Commerce Department Privacy Report
Chris provides a great summary of the Commerce Department Privacy report over here at the Hogan privacy blog.
Chris provides a great summary of the Commerce Department Privacy report over here at the Hogan privacy blog.
Chris participated in an interview presentation with Peter Hustinx, European Data Protection Supervisor, while in Europe for the IAPP Privacy Congress is Paris last week. Take a look at his blog post with a recap of his observations.
EU Data Protection Supervisor’s Interview at Hogan Lovells London
European Data Protection Supervisor Peter Hustinx traveled in frigid, snowy conditions from Brussels to London on 2 December for an interview presentation at the London Offices of Hogan Lovells attended by lawyers from the Hogan Lovells global Privacy and Information Management Practice as well as clients and friends of the firm.
Please find guest post below by Monique Altheim, Esq., CIPP, an EDiscovery and Privacy attorney. Also, be sure to check out her other writings on eDiscoveryMap.com!
The International Association of Privacy Professionals’ First Europe Data Protection Congress
By: Monique Altheim
I recently attended the International Association of Privacy Professionals’ (IAPP) very first Europe Data Protection Congress in Paris on November 29 and 30.
The attendee list was impressive:
The timing of this conference could not have been more opportune, as it took place in the wake of a ground breaking Communication by the European Commission on November 4, announcing a global overhaul of the current EU Data Protection framework.
In this communication, the European Commission announced that fifteen years after the original 1995 Data Protection Directive was enacted, the original twofold objective of protecting the fundamental right to data protection as well as of achieving the free flow of data in the internal European market is still valid.
However, two factors have caused the 1995 Directive to have become too outdated to guarantee these two objectives : The rapid technological advances and the globalisation in the ways information is collected, stored and transferred.
These dramatic changes were reflected in some of the topics debated during the breakout sessions:
This panel, presided over by Ruth Boardman, partner at Bird & Bird, stressed the fact, that for once the European Union had been inspired by the US initiatives in Breach Notification Legislation.
Again, it is the exponential growth in personal data holdings and the increased outsourcing of data to third countries and to the “cloud” that have caused increased data breach scandals and have required changes in the Directive. Some EU member states, like Germany, already have enacted a national general data breach law (Section 42 a FDPA- September 2009), but most others will have to implement their national laws once the new legal framework is in place.
Other important suggestions for consideration in reframing the Directive by the Commission are : The right to be forgotten, Privacy by Design, greater transparancy in internet related data collections, data portability rights, achieving more harmonization among the vastly different implementaions into national laws by the member states, the requirement of mandatory privacy officers in companies and organizations, the requirement of privacy impact assessments upon introducing new systems and technologies in companies and organizations, and strengthening as well as harmonizing enforcement of the Directive.
Concluding the panel on the revision of the 1995 Directive, Henriette Tielemans of Covington & Burling asked the European Commission representative Thomas Zerdeck: “Will the new baby be a directive or a regulation?” to which Thomas, in his usual style, replied: “This is way too complex. You will find out in 2011.”
The European Commission has opened a public consultation period (from November 4, 2010, to January 15,2011) to obtain views on its ideas for addressing new challenges to personal data protection in order to ensure an effective and comprehensive protection to individuals’ personal data within the EU.
They welcome contributions from citizens, organisations (i.e., Non-Governmental Organisations, businesses) and public authorities.
Thus all stake holders have a chance to be part of this sweeping overhaul of the European Union Data Protection framework.
http://ec.europa.eu/justice/news/consulting_public/news_consulting_0006_en.htm
Jules Polonetsky, the co-chairman and director of the Future of Privacy Forum, said users would most likely decide to use lists published by Web sites they trusted instead of creating their own, adding that most people would likely ignore the option all together.
“The average user is not going to have a list of 500 ad networks and 600 analytics companies,” Mr. Polonetsky said. “They end up relying on a privacy watch dog to give them a do-not-track list that the browser will respect.
Jules Polonetsky, former chief privacy officer for AOL Inc. and online ad network DoubleClick, which is now owned by Google Inc., said that while most consumers probably won’t use the new Internet Explorer features, they will likely appeal to people who are concerned about online privacy.
The Digital Privacy Forum will take place January 20, 2011 at the New Yorker Hotel in New York City.
Register by December 15 for the early-bird rate!
In case you were unable to join us for the December 1 “Do Not Track” Demystifed event, below is a link of the event’s audio recording. Forgive the white noise in the beginning (fast-forward about 10 minutes.)
Read Chris’ and Jules’ op-ed, featured on CNN.com, here: “Techies, not lawmakers, can curb online tracking.”
POLITICO featured Chris’ and Jules’ op-ed titled, “Time to double team on Internet privacy,” on its website today. The piece encourages the agencies, businesses and consumer advocates to come to an agreement in order to successfully find a solution for online privacy.
| FOR IMMEDIATE RELEASE: | Media Contact: Ted Kresse |
| December 1, 2010 | 202.777.3719 |
| [email protected] |
Future of Privacy Forum Releases Statement on Federal Trade Commission’s Privacy Report
WASHINGTON – Today, the Federal Trade Commission released their preliminary staff report on “Protecting Consumer Privacy in an Era of Rapid Change: A Proposed Framework for Businesses and Policymakers.” The Future of Privacy Forum (FPF) released the following statement in response to the report. This statement should be attributed to Jules Polonetsky and/or Christopher Wolf, co-chairs of the Future of Privacy Forum:
“Today’s FTC report identifies the most pressing privacy issues facing consumers today. The report raises a number of questions for public consideration and input; indeed, it raises more questions than it answers, which is understandable given the complexities. The Commission correctly recognizes that the current framework needs to be updated to reflect consumers’ ongoing concerns about how their data is being collected and used. By focusing on key issues such as Privacy By Design, employee training and consumer education the Commission lays out the foundation that needs to exist for any company to successfully deliver on its privacy promises. A key focus of the report is the failure of current privacy policies and notices that are provided to consumers. We applaud the Commission’s focus on the need for and testing of new types of notices to ensure their effectiveness.
As we have previously noted, the current cookie based opt-out system is ineffective in managing consumer choices. Rightly, the Commission calls for a better system for users to be able to control online data collection. The Commission was widely expected to call for legislation of a Do Not Track mechanism, but wisely left the door open to either legislative or self regulatory solutions. The industry should act quickly to explore and implement a Do Not Track mechanism that both supports responsible advertising practices and enhances consumer controls and choices.”
Later this afternoon the Future of Privacy Forum will hold an event entitled ‘Do Not Track’ Demystified, which will feature individuals from across the government, business, advocacy and academic arenas, discussing the merits, flaws, and technological capabilities of a ‘Do Not Track’ mechanism. To learn more about the event visit: fpf.org
The Future of Privacy Forum (FPF) is a Washington, DC based think tank that seeks to advance responsible data practices. The forum is led by Internet privacy experts Jules Polonetsky and Christopher Wolf and includes an advisory board comprised of leading figures from industry, academia, law and advocacy groups.
###