Tuesday, February 16, 2016

New ACLU Guide: Tips for Tech Companies on Protecting User Privacy and Free Speech in 2016

This third edition addresses new challenges facing businesses today and shows how to avoid missteps while building privacy and free speech into products and company culture. The lessons include:

Respect your data. Avoid Magna Carta-level mistakes by collecting only the data you need for your product and making sure that your algorithms and data use protect users andavoid replicating real world biases. 
Create a secure data ecosystem. Security isn’t just about outside threats – companies need to limit internal access to data to avoid Uber-embarrassment, incorporate encryption for data collection and storage to prevent disastrous breaches, and collaborate with security researchers to protect users.
Be transparent about practices. Clear descriptions of privacy practices are essential to avoiding PR disasters, whether the product is a music streaming service, a useful app, or a connected “Internet of Things” device.
Encourage speech by empowering users. Companies can create cohesive communities and avoid harmful, speech-chilling harassment by creating platforms with tools that empower users, account policies that respect user identities, and narrow rules focused on bad behavior rather than content censorship.
Fight for your users. Companies that support user privacy and speech protections routinely receive praise, while those that seek to limit how products are used or that fold to legal demands lose the trust of users and public alike. 

By Nicole A. Ozer
read full article at ACLU

EU’s ‘Right to Be Forgotten’ policy sets bad precedent for free expression

Last week’s announcement that Google will begin suppressing links to URLs not only for searches on EU country-level domains, but also for searches conducted from within EU countries, is bad news, write Jens-Henrik Jeppesen and Emma Llansó.

Jens-Henrik Jeppesen is director for European affairs and Emma Llansó is director for the Free Expression Project at the Center for Democracy and Technology.

The move is the latest development in the debate over the “right to be forgotten”. In 2014, the Court of Justice of the European Union found that under the data protection directive, people in the EU have a right to demand that search engines de-list URLs linking to information that is “inadequate, irrelevant or no longer relevant, or excessive.”

We are sympathetic to people distressed by information about them in the public domain, we understand the desire to suppress such information in certain contexts, and we support targeted and proportionate policies to protect individuals’ right to privacy.

But our overriding concern with the Google Spain v AEPD Mario Costeja Gonzales ruling that triggered the right to be forgotten is that it enables broad restriction of access to lawful, public information, inevitably curbing free expression. 

By Emma Llansó, Jens-Henrik Jeppesen
read full article at EurActiv

Article 29 Working Party lays out GDPR action plan

Last week, in a highly anticipated presser, the Article 29 Working Party shared its preliminary assessment of the proposed EU-U.S. Privacy Shield agreement. Lost amidst this anticipation, however, was an equally significant announcement from the regulatory collective’s head, Isabelle Falque-Pierrotin, regarding the group’s action plan for the implementation of the General Data Protection Regulation.

While the mandatory DPO doesn't come into force until 2019 at the earliest, and mechanisms like the European Data Protection Board and the one-stop shop won't be operational until 2018, look for guidance to be released on what those efforts will look like, along with guidance for controllers and processors on high-risk assessments and the operationalizing of data portability, before the end of the year. 

by Jedidiah Bracy, CIPP/E, CIPP/US
read full article at IAPP

‘I have nothing to hide’ is killing the privacy argument

The newfound interest in privacy is similar to previous debates on the same topic. What causes outrage today is quelled tomorrow and then ultimately forgotten until something else stirs the waters.

In the 2000s we had Echelon and Carnivore, two covert programs used by government agencies to monitor communications.

Later, we had Julian Assange and Wikileaks helping to further the fight by bringing attention to similar programs.

More recently, it was Edward Snowden detailing the newest incarnations of government spy tools known as XKeyscore and PRISM.

Today, we have GCHQ fanning the flames, the NSA continuing its spying programs (only this time, with transparency) and politicians waxing poetic about the dangers of this newfound tool that facilitates terrorism, encryption. 

by Bryan Clark
read full article at The Next Web

The Business Implications of the EU-U.S. “Privacy Shield”

Last week, the U.S. and EU announced a tentative agreement to allow U.S. companies to continue sending and receiving personal information about EU residents across EU borders — everything from an online employee directory for a multinational company to a Facebook profile stored in the cloud.

An earlier agreement, known as the Safe Harbor Privacy Principles, which went back 15 years and was relied on by some 4,000 companies, was declared illegal last year based on concerns, highlighted by the Edward Snowden disclosures, that compliance with surveillance requests from U.S. government agencies, notably the NSA, may have put U.S. companies into conflict with the EU’s broadly written privacy directives. 

by Larry Downes
read full article at Harvard Business Review

ISPs want “flexible” privacy rules that let them “innovate” with customer data

Broadband industry lobby groups urged the Federal Communications Commission on Thursday not to impose privacy rules that dictate "specific methods" of protecting customer data, since that would prevent "rapid innovation."

ISPs should have "flexibility" in how they protect customers' privacy and security, said the letter from the American Cable Association, Competitive Carriers Association, Consumer Technology Association, CTIA, the Internet Commerce Coalition, the National Cable & Telecommunications Association, and USTelecom. Together, these groups represent the biggest home Internet service providers and wireless carriers such as Comcast, AT&T, Verizon, Time Warner Cable, Charter, Sprint, T-Mobile, and many smaller ones. 

by Jon Brodkin
read full article at The Register

FCC poised to flex new privacy powers

Before the net neutrality ruling, the Federal Trade Commission policed privacy at both Internet service providers and online companies like Google and Facebook, using the same standards.

“Well, I think essentially, the key point is that consumers have certain expectations as to how their private information will be treated,” said Lynn Follansbee, a vice president for law and policy at USTelecom, which represents broadband providers.

“And we just take a position that no matter, across the whole Internet ecosystem, no matter what kind of technology is involved, consumers shouldn’t be surprised."

The privacy fight stems from the net neutrality rules approved in a party-line vote by the FCC a year ago.

The commission treated Internet service providers like traditional phone service to apply new rules requiring all Web traffic to be handled in the same way. That left the FCC in the difficult spot of applying privacy regulations for phone companies to broadband providers. Those rules protected information on whom a customer called and when, for example.

But applying those regulations directly to new technology would have been a tall order for the agency. The commission decided last year to instead create new regulations exclusively for broadband service.

By David McCabe
read full article at TheHill

Instagram’s multi-account feature has a privacy bug on Android

Users welcomed Instagram’s new multi-account feature earlier this month but it seems that there are some teething problems.

Some people using Android phones have reported that they are receiving private notifications and DMs intended for the other people who have mutual access to an account. 

by Amanda Connolly
read full article at TheNextWeb

8 Ways To Secure Data During US-EU Privacy Fight

The EU-US Safe Harbor that governed the flow of data between the US and European Commission countries is dead, and there's no formal framework text to replace it yet. The result is a lot of legal uncertainty for many organizations when it comes to transatlantic transfers of data. It may be weeks or months before the dust settles. What do enterprises need to know now?

First, some background. On October 6, 2015, the European Court of Justice invalidated the EU-US Safe Harbor framework in the Maximilian Schrems v Data Protection Commissioner case. A couple of weeks later, the Article 29 Working Party issued a statement about the practical effects of the ruling. The group urged businesses to proceed very carefully. Then on February 2, 2016, the European Commission (EU) announced it and the US had agreed on a new framework for transatlantic data flows called the EU-US Privacy Shield, but because no text is yet available, the framework cannot be interpreted. 

by Lisa Morgan
read full article at InformationWeek

How the new EU privacy regulations will help consumers

I’ve recently asked hundreds of people whether they knowingly allow their smartphones to be tracked and mined for data on their movements, and only two have so far said yes.

Even a recent meeting of 25 data scientists from the UK Geospatial Institute found only one person who knew about this. This small finding highlights how unaware most people are that their location privacy is being intruded upon by big tech companies every moment of every day. 

By Gary Flood
read full article at ITproportal

Justice Scalia: Underappreciated Fourth Amendment Defender

In addition to his many judicial bona fides, Justice Antonin Scalia was an underappreciated defender of the Fourth Amendment. With his typical thoroughness and deep textualism that reshaped American judging, the late conservative icon threw out convictions of individuals who were arrested as a result of unconstitutional violations. In Kyllo v. United States (2001), police illegally took thermal images of a man’s home to find a marijuana grow operation. In United States v. Jones (2012), a man had his Jeep tracked with GPS devices without a warrant, leading to a drug trafficking conviction. And in Florida v. Jardines (2013), police brought a drug dog onto a man’s porch to indicate drug activity inside, again, a marijuana grow operation. To Justice Scalia, the sanctity of a person’s home and property—beyond the “reasonable expectation of privacy” standard that dominates Fourth Amendment jurisprudence—was to be held above the governmental interests in fighting crime.

In Kyllo, Scalia wrote for a divided 5-4 majority that included Justices Clarence Thomas, Ruth Bader Ginsburg, David Souter, and Stephen Breyer: “The Fourth Amendment’s protection of the home has never been tied to the measurement of the quality or quantity of information obtained….In the home, our cases show, all details are intimate details, because the entire area is held safe from prying government eyes.” In Jardines, another non-traditional 5-4 split in which he was joined by Justices Thomas, Ginsburg, Sonia Sotomayor, and Elena Kagan, Scalia affirmed this dedication to the home, writing “[W]hen it comes to the Fourth Amendment, the home is first among equals.” 

By Jonathan Blanks
read full article at CatoInstitute

Solving disputes online: New platform for consumers and traders

The Online Dispute Resolution (ODR) platform offers a single point of entry that allows EU consumers and traders to settle their disputes for both domestic and cross-border online purchases. This is done by channeling the disputes to national Alternative Dispute Resolution (ADR) bodies that are connected to the platform and have been selected by the Member States according to quality criteria and notified to the Commission..

Key features of the platform:
The platform is user-friendly and accessible on all types of devices. Consumers can fill out the complaint form on the platform in three simple steps.
The platform offers users the possibility to conduct the entire resolution procedure online.
The platform is multilingual. A translation service is available on the platform to assist disputes involving parties based in different European countries. 

read full article at EuropeanCommission