|
|
||||||||||||||||
|
|||||||||||||||||
Draft Communications Data Protection DirectiveThe Communication and Information Industries Directorate of the Department of Trade and Industry would welcome views concerning the draft Communications Data Protection Directive COM(2000) 385. Let the Department know you care. See our statement. Implementation of Distance Selling Directive (97/7/EC)The Department of Trade and Industry announced a package of regulations
designed to implement the Distance Selling Directive under the heading
<...>
This is the nearest the DTI can come to admitting that the only "self-regulatory scheme" which has the ghost of a chance of working is the prohibition on all kinds of Unsolicited Bulk / Broadcast Email outlined in the LINX Best Current Practice (RIPE 206). Data Protection issues in relation to address gathering are not covered in these regulations. [*] the lack of built-in hyperlink on the above URL is
deliberate. We cannot and do not endorse this scheme because it is
| |||||||||||||||||
|
|||||||||||||||||
Unsolicited Messaging on the InternetThe conference opened with a very clueful account of the problem of Unsolicited Commercial Email, presented by Bill Onwusah of Lovell White Durrant. Cost shifting, waste of time, invasion of privacy, poor to non-existent targeting, and possible inclusion of hostile programs by way of "baggage" were all mentioned as factors explaining providers' and providers' customers' opposition to UCE. The majority of users dislike UCE: in one survey, 83% responded that they disliked UCE, dividing only on the degree (20% "somewhat", 63% "a lot"). Most users appear to be of the opinion that "someone else" should be taking care of the problem. European respondents tend to favour legislation, US respondents say that it is up to the service provider. Mark Rhoads of the United States Internet Council pointed out that it seemed a bit strange that on the one hand, the Internet is "hostile to geography", and yet, in the United States, it is the state governments who seem to be able to act more quickly and lead the way with legislation. Extensive material on the "Can Spam Act" (HR 2162) was presented (with arguments for), as well as an overview of other bills (with arguments against). (See the CAUCE site for similar details.) The Opt-In vs Opt-Out debate was enlivened by vigorous participation from both panel and floor. Our position was (and is):-
Christine Oddy, the former MEP, was Rapporteur for the Committee of Legal Affairs and Citizens' Rights on the e-commerce directive proposal. According to her, UCE was not a serious issue. The other parliamentarians were more concerned with other aspects of the directive proposal, such as providers' liability for illegal content (copyright infringements, child pornography) and so on. Since consumers' groups did not appear to be concerned, UCE does not appear to be too great a problem. [Well... there were supposed to be about 22 million 'net users in Europe, of which just under 30.000 signed the c't/politik-digital petition against spam, i.e. about 0,13%. We do maintain that the "activists" are but the tip of a much larger iceberg, and that it is only because the providers have been keeping the problem in check and that the current methods of address gathering are relatively inefficient (the same Webmasters and Usenet posters get pounded over and over again whilst many happy surfers are largely untouched) that many more 'net users are not affected. In any case, consumers' associations have other issues on their agendas, so net.abuse is seen as a matter for 'net users and providers anyway.] Malcolm Hutty of the Campaign Against Censorship of the Internet in Britain (CACIB) brought up a number of offending collateral issues. The biggest ones were the right to protest and the issue of anonymity. Protest is all well and good, but protesters' rights on private property are far more limited than they are on public ground. The UK is no exception in placing more restrictions on advertisements than on political or artistic expression. Those who run genuine anonymous mail services (as distinct from misconfigured servers functioning as open relays) tend to take measures to reduce the likelihood of abuse. In extreme cases of harassment, they will block outgoing mail destined for a particular address. The Direct Marketing Association was ably represented by Messrs. Dirskovski and Robottom. Their presentation included some elements of myth and wishful thinking, however. Most notably, it was mentioned that a preference scheme based on one implemented by the US DMA was already in place, which was not the case as at 2 October 1999 (to say nothing of the date of the conference). It should be noted that Rodney Joffe (who is also a member of the American DMA) counts it as one of the successes of his SAFEeps scheme that the DMA had not to date implemented its own scheme. A favourite myth of the small company making use of "targeted" UCE to "outrun" larger and slower competitors was also given an airing. No concrete examples were given, and the widespread prohibition on the part of many providers against their customers' sending of UBE would appear to militate against the practice becoming more common. DMAs in the USA and Europe are nevertheless keen to avoid a more restrictive "opt-in" regime which would tend to restrain their usual processes of address gathering and brokering (as currently practiced with postal addresses). They do not seem to have an answer to those who find the emailing policies of Progressive Networks or Amazon totally unacceptable, except perhaps for "individual opt-out". This has been demonstrated to be less than effective and is not likely to find much acceptance amongst recipients of UCE. Glyn Morgan of Taylor Joynson Garrett gave an overview of possibilities for regulating commercial email. Much of this revolves around the UK Data Protection Act of 1998 which will come into force on 1 March 2000. This Act is the UK implementation of the Data Protection Directive 95/46/EC and the Data Protection and Telecommunications Directive 97/66/EC. The Act makes it plain what is required for data to be processed "fairly and lawfully", namely the consent of the data subject. No processing is allowed except for the purposes originally stated and to which the data subject had given consent. This could have an impact not only on UCE but other forms of traffic in mailing lists, and practices such as scraping addresses from the Web or from Usenet would seem to be similarly prohibited. Jeremy Drew of Ashurst Morris Crisp concluded the conference with a review of the arsenal of legal measures possible under existing legislation. These include
Subsidiary claims can involve anything from computer fraud through unjust enrichment or unfair competition to nuisance or criminal damage. Remedies include temporary or permanent injunctions, and monetary compensation
for damages. Examples of actual cases were included, the one particularly
relevant to the UK being Virgin Net Limited vs Adrian Paris. | |||||||||||||||||
|
|||||||||||||||||
Building Confidence In Electronic CommerceAn initial consultation with a view to forming the UK's negotiating position on the "electronic commerce" directive was carried out early 1999. The report is now available. From the summary on responses to the question on whether "industry solutions" would be adequate, or whether government action would be needed:- There exists a strong case for the market to determine how to deploy technologies and methods to tackle the issue of 'spamming'. However, there is a need to recognise that some legal recourse could be required to address persistent offenders and the government needs to keep a watching brief on industry's progress on this issue. Promoting Electronic CommerceA further "Consultation on Draft Legislation and the Government's Response to the Trade and Industry Committee's Report" has been published. In its current form, the legislation proposed has more to do with encryption and electronic signatures. Concerning UCE:-
| |||||||||||||||||
|
|||||||||||||||||
UBM Conference: "Junk Mail Fatigue - Finding a Cure"A one day conference on the problems of Unsolicited Bulk Messaging on the Internet was hosted by the London Internet Exchange on 8 October 1998. Paul Vixie was the keynote speaker, and was joined on the platform by representatives of the DTI, the UK Direct Marketing Association, the Data Protection Registrar's Office, RIPE, and EuroCAUCE.
The Legal Fight Against SpamEduardo Ustaran of Paisner & Co in London writes:-
|
|||||||||||||||||
|
|||||||||||||||||
|
Concerning draft regulations implementing Directive 97/66/EC "Data Protection and Telecommunications" Among other things, the new regulations should provide:-
This should be good news to corporate subscribers who have hitherto been plagued with "junk" faxes. Although not as desirable from the subscriber's point of view, the "opt-out" scheme enforced by the Data Protection Commissioner could work well enough. On the other hand... Electronic mail
The recipient may have another opinion, because there is a great deal of similarity to being inundated with "junk" faxes and "junk" email. Nevertheless, this does demonstrate that the Department does not regard Internet providers as Public Carriers. This means that the providers are free to adopt whatever Terms of Service/Acceptable Use Policy they want and can persuade their subscribers to accept, and that traffic is carried or refused at their sole discretion. [So all we have to do is to convince the providers of the desirability of adopting and enforcing anti-UBE policies. Simple, yes?] The implementation of the Distance Selling Directive (97/7/EC) will be another matter, because the provisions governing contact by telecommunications are broader in scope:
[Paragraph 1 refers to automated dialing systems playing a pre-recorded message and fax. It ought to have included email...IMHO] (Beebit 1998-09-27) |
|||||||||||||||||
|
|||||||||||||||||
DTI Workshop - EU Directive on Data Protection and Telecommunications.A workshop was held at the Department of Trade and Industry recently. On the panel were representatives of OFTEL and the Data Protection Registrar, and in attendance were representatives of telecommunications providers (BT, Orange, and others), the (UK)DMA, operators of the Fax Preference Scheme, Internet providers (notably Demon), Internet "exchanges" (the London Internet Exchange and Joint Academic Network), the National Consumer Council, and others. The timetable for implementation looks something like:- Most of the directive covers directories, the contents and usage thereof. Two items can (by implication) apply to email. Other salient points emerging from the discussions:-
There was one moment when a question concerning fax-to-email and email-to-fax gateways simply could not be answered by anyone on the panel. Indeed, the members of the panel seemed a little frightened at the prospect of being blinded by science on the part of the "Internet brigade". It was generally acknowledged that the "economics of email" IOW cost-shifting create conditions which are unique. The junk-fax wallah was trying to advance the "everyone accepts adverts, however unwillingly". I just managed to get in my remarks about published and broadcast adverts paying the costs of the content and transmission, to which the viewer or reader "opts in" by virtue of reading the publication or viewing or listening to the programme. In a "sidebar" conversation between representatives of the DMA and Demon, the DMA person was somewhat amazed as to how negatively Demon's customers react to junk email. Who knows, there may be hope. Certainly our message to any DMA would be, "Look, no matter what the actual legislative framework turns out to be, opt-in is the only answer which makes sense. There was, is, and will be no way the punters are going to accept UBE. Organisations like ours will see to it, and that's both a promise and a statement of fact." At one point, when the trade in "umpty squillion email addresses" was mentioned, it was pointed out that the addresses themselves are only those of participants of one form or another: Usenet, the Web, or chat. Someone burbled something about addresses being snagged together with information concerning Web browsing habits. Now, I had thought that that problem had been sorted out in IE and NN, but a recent thread in n.a.n-a.e ('Scarfing Your Email Address When You Visit a Website') would seem to indicate otherwise. One correspondent related that there are some tricks with Javascript which I presume does something similar to the "FTP grab". Have a look at http://www.glenns.org/ftpgrab.html. In conversations elsewhere, it turns out that small businesses seem to be adversely affected by "junk faxes". Apparently once a fax number appears in an advertisement, that fax will be spammed mercilessly. It is significant here that it was business which pushed for the passage of the "junk fax law" in the United States. I see a crying need for agitation in the future to transform unfocused discontent into a coherent lobby for change. In a completely separate development, OFTEL was seen to be intervening in a case of harassment, where one party was continuing to send fax advertisements in spite of being asked to stop. The timing was merely coincidental, but it does show that it may be possible to stem the flow from one sender but only with a lot of bother. A currently widespread perception is that the UBE problem is "made in USA" for the most part. Experts and anyone with bit of common sense realise that it is only a matter of time before the local "cowboys" get in on the act, and anything giving UBE a patina of respectability and legality is best avoided. On current trends, it does not bode well for businesses with email in
the UK. Private users may fare better in the short term. |
|||||||||||||||||
|
|||||||||||||||||
DTIThe Department of Trade and Industry has requested comments (to be communicated by 1 June) concerning the implementation the 'Protection of Privacy in Telecommunications' Directive, which is to be implemented in October. The Department further comments:- Directive 97/7/EC on the protection of consumers in respect of distance contracts (the 'Distance Selling Directive') has similar provisions to Article 12.2 in respect of unsolicited calls for marketing purposes. Article 10.2 in the Distance Selling Directive (the equivalent provision to Article 12.2), however, covers a wider range of means of communication (i.e. mail as well as telecommunications). The Distance Selling Directive has to be implemented by 4 June 2000, and DTI will consult on implementation this summer. However, the same opt-in or opt-out system chosen to implement the Telecoms Data Protection Directive is likely to be used for the Distance Selling Directive in respect of telecommunications. (Beebit 1998-05-29) |
|||||||||||||||||
|
|||||||||||||||||
JANETA lot of spam seems to go to Academic networks here in the UK (.ac.uk) which means that it must go through JANET, the Joint Academic NETwork. In their document online of their Acceptable Use Policy: http://www.ja.net/documents/use.html they state that
(amongst other things) Which, in no short terms, means that spam may not be sent to any UK Academic institution. (Beebit 1998-05-29) |
|||||||||||||||||
|
[ Countries | EU | Feedback | Main ] |