Friday, August 22, 2008

More data loss!

More sensitive data loss (this time, on a unencrypted memory stick!) - Beeb has reported:

"Details of 84,000 prisoners in England and Wales were lost by private firm PA Consulting. The Home Office said a full investigation was being conducted.

The information commissioner's office described it as "deeply worrying".

PA Consulting has searched its premises and looked at CCTV recordings in an attempt to recover the missing memory stick - a commonly used portable storage device for computer files. It is not clear how it came to be lost."

Probably worth reading Ubisurv's comments on this.

Stricter privacy laws - Germany

This is the latest press release (courtesy of DataGuidance News) regarding recent developments about privacy laws in Germany:

Minister of Justice calls for stricter privacy laws after data trade scandal


The German Minister of Justice, Birgitte Zypries, has called for stricter privacy laws following the recent data trade scandal, which unveiled that German citizens’ personal data are easy to find for sale on the internet.

The Ministry of Justice, who has responsibility in Germany for most consumer issues, proposed that companies should only be able to transfer consumer’s data to other companies with the prior consent of the data subjects involved. “At the moment, it is legal for companies to transfer certainkinds of data, such as names, age and addresses of customers, to other companies for marketing analysis purposes”, a Ministry of Justice spokesperson said to DataGuidance on 20 August 2008. “This provision does not apply to bank account information, and customers have the possibility to opt-out from their data being shared at any time”.

The Ministry of Justice also suggested that controllers should have an obligation to notify a data breach to the subjects involved and that companies should be forced to return any profits made with the illegal collection and processing of data.

The Ministry of Justice spokesperson clarified that Mrs Zypries made the recommendations “as a politician and as a member of the Social Democratic Party, and not in her formal position as the Minister of Justice”.

“Having responsibility for consumers’ rights, the Minister of Justice felt that German consumers expected her to express an opinion on the data trade scandal”, the spokesman explained to DataGuidance. “It is then up to the Ministry of Interior to take the recommendations on board and take any steps necessary to amend the law”.

In August 2008, an employee of a call centre engaged in fraudulent activities delivered a disc containing the names, contact information and bank account details of 17,000 German citizens to the Schleswig-Holstein consumer agency. The call centre would have used the information on the disc to contact the subjects involved and ask them to confirm their banking details in order to withdraw money from their accounts.

After the incident, the Federation of German Consumer Organisations (VZBV) appointed a journalist to conduct an undercover research on the trade of personal data. “We instructed a journalist to find out how easy it would be to buy German citizens’ personal data on the internet”, a VZBV spokesperson explained to DataGuidance on 20 August 2008. “Within hours, our investigator was offered a database containing the personal data of 6 million people and the bank details of 4 million people for EU 850”.

VZBV are still investigating the sources of the illegally sold data. “We have no confirmation yet as to who made the data available for sale on the internet”, said the VZBZ spokesperson, “however we are aware of the involvement of lottery companies that unlawfully collect personal data”.

Dr. Jochen Lehmann, Partner at German law firm Görg, said: ”While data protection has only been the subject of discussions among experts in Germany, it is now all over the headlines. This suggests that the debate over the unlawful collection and use of data will not simply fade away this time, and the involvement of the Minister of Justice is certainly a strong sign. Should the Minister’s recommendations be put into practice even partially, the data protection landscape in Germany will be considerably affected.”

Thursday, August 21, 2008

Amendments to the Data Protection Act 1998

The Criminal Justice and Immigration Act 2008 received the Royal Assent on 8th May 2008, which amends the UK Data Protection Act 1998 and gives the ICO the power to impose substantial fines on organisations that deliberately or recklessly commit serious breaches of the Data Protection Act 1998. The main provisions to consider is s 77 Criminal Justice and Immigration Act 2008. The other main change is s 78 on new defences for the purposes of journalism and other special purpose when processing personal data. Explanatory note provides that:

"Section 78 inserts a new defence into section 55 of the Data Protection Act 1998. The defence applies when a person acts for journalistic, literary or artistic purposes with a view to the publication of journalistic, literary or artistic material and in the reasonable belief that their actions were justified as being in the public interest." (notwithstanding Pepper v Hart, will need to read through Hansard to look into the background of this as to why this amendment is necessary)

See also:

Thursday, August 07, 2008

Monday, August 04, 2008

CoE DP Treaty

Privacy, Laws and Business reports the following:

"The Council of Europe Convention on Data Protection, for the first time since it was opened for signature in 1981, is inviting non-European countries with data protection laws to sign and ratify it. The Convention’s Consultative Committee recommended “that non-member states, with data protection legislation in accordance with Convention 108, should be allowed to accede to the Convention”, and it “invited the Committee of Ministers to take note of this recommendation and to consider any subsequent accession request accordingly”. The Committee of Ministers, on 2 July 2008, “agreed to examine any accession request in the light of this recommendation” and “instructed the Secretariat to disseminate information about the Convention”.

See:

Google Maps and privacy

According to Out-Law News:

"Google's Street View service has received the blessing of UK privacy watchdog the Information Commissioner, who has said that the safeguards Google has put in place for people's privacy are 'adequate'.

The Street View service works by taking photographs of a city's streets and publishing them together so that they form a kind of photo-map of a city. It has raised privacy concerns because people are identifiable in the photos.

Google, though, has always said that it will change the service according to the privacy laws of the countries in which it operates. Cameras gathering data for the service have been spotted for the first time on UK streets in recent weeks.

We are satisfied that Google is putting in place adequate safeguards to avoid any risk to the privacy or safety of individuals, including the blurring ofvehicle registration marks and the faces of anyone included in Streetview images," said a statement from the Information Commissioner's Office (ICO)."

The Data Protection Act 1998 clearly gives rights to individuals (as data subjects) to request for information held about them and Google would be no exception. The Art 29 Working Party's opinion goes into greater detail over the broad notion of personal data, which one will not elaborate.

Tuesday, July 08, 2008

Revisiting the DPA 1998

This has been widely reported:

Addressing the annual conference on Privacy Laws and Business in Cambridge, UK's Information Commissioner, Richard Thomas, has emphasised the need to bringing out necessary changes in European Data Protection Laws.

The Information Commissioner has stated that the existing laws are outdated and excessively bureaucratic, and these laws aren't in line with the modern internet age.

The Information Commissioner's Office (ICO) has commissioned RAND Europe, a research group, to assessing the current laws, and to come up with the key areas of improvement in existing structure.

Thomas also added that the research will help in designing more straightforward and effective laws, without putting extra burden on enterprises.

A representative from RAND has mentioned that the assessment process will involve small interviews and workshops, with a significant participation of small organizations. The group is expected to publish its report in April 2009.

However, Thomas admitted that the reform process would be slow, and the proposed changes may not be applicable till five years down the line, but the start can't be delayed any further.

Whilst these developments are being considered, there are several issues that will need to be revisited not least:

1) Scope of "Personal data" as laid down under the European Data Protection Directive 95/46/EC

2) Distinction drawn between sensitive and non-sensitive data as applied online under Art. 8.1 of the Directive.

3) Onset of social networking (user-generated content)

4) The ease with which information can be easily transferred (Art. 25 of the Data Protection Directive 95/46/EC) will need to be revisited.

5) Scope of the exemptions laid down under Art. 9 of the Data Protection Directive 95/46/EC - processing of personal data for the purposes of artistic, literary and journalistic purposes.

On a separate note, however, identity principles ("identity commons") has been discussed to a greater extent:

"Id Commons is defined in Wiki-Commons as:

The following Purpose and Principles are the "core DNA" of Identity Commons as an organization. We use this term since all Identity Commons working groups agree to inherit these, i.e., each one is accomplishing a specialization of this Purpose, and each one is operating in accordance with a specialization of these Principles. See Background and see our old Wiki for more about how we got here. Feel free to leave comments or make suggestions as to how this statement of Purpose and these Principles can be further improved.

The purpose of Identity Commons is to support, facilitate, and promote the creation of an open identity layer for the Internet, one that maximizes control, convenience, and privacy for the individual while encouraging the development of healthy, interoperable communities."

This could work alongside the current EU legal framework, but remains to be seen how effective this would be.


Monday, July 07, 2008

Google Street View

Having had to take a break from blogging, Google Street - views raises more unusual privacy issues (not least data protection). Out-Law has the latest press release:

A privacy pressure group has told Google that its Street View photography service will break the law. But the company says that its technical measures will safeguard people's privacy.

Street View allows users of Google's maps to view 360 degree photographs of streetscapes in towns and cities that have been catalogued by Google cameras. The company's distinctive cars with cameras attached were spotted on the streets of London for the first time last week.

Pressure group Privacy International wrote to Google's senior privacy counsel Jane Horvath last week to explain its reservations. "You may be aware that Privacy International has stated, both privately to Google legal staff and to the media, that we are concerned about a number of potential violations of national law that this technology may create," wrote Simon Davies of Privacy International.

Davies said that if Google did not satisfy him that it had taken great enough account of users' privacy he would complain about the service to the Information Commissioner's Office (ICO).

Google, though, has implemented blurring technology in order to protect the identities of people and vehicles pictured. The technology blurs faces and vehicle number plates allowing high quality images to contain indistinct people and number plates.

Horvath has written back to Davies explaining that the face and number plate blurring technology has been in place since May. Though she conceded that it is not perfect, she said that it does protect privacy.

Source: Out-Law news

Wednesday, July 02, 2008

Surveillance case

The ECtHR has recently ruled on an important case (58243/00) concerning surveillance laws and privacy. According to Liberty:

"In a significant judgement today, the European Court of Human Rights found that UK surveillance laws had lacked the necessary clarity and accountability to prevent abuses of power when used to intercept cross-border communications.The ECHR agreed with human rights group Liberty that surveillance law and practice must be tighter to protect individual privacy rights.

Alex Gask, Liberty’s Legal Officer who brought the case, said:

“The Court of Human Rights has rightly found that greater accessibility and accountability is required to ensure respect for the privacy of thousands of innocent people. While secret surveillance is a valuable tool, the mechanisms for intercepting our telephone calls and e-mails should be as open and accountable as possible, and should ensure proportionate use of very wide powers.”

The ECHR referred to German authorities as an example of best practice in surveillance techniques, in part, because they ensured that monitoring of communications is suited to each investigation and required bi-annual reviews of the need to store the materials.

Gareth Crossman, Liberty’s Policy Director and leading expert on privacy rights, said:

“This judgement highlights the wider problem of excessive surveillance undermining public trust. Whether it’s fishing expeditions of our overseas phone calls or local councils using targeted surveillance to check on school catchment areas, we need a prompt review of the broad powers in RIPA.”

In the judgement, the ECHR states that it, “does not consider that the domestic law at the relevant time indicated with sufficient clarity, so as to provide adequate protection against abuse of power, the scope or manner of exercise of the very wide discretion conferred on the State to intercept and examine external communications. In particular, it did not, as required by the Court’s case-law, set out in a form accessible to the public any indication of the procedure to be followed for selecting for examination, sharing, storing and destroying intercepted material. The interference with the applicants’ rights under Article 8 (the right to privacy) was not, therefore, “in accordance with the law.”

Mark Kelly, Director of the Irish Council for Civil Liberties, added that:

“The Court has found that the United Kingdom’s relatively sophisticated rules on data interception have failed to prevent unlawful interference with privacy rights. This has clear implications for many other Council of Europe member states, including Ireland. Our lax data interception regime will require a thorough overhaul in order to ensure that it meets the standards required by the European Court of Human Rights under Article 8.”

Thursday, June 26, 2008

Data Protection Developments

Having been bogged down with marking, finally had some time to catch-up with the latest data protection developments:

Profiling on the internet is back on the agenda: Out-Law has recently posted this press release on Electronic Commerce:

A new set of consumer contract laws to harmonise the rules that govern online selling across the EU will be proposed this autumn by the European Commission. The EU's consumer chief also promised fresh guidance on viral adverts and profiling technology.

Addressing a roundtable on digital issues in London on Friday, European Consumer Commissioner Meglena Kuneva said that while e-commerce is succeeding at national level, cross-border e-commerce is failing to keep pace. The European Commission believes that simpler and better-harmonised consumer laws will boost the sector.

The results of EU surveys among 26,000 consumers and 7,200 businesses were announced by Kuneva on Friday. They show that while a third of the EU's 490 million consumers have bought something online, only seven percent have bought from foreign suppliers. Of those with web access at home, 56% have bought online; but only 13% have made a cross-border purchase.

These figures underline how much work we still have to do to boost confidence in the online internal market," said Kuneva.

Probably more of interest is the discussion on privacy and in particular that of "targeted advertising.

Kuneva expressed concern about the targeting of adverts in what might be interpreted as a reference to recent controversy over Phorm, an advertising technology firm.

"If you watch tennis over the internet, you will be targeted with ads for tennis items. If you read about home improvement, chances are that you will receive ads for repair services and new furniture," she said. "But there are some concerns that the amounts of personal data collected over the internet without the awareness of users, let alone their consent, is getting too large and a bit out of control." [on this point, the UK ICO has published its opinion on Phorm technology - consent of users will be required under Regulation 7 of the PECR)

"Currently many websites offer to click for 'enhanced services'. Is this an informed consent? How many people actually know that this amounts to consent to having their behaviour tracked, to have that data stored and then used commercially? What would be fair terms in an agreement to allow tracking? Publishers currently have privacy policies that allow the installation of tracking devices that are not themselves covered by their privacy policy. Is this a fair term? I believe that informed consent is the central issue that consumer policy must next address."

"I want to step up our work to develop core consumer principles that feed into policy across sectors and technologies delivering a more consistent approach the conditions surrounding tracking and profiling," she said."

Leaving aside whether individuals consent to targetted advertising or not, as discussed before, profiling takes place when individuals visit any websites (not least their clickstream data is captured by search engines; websites etc.). For those interested in researching profiling and data protection issues, recommended reading at this stage is Bygrave's Data Protection Law: approaching its law, rationale and limits.

See also:

  1. ICO: Phorm - Webwise and Open Internet Exchange
  2. Privacy and Electronic Communications (EC Directive) Regulations 2003
  3. ISPs sign up to targetted ad deals

Monday, May 26, 2008

Annual P&LB Conference on Data Protection

The Annual P&LB 21st Conference will be held in Cambridge 2008. The theme will be "Value Privacy, secure your reputation, reduce risk", 7-9th July 2008, St John's College, Cambridge, UK.

For further details, see

Spam, spam, spam

Courtesy of DataGuidance, this recent development was drawn to my attention:

Spam will become a criminal offence on the 26 May 2008, when the Consumer Protection from Unfair Trading Regulations 2008 will come into force. According to Schedule 1 of the new Regulations, Œmaking persistent and unwanted solicitations by telephone, fax, email and other remote media, except in circumstances and to the extent justified to enforce a contractual obligation, will be deemed unfair commercial practice in all circumstances. The maximum penalty for spamming is a two years imprisonment.

The regulations also cover Œdisplaying a trust mark, quality mark or equivalent without having obtained the necessary authorisation¹, and Œconducting personal visits to the consumer¹s home ignoring the consumer¹s request to leave¹.

The Consumer Protection from Unfair Trading Regulations 2008 implements the Unfair Commercial Practices Directive (UCPD) into UK Law.

The unusual thing is that we already have the Directive on Privacy and Electronic Communications 2002/58/EC (Art. 13) which deals with spam and is implemented in the UK Privacy and Electronic Communications Regulations, but this takes it one step further and makes it a criminal offence. Note, there are technological measures to deal with spam (not least e-mail filters) or as some prefer to use, Mailinator and SpamGourmet.

See:

Tuesday, May 20, 2008

Data Portability

Tech Crunch has recently posted this development in the social networking sphere, which raises some questions about the ease with which personal information can be transferred from one social networking website to another.

"How much are your friends worth? That is the question behind the big debate going on around social networks and data portability. In the last ten days, Facebook, Google, and MySpace have all announced ways to let people access their data (including friends lists) from other sites, except that what they are really trying to do is erect new walled gardens by positioning themselves as the primary repository of that personal and social data. This is valuable data and none of the big players want to cede any more of it than is necessary, which is why Facebook banned Google from tapping into its members’ social data. But here’s a little secret. All of this data is already leaking out in ways that Facebook and other social networks can hardly control. Startups are finding ways around their official APIs to get the data consumers want into their own systems. For instance, Zude, a personalized Webpage service, recently launched a feature called SocialMix that lets people import friends lists, photos, profile information, status updates, comments, and other data from Facebook, MySpace, Bebo, Orkut, and hi5. (See the screen shot below, which shows my Facebook friends on Zude). “What we are doing is taking the information and normalizing it and making it available in any manner you want,” claims Zude CTO Steve Repetti. He was tired of waiting around for true data portability to arrive, so he figured out a hack to offer it on his own (and it doesn’t involve screen scraping). Taking a different approach, Minggl has found a way to access your social data through a browser plug-in. And Media6° is placing cookies through the ads themselves on Facebook to collect social data for advertisers. If you click on an ad with one of its cookies, then the same ad will be shown to all of your friends, who supposedly are two to ten times more likely to click on the ad than other people. Media6° also should be able to target Facebook members as they wander across the Web (as long as a cookie has been placed in their browsers and they come across an ad with the Media6° Javascript code embedded in it). I’ve come across other startups who claim to be able to pull profile and friend data from Facebook. Facebook can go after them and shut them down, but it is rightly more concerned about Google gaining free and unfettered access to that data. Google is the bigger competitor and the bigger threat. But in the meantime, all of these little startups are finding ways to get at the same social data being so ferociously guarded by Facebook. In fact, they already have it, and Facebook is going to have a hell of a time trying to put it back in the barn."


Whilst users may want to control their "data" (by this, their personal information) and be able to transfer this from one network to another, what is unclear is the extent to which this is happening on a large scale? Secondly, a further complicated dimension to this is that the "profile" is not necessarily about an individual, but rather friends' data being held in another social networking environment, which leads to the question of the applicability of the Data Protection Directive 95/46/EC. There is no question that the processing of data other than yourself constitutes the processing of personal data under the Data Protection Directive (or corresponding national data protection laws), but some theoretical analysis: would Art. 3.2 of the Data Protection Directive 95/46/EC (processing personal information even of friends for private purposes) (and corresponding national data protection laws) be applicable? This would depend on whether the data is easily accessible on the internet. The ECJ's decision has been fairly clear in Lindqvist that Art. 3.2 is not applicable given that the the internet is likely to be accessible to anyone. However, whilst the Data Protection Directive 95/46/EC (and the corresponding national data protection laws) are relevant, the question will now hinge on the applicability of the the exemptions as covered under Art. 9 (artistic, literary and journalistic purposes) and Art. 13 of the Data Protection Directive 95/46/EC (and corresponding national data protection laws), which will need to be considered in more scope.


See:

Thursday, May 15, 2008

Data Retentions Directive and ISPs

Out-law has recently posted this press release concerning the Communications Data Bill which will implement the Data Retentions Directive 2006/24/EC ("DRD"):

"Phone and internet companies will soon be forced to keep logs of internet usage to be made available to the police under a new law announced by Prime Minister Gordon Brown this week.

The law, the Communications Data Bill, will implement the remainder of the European Union's Data Retention Directive.

Last October the Government enacted regulations which said that telcos must keep records of phone calls to and from land lines and mobile telephones. That requirement will be extended to records of customers' internet usage, email usage and voice over internet protocol (VoIP) records.

“The aim of the [Directive] is to ensure that certain data is retained to enable public authorities to undertake their lawful activities to investigate, detect and prosecute crime and to protect the public," said a Home Office spokeswoman.

“The first part of the [Directive] was transposed into UK law in October 2007 but the Government made a declaration … to postpone its application to the retention of communications data relating to internet access, internet telephony and internet email until 2009. So the measures referred to in the Communications Data Bill will complete the transposition of the Directive for IP [internet protocol] communications data," said the Home Office spokeswoman."

See also:

Monday, May 12, 2008

ICO Powers

According to the latest post from PL&B, the Criminal Justice and Immigration Act has received the Royal Assent, which would include strengthening the powers of the ICO to impose fines for serious breaches of the DPA 1998 -

Organisations now face substantial fines for deliberately or recklessly committing serious breaches of the Data Protection Act. The Criminal Justice and Immigration Act, which received Royal Assent (the final legislative stage) on 8 May, introduces a civil penalty rather than a criminal penalty, the result of an amendment adopted by the House of Lords last month.

The Information Commissioner can impose fines when organisations ‘knew or ought to have known that there was a risk that the contravention would occur, and that such a contravention would be of a kind likely to cause substantial distress or damage, but failed to take reasonable steps to prevent the contravention..’

Although not what it asked for, ICO welcomes the new penalty.

David Smith, Deputy Information Commissioner said: “This change in the law sends a very clear signal that data protection must be a priority and that it is completely unacceptable to be cavalier with people’s personal information. The prospect of substantial fines for deliberate or reckless breaches of the Data Protection Principles will act as a strong deterrent and help ensure that organisations take their data protection obligations more seriously.

“This new power will enable some of the worst breaches of the Data Protection Act to be punished. By demonstrating that the law is being taken seriously tougher sanctions will help to reassure individuals that data protection matters and give them confidence that organisations have no choice but to handle personal information properly.

See also:

Monday, May 05, 2008

Facebook Trust

Aside from the privacy issues, there is a discussion forum taking place with Stanford students on the psychology of facebook looking at "high-trust contexts" in Facebook. Beeb has recently written an article on this project:

"A group of students at Stanford University in the heart of Silicon Valley have turned their attention towards a unique course that blends popular culture with the more time-worn principles of psychology. The Psychology of Facebook is the brainchild of Professor B J Fogg, a pioneering persuasion psychologist who founded the Persuasive Technology Lab at Stanford.

He says: "When Facebook came along I was one of the developers at the launch and what struck me was how there was this new form of persuasion. This mass interpersonal persuasion."

The latest discussion focuses on high-contextualised trust:

"These are the high-level questions we should strive to answer to understand how trust works. The materials address one or more of these questions:
  1. What Defines and Affects Trust?
  2. How Do We Act in a Trusted vs. Untrusted Environment?

  3. How Does Trust Level Compare on Facebook vs. Internet vs. "Real World"

  4. Trust Creation: Slow, Gradual, Painstaking

  5. Trust Destruction: Instant, Deadly, Spectacular

Trust as a Function of "Perception of Risk

One way to think about trust is by examining the flipside - potential downside of opening up and sharing. Trusted environment is one where our perception of risk (something bad happening) is low. Untrusted environment is one we perceive as dangerous in some way. What could affect the perception of risk:

Anonymity vs. accountability for your actions

  • Your demographics / psychographic profile (compare Gen Y vs. Boomers)
  • Comfort with the environment (sense of control)
  • Strength & number of connections (social proof is critical to trust creation)
  • Social pressure to participate (downside of being excluded)
  • Understanding the potential abuse and how to prevent it
  • Predictability of the environment"
See:

Saturday, April 26, 2008

Social networking

Having returned from a roundtable discussion on social networking and identity and privacy at Leuven, ICRI, a few things to draw attention:

1) The International Working Group on Data Protection (pdf) has issued a report on social networking with the following:

"With respect to privacy, one of the most fundamental challenges may be seen in the fact that most of the personal information published in social network services is being published at the initiative of the users and based on their consent. While ”traditional” privacy regulation is concerned with defining rules to protect citizens against unfair or unproportional processing of personal data by the public administration (including law enforcement and secret services), and businesses, there are only very few rules governing the publication of personal data at the initiative of private individuals, partly because this had not been a major issue in the “offline world”, and neither on the Internet before social network services came into being. Furthermore, the processing of personal data from public sources has traditionally been privileged in data protection and privacy legislation."

Some points from the same report:

"Regulators

1. Introduce the option of a right to pseudonymous use – i.e. to act in a social network service
under a pseudonym –, where not already part of the regulatory framework.

2. Ensure that service providers are honest and clear about what information is required for the
basic service so that users can make an informed choice whether to take up the service, and that users can refuse any secondary uses (at least through opt-out), specifically for (targeted) marketing. Note that specific problems exist with consent of minors (note the work of the data protection commissioners)

3. Introduction of an obligation to data breach notification for social network services. Users will only be able to deal especially with the growing risks of identity theft if they are notified of any data breach. At the same time, such a measure would help to get a better picture of how well companies secure user data, and provide a further incentive to further optimise their security measures.

4. Re-thinking the current regulatory framework with respect to controllership of (specifically third party-) personal data published on social networking sites, with a view to possibly attributing more responsibility for personal data content on social networking sites to social network service providers (on this point, the Data Protection Directive is fairly clear about the obligations of data controllers)

5. Improve integration of privacy issues into the educational system. As giving away personal data online becomes part of the daily life especially of young people, privacy and tools for informational self-protection must become part of school curricula." (note the work of the data protection commissioners)"

2) Discussion on the changes made to the existing Electronic Communications Framework: has focussed more on:

– breach notification provisions - not merely the remit of ISPs, and network operators, but extended to
– better protection against spam and malware, particularly on strengthening the powers of ISPs against spammers
– better enforcement

3) Phorm was discussed briefly - the UK ICO has already indicated that opt-in consent of users will be required before the ISPs could use this:

"Phorm and the ISP will also have to comply with the Privacy and Electronic Communications Regulations 2003 (PECR) even where they do not process personal data. Under Regulation 6 of PECR a user must be informed when a cookie is placed on their computer, given clear and comprehensive information about the purpose of the storage and given the ability to refuse it being placed on the system. The information we have seen so far indicates that users will be informed by the ISP about the use of cookies as part of the process of being told about the service and given a choice about whether or not to participate. Users will also be able to configure their internet browser to block all cookies from Phorm and therefore prevent any profiling without a cookie being loaded. How this operates in practice will not be apparent until the trials by the ISP get underway or the product is rolled out but it should be possible for the ISPs and Phorm to achieve compliance with Regulation 6.

Regulation 7 of PECR will require the ISP to get the consent of users to the use of their traffic data for any value added services. This strongly supports the view that Phorm products will have to operate on an opt in basis to use traffic data as part of the process of returning relevant targeted marketing to internet users.

Whether or not the deployment of the Phorm products raise matters of concern to the Commissioner will depend on the extent to which the assurances Phorm has provided so far are true. The Commissioner has no reason to doubt the information provided by Phorm but some technical experts have publicly expressed concerns. The Commissioner welcomes the efforts Phorm is making to engage with concerned technical experts and believes that it is only by allowing its technology to be subject to detailed scrutiny by independent technical experts that it will be able to prove their assertions regarding privacy which will be important for the commercial success of the product."

See also:



Friday, April 18, 2008

Data notification breaches

The European Data Protection Supervisor has called for a data breach notification law (via Out-law) -

"The privacy watchdog for EU institutions has called for a planned requirement for telecoms companies to publish details of information security breaches to be extended to banks, businesses and medical bodies.

The European Commission has proposed a data breach notification law which would force telecoms companies to tell customers when personal information had been lost. The requirement was among other proposed changes to the Privacy and Electronic Communications Directive published last autumn.

The European Data Protection Supervisor (EDPS) has said that if the proposal is designed to help prevent identity theft it must be extended to include banks, businesses and others.

"While the EDPS is pleased with the security breach notification system … he would have favoured their application at a wider scale to include providers of information society services," said the EDPS's response. "This would mean that online banks, online businesses, online providers of health services etc would also be covered by the law."

Proposals to reform the European Electronic Communications Framework is likely to take place in Autumn this year. The main proposals to amend the Directive on Privacy and Electronic Communications 2002/58/EC include the following:

- introducing mandatory notification of security breaches resulting in users’ personal data being lost or compromised;

- strengthening implementation provisions related to network and information security to be adopted in consultation with the Authority;

- strengthening implementation and enforcement provisions to ensure that sufficient measures are available at Member State level to combat spam;

- clarifying that the Directive also applies to public communications networks supporting data collection and identification devices (including contactless devices such as Radio Frequency Identification Devices);

- modernising certain provisions that have become outdated, including the deletion of some obsolete or redundant provisions.

Some clarity is further given under the proposals over the use of spyware:

"In Article 5(3): this ensures that use of “spyware” and other malicious software remains prohibited under EC law, regardless of the method used for its delivery and installation on a user’s equipment (distribution through downloads from the Internet or via external data storage media, such as CD-ROMs, USB sticks, flash drives etc.)."

However, other than this, it should be noted that this can easily be removed by anti-spyware software (see this article) and stopbadware project.

See also:

Tuesday, April 15, 2008

Data Protection Developments

The latest issue of E-Commerce Law Reports (Vol. 7 Iss. 5 April 2008) is now available, which includes:

PRIVACY

In 'Promusicae v Telefónica', the European Court of Justice rules on the obligation of member states to order the disclosure of personal data on copyright infringers in civil actions (on the case of Promusicae v Telefónica, this has been discussed in a recent SCL article)

BROADCAST RIGHTS

In 'Karen Murphy v Media Protection Services', a pub landlord loses her appeal over the broadcast of live FA Premier League football matches using a foreign satellite system which is capable of decoding and broadcasting foreign satellite signals.

SUBJECT ACCESS RIGHTS

In Ezsias v Welsh Ministers, the High Court sets out the obligations placed on data controllers when faced with subject access requests under the Data Protection Act.

PUBLIC ACCESS

In an application to the Administrative Court by The Times, The Guardian and Financial Times, the Court applies a purposive construction to the CPR in facilitating public access to court documents.

BROADCAST RIGHTS

In 'The FA Football Association Premier League Limited v QC Leisure', the High Court considers the use of Article 81 of the EC Treaty as a defence to allegations of circumventing the cost of broadcasting FA Premier League matches using foreign satellite systems

DOMAIN NAMES

In MySpace, Inc v Total Web Solutions Ltd, MySpace wins the right to the 'myspace.co.uk' domain name, despite the respondent registering it approximately six years before MySpace was founded.

PATENTS

In 'Ingenico v Pendawell', the UK Intellectual Property Office revokes the patentability of an electronic payment system using assessment criteria which is at odds with European Patent Office caselaw.

IMAGE RIGHTS

In Grütter v Lombard, the South African Supreme Court of Appeal delivers a judgment paving the way for recognition and protection of image rights under South African common law.

PATENTS

In 'Astron Clinica Limited', the UK Patents Court considers whether patent claims could ever be granted for computer programs.

Friday, April 04, 2008

Ofcom's Study into Social networking

Having returned from a 2-day conference, Surveillance and Society, held at University of Sheffield (more to follow at a later stage), there has been a recent study published by Ofcom on Social networking. Some of the results stems from attitudes to social networking websites (no surprises about the likely usergroups):

Social networkers differ in their attitudes to social networking sites and in their behaviour while using them. Ofcom’s qualitative research indicates that site users tend to fall into five distinct groups based on their behaviours and attitudes. These are as follows:

  • Alpha Socialisers (a minority) – people who used sites in intense short bursts to flirt, meet new people, and be entertained.
  • Attention Seekers – (some) people who craved attention and comments from others, often by posting photos and customising their profiles.
  • Followers – (many) people who joined sites to keep up with what their peers were doing.
  • Faithfuls – (many) people who typically used social networking sites to rekindle old friendships, often from school or university.
  • Functionals – (a minority) people who tended to be single-minded in using sites for a particular purpose.
Non-users of social networking sites also fall into distinct groups

Non-users also appear to fall into distinct groups; these groups are based on their reasons for not using social networking sites:

  • Concerned about safety – people concerned about safety online, in particular making personal details available online.
  • Technically inexperienced – people who lack confidence in using the internet and computers.
  • Intellectual rejecters – people who have no interest in social networking sites and see them as a waste of time.
Although privacy was not given a high priority, some of the reasons that Ofcom has identified:
  • a lack of awareness of the issues;
  • an assumption that privacy and safety issues have been taken care of by the sites themselves;
  • low levels of confidence among users in their ability to manipulate privacy settings;
  • information on privacy and safety being hard to find on sites;
  • a feeling among younger users that they are invincible;
  • a perception that social networking sites are less dangerous than other online activities, such as internet banking; and, for some,
  • having consciously evaluated the risks, making the decision that they could be managed.
Whilst one is not wholly convinced about the lack of awareness, given that the ICO has published guidelines on the use of social networking, the use certainly has become more mainstream.

See: