2. Authorisation Processes
Specific instances of communications surveillance should be authorised by an
independent and competent judicial authority prior to surveillance taking place.
Some states have a process of executive sign-off rather than judicial authorisation.
Independence in this circumstance means separate and not connected to the
authorities that will be carrying out the surveillance. Competence means that those
with responsibility for giving authorisation must have sufficient knowledge of the
issues, both technologically and from a human rights perspective. This independence
and competence is absolutely critical to the integrity of any legal framework. Some
states have a process of executive sign-off rather than judicial authorisation. But the
prevailing view at the UN level and among civil society is that judicial authorisation is
preferable for its independence (the Authorising Authority).
• The Government of Myanmar has already committed to judicial authorisation. 16
Communications surveillance must be limited to that necessary to achieve a legitimate
aim and use the means least likely to infringe rights; it must be both necessary and
proportionate. An objective assessment of the necessity and proportionality of the
contemplated surveillance should be a core part of the authorisation process.
The legal framework should set out which agencies among government bodies can
request lawful interception (the Requesting Agencies).
The legal framework should also set out the criteria and conditions on which the court
will make the decision on whether to authorise the request.
Any authorisation should be time-bound with a requirement for the Requesting Agency
to return to the Authorising Authority to request a renewal as that period of time
expires; automatic renewals of surveillance requests should not be permitted.
The legal framework should set out clear limits on the amount of time that data
collected can be stored. It should require that data is destroyed once the period
expires. In addition, it should require that any data illegally collected is immediately
destroyed and not used.
3. Oversight
There is an on-going global debate about the best form of oversight of lawful
interception and access to user data. Increasingly there is interest in mixed models of
oversight that incorporate administrative, judicial and parliamentary actors.
Oversight must be vested in another body (or bodies) that is independent of the
Authorising Authority that originally authorised the surveillance.
Oversight must be rigorous and not a rubber stamping exercise.
Consideration should be given to permitting a confidential public interest advocate, for
example an independent human rights expert, within the surveillance authorisation
process to ensure that appropriate consideration is given to the human rights
implications of the request. This is particularly important given the high degree of
secrecy of authorisation processes that relate to national security.
The oversight body must have access to all potentially relevant information to enable it
to evaluate whether the government is carrying out its activities in a lawful way. This
must include secret and classified information. Third parties, for example companies,
should have the ability to bring relevant information to the oversight body.
The oversight body must have the resources and expertise to be able to carry out
effective oversight.
Sector Relating to Licensing, Access and Interconnection, Spectrum, Numbering, and Competition (November
4, 2013)
16 Telenor Myanmar sustainability presentation (August 19th 2014). See p8 of the transcript.
ANNEX TO THE RECOMMENDATIONS:
LAWFUL INTERCEPTION AND GOVERNMENT ACCESS TO USER DATA
37
Annex
to Recs