Monday, October 29, 2012

Singapore passes a modern privacy law. Cheers!









Singapore is the latest in the long list of countries that have recently passed privacy laws.  It's joining other Asian countries, like Malaysia and The Philippines, in this year's crop of countries with new privacy laws.

This is in part a tribute to Europe, where modern privacy laws were invented in the 1960's.  Well, they were modern then.  Now, they're pretty much out of date.  There was a school of thought in Europe that data protection laws are a perfect expression of fundamental human rights, a beacon to all mankind, like the Venus de Milo, to be admired and copied by all humanity. 

Singapore has passed a modern privacy law.  Europe, by contrast, is trying to modernize its old privacy law.  Europe should try to learn a lesson from Singapore's new law. 

To me, there is a simple test of whether a privacy law is modern:  how it handles the issue of "international transfers of data".   Indeed, if you asked me to pick the one notion of existing European privacy laws that is most in need of modernization, I'd pick this one:  Europe's restrictions on international transfers.  Bizarrely, in the long list of things that Europe is now proposing to "modernize", the need to create a more rational framework for international transfers is not on the list.  Singapore got this right.  Singapore's new law simply says that a company that transfers data outside Singapore is responsible for ensuring that it continues to respect the provisions of the privacy law.  Simple.  Effective.  Obvious.  

Or to quote Singapore's government minister's speech, when the law was passed:  "We are not adopting a prescriptive approach of restricting transfers of personal data to countries that have an adequate level of data protection. Instead, the Bill adopts a “principle-based” approach, where the onus will be on the organisation in Singapore to put in place measures, such as contractual arrangements, to ensure a comparable standard of protection is accorded to personal data transferred overseas. Therefore, there is no need to further burden organisations with disclosing to consumers where copies of their personal data will be transferred to."

Singapore's approach is a direct repudiation of the European approach, which makes it very hard to transfer data internationally.  The European framework has frankly become bizarre, with an entire legal industry contorting itself in gymnastics for international transfers:  
  • First, European laws declare transfers to be ok to other European countries and to countries deemed to have "adequate" privacy laws, but the list of "adequate" countries is a list of countries which make strange bedfellows, including mostly tax havens (yes, Monaco and Guernsey) and a few (I mean, literally, a few) others, ranging from Argentina and Uruguay to Israel and Canada.  
  • Second, there are a few hypothetical legal mechanisms to enable data to be transferred from Europe to other countries around the world.  Data can flow to the US if the company transferring it signs up the US-EU Safe Harbor Framework.  Data can also flow around the world if the company transferring it signs up to so-called Binding Corporate Rules, and if these Binding Corporate Rules are approved by Data Protection Authorities.  The pure simple fact is that only a tiny handful of Binding Corporate Rules have ever actually made it through the bureaucratic approvals process. E.g., to my knowledge, not a single Internet company has ever had Binding Corporate Rules approved.  So, practically, the option of obtaining Binding Corporate Rules is theoretical. 
  • Third, people can consent to having their data transferred internationally, although there's no consensus on what "consent" means or requires in practice, and no one even knows what a "transfer" is. 
Since we all know that data is being transferred internationally, every day, billions of  times per day, by everyone on the Internet, does that mean that every company, every government, every individual is "illegally" transferring data in Europe today?  Does that also mean that EU privacy laws are hopelessly out of data on this issue?  Well, yes.  And hardly a day goes by without yet another taxpayer-funded study by government authorities on the Cloud, sternly admonishing customers to comply with EU privacy laws on international transfers, and list the locations where data is processed, while at the same time acknowledging that there is no pragmatic, real-world solution to the archaic stuck-in-the-muck rules from the 80's on int'l transfers.  

Europe is attempting to modernize its privacy laws now.  It's proposing a number of sensible ways to modernize the laws.  But, missing an important opportunity, it is doing essentially nothing to try to modernize the single most important piece, namely, simplifying the rules around international data transfers.  Why not just get rid entirely of the reality-divorced restrictions on international data transfers, as most countries around the world have already done?  Whoever collects and transfers data should remain responsible for it, regardless of where the data is processed.  Period.  It's so simple.  

Singapore just passed a modern law, with a sensible provision on international transfers.  A modern law will help build a modern industry and create jobs.  If Singapore can do it, Europe can too.  Or if not, the rest of the world will just move on and build the future without us.  At least, the world will retain a deep affection for the historical treasures of Old Europe, like affluent Singaporean tourists snapping photos of the Venus de Milo in the Louvre, while our diminished-generation of children wait outside and hope to sell them a sandwich.  

Friday, October 26, 2012

Privacy-litigation: get ready for an avalanche in Europe








The US has long been a litigious country.  What's true in general in the US, is also true for privacy.  The US has a vibrant privacy litigation industry, led by privacy class actions.  Within hours of any newspaper headline (accurate or not) alleging any sort of privacy mistake, a race begins among privacy class action lawyers to find a plaintiff and file a class action.  Most of these class actions are soon dismissed, or settled as nuisance suits, because most of them fail to be able to demonstrate any "harm" from the alleged privacy breach.  But a small percentage of privacy class actions do result in large transfers of money, first and foremost to the class action lawyers themselves, which is enough to keep the wheels of the litigation-machine turning.  

Europe, by comparison, is not nearly as litigious as the US.  What's true in general in Europe, is also true for privacy.  In Europe, privacy is mostly handled as a regulatory matter, by Data Protection Authorities, who have the power to investigate complaints, launch enforcement actions and impose sanctions for breaches.  

In theory, any DPA enforcement action or sanction can be appealed to national courts.  In practice, this is rarely done.  Why?  Because European DPA sanctions tend to be very small.  Rationally, would you hire an expensive law firm to appeal a DPA enforcement action resulting in a 100,000 euro fine, if you knew that your outside counsel costs for the appeal alone would exceed that amount?  Even if you knew you'd win, you probably wouldn't appeal, as a purely rational matter. 

One of the unfortunate consequences of the current European DPA enforcement/sanctions model is that very few of its decisions are tested or validated by the courts.  If more of these cases were appealed to the courts, I am absolutely certain that many of them would be over-turned as a matter of law.  So, Europe is building up a body of regulatory "case law", which has never really had the discipline of judicial review, as we'd understand that concept in the US.  

Starting around 2015, when the new EU Privacy Regulation comes into effect, all this will change.  The new laws are almost certain to introduce vast new sanctions and fining levels for privacy breaches, expressed as a percentage (say 2%) of a company's global turnover.  Yes, you read that correctly.  Compare today, when the largest fine ever imposed by the CNIL in its history was 100,000 euros to this near-future, when fines could in theory run to many many millions.  You can do the math.  

Once there is real money at stake, everything changes.  Companies that today shrug their shoulders and pay small fines, rather than be bothered to hire lawyers and launch long legal processes, in the future will be confronted with the risk of massive fines.  Facing massive fines, companies will be required to hire expensive lawyers, launch intense legal battles, and generally handle privacy breach litigation with the full battery of legal process and tools.  Companies already do this in many other areas of law, so extending such practices to privacy law will not be hard.  

DPAs, on the other hand, are completely unprepared for this near-term future.  Many DPAs today operate "prosecution by press release", which is really not meant to withstand legal process, but rather to generate some press and reputational impact.  But DPAs are completely unprepared and un-staffed to launch serious legal actions, with a solid basis in law, and a solid respect of legal process, in a way that would withstand tough legal scrutiny and the judicial appeals process.  It's one thing to launch an enforcement action where the money at stake is 100,000 euros.  It's entirely different when the money at stake is 100,000,000 euros.  

In this post, I'm not commenting on whether creating large sanctions for privacy breaches in Europe makes sense or not.  I'm just saying that the entire legal/procedural game changes when there's lots of money at stake.  Privacy litigation will become an outside counsel growth area in Europe.  Companies will handle privacy in Europe increasingly as a litigation matter, rather than a regulatory matter.  And DPAs are going to have to figure out how to stand up to defendants' legal heavy artillery, something few of them have ever faced.  

Privacy litigation is already a big business in the US.  In a couple years, privacy litigation will go big time in Europe too, once big money is at stake.  Finally, we've found a growth industry in slow-growth-Europe.  


Thursday, October 25, 2012

Microsoft's brilliant master class on how to change a privacy policy



Privacy professionals are often asked how to change or update a Privacy Policy.  There are really just two basic choices:  openly or quietly.  

Naturally, I was professionally curious to see how Microsoft went about changing its privacy policy recently.  It was particularly interesting, because Microsoft made changes that were very similar to those Google made to its own privacy policy in March.  It's interesting when you have two large companies, making very similar changes to their privacy policies at the same time, but annoucing them in very different ways.  

Microsoft made its changes in legalistic language in something called the Microsoft Services Agreement.  

When Google announced its changes, Microsoft launched a worldwide PR campaign to discredit Google.  So, it is striking that Microsoft quietly made similar changes to its privacy policies that it so loudly criticized Google for making.  After Microsoft took out full-page newspaper ads to criticize Google for its changes, did Microsoft take out similar full-page ads to inform its users of the changes Microsoft was making?  Nope.  And "almost no one noticed" Microsoft's changes, as The New York Times reported.  

If the goal was to make changes in their privacy rules that "almost no one noticed", Microsoft was brilliant.  

I can guess what lessons will be drawn by most privacy professionals from this master class.   When the time comes for privacy professionals to update their own privacy policies, they now have two models to compare.  The open and transparent path led to worldword advocacy tirades and intense regulatory scrutiny.  The other path, well, Microsoft brilliantly blazed a trail so that "almost no one noticed".  Which path do you think privacy professionals will pick in the future?  Which path do you think is good for privacy?

Sadly, we all know the answer.   


Tuesday, October 23, 2012

Privacy Professionals peregrinate to Punta



Today in Punta del Este, Uruguay, is the annual conference of the world's data protection commissioners.  It also brings together a large number of people in their orbit, like privacy advocates, practitioners and lobbyists.  These are annual conferences, usually held in Europe, but occasionally in other countries around the world, as a "reward" for adopting European-style privacy laws.  Uruguay has just adopted euro-style-privacy laws, so it's the host this year.  In previous years, other countries that had recently adopted euro-style privacy laws, namely Mexico and Israel, were hosts.  Countries that have not adopted euro-style privacy laws, like the USA or Japan, are not deemed eligible to be hosts.  In fact, until recently, the US Federal Trade Commission wasn't even allowed to vote in the commissioners' meetings, but was only allowed to attend in a sort of second-class "observer" status.  Finally, two years ago, the FTC was admitted as a member of the commissioners' club.  

I have nothing against privacy confabulations.  There are always a lot of interesting things to talk about in the world of privacy.  Of course, all this talk could easily be conducted virtually, using simple Internet technologies, essentially for free. I won't be going to Punta, but I wonder if the Microsoft speaker, who will key-note there, will explain why they changed their privacy rules, as The New York Times reported, in a way that "almost no one noticed".  Or if he'll talk about how they use an army of privacy lobbying proxies, including former privacy regulators, as The Economist reported

I'm sure the conference will provide taxpayer-value-for-money, going by the pictures of the beach and the 5-star hotel in Punta on the Conference website. Flying half-way around the world to hear a Microsoft lecturer on privacy...priceless!  

Monday, October 8, 2012

Groupthink


There's an entire, vibrant privacy conference business.  There are privacy conferences somewhere in the world every week of the year.  Some are commercial, some are taxpayer-funded.  Why are they so boring?

Because they take one of the most interesting topics in the world, privacy, and discuss and debate it from an insular perspective, namely, from the perspective of people who are in the privacy "industry."  I'm very clearly part of this "industry" too.

The privacy "industry", or "privacy industrial complex", as some wags have dubbed it, consists of privacy professionals at companies, privacy advocates, privacy regulators, privacy consultants, etc.  So, conferences tend to be incredibly banal statements about who's more committed to privacy, and begin with stentorian declarations, like "privacy is a fundamental human right, therefore...".  Or they consist of a "debate" between two privacy advocates, which is like listening to two members of the National Rifle Association debate the social benefits of gun control.  Or they consist of paid-corporate advocates trashing their competitors' privacy record, often without disclosing who is paying them to do so.

The interesting privacy debates, in my opinion, are the debates where privacy is balanced against other fundamental human rights, like freedom of speech, or balanced against other social goals, like encouraging innovation, or tested against other yardsticks, like regulatory cost-benefit analysis.  But very little of that occurs at privacy conferences, because virtually no one from outside the privacy "industry" speaks at such events.  E.g., rather than hearing privacy-people talk endlessly about the need for more privacy regulation, I'd like to hear from an economist evaluating whether such regulations are effective, or whether their costs exceed their benefits.  Rather than hearing privacy-people talk about the need to create a "right to be forgotten", I'd rather hear from a free speech advocate on how such a right would undermine freedom of expression.  Rather than hear privacy-people talk about how technology needs to be reined in, and subject to bureaucratic prior approval (in other words, slowed-down), I'd rather hear from people who are committed to building modern and dynamic economies about how (archaic) privacy laws are hampering the creation of innovation-based economies.

But privacy conferences have largely become like any other conclaves of groupthink.  At a Vatican conclave, you don't get a serious discussion about the health benefits of promoting the use of condoms.  At a Tea Party rally, you don't get a serious discussion about whether government welfare benefits are a guarantor of minimal human decency.

I have pretty much stopped going to most privacy conferences, at least for now.  When I go, it's mostly to have a chance to have one-on-one chats with people I'd like to meet or catch-up with.  I think privacy is the most interesting topic in the world.  But groupthink gatherings don't move the debate forward.  If I was at an NRA meeting, I'd advocate for gun control to help reduce the shockingly high murder rates in the US, and I'd probably be run out of the room.  There are so many smart people in the privacy profession, why aren't we challenging each other more, to take a small, wild step outside the privacy-industrial-complex, and actually engage more with the real world?


Thursday, September 20, 2012

The algorithm decided not to hire you: is that legal?


I spend a lot of time thinking about privacy and algorithms.  

The Wall Street Journal carried an interesting story "Meet the New Boss:  Big Data", about how algorithms are now being widely used to make human resources decisions, like hiring and promotion.  The article pointed out that such algorithms could run into legal problems, if they intentionally or unintentionally filter out protected categories of employees, like older employees, under US anti-discrimination laws.  But the article didn't discuss a more fundamental legal issue, at least in Europe.

In Europe, "automated individual decisions" are a violation of EU privacy laws.  Article 15 of the EU Privacy Directive guarantees:  "...the right to every person not to be subject to a decision which produces legal effects concerning him or significantly affects him and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to him, such as his performance at work, creditworthiness, reliability, conduct, etc".  

Well, that's about as clear as a law can get.  In our age of Big Data, we all know algorithms are being refined and used more and more widely to make decisions about hiring and promotion, and many other topics.  But when these decisions are made solely by algorithms, they are violating EU privacy laws.  Period.  The only way such algorithms can be used legally is to supplement them with certain other measures to safeguard the legitimate interests of the person being evaluated, e.g., by allowing him to put his point of view.  

I'm a great believer that algorithms can help all of us (governments, businesses, individuals) make better decisions.  But when a computer program is making key decisions by itself about whom to hire or fire, or whether or not to extend credit to someone, it's fair to ask for additional safeguards.  The privacy laws in Europe require it.  I'm agnostic about whether algorithms are more or less fair than humans at making a lot of such decisions.  In any case, companies using such algorithms need to consider how to make them comply with European privacy laws.  When algorithms are used to supplement other evaluation tools, they should be legal.  When algorithms are used to make these decisions by themselves, there's a serious risk they would be considered illegal in Europe.  Use with care.  



Wednesday, August 22, 2012

August in Paris: has everyone left?



A VIP friend of mine, Monsieur Banal, rang me up

Mr Banal:  Bonjour, Pierre.  Sorry to interrupt you with a phone call in August, but I can't reach any other foreign executives in France.  Where have all the others gone?

Me:  Monsieur Banal, they have moved to Switzerland, or Belgium, or the UK, to escape your plans to tax them at 91%.  

Mr Banal:  No, it's 75% tax, plus social charges.  Together taxes are over 90%.  That's true.  But only for the rich. 

Me:  But, Monsieur Banal, your tax rates are double those of London or Switzerland.  Mitt Romney pays 13% tax!  Even for people who love France, like me, how can we ever save for retirement if there's nothing left after taxes?

Mr Banal:  You don't need to save for retirement, since we have a generous French pension system, and you can now retire with a full pension at 60, thanks to me, the lowest retirement age in Europe.   

Me:  Monsieur Banal, do you remember when George W Bush said:  "French doesn't even have a word for entrepreneur'.  Ok, it was a very funny line.   Entrepreneurs building new businesses around the world use stock options as a way to incentivize their workforce to create new companies.  So, why would you pursue a policy to make stock options illegal?

Mr Banal:  In the public sector, we don't get stock options, so we see no reason why you should either.  We believe in fairness. 

Me:  Entrepreneurs often complain about suffocating regulation and bureaucracy.  Will things get better here?

Mr Banal:  I have never worked one day in my life in the private sector, but I learned how to regulate the excesses of capitalism at the Ecole Nationale d'Administration. 

Me:  France has well-educated, productive workers, doesn't it?

Mr Banal:  Indeed.  In France, we have a happy workforce.  Our employees get more vacation than almost anywhere in the world (by law, a minimum of 5 weeks per year), and they work fewer hours than almost anywhere in the world (by law, 35 hours per week).  This makes them very happy.  It is true that they sometimes strike, but only when they are not happy.    

Me:  What if my business fails?  

Mr Banal:  My Ministre du Redressement Productif (I cannot translate this into the English) will castigate you in the media, but it's only populist politics.  Don't pay any attention to him.  I don't really hate the rich, I just say that to set the tone.  

Me:  Why would so many French entrepreneurs expatriate to London or Silicon Valley to build their businesses?

Mr Banal:  Indeed, this is completely unacceptable.  We have a tradition of engineering excellence, and my government will help select those French technologies and businesses that deserve to succeed in the future.  

Me:  Let's have lunch in September.  

Mr Banal:  Sorry, I've been invited to lunch in Berlin.  I don't like the food there, but at least they pick up the check.  Will you still be in France when I get back?  


Thursday, August 16, 2012

It's time for a "lead regulator" in Europe




Who's in charge in Europe?  That's a common conundrum for those of us who work in the privacy field in Europe.  When I was at a Berlin privacy conference, dopey picture attached, everyone was talking about it.

Privacy regulators play the key role in enforcing privacy laws.  Most companies (certainly all Internet companies) operate globally.  So, it's a natural question to ask which regulator(s) will or should have jurisdiction to enforce privacy laws.  For many years, I have advocated for the concept of a "lead regulator" in Europe.  It makes a lot of sense for one country's regulator to take the lead on behalf of all of Europe.  It encourages consistency across Europe, it provides for a deeper regulatory-relationship, it saves taxpayer money, when numerous regulators are not all re-inventing the regulatory wheel.  This is exactly what the European Commission is proposing in its re-write of privacy laws for Europe.  

Take the example of Facebook, whose European operations are headquartered (in legal terms, "established") in Ireland.  Normally, the Irish data protection authority would therefore be the lead regulator of Facebook, on behalf of Europe.  And indeed, it has been acting accordingly, conducting a company-wide audit of Facebook's privacy practices.  

The key to making all this work is clear:  the concept of "lead regulator" simply cannot work unless other regulators to defer to their sister-regulator.  That's why this story caught my eye:  German privacy regulators re-open their investigation into Facebook's face recognition software, notwithstanding the fact that the Irish are currently investigating the same thing, and notwithstanding having previously said that they would defer to the Irish audit before proceeding.  

The German regulatory world is a microcosm of the European regulatory world.  Each "Land" in Germany has its own independent data protection authority.  In theory, each is entirely independent, and is free to investigate or regulate separately, or in addition to, or even differently than one of its sister-German-DPAs.  But in practice, the German DPAs have developed a custom (not based in law, but based in deference and mutual respect) that they would defer to the "lead German DPA".  In the example of Facebook, the DPA of Hamburg is leading on behalf of its sister-German DPAs, because Facebook's German headquarters are based in Hamburg.  That's why Hamburg, rather than, say, Munich, is investigating Facebook.  

So, the question is simple:  German DPAs have developed the concept of "lead regulator" amongst themselves.  But are they willing to respect the same concept, and show the same necessary regulatory deference, at a European level, e.g., vis-a-vis the Irish DPA? 

If the European Commission proposal becomes law, then the concept of "lead regulator" will be cemented into law.  I often critique other aspects of the Commission's proposal, but on "lead regulator", I applaud their efforts. The issue is contentious, and the French authority, the CNIL, to take one example, is very publicly attacking the concept of a "lead regulator", precisely because they don't want to defer to a non-French lead regulator.  

In the meantime, it's hard to know who's in charge.  I'm someone who believes that regulatory enforcement is more effective when it's absolutely clear who's in charge.  


Wednesday, August 15, 2012

Rainbows in Ravello: Technocracy or Democracy?



As the European elite has for centuries, I love summertime in Ravello.  Civilization has flourished on these ravishing hills for millenia.  Democracy has ruled here for only very brief interludes.  Indeed, modern Italy has given up on having an elected Prime Minister, and instead appointed a (well-respected) technocrat as their leader. The "democracy deficit" in Europe is well-documented.  When things get tough in Europe, well, do we turn our backs on democracy?  Virtually all European-level legislation is drafted by un-elected Brussels-based European Commission technocrats.  (I have the greatest respect to the intelligence and professionalism of the Commission staff, so my comments are institutional, rather than individual.)  What's true for virtually all EU legislation is also true for data protection.  The current EU proposal for revising EU Data Protection is a technocratic tour-de-force. 

The Commission has chosen the approach of a Regulation (directly applicable law), rather than the approach of a Directive (prior law was a Directive, which included scope for national parliaments to make adjustments).  There are pro's and con's to the Regulation approach.  The biggest advantage is that it would result in fully harmonized, consistent privacy laws across Europe.  That's why businesses love it: it's easier to comply with one set of rules, rather than with dozens of (slightly) different rules.  The biggest disadvantage is that a Regulation leaves no scope for national parliaments to bring their own democratic choices and legitimacy to privacy laws in Europe.

Privacy is the product of culture and history, and naturally, attitudes to privacy vary widely across Europe, given the wildly different cultural and historical experiences.  Even neighboring countries, like Germany and Denmark, have very different views on privacy, given their different histories and cultures.  Given Germany's history, we expect Germans to be particularly sensitive to privacy issues.  But should German views on privacy, based on Germany's traumatic history, or French views on State-dirigisme, based on centuries of an all-powerful centralized State, dictate privacy laws in a country like Britain that has been a stable parliamentary democracy for centuries?  Half of European Member States are first-generation democracies.  Does one size fit all?

The toughest choices in privacy laws are deeply political.  For example, how much cost are we willing to impose on businesses to improve privacy compliance?  This is a clear political trade-off:  how much bureaucracy, like privacy impact assessments, mandatory appointments of Data Protection Officers, etc is enough, before the costs become too burdomsome for European businesses, in particular, SMEs?  Where do you draw the line between freedom of expression and the "right to be forgotten"?  Where do you draw the line between citizens' privacy and government surveillance?  How much flexibility should the laws include to reflect the cultural and regulatory differences amongst countries in Europe?  Is a Regulation the right instrument in the interest of harmonization, or is the flexibility of a Directive more democratic?  How high should fines be set for data handling compliance mistakes (high enough to punish/deter, but not so high as to freeze European innovation and risk-taking)?  All these are deeply political issues.  I have my views, and the unelected Commission has its views, and unelected data protection authorities have their views, but what do European elected officials think? 

There has been very little political debate in Europe about how privacy laws should be up-dated for the modern world.  The European Commission technocrats have had their say, and they are naturally wary of seeing their careful package of privacy-compromises re-opened in a messy democratic debate in the European Parliament, and elsewhere.   Democracy is indeed messy, but, as the saying goes...the alternative is worse.  

"Privacy" is a deeply political and democratic issue.  It is too precious to leave all difficult privacy law decisions to technocrats.  Privacy needs and deserves a political and democratic debate.  Perhaps this is all part of a much bigger democracy deficit in Europe.  We're on a path to "solve" the Euro crisis by transferring even more power from elected national leaders to unelected Brussels technocrats.  Nonetheless, I hope we see a vibrant debate in the European Parliament on data protection.  Privacy laws need democratic legitimacy.  Anyway, that's what we, the European elite, are debating, sipping Campari over the Amalfi coast.  


Wednesday, August 8, 2012

A travel blog post, about data centers



Sometimes I think I should write a travel blog instead of a privacy blog.  I'm the kind of guy who likes to be outdoors and physically active, and I'm just back from hiking in Spain.  Galicia has a pristine coast like Brittany, but with fewer tourists.  And it's relaxing to have a few days to enjoy privacy, instead of worrying about it.  If I don't feel safe hiking in a place, I sure wouldn't recommend putting a data center there. 

Data centers are now big business.  They're part of the fundamental infrastructure of the Web.  And people naturally want to know that the data that they choose to store in the cloud will be safe.  The location of data centers is one factor in ensuring that data will be safe.  

Some countries have proven successful at fostering a data center industry:  a few come to mind immediately, ranging from the US, UK, Ireland, Belgium, The Netherlands, Norway, Finland, Hong Kong, Singapore, Taiwan, Japan (of course there are others, but these were top of mind for me).  All these countries strike me as welcoming jurisdictions, and they are succeeding in convincing international investors to put their money and host data there. Nowadays, data centers can be large investments, involving hundreds of millions of euros, creation of hi-skilled jobs, and spurring a virtuous cycle of hi-tech clustering.  It's no surprise that many countries are competing to attract them.  

I think there are two big factors in picking locations for data centers, namely, physical-infrastructure stuff and law.  

Physical infrastructure includes:  1) cheap, reliable and renewable energy sources,  2) a cool climate to reduce electricity running costs,  3)  lots of bandwidth.  

But law is just as important.  What's the legal/regulatory environment in each country, with regards to:  
  • the rule of law?  
  • censorship?  
  • fair legal process to validate/challenge government and law enforcement requests for user data?  
  • holding intermediaries liable for third-party content in the cloud?  
Many countries around the world fail all of these tests.  Some of them only fail one or two of them.  There is no commonly-accepted "black list" of countries where international companies should avoid placing a data center.  That's an interesting challenge, and perhaps deserves some public discussion.  Maybe someone should do a study to rank countries according to these criteria, just as countries are regularly ranked for competitiveness.  For example, companies also need to worry about opening a data center in a country where its employees could be held personally liable for third-party content hosted there.  (friends, how's that for understatement?) 

Maybe the safest place to put data centers, in terms of protecting users' data from government surveillance, would be on boats floating in international waters, powered by waves, cooled by sea water, and safely beyond the jurisdictional reaches of most governments.  Ok, not really, but then again, try coming up with your own list of countries.   And if you're having trouble concentrating, would you run the risk of landing in jail for a risky bet?


Tuesday, August 7, 2012

Mud-slinging, Anonymously



As a privacy-sensitive guy, I have always had a soft spot for anonymity.  But I wonder if things have just gone too far.  Sometimes, I hold my nose and try to read the "comments" on un-moderated platforms that allow "anonymous" to post comments.  Frankly, these comments often sound like monkeys throwing their feces at each other.  And all of this happens, because, well, it's anonymous.  Anonymity has become the shield of the ignorant, the inhumane, and the uncivil.  

I'm all for freedom of speech.  And in some contexts, anonymity is an essential foundation for freedom of speech.  Without anonymity, there would be far impoverished freedom of speech for political dissidents, or whistle-blowers, or other types of speech that are socially desirable, but which put the speaker at personal risk.  Nonetheless, the real question is whether the social benefits of certain categories of anonymous speech outweigh the tsunami of garbage that is being un-leashed behind the veil of anonymity on Internet platforms today.  

It's a hard challenge: can we figure out how to enable the socially-desirable forms of anonymous speech, while filtering out the anonymous slime, without turning into censorship engines?  

On this blog, I do not allow unmoderated comments.  In other words, I welcome your comments, but I review all comments before they are posted here.  I am not censoring the critical comments posted anonymously (you need only take a look at them to verify this).  But I do delete the many comments that are spam, or blatantly ignorant or hate-speech.  Really, a picture of myself hiking without a shirt should hardly prompt an outpouring of homophobic rants, but well, sadly, it did.  

As I grow older, I think more and more sites should reconsider the idealism of the early web, when many of us believed the world would be a better place, and privacy would flourish, by enabling people to express themselves anonymously.  Forcing people to use their real names on many sites might stop much of the grotesque defamation, hate-speech, cyber-bullying, ignorance and incivility that we are all enduring today, under some out-dated (and algorithmically ordered) view that "anonymous" should be free to say anything.

It's not easy for an Internet platform to figure out how to balance the benefits of anonymity against the lack of accountability that goes with it.  By the way, I use my real name for this blog.  Here's a picture of myself, vulnerable and unclothed, covered in mud on the Dead Sea.  If you want to comment with a homophobic or anti-Semitic rant, would you dare to use your real name?  I'm not writing a blog to give "anonymous" a platform for bile.  

I predict the Web tide is going to start ebbing away from anonymity, with a sea-shift back to real-world identity.

Friday, May 25, 2012

A torrent of bureaucracy



As Europe slips into recession and economic decline, how is privacy law being changed in Europe?  Sadly, privacy debates here, like the other big political debates in Europe, are not about how to foster the digital economy, but rather about how to regulate it.  Tax and regulate:  is that Europe's plan to build its digital economy?

While policymakers around the world are frantically nurturing their digital economies, what's happening here in Europe?  Lots, lots more red tape is coming.  Politicians are furiously running around giving media interviews about how this will rein in Facebook or Google, as though all of Europe's privacy laws should be written for one or two companies.  Indeed, wags have started to call Europe's new proposed privacy laws "Lex Google" or "Lex Facebook".  But trying to write a privacy law to "rein in" Google or Facebook is a sure recipe for writing a bad privacy law that would apply to all companies in Europe.

Very few people have actually looked at how Europe is planning to change fundamental privacy laws.  While politicians are posturing that this is a reduction of red tape, the reality is that it is on track to become the biggest increase in paperwork and compliance process obligations in the history of privacy law anywhere on the planet.  Moreover, here's an assessment that would surprise some people:  I think Facebook and similar big companies could cope just fine with the new proposals, one way or another.  But there is absolutely no way Small and Medium-size Enterprises in Europe could cope.  SME's are already an embattled group in Europe, facing the highest regulatory and employment tax burdens in the world.  Data protection officers at large corporations generally have lots of resources, and they can manage bureaucracy and paperwork, even if it costs a few more million euros.  For big companies, it's not a big deal if the data protection "compliance tax" increases by a few million "new pesetas" or "new lira".  Frankly, I wonder how an SME could possibly deal with this paperwork and process torrent, and how they're supposed to pay for it.

Consider the details of this regulatory torrent, and ask yourself how new legal obligations like those below would impact an SME:
  • 1)  Breathtaking fines for routine paperwork data protection lapses.  Large fines are proposed for data protection violations, some of which are really nothing more than paperwork lapses or documentation foot-faults.  Does anyone really think European SME's are set up to be able to report a data breach in less than 24 hours?  It baffles me how policymakers can propose to impose fines of 1 or 2% of a company's global turnover for not "adequately" filling out paperwork, such as "privacy impact assessments" or "documentation of data processing", especially since there is not even any agreement on what such paperwork is even supposed to look like.  
  • 2)  Mandatory Data Protection Officers.  What happens if we obligate all enterprises with over 250 employees to appoint a Data Protection Officer?  Practically, where are all these people going to come from, since only a handful exist today?  Can SMEs afford the cost of these new employees, or of outsourcing this function to expensive law firms?  Or over-burden others on their staff, e.g., a Human Resources person, to try to play this role too?  and needless to say, some companies with 250 employees (like Internet or health companies) have vastly different privacy impacts than others (like construction companies), so laws with arbitrary fixed rules are rarely well-adapted to the different realities of the real world. 
  • 3)  Mandatory privacy impact assessments.  What will SMEs have to do, if they are obligated to carry out privacy impact assessments on all new projects?  While I think such privacy impact assessments can be a useful privacy compliance tool for some projects, I also know that they are burdensome and time-consuming.  Can SMEs handle this additional burden?  While "privacy impact assessments" are still undefined, I estimate doing one would cost, roughly 10,000 to 100,000 euros.  I imagine most SMEs would have several, and larger companies would have many projects requiring such privacy impact assessments.  
  • 4)  Mandatory data processing documentation.  Documenting such data handling processes is time-consuming and difficult.  How much will it cost SMEs to document their data processing practices?  I would roughly assume that the burden to comply with this requirement would be comparable to the time/money spent complying with tax laws.  No one knows what it means to "adequately" document data processing, but nonetheless, these confused proposed privacy laws would threaten massive fines for failing to comply with an undefined standard.  
I hope SMEs will have their voices heard in the up-coming political process.  As long as the laws are passed to "rein in" Google and Facebook, you can be sure the SMEs will be ensnared in rules that make no sense for them.  But I wonder if politicians can limit SME-killing regulatory over-load.  I am worried about the impact of excessive regulation on Europe's digital economy, which is surely the world's most promising to create the jobs of the future.  All successful technology companies start as SME's.  Europe is committing a crime against its youth, when 50% of young people in many countries here are out of work.  SMEs create jobs, especially for young people.  Although politicians can run around and get media headlines about how these new proposed fines would rein in Facebook and similar companies, the reality is that a law applies to all companies, including SMEs.  Surely, we can figure out how to apply data protection paperwork obligations in a more sensible fashion, more adapted to the sensitivity and scale of data processing, than what is contained in the current proposed law.  Let's not suffocate European SMEs, as the unfortunate collateral damage of trying to "get" the big American Internet companies.

Europe is about to threaten companies with fines so large that they will throw them into bankruptcy for bureaucracy and paperwork foot-faults?   As countries around the world begin the competitive race to build their digital economies, we in Europe are starting the race by shooting ourselves in the foot?   It's possible to be deeply committed to privacy, without drowning in a torrent of privacy bureaucracy.

Monday, March 19, 2012

The Safe Harbor


Periodically, and again today, there’s a conference to discuss trans-Atlantic privacy issues, and take stock of the Safe Harbor framework. As an American who works in this field in Paris, I have long cared more than most people about trans-Atlantic privacy issues.

Why is the Safe Harbor framework still relevant? Here’s a reminder: the Safe Harbor framework was created because of a quirk in European law dating from 1995 that divided the countries of the world into so-called "adequate" and not-"adequate", in terms of having European style data protection. Countries like the US and Japan are not currently deemed to have "adequate" protections under EU law, but other countries like Argentina and Mexico and Israel are. It's a fair question whether the criteria to assess "adequacy" are themselves realistic or out-dated. Essentially, the criteria area formalistic: e.g., does a country have a European-style “independent data protection authority” and European-style “comprehensive” privacy legislation? So, countries that do not, like Japan and the US, are not deemed to have “adequate” data protection, but countries like Mexico, Argentina or Israel are. The Safe Harbor framework constitutes an “adequacy” regime for the US-based companies that comply with it. Therefore, the Safe Harbor framework is a partial solution to a bigger “adequacy” problem.

Rather than debating the Safe Harbor framework, we should be debating the “adequacy” regime. In the real world, no one would believe for a minute that data is less protected in Japan or the US than in Mexico, Argentina or Israel. But this bureaucratic fiction has very real-world consequences, if it makes “illegal” the transfer of personal data from Europe to these non-”adequate” countries. Surely, such routine global data transfers from Europe to Japan, to take just one examples amongst many in the cloud, can’t all be “illegal”?

Why does Europe fight so hard to maintain these rather reality-divorced rules, and why is Europe choosing not to modernize them as part of its comprehensive data protection law review? There is a simple reason, and it has very little to do with the reality of privacy protections. The so-called “adequacy” test is a powerful tool used by European policymakers to cajole other countries into adopting European style data protection laws and regulations. In 2011 alone, 6 countries in Latin America adopted European-style data protection laws. The motivation for these countries is often unabashedly trade-based, namely, the unhindered transfer of personal data from Europe to these countries, which hope to build information-based out-sourcing industries. Europe holds out a significant carrot to countries, saying essentially, “if you copy my privacy legal structure, we’ll reward you with information-based trade.” This, in a nutshell, is why Europe is winning the global competition to influence privacy laws in countries around the world.

I have long been an advocate of the vision of global privacy standards. Instead, what the world is getting is the globalization of European privacy standards.

Tuesday, March 13, 2012

"I didn't have time to write a short letter, so I wrote a long one instead". Mark Twain

I recently spent a few days grappling with government regulations written for the public. Together with my Dad, who is in his 80's, we tried to get some answers to simple Medicare questions about prescription drugs. I almost gave up when I realized that I still had no clue, after spending hours trying to read the government's guidance. I'm a Harvard-trained lawyer, and I couldn't understand them. I looked at my Dad, and I wondered what seniors are supposed to do who are often old and sick, and might not have a Harvard-lawyer around the house to help them.

Thankfully, there's a very worthwhile initiative, to get the US Federal government to use Plain English. Indeed, I think it's worthwhile to simply quote from the government's site directly:

President Obama signed the Plain Writing Act of 2010Adobe Acrobat Reader icon on October 13, 2010. The law requires that federal agencies use "clear Government communication that the public can understand and use." On January 18, 2011, he issued a new Executive Order, "E.O. 13563 - Improving Regulation and Regulatory Review.Adobe Acrobat Reader icon" It states that "[our regulatory system] must ensure that regulations are accessible, consistent, written in plain language, and easy to understand."

And to bring it back to my blog's topic, namely, privacy, I'd encourage you to take a look at how plainlanguage.gov has drafted its own site's privacy policy. It's here.

Many government regulations aren't really drafted for normal citizens. They're drafted by and for lawyers, lobbyists, specialists, and regulators. The same is often true of privacy policies. I'm in the school that thinks that privacy policies should be drafted for the general public, and that they should look something like plainlanguage.gov's privacy policy. Even the IRS, which is not an agency generally celebrated for its brevity of its prose, managed to publish a privacy policy that is exactly 7 sentences long.

Friday, March 9, 2012

Data Protection Officers, required by law in Europe




Europe has long led the world in creating privacy rules. Soon, Europe will likely make it a requirement for all companies with over 250 employees to appoint a Data Protection Officer (DPO). Here are a few practical thoughts about DPOs in the modern corporation.

1) We need to train up more DPOs. The universe of privacy professionals is still quite small, today. There simply aren't enough experienced DPOs to fill the imminent legal requirements. Soon, many thousands of companies operating in Europe will be looking to appoint DPOs to meet legal obligations, and since there is no available pool of such people, companies need to start thinking now about how to recruit, train and resource a DPO, and/or an entire DPO team, for the large companies.

2) Companies should decide if their data processing is simple or complicated, and staff their DPO accordingly. Depending on what kind of company you are, you could legitimately take three different approaches:

1) DPO role is added to existing function: Some companies may have data processing operations that are quite simple and unproblematic. For them, it may make perfect sense to ask someone in the Human Resources or Marketing departments to train up and play this role too.

2) DPO role is out-sourced. Some companies may decide to outsource the role to DPO-consultants who might provide similar services for many clients. Note to entrepreneurial privacy professionals: creating such shared-DPO-consultant services is likely to be a booming business opportunity in the future. Realistically, I think DPO-out-sourcing is only really an option for companies with simple data processing operations, but there are still legions of those.

3) DPO heavy-weights needed. Some companies have complicated and sensitive data processing operations. They will want their DPOs to be strategic data-stewards, guiding their companies to use and protect data in responsible ways, navigating through the thickets of regulatory rules, and representing them before regulatory bodies and courts. I think large and complicated companies should be expected to have senior and experienced DPOs, or in the cases of big companies, indeed, teams of them. But today, rather shockingly, some of the world's largest data processing companies, with mega-databases of trillions of pieces of personal data, do not have a single heavy-weight DPO on staff.


3) Companies need to give their DPOs adequate resources and authority. It's pretty obvious to me, as a long-time insider, that privacy will be well-served by a growing profession of DPOs in companies. To succeed, DPOs will need two things, which are essential to getting things done in large organizations: namely, resources and authority. It takes significant resources to monitor/advise/document the data processing operations of a large corporation (as will likely be required under the new EU laws) and it takes people with real authority to implement the goals of the role of the DPO, as the laws envision it. As for authority, I don't think authority always flows from corporate reporting lines (let's get over this simplistic thinking that every DPO should report to the CEO). I believe authority is derived from substantive knowledge of privacy law and business goals, judgment, persuasiveness, credibility, and perhaps most important of all, the backbone to defend the precious goal of privacy. The European legal proposals go even further in trying to protect the DPO's independence, by providing the DPO with some legal protections against unfair dismissal.

Europe, once again, leads the world in creating privacy rules. Europe proposes many daft rules (e.g., mandatory security breach notifications sent to consumers within 24 hours!, as is currently proposed, get real!). But, Europe sometimes leads the world in creating rules that meaningfully improve privacy protections. In the decade ahead, let's work together to strengthen and spread the role of the Data Protection Officer.

Wednesday, February 15, 2012

Hey, Mom and Dad, look, I'm the most powerful censor on the planet



Not really. But I could be.

Europe's proposals to create a "right to be forgotten" are suggesting that people should be able to request Google/Yahoo!/Bing to delete any third-party content from the search engines that they don't like, if it violates their sense of "privacy". If such a law were to be passed, then it would mean that employees at Google and similar companies would become censors-in-chief of the world's web content. Whenever someone finds something on the web that they found unflattering about themselves, they could demand that the search engines delete it. The Google/Yahoo!/Bing global censors would then be obligated to delete the content, regardless of whether it was true or fair or legal, regardless of who published it, and regardless of the fact that the search companies had nothing to do with the content.

Hmmm, the prospect of becoming the world's most powerful censor makes me giddy. Eat your hearts out, you Iranian web censors, now I've got the sort of power you've only dreamt of. History, truth, memory, knowledge, it's all mine, mine, to decide what gets to survive. And a word of "merci" to the French, who put all this power into the hands of American employees like me. Now I can make Mom and Dad proud.

Sunday, January 29, 2012

The right to be forgotten, or how to edit your history




The "Right to be Forgotten" is a very successful political slogan. Like all successful political slogans, it is like a Rorschach test. People can see in it what they want. The debate would sound quite different if the slogan were actually something more descriptive, for example, the "right to delete". The European Commission has now proposed to make the "right to be forgotten" into a law. It's a big step to turn a vague political slogan into a law. The time for vague slogans must now give way to a more practical discussion of how the "right to be forgotten" could actually work.

What is the "right to be forgotten"? There is a spectrum of views. On one end of the spectrum, the "right to be forgotten" is simply viewed as a re-branding of long-standing data protection principles, in particular: the rights to access and rectify one's own personal data, the right to oppose processing of one's personal data in the absence of legitimate purposes, the principle of data minimization. On this end of the spectrum, people think that the "right to be forgotten" is nothing new; at most, it is simply an attempt to apply long-standing data protection principles to the new worlds of the Internet and modern technologies. I'm firmly in this school of thought.

On the other end of the spectrum, the "right to be forgotten" is viewed more sweepingly as a new right to delete information about oneself, even if published by a third-party, even if the publication was legitimate and the content was true. This school of thought believes that people should have the right to force third-parties to delete content about them (photos, blogs, anything) that violates their sense of privacy, which in practice usually means their online reputations. Common examples of things people want to remove are compromising photos, references to past criminal matters, negative comments, etc. While I strongly believe that people should have the right to complain to third-party websites about information that is published there about them, I am deeply skeptical that the laws should obligate such third-parties to delete information on request of data subjects. This raises troubling questions of freedom of expression.

There is an even more extreme end of the "right to be forgotten" spectrum, which holds that this deletion right can be exercized not just against the publisher of the content (e.g., a newspaper website), but even against hosting platforms and other intermediaries like search engines that merely host or link to this third-party content. This view is being litigated in Spain, as the Spanish Data Protection Authority is suing Google to delete links to third-party content, like newspaper articles, that the DPA has acknowledged are legal. In other words, the DPA is attempting to apply this reading of the "right to be forgotten" to delete links to content in a search engine, despite the fact that the original content is legal and will remain on the Web. Cases like this will require judicial review, since they clearly posit a conflict of two fundamental rights: privacy and the "right to be forgotten" against freedom of expression. I expect this issue to be considered at the European Court of Justice.

As this debate unfolds, the lack of clarity is raising false expectations. As people read that there will soon be a legal "right to be forgotten", they are asking DPAs and search engines to delete third-party content about themselves or links to such content. I regularly hear requests from people to "remove all references to me, Mrs. X, from the Internet". No law can or should provide such a right, and politicians and DPAs should not mis-lead them to expect it.

We need more public debate about what the "right to be forgotten" should mean. We also need a debate about how it should be applied to hosting platforms and search engines. I think a balanced and reasonable and implementable approach is possible, based on a few principles: 1) people should have the rights to access, rectify, delete or move the data they publish online. 2) people should not have the automatic right to delete what other people publish about them, since privacy rights cannot be deemed to trump freedom of expression, recognizing that some mechanisms need to be streamlined to resolve these conflicts. 3) web intermediaries host or find content, but they don't create or review it, and intermediaries shouldn't be used as tools to censor the web. Stay tuned, and Happy Data Protection Day.

Monday, January 2, 2012

Harsher data protection sanctions are coming



When Apollo wanted to stop Laokoon from warning the Trojans that there were Greek soldiers in the famous Trojan Horse, he sent two giant snakes to kill Laokoon and his sons. Talk about sanctions! Have we considered using killer snakes to punish data protection violations and to discourage future bad practices?

Since 2012 has now begun, here's a prediction about the future: there's going to be a lot more privacy enforcement actions. By a lot of different government authorities, not just DPAs. And the sanctions/damages are going to go through the roof. Indeed, it's not easy to keep track of which government officials are in charge of data protection enforcement actions. There are a lot of them.

We all think of Data Protection Authorities, and similar bodies, like the Federal Trade Commission, as responsible for enforcing privacy laws. These bodies around the world have vastly different enforcement powers, investigative cultures, and sanctions traditions, even within Europe. Some, like the Spanish DPA, impose a lot of large fines. Others, like the French CNIL, imposed only 5 financial sanctions in an entire year. The largest fine the CNIL has issued in its entire history was 100,000 euros. And yet others, like the Belgian DPA, don't have the legal power to impose fines at all. Other DPAs hardly ever use sanctions at all, in the classic sense, other than press releases and "name and shame" tactics. Moreover, in recent years, the US Federal Trade Commission has been moving in a different direction, namely negotiating consent decrees that are forward-looking, 20-year commitments for particular companies to abide by certain privacy standards and be subject to regular audits.

But if the plethora of DPAs and their varied enforcement practices were not divergent enough, privacy enforcement is by no means limited to these specialist regulators. In the US, the individual State Attorneys General regularly bring privacy actions. There's also an entire industry of US privacy-based class actions which has sprung up in the last few years.

Moreover, in many countries, privacy laws have been inscribed into the penal codes. Consequently, any criminal prosecutor can bring such privacy penal actions. For example, my prosecution and conviction in Italy for a "privacy violation" was brought by a Milanese public prosecutor and imposed by a criminal judge.

In the future, the proliferation of the numbers of authorities who can bring privacy enforcement actions is likely to increase. First, more and more countries are creating data protection authorities, e.g., roughly a dozen new ones have been created across Latin America and Asia in the last year. And in Europe, where class actions generally don't exist and don't fit into the existing legal framework, there are now serious proposals to create mechanisms for "collective redress" of privacy claims. And of course, there have always been the normal judicial channels, where anyone can bring privacy claims against someone else if they feel their privacy has been violated. The numbers of such cases is also exploding around the world, especially as more and more data about people is collected, exchanged and published.

I regularly hear people claim that there's not enough legal enforcement of privacy. In some places, as a matter of practice, that may well be true. But there is no shortage of overlapping authorities with the power to bring or adjudicate privacy claims. Curiously, in privacy circles, most of the focus is on the enforcement actions of the DPAs. But in practice, the DPAs are just one of many different authorities who can and do bring privacy enforcement actions. And the trend is clearly going up, both in terms of the numbers of laws that can be violated, in terms of the severity of sanctions, in terms of the numbers of complaints that are brought, and in terms of the breadth of authorities who are involved in enforcing privacy.

The European Commission has proposed instituting new fines for data protection breaches ranging up to 5% of global turnover! To a global company, that's probably scarier than killer snakes.

Tuesday, December 20, 2011

Is that all that's left?




2011 has come and almost gone, and I've already forgotten most of it. It's always been that way. I can barely remember my own life. No one else will remember it either. Most of humanity has lived and died and left little more lasting traces of its existence than crickets in a summer field.

Despite our collective social fears of data deluge and "the age of big data", the reality is that we're probably the last generation in human history that will disappear with relatively little trace. As I troll the web today, I don't find much about myself: a few dozen YouTube video clips, a few hundred photos, my blog postings, a few thousand media quotes. Frankly, it really doesn't amount to all that much. It's barely a sliver of my life. In the future, digital archeologists will try to understand our generation, making sense of these digital fragments of our generation, the last lost generation.

The current privacy debates about particular technologies will seem oddly quaint in a few years. I remember a time only a few years ago when serious people thought a spam filter in email must be an invasion of privacy, since a machine was doing the filtering. Now we're debating whether users should click on a pop-up screen for cookies. A decade from now, we'll laugh, I think, about the current fears of digital over-exposure, based on today's trivia: posting a photo to the web, or tweeting, or blogging, or sharing location info with friends, or whatever. Of course, some things shouldn't be published or shared, because they are hurtful or embarrassing. But the scale of data and technology is changing so fundamentally that the importance of a particular piece of data today is almost unknowable.

I'm sure that more and more data will be shared and published, sometimes openly to the Web, and sometimes privately to a community of friends or family. But the trend is clear. Most of the sharing will be utterly boring: nope, I don't care what you had for breakfast today. But what is boring individually can be fascinating in crowd-sourcing terms, as big data analysis discovers ever more insights into human nature, health, and economics from mountains of seemingly banal data bits. We already know that some data sets hold vast information, but we've barely begun to know how to read them yet, like genomes. Data holds massive knowledge and value, even, perhaps especially, when we do not yet know how to read it. Maybe it's a mistake to try to minimize data generation and retention. Maybe the privacy community's shibboleth of data deletion is a crime against science, in ways that we don't even understand yet.

Assuming I live a normal lifespan, I will live to be able to up-load my life memories to remote storage. I'll be able to start real-time recording of my experience of life, and to store it, share it, and edit it. My perceptions, thoughts, and memory, will be enhanced by machines guided by artificial intelligence. Perhaps it's human vanity, but I want to have the choice to store and share my life, before or after its biological limits are extinguished. I am already losing clear memories of my youth, and of places I've been, and people I've loved. What I've lost is lost forever. There was no back-up disk. That's not my idea of privacy, but privation. I suspect a future privacy debate will discuss whether "memory deletion" is a fundamental human right, or deeply anti-social.

I have no idea what this future will look like, or whether humans and society can adapt to it as quickly as the technology will enable it. But as the year draws to a close, I am grateful for a front row seat, hoping to live long enough to see a world of technologies that will stop me from just disappearing from the planet, without anything more than a few random photos and video clips, as part of the last human generation whose evanescent lives left almost no traces, disappearing from the earth like crickets at the end of summer.

Wednesday, November 23, 2011

Data Protection Officers: on solid ground?


I've worked in the field of privacy long enough to remember a time when almost no companies in the world had privacy officers. Now, almost all big companies do. And soon, Europe's privacy laws are likely to be amended in a way to mandate them, or at least to provide strong incentives to appoint them, which will lead to massive growth in this profession.

But what is a data protection officer? Or can we even agree on what to call them? "Data Protection Officer" or "DPO" is a euro-centric title, since Europe long ago invented the concept of "data protection" as an alternative (not synonym) for "privacy". Personally, I have long used the title "Global Privacy Counsel", since I think it's useful to express three things that define my job, namely, the topic (privacy), the geographic scope (global) and the functional perspective (namely, counsel, or lawyer). But privacy leaders are often not lawyers, and hence, use different monikers, ranging from Chief Privacy Officer to Director of Privacy Engineering, or Director of Privacy Compliance, or Chief Privacy Evangelist, in each case stressing a different functional perspective.

For very large companies, privacy needs to be a cross-functional effort, representing security, engineering, legal, compliance, policy and communications. Personally, I focus on the legal/regulatory/policy sides of privacy. For very large information-based Internet companies, literally hundreds of people work on privacy, across these different functions. For smaller companies, in my opinion, there should be at least one person who is accountable for privacy, in some sense, even if it's not a full-time job.

As Europe is on the verge of mandating "data protection officers", we need to understand what exactly these people will be accountable for. First, it's important to note that the European proposal will probably be modeled on the existing functions in France ("correspondent") and Germany ("Datenschutzbeauftragte"). In these countries, the DPO is responsible for supervising their companies' creation and use of databases of personal data, liaising with government privacy regulators, and providing good privacy advice and guidance. In practice, DPOs in Germany and France are sometimes focused on the legal side, and sometimes on the technical/security side.

In the US, there is a different vision of privacy leaders. At most US companies, lawyers play this role, just as I came to privacy through the legal profession. And we play this role in our capacity as lawyers, namely, providing privacy legal advice to our companies. As privacy lawyers, we provide advice, but are not empowered to make final decisions about whether or not our companies will follow our advice. The companies' executives are the decision-makers, ultimately, not the privacy lawyers. There are of course other models at some US companies, but they're still in the minority.

So, as Europe institutionalizes the role of DPO, it will be important to define what exactly these people will be accountable for, seen from inside and outside their companies. For multinationals, it will take some time to work out how to support their privacy leaders under these different legal regimes as they straddle jurisdictions. And as DPOs are held accountable for certain areas, they too may need protection and indemnification from their companies for personal liability, just like other professions, such as chief financial officers who are mandated by various laws with specific areas of accountability.

I welcome laws in Europe that will help strengthen the role of DPOs in their companies, and will help make DPOs more prevalent across industry. This will be a practical step forward for privacy. But at the same time, it will be important to define what we're accountable for, internally and externally, especially in a field where the very notion of "privacy" is highly subjective, and where the visions of what a privacy leader is supposed to do diverge dramatically, by country, by industry, and by function.