03/02/2020
CURIA - Documents
On the information provided in the order for reference in Case C‑698/15, that data includes ‘user location data’,
but not data relating to the content of a communication.
As regards access to retained data, Section 22 of RIPA provides:
This section applies where a person designated for the purposes of this Chapter believes that it is necessary on
grounds falling within subsection (2) to obtain any communications data.
It is necessary on grounds falling within this subsection to obtain communications data if it is necessary:
in the interests of national security;
for the purpose of preventing or detecting crime or of preventing disorder;
in the interests of the economic well-being of the United Kingdom;
in the interests of public safety;
for the purpose of protecting public health;
for the purpose of assessing or collecting any tax, duty, levy or other imposition, contribution or charge payable to
a government department;
or the purpose, in an emergency, of preventing death or injury or any damage to a person’s physical or mental
health, or of mitigating any injury or damage to a person’s physical or mental health; or
or any purpose (not falling within paragraphs (a) to (g)) which is specified for the purposes of this subsection by
an order made by the Secretary of State.
Subject to subsection (5), where it appears to the designated person that a postal or telecommunications operator
is or may be in possession of, or be capable of obtaining, any communications data, the designated person may, by
notice to the postal or telecommunications operator, require the operator:
if the operator is not already in possession of the data, to obtain the data; and
in any case, to disclose all of the data in his possession or subsequently obtained by him.
The designated person shall not grant an authorisation under subsection (3) or give a notice under subsection (4),
unless he believes that obtaining the data in question by the conduct authorised or required by the authorisation or
notice is proportionate to what is sought to be achieved by so obtaining the data.’
Under Section 65 of RIPA, complaints may be made to the Investigatory Powers Tribunal (United Kingdom) if there
is reason to believe that data has been acquired inappropriately.
The Data Retention Regulations 2014
The Data Retention Regulations 2014 (‘the 2014 Regulations’), adopted on the basis of DRIPA, are divided into
three parts, Part 2 containing regulations 2 to 14 of that legislation. Regulation 4, headed ‘Retention notices’,
provides:
retention notice must specify:
the public telecommunications operator (or description of operators) to whom it relates,
the relevant communications data which is to be retained,
the period or periods for which the data is to be retained,
any other requirements, or any restrictions, in relation to the retention of the data.
A retention notice must not require any data to be retained for more than 12 months beginning with:
in the case of traffic data or service use data, the day of the communication concerned, and
in the case of subscriber data, the day on which the person concerned leaves the telecommunications service
concerned or (if earlier) the day on which the data is changed.
...’
Regulation 7 of the 2014 Regulations, headed ‘Data integrity and security’, provides:
A public telecommunications operator who retains communications data by virtue of section 1 of [DRIPA] must:
secure that the data is of the same integrity and subject to at least the same security and protection as the data
on any system from which it is derived,
secure, by appropriate technical and organisational measures, that the data can be accessed only by specially
authorised personnel, and
protect, by appropriate technical and organisational measures, the data against accidental or unlawful destruction,
accidental loss or alteration, or unauthorised or unlawful retention, processing, access or disclosure.
A public telecommunications operator who retains communications data by virtue of section 1 of [DRIPA] must
destroy the data if the retention of the data ceases to be authorised by virtue of that section and is not otherwise
authorised by law.
The requirement in paragraph (2) to destroy the data is a requirement to delete the data in such a way as to make
access to the data impossible.
It is sufficient for the operator to make arrangements for the deletion of the data to take place at such monthly or
shorter intervals as appear to the operator to be practicable.’
Regulation 8 of the 2014 Regulations, headed Disclosure of retained data’, provides:
A public telecommunications operator must put in place adequate security systems (including technical and
organisational measures) governing access to communications data retained by virtue of section 1 of [DRIPA] in
order to protect against any disclosure of a kind which does not fall within section 1(6)(a) of [DRIPA].
A public telecommunications operator who retains communications data by virtue of section 1 of [DRIPA] must
retain the data in such a way that it can be transmitted without undue delay in response to requests.’
Regulation 9 of the 2014 Regulations, headed ‘Oversight by the Information Commissioner’, states:
‘The Information Commissioner must audit compliance with requirements or restrictions imposed by this Part in
relation to the integrity, security or destruction of data retained by virtue of section 1 of [DRIPA].’
The Code of Practice
The Acquisition and Disclosure of Communications Data Code of Practice (‘the Code of Practice’) contains, in
paragraphs 2.5 to 2.9 and 2.36 to 2.45, guidance on the necessity for and proportionality of obtaining
curia.europa.eu/juris/document/document.jsf?text=&docid=186492&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=1088733
7/16