The dawn of the electrical vertical take-off and landing aircraft

The dawn of the “flying taxi” will soon be upon us through the development and manufacture of the electrical vertical take-off and landing (‘eVTOL’) aircraft. The aircraft as envisaged will carry passengers from specially designed Skyports, enabling the use of eVTOL aircraft in built up areas. The Skyports are designed and built through the collaboration of specialists in architecture, design and engineering to produce landing and take-off sites capable of handling up to 1000 landings per hour in a small space; collaboration between Volocopter and Skyports has resulted in the creation of the world’s first full scale air taxi vertiport, which opened in Singapore on 21 October 2019.

Uber is one of the main competitors in the eVTOL industry, and it plans to “give riders the option of an affordable shared flight”. These aircraft would be autonomously controlled and would pick passengers up and drop them off in a similar way as to how the Uber Pool facility works.

The eVTOL aircraft must comply with the regulatory regimes in each country in which they operate. Singapore and China are places in which the Skyports co-founder and managing director Duncan Walker suggests the aircraft will launch faster, and that in other areas better progress must be made to promote the benefits of these aircraft to governments.

In relation to the regulation of these aircraft in Europe, on 2 July 2019, the European Aviation Safety Agency released its final “Special Condition”, which contains the framework for the Basic and Enhanced certification (aircraft capabilities after a critical malfunction of thrust/lift) for the small aircraft category which “covers aircraft with a passenger seating configuration of 9 or less and a maximum certified take-off mass up to 3175kg” [1].

However, there are currently problems limiting the benefits of this technology. The battery life of these aircraft limit them to short flights as the aircraft achieve a range of about 22 miles, with a maximum speed of 68mph, although prototypes are being designed that may achieve a range of 185 miles. As a result of this, short flights will be the current focus of these companies as there are many potential customers in cities such as London who would use the aircraft to travel to local airports and other destinations.

As these aircraft are developed and are programmed to be fully autonomous, the threat of cyberattacks will loom large, as the effect of an inflight disruption could prove disastrous. Companies using this technology must therefore have detailed plans in case of the event of a cyberattack, as well as a consideration as to whether cyberinsurance will develop to encompass such an event.

[1]https://www.easa.europa.eu/document-library/product-certification-consultations/special-condition-vtol#group-easa-downloads

© 2019 Whitestone Chambers
www.whitestonechambers.com
law@whitestonechambers.com

Beware Cookie Law

Websites that use cookies to track users and their interactions will have to pay close attention to the recent case of Bundesverband der Verbraucherzentralen und Verbraucherverbände — Verbraucherzentrale Bundesverband eV (the ‘Federation’) v Planet49 GmbH (‘Planet49’) Case C‑673/17, 1 October 2019, which clarifies the indication the user must provide as to their consent to the use of cookies.

Planet49 organised a promotional lottery accessed via a website. If users wished to take part in this competition, users were required to enter personal details such as their name and postcode on the website. The user was also presented with two boxes to check. The first box one was unchecked and required the user to check it to enter the competition, this would also allow certain sponsors and corporate partners to contact the user. The second box was pre-checked and if this approval were not removed it would allow multichannel retargeting company Remintrex to evaluate the user’s use and behaviour through the use of cookies.

With reference to EU Directives 95/46 and 2002/58, the court was asked to provide a preliminary ruling as to whether “the consent referred to in those provisions is validly constituted if, in the form of cookies, the storage of information or access to information already stored in a website user’s terminal equipment is permitted by way of a pre-checked checkbox which the user must deselect to refuse his or her consent”. Additionally, the court was asked to consider EU Regulation 2016/679, (the ‘GDPR’), on a ratione temporis basis, as the German Court previously stated that it may be applicable to the main proceedings.

Recital 17 of Directive 2002/58, provides examples of a user’s consent being validly given, for example, ‘by ticking a box when visiting an internet website’. EU Directive 95/46 Article 2(h) then specifies the user’s consent as ‘any freely given specific and informed indication of his wishes, and as per Article 7, the consent must be given unambiguously.’ In this instance the court determined that “only active behaviour on the part of the data subject with a view to giving his or her consent may fulfil that requirement.” After the entering into force of the GDPR, the data subject’s consent has been defined further in Article 6(1)(a) as requiring a ‘freely given, specific, informed and unambiguous” indication of the subject’s consent, and Recital 32 precludes “silence, pre-ticked boxes or inactivity” from constituting consent.

As a result of the court’s ruling, a website using a pre-checked box to act as consent to the use of cookies on the user’s terminal before 25 May 2018 would be in breach of EU Directive 95/46; as of 25 May 2018, Directive 95/46 has been repealed and replaced by the GDPR meaning that any breach after this date would be a breach of the GDPR rather than the Directive.

Interestingly, what the court was not asked to give an opinion on was whether the user’s consent was ‘freely given’ as set out by Article 2(h) of EU Directive 95/46, and Articles 4(11) and 6(1)(a) of the GDPR. The very important question still remains as to whether consent is freely given if the user must allow the use of cookies to enter the competition, or in a wider context, to enter a website.

© 2019 Whitestone Chambers

www.whitestonechambers.com

law@whitestonechambers.com

Flybe to be rebranded as Virgin Connect

After 40 years as the largest independent regional airline in Europe, Flybe has been acquired by the Connect Airways consortium. The Connect Airways consortium was created in December 2018 and consists of 40% ownership by Cyprus Capital, 30% by the Stobart Group, and 30% by Virgin Atlantic Limited.

The proposed merger of the consortium received approval from the European Commission on 5 July 2019 [1] on condition that full compliance is met by Connect Airways as to the commitments [2] that it offered, to ensure that it complies fully with competition law. Following the merger in July 2019, Flybe was acquired by Connect Airways and in the near future, the Flybe name will be changed to ‘Virgin Connect’. Switching from the current purple colour schemes, Flybe’s fleet of 76 aircrafts will be rebranded to match the distinctive red of the Virgin Group companies.

Based in Exeter, and with hubs at Birmingham and Manchester airport, Flybe currently carries 8 million passengers per year between 81 airports throughout the UK and the rest of Europe. Flybe has over 210 routes across 15 countries, and a number of codeshares permitting connections to long-haul flights from several airports including London Heathrow, Paris CDG and Amsterdam. These capabilities will be used by Virgin Connect to build upon the existing Virgin brand, and to offer a wider range of services.

The CEO of the newly branded Virgin Connect, Mark Anderson said: “We are hugely excited by this milestone in our airline’s 40-year history. We will remain true to our heritage and reason for being, which is offering essential regional connectivity to local communities. “At its heart, Virgin Connect will be passionately focused on becoming Europe’s most loved and successful regional airline. It will offer travel that is simple and convenient with the personal touch. Our customers will naturally expect the same exceptional travel experience as they do with other Virgin-related brands. Whatever their reason for flying, we want our customers to feel loved and know we will always put their needs first in every decision we take.

Customers are advised that their bookings will not be affected and that they may continue to visit www.flybe.com to book flights, check in and manage their booking. For those passengers concerned about Brexit, they can have their fears alleviated. In place is EU Regulation 2019/502 that provides for common rules ensuring basic air connectivity with regards to Brexit, allowing Virgin Connect to fly to European destinations until 24 October 2020.

[1] https://ec.europa.eu/commission/presscorner/detail/en/IP_19_3790

[2]https://ec.europa.eu/competition/mergers/cases/additional_data/m9287_881_5.pdf

© 2019 Whitestone Chambers

www.whitestonechambers.com

law@whitestonechambers.com

UK passengers concerned about European flights after 31 October 2019.

With the Brexit deadline of 31 October 2019 looming, many airline passengers that have booked flights to European destinations are concerned about flights scheduled after the deadline. Recent research by Which? Travel showed that “a third of flyers are worried that European flights could be disrupted once Britain leaves the EU”.

For the near future those passengers can have their fears alleviated. In place is EU Regulation 2019/502 that provides for common rules ensuring basic air connectivity with regards to Brexit, allowing UK planes to fly to European destinations. Article 16 4(b) of the Regulation extended the operation of this Regulation until 30 March 2020; recently the European Commission released a statement on 4 September 2019 extending the effect of the Regulation:

“Basic air connectivity (Regulation (EU) 2019/502): the Commission has today proposed to extend this Regulation until 24 October 2020, reflecting the logic and duration of the original Regulation.”

As such, UK-based airlines may continue to operate European flights until 24 October 2020.

Passengers will be reassured to know that they can continue to make travel arrangements for the future. However, what must be considered is that whilst the flights will continue to operate, there will be an increased scrutiny on passports for passengers travelling from the UK to an EU country. The increased scrutiny will require that passengers “have at least 6 months left on an adult or child passport to travel to most countries in Europe (not including Ireland).”

© 2019 Whitestone Chambers

www.whitestonechambers.com

law@whitestonechambers.com

Nearly 450 Drunk Airline passengers in 2 years

Police figures have shown that nearly 450 passengers have been arrested on suspicion of being drunk in the past 2 years. Freedom of information requests reveal that at least 245 people were arrested on suspicion of being drunk at a UK airport between 1 April 2017 and 31 March 2019.

Heathrow, the UK’s busiest airport, reported the highest number of arrests within that time period with 103 passengers, followed by Gatwick with 81, Glasgow with 47 and Liverpool with 40 arrests. Greater Manchester Police and 3 other forces did not provide figures within the time limit so the final figure is expected to be higher. The ages of those arrested range between 20-58.

The figures emerged after a woman was arrested at Southend Airport for attacking an easyJet crew member. A similar incident took place at Bristol Airport with a man arrested on suspicion of being drunk on an aircraft and sexually assaulting the female crew members.

Chief executive of trade body Airlines UK has described the arrest figures as “ridiculous’’ and has also requested for the introduction of new laws to reduce the number of passengers who drink too much before and during flights.

Ryanair, Europe’s biggest airline, support the proposed changes and stated that “We continue to call for significant changes to prohibit the sale of alcohol at airports, such as a two-drink limit per passenger and no alcohol sales before 10am.’’

The sale of alcohol once a passenger has gone through international airport security in England and Wales is not regulated by licensing laws. A Home Office consultation on whether legislation should be amended closed in February without a decision being announced.

Legislation is important for several reasons, including setting standards and controls to govern the actions of people and groups in the public and private spheres. However, with Parliament otherwise occupied, there seems no sign of any changes any time soon.

© 2019 Whitestone Chambers
www.whitestonechambers.com
law@whitestonechambers.com

Lawfulness of bulk hacking powers under the Investigatory Powers Act 2016

This article was first published on Lexis®PSL Corporate Crime on 20 August 2019. Click for a free trial of Lexis®PSL.

Corporate Crime analysis: Adam Richardson, barrister at Whitestone Chambers, considers the most recent judicial review challenge brought by Liberty concerning the lawfulness of the bulk hacking powers under the Investigatory Powers Act 2016 (IPA 2016).

R (on the application of National Council for Civil Liberties (Liberty)) v Secretary of State for the Home Department and another (National Union of Journalists intervening) [2019] EWHC 2057 (Admin), [2019] All ER (D) 02 (Aug)

What are the practical implications of this case?

As the claimants effectively lost the case, the existing regime vis-a-vis IPA 2016 still stands—arguably even more firmly than before. As such, there will be no new practical implications to consider other than those already created by IPA 2016. The largest concern for lawyers has to be the effect on legal professional privilege (LPP). Ever since the Regulation of Investigatory Powers Act 2000 (RIPA 2000), there has been a question of a surveillance authority legally acquiring information that is the subject of LPP. This goes against years of convention protecting privilege, however RIPA 2000 remained silent on the topic. When IPA 2016 was first drafted, the Bar Council raised explicit concerns about the erosion of LPP through either a failure to distinguish between privileged and non-privileged communications (as a result of bulk hacking) or the power given to authorities to monitor ‘sensitive, highly confidential communications that have nothing to with criminality, national security or threats to individuals’.

The government listened and added a few additional safeguards for privileged information. A warrant would be required to be issued for the interception and review of information that is subject to LPP. The authority issuing the warrant must have regard to the ‘public interest in the confidentiality of items that are subject to legal privilege’. Further, IPA 2016 also requires public interest, necessity and prevention of death, or serious injury conditions to be satisfied before such a warrant can be issued.

Needless to say, this is a very high bar. There can be no getting around that as a result of bulk hacking, privileged information will be intercepted if only through inadvertence. Given the number of practical and operational issues raised by the claimant in the case, this should be concerning at best.

The claimants have made clear they intend to appeal this, and it may end up in the European Court of Human Rights (ECtHR) where there may well be a different view taken, so, until all appeals are exhausted on this matter, no position is settled.

What was the background?

The High Court’s judgment in Liberty, R (On the Application Of) v Secretary of State for the Home Department & Another is the second iteration of the issues raised on this claim. See R (on the application of the National Council for Civil Liberties (Liberty)) v Secretary of State for the Home Department and another [2018] EWHC 975 (Admin), [2018] 3 WLR 1435, , [2018] All ER (D) 129 (Apr), where the court gave judgment on the first part of the claimant’s challenge to IPA 2016. That challenge was brought under EU law. It only concerned IPA 2016, Pt 4 (regarding powers to require the retention of ‘communications data’), as this part had just been brought into force. The court found in that judgment that IPA 2016, Pt 4 was incompatible with human rights law and gave the government until 1 November 2018 to redraft it, which it duly did.

In the instant judgment, the court was concerned with the second part of the claimant’s challenge, which arises under the Human Rights Act 1998 (HRA 1998). This challenge concerns various other parts of IPA 2016, which have now been brought into force on various dates.

The claimant challenged four different sets of provisions in IPA 2016. What they all have in common is that they concern bulk powers, rather than powers which are directed at any particular individual who may be a potential subject of interest (sometimes called targeted surveillance). The relevant provisions are as follows:

  • IPA 2016, Pt 6, Ch 1—which relates to bulk interception warrants
  • IPA 2016, Pt 6, Ch 3, and IPA 2016, Pt 5—these concern warrants for bulk and thematic equipment interference. The claimant has described this in its submissions as ‘hacking’
  • IPA 2016, Pt 7, which relates to warrants for bulk personal datasets (BPD)
  • IPA 2016, Pt 6, Ch 2, and IPA 2016, Pt 3–4—respectively warrants for bulk acquisition of communications data and retention notices for, and acquisition of, communications data. Communications data is not the content of communications but other matters such as where, when and who

The only remedy which the claimant sought was a declaration of incompatibility under HRA 1998, s 4.

A very simplistic summary of the claimant’s case is that the minimum safeguards established by the ECHR for secret surveillance regime were not met. As not all human rights are absolute, certain breaches may only take place where they are in accordance with law or necessary for a democratic society. The claimant submitted the measures in IPA 2016 were neither necessary nor proportionate.

What did the court decide?

The court went to great pains in this judgment to be as comprehensive as possible. The judgment itself is almost 400 paragraphs long (excluding accompanying legislation) and gives an incredibly detailed overview of the law. While the claimant was able to bring to light shocking examples of government data use, including data being lost in ungoverned spaces without the necessary controls, among others, the court still found that IPA 2016 was not incompatible with HRA 1998. Among the extensive reasoning is that the mechanisms for oversight within the legislation itself, such as the establishment of the office of the Investigatory Powers Commissioner (to conduct independent oversight of spy agencies’ use of the powers), provide sufficient checks on the risk of abuse. The court dubbed the regime as ‘a suite of interlocking safeguards’.

The court spoke specifically of Parliament’s consideration for the fears about abuse expressed by the claimant but noted they chose to address those in IPA 2016 through those various interlocking safeguards mentioned.

Interviewed by Alex Heshmaty.

Pressure on BA after customer email mix up.

British Airways have been instructed to reimburse passengers who were mistakenly told in an email that their original journeys had been cancelled and that they should source alternative means of transport. The airline emailed passengers who were not affected in error telling them that their flights had been cancelled and “it is likely that you will not be able to travel.’’

A source from the Daily Mail further explained that the passengers were later angered even more after receiving another email saying that, their flights would proceed as planned. This however was too little too late as some passengers had already acted on the first email and had booked another flight.

The Civil Aviation Authority have expressed the fact that “Those affected should not be left out of pocket for any extra expenses such as accommodation, food and travel which incurred due to the error.’’ This is illustrated in the case of Alitalia Linee Aeree Italiane, S.p.A. v. Airline Tariff Publishing Company [1968] where the court rejected Alitalia’s negligence and gross negligence causes of action because all of the parties’ duties to each were set forth in their agreement, and ATPCO had no data input duties to the airline that were separate from those set forth in the agreement.

British Airways stated that they will reimburse passengers on a ‘‘case by case basis’’, many are not hopeful and fear that they will not be reimbursed. This incident could have ramifications for similar mistakes in the future.

The CAA added pressure on British Airways by saying that; ‘’Those consumers that took action should not be left out of pocket and any reasonable costs of re-booked flights should be claimed from the airline.’’

Guy Anker, deputy editor at consumer website Money Saving Expert said that ‘’What British Airways did was amateurish in the extreme. The CAA is absolutely correct that British Airways should return every single penny to anyone who unnecessarily booked alternative flights, transport and accommodation.’’

A spokesperson for British Airways said: “We are sorry for the frustration and inconvenience. As soon as we were issued with dates, we contacted airlines across the world to support with rebooking agreements. Our teams are providing customers whose flights have been cancelled with options.’

 

© 2019 Whitestone Chambers
www.whitestonechambers.com
law@whitestonechambers.com

Plane damaged by bird strike may result in compensation to passengers

An Airbus 321 travelling from Russia to Crimea has crash-landed in a field as a result of damage caused by a flock of birds that were sucked into the plane’s engines. Although there were no deaths caused by the impact, some passengers experienced injuries, and all suffered significant delays. As a result of this the passengers may be able to make a claim under the Montreal Convention 1999 (the ‘Convention’) for a non-EU flight.

Article 19 of the Convention states that “the carrier is liable for damage occasioned in the carriage by air of passengers, baggage or cargo” however, the carrier will not be liable if “it and its servants and agents took all measures that could reasonably be required to avoid the damage or that it was impossible for it or them to take such measures.”

A bird strike is considered an extraordinary circumstance in EU law in relation to EU 261/2004 as per Marcela Pešková, Jirí Peška -v- Travel Service A.S. (C-315/15). Considering this judgment it would be unlikely that a view would be taken that the damage caused by a bird strike could be avoided or any further precautionary measures could be taken. As such, the passengers are unlikely to be able to recover for their delay.

Those injured may make a claim for compensation. Article 17 s(1) of the Convention states that “the carrier is liable for damage sustained in case of death or bodily injury of a passenger upon condition only that the accident which caused the death or injury took place on board the aircraft”. Any passengers who were onboard the aircraft at the time of the accident would therefore meet this requirement. Once a claim under this Article has been established Article 21 is considered.

Under Article 21 s(1) of the Convention, for damages arising under Article 17, the carrier may limit its liability to 100,000 Special Drawing Rights provided there was no negligence, wrongful act or omission of the carrier or its servants or agents; or if the damage was solely due to the negligence or other wrongful act or omission of a third party. At the time of publication of this article this would limit a carrier’s liability to around £113,000 per person in this event.

© 2019 Whitestone Chambers

www.whitestonechambers.com

law@whitestonechambers.com

Supreme Court rules that all courts and tribunals are subject to the open justice principle

The Supreme Court has ruled in the case of Cape Intermediate Holdings Ltd v Dring (Asbestos Victims Support Groups Forum UK) [2019] that all courts and tribunals that exercise the judicial power of the state are subject to the ‘open justice’ principle.

The principles of open justice are that the public can understand and scrutinise the court, thereby enabling the public to understand the issues and evidence that is provided by parties.

Civil proceedings have moved from being dominated by oral evidence to proceedings that generate a great deal of written evidence. As this movement has continued, questions have arisen as to how much of the written material placed before the court in a civil action should be accessible to those who are not parties to the proceedings and how this material should be made accessible to them. As most of the evidence is now reduced to writing and is not read out in court it is almost impossible to know what happens in court without access to the written material which, therefore, hinders open justice.

Lady Hale, delivering the Supreme Court’s judgment, said of access to court documents that “the court rules are not exhaustive of the circumstances in which non-parties may be given access to court documents. They are a minimum…”

As per R (Guardian News and Media Ltd) v City of Westminster Magistrates’ Court (Article 19 intervening) [2012] EWCA Civ 420, the default position as to court documents is that “the public should be allowed access, not only to the parties’ written submissions and arguments, but also to the documents which have been placed before the court and referred to during the hearing.”

The court has the power to grant access to these documents, however the applicant does not have an automatic right to be granted access to them. The applicant must put forward a cogent case as to how access will advance the open justice principle following which the court will balance against the possible harm caused by disclosure, such as the release of confidential information.

Also to be considered are the proportional and practical aspects of granting a request. It is advisable that the application for the written material is to be submitted during the trial as the documents would be readily available at this point. After the trial has concluded the likelihood of a successful application diminishes with time as identifying and retrieving the documents becomes practically difficult as the court and parties may not have retained them and, as such, the effort required to reproduce them may not be proportional to the principle of open justice.

Increasing the scope of access beyond the default position in relation to court documents is therefore “the inherent jurisdiction in support of the open justice principle, not the Civil Procedure Rules, CPR rule 5.4C(2).” The aforementioned CPR subsection states that:

“A non-party may, if the court gives permission, obtain from the records of the court a copy of any other document filed by a party, or communication between the court and a party or another person.”

With reference to CPR 5.4C(2), “records of the court” is outlined in the judgment delivered by Lady Hale as meaning “documents and records which the court itself keeps for its own purposes” and is, therefore, distinct from the purposes for which non-parties may be given access to court documents.

Judgment may be viewed at: https://www.bailii.org/uk/cases/UKSC/2019/38.html

© 2019 Whitestone Chambers

www.whitestonechambers.com

law@whitestonechambers.com

 

British Airways data breach results in a potential fine of £183m.

British Airways (‘BA’) are facing a historic fine of £183m following a major data breach  reported by the Information Commissioner’s Office (‘ICO’) on 6th September 2018 in which hackers successfully stole customers’ personal data consisting of passenger login details, card details, addresses and travel booking information. The ICO had previously reported that the personal data of around 500,000 passengers was stolen from BA’s website and the mobile app in a different data breach which purportedly started in June 2018.

Following the entry into force of the General Data Protection Regulation (‘GDPR’) on 25th May 2018, this is the first penalty for a personal data breach that has been made public and it demonstrates the serious nature of the approach undertaken by the ICO when personal data is not treated with the upmost care.

Although this constitutes a significant fine for BA, the ICO has the power to penalise a company for a serious data breach for the higher of either up to 4% or €20m of annual turnover, which could have resulted in a fine of around £460m.

To put the impact of the GDPR into context, some insight is provided by comparing this penalty to the one faced by Cambridge Analytica. Cambridge Analytica was fined £500,000 for a personal data breach that affected around 87 million users; the BA breach affected around 0.6% of the number of people affected by the Cambridge Analytica breach. However, at the time the fine facing Cambridge Analytica was governed by the Data Protection Act 1998, which set the maximum fine for a data breach at £500,000.

Elizabeth Denham, the Information Commissioner, said in relation to the BA data breach that “people’s personal data is just that – personal. When an organisation fails to protect it from loss, damage or theft it is more than an inconvenience. The law is clear, when you are entrusted with personal data you must look after it. Those that don’t will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights.”

Following the issue of the notice, Willie Walsh, Chief Executive of IAG, stated that British Airways would be making representations to the ICO and that “we intend to take all appropriate steps to defend the airline’s position vigorously, including making any necessary appeals”.

© 2019 Whitestone Chambers

www.whitestonechambers.com

law@whitestonechambers.com