Session 2022-23
Data Protection and Digital Information (No. 2) Bill
Written evidence submitted by Hyperoptic (DPDIB25)
R esponse to the c all for evidence on the D ata P rotection and D igital Information (No.2) Bill
1. Founded in 2011, Hyperoptic is a full-fibre network provider and internet service provider (ISP), focusing on the delivery of gigabit capable, FTTP connectivity in dense urban environments. At the time of this submission, our network covers over 1.2million premises, serving over 275,000 customers. As a provider of a public electronic communications service and network, a controller, processor, and holder of data, and a distributor of telecoms customer equipment, Hyperoptic is directly impacted by the DPDI Bill.
Summary
Security updates (clause 79)
2. This clause requires the provider of the user’s terminal equipment to allow users to opt-out of or disable/uninstall security updates that allow access to and/or storage of information on the equipment. Hyperoptic supports the rights of users to control the storage and access of their data on their devices. However, allowing users to opt-out of or undo a security update to the equipment used to provide their internet connection could expose individuals and the whole network to a significant degree of risk that far outweighs any benefit to the user stemming from the right to opt-out of security updates. We are also concerned that the clause as written could conflict with other pieces of legislation (enacted and draft, as discussed below).
Unlawful direct marketing (clause 85)
3. This clause requires electronic communications service and network providers to notify the Information Commissioner of any reasonable grounds to suspect a user of breaching direct marketing regulations. Hyperoptic supports the prevention of unsolicited direct marketing but considers that in practice it would not be possible for the clause to have this effect, as the data available to providers is so low a bar for suspicion that engaging the Commissioner on such grounds is unlikely to be of any material value.
Smart Data (Part 3)
4. This part allows the Government to create regulations requiring data holders from any sector to collect and provide specific customer and business data for the purpose of implementing a Smart Data scheme. While Hyperoptic recognises the potential benefits to consumers of Smart Data schemes in general, we urge caution over applying broad regulations to specific sectors and call for thorough impact assessments and consultations to inform this process before progressing.
Security updates
Wording of the Bill
5. Paragraph 558 of the explanatory notes [1] states that users "should be able to remove or disable the update after it has taken effect," whereas Paragraph (2C) in clause 79 (2)(a) ("PECR 6(2C)") itself says "remove or disable the software." These phrases describe different circumstances, so clarification is needed.
Software and firmware
6. PECR 6(2C) uses the word ‘software’, but security updates on telecoms Customer Premises Equipment (CPE or ‘router’) are usually installed on the firmware used to control hardware components. ‘Software’ is sometimes used as a catch-all term for both and we believe the DPDI Bill is likely using it in this sense, meaning PECR 6(2C) covers firmware. If this is not the case, then there are no exemptions for making security updates to firmware - as it is vital to provide security updates of all kinds, the matter of firmware needs to be addressed.
The necessity of security updates
7. The CPEs we provide to customers connect them to the network and are therefore an integral part of it. Unpatched security flaws could be used for malicious attacks on a user or network, even if only a small proportion of customers opt-out of the updates. A report commissioned by DCMS states: "insecure IoT is not just a threat to the individual user or corporate network into which it is plugged. It can actually represent a large-scale strategic risk to the overall digital environment." [2] The same circumstances could arise from any vulnerable connected device. The quoted point is a comment on IoT products that are not updated; creating barriers to patching security concerns in devices that currently have robust security because of regular updates could significantly widen the number and type of vulnerable devices. Allowing users to refuse a security update would open them and the entire network to a degree of potential risk that is vastly disproportionate to any user benefit (which is negligible in many cases).
Effects of uninstalling firmware
8. PECR 6(2C)(g) refers to removing or disabling software once a security update has been applied, but the purpose of firmware is to allow the device itself to function. Uninstalling/disabling it is either impossible, requires significant technical expertise, or could make the device unusable. PECR 6(2C)(g) requires that this process be "reasonably practicable," which may be impossible.
9. The explanatory notes refer to uninstalling the update alone, which has significant ramifications because some updates make fundamental changes. If an update enables integration with a new security database, undoing it means the device would not work with that database. It would not be proportionate, and often impossible, to maintain legacy systems to support devices where updates have been rejected or uninstalled.
Conflict with clause 1 paragraph (2) of DPDI
10. Clause 1 (2) introduces a new section to the Data Protection Act 2018 (DPA 3A(4)) placing responsibility for information breaches due to hacking on a controller or processor if they did not take appropriate steps to prevent it or reduce the risk. As security updates are a vital means of protection against malicious attacks, enabling their refusal contradicts the requirement to take appropriate measures to protect against hacking. By definition, companies issuing security updates subject to PECR 6(2C) will be controllers/processors subject to DPA 3A(4). These companies will effectively be put in the impossible position of choosing whether to enforce security updates to abide by DPA 3A(4), or allow security flaws to abide by PECR 6(2C).
11. Should both clauses remain, DPA 3A(4) must be amended to clarify that, where a breach is due to an end user exercising PECR 6(2C), this is not a failure by the controller or processor to take appropriate measures (except where they are the ones exercising PECR 6(2C)).
Conflict with Privacy and Electronic Communications (EC Directive) Regulations 2003 (S.I. 2003/2426)
12. Regulation 5 of PECR providers public electronic communications services/networks to take appropriate measures to safeguard the security of that service and notify customers of any risks the provider cannot address. Security updates for CPEs are a key safeguard; without them, risks will remain.
13. The test in PECR 5(4) is whether the technological developments and costs of those measures are proportionate to the risks. It is unclear how the requirements of PECR 6(2C) would integrate with 5(4) – since 6(2C) significantly diminishes the safeguarding ability of a security update, it directly impacts on that test. Should 6(2C) remain, the interaction between 6(2C) and 5(4) must be considered to clarify whether and how affected providers can and should comply with both.
14. Where an update is deployed to comply with 5(4) but a risk remains due to users opting-out under 6(2C), which could be every update, providers are required to notify customers of the risk. This could significantly increase the number of notifications and therefore damage trust in ISPs or telecoms more widely.
Conflict with the Product Security and Telecommunications Infrastructure Act (2022)
15. The Product Security and Telecommunications Infrastructure Act, under which CPEs would ostensibly be defined as ‘internet-connectable products’, was in part intended to incorporate the voluntary Code of Practice for Consumer IoT Security, which contains a requirement to keep software updated and publish a minimum security support period. [3] Schedule 2 of the draft Regulations [4] to implement the PSTIA’s relevant security requirements do this by reference to the EN 303 645 standard, which mirrors the Code. In relation to updates, compliance with elements including publication of a security update schedule and providing a way to report security vulnerabilities is mandated. Increasing obstacles to maintaining security puts the DPDI Bill at odds with regulations to implement recently enacted legislation.
16. Moreover, the UK has led the way on IoT security legislation and other countries are likely to follow. It is reasonable to consider that some may require compliance with a wider range of EN 303 645 clauses and that (like PSTIA) this would apply to imported devices. There is therefore the potential for an opt-out system to be a future barrier to exporting devices to other countries, if deemed non-compliant with EN 303 645.
Unlawful direct marketing
Application of PECR 26A
17. Clause 85 paragraph (2) of DPDI would require public electronic communications service and network providers to report any reasonable grounds for suspecting contravention PECR 19 to 22.
18. We assume that ‘calls’ in regulations 19 and 21 refers to PSTN and VOIP services alike, but the interpretation in PECR regulation 2 is not definitive. As 26A would confer new responsibilities on providers, it would be helpful to have this clarified, as well as whether it captures voice ‘notes’ and video calls.
Content monitoring
19. Paragraph 597 of the explanatory notes states "The network or service provider will not be required to intercept or examine the content of the communication." This is an important clarification and we request that it be included in 26A itself.
20. ‘Content of a communication’ is defined in the Investigatory Powers Act 2016, so the interaction between IPA and PECR needs to be carefully considered, including whether ‘reasonable grounds’ are likely to be the ‘content of a communication’ or ‘systems data’.
Scope of providers caught by PECR 26A and m eaning of ‘reasonable grounds’
21. The example of ‘reasonable grounds’ – high call volumes to sequential numbers – constitutes traffic data that the provider may hold and process for service provision under PECR. Sequential high-volume dialling is a strong indicator of automated and/or unsolicited marketing and therefore reasonable grounds for potential concerns under regulations 19 and/or 21 of PECR. However, this example is not relevant to breaches of PECR 22 through electronic mail, which is not provided by ISPs or networks. From traffic data (bandwidth used by a line) an ISP cannot identify an email, let alone the volume or the recipient.
22. The type of traffic and recipient could potentially be identified by deep packet inspection (DPI), but it would be resource-intensive to implement for ISPs who do not currently use this tool and could increase the amount of personal data held by an ISP, not just on their customers but on any recipients of marketing emails. Moreover, because it can be used to look at the content of data, mandating the use of DPI may attract significant concerns over privacy rights. We also note that the use of end-to-end encryption and virtual private networks would significantly or entirely reduce the ability of ISPs to carry out DPI.
23. 26A would potentially be more relevant to the providers of messaging services. As part of service provision, they have better access to information such as the volume of emails sent, which electronic communications service providers could only potentially seek to collect through the establishment of significant and more invasive new traffic inspection processes.
24. However, because PECR 22 breaches depend on what consent would be necessary and whether it was obtained, this data would be unlikely to constitute ‘reasonable grounds’ as there would be no indication of consent. Indeed, even if the specific content of messages were examined, it would not indicate breaches of regulation 22 to the extent of the calls example. It is therefore unclear what ‘reasonable grounds’ could be.
25. Directing 26A at electronic communications service and network providers is a circuitous and potentially burdensome route to gather information that is unlikely to achieve the aims of enforcing direct marketing regulations. Should 26A remain in DPDI, 26C must therefore be amended to include the requirement for the Commissioner to undertake an impact assessment prior to producing guidance on this regulation. We particularly support the inclusion of Ofcom and providers in the list at 26C(3) of persons to be consulted.
Smart D ata
Demonstrable b enefits to consumers
26. For Smart Data schemes to be effective, they must provide tangible benefits to consumers that are in addition to the industry’s own initiatives. Through its sectoral regulator, the telecoms sector already supports informed choices, including End of Contract Notifications to tell customers when their current contract is ending and what they could save by signing up to another deal, and is introducing One Touch Switching to make it easier for customers to move between providers. In relation to Smart Data for telecoms, Ofcom said "it will be important to consider the potential benefits of Open Communications alongside the effects of existing interventions intended to enable people to engage with the market more easily and effectively." [5]
27. A scheme commonly suggested is providing download data consumption to enable broadband customers to choose the most suitable tariff, simplifying a complex marketplace. However, this illustrates the downsides of broad-brush approach, as it doesn’t consider a sector’s specific characteristics. Broadband is overwhelmingly sold and used on bandwidth; consumption limits (except excessive use) are rare. Information on data consumption would not materially benefit consumers and adds a further dimension to comparing services, introducing unnecessary complexity – the very thing it intends to avoid.
28. Regulations concerning data collection must be tailored to the specific sectoral scheme, accounting for how it will actually be used by consumers and the real-world, tangible benefits it will bring them.
Impact of data collection and provision
29. Demonstrating consumer benefits is part of the need to assess the impact of any new data collection requirements on affected businesses. The cost of Smart Data schemes can be very high – Open Banking has reportedly cost the UK banking sector up to £1.5bn. The government’s indicative impact assessment uses telecoms as an example, concluding that a scheme would be less expensive than Open Banking, partly because it is a less complicated sector. We disagree with this conclusion. The ONS suggests that there are 260 banks [6] ; Openreach alone has over 650 ISPs [7] , with an array of other providers and networks that operate totally independently. This is a huge amount of data for services to utilise and a complex framework of network and service provision for a scheme design to navigate. Through implementing One Touch Switching we have seen the complexity involved in co-ordinating customer data across the industry. We are therefore concerned that the example used in the current impact assessment does not necessarily reflect the cost and difficulty of implementing a scheme.
30. It is imperative that a full impact assessment, with a comprehensive cost/benefit analysis, is completed for any regulations made in relation to Smart Data schemes, and that any such regulations should be specific to the sector(s) and the precise use case they intend to cover. Although 62(4) and 64(3) require the Secretary of State or Treasury to take account of effects on consumers, data holders, markets, and other relevant factors, it would be better for this to be bolstered with a requirement to undertake consultation and impact assessment, and be satisfied that the likely benefits outweigh the likely costs.
Involvement of sector regulators
31. The types of customer data that could be collected by data holders varies tremendously across the different sectors – water, banking, and broadband are vastly different in nature – and many sectors have existing interventions that must be taken into consideration when designing a Smart Data scheme. As such, any new regulations should take advantage of the sectoral expertise provided by the relevant regulators, both in devising regulations and enforcing them. This will help to ensure that the characteristics of services are fully understood and that the data requirements are in line with what is technologically possible and genuinely beneficial. To enable this, a new clause should be added to enable the Secretary of State or Treasury to direct a competent authority to exercise the powers given in Part 3.
May 2023
