Future of Privacy Forum is Turning 10!

On April 30, 2019 from 6:00 PM – 8:00 PM, we will host a 10th Anniversary Celebration in Washington D.C. — and you’re invited! We are delighted to announce that at the 10th Anniversary Celebration we will present the following awards:

Helen Dixon

Data Protection Commissioner, Ireland

Distinguished Public Service

J. Trevor Hughes

President & Chief Executive Officer, IAPP (International Association of Privacy Professionals)

Community Builder

Dale Skivington

Privacy Consultant and Adjunct Professor of Law, University of Colorado Law School

Former Chief Privacy Officer, Dell Inc. and Eastman Kodak Company

Career Achievement

Peter Swire

Peter Swire

Elizabeth and Tommy Holder Chair of Law and Ethics, Scheller College of Business Georgia Institute of Technology

Outstanding Academic Scholarship

Please note that this is a private event. For additional information and ticket options, please click here.

Additionally, FPF would like to thank the Leadership Sponsors who make this event possible:

Date and Time

Tue, April 30, 2019

6:00 PM – 8:00 PM EDT

Location

The Line

1770 Euclid St NW

Washington, DC 20009

Interested in attending?

Tickets and registration information can be found here. Individual tickets are available for purchase for non-members. Proceeds from ticket sales benefit FPF’s Scholarship Fund, which supports the Elise Berkower Memorial Fellowship and the Christopher Wolf Diversity Fellowship. Can’t attend? Show your support with a monetary contribution of your choice.

Interested in sponsoring?

Sponsorship opportunities are available and may be found here. For additional sponsorship opportunities for the 10th Anniversary Celebration, contact Barbara Kelly, Leadership Director at [email protected].

FamilyTreeDNA Agreement with FBI Creates Privacy Risks

Company’s Deal with Law Enforcement Surprises Consumers and Is Out-of-Step with Industry Norms and Best Practices 

By John Verdi and Carson Martinez

Last week, FamilyTreeDNA announced an agreement with the FBI to allow agents to test DNA samples from crime scenes, develop genetic profiles, and identify familial matches. This agreement marks the first time a prominent private company has agreed to voluntarily provide law enforcement with routine access to customers’ data. Genetic data, properly obtained and analyzed, can help law enforcement solve crimes and improve public safety. However, unfettered law enforcement access to genetic information on commercial services presents substantial privacy risks.

The FamilyTreeDNA agreement is outside industry norms and inconsistent with consumer expectations. FamilyTreeDNA should terminate the company’s agreement with the FBI and take steps to ensure that law enforcement does not access users’ data without appropriate legal process.

Leading genetic testing companies do not turn over consumer data to the government upon request. They require legal process such as a warrant before allowing law enforcement to access genetic data. Constitutional and statutory warrant requirements are longstanding mechanisms that support important values – they can help police solve crimes and protect individuals’ privacy. Warrants are issued based on evidence, typically target a specific individual, and allow a neutral judge to determine whether there is probable cause to suspect that a particular individual is linked to a crime. FBI genetic searches should be predicated on probable cause and conducted pursuant to appropriate process.

FamilyTreeDNA’s agreement is out of step with consumer expectations. Leading genetic testing companies understand that when users send in their DNA to learn more about their health or heritage, they do not expect their genetic data to become part of an FBI genetic lineup. FamilyTreeDNA users have not received a meaningful notice or opportunity to opt-in or opt-out of these searches. If this agreement remains in place and valid legal process is not obtained before access to genetic data is provided to the FBI, individuals may be erroneously swept up in investigations simply because their DNA was found near a crime scene or at a location where a victim or suspect lived or worked. Genetic profiles turned over to the FBI may also be covertly reused by the FBI on other commercial sites.

Furthermore, FamilyTreeDNA’s agreement conflicts with the Privacy Best Practices for Consumer Genetic Testing Services that FPF published last year. At the time, FamilyTreeDNA announced their support of the Best Practices as a clear articulation of how firms should protect consumers’ privacy. The Best Practices state that genetic data should not be disclosed to or made accessible to third parties, in particular to government agencies, except as required by law or with the separate express consent of the person concerned. The Best Practices also require that companies only process DNA samples and genetic data uploaded by the relevant individual, or with that individual’s permission. These are strong protections for sensitive genetic data.

The approach that the FBI would use to identify individuals by sending DNA samples from a crime scene to FamilyTreeDNA for testing and analysis would occur without a warrant. In light of the new agreement, FamilyTreeDNA has been removed as a supporter of the Best Practices.

Law enforcement should obtain a warrant before seeking disclosure of genetic data from companies, and companies should demand valid legal process before disclosing genetic data. Companies should only process DNA samples and genetic information uploaded with an individual’s permission. That way, genetic data can be used to identify suspects and victims – and consumer privacy can be respected.

AI and Machine Learning: Perspectives with FPF’s Brenda Leong



As we prepare to toast our 10th anniversary, we’re hearing from FPF policy experts about important privacy issues. Today, Brenda Leong, FPF Senior Counsel and Director of Strategy, is sharing her perspective on AI and machine learning. Brenda also manages the FPF portfolio on biometrics, particularly facial recognition, and oversees strategic planning for the organization.
Tell us what you think the next 10 years of AI, machine learning and privacy will bring.
Our 10th anniversary celebration will be on April 30. RSVP here.





AI and Machine Learning: Perspectives with FPF’s Brenda Leong





Brenda LeongHow did you come to join the Future of Privacy Forum and work on AI and machine learning privacy issues?






My first career was in the Air Force, and my last two assignments before I retired were at the Pentagon and the State Department. I learned that I really enjoy working on policy, and I decided to explore new policy areas after I retired from the military. I went to law school at George Mason University, where I became very interested in telecom issues and privacy law.






People kept telling me, if you want to work in privacy in Washington, DC, you need to meet Jules Polonetsky. So I went to a policy event and cornered Jules. That led to an FPF policy fellowship and I’ve been at FPF ever since – almost five years.





About a year after I joined FPF, Jules – who is an expert prognosticator – suggested we should learn more about AI because it was becoming a focus of the tech industry, incorporated into autonomous vehicles, facial recognition, advertising tech and a lot of other areas. I jumped at the chance and I’ve been working on AI and machine learning issues ever since.






What’s the difference between AI and machine learning?






That’s a good question, and something we explored in The Privacy Expert’s Guide to AI and Machine Learning, which FPF released last October. Most of what has been implemented is machine learning – algorithms that can evaluate their own output and make adjustments to their code without human involvement. Machine learning is used in image recognition, facial recognition, sensory inputs for autonomous vehicles, and many other tasks.
I like the definition of artificial intelligence by Stuart Russell, who wrote one of the key textbooks in this space:






“An entity is intelligent to the extent that it does the right thing, meaning that its actions are expected to achieve its objectives… This notion of doing the right thing is the key unifying principle of AI. When we break this principle down and look deeply at what is required to do the right thing in the real world, we realize that a successful AI system needs some key abilities, including perception, vision, speech recognition, and action.”





There aren’t yet many real-world applications for classic AI that meet that definition. Real-time language translation and email spam blocking come to mind. By the way, Russell’s quote is from Architects of Intelligence: The truth about AI from the people building it by Martin Ford – the current FPF Privacy Book Club selection. Anyone can join the book club and participate in our discussion on February 27.






What are some of the privacy issues around machine learning?






Some machine learning requires almost unimaginable amounts of data – millions of records. Traditional privacy practices emphasize data minimization, where you only collect the data you need for one purpose and keep it only as long as necessary for that purpose. However, data minimization is tough to reconcile with machine learning that needs lots of data, sometimes personal data.






There also can be issues of bias and fairness. Some people are concerned about what a company might do with a profile about them. Even without my name, machine learning can help a company come up with things about me that I don’t know it knows, or even things I don’t know about myself. An example would be an analysis of shopping data about people with similar profiles – that may be very accurate at predicting my preferences and behavior.






If a machine learning program is modelling off existing data sets, it can amplify biases that were in the original human-selected data. In that situation, the algorithm has to change to detect and adjust for bias in the data set. In that way, better math is part of the solution. Computer scientists tell us no system is without bias. The point is to understand what biases you have chosen, what priorities are built into the system and whether that will give you the results you want.






When we’re talking about race or ethnicity, some people ask, “can’t you just take that data out?” but it’s not that easy because many other data fields tend to correlate with race. You need to understand the bias in the data and adjust for it.





Another set of concerns are around transparency. People want to understand how their data is being used – that’s a key privacy practice. But that can be difficult if the algorithm can change itself. In machine learning, the program is constantly evolving. That makes it challenging to pick out a moment and determine why the program generated a specific result at that time. So traditional transparency analysis, which follows the steps for data use precisely, is hard to do with machine learning. There are ways to analyze it using math and statistics, but they can be tough to understand, which limits transparency.






What has FPF’s AI and Machine Learning Working Group been up to?






The working group brings together FPF members to stay abreast of how AI and machine learning are being used, learn from outside experts, and review and contribute to FPF documents.





We often have speakers come in to talk about AI and where it is headed. For example, we recently had a computer scientist come in and talk about AI and bias. Our presentations and discussions help the legal and policy people – who tend to be involved with FPF – better understand the technology and how it is being used so they are well-informed in discussions in their companies about products and services that their designers are building.





We also get input from working group members on our publications, like The Privacy Expert’s Guide to AI and Machine Learning, Beyond Explainability: A Practical Guide to Managing Risk in Machine Learning Models and our publications about facial recognition. The AI and Machine Learning Working Group members have tremendous expertise. It’s great to learn from them and share their perspective with our broader membership and the public.



IoT Devices Should Deal with Privacy Impacts for People with Disabilities

FOR IMMEDIATE RELEASE

January 31, 2019

IoT Devices Should Deal with Privacy Impacts for People with Disabilities

FPF Recommends Approaches to Incorporate Privacy, Accessibility by Design

WASHINGTON, DC – The Future of Privacy Forum today released The Internet of Things (IoT) and People with Disabilities: Exploring the Benefits, Challenges, and Privacy Tensions. This paper explores the nuances of privacy considerations for people with disabilities using IoT services and provides recommendations to address privacy considerations, which can include transparency, individual control, respect for context, the need for focused collection and security.

“Internet of Things devices in homes, cars and on our bodies can improve the quality of life for people with disabilities—if they are designed to be accessible and account for the sensitive nature of the data they collect,” said Jules Polonetsky, CEO of the Future of Privacy Forum. “We expect this first-of-its-kind paper to inspire collaboration among advocates, academia, government, and industry to ‘bake in’ privacy and accessibility from the start of the design process.”

“Data-driven innovation has created new tools that can improve disabled people’s safety, mobility, and independence, leading to enhanced privacy,” said Henry Claypool, Policy Director of the Community Living Policy Center at the University of California, San Francisco, Technology Consultant to the American Association of People with Disabilities and FPF Senior Fellow. “However, companies and advocates should recognize that the IoT can bring unique privacy considerations.”

FPF recommends companies and policymakers follow these recommendations to improve the experiences of people with disabilities when they use IoT-enables devices and respect their privacy:

  1. Prioritize inclusive design. Accessibility and the privacy of people with disabilities should not be an afterthought for the IoT and new technology developers—people with disabilities should be included in the design of IoT technologies. The appropriate timing for integrating accessibility is during the earliest possible stage of design.
  2. Promote research. In order to successfully build the IoT with universal or accessible design, research—both qualitative and quantitative—is needed to understand how people with disabilities utilize the IoT and feel about the current privacy landscape of the IoT.
  3. Privacy by Design approaches should consider people with disabilities. Companies should take into account the sensitive nature of the data collected from the IoT used by people with disabilities and address those consideration in the design of IoT products.
  4. Foster cross-sector collaborations. Advocates, academia, government, and industry should work together to develop IoT solutions that meet the needs of people with disabilities.
  5. Enhance awareness of data risks and benefits. Policymakers should consider not only the potential enhanced risks that people with disabilities face when using the IoT, but also the enhanced autonomy that these very same technologies provide. Members of the disability community should consider becoming engaged in policy processes and voicing their views on the privacy challenges that they face when using IoT devices and services.

IoT devices and services are empowering people with disabilities to participate more fully and autonomously in everyday life by reducing some needs for human intermediaries or accommodations. In addition to the potential benefits of IoT devices and services for people with disabilities, unique privacy risks and challenges can be raised by the collection, use, and sharing of user data. Depending on the circumstances, privacy can be enhanced or diminished by IoT technologies, creating potential tensions between privacy gains and losses.

FPF received support for the paper from the Comcast Innovation Fund and consulted with the American Association of People with Disabilities (AAPD) Technology Forum.

FPF and Comcast Innovation Fund host event today in Washington, DC

Today, Thursday, January 31, 2019, 4:30-5:30pm ET, FPF and the Comcast Innovation Fund are hosting an event about the IoT and people with disabilities at the XFINITY Store in Chinatown, 715 7th St. NW, Washington, DC 20001. Remarks and a panel discussion will be followed by audience Q&A, refreshments and networking. The remarks and panel discussion will be streamed via Facebook Live at https://www.facebook.com/FutureofPrivacy/.

###
The Future of Privacy Forum is a non-profit organization that serves as a catalyst for privacy leadership and scholarship, advancing principled data practices in support of emerging technologies. Learn more about FPF by visiting www.fpf.org.

Media Contact:

Nat Wood

[email protected]

410-507-7898

FPF Report: IoT Devices Should Deal with Privacy Impacts for People with Disabilities

FPF has released The Internet of Things (IoT) and People with Disabilities: Exploring the Benefits, Challenges, and Privacy Tensions. This paper explores the nuances of privacy considerations for people with disabilities using IoT services and provides recommendations to address privacy considerations, which can include transparency, individual control, respect for context, the need for focused collection and security.

IoT devices and services are empowering people with disabilities to participate more fully and autonomously in everyday life by reducing some needs for human intermediaries or accommodations. In addition to the potential benefits of IoT devices and services for people with disabilities, unique privacy risks and challenges can be raised by the collection, use, and sharing of user data. Depending on the circumstances, privacy can be enhanced or diminished by IoT technologies, creating potential tensions between privacy gains and losses.

FPF recommends companies and policymakers follow these recommendations to improve the experiences of people with disabilities when they use IoT-enables devices and respect their privacy:

  1. Prioritize inclusive design. Accessibility and the privacy of people with disabilities should not be an afterthought for the IoT and new technology developers—people with disabilities should be included in the design of IoT technologies. The appropriate timing for integrating accessibility is during the earliest possible stage of design.
  2. Promote research. In order to successfully build the IoT with universal or accessible design, research—both qualitative and quantitative—is needed to understand how people with disabilities utilize the IoT and feel about the current privacy landscape of the IoT.
  3. Privacy by Design approaches should consider people with disabilities. Companies should take into account the sensitive nature of the data collected from the IoT used by people with disabilities and address those consideration in the design of IoT products.
  4. Foster cross-sector collaborations. Advocates, academia, government, and industry should work together to develop IoT solutions that meet the needs of people with disabilities.
  5. Enhance awareness of data risks and benefits. Policymakers should consider not only the potential enhanced risks that people with disabilities face when using the IoT, but also the enhanced autonomy that these very same technologies provide. Members of the disability community should consider becoming engaged in policy processes and voicing their views on the privacy challenges that they face when using IoT devices and services.

FPF received support for the paper from the Comcast Innovation Fund and consulted with the American Association of People with Disabilities (AAPD) Technology Forum.

FPF and Comcast Innovation Fund host event today in Washington, DC

Today, Thursday, January 31, 2019, 4:30-5:30pm ET, FPF and the Comcast Innovation Fund are hosting an event about the IoT and people with disabilities at the XFINITY Store in Chinatown, 715 7th St. NW, Washington, DC 20001. Remarks and a panel discussion will be followed by audience Q&A, refreshments and networking. The remarks and panel discussion will be streamed via Facebook Live at https://www.facebook.com/FutureofPrivacy/.

FPF's John Verdi on Privacy Papers for Policymakers

In recognition of the Future of Privacy Forum’s 10th anniversary, FPF policy experts are sharing their thoughts on FPF’s work over the past decade, the current privacy landscape, and their vision of the future of privacy. This week, FPF Vice President for Policy John Verdi discusses the Privacy Papers for Policymakers project, which began in 2010. To read previous installments in this series, click here.

What do you expect the next 10 years of privacy to look like? Share your thoughts by clicking here.


Q&A: John Verdi on Privacy Papers for Policymakers

John VerdiFPF’s Privacy Papers for Policymakers program brings expertise from academic, tech and policy circles to Members of Congress, leaders from executive agencies, and their staffs to better inform policy approaches to thorny data protection issues. The event highlights the year’s most influential, practical academic work and connects academics with thought leaders from government, industry, and the advocacy community. Awarded articles are chosen both for their scholarly value and because they offer policymakers concrete solutions and practical insights into real-world challenges. Winners are selected by a diverse team of academics, advocates, and industry privacy professionals from FPF’s Advisory Board. Honorary Co-Hosts Senator Edward J. Markey and Congresswoman Diana DeGette will host FPF and this year’s winning authors as they present their work in the Russell Senate Office Building at 5:30pm on February 06, 2019. The event is free, open to the general public, and widely attended. A reception will follow. To RSVP, please visit privacypapersforpolicymakers.eventbrite.com.

How have the award-winning privacy papers changed over the last nine years?

The first award winners tended to deal with what we now consider broad topics in corporate privacy practices – the role of Chief Privacy Officers and federal law enforcers, how to value privacy, regulatory innovation, and so on. While those issues are still quite pertinent, recent award winners have been likely to examine more precise aspects of privacy, specific technical advances, or policies at the local, national, or international levels. A few examples from this year’s winners:

What’s been consistent from the beginning?

For nine years, the research and analysis into consumer beliefs, corporate practices, technological solutions and legal theory compiled in FPF’s Privacy Papers for Policymakers has informed the policy debate in Congress, in the states, and around the world. They are a valuable tool for legislators and staff considering the structure and elements of a national privacy framework.

Many of the papers have dealt with calls for an effective national privacy law in the US. In fact, here is the first line of the first Privacy Paper for Policymakers recognized in 2010 by the Future of Privacy Forum. “Privacy on the Books and on the Ground,” by Kenneth Bamberger and Deirdre Mulligan:

U.S. privacy law is under attack. Scholars and advocates criticize it as weak, incomplete and confusing, and argue that it fails to empower individuals to control the use of their personal information…”

They continued, “as Congress and the Obama Administration consider privacy reform, they encounter a drumbeat of arguments favoring the elimination of legal ambiguity by adoption of omnibus privacy statutes, the EU’s approach.” If you substitute “Trump” for “Obama” you could write the same words today; you would also find experts making many of the same arguments against imposing the top-down, prescriptive aspects of the EU’s approach in the US.

What are some of the research techniques authors use?

We’ve honored papers from academics, practitioners, technologists and lawyers, which means we’ve seen a wide range of approaches to research and analysis.

Some survey the privacy landscape and make recommendations based on the real-world practices they discover. For Shattering One-Way Mirrors. Data Subject Access Rights in Practice, Jef Ausloos (Postdoctoral Researcher, University of Amsterdam’s Institute for Information Law) and Pierre Dewitte (Researcher, KU Leuven Centre for IT & IP Law) contacted sixty information service providers and requested access to data. They concluded that data access rights in the EU are largely underused and not properly accommodated. Their research not only uncovered what they called an “often-flagrant lack of awareness, organization, motivation, and harmonization,” but also identified concrete suggestions aimed at data controllers, such as relatively easy fixes in privacy policies and access rights templates.

For Designing Without Privacy, Ari Ezra Waldman (Professor of Law and Founding Director, Innovation Center for Law and Technology at New York Law School) conducted an ethnographic study of how, if at all, people designing technology products think about privacy, integrate privacy into their work, and consider user needs in the design process. His paper references and expands upon the work of Kenneth Bamberger and Deirdre Mulligan – work that FPF recognized as one of our first award winners in 2010. Professor Waldman looks at how CPOs’ robust privacy norms can best be diffused throughout tech companies and the industry as a whole.

What’s next for Privacy Papers for Policymakers?

The Privacy Papers for Policymakers program will continue to highlight top scholarship, promote pragmatic solutions to privacy challenges, and generate thoughtful dialogue in Washington DC. We look forward to promoting constructive approaches to data protection around legislative drafting tables and in corporate boardrooms.

Most immediately, we are looking forward to a fantastic event honoring his year’s winning authors. On February 6, 2019, FPF and Honorary Co-Hosts Senator Edward J. Markey and Congresswoman Diana DeGette will host FPF and this year’s winning authors as they present their work in the Russell Senate Office Building at 5:30pm on February 06, 2019. The event is free, open to the general public, and widely attended. To RSVP, please visit privacypapersforpolicymakers.eventbrite.com.

FPF's Amelia Vance on the Future of Student Privacy

Amelia Vance, Policy Counsel and Director of the FPF Education Privacy Project, is one of the foremost experts in the nation on education privacy. She has a knack for making complex regulations and technical trends accessible to individuals who are not lawyers or computer scientists, but who care deeply about student privacy – school administrators, parents, students, and others. This skill is very much in demand; whether testifying before Congress or sharing her expertise at conferences across the country, Amelia has been a valuable resource for anyone who wants to understand how federal and state laws impact data practices in the classroom. In this installment of our 10th anniversary series, Amelia discusses FPF’s work in education, the current student privacy landscape, and the debates of the future.

Why do you like working on student privacy?

Student privacy is a microcosm of every privacy issue out there, except we’re talking about kids, which makes things so much more sensitive. FPF works on algorithms and ethics, health privacy, research privacy, IOT, online trackers – which are all part of the student privacy landscape. And because children are recognized – both legally and developmentally – as especially vulnerable, any privacy discussions must be nuanced and thoughtful because getting it wrong means you can end up derailing a child’s future. Student privacy requires not only legal expertise, but also the ability to put yourself in the shoes of a parent, a teacher, an edtech company, or other stakeholders so you can figure out their concerns and how to best respond to them. Framing the conversation correctly is just as important as getting the policies right.

What sort of work has FPF done on education privacy over the past 10 years? What challenges have arisen during that time?

FPF kicked off its education privacy program in 2014 with the launch of the Student Privacy Pledge. That year, over 100 student privacy bills were introduced in 39 states; the prior year, only one student privacy law had passed. This flurry of legislation highlighted a major gap in law and resources on this issue; the federal student privacy law, FERPA, was passed in 1974, and if you get 15 FERPA experts in a room, they’ll come up with 16 interpretations of any provision. The new state laws were creating mandates for states, districts, and companies without providing the resources and training necessary to implement the laws with fidelity. FPF decided to step in and worked with partners like the Data Quality Campaign, the Software and Information Industry Association (SIIA), ConnectSafely, and the National PTA to create actionable resources for different audiences.

The Student Privacy Pledge has been one of our most successful projects. Co-founded with SIIA, the Pledge is a Federal Trade Commission-enforceable code of conduct for edtech vendors. Now with nearly 330 companies as signatories, the Pledge was designed to both raise awareness of best practices and facilitate their implementation.

We are also particularly proud of FERPAǀSherpa, the student privacy resources website. Whether you’re a student, parent, educator, administrator, policymaker, or higher education staffer, we hope to make the vast student privacy landscape more understandable. The explosion in state privacy laws has made this a challenge, but it’s one we embrace. My primary goal is that everything we release be useful and move the student privacy conversation forward.

What should our readers know about the current student privacy landscape?

39 states and DC have passed 125 new laws since 2013, so right now most stakeholders are focused on implementation and seeing how these laws play out on the ground. There are now 450+ resources on student privacy to help stakeholders on the issue, but few state legislatures provide funding and training to districts and state education agencies to implement student privacy best practices. We have also seen many unintended consequences play out over the past few years. It is unfortunately easy to mess this up – for example, a complete ban on selling student data can result in banning school pictures! One state’s law made parents opt into almost all data sharing and caused some schools to stop announcing football players’ names, hanging student artwork in the hallways, and even referring some students to the state scholarship fund. It’s easy to get lost in sensationalism and misunderstandings when discussing issues that affect children; our work injects nuance and informed analysis into the public debate.

What about the next 10 years? What privacy challenges can we expect to emerge in this space?

Now that most of the new student privacy laws have been in place for a couple years, we are likely to start seeing enforcement actions – which, in some states, could mean jail time. There are fewer big student privacy bills being introduced in states at this point, but we’re seeing more legislation with idiosyncratic student privacy requirements that could trip up schools or edtech companies. We also see legislation that should have privacy requirements but doesn’t – that’s a big issue with school safety legislation! We’re also likely to see a re-write of FERPA pass in Congress at some point in the next five years. Finally, as we’ve seen over the past year, the privacy conversation has now spread past education into the general news; this means edtech companies will have to attempt to reconcile the burgeoning universe of consumer privacy law with parallel developments in education. There will likely be times when legal obligations conflict, and it will be interesting to see how well legislators take the lessons learned from student privacy laws to avoid unintended consequences in general consumer privacy laws.

 

The Future of Mobility in a Connected World: FPF’s Lauren Smith on Connected Cars, Data, and more

FPF is celebrating our tenth anniversary. In recognition of this milestone, FPF policy experts will be sharing their thoughts on FPF’s progress and the work ahead in a series of blogs over the coming weeks. Our 10th anniversary celebration will be on April 30. RSVP here.

This week, Policy Counsel Lauren Smith discusses connected cars and the future of mobility.

What do you expect the next 10 years of mobility and privacy to look like? Share your thoughts by clicking here.


Bearbeitet Headshot LaurenFPF Policy Counsel Lauren Smith didn’t see herself as a “car person” when she joined FPF in 2016. Three years later, she leads FPF’s Data and Mobility Working Group and regularly shares her expertise on the subject in speaking engagements, media interviews, and with state and federal regulators, among other stakeholders. She recently answered some questions on the state of connected cars, FPF’s work in the space, and the future of mobility.

So, what drew you to work on data and mobility at FPF? How did it differ from your prior work?

I had been advising on tech policy, privacy, and big data at the White House Office of Science and Technology Policy, where I contributed to a report on Big Data and Privacy. Those efforts raised several important questions around privacy and data access, the emergence of new technologies, and the social and ethical impact of these advancements. When I got to FPF, I was fascinated to see how rapidly the auto industry was changing, but I also noticed that it faced many of the same issues as the other “Internet of Things” technologies I was familiar with in my previous work. The maxim at most of the conferences I attend now is that we will see more change in the transportation industry over the next five years than we’ve seen in the past 50. Much of this transition is driven by technological advances and opportunities presented by data, and it has been fascinating to get to know an industry during such a unique period.

What sort of work has FPF done on connected cars over the past 10 years? What challenges have arisen during that time?

Data collection in cars isn’t new; for instance, there have been computer systems in most cars since at least the 1990s. The biggest change has been an explosion in the variety, volume, and connectivity of the data collected. As Americans, we tend to associate cars with personal autonomy, but we need to start thinking about cars like we think about our smart phones, rather than as mechanical chassis that get us from point A to point B.

A few years ago, the auto industry anticipated these changes, and nearly every automaker committed to a set of privacy principles for auto data that enable the benefits of these new technologies while establishing baseline privacy protections for consumers. FPF contributed to the effort to establish these principles and has proceeded to be one of the only groups deeply focused on this space. Our work has included creating a Consumer Guide to the Connected Car that auto dealers can hand to consumers; leading efforts to map the vehicle data ecosystem through projects like Data and the Connected Car 1.0; filing comments in federal, state, and local regulatory efforts; hosting convenings for thought leaders in this space throughout the U.S. and Israel; and continuous media and public speaking efforts to better educate consumers, regulators, and lawmakers alike on new developments. My TEDx talk was a fun highlight that allowed us to reach new audiences. It has been a pleasure learning from and working with our Data and Mobility Working Group members, which includes representatives from auto manufacturers, ridesharing companies, mapping, telecommunications firms, mobility startups, and more.

What are some current hot topics in mobility and connected cars?

Right now, we’re seeing a rapidly changing industry encounter a series of new scenarios. First, the mobility ecosystem includes so much more than connected cars. Scooters and shared bikes have grown immensely popular over the past few years, and they produce data that is increasingly of interest to state and local regulators. Mobility data has the potential to make our city transportation infrastructure and planning far more efficient, but any such efforts need to be thorough in creating credible privacy regimes around the data they collect.

Next, we’re seeing a growing number of sophisticated technologies, but we still haven’t answered some basic questions around mobility data, such as who can access it, who manages the consumer relationship in a vehicle, which of this data is “personal,” and how to efficiently wipe basic personal data when vehicles are transferred between users. At the same time, we’re seeing regulators who care about privacy trying to ascertain how to regulate such a new space without limiting the opportunities that these technologies can bring. As the industry navigates its compliance with new privacy laws like GDPR and CCPA, I’m hoping we will see new tools and have the needed conversations to ensure we build a trusted mobility data ecosystem.

As these conversations evolve, cars are gaining powerful on-board processing systems and advanced sensor technologies, with a growing ability to protect safety, monitor happenings inside the car, and gather information on driving habits and consumer preferences. We emphasize the word “ecosystem” because there are a growing number of entities involved. The impact of these technologies will extend far beyond just automakers, impacting the insurance industry, mapping companies, telecommunications providers, public transit, city planners, and more. As driver assistance and autonomous features enable serious safety benefits across our roads, we think it’s our job to ensure we can build a privacy-protective ecosystem that supports them and that earns consumer trust.

What about the next 10 years? What technological advancements and privacy challenges can we expect to emerge in this space?

It’s so exciting to look out on this space 10 years out. I get asked these questions a lot: Will there be flying cars? Will my 3-year-old ever need a driver’s license? The only constant is change right now, and it’s raising a lot of really interesting questions.

By some estimates, the global revenue pool from connected car data is expected to hit $750 billion by 2030. The companies using and generating this data will face many of the same questions around privacy and advertising and data sharing and access that we’ve tackled in other FPF verticals. The good news is that we aim to help the mobility industry learn from other sectors that have already tackled similar issues surrounding data privacy management and regulatory infrastructure. For example, our mobility work has often merged with our location work recently, and I expect that to continue as we face questions around sensitivity of the geolocation that is fundamental to mobility technologies.

I would expect to see major developments not just in advanced driving assistance systems and autonomous vehicles, but also vehicle-to-vehicle and vehicle-to-infrastructure communication. More advanced sensor technology using lidar, hi-definition mapping, radar and video sensors paired with higher processing powers and advanced connectivity options will enable the collection and transmission of significant datasets that will need to be privacy protected to ensure consumer trust in the technology. Vehicles will be more connected to each other and to the larger transportation grid as a result. Vehicles may be managed by fleets rather than individual owners. These advancements and more will save lives and make transportation more efficient, but will also pose challenges for regulators, policymakers, and consumers.

I can’t wait to see how this space changes going forward—there is rarely a dull moment and it’s a pleasure to navigate these exciting questions.


What do you expect the next 10 years of connected cars and privacy to look like? We’d love to hear from you on this subject or any other thoughts you have on privacy:[ninja_form id=8]

Advisory Board Reviewers: PPPM 2018

Each year, FPF awards the Privacy Papers for Policymakers Award to the authors of leading privacy research and analytical work that is relevant to policymakers in the United States Congress, at U.S. federal agencies, and for data protection authorities abroad. The Award showcases work that analyzes current and emerging privacy issues and proposes achievable  solutions or new means of analysis that could lead to real-world policy impact.

PPPM submissions receive an initial ranking from our Advisory Board Reviewers — a diverse team of academics, consumer advocates, and industry privacy professionals.

Winning Authors are invited to join FPF in Washington, DC to discuss their work at the United States Senate with policymakers, academics, and privacy professionals. This year, Privacy Papers for Policymakers will be held at 5:30 PM on February 6, 2019 in Room SR-325 (Kennedy Caucus Room), Russell Senate Office Building. For more information and to register, click here.

FPF would like to extend a special Thank You to our 2018 Advisory Board Reviewers, including:

Eduard Bartholme, Call For Action

Monica Bulger, Future of Privacy Forum

Maureen Cooney, Sprint

Philip Fabinger, HERE Technologies

Jonathan Fox, Cisco

Dona Fraser, The Children’s Advertising Review Unit 

Claire Gartland, Facebook

Lauren Gelman, BlurryEdge Strategies

Scott Goss, Qualcomm

John Grant, Palantir

Rita Heimes, International Association of Privacy Professionals 

Joseph Jerome, Center For Democracy & Technology

Barbara Lawler, Looker Data Services

Knut Mager, Novartis

Magnolia Mobley, LegalMatters, LLC

Lisa Martinelli, Highmark Health

Estelle Masse, Access Now

Drew Mitnick, Access Now

Robyn Mohr, Loeb & Loeb, LLP

Vivek Narayanadas, Shopify

Kara Selke, StreetLight Data

Amie Stepanovich, Access Now

Thomas van der Valk, Facebook

Heather West, Mozilla

Thank you for all your hard work!

 

Spotlight on PPPM Finalist Judges (2018)

On December 17th, the Future of Privacy Forum announced the winners of the 2018 Privacy Papers for Policymakers Award. Each year, FPF awards the Privacy Papers for Policymakers Award to the authors of leading privacy research and analytical work that is relevant to policymakers in the United States Congress, at U.S. federal agencies, and for data protection authorities abroad.

The goal of the Award is to advance academic-industry collaboration by showcasing work that analyzes current and emerging privacy issues and proposes achievable solutions or new means of analysis that could lead to real-world policy impact.

How are PPPM papers chosen?

This year, Privacy Papers for Policymakers will be held at 5:30 PM on February 06, 2018 in Room SR-325 (Kennedy Caucus Room), Russell Senate Office Building. For more information and to register, click here.

Finalist Judges:

Our Finalist Judges for 2018 include representatives from FPF, as well as one representative from Academia, one from Consumer Advocacy, and one from Industry.

Judges include Jules Polonetsky, CEO, Future of Privacy Forum; Christopher Wolf, Founder and Board Chair, Future of Privacy Forum; Mary Culnan, Professor Emeritus, Bentley University, and Board Vice President, Future of Privacy Forum; John Breyault, Vice President of Public Policy, Telecommunications and Fraud, National Consumers League; and Mark MacCarthy, Senior Vice President, Public Policy, Software & Information Industry Association.

More on our PPPM Judges:

Jules Polonetsky

CEO, Future of Privacy Forum

Jules Polonetsky

Jules serves as CEO of the Future of Privacy Forum. Jules’ previous roles have included serving as Chief Privacy Officer at AOL and before that at DoubleClick, as Consumer Affairs Commissioner for New York City, as an elected New York State Legislator and as a congressional staffer, and as an attorney. Jules serves on the Advisory Board of the Center for Copyright Information. He has served on the boards of a number of privacy and consumer protection organizations including TRUSTe, the International Association of Privacy Professionals, and the Network Advertising Initiative. From 2011-2012, Jules served on the Department of Homeland Security Data Privacy and Integrity Advisory Committee. In 2001, Crain’s NY Business magazine named Jules one of the top technology leaders in New York City. Jules is a regular speaker at privacy and technology events and has testified or presented before Congressional committees and the Federal Trade Commission.

 

Mary Culnan

culnanProfessor Emeritus, Bentley University

Vice President, Future of Privacy Forum Board of Directors

Dr. Mary J. Culnan is Professor Emeritus at Bentley University. She also serves as a Senior Research Fellow in the Center for IT and the Global Economy (CITGE) at the Kogod School of Business, American University. Mary has testified before Congress, the Massachusetts Senate, and other government agencies on a range of privacy issues. Mary’s primary research interest is governance of privacy and security. She has also conducted research on how organizations can gain value from social media. Mary’s work has been published in a range of academic journals as well as the New York Times, the Washington Post and the Wall Street Journal. Mary was employed for seven years as a systems analyst by the Burroughs Corporation prior to earning her Ph.D. in management from UCLA. Before joining the faculty at Bentley in fall 2000, she held faculty positions at the University of Virginia, University of California, Berkeley, the American University and Georgetown University.

 

Christopher Wolf

Founder and Board Chair, Future of Privacy Forum

wolfChristopher Wolf is the founder and Board Chair of the Future of Privacy Forum. Chris is also a senior partner in the Washington, DC office of Hogan Lovells LLP, where he is a leader of that firm’s Privacy and Information Management practice. He has been in private law practice in Washington, DC since 1982. Chris has served as an adjunct law professor on Internet and privacy law, and is a frequent lecturer in continuing legal education programs on the subject.

MSNBC called Chris Wolf a “pioneer in Internet law”, reflecting his involvement in some of the earliest and precedent setting cases involving technology agreements, copyright, domain names, jurisdiction — and privacy. As the ability to collect, store, share and transfer personal information over the Internet increased, privacy became the main focus of Chris’ law practice. And Chris became known as a pioneer in privacy law too. It was for that reason that the prestigious Practising Law Institute (PLI) tapped Chris to be Editor and Lead Author of its first-ever treatise on privacy law. He also is co-editor of the PLI book, “A Practical Guide to the Red Flag Rules”, the identity theft prevention regulations issued by the FTC and financial regulators.

John Breyault

Vice President of Public Policy, Telecommunications and Fraud, National Consumers League

breyault_headshotJohn joined the National Consumers League — America’s oldest consumer organization — in September 2008. His focus at NCL is advocating for stronger consumer and worker protections before Congress and federal agencies on a range of issues including telecommunications and technology policy, fraud, and consumer financial protections. In addition, John directs NCL’s Fraud Center an online hub for consumer education and advocacy related to fraud.

Prior to coming to NCL, John was Research Director at the Telecommunications Research and Action Center (TRAC), a non-profit consumer organization dedicated to promoting the interests of telecommunications consumers. Concurrent with his work at TRAC, John was Director of Research at Amplify Public Affairs (APA) where he helped launch the firm’s Web 2.0-based public affairs practice.

Prior to joining APA, John worked at Sprint in its International Carrier Services Division, at BellSouth in its Government Affairs office and at the American Center for Polish Culture. John has served on numerous Boards and advisory committees including the Federal Communications Commission’s Consumer Advisory Committee, the Commodity Futures Trading Commission’s Technology Advisory Committee and the Board of the Arlington-Alexandria Coalition for the Homeless.

 

Mark MacCarthy

Senior Vice President, Public Policy, Software & Information Industry Association

Mark MacCarthy is an adjunct faculty member in the Communication, Culture & Technology Program at Georgetown University. He teaches courses and conducts research in information privacy, AI and the future of work, global Internet freedom, algorithmic fairness and the development of electronic media. He also teaches courses in philosophy & privacy and philosophy & free speech and AI and Ethics in the Philosophy Department. He is an Affiliate of the Center for Business and Public Policy at Georgetown’s McDonough School of Business. He is also Senior Vice President for Public Policy at the Software & Information Industry Association, where he advises member companies and directs public policy initiatives in technology policy, information privacy, trade, Internet governance, intellectual property and educational technology. He has been a consultant on technology policy issues for the Organization for Economic Cooperation and Development and for the Aspen Institute. His previous public policy experience includes senior positions with Visa, Inc., the Wexler|Walker Group, Capital Cities/ABC and the Energy and Commerce Committee of the U.S. House of Representatives. He holds a Ph.D in philosophy from Indiana University and an MA in economics from the University of Notre Dame.

Thank you to our 2018 PPPM Finalist Judges!