Wednesday 2nd September 2020

(3 years, 7 months ago)

Grand Committee
Read Hansard Text
Moved by
Baroness Williams of Trafford Portrait Baroness Williams of Trafford
- Hansard - - - Excerpts

That the Grand Committee do consider the Investigatory Powers (Communications Data) (Relevant Public Authorities and Designated Senior Officers) Regulations 2020

Relevant document: Special attention drawn to the instrument by the Secondary Legislation Scrutiny Committee, 13th Report

Baroness Williams of Trafford Portrait The Minister of State, Home Office (Baroness Williams of Trafford) (Con)
- Hansard - - - Excerpts

My Lords, these regulations, and the Functions of the Investigatory Powers Commissioner (Oversight of the Data Access Agreement between the United Kingdom and the United States of America and of functions exercisable under the Crime (Overseas Production Orders) Act 2019) Regulations 2020, are both made under the Investigatory Powers Act 2016. That legislation brought together powers available to our public authorities to obtain communications and data about communications, powers that are vitally important to their efforts to tackle crime and protect our citizens. It also created extensive and world-leading safeguards, including a powerful new Investigatory Powers Commissioner who provides independent oversight and authorisation of the use of these powers.

As the operational requirements of our public authorities continually evolve, it is vital that the use of the investigatory powers can adapt in response, within the strict parameters that Parliament agreed during the passing of the Investigatory Powers Act. When we do adapt the use of the investigatory powers, it is equally important that the appropriate safeguards can be applied. The regulations we are debating today collectively represent this adaptation in action.

I turn first to the Functions of the Investigatory Powers Commissioner (Oversight of the Data Access Agreement between the United Kingdom and the United States of America and of functions exercisable under the Crime (Overseas Production Orders) Act 2019) Regulations 2020. As I have previously informed the House, the agreement will allow UK public authorities, with the appropriate legal authorisation, to obtain data directly from US-based telecommunications operators for the purposes of preventing, detecting, investigating and prosecuting serious crime.

It is a requirement of the agreement to ensure an appropriate level of audit and oversight of its use. Given that the agreement has been designated under the Investigatory Powers Act 2016 and that almost all the authorities using the agreement fall under the Investigatory Powers Commissioner’s remit for aspects of their work already, it was decided that the commissioner and his team should oversee the UK’s use of the agreement.

The commissioner will, in accordance with the agreement, keep under review the compliance of UK public authorities with its terms. This will include the ex post facto review, by a judicial commissioner, of communications data authorisations and certain modifications to targeted interception warrants that would not otherwise be specifically subject to a commissioner’s review. This ex post facto review must be conducted as soon as is reasonably practicable, and no later than three months from when the authorisation is given.

In addition to the Investigatory Powers Act 2016, the agreement has been designated under the Crime (Overseas Production Orders) Act 2019. These regulations therefore amend the Investigatory Powers Act to provide the statutory basis for the commissioner to perform his role in relation to the agreement and to oversee the use of overseas production orders under the agreement. The commissioner is supportive of this and his team have recruited additional resources in preparation for the agreement coming into use. Although, as I have described, these regulations require the commissioner to perform his review of public authorities’ compliance in accordance with the agreement, the commissioner, as an independent officeholder, will continue to discharge his functions of inspection, investigation and audit as he sees fit.

The Government remain resolutely committed to the independence of the Investigatory Powers Commissioner. The Investigatory Powers Communications Data (Relevant Public Authorities and Designated Senior Officers) Regulations 2020 amend Schedule 4 to the Investigatory Powers Act to add five public authorities to the list of bodies which can legally obtain communications data, and they make minor amendments to bring certain role titles and organisation names into line with the current terminology.

Communications data includes the “who, when, where and how” of a communication but not the content: the “what” was said or written. It includes the method and way in which one person or thing communicates with another person or thing. Access to this data is a crucial investigative tool for a variety of law enforcement bodies and has a range of operational uses.

The five public authorities that we propose to add to Schedule 4 by these regulations have each demonstrated through extensive consultation with the Home Office and the Investigatory Powers Commissioner’s Office that access to the data is now necessary and proportionate to their operational requirements and statutory duties. The authorities are the Civil Nuclear Constabulary, which requires these powers to investigate threats to the most sensitive nuclear sites in the UK; the Environment Agency, in order to tackle serious organised waste crime; the Insolvency Service, in order to investigate and prosecute criminal wrongdoing connected to personal and company insolvencies; the National Authority for Counter Eavesdropping, in order to protect the Government from technical espionage attack from hostile state actors; and the Pensions Regulator, in order to investigate serious crimes associated with workplace pension schemes, including fraud and money laundering.

In short, without communications data access, these public authorities often cannot carry out their role of investigating crime effectively. By adding them to Schedule 4, they will be subject to the stringent safeguards that already govern the use of communications data. These include the independent authorisation of most requests by the Office for Communications Data Authorisations, a serious crime threshold for requiring certain types of communications data and inspections conducted by the Investigatory Powers Commissioner’s Office. The oversight, together with the communications data code of practice, ensures that requests for communications data are necessary and proportionate. Where it is no longer necessary and proportionate for a public authority to acquire communications data, the entry in Schedule 4 will be removed. Noble Lords will see that in the recent removal of the fire and rescue service.

In summary, the regulations we are debating relate to provisions already set out in the Investigatory Powers Act 2016. They will allow the use of investigatory powers by our public authorities to adapt to changes in their operational requirements as they respond to an evolving threat picture, while ensuring that the appropriate safeguards can continue to apply. I beg to move.

--- Later in debate ---
Lord Rosser Portrait Lord Rosser (Lab) [V]
- Hansard - - - Excerpts

We are not opposed to either of these two draft orders. The first of the two draft orders we are debating adds a further five additional public authorities to the list that are now deemed to have a “necessary and proportionate” requirement to obtain communications data, which is, of course, information about communications rather than what was said or written.

This power to obtain communications data is, according to an extra government factsheet memorandum explaining the purpose and effect of the draft instrument, on the basis that these five public authorities

“are increasingly unable to rely on local police forces to investigate crimes on their behalf”.

The five additional public authorities are the Civil Nuclear Constabulary, the Environment Agency, the Insolvency Service, the UK National Authority for Counter Eavesdropping and the Pensions Regulator. Can the Minister explain why it is that, in the light of cuts in police numbers since 2010, each of these five additional public authorities

“are increasingly unable to rely on local police forces to investigate crimes on their behalf”?

Could the Minister say whether this inability to investigate these crimes applies across all local police forces or only to some police forces, and if the latter, which ones?

We will support measures that cut crime and deal effectively and meaningfully with offenders. Can the Minister explain why the remedy is not to increase the capacity of local police forces so that they can investigate these crimes, rather than give powers to obtain communications data to civilians within these five public authorities? On the latter point about civilians, can the Government give a categorical assurance that this draft instrument does not lower the rank or seniority of designated officers and that there is no widening of the authority to exercise the powers here within the organisations covered by this or by previous orders?

The Explanatory Memorandum states that in deciding whether to grant these powers to the public authorities concerned, the Government consider the seriousness of the offences they investigate and the number of requests for data the public authorities each estimate they will make. Can these powers be used only in respect of serious offences or can they be used in respect of any offence? Can the Minister also say how many such requests for communications data each of the five additional authorities have estimated they will make and how that compares with the number being made currently by local police forces investigating crimes on their behalf? How do the estimates of the number of requests each of the five public authorities have said they will make compare with the number of requests being made by broadly comparable public authorities that already have these powers?

Currently, the public authorities that can obtain communications data under the provisions of the 2016 IP Act include, among others, intelligence agencies, law enforcement agencies, the Food Standards Agency, the Gambling Commission, the Prison and Probation Service, and the NHS Counter Fraud Authority. Can the Minister give details of which public authorities have already been given powers in relation to investigating crimes because increasingly they too cannot rely on local police forces being able to investigate crimes on their behalf? Can she also say if any public authorities for whom powers to obtain communications data have been sought have had that request declined by the Government? This point was raised by the noble Lord, Lord Paddick.

The IP Act sets out the circumstances in which various investigatory powers may be used and the safeguards that apply in relation to ensuring that any interference with privacy is strictly necessary, proportionate, authorised and accountable. Since the Government are not required to report on the operation of the Act until five and a half years from Royal Assent, what assurances can the Government provide now that the statutory safeguards in relation to interference with privacy are proving to be effective and are delivering in line with the intentions of Parliament? What views did the Investigatory Powers Commissioner express about the addition to the list of these five further public authorities, and did the commissioner have any reservations or other comments?

The second draft instrument provides the statutory basis for the Investigatory Powers Commissioner to have the required oversight of compliance by UK public authorities on access to electronic data in relation to serious crime, as provided for in the 2019 international agreement between the UK and USA and exercisable under the Crime (Overseas Production Orders) Act 2019 and the IP Act 2016. According to the Explanatory Memorandum, this arrangement, which presumably relates to the IPC providing independent oversight of UK activity under the agreement with the USA, has been agreed with the US Department of Justice. However, to avoid any misunderstanding, can the Minister place on record in her response exactly what it is that has been agreed with the US Department of Justice? Can she also place on record in her response what arrangements the US Department of Justice has agreed with the UK in relation to independent oversight of USA activity under the agreement, since presumably there is reciprocity when it comes to agreeing each other’s arrangements?

Can the Minister also say if any UK public authorities have yet sought to obtain data directly from US-based telecommunications operators under the terms of the 2019 COPOA Act using an overseas production order? If so, on how many occasions? Likewise, have any US public authorities sought to obtain data from UK-based service providers under the same, or similar, arrangements? If so, on how many occasions? Have assurances been given in relation to the non-use of the death penalty, and has protection been given to journalistic sources and material? Finally, is the Investigatory Powers Commissioner likely to be using statutory oversight and compliance powers in relation to agreements between the UK and any other countries apart from the US?

Baroness Williams of Trafford Portrait Baroness Williams of Trafford (Con)
- Hansard - - - Excerpts

I thank all noble Lords who have taken part in the debate and the noble Lord, Lord Morris of Aberavon, for his brief appearance. I could not keep up with the questions from the noble Lord, Lord Rosser, so I have missed some bits out. I hope to pick them up in the answers to other questions, but I will write to him if not.

I was very pleased to hear the opening remarks from the noble Lord, Lord Blunkett; I thought he would be supportive. He admitted to never having heard of the UK National Authority for Counter Eavesdropping. I join him in that: neither have I. It is the national authority for technical security and counter-eavesdropping. It helps the Government on technical espionage attacks by hostile state actors. Its capabilities and purpose are distinct and focus on countering close-access technical operations that could ultimately damage national security.

As he will know only too well, hostile state actors currently have the desire and the means to gain access to or otherwise compromise the integrity of highly classified communications systems and secure facilities. They are known to be able to carry out close-attack technical attacks, as demonstrated by the attack on the Organisation for the Prohibition of Chemical Weapons in The Hague by the Russian intelligence services in 2018. In that case, the Dutch authorities were able to detect and apprehend the agents involved, along with a car full of equipment.

We assessed that Russia and other hostile state actors, particularly China, will continue to attempt to disrupt, attack and commit espionage in the UK. I do not think any noble Lords in the Committee would disagree with that. The Intelligence and Security Committee’s recent report into the interference by Russia in UK democracy demonstrates intent, capability and, indeed, tenacity.

There is also the insider threat to consider, whereby an individual in an organisation may place a device for eavesdropping purposes. Insider threats can be from corrupt, compromised, disgruntled staff or from contractors. They can be among the hardest threats to identify. In order to fulfil its role, the UK National Authority for Counter Eavesdropping needs to be able to identify illicit and covert eavesdropping devices that may be present in sensitive and classified areas and then identify the user behind the device using communications data. We are now all experts in that particular agency.

There were a number of questions, particularly from the noble Lords, Lord Paddick and Lord Foulkes, about agencies being added and taken away, about why that happens and about the purposes of the various agencies that have been added. For clarity, the authorities we are talking about are the Pensions Regulator, the Civil Nuclear Constabulary, the Environment Agency and the Insolvency Service. It was right that those powers were removed in 2015, just as it is right for them to be reinstated now. We cannot foresee how operational requirements will evolve in response to the crimes that public authorities are investigating. We need to have the option to add and remove authorities depending on the necessity of the powers; the noble Lord, Lord Paddick, was right that it is nothing to do with the coalition. This is precisely why the IPA included the power to add and remove bodies from Schedule 4.

These authorities have all demonstrated a strong necessity and proportionality case against similar criteria that the Home Office applied when removing powers in 2015. Those criteria were: the statutory responsibilities of the authorities with access; the seriousness of the offences that they investigate; and the number of requests that they made. As is demonstrated by the case of the Civil Nuclear Constabulary in particular, which does not expect to use the powers often, assessing the volume of applications made is perhaps not the most effective of criteria for deciding which bodies should be listed in Schedule 4. The risk here is just too high to ignore. A public authority can make infrequent use of powers, yet still lead on investigations where communications data is critical.

I congratulate my noble friend Lord Naseby on celebrating his diamond wedding anniversary today.

Baroness Williams of Trafford Portrait Baroness Williams of Trafford (Con)
- Hansard - - - Excerpts

In fact, I think I ought to congratulate his wife more than him on enduring 60 years of marital bliss with my noble friend.

My noble friend talked about local fly-tipping. That is precisely the type of thing for which the Environment Agency might wish to use its communications data powers to protect the natural environment. Its statutory duties include the protection of the environment, natural resources and, of course, human health, which fly-tipping affects. It prosecutes offences that create serious risks of harm to people and the environment, such as illegal landfills and hazardous waste disposal—that might come under my noble friend’s question—and treatment and shipments. Its remit encompasses more than 400 different offences and it encounters some 40,000 suspected offences each year. Of course, we know that waste crime costs the economy in excess of £600 million a year.

Back in 2018, the Secretary of State for the Environment announced an independent review into waste crime, which published the report Independent Review into Serious and Organised Crime in the Waste Sector. That report recommended that the Home Office grant communications data powers under Part 3 of the Investigatory Powers Act. We have a duty to respond to that recommendation.

My noble friend asked about the DHSC. Its inclusion has nothing to do with financial matters; it is purely because its name has changed. He also talked about the Pensions Regulator. It is sad to say so, but criminality in pensions is not only a present threat but a growing one. It is recognised as a risk by the Pensions Regulator and its supporting regulatory partners, including the Serious Fraud Office, the National Crime Agency and HMRC. Having previously referred cases to law enforcement partners to prosecute, the Pensions Regulator now actively leads on these types of investigations and the prosecution of offenders. As my noble friend will appreciate, communications data will be a vital tool in assisting these investigations.

The Pensions Regulator took ownership of Project Bloom from the NCA in 2016. Bloom is a multiagency approach to pension scams and fraud. The Pensions Regulator can evidence £500 million-worth of scams in its regulatory remit, which is quite significant. It estimates that the ongoing threat runs into several billion pounds. Through Project Bloom, the Pensions Regulator has been running a communications campaign with the FCA featuring national television advertising campaigns, which noble Lords may well have seen.

The noble Lord also asked about states, such as Delaware, that do not co-operate. It is to companies rather than states that these requests will be made. That is an important point. Overseas territories do not use it.

The noble Baroness, Lady Jones of Moulsecoomb, asked about the review. It has not yet appeared because the agreement is not yet in force. I am sure that when it is the review will be forthcoming.

The noble Lord, Lord Foulkes of Cumnock, asked about temporary powers. Those statutory powers will last for one year. He asked about the IPCO’s role in all this. It will cover its role in the agreement and in the annual report, which is publicly available.

The noble Lord, Lord Paddick, rightly asked about the business cases, which I did not go into at great length because they are sensitive and extremely lengthy. Reflecting on that thought, I am very happy to organise a private session to go through the business cases for interested noble Lords. The noble Lord also asked about the consultation period under the Investigatory Powers Act. A 12-week period is required for consultation with relevant public authorities and the IPCO on Schedule 4 changes.

The noble Lords, Lord Paddick and Lord Rosser, asked how many organisations have applied and been turned down. I do not know the answer to that question, but I can find out. They also covered the death penalty assurances, which they know are being sought. It was interesting that we have received assurances from the US that should the UK accede to the 2015 MLA request by transferring evidence, the death penalty will not be sought or imposed in any prosecution in the recent case of Kotey and Elsheikh. I hope noble Lords will understand—I know they will—that it would not be appropriate to comment any further while legal challenges are ongoing in that case.

The noble Lords, Lord Rosser and Lord Paddick, talked about additional resources. They are well-versed in our ambitions for 20,000 police officers. The noble Lord, Lord Rosser, also asked about lowering the rank. Quite simply, no lowering of the rank is required. On the ISC, it is not a requirement in the legislation already using the enhanced procedure—laid for 40 days and debated in both Houses—but I fundamentally agree with the noble Lords that engagement with the ISC is an important factor.

The final question to which I have an answer is about safeguards, raised by the noble Lord, Lord Rosser. I am sure the IPCO will lay out any concerns the commissioner has in his annual report, particularly on any safeguarding issues around the whole regime.

I will leave it there for now. I will attempt to answer any questions I have not answered in writing.

Motion agreed.