Blog / Privacy Law

  • uk-law
  • investigatory-powers-act
  • technical-capability-notice
  • telecoms
  • interception
  • surveillance

What a Technical Capability Notice Can Require of a Telecoms Operator

A technical capability notice (TCN) is not a blank cheque. The Secretary of State cannot tell an operator to "make yourself interceptable" in whatever way seems handy; the notice can only impose obligations that appear on a list set out in secondary legislation. The list is short, fairly dull, and rather more specific than the headlines suggest.

This is general information about the law as I read it, not legal advice. Where I am giving an opinion rather than describing the text, I say so.

The two layers: the Act and the regulations

Section 253 of the Investigatory Powers Act 2016 (IPA) gives the power. The notice itself, though, can only impose "applicable obligations", and those are whatever the Secretary of State has specified in regulations. The regulations are the Investigatory Powers (Technical Capability) Regulations 2018.

So there are two separate questions to ask of any notice:

  • Does the Act allow this operator to be given a notice at all?
  • Is every obligation in it on the list in the regulations?

A notice that asks for something outside the list is, on the face of the statute, outside the power. That is the bit people tend to skip.

Who can receive one

"Relevant operator" covers postal operators, telecommunications operators, and anyone proposing to become one. Section 253(8) allows a notice to reach operators outside the UK and to require things done outside the UK.

The 2018 regulations add a size filter for some obligations. As I read them, telecoms operators serving more than 10,000 people in the UK are the ones who can be given the interception and equipment interference obligations. Check the regulations directly if you are near that line, because the exact counting rules matter.

What the list actually contains

The regulations are organised by the kind of warrant or authorisation the operator is being made ready for. In outline:

  • Schedule 1: interception warrants (content), including timing and delivery obligations.
  • Schedule 2: communications data requests under Part 3 of the Act.
  • Schedule 3: equipment interference.

For interception, the telecoms obligations include keeping apparatus and systems capable of carrying out a warrant, delivering the intercepted material to an agreed hand-over point in near real time where practicable, and providing the product within a stated working-day timescale. They also include being able to intercept simultaneously for a stated proportion of users (I read this as 1 in 10,000 of those served), and telling the Secretary of State about proposed service changes that affect any of this.

Communications data has its own set: obtain and disclose data without undue delay, keep reliable systems for doing so, and install and maintain apparatus the Government supplies.

The encryption obligation, read closely

Section 253(5)(c) lets the regulations cover "removal by a relevant operator of electronic protection applied by or on behalf of that operator". The regulations use that for interception and communications data, and the wording is narrower than the slogan "backdoors".

Three things stand out:

  1. The protection has to be applied by or on behalf of the operator. Encryption applied by the user, with keys the operator never holds, is not obviously in scope.
  2. The obligation is qualified by practicability: where reasonably practicable.
  3. Before including it, the Secretary of State must have regard to technical feasibility (section 255).

Whether those limits survive contact with a service that offers end-to-end encryption on the operator's own platform is a live argument. My opinion: the words "on behalf of" are doing a great deal of work, and they have not been tested in a published court decision that I know of.

Quick detour: why an ISP is not the obvious target

Hang on, why does this matter for a telecoms operator at all? Mostly because traditional networks are where the obligations fit cleanly. Interception at a hand-over point is a network concept. Plain traffic crossing an ISP is often unencrypted at the operator's layer or encrypted with keys the operator does not have, so the electronic protection limb mainly bites on things the operator itself encrypts, such as its own signalling or storage.

The interesting pressure points are the big messaging and cloud providers, which the Act treats as telecommunications operators too. That is where the 2018 list gets stretched, and where the argument above gets loud.

The safeguards between notice and obligation

A notice does not appear out of thin air. The Act builds in several steps:

  • Consultation: the Secretary of State must consult the operator before giving the notice.
  • Consideration: factors include benefits, number of users affected, technical feasibility, cost and other effects on the operator.
  • Judicial approval: a Judicial Commissioner must approve the decision (section 254) by applying judicial review principles, including the privacy duty in section 2.
  • Reasonable time: the notice must specify a reasonable period for compliance (section 253(7)).
  • Review: an operator can ask for the notice to be reviewed, with the Technical Advisory Board and a Judicial Commissioner involved.

The Investigatory Powers (Amendment) Act 2024 changed parts of the process, including what happens while a review is pending and the wording of section 253(1). Read the current text of sections 253 to 257 rather than relying on pre-2024 commentary, including this article's simplifications.

Secrecy changes the practical picture

The operator and its staff cannot disclose the existence or content of a notice without the Secretary of State's permission (section 255). That is enforceable through civil proceedings. The result is that almost nothing is published about how many TCNs exist or what they contain.

The obvious consequence is that outside observers argue from the statute and the regulations, not from any real notice. That includes me. Anything stronger than "here is what the text allows" would be guesswork.

A sensible way to read one, if you ever see one

If you are in a position to be advising an operator, a simple test works: take each line of the notice and find the paragraph of the regulations it comes from. Anything without a home is a question to put to the Home Office and, if needed, to the review process. Anything with a home still has to be proportionate and, for encryption, reasonably practicable.

That is a lawyer's job in the end. But the structure, Act for the power and regulations for the content, is the thing to hold on to.