Showing posts with label Legislation. Show all posts
Showing posts with label Legislation. Show all posts

Monday, July 18, 2011

CDT Justin Brookman: Why the US needs a data privacy law-and why it might finally get one

Why the US needs a data privacy law—and why it might finally get one
By Justin Brookman | Published July 18, 2011  ARS

The general public and Congress have both discovered geolocation, data breaches, and tracking cookies—and they're worried about the privacy implications. In this op-ed, the Center for Democracy & Technology's Justin Brookman argues that this could be the moment at which everything comes together to make comprehensive privacy reform possible. The opinions in this op-ed do not necessarily represent those of Ars Technica.

With the understandable exceptions of the national debt and the deployments of our troops abroad, privacy is possibly the hottest issue in Congress today. After ten years of limited interest in the subject, we’ve recently seen a spate of legislation introduced to give consumers rights over how their information is collected and shared.

In the House of Representatives, Reps. Bobby Rush (D-IL) and Cliff Stearns (R-FL) have each introduced separate comprehensive bills. In the Senate, John Kerry (D-MA) and John McCain (R-AZ) recently introduced the "Commercial Privacy Bill of Rights" with similar goals. The (Democrat-led) Senate Commerce Committee recently held a hearing on the topic of privacy; the next week, the (Republican-led) House Energy and Commerce Committee looked at the same thing.

In a town where positions on issues are often deeply divided along partisan lines, it’s encouraging to see that there appears to be at least one issue that both parties recognize as a problem that needs to be addressed.

Not much company
Here’s why Congress is interested: today, the United States and Turkey are the only developed nations in the world without a comprehensive law protecting consumer privacy. European citizens have privacy rights, Asian citizens have privacy rights, Latin American citizens have privacy rights. In the US, however, in lieu of a comprehensive approach, we have a handful of inconsistent, sector-specific laws around particularly sensitive information like health and financial data. For everything else, the only rule for companies is just “don’t lie about what you’re doing with data.”

The Federal Trade Commission enforces this prohibition, and does a pretty good job with this limited authority, but risk-averse lawyers have figured out that the best way to not violate this rule is to not make explicit privacy promises at all. For this reason, corporate privacy policies tend to be legalistic and vague, reserving rights to use, sell, or share your information while not really describing the company’s practices. Consumers who want to find out what’s happening to their information often cannot, since current law actually incentivizes companies not to make concrete disclosures.

This has been the case for years, of course, but in the modern era of constant connectivity, social networking, and cheap data storage and processing, the stakes are remarkably higher. Before the advent of the Internet, there were only so many data points for marketers and information brokers to collect about you, and bookstores and libraries didn’t share what you were reading. Even just a few years ago, when you went to a major publisher website, there might have been a couple third-party trackers on the site who could drop a cookie on your computer to “anonymously” track you across other sites. Today, these same sites may deploy hundreds of trackers from dozens of different companies, many of which know your offline identity as well. What happens to all that information? With whom is it shared? No one really knows, and there is no framework to regulate it.

Bad for business
This black box into which our data flows is bad for consumers, but it’s increasingly an impediment to US businesses as well. As Silicon Valley companies encourage consumers to store their personal data in “the cloud,” people are legitimately asking, “Why? What’s going to happen to my data there?” Today, the US is the undisputed leader in cloud computing services, but international competitors are increasingly advertising the fact that their services aren’t US-based. The Department of Commerce recently issued a report arguing that the lack of privacy protections threatens both the adoption of new technologies by worried consumers and the ability to have international data sent to the US. Last week, Forrester Research released a study showing that privacy concerns were the biggest impediment to the growth of e-commerce on mobile technologies.

Companies would be better off if they all provided meaningful privacy protections for consumers, but privacy is a collective action problem for them: many companies would love to see the ecosystem fixed, but no one wants to put themselves at a competitive disadvantage by imposing unilateral limitations on what they can do with user data. It’s fantastic to see companies endeavoring to compete on privacy (such as Google touting the privacy features of its new social network), but so far such competition has been spotty and often takes place at the margins. Many companies that touch and store consumer data don’t have consumer-facing sides (like the ever-increasing number of intermediaries in the behavioral advertising space), so it’s hard to see the Internet ecosystem fixing itself on its own.

And let’s be frank: so far, self-regulation hasn’t been enough. Increasingly, leading multinational corporations have recognized this problem, and companies like Microsoft, Intel, and HP that have heavily invested in cloud technologies have endorsed specific legislative solutions such as the Kerry-McCain and Rush bills to provide consumers with comprehensive privacy protections.

Any privacy law that is enacted doesn’t need to, and shouldn’t, prohibit data sharing or invalidate business models. However, consumers have a right to know what’s happening with their information and to have a say in how it gets shared. If a company insists on sharing data about a consumer as a condition of doing service, fine. As long as that fact is clearly conveyed, and the consumer decides to accept the terms, we shouldn’t put limits on what consumers are willing to do with their own information. Unfortunately, consumers today aren’t even told what’s happening, so they can’t exercise meaningful control over their data unless they take extreme measures to anonymize their surfing though services like Tor or block third-party content (which surely isn’t the right result for anyone).

So will a new law be passed? As with anything in Washington, it’s hard to say what will happen—Congress has a lamentable tendency to kick problems down the road for another day. However, with tremendous attention to privacy issues and widespread consumer support for basic consumer protections, we have the best opportunity in memory to enact basic rules to give people control of their personal information and to give them confidence in an increasingly complex data ecosystem. We should take advantage of this moment to develop a considered consensus on reasonable baseline protections that work for both consumers and businesses.

Justin Brookman is Director of the Consumer Privacy Project at the Center for Democracy & Technology in Washington, DC.

Wednesday, July 13, 2011

Lack of Genuine Privacy Interest Doomed Vermont Drug Marketing Law

  
Deven McGraw        Monday, July 11, 2011  Ihealthbeat

On June 23, the Supreme Court issued its much anticipated decision in Sorrell v. IMS Health, striking down as unconstitutional a Vermont statute that prohibited the use of drug prescribing information for marketing purposes. In a 6-3 decision, the court found that the Vermont law violated the free speech rights of drug marketers. 

A number of privacy advocates had weighed in on the case, seeing it as a showdown between privacy and corporate claims of free speech rights. The Center for Democracy & Technology was skeptical of the privacy arguments made in defense of the law, but we too were worried about its potential impact on a range of health privacy and health IT issues.

After thorough review of the opinion, it is clear that the case should not be read as a threat to well-crafted privacy laws. As interpreted by the Supreme Court, the Vermont statute was an explicit effort to control specific speech by specific speakers -- a double no-no in First Amendment jurisprudence. And, as a privacy law, it was ineffective because it allowed pharmacies to share the covered information with anyone for any reason save one: marketing by drugmakers.

Ironically, a more comprehensive regulation of prescription data -- motivated by a genuine interest in protecting privacy and drawn to serve that interest -- would have been more likely to have been upheld.
Why Did the Supreme Court Strike Down This Law?

To begin with, it is important to recognize that patient privacy was not at issue in Sorrell v. IMS Health because the data at question did not identify patients.  Instead, the data identified prescribers, primarily doctors, and their prescribing patterns. In a process known as "detailing," drug company sales representatives use the data when they visit a doctor's office to persuade the doctor to buy a particular pharmaceutical, which the court noted was almost always a "high-profit brand-name" drug.

The Supreme Court found that the intent of the law was targeted solely at the marketing of brand-name drugs by drugmakers. The law prohibited the sale of prescriber-identifying data without the prescriber's consent, but the exceptions to that prohibition were so broad that they actually allowed sale to anyone except drugmakers. The law also prohibited the use of such data, absent prescriber consent, by pharmacies and drugmakers for marketing purposes. On the face of these provisions alone, the Supreme Court had no trouble finding that the law was a transparent attempt to stop pharmaceutical companies from engaging in effective marketing of their brand-name drugs. 

Matters got worse when the court looked at the findings adopted by the Vermont state Legislature when it passed the law. Those findings expressly said, "the goals of marketing programs are often in conflict with the goals of the state." Since the Supreme Court has long held that marketing is "speech" under the First Amendment, and since the whole point of the First Amendment is to protect speech that the government doesn't like, this statement alone probably doomed the law.

Normally, commercial speech is subject to a relatively weaker form of protection than non-commercial speech. But once the Supreme Court found the Vermont law was targeting a specific kind of speech -- drug marketing -- by a specific kind of speaker -- drug companies -- the law became subject to what the court calls "heightened scrutiny." On top of that, the court found the law appeared to allow the use of prescriber-identifying data to promote less-expensive generic drugs. 

So, in the Supreme Court's view, the law allowed covered information to be used for those marketing messages the state considered to be good, and only prohibited its use for marketing messages the state thought was bad. That kind of control is called "viewpoint" discrimination -- where the government is targeting only one side of an issue -- and that is the ultimate offense under the First Amendment.

With all of that, the Supreme Court said that the Vermont law might have withstood scrutiny if it in fact had been well crafted to serve a legitimate state interest. And, the court assumed that protecting doctor privacy was a legitimate state interest. The problem was that the law totally failed to protect privacy and was not an appropriate response to the other goals the state advanced in its defense.

In rejecting the privacy claim, the Supreme Court emphasized that under the Vermont law, "pharmacies may share prescriber-identifying information with anyone for any reason save one:" marketing. The court noted that the state "all but conceded" that the statute does not advance confidentiality interests. Further, arguments that the law also was intended to protect doctors from aggressive sales tactics carried no weight with a court that had previously held that the First Amendment protects speech even when it "may move people to action, bring them to tears or inflict great pain."

The state also argued that the law advanced legitimate public policy goals by lowering the cost of health care. That is a legitimate goal, the court agreed, but the government cannot pursue it by curtailing speech. Quoting from an earlier decision, the Supreme Court said, "the fear that people would make bad decisions if given truthful information cannot justify content-based burdens on free speech." The court said that if the government wants to control health care costs, it has to do so directly, not by curtailing speech or cutting off access to information that is used in speech the state thinks exacerbates the cost problem.

In sum, because the statute discriminated both on the basis of content and viewpoint, and because it was not actually drawn to serve its stated goal of protecting doctor privacy, it could not survive scrutiny under the First Amendment.

What Are the Potential Implications of This Decision?

The Supreme Court's decision might mean that similar drug marketing laws adopted for similar reasons by Maine and New Hampshire also are unconstitutional. In addition, the case is highly relevant to other laws that try to specifically regulate advertising. Beyond that, however, the case probably sets no new standards for review of health privacy or privacy regulation in general.

Some organizations had urged the court to find that the data at issue could identify patients. This implicated the question of whether the HIPAA de-identification standard provides sufficient protection for patient privacy. The Supreme Court did not take the bait on that issue. It never questioned the premise that the data were adequately de-identified as to patients. Consequently, the important public policy considerations surrounding de-identification should be resolved by legislatures and regulatory bodies, which are better suited to handle them.

Most importantly, the case does not deal a death blow to privacy regulation. To the contrary, the Supreme Court noted that the state could have advanced its asserted privacy interest "by allowing the information's sale or disclosure in only a few narrow and well-justified circumstances." Such a statute, said the court, "would present quite a different case than the one presented here." To illustrate its point, the Supreme Court specifically cited the HIPAA regulations, suggesting they were an example of a more comprehensive privacy regime that would be upheld.

Moreover, the opinion includes strong rhetoric showing the Supreme Court is sensitive to the privacy threats posed by modern IT. In particular, the court noted that "[t]he capacity of technology to find and publish personal information, including records required by the government, presents serious and unresolved issues with respect to personal privacy and the dignity it seeks to secure." 

Like many Supreme Court opinions, Sorrell v. IMS Health includes various broad statements that could be misconstrued if taken out of context. For example, at one point, the opinion says that there is a First Amendment right to collect and disclose facts. But that does not mean that any burden on the collection and dissemination of facts is impermissible under the First Amendment.

To the contrary, as the Court made clear, privacy is a legitimate state interest that can in some contexts be protected consistently with the First Amendment, if the burden on speech is carefully drawn to serve that interest. What the First Amendment will not tolerate is regulatory subterfuge. As the court said, "Privacy is a concept too integral to the person and a right too essential to freedom to allow its manipulation to support just those ideas the government prefers."

MORE ON THE WEB
·       Supreme Court Decision in Sorrell v. IMS Health
·       "Supreme Court Case on Rx Data Mining Requires Nuanced Understanding of Privacy" (McGraw, iHealthBeat, 4/19).
·       "Sorrell v. IMS Health Has Far-Reaching Privacy Implications" (McGraw, CDT blog, 5/6).
·       "Encouraging the Use of, and Rethinking Protections for, De-Identified (and "Anonymized") Health Data" (McGraw, CDT, 6/25/2009).

Read more: http://www.ihealthbeat.org/perspectives/2011/lack-of-genuine-privacy-interest-doomed-vermont-drug-marketing-law.aspx#ixzz1S3JK3Hif

Tuesday, May 24, 2011

Kerry and McCain: A fair privacy Bill of Rights for online users

By Sen. John McCain (R-Ariz) and Sen. John Kerry (D-Mass.) - 05/23/11 06:27 PM ET

During the past few months, more than 250 million Americans received the frightening news that their personal information, collected by many retailers where they shop, was stolen by hackers routinely.

Sixty-one million Americans who own a smartphone were told that their travels and movements are being tracked by companies who service their smartphones and shared with app providers without restriction on how the information was being used. (We don’t want to imply that Apple or Google phones steal information; they don’t, but the apps on the phones collect and use it without sufficient protections or information for consumers.) And 77 million Americans learned that personal information stored in their online gaming systems was lifted by hackers. 

Almost every American is vulnerable to the loss, theft or unanticipated use of their information (theft listed alone is too strong), because in this digital age we routinely turn over personal information to online retailers, social networks and other services in growing numbers.

Americans are rightfully concerned and should be. Is the requirement that you provide such information and cede control of it simply the price of doing business in today’s digital economy? It shouldn’t be. That is why we introduced a Commercial Privacy Bill of Rights — to put Americans back in control of their personal information.

Last year, Internet users sent 107 trillion emails, Facebook hosted 600 million users, Twitter hosted 155 million tweets per day, and Americans across the country shared personal data when checking into hotels, shopping for groceries and refilling their cars. In many ways, all this information sharing is good for consumers. When companies collect data and use it with high ethical standards and the full knowledge and participation of their customers, they can generate immense economic activity, innovate and tailor the services they deliver to the clients they serve. 

But today the data collectors are setting the rules. Companies can harvest our personal information and keep it for as long as they like. They can use it and sell it without asking permission. You shouldn’t have to be a computer genius to figure out how to opt out of a company’s information sharing policy. In short, these companies, from mobile phone operators to hotels to websites, can do almost whatever they want with our personal information, and we have no legal right to stop them. 

That’s why we introduced the The Commercial Privacy Bill of Rights to keep our private data safe by laying down fair information practices for anyone collecting it. Our legislation will ensure that businesses collecting personal information secure that information, tell people why their data is being collected and allow people to have a say in whether they want their information used. If these companies turn around and transfer this information, any agreements they have made to secure the privacy of their consumers’ information would travel along with it. And if someone requests a company to stop using personal information, they finally have the legal power to make that demand.

We also recognize that it’s important to allow for experimentation and flexibility in the implementation of privacy practices. The Commercial Privacy Bill of Rights does that by establishing voluntary safe-harbor programs to allow companies to design their own privacy programs for complying with the law. They could implement protections however they wanted as long as they still achieved privacy protections on par with the standards set out in the law. 

The business community is already responding to the concerns of consumers and regulators by recognizing that the time has come to establish these types of consumer-privacy protections. Industries are negotiating among themselves to establish uniform data collection and use practices. Three of the major Internet browser services have already created tools allowing their users to express their preferences regarding their personal information. Many companies are now making massive investments in privacy protection for their own customers — including employing chief privacy officers to ensure that they earn, retain and respect the trust of consumers. 

These companies see that it doesn’t just make good business sense to protect customers’ private information. They know it’s the right thing to do, and we want to take that good work and make it common practice for everyone.

Kerry is the chairman of the Senate Commerce Committee’s subcommittee on Communications, Technology and the Internet. McCain is a former chairman of the Senate Commerce Committee.
Source:http://thehill.com/opinion/op-ed/162781-a-fair-privacy-bill-of-rights-for-online-users

Wednesday, May 4, 2011

Europe Leads in Pushing for Privacy of User Data

By James Kanter, NYT, May 3, 2011

BRUSSELS — As pressure grows for technology companies like Apple and Google to adjust how their phones and devices gather data, Europe seems to be where the new rules are being determined.

Last year, Google generated a storm of controversy in Germany when it had to acknowledge it had been recording information from unsecured wireless networks while compiling its Street View mapping service.

Then, last week, regulators in France, Germany and Italy said they would examine whether Apple’s iPhone and iPad violated privacy rules by tracking the location of users. Also, reports emerged last month that the Dutch police had obtained information from TomTom, a maker of popular satellite navigation devices, while setting up speed traps, prompting concerns by users and an apology from TomTom.

The companies all said there was nothing sinister about their activities, though Apple said it would issue a software update limiting the time that location data was kept to seven days. None of the information, the companies said, is particularly sensitive from the point of view of personal privacy, and they claim it will help them to deliver better services in many cases.

To address concerns about data protection, Viviane Reding, the European justice commissioner, said in a speech Tuesday that she would propose extending unionwide rules about breaches of privacy to online banking, video games, shopping and social media.

The rules require phone companies and Internet service providers to inform customers of any data breach “without undue delay.” “European citizens care deeply about protecting their privacy and data protection rights,” Ms. Reding said in a separate statement. “Any company operating in the E.U. market or any online product that is targeted at E.U. consumers should comply with E.U. rules.”

Ms. Reding made her remarks shortly after Sony apologized for a data theft involving 77 million account holders of the PlayStation Network, and a week after Apple said it would change the software that logs the location of users of its iPhone and iPad tablet computer. “Seven days is too late,” Ms. Reding said Tuesday, referring to how long it took Sony to inform account holders. Regarding Apple, she said she understood how the discovery that the iPhone collected location data had eroded “the trust of our citizens.”

Abraham L. Newman, an assistant professor at Georgetown University and a specialist in European privacy issues, said Europe’s spotlight on privacy could offer companies like Apple and Google the chance to reorganize the way they handled policies worldwide, using European standards in their corporate strategy. Alternatively, he said, the companies could develop policies to ensure that data gathered in Europe was sufficiently “quarantined” to comply with rules, but limit changes in the rest of the world.

“Apple is entering a political dynamic in Europe which is similar to Google’s experience,” Mr. Newman said. “Authorities in Europe have decided that consumers better not be duped in a world of unlimited location data where companies know literally every step you take.” What particularly distinguishes Europe is the strong role played by so-called national data protection authorities in keeping tabs on privacy issues, he said.

In the United States, there is no single agency dedicated to privacy, and while the Federal Trade Commission and the Federal Communications Commission can deal with violations of privacy, those agencies are mainly focused on enforcing fair business practices.

But Ms. Reding said the differences between Europe and the United States should not overshadow signs of convergence, like the work by the Obama administration and Congress to pass a privacy bill of rights that would stop companies from collecting or sharing personal information without an Internet user’s consent.

“Until recently, there was a common belief that the E.U. and U.S. have different approaches on privacy and that it would be difficult to work together,” Ms. Reding said. “This can no longer be argued in such simple terms.”

Saturday, April 30, 2011

Data Privacy, Put to the Test

BIG Oil. Big Food. Big Pharma.

By Natasha Singer, NYTimes, April 30, 2011

To the catalog of corporate "bigs" that worry a lot of us little people, add this: Big Data. It was not a good week for those who guard their privacy. First, we learned that Apple and Google have been using our smartphones to collect location data. Then Sony acknowledged that its PlayStation network had been hacked — the latest in a string of troubling data breaches. You'd have to be living off the grid not to realize that just about everything there is to know about you — what you buy, where you go — is worth something to someone. And the more we live online, the more companies learn about us.

But to what extent do others have a right to share and sell that information? That is the crux of a data-mining case that had arguments last Tuesday before the Supreme Court. The case, Sorrell v. IMS Health, is ostensibly about medical privacy: Vermont passed a law in 2007 that lets each doctor decide whether pharmacies can, for marketing purposes, sell prescription records linking him or her by name to the kinds and amounts of drugs prescribed. State legislators passed the law after the Vermont Medical Society said that such marketing intruded on doctors and could exert too much influence on prescriptions.

But three health information firms, including IMS Health and Verispan, along with a pharmaceutical industry trade group, challenged the law, saying it restricted commercial free speech. Access to prescription records, IMS Health says, helps pharmaceutical companies market efficiently to doctors whose patients would most benefit from specific drugs. Now the justices are to decide whether the Vermont law is constitutional.

But with the recent headlines about privacy invasion — the PlayStation hack followed a recent breach at the online marketing company Epsilon that exposed e-mail addresses of customers of Citibank, Walgreens, Target and other companies — the Vermont case is tapping into a much broader conversation about consumer protection and informed consent.

The case raises questions about who is collecting, managing, storing, sharing and selling all that data. Just as important, privacy advocates say, it raises questions about whether data brokers are adequately safeguarding it.

People generally don't have much control over who collects and sells information about them. Moreover, says Christopher Calabrese, a legislative counsel at the American Civil Liberties Union, they also don't even know the names of the data brokers who compile those electronic profiles. And, so, consumer advocates are setting their sights on Big Data.

"Without government intervention, we may soon find the Internet has been transformed from a library and playground to a fishbowl," Mr. Calabrese testified in March during a Senate hearing on consumer privacy, "and that we have unwittingly ceded core values of privacy and autonomy."

There are a few laws, like the Video Privacy Protection Act, that prohibit businesses from releasing personally identifiable records, like video rental histories, without customer consent. The Digital Advertising Alliance, a coalition of online marketing groups, introduced a program last year that notifies consumers about online tracking and allows them to opt out of advertising tailored to them. The Vermont law amounts to a kind of do-not-call option for doctors who may welcome visits from pharmaceutical sales reps but don't want drug marketing based on their own prescription records.

That marketing practice is possible because pharmacies, which are required by law to collect detailed information about prescriptions they fill, can sell doctor-specific prescription records to data brokers. (According to federal privacy regulations, personal information about patients, like names and addresses, must be removed before the records can be sold for marketing.) Firms like IMS Health then combine the records, and pharmaceutical reps often use them to tailor presentations to individual doctors.

The central concern is privacy — of both doctors and their patients. While pharmacies remove the names of patients before selling the records, those names are replaced with unique codes that track patients over time from doctor to doctor, according to the Vermont complaint. That means data firms could create a profile that includes a person's prescriptions as well as the names of the pharmacies and dates at which the person picked up the medications, says Latanya Sweeney, a visiting professor of computer science at Harvard.

"It ends up building a detailed prescription profile of individuals," says Professor Sweeney, whose research on data re-identification was cited by several briefs in the case. "Those extended profiles tend to be very unique."

The concern, she says, particularly in a small state like Vermont, is that a nameless prescription record could theoretically be enough to identify someone who might not want others to know that he takes, say, anti-depressants. Moreover, Professor Sweeney argues, data miners could collate those files with public information, like voter registration and hospital discharge records, to link prescriptions to specific people.

Federal health privacy regulation, she says, does not protect patient records once they have been de-identified. Nor does the law prohibit re-identification. But IMS Health says it isn't aware of any case of re-identifying patients whose prescription records were de-identified in accordance with federal rules. The company says it doubly encrypts each patient's identity and gives the encryption keys to several third parties — meaning that no single entity can decode a file by itself, says Kimberly Gray, chief privacy officer at IMS Health.

The company typically sells combined reports that show how many patients received a certain drug from a certain doctor, but not the specific drugstores those patients frequent, Ms. Gray says. IMS never uses public information or outside data sets to try to re-identify patients, she says, and when it does provide encoded patient histories to others for research purposes, it prohibits those third parties from making such attempts. "We would never want to re-identify someone," Ms. Gray says. "No good can come from that."

Still, it is hard to prevent people from trying to re-identify patients, says Lee Tien, a staff lawyer at the Electronic Frontier Foundation, a digital civil liberties group that filed a brief in support of Vermont. It would be easier, he says, if Congress passed a law that went further than Vermont's, giving people the right to consent before their encrypted prescription records were sold for marketing purposes. "In Vermont, the doctor can decide," Mr. Tien says. "But we'd prefer it if the patient were able to say, 'Don't sell my data.' " 

Wednesday, April 20, 2011

CRS Report: "Privacy Protections for Personal Information Online"

Summary

There is no comprehensive federal privacy statute that protects personal information. Instead, a patchwork of federal laws and regulations govern the collection and disclosure of personal information and has been addressed by Congress on a sector-by-sector basis.

 Federal laws and regulations extend protection to consumer credit reports, electronic communications, federal agency records, education records, bank records, cable subscriber information, video rental records, motor vehicle records, health information, telecommunications subscriber information, children’s online information, and customer financial information. Some contend that this patchwork of laws and regulations is insufficient to meet the demands of today’s technology.

Congress, the Obama Administration, businesses, public interest groups, and citizens are all involved in the discussion of privacy solutions. This report examines some of those efforts with respect to the protection of personal information. This report provides a brief overview of selected recent developments in the area of federal privacy law. This report does not cover workplace privacy laws or state privacy laws.

Available at http://www.fas.org/sgp/crs/misc/R41756.pdf


Wednesday, April 13, 2011

Brookings Paper on Privacy

Databuse: Digital Privacy and the Mosaic
by Benjamin Wittes Senior Fellow, Governance Studies The Brookings Institution   •  April, 2011

Introduction

The question of privacy lies at, or just beneath, the surface of a huge range of contemporary policy disputes. It binds together the American debates over such disparate issues as counter-terrorism and surveillance, online pornography, abortion, and targeted advertising. It captures something deep that a free society necessarily values in our individual relations with the state, with companies, and with one another. And yet we see a strange frustration emerging in our debates over privacy, one in which we fret simultaneously that we have too much of it and too little.

This tendency is most pronounced in the counter-terrorism arena, where we routinely both demand—with no apparent irony—both that authorities do a better job of “connecting the dots” and worry about the privacy impact of data-mining and collection programs designed to connect those dots.

The New Republic on its cover recently declared 2010 “The Year We Were Exposed” and published an article by Jeffrey Rosen subtitled “Why Privacy Always Loses.”[1] By contrast, in a book published earlier in 2010, former Department of Homeland Security policy chief Stewart Baker described privacy concerns as debilitating counter-terrorism efforts across a range of areas:

Even after 9/11, privacy campaigners tried to rebuild the wall [between intelligence and law enforcement] and to keep DHS from using [airline] reservation data effectively. They failed; too much blood had been spilled. But in the fields where disaster has not yet struck—computer security and biotechnology—privacy groups have blocked the government from taking even modest steps to head off danger.[2]

Both of these theses cannot be true. Privacy cannot at once be always losing—a value so at risk that it requires, for so Rosen contends, “a genuinely independent [government] institution” dedicated to its protection—and be simultaneously impeding the government from taking even “modest steps” to prevent catastrophes.

Unless, that is, our concept of privacy is so muddled, so situational, and so in flux, that we are not quite sure any more what it is or how much of it we really want.

In this paper, I explore the possibility that technology’s advance and the proliferation of personal data in the hands of third parties has left us with a conceptually outmoded debate, whose reliance on the concept of privacy does not usefully guide the public policy questions we face. And I propose a different vocabulary for that debate—a concept I call “databuse.” When I say here that privacy has become obsolete, to be clear, I do not mean this in the crude sense that we have as a society abandoned privacy in the way that, say, we have abandoned once-held moral anxieties about lending money for interest. Nor do I mean that we have moved beyond privacy in the sense that we moved beyond the need for a constitutional protection against the peacetime quartering of soldiers in private houses without the owner’s consent.[3] Privacy still represents a deep value in our society and in any society committed to liberalism.

Rather, I mean to propose something more precise, and more subtle: that the concept of privacy as we have traditionally understood it in law no longer describes well or completely the actual value at stake in the set of issues we continue to argue in privacy’s name. The notion of privacy was always vague and hard to pin down as an operational matter in law. But this problem has grown dramatically worse as a result of the proliferation of data about all of us and the ability to analyze and cross-reference that data systematically and instantly. To put the matter bluntly, the concept of privacy will no longer bear the weight we are placing upon it. And because the term covers such a huge range of ground, its imprecision with respect to these new problems creates great indeterminacy as to what the value we are trying to protect really is, whether it is gaining or losing ground, and whether that is a good thing or a bad.

In this paper, I examine privacy’s conceptual obsolescence with respect only to a single area, albeit one that is by itself hopelessly sprawling: data about individuals held in the hands of third parties. Our lives, as I have elsewhere argued, are described by a mosaic of such data—an ever-widening array of digital fingerprints reflecting nearly all of life’s many aspects. Our mosaics record our transactions, our media consumption, our locations and travel, our communications, and our relationships. They are, quite simply, a detailed portrait of our lives—vastly more revealing than the contents of our underwear drawers yet protected by a weird and incoherent patchwork of laws that reflect no coherent value system.[4]

We tend to discuss policy issues concerning control over our mosaics in the language of privacy for the simple reason that privacy represents the closest value liberalism has yet articulated to the one we instinctively wish in this context both to protect and to balance against other goods—goods such as commerce, security, and the free exchange of information. And there is no doubt an intuitive logic to the use of the term in this context. If one imagines, for example, the malicious deployment of all of the government’s authorities to collect the components of a person’s mosaic and then the use of those components against that person, one is imagining a police state no less than if one imagines an unrestricted power to raid people’s homes. If one imagines the unrestricted commerce in personal information about people’s habits, tastes, and behaviors—innocent and deviant alike—one is imagining an invasion of personal space as destructive of a person's privacy as the breaking into that person's home and the selling of all the personal information one can pilfer there.

Yet the construction of these issues as principally implicating privacy is not inevitable; indeed, privacy itself is not inevitable as a legal matter. It was, as I shall argue, created in response to the obsolescence of previous legal constructions designed to shield individuals from government and one another, and it was created because technological developments made those earlier constructions inadequate to describe the violations people were feeling. Ironically, today it is privacy itself that no longer adequately describes the violations people are feeling with respect to the mosaic—and it describes those violations less and less well as time goes on. Much of the material that makes up the mosaic, after all, involves records of events that take place in public, not in private; driving through a toll booth or shopping at a store, for example, are not exactly private acts.

Most mosaic data is sensitive only in aggregation; it is often trivial in and of itself—and we consequently think little of giving it, or the rights to use it, away. Indeed, mosaic data by its nature is material we have disclosed to others, often in exchange for some benefit, and often with the understanding, implicit or explicit, that it would be aggregated and mined for what it might say about us. It takes a feat of intellectual jujitsu to construct a cognizable and actionable set of privacy interests out of the amalgamation of public activities which one transacted knowingly with a stranger in exchange for a benefit. The term privacy has become a crutch—a description of many different values of quite-different weights—that does not usefully describe the harms we fear.

The more sophisticated privacy scholars and advocates appreciate this. In his exhaustive effort to create a “Taxonomy of Privacy,” Daniel Solove argues up front that “The concept of ‘privacy’ is far too vague to guide adjudication and lawmaking”[5] and that “it is too complicated a concept to be boiled down to a single essence.” Rather, he treats privacy as “an umbrella term, referring to a wide and disparate group of related things.”[6] Just how wide becomes clear over the course of his 84-page article. His taxonomy contains four principal parts, each consisting of multiple subparts—creating, all in all, a 16-part typology that ranges from blackmail to data “aggregation” and “decisional interference.” And he concedes in the end that although all of the privacy harms he identifies “are related in some way, they are not related in the same way—there is no common denominator that links them all.”[7] Solove’s heroic effort to salvage privacy’s coherence through comprehensive cataloguing has the unintended effect of revealing its unsalvagability.

My purpose here is to propose a different vocabulary for discussing the mosaic—in some ways a simpler, cruder one, but one that both more accurately describes than privacy our behavior with respect to the mosaic and that offers more useful guidance than the concept of privacy does as to what activities we should and should not tolerate. The relevant concept is not, in my judgment, protecting some elusive positive right of user privacy but, rather, protecting a negative right—a right against the unjustified deployment of user data in a fashion adverse to the user's interests, a right, we might say, against databuse.

 The databuse conception of the user’s equity in the mosaic is more modest than privacy. It doesn’t ask to be “let alone.” It asks, rather, for a certain protection against tangible harms as a result of a user’s having entrusted elements of his or her mosai c to a third party. Sometimes, to be sure, these tangible harms will implicate privacy as traditionally understood, but sometimes, as I will explain, they will not. Think of it as a right to not have your data rise up and attack you.

Thinking about mosaic questions we currently debate in the language of privacy in terms of databuse has a clarifying effect on a number of contemporary public policy disputes. In some cases, it will tend to suggest policy outcomes roughly congruent with those suggested by a more conventional privacy analysis. In other cases, by contrast, it suggests both more and less aggressive policy interventions and market developments on behalf of users. In some areas, it argues for a complacent attitude towards data uses and acquisitions that have traditionally drawn the skeptical eye of privacy activists. Yet it also suggests more intense focus on a subset of privacy issues that are currently under-emphasized in privacy debates—specifically, issues that genuinely implicate personal security.

Full paper at http://www.brookings.edu/papers/2011/0401_databuse_wittes.aspx

Tuesday, March 22, 2011

Privacy Bill of Rights: Could Be a Long Slog

by Rob SpiegelE-Commerce Times 03/21/11 10:46 AM PT


"If a privacy bill passes and has some teeth, it's a good thing," said tech analyst Rob Enderle. "It really depends on what shape it's in when it gets through. A lot of politicians have kids and grandkids who need to be protected, as well as elderly parents who are exposed to attacks. I think the timing is right on this, but Congress tends to move slowly."

The Obama administration's top adviser on communications and information policy, Assistant Secretary of Commerce Lawrence E. Strickling, backed the Federal Trade Commission's proposal for a "Consumer Privacy Bill of Rights," calling for the passage of online privacy legislation last week.

In testimony before the U.S. Senate Committee on Commerce, Science and Transportation, Strickling recommended limiting the power of advertisers while retaining important online freedoms.

"The department has concluded that the U.S. consumer data privacy framework will benefit from legislation to establish a clearer set of rules for the road for businesses and consumers, while preserving the innovation and free flow of information that are hallmarks of the Internet," he said.

Strickling talked about different ways that guidelines regarding online advertiser practices could be applied.

"The Administration urges Congress to enact a 'consumer privacy bill of rights' to provide baseline consumer data privacy protections," he said. "Legislation should consider statutory baseline protections for consumer data privacy that are enforceable at law and are based on a comprehensive set of FIPPs (Fair Information Practice Principles).

"Comprehensive FIPPs, a collection of agreed-upon principles for the handling of consumer information, would provide clear privacy protections for personal data in commercial contexts that are not covered by existing Federal privacy laws or otherwise require additional protection," said Strickling.

Strickling recommended the Federal Trade Commission (FTC) handle the duty of implementing the new guidelines.

"Granting the FTC explicit authority to enforce baseline privacy principles would strengthen its role in consumer data privacy policy and enforcement, resulting in better protection for consumers and evolving standards that can adapt to a rapidly evolving online marketplace," said Strickling.

Legislation would follow recommendations published in last December's report by the Department of Commerce. The report recommended that consumers be informed more about why their data is being collected and how it will be used. It also called for more limitations of how companies can use consumer data.

What advertisers see as valuable marketing data, consumers could see as an infringement on their privacy.

"The good news is that Internet advertising can deliver results that are relevant to each consumer's wants and needs," Carl Howe, director of anywhere consumer research at the Yankee Group, told the E-Commerce Times. "But the bad news is that for Internet advertising to do that, it must know who you are and what your wants and needs are. It's that knowledge by advertisers and network operators that makes consumers uncomfortable that their privacy is violated."

New legislation would aim to protect customer rights, but it could be a jolt to the advertising industry. "I think this consumer bill of rights is an excellent first step, but the real challenges will be in how it is implemented," said Howe. "Advertisers will argue that blocking them from collecting consumer data will make Internet advertising less valuable to consumers -- and to businesses -- because without the information, ads will become faceless and generic."hanges in online privacy policies could empower consumers.

"Consumers will want control over which advertisers are allowed to target their needs," said Howe. "They may want the ability to allow the local school to target their children with ads for school supplies, but may not want to release that information to magazine publishers or candy manufacturers. The question is just how much control consumers will have."

New laws would likely try to protect consumers without completely hampering advertisers. "I think the challenge is striking a balance between consumer and advertiser interests," said Howe. "To date, the bias has been to the advertiser being allowed to collect whatever information might be useful. This bill tries to establish rights for the targets of those ads too."
Consumer protection could make the Internet a family-friendlier place to spend time.

"A lot of things that come out of Washington are more of a feel-good statement rather than something serious," Rob Enderle, principal analyst at the Enderle Group, told the E-Commerce Times. "The idea that there would be certain unalienable rights to your privacy is a good thing. Right now everybody and their brother is mining your personal information and making money off it but you."

The administration is trying to avoid the decade-long sluggishness from proposal to law. "Laws typically lag reality by a decade or more. The administration -- to its credit -- is trying to close that gap," said Enderle. "If a privacy bill passes and has some teeth, it's a good thing. It really depends on what shape it's in when it gets through. A lot of politicians have kids and grandkids who need to be protected, as well as elderly parents who are exposed to attacks. I think the timing is right on this, but Congress tends to move slowly."

Saturday, March 19, 2011

A New Internet Privacy Law?

March 18, 2011, NY Times

Considering how much information we entrust to the Internet every day, it is hard to believe there is no general law to protect people’s privacy online. Companies harvest data about people as they surf the Net, assemble it into detailed profiles and sell it to advertisers or others without ever asking permission.

So it is good to see a groundswell of support emerging for minimum standards of privacy, online and off. This week, the Obama administration called for legislation to protect consumers’ privacy. In the Senate, John Kerry is trying to draft a privacy bill of rights with the across-the-aisle support of John McCain.

Microsoft, which runs one of the biggest Internet advertising networks, said it supports a broad-based privacy law. It has just introduced a version of its Explorer browser that allows surfers to block some tools advertisers use to track consumers’ activities online.

It is crucial that lawmakers get this right. There is strong pressure from the advertising industry to water down rules aimed at limiting the data companies can collect and what they can do with it.

Most oppose a sensible proposal by the Federal Trade Commission for a do-not-track option — likely embedded in Web browsers. They have proposed self-regulation instead, and we applaud their desire to do that, but the zeal to self-regulate tends to wane when it is not backed by government rules and enforcement.

Senator Kerry has not yet proposed specific legislation, but he has laid out sound principles. Companies that track people’s activities online must obtain people’s consent first. They must specify what data they are collecting and how they will use it. They need consumers’ go-ahead to use data for any new purpose. They are responsible for the data’s integrity. And consumers should have the right to sever their relationship with data collectors and ask for their file to be deleted.

But there are potential areas of concern. Senator Kerry so far has not called for a do-not-track option. He would allow companies to write their own privacy plans and submit them to the F.T.C. for approval.

That would give companies flexibility to adapt their solutions as technology evolved, but it lacks the simplicity and universality of a do-not-track feature. It could yield a dizzying array of solutions that would confuse consumers about their rights and options and make it more difficult to enforce clear standards. Moreover, it would make it tougher for consumers to keep track of how their information is used and to whom it is sold.

Advertising firms still argue that privacy protections could undermine the free Internet, depriving it of ad revenue by reducing advertisers’ ability to target consumers. This is overstated. Advertisers will still need to advertise. If many people opt out of behavioral targeting, the firms will find other ways to do it.

Privacy protections are long overdue. We hope the swell of support will lead to significant legislation.

Wednesday, March 16, 2011

WSJ: Privacy Measure Draws Support

By JENNIFER VALENTINO-DEVRIES   TECHNOLOGY, MARCH 17, 2011

Sen. John Kerry, a senior Democrat, and technology giant Microsoft Corp. on Wednesday backed the Obama administration's call for broad privacy legislation at a Senate hearing that also exposed hurdles to passing such a law.

"Modern technology allows private entities to observe the activity of Americans on a scale that is unimaginable, and there is no general law" governing the collection and use of that data, Sen. Kerry told the Senate Commerce Committee.

The Massachusetts lawmaker said he was working with others and soon planned to introduce a "privacy bill of rights."

The Commerce Department called at Wednesday's hearing for a privacy law that includes enforceable protections for consumers' personal information and a stronger role for the Federal Trade Commission.

Unlike the European Union, the U.S. doesn't have a federal law establishing a general right to privacy. U.S. laws protect only certain types of information, such as some data about health care or personal finances.

Concerns about the online tracking industry have increased the public's interest in privacy rights. In the past year, The Wall Street Journal's "What They Know" series has revealed that popular websites install thousands of tracking technologies on people's computers without their knowledge, feeding an industry that gathers and sells information on their finances, political leanings and religious interests, among other things.

The FTC and the Commerce Department both have issued recent reports calling for enhanced privacy protections. FTC Chairman Jon Leibowitz told the committee Wednesday that the Journal series "really was a motivation for us to step up our enforcement efforts and write" the report.

He also said one of the articles in the series alerted the FTC to the fact that new tools to stop tracking were technically feasible.

An executive of Microsoft, which makes the most popular Web browser and also operates one of the largest Internet advertising networks, echoed the call for a broad privacy law. The current piecemeal approach to privacy law "is confusing to consumers and costly for businesses," said Erich Andersen, the company's deputy general counsel.

Microsoft is incorporating two additional privacy protections into the new version of its Internet Explorer browser.

The push to enact a federal privacy law remains in its early stages. Sen. Kerry said he has been working on proposed legislation with Sen. John McCain, an Arizona Republican, suggesting support for such a measure crosses party lines.

A spokeswoman for Sen. McCain said he and Sen. Kerry are discussing specific language for the bill.

"Sen. McCain believes that any legislation, if necessary, should respect the consumers' ability to control the use of their personal information, while recognizing the need of companies" to innovate and target advertising to consumers, she said.

Skepticism about the need for a new law also cuts across party lines. Sen. Claire McCaskill, a Missouri Democrat, questioned whether limitations on data collection would hinder the ability of websites to provide free content.

"I just want to make sure that we don't kill the goose that laid the golden egg here under the very laudable rubric of privacy," she said.

Advertisers, too, are wary of new rules. The industry has been promoting an icon that appears on certain ads to alert consumers that they are being targeted, and to let them opt out of the system.

Meanwhile, industry executives have objected to the FTC's call for browser makers to create a "do not track" system that would let Internet users signal they don't want their online movements recorded.

Having both a do-not-track tool and the industry-backed icon could confuse consumers, said John Montgomery, an executive with GroupM Interaction, part of advertising giant WPP PLC.
"It's vitally important to avoid mixed messages," he said.

The FTC's Mr. Leibowitz, however, said a majority of commissioners believe the icon system isn't adequate, because it would allow marketers to continue to collect some data on Web surfers.

"We need to make sure 'do not track' is not an empty slogan," he said.


Read more: http://online.wsj.com/article/SB10001424052748703899704576204932250006752.html#ixzz1GoakGwp5









The changing meaning of "personal data"

By William B. Baker and Anthony Matyjaszewski

When FTC Commissioner Julie Brill last year described her vision of privacy in the future, which she dubbed Privacy 3.0, she opined that the distinction between “personally identifiable information” (PII) and “non-PII” is “blurring.” This remark led the IAPP to start an inquiry into exactly what kind of information is “personal information” or “personal data” and how statutory definitions are subject to reinterpretation as technology evolves. The IAPP hopes that this initial effort will lead to further discussions about what should be protected by privacy law.

What is PII: Statutory Definitions
A starting point is a consideration of what constitutes PII under current statutory law. Is PII all information about a person? Does the information need to directly identify a person? Is it only recorded information? Does the information need to be true? Is a “person” only a natural person, or can they be legal persons such as corporations and organizations? If they are natural persons, does it matter if they are dead or alive?

       These and other queries can be answered by examining the definitions of “personal information” or “personal data” in various countries. To begin a conversation about the nature of “data,” the IAPP surveyed the definitions of personal data across 36 data protection laws in 30 countries. A summary of that research is attached.

       Those 36 laws have taken many approaches. Some of these definitions, such as those in the United States, are relatively narrow and often specify particular items, while others, especially those in European Union countries and other laws modeled on their approach, tend to be broader.

       Despite these differences, the statutes generally share a prototypical definition along the lines of “data or information relating to an identifiable person.” All countries employ some variation of the phrasing, data “that allow the identification of a person directly or indirectly.” For example, the European Union Directive on Data Privacy defines PII as data “relating to an identified or identifiable natural person ('data subject'); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity.”

       Despite this general similarity, laws differ in what actually qualifies for data protection.  Some countries list specific examples of what can constitute personal data; others are satisfied with a more flexible—or ambiguous—definition. Although specific definitions may offer the benefit of greater certainty, they are subject to criticism as rigid and incapable of responding to new developments. Conversely, the flexible definitions do allow for future adaptability but can lead to uncertainty.

        Under these laws, data that do not constitute PII are regarded as “non-PII,” subject to far less, if any, regulation. This concept has often applied to aggregated data and more recently has been extended to “de-identified” data from which identifying information purportedly has been removed.

Applying the Statutory Definitions
Looking abroad, the European Union Article 29 Working Party’s Opinion 4/2007 offers further guidance on the meaning of personal data. The Working Party analyzed first, the type of data or information; second, the relation between the data and its subject; third, the concept of identifiability, and fourth, the person or individual to be protected.

Types of Information
The first step in the Article 29 Working Group’s analysis looks at what types of information are protected. Consider first whether data must be in a recorded form to be protected or whether spoken words could come within the protection of the laws. Curiously, only Australia’s Privacy Act 1988 and the United States’ Health Insurance Portability and Accountability Act (HIPAA) expressly include protection for data that is not recorded either digitally or on paper in their respective definitions of personal data.

The IAPP’s research showed that most countries do not specify whether the data must be recorded—or if it can also be spoken words or opinions—leaving such matters open to interpretation or, perhaps, resolution, in cases involving difficult facts. This leaves open the possibility that not only recorded data but also information of a more ephemeral nature can fall under those nations’ privacy protections. One conjures intriguing possibilities, as privacy laws in those countries that do not address this matter could potentially protect one from having their names or other identifying characteristics spoken out loud. What a way to stop nasty gossip!

       On the other hand, some privacy laws, such as those of Hong Kong and the United Kingdom, mention recorded data only. Singapore’s Model Data Protection Code and the United States’ Children’s Online Privacy Protection Act (COPPA) further limit their reach to digital data or data collected online.

       Must data about a person be true to be protected? Interestingly, only two nations—Australia and Singapore—explicitly state in their definitions of personal information that protection extends to both true and false data. The remaining surveyed laws do not address this matter in their definitions of personal information. Does this mean that these other countries will only provide privacy protection for true data? Most likely not, as may be inferred from other provisions in their privacy laws requiring data controllers to allow a person the opportunity to access and correct any false data pertaining to oneself, especially in the financial or credit sectors. Even though the definition of personal data in the European Union Data Protection Directive also does not deal with the veracity of data, the Article 29 Working Party’s Opinion 4/2007 states that both true and false data, as well as viewpoints, are covered by the directive. As such, the mere omission of a topic from the definition of personal information does not necessarily remove that matter from the scope of privacy protection.

Relationship to a Person
Moving to the Working Party’s second analytical step—the relationship between the data and its subject—certain patterns emerge from the terms used in the various definitions of personal information in the laws researched by the IAPP. Privacy laws include terms such as “referring to,” “relating to,” “about” or “concerning” a person or individual. There is little substantive variance among the definitions, as they all establish a link between the data and the person. After all, there presumably is little need to protect data that have no reference to someone whose privacy is being safeguarded.

       Few problems exist where the relationship is quite straightforward, such as that of a name to a particular person. And this is especially true when the name is relatively distinctive, such as, say, Barack H. Obama. That does not mean, however, that a person necessarily has rights in her name. Ordinarily, the connections between the data and the subject are far more nebulous, and these can present difficult questions in privacy law.

       The Article 29 Working Party’s Opinion 4/2007 provides what is perhaps the most in-depth scrutiny of this factor by reducing it to three elements—content, purpose or result. The content element is perhaps the clearest of the three, as it addresses information about a person, such as their medical history, their contact information or their service record. Such information inherently refers to a particular individual.

       The purpose element stipulates that even data that may otherwise not be considered personal information, such as a corporate call log of a company’s telephones, may become personal information when used to monitor an employee’s telephone activity. In such a case, the Article 29 Working Party would consider the data to be personal data relating to both the employee making the calls and the recipient of the call on the other end of the connection.

       The result element posits that even data not about a particular person—thus lacking the content element—and not used to gain information about a person, lacking the purpose element—may still be considered personal information where a person’s rights or interests are affected. For example, a satellite positioning system being used solely for the purpose of ensuring efficient dispatching of taxis or delivery vehicles would still provide personal information because the location data could potentially result in the monitoring of drivers’ whereabouts and behavior.

       The Article 29 Working Group’s approach seems to leave room for the range of matter deemed to be “personal information” to expand—or shrink—over time in response to developments. The remainder of this article explores some of the issues that may arise in understanding what data and information will fall within the scope of “personal” under these laws.

Types of Persons
Although the meaning of persons who are entitled to privacy protection under these laws is listed fourth in the European Union analysis, we consider it third here. Predominantly, the definitions of personal information apply only to natural persons, or human beings. However, Argentina, Austria, Colombia, Italy and Switzerland also extend privacy protection to legal persons such as corporations, partnerships or other organizations. The potential scope of this presents fascinating questions. Does it mean that corporations cannot be made identifiable, and any information that makes it possible to identify a specific company should be treated as personal information? Or perhaps the protection is meant to protect corporate secrecy or the privacy of the individuals within the corporate structure.

       On the other hand, the Australian Law Reform Commission considered extending privacy rights to corporations but ultimately rejected the idea, stipulating that there are existing statutory protections of intellectual property and business confidentiality that serve the same purpose more effectively. And in Canada, both the Personal Information and Electronic Documents Act (PIPEDA) and the British Columbia Personal Information Protection Act (PIPA) specifically exclude an individual’s business contact information from privacy protection. These types of statutes exist worldwide, and they are perhaps the main reason why more countries have not moved to extend privacy protection to corporations on the same terms as they are applied to individuals. The U.S. Supreme Court on March 1, 2011, ruled that corporations are not “persons” for the purpose of the Freedom of Information Act.

       Even where the definition of “person” is narrowed to human beings, some countries view “personal” as protecting the privacy only of the living, but not the deceased. Again, most of the definitions are silent on this matter. Hong Kong, Ireland, Japan, New Zealand, Sweden and the United Kingdom specify that only the living are entitled to privacy protection, and New Zealand  protects information relating to a death. In the European Union, the Data Protection Directive does not require the extension of privacy protection to the deceased, although individual countries are free to do so at their discretion. The Article 29 Working Party has elaborated their position on data protection for the deceased by stating that such information only requires protection in the event that it can be used to identify living individuals, as would be the case in genetically transmitted diseases such as hemophilia. This demonstrates once more the variance in approaches to defining personal information among the surveyed laws, with some countries preferring a narrower scope while others choose to keep the definition more broad.

Identification
The remaining step of the inquiry looks at the substance of the identification requirement of the data subject. As to this point, a consensus appears among the various laws in the surveyed countries. Not one of these laws requires a person actually to become identified. They either leave this as an open-ended possibility, by using the term “identifiable,” or they specify that the data are protected if they can cause the data subject to be “identified or identifiable.” Thus, the mere possibility of identification can be enough for data to become personal information.
       Similarly, none of the laws require a person to be directly identified through the use of the data in question. While nearly half of the definitions of personal information are silent on this matter, many state that possible indirect identification is enough to trigger protection.

Essentially, this means that the information in one’s possession will need to be treated as personal information even if it does not identify an individual, so long as it can be combined with other available information for that very purpose. It should be apparent that determining how readily a person can be identified can be a very fact-specific inquiry, and what is not identifiable one year may, a few years later, be determined to be identifiable.

       An example used by the Article 29 Working Party envisions a newspaper article about a criminal case that describes some of the details but does not directly name any of the individuals. So long as there is publicly available information, either in court records or in other newspaper articles, that allows one to ascertain the identities of the people involved, then even an article that does not identify the individuals would be deemed, at least by the Article 29 Working Party, to contain personal information. American law generally reaches a different result, as a person named as a possible criminal suspect in a U.S. news article typically has little recourse other than a defamation action.

       Applying this “relating to” provision, nonetheless, can be a vexing task in privacy law. It is an area particularly vulnerable to technological developments that place great stress on existing statutory definitions.

Re-identification
In response to laws imposing greater obligations on the custodians of personal information, a practice arose over the years to remove certain information from a compilation of PII in order to “anonymize” or “deidentify” the data so that it could be processed as non-PII. This practice underlies many laws today, which typically require far less protections for “non-personally identifiable information.” For example, in the United States, the Privacy Rule implementing the Health Insurance Portability and Accountability Act specifies 18 different categories of identifying information that must be removed in order to “de-identify” health information. However, enterprising researchers in recent years began to demonstrate that it is often possible to “re-identify” supposedly anonymized data.

       There have been several well-publicized examples. One involved research by LaTanya Sweeney in Massachusetts, who identified then-Gov. William Weld’s medical records using only a state-released “anonymized” data set and a list of registered voters. More recently, Netflix found it appropriate to cancel a second “Netflix Contest” after researchers were able to identify “anonymized” Netflix viewers in the first “Netflix Contest”—in which it offered $1 million to any researcher who could best improve its recommendation engine—from viewer reviews posted on The Internet Movie Database Web site. Among the characteristics that could be identified were the users' political leanings and, in some instances, even sexual orientation.

       These episodes demonstrate that the process of de-identification is not nearly as simple or easy as once may have been believed. Data controllers that wish to de-identify PII are on notice to take greater pains to do so. At this point, however, it is not possible how much is enough, as resourceful researchers will invariably have many tools available to reassemble data if given sufficient motivation. And it is not clear that the answer lies in the “foreseeability” that re-identification is possible, but foreseeability may simply be a function of one’s ingenuity. Note that the tools these researchers used—voter registration lists, Internet databases—were not arcane but were commonplace items that, presumably, were never considered to the de-identifiers as posing a potential risk.

       Indeed, Professor Paul Ohm has gone so far as to declare that data can be “useful or perfectly anonymous but not both.” Time will tell whether Prof. Ohm’s provocative formulation is correct or not, but his aphorism highlights the difficulties of anonymizing PII.

Internet Protocol Addresses
A current topic of hot debate is whether a computer user’s Internet Protocol (IP) address should be considered PII. The law appears in flux at the moment, and complicating matters is that regulators and courts are reaching different conclusions.

       Privacy regulators in the European Union regard dynamic IP addresses as personal information. Even though dynamic IP addresses change over time, and cannot be directly used to identify an individual, the Article 29 Working Party believes that a copyright holder using “reasonable means” can obtain a user’s identity from an IP address when pursuing abusers of intellectual property rights. More recently, other European privacy regulators have voiced similar views regarding permanent IP addresses, noting that they can be used to track and, eventually, identify individuals.

       This contrasts sharply to the approach taken in the United States under laws such as COPPA where, a decade ago, the FTC considered whether to classify even static IP addresses as personal information but ultimately rejected the idea out of concern that it would unnecessarily increase the scope of the law. In the past few years, however, the FTC has begun to suggest that IP addresses should be considered PII for much the same reasons as their European counterparts. Indeed, in a recent consent decree, the FTC included within the definition of “nonpublic, individually-identifiable information” an “IP address (or other “persistent identifier”).” And the HIPAA Privacy Rule treats IP addresses as a form of “protected health information” by listing them as a type of data that must be removed from PHI for deidentification purposes.

       However, courts are more reluctant to do so. For example, the Irish High Court held in April 2010 that an IP address does not constitute “personal data” when being collected by record companies for the purpose of detecting copyright infringement. And a U.S. federal district court in Washington state also held that an IP address is not PII because it identifies a computer rather than a person. The law is far from settled on this point, however, so lawyers must follow developments closely.

Device Fingerprinting
A newer approach to identifying a particular Internet user is device fingerprinting or, in the online context, “browser fingerprinting.” This process focuses on the particular software configuration of a user’s browser—the browser type, fonts and other factors—and it happens that the particular combination of such factors on a user’s computer is often unique to that user. (The Electronic Freedom Foundation has done useful work in this area). Useful to the entity interesting in “tracking” a user is that no cookie or other code is placed on the user’s computer; the tracking is done remotely by using information routinely supplied by the browser to a Web site. The user’s name, by the way, is never disclosed, but her device is uniquely identified and capable of being tracked. This device fingerprinting technology did not even exist just a few years ago. The question, from a legal standpoint, is whether a user’s browser configurations are, or will soon become, “PII” for regulatory purposes.

Smart Grid
The “smart grid” will present similar issues in a few years. Once utility companies are capable of monitoring the usage of particular appliances in particular homes, it will be only a matter of time before telltale “identifying” patterns of usage begin to emerge. Energy companies might provide incentives to use certain appliances at off-peak hours; marketers might have a keen interest in knowing which consumers make frequent use of the microwave. The utility companies will surely have some ability to correlate usage patterns with particular customers, but how will definitions of PII factor into the smart grid.

Questions for the Future
These developments regarding reidentification, IP addresses, browser fingerprinting and the smart grid provide examples of how new technological developments can cause the reidentification of data previously deemed non-PII. Other issues abound, such as the extension of privacy to photographic data, especially as it relates to Google’s Street View map service, as well as geographic location information derived from a new generation of mobile devices. In none of these cases has a legislature changed a statutory definition; each involves the application of a previously-established definition in light of new technology. In this way, the process of re-identification can be said to enable technology to redefine PII.

       Is there a limit to how technology can redefine PII? To how much effort must a re-identifier go, or, put differently, is there some reasonable limit that a de-identifying entity can assume applies when attempting to render data non-identifiable? Or, is the problem a limit on people’s ability to imagine or foresee how a re-identifier might go about her task?

       Existing statutory laws neither ignore this problem nor resolve it. The laws often contain limitations to how practicable such indirect identification must be, and this is where different approaches are taken in the laws surveyed. For example, Hong Kong’s Personal Data Protection Ordinance and Poland’s Act on the Protection of Personal Data stipulate that data will not be protected if indirect identification is not practical or if it requires unreasonable cost, time or manpower, respectively. Of course, practicality and reasonability are unspecific concepts. Again, the Article 29 Working Party offers some guidance on this topic within the European Union by utilizing a cost-benefit analysis. Accordingly, the mere hypothetical possibility of identification is not enough, and one should consider the cost of conducting the search, the expected benefit of identifying the person and the interests at stake in order to determine whether a person is identifiable.

       Still, this leaves many questions unanswered. A calculation of costs and benefits will change as technology creates new ways of combining information or researchers become more clever. Remember that Ms. Sweeney needed only a registered voter list to identify Gov. Weld’s medical records, something plainly not foreseen by Massachusetts authorities but, in hindsight, perhaps not so surprising. How “practical” is device fingerprinting today or will it be in two years?

Conclusion
The different ways that  similar statutory language is applied around the world causes problems in practice. Any business that conducts operations in more than one country faces a continuing challenge of understanding and complying with legal terms that are applied differently across borders. And, after understanding the differing definitions, they must then comply with the corresponding policies that govern data in each country.

       Going forward, with new technological advances being made on a regular basis, these definitions of personal information, and the type of data they cover, will be reshaped, refined and revised. There is a strong likelihood that the driver of these “redefinitions” will be the technological developments themselves. That is, even where statutory definitions provide what legislators intended to be clear classifications, changes in technology may be, in effect, “amending” these statutes without any legislative action. The future course of such “blurring” is a trend worth watching.

       The IAPP hopes that the compendium of laws attached to this article will prove to be a helpful contribution to the discussion.

https://www.privacyassociation.org/knowledge_center/the_changing_meaning_of_personal_data/