France’s Assemblée Nationale believes that some issues still need to be resolved regarding the Proposal for a Council Framework Decision of November 6, 2007 on the use of Passenger Name Record (PNR) for law enforcement purposes, COM(2007) 654.
Among the issues that still need to be debated and resolved, according to the French representatives, are:
- Full respect for fundamental rights, including the right to privacy and the right to data protection, which must be respected at every step of the collection and processing of data;
- Data conservation must be reduced to a reasonable period, that is, between three and six years;
- Sensitive data must be subject to specific safeguards, regardless of whether it will be ultimately decided whether or not they can be used, partially or totally, in pending investigations or prosecutions;
- Stricter rules should be obtained regarding data transfers to third countries, so that a Member State cannot be a source of leakage of masses of raw data to a third State.
RE: Cyberlaw, IP, rivacy in the USA and Europe NB: This site is 100% legal-advice free.
Showing posts with label Database. Show all posts
Showing posts with label Database. Show all posts
Monday, October 19, 2009
Wednesday, October 14, 2009
Tracking Abortions in Oklahoma
H.B. 1595 was signed into law by the governor of Oklahoma on May 21, 2009, and will become effective on November 1, 2009. It prohibits abortions based only on the sex of the child, and it also creates the Statistical Reporting of Abortion Act, which will be codified as Section 1-738a of Title 63 of the Oklahoma Statutes.
The Oklahoma State Department of Health must make available on its ‘stable’ Internet website, by March 1, 2011, an Individual Abortion Form, that physicians will have to use in order to submit electronically the reports required by the Statistical Reporting of Abortion Act.
The ‘Stable Internet website’ is defined by the law as a website that, to the extent reasonably practicable, is safeguarded from having its content altered other than by the State Department of Health.
To the extent reasonably practicable? I could not find a definition of that rather vague notion in the Act. But no need to worry, because The Department shall take all necessary precautions to ensure the security of the electronically submitted reports so that the data they include is able to be accessed only by specially authorized departmental personnel during and following the process of transmission.
So necessary precautions must be taken, but only to an extent that is reasonably practicable? Who will represent this standard of reason? Patients concerned about their privacy, or the government concerned about keeping costs down, or with a particular political agenda?
Pursuant to a subsection of the law that shall become operative no later of April 1, 2011, or thirty calendar days following the date on which the State Department of Health will post the Individual Abortion Form on its web site:
Any physician performing abortions shall fully complete and submit, electronically, an Individual Abortion Form to the State Department of Health by the last business day of the calendar month following the month in which the physician performs an abortion, for
each abortion the physician performs.
The Department shall post the required Individual Abortion Form on its stable Internet website. Nothing in the Individual Abortion Form shall contain the name, address, or information specifically identifying any patient.
This is interesting. The Oklahoma Legislature seems to believe that not providing the name or the address of the women who received an abortion in the state is sufficient in ensuring that their anonymity is protected. Identity is, however, a much more complex concept, and one’s name and address are only two of its multiple components. The government understands this, since the American passport also contains our DOB and photograph. The French passport adds to this information the fingerprints of the bearer.
What defines our identity? I like what Stan Karas wrote in an article : “… modernity has transformed individuals from complete subjects to a collection of subjectivities. [Stan Karas: Privacy, Identity, Databases, 52 Am. U.L. Rev. 393 428 (2002)]
Yet a collection of subjectivities is what the law requires the physicians to provide on the web form, even though the law states that nothing in the form shall contain any information specifically identifying any patient.
What is the information that the physician will have to provide on the Individual Abortion Form? Here are the first eight items:
1. Date of abortion
2. County in which abortion performed
3. Age of mother
4. Marital status of mother
(married, divorced, separated, widowed, or never married)
5. Race of mother
6. Years of education of mother
(specify highest year completed)
7. State or foreign country of residence of mother
8. Total number of previous pregnancies of the mother
This information may not be enough to identify a woman living in New York county (Manhattan), but could be enough to identify a woman living in a sparsely populated county, especially if the woman’s race (I would rather use the term ethnic background though), or educational level, are not common in the area. In other words, if you are, say, a Native-American with a PhD, obtained at the age of 22, an achievement featured in the local paper, your name and address can be deducted easily from these facts, so the form may indeed contain information specifically identifying the patient.
The Oklahoma State Department of Health must make available on its ‘stable’ Internet website, by March 1, 2011, an Individual Abortion Form, that physicians will have to use in order to submit electronically the reports required by the Statistical Reporting of Abortion Act.
The ‘Stable Internet website’ is defined by the law as a website that, to the extent reasonably practicable, is safeguarded from having its content altered other than by the State Department of Health.
To the extent reasonably practicable? I could not find a definition of that rather vague notion in the Act. But no need to worry, because The Department shall take all necessary precautions to ensure the security of the electronically submitted reports so that the data they include is able to be accessed only by specially authorized departmental personnel during and following the process of transmission.
So necessary precautions must be taken, but only to an extent that is reasonably practicable? Who will represent this standard of reason? Patients concerned about their privacy, or the government concerned about keeping costs down, or with a particular political agenda?
Pursuant to a subsection of the law that shall become operative no later of April 1, 2011, or thirty calendar days following the date on which the State Department of Health will post the Individual Abortion Form on its web site:
Any physician performing abortions shall fully complete and submit, electronically, an Individual Abortion Form to the State Department of Health by the last business day of the calendar month following the month in which the physician performs an abortion, for
each abortion the physician performs.
The Department shall post the required Individual Abortion Form on its stable Internet website. Nothing in the Individual Abortion Form shall contain the name, address, or information specifically identifying any patient.
This is interesting. The Oklahoma Legislature seems to believe that not providing the name or the address of the women who received an abortion in the state is sufficient in ensuring that their anonymity is protected. Identity is, however, a much more complex concept, and one’s name and address are only two of its multiple components. The government understands this, since the American passport also contains our DOB and photograph. The French passport adds to this information the fingerprints of the bearer.
What defines our identity? I like what Stan Karas wrote in an article : “… modernity has transformed individuals from complete subjects to a collection of subjectivities. [Stan Karas: Privacy, Identity, Databases, 52 Am. U.L. Rev. 393 428 (2002)]
Yet a collection of subjectivities is what the law requires the physicians to provide on the web form, even though the law states that nothing in the form shall contain any information specifically identifying any patient.
What is the information that the physician will have to provide on the Individual Abortion Form? Here are the first eight items:
1. Date of abortion
2. County in which abortion performed
3. Age of mother
4. Marital status of mother
(married, divorced, separated, widowed, or never married)
5. Race of mother
6. Years of education of mother
(specify highest year completed)
7. State or foreign country of residence of mother
8. Total number of previous pregnancies of the mother
This information may not be enough to identify a woman living in New York county (Manhattan), but could be enough to identify a woman living in a sparsely populated county, especially if the woman’s race (I would rather use the term ethnic background though), or educational level, are not common in the area. In other words, if you are, say, a Native-American with a PhD, obtained at the age of 22, an achievement featured in the local paper, your name and address can be deducted easily from these facts, so the form may indeed contain information specifically identifying the patient.
Thursday, September 24, 2009
Government Use of Private Databases
Via Wired.com, an article on the FBI's National Security Branch Analysis Center (NSAC) database, which, according to declassified documents obtained by Wired, contains than 1.5 billion government and private-sector records about citizens and foreigners, ans is thus becoming the “Total Information Awareness” the government wanted to put in place after 9/11.
The government thought then of data mining private databases for national security reasons. The New York Times had reported in February 2002 that the Pentagon, under the leadership of Vice Admiral John Poindexter, was building a computer able to collect and data mine personal data, such as credit card records, school, travel and medical records, in order to track terrorists. The name of the program, Total Information Awareness, was later changed to Terrorism Information Awareness. Congress eliminated funding for the program in 2003.
TIA was followed by “The Matrix,” a data mining program linking government and commercial databases. Government agencies have also required in the past the assistance of telecommunication carriers to eavesdrop on suspect’s emails. The FBI’s CARNIVORE program plugs, (or plugged,) a computer (the DCS-1000) directly to an ISPs’ network to monitor suspect incoming and outgoing emails. ECHELON was a program eavesdropping on international private telephone calls, e-mails and faxes, using both ground and satellites.
Data mining, or Knowledge Discovery in Databases (KDD) is the process that allows experts to extract trends and patterns from data, using algorithms to identify relationships and patterns in data. There are two main data mining methods. The top-down method looks for a well-defined profile by asking questions and testing hypotheses. The bottom-up method analyzes raw data to find trends and groups.
Is data mining such an extensive amount of information an efficient method to increase security? This is an important question as citizens are asked to trade off some of their liberties for security, or at least for a renewed sense of security, and would be more reluctant to do so for a program efective in preventing terrorist attacks. Former Homeland Security Secretary Michael Chertoff believed in the ability of data mining to prevent terrorism. While an assistant attorney general, he testified in 2002 that he found data mining a promising way to fight terrorism. He further testified that the Department of Justice was “using computers to analyze information obtained in the course of criminal investigations, to uncover patterns of behavior.(…) Through what has come to be called ‘data mining’ and predictive technology, we seek to identify other potential terrorists and terrorism financing networks.”
Even some privacy advocates believe that the use of commercial databases can “help improve the amount and quality of identifying information in watch lists.” However, most of them do not believe that such massive data mining would protect us against terrorist attacks, and is not fail-proof. The Wired article quotes Kurt Opsahl, an EFF senior attorney: “We have a situation where the government is spending fairly large sums of money to use an unproven technology that has a possibility of false positives that would subject innocent Americans to unnecessary scrutiny and impinge on their freedom.”
The efficiency of a method should not be the ultimate test used to establish an opinion about government surveillance. But if we may have a high surveillance tolerance, we certainly have a zero tolerance for being arrested by mistake, or prevented to board an airplane.
The government thought then of data mining private databases for national security reasons. The New York Times had reported in February 2002 that the Pentagon, under the leadership of Vice Admiral John Poindexter, was building a computer able to collect and data mine personal data, such as credit card records, school, travel and medical records, in order to track terrorists. The name of the program, Total Information Awareness, was later changed to Terrorism Information Awareness. Congress eliminated funding for the program in 2003.
TIA was followed by “The Matrix,” a data mining program linking government and commercial databases. Government agencies have also required in the past the assistance of telecommunication carriers to eavesdrop on suspect’s emails. The FBI’s CARNIVORE program plugs, (or plugged,) a computer (the DCS-1000) directly to an ISPs’ network to monitor suspect incoming and outgoing emails. ECHELON was a program eavesdropping on international private telephone calls, e-mails and faxes, using both ground and satellites.
Data mining, or Knowledge Discovery in Databases (KDD) is the process that allows experts to extract trends and patterns from data, using algorithms to identify relationships and patterns in data. There are two main data mining methods. The top-down method looks for a well-defined profile by asking questions and testing hypotheses. The bottom-up method analyzes raw data to find trends and groups.
Is data mining such an extensive amount of information an efficient method to increase security? This is an important question as citizens are asked to trade off some of their liberties for security, or at least for a renewed sense of security, and would be more reluctant to do so for a program efective in preventing terrorist attacks. Former Homeland Security Secretary Michael Chertoff believed in the ability of data mining to prevent terrorism. While an assistant attorney general, he testified in 2002 that he found data mining a promising way to fight terrorism. He further testified that the Department of Justice was “using computers to analyze information obtained in the course of criminal investigations, to uncover patterns of behavior.(…) Through what has come to be called ‘data mining’ and predictive technology, we seek to identify other potential terrorists and terrorism financing networks.”
Even some privacy advocates believe that the use of commercial databases can “help improve the amount and quality of identifying information in watch lists.” However, most of them do not believe that such massive data mining would protect us against terrorist attacks, and is not fail-proof. The Wired article quotes Kurt Opsahl, an EFF senior attorney: “We have a situation where the government is spending fairly large sums of money to use an unproven technology that has a possibility of false positives that would subject innocent Americans to unnecessary scrutiny and impinge on their freedom.”
The efficiency of a method should not be the ultimate test used to establish an opinion about government surveillance. But if we may have a high surveillance tolerance, we certainly have a zero tolerance for being arrested by mistake, or prevented to board an airplane.
Labels:
Data Mining,
Data Privacy,
Database,
Patriot Act
Monday, September 21, 2009
ADN & Présomption d'Innocence
Le Monde parlait samedi de la multiplication des procès pour refus de prélèvement d’ADN. Selon le Monde, il a eu 245 condamnations en 2004, et 519 en 2005. Le nombre de personnes fichées étonne : 40 000 personnes ont été fichées en 2004, 806 356 personnes au 1er octobre 2008.
Rappelons la loi. Le Fichier National Automatisé des Empreintes Génétiques (FNAEG) a été créé par la loi du 17 juin 1998 relative à la prévention et à la répression des infractions sexuelles. Ce fichier, commun à la police et à la gendarmerie, contient les traces génétiques de suspects, qu’ils soient identifiés ou non, et les couplent, si ces informations sont connues, à différentes informations telles que le nom, prénoms, date et lieu de naissance, filiation et sexe de la personne. Selon l'article 706-54 du Code pénal, "Les empreintes génétiques des personnes à l'encontre desquelles il existe des indices graves ou concordants rendant vraisemblable qu'elles aient commis l'une des infractions mentionnées à l'article 706-55 sont également conservées dans ce fichier sur décision d'un officier de police judiciaire agissant soit d'office, soit à la demande du procureur de la République ou du juge d'instruction". L'article 706-55 du Code pénal précise les infractions pouvant donner lieu à inscription au fichier.
Selon le commissaire principal Bernard Manzoni, cité dans l’article du Monde, le fichier est « un outil efficace » pour la police. N’en doutons pas.
De même, le fichier que le gouvernement britannique se propose de créer afin de lutter contre la pédophilie serait, n’en doutons pas, un moyen de prévention efficace contre la pédophilie et les mauvais traitements. Est-ce une raison suffisante pour le mettre en place ? Désormais, les personnes souhaitant encadrer ou s’occuper d’enfants, ou d’adultes vulnérables, même si c’est seulement une fois par mois, devront s’inscrire sur le fichier de l’Independant Safeguarding Authority (ISA). Cette inscription leur coûtera 64 livres sterlings, et leur permettra de prouver qu’ils ne sont pas des pédophiles.
Si seules les empreintes génétiques "des personnes à l'encontre desquelles il existe des indices graves ou concordants rendant vraisemblable qu'elles aient commis l'une des infractions mentionnées à l'article 706-55" et celles des personnes condamnées pour l'une des infractions mentionnées à l'article 706-55 sont inscrites sur le fichier de la FNAEG, même des personnes innocentes de tout crime, qui ne sont nullement soupçonnées, dont le seul dessein est de s’occuper et d’encadrer des enfants, par exemple, en les cherchant de temps en temps à l'école, afin d’aider une voisine surmenée par exemple, devront s’y inscrire.
Le risque que ces fichiers soient utilisés en dehors de leur but premier est réel. L’ADN est une donnée biométrique dont l’analyse permet de dévoiler toutes sortes de renseignements sur la personne, beaucoup plus que ne le peuvent les empreintes digitales. Ainsi, selon l’AFP (29 mai 2008), des magistrats français auraient ordonné en 2008 des tests ADN à un laboratoire privé, afin de déterminer l’origine ethnique de suspects.
De plus, si des bases de données telles que celle de l’ISA devaient se multiplier, la présomption d’innocence dont nous bénéficions serait mise en danger. Les parents qui ne s’enregistreront pas sur la base de donnés de l’ISA seront poursuivis en justice. Cela veut dire qu’une personne complètement innocente, dont l’unique dessein était de participer à la vie communautaire et d’aider un voisin, une amie ou une école en encadrant sporadiquement des enfants, et qui aurait omis de prouver son innocence, alors qu’elle n’est accusée d’aucun crime, pourrait se voir sanctionnée par la justice pour défaut de preuve d’innocence…
Rappelons la loi. Le Fichier National Automatisé des Empreintes Génétiques (FNAEG) a été créé par la loi du 17 juin 1998 relative à la prévention et à la répression des infractions sexuelles. Ce fichier, commun à la police et à la gendarmerie, contient les traces génétiques de suspects, qu’ils soient identifiés ou non, et les couplent, si ces informations sont connues, à différentes informations telles que le nom, prénoms, date et lieu de naissance, filiation et sexe de la personne. Selon l'article 706-54 du Code pénal, "Les empreintes génétiques des personnes à l'encontre desquelles il existe des indices graves ou concordants rendant vraisemblable qu'elles aient commis l'une des infractions mentionnées à l'article 706-55 sont également conservées dans ce fichier sur décision d'un officier de police judiciaire agissant soit d'office, soit à la demande du procureur de la République ou du juge d'instruction". L'article 706-55 du Code pénal précise les infractions pouvant donner lieu à inscription au fichier.
Selon le commissaire principal Bernard Manzoni, cité dans l’article du Monde, le fichier est « un outil efficace » pour la police. N’en doutons pas.
De même, le fichier que le gouvernement britannique se propose de créer afin de lutter contre la pédophilie serait, n’en doutons pas, un moyen de prévention efficace contre la pédophilie et les mauvais traitements. Est-ce une raison suffisante pour le mettre en place ? Désormais, les personnes souhaitant encadrer ou s’occuper d’enfants, ou d’adultes vulnérables, même si c’est seulement une fois par mois, devront s’inscrire sur le fichier de l’Independant Safeguarding Authority (ISA). Cette inscription leur coûtera 64 livres sterlings, et leur permettra de prouver qu’ils ne sont pas des pédophiles.
Si seules les empreintes génétiques "des personnes à l'encontre desquelles il existe des indices graves ou concordants rendant vraisemblable qu'elles aient commis l'une des infractions mentionnées à l'article 706-55" et celles des personnes condamnées pour l'une des infractions mentionnées à l'article 706-55 sont inscrites sur le fichier de la FNAEG, même des personnes innocentes de tout crime, qui ne sont nullement soupçonnées, dont le seul dessein est de s’occuper et d’encadrer des enfants, par exemple, en les cherchant de temps en temps à l'école, afin d’aider une voisine surmenée par exemple, devront s’y inscrire.
Le risque que ces fichiers soient utilisés en dehors de leur but premier est réel. L’ADN est une donnée biométrique dont l’analyse permet de dévoiler toutes sortes de renseignements sur la personne, beaucoup plus que ne le peuvent les empreintes digitales. Ainsi, selon l’AFP (29 mai 2008), des magistrats français auraient ordonné en 2008 des tests ADN à un laboratoire privé, afin de déterminer l’origine ethnique de suspects.
De plus, si des bases de données telles que celle de l’ISA devaient se multiplier, la présomption d’innocence dont nous bénéficions serait mise en danger. Les parents qui ne s’enregistreront pas sur la base de donnés de l’ISA seront poursuivis en justice. Cela veut dire qu’une personne complètement innocente, dont l’unique dessein était de participer à la vie communautaire et d’aider un voisin, une amie ou une école en encadrant sporadiquement des enfants, et qui aurait omis de prouver son innocence, alors qu’elle n’est accusée d’aucun crime, pourrait se voir sanctionnée par la justice pour défaut de preuve d’innocence…
Wednesday, December 10, 2008
ADN et Droits de l’Homme
La Cour Européenne des Droits de l’Homme vient de décider que la conservation systématique par le Royaume-Uni de l’ADN, d’échantillons cellulaires et des empreintes digitales de suspects, est contraire à l’article 8 de la Déclaration des Droits de l’Homme.
La Cour a conclu à l’unanimité à la violation de l ‘article 8 protégeant le droit au respect à la vie privée et familiale. Les échantillons cellulaires contiennent des informations sensibles, notamment sur la santé d’un individu. En outre, il est possible, grâce à l’ADN d’un individu, d’ obtenir des informations sur le code génétique de sa famille. C'est pourquoi la conservation de telles données constitue une atteinte au droit au respect de la vie privée des individus. Voir aussi ici.
La Cour a conclu à l’unanimité à la violation de l ‘article 8 protégeant le droit au respect à la vie privée et familiale. Les échantillons cellulaires contiennent des informations sensibles, notamment sur la santé d’un individu. En outre, il est possible, grâce à l’ADN d’un individu, d’ obtenir des informations sur le code génétique de sa famille. C'est pourquoi la conservation de telles données constitue une atteinte au droit au respect de la vie privée des individus. Voir aussi ici.
Wednesday, August 27, 2008
Sign against Edvige
Edvige is the lovely name of the not-so-lovely new French police database. The June 27 2008 law, was published in the French"Journal Officiel" on July 1st, thanks to the CNIL, even though the government had not wished it to be published. Instead, it was published at a very quiet time of the year, during the vacances...
The French police is not entitled to gather personal data on individuals who have reached their 13th birthday, and who are likely to upset public order (susceptibles de porter atteinte à l'ordre public). Data thus gathered can be, of course, their names, addresses, and photographs, but also their tax reports, the names of the persons they associated with. Data regarding their health and sexuality can be gathered "exceptionally", but the law does not say how the police is supposed to evaluate the exceptional that measure must be.
Thanks to the CNIL, the database will not be connected with others. Imagine a banker trying to figure out whether to extend a credit denying it because he has access to his health data, or discover that his client was arrested ten years ago for smoking a Gauloise inside a bar?
The press had informed the French citizens about that new law, but it has not succeeded creating the uproar necessary to withdraw it. The petition is here.
The French police is not entitled to gather personal data on individuals who have reached their 13th birthday, and who are likely to upset public order (susceptibles de porter atteinte à l'ordre public). Data thus gathered can be, of course, their names, addresses, and photographs, but also their tax reports, the names of the persons they associated with. Data regarding their health and sexuality can be gathered "exceptionally", but the law does not say how the police is supposed to evaluate the exceptional that measure must be.
Thanks to the CNIL, the database will not be connected with others. Imagine a banker trying to figure out whether to extend a credit denying it because he has access to his health data, or discover that his client was arrested ten years ago for smoking a Gauloise inside a bar?
The press had informed the French citizens about that new law, but it has not succeeded creating the uproar necessary to withdraw it. The petition is here.
Subscribe to:
Posts (Atom)
Blog Archive
Labels
- ACTA
- Anomymat sur Internet
- Art Law
- Avatars
- Biometry
- blogs
- Book Worm Report
- Censorship
- Cloud Computing
- CNIL
- Compteurs Intelligents
- Contrefaçon
- Cookies
- Copie Privée
- Copyright
- Copyright Fair Use
- Counterfeiting
- Cyberlaw
- Cybersquatting
- Data Breaches
- Data Mining
- Data Privacy
- Database
- Defamation
- Diffamation
- Digital Identity
- DMP
- DNA
- Droit a l'image
- Droit à l'Oubli
- Droit de Réponse
- Droit Moral
- Droits Voisins
- e-commercre
- ECPA
- emails
- Fashion and Copyright
- Fashion and Patents
- Fashion and Trademark
- Fashion News
- FCC
- Fingerprints
- First Amendment
- Flag
- Fourth Amendment
- France
- Freedom of Expression
- Freedom of the Press
- French IP Law
- FTC
- Genetic Privacy
- Google's Book Settlement
- GPS
- Great Britain
- HADOPI
- How to be an Attorney
- HR 5055
- HR 683
- ID cards
- Identité Génétique
- Identity
- Identity Theft
- Indecent Speech
- International Privacy
- Internet of Things
- Internet Privacy
- Internet Security
- IP Address
- Locational Privacy
- LOPPSI 2
- Misc.
- Net Neutrality
- New York Privacy Laws
- New York State
- Online Identity
- Online Impersonation
- Online Privacy
- Pacifica
- Parody
- Passwords
- Patriot Act
- Privacy
- Privacy as a Human Right
- Privacy Breach as a Crime
- privacy in European Union
- Privacy in the EU
- Privacy in the Workplace
- Privacy Settings
- Professions Juridiques
- Propriété Intellectuelle
- Public Domain
- Public Records
- RFID
- Right of Publicity
- RSS
- Safe Harbor
- SCA
- Section 230
- Security Breaches
- Smart Grids
- Social Network
- Sports Law
- Subpoenas
- Surveillance
- Text-Messaging
- The Public Voice
- Three-Strikes
- Thrift Store Tee Shirts
- Trade Dress
- Trademark
- Trademark and Marketing
- Trademark Dilution
- Trademark Fair Use
- Trademark Infringement
- UK
- US Privacy Laws
- Vie Privee
- Virtual Worlds
- Web 2.0
- WHOIS
- Yankees