This blog is a bit on hold right now, as I write more for the "Information Security Breaches & the Law" blog.
Latest blog post, written with Cédric Laurant: "Will France adopt a law requiring the notification of security breaches? "
RE: Cyberlaw, IP, rivacy in the USA and Europe NB: This site is 100% legal-advice free.
Showing posts with label Data Privacy. Show all posts
Showing posts with label Data Privacy. Show all posts
Saturday, August 28, 2010
Sunday, May 23, 2010
Data as speech: we could become our own censors, in the name of privacy
The Electronic Frontier Foundation published on its site this week a proposal for “A Bill of Privacy Rights for Social Network Users.”
After Facebook (numerous) privacy policy changes which occurred recently, and the recent report in The Wall Street Journal that advertising companies were receiving information from Facebook and MySpace that could be then used to look up individual profiles, we certainly need to reassess the rights of social media users.
As a privacy advocate, I certainly applaud the proposed EFF bill of privacy rights. Privacy needs to be protected, especially online. It seems that social media users also need to be protected from themselves, and the right to delete embarrassing picture is certainly appealing.
But if I wear my First Amendment advocate hat, number 3 on the bill of privacy rights, The Right to Leave, does not seem to be such a good idea.
The author of the Bill, Kurt Opsahl, summarizes point 3 in this formula: “Users giveth, and users should have the right to taketh away."Social media users should have “the right to delete data or her entire account from a social network service.”
If I delete my data, should I have the right to take everything with me, including what I have posted on a friend’s wall? This is data, sure, but it is also speech after all.
I am not sure if the bill of privacy rights would cover only personal data. Point 3 refers to “data” or “uploaded information.” It could mean only personal data, but it could also mean all the information I have posted on social media sites, whether on my page, or on other’s people’s page. If the user chose to delete all of the information she uploaded over time on the social network, doesn’t this give her a right to censor other people speech?
Should we have a right to be forgotten online? Of course, we have the right to change opinion, anytime. You know how the saying goes, “Only stupid people never change their opinion,” and it is quite true. Having an opinion is one of the most difficult things one can achieve, and informing oneself, weighting different aspects of an issue, making a decision, should not be a process set in stone. A new piece of information, a new technology, a new event, may entice us to change opinion.
And we have opinions about just anything, right? Let’s just say I wrote years ago on my BFF’s Facebook wall: “I just so love kittens and sunsets on the beach!” Well, I have since changed my mind, and I now make a living in Alaska raising dogs. My formerly-professed love of kittens could damage my professional reputation.
This is just an opinion, and it is not defamatory, just maybe embarrassing for me. Should I be able to take these comments away, when I leave the site? What if my BFF had answered me: ”I love them too !” Her comment is now left tangling in cyberspace…
And should this Bill of Privacy Rights also apply to Twitter? Actually, that would be impossible right now, as Twitter has donated its entire archive of tweets to the Library of Congress.
According to Librarian of Congress James H. Billington: "The Twitter digital archive has extraordinary potential for research into our contemporary way of life. (...) The collection also documents a remarkable range of social trends. Anyone who wants to understand how an ever-broadening public is using social media to engage in an ongoing debate regarding social and cultural issues will have need of this material."
Our tweets are valuable speech indeed, and even the most mundane of tweets (aka the infamous what-I-ate-for-lunch tweet) could have great importance in the future.OK, so maybe Twitter is not a traditional social network site, and may be better defined as a micro-blogging, everything-is-public site, but it has a lot of social networking aspects.It also has been used, and probably will be used again, by eye witnesses to report important events instantly. Should they later be allowed to take this data away?
Should we have a right to be forgotten online? There is a bill recently introduced in the House that would allow us to be forgotten online. H.R.5108, the Cyber Privacy Act Bill, would “require certain Internet websites that contain personal information of individual's to remove such information at the request of such individuals.” The Act would define “personal information” as “any information about an individual that includes, at minimum, the individual's name together with either a telephone number of such individual or an address of such individual”.
The sponsors of this bill probably have in mind the protection of privacy, again, a very worthy cause! However, couldn’t this bill, if enacted, be used to have one’s name deleted from a message we have posted? (I love kittens, signed Jane Smith)
After Facebook (numerous) privacy policy changes which occurred recently, and the recent report in The Wall Street Journal that advertising companies were receiving information from Facebook and MySpace that could be then used to look up individual profiles, we certainly need to reassess the rights of social media users.
As a privacy advocate, I certainly applaud the proposed EFF bill of privacy rights. Privacy needs to be protected, especially online. It seems that social media users also need to be protected from themselves, and the right to delete embarrassing picture is certainly appealing.
But if I wear my First Amendment advocate hat, number 3 on the bill of privacy rights, The Right to Leave, does not seem to be such a good idea.
The author of the Bill, Kurt Opsahl, summarizes point 3 in this formula: “Users giveth, and users should have the right to taketh away."Social media users should have “the right to delete data or her entire account from a social network service.”
If I delete my data, should I have the right to take everything with me, including what I have posted on a friend’s wall? This is data, sure, but it is also speech after all.
I am not sure if the bill of privacy rights would cover only personal data. Point 3 refers to “data” or “uploaded information.” It could mean only personal data, but it could also mean all the information I have posted on social media sites, whether on my page, or on other’s people’s page. If the user chose to delete all of the information she uploaded over time on the social network, doesn’t this give her a right to censor other people speech?
Should we have a right to be forgotten online? Of course, we have the right to change opinion, anytime. You know how the saying goes, “Only stupid people never change their opinion,” and it is quite true. Having an opinion is one of the most difficult things one can achieve, and informing oneself, weighting different aspects of an issue, making a decision, should not be a process set in stone. A new piece of information, a new technology, a new event, may entice us to change opinion.
And we have opinions about just anything, right? Let’s just say I wrote years ago on my BFF’s Facebook wall: “I just so love kittens and sunsets on the beach!” Well, I have since changed my mind, and I now make a living in Alaska raising dogs. My formerly-professed love of kittens could damage my professional reputation.
This is just an opinion, and it is not defamatory, just maybe embarrassing for me. Should I be able to take these comments away, when I leave the site? What if my BFF had answered me: ”I love them too !” Her comment is now left tangling in cyberspace…
And should this Bill of Privacy Rights also apply to Twitter? Actually, that would be impossible right now, as Twitter has donated its entire archive of tweets to the Library of Congress.
According to Librarian of Congress James H. Billington: "The Twitter digital archive has extraordinary potential for research into our contemporary way of life. (...) The collection also documents a remarkable range of social trends. Anyone who wants to understand how an ever-broadening public is using social media to engage in an ongoing debate regarding social and cultural issues will have need of this material."
Our tweets are valuable speech indeed, and even the most mundane of tweets (aka the infamous what-I-ate-for-lunch tweet) could have great importance in the future.OK, so maybe Twitter is not a traditional social network site, and may be better defined as a micro-blogging, everything-is-public site, but it has a lot of social networking aspects.It also has been used, and probably will be used again, by eye witnesses to report important events instantly. Should they later be allowed to take this data away?
Should we have a right to be forgotten online? There is a bill recently introduced in the House that would allow us to be forgotten online. H.R.5108, the Cyber Privacy Act Bill, would “require certain Internet websites that contain personal information of individual's to remove such information at the request of such individuals.” The Act would define “personal information” as “any information about an individual that includes, at minimum, the individual's name together with either a telephone number of such individual or an address of such individual”.
The sponsors of this bill probably have in mind the protection of privacy, again, a very worthy cause! However, couldn’t this bill, if enacted, be used to have one’s name deleted from a message we have posted? (I love kittens, signed Jane Smith)
Labels:
Data Privacy,
Droit à l'Oubli,
Online Privacy
Friday, May 07, 2010
A Few Comments About the Privacy Bill Draft
A draft of a privacy bill which will be presented later this year by Representative Rick Boucher (D-Virginia) and co-sponsored by Representative Cliff Stearns (R-Florida) has been released this week.
Companies and nonprofit organizations, and generally “any person” collecting personal information from at least 5,000 people, would have to follow new privacy rules. If the information collected is “sensitive”, that is, medical records, financial records, or precise geolocation information, even an entity collecting information from fewer than 5,000 people would have to follow these rules. They would not apply, however, to governments agencies. (p.2)
Geolocation information
“Precise geolocation information” would be considered sensitive information, just as your bank records, or your patient’s file. What makes it sensitive is not the nature of the information (after all, everybody around me knows my geolocation when I stand on line for my morning coffee and bagel), but the fact that the information is collected, kept, and linked with a name, at least with an avatar.
Companies are more and more interested in knowing their (future) customer’s locations. Facebook will soon propose a check-In’ app in partnership with McDonald’s. Customers will be able to “check in” at McDonald, and their location will then appear on their Facebook page, complete with an ad featuring a McDonald product. Such application is likely to allow McDonald to know precisely when and where any customer using the app has visited one of their restaurants.
Render anonymous
The bill defines “render anonymous” as “remov[ing] or obscure[ing] covered information such that the remaining information does not identity and there is no reasonable basis to believe that the information can be used to identify [an individual or a computer/device used by a particular user.]" (p.6)
If “reasonable basis” is the benchmark used to assess whether an information is indeed anonymous, one can safely contend that it should be "reasonable” to take into account the paper written by Arvind Narayanan and Vitaly Shmatikov which proves that even anonymous data can be “re-identified” by using a specific algorithm.
Covered entities privacy policies must include how they render information anonymous after the expiration of the retention period. (p. 10). As we know, merely deleting name and addresses is not enough to make data anonymous. Remember in 2006 when New York Times journalists were able to identify an AOL user just by analyzing her different queries, even though the data had been rendered "anonymous” by AOL.
Covered entities would now have to delete or render anonymous any covered information, no later than 18 months after the date the covered information is first collected. (p.17)
Privacy notice
If the information is collected on the Internet, a privacy policy must be posted on the entity's website “clearly and conspicuously” and must be accessible through a direct link from the Internet home page of the covered entity.”
However, if the information is collected manually, the privacy notice must be made available to the individual, in writing, before the information is collected
The privacy notice must include how the information is collected the specific purpose for which the information is collected, and how the information is stored.
It also must inform the individual on how the entity may merge, link or combined his information with other information about him that the entity could obtain from third parties. This is very important as merging information from different sources allows for the building of digital files about one individual.
The policy must inform the individual on how to contact the entity, but also must contain either a hyperlink or a toll-free number for contacting the Federal Trade Commission. (p.11) This is a good point, as many consumers still do not know the role the FTC plays in defending their rights.
Opt-in?
The individual would have the option to opt-out. The entity must inform him of this option. The individual then either consents or decline consent. (p.12)
“Either”… Who has the power to choose between either opting-in or opting-out? If it is the entity, it is likely that it will always prefer to only allow the individual to opt-out. Opting-is much more protective for consumers. So, why use “either”? I am not sure why, and this point deserves clarification.
Opt-out
If the entity chooses the opt-out option, it must be done through a “readily accessible opt-out mechanism.”(p. 17)
Companies and nonprofit organizations, and generally “any person” collecting personal information from at least 5,000 people, would have to follow new privacy rules. If the information collected is “sensitive”, that is, medical records, financial records, or precise geolocation information, even an entity collecting information from fewer than 5,000 people would have to follow these rules. They would not apply, however, to governments agencies. (p.2)
Geolocation information
“Precise geolocation information” would be considered sensitive information, just as your bank records, or your patient’s file. What makes it sensitive is not the nature of the information (after all, everybody around me knows my geolocation when I stand on line for my morning coffee and bagel), but the fact that the information is collected, kept, and linked with a name, at least with an avatar.
Companies are more and more interested in knowing their (future) customer’s locations. Facebook will soon propose a check-In’ app in partnership with McDonald’s. Customers will be able to “check in” at McDonald, and their location will then appear on their Facebook page, complete with an ad featuring a McDonald product. Such application is likely to allow McDonald to know precisely when and where any customer using the app has visited one of their restaurants.
Render anonymous
The bill defines “render anonymous” as “remov[ing] or obscure[ing] covered information such that the remaining information does not identity and there is no reasonable basis to believe that the information can be used to identify [an individual or a computer/device used by a particular user.]" (p.6)
If “reasonable basis” is the benchmark used to assess whether an information is indeed anonymous, one can safely contend that it should be "reasonable” to take into account the paper written by Arvind Narayanan and Vitaly Shmatikov which proves that even anonymous data can be “re-identified” by using a specific algorithm.
Covered entities privacy policies must include how they render information anonymous after the expiration of the retention period. (p. 10). As we know, merely deleting name and addresses is not enough to make data anonymous. Remember in 2006 when New York Times journalists were able to identify an AOL user just by analyzing her different queries, even though the data had been rendered "anonymous” by AOL.
Covered entities would now have to delete or render anonymous any covered information, no later than 18 months after the date the covered information is first collected. (p.17)
Privacy notice
If the information is collected on the Internet, a privacy policy must be posted on the entity's website “clearly and conspicuously” and must be accessible through a direct link from the Internet home page of the covered entity.”
However, if the information is collected manually, the privacy notice must be made available to the individual, in writing, before the information is collected
The privacy notice must include how the information is collected the specific purpose for which the information is collected, and how the information is stored.
It also must inform the individual on how the entity may merge, link or combined his information with other information about him that the entity could obtain from third parties. This is very important as merging information from different sources allows for the building of digital files about one individual.
The policy must inform the individual on how to contact the entity, but also must contain either a hyperlink or a toll-free number for contacting the Federal Trade Commission. (p.11) This is a good point, as many consumers still do not know the role the FTC plays in defending their rights.
Opt-in?
The individual would have the option to opt-out. The entity must inform him of this option. The individual then either consents or decline consent. (p.12)
“Either”… Who has the power to choose between either opting-in or opting-out? If it is the entity, it is likely that it will always prefer to only allow the individual to opt-out. Opting-is much more protective for consumers. So, why use “either”? I am not sure why, and this point deserves clarification.
Opt-out
If the entity chooses the opt-out option, it must be done through a “readily accessible opt-out mechanism.”(p. 17)
Saturday, December 19, 2009
Who Owns Our Personal Data?
A class action suit was filed on Thursday against Netflix in the US District Court for the Northern District of California. The class is “All Netflix subscribers that rented a Netflix movie and also rated a movie on the Netflix website during the period of October 1998 through December 2005, residing in the United States.”
According to the class action complaint, “On October 2, 2006, Netflix perpetrated the largest voluntary privacy breach to date, disclosing sensitive and personal indentifying consumer information. The information was not compromised by malicious intruders. Rather, it was given away to the world freely, and with fanfare, as part of a contest intended to benefit its trusted custodian, Netflix.” The lawsuit is brought as a class action by and on behalf of similarly situated Netflix subscribers whose privacy was violated by Netflix as organizer of the “Netflix Prize” contest.
Nettflix launched a contest in the Fall of 2006 offering cash prizes to contestants who could provide collaborative filtering algorithms that would predict viewers' movie ratings with a greater accuracy than Cinematch, which is Netflix’s proprietary recommendation software.
According to the complaint "Netflix subscribers’ movie rental choices constitute personal information that subscribers reasonably expect will be treated as presumptively confidential and that their relationships with Netflix are relationships of confidentiality. Netflix has been entrusted with the confidential, sensitive, and personal information of millions of consumers.”
What is personal information? According to Netflix privacy policy: “Personal information means information that can be used to identify and contact you . . . as well as other information when such information is combined with your personal information.”
This point is interesting, as many pieces of information can become personal information, if there is a way to combine them with information that can be used to identify a person, most of the time a name or an address, but also in some cases a title (CEO of Microsoft, Secretary of the PTA of PS 2349 Pleasantville, IL). It is so easy nowadays to link databases that virtually every information may become, at any given time, a personal information.
One of the argument of the complaint is that “ Netflix was attempting to play a semantics game—“personal” information meaning pertaining to or concerning a particular person; however personal information is not limited to a Netflix subscriber’s name. Netflix subscribers reasonably believe that no record would be released showing that they watched a dogmatic, controversial, or sexually explicit show, regardless of whether their actual name is known.”
The notion of personal information goes way beyond the mere name of an individual. Netflix indeed disclosed the personal information of its subscribers “to over 51,000 individuals.”
A very interesting point in the complaint is the claim that Netflix has been unjustly enriched by this scheme, firstly because it has “benefited from its unlawful acts through the receipt of payments for Internet service from Plaintiffs" and secondly because it “continues to benefit from [its] unlawful acts through the receipt of payments in connection with its proprietary search engine, which continues to index websites associated with the subscriber data. (…) Plaintiffs are entitled to the establishment of a constructive trust consisting of the benefit to Netflix of such payments from which Plaintiffs and members of the Classes may make claims on a pro-rata basis for restitution."
The first part of the unjust enrichment argument, the receipt of payments for Internet service from Plaintiffs is not as strong as the second part of the argument, the receipt of payments in connection with the search engine. The way I understand both arguments is that Netflix benefited from the users' fees, and rightfully so, until the moment it disclosed unlawfully their personal information. After that, these fees were somehow the product of its unlawful acts. But Netflix continued to provide their rental services, and was entitled to collect fees for that service.
The second argument is much stronger. Netflix benefited unjustly from the value represented by its users' data. Most consumers still fail to realize that their personal data are very valuable, so much that it has a market value. Their shopping habits are sold by retailers to marketers.
In Dwyer v. American Express Co., 273 Ill. App. 3d 742, (Ill. App. Ct. 1st Dist. 1995), the court held that Amex did not commercially appropriate its cardholder’s personal spending habits. In that case, the plaintiffs also claimed that these actions constituted a deceptive practice claim under the Illinois Consumer Fraud Act. The plaintiff had to prove that these practices constituted a misrepresentation or a concealment of material fact, that it was the defendant’s intent that the plaintiff relies on this misrepresentation or concealment, and that the deception had occurred in the course of trade or commerce. Amex had not informed the cardholders that their spending habits would be analyzed and their names sold to merchants, and this is a deceptive practice under the Illinois Consumer Fraud Statute. However, the court held that the plaintiffs had failed to allege that they suffered any damages, except maybe for “a surfeit of unwanted mail.”
In the Netflix case, it could be easier to prove damages, because Jane Doe, one of the plaintiffs, "believes that, were her sexual orientation public knowledge, it would negatively affect her ability to pursue her livelihood and support her family and would hinder her and her children’s’ ability to live peaceful lives within Plaintiff Doe’s community.”
According to the class action complaint, “On October 2, 2006, Netflix perpetrated the largest voluntary privacy breach to date, disclosing sensitive and personal indentifying consumer information. The information was not compromised by malicious intruders. Rather, it was given away to the world freely, and with fanfare, as part of a contest intended to benefit its trusted custodian, Netflix.” The lawsuit is brought as a class action by and on behalf of similarly situated Netflix subscribers whose privacy was violated by Netflix as organizer of the “Netflix Prize” contest.
Nettflix launched a contest in the Fall of 2006 offering cash prizes to contestants who could provide collaborative filtering algorithms that would predict viewers' movie ratings with a greater accuracy than Cinematch, which is Netflix’s proprietary recommendation software.
According to the complaint "Netflix subscribers’ movie rental choices constitute personal information that subscribers reasonably expect will be treated as presumptively confidential and that their relationships with Netflix are relationships of confidentiality. Netflix has been entrusted with the confidential, sensitive, and personal information of millions of consumers.”
What is personal information? According to Netflix privacy policy: “Personal information means information that can be used to identify and contact you . . . as well as other information when such information is combined with your personal information.”
This point is interesting, as many pieces of information can become personal information, if there is a way to combine them with information that can be used to identify a person, most of the time a name or an address, but also in some cases a title (CEO of Microsoft, Secretary of the PTA of PS 2349 Pleasantville, IL). It is so easy nowadays to link databases that virtually every information may become, at any given time, a personal information.
One of the argument of the complaint is that “ Netflix was attempting to play a semantics game—“personal” information meaning pertaining to or concerning a particular person; however personal information is not limited to a Netflix subscriber’s name. Netflix subscribers reasonably believe that no record would be released showing that they watched a dogmatic, controversial, or sexually explicit show, regardless of whether their actual name is known.”
The notion of personal information goes way beyond the mere name of an individual. Netflix indeed disclosed the personal information of its subscribers “to over 51,000 individuals.”
A very interesting point in the complaint is the claim that Netflix has been unjustly enriched by this scheme, firstly because it has “benefited from its unlawful acts through the receipt of payments for Internet service from Plaintiffs" and secondly because it “continues to benefit from [its] unlawful acts through the receipt of payments in connection with its proprietary search engine, which continues to index websites associated with the subscriber data. (…) Plaintiffs are entitled to the establishment of a constructive trust consisting of the benefit to Netflix of such payments from which Plaintiffs and members of the Classes may make claims on a pro-rata basis for restitution."
The first part of the unjust enrichment argument, the receipt of payments for Internet service from Plaintiffs is not as strong as the second part of the argument, the receipt of payments in connection with the search engine. The way I understand both arguments is that Netflix benefited from the users' fees, and rightfully so, until the moment it disclosed unlawfully their personal information. After that, these fees were somehow the product of its unlawful acts. But Netflix continued to provide their rental services, and was entitled to collect fees for that service.
The second argument is much stronger. Netflix benefited unjustly from the value represented by its users' data. Most consumers still fail to realize that their personal data are very valuable, so much that it has a market value. Their shopping habits are sold by retailers to marketers.
In Dwyer v. American Express Co., 273 Ill. App. 3d 742, (Ill. App. Ct. 1st Dist. 1995), the court held that Amex did not commercially appropriate its cardholder’s personal spending habits. In that case, the plaintiffs also claimed that these actions constituted a deceptive practice claim under the Illinois Consumer Fraud Act. The plaintiff had to prove that these practices constituted a misrepresentation or a concealment of material fact, that it was the defendant’s intent that the plaintiff relies on this misrepresentation or concealment, and that the deception had occurred in the course of trade or commerce. Amex had not informed the cardholders that their spending habits would be analyzed and their names sold to merchants, and this is a deceptive practice under the Illinois Consumer Fraud Statute. However, the court held that the plaintiffs had failed to allege that they suffered any damages, except maybe for “a surfeit of unwanted mail.”
In the Netflix case, it could be easier to prove damages, because Jane Doe, one of the plaintiffs, "believes that, were her sexual orientation public knowledge, it would negatively affect her ability to pursue her livelihood and support her family and would hinder her and her children’s’ ability to live peaceful lives within Plaintiff Doe’s community.”
Tuesday, December 01, 2009
The Right to Have our Information Forgotten is a Fundamental Right
Here is an article (in French) written by Mr. Yann Padova, General Secretary of CNIL, the French Data Protection Agency. The title of the article, "Pas de liberté sans droit à l’oubli dans la société numérique," argues strongly that there cannot be any freedom in a digital society without the right to be forgotten.
Mr. Padova argues that all the information about us broadcasted on the web should have an expiration date. That would prevent HR directors, colleagues, your aunt, and just any other party curious about you to be able to see pictures of that wild weekend in Florida 10 years ago, when you and your friends played Monopoly all night long drinking non-diet cokes.
Mr. Padova argues that all the information about us broadcasted on the web should have an expiration date. That would prevent HR directors, colleagues, your aunt, and just any other party curious about you to be able to see pictures of that wild weekend in Florida 10 years ago, when you and your friends played Monopoly all night long drinking non-diet cokes.
Monday, October 19, 2009
PNR Deserves More Privacy Safeguards Say French Representatives
France’s Assemblée Nationale believes that some issues still need to be resolved regarding the Proposal for a Council Framework Decision of November 6, 2007 on the use of Passenger Name Record (PNR) for law enforcement purposes, COM(2007) 654.
Among the issues that still need to be debated and resolved, according to the French representatives, are:
- Full respect for fundamental rights, including the right to privacy and the right to data protection, which must be respected at every step of the collection and processing of data;
- Data conservation must be reduced to a reasonable period, that is, between three and six years;
- Sensitive data must be subject to specific safeguards, regardless of whether it will be ultimately decided whether or not they can be used, partially or totally, in pending investigations or prosecutions;
- Stricter rules should be obtained regarding data transfers to third countries, so that a Member State cannot be a source of leakage of masses of raw data to a third State.
Among the issues that still need to be debated and resolved, according to the French representatives, are:
- Full respect for fundamental rights, including the right to privacy and the right to data protection, which must be respected at every step of the collection and processing of data;
- Data conservation must be reduced to a reasonable period, that is, between three and six years;
- Sensitive data must be subject to specific safeguards, regardless of whether it will be ultimately decided whether or not they can be used, partially or totally, in pending investigations or prosecutions;
- Stricter rules should be obtained regarding data transfers to third countries, so that a Member State cannot be a source of leakage of masses of raw data to a third State.
Labels:
Data Privacy,
Database,
France,
Privacy in the EU
Wednesday, October 14, 2009
Tracking Abortions in Oklahoma
H.B. 1595 was signed into law by the governor of Oklahoma on May 21, 2009, and will become effective on November 1, 2009. It prohibits abortions based only on the sex of the child, and it also creates the Statistical Reporting of Abortion Act, which will be codified as Section 1-738a of Title 63 of the Oklahoma Statutes.
The Oklahoma State Department of Health must make available on its ‘stable’ Internet website, by March 1, 2011, an Individual Abortion Form, that physicians will have to use in order to submit electronically the reports required by the Statistical Reporting of Abortion Act.
The ‘Stable Internet website’ is defined by the law as a website that, to the extent reasonably practicable, is safeguarded from having its content altered other than by the State Department of Health.
To the extent reasonably practicable? I could not find a definition of that rather vague notion in the Act. But no need to worry, because The Department shall take all necessary precautions to ensure the security of the electronically submitted reports so that the data they include is able to be accessed only by specially authorized departmental personnel during and following the process of transmission.
So necessary precautions must be taken, but only to an extent that is reasonably practicable? Who will represent this standard of reason? Patients concerned about their privacy, or the government concerned about keeping costs down, or with a particular political agenda?
Pursuant to a subsection of the law that shall become operative no later of April 1, 2011, or thirty calendar days following the date on which the State Department of Health will post the Individual Abortion Form on its web site:
Any physician performing abortions shall fully complete and submit, electronically, an Individual Abortion Form to the State Department of Health by the last business day of the calendar month following the month in which the physician performs an abortion, for
each abortion the physician performs.
The Department shall post the required Individual Abortion Form on its stable Internet website. Nothing in the Individual Abortion Form shall contain the name, address, or information specifically identifying any patient.
This is interesting. The Oklahoma Legislature seems to believe that not providing the name or the address of the women who received an abortion in the state is sufficient in ensuring that their anonymity is protected. Identity is, however, a much more complex concept, and one’s name and address are only two of its multiple components. The government understands this, since the American passport also contains our DOB and photograph. The French passport adds to this information the fingerprints of the bearer.
What defines our identity? I like what Stan Karas wrote in an article : “… modernity has transformed individuals from complete subjects to a collection of subjectivities. [Stan Karas: Privacy, Identity, Databases, 52 Am. U.L. Rev. 393 428 (2002)]
Yet a collection of subjectivities is what the law requires the physicians to provide on the web form, even though the law states that nothing in the form shall contain any information specifically identifying any patient.
What is the information that the physician will have to provide on the Individual Abortion Form? Here are the first eight items:
1. Date of abortion
2. County in which abortion performed
3. Age of mother
4. Marital status of mother
(married, divorced, separated, widowed, or never married)
5. Race of mother
6. Years of education of mother
(specify highest year completed)
7. State or foreign country of residence of mother
8. Total number of previous pregnancies of the mother
This information may not be enough to identify a woman living in New York county (Manhattan), but could be enough to identify a woman living in a sparsely populated county, especially if the woman’s race (I would rather use the term ethnic background though), or educational level, are not common in the area. In other words, if you are, say, a Native-American with a PhD, obtained at the age of 22, an achievement featured in the local paper, your name and address can be deducted easily from these facts, so the form may indeed contain information specifically identifying the patient.
The Oklahoma State Department of Health must make available on its ‘stable’ Internet website, by March 1, 2011, an Individual Abortion Form, that physicians will have to use in order to submit electronically the reports required by the Statistical Reporting of Abortion Act.
The ‘Stable Internet website’ is defined by the law as a website that, to the extent reasonably practicable, is safeguarded from having its content altered other than by the State Department of Health.
To the extent reasonably practicable? I could not find a definition of that rather vague notion in the Act. But no need to worry, because The Department shall take all necessary precautions to ensure the security of the electronically submitted reports so that the data they include is able to be accessed only by specially authorized departmental personnel during and following the process of transmission.
So necessary precautions must be taken, but only to an extent that is reasonably practicable? Who will represent this standard of reason? Patients concerned about their privacy, or the government concerned about keeping costs down, or with a particular political agenda?
Pursuant to a subsection of the law that shall become operative no later of April 1, 2011, or thirty calendar days following the date on which the State Department of Health will post the Individual Abortion Form on its web site:
Any physician performing abortions shall fully complete and submit, electronically, an Individual Abortion Form to the State Department of Health by the last business day of the calendar month following the month in which the physician performs an abortion, for
each abortion the physician performs.
The Department shall post the required Individual Abortion Form on its stable Internet website. Nothing in the Individual Abortion Form shall contain the name, address, or information specifically identifying any patient.
This is interesting. The Oklahoma Legislature seems to believe that not providing the name or the address of the women who received an abortion in the state is sufficient in ensuring that their anonymity is protected. Identity is, however, a much more complex concept, and one’s name and address are only two of its multiple components. The government understands this, since the American passport also contains our DOB and photograph. The French passport adds to this information the fingerprints of the bearer.
What defines our identity? I like what Stan Karas wrote in an article : “… modernity has transformed individuals from complete subjects to a collection of subjectivities. [Stan Karas: Privacy, Identity, Databases, 52 Am. U.L. Rev. 393 428 (2002)]
Yet a collection of subjectivities is what the law requires the physicians to provide on the web form, even though the law states that nothing in the form shall contain any information specifically identifying any patient.
What is the information that the physician will have to provide on the Individual Abortion Form? Here are the first eight items:
1. Date of abortion
2. County in which abortion performed
3. Age of mother
4. Marital status of mother
(married, divorced, separated, widowed, or never married)
5. Race of mother
6. Years of education of mother
(specify highest year completed)
7. State or foreign country of residence of mother
8. Total number of previous pregnancies of the mother
This information may not be enough to identify a woman living in New York county (Manhattan), but could be enough to identify a woman living in a sparsely populated county, especially if the woman’s race (I would rather use the term ethnic background though), or educational level, are not common in the area. In other words, if you are, say, a Native-American with a PhD, obtained at the age of 22, an achievement featured in the local paper, your name and address can be deducted easily from these facts, so the form may indeed contain information specifically identifying the patient.
Thursday, September 24, 2009
Government Use of Private Databases
Via Wired.com, an article on the FBI's National Security Branch Analysis Center (NSAC) database, which, according to declassified documents obtained by Wired, contains than 1.5 billion government and private-sector records about citizens and foreigners, ans is thus becoming the “Total Information Awareness” the government wanted to put in place after 9/11.
The government thought then of data mining private databases for national security reasons. The New York Times had reported in February 2002 that the Pentagon, under the leadership of Vice Admiral John Poindexter, was building a computer able to collect and data mine personal data, such as credit card records, school, travel and medical records, in order to track terrorists. The name of the program, Total Information Awareness, was later changed to Terrorism Information Awareness. Congress eliminated funding for the program in 2003.
TIA was followed by “The Matrix,” a data mining program linking government and commercial databases. Government agencies have also required in the past the assistance of telecommunication carriers to eavesdrop on suspect’s emails. The FBI’s CARNIVORE program plugs, (or plugged,) a computer (the DCS-1000) directly to an ISPs’ network to monitor suspect incoming and outgoing emails. ECHELON was a program eavesdropping on international private telephone calls, e-mails and faxes, using both ground and satellites.
Data mining, or Knowledge Discovery in Databases (KDD) is the process that allows experts to extract trends and patterns from data, using algorithms to identify relationships and patterns in data. There are two main data mining methods. The top-down method looks for a well-defined profile by asking questions and testing hypotheses. The bottom-up method analyzes raw data to find trends and groups.
Is data mining such an extensive amount of information an efficient method to increase security? This is an important question as citizens are asked to trade off some of their liberties for security, or at least for a renewed sense of security, and would be more reluctant to do so for a program efective in preventing terrorist attacks. Former Homeland Security Secretary Michael Chertoff believed in the ability of data mining to prevent terrorism. While an assistant attorney general, he testified in 2002 that he found data mining a promising way to fight terrorism. He further testified that the Department of Justice was “using computers to analyze information obtained in the course of criminal investigations, to uncover patterns of behavior.(…) Through what has come to be called ‘data mining’ and predictive technology, we seek to identify other potential terrorists and terrorism financing networks.”
Even some privacy advocates believe that the use of commercial databases can “help improve the amount and quality of identifying information in watch lists.” However, most of them do not believe that such massive data mining would protect us against terrorist attacks, and is not fail-proof. The Wired article quotes Kurt Opsahl, an EFF senior attorney: “We have a situation where the government is spending fairly large sums of money to use an unproven technology that has a possibility of false positives that would subject innocent Americans to unnecessary scrutiny and impinge on their freedom.”
The efficiency of a method should not be the ultimate test used to establish an opinion about government surveillance. But if we may have a high surveillance tolerance, we certainly have a zero tolerance for being arrested by mistake, or prevented to board an airplane.
The government thought then of data mining private databases for national security reasons. The New York Times had reported in February 2002 that the Pentagon, under the leadership of Vice Admiral John Poindexter, was building a computer able to collect and data mine personal data, such as credit card records, school, travel and medical records, in order to track terrorists. The name of the program, Total Information Awareness, was later changed to Terrorism Information Awareness. Congress eliminated funding for the program in 2003.
TIA was followed by “The Matrix,” a data mining program linking government and commercial databases. Government agencies have also required in the past the assistance of telecommunication carriers to eavesdrop on suspect’s emails. The FBI’s CARNIVORE program plugs, (or plugged,) a computer (the DCS-1000) directly to an ISPs’ network to monitor suspect incoming and outgoing emails. ECHELON was a program eavesdropping on international private telephone calls, e-mails and faxes, using both ground and satellites.
Data mining, or Knowledge Discovery in Databases (KDD) is the process that allows experts to extract trends and patterns from data, using algorithms to identify relationships and patterns in data. There are two main data mining methods. The top-down method looks for a well-defined profile by asking questions and testing hypotheses. The bottom-up method analyzes raw data to find trends and groups.
Is data mining such an extensive amount of information an efficient method to increase security? This is an important question as citizens are asked to trade off some of their liberties for security, or at least for a renewed sense of security, and would be more reluctant to do so for a program efective in preventing terrorist attacks. Former Homeland Security Secretary Michael Chertoff believed in the ability of data mining to prevent terrorism. While an assistant attorney general, he testified in 2002 that he found data mining a promising way to fight terrorism. He further testified that the Department of Justice was “using computers to analyze information obtained in the course of criminal investigations, to uncover patterns of behavior.(…) Through what has come to be called ‘data mining’ and predictive technology, we seek to identify other potential terrorists and terrorism financing networks.”
Even some privacy advocates believe that the use of commercial databases can “help improve the amount and quality of identifying information in watch lists.” However, most of them do not believe that such massive data mining would protect us against terrorist attacks, and is not fail-proof. The Wired article quotes Kurt Opsahl, an EFF senior attorney: “We have a situation where the government is spending fairly large sums of money to use an unproven technology that has a possibility of false positives that would subject innocent Americans to unnecessary scrutiny and impinge on their freedom.”
The efficiency of a method should not be the ultimate test used to establish an opinion about government surveillance. But if we may have a high surveillance tolerance, we certainly have a zero tolerance for being arrested by mistake, or prevented to board an airplane.
Labels:
Data Mining,
Data Privacy,
Database,
Patriot Act
Wednesday, May 06, 2009
We need a new Katz!
Bruce Schneir writes: « Our protections against police abuse have been severely watered down. The courts have ruled that the police can search your data without a warrant, as long as others hold that data. If the police want to read the e-mail on your computer, they need a warrant; but they don't need one to read it from the backup tapes at your ISP” and that “just as the Supreme Court eventually ruled that tapping a telephone was a Fourth Amendment search, requiring a warrant -- even though it occurred at the phone company switching office and not in the target's home or office -- the Supreme Court must recognize that reading personal e-mail at an ISP is no different.”
The Supreme Court would then reconciliate somehow these two famous statements: the Fourth amendment protects people, not place” (Katz v. United States), but “ the Fourth Amendment does not prohibit the obtaining of information revealed to a third party and conveyed by him to Government authorities, even if the information is revealed on the assumption that it will be used only for a limited purpose and the confidence placed in the third party will not be betrayed.” (US v. Miller).
In US v. Miller, the respondent, relying on Katz, claimed that he had a Fourth Amendment interest in the records kept by his banks because they were merely copies of personal records that were made available to the banks for a limited purpose and in which he has a reasonable expectation of privacy. The Supreme Court argued that the Katz Court had stressed that "[w]hat a person knowingly exposes to the public . . . is not a subject of Fourth Amendment protection."
So we have these concepts, "copies", "limited purposes", "exposing knowingly to the public"…
In Miller, the Court noted that “checks are not confidential communications but negotiable instruments to be used in commercial transactions.” But our data, even though they are becoming a commercial commodity more and more every day, may be still confidential, if we treat them that way.
Our email could be considered copies of a confidential message sent to us, made available to our ISP for the limited purpose of storing it so we can access it later and read it on our private computer. We would then be in charge of storing that private message, in our own hard drive., protected by the Fourth Amendment. Well, what if we use web mail, what if our company is cloud computing? Should users of Outlook be more protected than the ones using, say Gmail?
The Supreme Court would then reconciliate somehow these two famous statements: the Fourth amendment protects people, not place” (Katz v. United States), but “ the Fourth Amendment does not prohibit the obtaining of information revealed to a third party and conveyed by him to Government authorities, even if the information is revealed on the assumption that it will be used only for a limited purpose and the confidence placed in the third party will not be betrayed.” (US v. Miller).
In US v. Miller, the respondent, relying on Katz, claimed that he had a Fourth Amendment interest in the records kept by his banks because they were merely copies of personal records that were made available to the banks for a limited purpose and in which he has a reasonable expectation of privacy. The Supreme Court argued that the Katz Court had stressed that "[w]hat a person knowingly exposes to the public . . . is not a subject of Fourth Amendment protection."
So we have these concepts, "copies", "limited purposes", "exposing knowingly to the public"…
In Miller, the Court noted that “checks are not confidential communications but negotiable instruments to be used in commercial transactions.” But our data, even though they are becoming a commercial commodity more and more every day, may be still confidential, if we treat them that way.
Our email could be considered copies of a confidential message sent to us, made available to our ISP for the limited purpose of storing it so we can access it later and read it on our private computer. We would then be in charge of storing that private message, in our own hard drive., protected by the Fourth Amendment. Well, what if we use web mail, what if our company is cloud computing? Should users of Outlook be more protected than the ones using, say Gmail?
Friday, April 25, 2008
Ground Breaking New Jersey Decision : Expectation of Privacy in IP address
In a case where a disgruntled employee changed the password and shipping address of her employer, a New Jersey court ruled in New Jersey v. Reid, that, under the New Jersey Constitution, one has an expectation of privacy in our Internet identities, our IP address and screen names. The defendant had changed the password and shipping address of her employer, using his password.
This is a very interesting decision, as American courts do not recognize an expectation of privacy in information held by a third party, and our IP address, screen nameswords.... are known by our Internet providers, and even by the sites we visit.
In Smith v. Maryland, the Supreme Court had held in 1979 that one does not have have expectation of privacy in our bank accounts, as they are held by a third party. However, New Jersey recognizes" a right to what has been called"informational privacy,"" which had been defined as "shorthand for the ability to control the acquisition or release of information about oneself".
But the New Jersey Court held that “citizens have a reasonable expectation of privacy, protected by Article I, Paragraph 7, of the New Jersey Constitution, in the subscriber information they provide to Internet service providers – just as New Jersey citizens have a privacy interest in their bank records stored by banks and telephone billing records kept by phone companies.”
It will be an interesting to see if this case will be the first of many more. EPIC's amicus brief here.
This is a very interesting decision, as American courts do not recognize an expectation of privacy in information held by a third party, and our IP address, screen nameswords.... are known by our Internet providers, and even by the sites we visit.
In Smith v. Maryland, the Supreme Court had held in 1979 that one does not have have expectation of privacy in our bank accounts, as they are held by a third party. However, New Jersey recognizes" a right to what has been called"informational privacy,"" which had been defined as "shorthand for the ability to control the acquisition or release of information about oneself".
But the New Jersey Court held that “citizens have a reasonable expectation of privacy, protected by Article I, Paragraph 7, of the New Jersey Constitution, in the subscriber information they provide to Internet service providers – just as New Jersey citizens have a privacy interest in their bank records stored by banks and telephone billing records kept by phone companies.”
It will be an interesting to see if this case will be the first of many more. EPIC's amicus brief here.
Friday, January 11, 2008
Researching the Internet and Protecting Your Privacy
This article published this week in Le Monde reports about ixquick, a search engine that claim it will protect the confidentiality of our data:
Read on their privacy page:
You have a right to privacy.
Your search data should never fall into the wrong hands.
The only real solution is deleting your data.
We delete our users' privacy data within 48 hrs.
We are the first and only search engine to do so.
Our initiative is receiving an overwhelmingly positive response!
Read on their privacy page:
You have a right to privacy.
Your search data should never fall into the wrong hands.
The only real solution is deleting your data.
We delete our users' privacy data within 48 hrs.
We are the first and only search engine to do so.
Our initiative is receiving an overwhelmingly positive response!
Subscribe to:
Posts (Atom)
Blog Archive
Labels
- ACTA
- Anomymat sur Internet
- Art Law
- Avatars
- Biometry
- blogs
- Book Worm Report
- Censorship
- Cloud Computing
- CNIL
- Compteurs Intelligents
- Contrefaçon
- Cookies
- Copie Privée
- Copyright
- Copyright Fair Use
- Counterfeiting
- Cyberlaw
- Cybersquatting
- Data Breaches
- Data Mining
- Data Privacy
- Database
- Defamation
- Diffamation
- Digital Identity
- DMP
- DNA
- Droit a l'image
- Droit à l'Oubli
- Droit de Réponse
- Droit Moral
- Droits Voisins
- e-commercre
- ECPA
- emails
- Fashion and Copyright
- Fashion and Patents
- Fashion and Trademark
- Fashion News
- FCC
- Fingerprints
- First Amendment
- Flag
- Fourth Amendment
- France
- Freedom of Expression
- Freedom of the Press
- French IP Law
- FTC
- Genetic Privacy
- Google's Book Settlement
- GPS
- Great Britain
- HADOPI
- How to be an Attorney
- HR 5055
- HR 683
- ID cards
- Identité Génétique
- Identity
- Identity Theft
- Indecent Speech
- International Privacy
- Internet of Things
- Internet Privacy
- Internet Security
- IP Address
- Locational Privacy
- LOPPSI 2
- Misc.
- Net Neutrality
- New York Privacy Laws
- New York State
- Online Identity
- Online Impersonation
- Online Privacy
- Pacifica
- Parody
- Passwords
- Patriot Act
- Privacy
- Privacy as a Human Right
- Privacy Breach as a Crime
- privacy in European Union
- Privacy in the EU
- Privacy in the Workplace
- Privacy Settings
- Professions Juridiques
- Propriété Intellectuelle
- Public Domain
- Public Records
- RFID
- Right of Publicity
- RSS
- Safe Harbor
- SCA
- Section 230
- Security Breaches
- Smart Grids
- Social Network
- Sports Law
- Subpoenas
- Surveillance
- Text-Messaging
- The Public Voice
- Three-Strikes
- Thrift Store Tee Shirts
- Trade Dress
- Trademark
- Trademark and Marketing
- Trademark Dilution
- Trademark Fair Use
- Trademark Infringement
- UK
- US Privacy Laws
- Vie Privee
- Virtual Worlds
- Web 2.0
- WHOIS
- Yankees