Tuesday, August 10, 2010
European Union Agency for Fundamental Rights: Document on Body Scanners
It addresses the following questions:
1. Which fundamental rights are at risk of being affected by the use of body scanners?
2. Is the use of a body scanner to be considered as processing personal data?
3. How could the requirements on the design and selection of body scanners best respect rules on data protection?
4. How can body scanners be assessed from a rule of law perspective?
5. Are there specific considerations to be taken into account when selecting people to be screened?
6. Should the person to be screened be given the choice between a body scanner and other screening methods?
7. Which information should be given to persons before they choose to be screened by a body scanner?
8. How intrusive are body scanners if compared to other screening methods?
9. Is the detection capability of body scanners an added value regarding security?
10. Which conditions should apply in order to address the concerns related to fundamental rights?
Monday, April 19, 2010
Study: Privacy Not Dead to the Younger Generation
• Eighty-eight percent of people of all ages said they have refused to give out information to a business because they thought it was too personal or unnecessary. Among young adults, 82 percent have refused, compared with 85 percent of those over 65.
• Most people — 86 percent — believe that anyone who posts a photo or video of them on the Internet should get their permission first, even if that photo was taken in public. Among young adults 18 to 24, 84 percent agreed — not far from the 90 percent among those 45 to 54.
• Forty percent of adults ages 18 to 24 believe executives should face jail time if their company uses someone's personal information illegally — the same as the response among those 35 to 44 years old.
The sample is big: about 1,000 people, though smaller than the 27,000 the Eurobarometer surveys use (which also record some interesting results on attitudes to privacy). It's interesting to see empirical research on an issue people are all too often happy to accept quite crude generalisations as obvious truths.
I'd also be interested to see work on whether there has been a change in people's attitudes over the last 5-10 years. I have a hunch many young people who didn't care about privacy when they first started using the Internet and social networking sites have become far more conscious of privacy issues as they have become more prominent topics of controversy online and in the wider media.
Tuesday, December 1, 2009
News: US SWIFT Access Granted
The Register quotes an EU official as saying that "The truth is that we in Europe don’t have the technical ability to interpret this stuff," and that this is the reason why "We rely on the Americans to process it and pass it on as intelligence." Many European intelligence agencies end up as beneficiaries in the arrangement as they are not permitted by their home countries to gather such information themselves. In the event, delegates were apparantly put under huge pressure from US representatives to pass the deal:
The pressure from the Americans was "massive," say diplomats in Brussels. U.S. Secretary of State Hillary Clinton apparently told her European counterparts that the fate of the West hung in the balance. And in the capital cities of Europe, American ambassadors stormed governments like door-to-door salespeople. As one EU foreign minister put it, "they pulled out all the moral and political stops."
Wednesday, November 18, 2009
News: Swiss take Google Street View to Court
Thür's patience has now run out, and his office said in a statement: "In its written response on 14 October 2009, Google for the most part declined to comply with the requests. For these reasons, the FDPIC has decided to take the matter further and to take legal action before the Federal Administrative Court."
AFP notes that Google has insisted it's "absolutely convinced that Swiss View is legal in Switzerland."
News: New Policy on UK DNA Retention
The national DNA database is already the largest in the world, with the profiles of 4.5 million people already recorded. They include 850,000 DNA profiles of people who have never been charged with or convicted of a crime. The need to find a new regime follows a landmark ruling in the S and Marper case by the European court of human rights, which ruled that the Home Office's current regime of "blanket and indefinite" retention of innocent people's DNA was illegal.
News: ICO to Fine Companies £500,000 For Serious Data Breaches
1) Deliberate or reckless
2) Of a sort that is likely to cause substantial damage or distress
The post makes two criticisms: first, the proposed cap of £500,000, as large as it might seem, compares less favourably with other regulator's powers to fine up to 10% of an organisations turnover. Second, as the government ultimately pays for many of the organisations in question, imposing large fines may have 'a slightly unreal quality to it'.
Comment: What's Worse?
Clearly this data is incredibly sensitive, and there are good reasons to want to restrict anyone's access to it. But, were such information to be stored, what would be worse? The idea of a centrally held database tends to make for bigger headlines, calling to mind, as it does, the vision of faceless government bureaucrats poring over our intimate secrets.
And the risk of government officials abusing such private information is indeed one of the reasons one would want to restrict access. But it's only one of the reasons. Surely another is the risk of any sort of public disclosure of this information. It is intrusive for anybody I haven't chosen to do so to view information about who I telephone or what websites I visit. But this information tends to be of much more interest to our neighbours, friends and work colleagues and of virtually zero interest to government. In deciding which is worse, one of the matters I think we should consider is which arrangement makes it less likely for some data breach to result in unauthorised access to my data.
Some will point to the many cases where various levels of government have proven hopelessly careless with our information (to the point of accidentally releasing vetting records with details of debt, extra marital affairs, drug use and use of prostitutes). But I don't think we can simplify this to a case of 'private sector good, public sector bad': some of the most notorious cases of releasing private information have been the fault of businesses - just think of the AOL scandal when records of people's searches were released, to remain posted in the internet to this very day. Private companies have a commercial interest in avoiding such scandals, to be sure, but is that any safer than trusting it to government?
Monday, November 9, 2009
News: Resolution on International Privacy Standards Adopted
Friday, November 6, 2009
News: Companies Clumsily Disclosing your Info may be Forced to go Public
Supporters of such schemes say that the fear of public recriminations for data loss will improve companies' performances, while opponents fear that if every breach is revealed the public will become desensitised to the issue of data loss.
News: Romanian Constitutional Court Strikes Down Data Retention Directive
CCR has accepted the motion for law's unconstitutionality through decision 1258/2009, based on the breach of article 28 of the Romanian Constitution, which stipulates the secrecy of correspondence. Other articles invoked were articles 25, 26 and 30 which deal with freedom of movement, privacy and freedom of expression respectively.
Wednesday, November 4, 2009
Conference News: Madrid Global Privacy Conference & Declaration
Another highlight was an emphatic speech by Stavros Lambrinidis, Vice President of the EU Parliament, declaring that the growing scope of surveillance within the western world is incompatible with democratic society and urging everyone not to simply allow the expanding creep of the level of surveillance to continue unchecked. There is a danger that the ultimate surveillance society will not emerge under a totalitarian regime, he claimed, but rather with citizens’ unreflected “consent.” You can have a look at what else was discussed by calling up the conference agenda here.
One special guest not listed on the program was a representative of Un barrio feliz – a grass-roots movement which has sprung up in opposition to plans to install a system of video surveillance cameras in Madrid’s Lavapiés district. You can view the movement’s blog in Spanish here. One major complaint was that the police have not been forthcoming concerning the plan and the underlying reasons for it. We heard that the local police have cited different grounds for installing camera systems in other neighborhoods (in one case – pick-pocketing, in another – prostitution), and that cameras were needed in Lavapiés because unsavory characters inhabited or frequented the area. The speaker from Un barrio feliz, however, reported that crime statistics indicate that criminal incidents have been decreasing in Lavapiés, making the police’s explanation all the more baffling. Lambrinidis picked up on these examples in his speech to question whether many of the methods of surveillance that have been proposed or implemented could be deemed necessary, proportional, and appropriate in a legal sense.
Monday, October 12, 2009
News: Targeted Billboard Ads Using DVLA Data
The campaign was making novel use of Automatic Number Plate Recognition technology, but the big question is how Castrol has come by the data about the drivers held by Driver and Vehicle Licensing Agency. The DVLA sells the data it holds on 34,000,000 drivers to a number of organisations. The article reports that sources admit that in this case the data was passed on from one of these to a third-party contractor who then themselves sold it in contravention of the ban on using registration numbers for marketing purposes:
Liberal Democrat transport spokesman Norman Baker said: ‘This completely inappropriate and unacceptable behaviour by the DVLA shows how cavalier it is with motorists’ information.
‘They don’t even check what the end use is. It seems all you have to do is ask and the DVLA will give, no matter who you are and for what purpose. It’s outrageous this was allowed to happen.’
The row is a fresh embarrassment for the DVLA and raises new questions about how highly sensitive drivers’ information is handled by the agency.
The Mail on Sunday has previously revealed that the agency was selling motorists’ names and home addresses to convicted criminals. In the past five years the DVLA has earned £15million from selling the names and addresses of more than six million motorists.
Thursday, October 1, 2009
News: Zurich Police Regulations Regarding Surveillance Ruled Unconstitutional
Friday, September 11, 2009
Comment: Henry Porter on DNA and Certainty
Police officers in the past have been tempted to "fit up" those they believe guilty of a crime. It is easy to imagine how DNA might, in the future, be manufactured to gain a rock solid conviction against a person who was proving inconvenient to the authorities. We may chose to doubt that this will ever happen but legislators must allow for the possibility. Whatever the advances we celebrate today the actual anniversary of the Jeffrey's discovery – it is vital to absorb that DNA evidence is not fool proof.
Thursday, September 3, 2009
News: Another Case of Intimate Information Lost
Of course, disclosure of this sort of information has been considerably more significant in some cases than others."Personal information is valuable," said Sally-anne Poole, head of enforcement and investigations at the ICO. “In this case, it also involved the details of criminal convictions which, if accessed, could potentially result in distress being caused to the individuals concerned."
The trade body has made a written undertaking to the ICO committing it to encrypting machines and to training staff in its information policies and procedures to try to ensure that such an incident is not repeated.
Zurich DETECTER Site Launched
Tuesday, September 1, 2009
Update: Registered Traveler
I discussed the Registered Traveler Program in a post concerning the CLEAR program last month. Verified Identity Pass, Inc., mentioned in the FederalComputerWeek article, is the parent company of CLEAR.
Monday, August 3, 2009
Lack of Clarity with respect to fate of CLEAR data?
Although CLEAR was not the only provider of such services in the US, it was the most popular with approximately 165,000 members, according to Ramasastry. She reports that members had to provide CLEAR with biometric data in the form of fingerprints and iris scans to participate in the program. This data was then encoded on the member’s CLEAR card, which had to be tendered to bypass the standard security checkpoint lines. Now that CLEAR is going out of business, what will happen to all the personal data they hold, Ramasastry asks: Will it be sold to one or more other companies? Will the TSA claim it? What say does each member have as to what will happen with his or her data?
Unlike the EU, the US doesn’t have any overarching legal instrument that establishes a basic framework for the handling of personal data. And as Ramasastry points out, CLEAR, as a private company is not subject to the same kinds of privacy regulations as government agencies. But should companies that operate in this area not be subject to the same privacy standards as government bodies? Or should the TSA be authorized to intervene to secure personal data on behalf of former customers of CLEAR? An announcement on the CLEAR website reassures customers of its commitment to protect their personally identifiable information. Yet, even assuming CLEAR had a strong corporate privacy policy in place, it’s UNclear how the company will ensure that that policy is upheld if it ends up being liquidated in bankruptcy. Not to mention, former customers may find it difficult if not impossible to seek compensation for any violation of the policy. The website also speaks of TSA/ federal requirements. But, one source has suggested that neither TSA nor the Dept. of Homeland Security have any relevant requirements in place. The TSA website itself states that “all RT [Registered Traveler] service providers were obligated to follow data security standards to continue offering service [following the initial pilot project]. Each service provider's use of data, however, is regulated under its own privacy policy and by its relationship with its customers and sponsoring airport or airline.” (emphasis added) The only data usage requirement that the TSA imposed may have been that “RT service providers . . . use customer data only for purposes of the RT program unless customers expressly opted-in to other uses.”
In the meantime, the other two Registered Traveler operators, FLO, Corp. and Vigilant Solutions, have reportedly also both closed down the special security clearance lanes they operated at US airports.