02 July 2018

WTO Panel decision re Tobacco Packaging

Past posts on this blog have referred to the Tobacco Plain Packaging Act 2011 (Cth) - aka TPP - and the Trade Marks Amendment (Tobacco Plain Packaging) Act 2011 (Cth), which provide restrictions on the packaging of tobacco products noted eg here, here, here and here.

The WTO Dispute Resolution Panel in Australia — Certain Measures Concerning Trademarks, Geographical Indications and Other Plain Packaging Requirements Applicable to Tobacco Products and Packaging (DS435, DS441, DS458 and DS467) has now rejected complaints by Cuba, Indonesia, Honduras and the Dominican Republic against that tobacco plain packaging regime.

The Panel considers that the complainants had not demonstrated that the TPP measures are inconsistent with Australia’s obligations under
  • Article 2.2 of the TBT Agreement; 
  • Article 2.1 of the TRIPS Agreement in conjunction with Article 6quinquies of the Paris Convention (1967); 
  • Article 15.4 of the TRIPS Agreement; 
  •  Article 16.1 of the TRIPS Agreement; 
  • Article 20 of the TRIPS Agreement; 
  • Article 2.1 of the TRIPS Agreement in conjunction with Article 10bis of the Paris Convention (1967); 
  • Article 22.2(b) of the TRIPS Agreement; and 
  • Article 24.3 of the TRIPS Agreement.

Australian Government Agencies Privacy Code

The OAIC has announced that The Australian Government Agencies Privacy Code came into effect on 1 July 2018
requiring Australian Government Agencies to move to a best practice approach to privacy governance across the APS, with the ongoing support of the Office of the Australian Information Commissioner (OAIC). 
As with many OAIC announcements, the news is less exiting than it sounds.

Under the Code, agencies are required to
  • have a privacy management plan 
  • appoint a Privacy Officer, or Privacy Officers, and ensure that particular Privacy Officer functions are undertaken
  •  appoint a senior official as a Privacy Champion to provide cultural leadership and promote the value of personal information, and ensure that the Privacy Champion functions are undertaken 
  • undertake a written Privacy Impact Assessment (PIA) for all ‘high privacy risk’ projects or initiatives that involve new or changed ways of handling personal information 
  • keep a register of all PIAs conducted and publish this register, or a version of the register, on their websites 
  • take steps to enhance internal privacy capability, including by providing appropriate privacy education or training in staff induction programs, and annually to all staff who have access to personal information.
In practice we can expect to see the traditional OAIC emphasis on process over outcome, activity counts over quality. Being busy - and having a champion or two - is not synonymous with best practice.

One context for championship is the OAIC's own advocacy. In the past week law academics, health specialists and consumer advocates have been busy tweeting and blogging about #HealthEngineFail, ie controversy regarding that health sector booking service's expungement of negative consumer reviews and sale to law firms of information about people using the service. In essence HealthEngine is making money from a spotters fee, something prohibited in NSW in the tow truck sector. Somewhat dourly I've quipped that people appear to be less valuable than bent cars.

HealthEngine has claimed that users of the service have consented to the sale of their details; critics disagree, claiming that disclosure was inadequate.

As yet, there is no tweet from the OAIC or statement on its site indicating that the agency is aware, concerned, taking action. Mainstream media reports indicate that the national Health Minister has asked for an investigation. The OAIC does have social media and other resources: in recent days it has for example tweeted release of the best practice code and the participation of two senior executives at a conference in San Francisco.

The agency has presumably been in contact with HealthEngine and in time - which judging by past performance may be several months, in contrast to more timely action by ACMA - will presumably release the usual terse statement that there was contact and we should all move on.

That is regrettable. The notion of a 'Privacy Champion' should include the OAIC itself. It should set the stage for the 'champions' in other parts of the Commonwealth administration by using its soft power through timely public statements that address specific controversies and look beyond the specifics to reiterate privacy as a statutorily-recognised value across Australia.

Bureaucratic complaisance is not championship; it is instead a lost opportunity to both foster a privacy-respecting culture and reinforce the legitimacy of the OAIC.

01 July 2018

Demonstrations and Privacy in NSW public places

I have written several times about privacy, freedom of communication, freedom of association and restrictions on protests in public private spaces such as retail malls, parks and public streets. Corneloup and other judgments indicate that restrictions are permissible.

 In New South Wales the state parliament has followed the ACT in passing the Public Health Amendment (Safe Access to Reproductive Health Clinical) Bill 2018 (NSW), which amends the Public Health Act 2010 (NSW) to establish a 150-metre ‘safe access zones’ around abortion clinics. 

The amended Act features the following offences (each with a maximum of six months imprisonment and/or a fine of $5,500 for a first offence, or 12 months in prison and/or a $11,000 fine for a second or subsequent offence) -
 Section 98C – Interfering with access of persons to reproductive health clinics 
(2) A person who is in a safe access zone must not interfere with any person accessing, leaving, or attempting to access or leave, any reproductive health clinic at which abortions are provided. 
(3) A person who is in a safe access zone must not, without reasonable excuse, obstruct or block a footpath or road leading to any reproductive health clinic at which abortions are provided. 
A ‘reproduction health clinic’ is defined as ‘any premises at which medical services relating to aspects of human reproduction or maternal health are provided, but does not include a pharmacy.’ 
The ‘safe access zone’ is: (a) the premises of a reproductive health clinic at which abortions are provided, and (b) the area within 150 metres of: any part of the premises of a reproductive health clinic at which abortions are provided, or (ii) a pedestrian access point to a building that houses a reproductive health clinic at which abortions are provided. ‘Interfere with’ is defined as including, to ‘harass, intimidate, beset, threaten, hinder, obstruct or impede by any means.’ 
Section 98D – Causing actual or potential distress or anxiety to persons in safe access zones 
(1) A person who is in a safe access zone must not make a communication that relates to abortions, by any means, in a manner: (a) that is able to be seen or heard by a person accessing, leaving, attempting to access or leave, or inside, a reproductive health clinic at which abortions are provided, and (b) that is reasonably likely to cause distress or anxiety to any such person. 
Employees and other person who provides services to the reproductive health clinic are exempted. 
Section 98E – Capturing and distributing visual data of persons in safe access zone 
(1) A person must not intentionally capture visual data of another person, by any means, without that other person’s consent if that other person is in a safe access zone. 
(2) A person must not publish or distribute a recording of another person without that other person’s consent if the recording: (a) was made while that other person was in a safe access zone, and (b) contains particulars likely to lead to the identification of that other person. 
‘Capture visual data’ of another person means to capture moving or still images of the other person by a camera or any other means in such a way that: (a) a recording is made of the images, or (b) the images are capable of being transmitted in real time with or without retention or storage in a physical or electronic form, or (c) the images are otherwise capable of being distributed. 
‘Distribute’ means: (a) communicate, exhibit, send, supply or transmit, whether to a particular person or not, or (b) make available for access, whether by a particular person or not, or (c) enter into an agreement or arrangement to do any thing mentioned in paragraph (a) or (b). 
The offence does not apply to: (a) the operation of a security camera, for security reasons only, by or on behalf of a person operating a reproductive health clinic at which abortions are provided, or premises adjacent to or near such a reproductive health clinic, or (b) a person employed or contracted to provide services at the reproductive health clinic at which abortions are provided, or (c) a person otherwise acting for or on behalf of a person operating a reproductive health clinic at which abortions are provided, but only if the visual data is provided either to the person operating the clinic or to a police officer, or (d) a police officer acting in the course of the officer’s duties as a police officer if the officer’s conduct is reasonable in the circumstances for the performance of those duties, or (e) a person who has another reasonable excuse.
The  Crown Land Management Regulation 2018 under the Crown Land Management Act 2016 (NSW) is now in effect, also restricting protests in crown estate land (inc town squares, parks, roads, public beaches and community halls). The Crown Lands Act 1989 (NSW) is replaced.

The Act provides for NSW police, local council officials and state government employees to direct individuals to refrain from conducting activities prescribed in the regulations, including 'taking part in any gathering, meeting or assembly'. It complements the Sydney Public Reserves (Public Safety) Act 2017 (NSW) which provided NSW police with enhanced move on powers, regarding Crown land within the City of Sydney local government area - for example camps in Martin Place - and the Inclosed Lands, Crimes and Law Enforcement Legislation Amendment (Interference) Act 2016 (NSW).  The latter creates a new offence of aggravated unlawful entry on inclosed lands (maximum fine  $5,500) alongside additional police powers to stop, search, detain, and seize the property of protesters

Section 9.5 of the Crown Land Management Act stipulates that the Minister for Lands and Forestry may order “a notice to be displayed in a conspicuous space” that prohibits individuals from carrying out prescribed activities on Crown lands. The Regulation specifies that a penalty notice for failing to comply with a direction will be $1,100. Failing  to comply with a notice has a penalty of $220.

30 June 2018

Trade challenges and public health

'Trade challenges at the World Trade Organization to national noncommunicable disease prevention policies: A thematic document analysis of trade and health policy space' by Pepita Barlow, Ronald Labonte, Martin McKee and David Stuckler in (2018) PLOS Medicine comments
It has long been contested that trade rules and agreements are used to dispute regulations aimed at preventing noncommunicable diseases (NCDs). Yet most analyses of trade rules and agreements focus on trade disputes, potentially overlooking how a challenge to a regulation’s consistency with trade rules may lead to ‘policy or regulatory chill’ effects whereby countries delay, alter, or repeal regulations in order to avoid the costs of a dispute. Systematic empirical analysis of this pathway to impact was previously prevented by a dearth of systematically coded data. ... 
Here, we analyse a newly created dataset of trade challenges about food, beverage, and tobacco regulations among 122 World Trade Organization (WTO) members from January 1, 1995 to December 31, 2016. We thematically describe the scope and frequency of trade challenges, analyse economic asymmetries between countries raising and defending them, and summarise 4 cases of their possible influence. Between 1995 and 2016, 93 food, beverage, and tobacco regulations were challenged at the WTO. ‘Unnecessary’ trade costs were the focus of 16.4% of the challenges. Only one (1.1%) challenge remained unresolved and escalated to a trade dispute. Thirty-nine (41.9%) challenges focussed on labelling regulations, and 18 (19.4%) focussed on quality standards and restrictions on certain products like processed meats and cigarette flavourings. High-income countries raised 77.4% (n = 72) of all challenges raised against low- and lower-middle–income countries. We further identified 4 cases in Indonesia, Chile, Colombia, and Saudi Arabia in which challenges were associated with changes to food and beverage regulations. Data limitations precluded a comprehensive evaluation of policy impact and challenge validity. ... 
Policy makers appear to face significant pressure to design food, beverage, and tobacco regulations that other countries will deem consistent with trade rules. Trade-related influence on public health policy is likely to be understated by analyses limited to formal trade disputes.

BioOffsets

'Are Koalas Fungible? Biodiversity Offsetting and the Law' by David Takacs in (2018) 26 NYU Environmental Law Journal comments
Humans are decimating nonhuman species and ecosystems, undercutting our own life support systems. In response, conservationists are crafting new ideas to sustain the biodiversity that sustains us all, and lawyers and policymakers are sculpting those ideas into law. 
Laws facilitating “biodiversity offsetting” are now on the books or in process in over 100 jurisdictions. Where biodiversity offsetting is permitted, developers may degrade or destroy biodiversity in one place in exchange for “offsetting” the damage elsewhere. 
But is life fungible? What does it signify — for human and nonhuman communities — when laws permit us to destroy koalas with certainty right here and now in exchange for offsetting hypothetical koalas in the future, over yonder? 
This Article describes this burgeoning practice of biodiversity offsetting, drawing on fieldwork in the United States, Australia, South Africa, and the United Kingdom. The Article explores the many, vehement objections to the process, and counter with the responses to those objections. It concludes that given the shortcomings of laws that guide traditional conservation efforts, and the specter of increasing human demands on a planet threatened by global climate change, offsetting done right can be one tool in a reconfigured approach to preserving nonhuman (and thus human) life on Earth. 
But how can offsetting be done “right?” Can it ever be anything other than a sop to developers? This Article develops criteria for what effective biodiversity offsetting would look like, explaining how offsetting can fit into landscape-level planning that serves human and nonhuman needs, and illustrate some examples of “best practice” offsetting from the field. 
The Article concludes with observations about what biodiversity offsetting says about conservation in the twenty-first century and what sustainable biodiversity conservation in the twenty-first century requires of biodiversity offsetting as we careen into a future of exploding human needs, chaotic climate change, and a renewed need to acknowledge our oft-overlooked crucial dependence on the natural world that sustains us all.

Monkey Selfie

'The Monkey Selfie case and the concept of authorship: an EU perspective' by Eleonora Rosati in (2017) 12(1) Journal of Intellectual Property Law and Practice 973–977 comments
 The question whether a macaque named Naruto can be regarded as the author of protectable works (self-portrait photographs, ie selfies) has captured popular attention, and has been the subject of litigation in the USA. Further to the 2016 decision of the US District Court for the Northern District of California that rejected that a monkey could have standing and the subsequent appeal to the Court of Appeals for the Ninth Circuit, the case was settled out of court in 2017. 
This short contribution discusses whether, generally speaking, copyright can vest in works by non-human authors. It does so from the perspective of international and EU laws, addressing issues such as originality, and the concept of ‘authorship’ in relevant legislative texts. 
It concludes that, while there remain ambiguities regarding who can qualify as an author, arguments can be advanced against consideration of works by non-human authors as protectable by copyright. However, the article also highlights how this issue is likely to resurface with reinvigorated force (and relevance) in light of technological advancement, notably in the context of artificial intelligence.
The appeal in the case is noted here.

29 June 2018

Resilience

The latest Australian National Audit Office report on cyber-resilience looks at the Department of the Treasury, National Archives of Australia and Geoscience Australia.  The objective was to assess the effectiveness of the management of cyber risks by those bodies.

ANAO in summary comments
Background 
1. Cyber security is a strategic priority for the Australian government. A secure cyberspace provides trust and confidence for individuals, business and the public sector to share ideas, collaborate and innovate. 
2 To strengthen trust online, effective implementation of a comprehensive cyber security strategy across government systems is critical to protect Australians’ privacy and Australia’s social, economic and national security interests from targeted cyber intrusions and emerging cyber threats. The Attorney-General’s Department Protective Security Policy Framework outlines the core requirements for the effective use of protective information and communications technology (ICT) security. 
2. In February 2017, the Australian Signals Directorate issued the updated Strategies to Mitigate Cyber Security Incidents as a priority list of practical actions entities can take to make their ICT environment more secure. It referred to these cyber security strategies as the Essential Eight and recommended that entities implement the strategies as a security baseline. In June 2017, the Australian Signals Directorate also released the Essential Eight Maturity Model, to assist entities to assess the level of implementation of the Essential Eight mitigation strategies. A revised Model was issued in October 2017. 
3. Of the eight mitigation strategies, four are mandatory (the Top Four).  Since 2013, entities have been required to undertake an annual self-assessment against the mandatory requirements of the Protective Security Policy Framework. Key elements to achieving compliance with the mandatory mitigation strategies are: sufficient investment; appropriate processes; and a culture that recognises the importance of and requirements for cyber resilience. 
4. Three entities were included in the audit: Department of the Treasury (Treasury), National Archives of Australia (National Archives), and Geoscience Australia. These entities were selected based on the character and sensitivity of the information collected, stored and reported. 
5. Since 2013–14, the Australian National Audit Office (ANAO) has conducted three performance audits to assess the cyber resilience of 11 different government entities.4 These audits have identified high rates of non-compliance with the requirements of the Protective Security Policy Framework. 
Audit rationale 
6. The ANAO decided to conduct this fourth audit of entities’ management of cyber risks recognising ongoing parliamentary interest (including enquiries by the Joint Committee of Public Accounts and Audit) and the level of non-compliance with mandatory requirements identified in previous audits. In Report 467: Cybersecurity Compliance, the Joint Committee of Public Accounts and Audit recommended that the ANAO outlines the behaviours and practices it would expect in a cyber resilient entity and assess against these. Audit objective and criteria 
7. The objective of the audit was to assess the effectiveness of the management of cyber risks by the Department of the Treasury, National Archives of Australia and Geoscience Australia. 
8. The audit criteria were: do entities have effective arrangements in place for managing cyber risks; do entities monitor and report against cyber security deliverables; and were entities cyber resilient, with a culture of cyber resilience? 
Conclusion 
9. As with the ANAO’s previous audits of cyber security, this audit identified relatively low levels of effectiveness of Commonwealth entities in managing cyber risks, with only one of the three audited entities compliant with the Top Four mitigation strategies. None of the three entities had implemented the four non-mandatory strategies in the Essential Eight and were largely at early stages of consideration and implementation. These findings provide further evidence that the implementation of the current framework is not achieving compliance with cyber security requirements, and needs to be strengthened. 
10. Of the three entities, only Treasury was compliant with the Top Four mitigation strategies and cyber resilient. National Archives was not compliant with the Top Four mitigation strategies but had sound ICT general controls and so was assessed as not cyber resilient but internally resilient. Geoscience Australia was not compliant with the Top Four mitigation strategies and did not have sound ICT general controls so was assessed as vulnerable to cyber attacks. All three entities had implemented only one of the four non-mandatory mitigation strategies in the Essential Eight, and were not well progressed in considering an implementation position for the other three strategies. Figure S.1 shows each entity’s cyber resilience. 
11. Two entities had accurately self-assessed and reported their level of compliance with the Top Four mitigation strategies, and the other entity had not. There are shortcomings in the Essential Eight Maturity Model that limits its usefulness in its current form, and could lead to entities inadvertently overstating their cyber security compliance if it is used in performing the self-assessment. With activities underway to revise security reporting under the Protective Security Policy Framework, it is timely to also strengthen guidance supporting entities to self-assess compliance with the mandatory mitigation strategies and processes to verify the correctness of those assessments. 
12. The three entities had partly effective arrangements for managing cyber security risks, with specialist staff in dedicated security positions contributing to existing ICT processes and broader business models. However, the entities did not adopt a risk-based approach to prioritise improvements to cyber security, with cyber security investments focused on short-term operational needs rather than long-term strategic objectives. Until the National Archives and Geoscience Australia achieve compliance with the mandatory strategies, it is inappropriate to consider that a positive cyber resilience culture is in place.