Showing posts with label Nigeria data privacy. Show all posts
Showing posts with label Nigeria data privacy. Show all posts

Friday, 30 September 2016

HISTORICAL CELL SITE LOCATION INFORMATION AND TELCOS IN NIGERIA


According to Wikipedia.com, a telco i.e. telephone company, telephone service provider or telecommunications operator:
is a kind of communications service provider (CSP) (more precisely a telecommunications service provider or TSP) that provides telecommunications services such as telephony and data communications access…With the advent of mobile telephony, telephone companies now include wireless carriers, or mobile network operators. Most telephone companies now also function as internet service providers (ISPs), and the distinction between a telephone company and an ISP may disappear completely over time, as the current trend for supplier convergence in the industry continues.

Historical cell site location information or mobile/cell phone location data is a collection of past connections between a mobile phone and cell towers or telecommunications masts. A cell site is mobile phone base station or antenna where radio signals are sent and received. In  the United States case of State v. Earls, it was stated that “Cell or (mobile) phones register or identify themselves with nearby cell towers every seven seconds. Cell providers (like MTN, Glo, Etisalat and Airtel in Nigeria) collect data from those contacts, which allow carriers to locate cell phones on a real-time basis and to reconstruct a phone’s movement from recorded data.”

Most times when you call the call centre of your GSM network provider or telco in Nigeria such MTN, Glo, Etisalat or Airtel, to make a complaint or inquiry, the customer care representative will ask you what town or city and local government you are calling from. I am usually taken aback by this question because they (telcos) already know or at least can approximate my location so why bother to ask me.

Whenever a mobile telephone makes a call, the call is routed through a cell site located at a fixed geographic location. Mobile telephone companies keep records of which cell site processes a call, and through this information law enforcement agents can locate the position of the SIM card, and therefore infer the location of the telephone user. This was used by the Nigerian Police to obtain the location of Timothy Dung, an armed robbery suspect in the case of The State v. Timothy Dung. On page three of the judgement it was stated thus:
According to the PW2 on the 20/8/2010 a case of armed robbery was transferred from the ‘E’ Division Police Station to the State Criminal Investigation Department (CID). PW1 volunteered a statement before the police.
According to the PW2 they swung into action by applying their detective mechanism to arrest the person because the line snatched was still going. Police applied to court to obtain a court order to serve Airtel/Zain who was the service provider of the line (Zain) snatched from the PW1. Airtel/Zain complied with the court order and released the coordinate to the Police. The coordinate enabled the Police to set a security trapping system that showed them the exact direction and position where the accused (that) was using that particular line at that time was standing. The system gave the latitude and longitude on google earth. lt shows(sic) that the accused person who was with the stolen line was at Abuja and the call history of the line after the robbery was within Abuja town and a town in Plateau State.  However, about three' days back, the line was showing that it, was in Abuja. The Police went to Abuja and the system directed them to Federal Fire Service in Abuja town and they went there. When the PW2 and his team called the number/line, it rang and the accused received the call. The PW2 then arrested the accused and interviewed him.
The case of United States v. Allums, also shows that telcos know or can estimate the location of their subscribers or customers at any given time using historical cell site location information (CSLI) or cell site analysis. James Edward Allums on 30th November, 2007, robbed a bank in Salt Lake City, Utah, United States. A bank employee dropped a chair from the second floor balcony onto Allums’ head as he stood brandishing a knife at a teller on the first floor.  In anger Allums removed his ski mask to look up and curse at the chair-dropper and in the process glowered directly into the surveillance camera. Allums had a mobile phone on him on 30th November.

Prosecutors introduced evidence that cell site tracking records showed that Allums’ phone, and presumably Allums, was located in close proximity to the bank and to two other locations also robbed by Allums. Thus, Allums was convicted on three counts of armed robbery.

Apart from historical CSLI mobile phone location can also be determined through GPS and mobile phone triangulation. At this juncture it is appropriate to state how mobile phone communications work as captured or explained in Re: Application for Telephone Information Needed for a Criminal Investigation:
Cell (mobile) phones operate through the use of radio waves.  To facilitate cell phone use, cellular service providers maintain a network of radio base stations—also known as cell towers (popularly referred to in Nigeria as mast)—throughout their coverage areas.
Whenever a cell phone makes or receives a call, sends or receives a text message, or otherwise sends or receives data, the phone connects via radio waves to an antenna on the closest cell tower, generating cell site location information (CSLI).  The resulting CSLI includes the precise location of the cell tower and cell site serving the subject cell phone during each voice call, text message, or data connection.  If a cell phone moves away from the cell tower with which it started a call and closer to another cell tower, the phone connects seamlessly to that next tower.
CSLI may be generated in the absence of user interaction with the cell phone. For example, CSLI may still be generated during an incoming phone call that is not answered.  Additionally, most modern smartphones have applications that continually run in the background, sending and receiving data without a user having to interact with the cell phone.
Indeed, cell phones, when turned on and not in airplane mode, are always scanning their network’s cellular environment. In so doing, cell phones periodically identify themselves to the closest cell tower—i.e., the one with the strongest radio signal—as they move throughout their network’s coverage area.  This process, known as “registration” or “pinging,” facilitates the making and receiving of calls, the sending and receiving of text messages, and the sending and receiving of cell phone data. Pinging is automatic and occurs whenever the phone is on, without the user’s input or control. A cell phone that is switched on will ping the nearest tower every seven to nine minutes. (Emphasis mine)
From the above it is crystal clear that CSLI can be used to estimate the location of an individual by identifying the nearest cell tower or mast and sector used when a call is made. It therefore presents circumstantial evidence of a person’s location.  This ability to locate a cell phone presents obvious benefits to law enforcement and intelligence authorities  as seen in the two cases referred to above. CSLI also poses a significant threat to privacy. Thus in State v. Earls (supra) the court observed that:
Advances in technology offer great benefits to society in many areas. At the same time, they can pose significant risks to individual privacy rights. This case highlights both principles as we consider recent strides in cell-phone technology. New improvements not only expand our ability to communicate with one another and access the Internet, but the cell phones we carry can also serve as powerful tracking devices able to pinpoint our movements with remarkable precision and accuracy.

Monday, 29 February 2016

RICKY TARFA (SAN): THE RIGHT TO REMAIN SILENT AND PASSWORD-PROTECTED MOBILE PHONES



 On the 24th of February, 2016 a Senior Advocate of Nigeria, Mr. Rickey Tarfa withdrew an N5billion fundamental rights violation suit he filed against the Economic and Financial Crimes Commission (EFCC) and four other respondents. The senior lawyer had filed the suit, alleging violation of his right to privacy by the respondents

Mr. Tarfa in the suit sought a court declaration that his right to privacy was violated when the call records/log on his phone with mobile number 08034600000 was allegedly accessed without his authority and made available to Sahara Reporters and other online news media without any reasonable cause or a lawful court order.

He also urged the court to hold that it was unlawful for his iPhone 6 with mobile number 08034600000 to have been used in calling one Alhaji Ado in Kaduna on mobile number 08061272929 on February 9, 2016 while the said phone was with Magu and the EFCC without any reasonable cause or any court order.

Furthermore, Mr. Tarfa also urged the court to hold that it was unlawful for the EFCC to access his bank details, clients’ information, private and confidential information contained in his iPhone 6 with number 08034600000 and Samsung 6 phone with number 08077341616 without any reasonable cause or any court order.

The writer cannot tell if Mr. Tarfa’s mobile phones were password-protected but assuming he had pass-worded/locked his mobile phones (just like Syed Rizwan Farook, one of the two killers (who were later killed in a shootout with the police) in the December 2, 2015 San Bernardino, California mass shootings, who left behind a pass-worded/locked iPhone 5c whose data the FBI has not been able to get access to) and the EFCC were unable to access the mobile phones either through hacking or guessing his passwords, would it have been lawful for the EFCC to demand from Mr. Tarfa or compel him to provide the passwords to his mobile phones?

The Position of the Law in Nigeria
According to Section 35(2) 1999 Constitution as amended:
“Any  person  who  is  arrested  or  detained  shall  have  right  to  remain silent  or  avoid  answering  any  question  until  after  consultation  with  a legal practitioner or any other person of his own choice”

Section 36(11) further provides that “No person who is tried for a criminal offence shall be compelled to give evidence”. However, section 35(2) is more germane to the issue at hand so this discourse will be limited to the said section.

The import of the section 35(2) is that whenever a suspect is in police custody, his constitutional right to remain silent begins, and this right is to the effect that he cannot be forced or coerced to say a word unless he volunteers to do so as it is the duty of the prosecution to prove its case beyond reasonable doubt. The above position of the law has been upheld by the Supreme Court of Nigeria in the case of Sugh v. State (1988) NWLR (Pt. 77)475. See also Ajudua v. FRN (2014) LPELR-24126(CA) where it was held that an  accused  has the  right  to  remain  silent  as  he  cannot  be forced to make a statement during investigation.

The Position of the Law in the United States
In the United States the general position of the law regarding the right to remain silent or right against compelled self-incrimination is provided for in the Fifth Amendment to the United States Constitution which provides that “No person shall…be compelled in any criminal case to be a witness against himself.”

In the case of Securities and Exchange Commission (SEC) v. Bonan Huang et al (Case 2:15-cv-00269-MAK), the SEC were investigating the defendants who allegedly used insider information associated with their jobs to trade stocks. The SEC suspected the mobile devices were holding evidence of insider trading and demanded (via a motion filed in court) that the defendants turn over their passcodes. The defendants declined supplying their passcodes contending that the Fifth Amendment protected them.  The issue was therefore, whether the defendants could be forced to give up passcodes to devices that were provided by their employer, but secured by passcodes chosen by the employees themselves. The Federal District Court (the Supreme Court has never ruled on the constitutionality of the issue) in Eastern Pennsylvania ruled that the defendants cannot be compelled to give up the passcode to their cell phones as doing so would be equal to giving self-incriminating  testimony.

The Position of the Law in the United Kingdom
The privilege against compelled self-incrimination or the right to remain silent is deeply rooted in the common law. Goddard LJ in Blunt v Park Lane Hotel [1942] 2 KB 53 at 257 stated thus;
"No one is bound to answer any question if the answer thereto would, in the opinion of the judge, have a tendency to expose (him) to any criminal charge, penalty or forfeiture which the judge regards as reasonably likely to be preferred …" 

In Saunders v UK [1996] 23 EHRR 313 it was held that Article 6 of the European Convention of Human Rights guarantees the protection against self-incrimination.
"The right to silence and the right not to incriminate oneself, are generally recognised international standards which lie at the heart of the notion of a fair procedure under article 6….the right not to incriminate oneself, in particular, presupposes that the prosecution in the criminal case seek to prove their case against the accused without resort to evidence obtained through methods of coercion or oppression in defiance of the will of the accused. In this sense the right is closely linked to the presumption of innocence contained in article 6(2)".

However, the right is subject to numerous statutory exceptions which limit, amend, or abrogate the privilege in specified circumstances. Therefore, despite the privilege, individuals may sometimes be required to answer questions or provide information or documents which may incriminate them. For instance the Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007, requires persons to supply decrypted information and/or keys/passwords to government representatives or law enforcement agents with a court order. Failure to disclose carries a maximum penalty of two years in jail. Thus, under the provisions of the RIPA Syed Hussain was convicted of failing to provide police with the password to the USB memory stick seized in a counter-terrorism operation. When Hussain was arrested in April 2012, police seized a USB memory stick from his home - but they discovered the information on the device was protected by sophisticated encryption technology. Hussain told detectives that he could not remember the password because he was suffering from stress – which meant they could not access its contents. Police called in experts from GCHQ, the government's secret eavesdropping and communications agency, but even they were unable to crack the device.

Oliver Drage, a 19-year old was arrested as part of an investigation into child sexual abuse images. His computer was seized by police who were unable to access some material on it thanks to a 50-character encryption password. Police formally requested the password from Drage, he refused to co-operate, an offence under the RIPA. He was accordingly sentenced to 16 weeks in a young offenders’ institution for refusing to give police the password to an encrypted file on his computer. See-

Conclusion
Considering the position or state of the law in Nigeria it may be safe to conclude that if Mr. Tarfa’s mobile phones were locked or pass-worded, the EFCC would have acted outside the law or illegally if they compelled Mr. Tarfa to disclose the passwords to his mobile phones which they seized. This is so as to the best of the writer’s knowledge there is no exception to the right to remain silent under Nigerian law; unlike the position in the UK, during interrogation in the custody of law enforcement agents.

However, as one writer observed:
“Realistically, the right to silence has a low value and not really exercised by most suspects. Only a suspect who knows the law and the right well would exercise the right as most people would not be able to withstand the mental pressures during the interrogation. False evidences, lies, isolation and many other psychological tactics are practiced to make the suspect confess the crime. As a result of this, many false confessions happen due to unbearable psychological pressures.”

It may therefore, not be out of place to suggest that it would take an extraordinarily strong-willed suspect undergoing interrogation during detention by any of the law enforcement agencies in Nigeria, especially the Nigerian Police who are notorious for torturing suspects in detention, to exercise his right to remain silent as guaranteed by section 35(2) of the 1999 Constitution as amended!

Monday, 18 November 2013

Barr. Timothy Tion discusses the NCC directive to cybercafe owners and cybercrime Part 1


Recently I was on “ICT WORLD”, a radio Benue program to discuss the Nigeria Communication Commission (NCC) directive to cybercafé operators which came into effect on the 1st of November, 2013 directing all cybercafé licencees and operators in the country to maintain an up to date data base of its subscribers/users detailing information such as; full names, names of corporate body (in the case of a corporate establishment), traceable physical address, full faced passport photograph, telephone numbers, permanent residential address(not P. O. Box), evidence of registration with Corporate Affairs Commission(CAC)(applicable to corporate bodies only) and other forms of identification including international passport, driver’s licence, national identity card, etc.
According to the NCC, this database is to aid law enforcement authorities in fighting the increasing rate of cybercrime committed through cybercafés across the country.
Here is the link to download the discussion. To download; click the "download" icon in green. Listen and let me get your feedback. Thank you.

UPDATE 22 DECEMBER 2020
The above link to the discussion is dead. Here is a new link to the discussion which is divided into parts 1 and 2. Listen to part 1 here and part 2 here

Friday, 1 November 2013

PRIVACY, NIGERIA COMMUNICATIONS COMMISSION AND CYBERCAFES


On the 21st of October, 2013 Nigeria’s telecommunications regulator; the Nigeria Communications Commission (NCC), issued a public notice via its twitter handle; @NgComCommission, which came into effect on the 1st of November, 2013 directing all cybercafé licencees and operators in the country to maintain an up to date data base of its subscribers/users detailing information such as; full names, names of corporate body (in the case of a corporate establishment), traceable physical address, full faced passport photograph, telephone numbers, permanent residential address(not P. O. Box), evidence of registration with Corporate Affairs Commission(CAC)(applicable to corporate bodies only) and other forms of identification including international passport, driver’s licence, national identity card, etc.  According to the NCC, this database is to aid law enforcement authorities in fighting the increasing rate of cybercrime committed through cybercafés across the country.

It is not in doubt that cybercrime is rampant in Nigeria. A February 2010 report by the Internet Crime Complaint Centre named Nigeria the top African nation and third in the world (after USA and UK) in its global cybercrime ranking.  It has also been reported that Nigerian consumers lost a total of N1.246 trillion to cybercrime in 2012 and recently the Central Bank of Nigeria (CBN) reported that the Nigerian banking sector lost over 20billion through internet fraud. There is therefore every need to fight this cankerworm called cybercrime in Nigeria.However,the Government (NCC, law enforcement agents, etc.)must ensure that the fight against cybercrime is done within the limits of the law and must avoid infringing;without lawful justification, the constitutional right to privacy of millions of innocent Nigerians who use cyber cafes or do anything that may negatively impact on that right. It is yet to be proven by NCC that most of these crimes are committed using cybercafés. It is even debatable if these internet crimes are perpetrated using cybercafés considering the availability of faster internet on smartphones coupled with cheap internet plans been offered by the GSM service providers(for instance on 31 October 2013, Globacom slashed its blackberry internet subscription (BIS) tariffs by half.The Absolute Month platform which hitherto was N2,800 with 3GB data, now goes for N1, 000 with 3GB data) and the convenience of browsing the internet on smartphones, tablets and personal laptops which are increasingly becoming affordable.

Without conceding that cybercafés are used to commit most of the cybercrimes in Nigeria, let us assume that it is actually the case and NCC rightfully desires to step in to curb this monstrous menace of cybercrime by urging cybercafé lincencees and operators to keep an up to date data base of its subscribers/users (that is assuming the users in the case of non-corporate bodies; submit their actual data and not fictitious data). What then becomes of this huge data base of personal and sensitive information of individuals in the hands of cybercafé operators since there are no data protection laws regulating the use of such data in Nigeria? How long will such data be kept? What remedies are available for any person whose personal information has been misused? The data; for instance, phone numbers could be sold or leaked to companies who could use it to send spam or unsolicited/unwanted text messages(adverts) to people. Someone’s identity could also be stolen and used by criminals for e.g. the name, passport and phone number could be used to fabricate or produce a fake identity card and left at a crime scene. The Police on arrival at the crime scene could pick up the identity card and arrest the person whose name, picture and address appear on the card and interrogate or let’s say torture (because a times that is what their interrogation is all about) the person. In the long run it may be discovered that the identity card was fabricated and the person whose details appear on the card was not actually at the crime scene, however, such person may have suffered bodily injuries (sometimes severe) from the torture by the Police.

These concerns and issues raised above could be addressed to a large extent with a data protection law. In recent times many subscribers of the GSM providers in Nigeria have been flooded with promotional or commercial messages. These messages sometimes are unwanted text messages including commercial messages otherwise known as spam which could be annoying and intrusive. In the United States, two laws– the Telephone Consumer Protection Act (TCPA) and the Controlling the Assault of Non- Solicited Pornography and Marketing (CAN- SPAM) Act – have been enacted to address spam. The TCPA and the Federal Communications Commission’s (FCC) rules ban many text messages sent to a mobile phone using an auto dialer(auto dialer; according to Wikipedia, is an electronic device or software that automatically dials telephone numbers. Once the call has been answered, the auto dialer either plays a recorded message or connects the call to a live person). These texts are banned unless (1) you previously gave consent to receive the message or (2) the message is sent for emergency purposes.In the UK, the Privacy and Electronic Communications Regulations 2003 cover the way organisations send direct marketing by electronic means, including by text message (SMS). Organisations cannot send you marketing text messages you didn’t agree to receive, unless: (a) the sender has obtained your details through a sale or negotiations for a sale; (b) the messages are about similar products or services offered by the sender; and (c) you were given an opportunity to refuse the texts when your details were collected and, if you did not refuse, you were given a simple way to opt out in all the text messages you received.

China too is not left out in the legislative efforts to curb spam and protect personal data thus on October 25, 2013, the Chinese Congress passed an amendment to the Peoples’ Republic of China Law on the Protection of Consumer Rights and Interests (the “Amendment”);to address growing problems related to the misuse of consumers’ personal information in contemporary China.The Amendment establishes strict rules on how business operators should collect and use personal information, and how offenders may be punished. The Amendment emphasizes that the personal information collected by a business operator and its staff must be kept strictly confidential. It also prohibits business operators from leaking, selling or illegally providing such information to others, and requires operators to adopt appropriate technical measures to safeguard the information. At the same time, business operators may not send commercial messages to a consumer unless the consumer has provided consent or requested the information.

Apart from those countries mentioned above, many other countries have a law or laws aimed at protecting personal information or data. In South Africa, the Protection of Personal Information Act has been passed by parliament and is awaiting assent by the President; and in Mauritius the Data Protection Act 2004 (the “MU DPA”) was enacted for the protection of the privacy rights of individuals in response to the developments in the techniques used to capture, transmit, manipulate, record or store data relating to individuals. The MU DPA came into operation in February 2009. Data Protection Regulations were issued in 2009 by the Data Protection Office. It is also responsible for ensuring compliance with the Data Protection Act and bringing enforcement actions.

Furthermore, in the UK they have the Data Protection Act;while in Mexico they have the Federal Data Protection Act. Also, in Japan they have the Personal Data Protection Act while in Canada they have the Personal Information Protection and Electronic Documents Act (PIPEDA).

In the United States they have a host of laws aimed at protecting personal information or data some of which include the Right to Financial Privacy Act of 1978whichrequires a  subpoena  or  search  warrant  for  law  enforcement  ocials  to  obtain nancial records, the Telephone Consumer Protection Act of 1991whichprovides certain remedies from repeat telephone calls by telemarketers; and the Driver’s Privacy Protection Act of 1994, which restricts the states from disclosing or selling personal information in their motor vehicle records.

It would therefore be of great help if NCC (as a regulator with so much of our data) and other stakeholders could push for data protection laws as is the case in other countries mentioned above.

Moreover, it is even doubtful if this directive by the NCC would be of much assistance in investigating cybercrime cases as by merely maintaining a database of subscribers/users one cannot tell which user browsed the internet for a fraudulent purpose.