Showing posts with label EU directive. Show all posts
Showing posts with label EU directive. Show all posts

Sunday, May 2, 2010

Limiting Information Sharing Based on Context

In this article, Computer World describes an argument made by Microsoft research Danah Boyd that social networks should consider the context in which information is provided, and not re-use the information outside of that context. The argument, to the extent it can be distilled down to one paragraph is as follows:

"You're out joking around with friends and all of a sudden you're being used to advertise something that had nothing to do with what you were joking about with your friends," Boyd said. People don't hold conversations on Facebook for marketing purposes, she said, so it would be incorrect for marketing efforts to capitalize on these conversations.

In the article, this concept was described as "relatively new." I'm not sure that that's correct. After all article 6 of the EU Data Privacy Directive provides that

1. Member States shall provide that personal data must be:
(a) processed fairly and lawfully;
(b) collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Further processing of data for historical, statistical or scientific purposes shall not be considered as incompatible provided that Member States provide appropriate safeguards;
(c) adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed;
(d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that data which are inaccurate or incomplete, having regard to the purposes for which they were collected or for which they are further processed, are erased or rectified;
(e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the data were collected or for which they are further processed. Member States shall lay down appropriate safeguards for personal data stored for longer periods for historical, statistical or scientific use.

which appears to be analogous to the concept of recognizing the context in which data is provided when deciding how that data should be used.

Of course, the question of whether an idea is a new one is entirely different from the question of whether the idea is a good one. However, recognizing the similarity between the proposed context limitations on social networks and the EU's data privacy directive can certainly be beneficial in evaluating the merits of the new idea. Specifically, the criticisms of the EU directive (e.g., here) can be examined to see if they also apply to the specific context based limitations, and if context based limitations can somehow be implemented in a way that addresses those criticisms.

Thursday, March 27, 2008

DATA PRIVACY PROTECTION LAWS POSE CHALLENGES

Compliance by U.S. multinational companies with the data protection and e-discovery laws, rules and regulations in both the U.S. as well as other international jurisdictions can pose significant challenges. While the laws do not impose conflicting requirements, the differences in the approach to data privacy protection between U.S. laws and those of the EU and its member states and the complexities of their requirements demand a comprehensive team approach to compliance.
The U.S. federal and state laws take a patchwork approach to personal data protection, with a myriad of data privacy requirements based upon industry. There is, however, no a comprehensive data privacy protection law. Nor are there special requirements for the transfer of personal data, cross-border or otherwise, as long as the “sharing” has been disclosed to the consumer, or is within the exceptions provided for by applicable law.
More than 35 states have enacted data breach notification and security freeze laws, with many variations on the method and timing of notification among them. To date, the U.S. Congress has not been able to agree upon a uniform approach for data breach notification and security freeze rights. Amendments to the Federal Rules of Civil Procedure that became effective in December, 2006 have underscored the importance of electronic discovery, so that corporate counsel must be concerned with the risks and potential sanctions that could result from non-compliance with a discovery order.
Companies that collect and process their own employee or customer data in the U.S. when that data resides in a European Union member country are presented with even greater challenges. The EU Data Protection Directive, as well as the data protection laws of the country of the data subjects’ residence, impose broader data privacy requirements on companies. In addition to the U.S. laws, such companies must be cognizant of the laws of the jurisdiction where the data to be processed resides. The aim of the Directive is to ensure that each member state imposes a similar level of protection of data, so that data can be transferred freely within the EU subject to the same security standards in the country of receipt as it is in the country of transfer.
The EU member states that were formerly under the control of fascist regimes during World War II are particularly keen on avoiding the abuses of individual privacy rights that occurred during that period. Thus, the Data Protection Authorities of France, Spain, Germany and Italy are very active in their enforcement efforts, conducting costly investigations, and levying monetary sanctions and fines against violators of their laws. On April 12, 2007, the French DPA, CNIL, announced the imposition of a fine of €30,000 against Tyco Healthcare France Corporation for non-cooperation and for providing CNIL with erroneous information. To date, the CNIL has imposed 16 monetary sanctions, ranging from €300 to €60,000, issued 170 summons, 11 orders or cease or amend processing practices, and 15 warnings. This equals a 200% increase in activity since 2006. In July, 2007, Spain’s Supreme Court confirmed its DPA’s largest ever fine in the amount of €1,081,822 against Zeppelin Television, S.A. Additionally, for the first time Spain’s DPA has conducted a data privacy audit outside of Spain, in Colombia, where Spanish citizens’ personal data is being processed. In addition, the EU’s Data Privacy Commission has been active in enforcing the requirements of the Privacy Directive on its member countries.
Earlier this year, an independent EU panel launched an investigation into whether U.S.-based Google Inc.'s Internet search engine abides by European Union privacy rules. The panel convinced Google to clear its user data of information that could be used to identify the user once the data has existed for 18 months. Google accurately noted, however, that governments and businesses are obliged to retain information, and it is difficult to operate a global Internet service according to different privacy standards in different countries.
The same observation can be made as to many other types of businesses as well. The complexities and risks associated with privacy laws have never been greater, and require vigilant monitoring by counsel and data security officers. One of the EU Directive principles requires that personal data be transferred cross-border only if the country of receipt provides “adequate protection.” Various options are available to companies to address the requirements of the EU Privacy Directive. Model contractual clauses have been approved by the EU, for inclusion in contracts between companies and their service providers. For companies with employees or customers in multiple European jurisdictions, adoption of Binding Corporate Rules that address all of the EU Directive requirements has also been deemed acceptable by the EU, provided that the BCR have been approved by the EU Data Privacy Commission and the applicable country’s DPA. The EU DPAs are also working on uniform BCRs, so that it would be unnecessary to obtain approval from each EU member state. Finally, certification within the U.S.-EU. Safe Harbor Framework provides protection against challenges of non-compliance with the EU Directive. More information on Safe Harbor certification, including a list of the more than 1300 U.S. companies who have joined the Safe Harbor Framework, can be found at http://www.export.gov/safeharbor/. Adopting one of the suggested methods to meet the “adequate protection” principle will permit multinational companies with European operations to truly operate without borders with respect to the personal data of their employees and customers.