The FAA released rules for the operation of commercial drones
This morning, the Federal Aviation Administration (FAA) released the highly anticipated rules governing the operation of small UAS (sUAS) for commercial purposes. The new rules are scheduled to take effect in late August – until that time, commercial operators may continue to operate under Section 333 exemptions. As expected, Part 107 generally follows the proposed rules that were contained in the Notice of Proposed Rulemaking (NPRM) that was issued by the FAA in February 2015.
One of the most significant changes for industry is that commercial operations that fit within the framework of Part 107 will no longer require approval by exemption, which has typically taken months to secure. Undoubtedly, the new framework will mean increased efficiency for commercial operators who will also not be required to secure airworthiness certification for their sUAS.
Samsung Electronics Vice Chairman Traveling to the United States for Internet of Things – Transforming the Future Conference
* * * MEDIA ALERT & INTERVIEW AVAILABILITY * * *
Samsung Electronics Vice Chairman O.H. Kwon to Host June 21st Inaugural Internet of Things – Transforming the Future Conference
in Washington, DCVice Chairman Traveling to the United States to Make Important Announcements About Samsung’s Vision for the Internet of Things
WHAT:
On June 21, 2016, Samsung will host its inaugural “Internet of Things – Transforming the Future” conference at the Washington Post, during which the company will lay out its vision for a human-centered approach to the Internet of Things (IoT) that focuses on the outcomes the technology will create for people and societies across the globe. As IoT is the connective tissue that brings the physical and digital world together into a system for smarter living, Samsung is hosting the event and convening leaders from government and industry to ensure that the rapid expansion of IoT benefits everyone, everywhere through the transformative power of innovation. The Washington, DC event will be the beginning of an international series of dialogues on IoT.
WHEN:
Tuesday, June 21, 2016
8:00 AM – 11:30 PM
WHERE:
The Washington Post Building
1301 K Street NW
Washington, DC 20071
WHO:
Doug Davis, Senior Vice President and General Manager, Internet of Things Group, Intel Corporation
Dean Garfield, President and CEO, Information Technology Industry Council (ITI)
John Godfrey, Senior Vice President for Government Affairs, Samsung Electronics America
Congressman Darrell Issa (R-CA)
Wonkyong Kim, Executive Vice President for Government Affairs, Samsung Electronics America
Oh-Hyun Kwon, Vice Chairman and CEO, Samsung Electronics
Jules Polonetsky, CEO, Future of Privacy Forum
Curtis Sasaki, Vice President of Ecosystems and IoT General Manager, Samsung Strategy and Innovation Center (SSIC) and more.
Join the conversation on Twitter at #VisionForTech Stay informed: @SamsungDC
CONTACT:
For interview requests or live-stream link for reporters unable to travel to Washington, DC please contact Alex Mitchell, 202-772-6965, [email protected]
From accessibility and aging in place to smart cities and global transportation, IoT has the power and potential to truly transform the world in which we live. The half-day Samsung event will bring together leading consumer, industry and government stakeholders to discuss the many ways IoT can benefit society, and tackle the challenges that remain. Following the Vice Chairman’s keynote speech, the conference will feature multiple panels engaging in a cross-sector dialogue about IoT technology and the path forward. The keynote and panel discussions are OPEN PRESS for credentialed media.
###
Examining Ethics, Privacy, and Research Reviews
Today, the Future of Privacy Forum (FPF) and the Ohio State University’s Program on Data and Governance are holding a discussion of ethics, privacy and practical research reviews in corporate settings. This timely event, which follows the White House’s call to develop strong data ethics frameworks, convened corporate and academic leaders to discuss how to integrate ethical and privacy considerations into innovative data projects and research. The roundtable is an important extension of FPF’s December 2015 workshop, “Beyond IRBs: Designing Ethical Review Processes for Big Data Research,” supported by the National Science Foundation and Alfred P. Sloan Foundation.
A major focus of the roundtable is a new paper by Facebook’s Molly Jackman and Lauri Kanerva entitled, “Evolving the IRB: Building Robust Review for Industry Research.” The paper provides a detailed overview of the company’s research review process. Informed by consultations with a wide range of experts, the Facebook process details the specifics steps taken by the company to review its internal research work and is an important step forward for corporate research ethics.
“Developing meaningful processes and standards for ethical reviews of data research is one of the critical challenges companies face today,” said Jules Polonetsky, CEO, Future of Privacy Forum. “Socially valuable advances will only be feasible if trustworthy paths are established for academic and corporate researchers alike. Kanerva and Jackman’s paper documenting the Facebook research process provides researchers with a valuable model for serious evaluation of the benefits and risks of new projects.”
Advancing Knowledge Regarding Practical Solutions for De-Identification of Personal Data: A Call for Papers
De-identification of personal information plays a central role in current privacy policy, law, and practice. Yet there are deep disagreements about the efficacy of de-identification to mitigate privacy risks. Some critics argue that it is impossible to eliminate privacy harms from publicly released data using de-identification because other available data sets will allow attackers to identify individuals through linkage attacks. Defenders of de-identification counter that despite the theoretical and demonstrated ability to mount such attacks, the likelihood of re-identification for most data sets remains minimal. As a practical matter, they argue most data sets remain securely de-identified based on established techniques.
There is not agreement regarding the technical questions underlying the de-identification debate, nor is there consensus over how best to advance the discussion about the benefits and limits of de-identification. The growing use of open data holds great promise for individuals and society, but also brings risk. And the need for sound principles governing data release has never been greater.
To help address these challenges, the Brussels Privacy Symposium, a joint program of FPF and the Brussels Privacy Hub of the Vrije Universiteit Brussel (Free University of Brussels or VUB), is pleased to announce an academic workshop and call for papers on Identifiability: Policy and Practical Solutions for Anonymization and Pseudonymization. Abstracts are due August 1, 2016, with full papers to follow on October 1, 2016.Selected papers will be considered for publication in a special symposium of International Data Privacy Law, a law journal published by Oxford University Press. In addition, authors will be invited to present at a workshop titled Identifiability: Policy and Practical Solutions for Anonymization and Pseudonymization in Brussels on November 8.
Authors from multiple disciplines including law, computer science, statistics, engineering, social science, ethics and business are invited to submit papers for presentation at a full-day program to take place in Brussels on November 8, 2016.
Submissions must be 2,500 to 3,500 words with minimal footnotes and in a readable style accessible to a wide academic audience. Abstracts must be submitted no later than August 1, 2016, at 11:59 PM ET, to [email protected]. Papers must be submitted no later than October 1, 2016, at 11:59 PM ET, to [email protected]. Publication decisions and workshop invitations will be sent in October.
Protecting the Privacy of Customers of Broadband and Other Telecommunications Services
The Future of Privacy Forum filed comments with the Federal Communications Commission (FCC) in response to the FCC’s proposed rules regarding the privacy and data practices of Internet Services Providers (ISPs). The FCC’s March 31, 2016 Notice of Proposed Rulemaking (NPRM or Notice) seeks to regulate ISP’s data practices pursuant to Section 222 of the Communications Act – a sector-specific statute that includes detailed requirements that apply to telecommunications services, but does not apply to other services offered by broadband providers nor to online services operating at the edge of the network (e.g. web sites).
The FCC’s notice states that responsible data practices protect important consumer interests. FPF wholeheartedly agrees. Because de-identification of personal data plays a key role in protecting consumers’ privacy, one portion of our comments seeks to ensure that the final FCC rules are consistent with the leading current thinking and practices regarding de-identification.
The FCC’s proposed rules erroneously treat data as either fully de-identified or fully identifiable. FPF’s comments urge the FCC to issue a rule recognizing that de-identification is not a black and white binary, but rather that data exists on a spectrum of identifiability. FPF’s comments take particular note of the Federal Trade Commission’s (FTC) extensive guidance regarding de-identification. According to the FTC, data are not “reasonably linkable” to individual identity to the extent that a company: (1) takes reasonable measures to ensure that the data are de-identified; (2) publicly commits not to try to re-identify the data; and (3) contractually prohibits downstream recipients from trying to re-identify the data. Industry self-regulatory guidelines use similar approaches. The FTC and self-regulatory frameworks recognize that data is not either “personal” or “non-personal.” Instead, it falls on a spectrum; with each step towards “very highly aggregated,” both the utility of the data and the risk of re-identification are reduced.
FPF’s comments argue that the proposed FCC rules reflect a rigid binary understanding of personal information that does not align with the spectrum of intermediate stages that exist between explicitly personal and wholly anonymous information. As a result, the FCC rules are simultaneously too narrow and too broad, both excluding and including data uses that should be permitted subject to reasonable controls and safeguards. In independent comments, FTC staff agree, stating “the [FCC’s] proposal to include any data that is ‘linkable’ could unnecessarily limit the use of data that does not pose a risk to consumers. While almost any piece of data could be linked to a consumer, it is appropriate to consider whether such a link is practical or likely in light of current technology. FTC staff thus recommends that the definition of PII only include information that is ‘reasonably’ linkable to an individual.”
FPF therefore proposes an alternative approach, which recognizes that non-aggregate data can be de-identified in a manner that makes it not reasonably linkable to a specific individual. This approach is consistent with leading government and industry guidelines with respect to de-identified data, including key work by the Federal Trade Commission, and is illustrated by FPF’s Visual Guide to Practical De-Identification.
June 22nd Webinar: PII Cookies and De-Identification – Accounting for Shades of Grey
PII, Cookies, and De-Identification – Accounting for Shades of Grey
Broadcast Date: June 22, 2016
Time: 1:00 – 2:30 pm ET
IAPP members: $159
Nonmembers: $179
Are tracking cookies personally identifiable information (PII)? What about IP addresses, MAC addresses, or mobile advertising identifiers — are they personal data, or can they be described as anonymous? EU laws, as well as HIPAA and COPPA in the U.S., have labeled these identifiers personal in many cases. Yet in most privacy policies, it remains widespread practice to describe these kinds of data points as “non-personal” or “anonymous.”
Despite a broad consensus around the need for and value of de-identification, one of the biggest challenges in the privacy profession remains how to determine when data is, or is not, de-identified. Join us for this in-depth discussion on how and when privacy professionals, industry groups, and regulators around the world have tackled this thorny question.
The panel will also explain and examine a recent effort by the Future of Privacy Forum to categorize data into a spectrum of identifiability, and make time to take your questions. You’ll hear us discuss how to create incentives for organizations to avoid explicit identification and to deploy elaborate safeguards and controls, while at the same time allowing data sets to maintain their utility.
What you’ll take away:
• A better understanding of current definitions of PII in varying environments and for different usages.
• Guidance on developing policy to effectively de-identify data sets, and under what circumstances.
• How current regulatory regimes are defining PII, and how that may change moving forward
• An understanding of the new Future of Privacy Forum’s data categorization tool, and how you could use it within your organization
Moderator:
Kelsey Finch, CIPP/US, Policy Counsel, Future of Privacy Forum
We are pleased to present this guest post from Prof. Lokke Moerel, a leading EU privacy lawyer. We think her blog and paper are fascinating and important contributions to the current discussion of key privacy topics, including big data, the Internet of Things, and EU data protection laws.
Let us imagine a mobile phone application that traces your movements and phone calls in order to inform you whether you are likely to catch influenza. The app can even tell you which friends you should avoid in order to minimize your risk of catching the flu – even if those friends have not yet been affected by it themselves (this is not fiction, see research of MIT Professor Alex Pentland). Would you install this application on your smartphone as soon as you had the chance? Then imagine the use of a similar app by the World Health Organization, in order to protect public health during pandemics. Two applications that both collect and process personal data for the same purpose: the monitoring and personalized prediction of health and illness. But the sentiments that these two applications give rise to are likely very different.
When we pause to reflect on this, the conclusion is that it is not so much the purposes for which personal data might be used that are the primary consideration here, but rather the interests that are served by the use of the data collected. And yet, both the current and the upcoming EU data protection regime are based primarily on the purpose for which data are collected and processed, while the interests served play a much more subordinate role. This raises the question of whether this legal regime can be effective and can be considered legitimate as we move into a future whereby society is driven by data.
In my paper with Prof. Corien Prins: “Privacy for the homo digitalis: Proposal for a new regulatory framework for data protection in the light of Big Data and the Internet of Things,” we analyze innovations in data processing as a result of developments such as big data and the Internet of Things and discuss why these developments undermine the effectiveness and legitimacy of the current as well as upcoming EU data protection regime, thereby focusing on the private sector. The paper includes a detailed analysis of key data processing principles used in the European data protection regime (purpose limitation, informational self-determination and data quality) and argues that due to social trends and technological developments, the principle of purpose limitation should be abandoned as a separate criterion. Also, other principles (such as consent and the performance of an agreement) should no longer be recognised as grounds that play a role on their own in legitimizing data processing. Instead, we propose a single test: whether there is a legitimate interest for the whole life cycle of personal data processing (collection, use, further use and destruction of data). We argue that such a test will provide for a more effective data protection regime that will have more legitimacy than the assessment under the existing legal regime that is primarily based on the purposes for which data may be collected and further used. This test has been drafted in such a way that it enables companies to comply with the new requirements under the upcoming EU General Data Protection Regulation, which will become effective in 2018. We conclude our analysis with proposals to increase the effectiveness of enforcement of the data protection rules.
June 28th Event: Ensuring Individual Privacy in a Data Driven World
Criteo and The Future of Privacy Forum are pleased to invite you to an exceptional conference gathering a very high-level selection of regulators, lawyers, advertisers, publishers and politics to discuss about individual privacy in a data driven world.
You will get valuable insights from Axelle Lemaire (French government), Jean-Baptiste Rudelle (Criteo), Jurgen Van Staden (NAI), Gwendal Le Grand (CNIL) and other speakers.
Save the date for Tuesday, June 28th from 09:00 to 18:00.
The Benefits, Challenges, and Potential Roles for the Government in Fostering the Advancement of the Internet of Things
Yesterday, the Future of Privacy Forum filed comments with the National Telecommunications and Information Administration (NTIA) in response to NTIA’s inquiry into the Internet of Things (IoT). NTIA asked policy experts and other stakeholders to identify key issues affecting deployment the IoT – a broad category of devices, appliances, and objects that can be connected via the Internet. The Internet of Things has been a focus of FPF’s work since our founding in 2008. FPF recognizes the enormous potential benefits to consumers and to society of the inter-connected applications offered through the Internet of Things.
FPF’s comments, “The Benefits, Challenges, and Potential Roles for the Government in Fostering the Advancement of the Internet of Things,” describe the privacy and security challenges presented by IoT technologies, as well as the enormous potential benefits to consumers and to society of the inter-connected applications offered through the Internet of Things. FPF urges NTIA to promote the use of IoT data in ways that will benefit disadvantaged populations and promote inclusion. Our comments highlight IoT technologies that offer direct, meaningful benefits for individuals who are elderly, infirm, visually impaired, deaf, living with chronic health conditions, suffering from mobility-related disabilities, or economically disadvantaged. Today, IoT technologies are improving the day-to-day quality of life of traditionally underserved groups:
Sensors can alert relatives when a family member fails to take medicine, eat, or return home from a walk.
IoT devices in hospitals can track when patients get in and out of bed, help prevent falls, monitor clinical roundups to ensure that clinicians check in on patients at least once per hour, and revolutionize the protocol for preventing and treating painful pressure ulcers.
Wearable video cameras can translate text to audio in real time, providing crucial assistance to the visually impaired.
Smart home technologies allow users to control things in his or her home that may be physically difficult to reach, such as lights, door locks or security systems.
M2M technology, integrated with new payment platforms, is expanding access to credit by enabling two new payment methods: pay-as-you-go asset financing, which allows consumers to pay for products over time, and prepaid, where consumers pay for services on an as-needed basis.
Emerging IoT technologies promise to broaden inclusiveness for traditionally underserved groups in the immediate future. Common sense privacy protections can build trust in IoT technologies and help ensure that consumers enjoy the full benefits of IoT sensors and devices.
Today, Google announced new features that provide users with additional customized options and controls over personal data, as well as easy-to-follow instructions and notifications that explain users’ choices in simple terms. The new features make privacy controls quicker to find and easier to understand and operate. For example, the changes make Google’s privacy controls more accessible via web search and voice commands; users are increasingly relying on search and voice to quickly get important information and operate mobile devices.
FPF is committed to advancing responsible data practices, including design techniques that create practical, usable tools that help consumers access and control personal data. Part of using data responsibly means going beyond just posting privacy policies; it should also mean putting the same effort that goes into making a product user friendly into making privacy and data-related functions easy to find and understand. When these attributes meet, consumers win with well-designed, user-friendly privacy settings and controls.
FPF has long talked about the need for companies to compete on privacy. We strongly support signs like Google’s new features that show how the market for privacy tools is growing. The biggest advances for consumers – privacy tools that consumers most want and use – are increasingly being driven by consumer demand and market competition.
The new Google features are additions to the company’s “My Account” – the hub Google created last year to give users a quick and easy way to safeguard their data and protect their privacy throughout Google accounts. “My Account” put these privacy and security tools in one place, simplifying users’ making it easy for the user to understand and select clear privacy settings from any one of their devices, to control settings across all their devices.
Now, it is easier than ever to find the access controls. From any device, signed-in Google users can simply search their name, and see a shortcut to the My Account hub. This interaction leverages the fact that people rarely remember where the account settings are in different programs – they are increasingly searching for options rather than using menus. Showing My Account atop Search – and linking to the options directly – promotes the functions that let people easily get to important information. Users follow this process for flights, to track package delivery, and to review payment accounts, so why not make account and privacy info and options just as easy and responsive?
In addition, Google offers a voice option to get to My Account. Voice controls are an increasingly important interface for mobile functions – to launch apps and to access options buried within apps or sites – so it is great to see voice controls that get you directly to privacy and security features on an account that is used across every device you have. According to Google, a user can simply say, “Ok Google, show me my Google account,” and it takes take the user there.
Finally, “find your phone” is a new feature that will help locate a phone that has been lost or stolen. Phones hold some of our most sensitive data: personal texts, family photos, work emails, financial information, and more. Millions of phones are lost or stolen every year. When users first first realizd their phone is missing, it’s easy to panic and not always easy to know what to do next. Now, a user can locate and lock their phone, as well as secure their account and leave a callback number on the screen.
These updates are a major step forward for practical, usable design in the privacy field. It is encouraging to see leading design principles applied to privacy controls that are available to more than 1 Billion users.