must be the exception not the rule.201 The Court
noted that it would be legitimate for States to
adopt data retention laws for the purpose of
fighting terrorism or serious crime if the retention
of data is limited to what is strictly necessary for
that purpose. 202 However, such laws must have
safeguards, effective oversight and remedies
mechanisms in place.203
The outcome of this case was questioned by
David Anderson, UK’s independent reviewer of
terrorism legislation, who described the decision
as “genuinely radical.” Anderson stated that:
A more rigorous analysis of proportionality
would have focussed on any actual harm that
this useful power might be shown to have caused
over its years of operations, and sought to
avoid assertions based on theory or on informal
predictions of popular feeling.204
The Special Rapporteur on the right to privacy
welcomed the ECtHR’s judgment. However, he
shared Anderson’s desire for a more rigorous
analysis of proportionality when it comes to mass
surveillance. In doing so, he noted that he has not
been granted, in the UK at least, access to any
information which would confirm that the utility
of bulk acquisition of data is both necessary and
proportional to the risk.205
Addressing, in part, concerns about data retention,
the EU’s General Data Protection Regulation,
which comes into force in May 2018, provides
for the right of data erasure. That is the right to
be forgotten which entitles the data subject to
have the data controller erase his/her personal
data, cease further dissemination of the data,
and potentially have third parties halt processing
of the data. The conditions for erasure under
the regulation include the data no longer being
relevant to original purposes for processing, or a
data subject withdrawing consent.206
In the context of storage of personal data that
201 bid. para. 108.
202 Ibid.
203 Ibid. paras. 103-111.
204 Report of Special Rapporteur on the right to privacy (24 February
2017) para. 16.
205 Ibid. para. 17.
206 http://data.consilium.europa.eu/doc/document/ST-5419-2016-INIT/
en/pdf.
is not necessarily gathered through surveillance,
the OECD Guidelines provide that:
The purposes for which personal data are
collected should be specified not later than at
the time of data collection and the subsequent
use limited to the fulfilment of those purposes or
such others as are not incompatible with those
purposes and as are specified on each occasion
of change of purpose.207
In New Zealand, the Privacy Act requires, in
unequivocal terms, that agencies should not
hold information for longer than what is required
for the purposes for which the information may
lawfully be used.208 Furthermore, the Privacy Act
and the sector specific codes that sit beneath
it (the Health Information Privacy Code, the
Telecommunications Information Privacy Code
and the Credit Reporting Privacy Code) require
relevant agencies to ensure security safeguards
are in place to protect against loss, access, use,
modification or disclosure or any other misuse
of the information.209 Notably, credit agencies
under the Credit Reporting Privacy Code have a
particularly detailed and specific set of prescribed
storage safeguards that they are required to have
in place.210
6.2 Mass Surveillance
Mass surveillance involves the indiscriminate
monitoring of the population or a significant
component of a group of persons.211 The
technology revolution has meant that
governments can now use mass surveillance
to capture data about virtually all aspects of
our lives. Traditionally such surveillance was
conducted through CCTV and national databases,
but the focus now is around the monitoring of
individual’s communications on phones and
computers.
Mass surveillance of meta data and intercepted
material is particularly problematic because it
interferes with the privacy of a large number
207 OECD Guidelines, art. 9.
208 Privacy Act 1993, Principle 9
209 Ibid. Principle 5.
210 Credit Reporting Privacy Code, Rule 5(2).
211 Privacy International, What is mass surveillance? https://www.
privacyinternational.org/node/52.
41