Future of Privacy Forum Launches Fellowship in Memory of Privacy Hero Elise Berkower

FOR IMMEDIATE RELEASE             

March 26, 2018

Contact: Melanie Bates, Director of Communications, [email protected]

Future of Privacy Forum Launches Fellowship in Memory of Privacy Hero Elise Berkower

Washington, DC – Today, the Future of Privacy Forum announced the launch of a new fellowship in memory of Elise Berkower. Elise was a senior privacy executive at global measurement and data analytics company Nielsen for nearly a decade and was a valued, longtime member of the FPF Advisory Board. FPF graciously acknowledges the Berkower Family and the Nielsen Foundation as founding sponsors of the Elise Berkower Memorial Fellowship.

“Elise was passionate about mentoring and teaching recent law school graduates because in addition to spreading her vast knowledge and experience to others, Elise understood that when teaching the teacher also learns and fine tunes their understanding,” said Howard Berkower, Elise’s brother. “Our family can think of no better way to honor Elise’s personal and professional life of generosity, commitment and accomplishment than to establish this Privacy Fellowship.”

Elise served as Chief Privacy Counsel at Nielsen, playing a lead role in efforts to ensure the company was best in class in the way it handles consumer data, in addition to playing an active role in working across industry groups to help raise the bar of consumer protection across a range of organizations.

“Elise’s leadership was critical in laying the foundation for what today is Nielsen’s industry-leading privacy efforts,” said Eric J. Dale, Nielsen’s Chief Legal Officer and Secretary and Director of the Nielsen Foundation.  “We are so excited about the FPF fellowship in her honor, which allows Elise’s legacy of excellence and development in privacy to continue for years to come.  We are thrilled that the Nielsen Foundation is a founding sponsor of the Elise Berkower Memorial Fellowship.”

The Nielsen Foundation is a private foundation funded by Nielsen. The Nielsen Foundation seeks to enhance use of data by the social sector to reduce discrimination, ease global hunger, promote effective education, and build strong leadership.

While at Nielsen, Elise was heavily involved in recruiting, training and mentoring interns, creating a pathway for a generation of students to enter the privacy field. Elise provided nearly 100 students with an opportunity to gain the experience and build the relationships needed to launch their careers in this field. The Elise Berkower Memorial Fellowship is designed for recent law school graduates and will honor Elise’s legacy by identifying and nurturing young lawyers interested in contemporary privacy issues with a focus on consumer protection and business ethics.

“Elise had a passion for privacy that was infectious,” said Farah Zaman, Senior Global Data Privacy Counsel, Colgate-Palmolive Company. “She could produce a practical, insightful, and thorough legal and technical solution off the top of her head, and educate interns, junior and senior legal colleagues, and even counsel across the table while doing so.  Elise was a remarkable person to work for not only because of her brilliance, but also because of her profound example of how to simultaneously be an effective in-house counsel, privacy advocate, and infinitely kind and thoughtful person. The legal profession and privacy community will be advanced by any attorney or intern who follows her example.”

The fellowship will be a one-year, public interest position for recent law school graduates committed to the advancement of responsible data practices. Candidates will be selected based on both academic qualifications and a commitment to the personal qualities exemplified by Elise – collaboration with co-workers, peers and the broader privacy community and a commitment to ethical conduct.

“She was one of the brightest stars in our privacy community,” said Zoe Strickland, Managing Director, Global Chief Privacy Officer, JPMorgan Chase. “She had such a deep understanding of privacy in that complicated intersection of data use, technology, tracking, and aggregation. And a quick and sharp wit as a bonus. This fellowship is a testament to her skill and legacy, and provides a wonderful avenue for students to follow in her big footsteps.”

“Elise was a quiet, but powerful, force in the privacy community,” said Trevor Hughes, President & CEO of the International Association of Privacy Professionals.  “For almost two decades, she worked for better outcomes for all involved. Her influence can be seen in many of the privacy standards that we work with today. She is terribly missed, and fondly remembered.”

“Elise was one of the quiet heroines of the earliest days of privacy compliance,” said Nuala O’Connor, President & CEO of Center for Democracy & Technology. “She was so much more than just a respected and valued colleague; she was a friend and a teacher and a partner to many. She was the best example of how to imbue privacy and data ethics into an organization.”

“Elise was one of the founding Board Members of the NAI, providing groundbreaking and effective leadership in developing standards and best practices for digital technology companies facing emerging privacy and public policy issues raised by complicated business models,” said Leigh Freund, President & CEO of the Network Advertising Initiative (NAI). “Elise’s incredible knack for diplomatic negotiation and collaboration with industry leaders at a critical point in the development of the internet economy resulted in a lasting legacy of effective and responsible self-regulation that we can all be proud of.”

“When I became Chief Privacy Officer at DoubleClick, I needed someone with a deep commitment to consumer protection to work with and educate thousands of companies and clients, teaching many of them for the first time the basics of internet privacy,” said Jules Polonetsky, FPF’s CEO. “Elise joined DoubleClick from her role as Chief Administrative Law Judge at the New York City Department of Consumer Affairs and played a critical role in shaping DoubleClick’s best practices as well as setting a standard for the industry.”

The Elise Berkower Memorial Fellow will focus on consumer and commercial privacy issues, from technology-specific areas such as advertising practices, drones, wearables, connected cars, and student privacy, to general data management and privacy issues related to ethics, de-identification, algorithms, and the Internet of Things.

To apply for the inaugural Elise Berkower Memorial Fellowship or to support our efforts, please visit https://fpf.org/2018/03/26/the-elise-berkower-memorial-fellowship.

 

### 

The Future of Privacy Forum (FPF) is a non-profit organization that serves as a catalyst for privacy leadership and scholarship, advancing principled data practices in support of emerging technologies. 

Deciphering “Legitimate Interests”: Report based on more than 40 cases from practice

FPF and Nymity collaborated to compile a Report on actual cases from practice and relevant guidance from the Article 29 Working Party and individual Data Protection Authorities (DPAs) concerning the use of “legitimate interests” as a lawful ground for processing under EU data protection law. Our aim is to help organizations better understand how to use and apply legitimate interests as a lawful basis for processing, while at the same time contributing to enhanced personal data protection for individuals.

We have identified specific cases that have been decided at national level by DPAs and Courts from the European Economic Area (EEA), as well as the most relevant cases where the Court of Justice of the European Union interpreted and applied the “legitimate interests” ground. We looked at cases across industries and we compiled them in two lists: one for uses of this ground that were found lawful and one for uses that were found unlawful.

There are over 40 cases discussed representing a wide variety of data processing activities from over 15 countries, such as:

The summary of cases contain useful examples of how the “balancing exercise” is conducted in practice, and in many instances, the safeguards that were needed to tilt the balance and make the processing lawful. Two examples are provided below.

READ REPORT

Facebook and Cambridge Analytica: Statement by Jules Polonetsky, FPF CEO

Yesterday, Mark Zuckerberg addressed concerns about misuse of Facebook users data by Cambridge Analytica.

I think Mark well addresses the key issues. The biggest change was made back in 2014 when Facebook altered the platform to reduce data access by apps. But did any other apps collect a suspicious amount of data back then? Facebook will conduct a full audit of any app with suspicious activity and ban apps that misused personal information. We hope those will also be reported to relevant authorities when appropriate.

Facebook will also tell people who are affected by apps that have misused their data and will build a way for people to know if their data might have been accessed via the “thisisyourdigitallife” app that provided data to Cambridge Analytica. Moving forward, if Facebook removes an app for misusing data, they will tell everyone who used it.

Facebook will also turn off access to information for unused apps, if someone hasn’t used an app for 3 months, which makes sense.

Do you ever use Login with Facebook on other apps or sites? In the next version, apps will only be able to request name, profile photo and email address, unless they get special approval.

I just checked and my Facebook profile is linked to dozens of apps. I turned a number of them off. A few are super useful – when I use TripAdvisor, I love seeing reviews by my FB friends listed first, so I can assess whether to take the review seriously! But as a Facebook power user, even I had to poke around to find the setting that displayed that information. Going forward, Facebook promises to make these choices more prominent and easier to manage.

And finally, Facebook will expand its bug bounty program to reward people who report misuses of data by app developers.

These are clearly all useful steps forward and should help shut the door on shady apps misusing Facebook data.

Thinking more broadly, it seems clear that many of the issues raised by the Cambridge Analytica controversy are not exclusive to a particular platform, data practice, or policy.

Do we need baseline, comprehensive privacy legislation in the US, with common sense data protections for users and greater certainty for companies?

Should the FTC have authority over political orgs and other non-profits to police unfair and deceptive practices? The Commission currently lacks this. And Congress is typically reluctant to pass laws that impact campaigns and political parties – the organizations that help members earn re-election.

How can new targeting capabilities – across the online ecosystem – be made more transparent for elections and issue campaigns? Do we need standards for election ads in the 21st century? Can we have data standards that are clear about what behavior is appropriate and what is not when communicating through TV, radio, in print, and online? This is an issue in the US and abroad, as the Irish Data Protection Commissioner (who handled and helped resolve a few years ago the issues of Facebook apps grabbing too much data) explains: “the micro-targeting of social media users with political ads remains an ongoing issue today.”  Although GDPR does capture the activity of political actors in Europe, guidance in the form of a Code of Conduct for political advertisers would be welcome, according to a new opinion from the European Data Protection Supervisor.

How can we support more legitimate research – for transparency about platforms and their impact, and for broader needs of society and science?  Can we have research programs managed by companies that provide more controls, a good vetting process, better informed consent for research, corporate ethics review processes?

Can we have a sophisticated conversation about the risks and mitigation strategies regarding data portability? Worries about Cambridge Analytica’s data exfiltration implicate many of the same issues raised by data portability tools and GDPR Article 20.

We are pleased to see Facebook’s response, but are looking forward to understanding how to best address the broader issues for all stakeholders.  These issues are important to discuss – they are not going away.

Understanding Session Replay Scripts – a Guide for Privacy Professionals

Over the last few months, privacy researchers at Princeton University’s Center for Information Technology Policy (CITP) have published the results of ongoing research demonstrating that many website operators are using third-party tools called “session replay scripts” to track visitors’ individual browsing sessions, including their keystrokes and mouse movements. These “session replay scripts,” typically used as analytics tools for publishers to better understand how visitors are navigating their websites, were found on 482 of the 50,000 most trafficked websites, including government (.gov) and educational (.edu) websites, and websites of major retailers.

As the research demonstrated, session replay scripts can raise serious privacy concerns if implemented incorrectly, causing security vulnerabilities and the potential for inadvertent collection of personal data (e.g. credit card numbers, health information, or other sensitive data). Therefore, privacy professionals should be involved in decisions related to whether and how to use these kinds of tools, and should carefully consider their usefulness and potential risks. With the right privacy and security safeguards in place, however, limited implementation of session replay scripts can be part of a range of ordinary, useful third-party web analytics tools.

FPF has developed a three-page guide for privacy professionals, who can in turn assist website marketing and design teams with decisions about whether and how to implement these types of analytics scripts. In this guide, we define and describe the term “session replay scripts,” and provide a checklist of privacy tips to use when deciding how best to implement them. In deciding whether and how to implement third-party scripts, privacy professionals should evaluate script providers’ terms and privacy policies, carefully select which pages within a site may or may not be appropriate for their use, and continue to assess the strength of technical safeguards — such as automated and manual redaction tools — over time.

Download the 3-page Guide here (link to PDF).

More Resources:

Taming The Golem: Challenges of Ethical Algorithmic Decision-Making

Omer Tene and Jules Polonetsky recently published, “Taming The Golem: Challenges of Ethical Algorithmic Decision-Making,” in Volume 19, Issue 1, of the North Carolina Journal of Law and Technology.

The prospect of digital manipulation on major online platforms reached fever pitch in the last election cycle in the United States. Jonathan Zittrain’s concern about “digital gerrymandering” found resonance in reports, which were resoundingly denied by Facebook, of the company’s alleged editing of content to tone down conservative voices. At the start of the last election cycle, critics blasted Facebook for allegedly injecting editorial bias into an apparently neutral content generator: its “Trending Topics” feature. Immediately after the election when the extent of dissemination of “fake news” through social media became known, commentators chastised Facebook for not proactively policing user- generated content to block and remove untrustworthy information. Which one is it then? Should Facebook have employed policy- directed technologies or should its content algorithm have remained policy-neutral?

This article examines the potential for bias and discrimination in automated algorithmic decision-making. As a group of commentators recently asserted, “[t]he accountability mechanisms and legal standards that govern such decision processes have not kept pace with technology.” Yet this article rejects an approach that depicts every algorithmic process as a “black box” that is inevitably plagued by bias and potential injustice. While recognizing that algorithms are man-made artifacts, written and edited by humans in order to code decision-making processes, the article argues that a distinction should be drawn between “policy-neutral algorithms,” which lack an active editorial hand, and “policy-directed algorithms,” which are intentionally framed to further a designer’s policy agenda.

Policy-neutral algorithms could, in some cases, reflect existing societal biases and historical inequities. Companies, in turn, can choose to fix their results through active social engineering. For example, after facing controversy in light of an algorithmic determination to not offer same-day delivery in low-income neighborhoods, Amazon nevertheless recently decided to provide those services in order to pursue an agenda of equal opportunity. Recognizing that its decision-making process, which was based on logistical factors and expected demand, had the effect of facilitating prevailing social inequality, Amazon chose to level the playing field.

Policy-directed algorithms are purposely engineered to correct for apparent bias and discrimination or to advance a predefined policy agenda. In this case, it is essential that companies provide transparency about their active pursuits of editorial policies. For example, if a search engine decides to scrub results clean of opposing viewpoints, it should let users know they are seeing a manicured version of the world. If a service optimizes results for financial motives without alerting users, it risks violating FTC standards for disclosure. So too should service providers consider themselves obligated to prominently disclose important criteria that reflect an unexpected policy agenda. The transparency called for is not one based on revealing source code but rather public accountability about the editorial nature of the algorithm.

The article addresses questions surrounding the boundaries of responsibility for algorithmic fairness and analyzes a series of case studies under the proposed framework.

READ ARTICLE

The Top 10 (& Federal Actions): Student Privacy News (November 2017-February 2018)

The Future of Privacy Forum tracks student privacy news very closely, and shares relevant news stories with our newsletter subscribers.* Approximately every month, we post “The Top 10,” a blog with our top student privacy stories. This blog is cross-posted at studentprivacycompass.org. 

The Top 10: Federal Edition

We had so many major student privacy news stories over the past two months that we decided to split our usual Top 10 into a federal vs other news edition. Scroll down to see the non-federal Top 10 stories.

  1. President Trump’s budget proposes $3 million in funding for USED’s Privacy Technical Assistance Center (PTAC), “which serves as a valuable resource center to State and local educational agencies, the postsecondary community, and other parties engaged in building and using education data systems on issues related to privacy, security, and confidentiality of student records” (page 49). The budget also proposes to eliminate federal funding for Statewide Longitudinal Data Systems and Regional Educational Laboratories (page 51). The USED budget request documentation also notes that “One of the significant challenges that ED will work to address is that the large number of ED applications & IT systems currently externally hosted at contractor managed sites across the country are fully compliant w/ Federal & ED cybersecurity and privacy policy and guidelines” (h/t Doug Levin).
  2. The Department of Education (USED) released the first FERPA complaint findings letter to mention an ed tech company in January. FPF released a blog analyzing the decision, and Jim Siegl posted some very interesting thoughts about the decision at his blog. The two key takeaways:
    • Requiring a parent/eligible student to accept a third party’s Terms of Use when they sign up for a school constitutes a forced waiver of rights under FERPA if those Terms of Use are not compliant with FERPA’s school official requirements.
    • When a school requires that an ed tech service be used as a condition of enrollment, that service must either comply with FERPA’s school official exception requirements or parents must be given the right to opt out of its use.
  3. In addition to the Agora letter, USED also released a findings letter that clarifies how video recordings of multiple students should be treated under FERPA (see a write-upof the findings letter from Pullman & Comley).
  4. The FTC and USED held a “Student Privacy and Ed Tech” workshop on December 1stthat examined how the FTC’s “Rule implementing the Children’s Online Privacy Protection Act (COPPA) applies to schools and intersects with the Family Educational Rights and Privacy Act (FERPA),” administered by USED. You can watch a recording of the workshop panels (at the bottom under “Video”), read write-ups via EdWeek and THE Journal, or read the comments filed before the workshop.
  5. On January 30th, the House Education and the Workforce Committee held a hearing, “Protecting Privacy, Promoting Policy: Evidence-Based Policymaking and the Future of Education” (watch the recording or read the EdWeek summary). The hearing was very similar to previous hearings in both 2016 and 2017 about protecting student privacy while allowing for ed research. It “remains up for debate whether increased protections for student data should come from updating the law, bolstering parental consent, improving technology or shaking up education policy research,” via Politico. Meanwhile, EdWeek reports that “The Tricky Dance of Researchers and Educators Gets Even More Complex,” in part due to privacy concerns.
  6. After the cyber threats made to schools last fall, the “FBI is asking school districts to make cyber security a priority” and the FBI and USED issued a “warning about cyber-extortion schemes focused on public schools.” This notice shared that the DarkOverlord hackers were responsible for “‘at least 69 intrusions into schools and other businesses, the attempted sale of over 100 million records containing personally identifiable information (PII), and the release of over 200,000 records including the PII of over 7,000 students due to nonpayment of ransoms.’” Meanwhile, “Cyberattacks Increasingly Target Student Data” (GovTech) and EdWeek reports that “Schools Struggle to Keep Pace With Hackings, Other Cyber Threats.” IT leaders are “likely underestimating the dangers they face;” only 15% of school technology leaders say “they have implemented a cybersecurity plan in their own district” according to a recent CoSN survey. FPF published an op-ed in The Hill with Bill Fitzgerald of Common Sense Media noting that “Securing student data is a challenge that requires sufficient funding,” not more legislation.
  7. The USED Inspector General is currently reviewing “whether Office of the Chief Privacy Officer effectively oversees and enforces compliance with selected provisions of [FERPA] and [PPRA]” (page 12).
  8. The “Student Right to Know Before You Go Act” was introduced in the Senate. The bill “makes data available to prospective college students about schools’ graduation rates, debt levels, how much graduates can expect to earn and other critical education and workforce-related measures of success,” while protecting privacy by “requiring the use of privacy-enhancing technologies that encrypt and protect the data that are used to produce this consumer information for students and families” – namely secure multi-party computation. The ACLU seems to support the bill.
  9. The legislation to reauthorize the Higher Education Act, known as the PROSPER Act, has been introduced. It maintains the ban on a federal student unit record, but does allow for a feasibility study to investigate whether to expand the National Student Clearinghouse to set up a third-party data system to analyze student outcomes (via Inside Higher Ed). PoliticoPro reports: “Push for better student data runs into privacy worries in higher education bill.”
  10. “The Education Department isn’t doing enough to protect student data collected as part of financial aid programs, according to an audit from the Government Accountability Office,” via Politico.

 

The Top 10

  1. Former tech company employees are “forming a coalition to fight what they built.” Among other actions (including a livestreamed event on February 7th), Common Sense Media and the coalition plan “an anti-tech addiction lobbying effort and an ad campaign at [the] 55,000 public schools in the United States [that currently use the CSM Digital Citizenship Curriculum]… It will be aimed at educating students, parents and teachers about the dangers of technology, including the depression that can come from heavy use of social media” (via NYTimes). The focus on children in schools is because they “had little agency over whether they opted into or out of a technology platform because of pressure from both peers and educators handing out assignments.” In the meantime, there were several articles over the past two months on technology and children: The Wall Street Journal reported on “New guidance on children and technology makes the distinction between passive exposure and active play and learning with screens;” The Atlantic asked “Should Children Form Emotional Bonds With Robots?”; and a couple Apple investors “called on the tech giant to take more steps to curb the ill effects of smartphones.” Axios reports that “The internet was created by adults for adults, but it has seen a sharp uptick in kid users over the past 10 years… Silicon Valley has bet its future on younger users, but has come under fire recently for building products that critics say aren’t safe for children.”
  2. Awesome new resource: the Utah State Board of Education has released a video that can be used to train administrators and educators on FERPA exceptions.
  3. Jim Siegl wrote a great blog about “Privacy Differences between Consumer Gmail and G Suite for Education,” and just released a creative commons document that districts can use to inform their community about the district’s G Suite for Education choices and provide information on the difference between Google’s consumer products and G Suite. In related news, some new features for G Suite for Education will “come with a fee.”
  4. Amazon Web Services released a whitepaper on “FERPA Compliance on AWS.”
  5. More news on privacy and personalized learning: EdWeek reports that “States [are taking] Steps to Fuel Personalized Learning,” and PoliticoPro notes that “A dozen states try out ‘personalized learning,’ but questions persist.” Inside Philanthropy asks “Is Personalized Learning the Next Big Thing in K-12 Philanthropy?” and Getting Smart discusses how “Chan Zuckerberg Backs Personalized Learning R&D Agenda” (read the blog on their approach to personalized learning). In the meantime, we have continued to see pushback against personalized learning over the past two months: Diane Ravitch, in an op-ed about “increasing misuse of technology in schools,” writes that “‘Personalized learning,’ …[is a] euphemism for computer adaptive instruction…parents want their children taught by a human being, not a computer.” The 74 shares “5 Ways to Talk (and Think) About Personalized Learning,” EdWeek reports that “Two Districts Roll Back Summit Personalized Learning Platform,” and A Long View on Education discusses “The Propaganda behind Personalised Learning,” But The Atlantic reports on “The Futile Resistance Against Classroom Tech,” noting that ed tech “is here to stay. It’s up to teachers, then, to build networks of learning, solidarity, mutual respect, and even trust.”
  6. Doug Levin has published the full results of his look at the security and privacy of state and (some) district public-facing websites. The primary reported finding is that “State and District Education Websites Fail to Disclose Ad Trackers” (see Doug’s Twitter thread of findings here and coverage from EdSurge). Another security researcher reported their findings that “Website operators are in the dark about privacy violations by third-party scripts,” including at least one ed tech provider described in the article.
  7. Common Sense Media announced that it will be releasing simpler “ratings” for ed tech apps on privacy in early 2018, based on large part on its previous evaluations. They explain more details about the new “roll-up score” apps will receive here. In the meantime, they released a blog on how “it’s often necessary to look in multiple places to find” privacy policies in order to evaluate software.”
  8. A very interesting lawsuit: an autistic, nonverbal student wants “his school to let him wear a device that records his day, but the district says that would violate the privacy of other students.” In related news, a Virginia mom was “charged for putting recording device in daughter’s backpack to catch bullies.”
  9. Virginia has introduced a few bills after a progressive political group “filed FOIA requests [last fall] seeking the publicly available student directories to get student cell phone numbers at every one of Virginia’s 39 public colleges.” The first bill would simply “remove student cell phone numbers and email addresses from publicly available directories,” but was “scrapped” by the House committee (however, its counterpart in the Senate did pass). The second bill, which has passed the House, is much broader, and could cause unintended consequences in schools: it would change how FERPA’s directory information exception currently works to require an opt-in from students for sharing of their directory information instead of an opt-out (this article provides a good overview of the issue and bills). Virginia Lawyers Weekly advocates for a “scalpel” (the first bill) instead of a “sledgehammer” (the second bill).
  10. Audrey Watters, the “Cassandra of Ed Tech,” has published her end-of-year top ed-tech trends articles. I highly recommend reading them; while you might not agree with her perspective, her trend articles provide a fantastic overview of the major student privacy and ed tech stories from 2017. The most relevant to student privacy: “The Weaponization of Education Data,” “Robots Are Coming For Your Children,” and “Education Technology and the New Behaviorism.”

Image: “School days” by Rachel  is licensed under CC BY-NC-SA 2.0.

FPF Welcomes New Senior Fellow

FPF is pleased to welcome Stanley W. Crosley as a senior fellow. Stanley has over 20 years of applied experience in law, data governance and data strategy across a broad sector of the economy, including from inside multinational corporations, academia, large law firm and boutique practices, not-for-profit advocacy organizations, and governmental agencies, and is the Co-Director of the Indiana University Center for Law, Ethics, and Applied Research in Health Information (CLEAR), is Counsel to the law firm of Drinker Biddle & Reath in Washington, DC, and Principal of Crosley Law Offices, LLC.  Stan is a Senior Strategist at the Information Accountability Foundation and a Senior Fellow at the Future of Privacy Forum, where he leads health policy efforts.  He is an Adjunct Professor of Law at Maurer School of Law, Indiana University and lectures on global privacy and data protection, health privacy, and data strategy.

Stan has served as the 2014-2016 Co-Chair of the federal Privacy and Security Workgroup for Health and Human Services Office of the National Coordinator for Health Information Technology (HHS/ONCHIT) providing guidance on health privacy and data security to HHS and the White House.  Stan also serves on the board of The Privacy Projects, and as the Co-Chair of the Research Committee for C-Change.  Stan is the former Chief Privacy Officer for Eli Lilly and Company and is a former board member of the International Association of Privacy Professionals (IAPP), the International Pharmaceutical Privacy Consortium, the Indiana Health Informatics Technology, Inc., served on the IOM HIPAA and Research Workgroup that delivered the first report on the research implications of HIPAA and the Brookings Institute workgroup providing guidance on the FDA’s Sentinel project.

In his global legal practice, and in his activity as a speaker/lecturer, Stan provides thought leadership and practical guidance on topics ranging from the full spectrum of health data issues, applied and innovative technology, and privacy to data strategy and applied data ethics working with a network of regulators from the US, EU and every region of the world and peers in multinational companies and start-ups in the technology, biopharma, medical device, biotech, communications, social media, and health provider industries.

Please join us in welcoming Stanley to the team!

Consumer Reports Publishes Initial Findings for Privacy and Security of Smart TVs

Today, Consumer Reports released their initial findings on the privacy and security aspects of Smart TVs. Applying their Digital Standard (developed with Ranking Digital Rights and other partner organizations), Consumer Reports identified a range of important privacy aspects and potential security vulnerabilities in Smart TVs from five leading manufacturers (Sony, Samsung, LG, TCL, and Vizio).

As we noted last week in our discussion of Smart TVs, it can be challenging for even well-informed buyers to locate and fully understand the data policies of their TVs. This is complicated by the fact that data from internet-connected TVs may be collected and processed by multiple entities (manufacturers, operating system providers, and third-party apps such as Netflix and Hulu). In addition, the market for TV data is still relatively nascent, although growing rapidly. As buyers become attuned to privacy and security features of all connected devices — including the broader Internet of Things (TVs, smartphones, smart homes, and connected cars) — we expect that the market for secure, privacy-conscious consumer technology will improve and grow.

In response, Roku has expressed their disagreement with Consumer Reports’ characterization of a potential security vulnerability, and Consumer Reports will be conducting a live Q&A Privacy Hour this evening (8-9pm ET / 5-6pm PT) about digital privacy, smart TV and toys, and best practices.

Looking Ahead

We expect Consumer Reports to continue studying and publishing their findings related to privacy and security features of connected devices. Here are some things we look forward to seeing:

Overall, we commend Consumer Reports on their important work. As internet-connected home devices continue to proliferate, these initial findings represent an important milestone in making privacy and security features accessible to consumers, researchers, and advocates.

FPF Welcomes New Interns

Lin-hsiu Huang

Lin is our Communication/Design intern for the Spring Semester. Lin is originally from Kaohsiung, Taiwan, and she is seeking a dual degree in BFA Art/Design and BS Mathematics at Morehead State University. She has presented her advocacy research and productions – documentaries and music videos – in over a dozen conferences (e.g. Poster on the Hill, the Appalachian Studies Conference, the Southern Honors Council Regional Conference). Lin works with Melanie Bates, the Director of Communications, and she will be focusing on various design and re-branding tasks such as the monthly newsletter, the Annual Report, and one-pagers, as well as updating FPF’s privacy calender and monitoring its website analytics.

Esther Lim

Esther is studying for her Masters of Laws in Global Health Law at the Georgetown University Law Center, where she previously served as a Global Health student fellow and a research assistant in the O’Neill Institute of National and Global Health Law. She earned her Bachelor of Laws degree from the University College of London. She previously worked as a Health Policy Analyst in Singapore’s Ministry of Health, working on issues of regulatory policy and health information.

Seeing the Big Picture on Smart TVs and Smart Home Tech

CES 2018 brought to light many exciting advancements in consumer technologies. Without a doubt, Smart TVs, Smart Homes, and voice assistants were dominant: LG has a TV that rolls up like a poster; Philips introduced a Google Assistant-enabled TV is designed for the kitchen; and Samsung revealed its new line of refrigerators, TVs, and other home devices powered by Bixby, their intelligent voice assistant. More than ever before, companies are emphasizing “seamless connectivity” between TVs and other connected home devices. In other words, users will be able to instruct their TV to dim the lights, display footage from their home security camera, show who is standing at the front door, or even see what’s inside the fridge — all features envisioning the TV as the command center of the ideal, futuristic Smart Home.

In the midst of this ongoing explosion in “intelligent” consumer electronics, we continue to see concern about TVs that “listen,” TVs that allegedly “spy,” and more recently, mobile apps that can “hear” what might be playing on the TV or happening in users’ living rooms. It can be challenging to distinguish accurate reports from inaccurate ones (for example, we wrote in 2015 about Samsung TVs and the confusion that stemmed from a privacy policy that was misinterpreted by many journalists).[1]

Nonetheless, Smart TVs are raising serious data privacy questions that apply broadly to all Smart Home devices – for example, how long should a manufacturer be responsible for installing software updates to keep an Internet-connected TV secure? Do buyers fully understand what kinds of data their TV manufacturer is collecting, and how to control it? How much information should be presented on the box before purchase? It is critical to identify solutions that maximize consumer benefits while avoiding privacy risks and harms.

A Deep Dive into Leading Smart TVs

In order to better understand the privacy and security issues raised by Smart TVs, we recently had the opportunity to informally review the policies and user interfaces of 2017 models from three leading manufacturers: Sony (which uses the Android TV interface), LG, and Samsung.[2] We aimed to learn more about the privacy and security aspects of leading Smart TVs.

Overall, Smart TV data practices vary considerably. Consumer choices are not always easy to exercise, and there remains a great need for transparency and consensus around how TV data should be used. Advertising using Smart TV data, for example, is a nascent but rapidly growing industry, and many TV buyers are not yet aware of the extent to which their other activities (online and offline) may be synced with their TV viewing information in a way that informs and drives advertising. Security is also a critical aspect — in today’s TVs, software updates are not necessarily automatic, or guaranteed to continue, and it can be difficult for even a well-informed person to make a purchasing decision on the basis of a company’s security practices. Although Smart TVs promise great benefits to consumers, there is clearly more work to be done to build consensus around privacy and security.

 

Skip ahead to:

What Makes a TV “Smart?”

Smart TVs Vary in their Privacy Settings and Features

Advertising using Smart TV Data is a Nascent, but Growing Industry

Conclusions

 

What Makes a TV “Smart?”

Smart TVs – or, as they are often promoted, “intelligent TVs,” are TVs that connect to the Internet to allow users to access streaming video services (such as Netflix or Hulu), other online media or entertainment, such as music, on-demand video, and web browsers. Many Smart TVs have their own App Stores, making them more similar to large-screen computers than traditional displays. Many are now integrating connectivity with other Smart Home technologies like lights, baby monitors, or kitchen appliances.

In addition to the wide variety of new entertainment options, a less appreciated benefit of Smart TVs is the ability to generate accurate, reliable TV viewing measurement data. Historically, TV viewing was difficult to measure, resulting in efforts by companies such as Nielsen to encourage families to voluntarily track their TV viewing habits. The inevitable result, as discussed by several speakers in the Federal Trade Commission’s recent workshop, was that only the most popular and mainstream TV viewing would typically be measured accurately.

In the last ten years, as TVs and streaming media has become more sophisticated, it has become possible to measure less popular or even obscure content. The ability to know what kinds of content people are actually interested in, even if it isn’t mainstream, has allowed for greater investment in content that previously would have been too risky – for example (as discussed by Samba TV’s Ashwin Navin at the FTC’s Smart TV workshop), Arrested Development (canceled and then re-launched by Netflix), or The Mindy Project (picked up by Hulu).

Nonetheless, the same data collection that allows for accurate TV viewing measurement often creates concerns around individual privacy. For example, individual data can be used to create detailed profiles based on viewing habits, sometimes in expected ways (e.g. Netflix suggestions), and sometimes in unexpected ways.

Smart TVs Vary in their Privacy Settings and Features

Are all Smart TVs the same with respect to their data practices? In many ways, they are not. The TVs we unboxed and set up had significant differences in privacy features, including things like: whether relevant policies are easily available; whether and how users are prompted to consent to data collection and uses; whether users can delete their personal data; and whether software updates are installed automatically. Notably, some TV manufacturers run software from other companies (e.g. LG TVs that run Android OS), but other manufacturers actively collect data for advertising and other purposes. Hardware manufacturers are responsible for many of the things buyers care about, like screen size, picture quality, and durability, but when it comes to data privacy, buyers should also think about the operating system and apps.

There are also some issues applicable to all modern TVs that deserve greater attention – specifically, the fact that digital advertising using TV data is a rapidly growing industry that has not yet developed consensus around privacy norms. These important questions about data privacy have broader implications for other connected devices in the Internet of Things (IoT) and the Smart Home.

Key privacy and security issues:

Relevant privacy policies are not always available.

A minimum standard for any connected device is the existence of a relevant, accurate, and, as far as possible, easy to comprehend privacy policy. Despite longstanding critiques of privacy policies – i.e. that many or most people do not read them – written policies nonetheless play a crucial role in U.S. privacy law. In addition to providing the basis for enforcement by the Federal Trade Commission if companies don’t keep their promises, they provide information to researchers, tech journalists, and privacy advocates, who routinely analyze and compare practices.

All Smart TVs that we reviewed provided users with access to privacy policies within the TV settings menu (although they varied somewhat in ease of navigation and text size). Some Smart TV manufacturers also provide access to their policies outside of the TV itself. For example, Samsung, Vizio, and Google (whose Android TV software powers devices offered by several manufacturers) make policies available online. In contrast, 2017 LG TVs provide a detailed privacy policy on the device, but it does not appear to be available on LG’s website or outside of the TV interface. No major manufacturers provide comprehensive privacy statements on TV packaging, which can make it challenging for prospective buyers in physical retail stores to compare privacy policies across brands.

Unsurprisingly, the TV manufacturer with the most readily available and clear Privacy Policy is most likely Vizio, which is also the only TV manufacturer to date (that we know of) whose TVs have been the subject of regulatory investigations, including a $2.2M settlement with the U.S. Federal Trade Commission and New Jersey Attorney General. Smart TV manufacturers would do well to follow the example of increased transparency and consumer education, and leaders in this space could go much further and present information “on the box” (as we called for in our connected toys report) so that prospective buyers can make well-informed decisions.

Automated Content Recognition (ACR) is a common feature of Smart TVs.

All Smart TVs that we reviewed – and probably, nearly all modern Smart TVs – are equipped with automated content recognition (ACR) technology.  ACR is usually built in to the TV software but also present in many third party apps. An early example of ACR technology is Shazam, the popular music recognition app that is now available on many leading TVs.

Generally, ACR technologies use one of two methods: fingerprinting or watermarking. The most common method, audio/video-based fingerprinting, relies on periodically extracting a “fingerprint” of unique characteristics of the content being watched, and sending it to a third party matching service to identify the content. Watermarking, in contrast, relies on the content creator to embed a unique “overlay” or “watermark” (often imperceptible) into the audio or video file so that it can be recognized again in the future.

Fingerprinting vs. Watermarking
Fingerprinting:

  • Audio or video-based
  • Extracts a set of unique properties from an audio or video signal (does not add any information)
  • Requires comparison with an external “matching” database to identify the content

Common Uses:

  • TV viewing measurement;
  • TV interactivity features (e.g. in-show trivia, live polls, or identifying songs or actors’ names during a show);
  • behavioral advertising;
  • detecting copyright infringement
Watermarking:

  • Audio or video-based
  • Adds a unique “overlay” or “watermark” of data (either perceptible or imperceptible), embedding it within an audio or video signal
  • Requires knowing what you’re looking for, i.e. allowing content creators to identify their own content

Common Uses:

  • tracking individually owned content;
  • identifying content creators;
  • tracing proprietary media (anti-piracy), e.g. in cinema distribution

Most Smart TVs provide users with notice of ACR data collection through on-screen notices, but the policies typically describe the collection of “Viewing Information,” or “Viewing History,” providing little detail about what the ACR technology collects or how it works in detail. Some examples of how ACR-enabled viewing data is described in on-screen policies (on file with author):

Some manufacturers also describe ACR data collection in privacy policies that users can access online; the most comprehensive description of ACR technology and its related uses appears in Vizio’s Privacy Policy, which contains a Viewing Data Supplement. The data practices and privacy disclosures of Vizio Smart TVs have been the subject of substantial public scrutiny, regulatory investigations, and a settlement with the U.S. Federal Trade Commission and New Jersey Attorney General.

TVs vary in how they obtain consent to collect and use ACR data.

A key principle of U.S. privacy law is that technology providers should ask users for their consent prior to the collection of use of their personal information, especially sensitive information such as granular TV viewing data. However, what this consent should look like, and how to structure users’ choices, is a frequent source of debate.

Occasionally, offering choices is not practical, because data might be necessary for a device to work as intended – for example, any Internet-connected device necessarily sends an IP address and MAC address in order to connect to a network. In contrast, automated content recognition data (“ACR Data”), while it may enable certain benefits, is not necessary for the TV to function. Furthermore, ACR involves the collection of sensitive information about everything that viewers are watching and when. As a result, it is appropriate for TV manufacturers to offer robust choices around the collection of this kind of data.

In the TVs that we “unboxed,” notice and consent for the collection of ACR data varied. For example, Samsung TVs ask users to opt in to optional data collection during set-up. In contrast, the LG TV presented a basic privacy statement during set-up, and then asked for additional permissions later when we tried to use the specific features that required those extra permissions. In general, these sorts of “just in time” notices reflect a more privacy-conscious design. Although in some ways it makes sense to place all the information “up front,” the set-up process is also a time when users are eager to get the device running, and not necessarily well-positioned to distinguish between routine terms of service (which may be required to set up the TV at all) and optional privacy choices related to added benefits.

Software updates (a key component of good security) are not necessarily automatic or guaranteed to continue.

As TVs become more like computers, a growing issue is the extent to which manufacturers have an obligation to continue supporting software and pushing updates to fix security vulnerabilities. As any smartphone user knows, receiving persistent reminders for app and OS updates can be frustrating, but updating software is crucial to good security.

In leading 2017 TVs, security updates are possible, but not necessarily automatic by default. In addition, it is not clear how often manufacturers push updates for security vulnerabilities. Most TV manufacturers have bug bounty programs (for example, Samsung’s Smart TV bug bounty program; Google’s vulnerability rewards program, which applies to Android TV; and Sony’s Secure@Sony program), which provide an incentive for independent security researchers to report security flaws so that companies can fix software before consumers are affected. However, without automatic updating or prominent notices on the TV interface, it can be difficult to ensure that TV buyers take the steps necessary to secure their devices.

Finally, many manufacturers do not yet make explicit assurances to their customers about how long they will continue to support older TV models. Given that the average lifespan of a TV is around 7-10 years, it is crucial that Smart TVs, with all of their added connectivity and software-dependent services, continue to be updated for a reasonable time. Furthermore, with enough transparency, software support can be a powerful selling point for a budget-impacting purchase. The importance of Smart TV security is heightened as the newest TVs become linked to other devices in smart homes.

Smart TVs vary in policies for data retention and deletion.

Finally, as with all connected devices, a key question for Smart TV providers is how they should handle users’ requests for deletion of accounts and associated data. Deletion of data is not only a practical consideration – for example, if a buyer decides to sell or re-purpose a TV – but increasingly viewed as an aspect of consumer privacy rights.

Leading Smart TV manufacturers have very different policies regarding data retention and users’ opportunity to meaningfully delete their personal information:

TV Manufacturer On-Screen Retention Policy
Sony (Bravia) “You can stop uploading the TV usage logs at any time in [Help] -> [Privacy setting]. If this uploading is disabled, the above information about the use of this TV will no longer be uploaded to Sony Corporation . . . Information already uploaded to Sony Corporation with a unique number shall be deleted or converted to anonymized statistical data within approximately six months. The viewing history data stored in this TV will also be deleted and as a result the functions which use viewing history data may not be available (such as “Popular” program recommendations).”
Samsung “Interest based advertisements will be linked to a randomized, non-persistent, and resettable device identifier called the “PSID.” You may reset your PSID at any time by visiting the settings menu, and once reset, your viewing history and Smart TV usage information will be cleared and de-linked.”
LGE “We will take reasonable steps to make sure that we keep your personal information for as long as is necessary for us to provide you with LG Smart TV Services or for the purpose for which it was collected, or as required by law.”
Vizio*

* We did not unbox a Vizio TV – the following is from Vizio’s online Privacy Policy

“If you request removal of Personal Information, you acknowledge that residual Personal Information may continue to reside in VIZIO’s records and archives, but VIZIO will not use that Personal Information going forward for commercial purposes.”

 

Digital advertising using Smart TV data is a nascent, but rapidly growing, industry.

While Smart TV data can be used for a wide range of useful features (including measurement, recommendations, and interactivity features such as in-show trivia, polling, or song recognition), it can also be used for personalized advertising in potentially unexpected or intrusive ways. As a result, there is a need for greater transparency, understanding, and consumer education on issues of TV data privacy.

Programmatic advertising, while well-established in the online ecosystem, is still nascent and growing rapidly for Smart TV data. There are two sides to TV data and advertising: (1) the use of TV viewing data for serving advertisements elsewhere, such as on associated devices; and (2) the use of data from other sources (online browsing behavior on associated devices, social media activities, or demographics) to display an advertisement on a TV. Although both activities may be surprising to consumers, they carry different implications for individual privacy.

In discussions around best practices, processors of TV data are often inclined to apply the same, or similar, standards as those that exist for online behavioral advertising, such as the Network Advertising Initiative’s Code of Conduct. Although similarities exist, direct application of standards for online advertising may not be appropriate unless they take into account key differences:

Finally, it was surprising to note that several leading Smart TVs are integrating advertising into their main user interfaces. In other words, the TV’s main screens are being designed to contain static placements for digital advertisements (whether personalized or otherwise). For many, this will be a serious downside that might not be understood at the time of purchase. Will we start to see differential pricing for Smart TVs – a less expensive TV with advertisements, and a more expensive TV without advertisements? Although this would not necessarily be unusual for connected devices, it remains to be seen how TV buyers would respond to such a pricing model.

Conclusions

Overall, the industry for Smart TVs and Smart TV data, much like the broader “Internet of Things” ecosystem, is relatively nascent. In the absence of baseline privacy legislation that would provide minimum standards for commercial collection and use of personal information, there is little consensus or consistency between different TV manufacturers about the appropriate ways to collect and use data. Smart TVs promise a range of benefits and interactive features – but are also collecting data for advertising and commercial purposes that might surprise many Smart TV users.

Unfortunately, even well-informed prospective buyers of Smart TVs do not yet have easily available tools to compare TVs on the basis of their privacy and security features. As more consumers start to use Smart TVs as a central hub for connected home devices, good security is also critical. Ironically, strong security practices can make it more difficult for independent researchers to evaluate privacy features. For example, a side effect of the increased use of SSL encryption (an important security safeguard for well-designed connected devices) is that security researchers are not able to analyze data being sent and received by a Smart TV.

We look forward to Consumer Reports’ emerging Digital Standard, which promises to provide such tools for prospective buyers to compare connected devices on many key privacy aspects – such as, for example, the existence of clear policies, or the default settings of ACR. Inevitably, it will be difficult for outside observers to compare Smart TVs on the basis of their internal business practices (especially as data is increasingly better secured and challenging to assess from external observation). For these reasons, independent trusted organizations will likely play a key role in addressing these challenges in years to come. By working towards greater transparency and privacy commitments,

 

 

[1] For more information on the 2015 Samsung concerns and other privacy issues related to voice data and speech-enabled devices, read Future of Privacy Forum’s 2015 report, “Always On: Privacy Implications of Microphone-Enabled Devices.”

[2] In evaluating Smart TVs, we approached each 2017-model TV from the perspective of an average user, relying only on public-facing documents and the communications presented in the TV’s user interface. Although some of the companies discussed here are also supporters of FPF, we applied the same approach to all TVs and believe that we have presented a fair, accurate comparison of key privacy and security aspects.