Data harvesting has dominated the news in recent weeks, and now law enforcement has found themselves under the microscope. This weekend the Sunday Herald reported that Police Scotland have been secretly hacking phones and harvesting public data.
It revealed through Freedom of Information (FoI) requests that the police have been piloting a new technology, known as Kiosk to override security systems and download all the information held on an individuals mobile phone.
Not only is this a gross intrusion of privacy, it begs serious questions about the use of intrusive technology by police services at a time where social media giants and analytics firms are coming under intense scrutiny for very similar practices – If it is unethical for Facebook or Cambridge Analytica to utilise intrusive technology, then where do we as a society draw the line?
With crime evolving via technology, police services say they need new tools to keep up. Speaking to The Herald, Detective Chief Inspector Brian Stuart said: “Given the explosion of mobile devices in recent years, law enforcement has to be innovative with technology and keep ahead of the curve to ensure the safety of its citizens.”
Clearly the motivations differ from that of the Cambridge Analytica case; yes securing public safety is a better application than political manipulation and profiteering. However, the public safety argument does not override the necessity for oversight, accountability and transparency.
What Is Kiosk?
Kiosk is a device similar in size to an iPad, allowing the user to access text messages, photos, passwords, browsing history, call records and a myriad of sensitive data which also includes encrypted conversations.
The Kiosk itself is designed by an Israeli company, Cellebrite, which describes the product as offering a “secure, closed hardware platform that empowers teams with actionable insights when they’re needed most” and, like a number of the firms’ products is marketed toward law enforcement and intelligence circles.
The pilot scheme, which took place in Edinburgh and Stirling, saw 18 officers access 375 phones and 262 sim cards during investigations into what Police Scotland described as ‘low-level crime’. According to the data obtained from the FoI request, the information extracted from devices cannot be taken within a specific time-frame, meaning police must access all photographs, messages and other forms of data, rather than just data on a specific date.
In addition to the accessing of current data, police can also access previously deleted data using the technology. Police Scotland told the Sunday Herald it complied with data protection guidelines throughout the trial and only accessed phones that were lawfully obtained. However, the issue lies in the ethics of such practices.
Are These Measures Proportionate for ‘Low-Level’ Crime?
For Police Scotland to use this technology to access data for what it claims to be ‘low-level crime’ is certainly questionable; especially when one considers the processes that UK security services must traverse to obtain this level of access.
For GCHQ to read messages or listen to calls, a warrant is required and must be signed by both a cabinet minister and a judge. The surveillance process itself is limited to a two week maximum so as to ensure they don’t access more than they need to. This level of activity is generally reserved for national security and not in tackling low-level crime such as drug investigations, which according to Police Scotland was what Kiosk was utilised for predominately at Gayfield in Edinburgh.
Police services across the UK, and indeed the world, are constantly having to evolve to new threats and forms of crime. With technology changing at such a rapid pace it’s understandable that police look to new tools to combat crime. If police services are to use such technology then a debate is needed on what measures are put in place to prevent misuse, as well as ensuring that police carefully handle our data.
When examining how police handle public data, there have been significant failings in the past, such as the issues surrounding the Custody Images Database.
Can Police be Trusted to Handle Data?
Despite a 2012 High Court ruling that keeping images of people on police databases was unlawful, police services expanded their database; free from the controls and safeguards that apply to DNA and fingerprint databases. A recent sitting in the House of Lords called for increased oversight of the processes involved in the storing of custody images; it would be wise to have a similar debate take place on this issue.
This instance strikes harrowing similarities to the police’s use of automated facial recognition technology – and the subsequent debate that surrounded it. Police often appear willing to utilise new tech without any safeguards until they are called out on it. If we are to trust police forces with new technology then we must first establish clear-cut rules and regulations surrounding its’ use. This is an issue that Millie Graham Wood, of Privacy International, was keen to point out.
She said: “The opaque nature of the use of these tools without anyone knowing about it means there is no independent oversight and when groups like Privacy International use FOIA to find out what is going on, we expose a regime with a shaky legal basis.”
Another Discussion on Police Oversight
The issue of oversight and transparency has since been raised by MSP’s of both the Scottish Liberal Democrats and the Scottish Greens, with John Finnie MSP (Lib Dems) telling the Sunday Herald “it’s important we see what checks and balances are in place to comply with data protection and human rights”, adding that “Police Scotland has not always had a strong track record in this area.”
Privacy rights groups are equally vocal about the issue, calling for strict regulation of police snooping practices. Big Brother Watch Legal & Policy Officer, Griff Ferris, told Digit: “Police are indiscriminately downloading huge amounts of personal information from phones and other devices without people’s knowledge or consent and a warrant.”
He added: “There must be a limit on police use of this far-reaching technology, including updated laws to provide checks and balances, including warrants for access to devices, and oversight of the process.”
Millie Graham Wood echoed the thoughts of Big Brother Watch in calling for updated laws, claiming there is “no formal national or local guidance and there is no independent oversight to act as a check against misuse or abuse of data” adding that regulations must be introduced so that people knows their rights when encountering police methods such as this.
Â





