the Home Office when questioned on the implications of some of those powers remain unclear.

The powers are such that the security services could request that telecom service providers remove any encryption used by them to provide information in the clear. What is not completely transparent is what happens where a third party has implemented end-to-end encryption themselves and it would not be technically feasible for the service provider to remove that encryption. There is still some uncertainty and concern across the industry about the implications for encryption. Having said that, if we take the comments made by the Home Secretary and other Ministers in the House, they have been very clear about how they interpret the Bill, and to some extent we are relying on that interpretation.

 

Q103   Graham Stringer: But you are not satisfied with the language in the draft Bill at the present time.

Antony Walker: It is more open to interpretation than we would like.

Mark Hughes: I agree with what Antony is saying. We think that if there is provision in the Bill it should be very targeted; there should be no blanket approach. An important principle that needs to be clear in the Bill is that, when information is requested, it needs to be requested from the most relevant party—those closest to the information requested. In the case that Antony just outlined, if it is a third-party, over-the-top provider who is delivering services across our networks, clearly they are closest to the customer using the service and to the service itself, so they are the ones who should be targeted. In principle, if a request is put upon them, they should produce and disclose the information under the correct framework within the Bill; it should not be down to organisations like ours. Of course, where there is a request for us, where we are running encrypted services, there are provisions in existing legislation and the draft legislation that mean that, under the correct legal instruments, we have to comply.

 

Q104   Graham Stringer: Is there a perception within the industry that this is a threat if the wording is not cleared up, or is the industry relaxed about it?

Mark Hughes: On a subject like this we are not relaxed about any area of it, frankly, because it is an incredibly serious matter. As far as this particular area is concerned, we would welcome greater clarity on that specific point, on the principle that the closer you are, that is the place that should be targeted in terms of disclosure.

 

Q105   Graham Stringer: How will you deal with the situation where it is your responsibility to keep the encryption secure but you are also being asked to de-encrypt? You have two competing responsibilities there. How do you balance them?

Mark Hughes: Increasingly, a lot of traffic is now encrypted. We had a debate earlier on internet connection records, where there are new levels of encryption. Transport layer security—TLS—1.3, which is now appearing, is a protocol that will have a big impact on the ability of internet connection records to be useful, to have utility. Encryption is there; it safeguards people who use the types of services we provide, so we think that is a good thing. We do not think there is an inherent conflict in the sense that we are carrying encrypted traffic. Where we are then requested and mandated under the legislation to deal with services that we may encrypt is quite a separate matter. There is one where we carry traffic that is encrypted and one where we encrypt traffic for our purposes, and they are quite distinct matters. The important point is that we should not do anything to undermine the fact that security and privacy are a continuum of the same thing. It is important, and encryption has a significant role to play in that.

 

Q106   Chair: To follow the point you made that those closest down the chain should be targeted for disclosure, do you not think that the technical feasibility test in clause 190 is a relevant safeguard? If the Bill required businesses to change their policy completely and move encryption from user to provider, surely it would breach the technical feasibility test, wouldn’t it?

Antony Walker: Again, it depends upon the interpretation. I must stress that many companies are themselves still trying to work through the implications of the Bill and to understand it, so there are different views at this stage. If we look at what is technically and reasonably practical in the various definitions of the Bill, we believe it means that when companies are providing services where there is end-to-end encryption instigated by a third party and not by themselves, it safeguards them from having to modify or change what they are doing, but it is open to interpretation.

 

Q107   Chair: Do you have confidence in the technical feasibility test as a safeguard?

Antony Walker: We would like to seek further reassurances about how it works in practice.

 

Q108   Chair: What sort of reassurance would reassure you?

Antony Walker: We have not yet heard from the Home Office or others that the interpretation we would like to place on it is indeed the interpretation that they would hold.

 

Q109   Chair: What interpretation do you want to place on it?

Antony Walker: That it provides a sufficient safeguard, which means that companies that are today providing end-to-end encrypted services on behalf of customers would not be required to modify their business practices.

 

Q110   Chair: What about you, Mr Hughes? What do you want the technical feasibility test to deliver?

Mark Hughes: We believe, first, that government has to have the right investigatory powers to protect society and balance customers’ privacy and security, and oversight and transparency are crucial. Strong law, with safeguards throughout the process, is absolutely important, and there are in the draft Bill mechanisms to achieve that. One of them is the technical advisory board. We think that, constituted in the way it is, it should probably be called the advisory board and not limited just to technical matters. It should include cost and legal matters, which we think are important parts of the composition of the board. In that forum we could have robust exchanges in understanding some of the matters we are dealing with here: for example, how one can practically work through and then issue of codes of practice, which are important, and have examples before getting into issuance of either a technical capability notice or a data retention order, which obviously is the net result of the Bill being enacted. It is in that area that we need to deal with these types of issues, because inevitably technology will move on. As I have said already, there is a new encryption protocol, although it is probably 18 months or two years away, but that will change the landscape quite dramatically.

 

Q111   Dr Mathias: Do you think the draft Bill gives a competitive edge to smaller service providers if they are not subject to measures like data retention?

Mark Hughes: It is not entirely clear that they would not be subject to the provisions of the legislation. I am not sure that is necessarily an issue. In some ways it could be the reverse. A small business that is made subject to the provisions may well face significant challenges in meeting them. As far as I understand it, the Bill applies to all communications service providers and other organisations that have data that may need to be subject to retention. They will have to comply with the legislation as well, especially if you take into account the principle I referred to earlier that those closest to the customer should be the ones subject to a request for information, if they have it.

 

Q112   Dr Mathias: Do you think they would they get their costs met?

Mark Hughes: I can speak only for our business, but we strongly advocate that costs should be met. I come back to what I said earlier. If in the consultation process cost is taken into account and there is a realisation that all the costs have to be packaged up in deciding what capability might be sought, it will provide a check to inadvertently going on technical fishing expeditions to ascertain what might or might not be possible. The costs inadvertently introduce, alongside the legal framework, a proportionality check that says we will not spend an enormous amount of money on what might be quite limited capability. That could immediately put paid to that happening, and resource could be more usefully used to create a better impact that might be more proportionate.

 

Q113   Matt Warman: If you were to receive an unreasonable request, or a request that you thought unreasonable, are you satisfied that the Bill provides a process for there to be some dialogue about the reasonableness or otherwise of that request?

Mark Hughes: Yes. One of the key strengths of the current draft legislation, compared with previous legislation, is that that is much clearer and the oversight is much stronger. It is imperative that there is a level playing field, as I alluded to quite a few times, for all communication providers in the UK, and for those existing outside the UK who terminate service and deliver service in the UK as well. To that end, the Bill does a number of things. First, at this level it brings together a number of pieces of legislation, which we welcome and think is good because it is much clearer. We also think that with that comes a stronger oversight regime. To answer your specific question, the technical advisory board, as it is constituted at the moment, and in the consultation that is going on, and has gone on throughout the drafting of the Bill, has been markedly different from before. We welcome that. Looking to the future, there are aspects and mechanisms enshrined in the draft legislation that we think give us a much better opportunity to challenge, which we have done in the past and will continue to do in the future. How that mechanism works is now much clearer in the Bill. In addition, the general oversight provisions are different from what they were before, and we welcome that as well.

Antony Walker: On the technical advisory board, given the broader scope of the legislation and the fact that it will potentially apply to a broader range of companies, it is probably appropriate to make sure the technical advisory board represents that range of companies; that it has the right technical and legal competencies and that it is clearly independent as a place where companies would go to seek appeals. It clearly means that the board has an extraordinarily important role to play in what is going to be quite a fast-moving and dynamic area.

 

Q114   Matt Warman: Are there any changes you would seek to make to its membership or role, or are you broadly happy with it?

Mark Hughes: Technical is slightly misleading; it should be “the advisory board”. It should still encompass technical matters, as well as policy, strategic issues, cost recovery and legal. It is important that legal is in there. Pretty well anything we would bring to that board would need a legal lens on it, because we would not be going there unless we felt there was a need for consultation and challenge.

We welcome the renewed powers around the investigatory powers commission. It is good that the investigatory powers commission will have oversight of all relevant aspects of the legislation, but the resourcing, funding and people need to be in the investigatory powers commissioner’s office to be able to cope with many of the newer things coming along, as Antony said, because this as an ongoing process. We have already noted today that there is quite a lot of detail to be nailed down, and that will continue to be the case as services change.

 

Q115   Derek Thomas: How clearly can communication content be distinguished from communication data, and do you think the Bill adequately recognises that distinction?

Mark Hughes: We welcome the fact that there is a definitional change between what is described as traffic data, which is split further into event and entity, and the actual content itself. We think that is helpful; it is in draft stage at the moment and we need to do more work through examples of how we do this. There is an extant way in which in the current legislation we look at the distinction drawn between content and communications data, less so in telephony data but more so in IP data. It is the so-called URL—the universal resource locator—and the information resource locator in the first slash. That remains as communications data, and anything beyond that becomes content.

We think that the Bill goes further in its definition between entity and event and content data. We welcome that, but we still think we need to work through more examples to understand exactly how you draw those distinctions, with the significant caveat that the whole purpose of the definition is to help deal with the point about intrusiveness. The definition needs to be there to ensure there is a check on how intrusive the powers are. We believe the definitions are important because we need to ensure that we establish a level of proportionality around the intrusiveness you go to or that is inadvertently happening. That is where the definition needs to be driven from, and, importantly, that you level up when you see that the definition might drive an intrusive power, when greater safeguards are required and need to be put in place.

Antony Walker: There is a technical definition and a technical distinction, but there is also a conceptual one in the minds of the consumer and citizen. The reality is that much of the data associated with communications will be regarded by many citizens as essentially highly personal and sensitive. That is where the analogy of the phone bill is quite unhelpful. I do not think that the full list of websites you have visited is an exact parallel with phone calls you might have made, because a great deal of information can be inferred from a list of destinations visited online about individuals’ thought processes, behaviour and preferences. For many citizens it will be regarded as sensitive and highly personal information in its own right, even though, according to the technical and legal definition, it is communications data and not content data. That has real significance in terms of oversight, in particular the safeguards around access to that data. There are some questions about whether the safeguards as currently written are appropriate for the sensitive nature of the data.

 

Q116   Matt Warman: Could we talk a little bit about equipment interference? Could you summarise what you think that really is?

Antony Walker: There are a number of important elements. We understand the need for a legal basis for the authorities to exploit vulnerabilities in devices and so on for investigative purposes when they are trying to gain more information and access more information about a targeted individual, as set out in clause 81 of the draft Bill. There is an important distinction, however, where potentially you are insisting that a private company assists in the process of gaining access or exploiting vulnerabilities in a device or service to get access to some information. In that situation, you are effectively asking a company to hack its own system or services to assist the security services. There is an important distinction that needs to be considered.

Another important distinction, which I think is even more problematic, is the area of bulk equipment interference. That is regarded by a lot of people across the industry as opening up the potential for the maintenance, or addition, of vulnerabilities in networks or services that should in reality be patched, because they present vulnerabilities for the individual and the service, and for the company in terms of liabilities and so on. This is one of the areas of the Bill that is most problematic for many technology companies. You really have to think forward to the world in five or 10 years’ time, to the sheer range and diversity of equipment that potentially could be interfered with and the consequences of that. For example, if a vulnerability is found in a system that means you can automatically stop an autonomous or a semi-autonomous vehicle, and that vulnerability is exploited by somebody else for malicious purposes, there is a serious risk to life for the people involved. In a much more connected world, with many more connected devices on which we all rely for our security and safety, we have to think carefully about taking that additional step.

 

Q117   Matt Warman: But is that primarily again about definitions to make sure there is not the vagueness in the Bill that you are talking about?

Antony Walker: Currently the definitions are very broad and open.

 

Q118   Chair: Surely, one of the reasons the definitions are broad is to future-proof the legislation. This has happened before in this place. There has been an attempt to make sure definitions are tight and very quickly the legislation becomes out of date. In an area as fastmoving as this that would be a mistake. Realistically, how tight can the definitions be in a piece of legislation like this, and how much needs to be left to secondary legislation, codes of conduct and the advisory board? It is a difficult question, but I am asking you, Mr Walker.

Antony Walker: It is indeed a difficult question. It is about understanding where it is appropriate to draw that line. In many ways it is an ethical question; it is about trying to foresee what the longer-term implications could be in areas where it is possible to perceive real potential for unintended consequences or misuse, or the opening up of other security vulnerabilities and opportunities for exploitation in terms of cyber-terrorism in the future. Those are the kinds of issues that should be informing the decision as to the appropriate safeguards to prevent that from happening. That is an area where we would welcome further discussion and debate in the process of scrutiny of the Bill.

 

Q119   Chair: What is your view, Mr Hughes?

Mark Hughes: Definitions are important, and I accept the fact that future-proofing is required. There is quite an important point: it is difficult for us to make definitions when we are not defining the purpose for which they are intended. It is important, therefore, that if law enforcement or other organisations need it, those definitions need to be laid down, which then helps us to comply. I come back to your previous point. I have already pointed out that inevitably there is more work to be done, which is why we are having a consultation process and evidence gathering to get it nailed into this process, but thereafter, the safeguards, oversight and the ability to consult, before we get to retention notices being issued, should be in place. That is something we welcome and, as I have already suggested, it could even be strengthened.

Chair: Thank you both for your time today. It has been very helpful and enlightening for us on what is a knotty technical question. I know there will be lots of scrutiny going on in this place on a number of other Committees as the Bill goes forward. If we have any further questions, I hope we can write to you before we report. Thank you very much.

 

Examination of Witnesses

Witnesses: Professor Bernard Silverman, Chief Scientific Adviser, Home Office, Richard Alcock, Programme Director of the Communication Capabilities Directorate, Home Office, and Dr Robert Nowill, Cyber Security Challenge UK Chairman and Herne Hill Consulting, gave evidence.

 

 

Q120   Chair: Welcome. It is a pleasure to have you here giving evidence at our second session on the Investigatory Powers Bill. Thank you for taking the time. I will dive right in. You may have heard some of the evidence from the previous panel, techUK and BT. We had some discussion about the issue of definitions in the Bill, which is causing some concern among industry and was raised in our first session. We have been discussing the balance between future-proofing the legislation and having definitions that are workable for those in industry. In closing, Mr Hughes made a very important point. He said that it is difficult for business to propose definitions if they are not defining the purpose for which the legislation is defined, yet we are hearing concerns that the definitions are too vague and are making it difficult for businesses to estimate cost and technical feasibility. Could I start with you, Mr Alcock? Do you have concerns that the definitions in the Bill are too vague? Do you think that more work needs to be done to tighten up the definitions?

Richard Alcock: Chapter 2 in part 9 of the Bill sets out the definitions of “communications data” and “content”. That is in response to the challenge that was set by David Anderson QC, who said that we ought to try to define those two things in particular. Telecommunications are by definition very complex, particularly in the internet age. Trying to produce definitions that are robust and will stand the test of time is quite hard, but we have been engaging very closely with industry over the past number of months—talking to them and to colleagues in other comms service providers—to establish the best form of words. We think that what we have addressed in the definitions of service providers, in terms of communications data and content, is quite clear. People may have their own interpretations, but what we are trying to do through the Bill is to set out clearly what is meant by communications data, what is meant by content, and the entities to which those obligations may well apply.

 

Q121   Chair: With the previous panel, we were wrestling with the question of exactly what the definition of equipment might be and whether, with the rise of the internet of things, it might apply to a nanny cam or an autonomous vehicle, whether that would be appropriate and whether it is the intention of the Bill. Perhaps you could help to clarify that, because witnesses to this Committee have not been sure.

Richard Alcock: One of the key aspects of the Bill is necessity and proportionality. In every case where an obligation was served on a particular organisation, it would be subject to very strict tests of necessity and proportionality. I cannot go into specific cases of how that might be applied, for security reasons, but the safeguards are increased significantly through the Bill. We now see judicial oversight for some of the most intrusive warrants that exist, new oversight by a new judicial investigatory powers commissioner and regular reviews of those arrangements.

 

Q122   Chair: Professor Silverman, we have just been discussing the issue of the technical advisory board. Some concerns were raised about the make-up of the board and exactly what its responsibilities would be. In particular, the comments were that there was a desire for the board to consider not just technical issues but also strategic issues, cost and, most of all, legal issues, given that almost everything arising from the Bill will have legal ramifications. What is your view on that?

Professor Silverman: It is obviously a good idea to have an independent advisory board to support legislation of any kind. There are lots of examples across government of boards that do that. Interestingly, of course, all I can talk about professionally is scientific advisory boards. I had not thought about this in detail, but it is a very good idea to have a board that covers things like legal issues as well. I gather that the current technical advisory board has not been consulted very often, which is not a sign that it is no good or not necessary; it may be a sign that the difficulties it is there to resolve have not arisen. In principle, the idea of a broadly based advisory board is important, but it is key that its terms of reference should be properly laid out. If you have a technical advisory board and it is going to mission-creep into legal issues, it is much better that it should have proper, formal legal terms of reference, rather than that it should be a scientific advisory board that then decides that it will have opinions about commercial and legal things.

 

Q123   Chair: If the technical advisory board has not been consulted very often regarding the technical aspects of the Bill, which is quite a technical Bill, have you, as the CSA in the Home Office, been consulted very often on this?

Professor Silverman: Yes. I should explain that we work together very closely. I am regularly at meetings where the progress of the Bill is talked about. I have therefore been aware from the very beginning of what was going on. My job is to make sure that the appropriate Departments of the Home Office have the appropriate scientific and technical capability. To be frank, they know much more about it than I do scientifically. I am very satisfied that Richard and his colleagues have the scientific and technical capability to deal with this. Furthermore, I was very impressed by the consultation exercises they went through. They talked to industry and suppliers and had round tables of experts. I cannot throw the ball to my neighbour on my left, but Robert Nowill was at one of those. I went to one the other day and was very impressed by the openness of discussion and the way in which the team was able to discuss at the highest technical level with the other people there. They were experts of all different opinions and were quite frank. I was very impressed by what was going on.

 

Q124   Chair: Dr Nowill, you were part of those debates and discussions. Some that we have heard imply that there are still some concerns and questions remaining. One, in particular, is how clause 190 will work out. That is the technical feasibility test. Do you have opinions on that?

Dr Nowill: Yes. To answer the first part of your question, the technical round tables went into a good level of detail on many of the thorny problems, including things like encryption and the ability to influence or obtain information from service providers who are overseas, in unfriendly countries. They did so not so much in an ethical sense but in a pure technology sense—can this be done? In terms of where we are on that clause and others around it, what do you want to explore?

 

Q125   Chair: What would be a technical feasibility test that would ensure that inappropriate intercept requests were not made?

Dr Nowill: It depends on what the example is or what the real-life case would be. We would have to have sufficient technology expertise in the room to be able to develop a case study or a use case to see whether it was going to work, in the most complex cases.

 

Q126   Graham Stringer: Professor Silverman, I listened carefully to your answers to the Chair. As the Home Office’s scientific adviser, what advice did you give in the consideration of this Bill?

Professor Silverman: Thank you, Mr Stringer. One thing that I did was to challenge quite hard on section 193(6). I think Richard will remember. I read that in detail and said—

Graham Stringer: You will have to remind me what that is.

Professor Silverman: It is the definition of the content of a communication. It is one of the tricky things. I said that with a communication it has to be explained in ways that I can understand how we will decide what are the communications data and what is the content, because that is one of the key issues that have been raised. We spent quite a long time with the team explaining. I am now content that that has been thought through. It is the difficulty of expressing science in legalese. I am now content that they have worked hard at doing something that is quite difficult to understand in plain English but satisfies both a legal and a scientific requirement to give us a proper definition that will work of the distinction between the who, when, what and how, which are the communications data, and the content—the text of an email or something like that. That is an example of the sort of detailed challenge that I gave.

 

Q127   Graham Stringer: Were there any other areas where you gave scientific advice? There is a second question, which may as well go at the same time. Did you give advice, as you mentioned to the Chair, about the structure of scientific advisory committees, how they should relate to one another and how quickly they should produce protocols?

Professor Silverman: No, I did not do that. Of course, as you know, I have done this for other committees, and we would do that. That is the sort of thing that would be worked out under codes of practice, but I would be very happy to do it.

 

Q128   Graham Stringer: Did you want to say something, Mr Alcock? You looked as though you were bursting to say something.

Richard Alcock: No. We have worked, and my team has been tested very thoroughly by Professor Silverman and by colleagues in industry and academia on the preparation of the Bill.

 

Q129   Graham Stringer: What communications data should law enforcement agencies have access to that they do not access already?

Richard Alcock: The Investigatory Powers Bill brings together a number of investigatory powers in response to three independent reviews—the review by David Anderson QC, the Intelligence and Security Committee review and the RUSI review. Right now, law enforcement can access communications data, where necessary and proportionate. For serious organised crime, interception can be granted by Ministers. The challenge with moving technology is that the kind of information required for some law enforcement investigations is not available, because it is not retained by certain communications service providers.

One new power that the Bill brings forward relates to what are called internet connection records. In simple terms, that means identifying the communications service that a person was using online at a particular point in time. Of course, what the Bill tries to do is to retain those data relating to individuals, but it also sets out clearly the terms under which the data can be accessed. Those three terms are as follows: one is to identify a person from a particular IP address—an internet protocol address; the second is to identify a person who may have been using an illegal website; the third is to identify what communications service an individual may have been using over time. Those internet connection records cannot be used for any other purpose.

Part of the Bill brings forward a new legal sanction whereby misuse of those retained data can result in imprisonment, so you have very strong safeguards. The intention is to create a new class of data—internet connection records—and to store those data, but to access them under those three strict terms. Law enforcement is satisfied, as are the agencies, that that will help them in their fight against crime. To give you one operational example, the Child Exploitation and Online Protection Centre, which is now part of the National Crime Agency, recently did an investigation into child sexual exploitation cases in relation to the exchange of indecent imagery. They say that 14% of those cases could only have been resolved had comms service providers retained internet connection records. That is exactly the kind of thing that we are trying to address by bringing forward the new power.

 

Q130   Graham Stringer: Do you think that all the gaps that the security services felt were there and that you have just outlined have been plugged?

Richard Alcock: What we try to do through the Bill is provide an array of different capabilities that give law enforcement and the agencies an array of different powers to meet the operational needs. There may be instances, in some cases, where the powers in the Bill will not be able to satisfy operational requirements, but we will continue to work with industry, which is really important, and with operational stakeholders to ensure that we have an array of capabilities. Again, those will be subject to strict oversight, safety and security controls.

 

Q131   Graham Stringer: To ask the Chair’s question again, following those questions, do you think that the Bill is future-proofed? Do you think that you will be back here in two or three years’ time saying that there are more gaps?

Richard Alcock: I would not anticipate revising the Bill in two or three years’ time. From the work that we have done and the work we have discussed with industry, academics, comms service providers and, importantly, the operational stakeholders, we feel that the powers that are made clear in one place, in this Bill, will meet the operational requirements for the foreseeable future.

 

Q132   Graham Stringer: Is the Bill having any impact on the current practices and capacities of the security and intelligence services?

Richard Alcock: In what context?

 

Q133   Graham Stringer: Just the fact that it exists. Is it changing practices?

Richard Alcock: There is an array of legal bases on which the agencies and law enforcement carry out certain operations. The only new power outlined in the Bill is that in relation to internet connection records. There is a strong legal basis for all the other powers that are contained in it. What we have tried to do in bringing forward the Bill is to bring everything together in a single place that is hopefully more easily understood, clearer and transparent for the public, so that they understand the totality of investigative capabilities that exist. We are increasing safeguards as part of this package, and rightly so. From working with operational stakeholders, we do not feel that those safeguards will have any operational impacts, if that makes sense, but the Bill will provide greater oversight.

 

Q134   Matt Warman: As Richard Alcock knows, we have been talking about this in the Joint Committee on the Bill. One thing that has come up there quite often is the issue of technical capability notices and what they might cover. Could you talk a little about what the technical capability notices in clause 189 might cover and whether it would include encryption?

Richard Alcock: In the context of communications data, we would define the kind of information or fair data fields that we would want a comms service provider to retain for a period of up to 12 months. The process by which we would do that is not as simple as engineers in the Home Office working up a list and then sending it to a supplier. We work very closely with the comms service providers, even before serving a notice, to understand the technical feasibility, practicality, costs and robustness of the arrangements, noting that in the context of communications data all the data that are retained and used, where necessary and proportionate, have to be built to an evidential standard. Once that was done, we would serve a written notice, signed by the Home Secretary, on those suppliers, defining the specific fields and data fields that we wished to collect. Those fields will be a function of the different industry suppliers, by virtue of the fact that all the back-office and technical systems are quite different, depending on which comms service provider you are talking to.

 

Q135   Matt Warman: At the Joint Committee, we heard Sir David Omand, for instance, say that he did not anticipate that notice including a request to decrypt stuff that is end-to-end encrypted. Is that your understanding as well?

Richard Alcock: In the context of interception, section 12 of RIPA mandates that there is an expectation that information is provided in the clear, effectively, by those on whom a notice is served. It may be the case that a service provider has certain encryption arrangements, but when you are putting someone on interception cover you want to be able to understand the content. There is an expectation—a clear mandation, in fact—that data will be provided to law enforcement in the clear, as has been the case. This Bill does exactly the same as section 12 of RIPA.

 

Q136   Carol Monaghan: The previous panel was quite clear that any compliance costs should be met by the Government, rather than the businesses. TechUK asked whether the figure of £174 million was a benchmark or a limit. First, can I ask how the compliance costs on businesses were estimated?

Richard Alcock: The costs outlined in the impact assessment associated with the Investigatory Powers Bill of £174 million, to which you refer, are the capital costs of implementing internet connection records. Right now, my team are working with industry to put in place data retention systems and associated infrastructure, under existing legislation. We work with industry and provide data retention stores, which hold comms data. Data are accessed when necessary and proportionate. By virtue of the work that we have done with industry, we have formed quite a good relationship with some of the suppliers. We understand their architectures and we have evidence of historical costs.

In terms of internet connection records, we worked over the summer with the service providers we are likely to place notices on. We shared information and projections over data volumes and estimates of historical costs for particular types of implementation, noting that those will vary over time, because comms service provider systems are constantly changing, either for technology’s sake or by virtue of mergers and acquisitions. We have had a number of bilateral and multilateral meetings with those providers to go through some of our assumptions.

To answer your question, we have done a lot of work with a number of different people. We have a body of knowledge and historical costs from the work that we are doing now. From that, we have put together an assessment of the likely costs of implementing internet connection records over a 10-year period, noting that we will probably phase things in waves. We would not be able to implement everything in one place, as there is only so much industrial capacity. We would phase it over time. To give you an example of some of the numbers that were cited at the Joint Committee, last year we spent in the order of £19 million, in terms of capital costs for data retention. The cost, divided over 10 years, is about £17 million additional per year, so effectively we are doubling the capital cost for retention to implement internet connection records, noting that we already have systems in place and that the £174 million does not include the costs of what we do at the moment.

 

Q137   Carol Monaghan: Does your latest assessment tally with this figure of £174 million?

Richard Alcock: Yes, for ICRs—internet connection records.

 

Q138   Carol Monaghan: Okay. Does the figure for compliance cost allow for the possibility that the Bill’s measures might be applied to all communications service providers?

Richard Alcock: We work with operational stakeholders to identify the comms service providers from which we are most likely to get operational benefit. There are in the order of 200 or 300 organisations that would class themselves as comms service providers in the United Kingdom. In relation to comms data, we will certainly not place obligations on every one of those providers. As I said, we will already have spoken to those that are likely to have notices placed on them.

 

Q139   Chair: We have had some questions raised about what the £174 million will be relevant for. You said capital cost. Does that include the capital cost of securing the data?

Richard Alcock: Yes. When we place a notice on a comms service provider, it will include security provisions; things will have to be built to a certain standard. There are separate costs in relation to annual oversight. The Information Commissioner, for example, has oversight. My team also conducts individual independent audits of systems on an annual basis, but those systems do not go live until such time as they have met the implementation standards, which we would define as part of the notices that we served on comms service providers.

 

Q140   Chair: What about any increased revenue costs, such as requiring higher skills in the companies so that you had the requisite security knowledge to retain such bulk data?

Richard Alcock: In the majority of cases, our data retention stores are completely separate from the business systems that exist within comms service providers. Effectively, they are subject to their own security arrangements. We have very high standards, as you would expect, for the security of the data that we require CSPs to keep.

 

Q141   Stella Creasy: It is quite interesting to hear you talk about this, versus what the companies are saying about it. One point that they made—I think that what you are saying backs it up—is that the question of cost in itself will be used as a metric for the proportionality of the request made. What happens if you disagree?

Richard Alcock: I do not necessarily—

 

Q142   Stella Creasy: What happens if the companies disagree about the assessment that you make of how much it should cost for them to retain data to meet the requirements that you are making?

Richard Alcock: We continue to work with the comms service providers. As I said, their systems are always changing. We have produced cost estimates. Those cost estimates may vary, depending on the different CSPs. We are working and continue to work with industry bodies to validate and test how those things would be implemented over time, but it is a best estimate.

 

Q143   Stella Creasy: I appreciate that, but, as you heard, the previous panel was quite clear; they would like to see all compliance costs in this legislation, to accommodate some of the points we are talking about. You are talking about a negotiation process.

Richard Alcock: No. I am saying that the Government meet reasonable costs.

 

Q144   Stella Creasy: As we all know, one person’s reasonableness is another person’s unreasonableness. What happens if there is a disagreement? Obviously you will be able to serve a notice. How does that accord with working with those companies?

Richard Alcock: I can go only on historical precedent. So far the Government have paid 100% of the costs relating to implementation.

 

Q145   Stella Creasy: Okay. That raises a number of questions for us on the technology of this. Are we committing to 100% of the costs? If not, what mechanism is there within the Bill to resolve disputes over what the costs should be?

Richard Alcock: The Bill makes it clear that we will place an obligation to pay reasonable costs and will meet those reasonable costs. The fall-back, if there is a disagreement, is to go through the technical advisory board, which will have considered the technical implementation. If it was not possible for a particular organisation to implement things for a certain cost, that would be addressed through the TAB.

 

Q146   Stella Creasy: What obligations are there on the technical board to resolve this? Obviously the large-scale collection of data will be a prize for many people to go for. If, for example, the cost of securing data to a standard is disputed, you are suggesting that this panel will—

Professor Silverman: The proposed membership of the board “includes persons likely…to represent the interests of the persons on whom obligations may be imposed” and “persons likely…to represent the interests of the persons…on whose behalf applications for warrants” are made. This goes back to the protocols that Mr Stringer mentioned would be a very good idea. The technical advisory board would have on it expertise in both directions. It would be a good idea, therefore, for the protocols to include what you would do in case of a dispute over some of these things.

 

Q147   Stella Creasy: But we cannot rule out the possibility that companies could be served with a notice, having disputed the costs and having been unable to resolve that dispute within the panel. Presumably, there could be prosecution consequences for those companies if the issues cannot be resolved.

Richard Alcock: I am very confident that we would be able to resolve the issues. There is an absolute commitment from Ministers that we would make reasonable costs. We genuinely have a very good relationship with all the UK service providers in particular.

 

Q148   Stella Creasy: There is a flipside of that. If there is a general assumption that the Government will meet 100% of the costs, how robust do you think the £174 million calculation is? Given that you have always met the costs, because we have never wanted to go down the route of litigation or prosecution, what accountability will there be to us in Parliament, for example, for those costs?

Richard Alcock: We are working with operational stakeholders to understand where we would accrue most operational benefit from the retention of particular data types. Through that work, we have come to our best assessment of the organisations on which we would be likely to serve notices. We have worked with those organisations to establish best estimates, noting all the examples that previous witnesses have given, but we continue to work with industry to validate some of the assumptions, noting that we will need to do some detailed engineering work really to hone down some of the figures. I would expect us to go through a process, possibly, of looking at providers again and prioritising some over others.

 

Q149   Stella Creasy: That is my final question for you. You said that you probably would not place obligations on all comms providers. Clearly you have good relationships with some, which might mitigate issues through the panel, were there to be a dispute. Does that rather create the presumption that there might be companies you would not deal with, if they were sticking on the costs? Might that create a loophole of providers who might be more amenable to be used by people we might not want to use them? If cost is going to be one of the questions about proportionality, does that create a gap in the system?

Richard Alcock: I would not associate costs with proportionality. There are two things: necessity and proportionality.

 

Q150   Stella Creasy: That is what you said previously about understanding and using costs as a way of determining proportionality.

Richard Alcock: It is about understanding where best to make capital investments to meet the operational requirements. I should have said that it is about understanding how best to balance the investment. That is the best way of phrasing it.

 

Q151   Stella Creasy: So it makes more sense for you to negotiate with the bigger companies, say, and therefore—

Richard Alcock: Primarily, work will be guided by operational stakeholders. If we know, for example, that there is a particular organisation where we really need to get access to the data, we will work with that company. We will resolve technical issues and we will resolve the cost issues to meet the operational requirements.

 

Q152   Stella Creasy: Both of you will have big sticks. The companies can hold out, and the Government can threaten to serve a notice.

Richard Alcock: For a number of years, we have managed to maintain very productive, very constructive relationships with UK providers.

 

Q153   Stella Creasy: As long as someone picks up the bill.

Richard Alcock: We will make reasonable cost provision.

 

Q154   Victoria Borwick: We are back on electronic protection. There is reference in the Bill to the “removal of electronic protection.” Do you think that is a route to compromising encryption?

Professor Silverman: Scientifically, no. Encryption is very important. Without encryption, of course, you could not do electronic banking, order things online and do all sorts of really important legitimate internet activity. My understanding of the Bill is that what has to be removed is the electronic protection that the service provider itself has put on the message. It is not removing encryption; it is removing electronic protection. I do not know whether Richard wants to go into more detail on that, but the short answer is that there is no threat to encryption as such.

Richard Alcock: It goes back to my previous point about provision of data in the clear. Companies may have all manner of different encryption equipment, which Government support. At the same time, when a notice is served to provide intercept data, the expectation is that those data will be provided in intelligible form—in the clear.

 

Q155   Victoria Borwick: Dr Nowill, do you want to add to that?

Dr Nowill: It may not always be possible, which I think is your point.

Victoria Borwick: Yes.

Dr Nowill: The ISP or CSP could unwrap whatever they have put on, but if the underlying data stream is encrypted by something proprietary and unknown and is originating and terminating overseas, you would probably have the devil of a job digging into it.

 

Q156   Victoria Borwick: Do you think that there is any way that the Bill could provide a means of balancing and reconciling those points? Obviously there will be competing demands for gaining access to encrypted communications, which we have talked about, and protecting such communications. As you say, people do not want their bank details to be hacked into. Do you think that there will be some in-built review mechanism? How would you envisage taking this forward and checking on it six months later, to see that it is working as people want it to work?

Dr Nowill: It is hard to generalise. It would be a case-by-case thing. It depends on what the underlying data are, what the operational requirement is and what the encryption is. It is difficult to say, “Yes, we would just do this,” because the “this” would not be constant.

 

Q157   Victoria Borwick: Inevitably, the skills involved are constantly ongoing, improving and developing. As you say, it is not quite a fixed position. Does anybody else have any views on maintaining that?

Richard Alcock: I go back to the point that I keep making. It is about forging constructive working relationships with the comms service providers. All comms service providers are different. All systems are different. We need to work out pragmatic ways in which we can satisfy requests from the UK Government.

 

Q158   Chair: The argument that we have been hearing and the questions that have been coming to us arise from clause 189(4) (c), putting an obligation on CSPs “relating to the removal of electronic protection,” the question being whether companies would be forced to replace products because some have end-to-end encryption at CSP level but others have it at user level. This is related to the point that Dr Nowill was making about whether there was third-party encryption. The question is whether companies would be required to change their entire business model in response to the Bill, in terms of encryption. That is quite an important point to clarify.

Richard Alcock: Going back to what I said, the expectation is that, when served with a notice, providers would provide us with data in the clear. That would involve working with the particular provider of the day to work out how best that could be achieved.

 

Q159   Chair: You are looking frowny, Professor Silverman.

Professor Silverman: No.

 

Q160   Chair: Would you like to add to that?

Professor Silverman: No. I have nothing to add to that.

 

Q161   Dr Mathias: What role do you envisage for DPI—deep packet inspection—either currently or in future practices?

Richard Alcock: Deep packet inspection technology is used by comms service providers all the time right now for network monitoring and such things. One way in which internet connection records might be implemented off switch—not in an individual’s business systems—would be through the application of deep packet inspection technology to collect the communications data from the system. That is one way in which that could be done. DPI is used all the time by CSPs now. They are very familiar with the technology. The suppliers that we use in support of our work are very familiar with the technology. Again, it depends.

 

Q162   Dr Mathias: Does that technology blur the content/data line?

Richard Alcock: The key thing is that within the Bill we have clearly defined comms data and content—I hope. What we would seek to do through the implementation of any technical arrangements would ensure strict compliance with those definitions. The answer is no. We would absolutely ensure strict compliance with the definitions, as Parliament will, hopefully, agree.

 

Q163   Dr Mathias: You do not think that it is unnecessary snooping.

Richard Alcock: I do not recognise the term snooping. We have clear powers in the Bill. We are trying to implement those powers in a technically robust way, and we are confident that we can do that.

 

Q164   Dr Mathias: What do you mean when you say that you do not understand the term snooping?

Derek Thomas: He doesn’t recognise it.

Dr Mathias: You do not recognise it.

Richard Alcock: This is an Investigatory Powers Bill. I know that it has been characterised as a snooper’s charter by some, but it is an Investigatory Powers Bill.

 

Q165   Chair: He does not agree, Tania.

Professor Silverman: Snooping would be illegal, because I would take snooping to mean exactly the inappropriate looking at things. The offence that is introduced here is looking at things you are not allowed to look at. That is snooping. Inspecting something when a warrant hasn’t been signed by the Home Secretary, a judge and so on—

Richard Alcock: With strict safeguards.

Professor Silverman: Yes, with strict safeguards. I am going beyond my scientific remit, but snooping is banned by the Bill. Snooping will get you two years in prison.

Richard Alcock: It will.

 

Q166   Dr Mathias: Two years.

Professor Silverman: Whatever the offence is.

 

Q167   Graham Stringer: It is a definitional argument, isn’t it?

Professor Silverman: Yes, it is.

Stella Creasy: It is a bit like reasonableness. It is one thing in one man’s eye.

Chair: Professor, we are very happy for you to go beyond your remit at any moment you feel inclined to comment.

I would like to thank the panel. We are about to have a vote, so I will bring this evidence session to a close. Thank you for the evidence we have received. Some of the evidence from this panel is reassuring. Some of it is quite contradictory to evidence that we have received from other witnesses. I hope that we may be able to write to you for points of clarification going forward, but I thank you for the time that you have given us today. I wish you luck as the Bill proceeds through the House.

              Oral evidence: Investigatory Powers Bill: technology issues, HC 573                            21