I do hope that Commissioner Reding will be taking notice of the chaos and confusion that is capable of being created when ill-thought through Euro-legislation makes its way through the Parliamentary processes and finally arrives on the Statute Book.
What’s the story behind this one? Well, it’s all about discussions that went on behind the scenes a decade ago as representatives from each EC Member State argued about what rules should be put in place to permit phone and internet records to be available for law enforcement investigations into serious crime, but in a way that protected the human rights of the phone and internet users.
The issue could be reduced, following long tedious arguments, to one of ensuring that the most serious law enforcement investigations should not be compromised because the communications records were no longer available. While that seemed a fine principle to agree about in theory, the principle couldn’t be implemented very easily. Why? Simply because the law enforcement agencies operating in the different Member States had different practices when it came to investigating crime using traffic records. In some Member States, the common practice was to rely on 6 months of records. In other Member States, the practice was to use up to 4 years of records. So given the disparity on investigation practices, lots of people got upset when the new rules prohibited the retention of records for more than 2 years, and ever since they’ve been devising new legal challenges to postpone the enforcement of these rules.
If my memory serves me right, the Irish were unhappy because they wanted records to be retained for 3 years, while the Italians wanted a 4 year limit. On the other hand, the Germans didn’t care so long as it could get hold of 6 months of records. Other Member States didn’t really seem to care as, at that time, the law enforcement agencies in that country didn’t seem to rely on phone or internet records at all.
And, if my memory serves me right, there was general acceptance that the words used in the draft legislation about the retention of internet records didn’t make any sense – but the point was that the statute had to be approved at that time because the Chairman of the relevant Committee of the Council of Ministers was completing his term of office and if the legislation wasn’t accepted, then the discussions would have to start again from the beginning of the tenure of the next Chairman. I won’t embarrass the Chairman of that Committee by naming him, nor will I point out which Member State had the honour of chairing the discussions and forcing the key decisions. (Well, not until someone asks me nicely.)
Does this approach to drafting legislation sound familiar?
The upshot of this unholy mess has been another appeal to the European Court on the basis that some people don’t like what’s going on, and they consider that their human rights have been abused.
And why am I writing about this now?
Because the more I read the European Commission’s proposals for a General Data Protection Regulation, the more convinced I am that the target that the Commission set itself was one focussed on the calendar, rather than common sense. I’m convinced that the Commission was so keen to launch “something” on 25 January that the “thing” was, to a large extent, immaterial.
Perhaps that was what was meant by Commisisoner Reding’s introductory remarks last week: “Ladies and Gentlemen, we have done it”.
We will now send the following months and years working out in detail what really is appropriate to meet the changing needs of our times.
I only trust we have time to undo the stupid bits and get it right before some other parliamentary timetable forces the pace, and we are left with a text that so many of us know is still not fit for purpose.
Source:
http://www.thejournal.ie/ecj-asked-to-rule-on-mandatory-retention-of-phone-and-internet-data-339434-Jan2012/
.
Tuesday, 31 January 2012
Monday, 30 January 2012
Getting into a lather over LinkedIn?
We data protection folk can be so busy worrying about other people’s privacy that we totally forget to think about our own.
Who, for example (in their right minds) actually reads the “we have changed our privacy policy” blurb which is spewed out each time a data controller changes their practices? And how do we know if we’ve missed anything serious?
This is where the blogosphere, with its notorious internal networks of friends and colleagues, can really shine. What concerns one person can very quickly concern lots of other people.
Today, for example, I was sent an email from the ever vigilant (and oh so brilliant) Pascale Gelly, pointing out that “Without attracting too much publicity, LinkedIn has updated their privacy conditions. Without any action from your side, LinkedIn is now permitted to use your name and picture in any of their advertisements.”
Whoops, I missed that one. On the other hand, if my name and picture sells sufficient quantities of dog food, or whatever else I am supposed to be endorsing, is this really such an invasion of my privacy? I do try to take care when I am on line, and I do what I can to obscure my digital vapour trails whenever my cursor accidentally clicks on a site that some folk might find alarming (or amusing).
But then again, I thought to myself, I can’t make myself aware of everything that happens around and about me. My life is too full already. I can’t take any more in. My mind already hurts (and plays tricks on me). The last thing I really want to do is spend more time in front of a screen, reading about data protection stuff. I do this for a living. Surely, I don’t have to do it as a private citizen too, do I? I shrug my shoulders with mock despair. After all, if we can’t be bothered to do it ourselves, and we actually know about the consequences of remaining digitally vigilant, then the great unwashed has no chance at all of keeping up to speed with things that data controllers think matters.
Accordingly, based on my own personal experience, I really don’t think that the European Commission’s cunning plan of encouraging European citizens to consent to more stuff is going to work. They can’t consent to what they can’t understand or can’t be bothered to read, or simply don’t have the time to read. It’s a brilliant example of a policy initiative that looks great in theory and turns out to be unworkable in practice.
So perhaps we need not blame LinkedIn.
Perhaps I can offer LinkedIn a special deal. Can I be a celebrity ambassador, and be paid decent money to have my image associated with products and services that the producers of those products and services will want me to be associated with?
Anyway, for those among us (not me) who wish to opt out of this new LinkedIn practice, Pascale tells me that all that needs to be done is:
• Place the cursor on your name at the top right corner of the screen. From the small pull down menu that appears, select "settings"
• Then click "Account" on the left/bottom
• In the column next to Account, select the option "Manage Social Advertising"
• Finally un-tick the box "LinkedIn may use my name and photo in social advertising"
• and Save
Source:
With thanks to the amazing Pascale Gelly for the news
.
Who, for example (in their right minds) actually reads the “we have changed our privacy policy” blurb which is spewed out each time a data controller changes their practices? And how do we know if we’ve missed anything serious?
This is where the blogosphere, with its notorious internal networks of friends and colleagues, can really shine. What concerns one person can very quickly concern lots of other people.
Today, for example, I was sent an email from the ever vigilant (and oh so brilliant) Pascale Gelly, pointing out that “Without attracting too much publicity, LinkedIn has updated their privacy conditions. Without any action from your side, LinkedIn is now permitted to use your name and picture in any of their advertisements.”
Whoops, I missed that one. On the other hand, if my name and picture sells sufficient quantities of dog food, or whatever else I am supposed to be endorsing, is this really such an invasion of my privacy? I do try to take care when I am on line, and I do what I can to obscure my digital vapour trails whenever my cursor accidentally clicks on a site that some folk might find alarming (or amusing).
But then again, I thought to myself, I can’t make myself aware of everything that happens around and about me. My life is too full already. I can’t take any more in. My mind already hurts (and plays tricks on me). The last thing I really want to do is spend more time in front of a screen, reading about data protection stuff. I do this for a living. Surely, I don’t have to do it as a private citizen too, do I? I shrug my shoulders with mock despair. After all, if we can’t be bothered to do it ourselves, and we actually know about the consequences of remaining digitally vigilant, then the great unwashed has no chance at all of keeping up to speed with things that data controllers think matters.
Accordingly, based on my own personal experience, I really don’t think that the European Commission’s cunning plan of encouraging European citizens to consent to more stuff is going to work. They can’t consent to what they can’t understand or can’t be bothered to read, or simply don’t have the time to read. It’s a brilliant example of a policy initiative that looks great in theory and turns out to be unworkable in practice.
So perhaps we need not blame LinkedIn.
Perhaps I can offer LinkedIn a special deal. Can I be a celebrity ambassador, and be paid decent money to have my image associated with products and services that the producers of those products and services will want me to be associated with?
Anyway, for those among us (not me) who wish to opt out of this new LinkedIn practice, Pascale tells me that all that needs to be done is:
• Place the cursor on your name at the top right corner of the screen. From the small pull down menu that appears, select "settings"
• Then click "Account" on the left/bottom
• In the column next to Account, select the option "Manage Social Advertising"
• Finally un-tick the box "LinkedIn may use my name and photo in social advertising"
• and Save
Source:
With thanks to the amazing Pascale Gelly for the news
.
Saturday, 28 January 2012
One policy, one Google experience
Happy International Data Protection Day!
In a brilliant move that can’t surely attract criticism from the European Data Protection Supervisor, Google is commemorating International Data Protection Day with a short message on its landing page, which may well be read by over half the internet-enabled population on the planet.
The message is sweet and simple: “We’re changing our privacy policy and terms. This stuff matters. Learn more”
It will be great to consult the Google Analytics team in a few months to see just how many people did actually click the hyperlink and take up the opportunity to “learn more”.
What has Google just done? Well, it’s announced changes to its privacy policy, which will take effect in 1 March. Over 60 different Google privacy policies are being replacing them with one that’s a lot shorter and easier to read. One rule to rule them all? Sounds suspiciously like what Commissioner Reding was trying to announce, last Wednesday. It’s also what Gandalf was striving to achieve, during his existence.
When you read the policy (some 2,300 words, depending on what parameters are selected before the automatic word counting exercise is carried out), you appreciate the trouble that has been taken to make Google's operating processes easy to understand. The Google team evidently agree with me that it’s better to draft policies in words that can be understood by Homer Simpson than just by Albert Einstein.
The words flow as if they had been penned by a Hollywood scriptwriter. The slick, lean and easy phrases don’t challenge anyone. I expect that some aspects of them will upset some of the privacy wonks, but for the remaining millions of data controllers who care, Google has created a great language that I’m sure many websites would benefit from being re-written in. Whether many lawyers and data protecton professionals are going to be brave enough to change their own, treasured, text for something that is written in common sense language, rather than obscure gobbledegook, is another matter.
Here is a sample of some of the headline stuff before users are directed to the actual policy:
”Our new policy covers multiple products and features, reflecting our desire to create one beautifully simple and intuitive experience across Google.
Our new policy reflects our desire to create a simple product experience that does what you need, when you want it to. Whether you’re reading an email that reminds you to schedule a family get-together or finding a favourite video that you want to share, we want to ensure that you can move across Gmail, Calendar, Search, YouTube or whatever your life calls for, with ease.
If you’re signed in to Google, we can do things like suggest search queries – or tailor your search results – based on the interests that you’ve expressed in Google+, Gmail and YouTube. We’ll better understand which version of Pink or Jaguar you’re searching for and get you those results faster.
When you post or create a document online, you often want others to see and contribute. By remembering the contact information of the people you want to share with, we make it easy for you to share in any Google product or service with minimal clicks and errors.
Our goal is to provide you with as much transparency and choice as possible through products like Google Dashboard and Ad Preferences Manager, alongside other tools. Our privacy principles remain unchanged. And we’ll never sell your personal information or share it without your permission (other than rare circumstances like valid legal requests).
If you want to learn more about your data on Google and across the web, including tips and advice for staying safe online, take a look at Good to Know.”
I did think of looking at the policy and of comparing it to the recently published General Data Protection Regulation to see what sort of changes might need to me made to ensure that it complied with the proposed new rules on dealing with children, using cookies and obtaining consent. But why spoil a joyous day? Let’s just relax and celebrate International Data Protection Day, rather than have a quiet dig at the Commission. Just for once.
And how will I celebrate International Data Protection Day?
Quietly.
Last night I followed the lead of those intrepid souls who made their way to the Front Line Club in Paddington, who were on a mission to celebrate at a dinner organised by the Privacy Advisors Supper Club. Laughter there was lots. And what an array of different experiences were brought to the supper table. You learn so many unexpected things about your privacy colleagues. Who would have thought, for example, that one of the advisors among us had published a book a few years ago on surgical implants and surgical appliances, and, while a Commission official, had lobbied the European Commission to adopt their ideas as the basis for a new way of regulating medical devices in the EU? And you thought that data protection law was an obscure subject!
I can confirm that everyone present is now entitled to tick off items 12 & 50 on my list of “50 things to do before a data protection professional dies”.(see my blog postings of 17 and 18 January.
Anyway, given what we had to eat last night, there is only one appropriate way to spend today – to abstain from cookies for as long as possible (well, until dusk, anyway).
Source:
https://www.google.com/intl/en-GB/policies/#utm_source=googlehp&utm_medium=hpp&utm_campaign=en_all-hpp_pp
.
In a brilliant move that can’t surely attract criticism from the European Data Protection Supervisor, Google is commemorating International Data Protection Day with a short message on its landing page, which may well be read by over half the internet-enabled population on the planet.
The message is sweet and simple: “We’re changing our privacy policy and terms. This stuff matters. Learn more”
It will be great to consult the Google Analytics team in a few months to see just how many people did actually click the hyperlink and take up the opportunity to “learn more”.
What has Google just done? Well, it’s announced changes to its privacy policy, which will take effect in 1 March. Over 60 different Google privacy policies are being replacing them with one that’s a lot shorter and easier to read. One rule to rule them all? Sounds suspiciously like what Commissioner Reding was trying to announce, last Wednesday. It’s also what Gandalf was striving to achieve, during his existence.
When you read the policy (some 2,300 words, depending on what parameters are selected before the automatic word counting exercise is carried out), you appreciate the trouble that has been taken to make Google's operating processes easy to understand. The Google team evidently agree with me that it’s better to draft policies in words that can be understood by Homer Simpson than just by Albert Einstein.
The words flow as if they had been penned by a Hollywood scriptwriter. The slick, lean and easy phrases don’t challenge anyone. I expect that some aspects of them will upset some of the privacy wonks, but for the remaining millions of data controllers who care, Google has created a great language that I’m sure many websites would benefit from being re-written in. Whether many lawyers and data protecton professionals are going to be brave enough to change their own, treasured, text for something that is written in common sense language, rather than obscure gobbledegook, is another matter.
Here is a sample of some of the headline stuff before users are directed to the actual policy:
”Our new policy covers multiple products and features, reflecting our desire to create one beautifully simple and intuitive experience across Google.
Our new policy reflects our desire to create a simple product experience that does what you need, when you want it to. Whether you’re reading an email that reminds you to schedule a family get-together or finding a favourite video that you want to share, we want to ensure that you can move across Gmail, Calendar, Search, YouTube or whatever your life calls for, with ease.
If you’re signed in to Google, we can do things like suggest search queries – or tailor your search results – based on the interests that you’ve expressed in Google+, Gmail and YouTube. We’ll better understand which version of Pink or Jaguar you’re searching for and get you those results faster.
When you post or create a document online, you often want others to see and contribute. By remembering the contact information of the people you want to share with, we make it easy for you to share in any Google product or service with minimal clicks and errors.
Our goal is to provide you with as much transparency and choice as possible through products like Google Dashboard and Ad Preferences Manager, alongside other tools. Our privacy principles remain unchanged. And we’ll never sell your personal information or share it without your permission (other than rare circumstances like valid legal requests).
If you want to learn more about your data on Google and across the web, including tips and advice for staying safe online, take a look at Good to Know.”
I did think of looking at the policy and of comparing it to the recently published General Data Protection Regulation to see what sort of changes might need to me made to ensure that it complied with the proposed new rules on dealing with children, using cookies and obtaining consent. But why spoil a joyous day? Let’s just relax and celebrate International Data Protection Day, rather than have a quiet dig at the Commission. Just for once.
And how will I celebrate International Data Protection Day?
Quietly.
Last night I followed the lead of those intrepid souls who made their way to the Front Line Club in Paddington, who were on a mission to celebrate at a dinner organised by the Privacy Advisors Supper Club. Laughter there was lots. And what an array of different experiences were brought to the supper table. You learn so many unexpected things about your privacy colleagues. Who would have thought, for example, that one of the advisors among us had published a book a few years ago on surgical implants and surgical appliances, and, while a Commission official, had lobbied the European Commission to adopt their ideas as the basis for a new way of regulating medical devices in the EU? And you thought that data protection law was an obscure subject!
I can confirm that everyone present is now entitled to tick off items 12 & 50 on my list of “50 things to do before a data protection professional dies”.(see my blog postings of 17 and 18 January.
Anyway, given what we had to eat last night, there is only one appropriate way to spend today – to abstain from cookies for as long as possible (well, until dusk, anyway).
Source:
https://www.google.com/intl/en-GB/policies/#utm_source=googlehp&utm_medium=hpp&utm_campaign=en_all-hpp_pp
.
Friday, 27 January 2012
Taking a butchers at our breaches
Yesterday afternoon, a select group of the usual suspects gathered together to share war stories about their experiences on dealing with data breaches.
The speakers included an official from the ICO, a couple of lawyers, and a pair of data protection officers, all of whom had different perspectives to share. And a useful sharing session it actually was, especially when it became pretty clear that everyone was keen on developing a reasonably settled view on precisely the same issues. We’re just not there, yet.
The usual elephants were in the room. Who would be the first to admit that they didn't actually know what a data breach actually was, as the definition (in the ePrivacy Directive and the proposed General Data Protection Regulation) was so vague? Who would be the first to point out that some reporting threshold was required, to avoid overburdening the regulator with trivia. And who would be the first to question the need for the regulator to receive breach reports, if it wasn't at all clear what they were doing with the information that was being supplied?
No one in the room suggested that data breach management was not an important issue. And everyone agreed that responsible data controllers would be striving every sinew to resolve the trivial, as well as the more serious, data breaches. This is because they cared about their customers and certainly wanted to engage, to the greatest extent possible, with their customers. News of an extremely recent UK data breach revealed how quickly the data controller was seen to act when allegations emerged in the blogosphere. Customers - and complainants - certainly have a voice, thanks to the internet. Many seem to be able to quickly detect irregular types of activity on their online accounts and, using their powers of social networking, get the data controller to respond responsibly.
So, turning to minor breaches, what role does the regulator play here? It is a valid, and important, question.
Later, over a data protection dinner most generously hosted by Bird & Bird, a few of the guests asked themselves whether there were any lessons to be learnt from the breach notification rules that were prevalent in the USA. Had these rules led to a measurable change in the behaviour of American data controllers? Were there now fewer breaches than before? Were citizens more confident that data controllers were more vigilant than before?
Well, we asked ourselves these questions, but answers were there few. I left the dinner confused. Not inebriated, but just still not clear what the point of the breach notification process to the regulator actually was.
Tonight, I’m off to dine, gossip and dance the night away at an event organised by the Data Protection Officers’ Supper Club. I’ll raise the same questions that were raised last night, and I’ll report back if any significant insights emerge.
Image credit:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrjuEP-0wMI5CZOLADFxiko6sfnxAO10cmnRbXn8MBcZ5-AzX8ei4e8I9l-w5-U9qqWJSBcWNLgUWkb_WidnzrS7b36WRsHx51nq0Bl968HXPbzMjk0CLmeOuJ2E-XGUNdSCLKtuwa70km/s1600/data%20breach-thumb-640x480.jpg
.
The speakers included an official from the ICO, a couple of lawyers, and a pair of data protection officers, all of whom had different perspectives to share. And a useful sharing session it actually was, especially when it became pretty clear that everyone was keen on developing a reasonably settled view on precisely the same issues. We’re just not there, yet.
The usual elephants were in the room. Who would be the first to admit that they didn't actually know what a data breach actually was, as the definition (in the ePrivacy Directive and the proposed General Data Protection Regulation) was so vague? Who would be the first to point out that some reporting threshold was required, to avoid overburdening the regulator with trivia. And who would be the first to question the need for the regulator to receive breach reports, if it wasn't at all clear what they were doing with the information that was being supplied?
No one in the room suggested that data breach management was not an important issue. And everyone agreed that responsible data controllers would be striving every sinew to resolve the trivial, as well as the more serious, data breaches. This is because they cared about their customers and certainly wanted to engage, to the greatest extent possible, with their customers. News of an extremely recent UK data breach revealed how quickly the data controller was seen to act when allegations emerged in the blogosphere. Customers - and complainants - certainly have a voice, thanks to the internet. Many seem to be able to quickly detect irregular types of activity on their online accounts and, using their powers of social networking, get the data controller to respond responsibly.
So, turning to minor breaches, what role does the regulator play here? It is a valid, and important, question.
Later, over a data protection dinner most generously hosted by Bird & Bird, a few of the guests asked themselves whether there were any lessons to be learnt from the breach notification rules that were prevalent in the USA. Had these rules led to a measurable change in the behaviour of American data controllers? Were there now fewer breaches than before? Were citizens more confident that data controllers were more vigilant than before?
Well, we asked ourselves these questions, but answers were there few. I left the dinner confused. Not inebriated, but just still not clear what the point of the breach notification process to the regulator actually was.
Tonight, I’m off to dine, gossip and dance the night away at an event organised by the Data Protection Officers’ Supper Club. I’ll raise the same questions that were raised last night, and I’ll report back if any significant insights emerge.
Image credit:
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrjuEP-0wMI5CZOLADFxiko6sfnxAO10cmnRbXn8MBcZ5-AzX8ei4e8I9l-w5-U9qqWJSBcWNLgUWkb_WidnzrS7b36WRsHx51nq0Bl968HXPbzMjk0CLmeOuJ2E-XGUNdSCLKtuwa70km/s1600/data%20breach-thumb-640x480.jpg
.
Wednesday, 25 January 2012
“Ladies and Gentlemen, we have done it”
With these words, Commissioner Reding unveiled the latest set of proposals for a comprehensive reform of Europe’s data protection today. The Commission has, apparently, just adopted what is called “a comprehensive reform on the use of the data protection rule”. I won't ask too many questions about how this agreement was reached. Like making sausages, you really don't want to know just how they managed to do it.
If you want to view the 34 minute recording of today's announcement yourself, click the “banbuser” link below.
There are some grand claims: “Our reform will eliminate the unnecessary administrative burden as well as the many costs linked to the different reporting requirements currently existing throughout the EU.” Apparently, there will be a single set of rules across the EU, which will save some 2.3 billion Euros each year. But, there will be special care for SME’s, who will be sheltered from some of the more onerous requirements, at least until they have grown into larger enterprises. Commissioner Reding wants to help these young companies to become big – and to help them to do their job without being drowned by administrative burdens. So, there will be no need for them to appoint Data Protection Officers, carry out impact assessments for low and medium risk processing operations, or put together documentation about other data processing activities.
As far as citizens are concerned: "there are to be immediate benefits, and these will ensure that they are well informed about what will happen to their personal data.”
If you listen closely to the recording of the announcement, you will occasionally hear the audience’s reaction. Once or twice there is nervous laughter. On at least one occasion someone out of vision is heard to ask their colleague “is this legal?” It will be interesting to learn the reaction of more of our learned friends once we've all had time to fully consider the implications of the published proposal.
Anyway, how did this one differ from the version that I saw a few days ago and blogged about on 20 January? What can be gleaned about the shifting nature of the text as it underwent those final revisions in the period of frantic activity up to today? The text has lost one Whereas clause (there are now just 139 of them), it has gained an additional Article (there are now 93) and, somewhere along the way, three pages of text. This tells me that the negotiations carried on for some time, and a lot of changes were made, compared to the infamous leaked “Version 56” (which had a mere 118 Whereas clauses, 91 Articles and 78 pages).
As predicted, there is new language around the territorial scope of the Regulation, and we can wait for our legal chums to opine on whether it clarifies matters or causes more confusion.
As predicted, the definition of personal data is still pretty vague and we need to work out whether “online identifiers” are the same as IP addresses. And, the definition of a personal data breach means that all of the problems faced by those trying to live within the data breach requirements of the ePrivacy Directive might now be shared with everyone else. Yuk.
A radical rethink on what to do about protecting the interests of children has resulted in special rules for the processing of children under 13, and some interesting questions to resolve if a data controller is dealing with people between the ages of 13 and 18. As the Regulation won’t affect the general contract law of Member States such as rules on the validity, formation, or effect in relation to a child, we’ll have to work out just what all this stuff means quite carefully. But the Commission wants to give itself the power to adopt other legislation to further specify the condition sunder which children’s data should be processed, so I don’t have a clue what the final effect will be.
As far as the principles of data processing are concerned, private data controllers can breathe a sigh of relief and the processing for legitimate interests condition survives. As predicted, the rules for public data controllers have been tweaked – but I have not had the time to consider whether there might be howls of protest around Brussels and town halls when the implications sink in.
As anticipated, the rules on consent have been tweaked, and to such an extent that I do expect that data controllers will react in an unexpected way to the lessons learnt when individuals exercise greater control of their information by exercising their right to withdraw their consent to the processing of that information. The natural result of this power to withdraw consent will, in many cases, simply lead to a flight from consent – as prudent data controllers will increasingly use the legitimate interests condition as a basis for legitimising their data processing, rather than rely on creaky notions of consent that could easily be withdrawn.
On the rights of data subjects, and as anticipated, we can brace ourselves for no Subject Access Request Fees, unless such requests are manifestly excessive (whatever that means). As I’ve suggested before. this could turn out, in essence, to be a brilliant EU job creation scheme, if armies of staff are to be required to be recruited to deal with these additional Subject Access Requests.
Just a few more headlines for today. The breach notification requirements still appear overly onerous (in the sense that there are draconian requirements to report matters fast, but no corresponding obligations on the part of the regulator to do anything with them in an equally speedy manner). We really need to make better sense of this provision. I'll be developing this theme when I presenting my ideas with the amazing Jeanette Fitzgerald, SVP and General Counsel of Epsilon, at a DataGuidance breach notification event at the London offices of Bird & Bird tomorrow. Jeanette and I do not see entirely eye to eye on such matters, so it will be a great opportunity to appreciate how the same issues can be handled differently by an American or an English data controller. Expect arguments – and laughter – as we share our passion with anyone who’s sufficiently interested.
Turning to the infamous sanction powers, the Commission continues to back down in the face of protests at their disproportionate nature. The ludicrous proposal to fine companies between 100,000 and 1 million Euros or up to 5% of their annual worldwide turnover for a failure to report a breach within 24 hours, which was lowered to a fine of merely between 1,000 and 1 million Euros or up to 4% of their annual worldwide turnover last week, has been further reduced to just up to 1 million Euros or just 2% of their annual worldwide turnover. But, is anyone celebrating?
There’s so much more to be said about this document and about the inevitable subsequent versions. And there are lots of people with good will, who want to see high data protection standards enforced by proactive data controllers and adequately equipped regulators. But that is a huge ask, especially in today’s economic climate.
Let’s hope that, as we work through the compliance cost assessments, the end result is an appropriate increase in standards that can be afforded by data controllers. My main worry is that, given the extensive powers the Comission wants to give itself to make further changes to the data protection rules, by means of delegated legislation, so they don't need to go through such an extensive consultation process, the result could be the creation of a monster that can turn on anyone at will.
If we get it wrong, we could get it wrong for an entire generation of EU citizens. And I don’t want my name associated with that.
Sources:
http://bambuser.com/channel/privateuser/broadcast/2313394
http://ec.europa.eu/justice/data-protection/document/review2012/com_2012_11_en.pdf
http://europa.eu/rapid/pressReleasesAction.do?reference=IP/12/46&format=HTML&aged=0&language=EN&guiLanguage=en
http://ec.europa.eu/justice/newsroom/data-protection/news/120125_en.htm
.
Tuesday, 24 January 2012
Was this the Commissioner's protocol statement?

Perhaps, we now know what is meant when we are told that a Commissioner will make a “protocol statement”. Commissioner Reding spoke in Munich last Sunday. Unlike my suggestion on 18 January, what she had to say was not an explanation of the behaviours that are to be exhibited when meeting a Commissioner. It’s more of an announcement of things to come. In this case, the things to come are to come “this week”. Yes, I know it was delivered last Sunday. But it’s not Data Protection Day, yet.
On the other hand, she might well be saying something tomorrow, too. Who knows? There's really no stopping her, once she puts her speaking shoes on. I am aware of arrangements for a press conference which will announce "something" tomorrow, but I wonder who will be at that conference, and what will be said ...
I was intrigued to find a few similarities between the draft I had prepared for Commissioner Reding on 12 January, and the text of Sunday's speech. They both start the same way (with the phrase “Check against delivery”). They both acknowledge that this is not the occasion on which the drafts are formally revealed. And they both contain a number of questionable statements.
First, let’s look on the bright side of life. I share her hope that the new rules achieve their purpose of creating legal certainty, in a simplified regulatory environment which provides for clear rules for international data transfers. And if they achieve this, then I will be among the first of many who will laud her to the skies and take to the streets to demand that she be appointed “Queen of the European Commission”, before she graces the UN as its next Secretary General.
On the other hand, the measures have to work fairly and proportionately, taking into account the legitimate rights of data controllers, as well as individuals. Will red tape be cut, as is hoped, or will the existing red tape simply be replaced with reams of other types of tape? I really hope that it will not be the latter – but I’m not yet persuaded. Will savings from the scrapping of a general notification rule simply be swallowed by hugely increased compliance expenditure in other areas, without commensurate protections being given to individuals? I fear this may be the case.
Will individuals actually be able to exercise many of the new rights that appear to be bequeathed to them? Commissioner Reding makes some play of the principle that individuals will be able to exercise greater control of their information by exercising their right to consent to the processing of that information. What she fails to point out is that the natural result of this power to withdraw consent will, in many cases, simply lead to a flight from consent – as prudent data controllers will increasingly use the legitimate interests condition as a basis for legitimising their data processing, rather than rely on creaky notions of consent that could easily be withdrawn.
The Commissioner skated over many of the details of the proposal (presumably so that she did not then need to refer to the manner in which other Directorate Generals had expressed their own reservations). She made the general commitment to extending the breach notification provisions to all data controllers, with notification as a general rule within 24 hours, even though the evidence that the current rules are either workable, effective or have brought about any measurable behavioural change among data controllers is questionable (if it actually exists, that is). Still, it’s a great headline, and we can enjoy many months of discussions fleshing out the details, as we first work out what we are trying to stop, and then assess whether the proposed measures actually achieve that aim.
But I should not be too cranky. Individuals deserve great protections whenever they go on line, and they’ll get the best protections that the state can afford to give them. Whether they will actually enjoy similar levels of protections wherever they are in the European Union, well, that’s another matter. European citizens don’t actually enjoy similar levels of healthcare, public housing, social security provision, taxation or education wherever they are just yet, so it is a brave Commissioner who commits themselves to ensuring that: “all data protection authorities in whichever EU country will have the same adequate tools and powers to enforce EU law.” I’ll believe that when I see it. And I’ll celebrate, when I see it, too. But I won’t hold my breath.
One casual, almost throw away remark that did take my breath away was her last statement. Then again, it may well have been designed to have left the audience in a state of shocked excitement as she left the stage and departed for Davos.
It was about freedom of information and copyright: “The protection of creators must never be used as a pretext to intervene in the freedom of the internet. That is why, for Europe, blocking the internet is not an option”.
Well said. What she didn’t say was that “blocking access to parts of the internet is not an option”.
Because we do block access to parts of the internet, and for very good reasons. Hold your horses, you civil libertarians, please hear me out. We block access to illegal content on the internet. We don’t want the on-line experience of minors or the easily led to be harmed by their ability to access information that might corrupt or deprave them.
So, we need an internet censor, or at least someone who cares passionately about the safety of internet users. And I’m happy to be that censor - or at least to be appointed as a person who cares passionately about the safety of the internet users of whichever service provider is employing me.
So, well done, Commissioner. Enjoy your trip to Davos. Then return refreshed, and ready to work with the rest of the passionate squad to develop a set of legal instruments that are truly fit for purpose.
Source:
Speech 12/26 to the Innovation Conference Digital, Life, Design, "The EU Data Protection Reform 2012: Making Europe the Standard Setter for Modern Data Protection Rules in the Digital Age” Munich 22 January 2012
http://ec.europa.eu/commission_2010-2-14/reding/pdf/speeches/s1226_en.pdf
.
Monday, 23 January 2012
Is there anything else to do before a data protection professional dies?
Suggestions for new additional things to achieve before a data protection professional dies (see my blog posting of 16 & 17 January) have been thin on the ground. But all is not lost. I’ve been chatting to some friends, who can already tick off a couple of items on the list, and who would rather not have any additional challenges set.
On the other hand, I met some chums at the Privacy International drinks party in central London last Thursday night, who were proud to have been able to tick off achievement 41. And I’ll be meeting more chums on Friday evening to witness them tick off achievements 12 and 50. There could still be time (and room) for you to join in the fun, if you are free.
But there must be more achievements for a data protection professional to accomplish, surely? Or is inanely a ticking off an item on a list a sign of autism? Are we data protection professionals just living with some disorder of neural development, with impaired social interaction and communication skills, exhibiting alarming tendencies of restricted and repetitive behaviour? Can we talk about anything other than data protection?
I do hope so.
Anyway, if you can (or want) to think of additional achievements, before the strain of crawling all over the documents that are just about to be launched by the Commissioner Reding numbs us into a state of oblivion, please feel free to contact me through the usual channels. A prize such as the one pictured (recently sent to me by a contact who is so useful to know in this business) may well be presented to the person who sends me the best set of suggestions.
.
Subscribe to:
Posts (Atom)

