Thursday, March 18, 2010

Privacy Audits


In theory, privacy audits are a sensible and useful thing. Regardless of whether they're conducted internally or externally, they can provide insights into data handling systems, identify shortcomings, and help prioritize resources. They can provide external, independent validation of compliance with privacy laws and contractual commitments. And they can be a useful source of transparency. Sometimes, they're even mandated by privacy law, e.g., in some controller-processor outsourcing arrangements under EU data protection rules. Considering how many good reasons there are to conduct privacy audits, it's a bit of a mystery to me why there isn't more of an industry to provide them. Indeed, if you were looking to hire external experts to conduct privacy audits, and if you asked me for a recommendation, well, I'd be kind of stuck to give you a name. I've asked a bunch of my peers at other companies too, and privately, they're stumped too.

Lots of people purport to be able do privacy audits. Law firms, accounting firms, consulting firms are all ready to sell this service, at sometimes astronomical costs, but in practice, if you ask around amongst people who have tried to hire them, you often hear people complain about high-priced pay-as-you-learn tutorials for junior professionals. There are also a few "low-cost" versions floating around, but they are often rudimentary checklists (e.g., "do you have a written privacy policy in place? yes, check!") etc. There must be more room for the happy middle ground between the super-high-cost customized audit and the self-audit checklist models.

So, here's a business idea. Why don't some enterprising people work to establish a privacy auditing business, combining some deep technical understanding with process rigor, offer the service at a competitive cost, and help fill a vacuum? Almost everyone in the profession whom I know agrees that privacy audits are, in theory, a useful tool for privacy hygiene, but in practice, it's hard to find the right level of professional service.

There seems to be a clear market failing here. Over time, surely, the idea of privacy audits will become more integrated into good privacy practice. Whoever can figure out how to provide this service will be contributing to the privacy profession and probably end up making a lot of money. Good luck!

Wednesday, March 10, 2010

A new chance to get the Working Party to work better?

I'm delighted to see a new Chairman, Jacob Kohnstamm, assume the helm at the Working Party, which is the group of all of Europe's national Data Protection Authorities, created to try to achieve common approaches to privacy across Europe. Mr. Kohnstamm is a privacy leader whom I've known for years, and whom I greatly admire, even when we find ourselves on the opposite sides of the debate. I'm confident he'll provide new leadership and relevance at the Working Party. I also think it's healthy for European institutions to break away from alternating franco-german leadership, which has so dominated the Working Party over many years.

As a privacy professional, people sometimes ask me why I take the Working Party seriously, and why I would want to see it play a greater role in privacy matters in Europe? The answer is simple: with all its institutional flaws, any body that contributes to a more harmonized data protection across Europe is better than the alternative, with 27 different approaches and inconsistent cacophony. Since the Working Party is the best instrument we've got in Europe to try to do things in a coherent way, I think it's worth taking a moment to make suggestions about how it could work better. My comments are strictly focused on only one aspect of its role, namely, the extent to which it interacts with the private sector in a semi-regulatory context. My critiques are offered in a spirit of constructive feedback.

So, what are the key issues that deserve attention to make the Working Party work better in the future?

Public Transparency: the Working Party operates behind closed doors. It rarely involves outsiders in its deliberations. It almost never publishes draft opinions for external review, and rarely (if ever) opens its meetings to the public. As far as I know, it never publishes the range of consenting/dissenting views with its opinions, and it publishes little more than a summary agenda and adopted Opinions. I strongly believe that transparent government is good government, and the Working Party is simply not transparent today.

Accountability and Review: the Working Party's opinions are not "binding" and therefore have never, to my knowledge, been subject to judicial review. Sometimes Working Party opinions make sense, sometimes not. Sometimes they're insightful, sometimes they're gibberish. External, objective, academic, technical, maybe even judicial review, is much needed.

Technical expertise: The Working Party has many times embarked on issues which turn on Internet technical architecture. There is not enough technical expertise at the Working Party level, which is unsurprising, considering that the members generally come from political or administrative backgrounds. But to have well-informed discussion about Internet regulation, a foundation of technical knowledge must be in place, or must be provided from the outside.

Confidentiality: To deal with confidential business matters in a semi-regulatory context, any regulatory body needs to be able to respect business secrets submitted to it. Maintaining confidentiality has not been a strong point of the Working Party, given that its documents are routinely distributed amongst 27 countries. But leaks damage the ability of the Working Party to be effective.

Speed: In tech circles, things move fast. This is an innovation business, after all. But a discussion with the Working Party can often take years, with rather stilted exchanges of letters, each exchange punctuated by multi-month pauses. Surely, there must be a faster, less formalistic, way to collaborate.

All in all, these critiques are meant to be constructive. I think privacy would be well-served by a more realistic and collaborative dialogue between the Working Party and industry. The old Working Party made some progress, but there's room for more. I'm hopeful about the future.

Friday, March 5, 2010

Billions of photos online, Billions of privacy offenders?


With the proliferation of Internet platforms for user-generated content, people are increasingly seeing examples where one person's right to freedom of expression may infringe someone else's right to privacy, and vice-versa. If I upload my holiday pictures to the Internet, taken from a public place, and if they capture you lounging by your pool, does my freedom of expression trump your right to privacy, or the other way around? Whatever you think, there are already billions of such photos online and publicly accessible.

Both freedom of expression and privacy are fundamental human rights. But those rights are not both equally enforced, protected or policed. There are literally thousands of data protection bureaucrats in Europe whose job is to enforce European data protection regulations. As far as I can tell, there is not a single government official in all of Europe whose sole job is to do the same for freedom of expression. Curious, no?

As I go to privacy-centric conferences where people invariably talk about the problems and risks of social networking sites, I'm often the odd guy out who seems to think that they're also precious platforms for freedom of expression. Lots of guys in power lecture about how lives or careers or futures are jeopardized by a single embarrassing photo posted to a platform.

Well, I'm not so sure. I was thinking about what this guy showed when he was young, and he just got elected Senator, so maybe things are changing.

A privacy regulator in Europe told me the other day that he thought it was a data protection violation for anyone to post a photo online if it captured someone's face or property without their consent. I asked him whether he thought this restricted the right to freedom of expression. He didn't seem to understand the question.

Tuesday, March 2, 2010

Grazie! for your support


I'm thinking about Italy a lot these days. Many of you have expressed your support, and I'm gratified by your concern and your solidarity.

I see this case has prompted an important debate and passionate expressions of support for the principles of freedom of expression that I have always felt are at stake in this prosecution. We'll get the Judge's written opinion within 90 days of last week's verdict, so probably around mid-May. Until then it's hard to speculate about his precise legal reasoning, even if the implications of this conviction are already being widely discussed in terms of the potential liability of employees working for internet platforms that host user-generated content. As for me, I'm not really at liberty to comment much publicly, because, anything I say about it can (and has!) been used against me.

Many thanks to you, my many friends in the privacy community who have reached out to me. Grazie!

Wednesday, February 24, 2010

Today's astonishing verdict in Milan

Google has already reacted to today's astonishing verdict in Milan. I'd like to add a few personal words.


I will vigorously appeal today's verdict in Milan. The judge has decided I am criminally responsible for the actions of some Italian teenagers who uploaded a reprehensible video to Google Video. I knew nothing about the video until after it was removed by Google in compliance with European and Italian law. I was very saddened by the plight of the boy in the video, not least as I have devoted my professional life to preserving and protecting personal privacy rights. Despite this a public prosecutor in Milan has spent 3 years investigating, indicting and successfully prosecuting me and 2 other Google colleagues.


This ruling also sets a very dangerous precedent. If company employees like me can be held criminally liable for any video on a hosting platform, when they had absolutely nothing to do with the video in question, then our liability is unlimited. The decision today therefore raises broader questions like the continued operation of many Internet platforms that are the essential foundations of freedom of expression in the digital age. I recognize that I am just a pawn in a larger battle of forces, but I remain confident that today’s ruling will be over-turned on appeal.

Monday, February 22, 2010

Austrian insights

I've been thinking about the conundrum of trying to fit all of the words data into two random black-and-white categories: "personal" data or "non-personal" data, or personally-identifiable information and non-PII if you prefer. The reason we're all trying to do this is because most of the world's legal regimes create these two categories, and only these two categories, even if it's obvious that many things sit uncomfortably in the gray zone between them. The big privacy debates generally turn on these gray-zone categories, which identify some things about an individual (e.g., speaks Spanish), but don't identify an actual human being. Think of the privacy debates around IP addresses, cookies, RFIDs etc, and you see that the debates can't be settled using only these two categories.

I think the way forward is the creation of a third-category, something we could call "indirectly identifiable data". Interestingly, Austrian law has already done that. Here are some insights into the Austrian law, the Austrian Federal Act concerning the Protection of Personal Data (Datenschutzgesetz 2000). Under Austrian Law, data is ‘only indirectly personal’ for a controller, a processor or recipient of a transmission when ‘the Data relate to the subject in such a manner that the controller, processor or recipient of a transmission cannot establish the identity of the data subject by legal means." In other words, the identity of the individual can be retraced but not by legal means.

When introducing the concept of indirectly personal data, the Austrian legislators referred on the face of the bill before Parliament to Article 2 (a) of the Directive and, in particular, to the phrase ‘…an identifiable person is one who can be identified, directly or indirectly…’. This suggests that a deliberate decision was made to distinguish between persons who can be identified directly (and for which the full force of the Austrian Law applies) and those persons who can only be identified indirectly – hence the concept of indirectly personal data. In the eyes of the legislators, indirectly personal data did not require the full range of protection that directly personal data required. There may additionally have been commercial and practical reasons considered by the legislators why to require organisations to treat indirectly personal data in the same way as directly personal data made no sense.

This is how I've been told Austrian Law treats indirectly personal data below:

Section

Provision

8 (2)

Use of only indirectly personal data shall not constitute an infringement of the fundamental interest in secrecy that deserves protection under s. 1 (1).

9 (1) (2)

Use of sensitive data does not infringe interests in secrecy deserving protection only and exclusively if data are used only in indirectly personal form.

12 (3)

Transborder data exchange shall not require authorisation if data are transferred or committed that are only indirectly personal to the recipient

17 (2)

There is no requirement to notify the Data Protection Commission where the data application only contains indirectly personal data.

24 (4)

There is no duty to provide information to data subjects when collecting data where such data is not subject to notification under s. 17 i.e. this would include the use of indirectly personal data.

29

The rights granted under s. 26 – 28 cannot be exercised insofar as only indirectly personal data are used.

Section 26: right of access

Section 27: right of rectification/ erasure

Section 28: right to object

46 (1)

For the purpose of scientific or statistical research projects where the goal is not to obtain results in a form relating to specific data subjects, the controller shall have the right to use all data that are only indirectly personal for the controller.

46 (5)

Where the use of data in a form which permits identification of data subjects is legal for purposes of scientific research or statistics, the data shall be coded without delay so that the data subjects are no longer identifiable if specific phases of scientific or statistic work can be performed with indirectly personal data only


All of this is interesting, because I think privacy law will never adapt to the nuances of the real world if the entire real world has to be fit into only two black and white categories. Finding a legal category to deal with the gray zone is essential to getting privacy laws right, and the Austrian model is one of the most promising I've seen.

Friday, February 12, 2010

An American in Paris

A year ago, in the early phases of thinking about how or whether to suggest revisions to the European Data Protection Directive, the European Commission created a little "group of experts" to provide ideas. This unpaid group was formed after a public call for applications, and had no mandate other than to produce some ideas. Expert groups are a common process at the Commission. Since I'm very interested in this topic, and since I represent a technical/global/Internet perspective on things, I was happy to apply and even happier to be accepted to join it. But the group was disbanded after only one meeting, as reported here.

As an American who has lived in Paris for many years, I was more than a little startled to see French politicians launch a campaign to get the European Commission to disband this group because it contained..."Americans". Naturally, I thought it was odd to hear this anti-American rhetoric applied to me. It's hard to find an American more Francophile than me. One of the other guys on the experts' group was an American of German origin who has lived in Brussels for many years and is universally recognized as one of the world's great legal experts on European data protection law.

Of course, it was distasteful for me to hear French government officials engaging in conventional French political rhetoric against "Americans", but this was the first time in my professional life that I was the explicit target of it. I don't like xenophobia in any guise, even if it's just public posturing. But I also remind myself that anti-Americanism has long been one of the common threads of European data protection rhetoric, such as the endless posturing of the EU Parliament on SWIFT.

Privately, things are different. Privately, these same French audiences regularly invite me to discussions or hearings on privacy issues. In recent months, I've had separate meetings with committees focusing on modernizing privacy laws in the French Senate, with French politicians, and with the French Data Protection Agency. Privately, there's a very thoughtful debate underway in many French government circles on these important questions, and I'm privileged to be invited to participate in them. Privately, we all understand that the privacy debate has become global, and only global solutions will work in the long run.

Anyway, here are some excellent ideas from the European Privacy Officers Forum about what needs to be modernized in this window of review of increasingly obsolete European privacy laws. Had our "experts' group" not been disbanded, we might have made similar recommendations...

Monday, February 1, 2010

The new rules for cookies in Europe

Despite some inaccurate press, the revised text of the ePrivacy directive does not require an opt-in for cookies. However, the text of the revised directive may be misunderstood especially if the preamble of the new directive is not transposed into national law. So national governments need to take great care when implementing the new law, in order not to jeopardise the development of the Internet and the information society.


In its Article 5(3), the ePrivacy directive outlines strong safeguards to protect users from unwanted software such as adware, junk, or even viruses and spyware, requiring software vendors to seek their consent.

For cookies, the EU legislation's preamble specifically says that the control settings in a browser are sufficient to comply with the consent requirement. Even for cookies that cannot be controlled by browsers – for example, Silverlight and Flash cookies – the new law also recognises that the settings of specific control panels satisfy the consent requirement.

The directive’s new preamble contributes to legal certainty by clarifying that websites can rely on browser controls and similar applications to define the acceptance of cookies. This was not clear under the current law.

Member States will have 18 months to transpose the new ePrivacy directive into national law (i.e. until April 2011). It's important they take great care so as to avoid misinterpretations that would create new barriers to the EU's internal market, confuse consumers, and ultimately put Europe at a competitive disadvantage.


So now, if a user configures his or her browser to accept only cookies from certain websites, or automatically delete cookies when closing a browser, these settings will be sufficient as expressing the wish of the user. Websites technologically rely on browsers and other applications for cookie management. The current directive had a blind spot in this regard as it did not explicitly recognise cookie control tools as a way to comply with the law. The new directive clarifies this, but it's important that implementation into national laws follows the letter and spirit of this goal.




Friday, January 22, 2010

Photos to the Web


I'm always amazed how many photos I find on the Web, of friends, family or myself, that none of us knew were there. Because things on the Web, in particular, photos, can last forever, forgetfulness is one of the big new themes in the privacy debate, particularly in Europe. There's lots of discussion about how to re-introduce a human concept of memory/forgetfulness/evanescence into a technical world of computers and websites and the Internet. I'll be joining a conference on this theme next week in Brussels.

I also joined a French government-sponsored conference on this theme recently in Paris. At the conference, much was said about the risks to people to having their photos posted online, without their knowledge or consent. With some sense of irony, I noticed a bunch of photos of me were published from that conference without my knowledge or consent, like the one here, in the online photo album of the Minister, no less,...I don't mind, and I would have happily consented, but it does make an interesting point, and I re-posted it to this blog, but that was my choice. If thoughtful people sitting in a conference about the problems of posting photos online are taking photos of people at the conference and posting them online, all without their knowledge or consent, well, maybe the sociology of online photo-sharing has developed beyond the state of the debate.

Monday, January 18, 2010

Happy 80th Birthday, Dad!

The "adequacy" regime is inadequate

There are many people in Europe who would rather eat their “chapeau” than admit that non-European countries like the United States might have adequate privacy protection, based on long-standing cultural or ideological bias. In my opinion, it’s the European “adequacy” regime that has become inadequate in today’s world. It’s near the top of my list of things that need to be modernized in European privacy law. It’s a political/bureaucratic fiction that some countries provide “adequate” data protection, while others don’t, because the decision is based on criteria that have almost nothing to do with the level of data protection on the ground, in the real world. A country can’t be deemed “adequate” if it doesn’t have an EU-style data protection authority. But the idea is ludicrous to me that privacy somehow couldn’t be protected in countries without such an agency, and in fact, the vast majority of countries in the world don’t have such an agency. And whatever labels are applied, the reality, in the age of the Internet, is that data is flowing around the globe. To take one topical example, cyber attacks do not respect borders, and take no note of whether or not a target is based in a country with “adequate” data protection.

So, recently, Israel and the Principality of Andorra have been added to the EU list of “adequate” countries. They join other countries already on the list, including: Argentina, Canada, Guernsey, Jersey, the Isle of Man, and Switzerland. Stop to read that list again, and ask yourself, really, this is the global list of “adequate” countries outside the EU? Really?

In privacy terms, what’s the right way forward for the future? As I’ve said before, follow the Canadian model, and make any company/government that collects personal data responsible and accountable for protecting it, regardless of where it happens to process it. If it can’t protect data adequately in a particular country, it shouldn’t send it there. If a company decides it can adequately protect its data in Japan, but not in Bulgaria, so be it, even if EU law would suggest the contrary. Common sense should prevail for the sake of privacy.

At the beginning of each year, I make a resolution to visit at least two new countries a year. If I’m lucky, I’ll have my wish and get to visit Andorra and Israel this year. They’re both on my adequacy list.

Friday, January 15, 2010

Privacy Officers with a French accent

Since I’m based in France, I’ve recently been appointed as Google’s “Correspondant” for data protection with the French Data Protection Authority, the CNIL. The profession of privacy officers is generally less developed in Europe than the US, and indeed, the position of “correspondant” was first created in France in 2004. Like many things in France, even this private-sector role is defined and guided by the government, in the long French tradition of dirigisme:


“From now on, local authorities, public services and associations are allowed to appoint a "Correspondant Informatique et Libertés" (CIL). It is a major innovation in the application of the law, as prior pedagogy and advice are emphasized. Indeed, the data controller which appoints a CIL is exempted, in most cases, from the notification process to the CNIL. The CIL has the duty to ascertain that the information system of the organization will expand without harming the rights of the users, clients and employees.”

As a privacy professional, I’m very excited by anything that supports the development of meaningful empowerment and development for the profession. As long as the role of Correspondant avoids the trap of becoming a purely administrative function, I think it could prove to become a serious contribution to the growth of this profession in Europe.

Monday, January 11, 2010

Practice makes perfect


I recently got away for a few days to play tennis in Florida. I left with a clear conscience, thinking that 2009 was a good year at Google in terms of privacy tools.

Google launched three major industry-leading privacy initiatives that implemented the key privacy principles of transparency and choice -- interest-based advertising, the data liberation front, and Google Dashboard.

It's a great tennis facility, on Key Biscayne, with grass courts, no less. Someone builds and maintains a grass court in that unlikely climate, and it must be a lot of work. And people pay a lot of money to live in "privacy", which usually means living in a place, like Key Biscayne, where they are secluded and protected from other people. So, now that there are online privacy tools, like the ones I just mentioned, I wonder if people will really use them more. I mean, to play tennis, you have to run and serve and swing. To protect your privacy, you should hustle a little too. Someone else can build the grass court, but it's up to you to play.



Friday, January 8, 2010

Watching people walk down the street


It's just snowed in Paris, and I'm looking out my window, watching the children and the dogs play. Almost everyone walking down avenue Foch seems to be speaking on a cell phone. I doubt many of them are thinking about how their location data is being captured, stored or used.

EU countries began passing the Data Retention laws mandated by a European Directive. That means that massive databases of communications logs will now be collected and stored by communications service providers across Europe for 6 months to 2 years, for police and law enforcement purposes (France, for example, chose 12 months). This is the largest police surveillance database ever mandated in the history of humanity to date. The year ahead will define how all this is going to work in practice: who will be able to access them, for what purposes, under what controls, how should this work in a cross-border context, etc. Will other countries follow Europe down this path? For most people, I imagine, the most sensitive aspect of this is the idea that their physical movements can be tracked by the police over long periods of time.

But the mobile revolution is just starting. Think for a moment about the intersection of mobile and face recognition software. For some years, in small controlled contexts, the police have already been using face recognition software to find individuals in a crowd. Online photo albums already offer some face recognition software in the contexts of particular albums, or in the contexts of social networking sites: take a look at face.com. But reflect on the prospect of face recognition software that could be used from any Internet-connected smart phone that can photograph a face and return instant search results. Google already announced the launch of Goggles without face recognition and acknowledged the privacy concerns in applying similar technologies to identifiable human faces. There's a lot of work to do to think through the privacy design of image recognition software applied to faces. The more I think about it, the more complicated it gets.

The web is going mobile, and as Internet apps go mobile too, location-aware services will explode in 2010 and beyond. That means that location data will be captured and used. Location privacy will become a key new issue in the mainstream in the year ahead. It's been around for years in cell phones, of course, but the issues will grow exponentially in the age of proliferating third-party location aware apps. It's one thing for you to know (or be dimly aware) that your cell phone company knows where you are based on your cell phone's location, it's quite another to have a plethora of third-party apps know that too.

Mobile is where the next generation of tough privacy issues will come, I muse, as I watch people walk down a Paris street that hasn't changed much in a hundred years.

Wednesday, January 6, 2010

DC: discussing privacy in public

I spent a few days in Washington DC in December. While I was there, I slipped into a public workshop hosted by the Federal Trade Commission on privacy. The content of the workshop has already been covered: http://blogs.wsj.com/digits/2009/12/07/ftc-takes-on-online-privacy/

Coming from Europe, I found this sort of transparency and public consultation by a privacy regulator novel and refreshing. The FTC regularly holds public workshops, where it invites stakeholders from many different sectors (academia, advocacy, government, private sector) to discuss problems in privacy and potential regulatory responses to them. This is meant to help the FTC staff understand the issues that it will grapple with. Moreover, the FTC often issues its guidelines in draft form, for the sake of public review and comment, before finalizing them, as it has done with its privacy guidelines for online behavioral advertising principles: http://www.ftc.gov/opa/2009/02/behavad.shtm

So, in my mind, I couldn't help but contrast all this with the practices of one of the world's other great bodies of privacy regulators, the EU Working Party. The Working Party has never, to my knowledge, held a public workshop. It has never opened any of its meetings to the public, and indeed, it is very rare that anyone from outside the closed world of Data Protection Authorities to be invited to attend one of its meetings. It publishes almost no information about its agendas, other than a few sentences to describe its annual work program. It never publishes its opinions in draft form for public review and comment before finalizing them. And finally, since it only issues "opinions", rather than enforceable decisions, its work has never, to my knowledge, been subject to judicial review. Seeing the transparency of the Federal Trade Commission's public workshop in action made me appreciate the benefits of transparent and open government.

Friday, December 4, 2009

On the sidewalk in Milan

I was relaxing with a glass of chianti watching The Bourne Ultimatum on tv. The shadowy authorities use surveillance technologies to try to track down Jason Bourne.

So, I'm no Jason Bourne. Back in January 2008, as I've blogged before, I was surrounded on a sidewalk in Milan in front of the ancient University by 5 Italian policemen. Many confused thoughts went through my head at that moment, as I'm sure you can imagine: fear, confusion, surprise, indignation. But also, a nagging question: how did these policemen know that I would walk down this sidewalk at this moment in a foreign city and how did they recognize me on a crowded city sidewalk?

As anyone who's checked into a hotel in Italy knows, the first thing that Reception asks you for is a passport. This is also true in most European countries. It's for the police. There is zero transparency or choice in this process: no one I've ever met knows where this data goes or how long it's kept or what it's used for. Needless to say, if you're sharing a room with another person, the police will know this too. You do not have the option of checking into your hotel room anonymously.

In my case in Milan, I don't think there was any great use of police surveillance technology. I'm guessing the police were waiting on the sidewalk because there had been some minor press coverage before the privacy conference where I was scheduled to speak. I assume they downloaded a photo of me from the web and knew from the conference program roughly when I'd be arriving. Why five policemen were sent, I have no clue. Were they expecting me to make a run for it, like Jason Bourne?

According to independent reports, Italy leads the world with more wiretaps per capita than any other country. Wiretaps in the age of the cell phone now include location information.


I've always enjoyed the freedom of walking down the streets of foreign cities with the liberating sense of anonymity. I feel a little less free now. I hope technology will find a way to put users in control of their location information. I'm off somewhere else now, but come to think of it, I'd rather you didn't know where.

Thursday, December 3, 2009

Remembering and Forgetting in Berlin



I've spent a few days in Berlin, and I've spoken with many interesting politicians and journalists about privacy. The most interesting case must surely be this one:

Two German Killers Demanding Anonymity Sue Wikipedia’s Parent

http://www.nytimes.com/2009/11/13/us/13wiki.html?_r=1&scp=3&sq=german%20wikipedia%20murder&st=cse

In some countries in Europe, like Germany and France, there are well-established principles about the "right to be forgotten", an awkward translation of the "Droit a l'Oubli." As a privacy-sensitive guy, I'm all for the idea that people ought to be able to walk away from some awkward facts at some point in their lives. But I have never heard anyone be able to tell me how the "right to be forgotten" does not quickly cross the line into censorship. If two German murderers can require German publishers to remove references to their names in articles after they have served their sentence, isn't that censorship? And wouldn't it be even worse if they tried to re-write news archives, which are now rapidly becoming instantly findable online? And in the real world what will be the consequences if German Wikipedia deletes content that English Wikipedia still publishes?

And while I was in Berlin, I visited the Holocaust memorial, as I always do when in Berlin, and I wondered about the "right to be forgotten" in the midst of the memorial to "never forget".

Friday, November 27, 2009

Madrid and Berlin, trying to find workable approaches

Here’s an interesting article about the day-to-day challenges and contradictions of national laws in the context of the global Internet (ok, it does use some of us Google guys as unhappy examples, but just to make a valid point):

http://www.bloomberg.com/apps/news?pid=20601039&sid=aAv2iLcBnqtI

At the International Data Protection Commissioners' Conference in Madrid, I added my voice to support the development of global privacy standards, as I've done for several years. I can’t think of a better way forward than trying to develop a more global approach to privacy standards internationally. Here's one example (in Spanish):

http://www.expansion.com/2009/11/12/juridico/entrevistas/1258051264.html

I’m off to Berlin now. Germany is one of those places where I feel the need to listen more than talk. I'll blog about what I learn afterwards.

Thursday, November 26, 2009

Thanksgiving

Like most Americans, I woke this morning to one of my favorite days of the year, Thanksgiving. Unlike most Americans, I also woke this morning to news reports of an Italian prosecutor calling for me to be sentenced to one year in prison.

http://www.boston.com/business/technology/articles/2009/11/25/italian_prosecutors_seek_jail_for_google_execs/

But in the spirit of the day, now that I’ve skimmed the news and reassured friends that I’m not going to prison (I hope), I’ll go about my day:

I’ll do some planning for my Dad’s 80th Birthday Party, do a kick-boxing class at gym, work on an academic privacy paper on the hotly-debated question of whether IP addresses should be considered “personal data” under EU law, give legal advice on some privacy questions, prepare for some meetings in Berlin, and, best of all, I’ll end the day with a candle-light dinner with the person I love in the city I love.

That’s a lot to be thankful for (well, not the Berlin or the Milan parts), but the rest anyway.

Wednesday, November 25, 2009

European law on hosting platforms


As you can imagine, I've spent a lot of time researching European law on hosting platforms. International legislation recognizes that hosting platforms like Google Video are neither the creators nor the controllers of content. The European Union's Electronic Commerce Directive, enacted in 2000, sets a clear legal framework for establishing liability for unlawful content on the Internet. It provides a safe harbor for entities acting as intermediaries, drawing a clear line between those who create content, and those who, in their capacity as technological intermediaries, provide the tools to make this content publicly available. By establishing legal certainty and creating a single EU-wide standard, the E-Commerce directive allows the development of open platforms that promote free expression and the free flow of information on an unprecedented scale, and play a crucial role in the development of the new economy in Europe.

How does the E-Commerce prescription work in real life? Say an Internet user uploads a video filled with illegal hate speech, nudity, or violence. When notified of this illegal content, the hosting platform is obliged to take it down. The hosting platform, however, is not obliged to monitor and prevent the upload. The responsible party is the Internet user who posts the content. In this case, Google did exactly what the law requir
es - it removed the content upon notification, and took the further step of complying
with law enforcement requests, helping to bring the wrongdoers to justice.

If Google and companies like it were responsible for every piece of content on the web, the Internet as we know it today – and all of the economic and social benefits it provides – would disappear. Without appropriate protections, no company would be immune: any potentially defamatory text, inappropriate image, bullying message or violent video would have the power to shut down the platform that had unknowingly hosted it. In the offline world, it would be like criminally prosecuting post office employees because someone mailed an inappropriate letter. European law recognizes the importance of providing limitations on the liability of hosting platforms.


The Directive applies horizontally across all areas of law which touch on the provision of information society services, regardless of whether it is a matter of public, private, or criminal law. This is confirmed in the first Report from the Commission to the European Parliament on the application of Directive 2000/31/EC dated 8 June 2000. See p. 4: "The Directive applies horizontally across all areas of law which touch on the provision of information society services, regardless of whether it is a matter of public, private, or criminal law. Furthermore, it applies equally both to business-to-business (B2B) and business-to-consumer (B2C) e-commerce." And see p. 12: "The limitations on liability provided for by the Directive are established in a horizontal manner, meaning that they cover liability, both civil and criminal, for all types of illegal activities initiated by third parties."

From a public policy perspective, it wouldn't make any sense if it didn't apply to criminal charges. The objective of the directive was to foster a competitive and dynamic knowledge-based economy in the EU. To provide an environment in which its citizens would have access to inexpensive, world-class communications infrastructure and a wide range of services. To create conditions for e-commerce and the internet to flourish. To enhance quality of life, to stimulate innovation and job creation, and to contribute to the free flow of information and freedom of expression. Those are words directly from the Commission. It wouldn't make any sense to apply these protections only to civil matters; doing so would permit criminal claims to eviscerate the very benefits the directive sought to achieve.