--- layout: default title: "State Surveillance and Human Rights Camp: Summary" description: "A CIS blog post by Elonnai Hickok summarizing discussions on communications surveillance, intrusive interception technologies, and the Draft International Principles on the Application of Human Rights to Communications Surveillance from the EFF camp in Rio de Janeiro." authors: ["Elonnai Hickok"] categories: [Elonnai Hickok] date: 2012-12-31 source: "Centre for Internet and Society" permalink: /elonnai/state-surveillance-human-rights-camp-summary/ created: 2026-08-15 homepage_featured: true --- **"State Surveillance and Human Rights Camp: Summary"** is an event summary written by [Elonnai Hickok](/elonnai/) and published by the [Centre for Internet and Society](/cis/) on 31 December 2012. It documents the proceedings of the Surveillance and Human Rights Camp organised by the Electronic Frontier Foundation (EFF) in Rio de Janeiro, Brazil, on 13 and 14 December 2012 as part of the SAFEGUARDS project. The article synthesises global discussions on state surveillance tactics, commercial spyware, deep packet inspection, metadata access, and the collaborative drafting of the *International Principles on the Application of Human Rights to Communications Surveillance*. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
📰 Published by:
Centre for Internet and Society
📅 Date:
31 December 2012
✍️ Author:
Elonnai Hickok
📄 Type:
Blog post
🔗 Original Link:
Read the original post
## Full Text

On December 13 and 14, 2012, the Electronic Frontier Foundation organized the Surveillance and Human Rights Camp held in Rio de Janeiro, Brazil. The meeting examined trends in surveillance, reasons for state surveillance, surveillance tactics that governments are using, and safeguards that can be put in place to protect against unlawful or disproportionate surveillance.


This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC.


The camp also examined different types of data, understanding tools that governments can use to access data, and looked at examples of surveillance measures in different contexts. The camp was divided into plenary sessions and individual participatory workshops, and brought together activists, researchers, and experts from all over the world. Experiences from multiple countries were shared, with an emphasis on the experience of surveillance in Latin America. Among other things, this blog summarizes my understanding of the discussions that took place.

The camp also served as a platform for collaboration on the Draft International Principles on Communications Surveillance and Human Rights. These principles seek to set an international standard for safeguards to the surveillance of communications that recognizes and upholds human rights, and provide guidance for legislative changes related to communications and communications meta data to ensure that the use of modern communications technology does not violate individual privacy. The principles were first drafted in October 2012 in Brussels, and are still in draft form. A global consultation is taking place to bring in feedback and perspective on the principles.

The draft principles were institutionalized for a number of reasons including:

This has placed the individual in a vulnerable position as opaque surveillance of communications is carried out by governments across the world — the abuse of which is unclear. The principles try to address these challenges by establishing standards and safeguards which should be upheld and incorporated into legislation and practices allowing the surveillance of communications.

A summary of the draft principles is below. As the principles are still a working draft, the most up to date version of the principles can be accessed here.

Summary of the Draft International Principles on Communications Surveillance and Human Rights

Types of Data

The conversations during the camp reviewed a number of practices related to surveillance of communications, and emphasized the importance of establishing the draft principles. Setting the background to various surveillance measures that can be carried out by the government, the different categories of communication data that can be easily accessed by governments and law enforcement were discussed. For example, law enforcement frequently accesses information such as IP address, account name and number, telephone number, transactional records, and location data. This data can be understood as 'non-content' data or communication data, and in many jurisdictions can easily be accessed by law enforcement/governments, as the requirements for accessing communication data are lower than the requirements for accessing the actual content of communications. For example, in the United States a court order is not needed to access communication data whereas a judicial order is needed to access the content of communications.1 Similarly, in the UK law enforcement can access communication data with authorization from a senior police officer.2

It was discussed how it is concerning that communication data can be accessed easily, as it provides a plethora of facts about an individual. Given the sensitivity of communication data and the ability for personal information to be derived from the data, the ease that law enforcement is accessing the data, and the unawareness of the individual about the access- places the privacy of users at risk.

Ways of Accessing Data

Ways in which governments and law enforcement access information and associated challenges was discussed, both in terms of the legislation that allows for access and the technology that is used for access.

Access and Technology

In this discussion it was pointed out that in traditional forms of accessing data governments are no longer effective for a number of reasons. For example, in many cases communications and transactions, etc., that take place on the internet are encrypted. The ubiquitous use of encryption means more protection for the individual in everyday use of the internet, but serves as an obstacle to law enforcement and governments, as the content of a message is even more difficult to access. Thus, law enforcement and governments are using technologies like commercial surveillance software, targeted hacking, and malware to survey individuals. The software is sold off the shelf at trade shows by commercial software companies to law enforcement and governments. Though the software has been developed to be a useful tool for governments, it was found that in some cases it has been abused by authoritarian regimes. For example in 2012, it was found that FinSpy, a computer espionage software made by the British company Gamma Group was being used to target political dissidents by the Government of Bahrain. FinSpy has the ability to capture computer screen shots, record Skype chats, turn on computer cameras and microphones, and log keystrokes.3

In order to intercept communications or block access to sites, governments and ISPs also rely on the use of deep packet inspection (DPI).4 Deep packet inspection is a tool traditionally used by internet service providers for effective management of the network. DPI allows for ISP's to monitor and filter data flowing through the network by inspecting the header of a packet of data and the content of the packet.5 With this information it is possible to read the actual content of packets, and identify the program or service being used.6

DPI can be used for the detection of viruses, spam, unfair use of bandwidth, and copyright enforcement. At the same time, DPI can allow for the possibility of unauthorized data mining and real time interception to take place, and can be used to block internet traffic whether it is encrypted or not.7

Governmental requirements for deep packet inspection can in some cases be found in legislation and policy. In other cases it is not clear if it is mandatory for ISP's to provide DPI capabilities, thus the use of DPI by governments is often an opaque area. Recently, the ITU has sought to define an international standard for deep packet inspection known as the "Y.2770" standard. The standard proposes a technical interoperable protocol for deep packet inspection systems, which would be applicable to "application identification, flow identification, and inspected traffic types".8

Access and Legislation

The discussions also examined similarities across legislation and policy which allows governments legal access to data. It was pointed out that legislation providing access to different types of data is increasingly becoming outdated, and is unable to distinguish between communications data and personal data. Thus, relevant legislation is often based on inaccurate and outdated assumptions about what information would be useful and what types of safeguards are necessary. For example, it was discussed how US surveillance law has traditionally established safeguards based on assumptions like: surveillance of data on a personal computer is more invasive than access to data stored in the cloud, real-time surveillance is more invasive than access to stored data, surveillance of newer communications is more invasive than surveillance of older communications, etc. These assumptions are no longer valid as information stored in the cloud, surveillance of older communications, and surveillance of stored data can be more invasive than access to newer communications, etc. It was also discussed that increasingly relevant legislation also contains provisions that have generic access standards, unclear authorization processes, and provide broad circumstances in which communication data and content can be accessed. The discussion also examined how governments are beginning to put in place mandatory and extensive data retention plans as tools of surveillance. These data retention mandates highlight the changing role of internet intermediaries including the fact that they are no longer independent from political pressure, and no longer have the ability to easily protect clients from unauthorized surveillance.

Notes

  1. Electronic Frontier Foundation. Mandatory Data Retention: United States. Available at: EFF Data Retention US Page.
  2. Espiner, Tom. "Communications Data Bill: Need to Know." ZDNet, 18 June 2012. Available at: ZDNet Article on Communications Data Bill.
  3. Perlroth, Nicole. "Software Meant to Fight Crime is Used to Spy on Dissidents." The New York Times, 30 August 2012. Available at: NYT Article on FinSpy Malware.
  4. Wawro, Alex. "What is Deep Packet Inspection?" PCWorld, 1 February 2012. Available at: PCWorld Article on DPI.
  5. Geere, Duncan. "How deep packet inspection works." Wired, 27 April 2012. Available at: Wired Article on Deep Packet Inspection.
  6. Kassner, Michael. "Deep Packet Inspection: What You Need to Know." TechRepublic, 27 July 2008. Available at: TechRepublic Article on DPI.
  7. Anonyproz. How to Bypass Deep Packet Inspection Devices or ISPs Blocking Open VPN Traffic. Available at: Anonyproz Knowledgebase Guide.
  8. Chirgwin, Richard. "Revealed: ITU's deep packet snooping standard leaks online: Boring tech doc or Internet eating monster." The Register, 6 December 2012. Available at: The Register Article on ITU Y.2770 Standard.
{% include back-to-top.html %} ## Context and Background In December 2012, the Electronic Frontier Foundation (EFF) organised a Surveillance and Human Rights Camp in Rio de Janeiro, Brazil. Held on 13 and 14 December, the camp brought together activists, researchers and experts to discuss trends in government surveillance, the reasons for surveillance, technologies used to obtain information, and safeguards against unlawful or disproportionate surveillance. The event was connected to the SAFEGUARDS research project involving the Centre for Internet and Society (CIS), Privacy International and the International Development Research Centre (IDRC). A significant part of the camp's discussions concerned the Draft International Principles on the Application of Human Rights to Communications Surveillance. The principles had first been drafted in Brussels in October 2012 and were still under consultation at the time of the camp. They sought to establish safeguards for government surveillance of communications and to provide guidance for laws and practices concerning communications and communications metadata. The discussions identified several challenges in existing approaches to communications surveillance. Elonnai's summary notes that laws and safeguards were often becoming outdated as surveillance technologies and practices changed. Proposed legislation in different jurisdictions was also increasingly addressing access to communications data across borders and placing extensive obligations on private companies, including requirements relating to data retention and surveillance capabilities. At the same time, surveillance practices could involve limited public transparency and limited opportunities for individuals to challenge or seek redress against access to their communications. The camp also examined the distinction between communications content and other forms of communications data, such as IP addresses, account information, telephone numbers, transactional records and location data. Elonnai notes that such information was often subject to lower access requirements than the actual content of communications, while still revealing significant information about an individual's activities and associations. Another area of discussion was the growing use of technological tools for accessing information. The article describes commercial surveillance software, targeted hacking and malware as tools being used by governments and law enforcement, and discusses the reported use of FinSpy against political dissidents in Bahrain. It also examines deep packet inspection (DPI), which can be used by network operators for purposes such as traffic management and security but can also enable monitoring, filtering and interception of network traffic. The discussions further considered how existing legislation was struggling to account for changing patterns of communication and data storage. Traditional legal distinctions between different types of data and different forms of access did not always reflect the way information was being stored and communicated through the Internet. The article also notes the increasing use of data retention requirements and the resulting changes in the relationship between governments, law enforcement and Internet intermediaries. Overall, the camp brought together discussion of surveillance practices, technological capabilities and legal safeguards around a common concern: how governments can exercise surveillance powers while protecting individual privacy and other human rights. Elonnai's summary records the emerging principles and the range of issues discussed at the camp rather than presenting them as a final or settled international framework. ## External Link - [State Surveillance and Human Rights Camp: Summary](https://cis-india.org/internet-governance/blog/state-surveillance-human-rights-camp-summary) on CIS website {% include navbox-elonnai.html %}