Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, September 12, 2018

Sen. Commerce Committee Hearing :: Sept 26 :: Examining Consumer Privacy Protections

"WASHINGTON – U.S. Sen. John Thune (R-S.D.), chairman of the Senate Committee on Commerce, Science, and Transportation, will convene a hearing titled “Examining Safeguards for Consumer Data Privacy,”at 10:00 a.m. on Wednesday, September 26, 2018. This hearing will examine privacy policies of top technology and communications firms, review the current state of consumer data privacy, and offer members the opportunity to discuss possible approaches to safeguarding privacy more effectively.
Consumers deserve clear answers and standards on data privacy protection,” said Thune“This hearing will provide leading technology companies and internet service providers an opportunity to explain their approaches to privacy, how they plan to address new requirements from the European Union and California, and what Congress can do to promote clear privacy expectations without hurting innovation.”
Witnesses:
  • Mr. Len Cali, Senior Vice President—Global Public Policy, AT&T Inc.
  • Mr. Andrew DeVore, Vice President and Associate General Counsel, Amazon.com, Inc.
  • Mr. Keith Enright, Chief Privacy Officer, Google LLC
  • Mr. Damian Kieran, Global Data Protection Officer and Associate Legal Director, Twitter, Inc.
  • Mr. Guy (Bud) Tribble, Vice President for Software Technology, Apple Inc.
  • Ms. Rachel Welch, Senior Vice President, Policy & External Affairs, Charter Communications, Inc.
*Witness list subject to change.
Hearing Details:
Wednesday, September 26, 2018
10:00 a.m.
Full Committee
Dirksen Senate Office Building G50
Witness testimony, opening statements, and a live video of the hearing will be available on www.commerce.senate.gov.

Monday, April 30, 2018

FTC Warns Gator Group, Tinitell that Online Services Might Violate COPPA

Press Release "The staff of the Federal Trade Commission sent letters to two foreign companies that market electronic devices and apps that appear to collect geolocation data from children, warning that the companies may be in violation of the Children’s Online Privacy Protection Act (COPPA) Rule.
The letters were sent to China-based Gator Group Co., Ltd., and Sweden-based Tinitell, Inc., which both provide online services. Gator Group advertises an app and a device called the Kids GPS Gator Watch, which it markets as a “child’s first cell phone.” Tinitell has also marketed an app that works with a mobile phone worn like a watch, which is also designed for children. Although Tinitell has stopped selling the devices, they will continue to operate through September 2018. Copies of the letters were also sent to the Apple App Store and the Google Play Store, which make the apps available to consumers in their stores.
The FTC’s COPPA Rule requires companies collecting personal information from children under the age of 13 to post clear privacy policies and to notify parents and get their consent before collecting, using or sharing personal information from a child.
In its letters to the two companies, the FTC noted that even though they are based outside the United States, foreign companies are required to comply with COPPA when their services are directed to children in the United States or they knowingly collect information from U.S.-based children.
The online services offered by both companies appear to be directed to children and to collect precise geolocation information from children. The letters note that a review of both companies’ services reveal that they do not appear to provide direct notice of their collection practices and do not seek verifiable parental consent before collecting, using or disclosing personal information as required by COPPA.
The letters encourage the companies to review their online services, policies and procedures to ensure they are in compliance with COPPA."

Monday, March 20, 2017

In Which I Get Another Excuse to Babble About the "Enhanced Service" / "Telecom Service" Dichotomy :: FTC v. American eVoice

Time to brush the dust off your Computer II notebooks.  Are voicemail, electronic fax, and call forwarding enhanced services or telecom services?

Today's case: FTC v. American eVoice, Ltd, et al, CV-13-03-M-DLC (DC Montana Mar. 14, 2017). See also Stipulated Permanent Injunction.

The FTC brought an action against Defendants claiming that they were engaged in cramming, adding unwanted voicemail, electronic fax, and call forwarding services to consumers bills to the tune of $70 million. Slip at 3. The FTC concluded that this was a violation of Sec. 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices in or affecting commerce." Slip at 3.


Defendants filed a motion to dismiss, arguing that they are common carriers and therefore exempt from FTC jurisdiction. This argument had been successful recently. In FTC v. ATT Mobility (9th Cir. Aug. 2016), the FTC had brought an action against ATT Mobility for data throttling (before the FCC's Open Internet order declaring Internet access service a telecommunications service). The 9th Circuit found that ATT Mobility had the status of a common carrier, therefore the FTC lacked jurisdiction over ATT Mobility. Specifically, Sec. 5 states that the FTC lacks jurisdiction over "common carriers subject to the Acts to regulate commerce."  The term "common carrier" is not defined in Sec. 5. The 9th Circuit conducted an extensive review, concluding that the language applied generally to firms that have the status of being a common carrier, and not specifically only to actions that constitute the provision of common carriage.  In other words, according to the holding of the 9th Circuit, the FTC lacks jurisdiction over ATT Mobility even if ATT Mobility is selling hot dogs out of a push cart because ATT Mobility has the status of common carriage for some other part of its business.

So are Defendants in the case at hand "common carriers" or not?

The Court cites to Computer II authority, for which it gets my thumbs up. But of course Computer II has been superseded by the Telecommunications Act of 1996 which codified definitions for an "information service" (a.k.a. "enhanced services") and a "telecom service." An "Information Service" is
the offering of a capability for generating, acquiring, storing, transforming, processing, retrieving, utilizing, or making available information via telecommunications, and includes electronic publishing... - 47 U.S.C. § 153(20)
By contrast, a "telecom service"
means the offering of telecommunications for a fee directly to the public 47 U.S.C. § 153(53)
And of course, "telecommunications"
means the transmission, between or among points specified by the user, of information of the user’s choosing, without change in the form or content of the information as sent and received. 47 U.S.C. § 153(50)
As the court states, telecom service is essentially a pipeline. It is the transmission layer of the communications service. It pretty much is someone saying "hi grandma" into a telephone network and "hi grandma" comes out the other end.

Anything more than that is an "information service." This is a bright line test. If "hi grandma" is spoken into the network and "Bonjour Grand-mère" comes out the other end of the network, you gots yourself "a change in the form or content of the information" sent.

The FCC and the courts have been deciphering the distinction between "information services" and "telecommunications services" for more than half a century. There is a bit of precedent here. What we know, according to the court, is that defendants offered "voicemail, electronic fax, and call forwarding." Have previous courts and the FCC passed on whether these are "information services"? Yes they have.


Service
Classification
Authority
Voicemail Information Service CPE Order 2001 ¶ 2; FWD MOOStevens Report, ¶ 73; BOC Petition Order 13770-774, App. A; Computer II Final Decision, ¶ 98; In re Southwestern Bell CEI Plan for the Provision of Voice Messaging Services, DA 88-1469, Memorandum Opinion and Order, 3 FCC Rcd. 6912, 65 Rad. Reg. 2d (PF) 527,  1 (September 29, 1988); Petition USTelecom2013 ¶ 20; Computer III Further NPRM 1998 ¶ 1
Electronic Fax Information Service (actually, the court does not describe what 'electronic fax' is so I am not 100% confident but....) :: Computer III Further NPRM 1998 ¶ 1; Review of Customer Premises Equipment and Enhanced Services Unbundling Rules in the Interexchange, Exchange Access and Local Exchange Markets, CC Docket No. 98-183, Further Notice of Proposed Rulemaking, para 1, n. 20 (October 9, 1998); MOO, Bell Operating Companies Joint Petition for Waiver of Computer II Rules, DA 95-36, 10 FCC Rcd 1724 n.3, 1995 FCC LEXIS 217 **2 (Jan 1995)
Call Forwarding Telecom Service Stevens Report, ¶ 73; Computer II Final Decision, ¶ 98

Whoops. That did not go as planned. "Call Forwarding" is a "Telecom Service"?? According to Computer II
We indicated that 'computer processing applications such as call forwarding, speed calling, directory assistance, itemized billing, traffic management studies, voice encryption, etc., may be used in conjunction with 'voice' service.'  The intent was to recognize that while POTS is a basic service, there are ancillary services [a.k.a. adjunct services] directly related to its provision that do not raise questions about the fundamental communications or data processing nature of a given service. Accordingly, we are not here foreclosing telephone companies from providing to consumers optional services to facilitate their use of traditional telephone service. - Computer II Final Decision, ¶ 98. 
Ah! So now we have to introduce one more concept: adjunct services. According to the FCC, adjunct services are services that may involve something that looks like an information service but facilitates the operation of the telecommunications service. Adjunct services take on the regulatory classification of the facilitated telecom service. Here is a simple example. If you call directory assistance to get a telephone number so that you can make a call, that's an adjunct service and therefore a telecom service. If however you call directory assistance with a reverse lookup, querying with a telephone number and asking for the name, that is an information service because that reverse lookup does not facilitate the operation of the telecom service (you already have the telephone number; getting the name doesn't help set up the call).

The policy behind this exception was that telecom services like ATT and the Baby Bells were prohibited from providing information services pursuant to the 1956 Consent Decree. The FCC wanted ATT to be able to offer services that facilitated operation of the telecommunications service - things like directory assistance, call forwarding, speed dialing, and caller ID. So the FCC classified these very telephone-like things as "adjunct-to-basic" services. The Telecommunications Act codified this as the Telecom Management Exception.

But an adjunct service must be adjunct to something. An adjunct service that is adjunct to nothing - this has no meaning. If ATT offers call forwarding, then this 'enhancement' facilitates the use of ATT's telecom service and therefore takes on the regulatory classification of ATT's telecom service (in other words, the "information service prohibition" would not have blocked ATT Mobility from offering this service). However, a company that just offers call forwarding but does not also offer a telecom service wasn't prohibited from offering information service in the first place and cannot offer an adjunct service to a non-existent telecom service. Thus, a stand-alone enhancement like call forwarding falls within the "information service" bucket and not the "adjunct service therefore telecom service" bucket. 

According to the court, "there is no evidence before the Court that the corporate Defendants operated a transmission pipeline" [a.k.a. telecom service]. Slip at 10. Unlike ATT Mobility which had the status of "common carrier" because some part of that company offers common carrier service (even though other parts of the company do not), no part of Defendants companies were found to offer "telecom service," thus Defendants do not fall within the FTC exception to jurisdiction over common carriers.

Oh, by the way, the Court noted a further problem with Defendants' claim to be "common carriers." According to the Court, they had not registered with the FCC as common carriers; they had not named an agent for service of process as a common carrier; they made no showing that they complied with common carrier obligations like paying into the universal fund. Slip at 11. Adding to the jurisprudence of the Duck Test, the Court concluded that these Defendants don't quack like a duck.

Defendants' Motion to Dismiss on the grounds that Defendants are common carriers outside the jurisdiction of the FTC dismissed.

Thursday, July 07, 2016

:: Priorities for the National Privacy Research Strategy

Release: Vast improvements in computing and communications are creating new opportunities for improving life and health, eliminating barriers to education and employment, and enabling advances in many sectors of the economy. The promise of these new applications frequently comes from their ability to create, collect, process, and archive information on a massive scale.
However, the rapid increase in the quantity of personal information that is being collected and retained, combined with our increased ability to analyze and combine it with other information, is creating concerns about privacy. When information about people and their activities can be collected, analyzed, and repurposed in so many ways, it can create new opportunities for crime, discrimination, inadvertent disclosure, embarrassment, and harassment.
This Administration has been a strong champion of initiatives to improve the state of privacy, such as the “Consumer Privacy Bill of Rights” proposal and the creation of the Federal Privacy Council. Similarly, the White House report Big Data: Seizing Opportunities, Preserving Values highlights the need for large-scale privacy research, stating: “We should dramatically increase investment for research and development in privacy-enhancing technologies, encouraging cross-cutting research that involves not only computer science and mathematics, but also social science, communications and legal disciplines.”
Today, we are pleased to release the National Privacy Research Strategy. Research agencies across government participated in the development of the strategy, reviewing existing Federal research activities in privacy-enhancing technologies, soliciting inputs from the private sector, and identifying priorities for privacy research funded by the Federal Government. The National Privacy Research Strategy calls for research along a continuum of challenges, from how people understand privacy in different situations and how their privacy needs can be formally specified, to how these needs can be addressed, to how to mitigate and remediate the effects when privacy expectations are violated. This strategy proposes the following priorities for privacy research:
  • Foster a multidisciplinary approach to privacy research and solutions;
  • Understand and measure privacy desires and impacts;
  • Develop system design methods that incorporate privacy desires, requirements, and controls;
  • Increase transparency of data collection, sharing, use, and retention;
  • Assure that information flows and use are consistent with privacy rules;
  • Develop approaches for remediation and recovery; and
  • Reduce privacy risks of analytical algorithms.



  With this strategy, our goal is to produce knowledge and technology that will enable individuals, commercial entities, and the Federal Government to benefit from technological advancements and data use while proactively identifying and mitigating privacy risks. Following the release of this strategy, we are also launching a Federal Privacy R&D Interagency Working Group, which will lead the coordination of the Federal Government’s privacy research efforts. Among the group’s first public activities will be to host a workshop to discuss the strategic plan and explore directions of follow-on research. It is our hope that this strategy will also inspire parallel efforts in the private sector.

Thursday, June 09, 2016

:: House Commerce Hearing: FCC Overreach: Examining the Proposed Privacy Rules.


FRED UPTON CHAIRMAN
FRANK PALLONE, JR. RANKING MEMBER
ONE HUNDRED FOURTEENTH CONGRESS
Congress of the United States
House of Representatives
COMMITTEE ON ENERGY AND COMMERCE
2125 Rayburn House Office Building Washington, D.C. 20515 Majority (202) 225-2927
Minority (202) 225-3641

June 7, 2016
Committee on Energy and Commerce
Subcommittee on Communications and Technology
HEARING NOTICE
The Subcommittee on Communications and Technology will hold a hearing on Tuesday, June 14, 2016, at 10:15 a.m. in 2123 Rayburn House Office Building. The hearing is entitled “FCC Overreach: Examining the Proposed Privacy Rules.” Witnesses will be announced and are by invitation only. The hearing webcast will be available at http://energycommerce.house.gov/.
By Order of Chairman Walden 
https://energycommerce.house.gov/hearings-and-votes/hearings/fcc-overreach-examining-proposed-privacy-rules

Tuesday, April 19, 2016

FCC Broadband Privacy NPRM RFC





Monday, November 09, 2015

:: "The Commission has been unequivocal in declaring that it has no intent to regulate edge providers."

In Re Consumer Watchdog Petition for Rulemaking toRequire Edge Providers to Honor ‘Do Not Track’Requests Released: November 6, 2015

1. In this Order, we dismiss Consumer Watchdog’s request that the Commission “initiate arulemaking proceeding requiring ‘edge providers’ (like Google, Facebook, YouTube, Pandora, Netflix, and LinkedIn) to honor ‘Do Not Track’ Requests from consumers.” 1 The Commission has been unequivocal in declaring that it has no intent to regulate edge providers.

2 We therefore find that, pursuant to section 1.401(e) of our rules, the Consumer Watchdog Petition “plainly do[es] not warrant consideration by the Commission.”3 2. Section 222 of the Communications Act governs telecommunications carriers’ protection and use of information obtained from their customers or other carriers, and calibrates the protection of such information based on its sensitivity. The Commission has adopted rules implementing section 222’s privacy protections with respect to providers of voice services, has amended those rules over time to respond to emerging threats to consumer privacy, and has vigorously enforced those rules.4

3. Earlier this year, when the Commission reclassified broadband Internet access service (BIAS) as a telecommunications service under Title II of the Communications Act, it declined to forbear from applying section 222 to BIAS providers. 5 The Commission found that broadband providers “serve as a necessary conduit for information passing between an Internet user and Internet sites or other Internet users, and are in a position to obtain vast amounts of personal and proprietary information about their customers.”6 Recognizing, however, that the existing rules were written for voice services, the Commission held it was “not persuaded that the Commission’s current rules implementing section 222 necessarily would be well suited to broadband Internet access service.”7 It therefore forbore from applying the section 222 rules to BIAS services, “pending adoption of rules to govern broadband Internet access service in a separate rulemaking proceeding.”8 At the same time, the Commission specified that in reclassifying BIAS, it was not “regulating the Internet, per se, or any Internet applications or content.”9 Rather, as the Commission explained, its “reclassification of broadband Internet access service involves only the transmission component of Internet access service.”10

 4. Consumer Watchdog’s request that “the Commission should, in addition to the CPNI rules it intends to adopt, promulgate rules protecting the authorized use of consumers’ personal information by requiring edge providers to honor ‘Do Not Track’ Requests” is inconsistent with the Commission’s articulation of the effect of its reclassification of BIAS and the scope of the privacy practices it stated that it intends to address pursuant to that reclassification. 11 We therefore find that the Consumer Watchdog Petition plainly does not warrant consideration by the Commission pursuant to section 1.401(e) of the Commission’s rules.

5. Accordingly, IT IS ORDERED that, pursuant to sections 0.91, 0.291, and 1.401(e) of the Commission’s rules, 47 C.F.R. §§ 0.91, 0.291, 1.401(e), Consumer Watchdog’s Petition for Rulemaking to Require Edge Providers to Honor ‘Do Not Track’ Requests IS DISMISSED.


Wednesday, October 28, 2015

:: NIST Seeks Comments on New Project Aimed at Protecting Privacy Online

The National Cybersecurity Center of Excellence (NCCoE), in partnership with the National Strategy for Trusted Identities in Cyberspace National Program Office, is seeking comments on a new project focused on protecting privacy and security when reusing credentials at multiple online service providers.
Many organizations now allow online customers to use third-party credentials to create and manage accounts and services. For example, your social media account login can be used to access your fitness tracker account. In effect, the social media company is vouching for you with the tracker company.
Allowing third-party credentials saves businesses time and resources in managing identities. For users, the benefit comes from not having yet another username and password to manage and remember.
As these arrangements become more common, a growing number of organizations are laboring to manage—and integrate—each third-party relationship. So now a new service, called brokered identity management, has emerged. Organizations can engage identity brokers to manage multiple third-party credentialing options on their behalf.
The benefits to organizations and individuals are significant, but there is also a concern that these connections meant to improve security can create opportunities for increased tracking of users.
This new collaborative project will examine how commercially available privacy-enhancing technologies can be integrated into identity broker solutions. The NCCoE is seeking comments on a draft document that describes a potential “building block”—one of a series of solutions that address cybersecurity concerns for multiple industry sectors. The document, Privacy-Enhanced Identity Brokers, describes the technical challenges of adding privacy-enhancing technologies to existing products or services, and the technical controls needed to address the privacy risks inherent in them.
Feedback from businesses and the public will inform the project and solution development. This will ultimately result in an 1800-series NIST Cybersecurity Practice Guide that will demonstrate the example solution and provide all the information necessary to replicate the reference design.
The NCCoE addresses businesses' most pressing cybersecurity problems with practical, standards-based solutions using commercially available technologies. The center collaborates with industry, academic and government experts to build modular, open, end-to-end reference designs that are broadly applicable and repeatable.
The document can be viewed on the NCCoE website. Comments should be submitted to via a web form or to petid-nccoe@nist.gov by Dec. 18, 2015.

Saturday, June 07, 2014

NTIA RFC Big Data and Consumer Privacy in Internet Economy

Request for Comments on Big Data and Consumer Privacy in the Internet Economy

Date: 
June 04, 2014
Docket Number: 
Docket No. 140514424-4424-01
NTIA is requesting comment on “big data” developments and how they impact the Consumer Privacy Bill of Rights. NTIA and the Department of Commerce invite public comment on these issues from all stakeholders, including the commercial, academic, and public interest sectors, legislators, and from governmental consumer protection and enforcement agencies.
Comments are due on or before 5 p.m. Eastern Time on August 5, 2014.

Tuesday, July 23, 2013

As the Nebuad Litigation Turns.... Mortensen v. Bresnan Communications

The litigation fallout from ISPs partnership with Nebuad continues.  Today's decision is the latest chapter out a lawsuit against a Montana ISP:
In 2008, Bresnan [Defendant ISP] entered into a temporary arrangement with advertising company NebuAd, Inc. Under the arrangement, in exchange for a share of NebuAd's advertising revenue, Bresnan [Defendant ISP] allowed NebuAd to place an appliance in its Billings, Montana, network. The appliance allowed NebuAd to gather information and create profiles of subscribers in order to target them with preference-sensitive advertising. Bresnan contends that it provided specific notice to consumers about the NebuAd trial and allowed individuals to opt out. Under a heading labeled "About Advanced Advertising," the company website provided detailed information about the trial. It also gave a list of thirteen frequently asked questions with corresponding answers that assured customers that no personally identifying information, such as first and last name, physical street address, email address, telephone numbers, or social security numbers would be collected. Plaintiffs contend that this notice was misleading and that consent was never obtained.
Plaintiffs brought suit Defendant ISP for violations of the Electronic Communications Privacy Act (dismissed previously), the Computer Fraud and Abuse Act, Montana state privacy law (dismissed previously), and trespass to chattels. 

Today's decision takes a contortious turn, not on Internet law (my normal beat), but on the Supremacy Clause of the U.S. Constitution and Defendant ISP's choice of law provision in the terms of service.  Today's case involves a Montana subscriber, an ISP doing business in Montana, an action that transpired in Montana, and a claim for a violation of a Montana law.  Pop Quiz: what state's law should apply??

Hint: The ISP is headquartered in New York and incorporated in Delaware.

Hint two:  The terms of service say that the law of New York applies (thus a cause of action based on Montana law would be bupkis).

Hint Three: The terms of service says that all claims shall be submitted to arbitration pursuant to the Federal Arbitration Act.

Okay, that seems unfair.  The case involves a Montana subscriber, an ISP's operations in Montana, and a violation that purportedly transpired in Montana.  Why should New York's law apply?? 

And when its seems this unfair, and when the customer has no choice in the matter, we call this a contract of adhesion, void as a matter of public policy.  That's what the lower court concluded, stating that Montana citizens had a constitutional right to trail by jury and access to the courts. Therefore, Plaintiff's litigation should go forward.

Not so fast, said the appeals court.  You see, there is this federal law called the Federal Arbitration Act, and it strongly favors arbitration. "Any general state-law contract defense, based in unconscionability or otherwise, that has a disproportionate effect on arbitration is displaced by the FAA."  If you are going to say that a contractual provision requiring arbitration is unconscionable because of some Montana law, then that state law is preempted - you lose.

Now comes the twister:  The Federal Arbitration Act just kicked the legs out from Montana saying its citizens have a right to a trail over arbitration.  Okay, what about the choice of law?  Does Montana law or New York law apply?  "Montana uses the Restatement (Second) of Conflict of Laws § 187(2), which finds a choice-of-law provision overcome where 
(1) Montana has a materially greater interest in the transaction than the state whose law was selected by the parties and 
(2) application of the selected state's law would be contrary to Montana's public policy."
Does Montana have a greater interest in this case?  Sure, says the court.  "The contract was received by the consumers in Montana as part of their Welcome Kit, and the contract governed services provided in Montana to Montana residents. The subject matter of the contract and performance of it took place almost entirely in Montana."

But here's the problem.  With the preemption of Montana law by the Federal Arbitration Act, there is no longer a public policy conflict with Montana law.  New York law favors arbitration; Montana law does not - Montana's disfavorance of arbitration got the boot.  Lacking a public policy conflict, the test for overriding a choice-of-law provision in a contract now fails.


Outside of the legal holding and the status of this litigation, the Court provides background on how another Nebuad litigation was resolved:
After NebuAd's temporary arrangement with Bresnan to gather information from the subscribers ended, a class of plaintiffs, including those involved in the present action, brought suit in the United States District Court for the Northern District of California against NebuAd and several Internet service providers who hosted NebuAd appliances, including Bresnan. Bresnan and the other providers moved to dismiss the action for lack of personal jurisdiction and failure to state a claim. The district court granted this motion finding personal jurisdiction lacking. Valentine v. NebuAd, Inc., No. C08-05113 TEH, 2009 WL 8186130, at *3-10 (N.D. Cal. Oct. 6, 2009). NebuAd became the sole defendant in that action and eventually reached a court-approved settlement with the plaintiffs.
According to Wikipedia, "Due to fallout following public and Congressional concern, NebuAd's largest ISP customers have all pulled out. NebuAd closed for business in the UK in August 2008, followed by the US in May 2009. NebuAd UK Ltd was dissolved in February 2010."

Monday, July 08, 2013

ART :: Schwartz, Paul M., Information Privacy in the Cloud (May 1, 2013). University of Pennsylvania Law Review

Schwartz, Paul M., Information Privacy in the Cloud (May 1, 2013). University of Pennsylvania Law Review, Vol. 161, No. 1623 (2013). Available at SSRN: http://ssrn.com/abstract=2290303

Abstract:  Cloud computing is the locating of computing resources on the Internet in a fashion that makes them highly dynamic and scalable. This kind of distributed computing environment can quickly expand to handle a greater system load or take on new tasks. Cloud computing thereby permits dramatic flexibility in processing decisions – and on a global basis. The rise of the cloud has also significantly challenged established legal paradigms. This Article analyzes current shortcomings of information privacy law in the context of the cloud. It also develops normative proposals to allow the cloud to become a central part of the evolving Internet. These proposals rest on strong and effective protections for information privacy that are sensitive to technological changes.

This Article examines three areas of change in personal data processing due to the cloud. The first area of change concerns the nature of information processing at companies. For many organizations, data transmissions are no longer point-to-point transactions within one country; they are now increasingly international in nature. As a result of this development, the legal distinction between national and international data processing is less meaningful than in the past. Computing activities now shift from country to country depending on load capacity, time of day, and a variety of other concerns. The jurisdictional concepts of EU law do not fit well with these changes in the scale and nature of international data processing.

A second legal issue concerns the multi-directional nature of modern data flows, which occur today as a networked series of processes made to deliver a business result. Due to this development, established concepts of privacy law, such as the definition of “personal information” and the meaning of “automated processing” have become problematic. There is also no international harmonization of these concepts. As a result, European Union and U.S. officials may differ on whether certain activities in the cloud implicate privacy law.

A final change relates to a shift to a process-oriented management approach. Users no longer need to own technology, whether software or hardware, that is placed in the cloud. Rather, different parties in the cloud can contribute inputs and outputs and execute other kinds of actions. In short, technology has provided new answers to a question that Ronald Coase first posed in “The Nature of the Firm.” New technologies and accompanying business models now allow firms to approach “make or buy” decisions in innovative ways. Yet, privacy law’s approach to liability for privacy violations and data losses in the new “make or buy” world of the cloud may not create adequate incentives for the multiple parties who handle personal data. 

Thursday, March 01, 2012

Workshop :: FTC Will Host Public Workshop to Explore Advertising Disclosures in Online and Mobile Media on May 30, 2012

"The Federal Trade Commission will host a day-long public workshop to consider the need for new guidance for online advertisers about making disclosures required under FTC law. The guidance will address technological advancements and marketing developments that have emerged since the FTC first issued its online advertising disclosure guidelines known as “Dot Com Disclosures” 12 years ago. 
 
The workshop, to be held on May 30, will cover revising the Dot Com Disclosures so they illustrate how to provide clear and conspicuous disclosures in the current online and mobile advertising environment. Any revisions will be consistent with the goals of the original guidelines and will continue to emphasize that consumer protection laws apply equally to online and mobile marketers, and to other media. The FTC began seeking input for revising the Dot Com Disclosures guidelines last year.  

"Topics may include:
  • How can effective disclosures be made on social media platforms and mobile devices – including when they are used in commercial texting – that limit the space available for disclosure?  For example, when consumers are paid or receive other benefits for providing an endorsement, how can they effectively disclose on platforms that allow only short messages or a simple sign of approval?
  • When can disclosures provided separately from an initial advertisement be considered adequate?  For example, if a consumer receives a location-based ad for a discounted cup of coffee on her mobile device because she is near a particular coffee shop, what terms must be disclosed in the mobile ad and what terms, if any, do not have to be disclosed until the consumer enters the coffee shop to make her purchase?
  • What are the options when using devices that do not allow downloading or printing the terms of an agreement?  For example, is providing consumers a means to send a copy of the agreement to themselves to read later an effective way to provide this information?
  • How can disclosures that are made in the original advertisement be retained when the advertisement is aggregated (for example, on dashboards) or re-transmitted (through, for example, re-tweeting)?  
  • What are the disclosure opportunities and limitations of hyperlinks, jump links, hashtags, click-throughs, layered disclosures, icons, and other similar options?  How should these options be evaluated in terms of placement and proximity?
  • How can short, effective, and accessible privacy disclosures be made on mobile devices?
  • What does the research show about how consumers’ use of mobile and other devices can affect the effectiveness of disclosures on particular devices or platforms?  And what does it show about the relationship between how consumers use mobile devices and their understanding of disclosures and advertising displayed on mobile devices?  What does the research show about how consumers make decisions based on that information?  Is there specific research on the effectiveness of disclosures on mobile devices, including layered disclosures and icons, and, if so, what are the implications of that research for disclosures such as offer terms and privacy practices?
The Commission also invites parties to submit suggestions for topics of discussion or original research.  In particular, the Commission invites the submission of realistic examples and mock-ups that can be used for illustration and discussion at the workshop. Individuals and organizations may submit requests to participate as panelists and may recommend topics for inclusion on the agenda.

  The requests and recommendations should be submitted electronically to dotcomdisclosuresworkshop@ftc.gov. Prospective panelists should submit a statement detailing their expertise on the issues to be addressed and contact information no later than March 30, 2012. Panelists will be selected based on expertise and the need to include a broad range of views.
Paper submissions should reference the Dot Com Disclosures Workshop both in the text and on the envelope, and should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-135 (Annex P), 600 Pennsylvania Avenue, N.W., Washington, DC 20580.  The FTC requests that any paper submissions be sent by courier or overnight service, if possible, because postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions. The workshop is free and open to the public.  It will be held on Wednesday, May 30, 2012, at the FTC Conference Center at 601 New Jersey Avenue, N.W., Washington, DC.  Pre-registration is not required.  Members of the public and press who wish to participate but who cannot attend can view a live Webcast at FTC.gov.

Wednesday, February 29, 2012

RFC :: NTIA :: #privacy :: Multistakeholder Process to Develop Consumer Data Privacy Codes of Conduct :: Comments Due TBD

Date: February 29, 2012  Docket Number:  Docket No. 120214135-2135-01

"NTIA is requesting comment on substantive consumer data privacy issues that warrant the development of legally enforceable codes of conduct, as well as procedures to foster the development of these codes.  NTIA invites public comment on these issues from all stakeholders with an interest in consumer data privacy, including the commercial, academic and civil society sectors, and from federal and state enforcement agencies.  Written comments may be submitted by e-mail to privacyrfc2012@ntia.doc.gov.