Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Monday, February 4, 2013

New Article: Privacy, Transparency and Google's Blurred Glass


I have just posted a new short article, Privacy, Transparency and Google's Blurred Glass, which looks at Google's privacy disclosures and how they may fall short of being as transparent as Google (and many others) would wish. The piece can be downloaded (as a PDF) from this link. Comments and questions are always welcome.

Thursday, January 24, 2013

The Other Google Search: 8438 Data Requests by U.S. Gov't


Google has released the latest version of its Transparency Report, covering the period from July 1 through December 31, 2012. In the report, Google states that the U.S. government made 8,438 requests of user data from Google during the period, covering a reported 14,791 users/accounts, and that Google responded fully or partially to an aggregate of 88% of those requests, broken down as follows:

July to December 2012

Records Requested

Users/Accounts

Percentage Fully/Partially Complied With

Search Warrant

1,896

3,152

88%

Subpoena

5,784

10,390

88%

Other 

758

1,249

90%

The number of of these requests, particularly from the U.S. government, has been steadily increasing over the past few years; the U.S. government made only 3,580 total requests in the same period in 2009. Google states in the introduction to its report, "We review each request to make sure that it complies with both the spirit and the letter of the law, and we may refuse to produce information or try to narrow the request in some cases." It also attributes some of the increase to its own growth: "Usage of our services have increased every year, and so have the user data request numbers."

While Google is to be commended for its efforts to disclose (some of) the requests for information it receives, the report and the increases it shows serve as a reminder of the size, scope and value of Google's collection of data about its users. Given how many products Google owns, many of which may not bear obvious Google branding (such as the Zagat Restaurant Guide) but may still be feeding user data into Google's central servers (Zagat's privacy policy is the Google shared one, as is that of its fellow non-obvious Google acquisition, the Frommer's Travel Guides site), one may legitimately question whether all users are able to provide truly informed consent to Google's data collection, which is increasingly a governmental resource as well.

Thursday, January 3, 2013

FTC/Google Settlement: Covers Patents, Advertising; No Actionable Search Bias


The FTC has reached a proposed settlement with Google regarding multiple antitrust-related claims. The FTC's investigations covered issues including Google's control over key patents after its Motorola Mobility acquisition, Google's policies regarding cross-platform advertising campaign management, and allegations of so-called "search bias" through which Google was supposedly favoring its own content in its search results over competitors' pages.

With regard to search bias, the FTC found:
...that the evidence presented at this time does not support the allegation that Google’s display of its own vertical content at or near the top of its search results page was a product design change undertaken without a legitimate business justification. Rather, we conclude that Google’s display of its own content could plausibly be viewed as an improvement in the overall quality of Google’s search product. Similarly, we have not found sufficient evidence that Google manipulates its search algorithms to unfairly disadvantage vertical websites that compete with Google-owned vertical properties....
The FTC did, however, find some evidence that Google may have unfairly "scraped" competing Web sites' content for its own use and threatened to delist those that protested, and may further have placed "unreasonable restrictions" on advertisers' abilities to advertise on Google and competing search engines at the same time. Google agreed to refrain from both types of practices in the future.

Google additionally agreed to make certain changes in its patent and advertising practices. The FTC found that Google had blocked willing licensees of its patents from making deals on so-called fair, reasonable and non-discriminatory ("FRAND") terms, including through use of injunctions; in the settlement, Google agreed not to pursue such injunctions against those with whom Google had previously agreed to FRAND terms:


Google also agreed to alter elements of the contract terms covering the use of its AdWords API (application programming interface), which impeded advertisers' efforts to better manage and control their ad campaigns both within and beyond Google and its properties.

The FTC's proposed consent agreement with Google is subject to public comment through February 4th, 2013, in hard copy or online. The release (with links to the relevant documents, including dissents) may be found on the FTC's Web site.

Wednesday, December 12, 2012

Peter Fleischer, Other Google Execs Still May Face Jail in Italy Privacy Case

AP Image of trial court via KLEWTV.com
 In the latest installment in a case that highlights both the legal risks and absurdity of the cross-border nature of the Internet, the Milanese prosecutor in the case against Peter Fleischer and two other Google executives has asked an appeals court to uphold the six-month jail sentences they received in a criminal privacy case. The case arose out of a 2006 posting to Google Video by Italian teenagers of a short video of a learning-disabled classmate. Although none of the executives had any involvement with the posting or its prompt removal by Google Video after notification, they were still charged (along with another colleague, later acquitted) of violations of Italian privacy law. Fleischer, who was then Google's chief privacy counsel in Europe, was arrested when he traveled from his Paris office to Italy to give a lecture in January 2009. After the case came to trial, Fleischer and two of his colleagues (including Google's chief legal officer, David Drummond) were convicted in February 2010 and given six month sentences, automatically suspended under Italian law. The case was then appealed, leading to the latest development.

Fleischer, in a recent blog entry about the appeal, describes both the facts and the illogical nature of the case against him, given that he and his colleagues had nothing to do with the incident:

Under European law, hosting platforms that do not create content, such as Google Video, YouTube, Bebo, Facebook, and even university bulletin boards, are not legally responsible for the content that others upload onto these sites. But in this instance, a public prosecutor in Milan decided to charge us with criminal defamation and a failure to comply with the Italian privacy code.  None of us, however, had anything to do with this video. We did not appear in it, film it, upload it or review it. None of us knew the people involved or were even aware of the video's existence until after it was removed.
 This case, similar in many ways to the action in Germany against Compuserve's Felix Somm in 1996, serves as a stark reminder that those associated with companies doing business online may find themselves facing personal liability or even prosecution based on the laws of other countries, even when the individuals had no connection with the activity in question, and even when the activity was fully legal under the laws of the jurisdiction in which the company is based. While it is impossible to research and be certain of compliance with every relevant law in every possible country with access to the Internet, those who work for high-profile businesses, especially companies whose activities may potentially violate particular nations' cultural norms, should at the least be aware of these risks when considering business or personal travel to other regions. Companies, for their part, must include these risks in their overall assessments when choosing to do business online.

Wednesday, November 28, 2012

Mobile App Privacy: A Slowly Expanding Area

The area of consumer privacy is a broad area that has been discussed, analyzed and given guidance by both the Federal Trade Commission and the White House. Mobile application privacy, an important subset of consumer privacy, is an area of privacy that has been receiving significant attention over the past year as the importance of the mobile platform increases.

The push for protection in mobile app privacy most clearly began with a Joint Statement of Principles laid out by the California Attorney General, created in February 2012. The California Joint Principles represent an agreement by several top companies in the mobile industry. The agreement, which includes Apple, Google, Research In Motion, HP, and Microsoft (in addition to Facebook, which signed on in June), states what these companies promise to do in their mobile app store. The agreement reached by the major mobile companies provides that the California Online Privacy Protection Act is applicable to any application that collects personal data from a consumer. Such an app requires a “conspicuously posted” privacy policy. The agreement provides that when an app is submitted to a mobile app store by the developer there should be a hyperlink to the privacy policy or the actual privacy policy for that particular app. The privacy policy, whether a hyperlink or the full text, should be available in the mobile app store prior to download of the app. The major mobile companies must also provide a method for users to report apps that do not have such a policy or whose policy does not comply with applicable law.

In addition to the Joint Principles, the FTC has released a new Report on marketing mobile applications, in September of 2012, that contains suggestions on how to limit privacy concerns in a mobile app.  The FTC suggests that mobile app creators:

Build privacy considerations in from the start.  The FTC calls this “privacy by design.”… Incorporating privacy protections into your practices, limiting the information you collect, securely storing what you hold on to, and safely disposing of what you no longer need.  Apply these principles in selecting the default settings for your app and make the default settings consistent with what people would expect based on the kind of app you’re selling.  For any collection or sharing of information that’s not apparent, get users’ express agreement.  That way your customers aren’t unwittingly disclosing information they didn’t mean to share.
Be transparent about your data practices….Offer choices that are easy to find and easy to use…Honor your privacy promises…The FTC has taken action against dozens of companies that claimed to safeguard the privacy or security of users’ information, but didn’t live up to their promises in the day-to-day operation of their business.  The FTC also has taken action against businesses that made broad statements about their privacy practices, but then failed to disclose the extent to which they collected or shared information with others – like advertisers or other app developers…Protect kids’ privacy…
Collect sensitive information only with consent.  Even when you’re not dealing with kids’ information, it’s important to get users’ affirmative OK before you collect any sensitive data from them, like medical, financial, or precise geolocation information.  It’s a mistake to assume they won’t mind.
Keep user data secure...The wisest policy is to:
  •  collect only the data you need;
  • secure the data you keep by taking reasonable precautions against well-known security risks;
  • limit access to a need-to-know basis; and
  • safely dispose of data you no longer need.
As mobile app privacy is a new and growing area, the actual implications on businesses are not yet clear. The California Joint Statements only require that those mobile app store providers will provide a location for the individual app’s privacy policy. This only implicitly requires that mobile app creators should have a privacy policy. The FTC guidelines are less stringent. As stated in its report on consumer privacy, the FTC does not believe that they have the powers, at this time, to broadly regulate the area of privacy. However, the FTC suggestions show what the the Commission might enforce if given the power to do so by Congress.

(Written by Brett Alazraki, Fall 2012 IBLT Entrepreneurship Assistance Fellow)

Tuesday, November 27, 2012

Facebook “Hoax” Shows Privacy A Serious Matter for Users


In recent days, numerous Facebook users have posted a legal-sounding statement as an update to their pages containing some version of the following:

“In response to the new Facebook guidelines I hereby declare that my copyright is attached to all of my personal details, illustrations, comics, paintings, professional photos and videos, etc. (as a result of the Berner Convention). For any commercial use of the above my written consent is needed at all times! Anyone reading this can copy this text and paste it on their Facebook Wall. This will place you under protection of copyright laws. By the present communiqué, I notify Facebook that it is strictly forbidden to disclose, copy, distribute, disseminate, or take any other action against me on the basis of this profile and/or its contents.

The aforementioned prohibited actions also apply to employees, students, agents and/or any staff of Facebook or under their direction or control. The content of this profile is private and confidential information. A violation of my privacy is punishable by law (UCC 1 1-308-308 1-103 and the Rome Statute).

Facebook is now an open capital entity. All members are recommended to publish a notice like this, or if you prefer, you may copy and paste this version. If you do not publish a statement at least once, you will be tacitly allowing the use of elements such as your photos as well as the information contained in your profile status updates.”

This is not the first time Facebook users have felt the need to add a legal disclaimer to their statuses in an effort to protect their rights. A similar statement made the rounds a few months ago, with a greater focus on privacy:

Facebook is now a publicly traded entity. Unless you state otherwise, anyone can infringe on your right to privacy once you post to this site. It is recommended that you and other members post a similar notice as this, or you may copy and paste this version. If you do not post such a statement once, then you are indirectly allowing public use of items such as your photos and the information contained in your status updates.

PRIVACY NOTICE: Warning - any person and/or institution and/or Agent and/or Agency of any governmental structure including but not limited to the United States Federal Government also using or monitoring/using this website or any of its associated websites, you do NOT have my permission to utilize any of my profile information nor any of the content contained herein including, but not limited to my photos, and/or the comments made about my photos or any other "picture" art posted on my profile.

You are hereby notified that you are strictly prohibited from disclosing, copying, distributing, disseminating, or taking any other action against me with regard to this profile and the contents herein. The foregoing prohibitions also apply to your employee , agent , student or any personnel under your direction or control.

The contents of this profile are private and legally privileged and confidential information, and the violation of my personal privacy is punishable by law. UCC 1-103 1-308 ALL RIGHTS RESERVED WITHOUT PREJUDICE

These two statements have a few elements in common. First, there was no new policy (or change to a policy) at Facebook to trigger these notices. Next, even had there been such a policy, the notices themselves were ineffectual and inaccurate from a legal perspective (e.g. profile notices do not modify contracts; there is a Berne Convention regarding copyright but no “Berner Convention”; the U.C.C., or Uniform Commercial Code, is a state law regarding the sale of goods, having nothing to do with Facebook profiles or privacy). Additionally, both notices went viral very quickly, spreading to literally tens of thousands or more Facebook users, even as others posted rebuttals and links to sites such as Snopes.com and news sites covered and furthered debunk the warnings about “new Facebook guidelines.”

The main factor that these viral postings share, though, is the lesson that they can provide to Facebook and numerous other organizations: namely, that users care deeply about, and do whatever they think they can to ensure, their privacy. This is not a new idea, nor is this the first time a rumored (though inaccurate) threat to privacy generated vast consumer and even legislative response. In late 1996, e-mails spread warning about the supposed revelation by Lexis/Nexis of Social Security numbers and mothers’ maiden names (two important pieces of data that could be misused by identity thieves to steal account access) in its new P-Trak consumer information database. In reality, P-Trak had originally included Social Security numbers but had been quickly revised to allow only searching by such numbers if the searcher already knew them, and the database had never contained mothers’ maiden names. Nonetheless, consumers jammed Lexis/Nexis’ customer service lines demanding to be removed, and the incident sparked a letter from three senators to the FTC and a resulting FTC public workshop and report to Congress on privacy of social security numbers and other information.

The overall idea of consumers and other users being able to know and manage the information being collected about them has long been a significant part of privacy best practices. The FTC and numerous other bodies in the U.S. and throughout the world have promulgated some version of Fair Information Practice Principles (“FIPP”), which generally include sections on notice, choice and participation. More recently, in February 2012, the Obama Administration published a report entitled Consumer Data Privacy In A Networked World: A Framework For Protecting Privacy And Promoting Innovation In The Global Digital Economy, which included a Consumer Privacy Bill of Rights incorporating individual control, transparency, and access and accuracy among its elements. The whole concept of a Web site’s “privacy policy” is that it serves as a disclosure document, informing and empowering consumers with regard to the personal information collection and use by the site’s owner, and even absent general federal mandates for privacy policies in the United States, the vast majority of sites offer them, largely because consumers might otherwise suspect a site without a privacy policy of misusing their personal data.

Unfortunately, the theory of privacy policies and fair information practices does not always translate into reality. The double wave of Facebook viral postings, which were frequently made by those who weren’t either privacy advocates or lawyers, shows both that accurate information about Facebook’s practices was not being effectively communicated to its millions of users, and that users did not know how to find and use Facebook’s actual privacy controls. As confusing as Facebook’s controls may be, those of search/software/service giant Google are substantially more challenging, given how many different products Google offers, the numerous platforms on which they run, and the sheer volume of information being collected and used by Google.

If Facebook is paying attention to its users, it can do a huge service to them and the overall Internet community by taking this latest viral reaction to heart. Facebook should use this incident as a spark to substantially improve user access to and understanding of, its information collection practices. Other sites, including those many news sites that covered the story, should likewise reexamine and improve their own user privacy experiences. Otherwise, they may face not only unhappy and confused users, but regulatory and legislative actions that have a much more severe and longlasting impact on their businesses and their ability to properly (and transparently) use what they learn about their customers.