Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

24 June 2016

The Future of UK Data Protection Laws after Brexit: Some Initial Thoughts

As UK (and the rest of the world) reels from the results of the UK referendum and we find ourselves living in a world where the dystopian Faragist (yes I know he is not the only one!) rhetoric reflects the current thinking of many in the UK, we face important and serious questions about our future laws, policies, social norms and the like in the UK.

For many UK data protection lawyers, the challenge ahead is to ensure that we remain important and relevant voices both with the context of the implementation, interpretation and enforcement of the General Data Protection Regulation and the reform of UK data protection laws.

Since the Brexit outcome, the  UK ICO has said that the UK will rely on "adequacy" decisions from the press release it seems to be more than the usual "essential adequacy". But this could just be down to poor drafting!



However, I doubt this will be effective given that adequacy decisions and similar mechanisms are under attack at EU level. Only BCRs  are not under attack although who knows for how long? And BCRs are not appropriate in all cases. Since the UK ICO release, Jan Phillip Albrecht has since noted on Twitter that the an "adequacy decision" may not be sufficient given surveillance concerns. The UK will need to develop and implement effective data transfer mechanisms, which are line with the robust requirements of the GDPR and protect the fundamental rights and freedoms of individuals. UK data protection lawyers will play key roles in ensuring that we have the relevant data transfer mechanisms in place which will support UK/EU data transfers, promote the growth of the data-driven economy and protect the fundamental rights and freedoms of individuals. 

This also bring us to the second task at hand for UK data protection lawyers. How will the UK amend its data protection laws in the aftermath of Brexit? Will the principles of the European Convention of Human Rights still apply in the UK? If so, how will they be reflected in the new laws? What is the status of decades of European jurisprudence which have impacted on how we have interpreted our national data protection laws? To what extent will and should the new the UK data protection laws include provisions which reflect the new realities since Google Spain and Schrems cases (and others!) to enable UK/EU data transfers.

These are some of the inital questions which UK data protection lawyers and policy- makers need to address once we have all recovered from the shock of Brexit. Anya Croops QC of 11KBW has also published interesting insights on the upcoming data protection challenges in the UK.

We need to ensure that the data-driven economy and digital innovation in the UK does not suffer because UK data protection laws cut us off from the rest of the world. This is not a small task and we all need to put our thinking hats on...fast!

7 April 2016

Data Privacy Regulation in the Context of Facebook Advertisements

The blog of the Vanderbilt Journal of Entertainment & Technology Law recently covered my upcoming article in the John Marshall Journal of Information Technology & Privacy Law on data privacy regulation in the context of Facebook advertisements.

You can read more about it here.

Smart Regulation and the General Data Protection Regulation

I recently published an article on smart regulation and the General Data Protection Regulation ("GDPR") on the website of the Society of Computers and Law.  The article will also feature in the next issue of Computers & Law. You can read the full text of the article below.

---------

Data protection and privacy practitioners are waiting anxiously for the official adoption of the GDPR. The latest indication from the European Commission is that the GDPR will officially be adopted in June/July 2016 and in force as from June/July 2018.

Since political agreement was reached on the GDPR in December 2015, we have a fairly good idea of some of the main aspects of the official legislation, such as the statutory recognition of an 'accountability' principle, a risk-based approach to data protection (eg data protection/privacy impact assessments, privacy by design, breach notification), and enhanced individual rights (eg new right of data portability and right to be forgotten). 

Once the GDPR is in force, the litmus test for success will be the consistent implementation, interpretation and enforcement of the Regulation. Many commentators have already warned that the GDPR's promise of harmonization may be more fiction than fact due to the vague and ambiguous provisions of the GDPR (eg legitimate interests provision) as well as the so-called 'open clauses'. 'Open clauses' refer to GDPR provisions where implementation is left to the member-states.
But looking beyond the immediate parapet of the rules, the GDPR is also heralding a move to smart regulation. One aspect of smart regulation is that it involves interactions between diverse stakeholders, such as law-makers, EU DPAs, European Data Protection Board, European Commission, data controllers, data processors, and quasi-regulators (eg third-party certification bodies). Some of these stakeholders, such as EU DPAs and the companies they regulate, used to interact with one another in the pre-GDPR era. However, a move towards smart regulation can often impact on these existing relationships. 

In this article, I explore what smart regulation may mean for the relationships between EU DPAs and the companies they regulate. I draw on some of the findings of my recent empirical research project, where I have analysed how some EU DPAs are starting to embrace smart regulation during their investigations of multinational cloud providers, to suggest four potential key aspects of a smart regulatory relationship between EU DPAs and their regulatees. These four points are mere starting points when reflecting on what smart regulation may look like for the relationships between EU DPAs and the companies they oversee. As noted below, much more work needs to be done to flesh out how such relationships will be developed in practice. 

Active Engagement between EU DPAs and Companies
Companies and EU DPAs will benefit from active, regular, and informal engagement with each other from the very beginning and in any event before a data breach is detected or reported. Opening the dialogue between the regulator and regulatees from an early stage has three key advantages. Firstly, it will enable both parties to build a productive rapport which will be crucial in many cases where there will be a long-term relationship between the regulator and the company. This will, in all likelihood, be the case for multinational companies with a strong European presence and the EU DPAs which will be their lead regulator for their EU operations.  

Secondly, this type of interaction will make it possible for EU DPAs to gain an in-depth knowledge of the processing operations and policies of the companies which fall within their jurisdiction, long before any data breach has been reported. 

Finally, this will provide companies with the opportunity to explain to the regulators their offerings, business drivers, and processing operations. Such engagement means that the regulator will have a detailed understanding of the organisation which can often be useful during enforcement. 

 Organisations can also discuss with EU DPAs the data protection and privacy issues which are potentially raised by their future products or services and tackle such issues head on at the ideation or preliminary design stage rather than after these products or services have been launched. This approach can often not only be cost-effective but also enable companies, especially multinationals, to reduce or avoid negative media coverage which plays a pivotal role in determining the reputation of such organisations. 

This level of engagement between EU DPAs and companies will be problematic if EU DPAs do not develop effective and consistent strategies which will enable them to prioritise tasks in an informed and systematic way. This will be even more crucial for EU DPAs which have limited resources. Unfortunately, the GDPR is silent on how EU DPAs can assess the priority of their activities.  Consequently, one of the tasks ahead before the GDRP is in force will be to formulate consistent guidelines which EU DPAs can use to evaluate which regulatory activity takes precedence over others. 

Compliance Attitudes of Companies
EU DPAs will need to recognize that companies will have different, and often complex, attitudes to compliance. Some organisations may be largely co-operative whilst others may often be recalcitrant. Additionally, the compliance attitudes of companies are likely to change over time for various reasons, including media coverage, reputation, change in management and so on. At times, an otherwise co-operative company can start to object to some of the data protection recommendations which an EU DPA may make. Consequently, EU DPAs need to learn how to deal with and manage the intricate and rapidly evolving compliance attitudes of the organisations they oversee.
Additionally, EU DPAs may often benefit from identifying the reasons why companies may wish to comply with the law. EU DPAs can then often use these reasons as bargaining chips during their interactions with these organisations in order to secure the desired data protection outcome. In many cases, compliance can often be driven by many (rather than one), often interconnected, reasons, such as avoiding reputational damage, generating the trust of customers in the company, avoiding citable binding court decisions, and moral reasons. 

Dynamic Regulatory Styles
EU DPAs may benefit from developing dynamic regulatory styles so that they can respond effectively to the diverse and often shifting compliance attitudes of their regulatees. In particular, in some cases it may be appropriate for EU DPAs to adopt regulatory styles which gradually escalate from soft strategies (eg persuasion, discussion) to harder strategies where the regulatee objects to base line compliance (eg threat to initiate enforcement action) to soft strategies again once the organisation co-operates. 

My recent study highlighted that regulatory styles which can seamlessly move from one end of the spectrum (soft) to the other (hard) and back are often the most effective ones. Additionally, my research also showed that EU DPAs which adopted a 'smarter' approach to regulation by (i) adopting not only dynamic regulatory styles but also recognising the business drivers of companies, (ii) attempting to find mutually convenient solutions, and (iii) not relying heavily on formalistic tools often achieved better outcomes in the longer term. 

This shift in the regulatory styles of EU DPAs will be one of the key challenges ahead when tackling smart regulation. Some EU DPAs may be bound by procedural rules which may prevent them from smoothly moving from soft to hard to soft regulatory styles. Other EU DPAs may need to learn how to regulate in this manner whilst being effective. Thus, we need to bear these points in mind when thinking about how to develop smart regulation when the GDPR is in force. 

Regulatory Relationship Management
Smart regulation also means that companies need to rethink how they approach and manage their relationships with the EU DPAs. In the pre-GDPR era, the regulatory relationship often started on an ex-post basis, for example, when a data breach was detected or when an individual filed a complaint against the company. In many cases, the regulatory relationship would often start on negative note with many companies being on the defensive from the start. 

In the GDPR era, the relationships between many companies (let's say multinationals) and their regulators, especially their lead EU DPAs, may often be from cradle to grave. Such relationships may often start on an ex-ante basis, for example, when a multinational opens a local branch in the territory of the EU DPA. 

In order to develop healthy and productive regulatory relationships, many organisations will have to change how they conceive and manage these relationships. We may need to look at how regulatory relationships in other industries are successfully built in order to learn how companies can build effective and long-term relationships with EU DPAs.

For example, showing the regulators that you want to co-operate (and mean it!), knowing how to negotiate compliance effectively so as to promote innovation whilst complying with the law, keeping the promises made to the regulators may be fruitful ways in which companies can start creating a positive dialogue with their regulators. We also need to consider how SMEs and other companies with a limited budget can cultivate this type of regulatory relationship despite their limited resources.  

Dr Asma Vranaki is an Associate Fellow at the University of Oxford where she investigates the regulation of computer-mediated communication technologies (eg cloud computing, social media). She is a non-practising barrister who specialises in the data protection and privacy law issues raised by the Digital Age.
 
For more see, Vranaki, Asma A.I., 'Cloud Investigations by European Data Protection Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, Forthcoming); Queen Mary School of Law Legal Studies Research Paper No. 195/2015 < http://ssrn.com/abstract=2602216>. The author conducted this research whilst working on the EC-funded 'Accountability for Cloud' research project.

14 May 2015

Dear Google: open letter from 80 academics on 'right to be forgotten'

Our open letter to Google published in today`s Guardian seeking the disclosure of compliance data in relation to its implementation of the right to be forgotten.

And Google`s response. Let`s see how this balancing exercise translates in practice and what concrete outputs are circulated. 


12 May 2015

Cloud Investigations by European Data Protection Authorities

You can find the recent draft of my book chapter entitled 'Cloud Investigations by European Data Protection Authorities: An Empirical View' on SSRN.

The full citation for the chapter is:

Vranaki, Asma A.I., Cloud Investigations by European Data Protection Authorities: An Empirical Account (March 31, 2015). Vranaki Asma, 'Cloud Investigations by European Data Protection Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, 2016). Available at SSRN: http://ssrn.com/abstract=2602216

Let me know your thoughts!

30 March 2015

Cloud Investigations by EU Data Protection Authorities

I was delighted to present part of my current research on the cloud investigations conducted by European data protection authorities at the recent launch of the Centre for Law and Information Policy at the Institute of Advanced Legal Studies.

My current research forms part of the 'Accountability for Cloud' research project which is a major European research project. I have designed and conducted a qualitative socio-legal research project which investigates how and why investigations of companies offering cloud computing technologies or services ('Cloud Providers') are being conducted by European data protection authorities. 

You can find a copy of my slides here.

4 June 2014

The rise of audits and/or investigations by national data protection authorities in cloud computing

I have recently written my current research where I am exploring the rise of audits and/or investigations by national data protection authorities in cloud computing. This is a socio-legal research project which forms part of the Accountability for Cloud research project.

16 November 2010

16.10.10 Weekly Cyber-Law News Round-Up

Another exciting week in the world of cyber-law with BT & Talk Talk being granted judicial review in relation to the Digital Economy Act, many proposals for legal measures from the Commission/Parliament relating to data protection and privacy, and the Parliament`s objection to the use of trademarks as Adwords. CyberPanda wonders what the impact of this opposition will mean in practice when it comes to the laws relating to keywords. Here is my personal pick of the week:

Copyright
·         Larry Lessig Calls For #WIPO To Lead Overhaul Of #Copyright System | IP Watch http://bit.ly/9qAHtp

·         Court Recognizes That DMCA Process Goes Against Basic Copyright Concepts” http://bit.ly/dos8eu


Digital Economy Act
·         Court grants fourth ground for Digital Economy review http://is.gd/h9rzM

·         Future of Digital Economy Act 'in limbo' until next year, say lawyers http://ow.ly/38j13

·         BT & TalkTalk granted judicial review of Digital Economy Act- what does it mean for file sharers? http://bit.ly/92lvxf
Data Protection & Privacy

·         Call to enforce EC strategy for data protection http://ow.ly/3a3IS #dataprotection #in

·         Summary of Draft Department of Commerce Privacy Green Paper http://ow.ly/3a2RK

·         Facebook, Background Checks and Job Applications http://bit.ly/9yyhN5 #privacy

·         Police recruits screened for digital dirt on Facebook, etc. http://usat.ly/avu0uQ #privacy

·         Swedes' emails to be stored for six months http://ht.ly/38lH2

·         Comparative Chart: Divergencies between Data Protection Laws in the EU. http://bit.ly/c0jbCp

·         Dangers of the Commission`s proposal to include the right to be forgotten in data protection laws http://ow.ly/38J6r

·         European Parliament proposes tough behavioural ad rules http://ow.ly/38j4c

·         Information Commissioner says new laws that impact on privacy should undergo post-legislative scrutiny http://bit.ly/cR1Jdj

·         ECJ holds unqualified legal requirement to disclose personal data on website violates right to privacy and data... http://j.mp/9nXWAC

Censorship

·         Palestinian blogger arrested for criticism of Islam on Facebook - Global Voices Advocacy - http://goo.gl/qUao6 #censorship

Unfair Competition
·         European Parliament joins French traders in opposing use of rival brands as keywords http://ow.ly/39QkR

3 March 2009

Another week where Facebook is in the press for the wrong reasons...

Another week and Facebook is yet again in the news for all the wrong reasons. It has been reported by BBC News that Facebook has been hit by five different security attacks in the past 7 days. The aim of these attacks have been to access the personal information of millions of Facebook users and resale them to third parties as commodities for various purposes including fraud and identity theft.

The attacks were concealed in what are commonly known as 'rogue applications.' This brings to light yet again Facebook`s worrying practice of not vetoing third party applications before they are published on the site. As a matter of fact, any individual can create an application and publish it on the site. S/he, then, has access to all the personal data of all the users of Facebook, irrespective of whether or not the users have subscribed to the application. Facebook justifies this practice on the grounds on 'open source,' namely, any user should be able to participate in the Facebook both as a user and as a developer of applications. However, this only serves to highlight the problem of the concept of open source or creative commons. The unfettered and unchecked proliferation of code by net users in such websites not only threatens the fundamental rights of other net users but also, and more importantly, yet again highlight the increasing risk posed by a regulatory framework which is based on technological determinism.
Disclaimer: The rights to the image used above belongs to a third party. The original image can be accessed here.

17 September 2008

Phorm is being rolled out.

The Government has stated that Phorm, the online ad system, will be rolled out in the UK. Avid readers of CyberPanda will remember that this issue was covered earlier this year when the EU questioned the lawfulness of Phorm especially in the context of data protection laws. The EU asked the Government to clarify the manner in which the system tracked the web habits of net users.

The Government has now clarified the manner in which the tracking will be done. In a nutshell, trials of the tracking will only be done with the consent of the net users being tracked. In the words of the Government to the EU: 'Users will be presented with an unavoidable statement about the product and asked to exercise choice about whether to be involved. Users will be able to easily access information on how to change their mind at any point and are free to opt in or out of the scheme (my emphasis).'

The Office of the Information Commissioner has already issued its response to this statement and is in the process of analysing the reply as well as undertaking a legal assessment of the situation in the UK. So the situation is far from being resolved. It seems that the better solution would have been for the UK government to wait for the response of the Commissioner before proceeding to roll out the system here.


Phorm argues that the system is legal: profiles of the users are created on the unique ID of the user rather than the identity of the user. Phorm also argues that it does not have any information which would enable it to link the user ID to the user. One still wonders what the ID of the user reveals about the identity of the user. Surely it must contain some unique characteristic of the user in question.


Another issue is the legality of the trials which were carried out without the consent/knowledge of the net users before the EU intervened. Police investigation is currently been carried out on this matter following several complaints by tracked users, so this matter is also pending.


Phorm raising a series of complex legal and commercial issues including data protection, rights of other content owners and privacy and the Government should have awaited the final determination by the EU before proceeding forward with the launching of the project here. But yet again, it seems to be a situation of act now and take it down later if it offends.
Disclaimer: The rights to the logo used above belongs to Phorm.

6 August 2008

Six degrees of separation between you and the advertisers.

The EU Commissioner, Viviane Reding, as asked the UK Government to clarify whether the use of the Phorm system is in breach of EU data protection laws in May 2008. the Government has to respond by August 2008.

Phorm is a digital technology company which has launched Open Internet Exchange ('OIX') and Webwise, which enable targeted advertising, based on the browsing habits of the users. Phorm has been in talks with some of the biggest ISPs in the UK; namely BT, Virgin Media; and TalkTalk, to this end. The attraction for ISPs and advertisers is clear as the closer the match the better. Advertisers are able to reach their target audience and the platform gets more revenue as the chances of the advertisements being clicked on by the end-user is far greater.

A quick read through the website of Phorm seems to suggest that this is a perfectly harmless activity which will improve the web experience of the user drastically. One has to wonder when an advertisement has improved the experience of its audience. Most of the time, online advertisements (just like their offline counterparts) are unwelcome at worst and informative at its best. But one struggles to see how they can stretch to improve the experience per se. The inflation of the experience as well as the constant use of the phrase 'protection of users` privacy' on the Phorm website, is a clear design by the company to hide the true nature of the surveillance taking place here.

Basically, Phorm will have equipment at ISPs which track the activities of the end user. Thus, it will note down the URL visited, search terms used and other relevant information. The IP address of the user is not captured, but a cookie with a unique number is installed on the browser of the end user.

The data collected is categorised and used to create the profile of the user. Hence, when the user visits a webpage whose adverts emanate from OIX, s/he is directed to adverts targeted to his/her profile.

BT is apparently considering starting a trial of the service in the near future. There have also been rumours of 'secret trials' having been conducted without the consent/knowledge of the end user.The Information Commission ruled in May that no action would be taken against BT as it was difficult to explain to users what was being done. However, it also ruled that any future use should only go ahead, with the consent of the users. The flaw in this ruling is quite apparent: surely the inherent difficult in explaining to the end-user what is being done, is still present: so it is very hard to understand how the nature of the difficulty has evolved so that now an explanation is more feasible.

The dangers inherent in this initiative (breach of privacy, breach of data protection etc) are very much apparent and it is very hard to see how the Government will be able to persuasively rationalise them. In addition, it is also very difficult to see the Commission approving of such a scheme. However, in the meantime, this does not put a stop to the launch of the Phorm initiative by the ISPs in the UK, which of course means that the end-user will be incredibly vulnerable until the Commission reaches a decision. A far better option, would have been to ask the ISPs not to launch this initiative until the Commission`s findings.
Disclaimer: This image is subject to copyright. Click here to access original image.

16 July 2008

Is the silver lining in the cloud hanging over YouTube no more than a silver thread actually?

It appears from the website of the Electronic Frontier Foundation that Viacom has formally responded to the concerns of the EFF in relation to the nature of the silver lining reported in the last post.

The EFF was concerned that the agreement between YouTube and Viacom in relation to the disclosure of the data of users of YouTube was not backed up by a court order. The obvious danger with that is that both parties can alter the agreement at a later date.

Viacom has now informed the EFF that the latter will be notified in advance if the agreement is to be amended so that the EFF can either discuss its concerns with YouTube and Viacom or raise more formal objections in Court.

Viacom has also forwarded a draft Protective Order to the EFF. CyberPanda agrees with the EFF that it is crucial that the scope and nature of the disclosure of the data should be formally defined by a court order. It is undeniable that Viacom has shown a lot of goodwill in this matter. Nonetheless, it will be in the best interests of the data subjects if the disclosure was more formally regulated by a Court order. That will breach the gap between the silver thread and the silver lining.

15 July 2008

The silver lining in the cloud hanging over YouTube.

Users of YouTube and indeed YouTube itself will, no doubt, be relieved that Viacom has now agreed for YouTube to handover the viewing history of its users without handing over any data that might enable Viacom to actually identify the specific user.

This is a welcome development which will no doubt be applauded by privacy activitists and users of YouTube as well since the original demand would have undoubtedly raised serious privacy concerns.

This is however a very tiny silver lining in the big cloud hanging over YouTube as the copyright infringement lawsuit is all but over.