As UK (and the rest of the world) reels from the results of the UK referendum and we find ourselves living in a world where the dystopian Faragist (yes I know he is not the only one!) rhetoric reflects the current thinking of many in the UK, we face important and serious questions about our future laws, policies, social norms and the like in the UK.
For many UK data protection lawyers, the challenge ahead is to ensure that we remain important and relevant voices both with the context of the implementation, interpretation and enforcement of the General Data Protection Regulation and the reform of UK data protection laws.
Since the Brexit outcome, the UK ICO has said that the UK will rely on
"adequacy" decisions from the press release it
seems to be more than the usual "essential adequacy". But this could
just be down to poor drafting!
However, I doubt this will be effective given that adequacy decisions
and similar mechanisms are under attack at EU level. Only BCRs are not
under attack although who knows for how long? And BCRs are not
appropriate in all cases. Since the UK ICO release, Jan Phillip Albrecht has since noted on Twitter that the an "adequacy decision" may not be sufficient given surveillance concerns. The UK will need to develop and implement effective data transfer mechanisms, which are line with the robust requirements of the GDPR and protect the fundamental
rights and freedoms of individuals. UK data protection lawyers will play key roles in ensuring that we have
the relevant data transfer mechanisms in place which will support UK/EU
data transfers, promote the growth of the data-driven economy and
protect the fundamental rights and freedoms of individuals.
This also bring us to the second task at hand for UK data protection lawyers. How will the UK amend its data
protection laws in the aftermath of Brexit? Will the principles of the European Convention of Human Rights still apply in the UK? If so, how will they be reflected in the new laws? What is the status of decades of European jurisprudence which have impacted on how we have interpreted our national data protection laws? To what extent will and should the new
the UK data protection laws include provisions which reflect the
new realities since Google Spain and Schrems cases (and others!) to enable UK/EU data
transfers.
These are some of the inital questions which UK data protection lawyers and policy- makers need to address once we have all recovered from the shock of Brexit. Anya Croops QC of 11KBW has also published interesting insights on the upcoming data protection challenges in the UK.
We need to ensure that the data-driven economy and digital innovation in the UK does not suffer because UK data protection laws cut us off from the rest of the world. This is not a small task and we all need to put our thinking hats on...fast!
A blog by Dr Asma Vranaki which analyses important legal developments in the field of cyberspace including privacy, defamation, intellectual property, e-commerce and online property in the UK, EU, USA and the Far East.
Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts
24 June 2016
7 April 2016
Data Privacy Regulation in the Context of Facebook Advertisements
The blog of the Vanderbilt Journal of Entertainment & Technology Law
recently covered my upcoming article in the John Marshall Journal of Information
Technology & Privacy Law on data privacy regulation in the context of Facebook advertisements.
You can read more about it here.
You can read more about it here.
Smart Regulation and the General Data Protection Regulation
I recently published an article on smart regulation and the General Data Protection Regulation ("GDPR") on the website of the Society of Computers and Law. The article will also feature in the next issue of Computers & Law. You can read the full text of the article below.
---------
Data protection and privacy practitioners are
waiting anxiously for the official adoption of the GDPR. The latest
indication from the European Commission is that the GDPR will officially
be adopted in June/July 2016 and in force as from June/July 2018.
Since political agreement was reached on the GDPR in December 2015,
we have a fairly good idea of some of the main aspects of the official
legislation, such as the statutory recognition of an 'accountability'
principle, a risk-based approach to data protection (eg data
protection/privacy impact assessments, privacy by design, breach
notification), and enhanced individual rights (eg new right of data
portability and right to be forgotten).
Once
the GDPR is in force, the litmus test for success will be the consistent
implementation, interpretation and enforcement of the Regulation. Many
commentators have already warned that the GDPR's promise of
harmonization may be more fiction than fact due to the vague and
ambiguous provisions of the GDPR (eg legitimate interests provision) as
well as the so-called 'open clauses'. 'Open clauses' refer to GDPR
provisions where implementation is left to the member-states.
But
looking beyond the immediate parapet of the rules, the GDPR is also
heralding a move to smart regulation. One aspect of smart regulation is
that it involves interactions between diverse stakeholders, such as
law-makers, EU DPAs, European Data Protection Board, European
Commission, data controllers, data processors, and quasi-regulators (eg
third-party certification bodies). Some of these stakeholders, such as
EU DPAs and the companies they regulate, used to interact with one
another in the pre-GDPR era. However, a move towards smart regulation
can often impact on these existing relationships.
In
this article, I explore what smart regulation may mean for the
relationships between EU DPAs and the companies they regulate. I draw on
some of the findings of my recent empirical research project,
where I have analysed how some EU DPAs are starting to embrace smart
regulation during their investigations of multinational cloud providers,
to suggest four potential key aspects of a smart regulatory
relationship between EU DPAs and their regulatees. These four points are
mere starting points when reflecting on what smart regulation may look
like for the relationships between EU DPAs and the companies they
oversee. As noted below, much more work needs to be done to flesh out
how such relationships will be developed in practice.
Active Engagement between EU DPAs and Companies
Companies
and EU DPAs will benefit from active, regular, and informal engagement
with each other from the very beginning and in any event before a data
breach is detected or reported. Opening the dialogue between the
regulator and regulatees from an early stage has three key advantages.
Firstly, it will enable both parties to build a productive rapport which
will be crucial in many cases where there will be a long-term
relationship between the regulator and the company. This will, in all
likelihood, be the case for multinational companies with a strong
European presence and the EU DPAs which will be their lead regulator for
their EU operations.
Secondly, this type of
interaction will make it possible for EU DPAs to gain an in-depth
knowledge of the processing operations and policies of the companies
which fall within their jurisdiction, long before any data breach has
been reported.
Finally, this will provide
companies with the opportunity to explain to the regulators their
offerings, business drivers, and processing operations. Such engagement
means that the regulator will have a detailed understanding of the
organisation which can often be useful during enforcement.
Organisations can also discuss with EU DPAs the data protection and
privacy issues which are potentially raised by their future products or
services and tackle such issues head on at the ideation or preliminary
design stage rather than after these products or services have been
launched. This approach can often not only be cost-effective but also
enable companies, especially multinationals, to reduce or avoid negative
media coverage which plays a pivotal role in determining the reputation
of such organisations.
This level of
engagement between EU DPAs and companies will be problematic if EU DPAs
do not develop effective and consistent strategies which will enable
them to prioritise tasks in an informed and systematic way. This will be
even more crucial for EU DPAs which have limited resources.
Unfortunately, the GDPR is silent on how EU DPAs can assess the priority
of their activities. Consequently, one of the tasks ahead before the
GDRP is in force will be to formulate consistent guidelines which EU
DPAs can use to evaluate which regulatory activity takes precedence over
others.
Compliance Attitudes of Companies
EU
DPAs will need to recognize that companies will have different, and
often complex, attitudes to compliance. Some organisations may be
largely co-operative whilst others may often be recalcitrant.
Additionally, the compliance attitudes of companies are likely to change
over time for various reasons, including media coverage, reputation,
change in management and so on. At times, an otherwise co-operative
company can start to object to some of the data protection
recommendations which an EU DPA may make. Consequently, EU DPAs need to
learn how to deal with and manage the intricate and rapidly evolving
compliance attitudes of the organisations they oversee.
Additionally,
EU DPAs may often benefit from identifying the reasons why companies
may wish to comply with the law. EU DPAs can then often use these
reasons as bargaining chips during their interactions with these
organisations in order to secure the desired data protection outcome. In
many cases, compliance can often be driven by many (rather than one),
often interconnected, reasons, such as avoiding reputational damage,
generating the trust of customers in the company, avoiding citable
binding court decisions, and moral reasons.
Dynamic Regulatory Styles
EU
DPAs may benefit from developing dynamic regulatory styles so that they
can respond effectively to the diverse and often shifting compliance
attitudes of their regulatees. In particular, in some cases it may be
appropriate for EU DPAs to adopt regulatory styles which gradually
escalate from soft strategies (eg persuasion, discussion) to harder
strategies where the regulatee objects to base line compliance (eg
threat to initiate enforcement action) to soft strategies again once the
organisation co-operates.
My recent study
highlighted that regulatory styles which can seamlessly move from one
end of the spectrum (soft) to the other (hard) and back are often the
most effective ones. Additionally, my research also showed that EU DPAs
which adopted a 'smarter' approach to regulation by (i) adopting not
only dynamic regulatory styles but also recognising the business drivers
of companies, (ii) attempting to find mutually convenient solutions,
and (iii) not relying heavily on formalistic tools often achieved better
outcomes in the longer term.
This shift in the
regulatory styles of EU DPAs will be one of the key challenges ahead
when tackling smart regulation. Some EU DPAs may be bound by procedural
rules which may prevent them from smoothly moving from soft to hard to
soft regulatory styles. Other EU DPAs may need to learn how to regulate
in this manner whilst being effective. Thus, we need to bear these
points in mind when thinking about how to develop smart regulation when
the GDPR is in force.
Regulatory Relationship Management
Smart
regulation also means that companies need to rethink how they approach
and manage their relationships with the EU DPAs. In the pre-GDPR era, the regulatory relationship often started on an ex-post
basis, for example, when a data breach was detected or when an
individual filed a complaint against the company. In many cases, the
regulatory relationship would often start on negative note with many
companies being on the defensive from the start.
In the GDPR era,
the relationships between many companies (let's say multinationals) and
their regulators, especially their lead EU DPAs, may often be from
cradle to grave. Such relationships may often start on an ex-ante basis, for example, when a multinational opens a local branch in the territory of the EU DPA.
In
order to develop healthy and productive regulatory relationships, many
organisations will have to change how they conceive and manage these
relationships. We may need to look at how regulatory relationships in
other industries are successfully built in order to learn how companies
can build effective and long-term relationships with EU DPAs.
For
example, showing the regulators that you want to co-operate (and mean
it!), knowing how to negotiate compliance effectively so as to promote
innovation whilst complying with the law, keeping the promises made to
the regulators may be fruitful ways in which companies can start
creating a positive dialogue with their regulators. We also need to
consider how SMEs and other companies with a limited budget can
cultivate this type of regulatory relationship despite their limited
resources.
Dr Asma Vranaki is an
Associate Fellow at the University of Oxford where she investigates the
regulation of computer-mediated communication technologies (eg cloud
computing, social media). She is a non-practising barrister who
specialises in the data protection and privacy law issues raised by the
Digital Age.
For more see,
Vranaki, Asma A.I., 'Cloud Investigations by European Data Protection
Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, Forthcoming); Queen Mary School of Law Legal Studies Research Paper No. 195/2015 < http://ssrn.com/abstract=2602216>. The author conducted this research whilst working on the EC-funded 'Accountability for Cloud' research project.
14 May 2015
Dear Google: open letter from 80 academics on 'right to be forgotten'
Our open letter to Google published in today`s Guardian seeking the disclosure of compliance data in relation to its implementation of the right to be forgotten.
And Google`s response. Let`s see how this balancing exercise translates in practice and what concrete outputs are circulated.
And Google`s response. Let`s see how this balancing exercise translates in practice and what concrete outputs are circulated.
12 May 2015
Cloud Investigations by European Data Protection Authorities
You can find the recent draft of my book chapter entitled 'Cloud Investigations by European Data Protection Authorities: An Empirical View' on SSRN.
The full citation for the chapter is:
Vranaki, Asma A.I., Cloud Investigations by European Data Protection Authorities: An Empirical Account (March 31, 2015). Vranaki Asma, 'Cloud Investigations by European Data Protection Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, 2016). Available at SSRN: http://ssrn.com/abstract=2602216
Let me know your thoughts!
The full citation for the chapter is:
Vranaki, Asma A.I., Cloud Investigations by European Data Protection Authorities: An Empirical Account (March 31, 2015). Vranaki Asma, 'Cloud Investigations by European Data Protection Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, 2016). Available at SSRN: http://ssrn.com/abstract=2602216
Let me know your thoughts!
30 March 2015
Cloud Investigations by EU Data Protection Authorities
I was delighted to present part of my current research on the cloud
investigations conducted by European data protection authorities at the
recent launch of the Centre for Law and Information Policy at the
Institute of Advanced Legal Studies.
My current research forms part of the 'Accountability for Cloud' research project which is a major European research project. I have designed and conducted a qualitative socio-legal research project which investigates how and why investigations of companies offering cloud computing technologies or services ('Cloud Providers') are being conducted by European data protection authorities.
You can find a copy of my slides here.
My current research forms part of the 'Accountability for Cloud' research project which is a major European research project. I have designed and conducted a qualitative socio-legal research project which investigates how and why investigations of companies offering cloud computing technologies or services ('Cloud Providers') are being conducted by European data protection authorities.
You can find a copy of my slides here.
4 June 2014
The rise of audits and/or investigations by national data protection authorities in cloud computing
I have recently written my current research where I am exploring the rise of audits and/or investigations by national data protection authorities in cloud computing. This is a socio-legal research project which forms part of the Accountability for Cloud research project.
16 November 2010
16.10.10 Weekly Cyber-Law News Round-Up
Another exciting week in the world of cyber-law with BT & Talk Talk being granted judicial review in relation to the Digital Economy Act, many proposals for legal measures from the Commission/Parliament relating to data protection and privacy, and the Parliament`s objection to the use of trademarks as Adwords. CyberPanda wonders what the impact of this opposition will mean in practice when it comes to the laws relating to keywords. Here is my personal pick of the week:
Copyright
· Larry Lessig Calls For #WIPO To Lead Overhaul Of #Copyright System | IP Watch http://bit.ly/9qAHtp
Digital Economy Act
· Court grants fourth ground for Digital Economy review http://is.gd/h9rzM
· Future of Digital Economy Act 'in limbo' until next year, say lawyers http://ow.ly/38j13
· BT & TalkTalk granted judicial review of Digital Economy Act- what does it mean for file sharers? http://bit.ly/92lvxf
Data Protection & Privacy
· Dangers of the Commission`s proposal to include the right to be forgotten in data protection laws http://ow.ly/38J6r
· Information Commissioner says new laws that impact on privacy should undergo post-legislative scrutiny http://bit.ly/cR1Jdj
· ECJ holds unqualified legal requirement to disclose personal data on website violates right to privacy and data... http://j.mp/9nXWAC
Censorship
· Palestinian blogger arrested for criticism of Islam on Facebook - Global Voices Advocacy - http://goo.gl/qUao6 #censorship
Unfair Competition
· European Parliament joins French traders in opposing use of rival brands as keywords http://ow.ly/39QkR
3 March 2009
Another week where Facebook is in the press for the wrong reasons...
Another week and Facebook is yet again in the news for all the wrong reasons. It has been reported by BBC News that Facebook has been hit by five different security attacks in the past 7 days. The aim of these attacks have been to access the personal information of millions of Facebook users and resale them to third parties as commodities for various purposes including fraud and identity theft.The attacks were concealed in what are commonly known as 'rogue applications.' This brings to light yet again Facebook`s worrying practice of not vetoing third party applications before they are published on the site. As a matter of fact, any individual can create an application and publish it on the site. S/he, then, has access to all the personal data of all the users of Facebook, irrespective of whether or not the users have subscribed to the application. Facebook justifies this practice on the grounds on 'open source,' namely, any user should be able to participate in the Facebook both as a user and as a developer of applications. However, this only serves to highlight the problem of the concept of open source or creative commons. The unfettered and unchecked proliferation of code by net users in such websites not only threatens the fundamental rights of other net users but also, and more importantly, yet again highlight the increasing risk posed by a regulatory framework which is based on technological determinism.
Disclaimer: The rights to the image used above belongs to a third party. The original image can be accessed here.
17 September 2008
Phorm is being rolled out.
The Government has stated that Phorm, the online ad system, will be rolled out in the UK. Avid readers of CyberPanda will remember that this issue was covered earlier this year when the EU questioned the lawfulness of Phorm especially in the context of data protection laws. The EU asked the Government to clarify the manner in which the system tracked the web habits of net users.The Government has now clarified the manner in which the tracking will be done. In a nutshell, trials of the tracking will only be done with the consent of the net users being tracked. In the words of the Government to the EU: 'Users will be presented with an unavoidable statement about the product and asked to exercise choice about whether to be involved. Users will be able to easily access information on how to change their mind at any point and are free to opt in or out of the scheme (my emphasis).'
The Office of the Information Commissioner has already issued its response to this statement and is in the process of analysing the reply as well as undertaking a legal assessment of the situation in the UK. So the situation is far from being resolved. It seems that the better solution would have been for the UK government to wait for the response of the Commissioner before proceeding to roll out the system here.
Phorm argues that the system is legal: profiles of the users are created on the unique ID of the user rather than the identity of the user. Phorm also argues that it does not have any information which would enable it to link the user ID to the user. One still wonders what the ID of the user reveals about the identity of the user. Surely it must contain some unique characteristic of the user in question.
Another issue is the legality of the trials which were carried out without the consent/knowledge of the net users before the EU intervened. Police investigation is currently been carried out on this matter following several complaints by tracked users, so this matter is also pending.
Phorm raising a series of complex legal and commercial issues including data protection, rights of other content owners and privacy and the Government should have awaited the final determination by the EU before proceeding forward with the launching of the project here. But yet again, it seems to be a situation of act now and take it down later if it offends.
Disclaimer: The rights to the logo used above belongs to Phorm.
6 August 2008
Six degrees of separation between you and the advertisers.
The EU Commissioner, Viviane Reding, as asked the UK Government to clarify whether the use of the Phorm system is in breach of EU data protection laws in May 2008. the Government has to respond by August 2008.Phorm is a digital technology company which has launched Open Internet Exchange ('OIX') and Webwise, which enable targeted advertising, based on the browsing habits of the users. Phorm has been in talks with some of the biggest ISPs in the UK; namely BT, Virgin Media; and TalkTalk, to this end. The attraction for ISPs and advertisers is clear as the closer the match the better. Advertisers are able to reach their target audience and the platform gets more revenue as the chances of the advertisements being clicked on by the end-user is far greater.
A quick read through the website of Phorm seems to suggest that this is a perfectly harmless activity which will improve the web experience of the user drastically. One has to wonder when an advertisement has improved the experience of its audience. Most of the time, online advertisements (just like their offline counterparts) are unwelcome at worst and informative at its best. But one struggles to see how they can stretch to improve the experience per se. The inflation of the experience as well as the constant use of the phrase 'protection of users` privacy' on the Phorm website, is a clear design by the company to hide the true nature of the surveillance taking place here.
A quick read through the website of Phorm seems to suggest that this is a perfectly harmless activity which will improve the web experience of the user drastically. One has to wonder when an advertisement has improved the experience of its audience. Most of the time, online advertisements (just like their offline counterparts) are unwelcome at worst and informative at its best. But one struggles to see how they can stretch to improve the experience per se. The inflation of the experience as well as the constant use of the phrase 'protection of users` privacy' on the Phorm website, is a clear design by the company to hide the true nature of the surveillance taking place here.
Basically, Phorm will have equipment at ISPs which track the activities of the end user. Thus, it will note down the URL visited, search terms used and other relevant information. The IP address of the user is not captured, but a cookie with a unique number is installed on the browser of the end user.
The data collected is categorised and used to create the profile of the user. Hence, when the user visits a webpage whose adverts emanate from OIX, s/he is directed to adverts targeted to his/her profile.
BT is apparently considering starting a trial of the service in the near future. There have also been rumours of 'secret trials' having been conducted without the consent/knowledge of the end user.The Information Commission ruled in May that no action would be taken against BT as it was difficult to explain to users what was being done. However, it also ruled that any future use should only go ahead, with the consent of the users. The flaw in this ruling is quite apparent: surely the inherent difficult in explaining to the end-user what is being done, is still present: so it is very hard to understand how the nature of the difficulty has evolved so that now an explanation is more feasible.
The dangers inherent in this initiative (breach of privacy, breach of data protection etc) are very much apparent and it is very hard to see how the Government will be able to persuasively rationalise them. In addition, it is also very difficult to see the Commission approving of such a scheme. However, in the meantime, this does not put a stop to the launch of the Phorm initiative by the ISPs in the UK, which of course means that the end-user will be incredibly vulnerable until the Commission reaches a decision. A far better option, would have been to ask the ISPs not to launch this initiative until the Commission`s findings.
Disclaimer: This image is subject to copyright. Click here to access original image.
16 July 2008
Is the silver lining in the cloud hanging over YouTube no more than a silver thread actually?
It appears from the website of the Electronic Frontier Foundation that Viacom has formally responded to the concerns of the EFF in relation to the nature of the silver lining reported in the last post.
The EFF was concerned that the agreement between YouTube and Viacom in relation to the disclosure of the data of users of YouTube was not backed up by a court order. The obvious danger with that is that both parties can alter the agreement at a later date.
Viacom has now informed the EFF that the latter will be notified in advance if the agreement is to be amended so that the EFF can either discuss its concerns with YouTube and Viacom or raise more formal objections in Court.
Viacom has also forwarded a draft Protective Order to the EFF. CyberPanda agrees with the EFF that it is crucial that the scope and nature of the disclosure of the data should be formally defined by a court order. It is undeniable that Viacom has shown a lot of goodwill in this matter. Nonetheless, it will be in the best interests of the data subjects if the disclosure was more formally regulated by a Court order. That will breach the gap between the silver thread and the silver lining.
The EFF was concerned that the agreement between YouTube and Viacom in relation to the disclosure of the data of users of YouTube was not backed up by a court order. The obvious danger with that is that both parties can alter the agreement at a later date.
Viacom has now informed the EFF that the latter will be notified in advance if the agreement is to be amended so that the EFF can either discuss its concerns with YouTube and Viacom or raise more formal objections in Court.
Viacom has also forwarded a draft Protective Order to the EFF. CyberPanda agrees with the EFF that it is crucial that the scope and nature of the disclosure of the data should be formally defined by a court order. It is undeniable that Viacom has shown a lot of goodwill in this matter. Nonetheless, it will be in the best interests of the data subjects if the disclosure was more formally regulated by a Court order. That will breach the gap between the silver thread and the silver lining.
15 July 2008
The silver lining in the cloud hanging over YouTube.
Users of YouTube and indeed YouTube itself will, no doubt, be relieved that Viacom has now agreed for YouTube to handover the viewing history of its users without handing over any data that might enable Viacom to actually identify the specific user.
This is a welcome development which will no doubt be applauded by privacy activitists and users of YouTube as well since the original demand would have undoubtedly raised serious privacy concerns.
This is however a very tiny silver lining in the big cloud hanging over YouTube as the copyright infringement lawsuit is all but over.
This is a welcome development which will no doubt be applauded by privacy activitists and users of YouTube as well since the original demand would have undoubtedly raised serious privacy concerns.
This is however a very tiny silver lining in the big cloud hanging over YouTube as the copyright infringement lawsuit is all but over.
Subscribe to:
Posts (Atom)