--- layout: default title: "Surveillance Camp IV: Disproportionate State Surveillance — A Violation of Privacy" description: "A February 2013 EFF Deeplinks post co-written by Katitza Rodriguez and Elonnai Hickok, the fourth in a series mapping global surveillance challenges discussed at EFF's State Surveillance and Human Rights Camp in Rio de Janeiro, examining state-mandated identity verification, encryption restrictions, and blanket interception mandates." authors: ["Katitza Rodriguez", "Elonnai Hickok"] categories: [Elonnai Hickok] date: 2013-02-13 source: "Electronic Frontier Foundation" permalink: /elonnai/disproportionate-state-surveillance-a-violation-of-privacy/ created: 2026-08-20 homepage_featured: true --- **"Surveillance Camp IV: Disproportionate State Surveillance — A Violation of Privacy"** is a policy post co-written by Katitza Rodriguez and [Elonnai Hickok](/elonnai/), published by the Electronic Frontier Foundation on 13 February 2013. It is the fourth in a series of posts mapping global surveillance challenges discussed at EFF's State Surveillance and Human Rights Camp in Rio de Janeiro, Brazil, and examines state-mandated identity verification in South Korea, encryption restrictions and backdoor mandates in India and the United States, and blanket interception facilities required of telecommunications providers in Colombia. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
📰 Published by:
Electronic Frontier Foundation
📅 Date:
13 February 2013
✍️ Authors:
Katitza Rodriguez and Elonnai Hickok
📄 Type:
Blog post
🔗 Original Link:
Read the original post
## Full Text

This is the fourth in a series of posts mapping global surveillance challenges discussed at EFF's State Surveillance and Human Rights Camp in Rio de Janeiro, Brazil. This article has been co-written with Elonnai Hickok — Centre for Internet and Society India, and a speaker at EFF's Camp.


States around the world are faced daily with the challenge of protecting their populations from potential and real threats. To detect and respond to them, many governments surveil communication networks, physical movements, and transactional records. Though surveillance by its nature compromises individual privacy, there are exceptional situations where state surveillance is justified. Yet, if state surveillance is unnecessary or overreaching, with weak legal safeguards and a failure to follow due process, it can become disproportionate to the threat — infringing on people's privacy rights.

Internationally, regulations concerning government surveillance of communications vary in approach and effectiveness, often with very weak or nonexistent legal safeguards. Some countries have strong regulations for the surveillance of communications, yet these regulations may be largely ineffective or unenforceable in practice. Other countries have no legal safeguards or legal standards differing vastly according to the type of communication data targeted. This is why, EFF organized at the end of last year a State Surveillance and Human Rights Camp in Brazil to build upon this discussion and focused on how states are facilitating unnecessary and disproportionate surveillance of communications in ways that lead to privacy violations.

State-Mandated Identity Verification

In 2012 the Constitutional Court in South Korea declared that country's "real-name identification system" unconstitutional. The system had mandated that any online portal with more than 100,000 daily users had to verify the identity of their users.1 This meant that the individual has to provide their real name before posting comments online. The legal challenge to this system was raised by People's Solidarity for Participatory Democracy (PSPD)'s Public Law Center and Korean Progressive Network — Jinbonet among others.

Korea University professor Kyung-shin Park, Chair of PSPD's Law Center told EFF that portals and phone companies would disclose identifying information about six million users annually — in a country of only 50 million people. The South Korean Government was using perceived online abuses as a convenient excuse to discourage political criticism, professor Park told EFF:

The user information shared with the police most commonly has been used by the government to monitor the anti-governmental sentiments of ordinary people. All this has gone on because the government, the legislature, and civil society have not clearly understood the privacy implications of turning over identifying information of individuals.

The decision by the South Korean Constitutional Court to declare the "real identification system" unconstitutional was a win for user privacy and anonymity because it clearly showed that blanket mandates for the disclosure of identifying information, and the subsequent sharing of that data without judicial authorization, are a disproportionate measure that violates the rights of individuals.2

States Restrict Encryption and Demand Backdoors

Some States are seeking to block, ban, or discourage the use of strong encryption and other privacy enhancing tools by requiring assistance in decrypting information. In India service providers are required to ensure that bulk encryption is not deployed. Additionally, no individual or entity can employ encryption with a key longer than 40 bits. If the encryption equipments is higher than this limit, the individual or entity will need prior written permission from the Department of Telecommunications and must deposit the decryption keys with the Department.3 The limitation on encryption in India means that technically any encrypted material over 40 bits would be accessible by the State. Ironically, the Reserve Bank of India issued security recommendations that banks should use strong encryption as higher as 128-bit for securing browser.4

In the United States, under the Communications Assistance for Law Enforcement Act, telecommunication carriers are required to provide decryption assistance only if they already possess the keys (and in many communications system designs, there's no reason carriers should need to possess the keys at all). In 2011, the US Government proposed a bill that would place new restrictions on domestic development or use of cryptography, privacy software, and encryption features on devices. The bill has not been adopted.

Allowing only low levels of encryption and requiring service providers to assist in the decryption of communications, facilitates surveillance by enabling States easier access to data and preventing individuals from using crypto tools to protect their personal communications.

States Establish Blanket Interception Facilities

In Colombia, telecommunications network and service providers carrying out business within the national territory must implement and ensure that interception facilities are available at all times to state agencies as prescribed by law. This is to enable authorized state agencies to intercept communications at any point of time. In addition to providing interception facilities, service providers must also retain subscriber data for a period of five years, and provide information such as subscriber identity, invoicing address, type of connection on request, and geographic location of terminals when requested.

Though Colombia has put in place regulations for the surveillance of communications, these regulations allow for broad surveillance and do not afford the individual clear rights in challenging the same.

Conclusion

The examples above demonstrate that, although state surveillance of communications can be justified in exceptional instances, it leads to the violation of individual privacy when implemented without adequate legal safeguards. Clearly there is a need for international principles articulating critical and necessary components of due process for the surveillance of communications. Those strong legal safeguards are necessary not only in countries that don't have laws in place, but also in countries where laws are lacking and fail to adequately protect privacy. Last year, EFF organized the State Surveillance and Human Rights Camp to discuss a set of International Principles on State Surveillance of Communications, a global effort led by EFF and Privacy International, to define, articulate, and promote legal standards to protect individual privacy when the state carries out surveillance of communications.

Footnotes

  1. Constitutional Court's Decision 2010 Hunma 47, 252 (consolidated) announced August 28, 2012.
  2. The illegality of this practice was proved by a High Court decision handed down 2 months after the Constitutional Court's decision in August 2012. Seoul Appellate Court 2011 Na 19012, Judgment Announced October 18, 2012. This case was prepared and followed singularly by PSPD Public Interest Law Center.
  3. License Agreement for Provision of Internet Services Section 2.2 (vii)
  4. Reserve Bank of India. Internet Banking Guidelines. Section (f (2)).
{% include back-to-top.html %} ## Context and Background In February 2013, the Electronic Frontier Foundation (EFF) published a joint post by Katitza Rodriguez and Elonnai Hickok as part of a series documenting discussions from EFF's State Surveillance and Human Rights Camp, held in Rio de Janeiro, Brazil at the end of 2012. Hickok, then with the Centre for Internet and Society (CIS) in India, had spoken at the Camp, and this fourth instalment in the series drew together three distinct national case studies to illustrate how state surveillance measures can become disproportionate when legal safeguards are weak or absent. The first case examined South Korea's "real-name identification system," which had required any online portal with more than 100,000 daily users to verify users' real identities before they could post comments. The piece cited Korea University professor Kyung-shin Park, Chair of the Public Law Center at People's Solidarity for Participatory Democracy (PSPD), who told EFF that portals and phone companies disclosed identifying information on roughly six million users annually in a country of about 50 million people, and that this data had chiefly been used to monitor anti-government sentiment. South Korea's Constitutional Court struck down the system as unconstitutional in a decision dated 28 August 2012, a ruling the authors characterised as a win for user privacy and anonymity because it rejected blanket disclosure mandates absent judicial authorisation. The second case addressed encryption restrictions and government backdoor demands, contrasting India's regulatory approach with that of the United States. Under India's Internet Service Licence, providers are barred from deploying bulk encryption, and no individual or entity may use encryption keys longer than 40 bits without prior written permission from the Department of Telecommunications, which also requires that decryption keys be deposited with the Department. The authors noted the apparent contradiction between this cap and the Reserve Bank of India's own guidelines, which recommend banks use encryption as strong as 128-bit for browser security. By comparison, the piece described the US Communications Assistance for Law Enforcement Act as requiring telecom carriers to provide decryption assistance only when they already hold the relevant keys, and noted that a 2011 US legislative proposal to further restrict domestic cryptography and privacy software had not been adopted. The third case looked at Colombia, where telecommunications providers operating in the country are legally required to maintain interception capabilities accessible to state agencies at all times, and to retain subscriber data, including identity, billing address, connection type and the geographic location of terminals, for five years. The authors argued that while Colombia's framework was more codified than some other jurisdictions, it still permitted broad surveillance without affording individuals clear avenues to challenge such access. The post concluded by arguing that these three cases collectively demonstrated the need for internationally articulated due process principles governing state surveillance of communications, applicable both to countries lacking legal frameworks altogether and to those whose existing frameworks fail to adequately protect privacy. It referenced the broader effort, led jointly by EFF and Privacy International, to develop a set of International Principles on State Surveillance of Communications. ## External Link - [Surveillance Camp IV: Disproportionate State Surveillance — A Violation of Privacy](https://www.eff.org/deeplinks/2013/02/disproportionate-state-surveillance-violation-privacy) on EFF website - [Surveillance Camp IV: Disproportionate State Surveillance — A Violation of Privacy](https://cis-india.org/internet-governance/blog/eff-feb-13-2013-katitza-rodriguez-and-elonnai-hickok-surveillance-camp-iv-disproportionate-state-surveillance-a-violation-of-privacy) on CIS website {% include navbox-elonnai.html %}