Proposed new UK surveillance bill requires ISPs to store which sites users visit for a year
May unveils plan to store web browsing — Internet firms will have to store data on what people access online for a year, under new surveillance law plans. — At the same time …
Context & Ripple Effects
This 2015 draft from Theresa May's Home Office was the opening move of what became the Investigatory Powers saga: a revised bill reached parliament within four months, carrying privacy safeguards but keeping the same 12-month ISP retention mandate, and by late 2016 the requirement that everyone's browsing history be stored and available to police and government agencies had passed into law.
What makes the proposal worth tracking now is how the retained data got used afterward: five years on, the Home Office was running a browsing-surveillance trial with two unnamed ISPs and the National Crime Agency — exactly the access pattern this bill created — even as a separate Data Protection Bill promised users a "right to be forgotten".
First-order effects
- UK ISPs become mandatory retention infrastructure overnight: they must log every customer's web destinations for 12 months and stand ready to hand those histories to police and several government agencies.
Second-order effects
- Once the database exists, demand for it compounds rather than sits idle — the Home Office's later trial tooling built on ISP partnerships shows agencies treating browsing history as an operational dataset, not an archive.
Third-order effects
- Bulk retention becomes self-normalizing: a mandate justified for one investigation model becomes the plumbing for successive surveillance programs, while parallel rights like data deletion have to be carved out against a state that requires the data be kept in the first place.
The trend: The UK is institutionalizing state-mandated mass data retention as default legal infrastructure, with each new surveillance capability building on the last.