Friday, September 21, 2007

UK Data Retention (EC Directive) Regulations 2007

As noted in my previous post, the UK Data Retention (EC Directive) Regulations 2007 will take effect on 1st October 2007. These regulations implement the Data Retentions Directive 2006/24/EC and apply to public communications providers. Public communications providers are defined under Regulation 2(d) as

(i) a provider of a public electronic communications network; or

(ii) a provider of a public electronic communications service;

Data will be retained for a period of 12 months from the date of communication (Regulation 4(2)). What is less than clear is whether a public communications provider can retain data for more than 12 months. The types of data to be retained are telephone numbers and mobile numbers (Regulation 5(1) and 5(2)). Under Regulation 8, the UK ICO continue to monitor the application of these regulations. The Regulations do not cover Internet access, Internet e-mail or Internet telephony to be retained (Regulation 4(5)). The Data Retention Directive, however. allows Member States to extend the rules to internet data at a later date, provided these rules are in force by 15 March 2009 (Art. 15(3)).

Luxembourg: Data Protection

(via Privacy, Laws and Business)

"On 1 September, Luxembourg modified its data protection law, removing some obligations to notify data processing to the CNPD (the national data protection authority) and simplifying other regulations.

The most common data processing in business and administration, such as that for human resources, no longer must be notified to the CNPD. Data processing by some professionals (lawyers, notaries, doctors, journalists, for example) will be considered to be sufficiently protected by professional ethics. The lists and conditions regarding the new rules on notification are on the CNPD website (www.cnpd.lu).

Data processing notification rules are also simplified for scientific research and health professionals, including clinical research for pharmaceutical companies. Data processing officers in charge of data protection for firms can now be employees of the firm (formerly they could only be external consultants). This means that these companies are exempt from notification requirements.

Perhaps the most significant change is that Luxembourg no longer extends protection to the privacy of legal persons, such as companies, as it does to natural persons. Of course, personal data processed by legal persons is covered by the amended data protection law."

See also:


Monday, September 17, 2007

UK's Implementation of the Data Protection Directive

Out-Law has recently put this post up (they have been successful in making an FOI request):

"EXCLUSIVE: The UK's Data Protection Act (DPA) does not implement European law properly, according to the European Commission which is investigating problems in the UK's implementation of 11 of the Data Protection Directive's articles, almost a third of the entire Directive.

Using freedom of information legislation, OUT-LAW.COM has learned that 11 articles are the subject of two Commission letters to the UK Government, even though the Government has refused to provide these details to Parliament. The Ministry of Justice has rejected the Commission's claims and told OUT-LAW.COM that the UK Government believes it has implemented the Directive fully.

In June 2005, Labour MP Harry Cohen asked the Government exactly what problems the Commission had identified when it said that the DPA was a defective implementation of the Directive.

Parliamentary undersecretary Bridget Prentice refused to answer.

"We currently have no plans to disclose the detail of those discussions as the formal Commission investigation process is still taking place," she said. "If the Government were to disclose the information requested, it would prejudice the negotiating process between the UK and the Commission and so prejudice UK interests".

The articles of the Directive which the Commission claims have not been implemented properly are articles 2, 3, 8, 10, 11, 12, 13, 22, 23, 25 and 28 – just under a third of the 34 articles in the Directive.

These Articles relate to: the definitions used in the Directive (e.g. the meaning of personal data); the scope of the Directive's application to manual files; the conditions when sensitive personal data can be processed; the fair processing notices give to individuals; the rights granted to data subjects; the application of exemptions from these rights; the ability of individuals to seek a remedy when there is a breach; the liability of organisations for breaches of data protection law; the transfer of personal data outside European Union; and the powers of the Information Commissioner.

Data Protection expert Dr Chris Pounder of Pinsent Masons, the law firm behind OUT-LAW.COM, said that the extent of the objections reflects official attitude towards data protection policy. "All UK Governments involved in implementing the Directive have had a policy of minimising the Data Protection Directive's effect," he said. "The number of problems raised by the Commission seem to indicate that the UK Government may have misjudged the situation and minimised the effect of too many obligations".

"The fact that the Commission has a problem with so many of the articles in the Directive is a surprise," he said. "I had expected just a handful of objections linked to the Court of Appeal decision in the Durant case."

That landmark ruling from 2003, in Michael Durant's dispute with the Financial Services Authority, narrowed the scope of what constituted personal data under the Data Protection Act.

Pounder continued: "Instead, there are unexpected issues, for example, in relation to transfers, fair processing notices, exemptions, powers of the Commissioner, penalties and remedies."

The Commission's investigations were not prompted by a complaint. They were initiated by the Commission itself, though they are thought to have been provoked by the Durant ruling.

A statement issued to OUT-LAW by the Ministry of Justice on Friday said: "The European Commission, as part of its review of the implementation of the 1995 Data Protection Directive by each member state, have raised a number of issues with the UK."

"We are in discussion with the Commission about these issues. We believe that the UK has properly implemented the Data Protection Directive via the Data Protection Act 1998 and other relevant provisions of UK law," it said.

The Commission sent the UK Government its first letter on the issue in 2004, setting out the problems with the Data Protection Act. Until now, those objections have remained secret. The letter threatened proceedings before the European Court of Justice if negotiations with the UK stalled."

Saturday, September 15, 2007

Data Protection Developments: Indian IT Act to be amended

(via NewIndPress.com)

"NEW DELHI: In its effort to face the upcoming tough challenges in cyber crime, India is all set to bring comprehensive amendments in Information Technology Act 2000.


IT and Communications Minister A Raja on Friday announced that the proposed amendments would address a number of serious concerns such as data protection, data theft, e-commerce frauds, child pornography, identity theft, privacy issues and immunity to intermediaries among others.

An official indicated that the proposed changes would include stiffer quantum of punishment, especially in areas such as child pornography, ID theft and privacy issues.

The proposed changes in the Act are based on our experience during the last seven years and inputs received from various international bodies, Raja said at the concluding day of the 7th Interpol Cyber Crime conference held in New Delhi from September 12 to 14.

Before placing the amended Act in public domain for comments, the IT Ministry is holding discussions with various stakeholders to fine tune the amendments.

Discussions are being held with the stakeholders, including private companies, CBI and other investigative agencies, he said."

See:


Friday, September 14, 2007

Google and Internet Privacy

FT reports the following story:

"Google will on Friday attempt to take the high ground in the debate over internet privacy, by calling for new international laws to be set up to protect personal information online. An International body such as the United Nations or the OECD should draw up new guidelines, Peter Fleischer, global privacy counsel for Google will tell Unesco members at a conference in Strasbourg on Friday. Google has become a focal point for a debate on internet privacy since European Union data protection bodies earlier this year questioned the length of time the company kept data on individuals using its search engine. Google was also criticised by Privacy International, the human rights group, as being potentially “hostile” to privacy. Since then, Google has taken steps to improve its image. It agreed to limit the time it keeps search data to just 18 months, and has started working with Privacy International in order to be removed from the organisation’s blacklist. Going further on the offensive, Mr Fleischer on Friday will say he believes existing internet privacy rules are out of date. The OECD’s guidelines on privacy and personal data, for example, were set up in 1980, well before the invention of the internet, and even the European Commission directive on privacy dates back to 1995, when the internet was still in its infancy. “Privacy laws have not kept up with the reality of the internet and technology, where we have vast amounts of information and every time a credit card is used online, the data on it can move across six or seven countries in a matter of minutes,” Mr Fleischer told the Financial Times ahead of his speech. Eric Schmidt, chief executive of Google, is expected to add his voice to the campaign over the next few weeks. Google is proposing that the privacy framework adopted in Asia by ministers at the Asia-Pacific Economic Co-operation conference in 2004 could be used as a basis of a broader, international agreement. The Apec agreement is relatively loose, setting out general principles, such as notifying individuals when their data is collected, but leaving enforcement up to individual countries. Simon Davies, director of Privacy International, said: “There seems to be a perceptible shift within the company. Over the past few months it seems that senior people have understood that privacy issues can affect the value of the company.” Mr Davies said the steps Google was taking were “symbolically huge and significant, but whether they have any meaning beyond that, no one can yet tell”. Analysts say it is crucial for Google to maintain an impeccable reputation on privacy, or it may begin losing users. A number of smaller search engine companies are already using the recent concerns over Google’s data policies as an opportunity to poach users."
See also:

Thursday, September 13, 2007

Surveillance and Society Conference 2008

InVisibilities: The Politics, Practice and Experience of Surveillance in Everyday Life

A two-day international conference hosted by the Centre for Criminological Research, University of Sheffield in association with the Surveillance Studies Network

Wednesday 2nd April - Thurs
day 3rd April 2008

Introduction

While many of the world’s nations are becoming surveillance societies, the nature of life with surveillance in those societies is far from homogeneous, and is not widely researched or theorised. This conference focuses on the lived realities of surveillance and is keen to encourage empirical studies which document its everyday experience.

By its very nature surveillance makes populations visible, and differentiates between their members; surveillance itself features varied techniques, intensities and foci. Whether as workers, consumers, children, patients, criminals, web surfers or travellers we are made visible in different ways, through different technologies and administrative regimes. Visibility is not always total, unproductive or oppressive – visibility is necessarily partial. For some it is actively embraced: lives are lived in visibility.

Nevertheless, widespread ambivalence towards surveillance has been noted in academic, policy and media circles. As surveillance confers benefits and incurs costs on individuals, personal information economies of surveillance emerge. In building personal strategies which involve surveillance practices, invisibilities are negotiated to mediate, limit and exploit exposure to surveillance. How individuals, groups, organizations and societies negotiate, experience, resist, comply with, and enjoy surveillance are critical empirical questions, which appeal to surveillance scholars from a wide range of social science disciplines.

Key themes to include:

• Experiencing Surveillance and Visibility
• Participatory and Voluntary Surveillance
• Theorising (in)visibility
• Histories of Surveillance and Visibility
• Surveillance of the Other - Visibility and Difference
• Representations of Surveillance in Film/Art/Literature/Media
• State Surveillance and Identification
• Surveillance, visibility and the welfare state
• Surveillance and consumer visibility
• The transparent body
• Electronic visibilities
• (In)visibility and labour
• Negotiating (in)visibility
• Researching (in)visibility
• Spatial visibilities
• Surveillance futures

Submission of Abstracts and Expressions of Interest

If you would like to give a paper please submit your abstract to Lisa Burns at the University of Sheffield by January 31st 2008. Abstracts should be no longer than 500 words. Your abstract should also contain the following information.

• Name
• Country of residence
• Institutional affiliation
• Institutional address
• Telephone number
• Email address


On the same theme about surveillance, Queen's University, Kingston has been working on the Surveillance Project.

Monday, September 10, 2007

Surveillance Seminar

Researchers working on surveillance:

Seminar: 'Surveillance in Scotland: Current Practices and Future Prospects'

The University of Edinburgh's Public Policy Network and the Scottish Regional Office of the (UK) Information Commissioner's Office (ICO) are pleased to invite you to a one-day seminar on Friday, 5th October 2007 on the nature, extent and diversity of surveillance practices, systems and technologies in the private and public sectors, including the collection and sharing of personal information and databases, as well as video surveillance, DNA and biometric identification systems, and many other forms of monitoring people's movement, habits and behaviour.

Surveillance has become an important and controversial public issue as the needs of commerce and government press forward to use citizens' and customers' personal information for a host of purposes, including marketing, banking, law enforcement, counter-terrorism, and the delivery of public services. Questions of privacy and civil liberties are implicated in these developments. The aim of the seminar is to inform and to encourage a wider public debate about these issues, especially as they affect daily life in Scotland now and in the future.

Drawing upon the widely acclaimed report, 'A Surveillance Society', specially commissioned from the Surveillance Studies Network (SSN) by the Information Commissioner's Office (available at http://www.ico.gov.uk/about_us/news_and_views/current_topics/Surveillance_society_report.aspx), the seminar will feature presentations by authors of the SSN report and the ICO, as well as by representatives of Scottish Government, ICO, the police, and the worlds of industry, politics and human rights protection. The seminar will be held at the University's Moray House College of Education, Holyrood Campus, from 9. 30 am to 4 pm on the 5th October. There is no charge for attendance at the seminar, which will include a buffet lunch. Details of the venue and programme will be circulated by e-mail to those attending.

Attendance will be limited, so to secure your place please RSVP to the Information Commissioner's Office at Scotland@ico.gsi.gov.uk before the 24th September.

Professor Charles Raab (PPN, University of Edinburgh) Dr. Ken Macdonald (ICO)

Wednesday, September 05, 2007

UK National DNA Database

A national debate is emerging on the discussion about UK National DNA Databases: Times reports:

"A senior judge has said the entire UK population and every visitor to the country should be on the national DNA database.

Lord Justice Sedley, one of the most experienced Appeal Court judges in England, said that an extended database would aid crime prevention and the current database was unfair and inconsistent.

He told BBC News: “Where we are at the moment is indefensible. We have a situation where if you happen to have been in the hands of the police, then your DNA is on permanent record. If you haven’t, it isn’t... that’s broadly the picture.”

Sir Stephen said disproportionate numbers of ethnic minorities get on to the database where there is ethnic profiling going on.

He added: “It also means that a great many people who are walking the streets, and whose DNA would show them guilty of crimes, go free”.

There are currently four million profiles held on the national DNA database.

Critics say those who commit certain offences should have their details removed after a set period.

The DNA database - which is 12 years old - grows by 30,000 samples a month taken from suspects or recovered from crime scenes. It is the largest in the world.

The data of everyone arrested for a recordable offence - all but the most minor offences - remains on the system regardless of their age, the seriousness of their alleged offence, and whether or not they were prosecuted.

It includes some 24,000 samples from young people between 10 and 17 years old, who were arrested but never convicted.

Sir Stephen said reducing the database would be a mistake. He knew of cases where a serious offender who had escaped conviction had ultimately been brought to justice by DNA evidence that may have been otherwise destroyed.

He said the only option was to expand the database to cover the whole population and all those who visit the UK.

There are four million DNA samples on the database

Professor Stephen Bain, a member of the national DNA database strategy board, warned expansion would be expensive and make mistakes more likely.

"The DNA genie can't be put back in the bottle," he said.

"If the information about you is exposed due to illegal or perhaps even legalised use of the
database, in a way that is not currently anticipated, then it's a very difficult situation."

Aside from the practicalities of a national DNA database, inevitably, there will be data protection/privacy/human rights implications on this. Irrespective of one's views on this (at this stage):

See also:

Monday, September 03, 2007

Privacy Market?

Wired has published this story concerning the privacy market. Putting on my "privacy hat" the idea of a "Privacy Market" is disagreeable - this is particularly the case when personal information is viewed as a commodity - than a human right as such (see Art. 1 of the Data Protection Directive 95/46/EC). This is not to imply that privacy is absolute (as can be seen in the exemptions under the European Data Protection Directive and the UK Data Protection Act 1998 and instances where we need to give our personal details), but once we start thinking of an individual's identity as something that can be traded commercially (property right), then this is a slippery slope into conceding that personal information is nothing more than monetary value.
Wired:

"The Privacy Market Has Many Sellers, but Few Buyers"


By Dan Tynan 09.03.07 2:00 AM

Privacy is fast becoming the trendy concept in online marketing. An increasing number of companies are flaunting the steps they've taken to protect the privacy of their customers. But studies suggest consumers won't pay even 25 cents to protect their data. In one week in July, Ask.com unveiled AskEraser, a tool that will allow users to obliterate their search histories; Microsoft announced enhanced privacy controls for its Windows Live service; and Google and Yahoo shrank the amount of time they retained IP addresses and search logs, reducing the ability of government agencies to subpoena such data. Startups are aiming to carve out a piece of the privacy market. ReputationDefender, which allows individuals to manage what people say about them online, launched the beta version of a new subscription service on Sep. 1. Its service, called MyPrivacy, lets users control how their personal data is brokered across the web (the service was announced last fall but is only now publicly available). Suddenly it seems that "privacy is the new black," as Duncan Riley wrote at TechCrunch. For $5 a month, MyPrivacy subscribers can locate their records in people-search directories, such as Yahoo People Search, 411.com, WhitePages.com, Yellowbook.com and Netscape White Pages, and click a button to remove their listing. As long as you keep paying, the service will keep you unlisted when these information brokers refresh their directories. MyPrivacy will feature at least 10 major consumer databases at launch and expects to have 75 such information brokers signed on by year end.

See also:

Tuesday, August 28, 2007

Latest issue of Data Protection Law and Policy

The latest Issue of Data Protection Law and Policy is available:

"EDITORIAL: PREVENTING HARM
In the UK, there is a growing consensus that the Information Commissioner's Office (ICO) is toughening up. It all started with the rogue traders who passed themselves as official registrars and demanded a few hundred pounds a shot for registration. That did not go down well in Wilmslow, given that their modest registration fees make up the bulk of their own funding. Then, a handful of aggressive marketers clogging small businesses' fax machines got to see the darker side of a normally peaceful regulator. But it is the good old Principle 7 - or the lack of compliance with it - that has kept the enforcement arm of the UK data protection authority especially busy in recent times.


OPINION: PNR AGREEMENT: SETTING A BAD PRECEDENT The recently enacted EU-US agreement on the transfer of Passenger Name Records (PNR) data is intended to provide a legal framework facilitating the transfer of this data whilst safeguarding individual privacy. In this article, Sophie in't Veld, Member of the European Parliament (MEP) for the Dutch social-liberal party 'D66', sets out why the agreement is fundamentally flawed, sets a bad precedent for future agreements and represents a defeat in the fight against terrorism.

PERSONAL DATA: ARTICLE 29 WORKING PARTY OPINION: 'PERSONAL DATA'

The Article 29 Data Protection Working Party's opinion on the concept of personal data, issued 20 June, interpreted the four 'building blocks' in the Data Protection Directive that determine what constitutes personal data.
Siobhan McManus of Bird & Bird explains the Working Party's findings, discussing the implications of its 'wide' interpretation of what constitutes personal data, in contrast to the 'narrow' UK position.

NETHERLANDS: DISMISSAL UNDER EMPLOYER TELEPHONE TAPPING A recent ruling by the Breda Subdistrict Court, which permitted the playing of a surreptitious recording of a telephone conversation between an employer and his employee in dismissal proceedings, has contradicted recent human rights case law concerning the privacy of employees in the workplace. Nicole Wolters Ruckert of the Dutch law firm, Kennedy Van der Laan examines the judgment and its implications for employee privacy.

ITALY: THE 'PEPPERMINT' CASE: PRIVACY V COPYRIGHT UPDATE An ongoing case in Italy concerning the desire of a German record company to obtain the identities of internet users from ISPS, over the alleged posting and downloading of copyright infringing music files on P2P networks, has attracted the attention of the Italian Privacy Commissioner over allegations of illicit monitoring of internet user activity. In this article, Daniela De Pasquale, a partner in La Scala & Associati in Milan, sets out current developments in this case and in this area at EU level.

IDENTITY THEFT: LIMITING CLASS ACTION LIABILITY FOR BUSINESSES As concern surrounding identity theft in the United States continues, financial organisations are threatened by lawsuits over failures to ensure sufficient levels of corporate security, particularly in the form of class-action lawsuits where customers are affected on a nationwide basis. R. Bruce Allensworth, Andrew C. Glass, Ryan M. Tosi and David D. Christensen of K&L Gates' Boston office report on a recent US district court case where they successfully represented the defendants and which may limit class action liability for organisations that electronically store consumer personal information."

Saturday, August 25, 2007

Standing the test of time!

Postman's book, which some have read, and is highly recommended, laments the shift of public discourse from typography to television. This made me think about whether the shift is changing with the widespread use of the internet through Web 2.0, blogs, podcasts and so forth:

"In this book, Neil Postman, Professor of Communication Arts and Sciences at New York University argues eloquently and convincingly that television is transforming our culture into one vast arena for show business in which all public affairs - politics, religion, news, education, journalism, commerce - have been turned into a form of entertainment. Amusing ourselves to death is an urgent plea for us to question what is happening before it is too late."

The book not only succinctly examines the communication medium (through television), but discusses the change from a typographic America (see chapter 3) to a "Now...This" mindset.

"This is Neil Postman's contention. Television, he argues, has taken the place of the printed word as the centre of our culture, and in so doing has trivialised the onnce serious and coherent discussion of all public affairs. Even our political and religious leaders today depend more on camera angles and showmanship than on reason and rhetoric. Using examples from America's past and present history, he makes a convincing, often wittily argued case that we are moving not towards Orwell's vision of the future but towards Aldous Huxley's Brave New World in which people become addicted to the technologies that take away their capacity to think: their critical faculties are destroyed and their sense of history is lost."

Although Postman has written a book on technology, I am more inclined to think that what is happening is another culture revolution (shift from television to the electronic medium) through the use of the internet (blogs, podcasts, videoblogs etc.) has taken. Would Postman have envisaged this? I don't know, but I leave you with a few thoughts from his book:

"Any yet there is reason to suppose that the situation is not hopeless. Educators are not unaware of the effects of television on their students. Stimulated by the arrival of the computer they discuss it a great deal - which is to say, they have become somewhat "media conscious". It is true enough that much of their conciousness centres on the question, How can we use television (or the computer, or word processor) to control education? They have not yet go to the question, How can we use education to control television (or the computer, or word processor)? But our reach for solutions ought to exceed our present grasp, or what's our dreaming for?...

What I suggest here as a solution is what Aldous Huxley suggested, as well. And I can do no better than he. He believed what H.G. Wells that we are in a race between education and disaster, and he wrote continuously about the necessity of our understanding the politics and epistemology of media. For the end, he was trying to tell us that what afflicted the people in Brave New World was not that they were laughing instead of thinking, but that they did not know what they were laughing about and why they had stopped thinking."

I would hope that the internet revolution (blogs, podcasts etc.) not only challenges the mindsets of teachers and students to be critically aware, but to evaluate the things that we read - the problem that I find is usually an information overload (not merely from the television medium, but also from the internet etc.) - evaluating the sources (whether television, internet, radio to name a few examples), sifting through the main points will be the key.

Friday, August 24, 2007

Google Maps and Privacy

According to the latest post from Out-Law news, google maps are changing its privacy policy on its street view. This follows concerns about photographs of streets showing people's faces, car number plates and views of their houses. However, the subject of photographs and maps is particularly relevant when considering this as "personal data" under the Data Protection Directive - as I have noted in previous blog posts, this concept can be quite broad. However, one should note that protection personal information is not absolute and a proportionate response will need to be taken. A further point to add is that Art. 9 of the Data Protection Directive 95/46/EC on artistic, literary and journalistic purposes may still apply (consider the national data protection laws of each Member State). I have written on this in my thesis (still yet to be published), but for those researching this area, the Commission's report on the transposition of the Data Protection Directive 95/46/EC is a good starting point.

Thursday, August 23, 2007

Six thinking hats!

I have been reading a book titled "Six thinking hats", written by Edward De Bono, which I would recommend. It is a technique that looks at important decisions from different perspectives.

Here is an extract:

"How to Use the Tool:

You can use the Six Thinking Hats technique in meetings or on your own. In meetings it has the benefit of blocking the confrontations that happen when people with different thinking styles discuss the same problem.Each 'Thinking Hat' is a different style of thinking. These are explained below:


White Hat:
With this thinking hat you focus on the data available. Look at the information you have, and see what you can learn from it. Look for gaps in your knowledge, and either try to fill them or take account of them.This is where you analyze past trends, and try to extrapolate from historical data.


Red Hat:'Wearing' the red hat, you look at problems using intuition, gut reaction, and emotion. Also try to think how other people will react emotionally. Try to understand the responses of people who do not fully know your reasoning.


Black Hat:Using black hat thinking, look at all the bad points of the decision. Look at it cautiously and defensively. Try to see why it might not work. This is important because it highlights the weak points in a plan. It allows you to eliminate them, alter them, or prepare contingency plans to counter them.


Black Hat thinking helps to make your plans 'tougher' and more resilient. It can also help you to spot fatal flaws and risks before you embark on a course of action. Black Hat thinking is one of the real benefits of this technique, as many successful people get so used to thinking positively that often they cannot see problems in advance. This leaves them under-prepared for difficulties.

· Yellow Hat:The yellow hat helps you to think positively. It is the optimistic viewpoint that helps you to see all the benefits of the decision and the value in it. Yellow Hat thinking helps you to keep going when everything looks gloomy and difficult.


Green Hat:The Green Hat stands for creativity. This is where you can develop creative solutions to a problem. It is a freewheeling way of thinking, in which there is little criticism of ideas. A whole range of creativity tools can help you here.


Blue Hat:The Blue Hat stands for process control. This is the hat worn by people chairing meetings. When running into difficulties because ideas are running dry, they may direct activity into Green Hat thinking. When contingency plans are needed, they will ask for Black Hat thinking, etc.


A variant of this technique is to look at problems from the point of view of different professionals (e.g. doctors, architects, sales directors, etc.) or different customers."



Useful for conferences and seminars - I wonder what hat I'll be wearing, when I am teaching my students! Next book on my list - lateral thinking!

Wednesday, August 22, 2007

YouTube, Private Exemptions and Lindqvist all in one!

Out-Law has recently posted an interesting case, which has YouTube, Private exemptions (under s 36 of the Data Protection Act 1998) and Lindqvist issues all wrapped up in one case:



"The woman at the centre of a battle with social services over the future of her unborn baby will not be able to claim an exemption from the UK's Data Protection Act, a legal expert has warned.
Vanessa Brookes of Calderdale, Halifax was recently told by a social worker that the local authority would apply for an interim court order to take her baby from her and place it with foster parents on birth. Worried about the outcome of the meeting, Brookes tape recorded it. The recording was published on video sharing website YouTube. Local authority Calderdale Council has objected to that publication and has said that it will take legal action to have it taken down because, it says, it breaches the Data Protection Act (DPA). "The Council believes that the YouTube recording breaches the Data Protection Act, since the recording was made without the knowledge or consent of our member of staff," said a statement from Calderdale Council. "We have concerns that, because the case involves court proceedings, it could prejudice child protection and safeguarding outcomes." Dr Chris Pounder, a data protection specialist at Pinsent Masons, the law firm behind OUT-LAW.COM, said that the DPA has an exemption in section 36 that applies when recordings like this are used for domestic purposes. This exemption excludes all of the data protection principles and rights, and applies, for example, when parents take their video cameras to record their children's performance in a school play. But, he said, as soon as the recording was published online it is ineligible for the 'domestic purposes' exemption because of the European Court of Justice (ECJ) ruling in a case involving Mrs Bodil Lindqvist in Sweden.
Lindqvist was a church activist who published personal details of parishioners on a website as part of a computing project. She said that publishing details should not breach the EU's Data Protection Directive, but the ECJ disagreed. The ECJ stated: "That [domestic purpose] exception must therefore be interpreted as relating only to activities which are carried out in the course of private or family life of individuals, which is clearly not the case with the processing of personal data consisting in publication on the internet so that those data are made accessible to an indefinite number of people." The Lindqvist judgment means that the section 36 exemption does not apply in the YouTube posting and the personal data is fully subject to the DPA and the enforcement powers of the Information Commissioner, said Pounder. He added "The exemption is also lost, even if I put up online information about myself. However, in this case, there are very few data protection obligations as there is my consent. The problems arise when I put someone else's personal data on these web-sites in the absence of consent" he said."


I have already written an article some time back with a colleague looking at publishing personal information on websites for private purposes and social networking in the context of data protection, so this case appears to be timely. The article is due to be published in the forthcoming John Marshall Journal of Computer and Information Law, but the working paper can be found here. Again, since the Lindqvist case, it is unlikely that publication of personal information on the internet would fall within the exemptions for private purposes (though, see the different EU Member States' approach, which I describe in the article). Comments welcome!

Tuesday, August 21, 2007

A few developments

Just a few developments to note on data protection in the UK:

1) The draft Data Retention (EC Directive) Regulations 2007 will take effect on 1st October 2007. These regulations implement the Data Retentions Directive 2006/24/EC and will apply to public electronic communications providers. Data will be retained for a period of 12 months from the date of communication (Regulation 4(2)). The types of data to be retained are telephone numbers and mobile numbers (Regulation 5(1) and 5(2)). The regulations do not apply to data from internet access, e-mail and internet telephony (VoIP). The Information Commissioner will monitor the application of these regulations (Regulation 8). A comparison of the other European Member States' Laws implementing the Data Retentions Directive 2006/24/EC can be found here.

2) On 24 October 2007, the transitional exemptions under the UK Data Protection Act 1998 will end. This means that structured manual filing systems containing personal records will be covered under the Data Protection Act, but would apply to data that was held before October 1998. The Durant case will be relevant, which took the view that most manual file files are not relevant filing systems.

3) Draft Freedom of Information and Data Protection (Appropriate Limit and Fees) Regulations 2007 - The Government has drafted amended freedom of information (FOI) fees regulations which will allow public authorities to take into account more comprehensively the work involved in dealing with an FOI request. The consultation was completed in June, but further details can be found here.

Saturday, August 18, 2007

MInggl - Persona Centric

This is an interesting website, Minggl, which enables users who have online profiles such as Facebook and MySpace to limit access to their profiles. Here is some information on their website:

"Minggl is a "Persona Centric" toolbar and the first service to put you in charge on popular social networking sites (MySpace, Facebook, etc). "Persona Centric" means that what you see, and what you show, can vary, based on the current social site, and based on who you are and who's profile you are viewing.

Privacy control---hide whole sections of your MySpace profile

If you have BLOGs, Photos or viewpoints that you don't want to share with the whole Internet, Minggl will let you password (or attribute) protect this content (by adding Minggl notes to your profile).
  • password protect sections of your MySpace or Facebook profile---other sites coming soon
  • minors no longer need fear that the WRONG people are seeing their personal details
  • bosses and recruiters can’t see your political or religious views
  • share details of your life with people you trust..…not the whole Internet
  • display different profile views for the public, your friends, and the people you want to date"
Mingll is currently by invitation only, but already a few have started to sign up. A video tutorial can be found here. Will it solve some of the privacy concerns involving social networking? Maybe, but putting the user in control is a starting point! Worth trying this out.

Thursday, August 16, 2007

Portolano case

This is an interesting case as it concerns ISPs, filesharing and data protection. Here are the facts (from Mondaq):

"On April 2007, Peppermint Jam Records GmbH (hereinafter "Peppermint"), a German music label, sent out 3,636 notices of copyright infringements to alleged Italian file-sharers informing them that they have been found guilty of uploading copyrighted songs.

The notices, sent by an Italian Law Firm, requested the 3,636 Italian swappers to stop persisting in their infringements of copyright laws and requested them to immediately remove from their PCs all songs belonging to the Peppermint label. In particular, each user has been specifically charged of sharing only a single song.

The notices also invited users to wire transfer EUR300.00 to the Italian Law Firm’s bank account within May 14, 2007, if they wanted to avoid a criminal and/or a civil lawsuit brought against them. The amount represented a symbolic compensation for damages caused by sharing that song, including legal and investigation expenses. Attached to the notices Italian users also received a draft settlement agreement, to be signed and returned to the Italian Law Firm in case of acceptance.

As mentioned above, the notices stated that the acceptance of the draft settlement agreement as well as payment of the requested amount, would avoid users from being subject to a criminal judgement for copyright infringements. This statement, however, is not exactly true. In fact, Italian file sharers could be subject to a criminal proceeding although they have paid the above amount and signed the settlement agreement. This is because, under Italian law, the crime of copyright infringement is prosecuted ex officio....

Italian Supreme Court‘s Recent Decision on File Sharing Practices

In the Peppermint’s case, the Court did not take any positions on the legality of file sharing practices.

According to a recent Italian Suprem Court’s decision, however, the copyright infringement deriving from file sharing – if not aimed at making profit - is not punishable.

The decision of the Italian’s Supreme Court, dated January 9, 2007, no. 149, concerned a specific case happened on 1999, when two Italian students made some copyrighted materials available for download on a University bulletin board. The students, according to the Supreme Court’s view, were not punished as their behavior was not aimed at making profit, and, therefore, it was not criminally punishable but it constituted only a civil offense that could be pursued for alleged damages.

Data Protection Issues Involved in the Case

In the Peppermint’s case the Court of Rome ordered to the ISP to disclose its clients’ personal data. This has triggered many criticisms as this disclosure was deemed to be an infringement of Italian Data Protection Law.

What has been criticized, however, is not the fact that the Court ordered the ISP to provide such data, as Italian Data Protection Law expressly allows that personJustify Fullal data disclosure in a judicial proceeding. What has triggered many discussions in Italy is whether Peppermint’s and Logistep’s activities aimed at collecting information of users were carried out infringing Italian Data Protection Law.

As to Peppermint’s activities, regardless the fact that the company has its registered offices in Switzerland, Italian Data Protection law should apply according to Section 5 of the Legislative Decree no. 196 of 30 June 2003, (hereinafter "Italian Data Protection Code" or " the Code"), under which the Code applies (i), to the processing performed by any entity established in Italy, including when data are held abroad and (ii) to the processing performed by an entity located in the territory of a non EU country (such as Switzerland) where said entity makes use, in connection to the processing, of equipment situated in the Italy.

Many commentators said that, in the case at hand, the Code applies to processing carried out in Italy (a) at the time personal data were collected from users’ PCs located in Italy (although this is an arguable position) (b) when users’ personal data were transferred to the Italian Law Firm, and were processed for the purposes of sending them the notices on the basis of the data collected from the Italian ISP.

As to Logistep’s activities, some argued that Section 122 of the Code should apply, under which an electronic communication network shall not be used to gain access to information stored in the terminal equipment of a subscriber or user or to store information or monitor operations performed by any user. This is also an arguable position, however, as users’ information are normally processed by P2P platforms with such users’ consent or, in any event, upon request of such users.

Furthermore, some commentators pointed out that Section 37, letter d) of the Code should also apply, under which the data controller shall notify to the Data Protection Authority the processing of personal data concerning data processed with the help of electronic means aimed at profiling the data subject or monitoring use of electronic communications services. This is also arguable, as Logistep’s activity was only aimed at collecting the IP addresses of Italian users: a stand alone IP address is not able to identify or profile users."

Source: http://www.mondaq.com/article.asp?articleid=50310

Although the Italian Data Protection Authority is investigating whether the Data Protection Code has been breached when collecting IP addresses, there are a number of cases that are beginning to emerge that deals with filesharing, IP addresses and data protection:Finally, we should not forget the Art. 29 Working Party's recent opinion on Personal data.


Friday, August 10, 2007

HL Report into Personal Internet Security published

The House of Lords Science and Technology Committee has published its report on Personal Internet Security. Here is the abstract:

"The Internet is a powerful force for good: within 20 years it has expanded from almost nothing to a key component of critical national infrastructure and a driver of innovation and economic growth. It facilitates the spread of information, news and culture. It underpins communications and social networks across the world. A return to a world without the Internet is now hardly conceivable. But the Internet is now increasingly the playground of criminals. Where a decade ago the public perception of the e-criminal was of a lonely hacker searching for attention, today’s “bad guys” belong to organised crime groups, are highly skilful, specialised, and focused on profit. They want to stay invisible, and so far they have largely succeeded. While the incidence and cost of e-crime are known to be huge, no accurate data exist. Underpinning the success of the Internet is the confidence of hundreds of millions of individual users across the globe. But there is a growing perception, fuelled by media reports, that the Internet is insecure and unsafe. When this is set against the rate of change and innovation, and the difficulty of keeping pace with the latest technology, the risk to public confidence is clear. The Government have insisted in evidence to this inquiry that the responsibility for personal Internet security ultimately rests with the individual. This is no longer realistic, and compounds the perception that the Internet is a lawless “wild west”. It is clear to us that many organisations with a stake in the Internet could do more to promote personal Internet security: the manufacturers of hardware and software; retailers; Internet Service Providers; businesses, such as banks, that operate online; the police and the criminal justice system. We believe as a general principle that well-targeted incentives are more likely to yield results in such a dynamic industry than formal regulation. However, if incentives are to be effective, they may in some cases need to be backed up by the possibility of direct regulation. Also, there are some areas, such as policing, where direct Government action is needed. So Government leadership across the board is required. Our recommendations urge the Government, through a flexible mix of incentives, regulation, and direct investment, to galvanise the key stakeholders. The threat to the Internet is clear, but it is still manageable. Now is the time to act, both domestically, and internationally, through the European Union and through international organisations and partnerships."

This is quite a lengthy report, but see also the recommendations (in the context of data security breaches):

"Conclusions and Recommendations

5.53. The steps currently being taken by many businesses trading over the Internet to protect their customer’s personal information are inadequate. The refusal of the financial services sector in particular to accept responsibility for the security of personal information is disturbing, and is compounded by apparent indifference at Government level. Governments and legislators are not in position to prescribe the security precautions that should be taken; however, they do have a responsibility to ensure that the right incentives are in place to persuade businesses to take the necessary steps to act proportionately to protect personal data.

5.54. We therefore recommend that the Government introduce legislation, consistent with the principles enshrined in common law and, with regard to cheques, in the Bills of Exchange Act 1882, to establish the principle that banks should be held liable for losses incurred as a result of electronic fraud.

5.55. We further believe that a data security breach notification law would be among the most important advances that the United Kingdom could make in promoting personal Internet security. We recommend that the Government, without waiting for action at European Commission level, accept the principle of such a law, and begin consultation on its scope as a matter of urgency.

5.56. We recommend that a data security breach notification law should incorporate the following key elements:

• Workable definitions of data security breaches, covering both a threshold for the sensitivity of the data lost, and criteria for theaccessibility of that data;
• A mandatory and uniform central reporting system;
• Clear rules on form and content of notification letters, which muststate clearly the nature of the breach and provide advice on the steps that individuals should take to deal with it.

5.57. We further recommend that the Government examine as a matter of urgency the effectiveness of the Information Commissioner’s Office in enforcing good standards of data protection across the business community. The Commissioner is currently handicapped in his work by lack of resources; a cumbersome “two strike” enforcement process; and inadequate penalties upon conviction. The Government have expressed readiness to address the question of penalties for one type of offence; we recommend that they reconsider the tariffs for the whole of the data protection regime, while also addressing resources and enforcement procedures as well. These should include the power to conduct random audits of the security measures in place in businesses and other organisations holding personal data."

See:

Thursday, August 09, 2007

Diminishing Privacy: Search Engines

With the number of people subscribing to social networking websites such as Facebook and Myspace, it appears that the phenomenom does not stop here. The Beeb has recently published a story indicating the growth of some personal search engines, (Wink.com, Spock.com etc) which would profile individuals and make it easily accessible to anybody:

"The niche search engines are making use of the information that is already out there about us on the web to cross reference details so they can index and build up searchable profiles. Zoominfo.com, which came online in 2001, was one of the first sites to do this. It began life as a subscription service where it gathered profile information from the web in response to requests from recruiters or salespeople, but in 2005 it added a public service, enabling free company and personal searches. Russell Glass, the firm's vice president of products and marketing, said: "Users can come in and search for a person's name, and we essentially crawl somewhere between one billion and two billion pages to gather, organise and summarise a virtual resume." It provides a detailed and rich look at who a person is from a professional perspective." The business-orientated directory contains more than 37 million personal profiles and 3.5 million companies profiles pulled from across the web. Other search engines are aiming for a different market. Some, like Wink.com, a US company that launched in 2006, are using the ever-growing swells of personal information found on social networking sites such as MySpace, Bebo and Friendster in addition to other web sources such as Wikipedia to create public profiles. Michael Tanne, founder and CEO of Wink, said: "The Wink service is where people find people.
"It's targeted at anyone who is trying to find someone else online - old friends, new friends, dates, people they heard or read about, job searches, business leads, celebs etc." Mr Tanne said users could search more than 200 million profiles but added that the company had ambitions to eventually index every person online."

This made me think about the current Data Protection Directive 95/46/EC. Surely, by aggregating personal information from various sources without obtaining individual's consent, would lend itself to a claim that it may fall foul of the Art. 11:

Article 11 Information where the data have not been obtained from the data subject

1. Where the data have not been obtained from the data subject, Member States shall provide that the controller or his representative must at the time of undertaking the recording of personal data or if a disclosure to a third party is envisaged, no later than the time when the data are first disclosed provide the data subject with at least the following information, except where he already has it:

(a) the identity of the controller and of his representative, if any;

(b) the purposes of the processing;

(c) any further information such as

    • the categories of data concerned,
    • the recipients or categories of recipients,
    • the existence of the right of access to and the right to rectify the data concerning him

in so far as such further information is necessary, having regard to the specific circumstances in which the data are processed, to guarantee fair processing in respect of the data subject.

Furthermore, Art. 14 of the Data Protection Directive 95/46/EC (and corresponding national legislation) provides the opportunity for individuals to object to the processing of their personal data.

Certainly a good starting point would be for Data Protection Authorities to start issuing guidelines on social networking and the data protection implications. The Ontario Privacy Commissioner has already issued some guidelines titled "When Privacy gets out of line" (pdf), but more still needs to be done. Furthermore, social responsibility will be the key - if individuals voluntarily put their personal information online, then they are also responsible for the information they share with other individuals. The three Ps, which the Ontario Privacy Commissioners warned students to beware of are quite memorable to remember when going on any social networking website: professors, prospective employers and predators. For such examples, see the recent example of Oxford Dons and Facebook and here.

Some interesting reading: