effects apply both to the data potentially accessible to monitoring and to the way users
will relate to the networks of trusted actors who have access to these data. As the cases
about client tools show, surveillance is both widespread and very difficult to detect on
a range of client devices, including the routers and other computers necessary to implement the EU directive. As a result, an unintended outcome of the directive will be that
both the mandated data (senders, recipients, and time stamps) and the potentially collected data (the content of the whole data stream) will be exposed to potential access
by a whole network of new actors. The cases about server tools and surveillance show
that the directive’s requirements, when applied to server-side companies like Google,
will have the effect of increasing the data stored by those companies and thereby further pushing the already strained trust relationship between users and servers. Similar
mandates related to data retention should be viewed in a similar context of growing
Internet surveillance practices in the OSCE member states and elsewhere around the
world.
Finally, the cases about network surveillance show that many users, including many
of the serious criminals that the directive is meant to track, have an incentive to
choose to use available rerouting methods to avoid monitoring. The increased use of
rerouting proxies will both pose a privacy risk to those users and potentially route a significant portion of EU Internet traffic through countries unfriendly (at least in terms of
data sharing) to the EU. As a result, the intended purpose of the EU data retention
directive may be thwarted in dangerous ways. The unintended consequences of the
EU data retention directive are likely to prove costly.
Notes
1. European Union, Directive 2006/24/EC of the European Parliament and of the Council of 15 March
2006 on the retention of data generated or processed in connection with the provision of publicly available
electronic communications services or of public communications networks and amending Directive 2002/
58/EC, 2006.
2. Federal Communications Commission, Order FCC 06–56 (Federal Communications Commission, May 12, 2006).
3. John Markoff and Scott Shane, ‘‘Documents Show Link between AT&T and Agency in
Eavesdropping Case,’’ New York Times, April 13, 2006, http://www.nytimes.com/2006/04/13/us/
nationalspecial3/13nsa.html.
4. Ibid.
5. Sara Sundelius, ‘‘Sweden Adopts Controversial Law to Allow Secret Tapping of E-mails, Phone
Calls,’’ International Herald Tribune, June 18, 2008; DW-World Staff, ‘‘Swedish Government Clears
Hurdles to Pass Surveillance Bill,’’ DW-World.de, June 19, 2008, http://www.dw-world.de/dw/
article/0,2144,3421627,00.html.
50
Hal Roberts and John Palfrey
Précédent

- 67/635

Suivant