Whistleblowers have come to us alleging spy agency wrongdoing, says UK auditor IPCO
- Reference: 1608208513
- News link: https://www.theregister.co.uk/2020/12/17/ipco_annual_report/
- Source link:
The investigation’s existence was revealed in audit body IPCO’s annual report for 2018-19, [1]published (PDF) earlier this week.
In addition, an MI6 spy “engaged in serious crime overseas” which senior managers tried to cover up – only to be forced to admit what had happened when the agent crossed “red lines”.
Meanwhile, police forces were found by IPCO to be treating applications to use spying powers as a tickbox exercise, perhaps unsurprisingly given that these are self-authorisations rubberstamped by police managers themselves. IPCO found that forces self-authorising surveillance fishing expeditions tended to use “templated or generic” reasons for doing so, often ignoring the “necessity and proportionality of the tactics requested”.
The auditor warned that police were paying less attention to supposedly strict surveillance laws, saying: “There were several forces where the processes for urgent applications for both surveillance and property interference fell below the standards expected, which was contrary to our findings from the previous year.”
On the bright side, court cases brought by privacy campaign organisations were having positive effects, with bulk personal datasets (collections of large amounts of personal information) being handled a little bit more diligently.
“To provide oversight that [2]satisfies this judgment , IPCO reviewed the use of bulk data at GCHQ and has now incorporated the sharing of bulk data with foreign partners into its regular oversight and inspection arrangements,” said IPCO in a statement.
Some allegations 'could not be substantiated' ... but third case being probed
As for the whistleblowers, IPCO tried to gloss over them in a single paragraph of its report, saying:
In 2019, three disclosures were made raising concerns with IPCO, all in relation to law enforcement agencies. In two of these cases, it was found that there was sufficient concern for IPCO to investigate further. Following investigation, however, it was decided no further action was necessary as the allegations could not be substantiated. The third case is still under investigation.
The whistleblowing pathway, as explained by IPCO in its report, stems from [3]section 237 of the Snoopers’ Charter Investigatory Powers Act. Though worded very obscurely, this means non-disclosure agreements and normal employment contract provisions about confidential information cannot be enforced against police workers and others who talk to IPCO’s commissioners about wrongdoing in their organisations.
“Although it is important to note that IPCO does not perform an ombudsman role (such a function is properly that of the Investigatory Powers Tribunal), IPCO’s statutory information gateway enables both current and former staff of the public authorities which we oversee to raise any serious concerns they have with us,” said IPCO.
The Investigatory Powers Commissioner’s Office functions mostly as an auditor that trawls through the use of surveillance powers by State agencies, though its judicial commissioners also provide before-the-event signoffs in some cases – and IPSO was keen to stress in its report that occasionally it does reject applications by police and other public sector bodies to spy on members of the public. ®
Get our [4]Tech Resources
[1] https://www.ipco.org.uk/docs/IPC%20Annual%20Report%202019_Web%20Accessible%20version_final.pdf
[2] https://www.theregister.com/2018/07/23/investigatory_powers_tribunal_gchq_15_years_illegal_surveillance_no_penalty/
[3] https://www.legislation.gov.uk/ukpga/2016/25/section/237/enacted
[4] https://whitepapers.theregister.com/
Re: "tended to use “templated or generic” reasons"
Being self authorising why would anyone expect anything different?
Authorisation should go through a magistrate from a different police region/s.
Re: "tended to use “templated or generic” reasons"
see also timesheets and travel authorisations etc.
Once the applicant has found a form of words that works, there is every incentive to use the "right answer" next time. The approver probably has many similar admin tasks, and may see their role as checking the form or process, not the truth or "proportionality" of the underlying facts behind it. That the form exists proves the applicant has thought about the matter , therefore due process has been done, therefore tick.
This research finding won't surprise anyone who has worked in a large organisation, I suspect. But good to have a study to conclusively prove it.
Re: "tended to use “templated or generic” reasons"
To be fair with timesheets and travel authorizations being mostly a 'write only' process is probably sufficient as it provides a paper trail and lets the submitted know there is a risk of being caught which is normally all that is sufficient to keep moral behaviour. It also means that if someone is caught there previous forms can be checked. After all what is the value to the business of someone fine combing every application - they are likely to be wasting far more time and expense (or worse still people avoiding doing something to invoke the process) than they protect.
Government and the publics legal rights however shouldn't be tracked on a basis of ROI as liberty is not something you can easily put a price on.
This surely didn't come as a surprise?
"In addition, an MI6 spy “engaged in serious crime overseas” which senior managers tried to cover up"
I mean, most countries consider spying on them to be a serious crime. So surely MI6 engages in serious crime all the time, as do all spy agencies? And they tend to cover them up as well. Unless they mean crimes other than those related to the job.
My impression is that spying is seen as a game and not something serious (except when politically useful, or when they win) after all we all know everyone is up to it and frequently know who the spies are but let them stay in play (better the spy you know).
Whoda thunk it...
Foxes guarding the hen house springs to mind.
Almost as unsurprising as the IPCC ever ruling for Police misconduct.
NSS
Not shocked, Sherlock.
Hmm
People fear facebook and such. At least you choose to volunteer your information to them. Spying by definition is very opaque and needs strong oversight.
"tended to use “templated or generic” reasons"
On the basis of our two years worth of research (shortly to be published with any luck), almost the entirety of data protection compliance is conducted using templated or generic statements. Come to think of it, most corporate "compliance" is too. The basic argument seems to be " what's the least effort we need to expend to keep the regulator off our backs? ". The actual intended purpose of compliance requirements doesn't seem to feature at all in decision making.