European negotiators reached a provisional deal with the United States on Wednesday, ending a year of wrangling over how to share information about trans-Atlantic air passengers that Washington says is needed to fight terrorism. The tentative agreement will be put to envoys from all 27 European Union nations Friday for approval, said the diplomats, who spoke on condition of anonymity because the deal has not been finalized. Differences over how to balance security needs with concerns over passengers' privacy had deadlocked negotiations since a 2004 deal on data sharing was voided by an EU court last year for technical reasons.
Monday, July 02, 2007
Passenger Data Sharing - EU and US
Thursday, June 28, 2007
OECD Recommendations
Source: Out-law International effort on privacy protection is launched
Social Networking
Even without having to look at the law itself (either data protection, privacy etc.) this report sheds light on how individuals (teens) protect their identities when using social networking such as MySpace.The majority of teens actively manage their online profiles to keep the information they believe is most sensitive away from the unwanted gaze of strangers, parents and other adults. While many teens post their first name and photos on their profiles, they rarely post information on public profiles they believe would help strangers actually locate them such as their full name, home phone number or cell phone number. At the same time, nearly two-thirds of teens with profiles (63%) believe that a motivated person could eventually identify them from the information they publicly provide on their profiles. A new report, based on a survey and a series of focus groups conducted by the Pew Internet & American Life Project examine how teens, particularly those with profiles online, make decisions about disclosing or shielding personal information. Some 55% of online teens have profiles and most of them restrict access to their profile in some way. Of those with profiles, 66% say their profile is not visible to all internet users. Of those whose profile can be accessed by anyone online, nearly half (46%) say they give at least some false information. Teens post fake information to protect themselves and also to be playful or silly.
Monday, June 18, 2007
Webcast on Identity Management
There is an interesting webcast on The Management of Identity and Personal Information on the Internet: Public and Private Initiatives for Addressing the Problems. Speakers on this panel include Sir David Normington (Keynote Speaker) Professor Brian Collins; Dr Stefan Brands, Jonathan Bamford, Assistant Information Commissioner (Open Public Panel Chair). The picture (on the right - source: Source: Semantic Pool.de), perhaps, encapsulates the types of personal information we give online. In the meantime, here is the abstract of what the webcast is about:There is much debate, and a number of competing initiatives, but the problems of identity and personal-information management over the Internet remain unsolved. These problems range from issues of convenience, such as requirements for multiple usernames and passwords, to the inability to carry out many transactions that require authentication of the user, to the security of systems that hold personal information, including identity information. Why do these problems persist? What are the opportunities in sight for moving ahead, and what risks are entailed in mitigating these concerns, including the failure to address these issues?
The Oxford Internet Institute organized a public panel to discuss this topic, chaired by Jonathan Bamford of the Information Commissioner's Office, and with a keynote by Sir David Normington, the permanent secretary at the Home Office. Other speakers include Professor Brian Collins (who combines the roles of academic, civil servant, and IT practitioner) and Dr Stefan Brands (an expert in privacy-enhancing technologies). The panel concludes with questions and an open discussion.
Wednesday, June 13, 2007
Google not covered by the Data Retention Directive
Google is not bound by the Data Retention Directive when it comes to search engine logs, Europe's data protection committee has said. Google has used the Directive to justify keeping data, but OUT-LAW has learned that the law does not apply. Google has come under increasing pressure in Europe to anonymise its server data, but the company says that it will wait until 18–24 months have passed before anonymising. Among its reasons for this was the Data Retention Directive. However, a senior European data protection official told OUT-LAW today that Google cannot rely on that law as justification for its retention. "The Data Retention Directive applies only to providers of publicly available electronic communications services or of public communication networks and not to search engine systems," said Philippos Mitletton. Mitletton works for the European Commission's Data Protection Unit, which itself is represented on the Article 29 Working Party, the committee of Europe's data protection authorities." Accordingly, Google is not subject to this Directive as far as it concerns the search engine part of its applications and has no obligations thereof," he said. Google offers other services that will be caught by the Directive – notably its email service, Gmail, and its internet telephony
service, Google Talk. If Google's search function were caught by the Directive, it could alarm operators of any site with a search function – i.e. most large websites – because potentially they would be similarly caught and therefore need to store details of every search conducted and the addresses of the computers that instruct each search.
Whilst this provides clarity over the scope of the Data Retentions Directive, one should not forget that we have the Data Protection Directive 95/46/EC (DPD) that applies to the automated processing of personal information and to a lesser extent manual files (if it can be shown that it formed part of a filing system such as card indexes) and the Directive on Privacy and Electronic Communications 2002/58/EC (complementing the DPD). For more on this, visit the European Commission, FSJ website at http://ec.europa.eu/justice_home/fsj/privacy/law/index_en.htm.
Tuesday, June 12, 2007
Talk about Google!
Google on Tuesday said it would cut the time for which it retains users’ personal search data to 18 months from 18-24 months, in a fresh concession to European Union data protection officials. The Article 29 working party, a group of national officials that advises the European Union on privacy policy, sent a letter to Google last month asking the company to justify its policy of keeping information on individuals’ internet searches for up to two years. Peter Fleischer, the internet search group’s global privacy counsel, wrote to Peter Scharr, chairman of the Article 29 group, confirming the move to cut the data retentoin period but pointing out that future data retention laws “may obligate us to raise the retention period to 24 months.” In a posting on the the official Google blog, Mr Fleischer wrote: “The internet is a global medium, and the principles at stake – privacy, security, innovation and legal obligations to retain data – have an impact beyond Europe, and outside of the realm of privacy. These principles sometimes conflict: while shorter retention periods are good for privacy, longer retention periods are needed for security, innovation and compliance reasons. We believe we’ve struck a reasonable balance between these various factors.”
Monday, June 11, 2007
Privacy Watchdog in India?
A data privacy watchdog is to be set up in India to oversee the country's IT industry amidst international concerns about the security of outsourced customer records and data. India does not have any data protection law equivalent to that in the UK and there have been recent cases of information being leaked from call centres to criminals who have then blackmailed the companies involved. The Data Security Council of India (DSCI) is being set up by Indian IT industry group Nasscom.
Tuesday, June 05, 2007
Reading to do
"We consider that in the area of data protection there is evidence of insufficient political appetite for protective measures as compared to law enforcement ones," said the Committee's just-published Third Report. "We note the Minister's expression of continuing Government support for the Data Protection Framework Decision. However, if proposals for a Framework Decision were to be superseded by the data protection provisions in the PrĂ¼m Treaty, we would have serious concerns as to whether these were adequate."
Here is the full-text of the report:
- "Inside the EU: the need for better protection" In this Report
See also:
Thursday, May 31, 2007
Google Saga
Although Google's headquarters are based in the United States, Google is under legal obligation to comply with European laws, in particular privacy laws, as Google's services are provided to European citizens and it maintains data processing activities in Europe, especially the processing of personal data that takes place at its European centre. As you are aware, server logs are information that can be linked to an identified or identifiable natural person and can, therefore, be considered personal data in the meaning of Data Protection Directive 95/46/EC. For that reason their collection and storage must respect data protection rules.The Article 29 Working Party considers a reduced storage period for server logs generated by the users of Google services as a valuable step to improve Google's privacy policies. However, it is of the opinion that the new storage period of 18 to 24 months on the basis indicated by Google thus far, does not seem to meet the requirements of the European legal data protection framework.The Article 29 Working Party is concerned that Google has so far not sufficiently specified the purposes for which server logs need to be kept, as required by Article 6(1)(e) of Data Protection Directive 95/46/EC. Taking account of Google's market position and ever-growing importance, the Article 29 Working Party would like further clarification as to why this long storage period was chosen. The Working Party would also be keen to hear Google's legal justification for the storage of server logs in general.
See also:
Saturday, May 26, 2007
Data theft - Call Centres
1. Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless-
(a) at least one of the conditions in Schedule 2 is met, and
(b) in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.
2. Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.
3. Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.
4. Personal data shall be accurate and, where necessary, kept up to date.
5. Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.
6. Personal data shall be processed in accordance with the rights of data subjects under this Act.
7. Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.
8. Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data.It is the eight data protection principle which is particularly relevant. A list of factors to take into account when considering an adequate level of protection can be found in Sch. 1, Part. II, para. 13 of the UK Data Protection Act 1998:
13. An adequate level of protection is one which is adequate in all the circumstances of the case, having regard in particular to-
(a) the nature of the personal data,
(b) the country or territory of origin of the information contained in the data,
(c) the country or territory of final destination of that information,
(d) the purposes for which and period during which the data are intended to be processed,
(e) the law in force in the country or territory in question,
(f) the international obligations of that country or territory,
(g) any relevant codes of conduct or other rules which are enforceable in that country or territory (whether generally or by arrangement in particular cases), and
(h) any security measures taken in respect of the data in that country or
territory.
Thursday, May 24, 2007
Anti-ID theft
The European Commission is considering new legislation against identity theft. The proposal is contained in a just-published policy on EU-wide plans to fight cybercrime. The European Commission's policy on fighting cybercrime in Europe is the product of many years of consultation and focuses on greater co-operation between European police forces. Though the Commission said that it did not believe that new legislation would be useful at this stage in stopping the fast growth of cybercrime, it said it will consider anti-ID theft laws later this year. "No general legislation on the fight against cyber crime can be expected to be effective at this moment," said a Commission statement. "However … targeted legislative actions may also prove to be appropriate or needed in specific areas. As an example, the Commission will consider an initiative
regarding European legislation against identity theft in 2007. Legislative action could also include developing a regulation on the responsibility of different actors in the relevant sector." Overall, the Commission said that its cyber crime fighting policies would depend on improved co-operation and communication between law enforcement forces across Europe. "The main feature of this policy instrument is a proactive policy in reinforcing the structures for operational law enforcement cooperation," said the Commission statement." The Commission will launch a reflection on how this cooperation can be strengthened and improved."
Saturday, May 19, 2007
New book on Privacy and Technology
Privacy is a growing concern in the United States and around the world. The spread of the Internet and the seemingly boundary less options for collecting, saving, sharing, and comparing information trigger consumer worries. Online practices of business and government agencies may present new ways to compromise privacy, and e-commerce and technologies that make a wide range of personal information available to anyone with a Web browser only begin to hint at the possibilities for inappropriate or unwarranted intrusion into our personal lives. Engaging Privacy and Information Technology in a Digital Age presents a comprehensive and multidisciplinary examination of privacy in the information age. It explores such important concepts as how the threats to privacy evolving, how can privacy be protected and how society can balance the interests of individuals, businesses and government in ways that omote privacy reasonably and effectively? This book seeks to raise awareness of the web of connectedness among the actions one takes and the privacy policies that are enacted, and provides a variety of tools and concepts with which debates over privacy can be more fruitfully engaged. Engaging Privacy and Information Technology in a Digital Age focuses on three major components affecting notions, perceptions, and expectations of privacy: technological change, societal shifts, and circumstantial discontinuities. This book will be of special interest to anyone interested in understanding why privacy issues are often so intractable.
Individuals can take a number of steps to enhance the privacy of their personal information and to become better informed about the extent to which their privacy has been compromised, although the effectiveness ofthese measures is bound to be limited. The committee thus recommends that if policy choices require that individuals shoulder the burden of protecting their own privacy, law and regulation should support theindividual in doing so. Firms and other organizations can design and implement self-regulatory regimes for protecting the privacy of the personal informationthey collect. Self-regulation is limited as a method for ensuring privacy,although it nevertheless offers protections that would not otherwise beavailable to the public. The committee offers a number of concrete recommendations to enhance the effectiveness of privacy policies. Specifically, organizations with self-regulatory privacy policies should take both technical and administrative measures to ensure their enforcement, routinely test whether their stated privacy policies are being fully implemented, produce privacy impact assessments when they are appropriate, strengthen their privacy policy by establishing a mechanism forrecourse if an individual or a group believes that they have been treated in a manner inconsistent with an organization’s stated policy, and establish an institutional advocate for privacy. The committee found that governmental bodies have important roles to play in protecting the privacy of individuals and or groups and in ensuring that decisions concerning privacy are made in an informedfashion. However, the U.S. legal and regulatory framework surrounding privacy is a patchwork that lacks consistent principles or unifying themes. Accordingly, the committee concluded that a less decentralized and moreintegrated approach to privacy policy in the United States could bring agreater degree of coherence to the subject of privacy. Two recommendationsf ollow from this conclusion. First, the committee recommends that the U.S. government should undertake a broad systematic review of national privacy laws and regulations. Second, the committee recommends that government policy makers should respect the spirit of privacy-related law.
Friday, May 11, 2007
Privacy Enhancing Technologies
The Commission adopts today a Communication with the purpose of identifying the benefits of Privacy Enhancing Technologies (PETs) and laying down the Commission's objectives in this field, to be achieved by a number of specific actions supporting the development of PETs and their use by data controllers and consumers. The development of information and communication technologies is constantly offering new services which improve people's life. However, alongside these benefits, new risks also arise for the individual, such as identity theft, discriminatory profiling, continuous surveillance or deceit. Vice-President Frattini, Commissioner responsible for Justice, Freedom and Security, highlighted that: "To ensure that breaches of the data protection rules and violations of individual's rights are not only something forbidden and subject to sanctions under the existing legal provisions, but also technically more difficult, the Commission puts forward a set of actions aiming at developing and promoting the use of Privacy Enhancing Technologies." Viviane Reding, Commissioner for Information Society and Media added "On line services provide a lot of benefits and convenience to citizens and huge competitive advantages to European businesses. Yet for such services to enjoy large scale growth and so boost Europe's economy, people must have sufficient confidence that their personal privacy and legitimate business interests are being properly safeguarded".The use PETs can help to design information and communication systems and services in a way that minimises the collection and use of personal data and facilitate compliance with data protection rules. The use of PETs should result in making breaches of certain data protection rules more difficult and /or helping to detect them, therefore having a positive impact on consumer trust, in particular in cyberspace, all without losing the functionality of the information system. The Commission Communication adopted today reflects on the benefits of PETs, lays down the Commission's objective to promote these technologies and sets out clear actions to achieve them in the future by supporting the development of PETs and their use by data controllers and by consumers. To pursue the objective of enhancing the level of privacy and data protection in the Community, the Commission intends to clearly identify the need and technological requirements of PETs and further promote the development of these technologies (in particular through RTD projects and large-scale pilot demonstrations) and their use by industry and public authorities, involving a vast array of actors, including its own services, national authorities, industry and consumers. The aim is to provide the foundation for user-empowering privacy protection services reconciling legal and technical differences across Europe through public-private partnerships. To ensure respect for appropriate standards in the protection of personal data through PETs, standardization and coordination of national technical rules on security measures for data processing are envisaged.
Tuesday, May 08, 2007
CCTV programme tonight
Don't forget, for those in the UK, that there is a two-part documentary beginning tonight on BBC1 at 9 pm on CCTV: CCTV: You Are Being Watched Smart Cameras: Jamie Theakston narrates a two-part documentary on the history of CCTV. He reveals how scientists are developing surveillance cameras which think for themselves. [S]
See also:
Monday, May 07, 2007
European Data Protection Intensive Conference 24-25 May 2007
The European Data Protection Intensive is a unique event designed to solve the challenge faced by so many data protection professionals: to find authoritative information, and reliable advisors, on the data protection rules and regulations throughout Europe. Data Protection Law & Policy has organised this two-day Intensive to provide you with all the information and analysis on the legal and practical issues throughout Europe. The European Intensive is supported by the data protection specialists of Ecomlex, a network of 18 European law firms. This pan-european conference brings together leading data protection experts and a strong multinational representation. At the European Intensive you will find data protection experts from all twenty-seven EU states, plus Switzerland and Norway, who will be available to lead discussions as well as to meet for individual appointments. KEY ISSUES IN PLENARY SESSIONS The two-day Intensive will feature a day of Plenary Sessions which will focus on the key issues facing European data protection professionals, followed by a day of Group Interactive Sessions. SIX GROUP INTERACTIVE SESSIONS The Six Group Interactive Sessions will enable participants to ask experts directly about their particular concerns in any and every country in Europe. COVER EVERY COUNTRY The programme has been structured to enable participants to cover every single country, if they so choose, in the course of the second day of the Intensive.
See:
Thursday, May 03, 2007
Revisiting the notion of "Processing" and the UK Court of Appeal's Decision in MDU v Johnson
Processing is given a wide definition by the Directive and this is again, followed by other EU Member States. Perhaps, a belated response on one's part, but given the UK's implementation of the Data Protection Directive 95/46/EC, the discussion by the Courts to the Lindqvist decision was not helpful. The Lindqvist judgment provides that:
25. According to the definition in Article 2(b) of Directive 95/46, the term processing of such data used in Article 3(1) covers any operation or set of operations which is performed upon personal data, whether or not by automatic means. That provision gives several examples of such operations, including disclosure by transmission, dissemination or otherwise making data available. It follows that the operation of loading personal data on an internet page must be considered to be such processing.
26. It remains to be determined whether such processing is wholly or partly by automatic means. In that connection, placing information on an internet page entails, under current technical and computer procedures, the operation of loading that page onto a server and the operations necessary to make that page accessible to people who are connected to the internet. Such operations are performed, at least in part, automatically.
27. The answer to the first question must therefore be that the act of referring, on an internet page, to various persons and identifying them by name or by other means, for instance by giving their telephone number or information regarding their working conditions and hobbies, constitutes the processing of personal data wholly orpartly by automatic means within the meaning of Article 3(1) of Directive 95/46.
The UK Court of Appeal in MDU v Johnson at paras. 33-34 stated that:
I should also note that reference was made to the decision of the European Court of Justice [ECJ] in Case C-101/01 [2004] QB 1014 (Lindqvist). A web page containing personal information about L and some of her fellow parishioners was composed by L on her home computer and placed on the internet. She was prosecuted for processing personal data by automatic means. The national court referred to the ECJ the question:
Does it constitute 'the processing of personal data wholly or partly by automatic means' to list on a self-made internet home page a number of persons with comments and statements about their jobs and hobbies etc?
The ECJ held that the listing of the parishioners was the processing of their personal data, and that the process had been "performed, at least in part, automatically" because of the loading of the page on to the server. The selection of the data had been purely manual, yet there was no suggestion that the processing taken as a whole was not automatic. It is, however, important to remind ourselves of the terms of the question that was asked in Lindqvist, which was limited to whether using the computer to place the list on the net was processing. Plainly it was, for the reason given by the ECJ. By the same token, when Dr Roberts caused the computer to transmit her conclusions to the RAG data was being processed. But it does not help [J] to establish the latter point, because what he complains of is unfair conduct in the reaching of those conclusions, before that processing of the conclusions took place. I think that in the end it was agreed by the appellant that Lindqvist does not assist in our present concerns. But [Counsel] has more formidable support from authority nearer home, the decision of this court in Campbell v MGN Ltd [2003] QB 633.
That case was regarded by the Judge as conclusive in [J's] favour on the processing issue, and it must therefore be analysed in some detail.
The judgment is slightly lengthy and warrants another article to be written. At this stage, however, much work is still needed (whether by academics, policy makers, lawyers etc) to inform not only the public about the European Data Protection Directive 95/46/EC and what it is intended (see also the UK Information Commissioner's Website), but that if the UK Data Protection Act 1998 continues to be narrowly construed (in the light of cases such as Durant and Johnson), data protection laws in the UK may, in all but name, be considered weak!
ONI Conference: The Future of Free Expression on the Internet
There is a conference being held on the 18th May and hosted at the Oxford Internet Institute, which judging by the website is well worth going:
The OpenNet Initiative is holding its first public conference to discuss the current state of play of Internet filtering worldwide. The conference will be hosted by the Oxford Internet Institute on May 18, 2007. The conference is free of charge and open to the public.
Results from the first global study of Internet filtering carried out by the OpenNet Initiative will be on the table for a day of discussion involving ICT development experts, speech and human rights advocates, journalists and bloggers, international laywers and scholars, and others interested in state responses to online information flows. We hope you will join us in exploring interpretations and implications of our data and helping to shape the OpenNet Initiative's evolving research agenda.
The day will conclude with a debate hosted by the Oxford Union - Resolved: the Internet is the greatest force for democracy around the world.
Further details can be found at:
Wednesday, May 02, 2007
House of Lords Decision in Douglas v Hello
Facts: Michael Douglas and Catherine Zeta-Jones entered into an agreement with OK! magazine by which OK! were given exclusive rights to publish photographs of the Douglas-Zeta-Jones wedding. At the wedding and reception photography was prohibited; employees signed agreements not to take photographs and guests were searched for cameras. Shortly after the wedding OK! became aware that Hello! magazine planned to publish surreptitiously taken photographs of the wedding. OK! brought claims against Hello! for breach of confidence and causing loss by unlawful means (the Douglases also brought proceedings but these were no longer in issue).Lindsay J held Hello! liable for breach of confidence. The Court of Appeal reversed the judge’s decision on the ground that the obligation of confidence for the benefit of OK! attached only to the photographs which the Douglases authorized them to publish and not to any others. OK! appealed.
Issue (1) Whether Hello! were lable to OK! for breach of confidence;(2) Whether Hello! were liable to OK! for interfering with their business interests by unlawful means.
Held Allowing the appeal by a 3-2 majority:(1) Reversing the judgment of the Court of Appeal; OK! had paid £1m for the benefit of the obligation of confidence imposed upon all those present at the wedding in respect of any photographs of the wedding and were entitled to enforce that obligation. It had no claim to privacy nor could it make a claim parasitic on the Douglases rights. (Per Lord Nicholls and Lord Walker dissenting) The unapproved photographs contained nothing not in the approved photographs and therefore, once the latter had been published, there could be no breach of confidence. (Per Lord Walker dissenting) The law would not protect exclusivity in a ‘spectacle’.
(2) If it were necessary to consider this, Hello! had the necessary intention to cause loss but had not used unlawful means to interfere with the actions of the Douglases.See also:
No doubt, there will be some academic discussion about the law of torts in this area (particularly, the protection of an individual's image). Commitments permitting, one will have to start writing an article on this.
European Data Protection Supervisor's Annual Report
The number of complaints to the European Data Protection Supervisor (EDPS) almost doubled in 2006, but only 20% were valid complaints for the privacy watchdog of the EU institutions, its annual report has said. The number of complaints remained small, rising from 27 in 2005 to 52 in 2006. All but 10 of the complaints should have been directed to national data protection authorities and not the European Supervisor. In 2005 all but five of the complaints were similarly misdirected. The EDPS is still a new body, having only been formed in 2004. It increased in size last year from having 19 staff to having 24, and its budget increased from €3 million to €4m. "A large majority of the complaints received continued to fall outside of the supervisory competences of the EDPS, for instance because they dealt exclusively with processing of personal data on the level of the member states, where national Data Protection Authorities are competent," said the report. The report revealed that the body is conducting an audit of Eurodac, the database of fingerprints of illegal immigrants and applicants for asylum. The in-depth security audit is due to report by the middle of this year, the EDPS said. The report acknowledged that the EDPS still has not managed to make data protection an automatic part of working life for EU bodies. "[One challenge] is the implementation of data protection rules and principles in the whole EU administration and to develop a data protection culture as part of good governance," said the report..
See also:
Tuesday, May 01, 2007
ICO to call for more powers
The Information Commissioner, Richard Thomas, is today proposing new safeguards – including privacy impact assessments and inspection powers –to ensure public confidence in initiatives and technologies which could otherwise accelerate the growth of a surveillance society.Giving evidence before the Home Affairs Select Committee the Information Commissioner will also call for stronger powers to allow his Office (the ICO) to carry out inspections and audits. Currently the Commissioner must gain consent before inspecting an organisation for compliance with the Data Protection Act. Information Commissioner, Richard Thomas, said: “People now understand that data protection is an essential barrier to excessive surveillance. But it is wrong that my Office cannot find out what is happening in practice without the consent of each organisation. The risks that arise from excessive surveillance affect both individuals and society as a whole. As well as risks such as identity mistakes and security breaches there can be unnecessary intrusion into people’s lives and loss of personal autonomy. There is also a concern that too much surveillance will create a climate of fear and suspicion. It is essential that before new surveillance technologies are introduced fullconsideration is given to the impact on individuals and that safeguards are inplace to minimise intrusion.”The introduction of privacy impact assessments will ensure organisations set out how they will minimise the threat to privacy and address all the risks of new surveillance arrangements prior to their implementation...
See also:
On Privacy Impact Assessments, see also:
Monday, April 30, 2007
Virtual conference on Negotiating Identities
Friday, April 27, 2007
House of Lords Committee: Surveillance and Data Collection
What forms of surveillance and data collection might be considered constitutionally proper or improper? Is there a line that should not be crossed? How could it be identified?
How have surveillance and data collection altered the nature of citizenship in the 21st century, especially in terms of citizens’ relationship with the state?
Is the Data Protection Act sufficient to protect citizens? Is there a need for additional constitutional protection for citizens in relation to surveillance and the collection of data?
“The nature and extent of surveillance and data collection have changed dramatically in recent years. We now have close to 4.2 million CCTV cameras in the UK and with the introduction of the NHS Spine and the ID card database the government will hold more information about us than ever before.
“The broad constitutional implications of these changes have not thus far been sufficiently closely scrutinised. As a Committee we hope to get to the bottom of how these changes are altering the relationship between individuals and the State, and to ascertain whether necessary protection is in place."Perhaps, an interesting question to ask about the sufficiency of the DPA 1998 to protect citizens. The DPA 1998 provides safeguards for the collection of personal information. Whether the existing legislative data protection framework is sufficient to prevent the surveillance is questionable. Do we need toughter penalties? On the subject about additional constitutional protection for citizens in relation to surveillance and the collection of data, the first starting point would be to look at the Human Rights Act 1998, which incorporates the ECHR and includes the"'right to respect for private and family life." Although the right to privacy is not absolute, it would be a good starting point.
Thursday, April 26, 2007
DCA Consultation on Freedom of Information Regulations
The Government has drafted amended FOI fees regulations which will allow public authorities to take into account more comprehensively the work involved in dealing with an FOI request. This consultation asks for views on the draft Regulations. The initial consultation period closed on 8 March 2007. A supplementary paper opened a second period of consultation on 29 March 2007 inviting views on the principle of amending the 2004 Regulations and also any further views on the draft Regulations themselves as set out in the consultation paper of 14 December 2006.
Saturday, April 21, 2007
Interpretation of "Processing"
David Paul Johnson took a case against the Medical Defence Union (MDU), a non-profit body which provides indemnity policies for its members. The MDU had refused to renew Johnson's policy after it conducted a review of his case and Johnson argued that the organisation had not
processed his data fairly and had therefore breached the Data Protection Act. The MDU operates a scoring system of its own invention which allocates points to certain complaints or allegations made against a doctor, even if they are never proved or pursued. By 2002 Johnson, who had been an MDU member since 1986, had built up enough of these points to trigger a review of his policy by the MDU. He had built up points by consulting the MDU over professional issues, including complaints. He had never been the subject of a claim of professional negligence. His case had been judged after an MDU staff member had looked through his files and collated information from them into a new computer document. Most of the files were manual and fell outside the Data Protection Act's definition of a "relevant filing system". Three were computer based, though, and so their use was controlled by the Act. Johnson claimed that this task was processing, as defined and controlled by the Act's first principle, which says that processing of personal data must be fair and lawful. Johnson claimed that his data was unfairly processed, in breach of the Act. The High Court agreed that the activity carried out by the MDU was processing under the Act, but said that it was unfair only in a minor and inconsequential way, and that therefore there was no breach. Both parties appealed the judgment, Johnson arguing that the processing was unfair and the MDU arguing that the High Court was wrong to say that its actions counted as data processing. The Court of Appeal said that the actions were not data processing. "Mr Johnson, who agrees that he has no right in contract or in any other chapter of English law to challenge [MDU examiner] Dr Roberts's selection of the information contained in his personal data, asserts that he can nonetheless mount these proceedings because her act of analysis is covered by the First Data Protection Principle," said presiding judge Lord Justice Buxton in his ruling. "I would not be prepared to conclude that the 1998 Act has had that effect, and the other widespread effects suggested above, unless I was driven to it. Far from that being the case, neither the 1998 Act nor the Directive give any support to the appellant's case. I would therefore hold that the Judge was wrong to find that Dr Roberts's selection of the data amounted to processing of data in the terms of the Act," he said.
Friday, April 13, 2007
Monitoring of Electronic Communications
Wednesday, April 11, 2007
DNA database
There is a case pending before the European Court of Human Rights concerning the storage of DNA. This is an interesting case as it concerns an individual who has not been charged with an offence. No doubt DNA of an individual is "personal data" within the meaning of the Data Protection Directive 95/46/EC ("sensitive data" if it relates to the health of the individual). See the extract below from Out-Law News: Tuesday, April 10, 2007
ICO's response to proposed changes to the FOIA by the Government
a more robust application of section 14 (exclusion of vexatious requests) would, to a very significant extent, address the mischief at which the new cost proposals purport to be directed;
• there are grave doubts about the extent to which the aggregation of non-similar requests would be workable in practice, particularly if determined applicants took steps to circumvent the new provisions;
• the proposed concepts of reading, consultation and consideration time, will present very real difficulties for challenge and adjudication;
• the proposals will introduce new layers of procedural and bureaucratic complexity. There is likely - as feared by Frontier Economics - to be “a substantial increase in
requests for internal review and appeals to the ICO, with a substantial increase in costs”.
• there will certainly be a surge of difficult procedural complaints to ICO which can be predicted to start no less than two months after the new Regulations have been implemented. Unless further resources are made available, regrettably, the net effect – at least for the forthcoming year - has to be the prospect of more time taken to resolve difficult cases, an increase rather than a reduction in the backlog of complaints and the diversion of resources onto complaints about costs rather than substantive issues of disclosure of official information in the public interest....
5. The ICO believes that a more robust application of section 14, in line with the published guidance and decision notices, would, to a very significant extent, address the mischief at which the new cost proposals purport to be directed.
See also:
Monday, April 09, 2007
Telemedia Act 2007
Saturday, April 07, 2007
Another paper
The Data Protection Directive 95/46/EC (hereinafter the “Directive”) was passed in 1995 to harmonise the national data protection laws within the European Community with the aim of protecting the fundamental rights and freedoms of individuals including their privacy as set out under Art. 1 of the Data Protection Directive. The rules governing the processing of personal data are deemed to be inapplicable in the two instances outlined by Art.3(2). Processing of personal data taking place as part of activities falling outside of Community law are excluded from the DPD. The Directive is also deemed to be inapplicable if the processing of personal data is undertaken by a natural person in the course of a purely personal or household activity. It is the second part of Art. 3(2) which is examined in more detail. The ruling by the European Court of Justice in Lindqvist provides us with a fresh opportunity to re-examine whether the policy justifications for the exclusion under Art 3(2) continue to remain relevant in the light of widespread use of new technologies such as blogs, podcasts and web pages for processing and distributing information. Greater clarity regarding the implication of new communication technologies for DPD policy is necessary if the laws on data protection are to evolve in a coherent and principled manner.
Keywords: Data Protection Directive 95/46/EC; internet, private purposes, blogs, podcasts
Although this is still a work in progress, we hope to have this published by the end of the year. Any thoughts or views are welcome.
Data Protection - a new website
Friday, March 30, 2007
Enquiry into a "Surveillance Society"
The UK Parliament has launched an enquiry into the surveillance conducted on citizens by the Government. It will investigate the growing number and scope of government databases holding increasing amounts of information on citizens. The Home Affairs Committee will conduct the inquiry, called 'A Surveillance Society?', so that it can produce rules for Government to follow when building up increasing amounts of sensitive and private information on the general public. "The inquiry will consider the growth of numerous public and private databases and forms of surveillance," said a Committee statement. "They either derive directly from the work of the Home Office and its related public functions or are controversial because whilst they offer the potential to play a part in the fight against crime their use may impinge on individual liberty." "The inquiry will focus on Home Office responsibilities such as identity cards, the National DNA Database and CCTV, but where relevant will look also at other departments’ responsibilities in this area, for instance the implications of databases being developed by the Department of Health and the Department for Education and Skills for use in the fight against crime," it said.
Data Protection Resources: new URL
Royal Academy of Engineers - Report on Privacy
This study identifies likely developments in information technology in the near future, considers their impact on thecitizen, and makes recommendations on how to optimize their benefits to society. The report focuses on an area wherethe developments in IT have had a particularly significant impact in our everyday lives - the use of IT in surveillance,data-capture, and identity management. It looks at the threats that these technologies may pose and at the roleengineering can play in avoiding and managing these risks.
Tuesday, March 20, 2007
RFID - changes to the Directive on Privacy and Electronic Communications 2002/58/EC
The European Commission will make changes to the Privacy and Electronic Communications Directive to take account of the exploding market in radio frequency identification (RFID) chips, it has said. Amendments will be proposed by the middle of this year. The Commission has published a Communication, intended as "a step towards a policy framework," for dealing with RFID chips, whose usefulness is seen by some to be at odds with privacy and data protection. RFID is a radio technology which allows chips to be identified at short distances by chip readers. The chips themselves are so cheap – just a few pence each – that they are useful in all sorts of commercial applications, from goods transit to stock management and even shop checkouts. It is the application of the chips to people and the things people do with the chipped goods, though, that has always worried privacy activists. Information Society and Media Commissioner Viviane Reding said that the advisory group she was forming to monitor RFID would work in conjunction with the Article 29 Data Protection Working Group, an existing, independent EU advisory body. Reding announced the creation of an RFID Stakeholder Group to help the Commission develop its RFID policy as part of an action plan to address the potential pitfalls and benefits of using RFID technology.
Thursday, March 15, 2007
Search Engine results
Privacy bodies have welcomed Google's decision to anonymise personal data it receives from users' web searches. The firm previously held information about searches for an indefinite period but will now anonymise it after 18 to 24 months. "This is an extremely positive development," said Ari Schwartz, deputy director of the Center for Democracy and Technology, a US-based watchdog. "It's the type of thing we have been advocating for a number of years." However, governments could still force Google to hold onto data or hand it over to authorities. "By anonymising our server logs after 18 to 24 months, we think we're striking the right balance between two goals: continuing to improve Google's services for you, while providing more transparency and certainty about our retention practices," a statement from the search giant said. It's a step forward, but I would like to see them anonymising data in a much shorter period Richard Clayton, Cambridge University It added: "Unless we're legally required to retain log data for longer, we will anonymise our server logs after a limited period of time." Peter Fleischer, Google's privacy counsel for Europe, said the decision has been taken after consulting with privacy bodies in theUS and Europe. He said: "We believe that privacy is one of the cornerstones of trust. We will be retroactively going back into our log database and anonymising all the information there."
Thursday, March 08, 2007
Privacy law in the US?
Microsoft Chairman Bill Gates has added to his legislative wish list, renewing his push for Congress to pass an "all-inclusive" consumer privacy and security law by year's end.
In his keynote speech at a dinner here Wednesday hosted by the advocacy group Center for Democracy and Technology, Gates shifted his focus away from the calls for education and immigration changes that dominated his appearance at a morning Senate hearing. There's a critical need for federal privacy rules that require transparency about data collection practices, grant users access to their own data and dictate what companies must do if a breach occurs, Gates told an audience of about 900 people in a cavernous ballroom at the Ritz-Carlton Hotel here. Microsoft isn't alone in requesting federal privacy legislation. The Windows maker is allied with a number of tech titans, including eBay, Hewlett-Packard, Google, Intel and Oracle, that have begun lobbying Congress to override what they deem a patchwork of disparate state laws.
Privacy in the US certainly seems to be patchy, but whereas the European Data Protection Framework is much stricter in protecting the privacy of individuals (Art. 1 states fundamental rights and freedoms of individuals), this cannot be said of the US. Whether the legislation will be framed along the lines of the European Data Protection Directive is not clear, but for anyone interested in the differences between the US/Europe protection of privacy, see:
- Kang and Buchner. Privacy in Atlantis, Harvard Journal of Law and Technology, Vol. 18, No. 1, Fall 2004.
Reidenberg, R. and P. Schwartz. Data privacy Law (Michie, 1996).
Tuesday, March 06, 2007
Art. 29 Working Party: Opinion on transfer of PNR to US Authorities
This opinion and its annexes (frequently asked questions and model notices) are aimed attravel agents, airlines, and any other organisations providing travel services to passengersflying to and from the United States of America. This opinion and the annexes update andreplace the previous opinion of 30 September 2004 (WP97).The current legal framework for transferring PNR information to the US authorities iscovered by the interim agreement of 16 October 2006. Negotiations for a new agreementare expected to start in 2007.There remain obligations on travel agents, airlines and other organisations to provideinformation to passengers about the processing of their personal information, and thisopinion aims to give advice and guidance on who needs to provide what information, how and when. Information should be provided to passengers when they agree to buy a flight ticket, andwhen they receive confirmation of this ticket.The opinion gives advice on providing information by phone, in person and on theinternet. The Art. 29 Working Party has established the model information notices (the annexes tothis opinion) to make providing this information easier for organisations, and to makesure the information provided is consistent across the European Union.The shorter information notice gives passengers summary information about transfers oftheir data to the US authorities, and how to find out more information.The longer notice is in the form of frequently asked questions and has more details aboutthe processing. It explains passenger data more widely, before focusing on PNR data. It also includes links to the interim agreement and other relevant documents.
Monday, March 05, 2007
Data Protection Resources: New URL
Freedom of information
The Information Commissioner will tomorrow demolish one of the main arguments being used by Government to introduce restrictions on people’s right to know about the State. Richard Thomas, who will be appearing before MPs on the Constitutional Affairs Committee, is expected to say that public bodies already have wide-ranging powers to ignore requests that are designed to waste civil servants’ time. The Government believes that laws introduced in 2005 requiring much greater disclosure of information from the public sector place an unfair burden on civil servants. However campaigners say that the proposed restrictions are unnecessary and designed to save the Government from embarrassment after a series of damaging disclosures.
Saturday, March 03, 2007
File Sharing and Privacy
Tuesday, February 27, 2007
First UK case on Spyware
There was a recent case R v Waters, that reached the Court of Appeal about a man who had conspired to install spyware software on his wife's computer. He was sentenced to four months imprisonment and the Court of Appeal upheld the ruling: Computers are an established part of modern life. An increasing amount of personal and private information is kept on computers, not only by the State and large organisations but also by individuals. The privacy of that information must be protected and it is vulnerable to the kind of unauthorised interference and intrusion that occurred in this case. The judge correctly identified deterrence as an element of sentencing in this case. In our judgment, a sentence of imprisonment for offences such as this was not wrong in principle.For further reading, see also:
Deterrent sentence appropriate for "computer spying" [2007] Justice of the Peace & Local Government Law 171(7),
115
Thursday, February 22, 2007
Data Protection Act 1998
Following the results of a consultation paper launched last summer, the Department of Constitutional Affairs has announced that much tougher powers to sentence those found guilty of breaching Data Protection principles will be given to courts. For the first time, this will mean that courts may impose prison sentences for individuals who trade in, or deliberately misuse personal data. The change is intended to combat the illegal trade in personal information which has become highly profitable in recent years. Several reports by the Information Commissioner have highlighted the inadequacy of current penalties, as the fines imposed on those who breach the provisions of the Data Protection Act do not appear to have deterred others from participating in the trade. In the worst cases, judges will have the power to impose prison sentences of up to two years in addition to unlimited fines.
This follows a recent report from the ICO who called for tougher penalties against those who are involved in the illegal trade of personal information. See:
- What price privacy? (pdf)
- What price privacy now? (pdf) - a review after 6 months since the ICO's first report on "What privacy privacy"
Thursday, February 15, 2007
Data snooping
Balancing the needs of the police to investigate crimes online with the privacy of individual web users has become controversial as governments seek to extend their snooping rights in cyberspace. Already European ISPs and phone companies are in the process of implementing an EU directive which forces them to retain a variety of communication data for up to two years. Now, a republican congressman, Lamar Smith, has put forward a bill for discussion in the US Congress that could see a similar regime operating Stateside. Experts think it is unlikely that the US will introduce draconian data retention laws any time soon, not because they do not want to but because similar European legislation is currently in varying degrees of disarray.
Friday, January 26, 2007
Data protection/privacy bloggers
PIPEDA Blog - Written by a Canadian Lawyer, this contains information related to the Personal Information Protection and Electronic Documents Act (aka PIPEDA) and other Canadian and international laws.
Privacy Podcast - By Aaron Titus, with a US bias on keeping identity secure.
Marketing by Permission - By Tim Trent with a UK focus on data protection developments
SpyBlog - Need no further explanation.
Let me know if there are any new blogs that have a data protection/privacy focus.