Thursday, January 31, 2008

Atlantic Canadian police want local ISPs to loosen up to nab suspected online predators

Earlier this week, the RCMP organized a conference of police, internet service providers and other "stakeholders" on internet safety. I wrangled an invite, but had to go out of town at the last minute. One of the topics under discussion was whether ISPs should disclose subscriber information without a warrant.

My opinion on the topic is well known to readers of this blog (see tag: lawful authority).

Today's Hailifax Daily News has an article on the fact that the two leading ISPs in Atlantic Canada, Eastlink and Aliant, have a policy of requiring a warrant. Interestingly, the article focuses on the word "may" and not "lawful authority" in PIPEDA:

Halifax, The Daily News: Local News Police want local ISPs to loosen up to nab suspected online predators

Police want local ISPs to loosen up to nab suspected online predators

Crime

PAUL MCLEOD

Police in Nova Scotia are at a disadvantage compared to the rest of Canada when it comes to tracking down online sexual predators. Partly it's because of a single word in a piece of legislation.

When someone posts child pornography online, police have to go through Internet service providers - or ISPs - to get the person's name and address.

Most ISPs - over 70 per cent across the country - give police basic information without making them get a warrant. But Cpl. Dave Fox of the RCMP Internet Child Exploitation Unit said the majority of those that require warrants are in Atlantic Canada.

Both of Nova Scotia's two main providers, Aliant and EastLink, make police get warrants before handing over information. It's a process that takes a week on average, police say, and eats up desperately needed resources.

"We're not looking for shortcuts. If we took a shortcut and we were breaching someone's charter rights ... We would risk all the evidence we obtained by this warrantless searches being ruled inadmissible at trial," Fox said.

When contacted by The Daily News, Aliant said it would share information with police in emergency situations, but otherwise ask for a warrant.

"This is how we approach it. We work with them. This is what's in place in terms of our practice," said Aliant communications director Kelly Gallant.

For EastLink, the reluctance comes from the wording of the Personal Information Protection and Electronic Documents Act.

The act states ISPs "may disclose personal information" to police without a warrant.

At issue is the word "may," which some ISPs see as being too vague.

Though the federal government has endorsed pre-warrant requests as complying with the legislation, a minority of companies say handing over personal information without a warrant could expose them to lawsuits.

"The way the law is dictated today it is not clear, so we're erring on the side of the law," said Paula Sibley, communications specialist for EastLink.

"If the legislation was to be clarified, we would fully work within that."

No company has been successfully sued for handing information over to police, though there are two suits in early stages - one in Ontario and one in British Columbia.

Sunday, January 27, 2008

UK Commissioner seeks additional powers and penalties

In stark contrast to Canada's Privacy Commissioner, the Information Commissioner in the UK is looking for stronger powers and penalties. See: IMPACT®: ICO publishes powers and penalties wishlist, which refers to "DATA PROTECTION POWERS AND PENALTIES: The Case for Amending the Data Protection Act 1998".

Wednesday, January 23, 2008

Cory Doctorow: why personal data is like nuclear waste

Cory Doctorow, of Boing Boing fame, has an opinion piece in The Guardian: Cory Doctorow: why personal data is like nuclear waste Technology guardian.co.uk

We should treat personal electronic data with the same care and respect as weapons-grade plutonium - it is dangerous, long-lasting and once it has leaked there's no getting it back...

I'm not sure that nuclear waste is the best analogy. In speaking on the topic, I usually liken personal information to heating oil. Many businesses need oil to operate. Either it is the raison d'etre of the business or it is just one of those things that supports the business. Whatever the case, it needs to be carefully stored or it can leak out and cause a huge, expensive mess. And personal information, like oil, should only be kept around while it is needed. If you don't need it, dispose of it carefully. Personal information that is no longer needed is akin to an underground oil tank: get rid of it (safely) as soon as you can.

No responsible business would allow employees to transport oil in inappropriate containers. The same should apply to personal information.

Personal information is an asset, but a dangerous one: if spilled, can cause a disastrous mess.

European privacy authorities consider IP addresses to be personal information

This is an interesting development.

In 2003, the Privacy Commissioner of Canada released a finding that strongly suggested that an IP address is "personal information" for the purposes of PIPEDA (Commissioner's Findings - PIPEDA Case Summary #25: A broadcaster accused of collecting personal information via Web site - November 20, 2001 - Privacy Commissioner of Canada). Now the European Union is taking a similar position.

This determination has implications for a range of businesses that operate websites, but particularly affects companies like Google, Yahoo! and the like.

Wired News - AP News - EU Official: IP Is Personal

By AOIFE WHITE

AP Business Writer

BRUSSELS, Belgium (AP) -- IP addresses, string of numbers that identify computers on the Internet, should generally be regarded as personal information, the head of the European Union's group of data privacy regulators said Monday.

Germany's data protection commissioner, Peter Scharr, leads the EU group preparing a report on how well the privacy policies of Internet search engines operated by Google Inc., Yahoo Inc., Microsoft Corp. and others comply with EU privacy law.

He told a European Parliament hearing on online data protection that when someone is identified by an IP, or Internet protocol, address "then it has to be regarded as personal data."

His view differs from that of Google, which insists an IP address merely identifies the location of a computer, not who the individual user is - something strictly true but which does not recognize that many people regularly use the same computer terminal and IP address.

Scharr acknowledged that IP addresses for a computer may not always be personal or linked to an individual. For example, some computers in Internet cafes or offices are used by several people.

But these exceptions have not stopped the emergence of a host of "whois" Internet sites that apply the general rule that typing in an IP address will generate a name for the person or company linked to it.

Treating IP addresses as personal information would have implications for how search engines record data.

Google led the pack by being the first last year to cut the time it stored search information to 18 months. It also reduced the time limit on the cookies that collect information on how people use the Internet from a default of 30 years to an automatic expiration in two years.

But a privacy advocate at the nonprofit Electronic Privacy Information Center, or EPIC, said it was "absurd" for Google to claim that stripping out the last two figures from the stored IP address made the address impossible to identify by making it one of 256 possible configurations.

"It's one of the things that make computer people giggle," EPIC executive director Marc Rotenberg told The Associated Press. "The more the companies know about you, the more commercial value is obtained."

Google's global privacy counsel, Peter Fleischer, however, said Google collects IP addresses to give customers a more accurate service because it knows what part of the world a search result comes from and what language they use - and that was not enough to identify an individual user.

"If someone taps in 'football' you get different results in London than in New York," he said.

He said the way Google stores IP addresses meant one of them forms part of a crowd, giving valuable information on general trends without infringing on an individual's privacy.

Google says it needs to store search queries and gather information on online activity to improve its search results and to provide advertisers with correct billing information that shows that genuine users are clicking on online ads.

Internet 'click fraud' can be tracked down by showing that the same IP address is jumping repeatedly to the same ad. Advertisers pay for each time a different person views the ad, so dozens of views by the same person can rack up costs without giving the company the publicity it wanted.

Microsoft does not record the IP address that identifies an individual computer when it logs search terms. Its Internet strategy relies on users logging into the Passport network that is linked to its popular Hotmail and Messenger services.

The company's European Internet policy director, Thomas Myrup Kristensen, described the move as part of Microsoft's commitment to privacy.

"In terms of the impact on user privacy, complete and irreversible anonymity is the most important point here - more impactful than whether the data is retained for 13 versus 18 versus 24 months," he said.

But neither of the search engines received a pat on the back from Spain's data protection regulator, Artemi Rallo Lombarte, who criticized them for not trying to make their privacy policies accessible to normal people.

Their privacy policies "could very well be considered virtual or fictional ... because search engines do not sufficiently emphasize their own privacy policies on their home pages, nor are they accessible to users," he said, describing the policies as "complex and unintelligible to users."

Tuesday, January 22, 2008

Google spars with European lawmakers over privacy in Doubleclick review

Google was able to coast through regulatory review in the US without any consideration of privacy, but Europe is a different matter:

Google spars with European lawmakers over privacy | Reuters

Mon Jan 21, 2008 1:54pm EST

By David Lawsky

BRUSSELS (Reuters) - Google attacked European parliamentarians and privacy advocates on Monday for trying to have competition authorities consider the handling of personal information in its $3.1 billion takeover of rival DoubleClick.

The argument was the centerpiece of a European Parliament hearing to consider the burgeoning role of the Internet in impinging on the privacy of citizens.

The U.S. Federal Trade Commission (FTC) signed off last month on Google's $3.1 billion deal, which combines its dominance in pay-per-click Internet advertising with DoubleClick's market-leading position in display ads.

After listening to a visiting FTC commissioner, U.S. and European privacy advocates and European parliamentarians question the impact of the deal on European citizens' on-line privacy, Google's global privacy counsel shot back.

"People (are) trying to take a privacy case and shoehorn it into a competition law review ... I can understand that people continue to peddle this theory in Europe after having lost in the United States," Peter Fleischer said. His attack did little to calm the waters.

"The reason you want to have the data is because it gives you a competitive advantage. It is business. I don't think they can be completely disconnected. And we should discuss that side of things too," said Sophie in 't Veld, the Dutch parliamentarian who sought the hearing.

She called information a competitive factor and declared: "Having that much information is market power."

Federal Trade Commissioner Pamela Harbour said her four colleagues at the FTC had taken a traditional approach and excluded questions of privacy in their decision. She dissented.

"I believe a traditional approach does not capture the interests of all the parties. There is no proxy for the consumer whose privacy is at stake," she said.

The European Commission has said it will not take privacy into consideration. In the past six years, it has not turned down any all-U.S. deal approved by U.S. authorities.

Fleischer, asked about the deal rationale, said Google wanted to get into banner advertising. He said his firm did not build dossiers on individuals through searches, instead using the words of each search to decide what ads to display with it.

Contractual limits would prevent Google from using DoubleClick information from individuals, he said.

Stavros Lambrinidis of Greece, who chaired the meeting, asked whether Google turned information over to government authorities.

Fleisher said that if authorities go "through a valid legal process we will respond to it".

(Editing by Dale Hudson)

Monday, January 21, 2008

US Department of Commerce privacy incident response plan

Sabrina Pacifici has posted on her (fantastic) blog, beSpacific, a link to the privacy breach response plan put together by the US Department of Commerce: Department of Commerce Breach Notification Response Plan, September 28, 2007 (21 pages, PDF). This, in and of itself, is not particularly newsworthy but it's worth taking a look at as a precedent document in formulating such policies.

The document includes the Department's matrix for determining whether notification is required:

US Office of Personnel Management says not to use SSN as primary identifier

In the better late than never department, the US Office of Personnel Management is telling US government departments and agencies not to use the social security number as a default personnel identifier. See: FederalTimes.com.

Thanks to beSpacific for leading me to the story.

NDP calls for VLT player tracking and intervention

The Government of Nova Scotia is planning to implement a new system for players of video lottery terminals (VLTs), requiring players to use a personal card so they can track their wins and losses, and put limits on their own playing. The system allows the players to remain anonymous. NDP Gambling Critic, Howard Epstein, wants the system to be changed so that the government knows how much players are losing so they can intervene if it appears to be a problem. The privacy issues in this one are obvious. See: Nova Scotia News - TheChronicleHerald.ca - NDP: No anonymous VLT cards - Counsellors should contact gamblers with big losses, critic says.

Privacy Commissioner wades into copyright debate and DRM

The Privacy Commissioner of Canada has waded into the debate over copyright reform in Canada, focusing on the possible privacy impact of digital rights management. The following is from a letter to the Minister of Industry and the Minister of Canadian Heritage:

Letter with respect to possible amendments to the Copyright Act (January 18, 2008) - Privacy Commissioner of Canada

...Technological protective measures can be embedded in various media to control copying and prevent copyright infringement, or they can be built into electronic devices to prevent the reading of unauthorized content. Digital rights management (DRM) is the general term for the varied technologies used to enforce pre-defined limitations on the use of digital content. These include any means by which publishers or manufacturers control use of data or hardware. My office has prepared an information sheet on DRM technology, a copy of which is enclosed for your information.

If DRM technologies only controlled copying and use of content, our Office would have few concerns. However, DRM technologies can also collect detailed personal information from users, who often do no more than access the content on a computer. This information is transmitted back to the copyright owner or content provider, without the consent or knowledge of the user. Although the means exist to circumvent these technologies and thus prevent the collection of this information, previous proposals to amend the Copyright Act contained anti-circumvention provisions.

Technologies that report back to a company about the use of a product reveal a great deal about an individual’s tastes and preferences. Indeed, such information can be extremely personal. Technologies that automatically collect personal information about individuals without their knowledge or consent violate the fair information principles that are central to PIPEDA and most other privacy legislation. That this occurs when individuals are engaged in a private activity in their homes or other places where they have a high expectation of privacy exacerbates the intrusiveness of the collection.

Update: Michael Geist's latest column is on this topic: TheStar.com | columnists | Copyright reform a potential threat to privacy.

Sunday, January 20, 2008

Incident: Personal info on 600K UK military recruits on stolen laptop

The Register reports that a laptop containing the personal information of 600,000 UK military recruits was on a laptop stolen from a naval officer's car. See: Join the army, get your ID pinched - MoD laptop goes AWOL | The Register.