Showing posts with label Social Networking. Show all posts
Showing posts with label Social Networking. Show all posts

Friday, April 29, 2011

Why the Online Identity & Data Ownership Debate Matters


There has been quite a bit of media attention the past week around the news that iPhones and iPads are recording and storing location data in an unencrypted manner. Apple replied that it’s not tracking iPhone location, it’s maintaining a database of surrounding Wi-Fi hotspots and cell towers so the iPhone can calculate its location when requested.Anyway, the little window of raised awareness and interest in data mining and privacy compelled me to want to write a bit about it.

I’ve been exploring many angles over the past few years of how humanity and our technologies are co-evolving, – how social media tools are offering us new ways to collaborate, to see ourselves through different lenses, to intentionally evolve our consciousness, and to explore new forms of value exchange.

I was invited to participate in the Internet Identity Workshop in Silicon Valley next week, and the Privacy Identity Innovation conference later in May, so my new learning objective has been to get a grasp on online identity and personal data ownership.  It’s really quite fascinating, and there is a real sense of urgency for awareness to be raised around what’s happening and what it means.

The Big Picture
We’re aware that the data we generate is “owned” (or at least maintained) by someone else – the government issues us our identification, the doctor’s office has our health records, the credit agencies know our financial history. We assume our information is private and secure.
But now with so much activity happening online and increasingly on mobile devices, we’re generating a digital representation of ourselves that not only expresses our interests, desires, needs, purchasing behaviors, and the range of social connections and relationships, but also the contextual information of our location in physical space and time.This is important because we’re generating a detailed profile of ourselves that reveals much more about us that we may realize.

What is Revealed: Macro Level
A recent article in the Wall Street Journal, The Really Smart Phone, discusses research conducted by scientists, and the interesting patterns of human behavior they were able to abstract from data collected from smartphones. For example, by analyzing people’s movement records, they were able to predict someone’s future whereabouts with 93.6% accuracy. They’re able to notice symptoms of mental illness, predict stock market fluctuations, and even chart the spread of ideas throughout society, revealing a “god’s-eye view of human behavior.” With billions of people on the planet now carrying a mobile device, we’re able to access data about human complexity that was simply not possible before.

What is Revealed: Micro Level
In a New York Times piece from the other day, Show Us the Data. (It’s Ours, After All.), professor of economics and behavioral science Richard Thaler writes about the vast amount of personal data that is being aggregated about us and sold to third parties.

In terms of consumption, this data is useful for companies in order to target you with highly personalized recommendations, advertising and offers. On a personally empowering level, it could potentially offer us a wealth of information about ourselves to assist us with intelligent decision-making. For example, by looking at medical records and family history, we might receive tailored recommendations for exercise plans or food choices. The problem is – we often don’t have access to this data.

What’s at Stake
There’s a lot of talk about “privacy” on the web right now, and I’m still not completely sure I understand the extent of the argument. If by privacy we mean security, and wanting protection of sensitive data like financial records or social security numbers, I completely agree. But if privacy concerns are around the fear of someone finding out about that bizarre fetish we have or the flavor of porn we prefer, I wonder how much that matters. While that information may be taboo in some circles, it’s actually infinitely less interesting than the data we reveal about ourselves publicly that’s being mined and sold online every day.

(check out this tongue in cheek video by The Onion – “CIA’s Facebook Program Dramatically Cut Agency’s Costs)

Most of the activity done online, from browsing websites to chatting with friends, is being recorded by someone. Your “private” conversations in Facebook are mined, as are your shopping habits on Amazon, or your preferences or personal connections on any number of services.

The issue with these things, moreso than that they are happening, is that we don’t have access to that data that we generate. Challenging this unfortunate reality was the big thrust that led to the formation of the Personal Data Ecosystem Consortium, a coalition of individuals and organizations who realize what’s at stake if we don’t reclaim the data that is ours.

Essentially, by third parties locking in our “digital self” into each of their services, we are losing massive collective intelligence opportunites for innovation, value creation, knowledge building, and citizen engagement as a global society.

We have multiple accounts and multiple levels of relationships within and across those social networks. When we click around on sites we are leaving a trail of ‘digital exhaust’, defining our habits, preferences, curiosities, and explorations. We don’t have control/access/ownership of this data, but 3rd parties do. Each of these pieces, and all the contextual information around it, is INCREDIBLY VALUABLE, but currently fragmented, fractured, and scattered. Shouldn’t we have access to it ALL, so we can connect the dots and make effecitve and meaningful choices?

Why can’t I just export my data, activity, and relationships from each service, and be in control of who gets to see it, which parts they get to access, and how they use it once I give them permission?

Why isn’t there an easy way for me to have an overview of everything about me, and be able to selectively share information about myself, my interests, my capacities, my needs, or my resources?

The Future We Deserve
At the moment, commercial entities know more about our preferences and behaviors online than we do. With all the services out there that facilitate social interaction, there is still no easy way to connect with people with whom we share affinities, and then to effectively exchange information with them or collaborate in a meaningful way.

Our online identity and data *should* be our right to control, so that we are empowered to make better decisions about our lives and well-being, find potential collaborators or kindred spirits, or generally create more meaningful and valuable relationships. It’s worth asking:

What would a people-centric web look like?

What if it felt more like walking through a town commons and less like walking through a shopping mall?

How could identity and trust be built into the architecture of the internet?

To contain the length here, I’ll flesh out some ideas about all this in an upcoming post -“A Framework for Building Online Intelligence”

In the meantime, I’d love to hear your thoughts about identity and personal data ownership.
see also:

Personal leverage for personal data - doc searlsDatabuse: Digital Privacy and the Mosaic

Wednesday, April 27, 2011

"Data trading is the new information economy"

Welcome to the age of data
By: Molly Wood, CNET, April 25, 2011
 In Daniel Suarez's book "Freedom," he describes a world in which members of a revolutionary "darknet" use glasses with heads-up displays to literally visualize the publicly available information about every person on earth.

It floats above them as a callout: Social Security numbers, bank balances, cell phone numbers, addresses, purchasing history, baby pictures, social network posts. That data is visible by anyone with the means to harvest it, and it can be manipulated at will by malicious hackers (like Loki, the Suarez character who "data curse" on someone who annoys him), by governments, and by companies.


Hopefully, you've all realized that Suarez's vision is hardly one of the future: it's a vision of the present. Welcome to the age of data. It's time to get control of your assets.
Caption: Yeah, dude. They're watching you.

Yeah, dude. They're watching you.
This week's iPhone location tracking scandal is just the latest glaring spotlight on how much of your personal information is gushing out the door, whether unprotected on your own devices and ripe for the picking, or into corporate and botnet servers worldwide. And despite reports of a Steve Jobs e-mail declaring that Apple doesn't track anyone, Apple's general counsel told a congressional inquiry in June 2010 that "(t)o provide the high-quality products and services that its customers demand, Apple must have access to the comprehensive location-based information."
Apple is hardly alone in demanding this level of comprehensive personal information. The iOS location-tracking revelations come on the heels of a federal investigation into mobile application data sharing. Investigators charge that seemingly harmless apps like Pandora are, while they're streaming you highly customized media, are also sending "age, gender, location and phone identifiers to various ad networks," according to the Wall Street Journal. The Journal report found that the majority of the 101 apps it tested sent some personal information to a third-party data broker, largely without your knowledge.


Subsequent investigations found that most Android phones transmit some user information, including location data, back to the mother ship, as well, with Google saying only that the data wasn't "traceable to a specific user." (The merits of that argument are up for debate, to say the least.) Even Microsoft is gathering location data on Windows phones.

Sadly, this informational espionage should hardly come as a surprise.
Caption: The iPhone 4: talk about a Trojan Horse.
The iPhone 4: talk about a Trojan Horse.
(Credit: EMMANUEL DUNAND/AFP/Getty Images)
The new cost of "free"
Personal information is the currency of the post-technological age, and the cost of "free" has never been higher. Your data, on an increasingly minute and personal level, powers every Web or network-based company, from start-up to monolith.
Google maintains literally acres of servers dedicated to storing your communications--from e-mail to texts to the transcripts of your voice mail; your browsing and shopping habits; your blog posts; your photos; your calendar appointments; and of course, your intensely personal search histories. If you're logged in to a Google service, that information is all tied to your IP address. Only the thinnest of artificial technical barriers--a sort of loose privacy honor system--keeps Google from combining the data into a scarily accurate digital version of you (like the first digital Cylon, if you will).
But pity poor Google, which must gather all this information by increasingly intrusive means, like the DoubleClick ad cookie that tracks your browsing all across the Web, surreptitious Wi-Fi sniffing, and sending location information about you back to its data centers even when you're not running location apps.

On the other side of the aisle lies Facebook, which has cleverly cajoled 500 million users (and growing) into giving up virtually all the same information for free. Profiles, Places, Deals, and of course, the ever-present Like button, which lets you easily record your preferences for everything from opinions to shoes to celebrities and bands...you can almost imagine Facebook whispering a little "thank you" every time you click that little blue button.

Want to understand why Google is so desperate to get into social that it's tied part of every employee's bonus to the success or failure of that strategy in 2011? It has nothing to do with helping you share your photos and restaurant check-ins, and everything to do with data collection--and data connections.
Caption: Connected, we stand.
Connected, we stand.
(Credit: Google)
The real magic of the new world of data collection is far more than just hoovering up reams of anonymous or semi-anonymous information. The real magic is in using that data to draw connections between action and reaction, consideration and purchase, brand and affinity, and to sip from the holiest of all commerce grails: recommendation.

The Web as real-time recommendation engine is the ultimate goal of initiatives ranging from the Amazon recommendation queue to Netflix's $1 million prize to the team who improved its recommendation algorithm by 10 percent or more to Facebook's original Beacon program.
Foursquare is working hard to integrate recommendations into its check-in service; Yahoo just spent a reported $20 million to $30 million on a TV check-in and recommendation service called IntoNow that's just 12 weeks old. It's a pretty simple equation: if they can figure out what you like, they can sell you more of what you like.

And the key to recommendation is scale. You can't do the math until you aggregate as many likes, dislikes, check-ins, one, two, and four stars as possible. All of these services depend, first and foremost, on you providing the data for them to crunch. And thanks to your life online, and, increasingly, the phone in your pocket, that data is as ever-present as the air we breathe.

Who's buying?
See, but Google, Facebook, and Apple are the companies we "trust," like we trusted that Pandora was just delivering great '80s tunes on my now-dusty Bon Jovi station. So, where's all our information going? To a silent but deadly collection of data brokers, marketers, and data aggregation services.

These ranks include Epsilon, recently the subject of what Computer World called "the hack of the century." No one knows how many e-mail addresses were exposed in the Epsilon breach, or the full scope of what else may have been revealed, but it has more than 2,000 clients and handles 40 billion e-mails a year. Its database of active shoppers (which included those who opted out but were retained in the database, if not actively emailed) was a gold mine for hackers and spear phishers, and there are 25 more companies where they came from--and that's just email marketing. Merlin Information Services: for all your massive personal information database needs
What should you do?
What can you do? The short answer is, not a lot. Sure, you can go opt out of every data broker on the list, you can stay off the grid, you can give false names and live on cash. But the real question is: do you need to? Or, should we accept that we're in the age of data and embrace--nay, demand--that the data transparency go both ways?

Take the time to own your own data and clear the Web of any information you'd rather not be out there--you can at least try to opt out of sites like Spokeo and other aggregators, if only to protect the most sensitive information. And you don't have to trust the cloud. Ironically, despite its aggregation of information at a scale that would make Skynet envious, Google has engineers in-house who've created the Data Liberation Front, which lets you freely export your own information from the big G. Facebook lets you download everything you've ever posted (surprising, right?).

If you just want to back up and retain your data, services like Backupify index your cloud data and back it up, while Greplin lets you index the cloud services and search them, too (yes, I'm aware that both sites may engage in the same kind of ad targeting or data brokering I'm complaining about: read your terms of service, folks!).

And hey, as long as start-ups are making money brokering data, I'd like to see one that lets you see, say, your Data Score. If Greplin or Backupify can index your cloud information, why can't a company index it and parse it? A Data Score could tell you how risky your overshares are: does it make you unemployable, or just questionable? It could tell you what data is unintentionally public, like the cell phone number you thought you were hiding behind Facebook's byzantine wall of privacy settings. It could even perform a TurboTax like audit, and warn you when publicly available information about you might lead to easy identity theft or obvious phishing attempts.

The best disaster mitigation is preparedness. At some point, data trading is the new information economy, our privacy expectations will adjust accordingly, and yes, there are benefits. But we shouldn't stumble blindly into it--we ought to at least be willing and informed partners in managing our digital identities. Then we can click the ad for those perfect nude pumps in relative peace. After all, they do go with everything.

Wednesday, March 16, 2011

New concern: The social media and privacy divide

"The Digital Divide" has vexed and worried researchers for at least a decade, raising concerns that entire groups of Americans might be left behind, unable to afford the gadgets of the 21st Century.
Perhaps it's the social network divide they should worry about instead.
There is plenty of empirical evidence that those who choose to avoid Facebook, MySpace, and Twitter suffer social consequences: Ask anyone who missed a party -- or for that matter, a wedding -- that was organized on Facebook.
New evidence from a survey conducted exclusively for msnbc.com suggests that divide is becoming a pitched battle, with simmering frustrations between pro- and anti-social network crowds over an issue that is central to the digital age and the future of social networks: Privacy.
The survey suggests that Americans' opinions on privacy are polarizing towards two extremes -- it's become either much more important or much less important -- and the fault line is social media participation.  It was conducted by The Ponemon Institute as part of msnbc.com's recent four-part privacy series.
The series comes as Congress and the Federal Trade Commission weigh a series of legislative initiatives designed to deal with online privacy issues, including the so-called Do Not Track list, modeled after the wildly popular Do Not Call list.  The Senate Commerce Committee is scheduled to hold a hearing on the issue on Wednesday.
Avid Facebook users said they care much less about privacy than they did five years ago, falling deeper into the "I have nothing to hide, so why worry" category; social media avoiders said they care much more now, and are more concerned than ever about their ability "to be left alone."
(For a deeper exploration of these points of view, read Wilson Rothman's piece aimed at the nothing to hide crowd, Helen Popkin's piece for the privacy elite, and my piece for the middle-of-the-road audience.)
Ordinarily, when asked a more/about the same/less question, most survey takers opt for the middle choice, said Larry Ponemon of The Ponemon Institute. In this case, 36 percent said they cared less about privacy than five years ago, and the same percentage said they care more. Only one in four picked "about the same."
"It is a surprising result," he said.  "The fact that the numbers are pulling to each side is an interesting finding.  The fact is there's not a lot of complacency about privacy now.  People are thinking about this."
A look inside the numbers offers an easy explanation for the polarization: Among active social network users, 58 percent said privacy was less important and only 14 percent said its importance was growing. Non-social media users were almost a mirror image in reverse, with 53 percent saying privacy is more important to them, but only 20 percent saying it was less so.
Privacy has been a vexing topic for researchers because consumers for years have said it's important to them, but rarely act out of that concern. They won't often shun supermarket discount loyalty cards, for example. Any survey result in which consumers admit caring less about privacy is intriguing, Ponemon said.
"It's the old convenience argument. I want a reason to do the things I like to do," he said. People who have chosen to use Facebook and its rivals want to believe they are safe; and very few people have experienced any real trouble from their privacy choices.  "People's experience seems to be, 'I went in the water and the shark didn't eat me, so they continue doing what they like to do."
On the other hand, the mere existence of social media tools has pushed non-users to think more seriously about privacy, Ponemon said.
Who doesn't use social networks? You'd be surprised. According to the Pew Internet and American Life Project, 39 percent of U.S. adult  Internet users still aren't on Facebook, Twitter or a similar service.  Non-users tend to be male (44 percent to 33 percent for women), older (56 percent of 50- to 64-year-olds aren't users), have less education (45 percent of non-high school graduates aren't) and less income (40 percent of those earning less than $30,000 aren't), according to Pew.
Privacy concerns are one of myriad reasons why someone might not join a social network.
Of course, you don't have to be a member of a social network to have your privacy violated by the service.  Non-Facebook users, for example, can have their photograph taken, published and shared a million times over on the site.
Alessandro Acquisti, an economist who studies privacy at Carnegie-Mellon University, says the privacy issue may be polarizing because the penalty for avoiding social networks is becoming more severe over time.
"Not having a mobile phone now would dramatically cut you off from professional and personal life opportunities.  It's the same story with social networks," Acquisti said. "The more people use them for socializing and for their professional life, the more costly it becomes for others (who aren't members) to be loyal to their views."
The cost in some ways is basic. Many Facebook users now assume all their posts are common knowledge, and skip old-fashioned ways of communicating even important events now. That leads to awkward, "What do you mean you didn't know I was engaged" conversations.
For some, the consequences are far more serious. It's hard to imagine a more powerful tool for job-search networking that Facebook; it's easy to imagine an unemployed worker suffering for taking a stand against joining the service. This social media usage gap effect could ultimately be as dramatic, or even more so, than the digital divide.
"I don't presume to have a good answer," Acquisti said. "But one can make an argument that protecting privacy in a world where people don't see the value of it is going to become costlier and costlier. That means some people's right to privacy is being rendered more difficult to protect precisely by the right of other people not to care about privacy."
Behind the numbers
The Ponemon Institute survey estimates that 42 percent of U.S. adults call themselves "active users" of social networks.
One interesting finding of the research: While Congress and companies involved extol the virtues of giving "control" of personal data to consumers as a solution to troubling privacy issues, users themselves are under no illusions that they maintain control. By equal amounts, both social network users and non-users overwhelmingly say they have less control over their data today than five years ago -- about 70 percent say they have less control; 18 percent say they about the same control; and only 1 in 7 users say they have more control.
Meanwhile, virtually no one believed the statement: "I am confident that I can protect my personal information when I'm online." Only 4 percent “strongly agreed”; another 14 percent agreed, while 33 percent disagreed and 18 percent strongly disagreed. The results, again, were essentially the same for social media users and non-users.
One in two users said they'd suffered a privacy-violating experience in the past two years, with most of them saying they'd been hit several times. Two-thirds said they'd suffered between four and 10 privacy violations during that time. The results were the same for social media users and non-users.
One in four survey takers said they'd been a victim of identity theft during their lifetime.
Consumers said they trusted the government more than private corporations by a factor of 2.5-1 when it came to protecting privacy, but two-thirds of respondents said they trusted neither.
The Ponemon survey was conducted using an online panel that included a representative sample of U.S. adults and comes with a margin of error of +/- 4.5 percent.

Wednesday, March 2, 2011

The Failure of Online Social Network Privacy Settings

The Failure of Online Social Network Privacy Settings
Michelle Madejskiy. Maritza Johnson, Steven M. Bellovin

CUCS-010-11


Abstract

Increasingly, people are sharing sensitive personal information via online social networks (OSN). While such networks do permit users to control what they share with whom, access control policies are notoriouslydifficult to con gure correctly; this raises the question of whether OSN users' privacy settings match theirsharing intentions.

We present the results of an empirical evaluation that measures privacy attitudes andintentions and compares these against the privacy settings on Facebook. Our results indicate a seriousmismatch: every one of the 65 participants in our study con rmed that at least one of the identi ed violationswas in fact a sharing violation. In other words, OSN users' privacy settings are incorrect.

Furthermore, a majority of users cannot or will not fix such errors. We conclude that the current approach to privacy settingsis fundamentally awed and cannot be fixed; a fundamentally different approach is needed. We presentrecommendations to ameliorate the current problems, as well as provide suggestions for future research. 


Available at https://mice.cs.columbia.edu/getTechreport.php?techreportID=1459&format=pdf&

Tuesday, March 1, 2011

Future of Privacy Forum Video

Swire vs Rosen Video at Future of Privacy Forum (March 1, 2011)
http://www.livestream.com/futureofprivacy/video?clipId=pla_363925a8-d44c-4848-a81a-8824cb4b40f6&utm_source=lslibrary&utm_medium=ui-thumb

Swire: How Individual Rights Can Both Encourage and Reduce Uses of Personal Information

Social Networks, Privacy, and Freedom of Association

By Peter Swire | February 28, 2011

Governments are concerned about protecting the privacy of social network users and other online activities. Yet a previously unaddressed question is precisely how to create privacy rules without jeopardizing the freedom of association inherent in these networks’ very existence.

The ongoing political transformation in Egypt highlights the crucial role that social networks play in helping individuals organize politically. Facebook was central to the initial sweep of Egyptians onto the streets of their nation’s main cities, allowing dispersed individuals to organize effectively. And democracy protesters could fear, if the popular movement to displace President Hosni Mubarak had not been successful, that the regime would be able to track them down individually, in part through their Facebook accounts.

At precisely the same time that everyday Egyptians were pouring out of their homes in protest, the U.S. Federal Trade Commission was receiving comments on how new online technologies, including social networks, affect privacy. The FTC request obviously did not spark protests across American cities but many here in the United States share the worries of those Egyptian protesters when it comes to privacy, including privacy of their political views but not just political privacy. These deeply held worries about information sharing must be considered given the growing role of social networking in our society—from Barack Obama’s successful online political campaign that helped propel him into the presidency in 2008 to the Tea Party’s successful social networking activism beginning a year later.

This report explores the tension between information sharing, which can promote the freedom of association, and limits on information sharing, notably for privacy protection. Although many experts have written about one or the other, my research has not found any analysis of how the two fit together—how freedom of association interacts with privacy protection. My analysis here, which I offer as a “discussion draft” because the issues have not been explained previously, highlights the profound connection between social networking and freedom of association.

At the most basic level, linguistically, “networks” and “associations” are close synonyms. They both depend on “links” and “relationships.” If there is a tool for lots and lots of networking, then it also is a tool for how we do lots and lots of associations. In this respect, social networks such as Facebook and LinkedIn are simply the latest and strongest associational tools for online group activity, building on email and the Web itself. Indeed, the importance of the Internet to modern political and other group activity is highlighted in a new study by the Pew Foundation, which finds that a majority of online users in the United States have been invited through the Internet to join a group, and a full 38 percent have used the Internet to invite others to join a group.

This new intensity of online associations through social networks is occurring at the same time as social networks and other emerging online activities receive increasing scrutiny from policymakers for privacy reasons, including the Federal Trade Commission, a recent report on privacy from the U.S. Department of Commerce, and a process underway in the European Union to update its Data Protection Directive. All these government efforts are concerned about protecting the privacy of users of social networks and other online activities, yet a previously unaddressed question is precisely how to create privacy rules without jeopardizing the freedom of association inherent in these networks’ very existence.

I stumbled into this tension between association and privacy due to a happenstance of work history. I have long worked and written on privacy and related information technology issues, including as the chief counselor for privacy under President Clinton. Then, during the Obama transition, I was asked to be counsel to the new media team. These were the people who had done such a good job at grassroots organizing during the campaign. During the transition, the team was building new media tools for the transition website and into the overhaul of whitehouse.gov.

My experience historically had been that people on the progressive side of politics often intuitively support privacy protection. They often believe that “they”— meaning big corporations or law enforcement—will grab our personal data and put “us” at risk. The Obama “new media” folks, by contrast, often had a different intuition. They saw personal information as something that “we” use. Modern grassroots organizing seeks to engage interested people and go viral, to galvanize one energetic individual who then gets his or her friends and contacts excited.
In this new media world, “we” the personally motivated use social networks, texts, and other outreach tools to tell our friends and associates about the campaign and remind them to vote. We may reach out to people we don’t know or barely know but who have a shared interest—the same college club, rock band, religious group, or whatever. In this way, “our” energy and commitment can achieve scale and effectiveness. The tools provide “data empowerment,” meaning ordinary people can do things with personal data that only large organizations used to be able to do.

This shift from only “them” using the data to “us” being able to use the data tracks the changes in information technology since the 1970s, when the privacy fair information practices were articulated and the United States passed the Privacy Act. In the 1970s, personal data resided in mainframe computers. These were operated by big government agencies and the largest corporations. Today, by contrast, my personal computer has more processing power than an IBM mainframe from 30 years ago. My home has a fiber-optic connection so bandwidth is rarely a limitation. Today, “we” own mainframes and use the Internet as a global distribution system.

To explain the interaction between privacy and freedom of association, this discussion draft has three sections. The first section explains how privacy debates to date have often featured the “right to privacy” on one side and utilitarian arguments in favor of data use on the other. This section provides more detail about how social networks are major enablers of the right of freedom of association. This means that rules about information flows involve individual rights on both sides, so advocates for either sort of right need to address how to take account of the opposing right.

The second section shows step by step how U.S. law will address the multiple claims of right to privacy and freedom of association. The outcome of litigation will depend on the facts in a particular case but the legal claims arising from freedom of expression appear relevant to a significant range of possible privacy rules that would apply to social networks.

The third section explains how the interesting arguments by New York University law professor Katherine Strandburg fit into the overall analysis. She has written about a somewhat different interaction between privacy and freedom of association, where the right of freedom of association is a limit on the power of government to require an association to reveal its members. As discussed below, her insights are powerful but turn out to address a somewhat different issue than much of the discussion here.

Peter Swire is a Senior Fellow at the Center for American Progress and the C. William O’Neill Professor of Law at the Ohio State University.
Read the full report (pdf)
Download the executive summary (pdf)
Download the report to mobile devices and e-readers from Scribd

Saving Facebook - James Grimmelman

 ABSTRACT

This Article provides the first comprehensive analysis of the law and policy of privacy on social network sites, using Facebook as its principal example.

It explains how Facebook users socialize on the site, why they misunderstand the risks involved, and how their privacy suffers as a result. Facebook offers a socially compelling platform that also facilitates peer-to-peer privacy violations: users harming each others’ privacy interests. These two facts are inextricably linked; people use Facebook with the goal of sharing information about themselves. Policymakers cannot make Facebook completely safe, but they can help people use it safely.

The Article makes this case by presenting a rich, factually grounded description of the social dynamics of privacy on Facebook. It then uses that description to evaluate a dozen possible policy interventions. Unhelpful interventions—such as mandatory data portability and bans on underage use—fail because they also fail to engage with key aspects of how and why people use social network sites. On the other hand, the potentially helpful interventions—such as a strengthened public-disclosure tort and a right to opt out completely—succeed because they do engage with these social dynamics.

DATA SEGMENTATION IN ELECTRONIC HEALTH INFORMATION EXCHANGE: POLICY CONSIDERATIONS AND ANALYSIS

Prepared for ONC

The issue of whether and, if so, to what extent patients should have control over the sharing or withholding of their health information represents one of the foremost policy challenges related to electronic health information exchange.

It is widely acknowledged that patients’ health information should flow where and when it is needed to support the provision of appropriate and high-quality care. Equally significant, however, is the notion that patients want their needs and preferences to be considered in the determination of what information is shared with other parties, for what purposes, and under what conditions.

Some patients may prefer to withhold or sequester certain elements of health information, often when it is deemed by them (or on their behalf) to be "sensitive," whereas others may feel strongly that all of their health information should be shared under any circumstance.

This discussion raises the issue of data segmentation, which we define for the purposes of this paper as the process of sequestering from capture, access or view certain data elements that are perceived by a legal entity, institution, organization, or individual as being undesirable to share.

This whitepaper explores key components of data segmentation, circumstances for its use, associated benefits and challenges, various applied approaches, and the current legal environment shaping these endeavors.

Full text at: www.gwumc.edu/sphhs/departments/healthpolicy/dhp_publications/pub_uploads/dhpPublication_168F948B-5056-9D20-3D2C53BEED88834B.pdf

Sunday, February 27, 2011

Facebook vs. FTC Round 2: Facebook Responds

BY GREGORY FERENSTEIN Wed Feb 23, 2011

Facebook's response to the FTC urges optimism and governmental restraint.

Facebook just released a 26-page retort to the Federal Trade Commission’s preliminary report on privacy regulation--a report that social media firms see as an ominous approaching storm of chaotic bureaucracy. In summary, Facebook fears that government meddling could stifle both its ability to profit and smother the industry’s progress on yet-unknown technological advancements.

Facebook responded in mirror-image to the FTC; first, (respectively) reminding the FTC how much social media has done for the government itself, the advancement of democracy, and the growing cottage industry of social software:

On government
"In government, leaders use social media services to promote transparency, as evidenced by the nearly 140,000 followers of the White House Press Secretary's Twitter feed and the fact that more than 70 federal agencies have Facebook pages."

On democracy
"Advocates of democracy used Twitter to make their voices heard following the contested 2009 Iranian election of and Oscar Morales in Colombia famously employed Facebook to organize massive street demonstrations against the FARC terrorist group in 2008. Most recently, people in Tunisia and Egypt used social media to spread up-to-the-minute news, share videos of local events with the broader population, and mobilize online communities of thousands (and sometimes millions) behind a common cause."

On business
"Finally, the social web is a crucial engine for economic growth and job creation. Hundreds of thousands of application developers have built businesses on Facebook Platform. To take just one example, games developer Zynga, creator of the popular Farmville game, has more than 1,300 employees and has been valued at about $5.8 billion."

Second, it pleaded for the FTC to be optimistic about how ostensibly intrusive technologies end up benefiting the public:

Caller ID
"Telephone companies originally collected and exchanged subscribers’ telephone numbers solely for the purpose of completing telephone calls. But telephone companies later realized that they could use this information to display the calling party's telephone number and name to the call recipient, allowing the recipient to identify the caller in advance. Today, caller ID is an accepted and valued part of telephone communication, and few subscribers choose to block outgoing caller ID even though it is easy to do so."

Facebook Newsfeed
"In 2006 Facebook launched a new feature called News Feed on every person's homepage. The product updated a personalized list of news stories throughout the day so users would know what their friends were posting. Before News Feed, people had to visit their friends' profiles to see what their friends were up to. Despite initial user skepticism when the product was first launched, News Feed is now--as any user would attest--an integral part of the Facebook experience."

Google Flu Trends
"When the founders of Google began collaborating on a search engine research project in 1996, they probably did not envision that search queries about topics would one day become an early detection system for flu outbreaks. Today, Google Flu Trends can estimate flu activity one to two weeks more quickly than traditional surveillance systems involving virologic and clinical data, and may help public health officials and health professionals better respond to seasonal epidemics."

Finally, Facebook urged the FTC to be sensitive to the business implications of its decisions: “For Facebook--like most other online service providers--getting this balance right is a matter of survival,” the report notes.

It continued, "Ultimately, the FTC's enforcement activities in the area of privacy must be guided by the realization that aggressive enforcement and imprecise standards can lead to more legalistic disclosures--and, as described above, chill economic growth--as companies seek to manage regulatory risk by over-disclosing, reserving broad rights, and under-innovating. To avoid these unintended consequences, the FTC should err on the side of clarifying its policies rather than taking aggressive enforcement action against practices that previously were not clearly prohibited."

Both the FTC and Facebook have been light on data on experimental evidence--and both are obscuring a yet unrevealed future value (or detriment) associated with all of this sharing. Then again, forecasting problems into a very turbulent future is nearly impossible. Ultimately, both documents read like the fight will come down to a philosophical debate. And billions of dollars.
Full Facebook response at: http://www.fastcompany.com/1731121/facebook-ftc-response

Monday, February 14, 2011

Healthcare Social Media Sites Neglect Privacy Protections

Analysis of diabetes sites indicates that many lack scientific accuracy and put users' personal information at risk.

By Nicole Lewis,  InformationWeek Feb. 14, 2011

As the Internet in general and social networking in particular are used as a point of reference for gathering and sharing health information, a study that examined 10 diabetes-focused social networking sites has found that the quality of clinical information, as well as privacy policies, significantly varied across these sites.

The study, "Social but safe? Quality and safety of diabetes-related online social networks," was conducted by researchers in the Children's Hospital Boston informatics program who performed an in-depth evaluation of the sites and found that only 50% presented content consistent with diabetes science and clinical practice.

The research, published in late January in the Journal of the American Medical Informatics Association, also revealed that sites lacked scientific accuracy and other safeguards such as personal health information privacy protection, effective internal and external review processes, and appropriate advertising.

For example, misinformation about a diabetes cure was found on four moderated sites. Additionally, of the nine sites with advertising, transparency was missing on five, and ads for unfounded cures were present on three. Technological safety was poor, with almost no use of procedures for secure data storage and transmission.

The study found that only three sites support member controls over personal information. Additionally, privacy policies were difficult to read and only three sites (30%) demonstrated better practice, wrote the study's authors.

Elissa R. Weitzman, lead author of the study and assistant professor at Harvard Medical School, told InformationWeek that she was surprised at the high use of online health-related social networking among people with diabetes, and noted that the healthcare community and key stakeholders at these sites should implement policies to protect member privacy and align site content with medical science and clinical practice.

"Exchanging information on these sites has the potential to accelerate what we know about this disease and to rapidly disseminate vital information and support. However, the spread of information throughout online communities poses a safety concern for patients," Weitzman observed. "I'm surprised that the clinical healthcare system seems to be lagging behind patients and consumers in engaging with this medium and finding ways to support them, synergistically -- without trying to replace or control them."


"I think a sustainable standard for how these communities operate with respect to privacy, security, and honesty will come about because the communities themselves and their users will adopt and enforce norms of transparency and protection," Weitzman predicted. "One way this could happen is for stakeholders of these sites to develop a system of 'peer review' around these issues to support better or best practices."

The study evaluated diabetes Web sites that appeared prominently in Google searches and allowed members to create personal profiles and interact with each other. The study examined four key factors:

-- agreement of content with diabetes science and clinical practice standards,
-- practices for auditing content and supporting transparency,
-- accessibility and readability of privacy policies, and
-- the degree of control members had over the sharing of personal data.

The average number of members per Web site was 6,707. Activity ranged widely among the sites, from over 100 new posts per day to less than 5 new posts per day.

Other findings were that the majority of sites did not include a "disclaimer" encouraging patients to discuss their care regimen with a healthcare provider. Several sites did not post essential diabetes information, such as the definition of "A1c" -- a biomarker commonly used by diabetics to access blood glucose levels.

In addition to recommending improvements in these areas, the authors saw a need for increased moderation, for the credentials of moderators to be more visible, and for periodic external review. Further, potential conflicts of interest -- such as ties to the pharmaceutical industry -- needed to be more clearly disclosed, and privacy policies easier to understand.

Weitzman is an assistant professor in the laboratory of Kenneth Mandl, who also co-authored the study. Last year the two developed an application for the social networking website TuDiabetes that allows users to submit their A1c levels to be displayed in a worldwide map, as part of an effort to encourage diabetes management and inform public health efforts and research.

Researchers said they chose to study diabetes-related networks because they were among the earliest to emerge and remain among the most active. The research team in the Children's Hospital informatics program will further study how these sites are used -- how people choose to interact with them and how specifically they share their medical information.
Weitzman also said the Web is a notoriously difficult sphere to regulate with respect to issues of privacy, information security, and honesty in advertising, but said she is hopeful that these sites will improve.

Tuesday, February 1, 2011

Peter Swire: Getting Online Privacy Policy Right

Commerce Department Considers New Private Policy Office

By Peter Swire  Center for American Progress  January 28, 2011

Online privacy is drawing increasing attention from policy makers, the press, and the public due to rapid changes in social networking, online targeted advertising, and location-based services for smart phones.

Last month, the Department of Commerce asked for comment on its new green paper, entitled “Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework.” One important proposal in the green paper was to create a Privacy Policy Office in the Department of Commerce.

I have submitted comments explaining “Why the Federal Government Should Have a Privacy Policy Office.” The chief criticism of the proposal is that the new office would weaken privacy protection. In one vivid turn of phrase, Jeff Chester of the Center for Digital Democracy said: “Having the Commerce Department play a role in protecting privacy will enable the data collection foxes to run the consumer privacy henhouse.” Chester and other privacy advocates essentially argue that having the Commerce Department play a role in privacy policy will dilute the effectiveness of the Federal Trade Commission’s privacy efforts.

I disagree, and reach three conclusions, which I explain below. My comments also consider whether the new office should be placed in the Department of Commerce, as the green paper recommends, or else in the Executive Office of the President, where I served as chief counselor for privacy under President Clinton. I conclude that the important thing is to ensure an ongoing privacy policy capability in the executive branch, while a good case can be made for housing it either in the Commerce Department or the Executive Office of the President. 

Why the Federal Government Should Have a Privacy Policy Office
These comments support the creation of a Privacy Policy Office in the executive branch, as called for in the Department of Commerce green paper, “Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework.”

The chief criticism of this proposal is that the office would weaken privacy protection. In one vivid turn of phrase, Jeff Chester of the Center for Digital Democracy said: “Having the Commerce Department play a role in protecting privacy will enable the data collection foxes to run the consumer privacy henhouse.” Mr. Chester and other privacy advocates essentially argue that having the Commerce Department play a role in privacy policy will dilute the effectiveness of the Federal Trade Commission’s privacy efforts.
I disagree. My comments support three conclusions:
      1. The office would provide important benefits to complement what the FTC does. As part of the executive branch, the office would make distinctive contributions to building privacy policy into the development and implementation of U.S. government positions for domestic and international policy. Relatedly, the office would be able to draw on the perspectives and expertise of other federal agencies far more effectively than can an independent agency such as the FTC. 2. The likely outcome with an office would be better protection of privacy than would occur without the office. 3. The likely outcome with an office would be better achievement of other policy goals than would occur without the office.
These comments also consider whether the office should be placed in the Department of Commerce, as the greenpaper recommends, or else in the Executive Office of the President, which housed the office of the chief counselor for privacy under President Clinton. I conclude that the important thing is to ensure an ongoing privacy policy capability in the executive branch, while a good case can be made for housing it either in the Commerce Department or the Executive Office of the President.

Background on privacy and the department of commerce
Much as is occurring this year, the FTC and Commerce Departments played complementary roles in the mid- to late-1990s in developing privacy policy. At the Federal Trade Commission, privacy initiatives were pushed by Chairman Robert Pitofsky, Commissioners Mozelle Thompson and Christine Varney, and Director of the Consumer Protection Bureau Jodie Bernstein (along with her dedicated staff, led by David Medine). At the Commerce Department, Barbara Wellbery and Becky Burr played important roles, as did Administrator of the National Telecommunications and Information Administration Larry Irving, General Counsel Andy Pincus, Undersecretary for the International Trade Administration David Aaron, and Secretary William Daley. The history of the FTC’s involvement in this period has been well discussed in work by Kenneth Bamberger and Deirdre Mulligan.

The vital work in that period of the Department of Commerce has been less fully discussed.[1] In 1997, Secretary Daley personally hosted a major conference and report on “Privacy and Self-Regulation in the Information Age.” That conference engaged many of the persons, and developed many of the concepts, that shaped U.S. privacy policy in the following years.[2] The department then led the complex and ongoing negotiations with the European Union about how to reconcile the E.U. Data Protection Directive and U.S. law, culminating in the Safe Harbor agreement in 2000, which is still in effect today. For the Safe Harbor and in numerous other privacy issues, the department, including its International Trade Administration, brought expertise to bear on topics such as e-commerce, international trade, and how privacy fits into broader business practices.

In the summer of 1998, Vice President Al Gore announced that a privacy policy position would be created in the U.S. Office of Management and Budget. As discussed further below, I entered the role of chief counselor for privacy in early 1999, and worked closely with the Department of Commerce, the FTC, and other agencies until early 2001. Under President George W. Bush, the Commerce Department administered the Safe Harbor program, but did not play as visible a policy role on privacy.

Under President Obama, Secretary Gary Locke created the Internet Policy Task Force , which has published the green paper that is the subject of these comments, entitled “Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework.” The green paper states:
      Recommendation #4: Using existing resources, the Commerce Department should establish a Privacy Policy Office (PPO) to serve as a center of commercial data privacy policy expertise. The proposed PPO would have the authority to convene multi-stakeholder discussions of commercial data privacy implementation models, best practices, codes of conduct, and other areas that would benefit from bringing stakeholders together; and it would work in concert with the Executive Office of the President as the Administration’s lead on international outreach for commercial data privacy policy. The PPO would be a peer of other Administration offices and components that have data privacy responsibilities; but, because the PPO would focus solely on commercial data privacy, its functions would not overlap with existing Administration offices. Nor would the PPO have any enforcement authority.
For reasons set forth below, I generally support this recommendation, but with greater emphasis on certain functions the office can play, especially as an ongoing source of institutional expertise on privacy and in order to facilitate the interagency clearance of privacy-related issues.

A complementary role for a privacy office in Commerce: The importance of clearance and international privacy issues
To assess the potential usefulness of the PPO, it helps to first understand some important roles played by the Federal Trade Commission in privacy protection:
      1. Enforcement. The FTC has the power to bring enforcement actions against “unfair and deceptive trade practices,” and has negotiated consent decrees on privacy with both large and small companies. 2. Rulemaking.In specific areas, such as children’s online privacy and anti-spam measures, the FTC has explicit authority to issue rules under the Administrative Procedure Act. More broadly, the FTC could write rules under the more burdensome procedures created by the Magnuson-Moss Act, but it has not chosen to do so on privacy. 3. Convener.The FTC has brought together stakeholders in a variety of ways to discuss emerging online privacy issues, and in some instances catalyze industry self-regulatory codes of conduct. 4. Institutional expertise. Leading members of today’s FTC efforts were also active during the privacy debates of the 1990’s. The continuity of FTC staff has contributed to the commission’s institutional expertise on privacy issues. 5. Bully pulpit. Top FTC officials and staff direct the attention of companies toward emerging privacy issues.
The Commerce Department has at least two distinctive roles that complement this list of FTC privacy functions: clearance and ability to speak internationally for the administration.
The role of “clearance” is particularly important yet often little understood. In a 2000 document prepared for publication in the Stanford Law Review but not actually published, I went into some detail on the subject. To ensure a unified administration position, for congressional testimony, executive orders, and many other documents, drafts of documents are circulated among the various agencies and components of the Executive Office of the President. Once comments are received, discussions are sometimes needed to resolve differences of opinion, with appeal to more senior officials if differences are not resolved at lower levels. In addition to these structured clearance procedures, agency experts on an issue such as privacy often get engaged earlier in the policy planning process, in a variety of working groups and less-formal methods of sharing expertise and views.

In my experience, an independent agency, such as the FTC, has a sharply limited ability to participate in the Administration’s clearance process. On some occasions, a draft document may be shared with the FTC, often early in a policy process, for whatever input the commission may wish to offer. The decision making, however, is done by persons in the executive branch, notably the Executive Office of the President and cabinet agencies such as the Department of Commerce. There are important and long-standing reasons for this separation between independent and executive agencies—the separation avoids the appearance of political pressure on independent agencies. Separation is especially important for enforcement decisions—the FTC has true independence on what enforcement actions it brings, but the corollary is that the FTC is not “inside” the administration when it comes to creating administration policy. A variety of rules exist to limit the interaction of independent agencies and the executive branch; new White House officials, for instance, are briefed by counsel to exercise great caution in their interaction with independent agencies.

As an example of the constructive role in clearance played by the Department of Commerce, consider testimony in 2010 on the controversial question of whether and how to amend the Electronic Communication Privacy Act of 1986. ECPA is an important law for law enforcement—it sets forth the standards by which police and prosecutors can get access to emails and other electronic communications. ECPA, though, is also an important law about corporations and personal privacy. For corporations, ECPA sets the rules for what sorts of access to corporate databases should be permitted, under what circumstances and at what cost. For individuals whose records may be seen by law enforcement, ECPA creates the rules of the road for privacy protection, especially in our modern world when many records are stored in the “cloud” and thus at least potentially accessible to law enforcement.

ECPA thus provides one example of how multiple, compelling values can come into play in clearing the administration’s testimony to Congress. On September 22, 2010, both James Baker of the Department of Justice and Cameron Kerry of the Commerce Department testified before the Senate Judiciary Committee. Under the clearance rules, the testimony of both witnesses had to be shared in advance with the other, and the administration had to develop a common position. In my experience, sharing a draft document with an agency with a sharply different perspective is often extremely valuable—assumptions held in the initial agency get challenged, overstatements are modified, and the number of mistakes is reduced. Although I have no direct knowledge of the clearance process in this instance,[3] I think it quite possible that the presence of the Department of Commerce in the process helped create a more nuanced and privacy-protective administration position.

The ability of an independent agency such as the FTC to have a similar role in clearance is sharply limited. Based on my own experience, and on background discussions with people at the FTC, the FTC is not staffed well enough or situated close enough to the “inside” to engage on the day-to-day clearance of documents on the many law enforcement issues affecting commerce and privacy, including ECPA, the Communications Assistance to Law Enforcement Act, rules about encryption controls, and so forth.

From my time as chief counselor for privacy, the number of privacy issues addressed by federal agencies is far greater than realized by most people who have worked primarily on privacy with the FTC. I offer a list here as an illustration of the sorts of privacy issues that can arise in each of the cabinet departments. For many of the agency activities, there are important implications for commerce, providing a natural role for the Department of Commerce on commercial privacy issues. For others, the link to commerce is less direct, but a broad-based experience with privacy issues at the Department of Commerce will facilitate development of a sound administration position on privacy:

·       Department of Agriculture. Migrant worker records
·       Department of Defense and Veterans Affairs. Records of service members
·       Department of Education. Education records, including for for-profit institutions
·       Department of Energy. Smart grid
·       Department of Health and Human Services. Medical records; many forms of human services records
·       Department of Homeland Security. Numerous issues, including transportation safety and immigration
·       Department of Housing and Urban Development. Public housing records
·       Department of Interior. National park reservations and other services provided online
·       Department of Justice. Numerous issues
·       Department of Labor. Records of union membership
·       Department of State. International privacy issues
·       Department of Transportation. Smart roads
·       Department of Treasury. Financial privacy; money laundering

Along with clearance, another role for the executive branch is to develop and announce the administration position in international settings. The green paper discusses the office’s role in international privacy activities, but is worth explaining a bit how this would complement any international activities by the FTC.

The FTC plays at least three roles on international privacy issues. First, the FTC is the designated enforcement agency for complaints under the U.S.-E.U. Safe Harbor. Second, the FTC’s overall privacy expertise and convening functions inform international discussions about privacy issues, and there has been international cooperation on enforcement actions. Third, last year the FTC for the first time received full member status in the closed session of data protection authorities at the International Conference of Data Protection and Privacy Commissioners. Executive branch officials continue to attend the closed session, as they have since 1999, but with “observer” status.

These important FTC international activities, however, do not replace the need for the executive branch to have policy capability about privacy. For instance, privacy and e-commerce issues arise in a wide range of bilateral and multilateral trade negotiations—because transborder data flows are such an important part of modern commerce, data-related issues can arise as one piece of many larger trade negotiations, which often involve the International Trade Administration of the Department of Commerce. Some multilateral fora persistently address privacy issues, such as the Asia-Pacific Economic Cooperation and the Organization for International Cooperation and Development. The U.S. delegations for these activities are led by the executive branch, with representation from the Commerce and State Departments.

More generally, the clearance process applies to developing and implementing the position of the United States in international negotiations. The FTC as an independent agency would have no basis for making representations, for instance, about what any executive branch agency would accept, including for law enforcement, homeland security, and non-privacy commercial issues. There is thus a sound basis for the green paper’s recommendation that the office “would work in concert with the Executive Office of the President as the Administration’s lead on international outreach for commercial data privacy policy.”

Whether privacy policy should be centered in the Commerce Department or the executive office of the president
I believe there is an extremely strong case in favor of developing an ongoing privacy policy capability in the executive branch. Privacy policy requires familiarity with a complex set of legal, technological, market, and consumer considerations. Good government thus calls for creating an institutional memory and a group of civil servants experienced in privacy policy. This privacy policy capability goes well beyond the need for federal agencies to comply with the Privacy Act and implement good practices for the personal information they hold.

Where to locate this privacy policy capability is less clear. In a 1998 book, Robert Litan and I discussed the question in detail, and concluded that a privacy policy office should be created in the Department of Commerce.[4] From 1999 until early 2001, by contrast, I served in the role of chief counselor for privacy in the U.S. Office of Management and Budget, and I have written reasons for supporting that approach as well.

The chief advantages and disadvantages are mirror images of each other. Placing the office in the Commerce Department allows for substantially greater staffing, increasing the chance that institutional expertise will accumulate through the ups and downs of public attention to privacy protection. The Commerce Department, however, will be only one of the various agencies that may have views on a particular privacy issue, increasing the risk that privacy will lose out in clearance. On the other hand, placing the policy leadership in OMB or elsewhere in the Executive Office of the President likely improves the possibility of effective coordination of privacy policy across the various agencies. Staffing, however, is always tight at the White House. The chief counselor for privacy, at most, had two full-time staff and one detailee from the Commerce Department.

One model worth considering is the position that Howard Schmidt now fills as cybersecurity coordinator. Mr. Schmidt is part of the national security staff, and also coordinates with the National Economic Council. My understanding is that a significant amount of support for the cybersecurity coordinator is provided by various agencies rather than directly by staff of the Executive Office of the President. A hybrid approach of this sort might achieve more effective privacy policy coordination while also retaining ongoing staffing.

This sort of role might also usefully integrate with the Privacy and Civil Liberties Oversight Board, for which President Obama recently nominated James Dempsey and Elizabeth Collins Cook. That board, to be effective, should have professional staff to carry out its task of working on privacy and civil liberties issues that affect anti-terrorist activities. As shown by the example of the Electronic Communications Privacy Act, anti-terrorist and law enforcement activities often have intricate interconnections with the commercial actors that own and operate most of the infrastructure for processing personal information. It quite possibly makes sense to permit dual tasking of personnel assigned to the board to work on privacy issues that concern commercial privacy. If this were done, an Executive Office of the President role for a privacy coordinator could be supported both by commercial privacy experts and persons assigned to the oversight board.

In short, various institutional choices might succeed for institutionalizing privacy policy in the executive branch. The privacy policy capability prior to 2009, and it is a good sign that the Department of Commerce green paper is reinvigorating the debate about how best to protect privacy policy while achieving other important goals.

Conclusion
In conclusion, the comments here show important tasks for a Privacy Policy Office in the executive branch, which would complement the FTC’s ongoing privacy activities. Notably, such an office would improve interagency clearance, and be important in developing and stating the position of the United States government in international settings. Based on my own discussions with people at the FTC, the FTC does not have the budget or institutional structure to attempt to participate in all of the issues touching on commercial privacy throughout the federal government.

Because these functions complement the existing activities of the FTC, the general effect of such an office would be to improve privacy policy expertise and capabilities, contrary to the concerns expressed by some privacy advocates that such an office would undermine privacy protections. In addition to the advantages described above, executive branch participation in development of industry codes of conduct permits expert input from a range of federal agencies and also brings those agencies up to speed on evolving technology. Another advantage is that an executive branch privacy capability can lend force to privacy legislative or other initiatives—when both the FTC and the administration work together on an issue, the combined effect is likely to be greater than when an independent agency such as the FTC acts alone. Because the administration is likely to be asked to provide its views on important legislation in any event, the existence of an ongoing privacy office in the executive branch will lead to better-informed privacy policy decisions by the administration.

The existence of such an office would also provide a more effective structure for the administration to weigh privacy concerns with other competing policy goals and values. The hope, which I believe is supported by experience, is that participation by privacy experts in executive branch decisions increases the likelihood of win-win situations, in which privacy goals are better achieved and other goals as well.

In short, the Department of Commerce deserves praise for advancing the idea of an ongoing Privacy Policy Office as part of its green paper.     

Download this memo (pdf)
Download the memo to mobile devices and e-readers from Scribd

Peter Swire is the C. William O’Neill Professor of Law at the Moritz College of Law of the Ohio State University, and a Senior Fellow at the Center of American Progress. From 1999 through early 2001 he served as Chief Counselor for Privacy in the U.S. Office of Management and Budget. From 2009 through August, 2010 he served as Special Assistant to the President for Economic Policy, including on privacy and related technology issues.   

Endnotes

[1] One reason may be the untimely death in 2003 of Barbara Wellbery, who worked tirelessly to address the issues of U.S. and E.U. relations in connection with the European Union Data Protection Directive and was instrumental to creation of the Safe Harbor privacy program that is now administered by the Department of Commerce.
[2] The conference invitation pushed me to write “Markets, Self-regulation, and Government Enforcement in the Protection of Personal Information,” my first article specifically on privacy issues.
[3] I served in the National Economic Council until August 2010, before the September 2010 testimony described in the text.
[4] Peter P. Swire and Robert E. Litan, None of Your Business: World Data Flows, Electronic Commerce, and the European Privacy Directive (Brookings, 1998), at 179-188.

To speak with our experts on this topic, please contact:
Print: Megan Smith (health care, education, economic policy)
202.741.6346 or
msmith@americanprogress.org
Print: Anna Soellner (foreign policy and security, energy)asoellner@americanprogress.org
Print: Raúl Arce-Contreras (ethnic media, immigration)
202.478.5318 or
rarcecontreras@americanprogress.org
Radio: Anne Shoup
202.481.7146 or
ashoup@americanprogress.org
TV: Andrea Purse
202.741.6250 or
apurse@americanprogress.org
Web: Erin Lindsay
202.741.6397 or
elindsay@americanprogress.org