Showing posts with label data privacy. Show all posts
Showing posts with label data privacy. Show all posts

Monday, September 14, 2009

Nilekani acknowledges security and privacy concerns over the UID [India - Data Protection/Privacy]

Nandan Nilekani conceded that there are “legitimate” apprehensions over the proposed Unique Identification Number database’s being vulnerable to hacking and misuse. He said that given the inclusivity, enormous opportunity and developmental benefits it will provide, Unique Identification Database (UID) project is worth the risks.
Mr. Nilekani, the chairman of Unique Identification Authority of India told Karan Thapar on CNN-IBN’s Devil’s Advocate program that the project had so many significant benefits for the poor in making it inclusive and in giving them a chance to participate in the country’s progress.To question on the possibility of the database being hacked, he said that they would have to design it as foolproof as possible by incorporating checks and balances. After saying “in every system, there will be people who will try to hack on it,” he asked if the security risks it involves are enough to do away with the project.
Responding to a question about the worthiness of spending an amount as huge as Rs 1.5 lakh crore in a country where 80 per cent of the population live under Rs 20 a day, Mr Nilkani rejected the estimation although he couldn’t spell out the exact amount. “Whatever the cost be, the social, economic and efficiency benefits of it would make it well worth it,” he said. The investment in this project would actually make all those other money be spent on education, health for women and children and sanitation programmes more efficiently. When asked whether the project will be helpful in solving the irregularities relating to the allotment of BPL cards as it can’t identify those who should have BPL cards and do not, replied that UID is not a panacea for all the problems but an enabler of more effective public delivery.

Wednesday, August 26, 2009

French Data Protection Authority Issues Guidelines on Personal Data Transfers Pursuant to U.S. Discovery Obligations [France]

On August 19, 2009, the Official Journal published guidelines issued by the French Data Protection Authority (Commission nationale de l’informatique et des libertés (the “CNIL”)) regarding transfers of personal data carried out in the context of U.S. discovery proceedings (the “Guidelines”). The CNIL’s publication comes in the wake of a recent increase in the volume of requests made to French-based companies involved in U.S. litigation to disclose information or documents for the purposes of civil pre-trial discovery.

According to the Guidelines, disclosure of personal data pursuant to foreign court proceedings must comply with applicable laws and treaties ratified by France, including the Hague Convention of March 19, 1970, which enables a contracting State to declare that it will not execute letters of request issued for the purpose of obtaining pre-trial discovery. In France, any judge receiving a letter of request from a foreign authority must verify that such a request is admissible under French law and, in particular, must refuse the request if it poses a threat to State sovereignty or security. In this respect, a French blocking statute (the July 27, 1968 Act) prohibits disclosure of any information of economic, commercial, industrial, financial or technical nature as part of foreign legal proceedings unless the disclosure complies with applicable treaties and laws. Any breach of this statute is punishable by imprisonment of six months and a fine of €18,000.
In addition, companies based in France that disclose documents containing personal data must also comply with the requirements of the French Data Protection Act of January 6, 1978, or risk heavy criminal sanctions for failing to do so. Data controllers are not required to file a specific “discovery” notification as long as their data processing activities have been regularly filed with the CNIL. Nevertheless, there must be a legal basis for any transfer of personal data to the U.S., and companies must notify the CNIL of such transfers. In some cases, the data controller may rely on the “establishment, exercise or defense of a legal claim” exception contained in Article 69.3 of the French Data Protection Act as a legal basis for a single and limited transfer of all relevant information relating to a particular litigation. Otherwise, the CNIL’s authorization is required for sizeable and frequent transfers of personal data that are based on an adequate safeguard (i.e., Safe Harbor, model clauses or binding corporate rules). Further, adequate safeguards must be put in place to cover onward transfers, such as when transferred data being stored in the U.S. are further disclosed to a judicial authority (i.e., court order) or to other third parties (e.g., model clauses or a letter of engagement to abide by the Safe Harbor principles).
More information on these Guidelines can be found (in French) at www.legifrance.gouv.fr

Friday, March 27, 2009

Advocacy group: UK databases illegal

An advocacy group says almost a quarter of British government databases are illegal under human rights or data privacy laws. The Joseph Rowntree Reform Trust said on Monday that 11 out of 46 major government databases breach laws intended to protect personal details of British citizens.

Britain uses databases to store information including DNA profiles, biographical details of all children, hospital records and details of welfare payments. The country's justice ministry says the trust's report offers no evidence that laws have been breached, or that the government's policy is flawed.
The trust says it has identified problems with a further 29 British databases. It says only 6 databases are both necessary and legal.

Facebook Aims for Privacy Compliance with New Public Policy Hire [International]

Facebook has hired former American Civil Liberties Union lawyer Timothy Sparapani as its new director of public policy. The move could score points for the social networking site in the eyes of online privacy advocates that have expressed concern over its data privacy policies. It also will help Facebook fill a gap if its Chief Privacy Officer Chris Kelly runs for California Attorney General, as is anticipated.

Sparapani will start work with Facebook in late April, and will be based in Washington, D.C., reporting to Kelly. The company would not provide additional details about Sparapani or his role.
As a senior legislative counsel with the ACLU, Sparapani testified before U.S. Congress regarding issues such as The Real ID Act, arguing the proposed federal identification program represented a threat to privacy and constitutional rights. In a 2007 ACLU press release, he contended that government data mining "will turn us all into suspects."
Though it is unclear how Sparapani stands when it comes to data mining for advertising purposes, there are indications he could be sympathetic toward privacy advocates and other detractors of unregulated online data gathering and storage for ad purposes.
Center for Digital Democracy Executive Director Jeff Chester said his organization, which has argued that Facebook's privacy policies are not stringent enough, has been working with Sparapani recently on privacy and online advertising issues. However, Chester expressed only cautious optimism regarding Sparapani's new role. "Does the announcement of the principles and the hiring of Tim indicate a kind of next generation Facebook?" asked Chester rhetorically. "I think it's too early."
He continued, "If Facebook thinks it can trade on [Sparapani's] relationship with [privacy groups]...then they're incredibly naive... Tim knows this community is willing to bite the hand that it just shook ten minutes ago."
The company came under fire last month after altering its terms of service, spurring an uproar among users and privacy protectionists regarding the amount of time Facebook could store user data. The firm quickly did an about-face, reverting to its original policy and presenting a new set of Facebook Principles and a Statement of Rights and Responsibilities for public comment. The firm has received thousands of comments and will close the commenting period March 29.
Chester's organization sent a letter to Facebook this week suggesting that the company needs to rewrite its proposed principles. For instance, the group stated the principles do not "discuss the gathering, mining, and sharing of user data. Users need to know how third-party developers use the data accessed or collected, including how the data is used for advertising and marketing."

Thursday, May 29, 2008

Staff of Deutsche Telekom suspected of privacy breaches [Germany]

Security staff at the German phones giant Deutsche Telekom are suspected of breaching German data privacy laws during a secret attempt to identify the sources of high-level leaks to the media, the company said Saturday. Using the company's own records of millions of numbers dialled, the dates and the durations, the internal-security unit had hunted for possible matches between news reporters and Telekom directors.


Both public prosecutors and a German law firm have been assigned to investigate the suspected breach three years ago of German data- retention laws. Bonn-based Telekom said it had purged the security department last year to ensure it operated within the law.

The scandal was first reported Saturday morning by the German news weekly Der Spiegel in advance of its Monday issue. Telekom, one of the biggest companies on the German stock market, remains one third in federal ownership. Its affairs are closely followed by the German news media, which have often reported leaks from authoritative sources. Spiegel said the corporate security division had suspected senior executives or supervisory board members might be to blame.


Telekom said calls were not actually tapped, but the billing data had been illegally accessed in 2005 and "according to new claims" in 2006 too. Chief executive Rene Obermann said, "We're taking this very seriously. We have reported it to the public prosecutor."


In recent years German companies whose shares are traded in the United States have adopted the US practice of investigating and publicizing criminal actions within their own bureaucracies.

Monday, May 19, 2008

Deter, detect & defend cyber crime: the new age mantra [India]


"It is not only one company or organization, but the entire industry and consumers joining hands and taking collective responsibility which is required to tackle the growing menace of cyber crime", emphasized Mr Deepak Maheshwari, Director-Corporate Affairs, Microsoft India Pvt. Ltd at the Seminar on Information Security "Building Trust in Computing", organized by the Confederation of Indian Industry (CII), along with Department of Information Technology and Computer Emergency Response Team-India (CERT-In) in Mumbai.
Mr Maheshwari said that with more and more people having criminal background using internet, online security and online safety have gained paramount importance. "We must secure our computers with technology and act in ways that help protect us against risks that come with internet use", explained, Mr Maheshwari. He further detailed various steps like turning on firewalls, use of automatic updates, installing and maintaining antivirus and anti spy software to meet online risks and threats to computers, families and personal information.Mr Mukund Pawar, Inspector with Mumbai Police – Crime Branch present at the occasion put forth the role of police and their endeavors in controlling, detecting, investigating and punishing persons involved in cyber crime. In response to queries on ways and means employed by Mumbai police to control cyber crime, Mr Pawar explained with the help of number of cases ranging from innocent cyber pranks to major cyber thefts, which the crime branch Mumbai police had registered and dealt, resulting in punishing the culprits. He assured the audience that the Mumbai Police was well equipped to tackle any threats in cyber crimes. He suggested the need to scale up this initiative of CII to reach out to more consumers. "Cyber culprits are from different strata of society which show the widespread reach of cyber crime", said Mr Pawar. He also released a resource kit consisting of a CD, posters and website which will be made available to school children as a part of this campaign.
Mr Vikram Shah, President – India Operations, NetApp said that "We must treat internet information as an asset. As individuals we are entrusting someone else with our online assets. Where some are trust worthy, others might not be", cautioned Mr Shah. He further mentioned that most of the companies now had training programmes and information systems for all employees, implying how companies are becoming sensitive towards security of information. Commending on the initiative taken by CII, Mr Shah stressed that it was a right step towards raising awareness among the youth and children, who are the potential targets of cyber crime.Speaking on safeguarding online identities and fraud prevention was Dr Shekhar Kirani, Vice President, Verisign who said that phishing is a global threat where India is the third largest phishing sites hosting country. "Phishing sites have increased from 4000 to over 55000 in 18 months with the result that consumer distrust is growing at alarming speeds", emphasized Mr Kirani. He went on to explain various steps to be taken for identity protection like avoiding public unsecured computers for logging on to online banks accounts, ensuring the padlock sign on the sites, presence of security certificates providers seal on sites, among others. "This CII effort is spread across six cities: Delhi, Mumbai, Kolkata, Chennai, Chandigarh and Bangalore. In these cities we will be reaching out to 30 schools targeting more than 3000 children. This CII initative is designed to raise consumer awareness about cyber crime targeting the children and youth who are increasingly using online facilities", said Mr Vikram Tiwathia, Chief Information Officer, CII. Emphasizing the importance of safe online access and sharing, Mr Tiwathia said that information security is not as much of a technical requirement but a social aspect.The Seminar is a part of the ongoing CII campaign, which brought together participants from the banking, finance, government and consumers to a common platform to share views, thoughts, experiences and solutions to safeguard the Indian economy from cyber crime.

Thursday, March 27, 2008

German court tightens up ISP, phone data retention rules

Germany's highest court apparently had memories of Nazi and Stasi abuses in mind when it ruled on a series of surveillance and data privacy cases this year. In the most recent ruling, made in Karlsruhe, the Constitutional Court found that Germany's recent data retention directive targeting ISPs and telephone companies was problematic; going forward, the data retention will still be mandatory, but the information can only be accessed with a warrant and only for serious crimes.

Germany's law went into effect last December, and it ordered telecommunications companies to keep various kinds of data (e-mail addresses, numbers dialed, etc.) for at least six months and to turn this information over to investigators who requested it.

30,000 Germans promptly filed a class-action suit over the law, concerned about the implications of data retention. Could the data be used in any investigation, for instance, such as copyright infringement cases or file-sharing? Would it make personal information too easy for law enforcement to obtain?

The court found that parts of the law were unconstitutional. In its ruling, it upheld the retention requirement but instituted much stricter safeguards around who might get access to the information.

The ruling follows other, similar rulings this year. Last week, the court also struck down indiscriminate license plate monitoring in the states of Schleswig-Holstein and Hesse, saying that authorities needed to have a reason for running people's plates. The court hoped to prevent the creation of automated systems that track movement around the country.

In late February, the court also ruled on the matter of police spyware. German authorities and intelligence agencies had developed spyware (much like the FBI in the US has done) that can monitor suspects' computers and remotely glean information from their hard drives. The court said that judicial oversight of this process was required, and it also carved out areas that cannot be examined. Police are not allowed to include unrelated personal information in their investigations of suspects. This is similar to restrictions faced by traditional surveillance, where authorities have to cut a phone tap if suspected terrorists start talking religion.

Keeping up appearances?
While the decisions have all favored privacy rights, the court did not altogether eliminate remote computer snooping or data retention. They can continue under certain conditions, but the fact that the court does keep whacking away bits of legislation on these issues leads some German observers to wonder why such boundary-pushing legislation continues to get passed. One might ask the same question about video game violence laws in the US, which have been repeatedly struck down by courts but continue to pass legislatures around the country.

The answer in both cases seems to be that it's politically more expedient to look "tough" on crime, violence, and terrorism and then leave the courts to sort out what's actually constitutional. Such votes rarely have negative political consequences; though can end up costing governments plenty of money when the rules end up in court.

Sunday, March 02, 2008

Free Speech, Privacy and Wikileaks [International]

Free speech advocates immediately hailed as a victory the decision on Friday of a federal judge to withdraw a prior order turning off the Web address of the site Wikileaks.org. But the reasoning of United States District Judge Jeffrey S. White also means that the court may dodge having to grapple with some of the meaty First Amendment questions posed by the case and touched on repeatedly at a lengthy hearing in San Francisco.

The lawsuit, brought by a Swiss bank and its Cayman Islands subsidiary against Wikileaks and Dynadot, the San Mateo, Calif., company that is the registrar for the domain name Wikileaks.org, became a cause célèbre for organizations like the American Civil Liberties Union, Public Citizen and the Electronic Frontier Foundation. Such organizations responded with a barrage of court filings in the wake of an order signed by Judge White last month that required Dynadot to disable the Wikileaks.org address, making it more difficult – but far from impossible – for Internet users to get to materials published by Wikileaks.
The bank, Bank Julius Baer & Co., claimed that Wikileaks had displayed confidential, personally identifiable account information of its customers, as a result of possibly criminal actions by a former employee. Lawyers for the bank on Friday repeatedly told Judge White that Julius Baer clients had a right to keep their account information private and that there was no compelling interest to justify their disclosure. In this way lawyers for the bank set up a conflict between freedom of speech and the right to personal privacy.
After hours of discussion that suggested the judge’s level of concern with reaching the correct outcome, Judge White looked unhappy that he could not think of a way to help the bank customers affected by the release of the documents. But he said that he feared the initial order suspending Wikileaks.org raised serious questions of unjustified prior restraint on free speech, and that in any event, once the documents were online, the court might well be powerless. “Maybe that’s just the reality of the world that we live in,” Judge White said. “When this genie gets out of the bottle, that’s it.”

Monday, February 04, 2008

India to Adopt Data Privacy Rules

Two powerful players in India’s outsourcing industry are drafting a data protection law designed to quell growing privacy concerns from their offshore clients. India’s Ministry of Information Technology and the National Association of Software and Service Companies (Nasscom) in New Delhi expect the legislation to be in place early next year. It would provide legal safeguards to ensure data privacy protection in India, according to Nasscom President Kiran Karnik.

Such safeguards are required for all data leaving the European Union, which is a result of the EU Data Protection Directive and is what prompted India to act. But the regulations could prove beneficial for American companies as well.
No U.S. law currently prohibits information—such as Social Security and driver’s license numbers, employment histories, and medical records—from being shipped to or accessed from other countries, says William Bierce, attorney and president of New York City-based law practice Bierce and Kenerson. However, the number of U.S. companies required to comply with industry-specific and state laws is growing. Laws such as the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act, and California’s pending SB 1386 identity-protection law regulate what data companies can share. With offshore outsourcing deals, data protection provisions are usually written into service contracts.
Some CIOs worry whether a data protection law would have any teeth in India’s courts. But competition for offshore business should keep the courts on the straight and narrow. "Nasscom and India understand how vital a clear policy on data protection and privacy are to the trust and confidence of foreign clients," says Bierce, adding that the rules will most likely be enforced by a special appellate court established under India’s Information Technology Act of 2000.
Nonetheless, CIOs must remain diligent about Indian vendors to ensure the privacy and security needs of their companies. "India’s privacy legislation is positive, but much more important is for CIOs to ensure that their outsourcing agreements contain detailed and precise contractual specifications regarding data privacy and protections," says Hank Zupnick, senior vice president and CIO of GE Real Estate, who works with several Indian IT services companies. Specific remedies for noncompliance should be spelled out in the contract, adds Zupnick, and the contract should have legal jurisdiction in the state or province where the CIO’s company is headquartered.

Friday, February 01, 2008

Google and Data Privacy Day

A year after the first Data Protection Day in Europe, Google will be part of the celebration of the now-renamed Data Privacy day, aimed at educating people about their data and how to manage it.

Today is Data Privacy Day, but apparently cake isn't involved, and forget about having a paid holiday, either. We wonder if Hallmark has a card for this?
Though we may take the idea of a day of privacy awareness talked up by Google with a shot of cynicism, the concept remains sound. People have valuable personal information to control, other people would love to steal it, and still more people wish to use it for various reasons. What's an online consumer to do? Well, he could watch a privacy video, Google's third in a series. Or read a handy privacy booklet.
A trio of notables at the search advertising giant discussed Data Privacy Day 2008 (woo hoo!) at the official Google blog. Among the highlights: Google will participate in a data privacy conference at Duke University today.

Speakers from the US and abroad tackle the topic of consumer data privacy. Differences between European and US privacy laws should be a focal point; we see the difference as privacy being mandated in Europe, but largely left up to private industry in the US.
Google also backed the creation of educational materials on teen online privacy. One slide advises teens to "think about tomorrow when acting today."

"Data Privacy Day": Bush Admin Launches Internet Monitoring Initiative

Monday, January 28 has been designated "Data Privacy Day" in North America and in 27 European countries in conjunction with the International Association of Privacy Professionals. Google's privacy counsel Jane Horvath says the company is joining in an international privacy conference being held at Duke University in Durham, North Carolina.

In accordance with that appearance and Data Privacy Day, Google has added a new video to its existing series of privacy videos, plus it has developed a privacy booklet (PDF) to educate consumers and parents about online data privacy. Horvath explains:
We've also developed a privacy booklet that you can download to get an in-depth look at our privacy practices and approach, and have co-sponsored the creation of educational materials on teen online privacy for parents and educators. The goal of all these efforts is to help educate you about online data privacy so that you can make more informed choices about how you use online products and services.
Google has in the past been the subject of criticism and complaints about online privacy. And privacy is at the center of the European inquiry into the Google-DoubleClick acquisition. But Google should also be applauded for efforts to educate consumers, who generally don't understand online privacy issues.
And given that the announcement came on Data Privacy Day, it's somewhat ironic that the Bush administration is pushing a cybersecurity initiative that would greatly expand its ability to spy on American online activity and data collection. According to the Wall Street Journal:
President Bush has promised a frugal budget proposal next month, but one big-ticket item is stirring controversy: an estimated $6 billion to build a secretive system protecting U.S. communication networks from attacks by terrorists, spies and hackers . . .
Protecting private computer systems would likely require the government to install sensors on private, company networks, officials familiar with the initiative said. Amid divisiveness about other government-surveillance programs, having the government monitor Internet traffic, even in the name of national security, will be a hard sell to Congress and the public.
In addition, RFID tags and "microchips" will eventually be everywhere, allowing the government, retailers and others to closely monitor consumer behavior and activity even as this technology promises to deliver all kinds of consumer benefits.
Online privacy is becoming an increasingly critical issue for ordinary people as more daily activity shifts to the Internet and consumer behavior, health histories and financial information become subject to unprecedented levels of data collection, monitoring and potential misappropriation.

Friday, November 30, 2007

Change your passwords for Computer Security Day [Data Security]

Most people keep the same password for too long and use it for too many purposes. So if you do one thing to mark Computer Security Day, change your passwords. If you do two things, change your passwords and vacuum your computer.

These are among the tips from the US organisers of the global event, including Security Awareness Inc. and the Information Systems Audit and Control Association. Now in its ninth year, Computer Security Day exists to remind people to protect their computers and information.

The day is on 30th November each year and the organisers list 53 ways that offices can participate.

Suggestions include:

  • Check for viruses
  • Protect against static electricity
  • Vacuum your computer and the immediate area
  • Back-up your data
  • Post 'No drinking' and 'No smoking' signs in computer areas
  • Hold a discussion of ethics with computer users

Passwords-schmasswords

Almost two-thirds of people never change their passwords, according to a survey of 1,800 adults reported by the Department of Trade and Industry in June. One in five people said they use the same password for non-banking websites as well as their online bank. And over one-third recorded their password or security information by either writing it down or storing it somewhere on their computer.

Such behaviour is asking for trouble, according to US security guru Bruce Schneier.

"People should change their online access passwords regularly," Schneier. "The risk is that a password has been compromised, and changing your password regains security."

Microsoft suggests that a password that is shorter than eight characters should be considered "only good for a week or so," while a password that is 14 characters or longer (provided it follows Microsoft's rules and tips for passwords) can be good for several years. Others suggest that you can safely keep a password for 60–90 days as a general rule of thumb.

The HMRC incident has prompted many individuals to take protective steps. HMRC wrote to the families potentially affected by the data loss. Its letter addressed online banking risks and stated: "If your password uses any of your personal data, for example your child's name or date of birth, you may also wish to consider changing any passwords you use."

According to APACS, the UK payments association, 10% of Child Benefit recipients have since changed their online banking passwords. Six percent changed their PINs.

How to choose a new password

Andrew Moloney, a director at security firm RSA who specialises in the financial services market, offers the following tips:

  • "If your password is linked to personal data – e.g. a date of birth or child’s name – it should be changed.
  • The longer a password, the more difficult it is to crack. Thus, make yours of a decent length, say 10 to 16 characters if possible.
  • Replace words for numbers e.g. For = 4, to/too = 2, add punctuation like exclamation marks and change capitalisation
  • Consider using a phrase that includes both numbers and words and use the first letters/numbers from that. An example would be “On the 12 days of Christmas my true love gave to me = Ot12docmtlgtm”. This has a great combination of being hard to guess but easy to remember. That's the ideal scenario."

Tuesday, November 13, 2007

Intel Official: Say Goodbye to Privacy

A top intelligence official says it is time people in the United States changed their definition of privacy.

Privacy no longer can mean anonymity, says Donald Kerr, the principal deputy director of national intelligence. Instead, it should mean that government and businesses properly safeguards people's private communications and financial information.

Kerr's comments come as Congress is taking a second look at the Foreign Surveillance Intelligence Act.

Lawmakers hastily changed the 1978 law last summer to allow the government to eavesdrop inside the United States without court permission, so long as one end of the conversation was reasonably believed to be located outside the U.S.

The original law required a court order for any surveillance conducted on U.S. soil, to protect Americans' privacy. The White House argued that the law was obstructing intelligence gathering.

The most contentious issue in the new legislation is whether to shield telecommunications companies from civil lawsuits for allegedly giving the government access to people's private e-mails and phone calls without a court order between 2001 and 2007.

Some lawmakers, including members of the Senate Judiciary Committee, appear reluctant to grant immunity. Suits might be the only way to determine how far the government has burrowed into people's privacy without court permission.

The committee is expected to decide this week whether its version of the bill will protect telecommunications companies.

The central witness in a California lawsuit against AT&T says the government is vacuuming up billions of e-mails and phone calls as they pass through an AT&T switching station in San Francisco.

Mark Klein, a retired AT&T technician, helped connect a device in 2003 that he says diverted and copied onto a government supercomputer every call, e-mail, and Internet site access on AT&T lines.

Tuesday, October 09, 2007

Google gets into 'data privacy' hot water

Google's proposed purchase of online ad giant DoubleClick would lead to "a massive violation of data privacy rights", says a German data protection expert.

As reported by web legal experts Out-law.com, the Data Protection Commissioner of the German state of Shleswig-Holstein Thilo Weichert has sent his views to Europe's Competition Commissioner Neelie Kroes saying that the $3.1 billion merger would result in the "fundamental provisions of the European Data Protection Directive [being] violated."

Weichert's views rely on the assumption "that in the event of a takeover of DoubleClick the databases of that company will be integrated into those of Google" he said.

"Such an approach contradicts fundamental data privacy principles of the European Union: limited specific use, transparency, the right to object, the protection of sensitive data and the right to having data deleted," he wrote in the letter.

Friday, October 05, 2007

Facebook warned on safety claims [International]

The social networking website Facebook has been warned that it could face a consumer fraud charge for failing to live up to claims that youngsters there are safer from sexual predators than at most sites and that it promptly responds to concerns, a spokesman for New York Attorney General Andrew Cuomo said Sunday.

"We expect an immediate correction eliminating the dangers exposed by our investigation," said the spokesman, Jeffrey Lerner.

Cuomo announced last week that he had subpoenaed Facebook after he said the company did not respond to "many" complaints by investigators who were solicited for sex while posing as 12- to 14-year-olds on the site.

Officials from Cuomo's office met with Facebook on Friday after they said Facebook took three days to answer calls and emails from state investigators.

An official in Cuomo's office said he and others are scheduled to meet with Facebook representatives this week and anticipate changes will follow immediately.

"We said, 'You have got to make accurate representations on your website," said the official, who spoke on the condition of anonymity because court filings haven't yet been made. "What we told them is, 'Correct the language describing the site and stop marketing yourself as this pristine website ... parents have a misimpression. You can't mislead people."

Lerner said Facebook's contention of being safer than most sites was accurate when it started out as a closed site 3 1/2 years ago. But it's now much larger, and the safeguards and apparently the response times for complaints aren't what they once were, he said.

There was no immediate response to email and phone messages left for a Facebook representative. But a statement issued a week ago stated the company was concerned about Cuomo's claim that sexual predators could use the site to meet with children.

"We strive to uphold our high standards for privacy on Facebook and are constantly working on processes and technologies that will further improve safety and user control on the site," Facebook spokeswoman Brandee Barker said in the statement.

Lerner said Facebook has continued to promise to cooperate.

Friday, September 14, 2007

Sony loses privacy complaint over Unfit Kids [International - Data Privacy]

A documentary that cited video games among the reasons for childhood obesity did not treat Sony unfairly when criticising the PlayStation maker's refusal to sponsor a fitness scheme for kids. Sony also lost a claim that the company's privacy was breached.

The ruling was published by Ofcom, the regulator for the UK's communications industries, yesterday. Sony Computer Entertainment UK Ltd had complained that Ian Wright's Unfit Kids, a Channel 4 show presented by the former footballer, made Sony the target for unfair, one-side and pejorative comment.

Sony also argued that its privacy was "unwarrantably infringed" when footage of the company's offices and logo were used and a confidential email from the company was included in the programme.

In the programme, Ian Wright explored some of the reasons behind childhood obesity. In the first show, Wright selected overweight 13–14 year olds who did little or no exercise and devised an After School Fitness Club programme for them. He tried to extend the project and the second episode of the series, broadcast on 20th September 2006, showed his attempt to secure funding.

He arranged to meet representatives of Sony to seek sponsorship from them. Sony decided not to sponsor the scheme. Sony was referred to in the programme which also showed an email from the company in relation to sponsorship and footage of the exterior of the company's offices.

Sony complained to Ofcom.

Sony said that Wright's comments created an erroneous and unfair impression of the company, which was disproportionate in the context of the refusal of a request for sponsorship. In particular, Sony complained about Wright's remark, "Fuck Sony, man. Sony's not gonna stop this from working".

Sony also argued that the programme implied wrongdoing on Sony's part, alleging that it failed to sponsor Wright's project and unfairly contrasted this with a statement about the firm's worldwide turnover of $8.6 billion from video games. Wright also said that there is a Sony PlayStation game for "every single thing that a child can go out and exercise [for]."

Sony also claimed that the programme makers did not explain the nature and purpose of the programme to them and that they did not inform Sony that its refusal to have the meeting with Wright filmed would be referred to negatively in the programme. It complained that Sony's positive views about Wright's project and the company's involvement in other sports-based initiatives were omitted.

Channel 4 countered that it was "perfectly reasonable" for Wright to express his frustration at the company's decision. It also said that Sony was made aware from the outset the nature and purpose of the programme.

Sony said its privacy was infringed when its offices and logo were filmed without permission and it pointed out that the email used in the programme was confidential correspondence intended for the addressee only. Channel 4 countered that the programme makers did not need permission to film Sony's offices "as the programme makers were filming openly from a public highway." It added, "All company emails are routinely accompanied by confidentiality wording," but said that there was express authorisation from a Sony representative to use the email.

Ofcom found that the inclusion of Wright's reaction to the news that Sony was not going to provide funding was "reasonable as a reflection of his disappointment." This did not amount to an allegation of wrongdoing to which the programme makers should have given Sony an opportunity to respond, said Ofcom.

Ofcom said it was "entirely acceptable" for the programme makers to film and broadcast footage recorded from a public place. Ofcom added: "Such material was firmly in the public domain and did not require consent from the company."

Ofcom noted that there was a clear conflict between Sony and Channel 4 as to whether the broadcaster had permission to use the email. It concluded that it was for the courts to determine the question of any misuse of confidential information.

However, Ofcom was able to consider whether there had been an infringement of Sony's privacy under Rule 8.1 of the Broadcasting Code which states: "Any infringement of privacy in programmes, or in connection with obtaining material included in programmes, must be warranted."

Ofcom said it considered both the subject matter and content of Sony's email and ruled that the parts used did not contain any information that was inherently private to Sony, such as exposing the inner workings of the company.

The regulator also said it was foreseeable that the programme would wish to make reference to what Sony had said in the email and there was no evidence Sony had specifically asked for it not to be included. Ofcom ruled that Sony did not have a legitimate expectation of privacy.

Ofcom's ruling concluded: "The complaints of unfair treatment and infringement of privacy were not upheld. Accordingly the complaint was not upheld."

Wednesday, August 22, 2007

Australia's data privacy landscape questioned [Data Privacy - Australia]

When it comes to privacy, bank customers in Australia are left to choose between garbage, trash or junk. That is how Gartner's vice president of research, Rich Mogull, describes the current data privacy landscape in Australia.

A strong advocate of the introduction of disclosure laws which force banks to notify customers of a security breach, Mogull said the Australian government needs to act by implementing legislation that includes penalties to ensure compliance.

Without these laws, Mogull said customers cannot make an informed decision when seeking a financial services provider.

He said breaches are occurring in Australia but it is impossible to get meaningful statistical data that could provide some insight into the current IT security landscape.

"There is no legislative protection in Australia just the National Privacy Principles [under the Privacy Act] which are not enforced; the current landscape in Australia is what it was like in the United States pre-2005 before the first breach notification law was introduced in California," he said.

Mogull's comments delivered at Gartner's IT security summit in Sydney today are part of a broader push for changes to the Privacy Act currently being reviewed by the Australian Law Reform Commission (ALRC).

The ALRC is releasing a discussion paper next month recommending the introduction of security breach disclosure laws in Australia with the final report to be delivered to the federal Attorney General, Philip Ruddock in March, 2008.

The recommendation also has the support of the Federal Privacy Commissioner, Karen Curtis.

Mogull said disclosure laws in the US have been the biggest single driver in improving the IT security landscape. Under the Californian law, which he said is the first of its kind in the world, if a specific combination of data is disclosed then customers must be notified. That combination includes the customer's first and last name, along with credit card and banking details, and social security number. "The law was ignored for two years until the Choice Point breach then the flood gates opened," Mogull explained.

"Previously there was no external pressure to act. If an organization is losing customer data and it doesn't affect the business then there is no impact.

"The customer suffers but the business doesn't. There is a built-in market force to keep your mouth shut. Basically, market forces are working against privacy protection."


Mogull said 40 states in the US now have disclosure laws providing customers with a level playing field to make informed decisions.

"The IT security landscape here today has been reduced to a choice of garbage, trash or junk but bad publicity about breaches can change that, it can force change," he said.

"Australia isn't any safer than the US when it comes to data protection I know breaches are occurring as I work with the financial services sector here and know what security programs the banks have in place.

"In fact I think it is a much harsher environment here, especially when it comes to phishing and Australia's proximity to Asian economies; it is just hidden more from consumers.

"There are no market forces pushing organizations to do better."

Mogull said disclosure laws are a good starting point to improve the IT security landscape because it would enable the collection of valuable data and to understand how breaches occur.

"With good stats we can make good decisions," he added.

While Mogull believes the laws should include penalties, he said there should also be a built-in mechanism that allows consumers to take legal action themselves.

He admits organizations may need to increase budgets to be compliant.

"If an organization is currently spending five percent of their budget on security they may have to bump that up to seven percent; but this usually involves a shifting of funds rather than new money," Mogull said.

The Australian Bankers Association (ABA) CEO, David Bell, told Computerworld banks already have a legal duty to protect customer data under a number of laws without the introduction of data disclosure legislation.

Bell said confidentiality and privacy is at the core of customer relationships.

He went on to say it would be premature to comment on the introduction of data disclosure laws before the ALRC's final report is handed down next year.

"But we are certainly awaiting the outcome of the report as the ABA has made a submission to the ALRC on the privacy review," Bell said.

Britain's Information Commissioner's Office Worried Over Data Privacy [Data Privacy - United Kingdom]

The UK's data protection watchdog has warned that greater transparency about data collection is needed as more personal information is shared between different organisations.

The Information Commissioner's Office (ICO) has published new guidelines for individuals to better understand how and why organisations use their data under the current Data Protection Act.

People are not always aware of the extent to which their personal data can be shared by different organisations, according to the ICO -- between, for instance, the police and a local authority.

Iain Bourne, head of data protection projects at the ICO, said in a statement: "More and more information is being shared about us, often for useful and wholly legitimate purposes. It is important that individuals are aware of their rights under the Data Protection Act."

Responding to the ICO's warning, Graham Hann, a technology partner at European law firm Taylor Wessing, said UK data protection laws "are not clearly interpreted in many areas" which can make it difficult for people to understand their rights. Wessing warned that although the general legal requirement is that companies cannot use individuals' data in ways they have not consented to, there are exceptions.

He said in a statement: "New laws brought in recently require that customers opt in to sharing of data for marketing purposes where the marketing would be by email. However not all organisations have caught up to speed with these laws and individuals may find their details being used by businesses wishing to sell them goods or services that they have no interest in receiving."

Businesses should be wary of buying data from third-party sources, he said, and be sure to verify they have legal right to use the data in the way they intend.

The law firm added that consumers' awareness of data protection issues has "risen dramatically in recent years".

The latest data warning from the data protection watchdog follows the launch of silicon.com's Full Disclosure campaign - which is aiming to persuade the UK government to change the law on data breaches so that companies have a legal requirement to inform individuals when their data has been put at risk by a security breach.