Tuesday, March 25, 2008

CFP on Consumer Privacy

CFP for this special issue, Journal of Consumer Affairs:

"Journal of Consumer Affairs Call for Papers on Privacy

The Journal of Consumer Affairs plans a special issue on Privacy Literacy -- How Consumers Understand and Protect Their Privacy. Here is the Call for Papers:

Special Issue Guest Editors


Jeff Langenderfer Anthony Miyazaki
Meredith College Florida International University

Consumers increasingly confront a wide array of privacy-related information and are called upon to make decisions impacting their privacy in a growing number of arenas and contexts. Existing research suggests that many consumers do not understand the decisions they are forced to make nor the impact of those decisions. For this special issue of the Journal of Consumer Affairs, manuscripts are being solicited devoted to the effects of privacy literacy on consumer welfare. The goal of this special issue is to extend our theoretical and practical knowledge of how consumers obtain, process, and use information and mechanisms that relate to their privacy. We seek contributions from multiple disciplines including communications, consumer education, economics, finance, law, public policy, psychology and marketing. Authors may submit empirical studies or conceptual work. Papers that are theoretically grounded and also contain significant implications for consumer welfare are especially appropriate.

Topics that would be appropriate for this special issue include, but are not limited to:

  • Consumer understanding of privacy and privacy-related information
  • The interplay between privacy knowledge and consumer behavior
  • Cost assessments for the surrender of personal information
  • Tradeoffs between the surrender of private information and online access
  • Deceptive or covert practices in information exchange
  • Measurement and assessment of privacy literacy
  • Legal and regulatory issues in privacy
  • How consumers respond to solicitations for private information
  • Consumer understanding of privacy certifications, trustmarks, and seals of approval
  • Methods to improve privacy literacy
  • The privacy literacy of vulnerable consumers (e.g., children, low-income, etc.)
  • Relationships between desire-for-privacy, privacy concern, trust, and privacy knowledge
  • Disclosure versus practice regarding privacy-related behaviors
  • Consumer awareness regarding seller use of private information
  • Consumer understanding of medical and financial privacy practices and disclosures


Submission Information

Manuscripts are due by June 1, 2008. Please follow the submission guidelines for The Journal of Consumer Affairs as detailed under "JCA Author Guidelines" on the Blackwell Publishing web site (http://www.blackwellpublishing.com/submit.asp?ref=0022-0078&site=1). Authors wishing to submit a manuscript should send two (2) electronic copies of their manuscript (one with the full title page and one copy cleaned of all information that identifies the authors) to the special issue co-editor."

Friday, March 21, 2008

RFIDs

Excerpt (courtesy of surveillance mailing list):


RFID JOURNAL : THE WORLD'S RFID AUTHORITY
THE WORLD'S RFID AUTHORITY
Companies, Agencies Use Clandestine RFID Systems to Catch Thieves
The NOX system includes RFID readers embedded in walls, surveillance cameras and—in some cases—luminescent dust to track the movement of personnel and assets.

By Claire Swedberg

March 20, 2008—A handful of government agencies and private companies such as electronics suppliers are employing a clandestine RFID system known as NOX that allows them to use RFID interrogators hidden in walls, in conjunction with video surveillance and, in some cases, luminescent dust, to thwart theft or other unauthorized activities within their facilities.

The NOX system is the creation of SimplyRFID, a company based in Warrenton, Va. Founded in 2002 by its president, Carl Brown, SimplyRFID has developed RFID solutions for a number of clients, including Stamps.com, UPS, FedEx, the U.S. Postal Service and Target, and its Pro-Tags product line is aimed at suppliers to the U.S. Department of Defense (DOD). During the past few years, Brown says, the company has moved into the clandestine market, following government interest in the use of RFID to prevent theft, or to monitor the movements of personnel wearing RFID-tagged badges.

Because of its location near Washington, D.C., SimplyRFID attracted the attention of several government agencies, including the FBI, which visited the company's office to purchase RFID readers and tags, but brought the hardware back to their location and installed the equipment themselves. "What we found was that they were happy to have any technology that would help them [with security]," Brown says. So the company began developing a more comprehensive security solution that included RFID with video surveillance and, in some cases, "optically charged" dust that could be tracked with cameras.

The NOX system uses RFID readers that can be embedded in walls, as well as surveillance cameras that can be hidden if so desired by a user. The system integrates the two functions to enable users to track theft or other undesirable behavior on their property. By linking RFID tracking with video footage, Brown says, users can not only know which items might be missing by tracking the locations of their assets, they can also link to video footage to determine what has occurred.

"The big problem in selling RFID is that it is not always a solution by itself," Brown states. Instead, he adds, RFID offers part of a security solution by helping users track activity without requiring them to watch it around the clock. But in conjunction with video surveillance, he says, users have information about activities that have occurred—such as which items were moved, as well as where and at what time—reinforced by a visual image of what transpired.

Brown likens RFID technology to a fence, which still has vulnerabilities. People can find ways around that fence, he explains, by not wearing their badge, by wearing someone else's badge or by tampering with an RFID sticker. Such vulnerabilities make video surveillance and optical dust a strong addition to RFID. The optically charged dust consists of microporous fibers that glow when exposed to low-power laser light. This luminescence is not visible to the human eye but can be detected by a video camera. The dust is scattered in areas where there is a risk of unauthorized activity, or where entry is generally forbidden.

A camera can be programmed to watch for any dust that a person might inadvertently pick by walking through an unauthorized area. When that individual passes in front of the camera, it detects the glow as the dust is illuminated by a laser and triggers an alarm. According to Brown, this system provides perimeter security from trespassers or wild animals that might enter a secured property.

Following interest from government agencies, SimplyRFID began providing its solution to the private sector, with clients (all of which wished to be unnamed for this article) located in such states as California, Texas and Florida. The systems allow them to track their employees, as well as high-value assets that, in many cases, pass through their facilities in large quantities and can end up missing.

One common practice for thieves, Brown says, is to load extra items—such as TVs or computers—onto a shipment, or to take assets to the recycling or trash area, where they can then be removed by another party. In some instances, these thefts can occur in extremely high volume, Brown says, adding that companies have had entire trailers loaded with assets disappear. Most firms, he notes, aren't interested in prosecuting, as much as in putting an end to the thievery. "The just want to find out who's doing it and stop it," he says

By placing tags on assets, as well as on personnel badges and such items as garbage cans, companies can track what is moving, and where. The cameras, Brown says, record all activity in their area and are generally used for forensic purposes. If items are determined to have been shipped when they were not ordered, and if that occurred repeatedly with one specific employee, a company can view video footage at the time of the occurrences to see what happened.

Brown says SimplyRFID uses RFID interrogators from Thing Magic and Motorola, among other vendors. A reader is typically installed in a wall at night, or during off-hours, and is connected via an Ethernet cable to a Dell computer server so the data can be reviewed by the company's security personnel.

Companies often install four or five clandestine readers, and about the same number of cameras, at sites where items have disappeared. In other cases, companies arm every doorway and dock door with an RFID interrogator and tag every item inside. Of the private customers for which NOX has been available since 2007, Brown says, "We have three in full deployment and nine others in pilot phases. We are adding about one new install per month."

The companies use the RFID readers to capture ID numbers and send that data to a Dell computer server capable of managing up to 100 interrogators. NOX software allows integration of RFID tag data and video imagery—also stored on the server—so that an image from the time and place of a specific RFID tag read can be automatically displayed on a computer screen, along with the name and ID numbers of the tagged assets and employees wearing RFID-enabled badges.

Most cameras are supplied by Axis Communications, Brown says. The NOX system uses Avery Dennison EPC Gen 2 UHF tags.

The cost for a NOX deployment can be around $40,000 for four or five readers, cameras and software. For larger deployments with more than 30 antennas and 15 cameras, Brown says, the cost averages $100,000 to $150,000. SimplyRFID also offers installation services, he adds, though users often do some of the work themselves, such as installing the cables connecting the interrogators, cameras and server. Other end users, including government agencies, prefer to handle installation entirely on their own."

Thursday, March 20, 2008

ICO's Survey

According to the ICO's latest commissioned survey, eight out of ten now take greater care in the way they look after their personal information. The survey shows that eighty eight per cent have started to check their regular bank statements and 85% now refuse to give their personal details. However, it also identified that:

"Fifty three per cent say we no longer have confidence in the way organisations such as banks, local authorities and government departments handle our personal information."

The ICO has produced a short checklist on data protection rights: Here it is:

• An organisation should tell you what it is going to do with your information before you provide any details unless this is obvious.

• Your information should only be used for the reason it was collected in the first place (unless you give your consent to your information being used in other ways).

• An organisation should not collect any information which is unnecessary. You only need to provide the basic information which is required to deliver the service required.

• Your information should be kept accurate and up to date – if you ask any organisation to make changes to your details, it should do this.

• An organisation should not keep your details if they are no longer needed.

• An organisation must provide you with copies of all information held on you - if you ask. You can also ask an organisation to stop using your personal information if it is causing you damage or distress or if you wish to stop it being used for marketing purposes.

• An organisation must keep your personal information secure at all times.

• An organisation should not transfer your personal details to another country unless adequate data protection arrangements are in place.


Tuesday, March 18, 2008

Report by Parliamentary Committee

The Joint Committee on Human Rights has published its recent report on data protection and human rights (also mentioned in Out-Law news). Main conclusions to be drawn from the report:

"Conclusions and recommendations

1. We agree that data sharing is not, in human rights terms, objectionable in itself. Indeed, the sharing of personal data may sometimes be positively required in order to discharge the State's duty to take steps to protect certain human rights, such as the right to life, and it is also in principle capable of being justified by sufficiently weighty public interest considerations. However, the sharing of personal data will inevitably raise human rights concerns, and the more sensitive the information the stronger those concerns will be. Government must show that any proposal for data sharing is both justifiable and proportionate, and that appropriate safeguards are in place to ensure that personal data is not disclosed arbitrarily but only in circumstances where it is proportionate to do so. (Paragraph 14)

2. We fundamentally disagree with the Government's approach to data sharing legislation, which is to include very broad enabling provisions in primary legislation and to leave the data protection safeguards to be set out later in secondary legislation. Where there is a demonstrable need to legislate to permit data sharing between public sector bodies, or between public and private sector bodies, the Government's intentions should be set out clearly in primary legislation. This would enable Parliament to scrutinise the Government's proposals more effectively and, bearing in mind that secondary legislation cannot usually be amended, would increase the opportunity for Parliament to hold the executive to account. (Paragraph 20)

3. The attention paid to human rights, outside of the legal department, is likely to be very scant if the concept is regarded solely in terms of compliance with the Human Rights Act. In our view, the same is true of data protection and the Data Protection Act. Setting out the purposes of data sharing and the limitations on data sharing powers in primary legislation would give a clear indication to the staff utilising such powers of the significance of data protection. (Paragraph 21)

4. Having heard the Minister's comments, we are concerned that the role of data protection minister is far too limited, being related exclusively to the maintenance of the legislative framework for data protection. It is clearly sensible to require Government departments to take responsibility themselves for abiding by the Data Protection Act, but we would expect there to be a degree of inter-departmental co-ordination to share best practice and help deal with the fall-out from significant breaches of data protection by departments. We heard no evidence that any co-ordinating activity of this sort is currently carried out: if it is, then the data protection minister is not involved. (Paragraph 25)

5. We recommend that the role of data protection minister should be enhanced. In addition to overseeing the data protection legislation, the data protection minister should have a high-profile role within Government, championing best practice in data protection and ensuring that lessons are learnt from breaches of data protection. (Paragraph 26)

6. Recent breaches in data protection appear mostly to have resulted from human error and procedural lapses rather than technological problems. However, it would be wrong to see these errors and lapses as unfortunate "one-off" events. In our view they are symptomatic of the Government's persistent failure to take data protection safeguards sufficiently seriously by defining data sharing powers more tightly in primary legislation and including detailed safeguards against arbitrary or unjustified disclosure. The rapid increase in the amount of data sharing has not been accompanied by a sufficiently strong commitment to the need for safeguards. The fundamental problem is a cultural one: there is insufficient respect for the right to respect for personal data in the public sector. (Paragraph 27)

7. We are surprised, and disappointed, to find that senior public officials need to be reminded of the main principles of the Data Protection Act. (Paragraph 28)

8. It is clear to us from a great deal of our work, and in particular recently our inquiries into human rights of older people in healthcare and adults with learning disabilities, as well as from this inquiry, that human rights are far from being a mainstream consideration in Government departments. The Minister has identified the cultural barrier to ensuring that personal data is adequately protected by the staff who handle it, but much more needs to be done to tackle this problem successfully. We have so far seen no evidence that the human rights champions in departments have made any impact, particularly in relation to front line staff. We will continue to scrutinise their work carefully. (Paragraph 34)

9. We await the outcomes of the various reviews of data protection with interest. We expect the Government to keep us informed about its proposals for reform in this area. We recommend that, in its responses to the reviews, the Government should acknowledge the close connection between data protection and human rights; and explain how it proposes to ensure that a culture of respect for personal data is fostered throughout Government. (Paragraph 35)

10. We see the Information Commissioner as an important defender of human rights in relation to data protection and freedom of information. His office should be regarded as an important part of the national human rights machinery. We support proposals to enhance the Commissioner's powers and the resources at his disposal to ensure that he can discharge his responsibilities more effectively.(Paragraph 39)

11. We support initiatives to ensure that data protection issues are dealt with at an early stage in the planning of Government projects, including legislative proposals. We intend to scrutinise how privacy impact assessments are used in practice. (Paragraph 40)

12. Recent breaches in data protection by Government departments do not encourage us to feel confident about the security of data collected as part of the National Identity Register project. We intend to take a close interest in the Government's detailed proposals for the National Identity Register as and when they emerge. (Paragraph 47)

13. We regret that it has taken the loss of personal data affecting 25 million people - a "train crash", in the words of the Information Commissioner - for the Government to take data protection seriously. Data protection is a human rights issue and should not be treated as a fringe concern, a matter for rarely-consulted policy documents and procedures which are all too easily ignored. The recent data protection breaches have revealed the complacency of the Government's repeated refusal to accept our recommendations that more detailed limits and safeguards be included in Government bills which authorise the sharing of personal data. The problem is symptomatic of a deeper problem to which we have drawn attention in recent reports and on which we recently commented in our annual Report on our work for 2007: the failure to root human rights in the mainstream of departmental decision-making. (Paragraph 49)

Monday, March 17, 2008

Another petition - this time on Phorm and ISPs

On the same theme about petitions, here is another one which has over 5,000 signatures:


"We petition the Prime Minister to investigate the Phorm technology and if found to breach UK or European privacy laws then ban all ISP's from adopting it's use. Additionally the privacy laws should be reviewed to cover any future technologies such as Phorm. The UK's three largest ISP's, Virgin Media, BT and TalkTalk are all in talks with a view to introducing the Phorm technology. This would result in the browsing habits of the majority of the UK population being sold to a third party for advertising purposes. The opt out system for this technology is vague and unproven, even when opting out your every move on the Internet might be recorded. Surely this must be a breach of privacy laws, if not then the privacy laws need to be changed to cover such invasive technology."

This sounds more like clickstream data under the breadth of the definition of "personal data" under the Data Protection Directive 95/46/EC and the recent opinion by the Art. 29 Working Party seems to cover this.

Further details can be found here.

See also:

Response from the petition on data security breaches

Here is the response from the petition on notification about data security breaches:

"The Government acknowledges public concerns over recent losses of personal data in both the public and private sectors. Although the Data Protection Act 1998 (DPA 1998) does not currently require data controllers to report breaches of security which result in the loss, release or corruption of personal data, data controllers have a statutory responsibility to ensure appropriate and proportionate security of the personal data they hold. This is reflected in the 7th Principle of the DPA 1998. In October 2007, the Prime Minister asked Richard Thomas, the Information Commissioner and Dr Mark Walport, Director of the Wellcome Trust, to undertake an independent review into the way personal information is shared and protected in the public and private sectors. The review is going to consider whether there should be any changes to the way the DPA operates in the UK and the options for implementing any such changes. The review will include recommendations on the powers and sanctions available to the regulator and courts in the legislation governing data sharing and data protection. It will also make recommendations about how data sharing policy should be developed in a way that ensures proper transparency, scrutiny and accountability. The Government awaits the outcome of the review with interest and will consider any recommendation that calls for legislative changes relating to breach notifications. In the meantime, we understand that the Office of the Information Commissioner plans to publish helpful guidance to all data controllers on breach management and notification. The Prime Minister has also asked Sir Gus O'Donnell, the Cabinet Secretary, with advice from the Government's security experts, to work with Departments to ensure that all Departments and agencies check their procedures for the storage and use of data. A full report will be published in Spring 2008."

Monday, March 10, 2008

Some more cases

Some cases which is likely to take some time before we hear the ECJ's ruling:

1) C-553/07 Reference for a preliminary ruling - Raad van State (Netherlands) lodged on 12 December 2007 - College van burgemeester en wethouders van Rotterdam v M.E.E. Rijkeboer: The question that has been referred to the ECJ under Art. 234 is as follows:

"Is the restriction, provided for in the Netherlands Law on local-authority personal records, on the communication of data to one year prior to the relevant request compatible with Article 12(a) of Directive 95/46/EC 1 of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, whether or not read in conjunction with Article 6(1)(e) of that directive and the principle of proportionality?"

2) C-518/07 Commission of the European Communities v Federal Republic of Germany:

This is more to do with the independence of the supervisory authorities (Data Protection Authorities) and whether Art. 28.1 of the Data Protection Directive has been incorrectly transposed re: the complete independence of the supervisory authorities.

"Forms of order sought: Declare that the Federal Republic of Germany has failed to fulfil its obligations under the second sentence of Article 28(1) of Directive 95/46/EC1, by making the supervisory authorities responsible for the monitoring of data processing within the private sector in the Länder Baden-Württemberg, Bayern, Berlin, Brandenburg, Bremen, Hamburg, Hessen, Mecklenburg-Vorpommern, Niedersachsen, Nordrhein-Westfalen, Rheinland-Pfalz, Saarland, Sachsen, Sachsen-Anhalt, Schleswig-Holstein and Thüringen subject to State supervision and thereby incorrectly transposing the requirement of 'complete independence' of the data protection supervisory authorities;

Pleas in law and argument:
The second sentence of Article 28(1) of Directive 95/46/EC of the European Parliament and of the Council puts Member States under an obligation to make 'one or more public authorities' responsible for monitoring 'the application ... of the provisions adopted by the Member States pursuant to this Directive', that is to say, of provisions on data protection. The second sentence of Article 28(1) of the directive requires the 'complete independence' of the supervisory authorities responsible. By virtue of its wording, the provision provides that the supervisory authorities are not to be subject to influence from other authorities or from outside of the State administration; the rules of the Member States must therefore preclude external influence from being exercised on the decisions of the supervisory authorities and on the implementation thereof. The wording 'complete' independence implies not only that there should be no dependence on any party, but also that there should be no dependence in any respect whatsoever.
It is thus incompatible with the second sentence of Article 28(1) of the directive to make the supervisory authorities which are responsible for the monitoring of data processing in the private sector subject to technical, legal or administrative supervision by the State, as has occurred in all 16 Länder of the Federal Republic of Germany. As the legislation of every Land makes the supervisory authority subject to those three types of supervision in varying combinations, the legislation of every Land constitutes a failure by the Federal Republic of Germany to fulfil the obligation in the second sentence of Article 28(1) of the directive to ensure the 'complete independence' of the supervisory authorities. Irrespective of the differences between legal, technical and administrative supervision, all these types of supervision constitute an infringement of the independence required by the directive.

From a teleological point of view, the Community legislature regarded complete independence as necessary so that the functions which the supervisory authority was intended to have under Article 28 of the Directive could be carried out effectively. Furthermore, light is also shed on the concept of 'complete independence' by the legislative background to the provision. The requirement of 'complete independence' of the supervisory authorities of the Member States also fits in systematically with the Community acquis existing in the area of data protection law. In addition, Article 8 of the Charter of Fundamental Rights of the European Union requires that compliance with the rules on the protection of personal data must be 'subject to control by an independent authority'.
The concept of relative independence advocated by the Federal Republic of Germany, that is to say, the independence of the supervisory authority only from that which is being supervised, cannot in any event be brought into conformity with the unambiguous, comprehensive wording of the directive, which requires 'complete' independence. In addition, on that interpretation, the second sentence of Article 28(1) would be completely meaningless. Furthermore, the argument that Article 95 EC, as the relevant legal basis for the directive, and the principles of subsidiarity and proportionality suggest a restrictive interpretation of the requirement of 'complete independence' must be rejected. The Court has already held that the directive was adopted in accordance with the areas of competence of the European Parliament and of the Council and that a restrictive interpretation of its provisions in non-economic situations is out of the question. Furthermore, the provision which is at issue does not exceed the limits of that which is necessary to achieve the objectives which the directive, in accordance with Article 95 EC and the principle of subsidiarity, pursues."

3) Case C-557/07 - LSG-Gesellschaft zur Wahrnehmung von Leistungsschutzrechten GmbH v Tele2 Telecommunication GmbH - Art. 234 preliminary ruling on the following questions:

- Is the term 'intermediary' in Article 5(1)(a) and Article 8(3) of Directive 2001/29/EC of the European Parliament and of the Council of 22 May 2001 on the harmonisation of certain aspects of copyright and related rights in the information society 1 to be interpreted as including an access provider who merely provides a user with access to the network by allocating him a dynamic IP address but does not himself provide him with any services such as e-mail, FTP or file-sharing services and does not exercise any control, either in law or in fact, over the services which the user makes use of?

If the first question is answered in the affirmative:

-Is Article 8(3) of Directive 2004/48/EC of the European Parliament and of the Council of 29 April 2004 on the enforcement of intellectual property rights, 2 having regard to Article 6 and Article 15 of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector, to be interpreted (restrictively) as not permitting the disclosure of personal traffic data to private third parties for the purpose of civil proceedings for alleged infringements of exclusive rights protected by copyright (rights of exploitation and use)?" (NB. the recent ECJ's decision in C-275/06 Productores de Música de España (Promusicae) v Telefónica de España SAU).

Saturday, March 01, 2008

Social Networks and Newspapers: drawing the boundaries?

Came across this recent Beeb press release concerning the use of information obtained from social network websites by newspapers including images and texts from Bebo, MySpace and Facebook:

Private data, public interest? (29th February 2008):

The use of material taken from personal profiles on social networks by newspapers is to be the subject of a major consultation undertaken by industry watchdog the Press Complaints Commission (PCC).

This comes in the wake of increasingly numbers of newspaper stories that include images and text taken from sites like Bebo, MySpace and Facebook.

But the subjects of press reports are not always happy with the use of content they have uploaded.

Tim Toulmin, director of the PCC, in an interview with BBC Radio 4 says the organisation was getting complaints from people about material, "that is being republished when they themselves are the subject of news stories".

Mr Toulmin says it would be useful to establish principles to guide the press in their use of social network content.

"It's down to the PCC to set the boundaries in a common sense way about what sort of information it is acceptable to re-publish," he says.

To that end the PCC has commissioned research by Ipsos MORI into public attitudes.

The newspaper watchdog wants to discover if people are aware that material they upload could be used in newspaper reports.

It also wants to discover if people would change their behaviour if they knew that information about them could be published in the media.

No doubt, this would need to be assessed in the light of the UK Data Protection Act 1998 and whether the data protection principles is adhered to (just to recap):

"Data Protection Principles

1 Personal data shall be processed fairly and lawfully and, in particular, shall not be processed unless—

(a) at least one of the conditions in Schedule 2 is met, and

(b) in the case of sensitive personal data, at least one of the conditions in Schedule 3 is also met.

2 Personal data shall be obtained only for one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.

3 Personal data shall be adequate, relevant and not excessive in relation to the purpose or purposes for which they are processed.

4 Personal data shall be accurate and, where necessary, kept up to date.

5 Personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes.

6 Personal data shall be processed in accordance with the rights of data subjects under this Act.

7 Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data.

8 Personal data shall not be transferred to a country or territory outside the European Economic Area unless that country or territory ensures an adequate level of protection for the rights and freedoms of data subjects in relation to the processing of personal data."

The first data protection principle, whether processing by newspapers constitutes "fair" and "lawful" processing before users' profiles are obtained. What procedures are in place to ensure that personal profiles obtained by newspapers will not be used for any other purpose?"

A second point to consider is whether the processing would be exempt under s 32 of the Data Protection Act 1998, which provides that:

"(1) Personal data which are processed only for the special purposes are exempt from any provision to which this subsection relates if—

(a) the processing is undertaken with a view to the publication by any person of any journalistic, literary or artistic material,

(b) the data controller reasonably believes that, having regard in particular to the special importance of the public interest in freedom of expression, publication would be in the public interest, and

(c) the data controller reasonably believes that, in all the circumstances, compliance with that provision is incompatible with the special purposes."

Special purposes is defined under s 3 of the UK Data Protection Act 1998 as the "processing for the purposes of:

(a) the purposes of journalism,

(b) artistic purposes, and

(c) literary purpose"

Whilst users on websites such as Facebook, MySpace and Bebo should not expect that information they post, is necessarily private, the ICO's guidelines does warn about the types of personal information given on such social networking websites. A general question that is often asked is how do you guarantee that information of users are not obtained out of context? Views welcome.

Friday, February 29, 2008

Another landmark case on privacy!

An important case (via Bendrath): implications still yet to be explored:

"The Court published on 27 February 2008 a landmark ruling about the constitutionality of secret online searches of computers by government agencies. The decision constitutes a new "basic right to the confidentiality and integrity of information-technological systems" as derived from the German Constitution.

The journalist and privacy activist Bettina Winsemann, the politician Fabian Brettel (Left Party), the lawyer and former federal minister for the interior Gerhart Baum (Liberal Party), and the lawyers Julius Reiter and Peter Schantz had challenged the constitutionality of a December 2006 amendmend to the law about the domestic intelligence service of the federal state of North-Rhine Westphalia. The amendmend had introduced a right for the intelligence service to "covertly observe and otherwise reconnoitre the Internet, especially the covert participation in its communication devices and the search for these, as well as the clandestine access to information-technological systems among others by technical means" (paragraph 5, number 11). Parts of the challenges also addressed other amendmends which are not covered here.

The decision of today is widely considered a landmark ruling, because it constitutes a new "basic right to the confidentiality and integrity of information-technological systems" as part of the general personality rights in the German constitution. The reasoning goes: "From the relevance of the use of information-technological systems for the expression of personality (Persönlichkeitsentfaltung) and from the dangers for personality that are connected to this use follows a need for protection that is significant for basic rights. The individual is depending upon the state respecting the justifiable expectations for the integrity and confidentiality of such systems with a view to the unrestricted expression of personality." (margin number 181). The decision complements earlier landmark privacy rulings by the Constitutional Court that had introduced the "right to informational self-determination" (1983) and the right to the "absolute protection of the core area of the private conduct of life" (2004)."

Tuesday, December 18, 2007

Petition on Data Security Breaches

Came across this petition:

"We the undersigned petition the Prime Minister to require all organisations notify customers immediately of any personal data security breaches. "

"The UK Government waited more than 10 days before telling Parliament and the Public it has accidentally lost sensitive personal details of 25 million individuals.

Under current US laws, the Government would have had to notify immediately.

The petition calls on the Prime Minister to place a legal duty on public and private sector organisations, so that affected customers are informed immediately if the security of their personal data has been compromised.

Individuals have a right to know straight away when this has occurred to protect against identify theft.

Mandatory notification would make organisations more careful and more accountable for the use of personal information."

See:

Monday, December 17, 2007

Data Security Lapse

According to the latest press releases, it appears that 3 million L-driver details for the driving theory test have gone missing:
"The details of three million candidates for the driving theory test have gone missing, Ruth Kelly has told MPs.

Names, addresses and phone numbers - but not financial data - were among details on a computer hard drive which went missing in the US in May.

It belonged to a contractor working for the Driving Standards Agency, the transport secretary told MPs.

It is the latest in a series of data losses since discs with 25m people's details on were lost by HM Revenue.

Ms Kelly said the details of learner drivers had been formatted specifically for the contractor, Pearson Driving Assessments Ltd, and was not readily accessible or usable by third parties.

Risks 'not substantial'

She said the details were not sent in the post - but the hard drive had not been found where it had been expected to be, in the "security facility" in Iowa.

She said the Information Commissioner had judged the risks presented by the loss were not "substantial" as the details did not include bank account details, National Insurance numbers, driving licence numbers or dates of birth.

But she apologised for anyone for any "uncertainty or concern" caused to anyone whose details might have been included - who took a driving theory test between September 2004 and April 2007...

However her Tory shadow Theresa Villiers said the government was failing in its duty to obey its own laws on data security and said it was further evidence of a "systemic failure" by the government in handling people's private data."

Source: BBC Millions of L-Driver Details Lost

The scale of the data lost is unfathomable - again, the Data Protection Act 1998 is clear, under the 7th data protection principle that:

"Appropriate technical and organisational measures shall be taken against unauthorised or unlawful processing of personal data and against accidental loss or destruction of, or damage to, personal data."

This is further elaborated under Part 2 of Sch. 1 of the Data Protection Act 1998:

Having regard to the state of technological development and the cost of implementing any measures, the measures must ensure a level of security appropriate to—

(a) the harm that might result from such unauthorised or unlawful processing or accidental loss, destruction or damage as are mentioned in the seventh principle, and

(b) the nature of the data to be protected.

10 The data controller must take reasonable steps to ensure the reliability of any employees of his who have access to the personal data.

11 Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller must in order to comply with the seventh principle—

(a) choose a data processor providing sufficient guarantees in respect of the technical and organisational security measures governing the processing to be carried out, and

(b) take reasonable steps to ensure compliance with those measures.

12 Where processing of personal data is carried out by a data processor on behalf of a data controller, the data controller is not to be regarded as complying with the seventh principle unless—

(a) the processing is carried out under a contract—

(i) which is made or evidenced in writing, and

(ii) under which the data processor is to act only on instructions from the data controller, and

(b) the contract requires the data processor to comply with obligations equivalent to those imposed on a data controller by the seventh principle.

Rights of those affected - The Data Protection Act 1998 (DPA) is clear to provide rights to data subjects affected by breaches under the DPA 1998.

s 10 of the DPA 1998 Right to prevent processing likely to cause damage or distress AND

s 13 of the DPA 1998 Compensation for failure to comply with certain requirements

For more information on this, visit the UK ICO's website. More powers for the ICO including a new criminal offence for knowingly or recklessly flouting data protection principles has been called for, so one awaits to see whether we will see a strengthening of the Data Protection Act 1998!

See also:

Thursday, December 13, 2007

Data Protection Developments Updates

Some latest developments on data protection:

  • The ICO called for a review of the data protection laws including a need for a data security breach notification, criminal sanctions and audit power. The transcript (uncorrected at present) is available here.
  • According to the latest press release, the ICO is currently investigating Facebook, following a complaint that one user could not delete his account. "Facebook does allow people to 'deactivate' their accounts. This means that most of their information becomes invisible to other viewers, but it remains on Facebook's servers - indefinitely." The data protection principles under the UK Data Protection Act 1998 is fairly clear that "personal data processed for any purpose or purposes shall not be kept for longer than is necessary for that purpose or those purposes" (5th data protection principle). It seems slightly odd that a user on FB account, who wishes to remove their profile from FB could not have their personal data deleted. One awaits to see what developments arise on this front. See also an interesting article on the social implications arising from the use of FB here.
  • Adequate level of data protection in Jersey and the Faroe Islands: "The Working Party adopted two Opinions, on the adequate level of data protection in both Jersey and the Faroe Islands, which will enable the Commission to take further steps towards a Commission decision on adequacy. In the past the Commission has adopted adequacy decisions on such countries as Switzerland and Argentina after receiving the advice of the Art. 29 Working Party. The Commission decision makes the transfer of personal data to such countries much easier than to third countries in relation to which such a decision has not been adopted." (Art. 29 Working Party Press Release, October 2007).
Update: Headed by Richard Thomas and Dr Mark Walport, there is consultation on the use and sharing of personal information in the public and private sectors as part of their independent Data Sharing Review. The closing date is 15 February 2008. Further details of the consultation can be found here.

Monday, December 10, 2007

Highlights of the LSPI Conference 2007

Having been absent for a week in Beijing to attend the LSPI Conference, there was the opportunity to visit the various "touristy" places including the Forbidden City and the Summer Palace.

As for the conference, this was held at the Communications University, Beijing. The theme centred on "Cyberlaw, Security and Privacy". There were some very interesting papers given including (not exhaustive):

The European proposal concerning the structure of the Internet has offered a more international and rounded approach to the debate surrounding Internet Governance. Encouraging the formation of ‘alliances’ by a certain number of governments, who wish to proceed to specific policy decisions, ‘enhanced cooperation’ is viewed as the viable solution that would potentially remove the control of the Internet outside the United States Government. However, can ‘enhanced cooperation’ meet the democratic mandate of how the Internet should be governed?

With its future still undetermined, even within the confines of the European Union, ‘enhanced cooperation’ could work as the catalyst for either the unification or the segregation of the medium. The current structure of the Internet does not encourage the creation of a ‘Constitution’, due to its domination by a specific segment of governments and private entities. Due to this state of affairs, the setting of basic principles and policies with the active participation of all interested parties – Governments, the Private Sector, Civil Society and the International Corporation for Assigned and Numbers (ICANN,) is vital. Otherwise, if not used appropriately, ‘enhanced cooperation’ can “support” coalitions of specific groups, leaving outside actors, whose role is significant.

This proposal’s starting point is the notion that, before we proceed in any governance of the Internet, first we need to identify the principles that we need to secure and, based on that premise, shape the boundaries and effects of the European proposal. Otherwise ‘enhanced coopeartion’ or any other proposal for that matter will have a detrimental effect and might even cause more problems than solutions.


"The Global Positioning System (GPS) has slowly permeated into the civilian community and has become an essential accessory for the modern individual. Various commercial applications heavily rely on GPS technology. GPS has also started receiving attention in court cases, where it has been admissible as evidence leading to convictions or proving innocence. However, GPS is a radio-navigation system and is prone to vulnerabilities that may be introduced intentionally or unintentionally. The legal literature has not debated the possibility of human alteration of GPS data in judicial reasoning which raises the prospect of forged GPS data being presented to courts by individuals who have the motive and the technical knowledge to do so. By exposing the weaknesses present, this paper aims to draw the attention of the legal fraternity to these issues which may put the legal system in a dilemma as over-reliance on GPS technology may produce disastrous results, especially when innocence or guilt largely depends on GPS evidence."

"The EU has developed a comprehensive framework for Information Society law that spans various areas ranging from a liberal regulation of e-commerce to a stringent legislation in the area of copyrights in the Information Society. This article discusses the evolution of the EU approach to the regulation of e-commerce in the Single Market and demonstrates the most important aspects of the current regulations relevant to this area."

In Internet governance transparency issues merit more extensive consideration: The Internet offers valuable opportunities for transparent communication and for the achievement of open access to discussion topics, thereby enhancing communication and dialogue between the governance-related institutions and the interested parties concerned. Transparency could also promote the mobilisation of new actors and the participation of the civil society; such development would increase the level of democratic legitimization through active involvement. ICANN has recognized the need to improve the transparency framework with its structures; the ongoing attempts should be strengthened by scholar research supporting the effort of the ICANN bodies in the present consultation phase. Since a transparent methodology for rule-making processes based on revisable procedures reduces mistrust, transparency should become a persistent objective of governance mechanisms.

The dichotomy between personal privacy and free access to information, which has come increasingly to the fore with the advance of information technology, justifies a reconsideration of these traditional values and interests. In this article, it is contended that privacy, as a constitutional right, is subject to changing norms as a result of the advent of the information society. In today’s information society, citizens weigh the importance of protecting privacy against the advantages of free access to information. The criterion they use is a rational one: an evaluation of which option provides the individual with the most benefit. The protection of privacy is no longer an unconditional good. For state organisations to champion privacy at any cost is, therefore, out of step with this development. A new balance has to be established between the citizen’s right to privacy and their right to know, taking into account this shift in values. In order to prevent on the one hand overzealous protection and, on the other, the abuse of information, it is necessary to set up the monitoring function in a new way.

Although one's paper concentrated on the subject of network neutrality, a topic which has received less attention in the UK and Europe, the feedback was very useful.

I hope to follow up on the feedback received from the two panel discussions convened on social networking (with diverse opinions/perspectives given). Again, the feedback has been extremely useful - my thanks to the delegates for making this topic a lively discussion even if some of us did not manage to agree! - a topic which has been covered to a greater extent! For those interested in the privacy implications and social networking, see the Clip below as an example:



Sunday, December 09, 2007

Lecture online

Further to my previous post on Sir Alec Jeffrey's lecture on Genetic fingerprinting and beyond, this is now available online.

"DNA fingerprinting, accidentally invented in 1984, has revolutionised many areas of Biology, most notably in forensic and legal medicine. This lecture will describe how DNA typing can be used to solve casework and will review the latest developments, including the creation of major national DNA databases that are already proving extraordinarily effective in the fight against crime."

Monday, November 26, 2007

Online advertising

According to this latest press release, the Art. 29 Working Party is investigating behaviour targetting and ads sent to people based on their web surfing. Although it does not touch upon this directly, one has explored the extent to which clickstream data can be protected under the current Data Protection Framework, particularly in the light of the Data Protection Directive 95/46/EC - a topic worthy of some academic discussion at some point. In the meantime, the following report:

"As online advertising comes under greater scrutiny in the United States, European authorities reportedly are also preparing to take a closer look at whether some marketing techniques violate privacy.

The Article 29 Working Party, an arm of the European Union that regulates protection of consumer data, is about to embark on an investigation of behavioral targeting--or sending ads to people based on their Web-surfing history--according to Reuters.

While any rules the EU issues won't directly affect companies in the United States, some companies as a practical matter will implement changes across the board. For example, in response to separate concerns of the EU Working Party, Google recently said it would "anonymize" search logs after 18 months, making it harder to connect specific IP addresses to search queries. That change is taking effect in the United States as well as Europe, although Google didn't face similar regulatory pressure here.

The Article 29 group's move to investigate behavioral targeting comes as privacy groups and consumer advocates in the United States are urging the Federal Trade Commission and other authorities to more closely regulate such techniques. Last month, a coalition of groups proposed that the FTC create a do-not-track list for consumers who don't wish online advertising companies to monitor the Web sites they visit and then send them ads based on their presumed interests.

Earlier this month, the FTC held a two-day town hall meeting about some of the privacy issues raised by behavioral targeting. Ad industry groups like the Interactive Advertising Bureau and Online Publishers Association weighed in against a do-not-track list, arguing that many companies allow consumers to opt out of behavioral targeting. Currently, many big U.S. ad networks participate in the Network Advertising Initiative--a group that formed in 2000 in response to privacy concerns, and that requires member companies to allow consumers to opt out of behavioral targeting programs.

Online ad industry executives also argued to the FTC that behavioral targeting doesn't compromise privacy because the ad companies don't collect so-called personally identifiable information, like names or addresses.

In the last few weeks, however, new variations of online advertising that arguably affect privacy have emerged. Most famously, Facebook earlier this month launched its Beacon program, which informs users' friends about purchases made at other sites. While users can opt out of sharing that data, some people say that Facebook shouldn't publicize information about purchases unless users have affirmatively consented to the program.

Last Tuesday, advocacy group MoveOn.org started a group on Facebook to protest the Beacon program. MoveOn is calling for Facebook to make the program opt-in rather than opt-out. By Sunday evening, around 20,000 Facebook members had joined the group, "Petition: Facebook, stop invading my privacy!"

Some privacy advocates say that any new regulation of online ad techniques abroad will inevitably lead to new policies in the United States as well. "It's a global business," says Jeff Chester, executive director of the Center for Digital Democracy, adding that behavioral targeting companies aren't likely to give consumers more privacy protections in Europe than the U.S. The Center for Digital Democracy argues that companies shouldn't use behavioral targeting techniques unless consumers explicitly consent.

Not all online ad industry executives think the EU investigation will necessarily lead to new regulation. Tacoda founder Dave Morgan, now executive vice president, global advertising strategy at AOL, says he's hopeful that reviews such as the EU's "will spur the online ad industry to adopt more and stronger consumer notice regimes and will drive greater participation in self-regulatory programs like the Network Advertising Initiative."

Source: Online Media Daily

Data Protection Developments

Given the latest press coverage over the benefits data fiasco, powers of the ICO have been increased to include spot checks. However, in a separate development, Privacy International is likely to take legal action on behalf of individuals affected by this against the government.

"More than 300 members of the public have contacted Privacy International since the revelation this week that Her Majesty’s Revenue & Customs unlawfully processed, and subsequently lost, personal details relating to around 25 million individuals. Most of these complainants have requested that PI undertakes, on their behalf, legal action against the government.

Accordingly, this organisation has over the past four days consulted a range of legal experts. The overall conclusion is that there is most likely a case that can be asserted. However, we must concede that not all lawyers are presently optimistic about a positive outcome. Nevertheless, given the unprecedented severity of this case we feel it is important to take some form of action on behalf of the many distressed and vulnerable families that have contacted us. It is even more important to assert the rights of the individual in the face of such circumstances.

We have therefore decided to pursue legal action against the government directly on behalf of the complainants and of course indirectly on behalf of all those people affected by the unlawful disclosure from HMRC. Our current intention is to pursue a claim for a general (not statute-based) breach of a duty of care on the basis of negligence.

We have been made aware that there are cases in which public authorities have been found to be very seriously at fault and where the courts seemed concerned not to impose liability where the claimant was one of a large and indeterminate class of people who might be affected by the careless conduct. The position would be different if the public authority actually created the danger itself or knew or ought to have known about the risk of harm resulting. It appears that courts are more willing to find “proximity” if a smaller group of persons is at risk than the public in general.

Three key issues remain to be resolved in the next few days.

1) We need to decide whether a specific "class" of individuals should be selected from amongst the complainants (for example, those who are in a particularly vulnerable situation). This will possibly help the issue of “proximity”.

2) We need to determine which individual or what department will be the target of the action (a named individual within the government or a section of HMRC), and,

3) We need to agree which law firm will handle the case. We are currently in discussions with potential companies.

Simon Davies, Privacy International’s Director, said:

"In seventeen years as a watchdog we have never received so many complaints over a single privacy issue. People are angry and distressed. They are deeply anxious over the potential threat to their children."

"Governments have hidden behind legal protection over negligence claims for many years. Now it is time to finally resolve the question of liability and duty of care so the citizen can enjoy a remedy against such blatant disregard for personal security."

"We believe there is a case to be heard and it is a case that can be won. However we realise we're going to face an uphill struggle winning that case, but we would be abandoning our responsibilities if we failed to take action."

For further information please contact Simon Davies on simon@privacy.org"

Source: Privacy International to pursue data breach legal action against UK Government

Monday, November 19, 2007

E-Comm Data Protection Law and Policy

Latest issue of E-Comm Data Protection Law and Policy, November 2007 is now available (requires subscription), but see the latest table of contents:

Contents:

# DHS defends PNR programme against 'misplaced' EU criticisms

The US Department of Homeland Security (DHS) has described EU criticisms of the recent controversial 'PNR' agreement, as 'misplaced', rejecting claims of discrimination against EU citizens.

# ICO to review DPA as part of UK's Freedom of Information expansion

The Information Commissioner's Office (ICO) is to lead a review of how personal information is shared in the public and private sector, as part of UK Government plans to expand freedom of information. The review, to be published in 2008, will examine if the Data Protection Act 1998 is adequate to protect shared personal details in the information age and will be led by Information Commissioner, Richard Thomas and Professor Mark Walport, Director of medical research charity, the Wellcome Trust.

# Businesses fined $7.7m for six DNC violations

Businesses have been fined almost $7.7 million for violations of the Do Not Call (DNC) Registry in the United States, in six settlements reached by the Federal Trade Commission (FTC).

Features:

# Editorial: The security debate

The security v privacy debate is heating up. Since 9/11, this has become one of the main challenges for privacy regulators worldwide. Clearly, the need for intelligence is more fundamental than ever in crime prevention terms and legislative measures like the data retention directive are a sign of the things to come. Recent calls for US-style passenger collection and storage obligations in privacy-conscious Europe are another step in that direction and the list of similar measures is bound to grow.

# United States: Department of Homeland Security addresses critics

US privacy policies, such as the recent Passenger Name Record (PNR) agreement, have attracted fierce criticism from European privacy experts. In this article, Lauren Saadat and Shannon Ballard, Associate Directors for International Privacy Policy at the US Department of Homeland Security (DHS), argue why such criticisms are misplaced stating that DHS policies - through recognition of the fundamental principles of transparency, an individual's right to know, individual redress and effective data security - arguably provide greater privacy protections than those offered by equivalent European agencies.

# Opinion: The Future of Privacy: part 1 - 'Privacy 1.0': the need for change

As information technology continues to evolve, regulators, privacy practitioners and citizens are increasingly questioning the suitability of current privacy frameworks to allow the effective processing of personal data whilst safeguarding individual privacy. In the first part of a two-part article, Christopher Millard, Partner at Linklaters LLP, suggests that current approaches to privacy regulation are fundamentally flawed. In particular, Millard argues that most privacy legislation is incompatible with the architecture of the internet and that the imposition by EU member states of bureaucratic obstacles destroys the usability of pre-approved rules which are supposed to facilitate simplified compliance procedures1.

# Personal Data: ICO Guidance: interpretation and consistency with 'Durant'

The recent ICO guidance on the concept of 'personal data' sets out eight questions to help organisations determine if they are processing such data. Some of the questions are designed to assist organisations in determining if information 'relates' to an individual, a key issue which was considered in the recent Durant judgment, which the ICO were bound by in drafting this guidance. Renzo Marchini, Counsel at Dechert LLP's London office, assesses this part of the guidance and its consistency with the Durant judgment.

# New Zealand: Privacy Risk Register: a practical perspective

A service enabling a person's identity to be verified quickly and easily is being built for use by government services in New Zealand. Developing this service while respecting an individual's right to privacy required the continued use of a Privacy Risk Register. Carolyn Adams, project advisor for the Department of Internal Affairs Te Tari Taiwhenua, provides a practical guide explaining how this was achieved.

# United States: Federal Court: ban on NSL notification is unconstitutional

National Security Letters work as administrative subpoenas that allow the FBI to obtain customer records without obtaining a court order. Michael Vatis, a partner in the New York office of Steptoe & Johnson LLP, explains the Federal Court's decision that 'gag' orders, which prohibit electronic communications providers from telling customers that they have received an NSL, violate the First Amendment.

DNA Lecture

There was a lecture held at NTU with Professor Sir Alec Jeffreys discussing the groundbreaking technique of DNA fingerprinting and beyond.

"DNA fingerprinting, accidentally invented in 1984, has revolutionised many areas of biology, most notably in forensic and legal medicine. Professor Jeffrey’s lecture will describe how DNA typing can be used to solve casework and will review the latest developments, including the creation of major national DNA databases that are already proving extraordinarily effective in the fight against crime. It will also discuss how this work has led to the discovery of some of the most unstable regions of human DNA, and how these can be used to study human evolution in real time and to explore the effects of environmental exposure to agents such as radiation on heritable mutations in human DNA."

We expect the a video version to be available at some point. What was interesting, when listening to his lecture was the moral and ethical dilemmas about genetic information, not simply what the DNA can reveal about individuals, but also the genetic profiles of their relatives. The subject of genetic information and privacy implications is well documented here and here. Jeffreys also touched on the subject of DNA databases. What was disconcerting was that even a minor parking offence would mean that your DNA would be taken - sounds like huge implications for privacy here.

Revisiting the Art. 29 Working Party's guidelines on genetic data, it is vitally important that the privacy of individual's DNA and what he/she is genetically pre-disposed to (whether he/she is party to the information is another matter) is preserved. Here is short extract from their concluding remarks:

"Any use of genetic data for purposes other than directly safeguarding the data subject's health and pursuing scientific research should require national rules to be implemented, in accordance with the data protection principles provided for in the Directive, and in particular the finality and proportionality principles. The application of these principles render the blanket implementation of mass genetic screening unlawful.

Furthermore, in accordance with these principles, the processing of genetic data should be authorised in the employment and insurance fields only in very exceptional cases provided for by law, so as to protect individuals from being discriminated against on the basis of their genetic profile.

In addition, the ease with which genetic material can be obtained unbeknownst to the data subject and the relevant information can be susbsequently extracted from such material, requires strict regulations in order to prevent the dangers related to new forms of "identity theft" – which would be especially dangerous in this sector and might affect fatherhood and motherhood, or even the possibility of using the material for cloning puposes. This is why, in regulating genetic data, one should not fail to consider the legal status of the DNA samples used for obtaining the information at stake. Among the issues addressed, special importance should be attached to the application of a wide range of data subjects' rights to the management of such samples, as well as to destruction and/or anonymisation of the samples after obtaining the required information.

Finally, procedures should be put in place in order to ensure that genetic data are only processed under the supervision of qualified professionals who are entitled to such processing on the basis of specific authorisations and rules.

• In Member States where the purposes and the appropriate safeguards for the processing of genetic data are not established by law, the DPAs are encouraged to play an even more active role in ensuring that the finality and proportionality principles of the Directive are fully respected.

In this respect, the Working Party recommends that Member States should consider submitting the processing of genetic data to prior checking by DPAs, in accordance with Article 20 of the Directive. This should in particular be the case with regard to the setting up and use of bio banks."

See also (not exhaustive):


Monday, November 12, 2007

Facebook, Social ads and the Data Protection Act 1998

There has been a lot of discussion centred on the facebook social ads and the likely privacy implications arising from this:

FACEBOOK wants to put your face on advertisements for products that you like.

Mark Zuckerberg, Facebook’s founder, discussed his company’s social advertising plan with marketers in New York.

Marko Georgiev for The New York Times

Facebook.com is a social networking site that lets people accumulate “friends” and share preferences and play games with them. Each member creates a home page where he or she can post photographs, likes and dislikes and updates about their activities.

Yesterday, in a twist on word-of-mouth marketing, Facebook began selling ads that display people’s profile photos next to commercial messages that are shown to their friends about items they purchased or registered an opinion about.

Source: Story, L. Facebook is marketing your brand preferences

Question: What about the Data Protection Act 1998?

What is absent from the debate is the extent to which individuals in the UK can use the Data Protection Act 1998 to request that Facebook do not use such information without their consent:

s 11 of the Data Protection Act 1998 (on the Right to Prevent Processing for Purposes of Direct Marketing) provides that:

(1) An individual is entitled at any time by notice in writing to a data controller to require the data controller at the end of such period as is reasonable in the circumstances to cease, or not to begin, processing for the purposes of direct marketing personal data in respect of which he/she is the data subject.

(2) If the Court is satisfied, on the application of any person who has given a notice under subsection (1), that the data controller has failed to comply with the notice, the court may order him to take such steps for complying with the notice as the court thinks fit.

In other words, you are entitled to request from Facebook that your profile is not used for the purposes of the Social Ads.

What about the Data Protection Principles?

There is the question whether facebook is adhering to the second data protection principle under the UK Data Protection Act 1998 that 'personal data shall be obtained only if one or more specified and lawful purposes, and shall not be further processed in any manner incompatible with that purpose or those purposes.' In other words, the user's name or image for marketing is beyond the purpose for which social networking was intended to be used. Further information can also be found on the UK ICO website.

More can be written on the application of the Data Protection Act to social networking websites, but this will have to be another article at some point. So, why wait, start complaining and exercise your data protection rights!

For more on the privacy implications arising from social networking, see also: