Showing posts with label Jonathan I. Ezor. Show all posts
Showing posts with label Jonathan I. Ezor. Show all posts

Wednesday, November 27, 2013

EU Calls for US to Restore Privacy Trust But Maintains Safe Harbor



On November 27th, 2013, the European Commission announced that it would not suspend the safe harbor agreement between the EU and the United States that has allowed cross-border personal data transfers between the two jurisdictions since 2000. The announcement followed the Edward Snowden revelations of U.S. surveillance activities, which prompted a number of public calls for suspension of the safe harbor by EU member states and statements by EU officials condemning the U.S.' reported practices.

In preserving (for now) the Safe Harbor, the EC nonetheless called for changes to U.S. governmental practices in order to "restore trust in EU-U.S. data flows." It released a Communication (strategy paper) on data flows between the regions, an analysis of how the Safe Harbor has functioned (and where it has failed), and other documents supporting its position. In the accompanying press release, the EC called for action in six key areas:

  • A swift adoption of the EU's data protection reform: the strong legislative framework, as proposed by the European Commission in January 2012 (IP/12/46), with clear rules that are enforceable also in situations when data is transferred and processed abroad is, more than ever, a necessity. The EU institutions should therefore continue working towards the adoption of the EU data protection reform by spring 2014, to make sure that personal data is effectively and comprehensively protected (see MEMO/13/923). 
  • Making Safe Harbour safer: the Commission today made 13 recommendations to improve the functioning of the Safe Harbour scheme, after an analysis also published today finds the functioning of the scheme deficient in several respects. Remedies should be identified by summer 2014. The Commission will then review the functioning of the scheme based on the implementation of these 13 recommendations. 
  • Strengthening data protection safeguards in the law enforcement area: the current negotiations on an “umbrella agreement” (IP/10/1661) for transfers and processing of data in the context of police and judicial cooperation should be concluded swiftly. An agreement must guarantee a high level of protection for citizens who should benefit from the same rights on both sides of the Atlantic. Notably, EU citizens not resident in the U.S. should benefit from judicial redress mechanisms. 
  • Using the existing Mutual Legal Assistance and Sectoral agreements to obtain data: The U.S. administration should commit to, as a general principle, making use of a legal framework like the mutual legal assistance and sectoral EU-U.S. Agreements such as the Passenger Name Records Agreement and Terrorist Financing Tracking Programme whenever transfers of data are required for law enforcement purposes. Asking the companies directly should only be possible under clearly defined, exceptional and judicially reviewable situations. 
  • Addressing European concerns in the on-going U.S. reform process: U.S. President Obama has announced a review of U.S. national security authorities’ activities. This process should also benefit EU citizens. The most important changes should be extending the safeguards available to US citizens to EU citizens not resident in the US, increased transparency and better oversight. 
  • Promoting privacy standards internationally: The U.S. should accede to the Council of Europe’s Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (“Convention 108”), as it acceded to the 2001 Convention on Cybercrime. 
The complete collection of the EC's materials accompanying the announcement may be found here.

Thursday, October 31, 2013

FAA Now Permits Use of Electronic Devices During Takeoff and Landing


The Federal Aviation Administration ("FAA") announced on October 31, 2013 that it would revise its rules regarding passenger use of personal electronic devices ("PEDs") during takeoffs and landings of commercial flights. According to the FAA's press release, the new rules would permit airlines to themselves determine whether or not to permit passengers to use PEDs, although the timing and details could vary among the airlines. These new rules, though, do not include permitting passenger use of the cellular radios in PEDs; these remain prohibited during all phases of flights.

The FAA's release included some guidance for passenger as well:

Top Things Passengers Should Know about Expanded Use of PEDs on Airplanes:
1. Make safety your first priority.
2. Changes to PED policies will not happen immediately and will vary by airline. Check with your airline to see if and when you can use your PED.
3. Current PED policies remain in effect until an airline completes a safety assessment, gets FAA approval, and changes its PED policy.
4. Cell phones may not be used for voice communications.
5. Devices must be used in airplane mode or with the cellular connection disabled. You may use the WiFi connection on your device if the plane has an installed WiFi system and the airline allows its use. You can also continue to use short-range Bluetooth accessories, like wireless keyboards.
6. Properly stow heavier devices under seats or in the overhead bins during takeoff and landing. These items could impede evacuation of an aircraft or may injure you or someone else in the event of turbulence or an accident.
7. During the safety briefing, put down electronic devices, books and newspapers and listen to the crewmember’s instructions.
8. It only takes a few minutes to secure items according to the crew’s instructions during takeoff and landing.
9. In some instances of low visibility – about one percent of flights – some landing systems may not be proved PED tolerant, so you may be asked to turn off your device.
10. Always follow crew instructions and immediately turn off your device if asked.
The complete set of PED materials is available on the FAA Web site.

Wednesday, October 30, 2013

Ezor on Secure Times: Recent FTC Actions and Statements Show Continuing Focus on Privacy

IBLT Director Jonathan I. Ezor is blogging this week at the American Bar Association Privacy & Security Law Committee's Secure Times blog. His first contribution is below:

Recent FTC Actions and Statements Show Continuing Focus on Privacy

The Federal Trade Commission has long taken a lead role in issues of privacy and data protection, under its general consumer protection jurisdiction under Section 5 of the FTC Act (15 U.S.C. §45) as well as specific legislation such as the Children's Online Privacy Protection Act of 1998 ("COPPA") (which itself arose out of FTC reports). The FTC continues to bring legal actions against companies it believes have improperly collected, used or shared consumer personal information, including the recent settlement of a complaint filed against Aaron's, Inc., a national rent-to-own retail chain based in Atlanta, GA. In its October 22, 2013 press release announcing the settlement, the FTC described Aaron's alleged violations of Section 5:
Aaron’s, Inc., a national, Atlanta-based rent-to-own retailer, has agreed to settle FTC charges that it knowingly played a direct and vital role in its franchisees’ installation and use of software on rental computers that secretly monitored consumers including by taking webcam pictures of them in their homes. According to the FTC’s complaint, Aaron’s franchisees used the software, which surreptitiously tracked consumers’ locations, captured images through the computers’ webcams – including those of adults engaged in intimate activities – and activated keyloggers that captured users’ login credentials for email accounts and financial and social media sites.... The complaint alleges that Aaron’s knew about the privacy-invasive features of the software, but nonetheless allowed its franchisees to access and use the software, known as PC Rental Agent. In addition, Aaron’s stored data collected by the software for its franchisees and also transmitted messages from the software to its franchisees. In addition, Aaron’s provided franchisees with instructions on how to install and use the software. The software was the subject of related FTC actions earlier this year against the software manufacturer and several rent-to-own stores, including Aaron’s franchisees, that used it. It included a feature called Detective Mode, which, in addition to monitoring keystrokes, capturing screenshots, and activating the computer’s webcam, also presented deceptive “software registration” screens designed to get computer users to provide personal information.
The FTC's Consent Order Agreement with Aaron's includes a prohibition on the company using keystroke- or screenshot-monitoring software or activating the consumer's microphone or Web cam and a requirement to obtain express consent before installing location-tracking technology and provide notice when it's activated. Aaron's may not use any data it received through improper activities in collections actions, must destroy illegally obtained information, and must encrypt any transmitted location or tracking data it properly collects. The FTC is also continuing its efforts to educate and promote best practices about privacy for both consumers and businesses. On October 28, 2013, FTC Commissioner Julie Brill published an opinion piece in Advertising Age magazine entitled Data Industry Must Step Up to Protect Consumer Privacy. In the piece, Commissioner Brill criticizes data collection and marketing firms for failing to uphold basic privacy principles, and calls on them to join an initiative called "Reclaim Your Name" which Commissioner Brill announced earlier this year. Brill writes in AdAge:
The concept is simple. Through creation of consumer-friendly online services, Reclaim Your Name would empower the consumer to find out how brokers are collecting and using data; give her access to information that data brokers have amassed about her; allow her to opt-out if a data broker is selling her information for marketing purposes; and provide her the opportunity to correct errors in information used for substantive decisions. Improving the handling of sensitive data is another part of Reclaim Your Name. Data brokers that participate in Reclaim Your Name would agree to tailor their data handling and notice and choice tools to the sensitivity of the information at issue. As the data they handle or create becomes more sensitive -- relating to health conditions, sexual orientation and financial condition, for example -- the data brokers would provide greater transparency and more robust notice and choice to consumers.
For more information on the FTC's privacy guidance and enforcement, see the privacy and security section of the FTC Web site.

Tuesday, October 15, 2013

Legal Aid Society of San Mateo CA Suffers Data Breach Including Health Info



On October 10, 2013, the Legal Aid Society of San Mateo County, California sent out a letter notifying potential victims of a data breach suffered by the Society. As the letter states,
On the night of August 12, 2013, our office was burglarized and ten of our laptops were stolen. The stolen laptops were used by our attorneys to assist individuals in getting services. We believe that your personal information may have been stored on the stolen laptops. The personal information believed to be stored on the stolen laptops includes your name, Social Security number, date of birth, medical and health information.
What makes this data breach particularly noteworthy is that, although it occurred at a legal aid organization, the information stolen reportedly included health information. The notice does not discuss how and why health information might have been collected and stored by LASSMC; it may relate to the Society's health advocacy services.

Beyond the immediate impact on the LASSMC clients and others whose stolen personal information may be misused, this incident serves as a reminder that even non-medical professionals may hold, and must keep safe, health information. Even where the formal privacy and security requirements of HIPAA may not directly apply, organizations may still need to comply with HIPAA's Business Associates rules as well as general consumer protection obligations. Attorneys in particular should be aware not only of these requirements, but of their ethical obligations to keep client information confidential, which may further be relevant in a data breach situation.

The California Attorney General's list of reported data breaches may be found here; the LACSSMC letter and information is at this link.

Thursday, October 10, 2013

Got an Internet Business Law Question? Ask the IBLT!


The Touro Law Center for Innovation in Business, Law and Technology ("IBLT") proudly announces "Ask the IBLT," a new initiative to help entrepreneurs and others better understand the business-critical issues of Internet-related law and risk management. Anyone can e-mail a question to asktheiblt@tourolaw.edu. The IBLT will provide answers (prepared by Touro Law students and IBLT faculty affiliates) through its blog, YouTube channel, Google+ page, Facebook page, Twitter account and other channels.

Among the topics for questions for the IBLT are:

  • Privacy and data breaches
  • Social media use (and misuse)
  • Intellectual property (copyright, trademark, patent, trade secrets)
  • Online advertising and marketing
  • Affiliate programs
  • Sweepstakes, contests and other prize promotions
  • Cybercrime
  • Crowdsourcing
  • Crowdfunding
  • International law


"Ask the IBLT is just one part of our overall mission to educate our students and the business and legal communities about these new and evolving areas of law and risk," says Prof. Jonathan I. Ezor, director of the IBLT. "We can't answer every question, and we won't be giving specific legal advice. Instead, we're answering those questions that apply to the most organizations, and offering information and links to resources they can use to succeed and grow while avoiding the biggest pitfalls of doing business online."

Wednesday, February 6, 2013

Mobile Application Privacy: NTIA Publishes Latest Multistakeholder Transparency Draft for Comment


The National Telecommunications and Information Administration ("NTIA"), part of the U.S. Department of Commerce, has been convening multistakeholder meetings to work on improvements to data collection/use transparency--an effort called for in the Obama Administration's Consumer Privacy Bill of Rights. On February 4th, 2013, the NTIA released the latest discussion draft of its Code of Conduct for Mobile Application Transparency. The goals of this initiative, as stated in the latest draft, are to "balance the objectives of transparency, brevity and functionality," or more specifically:


  • Transparency: Consumers expect clear, succinct explanations of an app’s data collection and third party data sharing policies.
  • Brevity: Short form notices must enhance app transparency and understanding in context.
  • Functionality: App developers need transparency standards that they can easily implement in the context of an app without diminishing the user experience.
  • Consumers hold a spectrum of attitudes towards sharing their data with apps. Consumers’ willingness to share data will vary with context and time, and apps should facilitate those choices.
  • Regulators, legislators, and privacy and consumer advocates all seek a fair balance among all of the interests involved, recognizing some consumers’ choice to share data with apps in exchange for a wide variety of tools, content, entertainment.
  • Apps will evolve over time to offer fixes, enhancements, and changes to the original functionality. Apps may need to offer new functionality and/or they may need to adapt their business models. When apps’ data policies evolve in material ways, the apps must promptly and prominently update their disclosures to consumers.
  • Continued work will need to be done to help integrate the full range of fair information practices with effective methods of transparency for innovative data uses. App developers understand that the implementation of these principles is just one aspect of satisfying consumer expectations and they commit to leading their industry to develop common practices and tools that adhere to fair information practices (these principles include access to personal information, control over storing information and sharing it with third parties).
  • App Developers who adhere to this code of conduct and provide short form notice as described in Section II, are engaging in a best practice that significantly enhances transparency of data practices. This code reflects the state of industry best practices for transparency. Although compliance with the code and provision of a short form notice does not guarantee that any individual developer is providing an accurate notice for their specific practices, the authors of this code believe that compliance with the standardization provided by this notice should be a compelling factor serving to limit claims that a notice is deficient.
According to John Verdi, Director of Privacy Initiatives for the NTIA,comments and proposed changes on the latest discussion draft should be sent either to Tim Sparapani or Verdi himself by February 18, 2013. Verdi further states that "[c]omments from prospective adopters are particularly encouraged!"

The informational page for the multistakeholder process on moible application transparency, including meeting schedules and other relevant links, may be found here.