On data retention laws: Why this is (still) not a good balance between mass surveillance and law enforcement
Response to latest EU data retention initative
In response to the Impact assessment on retention of data by service providers for criminal proceedings, I contributed the following statement:
There are many good reasons why unspecific mass data retention of Internet traffic metadata has (again and again) been considered to be in conflict with basic human rights to privacy. While it is not disputed that retention of traffic data (including but not limited to IP traffic flows and telephony networks connections) may be helpful for some post hoc law enforcement, it does not help in preventing crime, and, furthermore, can easily be circumvented with some effort on the end user side: by applying well-known and widely available techniques such as anonymizing network overlays (Tor, VPNs, botnet proxies, etc.) or anonymous endpoint connections (unregistered SIM cards, publicly accessible WiFi hotspots, etc.), users can effectively communicate with complete anonymity. This is inconvenient, and most users will therefore not use such methods regularly. Mass data retention thus primarily impacts regular, honest users. On the other hand, organized crime, terrorism networks, CSAM distributors, and other groups who have sufficient motivation to hide their communication, will not be significantly impacted by such simple mass data retention.
Therefore, the obvious conclusion is that the required balance between preventing potential harm (terrorism, CSAM, and other organized crime) and causing potential harm (surveillance, censorship, and oppression) is not met by data retention, and the proposal should therefore be rejected.