Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Thursday, February 14, 2013

A REVIEW OF THE TELEPHONE CONSUMER PROTECTION BILL 2013 HB. 427


In this article, I review the Telephone Consumer Protection Bill 2013 HB. 427 (the “Bill” or “TCPB”) and make some recommendations for the benefit of the House Committee on Communications (the “Committee”) currently tasked with producing an advisory report on the Bill.

OVERVIEW OF THE BILL
The Bill was introduced into the House of Representatives by Hon. Abiodun Abudu-Balogun (Ijebu North, Ijebu East and Ogun Waterside Federal Constituency) on 16th January 2013 when it was read for the first time. The Bill went through second reading on 12th February 2013 and was subsequently referred to the Committee for further legislative work. The long title of the Bill is “A Bill For An Act To Protect Telephone Consumers From The Activities Of Telemarketers And To Provide For Adequate Sanctions Against The Business Of Telemarketing in Nigeria And For Other Purposes Connected Therewith.” The Bill contains thirteen (13) sections and an explanatory note.

In its explanatory note, the Bill seeks to enact a law to protect telephone consumers from unsolicited advertisement by telemarketers in Nigeria. Accordingly, the Bill imposes restrictions on unsolicited advertisements and on the use of artificial or prerecorded voice, and online telemarketing. Specifically, the Bill prohibits; the posting of any unsolicited advertisement to a called party; and artificial or prerecorded voice calls to residential telephone lines, unless the call is made with the prior express consent of the called party. The Bill also prohibits calls made without prior express consent to a residential telephone line using an artificial or prerecorded voice to deliver a text message.

Under the Bill, unsolicited advertisement by telephone is prohibited between 9.00 pm and 8.00 am. Telemarketers are however exempted where the calls do not include a solicitation to purchase goods or services or where the consumer has provided prior express consent. Online telemarketing is also prohibited under the Bill except with the prior express consent of or application of a subscriber. Telemarketing organisations are subject under the Bill to certain identification requirements. Consumers who register their residential telephone line(s) in a “DO-NOT-call Register list”, after the expiration of thirty (30) days after the last call or solicitation may not be solicited without their prior express consent.

In accordance with the provisions of the Bill, the Nigerian Communications Commission (the “Commission” or “NCC”) is the sole administrator of the provisions of the Bill. The Commission is also required by the Bill to issue regulations to service providers on the operations of telemarketing business in Nigeria. The Bill provides consumers with the right to sue for damages for a violation of the provisions of the Bill at the Federal High Court or a High Court of a State. Finally any telephone service provider that calls or sends a text message in violation of the Bill is guilty of an offence and liable to a fine of N5,000,000.00 (Five Million Naira).

KEY ISSUES AND ANALYSIS
General Prohibitions

The Bill prohibits the posting of any unsolicited advertisement to any called party (Section 1). “Unsolicited Advertisement” is defined in Section 12 of the Bill to mean “any material advertising the commercial availability or quality of any property, goods or services which is transmitted to any person without that persons comment or permission”. The Bill also prohibits calls made without prior express consent to a residential telephone line using an artificial or prerecorded voice to deliver a text message (Section 2). The Bill, however exempts calls which are non-solicitation calls unless the consumer has provided prior express consent (Section 3).

Telemarketing to Mobile Telephone Lines
The Bill prohibits the posting of unsolicited advertisement to any called party (Section 1). Consistent with the literary interpretation of statutes, “any called party” will be interpreted to include owners of mobile telephone lines for the purpose of prohibition under Section 1.

In the same vein, the Bill specifically prohibits telephone calls using an artificial or prerecorded voice message to any telephone number assigned to residence, except with the prior express consent of the called party (Section 2) and also states that the use of artificial or prerecorded voice or text messages to residential telephone subscribers must comply with time of day restrictions (Supra). However the Bill does not indicate whether mobile telephone subscribers or a subset thereof are “residential telephone subscribers” for purposes of these restrictions.

Calling Hours
Under the Bill, no telephone solicitation using an artificial or prerecorded voice to deliver messages or text messages calls may be made to any residential telephone line prior to 8 a.m. or after 9 p.m (Section 2). Although the term “telephone solicitation” is not defined in the Bill, there is no record from the legislative history that the Bill intended for calls to be exempted from telephone solicitation restrictions unless the residential subscriber has (a) clearly stated that the telemarketer can call, and (b) clearly expressed an understanding that the telemarketer’s subsequent call will be made for the purpose solicitation. Thus, calls made before 8 a.m or after 9 p.m will not violate Section 3 if they are made with the prior express of the resident. If a resident withdraws such consent, any further solicitation to that resident will be in violation of the provision of the Bill barring calls before 8 a.m or after 9 p.m.

Prior Express Consent
The Bill allows all forms of telemarketing contact only if the contacted party consents to such contact (Sections 2, 3 and4). Because, the term “prior express consent” is not defined in the Bill (or from the legislative history of the Bill), it remains unclear whether telemarketers and/or telephone service providers would incur liability in circumstances where they place calls to a residential telephone line belonging to a consumer who provided the number as a number at which s/he could be reached.

Exemption
Calls that do not include a solicitation to purchase goods are exempted from general prohibitions, unless the consumer has provided prior express consent. (Section 3). The Bill is unclear whether Section 3 prohibits telephone calls from a person with whom the resident already has an established business relationship (or whether such established business relationship constitutes “prior express consent”), as such calls do not adversely affect the privacy rights of the resident. A typical situation where this applies would be in instances where debt collection calls are originated by automatic dialling machines. In this regard, the Bill does not clarify whether the continued existence of an unpaid debt will create an existing business relationship exemption for debt collection calls under Section 3.

Administration of the Bill
The Nigeria Communications Commission shall administer the provisions of the Bill. (Section 7). The Commission is also authorised to issue regulations to service providers on the operations of telemarketing business in Nigeria (Section 8).

Private Right of Action
The Bill provides consumers with the right to sue for damages in a Federal High Court or the High Court of a State for any violation of the Bill (Sections 9 and 10), however it is unclear whether consumers can file class actions based on the private right of action created by the Bill.

Fine and Penalty
Section 11 provides that “Any telephone service provider that call or sent text message to any of it is subscriber shall be guilty of an offence, and liable to a fine of N5,000,000.00 (Five Million Naira) provided that the called parts proof unsolicited call or text messages for the provision of goods and services”. This provision is unclear in its meaning and needs to be redrafted to make clear its meaning.

RECOMMENDATIONS FOR THE COMMITTEE
Since the proposed law will have serious ramifications for the individual privacy rights of consumers and the freedom of expression of business entities, the Committee must carefully review the law before its passage. The Committee in providing an advisory report on the Bill must ensure that individual privacy rights of consumers and the freedom of expression of business entities are balanced in such a way that protects the privacy of individuals and permits legitimate telemarketing practices in Nigeria.

Following are some of the recommendations for consideration by the Committee;
I. The Bill should be redrafted to attain the greatest possible accuracy and clearness of meaning in some of its provisions;

II. The Bill should be revised based on the study of the experiences of other countries with similar legislations;

III. The Bill should be revised to provide clarity on whether telemarketing to a wireless mobile telephone line is prohibited under Section 2; and

IV. The Bill should be revised to clarify the circumstances by which prior express consent would be deemed to have been given.


Saturday, May 1, 2010

DATA PROTECTION ISSUES AND LEGAL IMPLICATIONS IN NCC’S DIRECTIVE ON SIM CARD REGISTRATION

Towards the ending of year 2009, the Nigerian Telecommunications Regulator, Nigerian Communications Commission (NCC) in exercising the powers granted it under the Nigerian Communications Act (NCA) 2003 issued a directive which was published in the Thisday Newspaper of December 31, 2009 to the effect that as from the 1st of March 2010 (according to the to the online news service “Daily Independent,” this date has been postponed to May 1st 2010 ) all new Subscriber Identity Module (SIM) cards must be registered before activation, this will be followed by the subsequent registration of the SIM cards of existing SIM card holders at a later date.


This directive coming from the NCC was borne out of the need to have a credible database of SIM card holders in Nigeria that will be used to identify (for possible prosecution) criminal actors who perpetrate criminal activities through the use of mobile phones by exploiting the anonymity of an unregistered SIM Card.

This paper considers two issues; to identify & address the data protection & privacy issues that arises during the implementation of the SIM card registration process and the legal implications on the criminal model of crimes been perpetrated through the use of mobile phones. Discussing the technical framework for the implementation of this process is entirely outside the focus of this write-up.

Data Protection and the Concept of Privacy under Nigerian Law

The right to privacy is an inalienable human right that cannot be derogated from, neither can it be subsumed under any government law or policy. Though Nigeria presently has no legislative framework for Data Protection, the right to privacy can be traced to the Constitution of the Federal Republic of Nigeria (CFRN) 1999, in particular S. 37 provides “The privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is hereby guaranteed and protected.”

The broad import of this particular statutory provision is to guarantee from interference and intrusion, the private affairs of the Nigerian person. This statement finds meaning in the definition of privacy as “The right of the individual to be protected against intrusion into his personal life or affairs, or those of his family, by direct physical means or by publication of [personal] information [emphasis mine].

When this constitutional right is juxtaposed with NCC’s directive to register SIM cards, one is wont to ask the nature of privacy and or data protection issues involved in the registration of these SIM cards.

SIM cards as the name implies is used to identify subscribers to mobile telecommunications services. It is a removable card that allows the user to transfer its subscribed services to another mobile device.

As there is a dearth of data protection laws in Nigeria, I intend to propose as a reference model the principles contained in the EU wide Data Protection Directive 95/46 EC, as a guide for the implementation of this SIM card registration process. Amongst other things, this directive has been internationally touted as setting the benchmark by which data protection laws are evaluated, the standards set are widely regarded as “high” and places an emphasis on human rights while its principles have been flexible in their approach.

Pursuant to this Directive, data or personal data means any information relating to an identifiable natural person (data subject), the directive also goes further in defining an identifiable natural person as one who can be identified, directly or indirectly, in particular by reference to an identification number… Therefore for data to be “personal”, two conditions must be met, first the data must relate or concern another natural person, secondly, the data must be used in the identification of the natural person. Where data does not refer to a natural person, it falls outside the scope of the EU Directive. As SIM cards contain both the unique serial and international numbers of the subscriber, it no doubt would come within the meaning of “personal data” as contemplated under the EU Directive since another individual can be able to connect the personal data to a natural person.

The capture of the subscribers photograph and biometrics (which undoubtedly is also personal data) as required under the implementation process will be deemed to be the processing and or collection of personal data. (In accordance with this EU Directive), data processing occurs when an operation or a set of operations is carried out upon personal data, whether or not by automatic means. These operations will include the collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure and destruction of personal data.

Since it is evident that due to the nature of the personal information stored in the SIM card database, accessing this database would therefore be implicating the privacy rights of SIM card holders, the question then becomes, under what circumstances will these personal data or information of Mobile telephony subscribers be collected, accessed or used legitimately? This is important in order not to run the risk of abusing stored data by those accessing it as data specifically provided for one purpose might be used entirely in a different context.

The EU Directive has a set of principles that must be adhered to when accessing the personal data of the private individual, it sets out the right of the private individual in regards to his personal data and establishes the general principles guiding the processing of personal data. These principles will be summarized below and related to the proposed SIM card registration in Nigeria:-

1. Data may only be processed where the private individual (data subject) has given consent: For SIM card holders, this consent must be specific and informed, it cannot be inferred from any circumstances nor can this consent be given on the basis of misrepresented facts.

2. Data may be processed when the processing is necessary for the entering into a contract with the private individual: This is fulfilled when the contract between potential SIM card holders and mobile telephony service providers contain clauses to the effect that their SIM cards would be registered, for the existing SIM card holders, it would be necessary to obtain their consent.

3. Data may be processed in order to comply with a legal obligation imposed on the entity in charge of processing the data: That is, the entity in charge of registering SIM cards in Nigeria must legitimately access this information only in so far as it complies with the legal obligation imposed on it.

4. Data may be processed when the processing is necessary to protect the vital interest of the private individuals: A broad meaning should be given to this paragraph in so far as the processing of the personal data would be necessary to protect the interest of SIM card holders.

5. Data may be processed when processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller or in a third party to whom the data are disclosed. To rely on this paragraph, the relevant question then becomes, would accessing the SIM card database be justified on the basis of public interest which would override the privacy rights of SIM card holders.

6. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed. SIM card holders must be allowed access to this database at any time and to make the necessary correction of their personal data as contained in this database.

7. Personal data can only be processed for specified explicit and legitimate purposes and may not be processed further in a way incompatible with those purposes: This is the main thrust of any good data protection policy. What is the main purpose of registering SIM cards in Nigeria? Legitimate processing requires that uses of the personal data must be known and publicly stated at the time of registration. A 2006 decision of a German court comes to mind here, where the demand by a public prosecutor investigating a criminal case to access personal data stored on a SIM card of an on-board unit in a truck was denied by the court. The court was of the opinion that the German Federal Toll Collect Act, on which the collecting of SIM card data is based, restricts the use of toll data to only the control of toll payments. In this regard, access to the SIM card database in Nigeria must be restricted to only the purpose(s) specified by the NCC i.e. cases of criminal activities perpetrated through the use of mobile telephones, to override such a purpose would require legal justification and authorization.

Legal Implication

NCC’s directive to register SIM cards will trigger some practical implications for criminals intending to sustain their desire for committing crimes through the use of mobile telephony services. Some criminals in order to sustain this desire and circumvent their identification will have to migrate to other criminal models that will continue to guarantee anonymity to them. These models will be considered under three heads in the following:

1. SIM card cloning: Occurs where the information contained in one SIM card is replicated for the purpose of making fraudulent calls, the billing for which would be incurred by the owner of the cloned SIM card rather than the perpetrator. To achieve cloning, the Electronic Serial Number (ESN) and Mobile Identification Number (MIN) has to be successfully retrieved from the target phone for transfer to the cloned phone. When this happens, calls can be made from the cloned phone as if it were the original phone. It is possible for criminal entities to exploit SIM card cloning technologies so as to beat the identification process inherent in SIM card registration.

2. Roaming services: Roaming has been defined as the ability for a cellular customer to automatically make and receive voice calls, send and receive data, or access other services, including home data services, when travelling outside the geographical coverage area of the home network, by means of using a visited network. Now consider this scenario, a criminal obtains an registered SIM card outside Nigeria from a service provider that offers roaming services within a Nigerian service provider’s network. It is obvious here that this criminal has successfully circumvented the NCC registration process by virtue of this roaming service and can still be able to perpetrate his criminal intentions through this service within Nigeria.

3. Internet/Satellite Telephony: With services like Skype and the scramble for broadband services in Nigeria, Internet telephony seems to have found a niche for itself, on the part of Satellite telephony, this particular service connects to satellites in orbit rather than terrestrial cell towers. All these services can be used to circumvent NCC’s registration process and perpetrate criminal activities.

From these criminal models, it is obvious that NCC’s intention may not be sufficient to address the purpose for registering SIM cards, the author believes that a system of identity management should be implemented in the mobile telephony sector. This will help to address issues of anonymity posed in the mobile telephony sector.

Conclusion

Even though NCC’s directive commences today May 1st 2010, it still presents some level of data protection issues that must be addressed. As national governments are becoming more aware of the importance of a good data protection framework, Nigeria must consciously strive to ensure that the personal data (in whatever form) of the Nigerian person is safeguarded. No doubt, it goes without saying that the common Nigerian person values his privacy and should not be exposed to situations where his personal data is arbitrarily processed or accessed, the glaring realities of the lack of the appropriate legislative solutions put in place to address data protection issues is already been manifested in an IT savvy Nigerian society. We need to re-engineer our legislative processes to accommodate the challenges presented by data protection, in the absence of the appropriate law, it becomes safe to place reliance on the principles enshrined under the EU model for data protection which still remains a role model for implementing data protection laws worldwide.

As per curbing the menace of criminal activities perpetrated through mobile phones, a system of identity management should be implemented and enforced in the mobile telephony sector (however this is achieved is entirely outside the scope of the author’s knowledge), this will ensure that anonymity in the mobile telephony sector is not exploited so as to commit criminal activities.

Why protect personal data? I am constrained again to reiterate that the right to privacy is inalienable, it can never be derogated from.