Thursday, March 18, 2010
Privacy Audits
Wednesday, March 10, 2010
A new chance to get the Working Party to work better?
Friday, March 5, 2010
Billions of photos online, Billions of privacy offenders?
Tuesday, March 2, 2010
Grazie! for your support
Wednesday, February 24, 2010
Today's astonishing verdict in Milan
Google has already reacted to today's astonishing verdict in Milan. I'd like to add a few personal words.
I will vigorously appeal today's verdict in Milan. The judge has decided I am criminally responsible for the actions of some Italian teenagers who uploaded a reprehensible video to Google Video. I knew nothing about the video until after it was removed by Google in compliance with European and Italian law. I was very saddened by the plight of the boy in the video, not least as I have devoted my professional life to preserving and protecting personal privacy rights. Despite this a public prosecutor in Milan has spent 3 years investigating, indicting and successfully prosecuting me and 2 other Google colleagues.
Monday, February 22, 2010
Austrian insights
When introducing the concept of indirectly personal data, the Austrian legislators referred on the face of the bill before Parliament to Article 2 (a) of the Directive and, in particular, to the phrase ‘…an identifiable person is one who can be identified, directly or indirectly…’. This suggests that a deliberate decision was made to distinguish between persons who can be identified directly (and for which the full force of the Austrian Law applies) and those persons who can only be identified indirectly – hence the concept of indirectly personal data. In the eyes of the legislators, indirectly personal data did not require the full range of protection that directly personal data required. There may additionally have been commercial and practical reasons considered by the legislators why to require organisations to treat indirectly personal data in the same way as directly personal data made no sense.
This is how I've been told Austrian Law treats indirectly personal data below:
Section | Provision |
8 (2) | Use of only indirectly personal data shall not constitute an infringement of the fundamental interest in secrecy that deserves protection under s. 1 (1). |
9 (1) (2) | Use of sensitive data does not infringe interests in secrecy deserving protection only and exclusively if data are used only in indirectly personal form. |
12 (3) | Transborder data exchange shall not require authorisation if data are transferred or committed that are only indirectly personal to the recipient |
17 (2) | There is no requirement to notify the Data Protection Commission where the data application only contains indirectly personal data. |
24 (4) | There is no duty to provide information to data subjects when collecting data where such data is not subject to notification under s. 17 i.e. this would include the use of indirectly personal data. |
29 | The rights granted under s. 26 – 28 cannot be exercised insofar as only indirectly personal data are used. Section 26: right of access Section 27: right of rectification/ erasure Section 28: right to object |
46 (1) | For the purpose of scientific or statistical research projects where the goal is not to obtain results in a form relating to specific data subjects, the controller shall have the right to use all data that are only indirectly personal for the controller. |
46 (5) | Where the use of data in a form which permits identification of data subjects is legal for purposes of scientific research or statistics, the data shall be coded without delay so that the data subjects are no longer identifiable if specific phases of scientific or statistic work can be performed with indirectly personal data only |
Friday, February 12, 2010
An American in Paris
Monday, February 1, 2010
The new rules for cookies in Europe
Despite some inaccurate press, the revised text of the ePrivacy directive does not require an opt-in for cookies. However, the text of the revised directive may be misunderstood especially if the preamble of the new directive is not transposed into national law. So national governments need to take great care when implementing the new law, in order not to jeopardise the development of the Internet and the information society.
Friday, January 22, 2010
Photos to the Web

Monday, January 18, 2010
The "adequacy" regime is inadequate
There are many people in Europe who would rather eat their “chapeau” than admit that non-European countries like the United States might have adequate privacy protection, based on long-standing cultural or ideological bias. In my opinion, it’s the European “adequacy” regime that has become inadequate in today’s world. It’s near the top of my list of things that need to be modernized in European privacy law. It’s a political/bureaucratic fiction that some countries provide “adequate” data protection, while others don’t, because the decision is based on criteria that have almost nothing to do with the level of data protection on the ground, in the real world. A country can’t be deemed “adequate” if it doesn’t have an EU-style data protection authority. But the idea is ludicrous to me that privacy somehow couldn’t be protected in countries without such an agency, and in fact, the vast majority of countries in the world don’t have such an agency. And whatever labels are applied, the reality, in the age of the Internet, is that data is flowing around the globe. To take one topical example, cyber attacks do not respect borders, and take no note of whether or not a target is based in a country with “adequate” data protection.
So, recently, Israel and the Principality of Andorra have been added to the EU list of “adequate” countries. They join other countries already on the list, including: Argentina, Canada, Guernsey, Jersey, the Isle of Man, and Switzerland. Stop to read that list again, and ask yourself, really, this is the global list of “adequate” countries outside the EU? Really?
In privacy terms, what’s the right way forward for the future? As I’ve said before, follow the Canadian model, and make any company/government that collects personal data responsible and accountable for protecting it, regardless of where it happens to process it. If it can’t protect data adequately in a particular country, it shouldn’t send it there. If a company decides it can adequately protect its data in Japan, but not in Bulgaria, so be it, even if EU law would suggest the contrary. Common sense should prevail for the sake of privacy.
At the beginning of each year, I make a resolution to visit at least two new countries a year. If I’m lucky, I’ll have my wish and get to visit Andorra and Israel this year. They’re both on my adequacy list.
Friday, January 15, 2010
Privacy Officers with a French accent
Since I’m based in France, I’ve recently been appointed as Google’s “Correspondant” for data protection with the French Data Protection Authority, the CNIL. The profession of privacy officers is generally less developed in Europe than the US, and indeed, the position of “correspondant” was first created in France in 2004. Like many things in France, even this private-sector role is defined and guided by the government, in the long French tradition of dirigisme:
“From now on, local authorities, public services and associations are allowed to appoint a "Correspondant Informatique et Libertés" (CIL). It is a major innovation in the application of the law, as prior pedagogy and advice are emphasized. Indeed, the data controller which appoints a CIL is exempted, in most cases, from the notification process to the CNIL. The CIL has the duty to ascertain that the information system of the organization will expand without harming the rights of the users, clients and employees.”
Monday, January 11, 2010
Practice makes perfect

Google launched three major industry-leading privacy initiatives that implemented the key privacy principles of transparency and choice -- interest-based advertising, the data liberation front, and Google Dashboard.
It's a great tennis facility, on Key Biscayne, with grass courts, no less. Someone builds and maintains a grass court in that unlikely climate, and it must be a lot of work. And people pay a lot of money to live in "privacy", which usually means living in a place, like Key Biscayne, where they are secluded and protected from other people. So, now that there are online privacy tools, like the ones I just mentioned, I wonder if people will really use them more. I mean, to play tennis, you have to run and serve and swing. To protect your privacy, you should hustle a little too. Someone else can build the grass court, but it's up to you to play.
Friday, January 8, 2010
Watching people walk down the street
Wednesday, January 6, 2010
DC: discussing privacy in public
Friday, December 4, 2009
On the sidewalk in Milan
Thursday, December 3, 2009
Remembering and Forgetting in Berlin

I've spent a few days in Berlin, and I've spoken with many interesting politicians and journalists about privacy. The most interesting case must surely be this one:
Two German Killers Demanding Anonymity Sue Wikipedia’s Parent
http://www.nytimes.com/2009/11/13/us/13wiki.html?_r=1&scp=3&sq=german%20wikipedia%20murder&st=cse
In some countries in Europe, like Germany and France, there are well-established principles about the "right to be forgotten", an awkward translation of the "Droit a l'Oubli." As a privacy-sensitive guy, I'm all for the idea that people ought to be able to walk away from some awkward facts at some point in their lives. But I have never heard anyone be able to tell me how the "right to be forgotten" does not quickly cross the line into censorship. If two German murderers can require German publishers to remove references to their names in articles after they have served their sentence, isn't that censorship? And wouldn't it be even worse if they tried to re-write news archives, which are now rapidly becoming instantly findable online? And in the real world what will be the consequences if German Wikipedia deletes content that English Wikipedia still publishes?
And while I was in Berlin, I visited the Holocaust memorial, as I always do when in Berlin, and I wondered about the "right to be forgotten" in the midst of the memorial to "never forget".
Friday, November 27, 2009
Madrid and Berlin, trying to find workable approaches
Here’s an interesting article about the day-to-day challenges and contradictions of national laws in the context of the global Internet (ok, it does use some of us Google guys as unhappy examples, but just to make a valid point):
http://www.bloomberg.com/apps/news?pid=20601039&sid=aAv2iLcBnqtI
http://www.expansion.com/2009/11/12/juridico/entrevistas/1258051264.html
I’m off to Berlin now. Germany is one of those places where I feel the need to listen more than talk. I'll blog about what I learn afterwards.
Thursday, November 26, 2009
Thanksgiving
Like most Americans, I woke this morning to one of my favorite days of the year, Thanksgiving. Unlike most Americans, I also woke this morning to news reports of an Italian prosecutor calling for me to be sentenced to one year in prison.
But in the spirit of the day, now that I’ve skimmed the news and reassured friends that I’m not going to prison (I hope), I’ll go about my day:
I’ll do some planning for my Dad’s 80th Birthday Party, do a kick-boxing class at gym, work on an academic privacy paper on the hotly-debated question of whether IP addresses should be considered “personal data” under EU law, give legal advice on some privacy questions, prepare for some meetings in Berlin, and, best of all, I’ll end the day with a candle-light dinner with the person I love in the city I love.
That’s a lot to be thankful for (well, not the Berlin or the Milan parts), but the rest anyway.
Wednesday, November 25, 2009
European law on hosting platforms
How does the E-Commerce prescription work in real life? Say an Internet user uploads a video filled with illegal hate speech, nudity, or violence. When notified of this illegal content, the hosting platform is obliged to take it down. The hosting platform, however, is not obliged to monitor and prevent the upload. The responsible party is the Internet user who posts the content. In this case, Google did exactly what the law requires - it removed the content upon notification, and took the further step of complying with law enforcement requests, helping to bring the wrongdoers to justice.
If Google and companies like it were responsible for every piece of content on the web, the Internet as we know it today – and all of the economic and social benefits it provides – would disappear. Without appropriate protections, no company would be immune: any potentially defamatory text, inappropriate image, bullying message or violent video would have the power to shut down the platform that had unknowingly hosted it. In the offline world, it would be like criminally prosecuting post office employees because someone mailed an inappropriate letter. European law recognizes the importance of providing limitations on the liability of hosting platforms.
The Directive applies horizontally across all areas of law which touch on the provision of information society services, regardless of whether it is a matter of public, private, or criminal law. This is confirmed in the first Report from the Commission to the European Parliament on the application of Directive 2000/31/EC dated 8 June 2000. See p. 4: "The Directive applies horizontally across all areas of law which touch on the provision of information society services, regardless of whether it is a matter of public, private, or criminal law. Furthermore, it applies equally both to business-to-business (B2B) and business-to-consumer (B2C) e-commerce." And see p. 12: "The limitations on liability provided for by the Directive are established in a horizontal manner, meaning that they cover liability, both civil and criminal, for all types of illegal activities initiated by third parties."
From a public policy perspective, it wouldn't make any sense if it didn't apply to criminal charges. The objective of the directive was to foster a competitive and dynamic knowledge-based economy in the EU. To provide an environment in which its citizens would have access to inexpensive, world-class communications infrastructure and a wide range of services. To create conditions for e-commerce and the internet to flourish. To enhance quality of life, to stimulate innovation and job creation, and to contribute to the free flow of information and freedom of expression. Those are words directly from the Commission. It wouldn't make any sense to apply these protections only to civil matters; doing so would permit criminal claims to eviscerate the very benefits the directive sought to achieve.
