Tuesday, July 08, 2008

Revisiting the DPA 1998

This has been widely reported:

Addressing the annual conference on Privacy Laws and Business in Cambridge, UK's Information Commissioner, Richard Thomas, has emphasised the need to bringing out necessary changes in European Data Protection Laws.

The Information Commissioner has stated that the existing laws are outdated and excessively bureaucratic, and these laws aren't in line with the modern internet age.

The Information Commissioner's Office (ICO) has commissioned RAND Europe, a research group, to assessing the current laws, and to come up with the key areas of improvement in existing structure.

Thomas also added that the research will help in designing more straightforward and effective laws, without putting extra burden on enterprises.

A representative from RAND has mentioned that the assessment process will involve small interviews and workshops, with a significant participation of small organizations. The group is expected to publish its report in April 2009.

However, Thomas admitted that the reform process would be slow, and the proposed changes may not be applicable till five years down the line, but the start can't be delayed any further.

Whilst these developments are being considered, there are several issues that will need to be revisited not least:

1) Scope of "Personal data" as laid down under the European Data Protection Directive 95/46/EC

2) Distinction drawn between sensitive and non-sensitive data as applied online under Art. 8.1 of the Directive.

3) Onset of social networking (user-generated content)

4) The ease with which information can be easily transferred (Art. 25 of the Data Protection Directive 95/46/EC) will need to be revisited.

5) Scope of the exemptions laid down under Art. 9 of the Data Protection Directive 95/46/EC - processing of personal data for the purposes of artistic, literary and journalistic purposes.

On a separate note, however, identity principles ("identity commons") has been discussed to a greater extent:

"Id Commons is defined in Wiki-Commons as:

The following Purpose and Principles are the "core DNA" of Identity Commons as an organization. We use this term since all Identity Commons working groups agree to inherit these, i.e., each one is accomplishing a specialization of this Purpose, and each one is operating in accordance with a specialization of these Principles. See Background and see our old Wiki for more about how we got here. Feel free to leave comments or make suggestions as to how this statement of Purpose and these Principles can be further improved.

The purpose of Identity Commons is to support, facilitate, and promote the creation of an open identity layer for the Internet, one that maximizes control, convenience, and privacy for the individual while encouraging the development of healthy, interoperable communities."

This could work alongside the current EU legal framework, but remains to be seen how effective this would be.


Monday, July 07, 2008

Google Street View

Having had to take a break from blogging, Google Street - views raises more unusual privacy issues (not least data protection). Out-Law has the latest press release:

A privacy pressure group has told Google that its Street View photography service will break the law. But the company says that its technical measures will safeguard people's privacy.

Street View allows users of Google's maps to view 360 degree photographs of streetscapes in towns and cities that have been catalogued by Google cameras. The company's distinctive cars with cameras attached were spotted on the streets of London for the first time last week.

Pressure group Privacy International wrote to Google's senior privacy counsel Jane Horvath last week to explain its reservations. "You may be aware that Privacy International has stated, both privately to Google legal staff and to the media, that we are concerned about a number of potential violations of national law that this technology may create," wrote Simon Davies of Privacy International.

Davies said that if Google did not satisfy him that it had taken great enough account of users' privacy he would complain about the service to the Information Commissioner's Office (ICO).

Google, though, has implemented blurring technology in order to protect the identities of people and vehicles pictured. The technology blurs faces and vehicle number plates allowing high quality images to contain indistinct people and number plates.

Horvath has written back to Davies explaining that the face and number plate blurring technology has been in place since May. Though she conceded that it is not perfect, she said that it does protect privacy.

Source: Out-Law news

Wednesday, July 02, 2008

Surveillance case

The ECtHR has recently ruled on an important case (58243/00) concerning surveillance laws and privacy. According to Liberty:

"In a significant judgement today, the European Court of Human Rights found that UK surveillance laws had lacked the necessary clarity and accountability to prevent abuses of power when used to intercept cross-border communications.The ECHR agreed with human rights group Liberty that surveillance law and practice must be tighter to protect individual privacy rights.

Alex Gask, Liberty’s Legal Officer who brought the case, said:

“The Court of Human Rights has rightly found that greater accessibility and accountability is required to ensure respect for the privacy of thousands of innocent people. While secret surveillance is a valuable tool, the mechanisms for intercepting our telephone calls and e-mails should be as open and accountable as possible, and should ensure proportionate use of very wide powers.”

The ECHR referred to German authorities as an example of best practice in surveillance techniques, in part, because they ensured that monitoring of communications is suited to each investigation and required bi-annual reviews of the need to store the materials.

Gareth Crossman, Liberty’s Policy Director and leading expert on privacy rights, said:

“This judgement highlights the wider problem of excessive surveillance undermining public trust. Whether it’s fishing expeditions of our overseas phone calls or local councils using targeted surveillance to check on school catchment areas, we need a prompt review of the broad powers in RIPA.”

In the judgement, the ECHR states that it, “does not consider that the domestic law at the relevant time indicated with sufficient clarity, so as to provide adequate protection against abuse of power, the scope or manner of exercise of the very wide discretion conferred on the State to intercept and examine external communications. In particular, it did not, as required by the Court’s case-law, set out in a form accessible to the public any indication of the procedure to be followed for selecting for examination, sharing, storing and destroying intercepted material. The interference with the applicants’ rights under Article 8 (the right to privacy) was not, therefore, “in accordance with the law.”

Mark Kelly, Director of the Irish Council for Civil Liberties, added that:

“The Court has found that the United Kingdom’s relatively sophisticated rules on data interception have failed to prevent unlawful interference with privacy rights. This has clear implications for many other Council of Europe member states, including Ireland. Our lax data interception regime will require a thorough overhaul in order to ensure that it meets the standards required by the European Court of Human Rights under Article 8.”

Thursday, June 26, 2008

Data Protection Developments

Having been bogged down with marking, finally had some time to catch-up with the latest data protection developments:

Profiling on the internet is back on the agenda: Out-Law has recently posted this press release on Electronic Commerce:

A new set of consumer contract laws to harmonise the rules that govern online selling across the EU will be proposed this autumn by the European Commission. The EU's consumer chief also promised fresh guidance on viral adverts and profiling technology.

Addressing a roundtable on digital issues in London on Friday, European Consumer Commissioner Meglena Kuneva said that while e-commerce is succeeding at national level, cross-border e-commerce is failing to keep pace. The European Commission believes that simpler and better-harmonised consumer laws will boost the sector.

The results of EU surveys among 26,000 consumers and 7,200 businesses were announced by Kuneva on Friday. They show that while a third of the EU's 490 million consumers have bought something online, only seven percent have bought from foreign suppliers. Of those with web access at home, 56% have bought online; but only 13% have made a cross-border purchase.

These figures underline how much work we still have to do to boost confidence in the online internal market," said Kuneva.

Probably more of interest is the discussion on privacy and in particular that of "targeted advertising.

Kuneva expressed concern about the targeting of adverts in what might be interpreted as a reference to recent controversy over Phorm, an advertising technology firm.

"If you watch tennis over the internet, you will be targeted with ads for tennis items. If you read about home improvement, chances are that you will receive ads for repair services and new furniture," she said. "But there are some concerns that the amounts of personal data collected over the internet without the awareness of users, let alone their consent, is getting too large and a bit out of control." [on this point, the UK ICO has published its opinion on Phorm technology - consent of users will be required under Regulation 7 of the PECR)

"Currently many websites offer to click for 'enhanced services'. Is this an informed consent? How many people actually know that this amounts to consent to having their behaviour tracked, to have that data stored and then used commercially? What would be fair terms in an agreement to allow tracking? Publishers currently have privacy policies that allow the installation of tracking devices that are not themselves covered by their privacy policy. Is this a fair term? I believe that informed consent is the central issue that consumer policy must next address."

"I want to step up our work to develop core consumer principles that feed into policy across sectors and technologies delivering a more consistent approach the conditions surrounding tracking and profiling," she said."

Leaving aside whether individuals consent to targetted advertising or not, as discussed before, profiling takes place when individuals visit any websites (not least their clickstream data is captured by search engines; websites etc.). For those interested in researching profiling and data protection issues, recommended reading at this stage is Bygrave's Data Protection Law: approaching its law, rationale and limits.

See also:

  1. ICO: Phorm - Webwise and Open Internet Exchange
  2. Privacy and Electronic Communications (EC Directive) Regulations 2003
  3. ISPs sign up to targetted ad deals

Monday, May 26, 2008

Annual P&LB Conference on Data Protection

The Annual P&LB 21st Conference will be held in Cambridge 2008. The theme will be "Value Privacy, secure your reputation, reduce risk", 7-9th July 2008, St John's College, Cambridge, UK.

For further details, see

Spam, spam, spam

Courtesy of DataGuidance, this recent development was drawn to my attention:

Spam will become a criminal offence on the 26 May 2008, when the Consumer Protection from Unfair Trading Regulations 2008 will come into force. According to Schedule 1 of the new Regulations, Œmaking persistent and unwanted solicitations by telephone, fax, email and other remote media, except in circumstances and to the extent justified to enforce a contractual obligation, will be deemed unfair commercial practice in all circumstances. The maximum penalty for spamming is a two years imprisonment.

The regulations also cover Œdisplaying a trust mark, quality mark or equivalent without having obtained the necessary authorisation¹, and Œconducting personal visits to the consumer¹s home ignoring the consumer¹s request to leave¹.

The Consumer Protection from Unfair Trading Regulations 2008 implements the Unfair Commercial Practices Directive (UCPD) into UK Law.

The unusual thing is that we already have the Directive on Privacy and Electronic Communications 2002/58/EC (Art. 13) which deals with spam and is implemented in the UK Privacy and Electronic Communications Regulations, but this takes it one step further and makes it a criminal offence. Note, there are technological measures to deal with spam (not least e-mail filters) or as some prefer to use, Mailinator and SpamGourmet.

See:

Tuesday, May 20, 2008

Data Portability

Tech Crunch has recently posted this development in the social networking sphere, which raises some questions about the ease with which personal information can be transferred from one social networking website to another.

"How much are your friends worth? That is the question behind the big debate going on around social networks and data portability. In the last ten days, Facebook, Google, and MySpace have all announced ways to let people access their data (including friends lists) from other sites, except that what they are really trying to do is erect new walled gardens by positioning themselves as the primary repository of that personal and social data. This is valuable data and none of the big players want to cede any more of it than is necessary, which is why Facebook banned Google from tapping into its members’ social data. But here’s a little secret. All of this data is already leaking out in ways that Facebook and other social networks can hardly control. Startups are finding ways around their official APIs to get the data consumers want into their own systems. For instance, Zude, a personalized Webpage service, recently launched a feature called SocialMix that lets people import friends lists, photos, profile information, status updates, comments, and other data from Facebook, MySpace, Bebo, Orkut, and hi5. (See the screen shot below, which shows my Facebook friends on Zude). “What we are doing is taking the information and normalizing it and making it available in any manner you want,” claims Zude CTO Steve Repetti. He was tired of waiting around for true data portability to arrive, so he figured out a hack to offer it on his own (and it doesn’t involve screen scraping). Taking a different approach, Minggl has found a way to access your social data through a browser plug-in. And Media6° is placing cookies through the ads themselves on Facebook to collect social data for advertisers. If you click on an ad with one of its cookies, then the same ad will be shown to all of your friends, who supposedly are two to ten times more likely to click on the ad than other people. Media6° also should be able to target Facebook members as they wander across the Web (as long as a cookie has been placed in their browsers and they come across an ad with the Media6° Javascript code embedded in it). I’ve come across other startups who claim to be able to pull profile and friend data from Facebook. Facebook can go after them and shut them down, but it is rightly more concerned about Google gaining free and unfettered access to that data. Google is the bigger competitor and the bigger threat. But in the meantime, all of these little startups are finding ways to get at the same social data being so ferociously guarded by Facebook. In fact, they already have it, and Facebook is going to have a hell of a time trying to put it back in the barn."


Whilst users may want to control their "data" (by this, their personal information) and be able to transfer this from one network to another, what is unclear is the extent to which this is happening on a large scale? Secondly, a further complicated dimension to this is that the "profile" is not necessarily about an individual, but rather friends' data being held in another social networking environment, which leads to the question of the applicability of the Data Protection Directive 95/46/EC. There is no question that the processing of data other than yourself constitutes the processing of personal data under the Data Protection Directive (or corresponding national data protection laws), but some theoretical analysis: would Art. 3.2 of the Data Protection Directive 95/46/EC (processing personal information even of friends for private purposes) (and corresponding national data protection laws) be applicable? This would depend on whether the data is easily accessible on the internet. The ECJ's decision has been fairly clear in Lindqvist that Art. 3.2 is not applicable given that the the internet is likely to be accessible to anyone. However, whilst the Data Protection Directive 95/46/EC (and the corresponding national data protection laws) are relevant, the question will now hinge on the applicability of the the exemptions as covered under Art. 9 (artistic, literary and journalistic purposes) and Art. 13 of the Data Protection Directive 95/46/EC (and corresponding national data protection laws), which will need to be considered in more scope.


See:

Thursday, May 15, 2008

Data Retentions Directive and ISPs

Out-law has recently posted this press release concerning the Communications Data Bill which will implement the Data Retentions Directive 2006/24/EC ("DRD"):

"Phone and internet companies will soon be forced to keep logs of internet usage to be made available to the police under a new law announced by Prime Minister Gordon Brown this week.

The law, the Communications Data Bill, will implement the remainder of the European Union's Data Retention Directive.

Last October the Government enacted regulations which said that telcos must keep records of phone calls to and from land lines and mobile telephones. That requirement will be extended to records of customers' internet usage, email usage and voice over internet protocol (VoIP) records.

“The aim of the [Directive] is to ensure that certain data is retained to enable public authorities to undertake their lawful activities to investigate, detect and prosecute crime and to protect the public," said a Home Office spokeswoman.

“The first part of the [Directive] was transposed into UK law in October 2007 but the Government made a declaration … to postpone its application to the retention of communications data relating to internet access, internet telephony and internet email until 2009. So the measures referred to in the Communications Data Bill will complete the transposition of the Directive for IP [internet protocol] communications data," said the Home Office spokeswoman."

See also:

Monday, May 12, 2008

ICO Powers

According to the latest post from PL&B, the Criminal Justice and Immigration Act has received the Royal Assent, which would include strengthening the powers of the ICO to impose fines for serious breaches of the DPA 1998 -

Organisations now face substantial fines for deliberately or recklessly committing serious breaches of the Data Protection Act. The Criminal Justice and Immigration Act, which received Royal Assent (the final legislative stage) on 8 May, introduces a civil penalty rather than a criminal penalty, the result of an amendment adopted by the House of Lords last month.

The Information Commissioner can impose fines when organisations ‘knew or ought to have known that there was a risk that the contravention would occur, and that such a contravention would be of a kind likely to cause substantial distress or damage, but failed to take reasonable steps to prevent the contravention..’

Although not what it asked for, ICO welcomes the new penalty.

David Smith, Deputy Information Commissioner said: “This change in the law sends a very clear signal that data protection must be a priority and that it is completely unacceptable to be cavalier with people’s personal information. The prospect of substantial fines for deliberate or reckless breaches of the Data Protection Principles will act as a strong deterrent and help ensure that organisations take their data protection obligations more seriously.

“This new power will enable some of the worst breaches of the Data Protection Act to be punished. By demonstrating that the law is being taken seriously tougher sanctions will help to reassure individuals that data protection matters and give them confidence that organisations have no choice but to handle personal information properly.

See also:

Monday, May 05, 2008

Facebook Trust

Aside from the privacy issues, there is a discussion forum taking place with Stanford students on the psychology of facebook looking at "high-trust contexts" in Facebook. Beeb has recently written an article on this project:

"A group of students at Stanford University in the heart of Silicon Valley have turned their attention towards a unique course that blends popular culture with the more time-worn principles of psychology. The Psychology of Facebook is the brainchild of Professor B J Fogg, a pioneering persuasion psychologist who founded the Persuasive Technology Lab at Stanford.

He says: "When Facebook came along I was one of the developers at the launch and what struck me was how there was this new form of persuasion. This mass interpersonal persuasion."

The latest discussion focuses on high-contextualised trust:

"These are the high-level questions we should strive to answer to understand how trust works. The materials address one or more of these questions:
  1. What Defines and Affects Trust?
  2. How Do We Act in a Trusted vs. Untrusted Environment?

  3. How Does Trust Level Compare on Facebook vs. Internet vs. "Real World"

  4. Trust Creation: Slow, Gradual, Painstaking

  5. Trust Destruction: Instant, Deadly, Spectacular

Trust as a Function of "Perception of Risk

One way to think about trust is by examining the flipside - potential downside of opening up and sharing. Trusted environment is one where our perception of risk (something bad happening) is low. Untrusted environment is one we perceive as dangerous in some way. What could affect the perception of risk:

Anonymity vs. accountability for your actions

  • Your demographics / psychographic profile (compare Gen Y vs. Boomers)
  • Comfort with the environment (sense of control)
  • Strength & number of connections (social proof is critical to trust creation)
  • Social pressure to participate (downside of being excluded)
  • Understanding the potential abuse and how to prevent it
  • Predictability of the environment"
See:

Saturday, April 26, 2008

Social networking

Having returned from a roundtable discussion on social networking and identity and privacy at Leuven, ICRI, a few things to draw attention:

1) The International Working Group on Data Protection (pdf) has issued a report on social networking with the following:

"With respect to privacy, one of the most fundamental challenges may be seen in the fact that most of the personal information published in social network services is being published at the initiative of the users and based on their consent. While ”traditional” privacy regulation is concerned with defining rules to protect citizens against unfair or unproportional processing of personal data by the public administration (including law enforcement and secret services), and businesses, there are only very few rules governing the publication of personal data at the initiative of private individuals, partly because this had not been a major issue in the “offline world”, and neither on the Internet before social network services came into being. Furthermore, the processing of personal data from public sources has traditionally been privileged in data protection and privacy legislation."

Some points from the same report:

"Regulators

1. Introduce the option of a right to pseudonymous use – i.e. to act in a social network service
under a pseudonym –, where not already part of the regulatory framework.

2. Ensure that service providers are honest and clear about what information is required for the
basic service so that users can make an informed choice whether to take up the service, and that users can refuse any secondary uses (at least through opt-out), specifically for (targeted) marketing. Note that specific problems exist with consent of minors (note the work of the data protection commissioners)

3. Introduction of an obligation to data breach notification for social network services. Users will only be able to deal especially with the growing risks of identity theft if they are notified of any data breach. At the same time, such a measure would help to get a better picture of how well companies secure user data, and provide a further incentive to further optimise their security measures.

4. Re-thinking the current regulatory framework with respect to controllership of (specifically third party-) personal data published on social networking sites, with a view to possibly attributing more responsibility for personal data content on social networking sites to social network service providers (on this point, the Data Protection Directive is fairly clear about the obligations of data controllers)

5. Improve integration of privacy issues into the educational system. As giving away personal data online becomes part of the daily life especially of young people, privacy and tools for informational self-protection must become part of school curricula." (note the work of the data protection commissioners)"

2) Discussion on the changes made to the existing Electronic Communications Framework: has focussed more on:

– breach notification provisions - not merely the remit of ISPs, and network operators, but extended to
– better protection against spam and malware, particularly on strengthening the powers of ISPs against spammers
– better enforcement

3) Phorm was discussed briefly - the UK ICO has already indicated that opt-in consent of users will be required before the ISPs could use this:

"Phorm and the ISP will also have to comply with the Privacy and Electronic Communications Regulations 2003 (PECR) even where they do not process personal data. Under Regulation 6 of PECR a user must be informed when a cookie is placed on their computer, given clear and comprehensive information about the purpose of the storage and given the ability to refuse it being placed on the system. The information we have seen so far indicates that users will be informed by the ISP about the use of cookies as part of the process of being told about the service and given a choice about whether or not to participate. Users will also be able to configure their internet browser to block all cookies from Phorm and therefore prevent any profiling without a cookie being loaded. How this operates in practice will not be apparent until the trials by the ISP get underway or the product is rolled out but it should be possible for the ISPs and Phorm to achieve compliance with Regulation 6.

Regulation 7 of PECR will require the ISP to get the consent of users to the use of their traffic data for any value added services. This strongly supports the view that Phorm products will have to operate on an opt in basis to use traffic data as part of the process of returning relevant targeted marketing to internet users.

Whether or not the deployment of the Phorm products raise matters of concern to the Commissioner will depend on the extent to which the assurances Phorm has provided so far are true. The Commissioner has no reason to doubt the information provided by Phorm but some technical experts have publicly expressed concerns. The Commissioner welcomes the efforts Phorm is making to engage with concerned technical experts and believes that it is only by allowing its technology to be subject to detailed scrutiny by independent technical experts that it will be able to prove their assertions regarding privacy which will be important for the commercial success of the product."

See also:



Friday, April 18, 2008

Data notification breaches

The European Data Protection Supervisor has called for a data breach notification law (via Out-law) -

"The privacy watchdog for EU institutions has called for a planned requirement for telecoms companies to publish details of information security breaches to be extended to banks, businesses and medical bodies.

The European Commission has proposed a data breach notification law which would force telecoms companies to tell customers when personal information had been lost. The requirement was among other proposed changes to the Privacy and Electronic Communications Directive published last autumn.

The European Data Protection Supervisor (EDPS) has said that if the proposal is designed to help prevent identity theft it must be extended to include banks, businesses and others.

"While the EDPS is pleased with the security breach notification system … he would have favoured their application at a wider scale to include providers of information society services," said the EDPS's response. "This would mean that online banks, online businesses, online providers of health services etc would also be covered by the law."

Proposals to reform the European Electronic Communications Framework is likely to take place in Autumn this year. The main proposals to amend the Directive on Privacy and Electronic Communications 2002/58/EC include the following:

- introducing mandatory notification of security breaches resulting in users’ personal data being lost or compromised;

- strengthening implementation provisions related to network and information security to be adopted in consultation with the Authority;

- strengthening implementation and enforcement provisions to ensure that sufficient measures are available at Member State level to combat spam;

- clarifying that the Directive also applies to public communications networks supporting data collection and identification devices (including contactless devices such as Radio Frequency Identification Devices);

- modernising certain provisions that have become outdated, including the deletion of some obsolete or redundant provisions.

Some clarity is further given under the proposals over the use of spyware:

"In Article 5(3): this ensures that use of “spyware” and other malicious software remains prohibited under EC law, regardless of the method used for its delivery and installation on a user’s equipment (distribution through downloads from the Internet or via external data storage media, such as CD-ROMs, USB sticks, flash drives etc.)."

However, other than this, it should be noted that this can easily be removed by anti-spyware software (see this article) and stopbadware project.

See also:

Tuesday, April 15, 2008

Data Protection Developments

The latest issue of E-Commerce Law Reports (Vol. 7 Iss. 5 April 2008) is now available, which includes:

PRIVACY

In 'Promusicae v Telefónica', the European Court of Justice rules on the obligation of member states to order the disclosure of personal data on copyright infringers in civil actions (on the case of Promusicae v Telefónica, this has been discussed in a recent SCL article)

BROADCAST RIGHTS

In 'Karen Murphy v Media Protection Services', a pub landlord loses her appeal over the broadcast of live FA Premier League football matches using a foreign satellite system which is capable of decoding and broadcasting foreign satellite signals.

SUBJECT ACCESS RIGHTS

In Ezsias v Welsh Ministers, the High Court sets out the obligations placed on data controllers when faced with subject access requests under the Data Protection Act.

PUBLIC ACCESS

In an application to the Administrative Court by The Times, The Guardian and Financial Times, the Court applies a purposive construction to the CPR in facilitating public access to court documents.

BROADCAST RIGHTS

In 'The FA Football Association Premier League Limited v QC Leisure', the High Court considers the use of Article 81 of the EC Treaty as a defence to allegations of circumventing the cost of broadcasting FA Premier League matches using foreign satellite systems

DOMAIN NAMES

In MySpace, Inc v Total Web Solutions Ltd, MySpace wins the right to the 'myspace.co.uk' domain name, despite the respondent registering it approximately six years before MySpace was founded.

PATENTS

In 'Ingenico v Pendawell', the UK Intellectual Property Office revokes the patentability of an electronic payment system using assessment criteria which is at odds with European Patent Office caselaw.

IMAGE RIGHTS

In Grütter v Lombard, the South African Supreme Court of Appeal delivers a judgment paving the way for recognition and protection of image rights under South African common law.

PATENTS

In 'Astron Clinica Limited', the UK Patents Court considers whether patent claims could ever be granted for computer programs.

Friday, April 04, 2008

Ofcom's Study into Social networking

Having returned from a 2-day conference, Surveillance and Society, held at University of Sheffield (more to follow at a later stage), there has been a recent study published by Ofcom on Social networking. Some of the results stems from attitudes to social networking websites (no surprises about the likely usergroups):

Social networkers differ in their attitudes to social networking sites and in their behaviour while using them. Ofcom’s qualitative research indicates that site users tend to fall into five distinct groups based on their behaviours and attitudes. These are as follows:

  • Alpha Socialisers (a minority) – people who used sites in intense short bursts to flirt, meet new people, and be entertained.
  • Attention Seekers – (some) people who craved attention and comments from others, often by posting photos and customising their profiles.
  • Followers – (many) people who joined sites to keep up with what their peers were doing.
  • Faithfuls – (many) people who typically used social networking sites to rekindle old friendships, often from school or university.
  • Functionals – (a minority) people who tended to be single-minded in using sites for a particular purpose.
Non-users of social networking sites also fall into distinct groups

Non-users also appear to fall into distinct groups; these groups are based on their reasons for not using social networking sites:

  • Concerned about safety – people concerned about safety online, in particular making personal details available online.
  • Technically inexperienced – people who lack confidence in using the internet and computers.
  • Intellectual rejecters – people who have no interest in social networking sites and see them as a waste of time.
Although privacy was not given a high priority, some of the reasons that Ofcom has identified:
  • a lack of awareness of the issues;
  • an assumption that privacy and safety issues have been taken care of by the sites themselves;
  • low levels of confidence among users in their ability to manipulate privacy settings;
  • information on privacy and safety being hard to find on sites;
  • a feeling among younger users that they are invincible;
  • a perception that social networking sites are less dangerous than other online activities, such as internet banking; and, for some,
  • having consciously evaluated the risks, making the decision that they could be managed.
Whilst one is not wholly convinced about the lack of awareness, given that the ICO has published guidelines on the use of social networking, the use certainly has become more mainstream.

See:






Tuesday, March 25, 2008

CFP on Consumer Privacy

CFP for this special issue, Journal of Consumer Affairs:

"Journal of Consumer Affairs Call for Papers on Privacy

The Journal of Consumer Affairs plans a special issue on Privacy Literacy -- How Consumers Understand and Protect Their Privacy. Here is the Call for Papers:

Special Issue Guest Editors


Jeff Langenderfer Anthony Miyazaki
Meredith College Florida International University

Consumers increasingly confront a wide array of privacy-related information and are called upon to make decisions impacting their privacy in a growing number of arenas and contexts. Existing research suggests that many consumers do not understand the decisions they are forced to make nor the impact of those decisions. For this special issue of the Journal of Consumer Affairs, manuscripts are being solicited devoted to the effects of privacy literacy on consumer welfare. The goal of this special issue is to extend our theoretical and practical knowledge of how consumers obtain, process, and use information and mechanisms that relate to their privacy. We seek contributions from multiple disciplines including communications, consumer education, economics, finance, law, public policy, psychology and marketing. Authors may submit empirical studies or conceptual work. Papers that are theoretically grounded and also contain significant implications for consumer welfare are especially appropriate.

Topics that would be appropriate for this special issue include, but are not limited to:

  • Consumer understanding of privacy and privacy-related information
  • The interplay between privacy knowledge and consumer behavior
  • Cost assessments for the surrender of personal information
  • Tradeoffs between the surrender of private information and online access
  • Deceptive or covert practices in information exchange
  • Measurement and assessment of privacy literacy
  • Legal and regulatory issues in privacy
  • How consumers respond to solicitations for private information
  • Consumer understanding of privacy certifications, trustmarks, and seals of approval
  • Methods to improve privacy literacy
  • The privacy literacy of vulnerable consumers (e.g., children, low-income, etc.)
  • Relationships between desire-for-privacy, privacy concern, trust, and privacy knowledge
  • Disclosure versus practice regarding privacy-related behaviors
  • Consumer awareness regarding seller use of private information
  • Consumer understanding of medical and financial privacy practices and disclosures


Submission Information

Manuscripts are due by June 1, 2008. Please follow the submission guidelines for The Journal of Consumer Affairs as detailed under "JCA Author Guidelines" on the Blackwell Publishing web site (http://www.blackwellpublishing.com/submit.asp?ref=0022-0078&site=1). Authors wishing to submit a manuscript should send two (2) electronic copies of their manuscript (one with the full title page and one copy cleaned of all information that identifies the authors) to the special issue co-editor."

Friday, March 21, 2008

RFIDs

Excerpt (courtesy of surveillance mailing list):


RFID JOURNAL : THE WORLD'S RFID AUTHORITY
THE WORLD'S RFID AUTHORITY
Companies, Agencies Use Clandestine RFID Systems to Catch Thieves
The NOX system includes RFID readers embedded in walls, surveillance cameras and—in some cases—luminescent dust to track the movement of personnel and assets.

By Claire Swedberg

March 20, 2008—A handful of government agencies and private companies such as electronics suppliers are employing a clandestine RFID system known as NOX that allows them to use RFID interrogators hidden in walls, in conjunction with video surveillance and, in some cases, luminescent dust, to thwart theft or other unauthorized activities within their facilities.

The NOX system is the creation of SimplyRFID, a company based in Warrenton, Va. Founded in 2002 by its president, Carl Brown, SimplyRFID has developed RFID solutions for a number of clients, including Stamps.com, UPS, FedEx, the U.S. Postal Service and Target, and its Pro-Tags product line is aimed at suppliers to the U.S. Department of Defense (DOD). During the past few years, Brown says, the company has moved into the clandestine market, following government interest in the use of RFID to prevent theft, or to monitor the movements of personnel wearing RFID-tagged badges.

Because of its location near Washington, D.C., SimplyRFID attracted the attention of several government agencies, including the FBI, which visited the company's office to purchase RFID readers and tags, but brought the hardware back to their location and installed the equipment themselves. "What we found was that they were happy to have any technology that would help them [with security]," Brown says. So the company began developing a more comprehensive security solution that included RFID with video surveillance and, in some cases, "optically charged" dust that could be tracked with cameras.

The NOX system uses RFID readers that can be embedded in walls, as well as surveillance cameras that can be hidden if so desired by a user. The system integrates the two functions to enable users to track theft or other undesirable behavior on their property. By linking RFID tracking with video footage, Brown says, users can not only know which items might be missing by tracking the locations of their assets, they can also link to video footage to determine what has occurred.

"The big problem in selling RFID is that it is not always a solution by itself," Brown states. Instead, he adds, RFID offers part of a security solution by helping users track activity without requiring them to watch it around the clock. But in conjunction with video surveillance, he says, users have information about activities that have occurred—such as which items were moved, as well as where and at what time—reinforced by a visual image of what transpired.

Brown likens RFID technology to a fence, which still has vulnerabilities. People can find ways around that fence, he explains, by not wearing their badge, by wearing someone else's badge or by tampering with an RFID sticker. Such vulnerabilities make video surveillance and optical dust a strong addition to RFID. The optically charged dust consists of microporous fibers that glow when exposed to low-power laser light. This luminescence is not visible to the human eye but can be detected by a video camera. The dust is scattered in areas where there is a risk of unauthorized activity, or where entry is generally forbidden.

A camera can be programmed to watch for any dust that a person might inadvertently pick by walking through an unauthorized area. When that individual passes in front of the camera, it detects the glow as the dust is illuminated by a laser and triggers an alarm. According to Brown, this system provides perimeter security from trespassers or wild animals that might enter a secured property.

Following interest from government agencies, SimplyRFID began providing its solution to the private sector, with clients (all of which wished to be unnamed for this article) located in such states as California, Texas and Florida. The systems allow them to track their employees, as well as high-value assets that, in many cases, pass through their facilities in large quantities and can end up missing.

One common practice for thieves, Brown says, is to load extra items—such as TVs or computers—onto a shipment, or to take assets to the recycling or trash area, where they can then be removed by another party. In some instances, these thefts can occur in extremely high volume, Brown says, adding that companies have had entire trailers loaded with assets disappear. Most firms, he notes, aren't interested in prosecuting, as much as in putting an end to the thievery. "The just want to find out who's doing it and stop it," he says

By placing tags on assets, as well as on personnel badges and such items as garbage cans, companies can track what is moving, and where. The cameras, Brown says, record all activity in their area and are generally used for forensic purposes. If items are determined to have been shipped when they were not ordered, and if that occurred repeatedly with one specific employee, a company can view video footage at the time of the occurrences to see what happened.

Brown says SimplyRFID uses RFID interrogators from Thing Magic and Motorola, among other vendors. A reader is typically installed in a wall at night, or during off-hours, and is connected via an Ethernet cable to a Dell computer server so the data can be reviewed by the company's security personnel.

Companies often install four or five clandestine readers, and about the same number of cameras, at sites where items have disappeared. In other cases, companies arm every doorway and dock door with an RFID interrogator and tag every item inside. Of the private customers for which NOX has been available since 2007, Brown says, "We have three in full deployment and nine others in pilot phases. We are adding about one new install per month."

The companies use the RFID readers to capture ID numbers and send that data to a Dell computer server capable of managing up to 100 interrogators. NOX software allows integration of RFID tag data and video imagery—also stored on the server—so that an image from the time and place of a specific RFID tag read can be automatically displayed on a computer screen, along with the name and ID numbers of the tagged assets and employees wearing RFID-enabled badges.

Most cameras are supplied by Axis Communications, Brown says. The NOX system uses Avery Dennison EPC Gen 2 UHF tags.

The cost for a NOX deployment can be around $40,000 for four or five readers, cameras and software. For larger deployments with more than 30 antennas and 15 cameras, Brown says, the cost averages $100,000 to $150,000. SimplyRFID also offers installation services, he adds, though users often do some of the work themselves, such as installing the cables connecting the interrogators, cameras and server. Other end users, including government agencies, prefer to handle installation entirely on their own."

Thursday, March 20, 2008

ICO's Survey

According to the ICO's latest commissioned survey, eight out of ten now take greater care in the way they look after their personal information. The survey shows that eighty eight per cent have started to check their regular bank statements and 85% now refuse to give their personal details. However, it also identified that:

"Fifty three per cent say we no longer have confidence in the way organisations such as banks, local authorities and government departments handle our personal information."

The ICO has produced a short checklist on data protection rights: Here it is:

• An organisation should tell you what it is going to do with your information before you provide any details unless this is obvious.

• Your information should only be used for the reason it was collected in the first place (unless you give your consent to your information being used in other ways).

• An organisation should not collect any information which is unnecessary. You only need to provide the basic information which is required to deliver the service required.

• Your information should be kept accurate and up to date – if you ask any organisation to make changes to your details, it should do this.

• An organisation should not keep your details if they are no longer needed.

• An organisation must provide you with copies of all information held on you - if you ask. You can also ask an organisation to stop using your personal information if it is causing you damage or distress or if you wish to stop it being used for marketing purposes.

• An organisation must keep your personal information secure at all times.

• An organisation should not transfer your personal details to another country unless adequate data protection arrangements are in place.


Tuesday, March 18, 2008

Report by Parliamentary Committee

The Joint Committee on Human Rights has published its recent report on data protection and human rights (also mentioned in Out-Law news). Main conclusions to be drawn from the report:

"Conclusions and recommendations

1. We agree that data sharing is not, in human rights terms, objectionable in itself. Indeed, the sharing of personal data may sometimes be positively required in order to discharge the State's duty to take steps to protect certain human rights, such as the right to life, and it is also in principle capable of being justified by sufficiently weighty public interest considerations. However, the sharing of personal data will inevitably raise human rights concerns, and the more sensitive the information the stronger those concerns will be. Government must show that any proposal for data sharing is both justifiable and proportionate, and that appropriate safeguards are in place to ensure that personal data is not disclosed arbitrarily but only in circumstances where it is proportionate to do so. (Paragraph 14)

2. We fundamentally disagree with the Government's approach to data sharing legislation, which is to include very broad enabling provisions in primary legislation and to leave the data protection safeguards to be set out later in secondary legislation. Where there is a demonstrable need to legislate to permit data sharing between public sector bodies, or between public and private sector bodies, the Government's intentions should be set out clearly in primary legislation. This would enable Parliament to scrutinise the Government's proposals more effectively and, bearing in mind that secondary legislation cannot usually be amended, would increase the opportunity for Parliament to hold the executive to account. (Paragraph 20)

3. The attention paid to human rights, outside of the legal department, is likely to be very scant if the concept is regarded solely in terms of compliance with the Human Rights Act. In our view, the same is true of data protection and the Data Protection Act. Setting out the purposes of data sharing and the limitations on data sharing powers in primary legislation would give a clear indication to the staff utilising such powers of the significance of data protection. (Paragraph 21)

4. Having heard the Minister's comments, we are concerned that the role of data protection minister is far too limited, being related exclusively to the maintenance of the legislative framework for data protection. It is clearly sensible to require Government departments to take responsibility themselves for abiding by the Data Protection Act, but we would expect there to be a degree of inter-departmental co-ordination to share best practice and help deal with the fall-out from significant breaches of data protection by departments. We heard no evidence that any co-ordinating activity of this sort is currently carried out: if it is, then the data protection minister is not involved. (Paragraph 25)

5. We recommend that the role of data protection minister should be enhanced. In addition to overseeing the data protection legislation, the data protection minister should have a high-profile role within Government, championing best practice in data protection and ensuring that lessons are learnt from breaches of data protection. (Paragraph 26)

6. Recent breaches in data protection appear mostly to have resulted from human error and procedural lapses rather than technological problems. However, it would be wrong to see these errors and lapses as unfortunate "one-off" events. In our view they are symptomatic of the Government's persistent failure to take data protection safeguards sufficiently seriously by defining data sharing powers more tightly in primary legislation and including detailed safeguards against arbitrary or unjustified disclosure. The rapid increase in the amount of data sharing has not been accompanied by a sufficiently strong commitment to the need for safeguards. The fundamental problem is a cultural one: there is insufficient respect for the right to respect for personal data in the public sector. (Paragraph 27)

7. We are surprised, and disappointed, to find that senior public officials need to be reminded of the main principles of the Data Protection Act. (Paragraph 28)

8. It is clear to us from a great deal of our work, and in particular recently our inquiries into human rights of older people in healthcare and adults with learning disabilities, as well as from this inquiry, that human rights are far from being a mainstream consideration in Government departments. The Minister has identified the cultural barrier to ensuring that personal data is adequately protected by the staff who handle it, but much more needs to be done to tackle this problem successfully. We have so far seen no evidence that the human rights champions in departments have made any impact, particularly in relation to front line staff. We will continue to scrutinise their work carefully. (Paragraph 34)

9. We await the outcomes of the various reviews of data protection with interest. We expect the Government to keep us informed about its proposals for reform in this area. We recommend that, in its responses to the reviews, the Government should acknowledge the close connection between data protection and human rights; and explain how it proposes to ensure that a culture of respect for personal data is fostered throughout Government. (Paragraph 35)

10. We see the Information Commissioner as an important defender of human rights in relation to data protection and freedom of information. His office should be regarded as an important part of the national human rights machinery. We support proposals to enhance the Commissioner's powers and the resources at his disposal to ensure that he can discharge his responsibilities more effectively.(Paragraph 39)

11. We support initiatives to ensure that data protection issues are dealt with at an early stage in the planning of Government projects, including legislative proposals. We intend to scrutinise how privacy impact assessments are used in practice. (Paragraph 40)

12. Recent breaches in data protection by Government departments do not encourage us to feel confident about the security of data collected as part of the National Identity Register project. We intend to take a close interest in the Government's detailed proposals for the National Identity Register as and when they emerge. (Paragraph 47)

13. We regret that it has taken the loss of personal data affecting 25 million people - a "train crash", in the words of the Information Commissioner - for the Government to take data protection seriously. Data protection is a human rights issue and should not be treated as a fringe concern, a matter for rarely-consulted policy documents and procedures which are all too easily ignored. The recent data protection breaches have revealed the complacency of the Government's repeated refusal to accept our recommendations that more detailed limits and safeguards be included in Government bills which authorise the sharing of personal data. The problem is symptomatic of a deeper problem to which we have drawn attention in recent reports and on which we recently commented in our annual Report on our work for 2007: the failure to root human rights in the mainstream of departmental decision-making. (Paragraph 49)

Monday, March 17, 2008

Another petition - this time on Phorm and ISPs

On the same theme about petitions, here is another one which has over 5,000 signatures:


"We petition the Prime Minister to investigate the Phorm technology and if found to breach UK or European privacy laws then ban all ISP's from adopting it's use. Additionally the privacy laws should be reviewed to cover any future technologies such as Phorm. The UK's three largest ISP's, Virgin Media, BT and TalkTalk are all in talks with a view to introducing the Phorm technology. This would result in the browsing habits of the majority of the UK population being sold to a third party for advertising purposes. The opt out system for this technology is vague and unproven, even when opting out your every move on the Internet might be recorded. Surely this must be a breach of privacy laws, if not then the privacy laws need to be changed to cover such invasive technology."

This sounds more like clickstream data under the breadth of the definition of "personal data" under the Data Protection Directive 95/46/EC and the recent opinion by the Art. 29 Working Party seems to cover this.

Further details can be found here.

See also:

Response from the petition on data security breaches

Here is the response from the petition on notification about data security breaches:

"The Government acknowledges public concerns over recent losses of personal data in both the public and private sectors. Although the Data Protection Act 1998 (DPA 1998) does not currently require data controllers to report breaches of security which result in the loss, release or corruption of personal data, data controllers have a statutory responsibility to ensure appropriate and proportionate security of the personal data they hold. This is reflected in the 7th Principle of the DPA 1998. In October 2007, the Prime Minister asked Richard Thomas, the Information Commissioner and Dr Mark Walport, Director of the Wellcome Trust, to undertake an independent review into the way personal information is shared and protected in the public and private sectors. The review is going to consider whether there should be any changes to the way the DPA operates in the UK and the options for implementing any such changes. The review will include recommendations on the powers and sanctions available to the regulator and courts in the legislation governing data sharing and data protection. It will also make recommendations about how data sharing policy should be developed in a way that ensures proper transparency, scrutiny and accountability. The Government awaits the outcome of the review with interest and will consider any recommendation that calls for legislative changes relating to breach notifications. In the meantime, we understand that the Office of the Information Commissioner plans to publish helpful guidance to all data controllers on breach management and notification. The Prime Minister has also asked Sir Gus O'Donnell, the Cabinet Secretary, with advice from the Government's security experts, to work with Departments to ensure that all Departments and agencies check their procedures for the storage and use of data. A full report will be published in Spring 2008."