Friday, January 04, 2008

Thursday, January 03, 2008

Facebook prevents scraping of profiles

Apparently Facebook has banned Robert Scoble and suspended his account after Facebook determined he was violating the terms of service by using an automated script to "move his social graph" (Facebook disabled my account « Scobleizer — Tech geek blogger). What he was apparently doing was using a script or some other automated tool to "export" information related to his 5000 friends to import the data into Plaxo (What I was using to hit Facebook — unreleased Plaxo Pulse « Scobleizer — Tech geek blogger). Facebook lets you import data from Gmail and other services, but it's a one way street.

His account has been restored, but I hope this spurs some debate over the portability of one's own data, particularly if that includes data about others.

In my view, I think that Facebook is right to prevent this sort of scraping. Facebook is different from your usual address book. There's much more information being shared on social networking sites. Perhaps imprudently, many users add as friends people they really don't know and (un)wittingly expose sensitive information. A facebook profile not only lists that individual in question, but his or her friends.

All of this means that information from a Facebook is more prone to be abused in a manner that the individual may not anticipate. If I add Scoble (or you) as a friend on Facebook, I think I have a good sense of what may happen to that information on Facebook. But I have no clue about what can happen when that information is taken off a trusted platform into some other, unknown, system. It's a bit chilling and Facebook is correct to take the position it has.

There's some additional coverage here: The Scoble scuffle: Facebook, Plaxo at odds over data portability The Social - CNET News.com, but you should also read the comments on Scoble's own posts as they represent an interesting slice of opinion.

What intrusive "function creep" looks like

Just before New Year's, the Nova Scotia Utility and Review board reinstated the liquor license of a popular bar in Halifax on the condition (among others) that the bar double the number of surveillance cameras and allow liquor inspectors and the cops to have offsite access to the feeds (see: Canadian Privacy Law Blog: Offsite surveillance in Halifax bar may set precedent and Canadian Privacy Law Blog: Halifax bar gets liquor license back on condition that cops have off-site access to surveillance system).

When this report came out, I voiced some concerns that this may set a dangerous precedent. Any move to implement such a scheme has to include very tight controls over how this new-found surveillance power will be used lest it be a license for unimpeded and unrestricted intrusiveness.

In case you were wondering what the slippery slope of function creep (to mix my metaphors) looks like, look no further than random ID checks in casinos in Illinois. Random identification checks by law enforcement officers were put in place to deal with excluded problem gamblers. Assurances were given that there would be no other use of that information or other abuse of this power. Now it's reported, shockingly, that the cops in Illinois casinos are checking for problem gablers, sex offenders, outstanding warrants and other micreants. See: Daily Herald Police admit ID checks in casinos turn up more than problem gamblers.

To put it bluntly, function creep is a very real phenomenon that needs to be anticipated and guarded against whenever a new intrusive technique or technology is rolled out.

Wednesday, January 02, 2008

Happy birthday to the Canadian Privacy Law Blog

Today marks the fourth anniversary of the Canadian Privacy Law Blog. Four years ago, on January 2, 2004, I put fingers to keyboard and joined the interesting conversation that was beginning to take shape on the internet among veteran bloggers and I'm glad I did. (Welcome to the Canadian Privacy Law blog.) According to Blogger, this will be my 2740th post to the blog.

Forgive me if I get a bit melancholic and wistful as I look back on the past four years, but it has been a very eventful one for me and for the world of privacy. And both are related, I think. (I mean the changes in the world of privacy have influenced me, not the other way around.)

The day before my first posting, the Personal Information Protection and Electronic Documents Act ("PIPEDA") came fully into force for all commercial activities in Canada. That day, the Personal Information Protection Acts of British Columbia and Alberta came into force, but were not declared to be "substantially similar" to PIPEDA until ten months later (Alberta and British Columbia privacy laws declared to be substantially similar.) Also on the legislative front, Ontario passed the Personal Health Information Protection Act and it became law in May, 2004 (Ontario's Personal Health Information Protection Act receives royal assent.) Perhaps as importantly, it was declared substantially similar on November 28, 2005. (PHIPA declared substantially similar.)

Much attention has been paid to the continuing erosion of privacy rights in the United States and Canada. In 2004, the Information and Privacy Commissioner of British Columbia brought the USA Patriot Act under scrutiny. (U.S. Patriot Act worries Privacy Commissioner and BC Information and Privacy Commissioner releases his report: Patriot Act contravenes BC privacy laws.) In response, British Columbia, Alberta and Nova Scotia have passed laws or amendments to existing laws to closely regulate the export of personal information outside of Canada. In the US, the USA Patriot Act has been subject to many judicial challenges with some success.

Perhaps the area that has been most visible to laypeople is the growing trend of requiring companies to report data breaches. California led the way and now more than thirty US states have such requirements. We haven't seen it in Canada (except in PHIPA in Ontario) but advocates are calling for such a requirement in Canada's privacy laws of general application. Coming clean has led to the public disclosure of a number of huge breaches, including Cardsystems, TJX/Winners, Department of Veterans Affairs and the UK Revenue and Customs Service. Whether we see a change in Canadian law has yet to be seen. Despite the huge publicity given to these breaches, business built on personal information -- such as Facebook -- thrive.

On the professional front, I've been very fortunate to have been invited to speak on the topic of privacy on more occasions than I can estimate. Highlights have been speaking at the Canadian Bar Association general meeting in Winnipeg in 2005, Canadian IT Law Association for the past few years and innumerable professional organizations. The blog has also led to innumerable media interviews and some amazing awards (I'd like to thank the academy. And my blog ... and An honour to even be considered.)

Perhaps more satisfying is that I've been fortunate to have met (in some cases, in the flesh) and to have been inspired by some great fellow legal bloggers. This list includes Connie Crosby, Rob Hyndman, David Canton, Michael Geist, Michael Fitzgibbon and the amazing Slawyers.

To my readers, thank you very much for taking the time to drop by. I hope it has been informative and useful. Please pass along any suggestions or your thoughts, either in the comments to my posts or via e-mail at david.fraser@mcinnescooper.com.

Birthday cake graphic used under a creative commons license from K. Pierce.

Privacy Among Top 10 Law Firm Practice Areas of Media Interest in 2008

Legal Expert Connections, which specializes in marketing for lawyers, has issued a press release on the ten practice areas that it anticipates will garner the most media interest in 2008.

Privacy is on the list, which doesn't surprise me too much. Afterall, incidents are in the media regularly as are government policies that have an impact on personal information. And this is an area in which the media don't hesitate before calling a lawyer for comment. Just off the top of my head, I can think of a few colleagues at the privacy bar who have been repeatedly quoted in the media on privacy articles in the past year, including Brian Bowman in Winnipeg, Michael Geist in Ottawa, and David Canton in London.

Legal Expert Connections Projects Top 10 Law Firm Practice Areas of Media Interest in 2008

The top 10 law firm practice areas of interest to the media, based on current news events, are projected to be real estate, government, intellectual property, international, privacy, immigration, trusts & estates, environment, employment and health care. Attorneys and legal marketers are advised to plan their 2008 communications strategy accordingly, notes law firm marketing consultant Margaret Grisdela.

Boca Raton, FL (PRWEB) January 2, 2008 -- Law firms that position their attorneys as legal thought leaders and educators in key 2008 news stories will leverage their expertise and increase name recognition via a proven public relations strategy. According to Margaret Grisdela, President of the legal marketing firm Legal Expert Connections (http://www.legalexpertconnections.com/) and author of the new legal marketing book Courting Your Clients, attorneys in hot practice areas should take advantage of current media news coverage and emerging trends to capture a leadership position and competitive advantage in their areas of expertise.

"This approach is really Public Relations 101: offering high level legal insight and expertise to a variety of media outlets to garner the third party credibility and broad-based exposure in print, radio, television and on the web that PR offers," affirms Ms. Grisdela. "Journalists and radio and TV producers are always seeking experts on timely news topics. The following legal practice areas are poised to generate a high level of interest from the media in 2008, meaning that attorneys and their marketing advisors should strategize now to ensure that their name is top of mind with the media."

1. Real estate. As home sales continue to decline, attorneys with a real estate practice serving consumers or developers will find many opportunities to educate the market in areas of foreclosure, bankruptcy, mortgage fraud, and short sales.

2. Government. The 2008 presidential election will dominate the news, giving attorneys with an angle on leading voter concerns like the Iraq war, civil rights, the U.S. economy and education a big potential stage.

3. Intellectual Property. The U.S. Congress is evaluating major patent legislation, while Europe is actively implementing sweeping "EPC 2000" patent changes in 2008. IP attorneys have an unprecedented opportunity to explain digital rights, licensing, infringement and the need for trade secret protection.

4. International. In 2007, the Securities and Exchange Commission paved the way for likely adoption of International Financial Reporting Standards (IFRS), which could ultimately replace U.S. Generally Accepted Accounting Principles (GAAP). As business goes global, corporate and securities attorneys can educate audiences on business legalities in Brazil, Russia, India, China, and other rapidly growing countries.

5. Privacy. With digital consumer data growing exponentially, attorneys can address matters involving privacy policies, identify theft, data security, e-discovery, background checks, medical record protection, credit reports and more.

6. Immigration. Congress could not reach agreement on immigration reform in 2007 despite heated public debate, leaving this is a hot button for 2008 politics.

7. Trusts & Estates. 2008 is the first year Baby Boomers start turning 62 and become eligible for Social Security retirement benefits. Attorneys with a concentration in wills, trusts, and estates should position themselves as a credible legal partner for aging Boomers in need of retirement planning.

8. Environment. Leading world scientists documented an "unequivocal" warming in the global climate in 2007. Law firms can address a range of green topics, including alternative energy, recycling, energy efficiency, toxic tort litigation and more.

9. Employment. Wage and hour litigation brought under the Fair Labor Standards Act (FLSA) tripled in the past few years, according to court records. Employment law attorneys should be prepared to speak on a full range of employment law matters including overtime, discrimination, family leave, and other personnel policies.

10. Health Care. Universal coverage will be a big focus of media attention during the 2008 elections, giving health care attorneys a natural platform to address insurance haves and have-nots, HIPAA, health care fraud, billing practices, medical reimbursements and more.

In addition to direct media outreach on these topics, other public relations and communications opportunities for attorneys include speeches, articles and editorials, blogs, letters to the editor, newspaper columns, web site postings, white papers, client alerts, and educational seminars.

About Legal Expert Connections, Inc.

Legal Expert Connections specializes in marketing and business development exclusively in the legal and litigation support markets. Founded by law firm marketing consultant Margaret Grisdela, also known as the "Rainmaking Lady," the firm's services include business development seminars and campaigns, attorney marketing plans, law firm brochures, expert witness marketing, direct mail, web site development and more. The firm's web site is http://www.legalexpertconnections.com/ and lawyer marketing blog is http://www.rainmakingclub.com/.

Opinion: We have everything to fear from ID cards

Today's Telegraph has a great opinion piece against mandatory ID cards in the UK:

We have everything to fear from ID cards - Telegraph

By Andrew O'Hagan

We start the year in Britain with a challenge to our essential nature, for 2008 might turn out to be the year when we decide to rip up the Magna Carta.

Among the basic civil rights in this country, there has always been, at least in theory, an inclination towards liberal democracy, which includes a tolerance of an individual's right to privacy.

We are born free and have the right to decide what freedom means, each for ourselves, and to have control over our outward existence, yet that will no longer be the case if we agree to identity cards.

advertisement

Britain is already the most self-watching country in the world, with the largest network of security cameras; a new study suggests we are now every bit as poor at protecting privacy as Russia, China and America.

But surveillance cameras and lost data will prove minuscule problems next to ID cards, which will obliterate the fundamental right to walk around in society as an unknown.

Some of you may have taken that freedom so much for granted that you forget how basic and important it is, but in every country where ID cards have ever been introduced, they have changed the relation between the individual and the state in a way that has not proved beneficial to the individual. I am not just talking Nazi Germany, but everywhere.

It is also a spiritual matter: a person's identity is for him or her to decide and to control, and if someone decides to invest the details of their person in a higher authority, then it should not be the Home Office.

The compulsory ID card scheme is a sickness born of too much suspicion and too little regard for the meaning of tolerance and privacy in modern life.

Hooking individuals up to a system of instantly accessible data is an obscenity - not only a system waiting to be abused, but a system already abusing.

Though we don't pay much attention to moral philosophy in the mass media now - Bertrand Russell having long been exchanged for the Jeremy Kyle Show - it may be worth remembering that Britain has a tradition of excellence when it comes to distinguishing and upholding basic rights and laws in the face of excessive power.

The ID cards issue should be raising the most stimulating arguments about who we are and how we are - but no, it is not: we nose the grass like sheep and prepare to be herded once again.

It seems the only person speaking up with a broad sense of what this all means is Nick Clegg, the new leader of the Liberal Democrats, who has devoted much of his new year message to underlining the sheer horribleness of the scheme.

He has said he will go to jail rather than bow to this "expensive, invasive and unnecessary" affront to "our natural liberal tendencies".

I have to say I cheered when I heard this, not only because I agree, but because it is entirely salutary, in these sheepish times, to see a British politician express his personal feelings so strongly.

Many people on the other side of the argument make what might be called a category mistake when they say: "If you've nothing to hide, why object to carrying a card?"

Making it compulsory to prove oneself, in advance, not to be a threat to society is an insult to one's right not to be pre-judged or vetted.

Our system of justice is based on evidence, not on prior selection, and the onus on proving criminality is a matter for the justice system, where proof is of the essence.

Many regrettable things occur as a result of freedom - some teenage girls get pregnant, some businessmen steal from their shareholders, some soldiers torture their enemies, some priests exploit children - but these cases would not, in a liberal society, require us to end the private existence of all people just in case.

If the existence of terrorists, these few desperate extremists, makes it necessary for everybody in Britain to carry an ID card then it is a price too high.

It is more than a price, it is a defeat, and one that we will repent at our leisure. Challenges to security should, in fact, make us more protective of our basic freedoms; it should, indeed, make us warm to our rights.

In another age, it was thought sensible to try to understand the hatred in the eyes of our enemies, but now it seems we consider it wiser just to devalue the nature of our citizenship.

What's more - it won't work. Nick Clegg has pointed to the gigantic cost and fantastic hubris involved in this scheme, but recent gaffes with personal information have shown just how difficult it is to control and protect data.

A poll of doctors undertaken by doctors.net.uk has today shown that a majority of doctors believe that the National Programme for IT - seeking to contain all the country's medical records - will not be secure.

In fact, it is causing great worry. Many medical professionals fear that detailed information about each of us will soon be whizzing haphazardly from one place to another, leaving patients at the mercy of the negligent, the nosy, the opportunistic and the exploitative.

"Only people with something to hide will fear the introduction of compulsory ID cards."

That is what they say, and it sounds perfectly practical. If you think about it for a minute, though, it begins to sound less than practical and more like an affront to the reasonable (and traditional) notion that the state should mind its own business.

In a just society, what you have to hide is your business, until such times as your actions make it the business of others. Infringing people's rights is not an ethical form of defence against imaginary insult.

You shouldn't have to tell the government your eye colour if you don't want to, never mind your maiden name, your height, your personal persuasions in this or that direction, all to be printed up on a laminated card under some compulsory picture, to say you're one of us.

You weren't born to be one of us, that is something you choose, and to take the choice out of it is wrong. It marks the end of privacy, the end of civic volition, the end of true citizenship.

The Clawbies are out!

On New Year's Eve, Steve Matthews published his Clawbie awards for Canadian Legal Blogs. I was honoured to be a runner-up in the practitioner support category:

Clawbies.ca

2) Best Practitioner Support Blog - Garry Wise - Year-in and year-out, Garry is one committed law blogger. He offers his opinions on almost everything, and if you do a Google search for Toronto lawyer you’ll see how blogging benefits the online exposure of his practice. If you didn’t read his Starting a law firm post back in February, please do. Garry Wise consistently offers great vision to a lot of solos across the country. Runner ups: David Fraser’s Canadian Privacy Law Blog, Hull & Hull’s Toronto Estate Law Blog

Steve has been a big promoter of this blog and I'm grateful to have gotten to know him over the past years. Check out the full listing and support your local legal blogger!

New US passport cards for North American travel can be read at a distance

Over the holidays, the US government published information about a new passport card to facilitate travel by Americans in North America. One "feature" is causing a lot of concern: the technology (presumably RFID) built into the card means they can be read over a distance of up to eight metres. The cards will be issued with protective sleeves for those who want to use them, but this doesn't assuage privacy advocates who think the technology is inherently flawed. See: globeandmail.com: U.S. 'vicinity-read' cards assailed by privacy experts.

Tuesday, January 01, 2008

New breach blog

Emergent Chaos is linking to a reasonably new resource, the Breach Blog, that contains data on personal information breaches, similar to Pogo's and the Attrition.org Data Loss Archive and Database (DLDOS).

I've stopped blogging about most breaches, primiarily because they are too numerous and others can provide that service. I try, however, to keep on top of them and report on those that are particularly newsworthy or provide novel lessons to be learned. I'll certainly add it to my blogroll.

Happy New Year!

To all the readers of the Canadian Privacy Law Blog, I wish you all the best for 2008!

Happy new year!

Fireworks photo by ahisgett, used under a creative commons license.