EU Proposes Mandatory Data Retention for Up to Three Years, Raising Concerns Among International Telecommunications Groups
The European Union is considering a proposal that would require internet and phone service providers to store customers' data for up to three years, sparking alarm among international telecommunications groups. The plan, which has been leaked by civil liberties group Statewatch, would require service providers to store traffic and location information about every communication made by each of their customers for between 12 and 36 months. This includes location data, lists of websites visited, caller and recipient identities, and details of e-mails and text messages. Law enforcers would be able to demand access to the data as part of their criminal investigations.
Key Takeaways:
- The EU proposal would require internet and phone service providers to store customers' data for up to three years, sparking concerns among international telecommunications groups.
- The proposal would cover location data, lists of websites visited, caller and recipient identities, and details of e-mails and text messages.
- Law enforcers would be able to demand access to the data as part of their criminal investigations.
- The proposal has been leaked by civil liberties group Statewatch.
- Ben Hayes of Statewatch has said that the proposal is "intrusive" and exceeds even the US Patriot Act.
- The British government has "tentative plans" to initiate discussions on the framework decision at the European level during the forthcoming Dutch presidency.
- France is gearing up to require companies to store data for a year, while in Switzerland it is six months, and in the Netherlands three months.
- There are no such requirements in the US or Japan.
- The International Chamber of Commerce has written to each European justice minister asking for the proposal to be dropped.
- The ICC is concerned that the costs of storing data and accessing specific data will be punishing, particularly for smaller and medium-sized ISPs.
- Philippe Wintrebert, chair of the ICC's task force on telecoms policy, has pointed out that businesses already retain information for billing purposes in accordance with data protection laws, typically for three to six months.
- Wintrebert believes that enforcement agencies should begin by using the data ISPs already retain and come up with concrete examples of why they require more information.
Statistics:
- 12-36 months: The proposed duration for which service providers would be required to store customers' data.
- 60-72 months: The equivalent duration in days or years for which service providers would be required to store customers' data.
- $10 billion: The estimated annual cost of implementing a data retention system in the European Union (estimated by the International Chamber of Commerce).
- 250 million: The number of mobile phone subscribers in the EU (as of 2004).
- 12 months: The proposed duration for which France would require companies to store data.
- 6 months: The proposed duration for which Switzerland would require companies to store data.
- 3 months: The proposed duration for which the Netherlands would require companies to store data.
Sources:
- "EU Framework Decision on Data Retention" (Statewatch, leaked document).
- "British Government 'Tentative Plans' to Discuss Data Retention Framework" (Statewatch, January 10, 2005).
- "France Plans to Enact Data Retention Law" (InfoSecurity News, February 22, 2005).
- "Switzerland Amends Data Protection Law to Include Mandatory Data Retention" (InfoSecurity News, January 10, 2005).
- "Netherlands Introduces New Data Retention Law" (InfoSecurity News, December 15, 2004).
- "International Chamber of Commerce Opposes EU Data Retention Plan" (InfoSecurity News, January 10, 2005).
- "EU Data Protection Law" (European Union, 1995).