Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Tuesday, August 10, 2010

European Union Agency for Fundamental Rights: Document on Body Scanners

The European Union Agency for Fundamental Rights published a Q&A document on the use of full body scanners last month.

It addresses the following questions:

1. Which fundamental rights are at risk of being affected by the use of body scanners?

2. Is the use of a body scanner to be considered as processing personal data?

3. How could the requirements on the design and selection of body scanners best respect rules on data protection?

4. How can body scanners be assessed from a rule of law perspective?

5. Are there specific considerations to be taken into account when selecting people to be screened?

6. Should the person to be screened be given the choice between a body scanner and other screening methods?

7. Which information should be given to persons before they choose to be screened by a body scanner?

8. How intrusive are body scanners if compared to other screening methods?

9. Is the detection capability of body scanners an added value regarding security?

10. Which conditions should apply in order to address the concerns related to fundamental rights?

Monday, April 19, 2010

Study: Privacy Not Dead to the Younger Generation

From Yahoo News: A new study coming out of Berkeley and the University of Pennsylvania suggests young people do not care significantly less about privacy than the older generation. Amongst the findings:

• Eighty-eight percent of people of all ages said they have refused to give out information to a business because they thought it was too personal or unnecessary. Among young adults, 82 percent have refused, compared with 85 percent of those over 65.

• Most people — 86 percent — believe that anyone who posts a photo or video of them on the Internet should get their permission first, even if that photo was taken in public. Among young adults 18 to 24, 84 percent agreed — not far from the 90 percent among those 45 to 54.

• Forty percent of adults ages 18 to 24 believe executives should face jail time if their company uses someone's personal information illegally — the same as the response among those 35 to 44 years old.

The sample is big: about 1,000 people, though smaller than the 27,000 the Eurobarometer surveys use (which also record some interesting results on attitudes to privacy). It's interesting to see empirical research on an issue people are all too often happy to accept quite crude generalisations as obvious truths.

I'd also be interested to see work on whether there has been a change in people's attitudes over the last 5-10 years. I have a hunch many young people who didn't care about privacy when they first started using the Internet and social networking sites have become far more conscious of privacy issues as they have become more prominent topics of controversy online and in the wider media.

Tuesday, December 1, 2009

News: US SWIFT Access Granted

From the Lift: The EU has agreed a nine month interim deal to allow the US non reciprocal access to SWIFT banking data. Germany and Austria, reported as threatening a veto over the privacy implications of such a deal, abstained. A unanimous vote was required, not counting abstentions as votes against. The agreement can be annulled in the Spring, when the European Parliament will have to give their assent to the plan.

The Register quotes an EU official as saying that "The truth is that we in Europe don’t have the technical ability to interpret this stuff," and that this is the reason why "We rely on the Americans to process it and pass it on as intelligence." Many European intelligence agencies end up as beneficiaries in the arrangement as they are not permitted by their home countries to gather such information themselves. In the event, delegates were apparantly put under huge pressure from US representatives to pass the deal:

The pressure from the Americans was "massive," say diplomats in Brussels. U.S. Secretary of State Hillary Clinton apparently told her European counterparts that the fate of the West hung in the balance. And in the capital cities of Europe, American ambassadors stormed governments like door-to-door salespeople. As one EU foreign minister put it, "they pulled out all the moral and political stops."

Wednesday, November 18, 2009

News: Swiss take Google Street View to Court

From the Register: Swiss Federal Data Protection and Information Commissioner (FDPIC) Hans-Peter Thur is taking Google Street View to court, unsatisfied with the privacy enhancing blurring Google have offered in the Street View images so far:

Thür's patience has now run out, and his office said in a statement: "In its written response on 14 October 2009, Google for the most part declined to comply with the requests. For these reasons, the FDPIC has decided to take the matter further and to take legal action before the Federal Administrative Court."

AFP notes that Google has insisted it's "absolutely convinced that Swiss View is legal in Switzerland."

News: New Policy on UK DNA Retention

From the Guardian: Police have announced that they are to retain the DNA of those released without charge. Home Office Ministers say they want a 6 year limit (having previously sought a 12 year limit) for retaining profiles. Ministers are also advocating indefinite retention of those arrested on suspicion of terrorism or other national security provisions. Those convicted of any offence remain on the database for life. The Tories say they would implement the Scottish system whereby the profile of those unconvicted of any offence is destroyed on release from prison:

The national DNA database is already the largest in the world, with the profiles of 4.5 million people already recorded. They include 850,000 DNA profiles of people who have never been charged with or convicted of a crime. The need to find a new regime follows a landmark ruling in the S and Marper case by the European court of human rights, which ruled that the Home Office's current regime of "blanket and indefinite" retention of innocent people's DNA was illegal.

News: ICO to Fine Companies £500,000 For Serious Data Breaches

From Panopticon Blog: The Information Commissioner is to get powers to deliver civil penalty notices on a data controller for a serious contravention of the data protection principles if the contravention is:

1) Deliberate or reckless
2) Of a sort that is likely to cause substantial damage or distress

The post makes two criticisms: first, the proposed cap of £500,000, as large as it might seem, compares less favourably with other regulator's powers to fine up to 10% of an organisations turnover. Second, as the government ultimately pays for many of the organisations in question, imposing large fines may have 'a slightly unreal quality to it'.

Comment: What's Worse?

The discussion of the UK plans for the 'Big Brother Database' has me wondering: What's worse, centralised storage of this communications data, or forcing ISPs and Mobile Phone companies to hold on the data for long periods of time?

Clearly this data is incredibly sensitive, and there are good reasons to want to restrict anyone's access to it. But, were such information to be stored, what would be worse? The idea of a centrally held database tends to make for bigger headlines, calling to mind, as it does, the vision of faceless government bureaucrats poring over our intimate secrets.

And the risk of government officials abusing such private information is indeed one of the reasons one would want to restrict access. But it's only one of the reasons. Surely another is the risk of any sort of public disclosure of this information. It is intrusive for anybody I haven't chosen to do so to view information about who I telephone or what websites I visit. But this information tends to be of much more interest to our neighbours, friends and work colleagues and of virtually zero interest to government. In deciding which is worse, one of the matters I think we should consider is which arrangement makes it less likely for some data breach to result in unauthorised access to my data.

Some will point to the many cases where various levels of government have proven hopelessly careless with our information (to the point of accidentally releasing vetting records with details of debt, extra marital affairs, drug use and use of prostitutes). But I don't think we can simplify this to a case of 'private sector good, public sector bad': some of the most notorious cases of releasing private information have been the fault of businesses - just think of the AOL scandal when records of people's searches were released, to remain posted in the internet to this very day. Private companies have a commercial interest in avoiding such scandals, to be sure, but is that any safer than trusting it to government?

Monday, November 9, 2009

News: Resolution on International Privacy Standards Adopted

A resolution for International Standards on the Protection of Personal Data and Privacy was adopted at the 31st International Conference of Data Protection and Privacy Commissioners. A copy of the Resolution is available in Spanish here.

Friday, November 6, 2009

News: Companies Clumsily Disclosing your Info may be Forced to go Public

From The Register: The EC is considering passing new laws that would make it mandatory for organisations which accidentally lose personal data to inform the people concerned and relevant authorities:

Supporters of such schemes say that the fear of public recriminations for data loss will improve companies' performances, while opponents fear that if every breach is revealed the public will become desensitised to the issue of data loss.

News: Romanian Constitutional Court Strikes Down Data Retention Directive

From EDRI: The Romanian Consitutional Court (CCR) has declared the Data Retention Directive incompatible with the Romanian constitution. The case was initiated by a Romanian NGO, the Civil Society Commissariat, who sued its mobile phone company for retaining traffic data according to the new regulations, forcing a CCR ruling on the law's constitutionality:

CCR has accepted the motion for law's unconstitutionality through decision 1258/2009, based on the breach of article 28 of the Romanian Constitution, which stipulates the secrecy of correspondence. Other articles invoked were articles 25, 26 and 30 which deal with freedom of movement, privacy and freedom of expression respectively.

Wednesday, November 4, 2009

Conference News: Madrid Global Privacy Conference & Declaration

I’ve just gotten back from a privacy conference in Madrid titled “Global Privacy Standards for a Global World” which was organized by The Public Voice. One highlight of the conference was the presentation of a Civil Society Declaration calling for the development of international privacy standards — and perhaps most controversially — a moratorium on “the development or implementation of new systems of mass surveillance, including facial recognition, whole body imaging, biometric identifiers, and embedded RFID tags, subject to a full and transparent evaluation by independent authorities and democratic debate." Numerous organizations and individuals have signed the statement (already dubbed “The Madrid Declaration”) and you can, too, by sending an e-mail to privacyATDatos-personalesDOTorg.

Another highlight was an emphatic speech by Stavros Lambrinidis, Vice President of the EU Parliament, declaring that the growing scope of surveillance within the western world is incompatible with democratic society and urging everyone not to simply allow the expanding creep of the level of surveillance to continue unchecked. There is a danger that the ultimate surveillance society will not emerge under a totalitarian regime, he claimed, but rather with citizens’ unreflected “consent.” You can have a look at what else was discussed by calling up the conference agenda here.

One special guest not listed on the program was a representative of Un barrio feliz – a grass-roots movement which has sprung up in opposition to plans to install a system of video surveillance cameras in Madrid’s Lavapiés district. You can view the movement’s blog in Spanish here. One major complaint was that the police have not been forthcoming concerning the plan and the underlying reasons for it. We heard that the local police have cited different grounds for installing camera systems in other neighborhoods (in one case – pick-pocketing, in another – prostitution), and that cameras were needed in Lavapiés because unsavory characters inhabited or frequented the area. The speaker from Un barrio feliz, however, reported that crime statistics indicate that criminal incidents have been decreasing in Lavapiés, making the police’s explanation all the more baffling. Lambrinidis picked up on these examples in his speech to question whether many of the methods of surveillance that have been proposed or implemented could be deemed necessary, proportional, and appropriate in a legal sense.

Monday, October 12, 2009

News: Targeted Billboard Ads Using DVLA Data

From Spyblog: The Mail reports that Castrol, the motor oil company, has been conducting an innovative advertising campaign - they were using giant billboards to display targeted messages directing a particular vehicle to use specified fuel. A typical message you can see in the article reads ' 1 DF L The right oil for your car is: Castrol Magnatec 5W-30 A1'.

The campaign was making novel use of Automatic Number Plate Recognition technology, but the big question is how Castrol has come by the data about the drivers held by Driver and Vehicle Licensing Agency. The DVLA sells the data it holds on 34,000,000 drivers to a number of organisations. The article reports that sources admit that in this case the data was passed on from one of these to a third-party contractor who then themselves sold it in contravention of the ban on using registration numbers for marketing purposes:

Liberal Democrat transport spokesman Norman Baker said: ‘This completely inappropriate and unacceptable behaviour by the DVLA shows how cavalier it is with motorists’ information.
‘They don’t even check what the end use is. It seems all you have to do is ask and the DVLA will give, no matter who you are and for what purpose. It’s outrageous this was allowed to happen.’
The row is a fresh embarrassment for the DVLA and raises new questions about how highly sensitive drivers’ information is handled by the agency.
The Mail on Sunday has previously revealed that the agency was selling motorists’ names and home addresses to convicted criminals. In the past five years the DVLA has earned £15million from selling the names and addresses of more than six million motorists.

Thursday, October 1, 2009

News: Zurich Police Regulations Regarding Surveillance Ruled Unconstitutional

The Swiss Federal Court has ruled that certain amendments to Zurich cantonal police regulations that pertain to surveillance are unconstitutional. According to a story in the Neuer Zürcher Zeitung, provisions concerning both the scope of surveillance and the duration for which surveillance footage might be preserved were among those which the court deemed to be in violation of constitutional protections. The court found that the amendments would permit both plain and covert surveillance throughout all public spaces within the Canton and that this lack of constraint represented an impermissible encroachment upon the freedom and private sphere of citizens. Another provision would have permitted film footage from surveillance activities to be preserved for up to a year or until related investigations had been concluded. According to the NZZ, the court held that the maximum period for preservation of such records is 100 days, thus demonstrating agreement with a decision which had been reached two years earlier in a case from the Canton of St. Gallen.

Friday, September 11, 2009

Comment: Henry Porter on DNA and Certainty

Henry Porter at the Guardian reports on new research that DNA samples can be fabricated. He argues that this severely undermines the argument for mass DNA databases of everybody's DNA:

Police officers in the past have been tempted to "fit up" those they believe guilty of a crime. It is easy to imagine how DNA might, in the future, be manufactured to gain a rock solid conviction against a person who was proving inconvenient to the authorities. We may chose to doubt that this will ever happen but legislators must allow for the possibility. Whatever the advances we celebrate today the actual anniversary of the Jeffrey's discovery – it is vital to absorb that DNA evidence is not fool proof.

Thursday, September 3, 2009

News: Another Case of Intimate Information Lost

From the Register: Repair Management Services of Blackburn lost a laptop computer containing personal details of 37,000 people and information on 1,900 people's driving convictions. The information was stored on an unencrypted laptop and left in an unlocked vehicle, where it was stolen:

"Personal information is valuable," said Sally-anne Poole, head of enforcement and investigations at the ICO. “In this case, it also involved the details of criminal convictions which, if accessed, could potentially result in distress being caused to the individuals concerned."

The trade body has made a written undertaking to the ICO committing it to encrypting machines and to training staff in its information policies and procedures to try to ensure that such an incident is not repeated.

Of course, disclosure of this sort of information has been considerably more significant in some cases than others.

Zurich DETECTER Site Launched

We've set up a few webpages related to the DETECTER project on the University of Zurich's website. The pages provide some information about Work Package 6, contact information for the researchers involved, and will provide a platform for any future publications that may come out in connection with the project. The "homepage" for the site is accessible here.

Tuesday, September 1, 2009

Update: Registered Traveler

FederalComputerWeek reports that two members of the US House of Representatives have urged the TSA not to delete traveller information that is held in the TSA’s database for the Registered Traveler Program, the Central Information Management System (CIMS). The Representatives are concerned that the deletion of the data would hamper the continuation of the program.

I discussed the Registered Traveler Program in a post concerning the CLEAR program last month. Verified Identity Pass, Inc., mentioned in the FederalComputerWeek article, is the parent company of CLEAR.

Monday, August 3, 2009

Lack of Clarity with respect to fate of CLEAR data?

Anita Ramasastry recently wrote an article (Note: at the time of this post, this link no longer pointed to the correct article; until this problem is corrected, you may find the original article here in Google's cache) for FindLaw discussing the imminent demise of CLEAR—a private company which worked in conjunction with the Transportation Security Administration to offer customers less hassle at airport security in exchange for giving up some of their privacy (and payment of an annual membership fee). Perhaps it was inevitable that some enterprising American would develop this kind of business model following the ever increasingly burdensome and inconvenient security measures being imposed at airports subsequent to 9/11. One might question, however, whether the federal government should have allowed it (See also this article for criticism that CLEAR failed to deliver on its “promise”). The business model was made possible by the TSA’s "Registered Traveler" program.

Although CLEAR was not the only provider of such services in the US, it was the most popular with approximately 165,000 members, according to Ramasastry. She reports that members had to provide CLEAR with biometric data in the form of fingerprints and iris scans to participate in the program. This data was then encoded on the member’s CLEAR card, which had to be tendered to bypass the standard security checkpoint lines. Now that CLEAR is going out of business, what will happen to all the personal data they hold, Ramasastry asks: Will it be sold to one or more other companies? Will the TSA claim it? What say does each member have as to what will happen with his or her data?

Unlike the EU, the US doesn’t have any overarching legal instrument that establishes a basic framework for the handling of personal data. And as Ramasastry points out, CLEAR, as a private company is not subject to the same kinds of privacy regulations as government agencies. But should companies that operate in this area not be subject to the same privacy standards as government bodies? Or should the TSA be authorized to intervene to secure personal data on behalf of former customers of CLEAR? An announcement on the CLEAR website reassures customers of its commitment to protect their personally identifiable information. Yet, even assuming CLEAR had a strong corporate privacy policy in place, it’s UNclear how the company will ensure that that policy is upheld if it ends up being liquidated in bankruptcy. Not to mention, former customers may find it difficult if not impossible to seek compensation for any violation of the policy. The website also speaks of TSA/ federal requirements. But, one source has suggested that neither TSA nor the Dept. of Homeland Security have any relevant requirements in place. The TSA website itself states that “all RT [Registered Traveler] service providers were obligated to follow data security standards to continue offering service [following the initial pilot project]. Each service provider's use of data, however, is regulated under its own privacy policy and by its relationship with its customers and sponsoring airport or airline.” (emphasis added) The only data usage requirement that the TSA imposed may have been that “RT service providers . . . use customer data only for purposes of the RT program unless customers expressly opted-in to other uses.”

In the meantime, the other two Registered Traveler operators, FLO, Corp. and Vigilant Solutions, have reportedly also both closed down the special security clearance lanes they operated at US airports.