Catherine Murphy
Ceist:
431. Deputy Catherine Murphy asked the Minister for Justice the number of data access requests that An Garda Síochána, GSOC and CAB have made to telecommunications and social media companies in the past three years to date in 2023, under the Communications (Retention of Data) Act 2011; the number of access requests that were approved and declined by the companies that the data was requested from; and the reason the data was sought. [21163/23]
Amharc ar fhreagra
I have sought the information requested by the Deputy, and will contact her again when this is to hand.
The following deferred reply was received under Standing Order 51
I refer to Parliamentary Question No. 431 of 9 May 2023 where you sought: “To ask the Minister for Justice the number of data access requests that An Garda Síochána, GSOC and CAB have made to telecommunications and social media companies in the past three years to date in 2023, under the Communications (Retention of Data) Act 2011; the number of access requests that were approved and declined by the companies that the data was requested from; and the reason the data was sought.”
As you will recall, Minister Harris had sought the information you requested from the relevant authorities, and undertook to contact you again once the information was to hand.
I am advised by the Garda Síochána Ombudsman Commission (GSOC) and the Criminal Assets Bureau (CAB) that neither organisation has made any such requests in the years specified.
I am advised by the Garda authorities that the table below shows the number of data requests to telecom companies from the start of 2020 to 5 May 2023:
|
Year
|
2020
|
2021
|
2022
|
2023 (to 5 May
|
|
Trace Requests made under the Communications (Retention of Data) Act 2011
|
1000
|
1031
|
888
|
193
|
|
Subscriber Requests
|
3856
|
190
|
265
|
98
|
|
IP Requests under the Communications (Retention of Data) Act 2011
|
71
|
27
|
20
|
8
|
The Garda authorities have further advised that Trace Requests made under the Communications (Retention of Data) Act 2011 are requests to providers to trace and identify the source/destination/time/location of a call. They have further advised that Subscriber Requests are requests to providers to identify a specific subscriber/user of a service, and that IP Requests are for an IP address assigned to a user/subscriber, so as to identify the date/time/duration of internet access. Such a request would be based on subscriber information already granted to, or in the possession of, An Garda Síochána.
With regard to the Subscriber Requests in the table above, I am informed that subscriber data may be provided to An Garda Síochána under other legislation, including Section 41 of the Data Protection Act 2018. An Garda Síochána advises it is not possible to differentiate between requests made under the Communications (Retention of Data) Act 2011 and Section 41 of the Data Protection Act 2018.
I am further advised that An Garda Síochána operates a Single Point of Contact Office (SPOC), where applications are assessed. An Garda Síochána has strict procedures in place in relation to the accessing of data under the Communications (Retention of Data) Act 2011, which take into consideration the implications of the High Court Judgment of 6th December 2018 in the Dwyer Case. All applications made under the Communications (Data Retention) Act 2011 to designated Communications Service Providers were complied with.
As a result of the High Court Judgment the position up to 26 June 2023 was that members of An Garda Síochána are obliged to seek judicial approval when seeking to access traffic and location data for the purposes of investigating serious crime.
All requests made under the Communications (Retention of Data) Act referred to above relate to (a) the prevention, detection, investigation or prosecution of a serious offence, (b) the safeguarding of the security of the State or (c) the saving of human life. Requests made under other enactments, including section 41 of the Data Protection Act 2018, may be made on other grounds. Further information detailing the reasoning for the requests is not recorded centrally, and as such, is not available.
The above information relates to the situation prior to the commencement on 26th June 2023 of the Communications (Retention of Data) (Amendment) Act 2022.
The 2022 Act takes account of important rulings of the Court of Justice of the European Union and, in particular, limits the means and purpose for which communications data can be retained and accessed and implements a requirement for judicial authorisation in respect of certain types of data. As permitted by the Act, the Minister obtained a High Court order on 26th June requiring service providers to retain traffic and location data on a general and indiscriminate basis for a period of 12 months for the purpose of safeguarding the security of the State. The Minister’s application was based on her assessment of the security threat. Overall, the commencement of the Act gives legal certainty to service providers and competent bodies on their obligations and ensures that stronger safeguards apply to the retention of, and access to, communications data.
Access to communications data continues to be an important tool for the investigation of crime and for the safeguarding of the security of the State.