HomeCybercrime Law › Module 7 · Investigatory powers

Module 7 · Investigatory powers

What this module covers and why it matters. This module covers how the state gathers digital evidence once a cybercrime is suspected. It sits at the third stage of the subject's arc from offences to jurisdiction to investigations to cooperation between states. Having placed the offence and settled which state may try it the next question is how the police lawfully obtain the evidence. The powers fall into five families. Preservation freezes data before it is lost. Production compels a provider to hand over data it holds. Search and seizure takes data from a device or premises. Real-time collection captures traffic data as it flows. Interception captures the content of a communication in transit. Around those powers sit three cross-cutting themes that carry the research-essay load. The first is the balance between public policing and private policing. The second is the graduated protection given to three categories of data as they become more revealing. The third is the proportionality of retaining everyone's data in case it is later needed. The instruments are the Budapest Convention procedural powers in articles 14 to 21 and their Australian counterparts in the Telecommunications (Interception and Access) Act 1979 and the Crimes Act 1914.

How to use this guide. The Debate section is the centre of gravity because the assessment includes a 3000-word research essay and this module is where proportionality and privacy are argued. The RULE cards state the operative treaty and statutory powers. The Map of the debate box replaces the attack plan used in the offence modules because this module is analysed as a set of controversies rather than worked as a problem question. Read once to learn the five powers and the three themes and then revise from the headings and boxes.

Instruments at a glance

Instrument Key provisions What it does
Budapest Convention on Cybercrime (ETS 185, 2001) Art 14 scope; art 15 conditions and safeguards; art 16 expedited preservation of stored data; art 17 preservation and partial disclosure of traffic data; art 18 production order; art 19 search and seizure of stored data; art 20 real-time collection of traffic data; art 21 interception of content data Harmonises the domestic procedural powers to investigate cybercrime. Article 15 subjects every power to conditions and safeguards including proportionality
Budapest Convention, Explanatory Report Paras on the three data categories, including subscriber information (para 177 onward), traffic data and content data (para 209 onward) Interprets the powers. It sets out the three categories of data and confines interception of content to serious offences under art 21
Telecommunications (Interception and Access) Act 1979 (Cth) s 7 prohibition on interception; Ch 3 stored communications and preservation notices; Ch 4 access to telecommunications data; Part 5-1A mandatory data retention Australia's interception and access regime. Splits live interception from stored access from telecommunications data and holds providers to a two-year retention duty
Crimes Act 1914 (Cth) s 3E search warrants; s 3L operating electronic equipment at premises; s 3LA assistance orders Provides the search and seizure powers over devices and premises, including an order compelling a person to give access to protected data
Mutual Assistance in Criminal Matters Act 1987 (Cth) The formal channel for foreign requests Governs how evidence is sought from and given to other states, criticised for delay in cybercrime cases

Map of the debate

This module is analysed as a set of controversies rather than worked as a problem question so the frame to hold in mind is a map of the live debates. There are three, each returned to in the Debate section.

  1. Public and private policing. Cybercrime overwhelms traditional police so much of the work is done by providers, banks and platforms. Where should the line between state policing and private policing fall.
  2. Graduated protection of data categories. The law treats subscriber data, traffic data and content data differently. Should more revealing data attract a more onerous legal process.
  3. Retention and proportionality. Providers may be required to retain everyone's traffic data for later use. Is blanket retention a proportionate response to serious crime.

A fourth question sits across the first two. When a provider is served with a production order should it be permitted to tell the person whose data is disclosed.

The five investigatory powers

What this section covers and why it matters. Before the debates can be understood the five powers must be named and distinguished because each carries a different level of intrusion and so a different level of legal control. This section sets out each power as an operative rule with its treaty source and its Australian counterpart. The powers run in rough order of intrusion from freezing data that already exists to capturing the content of a live communication. Anchor each to the concrete act it authorises the moment it appears.

Start with the least intrusive power. Preservation does not disclose anything. It only freezes data so it is not lost while the legal machinery for disclosure is set in motion.

RULE. Expedited preservation requires a party to enable its authorities to order or obtain the expeditious preservation of specified stored computer data where there are grounds to believe the data is vulnerable to loss or modification. Preservation freezes data and does not by itself disclose it (Budapest art 16).
RULE. Preservation of traffic data requires that where the transmission passed through several providers a party can preserve the traffic data across all of them and can obtain expeditious disclosure of enough traffic data to identify the providers and the path of the communication (Budapest art 17).

In Australia a law enforcement agency investigating a serious contravention may compel a provider to preserve stored communications for a set period by issuing a preservation notice under Chapter 3 of the TIA Act. The notice freezes the data and any actual disclosure of the content then requires a stored communications warrant. Hooper Martini and Choo note the criticism that the preservation power at its introduction did not distinguish content from traffic data even though content attracts greater protection (Hooper Martini and Choo 2013).

The next power discloses data the provider already holds. Production compels the handover of stored data rather than the real-time capture of new data.

RULE. A production order requires a party to empower its authorities to order a person in its territory to submit specified stored computer data in that person's possession and to order a provider to submit subscriber information it holds. Production reaches data already stored rather than data yet to be created (Budapest art 18).

The Explanatory Report divides the data that can be produced into three categories which recur throughout this module. Subscriber information identifies the customer and the service. Traffic data records the origin, destination, route, time and duration of a communication but not its content. Content data is the substance of the communication itself. The categories matter because the law protects them in graduated fashion and the more revealing the category the more onerous the process should be (Budapest Explanatory Report; Hooper Martini and Choo 2013).

The third power reaches data on a device or premises.

RULE. Search and seizure requires a party to empower its authorities to search a computer system and to seize or secure computer data found in it, and to extend a search to a connected system in its territory where the data sought is accessible from the first (Budapest art 19).

Australia gives effect to this through the Crimes Act. A search warrant under s 3E authorises the executing officer to operate electronic equipment at the premises to access data under s 3L including data not held at the premises. Where access needs help the officer may apply for an order under s 3LA compelling a specified person to give the information or assistance needed to access data that is encrypted or password protected. The s 3LA power was justified in part by reference to the search power in Budapest art 19 (Hooper Martini and Choo 2013; Crimes Act ss 3E, 3L, 3LA).

RULE. scales An order under s 3LA compels a specified person to provide the information or assistance reasonable and necessary to allow an officer to access, copy or convert data covered by a warrant. It reaches encrypted or password-protected data and its use is weighed against the intrusion on the person ordered (Crimes Act 1914 (Cth) s 3LA).

The last two powers capture data as it is created rather than after it is stored. They are the most intrusive and so attract the tightest control.

RULE. Real-time collection of traffic data requires a party to empower its authorities to collect or record traffic data in real time and to compel a provider to do so. A party may reserve the right to apply this power only to a defined range of offences (Budapest art 20).
RULE. scales Interception of content data requires a party to empower its authorities to intercept content data in real time but only in relation to a range of serious offences to be determined by domestic law. Interception of content is confined to serious offences because it is the most intrusive power in the scheme (Budapest art 21).

In Australia the interception of a live communication is prohibited by s 7 of the TIA Act unless it falls within an exception, the principal exception being interception under a warrant. Access to a communication already stored is dealt with separately under the stored communications regime. This mirrors the treaty split between art 21 interception of content in transit and art 18 production of stored content (TIA Act s 7; Budapest arts 18, 21).

Consolidation. The five powers run from least to most intrusive. Preservation freezes, production discloses stored data, search and seizure takes data from a device, real-time collection captures traffic as it flows and interception captures content in transit. Article 15 subjects every one of them to conditions and safeguards including proportionality. The level of control rises with the intrusion and interception of content sits at the top confined to serious offences.

The three data categories

What this section covers and why it matters. The graduated-protection theme cannot be argued without the three data categories so this section fixes them with a concrete example and states how the law treats each. The categories decide how onerous the process to obtain the data should be and so they sit at the heart of the second debate.

Take a single email as the worked example. The subscriber information is the account name and the details the customer gave the provider on signing up. The traffic data is the fact that this account sent a message to that account at a stated time from a stated IP address. The content data is the words of the email itself. Each layer reveals more about the person than the last.

The three data categories, least to most revealing.

  1. Subscriber information. Who holds the account and what service they use. It identifies the customer but reveals nothing of what was communicated.
  2. Traffic data. The origin, destination, route, time and duration of a communication. It reveals the pattern of a person's contacts and movements but not the substance.
  3. Content data. The substance of the communication itself. It reveals what was actually said (Budapest Explanatory Report; Hooper Martini and Choo 2013).

The law protects the categories in graduated fashion. Content data is accorded greater protection than traffic data under Australian law and interception of content is confined to serious offences under art 21. Traffic data can be obtained on a lower threshold and in Australia certain telecommunications data can be disclosed on an internal authorisation rather than a warrant. Subscriber information sits at the least protected end (Hooper Martini and Choo 2013; Budapest art 21).

The graduated scheme has a critic's edge. Hooper Martini and Choo report the concern that the preservation power failed to distinguish content from traffic data which risks eroding the greater protection content is meant to carry. The tension returns when a single request captures more than one category at once (Hooper Martini and Choo 2013).

Consolidation. Three categories run from subscriber information to traffic data to content data and each is more revealing than the last. The graduated principle says the more revealing the category the more onerous the process to obtain it. Whether the law lives up to that principle is the second debate.

Retention and proportionality

What this section covers and why it matters. Retention is where proportionality bites hardest so this section states the retention duty and frames the proportionality problem the Debate section then argues. Retention is different from the five powers above. Those powers gather data about a suspect. Retention requires providers to keep everyone's data in advance in case any of it is later needed.

RULE. scales A provider that operates communications infrastructure in Australia must retain a defined set of telecommunications data for at least two years. The duty covers traffic and subscriber data and not the content of communications and it applies to every customer whether or not suspected of an offence (TIA Act 1979 (Cth) Part 5-1A).

The proportionality problem is that retention is blanket. It gathers data on the whole population rather than on a suspect. Gillespie sets out the objection through the analogy of Bentham's Panopticon. Because everyone knows their data is retained everyone behaves as though observed. The difference from the Panopticon is that it was designed for those who had committed serious offences whereas retention gathers data on everyone (Gillespie ch 14, citing Bernal).

The counter-argument is that retention is a justified interference because it helps combat serious crime and privacy rights are not absolute. Roberts frames the real question as whether the loss of privacy gives the state power to interfere on an arbitrary basis rather than the collection of the data itself (Gillespie ch 14, citing Roberts).

The European courts have twice found blanket retention disproportionate. The Court of Justice struck down the Data Retention Directive because it required retention of all traffic data across the whole population without limit as to the crimes covered and without independent review of access (Gillespie ch 14). That reasoning has shaped the debate ever since even though the Australian regime remains in force.

Consolidation. Retention is proportionate on the government's account because it is limited to traffic and subscriber data and serves serious crime, and disproportionate on the critics' account because it treats the whole population as suspects. The clash is argued in full in the Debate section.

Public policing and private policing

What this section covers and why it matters. The first debate turns on who actually polices cybercrime so this section sets out the private actors that now carry much of the load. The point matters because the more the work shifts to private hands the more the safeguards that bind the state may fall away.

Cybercrime overwhelms traditional police. Gillespie shows how far the burden has shifted. Fraud is largely handled through Action Fraud and the banking industry which refunds small-scale losses so the victim suffers no financial loss and no criminal justice response follows. Gillespie describes fraud as de facto decriminalised because so few cases reach a judicial outcome (Gillespie ch 13).

Private actors also police content. Content providers run notice and takedown systems and employ moderators to seek out material that breaches their terms. Gillespie treats platform moderation as private policing by another name because the moderators decide what is or is not acceptable (Gillespie ch 13).

Public and private actors also cooperate directly. Gillespie gives the example of CEOP working with Microsoft to develop PhotoDNA which identifies known child sexual abuse images by analysing their characteristics rather than an exact copy. The partnership let a public agency do far more than it could alone (Gillespie ch 13).

Hooper Martini and Choo frame the same balance in Australian terms. The interception and access regime is built on the relationship between law enforcement and the private sector because the suspect data passes across and is stored on private networks. Providers are required to keep the capability to give agencies access to data flowing across their infrastructure (Hooper Martini and Choo 2013).

Consolidation. Much of the policing of cybercrime is now done by banks, platforms and providers rather than the state. The benefit is reach the state cannot match. The cost is that private policing need not carry the safeguards that bind public policing. Where the line should fall is the first debate.

Common confusions

These are the errors that cost marks. Each states the mistake and then the correction.

Confusion. Preservation and production are the same power. They are not. Preservation under art 16 only freezes data so it is not lost while production under art 18 compels the actual handover of stored data, so preservation is a holding step and production is the disclosure (Budapest arts 16, 18).
Confusion. Interception and access to stored data are the same act. They are not. Interception under art 21 and s 7 of the TIA Act captures content in transit while access to a communication already stored is dealt with under the stored communications regime and art 18, so the timing of the capture decides which power applies (TIA Act s 7; Budapest arts 18, 21).
Confusion. Traffic data and content data attract the same protection. They do not. Content data is accorded greater protection than traffic data and interception of content is confined to serious offences under art 21 while traffic data can be obtained on a lower threshold (Budapest art 21; Hooper Martini and Choo 2013).
Confusion. Data retention and data access are the same thing. They are not. Retention under Part 5-1A requires providers to keep everyone's data in advance while access is the separate step of an agency obtaining specified data for an investigation, so retention creates the pool and access draws from it (TIA Act Part 5-1A).
Confusion. Real-time collection of traffic data and interception of content are governed alike. They are not. Interception of content under art 21 is confined to serious offences whereas real-time collection of traffic data under art 20 may be applied more widely subject to any reservation a party enters (Budapest arts 20, 21).

Debate

This is the centre of gravity for the research essay. Each strand is a two-sided contest with the leading voices named and each closes with questions to test a position rather than settle it.

Where should the line between public and private policing fall? On one side the sheer scale of cybercrime makes private policing unavoidable. Wall argues that collaborative policing is the only solution because the state cannot resource the response alone (Gillespie ch 13, citing Wall). Yar makes the wider point that policing is a broad term and should not be confined to traditional agencies because a variety of private actors now do enforcement work (Gillespie ch 13, citing Yar). Gillespie's own examples support this. Banks refund fraud and platforms moderate content and CEOP partners with Microsoft to build tools no single agency could. On the other side private policing escapes the safeguards that bind the state. When a bank quietly refunds a fraud there is no criminal justice response and Gillespie notes the criminal law is not about compensation so treating fraud as a refund leaves its harm unaddressed (Gillespie ch 13). When a platform decides what content to remove it exercises a policing power with no warrant, no oversight and terms it can change at will, as when the ownership of one platform changed and moderation was cut back (Gillespie ch 13). Hooper Martini and Choo frame the Australian version as a balance between effective investigation and the privacy of the individual and argue the reforms strike the right balance (Hooper Martini and Choo 2013).

Should a provider be allowed to notify the person whose data it discloses? When a provider is served with a production order the person whose data is handed over usually does not know. On one side notification protects the data subject. A person told their data has been disclosed can challenge the order, seek advice and hold the state to account, which is the ordinary position for a search of a home where the occupier is present. On the other side notification defeats the investigation. Data is volatile and a suspect who learns of an order can delete evidence or warn associates or flee. The value of preservation and production lies in acting before the trail goes cold and this is a concern Hooper Martini and Choo stress throughout (Hooper Martini and Choo 2013). The law generally resolves this against notification for stored-data powers because secrecy is what makes them work, but the cost is that the person most affected is the one least able to contest the intrusion. The deeper question is whether the safeguards that replace notification, such as the threshold for the order and later oversight, do enough work to substitute for the subject's own ability to object.

Should more revealing data require a more onerous legal process? The graduated principle says yes. The three categories run from subscriber information to traffic data to content data and each reveals more than the last, so content is accorded greater protection and its interception is confined to serious offences under art 21 (Budapest art 21; Hooper Martini and Choo 2013). The argument for graduation is that the process should track the intrusion and content reveals what was said while traffic data reveals only patterns. The argument against a rigid line is that traffic data in bulk can be as revealing as content. Gillespie records the point that a detailed analysis of communications data can disclose a person's relationships, finances, religion, sexual orientation and health without any content being read (Gillespie ch 14, citing Roberts). If traffic data can paint that picture then treating it as less protected than content may be a distinction the technology has outgrown. Hooper Martini and Choo report the specific criticism that the preservation power failed to distinguish content from traffic which threatens the greater protection content is meant to carry (Hooper Martini and Choo 2013).

Is blanket data retention a proportionate response to serious crime? The government's case is that retention is a justified interference. It is limited to traffic and subscriber data and not content. It serves the detection of serious crime. Privacy rights are not absolute and must be weighed against usefulness (Gillespie ch 14). Roberts accepts that automatic gathering is not inherently oppressive and locates the real risk in whether the state can then interfere on an arbitrary basis (Gillespie ch 14, citing Roberts). The critics' case is that blanket retention treats the whole population as suspects. Bernal draws the Panopticon analogy and stresses that retention gathers data on everyone rather than on those suspected of crime (Gillespie ch 14, citing Bernal). The Court of Justice struck down the Data Retention Directive as disproportionate because it required retention of all traffic data across the whole population without limit as to crimes and without independent review of access (Gillespie ch 14). Hooper Martini and Choo record the further concern that a two-year retention duty may not be a necessary or proportionate response and that providers holding vast data pools become targets for the very criminals the scheme is meant to catch (Hooper Martini and Choo 2013).

Discussion prompts

  1. Cybercrime has pushed much of the policing of fraud and content onto banks, platforms and providers. Assess where the line between public and private policing should fall and what safeguards should follow the power into private hands.
  2. When a provider discloses a customer's data under a production order the customer is usually not told. Argue for and against a rule that would permit or require the provider to notify the data subject.
  3. The law protects subscriber information, traffic data and content data in graduated fashion. Evaluate whether more revealing categories of data should require a more onerous legal process and whether the traffic and content line still holds.
  4. Set out the government's case for mandatory data retention and the critics' case against it, and assess whether blanket retention is a proportionate response to serious crime.
  5. Distinguish the five investigatory powers of preservation, production, search and seizure, real-time collection and interception, and explain why interception of content sits at the top of the scale of legal control.
  6. Explain how article 15 of the Budapest Convention subjects the investigatory powers to conditions and safeguards, and assess whether proportionality is an adequate check on the more intrusive powers.

Check your understanding

Auto-marked drills. Answer, then read the authority in the feedback.