“1. Legality of JIT – reason why UK cannot join a JIT with France and Netherlands 59 Convention accepted by France but not willing to do a separate Jits on different basis ut Netherlands will not be used by Netherlands. For this reason bilateral JIT france and Netherlands with communication with other countries based on other legal instruments such as EIO and MLAT Netherlands Position with UK is that have renewed on 59 protocol. Not in a position to decide if multilateral can use that as sole basis. Consideration is taking place. UK cannot work with 2000 convention. Waiting for decision to be taken by Dutch JIT expert. Start bilaterial Jit with France and should the confirmation be made that sole basis if possible can be given in future. KT from Uk explains reason for only 59 protocol as basis for a JIT by UK. One basis and non eu instrument. France drafted on basis of previous case. Both countries want to finalise. Netherlands will look at document and respond after consulting Higher level in Holland. One issue complicated which is can only share information between jit partners in JIT and not outside of the JIT agreement with other countries – need permission on that topic. UK going forward information sharing: EIO to be utilised with France, Netherlands Europol work and sharing of expertise between countries. Data sharing JIT will allow use of data unlimited basis. Precise draft which may say: Data could jeopardise investigations so it must not mention the origins of information until restrictions are lifted and server taken down. JIT will have timely conversation on what to share and when. Europol on board to deal with National packages. Will deal with threats to life eg CT and murders in intelligence phase of intercept. Netherlands – will share all information of JIT and work with UK and other EU partners. Easiest way is through Europol, can share data NCA. France concurs can envisage technical co-operation on filters for idea and tools. 2 month period finalise of infection application. Europol can assist with design of filters ad hoc dedicated meeting at Europol. Passing of intelligence between countries with correct handling comes. Working group.”
“SECTION C: Investigative measure(s) to be carried out 1. Describe the assistance/investigative measure(s) required AND indicate, if applicable, if it is one of the following investigative measures: We request access to data obtained by the French Authorities in respect of all EncroChat devices identified as located in the UK. We anticipate the data will be disseminated by Europol systems set up specifically for this purpose. In addition, we ask the French Prosecutor to confirm: • A list of any handling conditions for the EncroChat data. • Confirmation that the data can be shared with other law enforcement agencies within the United Kingdom by the National Crime Agency (NCA) including with Police Scotland and the Police Service of Northern Ireland. • Confirmation that UK authorities will be informed once the data handling conditions are lifted and the data may thereafter be used as evidence in criminal proceedings if appropriate. (ii) Once the data handling conditions are lifted, we request a statement from an officer of the Gendarmerie describing the actions taken and methods employed by the French authorities to obtain the material referred to. Obtaining information or evidence which is already in the possession of the executing authority”
“Dear colleagues, Operational Task Force (OTF) EMMA provides the cooperation environment between the forthcoming JIT JR (Op. Emma)/ NL (Op. 26LEMONT) and non-JIT countries engaged in similar cases. The OTF includes the establishment of a Joint Operational Centre (JOC) at Europol, which will have the key objective of contributing to the identification of potential threats to life and limb affecting the participating countries. The competent authorities of each country that are willing to participate have to provide the JIT a written consent including that: - They have been briefed about the methods that are being used to generate data from devices in their jurisdiction, - They would like to receive the data as intelligence under the following conditions: ◦ If a situation occurs when the data reveal that an imminent threat to life or serious injury for a person (or persons). When that happens the joint investigation partners will decide ad hoc, in cooperation with Europol, about the way the competent authority will be briefed about this data and how this data may be used to combat the serious threat (handling code H0). ◦ Data can be supplied on intelligence basis. Europol will make an intel package for each participating country. France will try to supply Europol with packages already split up by countries. These packages can be distributed to countries not part of the joint investigation team after permission granted by the joint investigation parties. The receiving country will have to guarantee that the data will be analyzed by a small group of police officers and will be held strictly confidential. In no case this data may be used in an ongoing investigation, unless permission is granted by the joint investigation parties (handling code H1). The reason for this is to protect the operation. So there will be possibilities to use the information as intelligence in ongoing investigations in other countries, but only if the interests of the operation of the JIT can be protected. Furthermore the countries that will use this intelligence based information express that they understand the legal basis for the deployment of this investigative method in France. - They understand that the data can only be used in judicial procedures after following the applicable EIO or MLAT procedures. Kind regards, Netherlands J-CAT” ◦ If a situation occurs when the data reveal that an imminent threat to life or serious injury for a person (or persons). When that happens the joint investigation partners will decide ad hoc, in cooperation with Europol, about the way the competent authority will be briefed about this data and how this data may be used to combat the serious threat (handling code H0). ◦ Data can be supplied on intelligence basis. Europol will make an intel package for each participating country. France will try to supply Europol with packages already split up by countries. These packages can be distributed to countries not part of the joint investigation team after permission granted by the joint investigation parties. The receiving country will have to guarantee that the data will be analyzed by a small group of police officers and will be held strictly confidential. In no case this data may be used in an ongoing investigation, unless permission is granted by the joint investigation parties (handling code H1). The reason for this is to protect the operation. So there will be possibilities to use the information as intelligence in ongoing investigations in other countries, but only if the interests of the operation of the JIT can be protected. Furthermore the countries that will use this intelligence based information express that they understand the legal basis for the deployment of this investigative method in France. Netherlands J-CAT”
“On behalf of the UK Law Enforcement community, in my capacity as the Gold Commander for NCA Operation Venetic, which coordinates the UK response, I can confirm my agreement on behalf of the NCA and our UK Law Enforcement partners, to receiving the data in respect of Encrochat devices as described in the Siena message as follows: In particular; I have been briefed about the methods that are being used to generate data from devices in their jurisdiction, I would like to receive the data as intelligence under the following conditions: ◦ If a situation occurs when the data reveal an imminent threat to life or serious injury for a person (or persons). When that happens the joint investigation partners will decide ad hoc, in cooperation with Europol, about the way the competent authority will be briefed about this data and how this data may be used to combat the serious threat (handling code H0). In the UK data can either be relied upon on an intelligence basis which means that it will not be revealed in criminal proceedings (including overt investigations) or judicial procedures or it can be used on an evidential basis and therefore can be revealed in criminal proceedings (including overt investigations) or judicial procedures. If data is treated as intelligence only it can be relied upon the develop ongoing investigations without being disclosed to any party at this stage. As a result, the NCA confirms that this data will be relied upon on an intelligence basis but will be used to inform investigations and it will not be revealed in any judicial procedures at this stage to protect the interests of the operation of the JIT. There is a positive legal duty on UK law enforcement to take reasonable steps to minimise the risk of death or serious injury where the UK law enforcement is aware, or ought to be aware, of a real and immediate threat to life. In the event of intelligence being disseminated that relates to a threat to life it is recognised that the source of the intelligence should not be disclosed by UK law enforcement. However in order to manage the threat and protect life it may be necessary for UK law enforcement to take action quickly and this may involve contacting the victim or aggressor As a result, the UK requests the agreement of the JIT to respond to any potential threat to life as is necessary, justified and proportionate in the circumstances whilst recognising that the source of the intelligence should not be disclosed. In order to protect and prevent serious crime and to fulfil its functions under theCrime and Courts Act 2013 the NCA will limit the number of individuals who will have sight of this data to the minimum possible and will ensure that it is held in strictest confidence unless otherwise directed by the JIT. I understand that the data can only be used in judicial procedures after following the applicable EIO and MLAT procedures. I have asked my team to load this message onto Siena and to forward it to the competent authorities responsible for Operation Emma in order to formally confirm in writing the UK’s participation in this operation on the basis of the terms and conditions detailed above. I also confirm that the UK has supplied a European Investigation Order in respect of this activity and the UK has a legal authorisation in terms of an Investigatory Powers Act Thematic Targeted Equipment Interference Warrant in existence, which renders the activity proposed lawful in the UK. Kind regards, Matt Horne Deputy Director Investigations” ◦ If a situation occurs when the data reveal an imminent threat to life or serious injury for a person (or persons). When that happens the joint investigation partners will decide ad hoc, in cooperation with Europol, about the way the competent authority will be briefed about this data and how this data may be used to combat the serious threat (handling code H0). In the UK data can either be relied upon on an intelligence basis which means that it will not be revealed in criminal proceedings (including overt investigations) or judicial procedures or it can be used on an evidential basis and therefore can be revealed in criminal proceedings (including overt investigations) or judicial procedures. If data is treated as intelligence only it can be relied upon the develop ongoing investigations without being disclosed to any party at this stage. As a result, the NCA confirms that this data will be relied upon on an intelligence basis but will be used to inform investigations and it will not be revealed in any judicial procedures at this stage to protect the interests of the operation of the JIT. There is a positive legal duty on UK law enforcement to take reasonable steps to minimise the risk of death or serious injury where the UK law enforcement is aware, or ought to be aware, of a real and immediate threat to life. In the event of intelligence being disseminated that relates to a threat to life it is recognised that the source of the intelligence should not be disclosed by UK law enforcement. However in order to manage the threat and protect life it may be necessary for UK law enforcement to take action quickly and this may involve contacting the victim or aggressor As a result, the UK requests the agreement of the JIT to respond to any potential threat to life as is necessary, justified and proportionate in the circumstances whilst recognising that the source of the intelligence should not be disclosed. In order to protect and prevent serious crime and to fulfil its functions under theCrime and Courts Act 2013 the NCA will limit the number of individuals who will have sight of this data to the minimum possible and will ensure that it is held in strictest confidence unless otherwise directed by the JIT. I understand that the data can only be used in judicial procedures after following the applicable EIO and MLAT procedures. I have asked my team to load this message onto Siena and to forward it to the competent authorities responsible for Operation Emma in order to formally confirm in writing the UK’s participation in this operation on the basis of the terms and conditions detailed above. I also confirm that the UK has supplied a European Investigation Order in respect of this activity and the UK has a legal authorisation in terms of an Investigatory Powers Act Thematic Targeted Equipment Interference Warrant in existence, which renders the activity proposed lawful in the UK. Kind regards, Matt Horne Deputy Director Investigations”
“96. We further accept the submissions of the respondent that none of the EIOs relevant to this case was defective, and that there was no breach of s10 of IPA 2016. We reject the submissions of the applicants to the effect that the relevant EU Directive (Directive 2014/41/EO of the European Parliament and of the Council of3 April 2014 regarding the European Investigation Order in Criminal Matters) excluded the use of EIOs in circumstances where a JIT had been formed. In any event, messages between the AmazonWorld and WhiteStuff devices which were contained in the material from the French TTL system were also contained in the material provided in response to the EIO issued in September 2020. That EIO was a lawful request for assistance in connection with the interception of communications stored in a telecommunication system, made in the exercise of a statutory power. The Dubai data provided in response to it, and relied on by the prosecution at trial, was not obtained by monitoring the French TTL system; so even if the monitoring of that system had been unlawful (which we do not accept), the evidence at trial did not disclose anything relating to that system and did not breach s56 of the Act. 97. We note moreover that in relation to the AmazonWorld device, the French TTL system contained no data which could be accessed by the NCA officers: the first information about a threat to life revealed by that device was sent in a different way, way, on a “police-to-police” basis, several days after the device had ceased to be used. 98. The applicants’ arguments are not in our view assisted by reference to MN. In the circumstances of this case, the CPS were competent to issue an EIO requesting data which had already been intercepted; and the defence plainly were able to challenge and comment on the evidence effectively. The fact that the jury were nonetheless sure of guilt does not mean that no effective challenge to the evidence was possible. Moreover, it must be remembered that one part of the relevant messages was sent or received by a UK-based device attributed to an applicant, the user of which would have a full knowledge of it, and that each of the applicants in any event denied making or receiving any of the relevant messages. 99. We are not persuaded that the assertion of a breach of the sovereignty of the UAE is correct; but even if it were, it would do no more than provide an alternative basis on which the applicants might have sought to exclude the Dubai data pursuant to s78 of PACE. It would not have rendered the evidence inadmissible, and we reject the submission that it would have provided a basis for taking the exceptional step of staying the proceedings as an abuse of the process.”
“(7) This new approach is based on a single instrument called the European Investigation Order (EIO). An EIO is to be issued for the purpose of having one or several specific investigative measure(s) carried out in the State executing the EIO (‘the executing State’) with a view to gathering evidence. This includes the obtaining of evidence that is already in the possession of the executing authority. (8) The EIO should have a horizontal scope and therefore should apply to all investigative measures aimed at gathering evidence. However, the setting up of a joint investigation team and the gathering of evidence within such a team require specific rules which are better dealt with separately. Without prejudice to the application of this Directive, existing instruments should therefore continue to apply to this type of investigative measure.”
“The EIO shall cover any investigative measure with the exception of the setting up of a joint investigation team and the gathering of evidence within such a team as provided inArticle 13 of the Convention on Mutual Assistance in Criminal Matters between the Member States of the European Union (‘the Convention’) and in Council Framework Decision 2002/465/JHA, other than for the purposes of applying, respectively,Article 13(8) of the Convention and Article 1(8) of the Framework Decision.”
“88 Article 6(1)(a) of Directive 2014/41 thus requires a review of the necessity and proportionality of the issuing of the EIO by reference to the purpose of the proceedings referred to in Article 4 of that directive. The latter article, which determines the types of proceedings for which an EIO can be issued, provides, in point (a), that an EIO may be issued ‘with respect to criminal proceedings that are brought by, or that may be brought before, a judicial authority in respect of a criminal offence under the national law of the issuing State’. Since that provision refers to the national law of the issuing State, the necessity and proportionality of the issuing of an EIO must be assessed only in the light of that law. 89 In that regard, in view of the referring court’s queries as set out in paragraphs 82 and 83 of the present judgment, it should be made clear that, first, Article 6(1)(a) of Directive 2014/41 does not require that the issuing of an EIO for the transmission of evidence already in the possession of the competent authorities of the executing State is necessarily subject to the existence, at the time when that EIO is issued, of a suspicion, based on specific facts, of a serious offence in respect of each person concerned, if no such requirement arises under the national law of the issuing State.”
“It is important to reach agreements before the operational phase on the sharing of data and electronic evidence with non-JIT countries. Very often, JIT countries will not share such data during a live phase in order not to compromise the case. Moreover, countries outside the JIT that want to receive data will need to know to which JIT party they have to address an EIO or MLA request.”