French Gathering of Global Govt & Bus Leaders Focus on Privacy

 

By Chris Wolf, FPF Founder and Co-Chair

On October 21st, I was invited by the French Minister for Industry, Energy and the Digital Economy, Eric Besson, to participate in a seminar on the future of the Internet in Paris. The privacy session was entitled “Reconciling the Internet business model and respect for privacy” and billed as follows:

Since the appearance of data processing tools more than four decades ago and the introduction of personal data files, States have acquired both tools and organizational structures in order to protect their citizens’ privacy. These include strict legal and regulatory frameworks, guidelines (like those of the OECD), the appointment of privacy-protection authorities, and the development of “privacy by design” technologies and applications.

Moreover, the use of personal data is a complex issue today, given the number of intermediaries involved in an Internet-based transaction, and given the arrival of cloud computing. Cross-border flows of personal data are today widespread, given the global nature of the Internet.

These shifts are overturning the relationship between personal data held by individuals and organizations. Given these challenges and conflicting interests, we need to strike the right balance between the right to privacy and the Internet’s business model.

How can we give individuals permanent control over their personal data on the Internet, particularly given the explosion in the use of social networks, without hampering the growth of the digital economy? What are the best practices to avoid using personal data for commercial purposes, without individuals’ consent? What initiatives can be taken in terms of international cooperation?

I was asked to be the first intervener following a presentation by this panel of government officials and business representatives:

Simon Kennedy, Vice—Minister for Industry – Canada

Igor Shchegolev, Minister of Communications and Mass Media – Russia

Yong Sup Shin, Commissioner, Korean Communications Commission

Ed Vaizey, Minister of Culture , Communications and Creative Industries – United Kingdom

Esko Aho, Executive Vice-President, NOKIA

Simon Davies, PRIVACY INTERNATIONAL

Herman Heunis, Founder and CEO , MXit

Denis Jacquet, Chairman, YATEDO

Elliot Schrage, Vice-President of Global Communications, Marketing and Public Policy, FACEBOOK

Moderator: Shrrry Contu, UK-based Entrepreneur

The government officials uniformly stressed the need for a light regulatory touch (what former Finland Prime Minister and NOKIA representative called “smart regulation”).   Still, there were repeated references to the need for businesses to adopt self-regulation and follow principles of Privacy by Design (the concept originated by Ontario DPA Ann Cavoukian and highlighted at the conference by the Canadian Minister). The Russian Minister expressed his government’s commitment to Internet privacy.  M. Jacquet stressed the importance of consumer education.  Elliot Schrage highlighted the granular tools available to Facebook users to control their data, and the fact that Facebook does not share personal data with third parties.  The other industry representatives highlighted some of their best practices.  And Simon Davies of Privacy International sounded the only slightly negative note of the panel, questioning whether Privacy by Design was more than just a slogan, and challenging Facebook on its privacy protection.

Notably, one of the more important policy questions on the agenda, “What initiatives can be taken in terms of international cooperation?” was addressed only in passing.

Thus, when I was called upon, I praised the panel for highlighting the importance of sharing best practices and for recognizing the role of limited regulation combined with private sector responsibility. Still, I urged the panel and the few Data Protection Authority representatives in the audience, mostly from the French DPA — the CNIL, to focus more on the convergence internationally in privacy protection and less on the differences in national frameworks.  I mentioned how Fair Information Practice Principles, reflected in the OECD guidelines, underlie all modern privacy protection regimes.  And I mentioned how concepts of Privacy by Design, Codes of Conduct, Accountability, cross-border enforcement, the rise of the Chief Privacy Officer profession and the international sharing of best practices (such as data breach notifications and new ways to notify and empower consumers) were far more important in an interconnected/cloud computing world than the perceived superiority of a national framework.  Finally, I noted the extreme cost that framework superiority rules impose on businesses in countries deemed not to have the identical protections as a national framework, and that the cost ultimately is borne by consumers.

 

EuroPriSe Expert Workshop, November 2011

Participate in the EuroPriSe Expert Workshop held on Nov. 23-25 and acquire the skills necessary to compose a EuroPriSe Evaluation Report and qualify as a EuroPrise Privacy Expert. International privacy experts are invited to take the certification exam to receive the accreditation to become expert reviewers. EuroPriSe is a government-backed European privacy seal; an initiative of the data protection authority of Schleswig-Holstein (ULD), Germany. Register here.

Jules Polonetsky’s KRLD Radio Interview on Online Privacy

On Tuesday October 18, FPF’s Jules Polonetsky spoke with Mitch Carr from KRLD Radio broadcasting out to Dallas and Fort Worth, Texas about online privacy and the current state of Do Not Track. Please click here to listen to the clip.

December 5th Privacy Conference

The Future of Privacy Forum Presents

Personal Information: The Benefits and Risks of De-Identification

On December 5, 2011, leading academics, advocates, Chief Privacy Officers, legal experts and policymakers will gather to discuss and debate the benefits and risks of de-identification and the definition of personal information. Please join us for this discussion of one of the most central issues for the future of privacy, data use and innovation.

Please click here (link expired) to register to attend in person or receive log-in information for our live-blog and twitter feed.

Where:

The National Press Club

Murrow Room

529 14th Street, NW

Washington, DC 20045

Agenda:

9:00 – 9:30 am – Opening Presentation: How is De-Identified Data Used: Overview of the ways de-identified data is used in the areas of health, marketing, traffic management, and fraud.

9:30 – 10:30 am – Panel 1: What are the Risks? De-Identification and Re-Identification Risk Analysis.

Panelists:

Moderator: Kim Gray, Chief Privacy Officer, IMS Health

10:30 – 11:30 pm – Panel 2: Common Secondary Uses of De-Identified Data: How are companies or governments using data? What are the Benefits? How are the Risks Being Handled Today?

Panelists:

Moderator: Marcy Wilder, Partner, Privacy and Information Management, Hogan Lovells

11:30 – 12:30 pm – Panel 3: Data Use for Consumer Services

Panelists:

Moderator: Lance J. Hoffman, Distinguished Research Professor, Computer Science Department, Director, Cyber Security Policy and Research Institute, The George Washington University

12:30 – 1:30 pm – Keynote Luncheon with The Honorable Louis W. Sullivan, MD, Former Secretary, U.S. Department of Health and Human Services

1:30 – 2:30 pm – Panel 4: Advertising and Marketing Uses and Concerns

Panelists:

Moderator: Jules Polonetsky, Director and Co-Chair, Future of Privacy Forum

2:30 to 3:30 pm – Panel 5: Legal Perspectives on Anonymization

Panelists:

Moderator: David Hoffman, Director of Security Policy and Global Privacy Officer, Intel

Special Thanks to our Partners:

*This is a preliminary program and is subject to change.

No fee to attend, but advance registration is required. Space is limited, so register now!

For questions, email [email protected].

More Companies Need to Get on the Privacy Bandwagon

FPF Co-chairs Chris Wolf and Jules Polonetsky presented today at the Online Trust Alliance (OTA) Forum. Wolf moderated the panel, “View from the Hill; Legislation Landscape & Regulatory Concerns- Looking into the Crystal Ball.” The panel captured the view that while there will most likely be no privacy and data stewardship legislation this year, self-regulatory organizations certified by the FTC may play a greater role. In a separate panel on competing best business practices, Justin Brookman, Director at the Center for Democracy & Technology (CDT) advocated for baseline privacy legislation based on the notion that “without standards, it is really hard for companies to compete on privacy.” “There should be industry wide standards. We can’t expect any one actor to be the good guy,” Brookman said. Fran Maier, President of TRUSTe, stated that the current standard is similar to a “carrot and stick approach,” where the threat of the stick through compliance efforts has motivated positive changes in the industry. “But, there are still a lot of companies that haven’t been taking initiative,” she said.

Controlling Your Reputation in a World that Holds No Secrets

Please click here to read a piece by FPF’s Christopher Wolf on the steps consumers can take to protect their online reputation.

FTC Says Significant Steps Made For DNT- Still Work To Be Done

FTC Commissioner Julie Brill spoke at the Online Trust Alliance (OTA) Forum today and noted that the “industry has really stepped up to the plate” since the Commission released its Staff Report in Dec. 2010. Since the Report, browser companies including Microsoft, Mozilla, and Apple have implemented different models of Do Not Track. On the advertiser side, the Digital Advertising Alliance (DAA) has launched a self-regulatory program that uses a cookie-based Advertising Option Icon. “We are looking to see how effective they [industry responses] are and how easy it is for consumers to use these mechanisms,” said Commissioner Brill. She does not believe “we’re going to see a vast exodus of consumers from current Web sites or opting out of the way their information is used.” “Some consumers are going to want relevant ads.” “I don’t see this as a toggle switch- on or off,” but rather “a place where consumers can choose through a dashboard mechanism what they want to do.” She further stated that the World Wide Web Consortium (W3C) Tracking Protection Working Group is working around issues like “what does tracking mean” and other technical issues. “These are all incredibly positive developments, but it is still a work in progress.”

MMA Releases Privacy Policy Guidelines for Mobile Apps

The Mobile Marketing Association (MMA) released a mobile app model privacy policy document on Monday for public comment. “The guidelines are intended to provide ways to give the mobile application developer with clear and transparent policy language that can be quickly and completely understood by the consumer,” said MMA Global CEO Greg Stuart. Read more about the Guidelines here.

PrivacyChoice Launches New Resource Center for App Developers

PrivacyChoice CEO and FPF Advisory Board member Jim Brock announced a new privacy resource center for app developers at today’s Online Trust Alliance 2011 Forum. Features include PrivacyChoice’s Policymaker tool, sample templates, code resources, and other guidance. Read more about the center here.

The State of Mobile: The What and Where of Mobile Privacy

FPF Director and Co-chair, Jules Polonetsky presented along with other leading industry professionals at the OTA Forum Workshop titled, “The State of Mobile: The What and Where of Mobile Privacy. Redefining the role of business and industry.” Jules Polonetsky highlighted some of the issues with having mobile privacy policies. “Is anyone actually eager to read a long mobile privacy policy?” “One way or another we have to communicate to users how data will be used,” said Jim Brock, President and Founder of PrivacyChoice, who recently released PrivacyChoice Policymaker for mobile apps and sites, a tool that summarizes to users how data is used in less than eighteen syllables. Justin Brookman, Director, Center for Democracy & Technology (CDT), responded that there should still be a place where the entire privacy policy is discoverable, as it is probably hard to explain the full extent to which data is used in such a tool.

“UDID [Unique Device Identifiers] is not the concept of personal information that most people have. Having a unique identifier has some real advantages,” said Morgan Reed, Executive Director, Association for Competitive Technology (ACT). For example, an educational app can inform invested parties such as parents and teachers when a child completes his homework or how to restore data from an app that was accidentally deleted. Polonetsky added that more responsible networks are hashing the UDID and offering consumers a choice of opting out.

“It is important to remember that this whole industry has only existed since 2008. Advertising in mobile apps is less than 24 months old,” stated Reed. Given that apps are so recent, he stressed that the app industry needs a chance to experiment and even make some mistakes in order to fully realize the business model and potential for growth.