Commerce Department Considers New Private Policy Office
By Peter Swire Center for American Progress January 28, 2011
Online privacy is drawing increasing attention from policy makers, the press, and the public due to rapid changes in social networking, online targeted advertising, and location-based services for smart phones.
Last month, the Department of Commerce asked for comment on its new green paper, entitled “Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework.” One important proposal in the green paper was to create a Privacy Policy Office in the Department of Commerce.
I have submitted comments explaining “Why the Federal Government Should Have a Privacy Policy Office.” The chief criticism of the proposal is that the new office would weaken privacy protection. In one vivid turn of phrase, Jeff Chester of the Center for Digital Democracy said: “Having the Commerce Department play a role in protecting privacy will enable the data collection foxes to run the consumer privacy henhouse.” Chester and other privacy advocates essentially argue that having the Commerce Department play a role in privacy policy will dilute the effectiveness of the Federal Trade Commission’s privacy efforts.
I disagree, and reach three conclusions, which I explain below. My comments also consider whether the new office should be placed in the Department of Commerce, as the green paper recommends, or else in the Executive Office of the President, where I served as chief counselor for privacy under President Clinton. I conclude that the important thing is to ensure an ongoing privacy policy capability in the executive branch, while a good case can be made for housing it either in the Commerce Department or the Executive Office of the President.
Why the Federal Government Should Have a Privacy Policy Office
These comments support the creation of a Privacy Policy Office in the executive branch, as called for in the Department of Commerce green paper, “Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework.”
The chief criticism of this proposal is that the office would weaken privacy protection. In one vivid turn of phrase, Jeff Chester of the Center for Digital Democracy said: “Having the Commerce Department play a role in protecting privacy will enable the data collection foxes to run the consumer privacy henhouse.” Mr. Chester and other privacy advocates essentially argue that having the Commerce Department play a role in privacy policy will dilute the effectiveness of the Federal Trade Commission’s privacy efforts.
I disagree. My comments support three conclusions:
1. The office would provide important benefits to complement what the FTC does. As part of the executive branch, the office would make distinctive contributions to building privacy policy into the development and implementation of U.S. government positions for domestic and international policy. Relatedly, the office would be able to draw on the perspectives and expertise of other federal agencies far more effectively than can an independent agency such as the FTC.
2. The likely outcome with an office would be better protection of privacy than would occur without the office.
3. The likely outcome with an office would be better achievement of other policy goals than would occur without the office.
These comments also consider whether the office should be placed in the Department of Commerce, as the greenpaper recommends, or else in the Executive Office of the President, which housed the office of the chief counselor for privacy under President Clinton. I conclude that the important thing is to ensure an ongoing privacy policy capability in the executive branch, while a good case can be made for housing it either in the Commerce Department or the Executive Office of the President.
Background on privacy and the department of commerce
Much as is occurring this year, the FTC and Commerce Departments played complementary roles in the mid- to late-1990s in developing privacy policy. At the Federal Trade Commission, privacy initiatives were pushed by Chairman Robert Pitofsky, Commissioners Mozelle Thompson and Christine Varney, and Director of the Consumer Protection Bureau Jodie Bernstein (along with her dedicated staff, led by David Medine). At the Commerce Department, Barbara Wellbery and Becky Burr played important roles, as did Administrator of the National Telecommunications and Information Administration Larry Irving, General Counsel Andy Pincus, Undersecretary for the International Trade Administration David Aaron, and Secretary William Daley. The history of the FTC’s involvement in this period has been well discussed in work by Kenneth Bamberger and Deirdre Mulligan.
The vital work in that period of the Department of Commerce has been less fully discussed.[1] In 1997, Secretary Daley personally hosted a major conference and report on “Privacy and Self-Regulation in the Information Age.” That conference engaged many of the persons, and developed many of the concepts, that shaped U.S. privacy policy in the following years.[2] The department then led the complex and ongoing negotiations with the European Union about how to reconcile the E.U. Data Protection Directive and U.S. law, culminating in the Safe Harbor agreement in 2000, which is still in effect today. For the Safe Harbor and in numerous other privacy issues, the department, including its International Trade Administration, brought expertise to bear on topics such as e-commerce, international trade, and how privacy fits into broader business practices.
In the summer of 1998, Vice President Al Gore announced that a privacy policy position would be created in the U.S. Office of Management and Budget. As discussed further below, I entered the role of chief counselor for privacy in early 1999, and worked closely with the Department of Commerce, the FTC, and other agencies until early 2001. Under President George W. Bush, the Commerce Department administered the Safe Harbor program, but did not play as visible a policy role on privacy.
Under President Obama, Secretary Gary Locke created the Internet Policy Task Force , which has published the green paper that is the subject of these comments, entitled “Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework.” The green paper states:
Recommendation #4: Using existing resources, the Commerce Department should establish a Privacy Policy Office (PPO) to serve as a center of commercial data privacy policy expertise. The proposed PPO would have the authority to convene multi-stakeholder discussions of commercial data privacy implementation models, best practices, codes of conduct, and other areas that would benefit from bringing stakeholders together; and it would work in concert with the Executive Office of the President as the Administration’s lead on international outreach for commercial data privacy policy. The PPO would be a peer of other Administration offices and components that have data privacy responsibilities; but, because the PPO would focus solely on commercial data privacy, its functions would not overlap with existing Administration offices. Nor would the PPO have any enforcement authority.
For reasons set forth below, I generally support this recommendation, but with greater emphasis on certain functions the office can play, especially as an ongoing source of institutional expertise on privacy and in order to facilitate the interagency clearance of privacy-related issues.
A complementary role for a privacy office in Commerce: The importance of clearance and international privacy issues
To assess the potential usefulness of the PPO, it helps to first understand some important roles played by the Federal Trade Commission in privacy protection:
1. Enforcement. The FTC has the power to bring enforcement actions against “unfair and deceptive trade practices,” and has negotiated consent decrees on privacy with both large and small companies.
2. Rulemaking.In specific areas, such as children’s online privacy and anti-spam measures, the FTC has explicit authority to issue rules under the Administrative Procedure Act. More broadly, the FTC could write rules under the more burdensome procedures created by the Magnuson-Moss Act, but it has not chosen to do so on privacy.
3. Convener.The FTC has brought together stakeholders in a variety of ways to discuss emerging online privacy issues, and in some instances catalyze industry self-regulatory codes of conduct.
4. Institutional expertise. Leading members of today’s FTC efforts were also active during the privacy debates of the 1990’s. The continuity of FTC staff has contributed to the commission’s institutional expertise on privacy issues.
5. Bully pulpit. Top FTC officials and staff direct the attention of companies toward emerging privacy issues.
The Commerce Department has at least two distinctive roles that complement this list of FTC privacy functions: clearance and ability to speak internationally for the administration.
The role of “clearance” is particularly important yet often little understood. In a 2000 document prepared for publication in the Stanford Law Review but not actually published, I went into some detail on the subject. To ensure a unified administration position, for congressional testimony, executive orders, and many other documents, drafts of documents are circulated among the various agencies and components of the Executive Office of the President. Once comments are received, discussions are sometimes needed to resolve differences of opinion, with appeal to more senior officials if differences are not resolved at lower levels. In addition to these structured clearance procedures, agency experts on an issue such as privacy often get engaged earlier in the policy planning process, in a variety of working groups and less-formal methods of sharing expertise and views.
In my experience, an independent agency, such as the FTC, has a sharply limited ability to participate in the Administration’s clearance process. On some occasions, a draft document may be shared with the FTC, often early in a policy process, for whatever input the commission may wish to offer. The decision making, however, is done by persons in the executive branch, notably the Executive Office of the President and cabinet agencies such as the Department of Commerce. There are important and long-standing reasons for this separation between independent and executive agencies—the separation avoids the appearance of political pressure on independent agencies. Separation is especially important for enforcement decisions—the FTC has true independence on what enforcement actions it brings, but the corollary is that the FTC is not “inside” the administration when it comes to creating administration policy. A variety of rules exist to limit the interaction of independent agencies and the executive branch; new White House officials, for instance, are briefed by counsel to exercise great caution in their interaction with independent agencies.
As an example of the constructive role in clearance played by the Department of Commerce, consider testimony in 2010 on the controversial question of whether and how to amend the Electronic Communication Privacy Act of 1986. ECPA is an important law for law enforcement—it sets forth the standards by which police and prosecutors can get access to emails and other electronic communications. ECPA, though, is also an important law about corporations and personal privacy. For corporations, ECPA sets the rules for what sorts of access to corporate databases should be permitted, under what circumstances and at what cost. For individuals whose records may be seen by law enforcement, ECPA creates the rules of the road for privacy protection, especially in our modern world when many records are stored in the “cloud” and thus at least potentially accessible to law enforcement.
ECPA thus provides one example of how multiple, compelling values can come into play in clearing the administration’s testimony to Congress. On September 22, 2010, both James Baker of the Department of Justice and Cameron Kerry of the Commerce Department testified before the Senate Judiciary Committee. Under the clearance rules, the testimony of both witnesses had to be shared in advance with the other, and the administration had to develop a common position. In my experience, sharing a draft document with an agency with a sharply different perspective is often extremely valuable—assumptions held in the initial agency get challenged, overstatements are modified, and the number of mistakes is reduced. Although I have no direct knowledge of the clearance process in this instance,[3] I think it quite possible that the presence of the Department of Commerce in the process helped create a more nuanced and privacy-protective administration position.
The ability of an independent agency such as the FTC to have a similar role in clearance is sharply limited. Based on my own experience, and on background discussions with people at the FTC, the FTC is not staffed well enough or situated close enough to the “inside” to engage on the day-to-day clearance of documents on the many law enforcement issues affecting commerce and privacy, including ECPA, the Communications Assistance to Law Enforcement Act, rules about encryption controls, and so forth.
From my time as chief counselor for privacy, the number of privacy issues addressed by federal agencies is far greater than realized by most people who have worked primarily on privacy with the FTC. I offer a list here as an illustration of the sorts of privacy issues that can arise in each of the cabinet departments. For many of the agency activities, there are important implications for commerce, providing a natural role for the Department of Commerce on commercial privacy issues. For others, the link to commerce is less direct, but a broad-based experience with privacy issues at the Department of Commerce will facilitate development of a sound administration position on privacy:
· Department of Agriculture. Migrant worker records
· Department of Defense and Veterans Affairs. Records of service members
· Department of Education. Education records, including for for-profit institutions
· Department of Energy. Smart grid
· Department of Health and Human Services. Medical records; many forms of human services records
· Department of Homeland Security. Numerous issues, including transportation safety and immigration
· Department of Housing and Urban Development. Public housing records
· Department of Interior. National park reservations and other services provided online
· Department of Justice. Numerous issues
· Department of Labor. Records of union membership
· Department of State. International privacy issues
· Department of Transportation. Smart roads
· Department of Treasury. Financial privacy; money laundering
Along with clearance, another role for the executive branch is to develop and announce the administration position in international settings. The green paper discusses the office’s role in international privacy activities, but is worth explaining a bit how this would complement any international activities by the FTC.
The FTC plays at least three roles on international privacy issues. First, the FTC is the designated enforcement agency for complaints under the U.S.-E.U. Safe Harbor. Second, the FTC’s overall privacy expertise and convening functions inform international discussions about privacy issues, and there has been international cooperation on enforcement actions. Third, last year the FTC for the first time received full member status in the closed session of data protection authorities at the International Conference of Data Protection and Privacy Commissioners. Executive branch officials continue to attend the closed session, as they have since 1999, but with “observer” status.
These important FTC international activities, however, do not replace the need for the executive branch to have policy capability about privacy. For instance, privacy and e-commerce issues arise in a wide range of bilateral and multilateral trade negotiations—because transborder data flows are such an important part of modern commerce, data-related issues can arise as one piece of many larger trade negotiations, which often involve the International Trade Administration of the Department of Commerce. Some multilateral fora persistently address privacy issues, such as the Asia-Pacific Economic Cooperation and the Organization for International Cooperation and Development. The U.S. delegations for these activities are led by the executive branch, with representation from the Commerce and State Departments.
More generally, the clearance process applies to developing and implementing the position of the United States in international negotiations. The FTC as an independent agency would have no basis for making representations, for instance, about what any executive branch agency would accept, including for law enforcement, homeland security, and non-privacy commercial issues. There is thus a sound basis for the green paper’s recommendation that the office “would work in concert with the Executive Office of the President as the Administration’s lead on international outreach for commercial data privacy policy.”
Whether privacy policy should be centered in the Commerce Department or the executive office of the president
I believe there is an extremely strong case in favor of developing an ongoing privacy policy capability in the executive branch. Privacy policy requires familiarity with a complex set of legal, technological, market, and consumer considerations. Good government thus calls for creating an institutional memory and a group of civil servants experienced in privacy policy. This privacy policy capability goes well beyond the need for federal agencies to comply with the Privacy Act and implement good practices for the personal information they hold.
Where to locate this privacy policy capability is less clear. In a 1998 book, Robert Litan and I discussed the question in detail, and concluded that a privacy policy office should be created in the Department of Commerce.[4] From 1999 until early 2001, by contrast, I served in the role of chief counselor for privacy in the U.S. Office of Management and Budget, and I have written reasons for supporting that approach as well.
The chief advantages and disadvantages are mirror images of each other. Placing the office in the Commerce Department allows for substantially greater staffing, increasing the chance that institutional expertise will accumulate through the ups and downs of public attention to privacy protection. The Commerce Department, however, will be only one of the various agencies that may have views on a particular privacy issue, increasing the risk that privacy will lose out in clearance. On the other hand, placing the policy leadership in OMB or elsewhere in the Executive Office of the President likely improves the possibility of effective coordination of privacy policy across the various agencies. Staffing, however, is always tight at the White House. The chief counselor for privacy, at most, had two full-time staff and one detailee from the Commerce Department.
One model worth considering is the position that Howard Schmidt now fills as cybersecurity coordinator. Mr. Schmidt is part of the national security staff, and also coordinates with the National Economic Council. My understanding is that a significant amount of support for the cybersecurity coordinator is provided by various agencies rather than directly by staff of the Executive Office of the President. A hybrid approach of this sort might achieve more effective privacy policy coordination while also retaining ongoing staffing.
This sort of role might also usefully integrate with the Privacy and Civil Liberties Oversight Board, for which President Obama recently nominated James Dempsey and Elizabeth Collins Cook. That board, to be effective, should have professional staff to carry out its task of working on privacy and civil liberties issues that affect anti-terrorist activities. As shown by the example of the Electronic Communications Privacy Act, anti-terrorist and law enforcement activities often have intricate interconnections with the commercial actors that own and operate most of the infrastructure for processing personal information. It quite possibly makes sense to permit dual tasking of personnel assigned to the board to work on privacy issues that concern commercial privacy. If this were done, an Executive Office of the President role for a privacy coordinator could be supported both by commercial privacy experts and persons assigned to the oversight board.
In short, various institutional choices might succeed for institutionalizing privacy policy in the executive branch. The privacy policy capability prior to 2009, and it is a good sign that the Department of Commerce green paper is reinvigorating the debate about how best to protect privacy policy while achieving other important goals.
Conclusion
In conclusion, the comments here show important tasks for a Privacy Policy Office in the executive branch, which would complement the FTC’s ongoing privacy activities. Notably, such an office would improve interagency clearance, and be important in developing and stating the position of the United States government in international settings. Based on my own discussions with people at the FTC, the FTC does not have the budget or institutional structure to attempt to participate in all of the issues touching on commercial privacy throughout the federal government.
Because these functions complement the existing activities of the FTC, the general effect of such an office would be to improve privacy policy expertise and capabilities, contrary to the concerns expressed by some privacy advocates that such an office would undermine privacy protections. In addition to the advantages described above, executive branch participation in development of industry codes of conduct permits expert input from a range of federal agencies and also brings those agencies up to speed on evolving technology. Another advantage is that an executive branch privacy capability can lend force to privacy legislative or other initiatives—when both the FTC and the administration work together on an issue, the combined effect is likely to be greater than when an independent agency such as the FTC acts alone. Because the administration is likely to be asked to provide its views on important legislation in any event, the existence of an ongoing privacy office in the executive branch will lead to better-informed privacy policy decisions by the administration.
The existence of such an office would also provide a more effective structure for the administration to weigh privacy concerns with other competing policy goals and values. The hope, which I believe is supported by experience, is that participation by privacy experts in executive branch decisions increases the likelihood of win-win situations, in which privacy goals are better achieved and other goals as well.
In short, the Department of Commerce deserves praise for advancing the idea of an ongoing Privacy Policy Office as part of its green paper.
Download this memo (pdf)
Download the memo to mobile devices and e-readers from Scribd
Peter Swire is the C. William O’Neill Professor of Law at the Moritz College of Law of the Ohio State University, and a Senior Fellow at the Center of American Progress. From 1999 through early 2001 he served as Chief Counselor for Privacy in the U.S. Office of Management and Budget. From 2009 through August, 2010 he served as Special Assistant to the President for Economic Policy, including on privacy and related technology issues.
Endnotes
[1] One reason may be the untimely death in 2003 of Barbara Wellbery, who worked tirelessly to address the issues of U.S. and E.U. relations in connection with the European Union Data Protection Directive and was instrumental to creation of the Safe Harbor privacy program that is now administered by the Department of Commerce.
[2] The conference invitation pushed me to write “Markets, Self-regulation, and Government Enforcement in the Protection of Personal Information,” my first article specifically on privacy issues.
[3] I served in the National Economic Council until August 2010, before the September 2010 testimony described in the text.
[4] Peter P. Swire and Robert E. Litan, None of Your Business: World Data Flows, Electronic Commerce, and the European Privacy Directive (Brookings, 1998), at 179-188.
To speak with our experts on this topic, please contact:
Print: Megan Smith (health care, education, economic policy)
202.741.6346 or msmith@americanprogress.org
Print: Anna Soellner (foreign policy and security, energy)asoellner@americanprogress.org
Print: Raúl Arce-Contreras (ethnic media, immigration)
202.478.5318 or rarcecontreras@americanprogress.org
Radio: Anne Shoup
202.481.7146 or ashoup@americanprogress.org
TV: Andrea Purse
202.741.6250 or apurse@americanprogress.org
Web: Erin Lindsay
202.741.6397 or elindsay@americanprogress.org
Following a forum on the Obama Administration’s efforts to enhance online security and privacy with U.S. Secretary of Commerce Gary Locke, White House Cybersecurity Coordinator Howard A. Schmidt, and Silicon Valley business and academic leaders at Stanford University on Friday, Jan. 7, a new website is now available with further information on the administration’s forthcoming National Strategy for Trusted Identities in Cyberspace (NSTIC).
NSTIC aims to help establish voluntary identity solutions and privacy-enhancing technologies that will improve the security and convenience of sensitive online transactions through the process of authenticating individuals, organizations, and underlying infrastructure - such as routers and servers. The Strategy was developed with substantial input from the private sector and the public. It calls for the effort to be led by the private sector, in partnership with the federal government, consumer advocacy organizations, privacy experts, and others.
Hosted at the Stanford Institute for Economic Policy Research (SIEPR) and co-sponsored by TechAmerica, TechNet, the Churchill Club, and the Team for Research in Ubiquitous Secure Technology (TRUST), Friday’s event also featured a panel discussion with industry and privacy experts on the current and future real world applications of trusted identities. Patrick Gallagher, Under Secretary of Commerce for Standards and Technology, and Director of the National Institute of Standards and Technology moderated the panel.
Learn more about NSTIC and see a webcast of the event at: http://www.nist.gov/nstic.
By Simson Garfinkel Technology Review Wednesday, January 5, 2011
And new security measures protect everyone's data.
Although it's not apparent to many, Facebook is in the process of transforming itself from the world's most popular social-media website into a critical part of the Internet's identity infrastructure. If it succeeds, Facebook and Facebook accounts will become an even bigger target for hackers.
As security professionals debate whether the Internet needs an "identity layer"—a uniform protocol for authenticating users' identities—a growing number of websites are voting with their code, adopting "Facebook Connect" as a way for anyone with a Facebook account to log into the site at the click of a button.
Facebook introduced Connect back in July 2008, offering third-party websites tools to coordinate with the user information that Facebook holds, including logins. Thus websites had the option of allowing Facebook users to identify themselves with their Facebook identities.
So, for instance, the Web statistics vendor Alexa gives new users the choice of creating an account by entering a username and a password or by simply clicking the "Connect with Facebook" button. Well-known websites that also use Connect include the Internet Movie Database, Ask.com, and ESPN. Others will almost certainly jump on the bandwagon in 2011.
Facebook's identity system might very well supply something that VeriSign, Microsoft, Yahoo, and Google have all struggled to offer: a single "driver's license" for the Internet. (This leaves aside the question of whether it's a good thing for one company to hold such a position of power.)
A unique combination of factors makes Facebook well suited to being the repository for people's identities on the Internet. Unlike many popular websites, it requires users to register and log in. And Facebook's terms of service require that "users provide their real names and information"—indeed, Facebook has terminated accounts that were created with seemingly fake names or for fictional characters. Since Facebook users invest their accounts with a tremendous amount of durable personal content—including photographs, contact information, and connections to their social network—they are likely to keep a long-term relationship with the site.
This persistence of real identity puts Facebook in a position to solve one of the most pressing problems on the Internet today—the proliferation of user names and passwords.
Contrary to today's practice, there is no reason for most websites to force their users to create usernames and passwords. Most websites don't need or even want or need to manage the identities of their users—they simply want a way to reliably identify their users over time. Media websites, for instance, want to be able to attribute comments and limit spam. Personal-finance websites want to give users a way to monitor highly personal information securely—for example, a portfolio of stocks that the user might enter.
What's more, maintaining a user-identity infrastructure has its risks—as was made painfully clear last month when hackers broke into servers operated by Gawker Media and downloaded the user names and passwords for more than a million of Gawker's accounts. Even though the passwords were encrypted, many were easy to guess, so the accounts could be readily cracked, according to an analysis of the attack by security researchers at the University of Cambridge. Following the attack several unrelated websites, including LinkedIn and Woot, sent e-mail to their users warning them to change their passwords if these were the same ones as they used for Gawker.
Facebook Login lets any website on the planet use its identity infrastructure—and underlying security safeguards. It's easy to implement Facebook Login, simply by adding few lines of code to a web server. Once that change is made, the site's users will see a "Connect with Facebook" button. If they're already logged into Facebook (having recently visited the site), they can just click on it and they're in. If they haven't logged in recently, they are prompted for their Facebook user name and password.
An interesting side benefit for website operators is that Facebook Login provides the site with users' real names (in most cases) and optionallya variety of other information, such as the users' "friends" and "likes." Currently, Facebook doesn't charge websites to use its identity infrastructure or access this additional information, though Facebook certainly could in the future.
Facebook is already well acquainted with Internet security issues, simply because it holds personal data for more than 500 million people. The increased use of the Facebook platform for things beyond social media—a bank in New Zealand, for instance, announced in November that it would allow customers to access banking information on Facebook—obviously raises new concerns. And if the company extends its reach to offer a universal login on the Web, the challenges it's likely to face will become greater still.
Excerpted from Facebook Wants to Supply Your Internet Driver's License - Technology Review
http://www.technologyreview.com/web/27027/?ref=rss&a=f
--------------------------------------------------
Stefaan G. Verhulst
Chief of Research
Markle Foundation
10 Rockefeller Plaza, Floor 16
New York, NY 10020-1903
Tel. 212 713 7630
Cell 646 573 1361
http://www.markle.org
Based on current advice, HHS rule-makers can have their pick of three possible paths to take on patient privacy and consent.
One path was laid out this month by the Federal Trade Commission in a report on privacy involving commercial personal health record systems. The FTC calls for a standard of protection that defines privacy as consent.
In drafting its recommendations, the FTC looked at the Fair Information Practices Principles, or FIPPs, developed by the Department of Health Education and Welfare in 1973. One of the five FIPPs says: “There must be a way for an individual to prevent information about him that was obtained for one purpose from being used or made available for other purposes without his consent.”
The FIPPs have been one of America's most welcome exports, forming the basis for privacy policies (PDF) in Canada and Europe.
A similar path was cleared for HHS by the Commerce Department in its report on commercial data privacy released Thursday. It called for a privacy policy relying on self-regulation and voluntary compliance by “stakeholders” such as the Direct Marketing Association, Network Advertising Initiative, Financial Services Forum, Intel, Google and Microsoft. The Commerce Department suggests these guidelines might be based on “revitalized” FIPPs that would “emphasize substantive privacy protection rather than simply creating procedural hurdles.”
And the department recommended these self-regulators “promote informed consent.”
Finally, last week, the President's Council of Advisors on Science and Technology said data-tagging technology should be used to enable patients' consent and control over their information.
All three bodies recommended personal control and consent. But if HHS decides to follow their advice, it will have to do some backtracking.
That's because in 2002, HHS rule-makers scrapped a patient's right of consent that had been part of an earlier privacy rule. They replaced consent with “regulatory permission” for the movement of a patient's medical records without consent for a vast array of uses. HHS has been stumbling over its pro-privacy rhetoric ever since.
In late 2008, after badgering by the General Accountability Office, HHS released its National Privacy and Security Framework. The document cited as one of its authorities—you guessed it—FIPPs.
Yet the HHS framework never mentions consent and goes on to define privacy, not as a right, but merely a patient's “interest” in controlling the disclosure of his healthcare information.
A workgroup of the federally chartered Health Information Technology Policy Committee has been drawing fire from industry quarters for having the temerity to try to re-introduce the concept of patient consent—albeit in a very limited form—in its recommendations to the government.
First the Federation of American Hospitals and then Kevin Nicholson, the vice president of government affairs for the National Association of Chain Drug Stores, expressed displeasure at the tiger team's direction.
HHS rule-makers soon have to update the language on enforcement, breach notification and the final updates to the HIPAA privacy rule in the American Recovery and Reinvestment Act of 2009.
Which path will they take?
http://www.modernhealthcare.com/blogs/it-everything/20101217/312179999
--------------------------------------------------
Stefaan G. Verhulst
Chief of Research
Markle Foundation
10 Rockefeller Plaza, Floor 16
New York, NY 10020-1903
Tel. 212 713 7630
Cell 646 573 1361
http://www.markle.org
By NATASHA SINGER NY Times December 11, 2010
HOW far does consumer privacy protection lag behind data-collection systems, those advanced technologies that media companies use to gather, share and profit from our personal information?
Too far, according to two privacy advocates.
“Solitude and privacy have become more essential to the individual; but modern enterprise and invention have, through invasions upon his privacy, subjected him to mental pain and distress,” the privacy experts wrote in the Harvard Law Review. “In this, as in other branches of commerce, the supply creates demand,” they added; and that demand, they noted, ends up broadcasting our private matters in public spheres.
Sound familiar?
The review article, written in 1890 by the young lawyers Samuel D. Warren and Louis D. Brandeis, concerned the spread of that era’s viral technology: snapshot photography. Newspaper photographers, the lawyers wrote, were feeding an “unseemly gossip” industry by taking and publishing candid shots of people without their consent.
Before the advent of the camera, explains Jon Leibowitz, the chairman of the Federal Trade Commission, newspaper photographers would have had difficulty carting heavy daguerreotype equipment and using it to peer over people’s back garden fences.
“But once you went to a real camera,” Mr. Leibowitz said in an interview last week, “that could easily be done.”
As the adage goes: Everything old is new again.
On the one hand, consumers often benefit from newfangled gizmos — be they cameras, tape recorders or cellphones. On the other hand, the widespread adoption of technology has often left legislators and regulators racing to play catch up.
The F.T.C., for instance, just published a report in which agency experts concluded that data-collection techniques on the Web had outdistanced user privacy control. So it was only natural that Mr. Leibowitz looked to tradition and invoked the 19th-century law review article, which essentially laid the legal foundations for protecting Americans’ privacy rights.
(My colleagues Tanzina Vega, Edward Wyatt and Verne Kopytoff have written in depth this month about the F.T.C. report, its proposed framework for increasing consumers’ privacy choices and its implications for the online marketing industry).
Mr. Warren and Mr. Brandeis wrote, for example, that privacy, an intangible right, was as important as more tangible common law rights, like the ownership of private property. People have the right, they wrote, to control dissemination of their personal thoughts or images. People also have “the right to be let alone.”
In a similar fashion, the F.T.C.’s report recommends that Internet and mobile app users receive better control over who sees, collects and shares information about their electronic behavior — like, say, the Web sites they peruse or the terms they plug into search engines. Indeed, the commission proposed a “do not track” mechanism that would allow consumers to opt out of “behavioral advertising,” the kind of marketing that tailors ads to a consumer’s personal track record.
This is not the first time since snapshot photography that new technology has inspired legal experts to rethink privacy protections.
“The laws haven’t really kept pace with the unbelievable developments,” says Jessica Rich, deputy director of the trade commission’s bureau on consumer protection.
As an example, Ms. Rich cited the 1960s, when deeper credit reporting allowed companies to use advanced database technology to collect consumers’ financial information. Once legislators began to understand how such databases could affect people’s ability to obtain mortgages, housing and even jobs, she said, Congress enacted the Fair Credit Reporting Act. The 1970 law allowed consumers to retrieve and correct credit information about themselves.
Indeed, privacy regulation is often reactive, says William McGeveran, a privacy scholar at the University of Minnesota Law School.
Take the Video Privacy Protection Act, enacted by Congress in 1988, after a local newspaper in Washington obtained and published the video rental records of Robert Bork, a Supreme Court nominee. The so-called Bork law, one of the country’s strongest privacy statutes, prohibits the disclosure of personally identifiable rental information without consumer consent.
“One of the comical attributes of privacy regulation is — a lot of it is responsive to fire alarms,” says Professor McGeveran.
Indeed, over time Congress has increased privacy regulation in different industries, he says. There’s the Health Insurance Portability and Accountability Act, for one, that in 1996 established certain federal protections for personal health information. And the Gramm-Leach-Bliley Act of 1999, which required financial service companies to notify customers about their information policies and allow them to opt out from having their data shared with unaffiliated parties.
“Maybe now it’s online privacy’s turn to have more of a direct regulatory intervention,” Professor McGeveran says.
The trade commission’s report proposes new industry practices to enhance online privacy choices for consumers. For those to take effect, however, either the interactive advertising industry would have to increase self-regulation or Congress would have to enact a law enabling the commission to enforce new rules.
Some industry groups are already stepping up transparency.
In October, the Digital Advertising Alliance, a coalition of trade groups, introduced an “advertising option icon”— a logo that Web sites can display to indicate that they collect consumer data and that they allow people to opt out of behavioral advertising. Next month, some data collection firms in that coalition are introducing the Open Data Partnership, a program that will allow consumers to edit their information profiles on certain sites or opt out of being tracked by participating companies.
But Christopher Soghoian, a privacy researcher and graduate student at Indiana University, says most Web sites don’t allow consumers to opt out of tracking.
Companies “promise they won’t use the data they collect for the purpose of picking the individual ads they are showing you,” he says, “but they don’t actually offer to stop collecting data about you.”
AND there’s another potential problem, Mr. Soghoian says.
Web sites often deposit cookies on consumers’ computers to track online preferences and activities. The F.T.C.’s recommendation for an opt-out mechanism would play on that idea with a privacy cookie, encoded in people’s browsers, that would alert advertising networks to users’ privacy choices.
But a few smaller companies have already moved beyond cookies, Mr. Soghoian says, with a technique called “device fingerprinting.” That advanced technology can follow online behavior — not by using cookies but by tracking signals that are specific to a person’s individual laptop or mobile device.
“That’s not something you can opt out of,” Mr. Soghoian says. “There’s no way to delete my fingerprint because there’s no way for me to delete my phone or my computer.”
Once again, technology forges ahead. Not much has changed since 1890.
Excerpted from Online Privacy Races Against Technology - NYTimes.com
http://www.nytimes.com/2010/12/12/business/12stream.html?_r=2&src=busln&pagewanted=print
Readability — An Arc90 Laboratory Experiment http://lab.arc90.com/experiments/readability
Follow us on Twitter »Readability version 1.7.1
An Office of Personnel Management plan to launch a comprehensive database of federal workers' health care records has raised the ire of some privacy advocates, employee unions and consumer groups.
OPM is organizing a research database of insurance claims filed by the eight million workers and dependents enrolled in the Federal Employees Health Benefits Program, as well as participants in two other federally administered programs. The claims data, which will be supplied by the private insurers that participate in the FEHBP, will help OPM figure out ways to lower costs, improve quality and fight fraud, the agency has said.
But critics - which include the American Civil Liberties Union, Consumers Union and the American Federation of Government Employees - argue that the government should avoid setting up a repository of sensitive information that could be vulnerable to privacy breaches. At minimum, they say, OPM should provide more information about how the database, called the Health Claims Data Warehouse, will work and who will have access to it.
"We're talking about a government database with health diagnoses, payment information, and procedures," said Harley Geiger, policy counsel at the Center for Democracy and Technology, a public interest firm based in Washington. "Enrollees are almost certainly unaware that the government plans to compile all that into one big federal database."
OPM has asserted that it has "a strong track record" of protecting the privacy of sensitive employee information. It also extended, until Dec. 15, the comment period for the project, and said it's considering putting out "a more detailed explanation of how the records in this system will be protected and secured."
The database, approved as part of the new health care law, will collect health-services data from about 230 private health plan options offered to federal workers through the FEHBP.
Information also will be compiled from enrollees in two other programs created by the health law. One involves the high-risk pools set up by the Department of Health and Human Services for people who can't get insurance because of medical problems. The other involves private "multi-state plan options" for individuals and small businesses. These plans, to be administered by OPM, will be available on state-based exchanges beginning in 2014. The database will be the largest government aggregation of private health plan data compiled in the United States, analysts say.
Once the OPM database is functioning, the agency plans to gather monthly updates on everything from medical diagnoses to surgical procedures to prescription-drug use. In theory, the database will allow OPM to scrutinize a specific group of enrollees - those with diabetes, for example - to identify the most effective treatments.
The data, according to an Oct. 5 Federal Register notice by OPM, will be used by agency analysts as well as some other federal agencies, to discern costs and trends. Certain outside researchers also could get access to the material, almost always in an aggregated form, according to a senior OPM official involved in the project who asked not to be named given that the details for the database remain under review.
Researchers say the database could be helpful if constructed and used properly; it could, for example, lead to wider adoption of "best practices" as well as lower costs, said Kevin O'Brien, a director of the California-based data analytics firm Berkeley Research Group.
Even modest cost reductions could produce substantial savings for the government and workers. OPM Director John Berry, in a report on the agency's 2009 performance, said reducing annual premium growth by 0.1 percent for three consecutive years would save the FEHBP $1.25 billion over 10 years. The agency, on average, picks up 70 percent of the cost of premiums; workers pay the rest.
But privacy advocates aren't assuaged. They note that the data collected by OPM will include names, birthdates and other personal identifying information. In addition, they say it's unnecessary for OPM to set up its own database, since insurers already store health information.
"One of the big concerns here is the duplication," said Chris Calabrese, legislative counsel to the ACLU. Calabrese would rather see OPM use a "pointer system" to locate the information it needs. "Instead of having all the information in one database, if you want info on Patient 'X' … go directly to the record source," he said.
OPM officials counter that the privacy concerns are overblown. The senior OPM official said researchers won't be permitted to see personal identifiers. The agency had said earlier that the health data could be subject to the "routine uses" that apply to most federal databases under the Privacy Act of 1974. That means the records could be pulled by law enforcement officials in a criminal investigation or used in a congressional inquiry. Now, the official said, the agency is considering narrowing the list of agencies that would be granted special access to its records.
Within OPM, the data will only be made available to analysts with the proper clearances, the official said.
In addition, the OPM official said asking insurance companies to independently analyze their own data would defeat a key purpose of the database - which is to compare health plans. For example, one health plan might charge more than another for prescription drug programs and the data might help OPM decide whether to drop one pharmacy benefits manager in favor of another. About 30 percent of FEHBP's spending goes for prescription drugs.
OPM's plans aren't unprecedented - TRICARE, the military's health care program, has data on its participants, and the federal Centers for Medicare and Medicaid Services keeps information on Medicare beneficiaries. But TRICARE, Medicare and Medicaid are public health programs; OPM's database will be collecting health information from private plans. The California Public Employees' Retirement System maintains a database on the private health plans it manages. OPM's project would be similar.
http://www.blogger.com/post-edit.g?blogID=6967655473927968040&postID=7430133686595109772
Kaiser Health News (www.kaiserhealthnews.org) is an editorially independent news service of the Kaiser Family Foundation, a nonpartisan health care policy organization that isn't affiliated with Kaiser Permanente.
12.01.2010
The U.S. Federal Trade Commission has released its long-anticipated staff report on consumer privacy. The report, “Protecting Consumer Privacy in an Era of Rapid Change: A Proposed Framework for Businesses and Policymakers,” is the culmination of the FTC’s “privacy rethink” project and includes preliminary recommendations.
"The report appears to address the key themes that [the commission] previously had indicated would be covered,” said Hunton & Williams partner Lisa Sotto. “Industry leaders undoubtedly will pay close attention to the FTC's pronouncements.”
One of the major themes of the 122-page report is the need to reduce the burden on consumers by simplifying choice, embracing privacy-by-design principles and making privacy policies more consistent across the board.
“We need to greatly simplify consumer choice,” FTC consumer protection director David Vladeck said while previewing the report at a Consumer Watchdog event in Washington, DC, this morning.
Morrison & Foerster partner D. Reed Freeman, CIPP, commented on the breadth of the report, noting that it applies to online and offline data and encourages companies to adopt the full panoply of Fair Information Practice Principles, among other proposals. Freeman says it will be important to determine to what extent the report’s recommendations are enforceable by Section 5 of the FTC Act.
Freeman also noted that the commission left open the issue of whether, when and under what circumstances consent should be opt in or opt out, as well as whether or when opt in would be appropriate for practices involving sensitive data.
There has been much speculation about the commission’s position on the viability of a do-not-track mechanism, designed to let consumers opt out of having their browsing activities monitored. In its report, the FTC supports the idea of such a system, but does not propose to develop or implement one of its own.
"The most practical method of providing such universal choice would likely involve the placement of a persistent setting, similar to a cookie, on the consumer's browser signaling the consumer's choices about being tracked and receiving targeted ads," the report says. "Commission staff supports this approach, sometimes referred to as 'Do Not Track.'"
In this regard, “The commission…wisely left the door open to either legislative or self-regulatory solutions,” said Jules Polonetsky, CIPP, co-chair of the Future of Privacy Forum. “The industry should act quickly to explore and implement a do-not-track mechanism that both supports responsible advertising practices and enhances consumer controls and choices.”
On a call with members of the media this afternoon, FTC Chairman Jon Leibowitz addressed whether, given the scope of the report, the FTC is moving towards a definition of “consumer” data rather than “personal” data and whether this is a broadening of the FTC’s overall approach to consumer privacy. Leibowitz said that the commission’s approach today is in some ways consistent with what it has done in previous decades, but personal data can be synthesized differently today. “You can take information that’s not technically a Social Security number or name” and find out who that person is. “We’re not looking for more authority,” Leibowitz said. “This is only advice to businesses and advice to consumers.”
The staff report also addresses increased transparency and outlines the commission’s desire for better privacy policies and systems to enhance notice and choice and outlines the commission’s hopes to improve “consumers’ ability to compare data practices across companies, thereby encouraging competition on privacy issues,” and it calls for strong protections surrounding sensitive information such as healthcare and financial data, children’s information and geo-location data. The commission is exploring what other areas might need to be treated as sensitive.
At the morning forum, Vladeck provided an indication of how the FTC will deal with the disregard of consumers’ privacy wishes.
“Consumer choices, once exercised, must be respected,” Vladeck said, adding that the commission “will not tolerate a technological arms race” aimed at subverting those choices.
The FTC will accept comments on its proposals through January 31, 2011. The report includes a number of specific questions in areas where the commission seeks feedback.
--------------------------------------------------
Stefaan G. Verhulst
Chief of Research
Markle Foundation
10 Rockefeller Plaza, Floor 16
New York, NY 10020-1903
Tel. 212 713 7630
Cell 646 573 1361
http://www.markle.org