Cyberpatrolling or intelligence?
The Ministry’s responses leave serious questions unanswered. Among the points worth noting, it is alarming that prevention efforts are carried out “manually,” as indicated by the authorities at the meeting. What does this mean? How are these tasks carried out on a day-to-day basis? How can content be anonymized if monitoring is “manual”? The impact of social media surveillance on our fundamental rights takes on even greater significance in the current pandemic, where our lives are increasingly played out through electronic devices. As a society, we must demand accountability and speak out—as numerous organizations have done—to warn of the dangers of these practices and ensure that our human rights are respected. We hope that, in response to our request for access to information, the Ministry will address the concerns that trouble us.
On July 23, the Argentine Agency for Access to Public Information (AAIP), the Supervisory Authority for Law No. 25,326 on the Protection of Personal Data, recommended that the National Ministry of Security suspend the implementation of the General Protocol for Police Crime Prevention Using Open Digital Sources (hereinafter, “the Protocol”) until its compliance with current regulations on personal data protection has been reevaluated. More than two months have passed since that letter was issued, and it remains unknown whether its implementation has undergone any review.
The Protocol, approved in late May of this year by Resolution No. 144/2020 of the National Ministry of Security within the framework of the public health emergency established by Law No. 27,541 et seq., in relation to the COVID-19 coronavirus, establishes the “principles, criteria, and general guidelines for crime prevention efforts carried out in cyberspace by police agencies and security forces under the Ministry’s jurisdiction”. The Protocol renews a pre-existing state policy and sparks a debate regarding the legality, proportionality, and necessity of these types of state practices, known in the field as Open Source Intelligence (OSINT) and Social Media Intelligence (SOCMINT).
The various open-source intelligence methods have adapted as technology has evolved. Prior to the Protocol’s approval, there was a very similar document adopted by former Minister of Security Patricia Bullrich, which only came to light in April 2020, when Minister Frederic instructed law enforcement agencies to seek any type of regulation that would allow her to monitor online information in order to “[gauge public sentiment]”(https://www.perfil.com/noticias/actualidad/sabina-frederic-ciberpatrullaje-redes-sociales-medir-humor-social-no-me-van-a-callar.phtml).”
Although the AAIP suggested suspending the Protocol due to its failure to comply with personal data protection regulations (which is no small matter coming from a government agency), the Protocol raises another debate regarding the legal framework for these activities: are they crime prevention tasks or intelligence operations? Given the impact of these practices on our fundamental rights—particularly their effect on the rights to freedom of expression and privacy—it is essential that the legal nature of the activity be clearly established. In any case, the mechanism for oversight and control over these tools must be clearly stipulated, both at the administrative and judicial levels. Allowing—or, worse still, normalizing—state agencies to collect, systematize, monitor, and use information published on the Internet without any accountability, simply because it is obtained from open sources, poses enormous risks to the exercise of human rights online and to democracy.
Legal Framework: Intelligence Disguised as Surveillance?
Open-source intelligence (OSINT) “is the practice that involves the use of a set of techniques and technologies that facilitate the collection of publicly available information, such as text, images, videos, audio, and even geospatial data. Only when such information is found to have a use or purpose, and is assigned to a specific action, does it then become intelligence proper”_. (1)
OSINT and SOCMINT practices have existed for decades, and debates surrounding their legality are more relevant than ever. Earlier this year, in the wake of the scandal sparked by allegations of illegal wiretapping of judges, politicians, and journalists in Colombia, the IACHR and its Special Rapporteur on Freedom of Expression, Edison Lanza, stated that “the use of any program or system for monitoring private communications must be clearly and precisely established by law, be truly exceptional, and be limited to what is strictly necessary to fulfill imperative purposes such as the investigation of serious crimes defined by law, and be subject to prior judicial review. Surveillance of communications and intrusions into privacy that exceed what is stipulated by law, that are directed toward purposes other than those authorized by law, or that are carried out clandestinely must be severely punished.” In another statement along the same lines, they reiterated that “the IACHR has established that mass surveillance of communications may under no circumstances be considered proportionate. Similarly, the systematic collection of public data—voluntarily disclosed by the owner of such data, such as posts on blogs, social media, or any other content in the public domain—also constitutes an interference with individuals’ private lives. The fact that an individual leaves public traces of their activities—which is inevitable on the internet—does not authorize the State to systematically collect such data except in specific circumstances where such interference would be justified.”
Under Argentine law, intelligence activities are permitted subject to specific authorizations and limits, in accordance with the provisions of the National Intelligence Law 25,520, Decree 1311/15 et seq., the Internal Security Law, and the National Code of Criminal Procedure. Law No. 25,520 defines National Intelligence as “the activity consisting of obtaining, gathering, systematizing, and analyzing specific information regarding events, risks, and conflicts that affect national defense and the nation’s internal security” (2), and defines criminal intelligence as “the part of intelligence pertaining to specific criminal activities which, due to their nature, magnitude, foreseeable consequences, dangerousness, or methods, affect the liberty, life, and property of the inhabitants, their rights and guarantees, and the institutions of the representative, republican, and federal system established by the National Constitution__l_” (3), and provides that_ “no intelligence agency may: 1. Carry out repressive tasks, exercise coercive powers, or perform police or criminal investigative functions”. _(4).
Intelligence Law No. 25,520 does not expressly prohibit the collection of intelligence from publicly available sources. In fact, Decree 1311/15, which approves the “New National Intelligence Doctrine,” defines intelligence information as “that which comprises observations and measurements obtained or gathered from public or classified sources, pertaining to events or issues relevant to national defense or internal security, or that have an impact on these spheres, and whose collection, systematization, and analysis make it possible to develop a situational picture of the set of issues at the strategic or tactical level_” (emphasis added).
Without prejudice to the regulations governing intelligence and the definitions provided by the law itself, the Cyberpatrol Protocol emphasizes that police crime prevention tasks on open digital sources are not criminal intelligence tasks, but rather tasks inherent to the functions of law enforcement agencies. This is where the confusion begins: What is the difference between intelligence tasks and crime prevention tasks (understood as surveillance)?
The distinction between surveillance and intelligence is unclear, and, unfortunately, the Argentine legal framework does not provide sufficient clarity. While it can be argued that surveillance or patrolling appears to be a power inherent to the duties of police and security forces, intelligence activities, as we mentioned at the beginning, require specific authorizations and are subject to limitations regarding their application to specific crimes, in accordance with the provisions of the National Intelligence Law 25,520.
Carolina Botero, Director of the Karisma Foundation in Colombia, points out in this article that while OSINT “is a legitimate and useful activity for anyone”, the problem arises when its use ceases to be monitoring and becomes surveillance, harassment, or stalking of an individual. In this regard, she concludes that the more individualized open-source monitoring becomes, the further it strays from mere monitoring and the more it becomes surveillance—which is a “regulated activity that requires controls and cannot be carried out on the basis of race, religion, or political preferences”. That said, it appears to identify the anonymization or depersonalization of information as one of the distinguishing elements between the different practices. This is a relevant point in the discussion, since there are those who consider that, on the contrary, indiscriminate monitoring can fall within the scope of intelligence activities.
At the national level, both the Fundación Vía Libre and the CELS consider that the activities covered by the Protocol go beyond “patrolling” and effectively constitute intelligence gathering.
Regarding the crimes being monitored:
Furthermore, the Protocol establishes an alarming number of crimes subject to prevention efforts (some of which, incidentally, do not appear to have a direct connection to the health emergency caused by the pandemic). This promotes broad-based monitoring, which not only runs counter to the principles of personal data protection established in Law 25,326 but also conflicts with the specificity requirements outlined in national intelligence regulations. Any indiscriminate collection of information for the purpose of analyzing, after the fact, whether or not it constitutes a crime runs counter to the very nature of that law. In this regard, CELS argued that “a minimum degree of substantive suspicion regarding the existence of a specific criminal phenomenon is required (hence the term ‘specific’), with certain spatial, temporal, and/or personal parameters, and in relation to the likelihood of finding relevant data in the open source in question.” Intelligence activities cannot be used as a blank check to gather information through public sources, only to later analyze it in depth and rule out any criminal activity.
Consequences for freedom of expression:
There are several studies that demonstrate the “silencing” impact that OSINT and SOCMINT practices have on discourse: people tend to remain silent if they know they are being monitored, especially when posting content on social media. In the words of Karen Gullo, an analyst at the Electronic Frontier Foundation, “What happens is that people begin to self-censor their communications: they’re more likely to avoid associating with certain groups or individuals, or viewing websites or articles, when they believe the government is monitoring them or the groups or people with whom they connect. This undermines our democracy and society as a whole” (own translation).
At CELE, we analyze the Protocol from a critical perspective regarding the impact that these types of procedures can have on human rights, particularly the right to freedom of expression. We are concerned about the lack of clear regulations to govern these types of activities within the Ministry of Security and the lack of clarity regarding the oversight of these tasks. We are also concerned about the lack of transparency regarding the systems used, the methods employed to carry out these tasks, and the security of the data collected. Finally, we are also concerned about the lack of proportionality with which security forces are acting in the investigation and arrest of certain individuals based on what they post on social media, and the forced application of criminal offenses such as threats (Article 149 bis of the Penal Code) or public intimidation (Article 211 of the Penal Code), which were not intended for these purposes. One need only look at the cases of Kevin Guerra and the raids “against agitators on social media”. These are some of the cases we are aware of because they became “high-profile,” but we do not know how many more there are—cases that have gone to trial but have gone unnoticed.
In order to address some of these unknowns, in early September we filed a request for access to public information with the Ministry of Security to obtain answers to the following questions, among others (5):
- Has the implementation of the Protocol been suspended as a result of the memorandum from the Agency for Access to Public Information?
- Of all police crime prevention activities in cyberspace, what percentage is carried out automatically, without security agents reviewing the content being monitored?
- How many cases arising from police crime prevention efforts in cyberspace have been prosecuted? Please indicate how many crimes were detected through monitoring, broken down by each of the crimes mentioned in Article 3 of the Protocol, since the Protocol took effect.
- What security measures are in place for the databases that store the information obtained as a result of police crime prevention efforts in cyberspace?
On September 25, the bimonthly meeting of the Advisory Board was held to evaluate compliance with the Protocol, in accordance with Article 3 of Resolution 144/20 issued by the aforementioned body. The meeting was attended by representatives of civil society organizations, including Beatríz Busaniche of the Vía Libre Foundation, who shared the most relevant points of the meeting in her “Weekly Summary of News and Updates.” At least one of the questions we raised in our request for information was answered at the meeting: the authorities confirmed that they had not acquired any devices or systems to carry out the prevention tasks referred to in the Protocol.
However, the Ministry’s responses leave serious questions unanswered. Among the points worth highlighting, it is alarming that prevention tasks are carried out “manually,” as indicated by the authorities at the meeting. What does this mean? How are these tasks carried out on a day-to-day basis? How is content anonymized when monitoring is “manual”?
The impact of social media intelligence on our fundamental rights takes on greater significance in the current pandemic, where our lives are increasingly conducted through electronic devices. As a society, we must demand accountability and speak out —as numerous organizations have done—to warn of the dangers of these practices and ensure that our human rights are respected. We hope that, in response to our request for access to information, the Ministry will address the concerns that trouble us.
Footnotes:
- “Followers We Don’t See. A Preliminary Analysis of the Government’s Use of Open-Source Intelligence (OSINT) and Social Media Intelligence (SOCMINT),” Association for Civil Rights (ADC), 2018, available for download here.
- Article 2.1 of Law 25,520
- Article 2.3 of Law 25,520
- Article 4 of Law 25,520
- The request for access was submitted on September 8, 2020, and as of the date of this publication, we have not yet received a response. Click here to download the complete request for information.
By Morena Schatzky (@morschatzky) and Agustina Del Campo (@agustinadelcamp)
Photo Credit: @matthewhenry