
Wednesday, November 14, 2012
Book Burning, updated for the Digital Age

Monday, November 5, 2012
The Marketplace of Privacy Compliance Programs
- Accountability
- Privacy by Design
- Privacy Impact Assessments
- Consent Decrees
- Audits (internal and external)
- Regulatory reviews
- Data Processing Documentation
- Database notifications/registrations
- Binding Corporate Rules
- Safe Harbor Compliance programs
Friday, November 2, 2012
Greece: protecting freedom of expression
You may have read about the widely-reported case of the Greek journalist who published the list of 2000 Greeks with Swiss bank accounts. The journalist was put on trial for criminal breach of data protection rules. Thankfully, the courts recognized that this journalist published the names in the public interest. Indeed, the case confirmed the world's strong suspicions that the Greek political and financial elites were protecting themselves from investigations into tax evasion. Rather than investigate why the Greek tax authorities failed to investigate this list of 2000 names, after having been given the list two years ago by the IMF, the authorities put the journalist on trial. This was a transparent attempt to use the criminal justice system, and "data protection", as a way to chill this (and other) journalists' attempts to expose tax evasion and political connivance.
Thankfully, the Greek court dismissed the charges of data protection crimes against the journalist.
As a privacy lawyer, I note a few things. Data protection laws in Europe explicitly foresee an exemption from normal privacy laws, for journalistic purposes, such as "necessary to reconcile the right to privacy with the rules governing freedom of expression" and for "substantial public interest". Articles 9 and 8 of the Directive. Surely, this Greek example meets both tests, and the court was quick to reach that result.
Nonetheless, I'm very worried about the increasingly criminalization of privacy laws, especially across Southern Europe. Once privacy laws are inscribed into penal codes, they open the door to prosecutors and criminal judges pursuing such cases with the blunt machinery of criminal justice, backed up with threats of jail. Many such cases, like this Greek example, are nuanced cases balancing fundamental human rights, like privacy and freedom of expression. Nothing is more dangerous to freedom of expression than using vague notions of "privacy" to threaten journalists, or newspapers, or Internet platforms, or employees of Internet platforms, with jail time, when they are exercizing their rights to freedom of expression or operating a platform for others to do so. There are now hundreds of such cases around the world.
Luckily, the Greek justice system was quick, and resolved this case in days. But many criminal justice systems are notoriously slow. As reported in The Economist, to take the example of Italy: "Italian justice has a reputation for moving very slowly." My own Italian privacy criminal trial has been dragging on for years, and is expected to begin the appeals phase soon, on December 4, almost 5 years after I was first "detained" by Italian police in Milan. 5 years is a long time to put someone through criminal justice hell, in a landmark case trying to make me vicariously liable for user-generated content uploaded to an Internet video platform.
Congratulations, Costas Vaxevanis, I respect your courage. Powerful forces try to use criminal privacy statutes to restrict freedom of expression. Thank you for standing up to them.
Monday, October 29, 2012
Singapore passes a modern privacy law. Cheers!
- First, European laws declare transfers to be ok to other European countries and to countries deemed to have "adequate" privacy laws, but the list of "adequate" countries is a list of countries which make strange bedfellows, including mostly tax havens (yes, Monaco and Guernsey) and a few (I mean, literally, a few) others, ranging from Argentina and Uruguay to Israel and Canada.
- Second, there are a few hypothetical legal mechanisms to enable data to be transferred from Europe to other countries around the world. Data can flow to the US if the company transferring it signs up the US-EU Safe Harbor Framework. Data can also flow around the world if the company transferring it signs up to so-called Binding Corporate Rules, and if these Binding Corporate Rules are approved by Data Protection Authorities. The pure simple fact is that only a tiny handful of Binding Corporate Rules have ever actually made it through the bureaucratic approvals process. E.g., to my knowledge, not a single Internet company has ever had Binding Corporate Rules approved. So, practically, the option of obtaining Binding Corporate Rules is theoretical.
- Third, people can consent to having their data transferred internationally, although there's no consensus on what "consent" means or requires in practice, and no one even knows what a "transfer" is.
Friday, October 26, 2012
Privacy-litigation: get ready for an avalanche in Europe
Thursday, October 25, 2012
Microsoft's brilliant master class on how to change a privacy policy
Tuesday, October 23, 2012
Privacy Professionals peregrinate to Punta
Monday, October 8, 2012
Groupthink
There's an entire, vibrant privacy conference business. There are privacy conferences somewhere in the world every week of the year. Some are commercial, some are taxpayer-funded. Why are they so boring?
Because they take one of the most interesting topics in the world, privacy, and discuss and debate it from an insular perspective, namely, from the perspective of people who are in the privacy "industry." I'm very clearly part of this "industry" too.
The privacy "industry", or "privacy industrial complex", as some wags have dubbed it, consists of privacy professionals at companies, privacy advocates, privacy regulators, privacy consultants, etc. So, conferences tend to be incredibly banal statements about who's more committed to privacy, and begin with stentorian declarations, like "privacy is a fundamental human right, therefore...". Or they consist of a "debate" between two privacy advocates, which is like listening to two members of the National Rifle Association debate the social benefits of gun control. Or they consist of paid-corporate advocates trashing their competitors' privacy record, often without disclosing who is paying them to do so.
The interesting privacy debates, in my opinion, are the debates where privacy is balanced against other fundamental human rights, like freedom of speech, or balanced against other social goals, like encouraging innovation, or tested against other yardsticks, like regulatory cost-benefit analysis. But very little of that occurs at privacy conferences, because virtually no one from outside the privacy "industry" speaks at such events. E.g., rather than hearing privacy-people talk endlessly about the need for more privacy regulation, I'd like to hear from an economist evaluating whether such regulations are effective, or whether their costs exceed their benefits. Rather than hearing privacy-people talk about the need to create a "right to be forgotten", I'd rather hear from a free speech advocate on how such a right would undermine freedom of expression. Rather than hear privacy-people talk about how technology needs to be reined in, and subject to bureaucratic prior approval (in other words, slowed-down), I'd rather hear from people who are committed to building modern and dynamic economies about how (archaic) privacy laws are hampering the creation of innovation-based economies.
But privacy conferences have largely become like any other conclaves of groupthink. At a Vatican conclave, you don't get a serious discussion about the health benefits of promoting the use of condoms. At a Tea Party rally, you don't get a serious discussion about whether government welfare benefits are a guarantor of minimal human decency.
I have pretty much stopped going to most privacy conferences, at least for now. When I go, it's mostly to have a chance to have one-on-one chats with people I'd like to meet or catch-up with. I think privacy is the most interesting topic in the world. But groupthink gatherings don't move the debate forward. If I was at an NRA meeting, I'd advocate for gun control to help reduce the shockingly high murder rates in the US, and I'd probably be run out of the room. There are so many smart people in the privacy profession, why aren't we challenging each other more, to take a small, wild step outside the privacy-industrial-complex, and actually engage more with the real world?
Thursday, September 20, 2012
The algorithm decided not to hire you: is that legal?
Wednesday, August 22, 2012
August in Paris: has everyone left?
Thursday, August 16, 2012
It's time for a "lead regulator" in Europe
Who's in charge in Europe? That's a common conundrum for those of us who work in the privacy field in Europe. When I was at a Berlin privacy conference, dopey picture attached, everyone was talking about it.
Wednesday, August 15, 2012
Rainbows in Ravello: Technocracy or Democracy?
Wednesday, August 8, 2012
A travel blog post, about data centers
- the rule of law?
- censorship?
- fair legal process to validate/challenge government and law enforcement requests for user data?
- holding intermediaries liable for third-party content in the cloud?
Tuesday, August 7, 2012
Mud-slinging, Anonymously
Friday, May 25, 2012
A torrent of bureaucracy
While policymakers around the world are frantically nurturing their digital economies, what's happening here in Europe? Lots, lots more red tape is coming. Politicians are furiously running around giving media interviews about how this will rein in Facebook or Google, as though all of Europe's privacy laws should be written for one or two companies. Indeed, wags have started to call Europe's new proposed privacy laws "Lex Google" or "Lex Facebook". But trying to write a privacy law to "rein in" Google or Facebook is a sure recipe for writing a bad privacy law that would apply to all companies in Europe.
Very few people have actually looked at how Europe is planning to change fundamental privacy laws. While politicians are posturing that this is a reduction of red tape, the reality is that it is on track to become the biggest increase in paperwork and compliance process obligations in the history of privacy law anywhere on the planet. Moreover, here's an assessment that would surprise some people: I think Facebook and similar big companies could cope just fine with the new proposals, one way or another. But there is absolutely no way Small and Medium-size Enterprises in Europe could cope. SME's are already an embattled group in Europe, facing the highest regulatory and employment tax burdens in the world. Data protection officers at large corporations generally have lots of resources, and they can manage bureaucracy and paperwork, even if it costs a few more million euros. For big companies, it's not a big deal if the data protection "compliance tax" increases by a few million "new pesetas" or "new lira". Frankly, I wonder how an SME could possibly deal with this paperwork and process torrent, and how they're supposed to pay for it.
Consider the details of this regulatory torrent, and ask yourself how new legal obligations like those below would impact an SME:
- 1) Breathtaking fines for routine paperwork data protection lapses. Large fines are proposed for data protection violations, some of which are really nothing more than paperwork lapses or documentation foot-faults. Does anyone really think European SME's are set up to be able to report a data breach in less than 24 hours? It baffles me how policymakers can propose to impose fines of 1 or 2% of a company's global turnover for not "adequately" filling out paperwork, such as "privacy impact assessments" or "documentation of data processing", especially since there is not even any agreement on what such paperwork is even supposed to look like.
- 2) Mandatory Data Protection Officers. What happens if we obligate all enterprises with over 250 employees to appoint a Data Protection Officer? Practically, where are all these people going to come from, since only a handful exist today? Can SMEs afford the cost of these new employees, or of outsourcing this function to expensive law firms? Or over-burden others on their staff, e.g., a Human Resources person, to try to play this role too? and needless to say, some companies with 250 employees (like Internet or health companies) have vastly different privacy impacts than others (like construction companies), so laws with arbitrary fixed rules are rarely well-adapted to the different realities of the real world.
- 3) Mandatory privacy impact assessments. What will SMEs have to do, if they are obligated to carry out privacy impact assessments on all new projects? While I think such privacy impact assessments can be a useful privacy compliance tool for some projects, I also know that they are burdensome and time-consuming. Can SMEs handle this additional burden? While "privacy impact assessments" are still undefined, I estimate doing one would cost, roughly 10,000 to 100,000 euros. I imagine most SMEs would have several, and larger companies would have many projects requiring such privacy impact assessments.
- 4) Mandatory data processing documentation. Documenting such data handling processes is time-consuming and difficult. How much will it cost SMEs to document their data processing practices? I would roughly assume that the burden to comply with this requirement would be comparable to the time/money spent complying with tax laws. No one knows what it means to "adequately" document data processing, but nonetheless, these confused proposed privacy laws would threaten massive fines for failing to comply with an undefined standard.
Europe is about to threaten companies with fines so large that they will throw them into bankruptcy for bureaucracy and paperwork foot-faults? As countries around the world begin the competitive race to build their digital economies, we in Europe are starting the race by shooting ourselves in the foot? It's possible to be deeply committed to privacy, without drowning in a torrent of privacy bureaucracy.
Monday, March 19, 2012
The Safe Harbor

Periodically, and again today, there’s a conference to discuss trans-Atlantic privacy issues, and take stock of the Safe Harbor framework. As an American who works in this field in Paris, I have long cared more than most people about trans-Atlantic privacy issues.
Why is the Safe Harbor framework still relevant? Here’s a reminder: the Safe Harbor framework was created because of a quirk in European law dating from 1995 that divided the countries of the world into so-called "adequate" and not-"adequate", in terms of having European style data protection. Countries like the US and Japan are not currently deemed to have "adequate" protections under EU law, but other countries like Argentina and Mexico and Israel are. It's a fair question whether the criteria to assess "adequacy" are themselves realistic or out-dated. Essentially, the criteria area formalistic: e.g., does a country have a European-style “independent data protection authority” and European-style “comprehensive” privacy legislation? So, countries that do not, like Japan and the US, are not deemed to have “adequate” data protection, but countries like Mexico, Argentina or Israel are. The Safe Harbor framework constitutes an “adequacy” regime for the US-based companies that comply with it. Therefore, the Safe Harbor framework is a partial solution to a bigger “adequacy” problem.
Rather than debating the Safe Harbor framework, we should be debating the “adequacy” regime. In the real world, no one would believe for a minute that data is less protected in Japan or the US than in Mexico, Argentina or Israel. But this bureaucratic fiction has very real-world consequences, if it makes “illegal” the transfer of personal data from Europe to these non-”adequate” countries. Surely, such routine global data transfers from Europe to Japan, to take just one examples amongst many in the cloud, can’t all be “illegal”?
Why does Europe fight so hard to maintain these rather reality-divorced rules, and why is Europe choosing not to modernize them as part of its comprehensive data protection law review? There is a simple reason, and it has very little to do with the reality of privacy protections. The so-called “adequacy” test is a powerful tool used by European policymakers to cajole other countries into adopting European style data protection laws and regulations. In 2011 alone, 6 countries in Latin America adopted European-style data protection laws. The motivation for these countries is often unabashedly trade-based, namely, the unhindered transfer of personal data from Europe to these countries, which hope to build information-based out-sourcing industries. Europe holds out a significant carrot to countries, saying essentially, “if you copy my privacy legal structure, we’ll reward you with information-based trade.” This, in a nutshell, is why Europe is winning the global competition to influence privacy laws in countries around the world.
I have long been an advocate of the vision of global privacy standards. Instead, what the world is getting is the globalization of European privacy standards.
Tuesday, March 13, 2012
"I didn't have time to write a short letter, so I wrote a long one instead". Mark Twain
I recently spent a few days grappling with government regulations written for the public. Together with my Dad, who is in his 80's, we tried to get some answers to simple Medicare questions about prescription drugs. I almost gave up when I realized that I still had no clue, after spending hours trying to read the government's guidance. I'm a Harvard-trained lawyer, and I couldn't understand them. I looked at my Dad, and I wondered what seniors are supposed to do who are often old and sick, and might not have a Harvard-lawyer around the house to help them.
Thankfully, there's a very worthwhile initiative, to get the US Federal government to use Plain English. Indeed, I think it's worthwhile to simply quote from the government's site directly:
President Obama signed the Plain Writing Act of 2010
on October 13, 2010. The law requires that federal agencies use "clear Government communication that the public can understand and use." On January 18, 2011, he issued a new Executive Order, "E.O. 13563 - Improving Regulation and Regulatory Review.
" It states that "[our regulatory system] must ensure that regulations are accessible, consistent, written in plain language, and easy to understand."
And to bring it back to my blog's topic, namely, privacy, I'd encourage you to take a look at how plainlanguage.gov has drafted its own site's privacy policy. It's here.
Many government regulations aren't really drafted for normal citizens. They're drafted by and for lawyers, lobbyists, specialists, and regulators. The same is often true of privacy policies. I'm in the school that thinks that privacy policies should be drafted for the general public, and that they should look something like plainlanguage.gov's privacy policy. Even the IRS, which is not an agency generally celebrated for its brevity of its prose, managed to publish a privacy policy that is exactly 7 sentences long.
Friday, March 9, 2012
Data Protection Officers, required by law in Europe
Europe has long led the world in creating privacy rules. Soon, Europe will likely make it a requirement for all companies with over 250 employees to appoint a Data Protection Officer (DPO). Here are a few practical thoughts about DPOs in the modern corporation.
1) We need to train up more DPOs. The universe of privacy professionals is still quite small, today. There simply aren't enough experienced DPOs to fill the imminent legal requirements. Soon, many thousands of companies operating in Europe will be looking to appoint DPOs to meet legal obligations, and since there is no available pool of such people, companies need to start thinking now about how to recruit, train and resource a DPO, and/or an entire DPO team, for the large companies.
2) Companies should decide if their data processing is simple or complicated, and staff their DPO accordingly. Depending on what kind of company you are, you could legitimately take three different approaches:
1) DPO role is added to existing function: Some companies may have data processing operations that are quite simple and unproblematic. For them, it may make perfect sense to ask someone in the Human Resources or Marketing departments to train up and play this role too.
2) DPO role is out-sourced. Some companies may decide to outsource the role to DPO-consultants who might provide similar services for many clients. Note to entrepreneurial privacy professionals: creating such shared-DPO-consultant services is likely to be a booming business opportunity in the future. Realistically, I think DPO-out-sourcing is only really an option for companies with simple data processing operations, but there are still legions of those.
3) DPO heavy-weights needed. Some companies have complicated and sensitive data processing operations. They will want their DPOs to be strategic data-stewards, guiding their companies to use and protect data in responsible ways, navigating through the thickets of regulatory rules, and representing them before regulatory bodies and courts. I think large and complicated companies should be expected to have senior and experienced DPOs, or in the cases of big companies, indeed, teams of them. But today, rather shockingly, some of the world's largest data processing companies, with mega-databases of trillions of pieces of personal data, do not have a single heavy-weight DPO on staff.
3) Companies need to give their DPOs adequate resources and authority. It's pretty obvious to me, as a long-time insider, that privacy will be well-served by a growing profession of DPOs in companies. To succeed, DPOs will need two things, which are essential to getting things done in large organizations: namely, resources and authority. It takes significant resources to monitor/advise/document the data processing operations of a large corporation (as will likely be required under the new EU laws) and it takes people with real authority to implement the goals of the role of the DPO, as the laws envision it. As for authority, I don't think authority always flows from corporate reporting lines (let's get over this simplistic thinking that every DPO should report to the CEO). I believe authority is derived from substantive knowledge of privacy law and business goals, judgment, persuasiveness, credibility, and perhaps most important of all, the backbone to defend the precious goal of privacy. The European legal proposals go even further in trying to protect the DPO's independence, by providing the DPO with some legal protections against unfair dismissal.
Europe, once again, leads the world in creating privacy rules. Europe proposes many daft rules (e.g., mandatory security breach notifications sent to consumers within 24 hours!, as is currently proposed, get real!). But, Europe sometimes leads the world in creating rules that meaningfully improve privacy protections. In the decade ahead, let's work together to strengthen and spread the role of the Data Protection Officer.






