¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
15. The Chamber majority in the present case considered “that the stored data is further protected against excessive or abusive information requests by the fact that the requesting authority requires an additional legal basis to retrieve the data” (see paragraph 100). While it is true that the Constitutional Court confirmed that an additional legal basis was required for data retrieval by the relevant authorities, it also conceded that general powers of data collection were sufficient (see § 163 of the Constitutional Court’s decision). If one considers the legal provisions in question, which are listed in the judgment (see paragraphs 32-38), it is apparent that most authorities are generally entitled to collect data in performing their legal tasks and duties. Consequently, there is no clear threshold limiting data collection to the investigation of serious crimes or specific serious threats to national security. In that regard, it should also be noted that the Court has already considered the “general clause” for investigative measures under Article 161 of the Code of Criminal Procedure (“CCP) as one of the additional legal bases which, according to the majority, protects mobile subscribers against excessive or abusive information requests. In Sommer v. Germany (no. 73607/13, § 58, 27 April 2017) the Court concluded that the threshold for interferences was relatively low and that the provision did not provide particular safeguards.
16. The number of affected persons, which is already high owing to the breadth of the legal regulations, is further increased by the technical design of the database and the query possibilities. Information requests do not need to be limited to specific telephone numbers or names. Section 112(1) of the Telecommunications Act enables the authorities to search on the basis of incomplete data, by means of a similarity function. Therefore, the retrieved data may concern a large number of persons for whom there is no evidence whatsoever to suggest that their conduct might have even an indirect or remote link to criminal or regulatory offences, other than having a similar name or telephone number. Nonetheless, these persons might still be subjected to further investigative measures based on data retrieval under section 112 of the Telecommunications Act.
17. When information is requested and the database is searched, the name/number is compared to every mobile user in the database. Consequently, the personal data of every user is processed, albeit in a limited manner. Depending on the precision of the search criteria, the search provides a list of all subscribers who meet the criteria. Taking into account the similarity function and incomplete searches, this result list can still encompass data relating to a very large number of people. In order to further reduce the list - and ultimately identify the relevant number or person - the authorities have then to implement additional investigative measures. Therefore, those persons may be subjected to further interferences based on data retrieval under section 112 of the Telecommunications Act, even though they have given no reason for being investigated apart from having a similar name or telephone number. It is important to point out that around 35 million data sets were consulted in 2015 under the automated procedure (see paragraph 67), each data set corresponding to an individual.
18. One of my main disagreements with the majority, however, lies in the assessment of safeguards and whether the existing ones, if any, are sufficient in order to effectively prevent the misuse and abuse of personal data (S. and Marper v. the United Kingdom [GC], nos. 30562/04 and 30566/04, § 103, ECHR 2008; referred to by the majority in paragraph 78). This is, as I see it, the crux of the case.
19. The outcome of the assessment depends inter alia on the meaning of “effective” safeguards. In particular, does domestic or international legislation entail, in itself, a sufficient safeguard? The answer should be “no”, because legislation only constitutes the legal basis determining the lawfulness of the interference: it does not, in addition and in itself, constitute an effective safeguard. In my understanding of the requirement of effective safeguards, they should protect the individual from the application of national law by domestic authorities in an arbitrary manner and from abuse of legal powers. Such protection must go beyond legal rules, in particular when those rules and legal powers are couched in broad terms, as conceded in this case by the Constitutional Court, and when the rules and powers allow data retrieval in a highly simplified and automated manner. In this regard, I would once again refer to the total of some 35 million data sets which were consulted under the automated procedure in 2015.
20. In support of assertion that sufficient safeguards were in place, the majority relied on the double-door comparison made by the Constitutional Court (see paragraphs 17, 85 and 100). However, as seen above, the legal provisions for data retrieval are very general and broad. While they may suffice as legal keys for the double-door, there is no subsequent mechanism to control the information passing through. The double-door can be easily opened by those keys, but there is nobody waiting on the other side of the door to check which items pass the door and are subsequently used.
21. Furthermore, the majority argue that not only was the retrieval safeguarded by legal provisions, but it was also limited to necessary data, a requirement itself safeguarded by a general obligation to erase data that is not needed (see paragraph 100). What does that mean and what do the safeguards actually consist of? In my view, to put it simple, they consist of general provisions for data retrieval which, according to the majority, are “protected” by a general necessity requirement, which is “safeguarded” by a further general obligation. I fail to see any real protection against possible misuse and abuse. Consequently, in the circumstances of the present case, the double-door concept does not provide such an efficient safeguard.
22. Retrievals of personal data do not require an order by a judicial or otherwise independent authority. While the Federal Network Agency ought - at least for requests under section 112 of the Telecommunications Act - to examine the admissibility of the transmission when there is a special reason for doing so, the Constitutional Court itself has rightly pointed out that since the retrieving authority does not have to give reasons for its request, such an eventuality will hardly ever arise (see paragraph 18). Therefore, this agency is not able to act as an efficient safeguard. For information retrievals under section 113 of the Telecommunications Act, paragraph 2 of that section makes clear that the responsibility for the legality of the information request lies with the retrieving agency and that the telecommunication providers have no competence to review admissibility, as long as the information is requested in written form and a legal basis is invoked. In sum, the retrieving authority is competent to issue an information request and at the same time also to examine the admissibility of its request. In other words, the retrieving authority is its own safeguard. However, effective review and supervision of retrieval requests, whether submitted under section 112 or 113 of the Telecommunications Act, by a judicial or otherwise independent authority, are lacking.
23. The Court has previously accepted that a retrospective review of interference can be sufficient in the context of security operations. However, information requests under the automated procedure occur without the knowledge of the telecommunication provider or of the relevant subscriber, and there is no obligation to notify a mobile telephone subscriber of the fact that his or her personal details have been retrieved. A similar situation exists for manual information requests under section 113 of the Telecommunications Act, since paragraph 4 of that provision requires telecommunications providers to ensure the confidentiality of the request for information and of the information provided in support of it (see paragraph 31). Consequently, the victim of the interference has no knowledge and cannot seek a review of the information retrieval.
24. The majority accepted this consequence by relying inter alia on the Constitutional Court’s argument that redress can be sought together with legal redress proceedings against final decisions of the authorities (see paragraph 105). However, this only applies to information requests that have led to further telecommunication surveillance or other investigative measures. Even in this case, only the further investigative measure can be challenged, but not the information retrieval and storage itself. Moreover, this form of review is only available to a very limited number of victim categories. The vast majority of them are left without any possibility of review.
25. In this connection, the Chamber judgment eventually refers to the supervision conducted by the data protection authorities (see paragraph 107). Notwithstanding the important work done by these authorities, it appears unrealistic for them to review some 35 million data sets consulted by a wide range of different authorities. Given the personnel available to these data protection authorities and their broad range of tasks, this constitutes neither an adequate form of review nor an effective safeguard.
IV. Conclusion
26. My assessment of domestic legislation and practice in the present case leads me to conclude that the available safeguards are not at all sufficient to effectively prevent the misuse and abuse of vast amounts of personal data, to which I attach considerably more weight than my colleagues in the Chamber have done. I take the view, therefore, that the interference in the applicant’s Article 8 rights was not proportionate to the legitimate aims pursued, in particular because the domestic legislation was not confined to measures against terrorism or other serious crimes or to issues of national security, but in fact went far beyond that. The interference did not correspond to a “pressing social need” and, consequently, was not necessary in a democratic society.
27. This led me to vote for finding a violation of Article 8 of the Convention.
BAILII: