Monday, 14 January 2013

Naked actors used in latest attempt to spark interest in data protection reforms

The European Commission has found a novel way of attracting attention to its current "Take control of your personal data" awareness campaign - by using naked actors.

If you don't believe me, take a look yourself!

Admittedly, the campaign does get your attention - although it's quite hard to work out why people become naked just because they've gone online. 

If the video raises a smile, then so does the Commission's factsheet on what the key changes for businesses will be, if their proposals are implemented.

Evidently, these changes include: "A level playing field for businesses through one single law applicable to any business across the EU. This harmonisation is expected to save businesses by up to Euro 2.3 billion per year." And: "Simplification of the regulatory environment by drastically cutting red tape and bureaucratic requirements which impose unnecessary costs on businesses."

I don't know which of these is the more fanciful -  the idea that people who surf the web frequently lose their clothes, or that the Commission's proposals will save businesses billions of Euros each year and drastically cut red tape.

If my life depended on it, I would plump for the "fact" that people who surf the web frequently lose their clothes.

(Then again, if I were responsible for either piece of propaganda,  I would seriously worry whether I was under an obligation to give an equivalent opportunity for the other side to put their point across.)


Warning:
The embedded video uses images of naked actors. Don't blame me if the link is blocked by your corporate profanity firewall. It was published by the European Commission, though - so you are free to argue, in mitigation and in connection with any internal disciplinary proceedings, that you were trying to access an official work of art, not porn.

Source:

http://youtu.be/5ByVaZ0rg8U


http://ec.europa.eu/justice/data-protection/document/review2012/factsheets/7_en.pdf

.

Why it is so hard to agree on changes to the current Directive



A very wise person has recently reminded me why it is so hard for European policymakers to agree on just what should replace the current Data Protection Directive.

The fundamental problem can be boiled down to differences in the way that policymakers in different European countries legislate.

Essentially, the argument goes, there are a number of different approaches:

There is the precautionary approach. This is where it is considered that actions should not be taken if the consequences are uncertain and potentially dangerous. 

Or, there is the risk-based approach. This is where the likelihood and the consequence of an incident are considered, as a way of rationalising the resources that are available, so that the areas more prone to fault are addressed first.

Also, there is the harm-based approach. This is where the likelihood of actual damage to an individual is taken into account, when prioritising an inspection or compliance regime.

There are plenty of other approaches too, but these are enough for the purposes of the argument I’m making today.

In some sectors, it’s pretty obvious which approach should be adopted. In aviation safety, for example, I would expect regulators to adopt the precautionary approach. Hundreds of lives, after all, are at risk, each time an airplane flies.

But what about in the field of data protection?

Can it really be said that hundreds of lives are at risk each time a new processing operation occurs? I say no. Or when a webmaster does not seek the user’s consent before cookies are placed on a user’s laptop? Or when a data controller makes a late notification of a data breach to victims? Or when an already complicated privacy policy fails to explain yet another disclosure of information to some obscure third party? Or when a cursory, rather than a comprehensive, privacy impact analysis is carried out?   

This is where the main fault lies.

While the current proposals for a new regime fall squarely within the principles set out in the precautionary approach, they are very much at odds with countries whose Governments have a different appetite for risk.  

And, as so little discussion seems to have taken place on the type of approach that is considered necessary to address the issue of data protection, I’m not surprised at the uproar that the detailed drafting proposals have raised. The “fundamental rights” brigade appears to argue that absolutely all of this stuff is so important that the European Parliament can only adopt the precautionary approach.

I don’t think that argument has been properly tested. Yes, in the eyes of some regulators, some global data controllers have behaved particularly badly in some respects – but does that mean that every European data controller needs to be tarred with the same degree of suspicion? I say no.

Where do we go from here?

In a sentence, it could be back to the drawing board. It would be more than helpful if everyone was absolutely clear as to what menace was being tamed.  The only bad boys I know of are a few extremely small players, who will certainly ignore whatever laws are implemented, and (in the eyes of some regulators) a few extremely large players, whose resources will dwarf those of whatever regulator is minded to challenge them.

There will always be stupid boys too (such as those that can’t get the basics right, like encrypting data in transit), but tougher laws are unlikely to effect behavioural change among the stupid.


Image credit:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCCkoWR1kFOx0EbyfTsqvnEEeKzRz1xxiLqaMOaK1ij-OwRivcN6DfPWyzfyHWFytkVcpcaonfx9jdja6CiaBXl58Et29zCa89mmtztUDrJY3WyUzv0-S4rAX1vzJ1zGNBbgp0DEwLBpA/s400/6a00d8341bf89d53ef00e54f4503ce8834-640wi.jpg

.

Saturday, 12 January 2013

Drowning in data protection events



Privacy officers face another year of being deluged with literally hundreds of opportunities to attend data protection awareness sessions to ensure that everyone understands what the rules are, and how these can best be implemented.
They can expect a tsunami of events related to the recent reactions to the latest proposals that have been published to change the current Data Protection Directive. The latest reactions, either from European Parliamentarians, national Governments, or from the usual suspects, will spew out into cyberspace like water from a fire hydrant.
If you can’t cope with all the invites, don’t worry. Join the club.
Last February, I started to note privacy events that might be of interest to (the average) British privacy officer.  By the end of the year, my list had grown to some 140 events. On any given Tuesday, Wednesday or Thursday, somewhere near London a privacy event was taking place. Earlier in my career, when working for a Congressman on Capitol Hill in Washington DC, I would hardly ever need to eat at home, such was the abundance of canapés at the political events I attended every evening. Well, those gluttonous days are back again. Thanks to the most gracious generosity of so many legal firms, holding seminars and workshops for those who know how to get an invite, my home cooking days are long gone.
I expect to see lots of friends towards the end of the month, when the conference circus briefly moves to Brussels. Three whole days of earnest debate. Detailed philosophical speeches on the meaning and the future of privacy – before most people return to work with a bump and remember how hard it currently is to actually get even the basics right.
All this utopian academic speculation really is wonderful, but it is worlds away from life as I live it, which involves inspiring real people to realise that it’s in their own interests to effect minor behavioural changes to make things more transparent.
I do feel slightly sorry, though, for those who are constantly on the conference circuit. They appear to glide from one venue to the next, woven into a bubble with their contemporaries, with their feet mostly just above the ground, rather than on it. Pontificating on grand principles and statements are fine, but what works in theory has to work in practice. If it doesn’t work in practice, it’s worthless.
After that, the next global bash will be Data Protection Day (also known as Groundhog Day”) on 28 January, where privacy professionals from all over the world will gather in their local groups to celebrate the wonderful careers that can be carved out in this field. Sometimes, it appears that cities just don’t have venues that are large enough to hold all the privacy professionals that want to attend. In Washington DC, for example, two IAPP parties will be held to commemorate Data Protection Day. No, the venues aren’t miles apart from each other, either. Privacy folk can either choose the Asia Nine Bar at 915 E Street, or they can go to Penn Social, situated on the next block at 801 E Street.
In case party goers get confused as to which venue to attend, a special instruction announces that the Penn Social event: is for Young Professionals in the Washington, DC, area.”
How about that! So when will we all next get invited to a presentation on “Privacy and Ageism?”
Joking apart, I would like to attend an event on privacy and ageism. There is a generational divide in attitudes to privacy, and I would like to hope that any new privacy rules focus on the needs of emerging generations. Not just the concerns of the generation representing the crusties who are currently at the pinnacle of their own regulatory careers.

 Source:
 http://www.martinhoskins.com/privacy-events/archive-of-previous-events

Image Credit:

.

Friday, 11 January 2013

Ministry of Justice declares war on the Regulation



Before everyone gets too focused on the LIBE Committee’s recent 215 page report, there is some good news to end the week on. An equally hard hitting report has just been published, which may well have far more of an impact on the future direction of European data protection legislation.

This is the Government’s latest position on the proposals – which is contained in the snappily titled “Government response to Justice Select Committee’s opinion on the European Union Data Protection framework.”

Mercifully, this document is only 19 pages long.

It's full of passages like this:

 “In terms of the level of protection provided by the [policing] Directive, as opposed to the draft Regulation, there is no contradiction between providing a more flexible instrument and the delivery of fundamental rights.”

And:

“The Government’s position that the proposed Regulation should be re-cast as a Directive would allow for harmonisation in the areas where it is advantageous and flexibility for Member States where it is required. The European Commission’s Impact Assessment acknowledges that harmonisation could be achieved through the use of a Directive.

For example there could be harmonisation of: the fundamental principles found within the proposals; the rights that data subjects enjoy; and the rules relating to independent supervisory authorities and the European Data Protection Board. The Government also supports the principle of the consistency mechanism. We believe that the data protection framework should protect the civil liberties of individuals. This means putting rules in place that ensure that the processing of personal data is fair, secure, and that data should be retained for no longer than is necessary. 

EU data protection legislation must secure individuals’ privacy without placing constraints on businesses practices that harm innovation and growth. For example, the proposed Regulation places prescriptive obligations upon data controllers as to how they will comply with the proposed Regulation, such as completing data protection impact assessments and hiring data protection officers. This is a ‘one size fits all’ approach which does not allow data controllers (from small online retailers to multinational Internet companies) to adopt their own practices in order to ensure compliance with the legislation. The European Commission’s proposal should focus on regulating outcomes, not processes.”

And it just goes on and on:

"The Government wants to see EU data protection legislation which protects the civil liberties of the individual whilst allowing for proper public protection and economic growth and innovation. These should be achieved in tandem, not at the expense of one or the other."

Also, in terms of its impact on the ICO:

“The Government agrees with the ICO’s assertion that the system set out in the draft Regulation ‘cannot work’ and is ‘a regime which no-one will pay for’.”

This really is the sort of pragmatic, common-sense stuff that we Brits love so much.

As Shakespeare might well have cried:

“Three cheers for the Ministry of Justice, England, and St George!”


Source:
http://www.justice.gov.uk/downloads/publications/policy/moj/response-eu-data-protection-framework-proposals.pdf

.