Monday, February 28, 2011

Privacy: Web's Hot New Commodity

by JULIA ANGWIN and EMILY STEEL   WSJ  Feb. 28, 2011


As the surreptitious tracking of Internet users becomes more aggressive and widespread, tiny start-ups and technology giants alike are pushing a new product: privacy.

Companies including Microsoft Corp., McAfee Inc.—and even some online-tracking companies themselves—are rolling out new ways to protect users from having their movements monitored online. Some are going further and starting to pay people a commission every time their personal details are used by marketing companies.


"Data is a new form of currency," says Shane Green, chief executive of a Washington start-up, Personal Inc.1 , which has raised $7.6 million for a business that aims to help people profit from providing their personal information to advertisers.

The Wall Street Journal's year-long What They Know investigation into online tracking has exposed a fast-growing network of hundreds of companies that collect highly personal details about Internet users—their online activities, political views, health worries, shopping habits, financial situations and even, in some cases, their real names—to feed the $26 billion U.S. online-advertising industry.

In the first nine months of last year, spending on Internet advertising rose nearly 14%, while the overall ad industry only grew about 6%, according to data from PriceWaterhouseCoopers LLP and WPP PLC's Kantar Media.

Testing the new privacy marketplace are people like Giles Sequeira, a London real-estate developer who recently began selling his own personal data. "I'm not paranoid about privacy," he says. But as he learned more, he says, he became concerned about how his data was getting used.

Graphic
Companies are introducing free and paid products that help people manage the way companies track their online activities. Some services pay people when their personal details are used.
Picture (Device Independent Bitmap)
People "have no idea where it is going to end up," he says.
So in December, Mr. Sequeira became one of the first customers of London start-up Allow Ltd.2 , which offers to sell people's personal information on their behalf, and give them 70% of the sale. Mr. Sequeira has already received one payment of £5.56 ($8.95) for letting Allow tell a credit-card company he is shopping for new plastic.

"I wouldn't give my car to a stranger" for free, Mr. Sequeira says, "So why do I do that with my personal data?"

As people are becoming more aware of the value of their data, some are seeking to protect it, and sometimes sell it. In January at the World Economic Forum in Davos, Switzerland, executives and academics gathered to discuss how to turn personal data into an "asset class" by giving people the right to manage and sell it on their own behalf.

"We are trying to shift the focus from purely privacy to what we call property rights," says Michele Luzi, a director at consulting firm Bain & Co. who led the Davos discussion.
Allow, the company that paid Mr. Sequeira, is just one of nearly a dozen start-ups hoping to profit from the nascent privacy market. Several promise to pay people a commission on the sale of their data. Others offer free products to block online tracking, in the hopes of later selling users other services—such as disposable phone numbers or email addresses that make personal tracking tougher. Still others sell paid services, such as removing people's names from marketing databases.

"Entrepreneurs smell opportunity," says Satya Patel, venture capitalist at Battery Ventures, which led a group of investors that poured $8 million in June into a start-up called SafetyWeb3 , which helps parents monitor their children's activities on social-networking sites and is rolling out a new privacy-protection service for adults, myID.com 4.

For the lightly regulated tracking industry, a big test of the new privacy marketplace is whether it will quiet the growing chorus of critics calling for tougher government oversight. Lawmakers this month introduced two separate privacy bills in Congress, and in December the Obama administration called for an online-privacy "bill of rights." The Federal Trade Commission is pushing for a do-not-track system inspired by the do-not-call registry that blocks phone calls from telemarketers.

The industry is hustling on several fronts to respond to regulatory concerns. Last week, Microsoft endorsed a do-not-track system. Microsoft also plans to add a powerful anti-tracking tool to the next version of its Web-browsing software, Internet Explorer 9. That's a reversal: Microsoft's earlier decision to remove a similar privacy feature from Explorer was the subject of a Journal article last year5.

The online-ad industry itself is also rolling out new privacy services in hopes of heading off regulation. Most let users opt out of seeing targeted ads, though they generally don't prevent tracking.

The privacy market has been tested before, during the dot-com boom around 2000, a time when online tracking was just being born. A flurry of online-privacy-related start-ups sprang up but only a few survived due to limited consumer appetite.

As recently as 2008, privacy was so hard to sell that entrepreneur Rob Shavell says he avoided even using the word when he pitched investors on his start-up, Abine Inc.6 , which blocks online tracking. Today, he says, Abine uses the word "privacy" again, and has received more than 30 unsolicited approaches from investors in the past six months.

It's rarely a coincidence when you see Web ads for products that match your interests. WSJ's Christina Tsuei explains how advertisers use cookies to track your online habits.

In June, another company, TRUSTe, raised $12 million from venture capitalists to expand its privacy services. At the same time, Reputation.com Inc. raised $15 million and tripled its investments in new privacy initiatives including a service that removes people's names from online databases and a tool to let people encrypt their Facebook posts.

"It's just night and day out there," says Abine's Mr. Shavell.

Online advertising companies—many of which use online tracking to target ads—are also jumping into the privacy-protection business. AOL, one of largest online trackers, recently ramped up promotion of privacy services that it sells.

And in December, enCircle Media, an ad agency that works with tracking companies, invested in the creation of a privacy start-up, IntelliProtect7 . Last month IntelliProtect launched a $8.95-a-month privacy service that will, among other things, prevent people from seeing some online ads based on tracking data.

In its marketing material, IntelliProtect doesn't disclose its affiliation with the ad company, enCircle Media, that invested in it. When contacted by the Journal, IntelliProtect said it would never give or sell customer data to other entities, including its parent companies.

A cofounder of Allow, Justin Basini, also traces his roots to the ad industry. Mr. Basini came up with the idea for his new business when working as head of brand marketing for Capital One Europe. He says he was amazed at the "huge amounts" of data the credit-card companies had amassed about individuals.

But the data didn't produce great results, he says. The response rate to Capital One's targeted mailings was 1-in-100, he says—vastly better than untargeted mailings, but still "massively inefficient." Mr. Basini says. "So I thought, 'Why not try to incentivize the customer to become part of the process?"

People feel targeted ads online are "spooky," he says, because people aren't aware of how much personal data is being traded. His proposed solution: Ask people permission before showing them ads targeted at their personal interests, and base the ads only on information people agree to provide.

In 2009, Mr. Basini left Capital One and teamed up with cofounder Howard Huntley, a technologist. He raised £440,000 ($708,400) from family, friends and a few investors, and launched Allow in December. The company has attracted 4,000 customers, he says.

Mr. Basini says his strategy is to first make individuals' data scarce, so it can become more valuable when he sells it later. To do that, Allow removes its customers from the top 12 marketing databases in the U.K., which Mr. Basini says account for 90% of the market. Allow also lists its customers in the official U.K. registries for people who don't want to receive telemarketing or postal solicitations.

Currently, Allow operates only in the U.K., which (unlike the U.S.) has a law that requires companies to honor individuals' requests to be removed from marketing databases.
Then, Mr. Basini asks his customers to create a profile that can contain their name, address, employment, number of kids, hobbies and shopping intent—in other words, lists of things they're thinking about buying. Customers can choose to grant certain marketers permission to send them offers, in return for a 70% cut of the price marketers pay to reach them. Allow says it has finalized a deal with one marketer and has five more deals it hopes to close soon. Mr. Basini says Allow tries to prevent people from "gaming" the system by watching for people who state an intention to buy lots of things, but don't follow through.

Because Allow's data comes from people who have explicitly stated their interest in being contacted about specific products, it can command a higher price than data gathered by stealthier online-tracking technologies. For instance, online-tracking companies routinely sell pieces of information about people's Web-browsing habits for less than a penny per person. By comparison, Allow says it sells access to Mr. Sequeira for £5 to £10 per marketer.

Mr. Sequeira, the London real-estate executive, says that after he filled out an "intention" to get a new credit card, he received a £15.56 credit in his Allow account: a £10 signing fee plus a £5.56 payment from the sale of his data to a credit-card marketer. So far, he says, he hasn't received a card offer from the company.

"I don't think it's going to make a life-changing amount of money," says Mr. Sequeira. But, he says he enjoyed the little windfall enough that he is now letting Allow offer his data to other advertisers. "I can see this becoming somewhat addictive."

Write to Julia Angwin at julia.angwin@wsj.com8 and Emily Steel at emily.steel@wsj.com

Sunday, February 27, 2011

Facebook vs. FTC Round 2: Facebook Responds

BY GREGORY FERENSTEIN Wed Feb 23, 2011

Facebook's response to the FTC urges optimism and governmental restraint.

Facebook just released a 26-page retort to the Federal Trade Commission’s preliminary report on privacy regulation--a report that social media firms see as an ominous approaching storm of chaotic bureaucracy. In summary, Facebook fears that government meddling could stifle both its ability to profit and smother the industry’s progress on yet-unknown technological advancements.

Facebook responded in mirror-image to the FTC; first, (respectively) reminding the FTC how much social media has done for the government itself, the advancement of democracy, and the growing cottage industry of social software:

On government
"In government, leaders use social media services to promote transparency, as evidenced by the nearly 140,000 followers of the White House Press Secretary's Twitter feed and the fact that more than 70 federal agencies have Facebook pages."

On democracy
"Advocates of democracy used Twitter to make their voices heard following the contested 2009 Iranian election of and Oscar Morales in Colombia famously employed Facebook to organize massive street demonstrations against the FARC terrorist group in 2008. Most recently, people in Tunisia and Egypt used social media to spread up-to-the-minute news, share videos of local events with the broader population, and mobilize online communities of thousands (and sometimes millions) behind a common cause."

On business
"Finally, the social web is a crucial engine for economic growth and job creation. Hundreds of thousands of application developers have built businesses on Facebook Platform. To take just one example, games developer Zynga, creator of the popular Farmville game, has more than 1,300 employees and has been valued at about $5.8 billion."

Second, it pleaded for the FTC to be optimistic about how ostensibly intrusive technologies end up benefiting the public:

Caller ID
"Telephone companies originally collected and exchanged subscribers’ telephone numbers solely for the purpose of completing telephone calls. But telephone companies later realized that they could use this information to display the calling party's telephone number and name to the call recipient, allowing the recipient to identify the caller in advance. Today, caller ID is an accepted and valued part of telephone communication, and few subscribers choose to block outgoing caller ID even though it is easy to do so."

Facebook Newsfeed
"In 2006 Facebook launched a new feature called News Feed on every person's homepage. The product updated a personalized list of news stories throughout the day so users would know what their friends were posting. Before News Feed, people had to visit their friends' profiles to see what their friends were up to. Despite initial user skepticism when the product was first launched, News Feed is now--as any user would attest--an integral part of the Facebook experience."

Google Flu Trends
"When the founders of Google began collaborating on a search engine research project in 1996, they probably did not envision that search queries about topics would one day become an early detection system for flu outbreaks. Today, Google Flu Trends can estimate flu activity one to two weeks more quickly than traditional surveillance systems involving virologic and clinical data, and may help public health officials and health professionals better respond to seasonal epidemics."

Finally, Facebook urged the FTC to be sensitive to the business implications of its decisions: “For Facebook--like most other online service providers--getting this balance right is a matter of survival,” the report notes.

It continued, "Ultimately, the FTC's enforcement activities in the area of privacy must be guided by the realization that aggressive enforcement and imprecise standards can lead to more legalistic disclosures--and, as described above, chill economic growth--as companies seek to manage regulatory risk by over-disclosing, reserving broad rights, and under-innovating. To avoid these unintended consequences, the FTC should err on the side of clarifying its policies rather than taking aggressive enforcement action against practices that previously were not clearly prohibited."

Both the FTC and Facebook have been light on data on experimental evidence--and both are obscuring a yet unrevealed future value (or detriment) associated with all of this sharing. Then again, forecasting problems into a very turbulent future is nearly impossible. Ultimately, both documents read like the fight will come down to a philosophical debate. And billions of dollars.
Full Facebook response at: http://www.fastcompany.com/1731121/facebook-ftc-response

Privacy and Security in Health Care: A Fresh Look (Deloitte)

"Privacy and security is a significant challenge for every health care organization and a concern for every U.S. citizen. The move toward an entirely automated health care system featuring electronic and personal health records, clinical data warehousing, and increased transparency means more data is at risk and suggests an urgent review of industry privacy and security safeguards.

The potential liability for data breaches is significant and increasing. Stakeholders must act now to prevent compromising sensitive patient data, preserve brand value, and avoid substantial financial penalties for violations.

This Issue Brief from the Deloitte Center for Health Solutions (DCHS):
    • Provides an update about current and emergent privacy and security challenges in health care;
    • Examines notable hot spots where current policies, rules, and regulations are a focus of industry risk;
    • Reviews the state of preparedness for privacy and security risk throughout the industry;
    • Suggests an approach to assessing an organization's current preparedness."
http://www.deloitte.com/us/privacyandsecurityinhealthcare

Thursday, February 17, 2011

Rethinking personal data | New World Economic Forum Report

Personal data – digital data created by and about people – represents a new economic “asset class”, touching all aspects of society. The abundance of personal data represents untapped opportunities for economic growth and social benefit; however, the barriers restricting personal data’s movement and protection need to be resolved. Granting individuals greater control over their data is necessary to create a balanced personal data ecosystem.

The report addresses the interrelated and complex cultural, business, technology and policy trends shaping the personal data ecosystem by presenting a user-centric set of recommendations for individuals, private enterprise and policy-makers. In particular, the report suggests five areas for collective action:

1) Innovate around user-centricity and trust. The personal data ecosystem will be built on the trust and control individuals have in sharing their data. Continued testing and promoting of trust frameworks that explore innovative approaches for identity assurance at Internet scale are needed.

2) Define global principles for using and sharing personal data. Given the lack of globally accepted policies governing the use and exchange of personal data, an international community should articulate core principles of a user-centric personal data ecosystem.

3) Strengthen the dialogue between regulators and the private sector. Technologists should closely align with regulators to establish processes that enable stakeholders to formulate and update a standardized set of rules to create a basic legal infrastructure.

4) Focus on interoperability and open standards. Stakeholders should identify best practices and engage with standards bodies, advocacy groups, think tanks and various consortia on the user-centric approaches required to scale the value of personal data. 

5) Continually share knowledge. To stay current, stakeholders should actively share insights and lessons learned on their relevant activities (both successes and failures). The ecosystem promises tremendous value created when individuals share information about who they are and what they know. This principle should also apply to practitioners within the development community.

Launched in 2010, the Rethinking Personal Data project is a multi-year project intended to bring together private companies, public sector representatives, end-user privacy and rights groups, academics and topic experts to deepen the collective understanding of how a principled, collaborative and balanced personal data ecosystem can evolve.

Report at http://www3.weforum.org/docs/WEF_ITTC_PersonalDataNewAsset_Report_2011.pdf

For more information, please contact jessica.lewis@weforum.org 

Monday, February 14, 2011

Healthcare Social Media Sites Neglect Privacy Protections

Analysis of diabetes sites indicates that many lack scientific accuracy and put users' personal information at risk.

By Nicole Lewis,  InformationWeek Feb. 14, 2011

As the Internet in general and social networking in particular are used as a point of reference for gathering and sharing health information, a study that examined 10 diabetes-focused social networking sites has found that the quality of clinical information, as well as privacy policies, significantly varied across these sites.

The study, "Social but safe? Quality and safety of diabetes-related online social networks," was conducted by researchers in the Children's Hospital Boston informatics program who performed an in-depth evaluation of the sites and found that only 50% presented content consistent with diabetes science and clinical practice.

The research, published in late January in the Journal of the American Medical Informatics Association, also revealed that sites lacked scientific accuracy and other safeguards such as personal health information privacy protection, effective internal and external review processes, and appropriate advertising.

For example, misinformation about a diabetes cure was found on four moderated sites. Additionally, of the nine sites with advertising, transparency was missing on five, and ads for unfounded cures were present on three. Technological safety was poor, with almost no use of procedures for secure data storage and transmission.

The study found that only three sites support member controls over personal information. Additionally, privacy policies were difficult to read and only three sites (30%) demonstrated better practice, wrote the study's authors.

Elissa R. Weitzman, lead author of the study and assistant professor at Harvard Medical School, told InformationWeek that she was surprised at the high use of online health-related social networking among people with diabetes, and noted that the healthcare community and key stakeholders at these sites should implement policies to protect member privacy and align site content with medical science and clinical practice.

"Exchanging information on these sites has the potential to accelerate what we know about this disease and to rapidly disseminate vital information and support. However, the spread of information throughout online communities poses a safety concern for patients," Weitzman observed. "I'm surprised that the clinical healthcare system seems to be lagging behind patients and consumers in engaging with this medium and finding ways to support them, synergistically -- without trying to replace or control them."


"I think a sustainable standard for how these communities operate with respect to privacy, security, and honesty will come about because the communities themselves and their users will adopt and enforce norms of transparency and protection," Weitzman predicted. "One way this could happen is for stakeholders of these sites to develop a system of 'peer review' around these issues to support better or best practices."

The study evaluated diabetes Web sites that appeared prominently in Google searches and allowed members to create personal profiles and interact with each other. The study examined four key factors:

-- agreement of content with diabetes science and clinical practice standards,
-- practices for auditing content and supporting transparency,
-- accessibility and readability of privacy policies, and
-- the degree of control members had over the sharing of personal data.

The average number of members per Web site was 6,707. Activity ranged widely among the sites, from over 100 new posts per day to less than 5 new posts per day.

Other findings were that the majority of sites did not include a "disclaimer" encouraging patients to discuss their care regimen with a healthcare provider. Several sites did not post essential diabetes information, such as the definition of "A1c" -- a biomarker commonly used by diabetics to access blood glucose levels.

In addition to recommending improvements in these areas, the authors saw a need for increased moderation, for the credentials of moderators to be more visible, and for periodic external review. Further, potential conflicts of interest -- such as ties to the pharmaceutical industry -- needed to be more clearly disclosed, and privacy policies easier to understand.

Weitzman is an assistant professor in the laboratory of Kenneth Mandl, who also co-authored the study. Last year the two developed an application for the social networking website TuDiabetes that allows users to submit their A1c levels to be displayed in a worldwide map, as part of an effort to encourage diabetes management and inform public health efforts and research.

Researchers said they chose to study diabetes-related networks because they were among the earliest to emerge and remain among the most active. The research team in the Children's Hospital informatics program will further study how these sites are used -- how people choose to interact with them and how specifically they share their medical information.
Weitzman also said the Web is a notoriously difficult sphere to regulate with respect to issues of privacy, information security, and honesty in advertising, but said she is hopeful that these sites will improve.

California Supreme Court Finds that ZIP Codes Are Personal Identification Information Under Song-Beverly Act

Posted at 3:14 PM on February 14, 2011 by Hunton & Williams LLP

California Supreme Court Finds that ZIP Codes Are Personal Identification Information Under Song-Beverly Act

On February 10, 2011, the California Supreme Court ruled in Pineda v. Williams-Sonoma Stores, Inc. that ZIP codes are “personal identification information” under the state’s Song-Beverly Credit Card Act of 1971 (the “Credit Card Act”).  This finding effectively prohibits California businesses from requesting and recording cardholders’ ZIP codes during credit card transactions.

When the plaintiff made a purchase by credit card at the defendant retailer, a cashier requested her ZIP code and she provided it, believing that it was necessary to complete the transaction.  The plaintiff alleged that the store then used her name and ZIP code to locate her home address, which it added to a marketing database. 

The Court of Appeals affirmed the trial court’s dismissal of the claim, holding that a ZIP code, without more, does not constitute personal identification information under the Credit Card Act.  The California Supreme Court reversed and remanded.

The Court first looked to statutory construction in its analysis of whether ZIP codes constitute personal identification information.  The Credit Card Act defines personal identification information as “information concerning the cardholder, other than information set forth on the credit card, and including, but not limited to, the cardholder’s address and telephone number.” 

The Court found that the word “address” in the statute should be construed as encompassing not only a complete address, but also its components.  Furthermore, the Court rejected the lower court’s conclusion that a ZIP code is not personal identification information because it pertains to a group, rather than a specific individual.  The Court found that ZIP codes are like addresses or telephone numbers in that such information is “unnecessary to the sales transaction” and “alone or together with other data such as a cardholder’s name or credit card number, can be used for the retailer’s business purposes.” 

The Court noted that this interpretation is also consistent with the Credit Card Act’s provision which allows businesses to require the cardholder to provide a form of identification, such as a driver’s license, “provided that none of the information contained thereon is written or recorded.”

In addition to examining the statute’s provisions, the Court reviewed the legislative history of the Credit Card Act.  The Court found that the California Legislature “intended to provide robust consumer protections by prohibiting retailers from soliciting and recording information about the cardholder that is unnecessary to the credit card transaction.”  A primary issue motivating the creation of the statute was how retailers acquired additional personal information, unnecessary to the transaction, to build mailing and telephone lists for its in-house marketing or to sell or others.  Later amendments of the statute prohibited businesses from recording information in consumers’ provided identification; the purpose of which was to prevent retailers from matching this information with the consumer’s credit card number.

The Court rejected the defendant’s argument that its construction of the Credit Card Act violates due process, and found that a broad interpretation of the Credit Card Act did not render the statute unconstitutionally vague because the law includes adequate notice of prohibited conduct.

Trackbacks (0) Links to blogs that reference this article Trackback URL

http://www.huntonprivacyblog.com/admin/trackback/239896


Comments (0) Read through and enter the discussion with the form at the end
© Hunton & Williams LLP 2011 - ATTORNEY ADVERTISING. Case results depend upon a variety of factors unique to each case. Case results do not guarantee or predict a similar result in any future case.
Unless otherwise noted, attorneys not certified by the Texas Board of Legal Specialization.

Friday, February 11, 2011

Civil rights office seeks review of privacy rule

       
The Office for Civil Rights at HHS has sent to the White House Office of Management and Budget for review a new privacy rule covering an expanded requirement that healthcare providers track and be able to report to patients any disclosures of their medical records.

Patients have long had limited rights under the privacy provisions of the Health Insurance Portability and Accountability Act of 1996 to demand that providers and other “covered entities” provide them with an accounting of disclosures of their personally identifiable medical information.

The American Recovery and Reinvestment Act of 2009, however, expanded patients' privacy rights and closed a HIPAA exemption that covered entities were not required to audit and account for disclosures for treatment, payment and a broad, catch-all category known as other “healthcare operations,” if the covered entity uses an electronic health-record system. The ARRA eliminated that exemption and the new rule before the OMB provides language to implement the rule change. Patients can demand an accounting of disclosures going back three years from the date the demand is made. The accounting requirement also applies to business associates of covered entities.

In a May 3, 2010, request for
public comment on the disclosure rules (PDF), the Office for Civil Rights at HHS noted that the new rule would require covered entities who have acquired an EHR after Jan. 1, 2009, to comply with the new accounting requirement by Jan. 1, 2011, unless the OCR extends the deadline, which is allowed but only no later than 2013. - Joseph Conn