Metadata Regulations and Which Data?
https://www.telcoinabox.com.au/2018/02/18/australias-new-metadata-laws-implications-telcos/
Australia’s new metadata regulations came into effect in March 2015. Under the new rules, commercial telcos are to start retaining metadata from October 2015. This data must be kept in encrypted form and secured for two years. These changes were made to allow securities agencies and other law-enforcement bodies access metadata without a warrant.
Why has the government introduced these changes?
According to the Attorney-General’s Department, the new data retention laws are needed because telcos are keeping less data and keeping it for shorter periods of time. Retaining metadata supports the work of Australia’s security agencies and other law-enforcement bodies working to address serious crimes, counter-terrorism, and other security and criminal challenges. Agencies that can access the metadata include ASIO, the ATO, the Australian Crime Commission, and the police.
Which businesses are affected by the changes?
The new regulations affect most telecommunication providers carrying or enabling communications. Licensed carriers, Internet service providers, and carriage service providers will come under the new rules. Section 23 of the Telecommunications Act 1997 lists exceptions such as hobbyist providers and government agencies.
What data needs to be kept?
The regulations set out six key types of metadata to be retained by service providers. This data includes information that can be used to identify account holders, the source and destination of communications, and the location of the equipment or service line. The data to be retained doesn’t cover the actual content of communications, such as Internet browsing histories, the content of emails, or phone conversations.
- Account holder information – This includes contact details, payment information, and service information for the account.
- Source of the communication – Examples are mobile or landline numbers used to make calls or send text messages, or originating IP addresses.
- Destination of the communication – Examples include phone numbers or IP addresses.
- Date, time, and duration information – The date, time, and duration information of the communication or connection to the service.
- Type of communication and service – Whether it was a text, chat, social media, email, or some other type of communication. Telcos are to keep data on whether the service was VoIP, ADSL, Wi-Fi, or another service category.
- Location of equipment or line – Data on the location of the phone line or service line at the beginning and at the end of the communication. Examples are an ADSL subscriber’s address, the cell towers accessed, and data on the Wi-Fi hotspots used.
How long do providers have to keep the metadata?
Telcos must keep the information for two years after the data is first created. While technically service providers need to start retaining data from the 13th of October, 2015, providers can submit data retention implementation plans and applications for exemptions for a more gradual compliance process that reflects their business situation.
Implications for businesses
Some reports have suggested that only one in five providers are ready to implement the retention scheme. Other reports show that some telcos are confused about how to integrate the requirements into their business, with only 11% of providers feeling very confident they understand their obligations. Most major providers will not be fully compliant with their data retention obligations for another 18 months, an unsurprising outcome given the large scale of the changes.
Cost and Data Security
Like any change in compliance requirements, the metadata retention scheme means implementation costs for telcos. In addition to retaining the data, the changes to the law require providers to safeguard the metadata by encryption, and to protect data from unauthorised interference and access.
The storage, infrastructure, and encryption requirements will form the core cost of implementation. According to a study by PricewaterhouseCoopers, the upfront industry-wide cost to telecommunications businesses is unlikely exceed $319.1 million, which around 1% of the sector’s annual revenue. This year’s federal budget has set aside $131.3 million over three years in grants to assist the sector with implementing the scheme, but exact details have yet to be released.
Implementation plans, exemptions, and variations
According to the Communications Alliance, the Attorney-General’s Department is working collaboratively with service providers on compliance rather than taking a strict enforcement approach. The Attorney-General has also indicated that implementation is a stronger priority than enforcement at this stage.
The government is offering providers a transitional pathway through data retention implementation plans, which allow telcos more time to comply with the scheme. Businesses can submit a data retention implementation plan to the Communications Access Coordinator of the Attorney-General’s Department. If the Coordinator approves the plan, the provider can delay implementation until 12th April 2017, at the latest.
Telcos can also apply to the Coordinator for specific exemptions and/or variations for their retention obligations. These are considered on a case-by-case basis, and the decision of the Coordinator are kept confidential.
Major providers such as Telstra, Optus, and Vodafone have already moved ahead with data retention implementation plans and/or compliance plans. However, at this stage, hundreds of providers have not yet provided plans, and the government has processed just 79 of the 229 plans already submitted. As John Stanton of Communications Alliance noted, many telcos won’t be fully compliant simply because they’re still waiting to hear back about their implementation plans.
Without doubt, these new metadata regulations are asking service providers to make big changes to their data management practices. However, the data retention implementation plans offer providers a flexible option for setting out their own pathway to compliance. With careful planning and a clear understanding of their obligations and options, all telcos can have a smooth and gradual transition to full compliance. And while the majority of telecommunications providers will not assist a reseller with the new Metadata laws, Telcoinabox is the only supplier to state publicly that we will assist our resellers in becoming Metadata-law compliant. To switch your resales over to us for assistance or to find out more about becoming an AAPT Wholesale, Optus Wholesale, Telstra Wholesale and Vocus Wholesale or a reseller, get in touch today.
“Gentleness, self-sacrifice and generosity are the exclusive possession of no one race or religion.”
- 1 Worldpeacefull Empowerment Training
- 2 Happiness Is Our True Nature
- 3 Clowning Around Australia
- 4 Clowning Around The World
- 5 Peace For The World
- Byron Katie in Israel 2007 – The Arab/Jew conflict
- Syria: Deadly reprisals: Deliberate killings and other abuses by Syria’s armed forces
- WWF Living Planet Summary Report 2012