(8 years, 2 months ago)
Lords ChamberMy Lords, Amendments 180, 181, 197, 198, 205, 206, 231 and 232 relate to judicial commissioner approval of major modifications to warrants issued under Parts 6 and 7 of the Bill. They seek to provide additional clarity regarding the matters the commissioner must review when deciding whether to approve such a modification.
The Bill already provides for major modifications to such warrants. In the context of bulk interception, bulk acquisition and bulk personal dataset warrants, a major modification may be used to add or vary one of the operational purposes for which data may be examined under the warrant. As regards bulk equipment interference warrants, a major modification can additionally add to or vary any description of conduct in the warrant.
The Bill requires full double-lock authorisation from a Secretary of State and a judicial commissioner for any major modification to a bulk warrant. These amendments will not change that. Instead, they provide greater clarity about the matters that a commissioner must consider when determining whether to approve a modification to a bulk warrant.
The amendments specify that, for major modifications to add or vary an “operational purpose”, a judicial commissioner must review the Secretary of State’s conclusions as to whether the modification is necessary, applying the same principles as would be applied by a court on an application for judicial review and ensuring that the commissioner complies with the duties in relation to privacy set out in Clause 2, the so-called privacy clause.
In the context of bulk equipment interference, if a major modification proposes to add or vary a description of conduct, the judicial commissioner must also review the Secretary of State’s conclusions as to whether the conduct authorised by the modification is proportionate to what is sought to be achieved by it. The amendments are intended to ensure clarity and consistency across the Bill, and as such are to be welcomed.
The sharing of data and intelligence with our overseas partners is critical to the work of our security and intelligence agencies. Without working together with our allies, those agencies could not do their vital work of keeping us safe. Amendments 184, 185, 201, 202, 209 and 210 simply clarify the consideration that must be given by the Secretary of State before authorising the disclosure to overseas authorities of data acquired under the bulk powers in the Bill.
The Bill already places a duty on the Secretary of State to consider whether corresponding safeguards will be applied to the data that are to be shared with the overseas authority in relation to their retention and disclosure. These amendments make explicit that the Secretary of State must be satisfied that the overseas authority has in place safeguards, to the extent appropriate, that correspond to those in the Bill not only in respect of the retention and disclosure of the data shared in bulk but in relation to their selection for examination. This group of amendments therefore makes absolutely clear that proper consideration will be given to the examination safeguards that are applied whenever bulk data are shared with another country. I beg to move.
My Lords, I thank the Minister for moving these amendments, all of which we are happy to support and some of which respond to concerns we raised in Committee.
It may assist the House if I outline at this stage the purpose of Amendment 185A, in the names of my noble friend Lord Rosser and myself, which is about safeguards for disclosing overseas-related material for our foreign allies and agencies. That is material, possibly including information sent overseas by UK residents, obtained by our security and intelligence services under bulk interception warrants. It is an amendment which we hope the Government will feel able to accept.
In Clause 142, before any information obtained under a bulk interception warrant is disclosed overseas, the Secretary of State must ensure that arrangements and safeguards are in place regarding the retention and disclosure of such material, as the Minister has outlined. These requirements correspond to Clause 141 safeguards for domestic arrangements: that is, requiring that the number of people to whom the bulk-intercepted material is disclosed, the extent of disclosure and the number of copies made is limited to the minimum necessary. These safeguards also require the destruction of such material where there are no longer grounds for retaining it.
However, unlike Clause 141 for domestic arrangements, Clause 142 for overseas disclosure provides a wide discretion for the Secretary of State, whereby she or he must ensure equivalent safeguards only,
“to such extent (if any) as the Secretary of State considers appropriate”.
It could, therefore, be possible for the Secretary of State to decide that no safeguards are required in a particular case.
We recognise absolutely that the UK will need to share intelligence with overseas agencies and our amendment does not undermine the ability of UK agencies to do that. We also accept that overseas disclosure may be of a different nature, with particular political, diplomatic or security implications, all of which the Secretary of State must consider. However, the present wording is surely too wide and, if I have understood it correctly, would not be subject to subsequent review. Amendment 185A removes this very broad discretion and requires that it must appear to the Secretary of State that safeguards corresponding to the requirements under Clause 141(2) and (5) will apply in relation to disclosure overseas.
The Minister will not be surprised if I make reference to the Szabó v Hungary finding that minimum standards should be set out in law to avoid abuses of power and that,
“it would be contrary to the rule of law … for a discretion granted to the executive in the sphere of national security to be expressed in terms of unfettered power”.
The judgment notes that,
“the law must indicate the scope of any such discretion … with sufficient clarity … to give … adequate protection against arbitrary interference”.
I hope that the Government will feel able to accept the amendment as, if anything, extra safeguards may, indeed, be required where sensitive information is being disclosed abroad. We look forward to the Minister’s response on this.
My Lords, we, too, are happy with the government amendments in this group and we support Amendment 185A. The issue is about the discretion in the application of Clauses 141(2) and 141(5)—and, shortly, Clause 143—not their relevance. The term “appropriate” suggests to me a degree of discretion which may not be related to relevance. The term “mutatis mutandis” is not one commonly used in legislation, I think, but it is that provision that one wants to see—only changing what is necessary to be changed. I do not know the proper way of dealing with that, but “appropriate” seems to be inappropriate in the context.
My Lords, as the noble Baroness, Lady Hayter, has observed, Amendment 185A would remove the Secretary of State’s discretion to consider the extent to which the application of corresponding safeguards is appropriate in relation to the sharing with an overseas authority. The Government consider that this is a vital provision and its removal from the Bill would pose a real risk to the national security of this country and other countries around the world. The threat we face from terrorism and serious and organised crime is global. It is inevitable that there will be circumstances where our security and intelligence agencies uncover threats to other countries through intelligence derived from a bulk interception warrant.
In some circumstances, such threats will be against countries with which the United Kingdom has well-established intelligence-sharing relationships, and in such circumstances there are likely to be corresponding safeguards applying to the handling of intercepted material. However, there will be occasions when such intelligence indicates a serious threat to a country overseas, potentially in urgent circumstances, whose authorities simply do not apply the same level of safeguards as those included in the Bill. In such circumstances, it is crucial that the Bill places a duty on the Secretary of State to consider the arrangements that should be in place to regulate the disclosure. This decision will need to balance the risk that the material will not be subject to the same level of safeguards that it would be in this country against the risks to the security of the country in question if material is not shared.
For example, in some circumstances a failure to share intercepted material containing vital intelligence could result in a terrorist atrocity. Even in such a scenario, the amendment would place an absolute prohibition on the relevant intercepted material being shared because the overseas authority does not apply safeguards corresponding to those in the Bill. This would not be a responsible position and I believe it is only right that the Secretary of State must be responsible for deciding the appropriate arrangements for sharing intercepted material with an overseas authority, considering the particular circumstances of each case. In addition to this consideration by the Secretary of State, the safeguards that apply to the use of bulk interception will be subject to rigorous, independent oversight and scrutiny by the Investigatory Powers Commissioner. This will, of course, include the arrangements for the disclosure of intercepted material overseas.
For the reasons I have outlined, it is absolutely crucial that the Bill provides for the Secretary of State to consider the extent to which corresponding safeguards should apply where intercepted material is being shared overseas. The amendment would fetter that consideration and is both unnecessary and potentially dangerous. Accordingly, I invite the noble Baroness not to move it.
My Lords, Amendment 196A is in my name and that of my noble friend Lady Hamwee. It seeks to remove internet connection records from the type of communications data that can be acquired in bulk. Noble Lords will be very well aware of my views, and the agreed view of the Liberal Democrats, on internet connection records. We believe that they are unnecessary and disproportionate, for the reasons that I have articulated in detail throughout the passage of the Bill.
I shall just remind your Lordships what internet connection records mean. Internet service providers are being forced to keep a record of every website that everyone in the UK has visited in the last 12 months, whether the subscriber is suspected of crime or not. Even though only the first page of each website visited is shown, visiting www.relate.org.uk could, for example, immediately indicate that your marriage was in trouble. However there are some safeguards, including some concessions extracted by the Labour Opposition, to ensure that only the internet connection records of those suspected of crimes that could result on conviction in a sentence of 12 months’ imprisonment or more can be examined by law enforcement agencies.
We are also grateful to the Labour Opposition for securing the review of bulk powers carried out by David Anderson QC, the Independent Reviewer of Terrorism Legislation. We are particularly grateful to David Anderson for highlighting in paragraph 2.41(b), on page 33 of his report on bulk powers, that,
“it is not currently envisaged that the bulk acquisition power in the Bill will be used to obtain internet connection records”.
However, in a footnote at the bottom of that page, Mr Anderson states that he has been told,
“that this is no more than a statement of present practice and intention: neither the Bill nor the draft Code of Practice rules out the future use of the bulk acquisition power in relation to ICRs”.
In Committee, the noble and learned Lord, Lord Keen, said:
“I can confirm to the Committee that the agencies do not currently acquire internet connection records in bulk and have no current intention to do so. It is however important to ensure that we do not legislate against the possibility of internet connection records being acquired in bulk, should agencies make a case which demonstrates that this might be necessary and proportionate in the interests of national security in future”.—[Official Report, 7/9/16; cols. 1087-88.]
Surely we should be legislating for a proven need, not not legislating against a possible but unlikely proven one.
Noble Lords will remember that the security services—GCHQ, MI5 and MI6—have all said that they do not need internet connection records in order to do their work. The power to acquire communications data in bulk, including the power to acquire ICRs in bulk, is available only to those agencies. The power to acquire internet connection records in bulk is therefore not needed. They are not collected in bulk at the moment, and there is no current intention to do so. If this were an opposition amendment to include ICRs in bulk data acquisition, the Government would quite rightly say it was unnecessary. The power to acquire ICRs in bulk also strips away all the safeguards that are in place when law enforcement agencies apply for individual internet connection records.
This is the online equivalent of Section 44 of the Terrorism Act, which allowed the police to stop and search people without any reasonable suspicion. The former Home Secretary, now the Prime Minister, Theresa May took that power away from the police because she considered it disproportionate.
Surely Section 44 was for target hardening and deterrence rather than for any other purpose.
I am very grateful to the noble Lord, Lord Harris, but that is not what I understood Parliament’s intention was when the legislation was enacted. We can argue the point. If the analogy with stop and search sounds familiar to noble Lords next to me, including the noble Lord, Lord Harris of Haringey, it is because it is an analogy that was used by the shadow Home Secretary Diane Abbott in describing the powers under the Bill, which she describes as draconian.
The pieces of this legislative jigsaw are beginning to fall into place. Telephone operators already keep a record of the details of every phone call made and every text message sent. Internet service providers are being forced by this Bill to keep a record of every website, you, I and everyone else in this country have visited over the previous 12 months, which is a provision this House agreed to on Monday in a Division when it rejected the Liberal Democrat amendment to prevent it. A request filter, operated by or on behalf of the Government will be constructed. It will have direct feeds into the databases of communications providers, including access to the sensitive personal information of every subscriber to telephone and internet services in the UK, every call they make and every website they visit. The House agreed to that provision in a Division on Monday when it rejected the Liberal Democrat amendment to prevent it. The power is then given by this part of the Bill to allow all that sensitive personal information—details of every phone call made and every website visited—to be downloaded at will by the security agencies with no further authorisation. I hope that at least some noble Lords are feeling uncomfortable at that prospect. Our amendment removes internet connection records from the data that can be acquired under a bulk acquisition warrant. I beg to move.
My Lords, it will not surprise my noble friend to learn that I oppose the amendment that he has just moved. We made reference during our previous day on Report to papers that were presented by the Government at the time of First Reading. Those papers included, as was mentioned on Monday of this week, a paper in which GCHQ explained why the bulk acquisition of communications data material might be crucial to interdicting a major terrorism event which it thought was likely to occur, or might possibly occur, in the near future.
The issue was then referred to David Anderson—and I am surprised that my noble friend does not accept what Mr Anderson, the independent reviewer, said on the matter. He reminded us that three of the powers under review—bulk interception, bulk acquisition of communications data and bulk personal datasets—were already in use across the range of MI5, MI6 and GCHQ activity, from cyberdefence, counterterrorism and counterespionage to combating child sexual abuse and organised crime. He said:
“They play an important part in identifying, understanding and averting threats in Great Britain, Northern Ireland and further afield”.
The GCHQ paper to which I referred dealt with “further afield”.
Mr Anderson continued:
“After close examination of numerous case studies, the review concluded that other techniques could sometimes, though not always, be used to achieve these objectives: but that they would often be less effective, more dangerous, more resource-intensive, more intrusive or slower”.
Mr Anderson concluded that there was a proven operational case for three of the powers already in use, and he agreed that there was a distinct though as yet unproven operational case for the fourth power: bulk equipment interference. He also recognised the “breath-taking”—that was his word—pace of change in this area, and that we needed to make sure that the authorities had the proportionate powers that were required to protect this country, and other countries, from terrorism.
Therefore, the Bill provides the powers with a very elaborate set of protections. We also have—it is available in the Public Bill Office—the Bulk Acquisition DRAFT Code of Practice, dated autumn 2016: it is very recent. In paragraphs 3.10 and 3.11 of the code—and, indeed, elsewhere in the code—the most elaborate protections are described. For example, paragraph 3.10 contains operational guidance and advice for those who are dealing with these matters and states in terms:
“No interference with privacy should be considered proportionate if the information which is sought could reasonably be obtained by other less intrusive means”.
Paragraph 3.11 of the code sets out in four very carefully drafted bullet points the elements of proportionality that should be considered before the powers are used. It includes assessing whether other methods have been considered and whether those other methods could have provided a reasonable outcome without the necessity of the invasion of privacy which undoubtedly the provisions describe.
I therefore ask my noble friend to state, when he comes to reply to this short debate, what his view is of the code of practice—and, in particular, of the part to which I referred.
The amendment relates specifically to internet connection records being acquired, and I have yet to hear my noble friend address any of his remarks to the issue of those records.
If my noble friend wants me to be specific, I will, but I was trying not to take up too much time. Let us take the example of a piece of information, given to a security service, that people in possession of a bulk delivery of a certain type of telecommunications equipment, say a phone brand, are involved in the planning of a terrorist event. In order to find out quickly who these people are, the authorities would need to attack the bulk, so as to exclude all people who are not involved in the planned event. This is an absolutely routine technique that is used. I see one or two of my noble friends turning round in surprise. If they are surprised, they have not even read modern spy novels, let alone about the reality of what is being done by intelligence agencies all around the world.
The answer to my noble friend is as simple as that. I will just repeat my question, because I would like him to reply to it in due course. I take it that he has read the code of practice. What is missing from the code of practice that is required in order to provide the protection he wishes for? It is all in the code of practice; it is all in the statute. I apologise for repeating something I said on Monday, but these provisions, as drafted, are a careful and responsible response by a Government who wish to do no more than the state absolutely has to, safely, to protect their citizens.
I will answer that point. The Bill of course is not draconian in any way whatever. It is a modest response to the technology that exists today, and an attempt to look at the technology of tomorrow that we do not know about. That is part of the problem. I regret that I was a bit late and missed the first 20 seconds of the noble Lord’s introduction, so I may have this wrong, but he gave the impression that David Anderson supported his amendment. One only has to go to the report published in August, from which I want to put two sentences on the record. Paragraph 6.16 says:
“There is a clear value in the use of bulk powers to eliminate lines of enquiry, so that resources can be concentrated elsewhere and disruption to the public minimised”.
I do not think we should fetter the security services by this amendment. The other sentence from the report that I want to put on the record is in paragraph 6.47, at point (d):
“Even where alternatives might be available, they are frequently more intrusive than the use of bulk acquisition”.
Most of the bulk acquisition will never, ever be read. The vast majority—99.999%—will never be read or studied by anybody, and it gives a false impression when the noble Lord says that all our telephone calls, internet searches, and web browsing will be read by someone. That is simply not true. What is more, he has been briefed and knows that that is the case. I do not see why the opponents of the Bill, in this House or the other House, should try to give a false impression of what it is trying to do. I hope the noble Lord tests the opinion of the House, because I would like it clearly on the record that he probably has little or no support for his amendment.
I can be brief. I must begin of course by expressing my regret that I do not agree with my noble friend on the Front Bench. There is nothing more insulting than the expression, “If you could only see what passes across my desk, you would take a different view”. I do not use that expression, but I have to admit that I cannot expunge from my memory my experience as a member of the Intelligence and Security Committee and my contact during that period with the security services. Essentially, we are talking about a question of judgment. My judgment is legitimately assisted by the conclusions of the report from Mr David Anderson, who was, a bit like Moses, dispatched up the mountain and told to come back with tablets of stone. In particular he came back with case studies, and I defy anyone to read them and not be persuaded beyond all doubt of the necessity for the powers that we are discussing today. As my noble friend Lord Carlile has pointed out, Mr Anderson reached the proven conclusion of the operational purpose of three powers and made a further case in respect of the fourth.
Sometimes in the course of these deliberations we confine ourselves to the question of terrorism. As has been mentioned, I think in passing, we should always remember that these are powers that are apt to deal with the question of organised crime and, more particularly, in the rather febrile atmosphere that surrounds the matter, the question of child sexual abuse.
Mr Anderson made the observation, which I doubt anyone would wish to challenge, that the pace of technological change is frightening. We all carry a mobile phone in our pockets; if we think of the first one we ever got some 20 years ago and compare it with the capacity of the one that we now have, that is as powerful an illustration of technological change as one could imagine.
I suppose the question may arise as to whether what we are discussing is necessary and proportionate. I respectfully suggest that the nature of the threat—I noticed as soon as I came into the building that the threat level is still severe—and the experience across the Channel, plus the experience of the security services in dealing with plots, argues beyond peradventure that what is proposed here is both necessary and proportionate. For these reasons, I regret I will not be able to follow my noble friend Lord Paddick when he tests the opinion of the House.
My Lords, I support my noble friend Lord Paddick and the amendment that he has moved. I should say at the outset that I do not doubt for one moment the very severe threats that we face, nor the essential and dedicated work done by our security services and the police. In the coalition Government we had to tackle many of these issues, and the then Deputy Prime Minister was always as impatient with those who were careless about our security as he was with those who were careless about our liberty.
So I understand the reality of the threats that we face. However, I am afraid I cannot agree with my two noble friends who have just spoken. We have to be very clear what we are talking about in the amendment, which is specifically about ICRs. I think that in some of this debate we might have missed that point.
My noble friend Lord Carlile referred to the fact that powers were already in use, but the bulk powers in relation to ICRs obviously cannot be in place because the powers of the Bill granting the requirement to collect ICRs have not come into effect, so they are not collected in that way. I am surprised that my noble friend takes the view that he does, because during the whole course of the debate on the Bill he has made much of the point that he has been consistent. I am not clear why his position has changed so significantly on the collection of ICRs. As I have noted in our previous debates on the subject, on 25 May 2013, writing in the Daily Mail, my noble friend wrote the following:
“I, Lord Reid, Lord West and others of like mind have never favoured the recording of every website visited by every … user, though we have been accused of that”.
My noble friend is playing with language. I have never favoured the recording of every website use we make, and I do not support the recording of them now. It is the availability of the metadata that is important. I ask my noble friend to deal with the example I gave in answer to my noble friend Lord Paddick and tell us whether he thinks it is reasonable.
I am dealing with the fact that we are granting a power under the Bill, as this House voted only a couple of days ago, for all the websites visited by every user in this country, whether suspected of anything or innocent, to be recorded. That is a matter of fact, not a matter of debate.
We also need to deal with the canard that we have heard from people such as the noble Lord who spoke from the Labour Benches earlier, which is that to question the powers granted under the Bill is somehow to question the integrity of the police or the security and intelligence agencies, to cast aspersions on them. That is nonsense. I have nothing but respect for the difficult, often dangerous and always demanding jobs carried out on our behalf by the police and security services. There is no doubt that the vast majority of them do so with absolute dedication and integrity, but it is absurd to suggest that such powers are not on occasion abused. We know they are. That is a matter of fact; it is recorded in our history. Of course, it is inevitable that that is the case: all such agencies are made up of human beings and we are all subject to frailty. That is why, over the years, those who believe in constitutional democracy have insisted on limiting the powers granted to the state and its agents.
That is why we have such concern about the power granted after our debate the other day to record—I repeat—every website visited by every person in this country. The Government will now have the power to demand that that be recorded. That is why we are concerned about that and about the bulk power in relation to it. That is why I will be supporting my noble friend Lord Paddick and my colleagues on the Front Bench: I think that is rightly a matter of grave concern for liberties in this country.
My Lords, I think the noble Lord accepts one thing: the use of these powers, which are very substantial, could in certain circumstances be essential to obstruct or prevent an otherwise very serious terrorist incident. I am not sure whether he challenges that. The noble Lord, Lord Carlile, referred to the supporting evidence from David Anderson to that effect. So the noble Lord, Lord Oates, is taking the courageous position—as is the noble Lord, Lord Paddick—of being prepared to accept that risk. In the current situation, nobody in this House has any right to be ignorant that the threat at present is severe—and “severe” may be slightly underplaying the scale of the situation at the moment. We know the situation; there is no point drawing attention to it. We know what is happening in Mosul at present, where the instruction among ISIS is, “Don’t hang around here. Get into some of the capitals of the West and see what you can do”. The message is going out to try to cause a terrorist incident right on our doorstep.
The noble Lord asks me specifically what I believe. It is very simple. I do not believe that we should record the websites visited by every person in this country. I do not think that is merited; it is not a power used by any other “Five Eyes” country or any constitutional democracy that I know of.
So the noble Lord does not agree with David Anderson or with those who said that this could be an essential asset and ingredient in possibly preventing a serious terrorist attack. He is saying that he does not believe that that is true, if I understand him; if he believes that it is true, he is being extremely courageous, in the words of “Yes Minister”, in taking that position. He is taking responsibility for what might happen to people in this country, which is a very brave thing to do.
I do not want to interfere with the slight divisions of view that are appearing among the Liberal Democrats in this House, but I have listened to the noble Lord, Lord Paddick, in a number of these debates. He is very conscientious and he looks as though he has worked very hard in preparing his brief and making speeches in support of the amendments, but he only ever gives us about half the story. He suggested in earlier debates that we were looking for powers that the agencies have not asked for and did not want, and said that he did not know why they were in the Bill. He knows the police—it is the police who are keen to get those powers. He did not put that in his speech; he did not tell the House the background, or that this was not some quirk of the noble Earl, Lord Howe, who wanted to shove stuff into the Bill for his own amusement. That is where that came from. I was disappointed by the noble Lord’s presentation of the amendment, as was exposed by the noble Lord, Lord Carlile. I do not think I heard a single mention of David Anderson or his report in the presentation of this amendment, although I may be wrong.
What stands out in this whole debate is that the Government know that these are very substantial powers, which nobody would wish to see if we could avoid it—and they are there because of the serious threat we face. The Government have recognised that if you are to have those powers, they must be surrounded by the most substantial safeguards there can be. I am known to be a critic of how much time the Government took before the Bill came forward. A number of us thought that there was an urgency about the matter and tried to get it earlier. But the Government have gone to great lengths, setting out the Anderson report and now, as the noble Lord, Lord Carlile, said, producing the code of practice. There was not a single mention from the noble Lord, Lord Paddick, of the code of practice, and I do not know whether he has considered it. I should like him to answer the question of the noble Lord, Lord Carlile. What does he think of the code of practice? It is a further safeguard that the Government have included in these proposals.
We have to protect our citizens. A number of us live with the threat of terrorism in our lives, in one way or another, and we know the tragedies it can cause in so many different fields. Sometimes we have to take tough and regrettable steps to make sure that innocent people—that everybody—is protected as far as possible. If that happens, I am determined to see that we do it in a situation and structure in which every possible protection is included against abuse and every possible system of accountability for their exercise is kept up to date and regularly inspected. The very elaborate provision that the Government have made in this Bill generally commands respect, except in one or two quarters, where people are still fighting an old battle about what old rights should be and how there should be no interference. In the modern situation in which we live, we must have proper provision to protect our nation and, at the same time, ensure that there is every possible safeguard against abuse.
My Lords, I am sure we do not want to prolong this debate. As I said on Monday, I was a member of the pre-legislative scrutiny group. You might wonder why a Bishop was invited to be part of that exercise, but I think it was because of this point—the ethics of interference with privacy. I am sorry that the discussion so far has almost become too polarised, because the noble Lord, Lord Paddick, is making a serious point, which I demonstrate by quoting David Anderson in his evidence to the Joint Committee on Human Rights. He said:
“I think there is a human rights issue in relation to this Bill that dwarfs all the others, and it is the question of the compatibility of bulk collection and retention of data with Article 8 of the European convention”.
The noble Lords, Lord Paddick and Lord Oates, make a serious point and we should acknowledge it, even if we come down on the side of the noble Lord, Lord King—as I do—that these powers are necessary and proportionate. The argument is about the safeguards—namely, that the warrant has to be personally signed by the Secretary of State, lapses after six months if it is not renewed, and is subject to the judicial commissioners. The real argument is about that. I do not think internet connection records are in principle different from other things that might be intercepted. However, I acknowledge the serious ethical point that the noble Lords, Lord Paddick and Lord Oates, raised, even if I come down on the side of the Government and the noble Lord, Lord King, in opposing the amendment.
My Lords, I fear that we are repeating the debate we had the day before yesterday. If noble Lords look at this amendment, they will see three reasons why they could support it. One is if they feel that bulk data powers are unacceptable in any circumstances. A second is if they feel that the elaborate controls referred to by my noble friend Lord King and the noble Lord, Lord Carlile, are not good enough. The third is if they object in principle to the collection of internet connection records. From what I have heard this afternoon, the argument of the noble Lord, Lord Paddick, is entirely the third point. I respect his view on internet connection records but we debated this on Monday and the view of the House was very clear. I fear that we are simply repeating that discussion. We should move on.
As the noble Lord, Lord Paddick, said, David Anderson QC commented in his report that neither the Bill nor the draft code of practice rules out the future use of the bulk acquisition power for internet connection records. Internet connection records are not currently acquired in bulk but existing legislation already permits the agencies to acquire such records in bulk, albeit there appears to be no present intention to do so.
The effect of this amendment would be to remove an existing legislative provision which could be needed in the future for bulk acquisition—bulk acquisition which David Anderson QC found had contributed significantly to the disruption of terrorist operations and, through that disruption, almost certainly to the saving of lives, and which had also been demonstrated to be crucial in a variety of fields. In addition, any such application in the future to obtain such data by the security and intelligence agencies would be covered by the relevant safeguards in the Bill, including in relation to necessity and proportionality in the interests of national security and the approval process.
This Bill is, among other things, about the appropriate balance between security and privacy. We clearly have a different view from that of some other noble Lords on where that appropriate balance lies. Our view is that, for the reasons I have sought to set out, we are unable to support this amendment and, if it is put to a vote, we shall oppose it.
My Lords, this amendment would remove the ability for the intelligence agencies to acquire internet connection records in bulk, an issue we have already discussed in Committee and revisited on a number of occasions, as observed by my noble friend Lady Harding. At the time we debated this in Committee, I highlighted the point now made by the noble Lord, Lord Rosser, that this is not a new power introduced by the Bill. This is an existing power. It exists in legislation, albeit, while it is provided for, it is not at present utilised.
As I explained in Committee, it is vital in the current climate, when methods of electronic communication are changing and developing at an exponential rate, that we provide technology-neutral legislation—a point made by the noble Lord, Lord Rooker. We remain of the view that we would not wish to legislate against the possibility of internet connection records being acquired in bulk, should the agencies make a case—and they must make a case—which demonstrates that this might be necessary and proportionate in the interests of national security.
We strongly believe that it is right that the intelligence agencies have the power to acquire communications data in bulk, and David Anderson supported this in his bulk powers review. The noble Lords, Lord Carlile and Lord Campbell of Pittenweem, alluded to the observations made by David Anderson. I will refer to only one further quotation: he said that,
“bulk acquisition has contributed significantly to the disruption of terrorist operations and, though that disruption, almost certainly the saving of lives”.
The noble Lord, Lord Carlile, alluded to some of the examples that were given by David Anderson and worked through in his report.
I am grateful to the Minister and to other noble Lords who have contributed to this debate. As regards the comments of my noble friend Lord Carlile of Berriew, despite my request that he specifically address the issue of internet connection records, I did not hear him do so. We are not against the bulk acquisition of communications data in general or per se. We oppose only the bulk acquisition of internet connection records as part of those data.
On the question my noble friend Lord Carlile raised about the codes of practice, of course they are comprehensive. However, through this amendment we are trying to prevent internet connection records being acquired in bulk, which is allowed for in the codes of practice.
The noble Lord, Lord Rooker, was of a different opinion from the one that I quoted—that the Bill was draconian. I am grateful to him for giving me the opportunity to emphasise to the House that it was the current Labour shadow Home Secretary, Diane Abbott, who described the Bill as draconian.
For the avoidance of doubt, I understood that—that was the point I made.
I did not suggest in any way that David Anderson agreed with this amendment, or that the lists of everybody’s websites would be read, as the noble Lord, Lord Rooker, suggested.
As regards the comments made by my noble friend Lord Campbell of Pittenweem, he referred to case studies in the David Anderson report on bulk data. I cannot emphasise this enough to noble Lords: internet connection records do not currently exist. The telecommunications companies will have to create them. Therefore any case studies in David Anderson’s report do not relate to the bulk collection of internet connection records. Internet connection records do not exist, so they cannot be collected in bulk at the moment.
I acknowledge the great experience of the noble Lord, Lord King of Bridgwater, and his passion about these issues. He emphasised that everything needs to be done to prevent a terrorist attack, and I agree with him 100%. The point that I made in my opening speech when I quoted David Anderson directly, saying that it was a direct quote from him, was that GCHQ, MI5 and MI6—the agencies responsible for keeping us safe from terrorism—say that they do not need internet connection records. Even the Minister said that at present there is no anticipated need to collect internet connection records to prevent a terrorist attack.
I am very grateful to the right reverend Prelate the Bishop of Chester for saying that we are making a fundamental point here. The difference between today’s debate and Monday’s debate is that requiring individuals’ internet connection records has to be based on reasonable suspicion. Thanks to the intervention of the Labour Front Bench, the level of the seriousness of the crime that needs to be suspected before those records can be handed over is higher than the Government first suggested. However, this power would allow everybody’s internet connection records to be acquired in bulk by the security agencies with no reasonable suspicion at all.
I am sorry but this is Report and I do not have to give way, unless the noble Lord wishes to clarify what I have just said.
I wish to make an intervention. The noble Lord said again that nobody wants this power. Can he explain why it is in the Bill?
It is not for me to explain why the Government want in the Bill a power that currently does not exist, because internet connection records do not exist, and which the security services say they do not want but which the noble and learned Lord says might be needed in the future. It is not for me to justify this power; I am saying to the House why I do not believe it is justified. The noble and learned Lord and the noble Lord, Lord Rosser, made the point that this is an existing power, but how can you have an existing power to acquire something that will not exist until the Bill is enacted?
I have tried to explain very clearly—although unfortunately some people have not heard what I have said—why we cannot accept this provision, and that is why I want to test the opinion of the House.
My Lords, the amendment is in my name and that of my noble friend Lady Hamwee. I shall speak also to all the other amendments in this group, Amendments 203B to 203D, 204A to 204F, 205A, 208A to 208C, 209A, 210A and 210B, 215A, 217A and 218A. The sole effect of all the amendments would be to remove from the Bill the power to engage in bulk equipment interference.
This is a new power for the security and intelligence agencies to carry out equipment interference in bulk overseas. It is not a power they currently have and, according to David Anderson QC, it is not something that they currently do. As a result, David Anderson said in his review of bulk powers that the operational case for bulk equipment interference was “not yet proven”. The noble Lord, Lord Murphy, has said:
“The case for bulk equipment interference was less strong, but nevertheless still there”.—[Official Report, 7/9/2016; col. 1049.]
As the noble Lord, Lord Rosser, said in Committee, there is a difference between an operational case, let alone an unproven one, and proportionality or desirability. Quoting Mr Anderson, he pointed out that Mr Anderson assessed only the operational cases in his review, saying that the issues of proportionality and necessity were a matter for Parliament—which is why we are debating these amendments today.
We heard in earlier debates about the potentially broad scope of targeted equipment interference warrants. They can specify all equipment used by anyone in a particular organisation or more than one organisation involved in a single investigation or operation; all equipment used by members of a group with a common purpose or engaged in a particular activity; equipment in a particular location or more than one location for the purpose of a single investigation or operation; and equipment being used or that may be used for a particular activity or activities. That is all contained in Clause 108.
Although I realise that the primary focus of this House should be to protect the citizens of this country, I ask noble Lords to consider how they would feel if overseas Governments took our lead and enacted similar legislation that could be deployed against the UK and its citizens. UK citizens’ communications could be acquired through the use of bulk equipment interference warrants if they communicated with others based overseas.
In paragraph 7.37 of his report into bulk powers, David Anderson QC warns that considerable caution is required for a series of reasons. He concludes in paragraph 7.38:
“All this means that bulk EI will require, to an even greater extent than the other powers subject to review, the most rigorous scrutiny not only by the Secretary of State but by the Judicial Commissioners who must approve its use and by the IPC which will have oversight of its consequences”.
It is the nearest David Anderson comes to expressing an opinion on necessity and proportionality and, reading between the lines, it is clear that he is not keen.
For those reasons—and as the Intelligence and Security Committee initially recommended, although it was subsequently persuaded—we believe that bulk equipment interference warrants should be removed from the Bill. I beg to move.
My Lords, these amendments would remove the bulk equipment interference provisions from the Bill. Before I address the amendments specifically, it is worth pausing to reflect briefly on the importance of bulk powers in the round and the very significant steps that the Government have taken to ensure both that a robust operational case has been made for their necessity and that the most rigorous safeguards will apply to their use.
Extremely detailed and extensive scrutiny has been applied to bulk powers during the passage of the Bill, both in Parliament and, of course, by David Anderson QC as part of his bulk powers review. The conclusion of that review was that bulk powers,
“have a clear operational purpose”;
that they,
“play an important part in identifying, understanding and averting threats in Great Britain, Northern Ireland and further afield”;
and that where alternatives exist to their use,
“they were likely to produce less comprehensive intelligence and were often more dangerous (for example to agents and their handlers), more resource-intensive, more intrusive or—crucially—slower”.
The Government have now tabled amendments giving full effect to the sole recommendation of that review, establishing in statute a Technology Advisory Panel to the Investigatory Powers Commissioner. We have also accepted an amendment tabled by the Intelligence and Security Committee which introduces a specific offence in the Bill to address deliberate misuse of the bulk powers. We have addressed wider concerns of that committee by adding very significant detail to the Bill on the safeguards that will regulate the use of these powers. I am grateful for the intensive scrutiny that has been applied to the bulk provisions in the Bill and believe that those provisions are all the stronger for it. There should now be no question that these powers are necessary and they are subject to world-leading safeguards.
I am grateful to the Minister for his comments. He kept saying that this power to conduct bulk equipment interference was absolutely essential to keeping us safe. What I do not understand is, first, why the very broad powers provided and the very broad range of targets that could be specified using targeted equipment interference could not be used in almost every case, rather than this power. Secondly, if bulk equipment interference is absolutely essential, if it could be authorised under existing legislation, why has it never been used by the security services? That is what David Anderson says.
As the Minister took the opportunity to talk about bulk powers in the round, perhaps I might get two things on the record. First, I cannot stress strongly enough that we are not opposed to the bulk acquisition of communications data generally. We are not opposed to bulk powers generally. We have specific issues with specific powers. Secondly, it has been suggested to me that I am standing here saying these things because it is my party policy. My party policy was decided by a working group that I chaired. I wrote the conclusions to that policy paper. I not only agree with the conclusions of that policy paper, I believe that they are absolutely the right conclusions. However, we have made the points that we wanted to make. They are on the record. I beg leave to withdraw the amendment.
My Lords, this group contains a number of amendments specific to Part 7 of the Bill, which covers bulk personal datasets. I first turn to government Amendments 219, 220, 224, 226, 227, 229, 230, 237, 238, 239, 240 and 265, 266 and 267.
In David Anderson QC’s review of bulk powers he stated:
“It has come to my attention that some”,
bulk personal datasets,
“may contain material that is comparable to the content of communications, and in rare cases even material subject to”,
legal professional privilege. He continued:
“In the light of these facts I have already recommended to the Home Office that consideration be given to the introduction of additional safeguards to the Bill and Code of Practice”.
We welcome David Anderson’s review and the attention he has given to these matters. I stress that it is unlikely to be the case that many bulk personal datasets will contain this sort of material, but in those instances where they do, it is right that it is protected appropriately. These amendments ensure that the Bill provides such protection.
Amendment 219 explains that an intelligence agency may not use a class BPD warrant to,
“retain, or retain and examine, a bulk personal dataset”,
that consists of or includes “protected data”. Amendment 220 would insert a new clause which defines what protected data are in this context. In essence, protected data are the same class of data as “content” in the telecommunications context or “protected material” in the equipment interference context. Protected data in a bulk personal dataset may include, for example, the contents of letters, emails or other documents. They do not include identifying data—for example, data that may help to identify persons, systems, services, locations or events—nor do they include systems data, which are data that enable or facilitate the functioning of any system or service.
My Lords, I will now address government amendments relating to definitions and extent, and consequential provisions. They aim to ensure consistency within the Bill and with other statutes. Clause 246 contains the usual power to make amendments to other legislation consequential on the provisions of the Bill. Schedule 8 contains a similar power to make amendments consequential on the provisions in that schedule. As currently drafted, the powers would permit the amendment of legislation passed at any time in future.
The power to make consequential amendments to future enactments is necessary because other Bills before Parliament at the same time as this Bill touch upon the powers and public authorities covered by the Bill—such as, for example, the Policing and Crime Bill. Since it is impossible to predict how those Bills, or the Investigatory Powers Bill, may be amended during their parliamentary passage, and which Bill may achieve Royal Assent first, it is necessary to allow for the possibility of consequential amendment of future enactments.
In its recent report on the powers in the Bill, the Delegated Powers and Regulatory Reform Committee recommended that the powers should be restricted to the amending of future enactments passed or made during the current Session. The Government indicated in Committee in this House that they intended to accept this recommendation. Amendments 243 and 281 give effect to the committee’s recommendation, and I commend them to the House.
Amendments 260 and 271 are technical amendments that remove the definition of “person” from the Bill. The Bill’s definition of “person” in Clause 239 was carried over from the Regulation of Investigatory Powers Act 2000. It does not apply in relation to Parts 2 or 5 of the Bill, and we have concluded that it is not needed in respect of the other parts. The Interpretation Act definition will apply throughout the Bill. The definition of “person” in Clause 239 is therefore not required and Amendments 260 and 271 simply remove it.
Amendment 268 provides definitions of “journalistic material” and “confidential journalistic material”. It makes it clear where the additional protections provided for in Parts 2 and 5 of the Bill, which we debated here on the first day of Report, will apply. It is of course the case that the Government are seeking to protect legitimate journalism while ensuring that those who wish to do us harm cannot hide behind spurious claims of journalism. For this reason, Amendment 268 makes it clear that material acquired or created to further a criminal purpose is not considered journalistic material in the context of the Bill. This seeks to prevent persons such as those in the media wing of Daesh attracting a safeguard intended for legitimate journalists.
Amendments 280 and 286 clarify the drafting in relation to the definition of a postal operator, and to consequential amendments being made to RIPA. These drafting amendments make no changes to the effect of the provisions. Amendments 282, 283, 284 and 292 make minor amendments to the Security Service Act 1989, Intelligence Services Act 1994, Police Act 1997 and Anti-terrorism, Crime and Security Act 2001 in consequence of the updated targeted-interception provisions in Part 2 of this Bill.
Amendment 289 relates to the IPC’s duties to report to Scottish Ministers. Where the Police Act 1997 requires the IPC to report certain matters to Scottish Ministers, this amendment provides that the IPC can do so at any time, as opposed to only in its annual report. Amendment 285 is a minor and consequential amendment. As we have discussed previously, the Bill provides for an interception warrant to be obtained that has the main purpose of obtaining secondary data from communications, rather than intercepting communications content. This amendment simply amends RIPA to make it clear that a notice served under Part 3 of that Act can relate to an interception warrant that has the main purpose only of obtaining secondary data.
Amendment 287 ensures that the provisions of RIPA will make proper reference to powers provided for in this Bill, alongside existing legislative references. It will make two key changes to RIPA. First, it inserts a reference in Section 48 of RIPA to the equipment interference powers provided for in the Bill, which will sit alongside existing references to property interference powers contained in the Intelligence Services Act 1994 and the Police Act 1997. This amendment makes it clear that references to surveillance in Part 2 of RIPA do not include equipment interference activity which will be authorised under the Bill when it becomes the Investigatory Powers Act. This minor amendment will simply ensure consistency with the existing drafting of RIPA.
Secondly, and similarly, the amendment inserts a reference to equipment interference warrants into Schedule 2 to RIPA, which will sit alongside an existing reference to property interference authorisations under Part 3 of the Police Act 1997. Schedule 2 to RIPA relates to the issuing of a Section 49 notice under Part 3 of RIPA. A Section 49 notice allows relevant authorities to require a person to put protected electronic information into an “intelligible form”. In the future, acquisitions of these types of data will be done using equipment interference powers provided for in the Bill, so it is essential that law enforcement agencies continue to be able to use Section 49 notices with the new statutory framework. This amendment ensures that, in future, a law enforcement chief or an appropriate delegate will retain the same powers they currently hold in relation to protected electronic information obtained under existing legislation.
Amendment 288 is a minor, technical amendment that corrects a drafting error in Schedule 10. Paragraph 62 of Schedule 10 amends the Regulation of Investigatory Powers (Scotland) Act 2000 to ensure that Scottish Ministers can issue a code of practice in relation to equipment interference. This amendment clarifies that any such code of practice will be limited to targeted equipment interference so far as it relates to the police service or the Police Investigations and Review Commissioner, and will not relate to bulk equipment interference, a power which is not authorised by Scottish Ministers.
Finally, Amendments 296 to 300 are technical amendments which simply clarify the extent of the provisions of the Bill in relation to the Crown dependencies. They make two key changes. The first is being made following a request from the Isle of Man Government and will enable the extension of any of the provisions of the Bill, with or without modification, to the Isle of Man. This could assist the Isle of Man in ensuring that its legislative framework for law enforcement can be fully up to date and future-proof, enabling greater consistency with UK law.
The second of these changes will provide a more limited extension of provision for the Channel Islands, simply ensuring that any amendments made by the Bill to the provisions of another Act, such as the consequential amendments detailed at Schedule 10, may be extended to the Channel Islands by Order in Council, if that Act contains such a power. Any extension by Order in Council would of course only take place in consultation with the Governments of Jersey and Guernsey, and with their consent, and they would retain the option to make those amendments in domestic legislation instead. These technical amendments will help to clarify the extent of the provisions of the Bill. I beg to move.
My Lords, I shall speak to Amendments 294 and 295, tabled by the noble Baronesses, Lady Hollins and Lady O’Neill, and the noble and learned Lords, Lord Falconer and Lord Wallace. The noble Baronesses very much regret that they cannot be present in the House today, and they have asked me to speak to their amendments. I will be brief, as I understand that, without prejudice to the Government’s ultimate position, the Minister is not seeking to divide the House, and we are all most grateful to him for that.
The amendments would have no impact on the security measures in the Bill, nor would they affect the other measures in the Bill in any way. Their sole purpose is to bring into force automatically after Royal Assent Clause 8 and the new clause that was added to the Bill by this House last week by a large majority.
The amendments would deliver cost protections in hacking cases, which Section 40 of the Crime and Courts Act 2013 was enacted to provide for all publication torts. Section 40 is a key part of the Leveson recommendations that the Government promised to implement but has not been commenced. Non-commencement frustrates the will of Parliament and is a breach of the 2013 cross-party agreement. The commencement of these clauses automatically after Royal Assent is necessary to ensure that the device of non-commencement is not employed again on the amendments that the House passed last week. For these reasons, I commend Amendments 294 and 295 to the House.
My Lords, we discussed the substantive points on this issue on day one of Report. We consider these amendments consequential to the ones we discussed then. Although the Government’s position on the substantive issue remains as we set out last week, we are not opposing these amendments.
My Lords, I shall also speak to Amendments 245 and 246. These amendments take us back to the question of the reimbursement of the operators’ costs. We have heard frequent assurances about the operators’ compliance costs and that they are to be met, but the words of the Bill do not quite live up to some of the narrative.
Our three amendments cover two alternatives; they would not all be possible. Amendments 244 and 245 would provide that arrangements were in force to secure for the operators the full amount of all relevant costs—“relevant costs” are defined later in the clause—not an appropriate contribution. As Clause 225(1) is framed, the Secretary of State must ensure,
“an appropriate contribution in respect of such of their relevant costs as the Secretary of State considers appropriate”.
With these two amendments, we seek to take out that element of discretion.
Amendment 246 would provide that if the contribution was not an equal amount, there should be regulations regarding the basis of how the contribution is calculated. Our amendments provide that the Secretary of State should lay regulations to that effect. It will be obvious to noble Lords that our reasons are transparency, equality between operators and the opportunity to consider the criteria—the factors, if you like—applied in calculating the contribution. In other words, our intention is scrutiny, using the opportunity that regulations give for debate of their content.
We have debated this matter on a number of occasions, and the Minister will be well aware of our concern. This is an attempt, at this almost last stage, to pin down just how the contribution will be made. I beg to move.
My Lords, Amendments 244 and 245 are intended to ensure that communications service providers are fully reimbursed for their costs in connection with complying with obligations under the Bill. As the noble Baroness knows, this matter has been considered at length both in this House and in the Commons. It is important to recognise that service providers must not be unduly disadvantaged financially for complying with obligations placed on them aimed at protecting national security or combating crime. Indeed, the Government have a long history of working with service providers on these matters and we have been absolutely clear that we are committed to cost recovery.
I once again take the opportunity to reaffirm to the House a point that both my right honourable friend the former Security Minister and my right honourable friend the Prime Minister made very clear in the other place and that I made in Committee: this Government will reimburse 100% of reasonable costs incurred by communications service providers in relation to the acquisition and retention of communications data. This includes both capital and operational costs, including the costs associated with the retention of internet connection records.
The question that the House needs to consider, I submit, is whether it is appropriate for the Parliament of today to tie the hands of future Governments on this issue. That does not mean that we take our commitment lightly, or that future Governments will necessarily or lightly change course. Indeed, it is unlikely that any change in policy will ever take place. For example, the current policy has not changed since the passage of the Regulation of Investigatory Powers Act 2000, and so has survived Governments of three different colours, or combinations of colours.
The Bill adds further safeguards, requiring a data retention notice to set out the level of contribution that applies. This ensures that the provider must be consulted on any changes to the cost model and means that the provider could seek a review of any variation to the notice which affected the level of contribution.
Another question that I hope the House will consider is whether a communications service provider should be able to derive commercial benefit as a result of the obligations imposed on them in relation to the other powers under the Bill. Sometimes, it may be necessary for a communications service provider to upgrade part of its infrastructure to comply with an obligation imposed on it under a technical capability notice. As the communications service providers may be able to derive some business benefit from that upgrade, it is right that the legislation allows for the contribution to the costs to be appropriate to the circumstances.
Some noble Lords have expressed concern about the term “reasonable costs” and asked what it means. I hope I can provide some reassurance on that point. Significant public funding is made available to companies to ensure that they can provide assistance to public authorities in tackling terrorism, crime and other threats. As costs are reimbursed from public funds, the codes of practice make very clear that companies should take value for money into account when procuring, operating and maintaining the infrastructure required to comply with a notice. Were a company to select a solution that did not deliver best value for public funds, I am sure noble Lords would agree that it is absolutely right that the Government would need to consider carefully whether those costs were reasonable and therefore whether it was appropriate to reimburse the company in full.
The noble Baroness’s Amendment 246 acknowledges that there may be circumstances where it is appropriate for a communications service provider to be reimbursed less than its full costs. However, we do not think her proposed regulations provide the required flexibility. As I just explained, communications service providers may receive some business benefit from the changes made to their systems and it is appropriate that the Government are able to discuss these matters with them on a case-by-case basis, rather than be bound by general regulations. Indeed, while communications service providers would welcome an amendment to require 100% cost recovery in all cases, I suggest that they are unlikely to welcome regulations which enshrine in law circumstances where they would not receive full reimbursement.
I hope I have allayed any concerns about the Government’s position on costs and accordingly invite the noble Baroness to withdraw her amendment.
My Lords, until the last two or three sentences, I thought the noble Earl had made a much better case for regulations than I did. I am a little worried about his argument that regulations cannot provide for flexibility. Flexibility is not necessarily bad, but how it is exercised should be transparent, and that is what my amendment is driving at.
The noble Earl started his remarks by saying that the operators should not be “unduly disadvantaged”, and it is those words which caveat the commitment that has troubled us throughout our debates. We have tried, particularly with the third amendment, to meet the points made by the Government. I will obviously not pursue this any further; we have reached the end of the road. I have no doubt that someone will draw to our attention any problem in practice in future. I beg leave to withdraw the amendment.
My Lords, I shall speak also to the other government amendments. Government Amendments 247 to 250 clarify the activity that can be authorised by a national security notice to provide greater reassurance to telecommunications operators to whom such a notice may be given. These amendments also respond to concerns raised in the Commons that the detail set out in the draft code of practice was clearer than the provisions in the Bill.
Clause 228 states that the Secretary of State may give such a notice to a telecommunications operator in the UK, requiring the taking of such specified steps as are considered necessary in the interests of national security. The type of support that may be required includes the provision of services or facilities which would help the intelligence agencies to safeguard the security of their personnel and operations, or provide assistance with an emergency as defined in Section 1 of the Civil Contingencies Act 2004.
Amendment 248 makes it clear that a national security notice cannot be used for the primary purpose of acquiring communications or data. The proposed amendments further clarify that, in any circumstance where the taking of a step set out in the notice would involve the acquisition of private data, any interference with privacy must be authorised by an appropriate warrant or other authorisation under the Bill, or another relevant statute, where it is available. Therefore, a notice, of itself, cannot authorise as its primary purpose an intrusion into an individual’s privacy.
I should like to emphasise here that this power can be exercised only if the Secretary of State and a judicial commissioner are satisfied that the conduct required by a notice is necessary and proportionate to what is sought to be achieved.
In addition, Amendment 250 makes it clear that any conduct required under a notice is lawful for all purposes, providing reassurance for telecommunications operators that, when conduct is carried out in accordance with the requirements of a notice, the operator will not risk being found to be in breach of any other legal requirement.
I hope that these amendments reassure noble Lords that a national security notice cannot be used to circumvent the need to obtain a warrant or authorisation, but neither could it prohibit the acquisition of private data when such conduct has been appropriately authorised.
My Lords, Amendments 250A and 251A, in my name and that of my noble friend Lady Hamwee, relate to technical capability notices through which the Secretary of State can require an operator to have a capacity to provide any assistance necessary that might be required to give effect to the powers under the Bill. We have received representations on behalf of operators asking that those notices should be specific about the distinct service or product to which the notice applies, rather than a blanket, “You must have the capability to do anything we may require you to do under the powers contained in legislation”. Amendment 250A is intended to have that effect, while Amendment 251A tries to limit the scope of technical capability notices. The power to issue a technical capability notice applies to any provider capable of being considered a telecommunications provider under the very broad definitions in the Bill. It would not be proportionate or necessary for this power to be so broad. The amendment aims to narrow the definition to exclude services that are not primarily communications services, even when there may be a communications element. Whether the wording of our amendment achieves that is a matter for debate, but that is what is intended. I beg to move.
I can certainly tell the noble Lord that Yahoo! was one of the operators, but I do not have a list to hand.
My Lords, Amendment 250A would define a technical capability notice as,
“specifying the distinct service or product to which the notice applies”.
I do not believe this amendment is necessary. The safeguards that apply to the giving of a notice under the Bill already ensure that a technical capability notice cannot be of a generic nature. I will not go into detail here about the lengthy process that must be undertaken before a notice can be given; we have discussed them at length previously and we will undoubtedly review them again shortly during our discussions on encryption. But it might be helpful for me to summarise.
Before giving a notice, the Secretary of State must consult the company concerned. This process will ensure that the company is fully aware of which services the notice applies to. The decision to issue a notice must be approved by the Secretary of State and a judicial commissioner. The obligations set out in the notice must be clear so that the Secretary of State and judicial commissioner can take a view as to the necessity and proportionality of the conduct required. As I have already mentioned, we propose a similar role for the judicial commissioner when a notice is varied. The operator may raise any concerns about the requirements to be set out in the notice, including any lack of clarity regarding their scope, during the consultation process. The operator may also seek a formal review of their obligations, as provided for in Clause 233. The safeguards which apply to the giving of a notice have been strengthened during the Bill’s passage through Parliament, and will ensure that the regime provided for under the Bill will be more targeted than that under existing legislation. It is for these reasons that I consider the amendment unnecessary.
Amendment 251A seeks to narrow the category of operators to whom a technical capability notice could be given. This change would exclude operators that provide services that have a communications element but are not primarily a communication service. This amendment, which has already been discussed in the Commons, is also unnecessary and, in my view, risks dangerously limiting the capabilities of law enforcement and the security and intelligence agencies. We are aware that the manner in which criminals and terrorists communicate is diversifying, as they attempt to find new ways to evade detection. We cannot be in a situation where terrorists, paedophiles and other criminals can use technology to escape justice. As David Anderson said,
“no-go areas for law enforcement should be minimised as far as possible, whether in the physical or the digital world”.
It is important that the Government can continue to impose obligations relating to technical capabilities on a range of operators to ensure that law enforcement and the security and intelligence agencies can access, in a timely manner, communications of criminals and terrorists using less conventional services, such as those offered by gaming service providers and online marketplaces. It may be appropriate to exclude certain categories of operators from obligations under this clause, such as small businesses, but it is our intention to use secondary legislation to do so. It would not be appropriate to impose blanket exemptions on services that have a communications element but are primarily not a communication service, since to do so would make it clear to terrorists and criminals that communications over such systems could not be monitored.
For all the reasons I have set out, I hope that the noble Lord, Lord Paddick, will feel able to withdraw his amendment.
Before the noble Earl sits down, I refer to a point which at least needs to be borne in mind in drafting regulations. In most circumstances, if the Government impose upon a business an obligation of some kind, and behave totally unreasonably in doing so—or the business thinks that the Government are behaving unreasonably—the matter will end up in public discussion and the company has the weapon of saying to the public at large, “The Government are asking us to do something unreasonable”. That must not happen in these circumstances because clearly secrecy must be maintained. Therefore, the company is in a weaker position than it would be in the normal exchange between government and business. I hope that Ministers will recognise that fact.
With the leave of the House, I am grateful to the noble Lord for raising that point, which I think will come up in the next group of amendments when we discuss encryption because it is centre stage in that issue. He is absolutely right and I hope that I can assuage his concerns in the next debate.
I am very grateful to the Minister, particularly for his explanation around Amendment 251A. I completely accept that the whole range of ways in which people can communicate potentially needs to be covered. I am encouraged by the fact that there may be some exceptions in secondary legislation. It is unfortunate that we do not have sight of that before I withdraw this amendment but life is like that.
Bearing in mind the fact that the Minister did not articulate any downside to Amendment 250A, I wonder why the Government will not accept it, given that it appears not to limit the Government’s action in any way. However, at this stage, I beg leave to withdraw the amendment.
My Lords, noble Lords who have followed my limited contributions to the Bill will know that I take a fairly robust approach in support of what the Government seek to do in it. Indeed, they may even be slightly perplexed that I have tabled this amendment, which is supported by the Liberal Democrat Front Bench, given the slightly testy exchanges that have occurred once or twice during the passage of the Bill. However, my philosophy throughout has always been clear—namely, that by and large this Bill is needed to update current legislation and to protect the public. However, all the measures have to be tested in terms of the balance that they strike between protecting the public and their potential invasion of privacy. We have debated that issue but in this case the disbenefits I am concerned about are the extent to which what the Government may be trying to do—the Minister will no doubt explain what that is in more detail in a few minutes—under the Bill as drafted will weaken the security that people would otherwise have.
The Bill provides the Home Secretary with the power to require a communications provider to install some sort of technical capability to provide data on request, including where those data would otherwise be encrypted and are therefore not so easily available. The Bill includes an impressive array of safeguards. The Home Secretary is required to apply a series of tests before they make a decision to serve an order on a communications provider, and a process of consultation and discussion has to go forward. Those measures are all designed to ensure that not only is the Home Secretary properly informed in making that judgment but using the power is practical and reasonable. Indeed, the Bill emphasises the importance of the test of something being reasonably practical and technically feasible. I have asked for an explanation of the precise distinction between reasonably practical and technically feasible. I accept that there may be a distinction.
A whole series of tests applies under those circumstances but we do not know how those tests might be applied in future or what the Home Secretary might decide. Therefore, we cannot know how a future Home Secretary, or the present Home Secretary, would interpret what is and is not practicable and reasonable. In particular, we face an ambiguity—at least I think there is an ambiguity here—over what it will mean for end-to-end encrypted services. End-to-end encrypted services allow an end-user to send a message via a particular service which can be opened and read only by the person to whom it is sent. That is an important reassurance which we would all like to have in terms of our private communications. The company that conveys that message to the other person—the company in the middle—has no ability to see that message. The communications provider has provided that as a service because it is believed that that is what customers want.
Not all communications providers do that. Some provide a service where it is clear—it says so on the tin—that they will have the option to be aware of what is in the message because they use that to sell advertising. However, not all communications providers operate on that basis. The purpose of that encryption arrangement is to ensure that the data are protected by means of encryption against outsiders looking at them. The encryption key is held only by the person who sends the message and the person who receives it. Nobody else in between has that capacity. The potential implication of that is that the communications provider cannot find a way to discover the content of such a message, even if it wanted to and even if required to do so by the Government.
My Lords, I will speak to our Amendments 252 to 254 and the other amendments in this group. To save the noble Lord, Lord Rooker, having to get to his feet, this one is from Apple.
As the noble Lord, Lord Harris of Haringey, just outlined, it is essential that end-to-end encryption is not compromised by technical capability notices. I anticipate that the Minister might say that Clause 231(3)(c) covers this in that it would not be technically feasible for the operator to remove electronic protection of this nature, but we support this amendment and believe that it needs to be explicit in the Bill. However, we do not believe that this amendment covers other forms of encryption. Our Amendment 252 is intended to protect UK operators from the real or perceived disadvantage they would be placed under if technical capability notices required them to make modifications that would make their product or service less secure than overseas operators, who may not be subject to or may refuse to comply with a similar technical capability notice.
Similarly, Amendment 253 is intended to prevent a technical capability notice stopping UK operators from innovating to improve the levels of security or encryption provided by their products and services in a way that would disadvantage them against overseas operators, which may not be subject to or refuse to comply with a similar technical capability notice.
Amendment 254 is intended to deal with the criticism of our amendment in Committee by the Minister, who said that he believed that it,
“would remove the Government’s ability to give a technical capability notice to telecommunications operators requiring them to remove encryption from the communications of criminals, terrorists and foreign spies”.—[Official Report, 13/7/16; cols. 272-73.]
This new amendment makes it clear that technical assistance can be given to enable interpretation and deciphering provided that it does not open the door to unauthorised access to encrypted materials by criminals, terrorists and foreign spies—essentially, what the noble Lord, Lord Harris, just said.
Amendment 252A, in the name of my noble friend Lord Strasburger, is an attempt to combine all the other amendments in this group into a much better-worded amendment. I look forward to hearing from him why this might be the case.
My Lords, I shall rise to that opportunity. Amendment 251, in the name of the noble Lord, Lord Harris, and my noble friends Lord Paddick and Lady Hamwee, addresses one particular kind of encryption—namely end-to-end encryption—and it is very good as far as it goes, which is end-to-end encryption. My own Amendment 252A is also in this group and is complementary to Amendment 251. It is, in my humble opinion, a neater way of dealing with encryption that is not end-to-end encrypted than the combination of the other amendments in this group: Amendments 252, 253 and 254. It is an alternative to them.
We have been around the block many times on the subject of encryption in the context of Clauses 229 to 231. It has come up several times in our debates on the Bill, as well as in questions in this House and in the Joint Committee on the Bill. Yet we are no closer to a clear and unambiguous understanding of the Government’s position on this vital issue, as the noble Lord, Lord Harris, has so eloquently said.
It might help if we start from common ground. I doubt that any noble Lord, myself included, would deny the authorities the option of requiring an operator to decrypt a communication where: the operator already possesses the capability to do so; the sender or receiver of the communication is genuinely suspected of committing or planning a serious crime; and the appropriate process has been followed and the action has been judged necessary and proportionate by a judicial commissioner. I do not think that anybody would argue about that.
I believe there is more common ground. Ministers have repeatedly confirmed that the Government fully accept that many uses of the internet that are now an essential part of everyday life, both for individuals and for large organisations, cannot possibly continue to happen without the security provided by unbreakable encryption.
If we take those two points as read, we are left with two questions about what happens if the operator is not able to decrypt the communication. The first is: should the Secretary of State be able to force an operator to redesign its product so that in future its encryption has a weakness that permits the operator, or perhaps GCHQ, to read a suspect’s messages? The other question is: should the Secretary of State have the power to prevent an operator introducing new or modified encryption services which neither the authorities nor the operator can break? The answer to both those questions is an unequivocal, “No, the Secretary of State should not have those powers”, and noble Lords will be hard pressed to find a single cryptography specialist who has a different view. If the Government concur, as I hope they do, they should have no problem accepting Amendments 251 and 252A, which would remove the ambiguity in the current drafting.
My Lords, if I could be convinced that the same rules applied everywhere on the globe—because we are talking about a global function—in respect of the rule of law, freedom, transparency and privacy protection, then I might have a bit of sympathy with the business operators, as we will call them.
I had the privilege of being among those serving on the RUSI panel. We had a discussion with the providers, but they did not all want to come and sit round the table at the same time—I recall two or three sessions—because they are competitors. We put it to them—it was not original; it had come up elsewhere—that not one of these companies, whether Apple, Google, Facebook, Twitter, Yahoo or Microsoft, would ever have been able to start what is now their global business in countries such as Russia, Iran and China. Yet they have become global and make enormous profits, although I will not go into the issue of them paying their taxes.
These providers hide behind the fact that the countries where they are able to start and function have the rule of law and are democracies where you can challenge Governments in the courts and get redress, yet they then go and operate in countries where they cannot do that. If they all said, “When we operate in China, we’re going to produce all our phones fully encrypted, exactly as we do for everybody else. The Chinese Government are allowing us to close end to end. They don’t want to know what their citizens are saying”, then fine, but I do not believe that that is the case, and that is part of the problem.
My noble friend Lord Harris touched on the issue of other Governments, but we can legislate only for the UK. I fully understand that, yet half of an email sent from my office upstairs to a colleague here might be split and end up travelling through the rest of Europe or America or half-way round the world. That is how the system works. Just because you are emailing someone in this country from within this country, you cannot guarantee that the entire message will stay in this country while it is being whizzed round the world. The system does not work as I originally thought it did. So we can legislate only for this country and messages get split up around the world.
The fact is that the business plans and business operations of these companies depend on open, transparent and democratic countries with the rule of law, yet they are willing to work in countries where there is no rule of law and where there are corrupt regimes, such as in Russia, or undemocratic regimes, as in China. These are countries with huge populations and the companies can do business there according to a different business plan from the one that applies here. From the point of view of those who are there to protect us, that has to lead to a suspicion that at some point we might need a bit more information than we have and that we might need to ask for that to be provided.
I take second place to no one on the protection of privacy, but the fact is that you cannot discuss this issue just in the context of the UK or Europe; it is global, and the rules do not apply equally across the globe. If we take that on board, I think we ought to have a fair degree of sympathy with how the Government will operate these measures.
I have listened to other people and have read more about this matter since finishing our work on the RUSI panel, and the fact is that there is a great reluctance to have these powers. In a democracy there is an incredible reluctance for private information to be treated in this way, but at the end of the day there will be proportionality and our people will be tested on the need for these powers. One of the raisons d’être of the Bill is to put in second and third checks, so those with the powers will be watched and the watchers will be watched, and that is how we can give the public confidence. I do not think that we ought to write the Bill to suit the business operators’ original business plans, because they are not implementing them on an equal basis across the globe. Therefore, I hope that the Government will reject these amendments.
Before my noble friend sits down, to be honest I think that he has slightly misunderstood the point that has been made. I am not putting this forward because of the business models of particular companies; I am proposing it because of the inherent weakness that could conceivably be created. His argument, if I understood what he just said, is that because Russia or China may require, or may force because the business there is so valuable, a communications service provider to put in one of these back doors, therefore we need to have the same facility. The point is that, because it is a global provision, if a back door is built in—because Russia or China or wherever else has demanded it—then a technical capability notice would operate because the operator would have that existing facility. That is precisely the circumstance in which a technical capability notice could be served. This amendment seeks to exclude a requirement from our Government that it should be created at our behest, which other people would then use.
I take on board what my noble friend is saying. I fully accept the distinction he makes but, basically, although I am a customer of some of these companies, I do not trust them—they will tell us that this has been built in and is secure, but do deals with those other regimes.
My Lords, there have not been very many points in the course of this legislation on which I have agreed with the noble Lord, Lord Strasburger, but on this point I do. Amendment 252A raises a very interesting and important point.
Although I am absolutely in favour, as you would imagine, of the Government having the opportunity to access the communications of anybody who is a threat to us—due to terrorism, criminal activities or anything of that sort—there is a competing national security issue here of this country having effective cybersecurity. We have seen the way in which hostile Governments have been seeking to intervene in the American elections, and we have seen all sorts of attempts by hostile states, criminal groups and others to use cyber weaknesses to take forward hostile agendas. Therefore, there is a genuine national security interest in ensuring that, as far as we can, our citizens can communicate securely and privately when they are not going about mischievous business.
The idea that we should take into consideration the requirement not to place non-targeted customers or others at additional security risk is an entirely legitimate one, and I am very interested to hear how the Minister would want to interpret this. We have competing national security issues here and it is a point well made.
My Lords, we have had some rather good discussions with the tech companies. In Committee, we put in some of the amendments that they suggested to us, and some of the government amendments we have been dealing with over the past few days reflect that. I thank the tech companies for their very responsible attitude in continuing discussions with the Government over this period. Certainly with us they have been open, flexible and fairly straight as to what is possible and what the dangers are for them—for example, and as we have discussed, whether a weakness in end-to-end encryption could actually undermine the security that banks and others rely on in their systems—and for their clients, public confidence and national security. The companies recognise that they have a duty of care and loyalty to their customers, while fully respecting the law of the land in which they operate and the legal demands on their staff, wherever they are located.
In their discussions with us, companies have sought clarity that they will not be asked, effectively, to create a new system that would breach end-to-end encryption. They need this clarity for their shareholders and customers’ peace of mind because the reality is that they could never be forced to create a new computer program to hack their own security. I for one cannot imagine the noble Earl, Lord Howe, or anyone else standing over a hapless computer programmer shouting, “Break into it!”, if that company did not want to do it or the computer genius was on a go-slow that day. The idea that you could force somebody to create a program that the company and the employee did not want to is probably not possible.
Given that, the reality is that the things the Government want to ask will happen only when there is a good working understanding between the security services and the company. Therefore, if the tech companies want this clarity as set out in Amendment 251—as we know they do—our interest is to hear from the Minister just what the obstacles are to giving them the clarity that they seek.
My Lords, I hope that the House will allow me to speak at somewhat greater length than usual in responding to these amendments. I recognise the concern that lies behind them and I also recognise that, although we debated the Bill’s provisions on encryption in Committee, there is a need to correct a number of misconceptions that have been expressed and to set out the reality of the Government’s position on encryption. I would also like to make clear what the provisions in the Bill do and, crucially, what they do not do, and to explain why these provisions are so important to our law enforcement and intelligence agencies. I hope that by, setting this out, I can reassure noble Lords that the amendments are not necessary.
As we have made clear before, the Government recognise the importance of encryption. It keeps people’s personal data and intellectual property secure and ensures safe online commerce. The Government work closely with industry and businesses to improve their cybersecurity. For example, GCHQ plays a vital information assurance role, providing advice and guidance to enable government, industry and the public to protect their IT systems and use the internet safely. Indeed, the director of GCHQ said in March that he is accountable to the Prime Minister just as much, if not more, for the state of cybersecurity in the UK as he is for intelligence collection.
In the past two years, the security and intelligence agencies have disclosed vulnerabilities in every major mobile and desktop platform, including the big names that underpin British business. You do not have to take the Government’s word for that. In September 2015, Apple publicly credited the information assurance arm of GCHQ with the detection of a vulnerability in its operating system for iPhones and iPads, which could otherwise have been exploited by criminals to disrupt devices and extract information from them. As a result, this vulnerability could be fixed.
The assertion that the Government are opposed to encryption or would legislate to undermine it is fanciful. However, the Government and Parliament also have a responsibility to ensure that our security and intelligence services and law enforcement agencies have the capabilities necessary to keep our citizens safe. Encryption is now almost ubiquitous and is the default setting for most IT products and online services. While this technology is primarily used by law-abiding citizens, it can also be used—easily and cheaply—by terrorists and other criminals. Therefore, it can only be right that we retain the ability, as currently exists in legislation, to require a telecommunications operator to remove encryption in limited circumstances, subject to strong controls and safeguards. If we do not provide for this ability, then we must simply accept that there can be areas online beyond the reach of the law where criminals can go about their business unimpeded and without the risk of detection. That would be both irresponsible and wrong.
That is our starting principle, and it is one that we share with David Anderson QC. I have quoted this before, but he stated in his investigatory powers review, A Question of Trust:
“My first principle is that no-go areas for law enforcement should be minimised as far as possible, whether in the physical or digital world”.
This principle was also shared by the Joint Committee on the draft Bill and the Science and Technology Committee, both of which recognised that, in tightly prescribed circumstances, it should remain possible for our law enforcement agencies and security and intelligence services to be able to access unencrypted communications or data. That is exactly what Clauses 229 to 234 of the Bill provide for: strong safeguards to ensure that obligations to remove encryption can be imposed only in limited circumstances and subject to rigorous controls.
Clause 229 enables the Secretary of State to give a technical capability notice to a telecommunications operator in relation to interception, communications data or equipment interference. As part of maintaining a technical capability, the Bill makes clear at Clause 229(5)(c) that the obligations that may be imposed on an operator by the Secretary of State can include the removal of encryption. Before a technical capability notice is given, the Secretary of State must specifically consider the technical feasibility and likely cost of complying with it. Clause 231(4) provides that this consideration must explicitly take account of any obligations to remove encryption.
The Secretary of State must also consult the relevant operator before a notice is given. The draft codes of practice, which were published on 4 October, make clear that should the telecommunications operator have concerns about the reasonableness, cost or technical feasibility of any requirements to be set out in the notice, which of course includes any obligations relating to the removal of encryption, it should raise these concerns during the consultation process.
We have also amended the Bill to make clear that the Secretary of State may give a technical capability notice only where he or she considers that it is necessary and proportionate to do so, and, under Clause 230, that decision must also now be approved by a judicial commissioner, placing the stringent safeguard of the double lock on to any giving of a notice to require the removal of encryption. Clause 2 of the Bill, the privacy clause, also makes explicit that, before the Secretary of State may decide to give a notice, he or she must have regard to the public interest in the integrity and security of telecommunications systems.
In addition, a telecommunications operator that is given a technical capability notice may refer any aspect of the notice, including obligations relating to the removal of encryption, back to the Secretary of State for a review. In undertaking such a review, the Secretary of State must consult the Technical Advisory Board in relation to the technical and financial requirements of the notice, as well as a judicial commissioner in relation to its proportionality. We have amended the review clauses in the Bill to strengthen these provisions further. Where the Secretary of State decides that the outcome of the review should be to vary or confirm the effect of the notice, rather than to revoke it, that decision must be approved by the Investigatory Powers Commissioner.
The Bill also makes absolutely clear that, in line with current practice, obligations imposed on telecommunications operators to remove encryption may relate only to encryption applied by or on behalf of the company on whom the obligation is being placed. That ensures that such an obligation cannot require a telecommunications operator to remove encryption applied by other companies to data transiting their network. As we have already outlined, we have also now tabled a government amendment that would further strengthen the Bill’s provisions on technical capability notices. This amendment makes clear that the Secretary of State may vary a notice only where they consider that it is necessary and proportionate to do so. The amendment also makes clear that, in circumstances where a notice is being varied in such a way that would impose new obligations on the operator, the variation must be approved by a judicial commissioner.
Furthermore, obligations imposed under a technical capability notice to remove encryption require the relevant operator to maintain the capability to remove encryption when it is subsequently served with a warrant, notice or authorisation, rather than requiring it to remove encryption per se. That means that companies will not be forced to hand over encryption keys to the Government. Such a warrant, notice or authorisation will be subject to the double lock of Secretary of State and judicial commissioner approval, and the company on whom the warrant is served will not be required to take any steps, such as the removal of encryption, if they are not reasonably practicable steps for that company to take. So a technical capability notice could not, in itself, authorise an interference with privacy. It would simply require a capability to be maintained that would allow a telecommunications operator to give effect to a warrant quickly and securely including, where applicable, the ability to remove encryption.
That is an enormously long list of safeguards. Indeed, it is difficult to think what more the Government could do. These safeguards ensure that an obligation to remove encryption under Clause 229 of the Bill will be subject to very strict controls and may be imposed only where it is necessary and proportionate, technically feasible and reasonably practicable for the relevant operator to comply. Let me be clear: the Bill’s provisions on encryption simply maintain and clarify the current legal position, and apply strengthened safeguards to those provisions. They will mean that our law enforcement and security and intelligence agencies maintain the ability to require telecommunications operators to remove encryption in very tightly defined circumstances.
I would also like to make absolutely clear what the Bill does not provide for on encryption.
Could the Minister help those of us who are not deeply technical in these matters? We fear that circumstances by their nature cannot be technical and defined. In at least some cases, the consequences of serving a notice would be that the operator would have to create a significant weakness, which would apply far beyond the objective for which the notice was being served, and the operator would have to say in future to its customers, “This system is not as strong as we would like it to be”.
We come back to the test of reasonable practicability here. I am about to come on to what the Bill does not provide for on encryption and I hope that this will help the noble Lord.
The Bill does not ban encryption or do anything to limit its use. The Bill will not be used to force providers to undermine their business models, to create so-called back doors or to compromise encryption keys. It will not be used to prevent new encrypted products or services from being launched and it will not undermine internet security.
I am very grateful for the detailed exposition that has been given. The Minister says that the Bill will not be used to do those things. Can he confirm that it cannot be used to do those things?
My Lords, some noble Lords have suggested the Bill’s provisions cause a weakening in encryption, which I think is the central point that the noble Lord is getting at. Many of the biggest companies in the world rely on strong encryption to provide safe and secure communications and e-commerce, but retain the ability to access the content of their users’ communications for their own business purposes, such as advertising, as we have heard. These companies’ reputations rest on their ability to protect their users’ data. This model of encryption can, and does, maintain users’ security. I do not think that anyone would dispute that.
Before I come on to the individual amendments, it would be helpful to address a number of specific points that were raised in relation to encryption. There was a suggestion that a company should never be asked to do something that it does not already do. Such an approach would of course, at a stroke, remove our ability to use any of the powers in the Bill, including carrying out any interception of terrorists’ and serious criminals’ communications, because companies do not do this in the normal course of their business.
There was a suggestion that equipment interference would do away with the need for these provisions. It will not. Equipment interference is no substitute for having a company’s assistance. Even if it were, there are only a very small number of very clever people who are able to carry out equipment interference. There will never be the capacity to deploy them on each and every operation.
Finally, there was a suggestion that encryption is not a problem for the security and intelligence agencies. The heads of those agencies have repeatedly made clear that ubiquitous encryption is one of the most difficult challenges they face.
I now turn to the individual amendments, because I hope that this will clarify the picture further. Amendment 251 seeks to preclude an obligation to remove encryption from being imposed under a technical capability notice in relation to end-to-end encrypted services. I hope that the points I have already made make clear why the proposed amendment is not necessary and indeed why it is not desirable. As I have set out, the Government recognise the vital importance of encryption. Nothing in the Bill does anything to limit its use, and that of course includes the use of end-to-end encryption. But I have also set out the dangers of creating a guaranteed safe space online for those who would seek to do the public harm such as terrorists and other serious criminals, and I am afraid that that is exactly what this amendment would do. The amendment seeks to make explicit provision in law for there to be certain online services that criminals can use to go about their business unimpeded with no fear of being caught. That is not a position that any responsible Government or, I hope, Parliament could support.
What we must ensure is that the Bill enables us to work collaboratively with individual telecommunications operators to establish what steps are reasonably practicable for them to take, considering a range of factors including technical feasibility and likely cost. Any decision will have regard to the particular circumstances of the case, recognising that there are many different models of encryption, including many different models of end-to-end encryption, and that what is reasonably practicable for one telecommunications operator may not be for another.
As I have already said, this is not about asking companies to undermine their existing business models; it is about working with them to find a solution to ensure both that their customers’ data remain secure and that their services cannot be exploited by individuals who pose a threat to the UK. So in answer to the question put by the noble Lord, Lord Harris, I can confirm that these provisions cannot be used to introduce back doors or undermine internet security.
My Lords, if the noble Earl is so confident that none of the unintended consequences listed in Amendment 252A can occur, and that the Government do not want them to occur, what is his objection to putting them into the Bill?
We already have a wide range of safeguards which I have listed. I do not see that it is necessary to go down the road the noble Lord is advocating because of the dangers that I have pointed out. These amendments would create safe spaces which I am sure that neither he nor any noble Lord would desire to occur.
My Lords, I am enormously grateful to the noble Earl for his detailed response and for reiterating the welcome and voluminous safeguards that are set out in the Bill. They are important and valuable, and they give me confidence about the context of the whole Bill. However, the argument with which he concluded does not quite hold together and there is an elision between different issues. The noble Earl has given an absolute assurance, I think on the basis of a piece of paper that was handed to him, that it cannot be used to require a communications service provider to build a back door or to create one in a future area. But then he said that we must not put in the Bill something that creates a safe space. Either the Government’s position is that this cannot be used to require a company to produce a back door, in which case the safe space exists and presumably the Government are not happy with their own legislation, or it is the case that the Bill could require a communications service provider to build such a back door.
We have already heard from the noble Lord, Lord Evans of Weardale, that what we are trying to do here is balance two national security concerns: the national security concern to prevent terrorism and so on and the national security concern about making it slightly easier for cybercriminals. These are very important issues. If the Government are clear that, as a result of the Bill, a technical capability notice could not require an operator to build a back door that would otherwise not exist, it is important to set that out in the Bill. If we are in a position where techUK says—as it has in the briefing it circulated to me and, I am sure, to other noble Lords—that this is ambiguous, perhaps it is the responsibility of the Government to remove that ambiguity and make the position clear. I do not really want to have to divide the House on this matter, so between now and Third Reading, is the noble Earl prepared to turn the unequivocal assurance he has given that it cannot be used in this way into an amendment to the Bill that will remove that ambiguity?
With the leave of the House, I hope I can help the noble Lord on this because I do not believe that the Bill is contradictory. First, the term “back door” has been used, but I do not think that is a helpful or accurate way of describing the Bill’s provisions. “Back door” is in everyone’s judgment a loosely defined term. It is used incorrectly to imply that the Bill would enable our law enforcement, security and intelligence agencies to gain unrestricted access to a telecommunications operator’s services or systems, thereby undermining the security of those services—to force that to happen. That is absolutely not the case. The Bill enables our agencies to require telecommunications operators to remove encryption themselves, only in tightly defined circumstances: where they have applied the encryption themselves; where it has been applied on their behalf; where it is reasonably practicable for them to remove it; and where doing so is required to comply with a relevant warrant, notice or authorisation.
I come back to the point I made earlier. This is about the Government being able to sit down with companies and reach agreement with them on the basis of what is reasonably practicable, affordable and so on. It would not be responsible for any Government to deny themselves the possibility of doing that and discussing what in all the circumstances is reasonably practicable for the company, and for the company to agree to do it.
Again I am grateful to the noble Earl. I do not think anyone here has misunderstood the point that this is not about giving the Government uninterrupted access. It is about requiring companies to create a facility so that if they are asked, after all the suitable warrants have been gone through and all the safeguards have been fulfilled, to gain information and pass it back to the Government. I accept that that is the position and that is what is intended here. However, the Minister has still not been unequivocal on whether technical capability measures could require such a facility to be created, so that, in those circumstances and with all those safeguards in place, something could be done. It is a critical issue that we need to clarify. Otherwise, we do not know where we stand as far as the amendment is concerned. The Minister needs to provide the House and the IT industry with as much clarity as he can on this point, because the danger is that it will become the subject of continual argument.
Were the Bill to be amended by any of the amendments in this group, the Government would still have the option to say that they were minded to serve a technical capability notice on a particular company. That would then trigger a series of discussions, because it is what the Bill provides for, and a communications service provider might come back at that point and say, “Look, we literally cannot do it. We do not have the facility”. However, it is not clear whether the Government could none the less say, “Well, we understand that, but we are requiring you to do it”. The question then is: what is or what is not feasible? I happen to believe that some of the biggest communications service providers in the world have more computing expertise than any nation state. If they are told, “You are legally required to do this”, they could do it; they could find a way of making it happen. We have to be explicit as to what the Government’s expectation is. Are they saying, “No, that is not what we are requiring”, or are they saying, “Well, we might”? If they are saying, “We might”, that clarifies the position, if not helpfully. If they are saying, “No, we are not”, which is what the Minister said earlier, perhaps we could put that in the Bill—if not in the form of words proposed, then in some form of words that the Government could craft between now and next week. That would be a helpful way forward and provide absolute clarity as to the extent to which technical capability notices could be served. If I am not able to get that assurance from him—I appreciate that bits of paper have been flying backwards and forwards between him and the Box—we are in a very difficult position.
I can state categorically to the noble Lord that it is absolutely not the case that the Bill would force a company to insert a back door, thereby undermining internet security. We might ask a company in certain circumstances to decrypt particular data if it was reasonably practicable and feasible for them to do so.
My Lords, I understand that that is the case; that is, if they have the encryption key—we will not use “back door”; we will find another form of words—and the capability to do it, and it is not too complicated and all the relevant warrants are in place, yes, they will do that. As I understand it, most tech companies are perfectly understanding of that and willing to do it. The question is whether, if the Government were presented with a situation they were concerned about, they could say to one of the biggest communications service providers in the world, “We are asking you to build something which is not there at the moment, but we’ll provide that facility for those circumstances that might arise in the future when we’ve gone through all the relevant warrants and so on”. I am looking for an assurance from the Minister that that is not sought here, because of the dangers that we have already discussed. If he wishes, I can reiterate the question to give the Minister the opportunity to read the piece of paper that has just arrived.
Of course, a technical capability notice can require a new capability to be built; that is what they are there for. If it was neither practicable nor feasible, they would not have to do it. The problem here is that it is very difficult to generalise, because any decision about these things would have to have regard to the particular circumstances of the case. As I said, there are many different models of encryption, including many different models of end-to-end encryption. Any decision has to recognise that what is reasonably practicable for one telecommunications operator may not be for another. That is why I have referred repeatedly to the need for the Government and industry to have that easy interchange which they do at the moment. It is important to emphasise that these powers already exist in law today. We should not do anything that undermines the basis for the constructive discussions that we are having.
The Minister reminds us that the ideal arrangement is one of easy interchange and discussion—I understand that that carries on and works very well. He is right to say—this is why the wording of the current legislation is ambiguous and therefore a problem—that building a technical capability could mean simply putting in a piece of equipment, which means that, at the point at which the Government ask, having gone through all the voluntary processes, it is quite a straightforward matter to provide the information that the Government have legitimately and lawfully requested. That is one definition of technical capability.
What I want to know is whether “technical capability” could apply to a very secure end-to-end encryption process which no communications service provider could break but where, if they devoted thousands of person hours in California or wherever they operate from, they could develop something which might do that. If that is what the Bill is saying, we need to know.
I accept that it would not be reasonably practicable; it would also be very expensive—as I understand the Bill, the Government would have to pay for it and I am sure that technical experts in California or wherever might be very expensive. If that is the case, and if it is not possible to write it into the Bill—I would have thought it could be—it would be helpful for the Minister to write and make very clear what the Government’s intentions are in that regard and confirm that such circumstances are precluded by the Bill. If the Minister is prepared to do that, I am prepared not to press the amendment to a vote.
I think I have made the Government’s position as clear as I possibly can and I am not sure what I can do to amplify the remarks I have already made. While I want to be as helpful as possible to the noble Lord, I am struggling to see how a letter from me would make the position clearer.
I understand the Minister’s dilemma and I am sure that a letter from him to me would have far less force than the words appearing in Hansard. I appreciate that the courts can look at the debates in Hansard to try to interpret them. However, I ask that the Minister spends the next few days just thinking about some further modification to the Bill to make sure that this ambiguity, which I think genuinely exists—because techUK tells me so—is cleared up. On the basis that I am sure he will spend his waking hours between now and next Monday thinking about precisely these matters, I beg leave to withdraw the amendment.
My Lords, I shall also speak to Amendment 258B. The powers in the Bill are significant, as are the checks and auditing measures, but the Government accept, in providing for a review of the operation of the Act and in anticipating that a Select Committee of one or both Houses of Parliament will also want to look at the operation of the Act, that a full, independent review is both necessary and desirable. The Bill sets the initial period at five years and six months and requires the Secretary of State to prepare a report within six months of the initial period. These amendments would ensure that before any Government are held to account by the electorate at a general election, the electorate know what that Government have used the powers in the Bill for.
Amendment 258A adds to the requirement to produce a report within six months of the initial period that the report must be produced at least once during each Parliament. Amendment 258B reduces the initial period from five years and six months to two years and six months, to ensure that the actions of the present Government are clear to the electorate at the next general election, subject, obviously, to the current Government remaining in office for the full term. I beg to move.
There is obviously going to be a desire to know how the Act is operating and the Bill does provide for a report from the Secretary of State, but it is, let us just say, some time after the day on which the Bill becomes an Act. Assuming that the Government do not accept the amendment, I hope that in responding they will set out, or give some indication, of the bodies and committees which will look at how the Act is operating, including whether it is doing so in line with the terms of the Bill. In that, I include the codes of practice and, particularly in light of the last discussion we had, the statements on the record from the Government in the two Hansards during the passage of the Bill.
My Lords, I shall add some points to what my noble friend has just said. During our rather long deliberations this evening and afternoon, I went to the Library to look up the definition of “draconian”. It seems to me to be very harsh, very severe. Apparently, it goes back to ancient Greece, where Draco was the statesman who decided that every single crime would be dealt with by a death sentence. It is not a good description of the Bill and the shadow Home Secretary is unfair and, I think, mischievous in what she said, because the Bill is significant, extremely serious and very difficult. It tries to balance the importance of security in our country, which was discussed at some length today, and our liberties.
I have to say that in 30 years in Parliament I do not think I have seen a Bill which has been scrutinised quite as well as this—not just by the Joint Committee that we were on in November and December but by other committees as well and, indeed, what we have seen in this House and the House of Commons. Nevertheless, the Joint Committee, at the very end of its deliberations, knowing full well that there would be an enormous amount of scrutiny, looked at what could happen in terms of review of the Bill. The Information Commissioner, indeed, gave evidence to the Joint Committee indicating that he thought there should be a sunset clause. The then Home Secretary, who has gone on to greater things, indicated that this was not appropriate, but the committee believed that parliamentary review of the operation of what will then be an Act should take place within six months after five years. That has been incorporated into the Bill and it is the most important type of scrutiny that could happen, because that would be a Joint Committee of both Houses of Parliament, one hopes, which could look at how the Bill has operated. The reason the Joint Committee said that was because of the hugely grave and serious nature of the Bill—not just because of the way it touches on the liberties of the subject, but protecting the subject as well.
My Lords, we remain sympathetic to the desire for ongoing scrutiny of the Bill, and this is already provided for. In these circumstances we suggest that these amendments are not necessary. The Bill requires that the operation of the Act will be reviewed after five years, which is an entirely appropriate period. It is also consistent with the recommendation, as indicated, of the Joint Committee that scrutinised the draft Bill. We must ensure that, before a review takes place, all the Bill’s provisions have been in effect for a sufficient period that a review is justified and can be meaningful. A review after three years, as provided for by Amendments 258A and 258B, runs the risk that this would not be the case.
We also fully expect the review after five years to be informed by a report of a Joint Committee of Parliament, in line with the recommendation made by the Joint Committee. In addition, concurrent with such a review the Intelligence and Security Committee of Parliament would have the opportunity to assess the more sensitive aspects of the operation of the Act. Let us remember that, in addition, the exercise of the powers provided for under the Bill will of course be subject to the ongoing oversight of the Investigatory Powers Commissioner, who will be obliged to make an annual report to the Prime Minister.
The Government have listened to the previous debates in Parliament and amended the Bill to ensure that the Investigatory Powers Commissioner must, in particular, keep under review and report on the operation of safeguards to protect privacy. Furthermore, the Investigatory Powers Commissioner’s reports must be published and laid before Parliament, providing Parliament with ongoing scrutiny of the operation of the Act. Accordingly, I invite the noble Lord to withdraw the amendment.
My Lords, I am grateful to the noble and learned Lord for his explanation. We are still of the view that at least once every Parliament, before a general election is called, a Joint Committee of both Houses of Parliament, as suggested by the noble Lord, Lord Murphy, should look at what the Government have been up to during their time in office so that the electorate are fully aware of how the Government have used the Bill. However, at this stage I beg leave to withdraw the amendment.
I apologise to the House both that this is a rather inelegantly presented amendment and that it comes at a rather odd point in the Bill, but it covers a matter that was brought to our attention only very recently. I put thanks on the record to the organisation Reprieve for spotting the point. It would more naturally have come with clauses we debated on Monday, but we did not want to table a manuscript amendment for that.
In 2013, the Intelligence Services Commissioner was given additional functions by the then new Section 59A of RIPA. The commissioner is required, so far as directed by the Prime Minister, to keep under review the carrying out of any aspect of the functions of the intelligence services, their heads and the Ministry of Defence and forces engaging in intelligence activities.
My Lords, this amendment is unnecessary. The Government have already made it clear that the new Investigatory Powers Commissioner will bring together the existing responsibilities of the Intelligence Services Commissioner, the Interception of Communications Commissioner and the Chief Surveillance Commissioner. That includes oversight of the consolidated guidance on the detention and interviewing of detainees. In addition, the Investigatory Powers Commissioner will have a bigger budget and a dedicated staff of commissioners and inspectors, as well as independent legal advisers, to ensure that the highest levels of independent scrutiny are maintained. In these circumstances, I invite the noble Baroness to withdraw her amendment.
My Lords, I chose the last words of my remarks quite carefully because it is the statutory basis of the current arrangements that is so important, which is why we raised it at this—I acknowledge—late stage. Obviously, I am glad to have these assurances. They do not answer my question but that position is now on the record. I beg leave to withdraw the amendment.
“Confidential journalistic material | Section (General definitions: “journalistic material” etc.)(6) and (7)” |
“Journalistic material | Section (General definitions: “journalistic material” etc.)(2) to (5)” |
“Premises | Section 239 (1)” |
“Statutory (in relation to any function) | Section 239(1)” |
“Technology Advisory Panel | Section 239(1)” |
“Anti-terrorism, Crime and Security Act 2001 | Section 116(3).” |