Friday, September 12, 2008

Your privacy, your responsibility says Ontario Privacy Commissioner

ITBusiness has an interesting article on the collaboration between the Ontario Privacy Commissioner and Facebook, including a video interview with the commissioner: Your privacy, your responsibility says Ontario Privacy Commissioner.

Wednesday, September 10, 2008

Nova Scotia introduces and then drops intrusive licence renewal form

Earlier today, the Nova Scotia government came under fire for introducing a new form for driver's licence renewals that asked applicants to say whether they had any kind of mental illness. (Critics: Don’t tie driver’s licence renewal to psychiatric history) Too much information, I say. So says the FOIPOP Review Officer, Dulcie McCallum.

Apparently anyone who checks off affirmatively will be required to provide a medical report detailing their mental illnesses, which may be referred to a medical panel to determine fitness to drive.

The question is so broad that it would capture loads of irrelevant information, including a bout of post-partum depression twenty years previously. Of course, many people will lie to keep their licences.

The form was introduced to replace a form that many called confusing.

What's most interesting is that the government promptly pulled the form and went back to the old one.

Backlash forces N.S. to drop new driver's licence form

“They should not be collecting personal information on this basis,” Dulcie McCallum, the province’s Freedom of Information and Protection of Privacy review officer, said.

“It’s completely unnecessary.”

That kind of information has historically been used against people, she said.

“It goes kind of to the heart of things that are most intimate and that people want most protected,” Ms. McCallum said. “You can’t make any assumptions about people. You can’t have a policy that automatically creates a different standard for people.

“There’s no evidence to support that somehow psychiatric challenges make you more or less of a bad driver.”

It would be more appropriate to ask if people were taking any prescription medication that could affect their driving, she said.

“That doesn’t connect it to any particular illness or disability or historically disadvantaged group and it may be a bona fide question,” she said.

David Fraser, a Halifax lawyer who specializes in privacy law, said the province deserves credit for acting quickly to fix its error but questioned whether reverting to the old form would solve the problem.

“It sounds to me like an interesting response,” he said. “I’m not sure if it’s to everybody’s benefit if they’re going back to a form that had previously been confusing.

Tuesday, September 09, 2008

Google reduces log retention times

Google has just announced that they are cutting their log retention period in half: from 18 monts to 9 months.

From the Official Google Blog:

Official Google Blog: Another step to protect user privacy

Today, we're announcing a new logs retention policy: we'll anonymize IP addresses on our server logs after 9 months. We're significantly shortening our previous 18-month retention policy to address regulatory concerns and to take another step to improve privacy for our users.

Back in March 2007, Google became the first leading search engine to announce a policy to anonymize our search server logs in the interests of privacy. And many others in the industry quickly followed our lead. Although that was good for privacy, it was a difficult decision because the routine server log data we collect has always been a critical ingredient of innovation. We have published a series of blog posts explaining how we use logs data for the benefit of our users: to make improvements to search quality, improve security, fight fraud and reduce spam.

Over the last two years, policymakers and regulators -- especially in Europe and the U.S. -- have continued to ask us (and others in the industry) to explain and justify this shortened logs retention policy. We responded by open letter to explain how we were trying to strike the right balance between sometimes conflicting factors like privacy, security, and innovation. Some in the community of EU data protection regulators continued to be skeptical of the legitimacy of logs retention and demanded detailed justifications for this retention. Many of these privacy leaders also highlighted the risks of litigants using court-ordered discovery to gain access to logs, as in the recent Viacom suit.

Today, we are filing this response (PDF file) to the EU privacy regulators. Since we announced our original logs anonymization policy, we have had literally hundreds of discussions with data protection officials, government leaders and privacy advocates around the world to explain our privacy practices and to work together to develop ways to improve privacy. When we began anonymizing after 18 months, we knew it meant sacrifices in future innovations in all of these areas. We believed further reducing the period before anonymizing would degrade the utility of the data too much and outweigh the incremental privacy benefit for users.

We didn't stop working on this computer science problem, though. The problem is difficult to solve because the characteristics of the data that make it useful to prevent fraud, for example, are the very characteristics that also introduce some privacy risk. After months of work our engineers developed methods for preserving more of the data's utility while also anonymizing IP addresses sooner. We haven't sorted out all of the implementation details, and we may not be able to use precisely the same methods for anonymizing as we do after 18 months, but we are committed to making it work.

While we're glad that this will bring some additional improvement in privacy, we're also concerned about the potential loss of security, quality, and innovation that may result from having less data. As the period prior to anonymization gets shorter, the added privacy benefits are less significant and the utility lost from the data grows. So, it's difficult to find the perfect equilibrium between privacy on the one hand, and other factors, such as innovation and security, on the other. Technology will certainly evolve, and we will always be working on ways to improve privacy for our users, seeking new innovations, and also finding the right balance between the benefits of data and advancement of privacy.

Wednesday, September 03, 2008

PIPEDA self-assessment tool

Just in time for Privacy Awareness Week (last week), the Privacy Commissioner has released a PIPEDA Self-Assessment Tool which is worth checking out.

Here's some backgound and further info from the Commissioner's website:

News Release: Canada celebrates Privacy Awareness Week by helping businesses improve privacy practices (August 27, 2008) - Privacy Commissioner of Canada

Canada celebrates Privacy Awareness Week by helping businesses improve privacy practices

Ottawa, August 27, 2008 —The Office of the Privacy Commissioner of Canada (OPC) today launched a new tool to help businesses evaluate their privacy practices and compliance with Canada’s private sector privacy law. The launch of the tool coincides with Privacy Awareness Week, which is organized by the Asia Pacific Privacy Authorities (APPA) and runs from August 24 to 30.

The OPC’s new Personal Information Protection and Electronics Documents Act (PIPEDA) Self-Assessment Tool is made up of two parts:

  • A compliance guide, which informs organizations of their obligations under PIPEDA and outlines what organizations must do to meet these obligations; and
  • A diagnostic tool, which gives organizations a series of checklists they can use to assess how compliant they are with the 10 Fair Information Principles of PIPEDA.

With the results of this self-assessment, organizations will be able determine the weaknesses in their privacy systems and understand the risks they pose for the business and customers. It will also help them ensure they dedicate the appropriate resources to ensuring privacy compliance.

“Good privacy practices are good for business,” says Privacy Commissioner of Canada, Jennifer Stoddart. “More and more, organizations are realizing this, and by giving them an efficient and effective means of evaluating and improving their privacy practices, they can develop a competitive advantage.”

The theme for this year’s Privacy Awareness Week is “Privacy is your business”. During the week, participating countries, such as Canada, which is a member of APPA, can promote privacy responsibilities within the public and private sectors, and raise awareness of the public's privacy rights.

The Office of the Privacy Commissioner of Canada recently launched two initiatives aimed at engaging Canadian youth in the privacy debate: an essay competition designed to encourage students in law schools and legal studies programs across Canada to explore privacy issues and a video public service announcement competition for students between the ages of 12 and 18. Information about these initiatives and the new PIPEDA Self-Assessment Tool, as well as other tools to help organizations comply with privacy law, such as a guide for businesses and organizations, an e-learning tool for retailers, fact sheets and a number of new case summaries, can be found at http://www.privcom.gc.ca/media/nr-c/2008/index_e.asp.

For more information on Privacy Awareness Week, visit http://www.privacyawarenessweek.org/.

The Office of the Privacy Commissioner of Canada is mandated by Parliament to act as an ombudsman, advocate and guardian of privacy rights in Canada.

To view the tool: PIPEDA Self-Assessment Tool (Printable Adobe Format)

Tuesday, September 02, 2008

Mass surrender of online privacy

One of the most interesting phenomena (at least to me) is that privacy is not only being taken away on a number of fronts, the wider front is the mass surrender of privacy by the millions of people who put loads of personal data online.

Some people may think it's ironic that I'm on Facebook or Flickr, but I'm pretty mindful of what I put online and who is my "friend". When I was young and foolish, I posted stuff that's still to be found on the internet. Nothing scaldalous: stuff like a travelogue of a visit to Romania and contributions to listservs about academic freedom. But kids these days, armed with digital cameras, are posting vast quantities of personal information that will hang around for years. And is there for those who may not be their friends.

I happened upon an interesting illustration of this on MetaFilter today (It's not dead, it's just resting MetaFilter). Check out these two videos in which private investigator Steve Ramblan discusses his tradecraft:

Hope2604 – Privacy Is Dead – Get Over It In 2006, privacy expert Steven Rambam’s two hour panel was disrupted by federal authorities who arrested him at the conference just prior to its commencement. In the end, he was completely vindicated and went on to finally give his talk several months later to a packed house at a local university. This year, Steven will be on for three hours, in part to make up for what you may have missed last time, but mostly because what he says about the state of privacy in our society will captivate you. Since 1980, Pallorium's investigators have successfully closed more than 9,500 cases, ranging from homicide investigations to missing persons cases to the investigation of various types of sophisticated financial and insurance frauds. Steven Rambam has coordinated investigations in more than fifty (50) countries, and in nearly every U.S. State and Canadian province. Steven specializes in international and multi-jurisdictional investigations, and within the past few years he has conducted investigations in Israel, South Africa, Holland, France, England, India, Mexico, Guatemala, Spain, Portugal, Bulgaria, Germany, Abu Dhabi, China, Mongolia, the Philippines, Thailand, Laos, Jordan, Vietnam and Brazil, among other locations. For More Information Visit www.pallorium.com

Sunday, August 31, 2008

Newly noticed: Photo Attorney

After a very long hiatus, I've been reinfected with the photography bug thanks to acquiring a new digital SLR (some of my recent work is at http://www.privacylawyer.ca/photo or can be found on Flickr here (RSS)).

And of course, everything has to do with privacy and civil liberties, so I've also become quite interested in the recent "war against photography" (examples here, here, here and here). There are also a few interesting perspectives about photography in public places and privacy. People have been harassed for taking pictures of their own children because other children may also be included in the photos. I don't have all the answers, but it's interesting to try to keep up with the debate. To that end, I've added Photo Attorney to my RSS reader, to follow what Carolyn E. Wright has to say on the topic.

Tuesday, August 26, 2008

Privacy? We Got Over It.

Yesterday's Wall Street Journal had an interesting Op/Ed on privacy, highlighting contemporary expectations of privacy.

Information Age - WSJ.com

Privacy? We Got Over It.

August 25, 2008; Page A11

In 1988, Congress banned video stores from disclosing the titles of films that people rent. The issue arose because in the battle to block Robert Bork from the Supreme Court, someone leaked his video rentals.

Fast-forward to this summer, and a federal judge hearing a $1 billion copyright complaint by Viacom ordered YouTube to turn over online records about which computer addresses were used to watch which videos on the site. The judge dismissed privacy concerns as "speculative." How quickly our expectations of privacy have changed.

Privacy advocates objected that with access to Internet protocol addresses, it would be possible to track who watched what. Hundreds of millions of people have watched videos on YouTube since its founding in 2005 -- indeed, by one estimate, virtually everyone who uses the Web has watched a video on the site. This makes it surprising that there was such little public outcry about this potential loss of privacy. Google, which owns YouTube, has complied with the judge's order by using encryption to hide individual records, but it is indeed "speculative" how much people would object to disclosing this online behavior.

This incident is a telling moment. We seem to be following the advice of Scott McNealy, chairman of Sun Microsystems, who in 1999 said, "You have zero privacy anyway. Get over it." And the observation by Oracle CEO Larry Ellison: "The privacy you're concerned about is largely an illusion. All you have to give up is your illusions, not any of your privacy."

These comments could be dismissed as technology executives trying to minimize complaints about technology. But whatever we say about how much we value privacy, a close look at our actual behavior suggests we have gotten over it. A recent study by AOL of privacy in Britain found that 84% of people said they would not disclose details about their income online, but in fact 89% of them willingly did.

Amazon closely records our taste in books, Gmail scans our emails to deliver relevant ads, and electronic tolls track where we drive. Profiles on MySpace and Facebook are accessible, forever. The disclosure that Judge Bork liked to rent British comedies seems quaint in comparison.

Records about us are no longer kept in scattered manila files in dusty cabinets, but digitally, which means in permanent records that can be combined with other records to paint a full picture of our tastes and habits. Information held by different retailers, insurers and government agencies can be mined to create constantly updated files more complete than the most tenacious intelligence report on a suspected criminal a generation ago.

Privacy advocates do their jobs by reminding us of these risks, but our choices all seem to be in the direction of trading away privacy. The fantastic power and convenience of digital life has led us to change what we consider private in ways that we can only begin to understand.

Indeed, our expectations of privacy have changed radically over time. Stanford law professor Lawrence Friedman in his recent book, "Guarding Life's Dark Secrets," documents the total lack of privacy expectations through the medieval period, when people lived together with no option for privacy, to a period of privacy for some people and some purposes as part of what he calls the "Victorian compromise." Propriety was defined through social norms focused on reputation, which included significant freedom for otherwise scandalous behavior if it was done carefully, in private.

"If the nineteenth century was a world of privacy and prudery, a world of closed doors and drawn blinds," Mr. Friedman writes, "then the world of the twenty-first century is the world of the one-way mirror, the world of the all-seeing eye."

We now seem happy to trust companies with our information for benefits such as one-click buying and online searches for personally relevant results. In a digital world where it is possible to know more than ever about everything, including one another, the new vice may be the flip side of privacy -- concealing information about ourselves of legitimate value to others.

In the physical world, surveillance cameras, satellites and bio-recognition systems have redefined privacy expectations. We have learned that "privacy can be very dangerous," as federal appeals judge Richard Posner has observed. "Obviously if you're a terrorist, privacy is enormously important. So the more we think of privacy as endangering us, that will reinforce these commercial incentives to surrender privacy."

Privacy remains a virtue, or at least we still say it does. But the balance has been tipped by other values, such as transparency, a free flow of information and physical security. We're in the early stages of adapting to more digital and visible lives, with privacy expectations better defined by what we do than by what we say.

Monday, August 25, 2008

Hackers target hotel chain and swipe details of all guests from the past year

This is simply staggering, but a harbinger of things to come I am sure:

The Sunday Herald - Scotland's award-winning independent newspaper

Revealed: 8 million victims in the world's biggest cyber heist

EXCLUSIVE: Sunday Herald uncovers theft of data from every guest in 1300 Best Western Hotels in past 12 months

By Iain S Bruce

AN INTERNATIONAL criminal gang has pulled off one of the most audacious cyber-crimes ever and stolen the identities of an estimated eight million people in a hacking raid that could ultimately net more than £2.8billion in illegal funds.

A Sunday Herald investigation has discovered that late on Thursday night, a previously unknown Indian hacker successfully breached the IT defences of the Best Western Hotel group's online booking system and sold details of how to access it through an underground network operated by the Russian mafia.

It is a move that has been dubbed the greatest cyber-heist in world history. The attack scooped up the personal details of every single customer that has booked into one of Best Western's 1312 continental hotels since 2007.

Amounting to a complete identity-theft kit, the stolen data includes a range of private information including home addresses, telephone numbers, credit card details and place of employment....

Thanks to the ever-vigilant Rob Hyndman for the link.

China considers criminal penalty on leaking personal data

Some non-Olympic news from China:

It appears that China is considering criminal law amendments similar to those passed recently in Canada to make it a criminal offense to traffic in personal information. See: China weighs criminal penalty on leaking personal data_English_Xinhua.