Dr Paul Bernal, University of East Anglia Law School – written evidence (IRN0019)
 

 

Submission to the House of Lords Select Committee on Communications

in relation to the inquiry into regulation of the Internet

 

I am making this submission in my capacity as Senior Lecturer in Information Technology, Intellectual Property and Media Law at the UEA Law School. I research in internet law and specialise in internet regulation from both a theoretical and a practical perspective. My first book, Internet Privacy Rights – Rights to Protect Autonomy, was published by Cambridge University Press in 2014. My second book, The Internet, Warts and All: Free Speech, Privacy and Truth, which will be published by Cambridge University Press this summer, has the question of regulation of the Internet as one of its central themes. The subject of internet regulation therefore lies precisely within my academic field.

 

Brief summary of this submission

 

This submission notes that to a significant extent the internet is already regulated, and we need to be clear about that so as not to let people think that it is some kind of ‘Wild West’ overrun by rogues. It also suggests that though in some ways further internet regulation is necessary, those regulating need to be very wary of doing so. There are a number of significant risks attached, including:

 

(1)     Of overregulation, stultifying areas of expansion and benefit to the community and to business;

(2)     Of regulation missing its targets and having significant and damaging consequences in other areas;

(3)     Of creating misleading and unhelpful expectations in the eyes of the public, potentially reducing their ability to navigate the complex environment;

(4)     Of creating opportunities for regulatory arbitrage;

(5)     Of the regulators being subjected to significant lobbying; and

(6)     Of incurring significant and unnecessary expense.

 

This does not mean that regulation should not be considered – particularly, for example, on algorithmic accountability - but it needs to be taken very seriously and monitored very closely if a decision is made to regulate. Where regulation is not working or being counterproductive, it needs to be reversed. The possibility of that kind of reversal needs to be built into the regulatory system from the offset.

 

There has been more focus upon the role of online platforms and intermediaries in relation to their content (including hate speech, copyright infractions, obscenity and pornography, extremism etc) than on the delivery methods and the way that they often rely upon access to and use of personal information. That betrays a limited and somewhat old-fashioned understanding of the internet, considering it in terms of ‘publishers’ or ‘platforms’ – the question seemingly often asked being ‘should we consider them as publishers, with all the responsibilities in law that this implies’. That, this submission will suggest, misses the key point. That systems like Facebook host material is less important than the way that the material reaches its intended audience – through targeting based on profiles from personal information, either directly or automatically through Facebook’s tailored news feeds and so forth. The use of personal information is the key that unlocks the audiences, enables political manipulation by things like fake news and so forth. It is the underlying systems that underpin the problem: regulating the content without looking at this is to a great extent like rearranging the deck chairs on the Titanic.

 

1              The Internet is already regulated

 

1.1              It is important not just to understand but to make clear to others that the internet is already regulated by a wide range of laws, from those governing speech (such as S127 of the Communications Act 2003, the Malicious Communication Act 1988) and public order law to data protection, copyright and fraud, as well as civil law such as defamation law, misuse of private information and much more. It is a commonly held and unfortunate belief amongst some that the internet is a lawless ‘wild west’ where the law does not apply. It does, and some of that law works very well. Regulatory bodies such as the ICO and Ofcom have powers that function on the internet, there are quasi-regulators such as the Internet Watch Foundation and more.

 

1.2              What this means is that parliament should first be considering how well the existing regulation works before considering further regulation. Rationalising law where there are overlaps and confusion (for example over speech), strengthening laws and putting more resources into enforcement and so forth where it is needed – the ICO in particular is distinctly under-resourced for the critical tasks that it has to perform in the internet era.

 

1.3              It also means that emphasis should be placed in making sure that all of those involved in the process – and this starts with MPs, for example – have a better knowledge and understanding of the technology, of the environment, of the regulation and law that exists, and of the problems surrounding that regulation and law. The record in the recent past on this is not very good, from inappropriate prosecutions (such as the so-called ‘Twitter Joke Trial’, R. v Chambers) to laws that essentially fail (such as many parts of the Digital Economy Act 2010). Getting this right is critical before considering further regulation or legislation.

 

2              The risks of regulation

 

2.1              When considering regulation, the risks of that regulation have to be considered as well as the potential benefits. In relation to the internet, this is particularly pertinent, as the risks are multifaceted and often hard to quantify. Regulating intermediaries (including ‘platforms’ – though the term ‘platform’ is itself a loaded one, implying a lack of responsibility for the content) has many such risks, most directly that any restrictions on their actions could end up being restrictions on all their users – and to most intents and purposes that means all of us. We have grown to rely on these intermediaries for many aspects of our lives – if their actions and activities are restricted then so are ours.

2.2              Further to this, one of the biggest risks is that regulatory action will fail to find its targets but instead hit ‘innocents’. A highly skilled malicious actor will be able to avoid or sidestep regulatory action, but the regulation might catch innocent and positive people instead. Sex education websites can be blocked by porn-blocking systems whilst those distributing child-abuse images bypass the systems by using the dark web, for example.

 

2.3              Regulation can also create false and damaging expectations. If a parent is told that the new law will make sure there is no damaging material on the internet they may be less likely to pay proper attention to what their child is doing on the internet, for example. As I discuss in depth in my new book, The Internet, Warts and All, the internet is a messy and sometimes confusing place, and will always be so, which makes it vitally important that the emphasis is placed first and foremost on education and understanding. Our children need to become ‘savvy’ and encouraged to be sensible, rather than our suggesting that we can make the environment fundamentally safe. Similarly, consumers of news on the internet need to become savvy at understanding what they are seeing, if we are to address the issues surrounding ‘fake news’ (see section 4 below).

 

2.4              Regulation can also create opportunities for ‘arbitrage’ – playing one regulator against another, choosing which jurisdiction to base an operation in based on the local regulations. This can result in a kind of ‘race to the bottom’ – one of the risks associated with Brexit (see section 8 below). It can also mean a loss of business opportunities where regulation is excessive or inappropriate.

 

2.5              Regulators and lawmakers can also be pressurised, whether directly or indirectly, by powerful lobbies. As the committee is aware, the dominance of a small number of online platforms is one of the characteristics of the internet in its current form: this also means that the small number of very powerful companies that own these platforms have a very significant lobbying power, one that they often wield with great expertise and effect. That can mean that regulations fail to achieve what they need to achieve because the lobbyists manage to persuade those drafting the regulation into shaping it into a form that suits those companies. The massive lobbying budgets of Facebook, Google and others exist for a reason: part of that reason is to try to shape any regulations that are put into place.

 

3              Online ‘platforms’ and their responsibilities

 

3.1              Online platforms are already to an extent responsible for the material they host. Many kinds of material have to be removed under a range of laws. Google’s transparency report includes take-downs on the basis of copyright, on the basis of government requests, and on the basis of ‘right to be forgotten’ claims under data protection law following the ‘Google Spain’ case. ISPs use the Internet Watch Foundation to block access to child abuse imagery. The idea, therefore, that intermediaries (including ‘platforms’) can be held responsible for content has been established and accepted, albeit in relatively limited circumstances.

 

3.2              How this might be taken further is another matter. It is important to understand that it is a very slippery slope, and that there could easily be a chilling effect on freedom of speech if it is taken too far. A platform may be cautious about hosting, reducing the opportunities for people to find places to host their material if it is in any way controversial. Again, issues like sex education, minority rights, politically contentious material such as that relating to dissidents or people who do not fit with a particular orthodoxy should come into play here. The result is therefore that power balances are exacerbated – the already powerful and orthodox find their platforms easily, those without power find it very hard. As one of the primary functions of freedom of speech is to allow the relatively weak to face up to the powerful, this is of great significance. It means that extending responsibility to the platforms into more areas should be done with great caution.

 

4              Fake News and other misinformation

 

4.1              A particular area of importance in relation to the online platforms is their role in relation to fake news. It is important at the outset to understand that there has always been fake news – and there always will be. Examples can be found from almost every period of history, from the false stories spread about Oliver Cromwell by his Royalist adversaries and the subversive rumours spread about Cardinal Mazarin in 17th century France to the broadcasts of Lord Haw-Haw and the press conferences of Iraqi Information Minister Muhammad Saeed al-Sahhaf, known as ‘Comical Ali’. It is not possible to stop people from creating stories about their political enemies – and these days it is particularly easy to do so.  Websites, and Facebook pages in particular, can be created in minutes.

 

4.2              The existing mass of media, and the narratives created by it, provides a fertile ground and much ammunition with which to craft the false but convincing stories that constitute much fake news. It is important to understand that the ‘new’ form of fake news works with rather than against the traditional media. A headline story in the Daily Mail, whether true or not, might be used as the basis of another, wholly false story. It is important also to understand that the ‘news’ presented by the traditional media can easily be as ‘fake’ as that found on the internet – or it may be used to create a narrative that is essentially fake, even if the particular facts used are actually true, though taken out of context or misinterpreted.

 

4.3              This means that taking measures against ‘fake news’ whilst not addressing the fake narratives that are already in circulation is doomed to failure. More fake news can be created very fast, and posted up as soon as it is created, ready to be spread around the internet in a matter of moments. Dealing with just the content is little more than a doomed game of ‘whack-a-mole’.

 

4.4              Fact checking and labelling fake news does not help. The empirical evidence shows labelling something as fake can actually make it more likely to be read and more likely to be believed. This may be to do with just the highlighting, or to do with a label being seen as a ‘badge of honour’ that the piece is not trusted by the ‘mainstream’ or the ‘elite’. This means that any measures to require platforms to fact-check and label fake news are likely to be not just ineffective but actively counterproductive.

 

4.5              The underlying problems with fake news are not the content but the mechanisms of distribution. The way that Facebook ‘tailors’ its news feed to your ‘interests’ means that fake news in your interest area will be actively pushed to you. If you have shown, for example, a particular interest in what you see as problems with immigration, stories about immigrants committing crimes or being given massive amounts of benefits will be algorithmically selected to be suitable for you – whether they are true or not. Fake news creators know this and can craft their stories to work in this way.

 

4.6              This in turn relies on the profiles built up on users based on their personal data: if they cannot profile people as precisely, the fake news cannot be targeted as accurately. This has big implications in relation to political manipulation to: the Cambridge Analytica saga, so far as we can determine started with big data analysis of people’s personal data to derive political opinions and finished by using that data to target individuals with both fake news and other content.

 

5              Online behaviour and safety – dealing with trolls

 

5.1              There is a qualitative difference between dealing with content and dealing with behaviour: targeted aggression, bullying and so forth are not so much about the specific content as they are with how that content is used, how people interact with each other and so forth. That means that regulation of it is also qualitatively different. As noted above, there is already a considerable body of law (both statute and case law) governing this kind of behaviour: what is needed most is an improvement in understanding and implementation of that law.

 

5.2              The social media companies are also already putting a considerable effort into dealing with these kinds of problems on their platforms. It is neither fair nor true to suggest, as is often done in the media, that they are not really trying. They are, and it should not be surprising that they are, as the success of their platforms relies on their not being hostile environments for their users. That they do not always succeed is mostly a reflection on how difficult a task it is, not on their failure to try. Part of the problem is that it is easy for arguments to become heated, and also easy for people not to understand how their actions appear to others: many ‘trolls’ have no idea that they are ‘trolling’.

 

5.3              There are two particular findings from research that should be noted in this area. The first is that the superficially attractive idea of enforcing ‘real names’ on the internet (and on social media in particular) is not just unlikely to succeed but could even be counterproductive, as well as having devastating effects on certain vulnerable people. A key empirical study showed that when forced to use real names, trolls can become even more likely to be aggressive in their language and actions – whether from bravado or to make a point, or some other reason. In addition, forcing real names puts many people at risk, from those with abusive spouses to whistle-blowers, from those with names that indicate their ethnic, religious or other background – or simply to women and girls operating in oppressively male environments, of which there are many on the internet. It is no coincidence that one of the methods of the most aggressive trolls is ‘doxxing’ – finding and releasing personal information about their victims to scare them or even cause them harm. ‘Real names’ policies help doxxing.

 

5.4              The second, which fits with this latter point is that tools created to ‘deal with’ trolls – whether they be software tools such as ‘report abuse’ buttons or legal tools as mentioned above – can end up being used by trolls against their victims. A troll will report their victim as a troll, in the hope of getting them banned from a platform or worse. This means that providing more such tools needs to be done with a great deal of care, or it may simply make the trolling situation worse.

 

6              Personal data, privacy, and its critical role

 

6.1              As noted above, the gathering and use of personal information underpins many of the worst problems on the internet at present. Privacy invasion and profiling lies behind the fake news phenomenon and the broader issue of political manipulation (as graphically illustrated by the Cambridge Analytica saga), as well as providing tools for scammers and other criminals, creating vulnerabilities that can be exploited and much more. It is critical that privacy is not downplayed or seen as playing second fiddle to issues such as security and freedom of speech. It matters as much in its own right and also supports those rights and issues. Without privacy it is very hard to have security, and without privacy it is hard to have real freedom of speech. A lack of privacy causes a chill in free speech – not just theoretically but in practice, as has been demonstrated through a series of empirical studies.

 

6.2              Privacy and personal data is also an area where extensive law already exists. Data protection law, and in particular the new General Data Protection Regulation, has the potential to provide a good deal of support for individual privacy – but only if it is enforced with sufficient rigour and support. The Information Commissioner’s Office (‘ICO’) needs to be given more resources both in terms of finance and expertise, and perhaps more responsibilities. If the ideas of algorithmic accountability and algorithmic audit (see section 8 below) are to be both useful and appropriately independent, the ICO is likely to be the best body to oversee them. This, together with the growing responsibilities in relation to data protection, means that they will need much more support.

 

6.3              Asking what information online platforms should provide to users about the use of their personal data is only part of the question that should be asked. What is more important is what they actually do with that data: people will generally simply scroll through whatever information is provided and click ‘OK’ at the end. Regulation of the use of personal data based on information and ‘consent’ is not sufficient: it is more important to set clear and strong rules about what is and is not allowed. It is also important to understand that it is not just how the information is used directly, but what can be derived from it, and the profiling and targeting practices of the platforms that need to be addressed.

 

7              The dominance of a small number of platforms.

 

7.1              The domination of the online world by a few platforms owned by even fewer corporations (Instagram and WhatsApp owned by Facebook, YouTube owned by Google, for example) has many implications. It means that their methods have a massive impact on the online world – and that they have immense power, some of it wielded through their market domination, crowding others out, some wielded algorithmically as they control what we see, read and hear. What appears on your Facebook news feed, or at the top of your Google search results or in predictive text as you search, has a massive influence over the information that you see and consume. It is critical to understand that the algorithms that determine these are not in any real sense neutral, objective or ‘organic’, and neither are they purely ‘crowdsourced’. They are the result of design and decisions by people employed by the companies.

 

7.2              Part of the reason for this dominance is the effectiveness of the services – but part of the effectiveness is caused by the dominance. The number of users and the amount of data gathered by and through those users makes the profiling and other big data analyses more effective. It makes the search results better and so forth. The more data the companies have, the more they can derive – and the more effectively they can use it. Sometimes this is very positive – but it also opens dangerous possibilities. The more ‘base’ data on a population that is available, the less specific data on a particular individual is needed to profile them. This, again, is fundamental to understanding how the kind of targeting used by the likes of Cambridge Analytica works. It is also important to understand that this also means that deeply sensitive data – from data about health to sexuality and political views – can now be derived from the most mundane information about shopping habits, tastes in music and so forth. That in turn means that providing protection only for the directly sensitive data will not protect individuals in practice.

 

7.3              The size and strength of the companies behind the platforms, as noted in 2.5 above, gives them massive lobbying power. Lawmakers and regulators need to be able to resist this power – and in particular resist the temptation to give these companies special access, private hearings and so forth.

 

8              Algorithmic transparency, accountability and audit

 

8.1              Perhaps the most important area where further regulation needs to be considered concerns algorithms. The power of the algorithms of the internet giants – search engines like Google and social networks like Facebook in particular – has already been noted above. That these algorithms are treated effectively as trade secrets, ‘black boxes’ that we cannot see into, should be seen as increasingly untenable. If they have so much influence on our lives means that the companies that control them should be accountable for them – much more so than they should be held accountable for the content hosted on them. It is the algorithms that lie behind the effectiveness of the products and underpin the business models of the companies.

 

8.2              Being accountable for the algorithms includes more transparency as to how the algorithms are used – not the technical details, but the things that they are used for. People need to be made properly aware, for example, that algorithms curate their news, and the overall aims of that curation – and not in terms like ‘we tailor news to better match your expectations’ but more realistic assessments acknowledging how profiling is done and so forth. Transparency, however, is not enough. It will very easily become little more than the ‘scroll down, don’t read, then click OK’ procedure that is supposed to constitute consent. What needs to be considered is ‘algorithmic audit’, where algorithms are regularly tested by an independent auditor – not analysed for their technical content, which should rightly remain effectively a trade secret – but for the results that they produce.

 

8.3              How that independent audit would function would need a lot of thought and expertise. Which algorithmic systems need to be audited, and when. Who would be qualified to perform these audits, and how would the results be communicated. This in turn requires a regulator with the power and resources necessary to make it work. The ICO is the most obvious body to oversee such a function, but it would need considerably more resources than it currently has, reporting responsibilities to parliament on this, and power to enforce both the requirement to algorithmic audit and the results of the audit itself. The role of algorithms is only going to grow and become more complex – particularly with the growth of ‘machine learning’ and ‘artificial intelligence’ (and the grey areas between them). This makes addressing this issue of critical importance. As noted above, it has more impact on many of the areas for which regulation is being considered than regulating the hosted content itself. Moreover, there is no existing regulation in the area, unlike such things as extremism, hate speech, obscenity and copyright infringement.

 

9              Brexit and related problems

 

9.1              The primary impact of Brexit on internet regulation is negative – it creates gaps in regulation that could be exploited, could provide opportunities for regulatory arbitrage and could reduce the ability for regulators to take on the giants of the internet. The European Union has much more strength to resist the lobbying of the internet giants, and much more capacity to punish them through law. The new fining capabilities in the GDPR are the most recent example but there is an effective track record through competition law, including a €2.4 billion fine to Google in 2017 over the Google Shopping case. That sort of strength is unlikely to be possible for UK regulators outside the EU.

 

9.2              The best that can be done to limit this is to ensure that the UK aligns itself as closely as possible with the EU in regulatory terms. Lawmakers should resist the temptation to differentiate the UK from the EU, particularly in terms of data protection and electronic commerce, even if it perceives weaknesses in EU regulations – any marginal advantages are likely to be miniscule in comparison with the advantages of regulatory harmony and shared lobbying power, as well as potentially driving a ‘race to the bottom’ in terms of regulation of the big internet companies. This also means that the UK should be willing to adjust its surveillance practices and law to make GDPR adequacy more likely. Access to the digital single market is another aspect of this – again, if Brexit means that the UK loses these advantages it could have a seriously detrimental impact in both economic and regulatory terms.

 

10              Conclusions

 

The most important thing to understand is that bringing any further regulation into the internet should be considered very carefully. Regulation could very well be counterproductive, have serious side effects and have an impact on privacy, freedom of expression and a wide range of other human rights whilst failing to deal with the real problems. We use the internet for so many different parts of our life that anything done to regulate it – to restrict it in particular – can have an impact on all those things. For this reason, the default position, particularly insofar as regulation of content is concerned, should be not to regulate rather than to regulate. Freedom of speech should be the starting point. Moreover, the regulation of content on its own may be a fruitless task: in most cases similar content will reappear and be spread throughout the net. The negative side effects may well be the only real effects.

 

The two areas where this is not true, are the protection of privacy and the regulation of algorithms. Privacy underpins many of the issues that should be of concern – including fake news, trolling, the excesses of power of the internet giants, the potential for the undermining of democracy as demonstrated by Cambridge Analytica and more. There is already good law in this area – data protection law – which should be supported and more strongly enforced. More resources for the ICO, and encouragement to the ICO to use its enforcement powers, would be very much a positive. The regulation of algorithms is something that needs to be addressed and addressed soon. The power of algorithms and their influence in many different areas of our lives is growing all the time: the discussion about how to deal with them needs to begin now.

 

There has been a lot of academic research into a number of these areas, and the evidence from it may sometimes seem counterintuitive – the idea that ‘real names’ policies are likely to make trolling worse rather than better, for example. This make it important that lawmakers and regulators engage with the research community, including both academics and NGOs. Being willing to take in even the more counterintuitive research results will mean that regulation, should it be deemed necessary, should be more effective, with fewer bad side effects and less likelihood to need reassessing and reversing in the future.

 

I hope this submission is of use to the committee, and I would be happy to provide more detailed information, either written or oral, should the committee wish. This could include links to the relevant pieces of empirical and other academic work referred to, and subject to permission from my publisher to drafts of the relevant chapters of my forthcoming book that cover some of these areas – fake news and trolling in particular – in some detail.

 

 

10 May 2018

              Page 9