Friday, August 23, 2013

Saying Nyet to the Russian Homophobolympics



As a gay-athlete, and oh yes, also privacy professional, I've decided not to set foot in Russia, as a personal protest against Russia's offensive homophobic laws.  My swim team friends and I agreed that Putin is demeaning the Olympics and turning them into his Homophobolympics.  We know something about athletic discipline:  we swim a lot and hard.  We've all trained with real Olympians, and we're in awe of them.  So, how should we react when political thugs attack the core values of the Olympics? 

When some politicians in Russia recently started "investigating"  American tech companies, I was invited to go to Moscow to meet with them.  But in the case of Russia, in light of its recent Anti-Gay Propaganda law, I declined.  I decided not to set foot in Russia, as an act of personal conscience.   Many other people whom I respect are making similar decisions not to set foot in Russia.  

Russia joins a rogue's gallery of countries with state-sponsored homophobia, but unlike the others, Russia is soon to host the Winter Olympics.  Ever since Hitler hosted the Berlin Olympics in 1936, we know how miscreants in power want to use the Oympic global stage to win international attention and acclaim.  

I have deep respect for athletes.  We should do nothing to hurt athletes in Sochi.  But let's also use the Sochi Games to shine a spotlight on Putin's regime.  Putin wants the spotlight, let him have it.  Let's shine a spotlight on government corruption in constructing the $50 billion Olympics facilities.  Let's shine a spotlight on Putin's crackdown on human rights, on democracy, on the judicial system in Russia.  Let's shine a spotlight on Putin's coterie of friendly rogue-regimes, like Syria's Assad.  Let's shine a spotlight on the personal wealth accumulated by friends of the regime.  Let's use social media to disseminate evidence of the vicious homophobia that Putin is inciting.  

Each of us must make a choice.  I'm not setting foot in Russia.  Despite its lofty self-congratulatory rhetoric, the IOC is taking the amoral path. But many people will go to Sochi, and I have a wish for athletes and spectators alike:  wave a rainbow flag as you march at the Opening Ceremony, or wear a rainbow scarf or pin.  Some politicians around the world are already showing ethical leadership, and I hope the clutch of global politicians attending the G20 in St Petersburg soon will too.  Imagine if we had all had the courage in 1936, Jews and non-Jews alike, to march at the Opening Ceremony in Berlin wearing Yellow Stars.  

Say Nyet to the Homophobolympics.

Friday, August 2, 2013

How to feign outrage over PRISM


Around the world, politicians are under pressure to express their outrage over US government surveillance.  It's August, and your PR teams may be on holiday, so here are some hints on how to get a good headline:

1)  Focus your outrage on the American government.  Distract everyone from the fact that your own government does it too.  e.g., Europe has the most privacy-invasive government surveillance regime in the world, based on the mandatory data retention of the communications logs (aka, metadata) on every single electronic communication for periods ranging from 6 to 24 months.  The US does not have such a data retention regime, because it was deemed too privacy-invasive by the US Congress.  But don't talk about that. 

2)  Focus your outrage on foreign private companies (e.g., Twitter or whatever).  Companies of course are not in control of government surveillance, but just the tools.  In any case, only talk about foreign companies, and never suggest that your own domestic companies are subject to similar (or much greater) surveillance. 

3)  Feel free to make up the facts.  Since much government surveillance is by its very nature secret, you can say pretty much anything without risk of being contradicted by the facts.  

4)  Propose credible-sounding but irrelevant solutions.   Like suggesting that the way to rein in US government surveillance is to abrogate the US-EU Safe Harbor Framework, which governs data transfers in the private sector, even though you know of course that the location of data is irrelevant to the US government's power to order access to it.  Location of data sounds relevant, and only a few lawyers know otherwise.  

5)  Use it as leverage for an unrelated political goal.  Politics is all about deal-making, and trade-offs.  So, use this PRISM scandal to exert pressure for whatever else you want: trade deals, global warming treaties, anything is fair game.  In fact, you can even use this as a good excuse to increase your own government surveillance powers:  "we want to be able to do what the Americans are doing." 

6)  Get your headlines now.  You know that all this will blow over.  Snowden will melt away like a snowman in spring.  Nothing much will change in the realm of government surveillance.  Perhaps there will be a few cosmetic changes, like reforming the FISA Court.  You also know that the next big terrorist attack will completely change the political winds.  It's August, so go sailing, and be ready to tack when the winds shift.  

Monday, July 29, 2013

Russia ratifies Privacy Rights...but not for Gays


Modern privacy law was invented over a century ago in the United States, was re-discovered in post-war-Europe, and is now spreading around the world.  Privacy laws have historically been built on three foundations:  1)  democracy,  2)  rule of law, and  3)  respect for fundamental human rights. 

So, what should we make of the fact that a rogue's gallery of autocratic countries, with neither rule of law, nor respect for fundamental human rights, are starting to pass privacy laws?

Take the example of Russia.  Last month, at the same time that Putin's regime ratified an international framework of privacy law, known as Convention of Europe 108, it also launched its war on gays.  

Why would Putin's regime ratify a privacy law, while subverting democracy, subverting the rule of law, and inciting vicious homophobia as official policy?  Is it just to distract an ignorant electorate from the Kremlin's kleptocracy?  How exactly is the International Olympic Committee going to deal with Sochi?  Should Russia or Russian products be boycotted by people of conscience?  I don't want to see the world's athletes held hostage to this, but nor do I want to see them march under the salute of Putin, recollecting those tragic Games in Berlin.    

What, I wonder, does a privacy law mean in this context?  And if you think all this is just Russian thugocratic posturing, imagine if your gay teenage son were Russian.  I dare you to click.    I doubt this tortured teen will find redress under Russia's ratification of privacy laws, do you?

Monday, July 15, 2013

We need global privacy standards...now more than ever

As a reaction to the recent spate of government surveillance revelations, this week the Chancellor of Germany and others have issued calls for an international data protection treaty.  

Back in 2007, I gave a speech to UNESCO calling for...global privacy standards.  

My speech was broadly covered by the press:  Google urges UN to set global internet privacy rules.

On re-reading it, I'm struck by how little has changed since 2007, both in terms of the need for global privacy standards, and how little progress has been made to achieve them.  After two years of acrimonious debate, we can't even agree on a draft privacy law for Europe, much less a treaty for the world.  Nonetheless, I'm firmly in the camp of people who believe that privacy can only be protected in a global context, and that global privacy standards are part of that fabric.  I'm taking the liberty of re-posting it below. 

Friday, September 14, 2007

The Need for Global Privacy Standards

Introduction

How should we update privacy concepts for the Information Age? The total amount of data in the world is exploding, and data flows around the globe with the click of mouse. Every time you use a credit card, or every time you use an online service, your data is zipping around the planet. Let’s say you live in France and you use a US company’s online service. The US company may serve you from any one of its numerous data centers, from the “cloud” as we say in technology circles, in other words, from infrastructure which could be in Belgium or Ireland – and which could change based on momentary traffic flows. The company may store offline disaster recovery tapes in yet another location (without disclosing the location, for security purposes). And the company may engage customer service reps in yet another country, say India. So, your data may move across 6 or 7 countries, even for very routine transactions.
As a consumer, how do you know that your data is protected, wherever it is located? As a business, how do you know which standards of data protection to apply? As governments, how do you ensure that your consumers and your businesses can participate fully in the global digital economy, while ensuring their privacy is protected?

The story illustrates the argument I want to make today. It is that businesses, governments but most of all citizens and consumers would all benefit if we could devise and implement global privacy standards. In an age when billions of people are used to connecting with data around the world at the speed of light, we need to ensure that there are minimum privacy protections around the world. We can do better, when the majority of the world’s countries offer virtually no privacy standards to their citizens or to their businesses. And the minority of the world’s countries that have privacy regimes follow divergent models. Today, citizens lose out because they are unsure about what rights they have given the patchwork of competing regimes, and the cost of compliance for businesses risks chilling economic activity. Governments often struggle to find any clear internationally recognised standards on which to build their privacy legislation.

Of course there are good reasons for some country-specific privacy legislation. The benefits of homogeneity must be balanced by the rights of legitimate authorities to determine laws within their jurisdictions. We don’t expect the same tax rules in every country, say some critics, so why should we expect the same privacy rules? But in many areas affecting international trade, from copyright to aviation regulations to world health issues, huge benefits have been achieved by the setting of globally respected standards. In today’s inter-connected world, no one country and no one national law by itself can address the global issues of copyright or airplane safety or influenza pandemics. It is time that the most globalised and transportable commodity in the world today, data, was given similar treatment.

So today I would like to set out why I think international privacy rules are necessary, and to discuss ideas about how we create universally respected rules. I don’t claim to have all the answers to these big questions, but I hope we can contribute to the debate and the awareness of the need to make progress.

Drivers behind the original privacy standards

But first a bit of history. Modern privacy law is a response to historical and technological developments of the second-half of the 20th century. The ability to collect, store and disseminate vast amounts of information about individuals through the use of computers was clearly chilling against the collective memories of the dreadful mass-misuse of information about people that Europe had experienced during WWII. Not surprisingly, therefore, the first data privacy initiatives arose in Europe, and they were primarily aimed at imposing obligations that would protect individuals from unjustified intrusions by the state or large corporations, as reflected in the 1950 European Convention for the Protection of Rights and Fundamental Freedoms.

Early international instruments

After a decade of uncoordinated legislative activity across Europe, the Organisation for Economic Co-operation and Development identified a danger: that disparities in national legislations could hamper the free flow of personal data across frontiers. In order to avoid unjustified obstacles to transborder data flows, in 1980 the OECD adopted its Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. It’s worth underscoring that concerns about international data flows were already being addressed in a multinational context as early as 1980, with the awareness that a purely national approach to privacy regulation simply wasn’t keeping abreast of technological and business realities.

These OECD Guidelines became particularly influential for the development of data privacy laws in non-European jurisdictions. The Guidelines represent the first codification of the so-called ‘fair information principles’. These eight principles were meant to be taken into account by OECD member countries when passing domestic legislation and include: 1) collection limitation, 2) data quality, 3) purpose specification, 4) use limitation, 5) security safeguards, 6) openness, 7) individual participation, and 8) accountability.

A parallel development in the same area but with a slightly different primary aim was the Council of EuropeConvention on the Automated Processing of Personal Data adopted in 1981. The Convention’s purpose was to secure individuals’ right to privacy with regard to the automatic processing of personal data and was directly inspired by the original European Convention on human rights. The Council of Europe instrument sets out a number of basic principles for data protection, which are similar to the ‘fair information principles’ of the OECD Guidelines. In addition, the Convention establishes special categories of data, provides additional safeguards for individuals and requires countries to establish sanctions and remedies.
The different origins and aims of both instruments result in rather different approaches to data privacy regulation. For example, whilst the Convention relies heavily on the establishment of a supervisory authority with responsibility for enforcement, the OECD Guidelines rely on court-driven enforcement mechanisms. These disparities have been reflected in the laws of the countries within the sphere of influence of each model. So, for example, in Europe, privacy abuses are regulated by independent, single-purpose bureaucracies, while in the US, privacy abuses can be regulated by many different government and private bodies (e.g., the Federal Trade Commission at the Federal level, Attorneys General at the State levels, and private litigants everywhere). It’s impossible to say which model is more effective, since each reflects the unique regulatory and legal cultures of their respective traditions. Globally, we need to focus on advocating privacy standards to countries around the world. But we should defer to each country to decide on its own regulatory models, given its own traditions.

Current situation

Today, a quarter century later, some countries are inspired by the OECD Guidelines, others follow the European approach, and some newer ones incorporate hybrid approaches by cherry-picking elements from existing frameworks, while the significant majority still has no privacy regimes at all.

After half a decade of negotiations, in 1995, the EU adopted the Data Protection Directive 95/46/EC. The EU Directive has a two-fold aim: to protect the right to privacy of individuals, and to facilitate the free flow of personal data between EU Member States. Despite its harmonisation purpose, according to a recent EU Commission Communication, the Directive has not been properly implemented in some countries yet. This shows the inherent difficulty in trying to roll out a detailed and strict set of principles, obligations and rights across jurisdictions. However, the Commission has also made it clear that at this stage, it does not envisage submitting any legislative proposals to amend the Directive.

In terms of core European standards, the best description of what the EU privacy authorities would regard as “adequate data protection” can be found in the Article 29 Working Party’s document WP 12. This document is a useful and detailed point of reference to the essence of European data privacy rules, comprising both content principles and procedural requirements. In comparison with other international approaches, EU data privacy laws appear restrictive and cumbersome, particularly as a result of the stringent prohibition on transfers of data to most countries outside the European Union. The EU’s formalistic criteria for determining “adequacy” have been widely criticized: why should Argentina be “adequate”, but not Japan? As a European citizen, why can companies transfer your data (even without your consent) to Argentina and Bulgaria and other “adequate” countries, but not to the vast majority of the countries of the world, like the US and Japan? In short, if we want to achieve global privacy standards, the European Commission will have to learn to demonstrate more respect for other countries’ approach to privacy regimes.

But at least in Europe there is some degree of harmonisation. In contrast, the USA has so far avoided the adoption of an all-encompassing Federal privacy regime. Unlike in Europe, the USA has traditionally made a distinction between the need for privacy-related legislation in respect of the public and the private sectors. Specific laws have been passed to ensure that government and administrative bodies undertake certain obligations in this field. With regard to the use of personal information by private undertakings, the preferred practice has been to work on the basis of sector-specific laws at a Federal level whilst allowing individual states to develop their own legislative approaches. This has led to a flurry of state laws dealing with a whole range of privacy issues, from spam to pretexting. There are now something like 37 different USA State laws requiring security breach notifications to consumers, a patchwork that is hardly ideal for either American consumer confidence or American business compliance.

The complex patchwork of privacy laws in the US has led many people to call for a simplified, uniform and flexible legal framework, and in particular for comprehensive harmonised Federal privacy legislation. To kick start a serious debate on this front, a number of leading US corporations set up in 2006 the Consumer Privacy Legislative Forum, of which Google forms part. It aims to make the case for harmonised legislation. We believe that the same arguments for global privacy standards should also apply to US Federal privacy standards: improve consumer protections and confidence by applying a consistent minimum standard, and ease the burdens on businesses trying to comply with multiple (sometimes conflicting) standards.
A third and increasingly influential approach to privacy legislation has been developing in Canada, particularly since the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) was adopted in 2000. The Canadian PIPEDA aims to have the flexibility of the OECD Guidelines – on which it is based – whilst providing the rigour of the European approach. In Canada, as in the USA, the law establishes different regimes for the public and private sectors, which allows for a greater focus on each. As has also been happening in the USA in recent years with state laws, provincial laws have recently taken a leading role in developing the Canadian model. Despite the fact that PIPEDA creates a privacy framework that requires the provincial laws to be "substantially similar" to the federal statute, a Parliamentary Committee carrying out a formal review of the existing framework earlier this year, recommended reforms for PIPEDA to be modelled on provincial laws. Overall, Canada should be praised for encouraging the development of progressive legislation which serves the interests of both citizens and businesses well.

Perhaps the best example of a modern approach to the OECD privacy principles is to be found in the APEC Privacy Framework, which has emerged from the work of the 21 countries of the Asia-Pacific Economic Cooperation forum. The Framework focuses its attention on ensuring practical and consistent privacy protection across a very wide range of economic and political perspectives that include global powerhouses such as the US and China, plus some key players in the privacy world (some old, some new), such as Australia, New Zealand, Korea, Hong Kong and Japan. In addition to being a sort of modern version of the old OECD Guidelines, the Framework suggests that privacy legislation should be primarily aimed at preventing harm to individuals from the wrongful collection and misuse of their information. The proposed framework points out that under the new “preventing harm” principle, any remedial measures should be proportionate to the likelihood and severity of the harm.

Unfortunately, the co-existence of such diverse international approaches to privacy protection has three very damaging consequences: uncertainty for international organisations, unrealistic limits on data flows in conflict with global electronic communications, and ultimately loss of effective privacy protection.

New (interconnected) drivers for global privacy standards

Against this background, we are witnessing a series of new phenomena that evidence the need for global privacy standards much more compellingly than in the 70s, 80s or 90s. The development of communications and technology in the past decade has had a marked economic impact and accelerated what is commonly known as ‘globalisation’. Doing business internationally, exchanging information across borders and providing global services has become the norm in an unprecedented way. This means that many organisations and those within them operate across multiple jurisdictions. The Internet has made this phenomenon real for everyone.

A welcome concomitant of the unprecedented technological power to collect and share all this personal information on a global basis is the increasing recognition of privacy rights. The concept of privacy and data protection regimes has moved from one discussed by experts at learned conferences to an issue that is discussed and debated by ordinary people who are increasingly used to the trade offs between privacy and utility in their daily lives. As citizens’ interest in the issue has grown, so, of course has politicians’ interest. The adoption of new and more sophisticated data privacy laws across the world and the radical legal changes affecting more traditional areas of law show that both law makers and the courts perceive the need to strengthen the right to privacy. Events which have highlighted the risks attached to the loss or misuse of personal information have led to a continuous demand for greater data security which often translates into more local laws, such as those requiring the reporting of security breaches, and greater scrutiny.

Routes to the development of global privacy standards

The net result is that we have a fragmentation of competing local regimes, at the same time as we the massively increased ability for data to travel globally. Data on the Internet flows around the globe at nearly the speed of light. To be effective, privacy laws need to go global. But for those laws to be observed and effective, a realistic set of standards must emerge. It is absolutely imperative that these standards are aligned to today’s commercial realities and political needs, but they must also reflect technological realities. Such standards must be strong and credible but above all, they must be clear and they must workable.

At the moment, there are a number of initiatives that could become the guiding force. As the most recent manifestation of the original OECD privacy principles, one possible route would be to follow the lead of the APEC Privacy Framework and extend its ambit of influence beyond the Asia-Pacific region. One good reason for adopting this route is that it already balances very carefully information privacy with business needs and commercial interests. At the same time, it also accords due recognition to cultural and other diversities that exist within its member economies.

One distinctive example of an attempt to rally the UN and the world’s leaders behind the adoption of legal instruments of data protection and privacy according to basic principles is the Montreux Declaration of 2005. This Declaration probably represents the first official written attempt to encourage every government in the world to do something like this and this is an ambition that must be praised. Little further was heard about the progress of the Montreux Declaration until the International Privacy Commissioners’ Conference took place in November 2006 and the London initiative was presented. The London Initiative acknowledged that the global challenges that threaten individuals’ privacy rights require a global solution. It focuses on the role of the Commissioners’ Conference to spearhead the necessary actions at an international level. The international privacy commissioners behind the London Initiative argue that concrete suggestions must emerge in order to accomplish international initiatives, harmonise global practices and adopt common positions.

One privacy commissioner who has expressed great interest in taking an international role aimed developing global standards is the UK Information Commissioner. The Data Protection Strategy of the Information Commissioner’s Office published at the end of June 2007 stresses the importance of improving the image, relevance and effectiveness of data protection worldwide and, crucially, recognises the need for simplification.

Way forward

The key priority now should be to build awareness of the need for global privacy standards. Highlighting and understanding the drivers behind this need – globalisation, technological development, and emerging threats to privacy rights – will help policymakers better understand the crucial challenge we face and how best to find solutions to address them.
The ultimate goal should be to create minimum standards of privacy protection that meet the expectations and demands of consumers, businesses and governments. Such standards should be relevant today yet flexible enough to meet the needs of an ever changing world. Such standards must also respect the value of privacy as an innate dimension of the individual. To my mind, the APEC Framework is the most promising foundation on which to build, especially since competing models are flawed (the USA model is too complex and too much of a patchwork, the EU model is too bureaucratic and inflexible).

As with all goals, we must devise a plan to achieve it. Determining the appropriate international forum for such standards would be an important first step, and this is a choice that belongs in the hands of many different stakeholders. It may be the OECD or the Council of Europe. It may be the International Chamber of Commerce or the World Economic Forum. It may be the International Commissioners’ Conference or it may be UNESCO. Whatever the right forum is, we should work together to devise a set of standards that reflects the needs of a truly globalised world. That gives each citizen certainty about the rules affecting their data, and the ability to manage their privacy according to their needs. That gives businesses the ability to work within one framework rather than dozens. And that gives governments clear direction about internationally recognised standards, and how they should be applied.

Data is flowing across the Internet and across the globe. That’s the reality. The early initiatives to create global privacy standards have become more urgent and more necessary than ever. We must face the challenge together.

Friday, July 12, 2013

You can run, but you can't hide


Government surveillance is running amock, worldwide.  This is the sort of topic that Obama and I might have debated, when we were both idealists at our alma mater, Harvard Law School.  

Revelations about US government surveillance continue to surprise in their scale and scope.  We all now know that the NSA is hoovering up trillions of communications logs.  We all now know that there are essentially no legal protections of non-US citizens from US government surveillance.  We all now know that the FISA court, which is meant to provide judicial review of snooping on US citizens' communications, is little more than a rubber-stamp.  We all now know that US government spying is directed at friend and foe alike.  We all now know that the US government is bullying governments around the world to hand over the whistle-blower Snowden (forcing down the Presidential aircraft of a Sovereign State?), and most governments are collaborating meekly.  

As more people wake up to the idea of living in a Panopticon, one would think there would be a serious political debate about how to subject government surveillance to serious legal and judicial checks and balances.  Where's the serious debate about finally updating ECPA, so that emails sitting in users' accounts do not lose most effective privacy protections after they're more than 180 days old?  Where's the serious debate in countries around the world about their own governments' surveillance programs, not just about the Americans'?  e.g., the French privacy watchdog launched an investigation into foreign government surveillance, curiously excluding France's own recently-documented surveillance programs.   Where's the serious debate about whether Europe's much-debated privacy-law revamp has completely missed the boat by failing to address government surveillance?  Where's the serious debate about whether US government surveillance makes a mockery of the long-debated, long-negotiated US-EU Parliamentary accords over the privacy safeguards governing US government access to Europeans'  Passenger Name Records or SWIFT bank transfer data?


I have long had a healthy wariness about governmental abuse of power. In my personal life, I've had a taste of what a government can do to prosecute an innocent person, sentenced to jail for a non-crime, then acquitted, and still being put through a decade of criminal justice hell.  


If the Snowden revelations do not suffice to create the political momentum to impose meaningful legal and judicial checks on secret government surveillance, then we're all on an unstoppable trajectory towards total surveillance.  Or we can follow the lead of France's President, who expressed his outrage at revelations of US government spying by suggesting that trade talks with Les Americains should be subjected to a mid-July two-week delay.   Take that! 


Obama and I were at the same law school, and I recognize the skillset of my fellow Harvard Law School grad, where we were all trained in rhetoric, sometimes so empty that it would prompt even Ari Fleischer to zap (btw, no relation to me):  "It's like George Bush is having his fourth term..." 


Tuesday, July 2, 2013

Life in the Goldfish Bowl: Privacy in the Age of Government Surveillance


As each day goes by, there are new revelations of the scope and scale of government surveillance.  I had long known or suspected that all governments engage in secret surveillance, but the Snowden revelations are opening our collective eyes to how vast these operations have become.  The limits on government surveillance seem to be set less by law or ethics than by the limits of the technical infrastructure to collect, store and interpret data.  

The entire privacy profession needs to re-think its priorities in the Age of Government Surveillance.  How does our use and development of technology change if people come to feel (rightly or wrongly) that we are all just goldfish swimming in a bowl of government surveillance?  How do we ourselves change, in a basic sociological sense, if we think we're being watched?  Are we being watched?

The Snowden revelations are already having significant political impacts.  Already, European officials are threatening to abandon the proposed Europe-US Free Trade Agreement negotiations.  Already, people and institutions are re-assessing their trust in the US government.  

Over time, I think we'll see a few long-lasting global trends as a reaction to these revelations about government surveillance (regardless of whether any of these actually provide for enhanced privacy or not):
  • There will be more development and adoption of encryption technologies, in particular, end-to-end encryption, and other privacy-enhancing technologies.   
  • There may be a systemic decrease in trust and use of cloud-based services, like not trusting email with your sensitive communications. 
  • There will be a series of initiatives to demand local-data-storage and to restrict international data transfers for cloud services, just as there are already calls to rescind the EU-US Safe Harbor Agreement. 
  • There may be a series of trade-protectionist measures around the world in favor of local (i.e., non-US) companies.  
  • There will be a series of criminal prosecutions, around the world, against companies and individuals, who will be caught in classic conflict of laws scenarios:  testing whether their compliance with US legal obligations to comply with US government surveillance orders puts them in violation of other countries' privacy laws.
  • Finally, there will be citizen and civil society demands for increased government transparency and democratic control of surveillance programs,  Some governments will respond and some will not.
For those of us who have a deep love for a free and open Internet, and a deep love for transparent and democratic government, it's all sobering.  The ineluctable progress of technology means that the governments' abilities to capture, store, and analyze data will double roughly every 18 months, absent legal or political decisions to restrain it.    

Some government surveillance is necessary and appropriate for governments to carry out their responsibilities to protect and defend their national security, but there's a reason John F. Kennedy didn't say:  "Ich bin ein Ost-Berliner."

Friday, June 28, 2013

It Gets Better


If there's anything I've learned in this half-century adventure of life, it's that being gay is no private matter.  In this historic week, when the "Defense of Marriage Act" was struck down by the Supreme Court, I salute all of those people who have had the courage to stand up, publicly, and say:  I'm gay, I'm proud, and I demand equal rights under the law.  

I applaud all of those people who surrender their privacy to tell their stories, to show the world their all-too-human faces.  

It takes great dignity to show the world your battered face, bloodied in a homophobic attack on the streets of Paris.  

It takes great dignity to show the world your raw grief at the loss of your partner.  

It takes great dignity to walk onto the pitch as a professional sportsman to come out.  

The world is a richer place for the magnanimity of these people.  

Being gay is no private matter.  As each new person finds the strength and confidence to come out, as the laws evolve to provide dignity and equality for all of us, and as more and more of us share our stories, like my colleagues at Google: It gets better. 

Tuesday, June 18, 2013

Mirror, mirror on the wall, who is the ugliest one of them all?


Many years ago, a legal journal called me a man on a "crusade" to protect users' privacy against government surveillance.  That was back in 2007, and since then, the scale and scope of government surveillance has increased dramatically, just as the total amount of data circulating on the Internet has too.  I've been blogging about it for years:  Should you cover your tracks from government snooping?.  

Government surveillance is a worldwide phenomenon.  The purposes of government surveillance vary from country to country, from the conventional to the creepy:  fighting crime, preventing terrorism, spying on political opponents, stealing trade secrets.  In short, everyone does it.  

There's always been more focus on government surveillance conducted by the US government, compared to surveillance conducted by other countries.  That's understandable, because the US is a big country, with big companies, and big technology resources, but also because the US is comparatively transparent about its surveillance programs and the laws governing them, notwithstanding the recent revelations about certain secret programs.  

Transparency is the best answer to worldwide queasiness about government surveillance.  Various companies are already publishing data (to the extent that the governments let them) about how and when they respond to government requests.  However, I'm not aware of a single government that publishes credible statistics about its own surveillance programs.  Governments are not telling their citizens what or how much data they're collecting, why they're doing it, or how long they're keeping it.  

In Europe, it's become a parlour game to debate and decry US government surveillance programs.  By contrast, there's far less debate or transparency about European government surveillance programs.  I can't even count the number of EU Parliament debates about US government surveillance, but I can't remember a single meaningful debate in that chamber about EU governments' surveillance programs.  Similarly, media coverage focuses heavily on US government surveillance, and rarely asks hard questions about what other countries are up to, aside from the routine Chinese-hack-a-day stories.  And side-lined, the data protection regulators are largely excluded from scrutinizing their own countries' surveillance programs.  One of the few exceptions, Richard Thomas, UK Information Commissioner some years ago, tried valiantly to raise the alarm about the risks of "sleep-walk into a surveillance society".  More typical, when the French CNIL was created four decades ago, it focused almost entirely on French government data collection and privacy, but today, the CNIL has shifted its focus 180 degrees and focuses almost entirely on private sector privacy issues.  

We need more transparency about government surveillance programs, not just in the US, but worldwide.  As unsettling as some revelations about the US programs prove to be, it's even worse to know almost nothing about what all these other countries are up to.  I understand that a public scandal a day keeps media coverage in play, but the super-secret surveillance programs in Europe and around the world need scrutiny.  Thankfully, some legal experts, including privacy scholars at Hogan Lovells, are adding sober analysis of the global dimensions of this challenge to an otherwise shrill and polemical debate.  There's no hope of getting transparency about government surveillance programs in China or Russia or Turkey, but there should be vastly more transparency in democratic, privacy-sensitive countries like Europe.  For example, we know almost nothing about what the German spy agency collects, and there's very little public discussion of it, despite Germany being one of the most privacy-sensitive countries on earth.  

I've spent many years advocating for privacy protections against excessive government surveillance, in a global context.  For example, in 2007, I was blogging about government surveillance issues in Sweden.  Only governments themselves can provide real transparency.  Asking a company like Apple to explain US government surveillance is like asking a fish to explain what the fishing boat is doing.   

First, we need more transparency from governments.  Then, we can ask the tough questions:  Mirror, mirror on the wall, who is the ugliest one of them all?

Thursday, May 2, 2013

My favorite holiday photos, and a trillion others



The two-centuries-long evolution of photography has constantly pushed the boundaries of privacy.  At each stage of its evolution, photographing the world has become easier, quicker, more mobile, more ubiquitous, more systematic, and sometimes more furtive.  And in parallel, technology has constantly evolved, to make it easier to store, share, tag, identify and analyze photographs at great scale.  Throughout the evolution of photography, privacy has always depended on social etiquette to regulate what people should and should not photograph, and should and should not share.  

Some places, like my swimming club, have long had rules against photographing.  But all the rules in the world will do almost nothing, unless individuals exercize self-restraint in what they choose to photograph, or not, and what they choose to share with other people, or not.  

This process has been going on a long time, and it will continue.  In the near future, can individuals lifeblog photos or videos of everything and everyone they see?  Technology will enable it.  Some people will love it.  So, once again, the question will be how social etiquette evolves in parallel to the technological evolutions.  

In privacy terms, we generally look to consent from data subjects to legitimize data collection.  But what about random people photographed in public places?  Practically speaking, it's not possible to obtain their consent to photograph them.  We live in a world with literally billions of people carrying cameras, built into small devices, with instant Internet connections.  Our world is becoming more transparent:  do the math, with billions of people, all snapping thousands (or someday, millions?) of photos.  

You can debate, and to some extent regulate, the collection of photos by large entities, like governments and companies, using drones or surveillance cameras, but you can't control what billions of free human beings will photograph and share.  Over time, governments and companies will try to figure out how they can analyze these mountains of crowd-sourced user-generated photos for their own purposes.  

As always, expectations of privacy are heavily cultural.  Technology will continue to evolve.  Expectations of privacy will sometimes collide with the technology, and each will influence the other.  Sometimes, technology will just be a few years ahead of the social consensus evolving to accept it.  Sometimes, it will be a generation ahead.  We're quickly moving from a world where billions of photos are published online, to a world of trillions.  Technology will follow its ineluctable and unpredictable logic.

As humans, we learn when it's rude to peep.  That's a super-subtle human-cultural contextually-dependent evolving social convention.  You can't (yet) teach a machine to know when it's rude to peep, or when it's rude to photograph someone's private moment in a public place.  But you can teach fellow humans.   

Smile!, as you think of 5 billion humans who will be roaming the earth photographing everything and everyone they see.  

Wednesday, April 17, 2013

The Saga Continues...now to the Italian Supreme Court


In December of last year, an Italian Court of Appeals overturned my conviction—as well as that of two other Googlers—for violating Italian privacy law in a case that stemmed from a user-uploaded video.  I was pleased that well-reasoned legal principles had prevailed, and was hopeful that that would be the end of this long saga.  Last week, however, the Italian prosecutor appealed the Court’s decision to the Court of Cassation (the Italian Supreme Court).  This case, unfortunately, is not over.  In its appeal to the Court of Cassation, the Italian prosecutor asserts—in addition to arguing that employees like me can be held criminally responsible for user-uploaded videos that we had no knowledge of and nothing to do with—that platforms like YouTube should be responsible for prescreening user-uploaded content and obtaining the consent of people shown in user-uploaded videos.  I, and the many others who have voiced their support, view this as a threat to freedom of expression on the Internet.  I’m disappointed that this case is not over, but continue to believe that ultimately justice will prevail. 

Saturday, April 6, 2013

What people in the know now know that you don't know



When I was on Rhodes recently, I marveled at how virtually every building was designed with one principle in mind:  security.  What's the biggest threat to privacy in the world today?  It's security breaches!  People in the know now worry how vulnerable the world's databases have become to security breaches.  

Shadowy armies of hackers around the world, especially in China and Russia, sometimes loosely affiliated with the governments, are succeeding in hacking the world's most sophisticated corporate and government databases.  Security experts know that it's often hard to know that you've been hacked.  I'm more worried about the companies and governments that blithely think (probably wrongly) that they have not been hacked, rather than those that have identified security breaches.  


Real people, year after year, say that identity theft is their number one privacy concern.  And usually, people become victims of identity theft after their personal data has been hacked from a legitimate controller's database, e.g., from your local hospital..  


The risks of security breach are getting worse, and will continue to get much worse for several reasons.  First, the hackers continue to get more sophisticated.  Second, there's just more and more data being collected and stored everywhere.  Third, there's a proliferation of devices being used to collect, store and share data.  Fourth, the lines are being blurred between public and private databases, e.g., between what's behind a firewall and what is not.  Fifth, the rise of social networking and mass-sharing of data.
How should the laws respond to these threats?  


First, security breach notification laws are a good thing.  They bring transparency and help people take precautions, after being told that their personal data may have been compromised.  The US has had these laws for over a decade, and Europe proposes to adopt similar laws soon.  


Second, controllers need to be held to account for having adequate security.  But we also have to be careful not to punish the victim.  In most cases of security hacks, the company/government that has been hacked is the victim of a crime.  They have often been hacked by highly sophisticated organized criminals.  The laws need to be careful not to punish the victims of such crimes, unless it can be demonstrated that they had failed in their duties to maintain adequate security.  If you are the victim of a burglary in your home, you don't expect the police to fine you for not having had adequate security protecting your house.  Ex post, you could always have had more security.  The challenge is figuring out what an appropriate level of security should be, or should have been.  


Third, governments and law enforcement need to step up their games in finding, punishing and dissuading hackers.  The Obama Administration has raised the issue of Chinese hackers at the highest levels of the Chinese government.  Today, sophisticated hackers successfully evade identification and punishment.  


Fourth, individuals need to be helped to protect themselves better.  For example, they can be educated and prodded to use stronger passwords, learn to use privacy settings, keep their systems' security up to date, etc.  


Fifth, ask yourself who's protecting you from the risks of cyberwarfare and cyberterrorism and industrial espionnage.  Are the people who are supposed to be protecting you working together effectively?


It's pretty obvious that most government and corporate controllers have weak security.  I was recently in the offices of a French government agency processing a lifetime of my personal sensitive data, and it was operating a computer system from the 1990's!.  Romanian hackers would probably need 5 minutes to steal every piece of my personal sensitive data from that system, and neither the French government nor I would ever know it had happened.  


If you care about privacy, and you're not worried about security, then you're like a baby turtle, just hatched, hurtling your way to the sea, oblivious to the seagull that's about to extinguish your young life. 


Thursday, April 4, 2013

Stretch Goals for Privacy Lawyers



The global trends in privacy are crystal clear:  more privacy laws, more litigation, more regulation, more compliance obligations, more enforcement actions, bigger sanctions.  These trends are in place in almost all countries around the world, so the cumulative global impact of these trends on companies is dramatic.  So, want to guess which profession will profit from these trends?:  yes, the lawyers.  (In full disclosure, I'm a lawyer.) 

Historically, privacy leaders at companies have come from different backgrounds.  Some were lawyers, some were engineers, some were compliance managers.  At most companies, lawyers are already filling the roles of chief privacy officers (or data protection officers, as they're called in Europe).     

Privacy has changed over the years.  It is becoming an increasingly litigious matter.  A few years ago, privacy class actions hardly existed.  Now they're as common as locusts in Egypt.  

A few years ago, the sanctions for privacy breaches were relatively small, generally in line with the fact that the "harm" from them was often negligible, or difficult to define or measure.  Now, fines are increasing rapidly, and indeed, Europe plans to introduce fines in the range of 2% of global turnover, for rather routine privacy mis-steps.  Companies will have no choice but to fight threats of billion-dollar fines with teams of lawyers.  Europe is proposing billion-dollar fines for having a privacy policy that is "too vague", or for failing to properly document data processing, or for security breaches, or for riding a bicycle without a helmet.   In other words, you can face mega-fines for just about everything and anything, so you'll need plenty of lawyers to defend you. 

Lawyers are trained in reading, understanding, interpreting and advising on laws and legal compliance programs, and defending their clients from litigants and regulators.  Privacy laws, everywhere in the world, are vague, so they leave much room for legal interpretations.  The lawyers' skill set is becoming more and more central to the role of privacy leadership.  Moreover, lawyers benefit from attorney-client privileged communications internally, which is becoming an absolutely essential mechanism for privacy lawyers to have deep, unfettered, unfiltered exchanges of information and advice with their clients.  

Of course, non-legal disciplines will always play an essential role in safeguarding privacy at companies, e.g., the vital role played by security engineers.  Privacy will always be a cross-disciplinary project.  I'm not saying that the rise of the lawyer-privacy-leader is necessarily the best thing for "privacy".  Yet in the face of rampant litigation, discovery orders, vague laws, political debates, regulatory actions,  threats of billion dollar fines, companies will be looking to their privacy lawyers for a lot more than drafting a privacy policy.  It's a great profession, if you like stretch goals.  

Wednesday, March 27, 2013

Why Johnny can't read...a privacy policy



Why can't Johnny read a privacy policy?  It's because privacy policies aren't being written for Johnny to read.  They're being written for regulators and lawyers to read.  Or well, more fairly, they're being written for Johnny, in the ways that regulators and lawyers think they should be written.  

Today, privacy policies are being written to try to do two contradictory things.  Like most things in life, if you try to do two contradictory things at the same time, you end up doing neither well.  Here's the contradiction:  should a privacy policy be a short, simple, readable notice that the average end-user could understand? Or should it be a long, detailed, legalistic disclosure document written for regulators?  Since average users and expert regulators have different expectations about what should be disclosed, the privacy policies in use today largely disappoint both groups.  

On the one hand, privacy policies are supposed to be disclosure documents for the average end user.  In other words, privacy policies are supposed to be simple, readable notices that are used by any entity that processes personal data to tell their users basic stuff, like what data they collect, how they use that data, whether they transfer that data to any third parties, etc.  In addition, privacy policies are the main mechanism for entities to obtain consent from end users to process their data, even if that consent is often implicit.

On the other hand, regulators around the world, with good intentions, continually call for longer and longer privacy policies (not in those words, of course), by demanding that X, Y, and Z be disclosed.  Whether Johnny cares about X, Y, and Z is irrelevant.  Companies have to disclose X, Y, and Z, or they'll risk regulatory sanctions.  Johnny probably couldn't understand X, Y, and Z anyway, and X, Y, and Z are probably privacy-legal terms of art.  HIPPA is a famous example of legally-required privacy notices that Johnny can't read.  

The time has come for a global reflection on what, exactly, a privacy policy should look like.  Today, there is no consensus.  I don't just mean consensus amongst regulators and lawyers.  My suggestion would be to start by doing some serious user-research, and actually ask Johnny and Jean and Johann.

Tuesday, March 12, 2013

We Need a Better, Simpler Narrative of US Privacy Laws



Ask yourself why a European privacy regulator can propagate the preposterous view publicly that the US has "no effective privacy laws."  And lots of people seem to believe that.  And why does it matter?

On the global stage, Europe is convincing many countries around the world to implement privacy laws that follow the European model.  The facts speak for themselves:  in the last year alone, a dozen countries in Latin America and Asia have adopted euro-style privacy laws.  Not a single country, anywhere, has followed the US-model.

Indeed, what is the US model?  People in the privacy profession know that the US has a dense "patchwork" model of privacy laws:  every individual US State has numerous privacy laws, the Federal government has numerous sectoral laws, and numerous other "non-privacy" laws, like consumer protection laws, are regularly invoked in privacy matters.  Regulators in many corners of government, ranging from State attorneys general, to the Federal Trade Commission, and armies of class action lawyers inspect every privacy issue for possible actions.   

How on earth do you explain US privacy laws to an international audience?  How do you explain the role of class action litigation to people in countries where it doesn't even exist?  The US privacy law narrative is convoluted.  That's a pity, since almost all of the global privacy professionals with whom I've discussed this issue agree with me that the sum of all the individual parts of US privacy laws amounts to a robust legal framework to protect privacy.  (I didn't say "perfect", since laws never are, and I'm not grading them either.)

By contrast, Europe's privacy narrative is simple and appealing.  Its laws are very general, aspirational, horizontal and concise.  Critics could say they're also inevitably vague, as any high-level law would have to be.  But, like the US Bill of Rights, they have a sort of simple and profound universality that has inspired people around the world.  And they are enforced (at least, on paper) by a single, identifiable, specialist regulator. 

Europe does a great job explaining (or marketing, if you prefer).  The US has to figure out how to explain its privacy laws on the global stage. There's more at stake than just prestige.  There's more at stake than just asking why Uruguay, to take a random recent example, looked to Spain, rather than the US, for inspiration as it wrote its recent privacy laws.  What is at stake are important things:  first, trust in US-based companies and trust in the US Government around the world.  People will trust them less if they believe the story-line that they operate in a country with "no effective privacy laws".  And second, hopes to include digital trade in President Obama's initiative for a grand new US-Europe Trade Pact.  The lack of "adequate" US privacy laws is cited by Europeans as a reason why it is illegal to transfer personal data from Europe to the US, which is quite obviously, at least in part, a free trade issue.  Privacy will prove a serious roadblock to any such future trade pact, as long as some people in Europe can argue that the US has no effective privacy laws.  

Privacy is not alone among complicated subjects in need of a simple narrative. Visit a cathedral, if you need inspiration.   

Monday, March 4, 2013

A Glorious Day for a Free Internet in Italy



Just before Christmas, an Italian Appeals Court over-turned the convictions of three Googlers, including myself, for allegedly violating Italian privacy law.  Now, after roughly 2 months, the Court has issued its written opinion to explain its decision.  The Court's opinion is a lucid and ringing endorsement of the principles Google and I have been defending since the beginning of this prosecution 6 years ago:  
  • Intermediary Liability:  The Court held that Internet platforms, like Google Video or YouTube, are not responsible for user-uploaded content, absent notice of inappropriate content.  These platforms also cannot—and should not—be required to pre-screen content that is uploaded to them.  Any efforts to pre-screen content would raise serious risks to users’ freedom of expression.  In the Court's own words:   “Imposing a duty on or granting the power to, an internet provider to carry out prior screening seems to be a step that is to be afforded particularly careful consideration, given that it is not entirely free of risk due to the possibility of a conflict arising with the principles of freedom of expression of thought”.
  • Privacy:  The Court held that people who film and upload videos are responsible for compliance with data privacy laws.  Internet platforms cannot possibly obtain the consent of people appearing in user-uploaded videos.   In the words of the Court:  "it is patently clear that any assessment of the purpose of an image contained in a video, capable of ascertaining whether or not a piece of data is sensitive, implies a semantic, variable judgement which can certainly not be delegated to an IT process".
  • Criminal Responsibility:  The Court recognized the basic legal principle that employees like me could not have the required criminal intent to violate data privacy laws when they had nothing to do with, and weren't even aware of, the alleged criminal data privacy violation.  

This case was never about me at all, as I was just a random and unfortunate vehicle for a broader judicial test of  intermediary liability.  Obviously, I'm relieved personally to be acquitted.  But I'm delighted that this case has generated a clarion legal precedent in favor of freedom of expression.  In particular, I'd like to thank the many people who expressed their support for me throughout these six years, in particular, my numerous colleagues at Google and my stellar team of outside counsel, all of whom worked tirelessly to see these principles prevail.  And I'd like to thank the many people who realized that there were important principles at stake in this prosecution, who added their voices to the policy debate, in Italy and beyond.  This saga is (probably, hopefully) over for me.  

Together today, we can celebrate and applaud this step forward towards a brighter digital future in Italy.  

Sunday, February 17, 2013

Don Quixote



Re-read Don Quixote as you follow the debate about revising Europe's privacy laws. Is it more noble to pursue the glory of fantasy over the indignities of the real world? Do we want to defend an obsolete chivalric code, while the rest of the world looks on with derision?  Do we want a strong privacy law that can be operationalized or a glorious piece of literature? 
 
American companies are starting to freak and shriek about Europe's upcoming new privacy laws. In turn, various European politicians are publicly posturing about how all this is required to rein in American companies, while feigning resentment that American companies are lobbying for their interests in Brussels. In reality, of course, the new proposed EU laws are full of flaws, in particular imposing lots of pricey new compliance-bureaucracy obligations, and threatening minor compliance violations with absurdly-high fines in the range of 2% of a company's global turnover. But let's not let reality sully this tale. Don Quixote is defending privacy against the American-mega-corporate-privacy-slayers. Don Quixote is defending the Right to be Forgotten.
 
Sadly, things don't end well for the noble knight, unsettling and unsaid...American companies will come out big winners, compared to their European rivals. European companies face decades of innovation-paralysis under the new rules. American companies will just reorganize and relocate certain operations out of Europe to mitigate risk.
 
Like many people in the privacy profession, throughout my career, I had always thought it was sensible to apply Europe's privacy laws worldwide, in the interests of maintaining one, consistent worldwide standard. I'm changing my mind now. As the proposals to revise the privacy laws in Europe become whackier by the day, I am starting to believe that the "world" will have to watch Europe do its own thing in its own backyard, while maintaining a different, faster, more innovative pace in the "rest of world". Granted, Europe is a market that is just too big to ignore, but that's no reason why special compliance rules for it should be exported globally. No one applies Chinese censorship rules outside of China, so this would hardly be the first time that companies apply special rules in one particular country/region.
 
Europe's proposed rules will end up costing a lot, if you care about innovation in Europe. I'm a technophile, in the sense of believing that fast innovation is the only hope to maintain high rich-world living standards for our aging Western societies in the future. But I am troubled by how many roadblocks are being put in place to drag down the speed of innovation. Don't get me wrong: I'm all for serious privacy ethics, for privacy sensitivity, for privacy by design. But I'm not a fan of privacy-bureaucracy-drag. Europe, as one would expect, developed the world's most extreme form of bureaucracy-drag, when it invented the notion of bureaucratic "prior approval" for new technologies. That means that a new technology is dependent on a bureaucracy's prior approval before being launched. Or prior approvals for international data transfers (how absurd, in the age of the Internet!). Or prior approvals for binding corporate rules, and a thousand other bureaucratic hills and hurdles. Reality, again, is often a rather dis-spiriting affair.
 
Despite all its good intentions, Europe is also giving the world hopelessly vague privacy laws, sometimes enforced with criminal penalties. For example, what does it mean to impose jail time on someone for "processing sensitive personal data without the data subject's consent"? Does that justify jail time for posting a photo to a social networking site, given that a photo will reveal a person's race and sometimes health conditions (all, "sensitive" categories)? I have faced personal criminal prosecutions on flimsier privacy-law grounds than that, so these are hardly hypothetical risks. In short, Europe is making it increasingly risky to pursue innovation in the field of Big Data, in Europe.
 
The cynical realists will see that Europe's innovation-inhibiting privacy laws will simply drive more Big Data and Internet innovation to move increasingly outside of Europe. Will we see companies choose to move their research arms elsewhere, for example, to the US or India or Singapore? Ask yourself whether US or European companies will turn out to be more hobbled by Europe's rules? The answer is obvious: European companies will have to swallow these new rules entirely, while non-European companies can simply ring-fence their slower, less innovative operations in Europe. Companies may end up offering a series of slower, less-cutting-edge services in Europe, given the significant risks that cutting-edge data-services could be smacked with massive fines.
 
I say all this with sadness, as the world moves on. Who am I to deride Don Quixote's dream? Who am I to celebrate the demise of his delusions?

Monday, February 11, 2013

Talking Privacy to the Guys in the Pool


I'm in Florida for a few days, joining the Privacy Law Salon, and a chance to talk about privacy with a lot of experts in the field. But I usually think it's more fun to talk about privacy with the guys in the pool. Ft Lauderdale is the home of the International Swimming Hall of Fame, so it's a change of scene from my usual Paris pool. We don't hang on the walls long, so conversations are short.
   
Privacy is more important than security? Not true. Without security, you drown. You're either being hacked and know it or being hacked and don't know it. Imagine drowning without even realizing it. All of privacy is a wobbly edifice built on the foundations of security. If the foundations aren't solid, then the edifice will crumble.
 
Privacy is contextual: We live in Speedos, but can't wear one to the office. Online screws up context, because it takes data from one context and re-uses in another. People peek, machines record. You can't attribute human motives to a machine, or teach it that it's rude to stare.
 
Privacy is about losing it: We never give a thought to privacy, until it's gone.  Like breathing, you don't think about it, but in a lungbuster set, breathing on stroke 3, 5, 7, by 9 you will explode if you don't breathe.
 
Privacy requires discipline: 6 am, get up, go to pool. People expect anyone who holds their data to have fault-proof privacy, in particular iron-tight security, no excuses, no days-off. But in reality, nothing is perfect and people are only human. Like a cramp in the middle of your swim. You younger start-up guys are faster, but you're half my age. Sure, you can swim 50 free faster, but can you sustain it for a lifetime?
 
Privacy requires transparency: Coach sees your stroke. Privacy should be as transparent as possible. But privacy processing on the modern Internet has become so complicated, technically and in terms of scale, that human brains can scarcely comprehend it anymore. How can I grasp machine learning algorithms, when I can barely count laps? And you're supposed to explain every aspect of online processing to the average user, like explaining a flip turn in words to a non-swimmer?

Privacy is not a team sport: Even if you swim in a team, you still swim alone. Privacy is a social construct about one individual identifiable human being. Nothing in the Age of Big Data is going to change the fact that privacy is about the individual. And conversely, if it's not about an individual, then it's not about privacy. The team doesn't have privacy, it's about each of us individually, just like a team medley is really four individual swims in a row.
 
There's no place called privacy. There's no destination in swimming either, you just go round and round until your mind or body gives up. Most of my work in the field of privacy and technology is like a sandcastle on the beach, washed into irrelevance by the next tide of technology. And yet, I never doubt its importance.

The zone is furtive. A lifetime of work and setbacks, 10K per day, and then for a fleeting moment in the pre-dawn darkness, my mind goes blank and everything disappears except the sensation of an ecstatic wave chasing a vision of the perfect fly.