15 November 2019

Privacy Principles

'Privacy Design Strategies' by Jaap-Henk Hoepman in N. Cuppens-Boulahia et al (eds.) SEC 2014, IFIP AICT (International Federation for Information Processing, 2014) defines the notion of a privacy design strategy.

Hoepman comments
These strategies help IT architects to support privacy by design early in the software development life cycle, during concept development and analysis. Using current data protection legislation as point of departure we derive the following eight privacy design strategies:
  • MINIMISE,
  • HIDE, 
  • SEPARATE, 
  • AGGREGATE, 
  • INFORM, 
  • CONTROL, 
  • ENFORCE, and 
  • DEMONSTRATE.
The strategies also provide a useful classification of privacy design patterns and the underlying privacy enhancing technologies. We therefore believe that these privacy design strategies are not only useful when designing privacy friendly systems, but also helpful when evaluating the privacy impact of existing IT systems.
Privacy by design [5] is a system design philosophy that aims to improve the overall privacy1 friendliness of IT systems. Point of departure is the observation that privacy (like security) is a core property of a system that is heavily influenced by the underlying system design. As a consequence, privacy protection cannot be implemented as an add- on. Privacy must be addressed from the outset instead. The fundamental principle of privacy by design is, therefore, that privacy requirements must be addressed throughout the full system development process. In other words starting when the initial concepts and ideas for a new system are drafted, up to and including the final implementation of that system. Privacy by design is gaining importance. For example, the proposal for a new European data protection regulation [10] explicitly requires data protection by design and by default. It is therefore crucial to support developers in satisfying these requirements with practical tools and guidelines.
As explained in Section 2, an important design methodology is the application of so called software design patterns. These design patterns refine the system architecture to achieve certain functional requirements within a given set of constraints. During soft- ware development the availability of practical methods to protect privacy is high during actual implementation, but low when starting the project. Numerous privacy enhanc- ing technologies (PETs) exists that can be applied more or less ’off the shelf’. Before that implementation stage, privacy design patterns can be used during system design. Significantly less design patterns exist compared to PETs, however. And at the start of the project, during the concept development and analysis phases, the developer stands basically empty handed.
This paper aims to close this gap [13,26]. Design patterns do not necessarily play a role in the earlier, concept development and analysis, phases of the software develop- ment cycle. The main reason is that such design patterns are already quite detailed in nature, and more geared towards solving an implementation problem. To guide the de- velopment team in the earlier stages, we define the notion of a privacy design strategy. Because these strategies describe fundamental, more strategic, approaches to protecting privacy, they enable the IT developer to make well founded choices during the concept development and analysis phase as well. These choices have a huge impact on the over- all privacy protection properties of the final system.
The privacy design strategies developed in this paper are derived from existing pri- vacy principles and data protection laws. These are described in section 3. We focus on the principles and laws on which the design of an IT system has a potential impact. By taking an abstract information storage model of an IT system as a point of departure, these legal principles are translated to a context more relevant for the IT developer in section 4. This leads us to define the following privacy design strategies: MINIMISE, HIDE, SEPARATE, AGGREGATE, INFORM, CONTROL, ENFORCE and DEMONSTRATE. They are described in detail in section 5.
We believe these strategies help to support privacy by design throughout the full software development life cycle, even before the design phase. It makes explicit which high level decisions can be made to protect privacy, when the first concepts for a new information system are drafted. The strategies also provide a useful classification of pri- vacy design patterns and the underlying privacy enhancing technologies. We therefore believe that these privacy design strategies are not only useful when designing privacy friendly systems, but that they also provide a starting point for evaluating the privacy impact of existing information systems.

Teaching

Teaching Law Students about Sexual Orientation, Gender Identity and Intersex Status within Human Rights Law: Seven Principles for Curriculum Design and Pedagogy' by Paula Gerber and Claerwen O’Hara in (2019) 68(2) Journal of Legal Education comments
Over the past two decades, sexual orientation, gender identity, and intersex status (SOGII) have become important aspects of human rights law. However, this reality is not widely reflected in the curriculum of human rights law programs. The reasons for this are varied but may include wariness about causing offense by using the wrong terminology or language and concern about the complexities and sensitivities surrounding different issues. This article aims to assist law school educators to overcome these concerns by providing curricular and pedagogical guidance relating to the effective and comprehensive incorporation of SOGII into a human rights law program. In particular, it provides recommendations for educators who wish to establish a stand-alone course on SOGII and human rights, as well as for those who would like to incorporate SOGII-related issues into a more general human rights law course. 
It begins with an overview of the existing scholarship concerning the incorporation of SOGII issues into the law school curriculum. This analysis provides insight into the importance of teaching law students about SOGII, as well as some recommendations on how to do so. However, it also highlights how little scholarly attention has been given to the teaching of SOGII issues in the human rights law setting. 
The article then goes on to posit seven curricular and pedagogical principles on how to teach SOGII issues in the specific context of human rights law. Together, these principles provide a holistic and critical approach that responds to unique aspects of human rights law, including its international focus and the “living” nature of human rights law instruments. This method involves incorporating interdisciplinary topics such as the historical treatment of sexual and gender identity minorities, highlighting the relevance of international relations and political science to rights relating to SOGII, and developing an understanding of queer theory. It also entails examining a wide variety of international and regional human rights norms and processes, as well as applicable domestic laws. In addition, this method encourages an exploration of the role that local and international nongovernmental organizations (NGOs) play in protecting rights relating to SOGII.
There is a somewhat different approach in my ‘Silences And Sexual Diversity: Difference, Comfort And Emulation In Australian First Year Law Teaching And Beyond’ in (2019) 21(1) Flinders Law Journal 49-72.

Corporate Criminal Responsibility

The Australian Law Reform Commission Corporate Criminal Responsibility Discussion Paper (DP 87, 2019) comments that the ALRC has found that
Commonwealth criminal law as it applies to corporations is impenetrably complex and in need of significant reform. There is an overregulation by the criminal law of low-level contraventions and a failure to effectively use the criminal law for serious contraventions.
The Commission offers the following Questions and Proposals 
4. Appropriate and Effective Regulation of Corporations 
Proposal 1 Commonwealth legislation should be amended to recalibrate the regulation of corporations so that unlawful conduct is divided into three categories (in descending order of seriousness): a) criminal offences; b) civil penalty proceeding provisions; and c) civil penalty notice provisions. 
Proposal 2 A contravention of a Commonwealth law by a corporation should only be designated as a criminal offence when: a) the contravention by the corporation is deserving of denunciation and condemnation by the community; b) the imposition of the stigma that attaches to criminal offending is appropriate; c) the deterrent characteristics of a civil penalty are insufficient; and d) there is a public interest in pursuing the corporation itself for criminal sanctions. 
Proposal 3 A contravention of a Commonwealth law by a corporation that does not meet the requirements for designation as a criminal offence should be designated either: a) as a civil penalty proceeding provision when the contravention involves actual misconduct by the corporation (whether by commission or omission) that must be established in court proceedings; or b) as a civil penalty notice provision when the contravention is prima facie evident without court proceedings. 
Proposal 4 When Commonwealth legislation includes a civil penalty notice provision: a) the legislation should specify the penalty for contravention payable upon the issuing of a civil penalty notice; b) there should be a mechanism for a contravenor to make representations to the regulator for withdrawal of the civil penalty notice; and c) there should be a mechanism for a contravenor to challenge the issuing of the civil penalty notice in court if the civil penalty notice is not withdrawn, with costs to follow the event. 
Proposal 5 Commonwealth legislation containing civil penalty provisions for corporations should be amended to provide that when a corporation has: a) been found previously to have contravened a civil penalty proceeding provision or a civil penalty notice provision, and is found to have contravened the provision again; or b) contravened a civil penalty proceeding provision or a civil penalty notice provision in such a way as to demonstrate a flouting of or flagrant disregard for the prohibition; the contravention constitutes a criminal offence. 
Proposal 6 The Attorney-General’s Department (Cth) Guide to Framing Commonwealth Offences, Infringement Notices and Enforcement Powers should be amended to reflect the principles embodied in Proposals 1 to 5 and to remove Ch 2.2.6. 
Proposal 7 The Attorney-General’s Department (Cth) should develop administrative mechanisms that require substantial justification for criminal offence provisions that are not consistent with the Guide to Framing Commonwealth Offences, Infringement Notices and Enforcement Powers as amended in accordance with Proposal 6. 
6. Reforming Corporate Criminal Responsibility 
Proposal 8 There should be a single method for attributing criminal (and civil) liability to a corporation for the contravention of Commonwealth laws, pursuant to which: a) the conduct and state of mind of persons (individual or corporate) acting on behalf of the corporation is attributable to the corporation; and b) a due diligence defence is available to the corporation. 
7. Individual Liability for Corporate Conduct 
Proposal 9 The Corporations Act 2001 (Cth) should be amended to provide that, when a body corporate commits a relevant offence, or engages in conduct the subject of a relevant offence provision, any officer who was in a position to influence the conduct of the body corporate in relation to the contravention is subject to a civil penalty, unless the officer proves that the officer took reasonable measures to prevent the contravention. Proposal 10 The Corporations Act 2001 (Cth) should be amended to include an offence of engaging intentionally, knowingly, or recklessly in conduct the subject of a civil penalty provision as set out in Proposal 9. 
Question A Should Proposals 9 and 10 apply to ‘officers’, ‘executive officers’, or some other category of persons? 
Question B Are there any provisions, either in Appendix I or any relevant others, that should not be replaced by the provisions set out in Proposals 9 and 10? 
8. Whistleblower Protections 
Proposal 11 Guidance should be developed to explain that an effective corporate whistleblower protection policy is a relevant consideration in determining whether a corporation has exercised due diligence to prevent the commission of a relevant offence. 
Question C Should the whistleblower protections contained in the Corporations Act 2001 (Cth), Taxation Administration Act 1953 (Cth), Banking Act 1959 (Cth), and Insurance Act 1973 (Cth) be amended to provide a compensation scheme for whistleblowers? 
Question D Should the whistleblower protections contained in the Corporations Act 2001 (Cth), Taxation Administration Act 1953 (Cth), Banking Act 1959 (Cth), and Insurance Act 1973 (Cth) be amended to apply extraterritorially? 
9. Deferred Prosecution Agreements 
Question E Should a deferred prosecution agreement scheme for corporations be introduced in Australia, as proposed by the Crimes Legislation Amendment (Combatting Corporate Crime) Bill 2017, or with modifications? 
10. Sentencing Corporations 
Proposal 12 Part IB of the Crimes Act 1914 (Cth) should be amended to implement the substance of Recommendations 4–1, 5–1, 6–1, and 6–8 of Same Crime, Same Time: Sentencing of Federal Offenders (ALRC Report 103, April 2006). 
Proposal 13 The Crimes Act 1914 (Cth) should be amended to require the court to consider the following factors when sentencing a corporation, to the extent they are relevant and known to the court: a) the type, size, internal culture, and financial circumstances of the corporation; b) the existence at the time of the offence of a compliance program within the corporation designed to prevent and detect criminal conduct; c) the extent to which the offence or its consequences ought to have been foreseen by the corporation; d) the involvement in, or tolerance of, the criminal activity by management; e) whether the corporation ceased the unlawful conduct voluntarily and promptly upon its discovery of the offence; f) whether the corporation self-reported the unlawful conduct;  g) any advantage realised by the corporation as a result of the offence; h) the extent of any efforts by the corporation to compensate victims and repair harm; i) any measures that the corporation has taken to reduce the likelihood of its committing a subsequent offence, including: i. internal investigations into the causes of the offence; ii. internal disciplinary actions; and iii. measures to implement or improve a compliance program; and j) the effect of the sentence on third parties. This list should be non-exhaustive and should supplement rather than replace the general sentencing factors, principles, and purposes as amended in accordance with Proposal 12. 
Proposal 14 The Corporations Act 2001 (Cth) should be amended to require the court to consider the following factors when imposing a civil penalty on a corporation, to the extent they are relevant and known to the court, in addition to any other matters: a) the nature and circumstances of the contravention; b) any injury, loss, or damage resulting from the contravention; c) any advantage realised by the corporation as a result of the contravention; d) the personal circumstances of any victim of the offence; e) the type, size, internal culture, and financial circumstances of the corporation; f) whether the corporation has previously been found to have engaged in any related or similar conduct; g) the existence at the time of the contravention of a compliance program within the corporation designed to prevent and detect the unlawful conduct; h) whether the corporation ceased the unlawful conduct voluntarily and promptly upon its discovery of the contravention; i) the extent to which the contravention or its consequences ought to have been foreseen by the corporation; j) the involvement in, or tolerance of, the contravening conduct by management; k) the degree of cooperation with the authorities, including whether the contravention was self-reported; l) whether the corporation admitted liability for the contravention; m) the extent of any efforts by the corporation to compensate victims and repair harm; n) any measures that the corporation has taken to reduce the likelihood of its committing a subsequent contravention, including: i. any internal investigation into the causes of the contravention; ii. internal disciplinary actions; and iii. measures to implement or improve a compliance program; o) the deterrent effect that any order under consideration may have on the corporation or other corporations; and p) the effect of the penalty on third parties. 
Proposal 15 The Crimes Act 1914 (Cth) should be amended to provide the following sentencing options for corporations that have committed a Commonwealth offence: a) orders requiring the corporation to publicise or disclose certain information; b) orders requiring the corporation to undertake activities for the benefit of the community; c) orders requiring the corporation to take corrective action within the organisation, such as internal disciplinary action or organisational reform; d) orders disqualifying the corporation from undertaking specified commercial activities; and e) orders dissolving the corporation. 
Proposal 16 The Corporations Act 2001 (Cth) should be amended to provide the following non-monetary penalty options for corporations that have contravened a Commonwealth civil penalty provision: a) orders requiring the corporation to publicise or disclose certain information; b) orders requiring the corporation to undertake activities for the benefit of the community; c) orders requiring the corporation to take corrective action within the organisation, such as internal disciplinary action or organisational reform; and d) orders disqualifying the corporation from undertaking specified commercial activities. 
Proposal 17 The Corporations Act 2001 (Cth) should be amended to provide that a court may make an order disqualifying a person from managing corporations for a period that the court considers appropriate, if that person was involved in the management of a corporation that was dissolved in accordance with a sentencing order. 
Question F Are there any Commonwealth offences for which the maximum penalty for corporations requires review? 
Question G Should the maximum penalty for certain offences be removed for corporate offenders? 
Question H Do court powers need to be reformed to better facilitate the compensation of victims of criminal conduct and civil penalty proceeding provision contraventions by corporations? 
Proposal 18 The Australian Government, together with state and territory governments, should develop a unified debarment regime. 
Proposal 19 The Crimes Act 1914 (Cth) should be amended to permit courts to order pre-sentence reports for corporations convicted of Commonwealth offences. 
Question I Who should be authorised to prepare pre-sentence reports for corporations? 
Proposal 20 Sections 16AAA and 16AB of the Crimes Act 1914 (Cth) should be amended to permit courts, when sentencing a corporation for a Commonwealth offence, to consider victim impact statements made by a representative on behalf of a group of victims and/or a corporation that has suffered economic loss as a result of the offence. 
11. Illegal Phoenix Activity 
Proposal 21 The Treasury Laws Amendment (Combating Illegal Phoenixing) Bill 2019 should be amended to: a) provide that only a court may make orders undoing a creditor-defeating disposition by a company, on application by either the liquidator of that company or the Australian Securities and Investments Commission; and b) provide the Australian Securities and Investments Commission with the capacity to apply to a court for an order that any benefits obtained by a person from a creditor-defeating disposition be disgorged to the Commonwealth, rather than to the original company, where there has been no loss to the original company or the original company has been set up to facilitate fraud. 
Proposal 22 The Treasury Laws Amendment (Combating Illegal Phoenixing) Bill 2019 should be amended to: a) provide the Australian Securities and Investments Commission and the Australian Taxation Office with a power to issue interim restraining notices in respect of assets held by a company where it has a reasonable suspicion that there has been, or will imminently be, a creditor-defeating disposition; b) require the Australian Securities and Investments Commission and the Australian Taxation Office to apply to a court within 48 hours for imposition of a continuing restraining order; and c) grant liberty to companies or individuals the subject of a restraining notice to apply immediately for a full de novo review before a court. 
Proposal 23 The Corporations Act 2001 (Cth) should be amended to establish a ‘director identification number’ register. 
Question J Should there be an express statutory power to disqualify insolvency and restructuring advisors who are found to have contravened the proposed creditordefeating disposition provisions? 
Question K Are there any other legislative amendments that should be made to combat illegal phoenix activity? 
12. Transnational Business 
Question L Should the due diligence obligations of Australian corporations in relation to extraterritorial offences be expanded?

14 November 2019

Soundscapes

'Sonic Havens: Towards a Goffmanesque Account of Homely Listening' by Michael James Walsh and Eduardo de la Fuente in (2019) Housing, Theory and Society comments
Drawing upon Goffman’s notion of the interaction order we propose that home and homeliness pertain to the degree to which we can control our auditory involvements with the world and with others. What we term “homely listening” concerns the use of music to make oneself feel at home, in some cases, through seclusion and immersion, and, in others, through either the musical ordering of mundane routines or the use of music to engage in sociality with others. Drawing on 29 in-depth qualitative interviews concerning mundane instances of musical listening, we propose the home is a complex sonic order involving territoriality as well as the aesthetic framing of activity through musical and non-musical sounds. We argue the home represents a negotiated sonic interaction order where individuals skilfully manage involvements with others and activities through their musical and other sound practices.
 The authors note
 This article offers an analysis of a phenomenon we term “homely listening”, and the social and material relations that underpin it, via a framework primarily derived from the microsociology of Erving Goffman. As Manning (1992, 154) observes Goffman’s approach is to transform ethnographies of places, such as the Shetland Islands, hospitals, asylums, and sidewalks into ethnographies of concepts, such as presentation of self, encounters, face-work, territories of the self, etc. As such we aim to contribute to the socio-cultural study of urban sensory ecologies via an ethnography of the phenomenon of homely listening. Our argument is that homely listening may or may not coincide with the strict physical boundaries of the home; and, in any case, the latter gives rise to a range of private and shared modalities of listening. In short, the home is fundamentally a negotiated socio-material, as well as complex sonic order. We follow the foundational efforts of sociologists and other socio-cultural researchers interested in music’s role in everyday life such as DeNora (2000, 2003) and Bull (2007). We also concur with Nowak and Bennett (2014, 375) who suggest that studying musical listening requires a focus on “sound environments”: meaning the spaces, temporal orientations, bodily states and choice of technologies, that enable the consumption of music in everyday life. Our approach therefore focuses on one central sound phenomena within the home: the use of music as a means of aestheticizing and manufacturing domestic sonic havens. This approach provides our argument with an empirical anchorage point, allowing for the exploration of how music and its placement within the home responds to and signifies the presence of a finely balanced auditory interaction order.

05 November 2019

Legal practitioner and police fraud

In Legal Profession Conduct Commissioner v Semaan [2017] SASCFC 19 the South Australian Supreme Court stated
This is an application by the Legal Profession Conduct Commissioner (the Commissioner) seeking an order that the name Fadi Semaan (the Practitioner) be struck off the roll of legal practitioners. The Practitioner does not oppose that order. 
2 In December 2010, the Practitioner was conferred a Bachelor of Laws and Legal Practice by Flinders University. He was engaged as an associate in the High Court of Australia during 2011. 
3 In January 2012, towards the end of his associateship, the Practitioner applied to a law firm (the firm) for employment as a solicitor. He sent the firm a copy of his curriculum vitae (CV) by email on 17 January 2012. The Practitioner later admitted having falsified the part of his CV which set out his work experience. 
4 On or about 2 February 2012, the Practitioner deliberately altered his academic transcript using computer imaging technology. On the altered transcript he:
  • elevated his law degree to show that he had been conferred Honours when he had not; 
  • falsified 21 subject grades in his law degree, generally increasing his grades to distinctions and high distinctions; and 
  • forged a commerce degree, which he had never been awarded.
5 On 6 February 2012 the Practitioner was admitted to practice as a barrister and solicitor in the Supreme Court of South Australia. On 10 February 2012, four days after his admission, the Practitioner sent the altered transcript (dated 2 February 2012) to the firm by email in support of his application for employment. 
6 It was the second time that the Practitioner had provided a falsified academic record to the firm. The first time was in 2010 on an unsuccessful attempt to obtain a clerkship. However, the Practitioner was successful on this second attempt and was employed by the firm on 2 April 2012. On 29 June 2012, he resigned from his employment. 
7 On 14 August 2012 the firm discovered that the Practitioner’s altered transcript was fraudulent after noting discrepancies between the transcript he had submitted in 2010 and the altered transcript submitted on 10 February. The firm reported the matter to the Law Society of South Australia, who then reported the matter to the Legal Practitioners Conduct Board, pursuant to s 14AB of the Legal Practitioners Act 1981 (SA) (the Legal Practitioners Act).
Meanwhile, we might be asking some disquieting questions about the effectiveness of vetting in the Victoria Police.

Following an IBAC investigation (labelled Operation Salina) The Age reports
A senior Victoria Police officer has pleaded guilty to 10 fraud offences, including dishonestly obtaining six properties and rorting Centrelink, following a major investigation by the state's corruption watchdog. Sergeant Rosa Catherine Rossi, 57, also pleaded guilty in the Melbourne Magistrates Court to unauthorised access of the police database, LEAP, and falsely claiming in statutory declarations that her name was Dianne Marshall and she lived in Endeavour Hills. 
Misuse of the database and fake identification are salient because Rossi has been using the data to appropriate residential properties.

The Age states that
Rossi used a string of aliases over the past 20 years, including Nora Marguglio, Rosa Spencer and Bella Rossi. 
In 2005, she declared bankruptcy under her former name Rossa Catherine Marguglio, owing more than $750,000 to several banks and racking up massive debts on several credit cards. Rossi became familiar with the financial system while working as a teller at a bank. 
At the same time she worked as a beautician at a Cheltenham nursing home. She left both jobs under a cloud.
She then joined Victoria Police. Filter fail, as one of my students says!
Rossi exploited her role during an 18-month crime spree, often wearing her uniform to help persuade others to furnish her with private information. 
Rossi pleaded guilty to deceiving locksmiths to fraudulently take possession of houses in Malvern East, Chadstone, Brooklyn and three rural properties in Willaura, about 230 kilometres west of Melbourne. 
She accessed LEAP, without authorisation, to acquire information about the owner of the Malvern East home in October 2016. A month later, she obtained the property by deception after telling a locksmith it was a deceased estate and she was the owner ... 
Operation Salina, also resulted in Rossi being charged with fraudulently claiming rent assistance from Centrelink on behalf of another woman.
The Herald Sun reports
A decorated police sergeant has admitted to fraud and perjury after she was ­busted using her badge and position in the force to steal homes across the state. Sgt Rosa Rossi deceived locksmiths during an 18-month crime spree, ordering them to change locks on five houses, ­allowing her to illegally obtain vacant properties. 
The senior officer [an Inspector] has also admitted to trying to lease a stolen home in Brooklyn to an unsuspecting tenant. 
Sgt Rossi, a high-ranking police member who was awarded a group citation medal for merit, had earlier stated she was looking forward to her day in court so that she could tell her side of the story. But yesterday the police-woman remained silent as the Melbourne Magistrates’ Court heard she would plead guilty to 10 offences on the morning her committal trial was to begin. ... 
Sgt Rossi pleaded guilty to five counts of obtaining property by deception and defrauding the Commonwealth by receiving “rent assistance” payments to which she was not entitled. She has also admitted to using the Victoria Police ­database to access restricted information and making false statements about her identity.
The Inspector charged by IBAC admitted he lied to anti-corruption investigators about his relationship with Sgt Rossi. He reportedly claimed he perjured himself because he was worried his wife would find out he had been texting Rossi.

03 November 2019

NSW Offender Registration

The NSW Law Enforcement Conduct Commission's The New South Wales Child Protection Register: Operation Tusket Final Report released last week reveals disquieting problems with administration of a key offender and identity register.

The Commission states 
 The NSW Police Force established the Child Protection Register (the Register) in 2001, following the passage of the Child Protection (Offenders Registration) Act 2000 (NSW) (CPOR Act). The CPOR Act requires offenders who have been convicted and sentenced for certain offences involving children or child abuse material to register with police when they re-enter the community. They must then provide reports to police of their personal details for a number of years. The purpose of the Register is to protect children from serious harm and ensure the early detection of offences by repeat child sex offenders who are in the community. The Register is a database that assists police to monitor and investigate these offenders. 
The Commission’s investigation has established that there have been problems with the Register for 17 years. Significant errors in the application of the CPOR Act started occurring as early as 2002. These errors have included incorrect decisions by the NSW Police Force about which persons should be included on the Register, and incorrect decisions about how long persons were legally required to make reports of their personal information to police under the CPOR Act (their ‘reporting period’). Some of these errors have resulted in child sex offenders being in the community without being monitored by the NSW Police Force as required by the CPOR Act. The Commission reviewed one case in which a person reoffended while unmonitored. Other errors have caused the NSW Police Force to unlawfully require people to report their personal information to police for a number of years. As a result, people have been wrongly convicted, and even imprisoned, for failing to comply with CPOR Act reporting obligations, when in fact those obligations did not apply to them at the relevant time. Two persons were unlawfully imprisoned for more than a year in total. 
The NSW Police Force has been aware for a number of years that there were significant issues with the Register. In 2014 the NSW Police Force Child Protection Registry (the Registry), the specialist unit in the State Crime Command responsible for maintaining the Register, started filing internal reports warning of systemic issues causing inaccuracies in the Register. Multiple reports from the Registry prompted the NSW Police Force to review 5,749 Register case files. This review was started in 2016 and took two years to complete. In October 2018 it concluded that 44 per cent (2,557) of those Register case files had contained errors. 
There are a number of factors which have contributed over time to the errors in the Register. One of the most significant factors is the difficulty of interpreting and applying the provisions of the CPOR Act. Another is the insufficient resources allocated to the Registry to handle an ever-increasing workload. 
The CPOR Act places obligations on courts and certain government agencies to assist the NSW Police Force to implement the registration scheme. However, almost since its inception, this multi-agency system has not been functioning as Parliament intended, particularly in relation to the identification of who are registrable persons. The NSW Police Force has taken a number of significant steps since the start of the Commission’s investigation to improve the administration of the Register, including doubling the staff in the Registry. This report contains 11 recommendations to remedy the unlawful conduct that has occurred and prevent further errors in the Register. Our key recommendations are that the NSW Police Force ensures that adequate resources are allocated to the Registry now and into the future to enable it to maintain the Register; that the CPOR Act be urgently referred to the NSW Law Reform Commission for comprehensive review so that the fundamental problems with the legislative framework can be addressed and the various statutory responsibilities of the NSW Police Force, courts and government agencies reconsidered, and that an independent body conduct audits of the Register. 
In Chapter 1 we describe how we conducted our investigation, referred to as Operation Tusket. Our investigation commenced in September 2017 on the basis of information provided in a public interest disclosure. Early in the investigation the NSW Police Force acknowledged there were a significant number of errors in the Register. The Commission and the NSW Police Force adopted a collaborative approach, sharing information and expertise to identify and address issues throughout the investigation. 
In Chapter 2 we set out the key elements of the Child Protection Register. We explain the purposes of the Register, and what are the consequences under the CPOR Act if a person is determined to be a ‘registrable person’. We describe the roles and responsibilities of the NSW Police Force Child Protection Registry and other police officers in relation to the Register. We explain that the Register is part of a national framework of different statutory registration schemes for sex offenders across Australia. 
In Chapter 3 we discuss the nature and extent of the errors that have occurred in the Register over time, including the results of the review of Register case files initiated by the NSW Police Force (called the ‘CPR case review’). We highlight the serious consequences of these errors through several case studies. We found that since 2002 the NSW Police Force has made over 700 incorrect decisions about who were ‘registrable persons’ under the CPOR Act, or about the length of registrable persons’ reporting periods. We also found that the NSW Police Force has unlawfully required people to report their personal information, and conducted unlawful inspections of persons’ homes, as a result of incorrect information in the Register. The NSW Police Force has also charged and arrested people for not complying with CPOR Act reporting obligations when those people were not under any obligation to report under that Act. As a result, at least seven people were wrongly convicted of offences under the CPOR Act. 
Chapter 4 explores the responses of the NSW Police Force to those persons who have been subjected to unlawful or unjust actions as a consequence of the errors in the Register. The NSW Police Force was generally proactive in seeking annulments from the courts when it identified that persons had been wrongly convicted for offences under the CPOR Act. However, in 2016 the NSW Police Force made the decision not to notify persons that it had made errors in their cases. Relying on internal legal advice, the NSW Police Force intentionally limited the information it provided to such persons, to avoid the prospect of civil claims. We found that on at least three occasions, the NSW Police Force wrote letters which were in fact misleading. The NSW Police Force now acknowledges that these letters are misleading, and has agreed to notify all those who may have been subjected to unlawful or unjust actions as a result of errors in the Register. 
In Chapters 5 to 8 we discuss the systemic problems which have contributed to the occurrence of so many errors in the administration of the Register. 
Chapter 5 looks at the resourcing of the Registry over time. There has been a steady increase in the demand, complexity and scope of the Registry’s work. In October 2003 there were 916 persons on the Register. By August 2019 there were 4,344. The Registry’s resources were not increased proportionate to its increasing workload. This resulted in the Registry being understaffed, which impacted on the accuracy of its work, its ability to engage in proactive investigative activities, and the welfare of its staff. Since the start of our investigation the NSW Police Force has added 14 officers to the Registry. We recommend that the NSW Police Force adopt a responsive model of resourcing for the Registry into the future. 
Chapter 6 examines the legislative framework for the Register. The NSW Police Force and the Commission agree that the CPOR Act is so complex and ambiguous in important respects that it creates an inherent risk of errors in the Register that the NSW Police Force cannot effectively mitigate. The legislative framework creates such practical difficulties that it undermines the Act’s object of ensuring that registrable persons are monitored and comply with their obligations. The Commission’s analysis of the CPOR Act, incorporating input from the NSW Police Force, identified over 20 issues. These issues are set out in full in Appendix 2, with examples of cases in which the complexity or ambiguity in the Act have led to errors. We recommend that the Attorney-General urgently refer the CPOR Act to the NSW Law Reform Commission for comprehensive review, to be completed within six months. 
In Chapter 7 we explain that courts and ‘supervising authorities’ have obligations under the CPOR Act to assist the NSW Police Force to implement the Register. However, there have been problems with compliance with some of these obligations for many years. Since 2003 authorities have been relying on the NSW Police Force to determine who the CPOR Act requires to be registered, even though the Act does not contemplate this role being performed by police. This shift away from the system envisioned by the CPOR Act has resulted in the NSW Police Force making decisions under that Act without access to adequate information. The NSW Police Force has already adopted some of our recommendations for interim solutions to improve the Registry’s access to the information necessary to implement the CPOR Act. However, ultimately, the respective roles of the courts, the NSW Police Force and other authorities in relation to the Register need to be reconsidered as part of the review of the CPOR Act recommended in Chapter 6. 
In Chapter 8 we discuss the electronic systems that the Registry uses to keep the information on the Register about offenders’ reporting obligations up to date. In 2014 Registry officers began to notice issues with these systems, and in 2015 it was reported that these problems had resulted in registered child sex offenders being released into the community without being monitored by the NSW Police Force under the CPOR Act. The NSW Police Force approved an IT project in 2017 to fix the issues with the electronic systems. At the time of writing, this project had not yet been completed. We recommend that the NSW Police Force take steps to ensure that the project is completed as soon as possible. 
In Chapter 9 we consider mechanisms to improve governance, quality assurance and accountability in relation to the Register. We recommend that an interagency committee and governance framework, involving the NSW Police Force, courts and supervising authorities, be established to improve compliance with each authority’s obligations under the CPOR Act. We also recommend that the NSW Police Force develop an internal governance framework to ensure all local commands comply with the statutory framework when managing registrable persons. We further recommend that the statutory framework for the Register be amended to provide for independent compliance audits of the Register, similar to the Sex Offenders Registration Act 2004 (Vic).
The Commission summarises its findings as
1: Since 2002 the NSW Police Force has made over 700 incorrect decisions about the administration of the Child Protection Register, including: • incorrect decisions that 96 people were not ‘registrable persons’ under the CPOR Act; • incorrect decisions that 43 people were ‘registrable persons’ under the CPOR Act; • incorrectly calculating the reporting periods of 485 registrable persons as being shorter than the periods required by the CPOR Act, and • incorrectly calculating the reporting periods of 144 registrable persons as being longer than the periods required by the CPOR Act. These incorrect decisions arose, wholly or in part, from mistakes of law or fact. 
2: As a result of the incorrect decisions referred to in Finding 1, the NSW Police Force unlawfully required persons to report their personal details to police for a number of years. Some of these persons were also subjected to unlawful home inspections by the NSW Police Force, in purported reliance on the power in s 16C of the CPOR Act. 
3: As a result of the incorrect decisions referred to in Finding 1, the NSW Police Force charged and arrested persons for failing to comply with reporting obligations or providing false or misleading information under the CPOR Act, when those persons were not under any obligation to report under that Act at the relevant time. These were actions of a serious nature which, although not unlawful, were unjust or oppressive in their effects. 
4: The NSW Police Force made decisions to write letters to Mr DD, Mr NN and Mr KK about their obligations under the CPOR Act, which were in effect misleading. These decisions, although not unlawful, were unreasonable or unjust in their effects.
Recommendations are
 1: Notify persons who may have been subjected to unlawful or unjust actions by the NSW Police Force. The NSW Police Force write to each of the 277 people identified by the CPR case review who may have been subjected to unlawful or unjust actions by the NSW Police Force as a result of errors in the Child Protection Register. Each letter should: • explain the specific error that was made in their case; • identify each of the types of actions that the NSW Police Force may have mistakenly subjected the person to as a result of that error, and • apologise for these errors, and suggest the person may wish to obtain independent legal advice. 
2: Adopt a responsive model of resourcing for the Child Protection Registry. The NSW Police Force ensure that the resourcing of the Registry is reviewed at least every two years, and that staffing is maintained at a level sufficient to perform statutory functions under the CPOR Act efficiently and accurately. 
3: Refer the CPOR Act to the NSW Law Reform Commission for review. The Attorney-General urgently refer the Child Protection (Offenders Registration) Act 2000 (NSW) to the NSW Law Reform Commission for comprehensive review, to be completed within six months. 
4: Introduce a statutory review mechanism. A provision should be included in the Child Protection (Offenders Registration) Act 2000 (NSW) (or any Act which replaces it) which gives a person the right to seek review by the NSW Police Force of the decision that they meet the definition of a registrable person under the Act, and/or the decision as to which reporting period applies to the person. Consideration should be given to providing a right of appeal from the NSW Police Force review to a tribunal or court. 
5: Establish a dedicated legal officer position in the Child Protection Registry. The NSW Police Force establish at least one ongoing legal officer position within the Registry that is dedicated solely to supporting Registry staff, and fill that position as a matter of priority. 
6: Provide reasons for decisions under the CPOR Act. The NSW Police Force provide written notification to each person placed on the Register of the basis upon which their status as a registrable person and their reporting period has been determined, including the sections of the CPOR Act relied on. For persons already on the Register, this information is to be provided upon request. 
7: Prioritise the ‘CPR COPS’ upgrade project. The NSW Police Force prioritise the recruitment for the CPR COPS upgrade project to ensure that the project is completed as soon as possible. 
8: Establish an Interagency Child Protection Register Committee. The NSW Police Force initiate the establishment of a Child Protection Register Committee with relevant authorities to discuss and decide the obligations,  compliance risks and mitigation strategies of each authority in relation to the statutory framework governing the Register.  
9: Develop an interagency governance framework. The NSW Police Force initiate the creation and implementation of a robust interagency governance framework to ensure consistent service delivery in accordance with each authority’s responsibilities under the statutory framework for the Register.
10: Implement a Child Protection Register governance framework. The NSW Police Force develop and implement a governance framework to ensure compliance by all local commands across New South Wales with the statutory framework for the Register. This framework should: • leverage the expertise of the Child Protection Registry to support local commands and provide quality assurance; • ensure that emerging compliance risks are identified and addressed, and • contain appropriate reporting mechanisms to ensure future accountability. 
11: Introduce independent compliance auditing of the Child Protection Register. Provisions should be included in the Child Protection (Offenders Registration) Act 2000 (NSW) (or any Act which replaces it) for independent compliance audits of the Register, with publicly reported (and de-identified) results, similar to those in the Sex Offenders Registration Act 2004 (Vic).

Photos

'Gorgeous Photograph, Limited Copyright' by Justin Hughes in Routledge Companion to Copyright and Creativity in the 21st Century (Routledge, 2020, Forthcoming) comments 
 This chapter explores how copyright protection of photographs is shaped by the dual nature of photography as both creative expression and a system of recording reality. Starting with the Supreme Court’s 1884 Burrow-Giles Lithographic Co. v. Sarony opinion, the chapter explains how under American copyright law a photograph will have copyright protection only if it has original expression; that original expression can take the form of composition, selection of background, lighting, angle, shading, positioning of subjects, and a whole variety of “inputs” in the process of creating the photograph. Indeed, reading court decisions carefully it is clear that courts look for creativity less in the final photographs and more in the process of photography (including choice of camera, filters, lenses, and processing techniques, both analog and digital). 
The chapter describes how we can generally organize the recognized sources of copyrightable expression in a photograph into three categories: [a] creative choices in constructing the scene; [b] creative choices in initial image capture, and [c] creative choices in manipulating the image. 
The chapter then explores what this legal framework means for modern practices, concluding that many photographic and audiovisual records do not merit copyright protection; that photojournalists will often have only “thin” copyright protection over their work; that copyright law is only a very limited tool against “deep fakes;” and that most selfies do get at least some copyright protection. 
The chapter concludes with a discussion of the fair use doctrine and how the emergence of “transformative use” analysis threatens the work of freelance photographers far more than other creative professionals. Fortunately, it appears that appellate courts have recognized that concern and have appropriately dialed back “transformative use” analysis as it applies to photography.