- An officer can use these requirements on anyone who "appears to him or her to have access". They don't appear to need any evidence beyond that. The person does not need to be a suspect or, it appears, the subject of a warrant, just a person present at the location subject to the search warrant.
- It applies not just to access to information on the device, but information "which can be accessed by the use of that computer", and thus presumably includes information that is on other machine, or potentially not even in Ireland or the EU.
- It allows officers to freely operate computers on site during a search (this seems like horrible forensic practice?), and use passwords found on the site to try to access any information accessible from the computer.
- It does not just include disclosing passwords. It includes "any password or encryption key", and anything "to otherwise enable [the officer] to examine the information accessible by the computer".
- It even appears that it allows officers to compel people not just to disclose passwords but to actually operate the device for them so as to enable information access, and "to produce the information in a form in which it can be removed".
- It is not clear to me that there is any restriction on the scope of information, so long as it is in some way accessible.
- Head 17 appears to allow even legally (or otherwise) privileged information to be seized, so long as "the confidentiality of the material can be maintained pending the determination by the court of the issue as to whether the material is privileged material".
Combining these powers would seem to be able to result in ridiculous situations, for example, forcing a person to take data from a US server using an SSH key on their laptop, potentially violating US law by doing so, and for the person to do all the work necessary to do this themselves.