Showing posts with label consent. Show all posts
Showing posts with label consent. Show all posts

Friday, April 24, 2015

Consent and Trust

Biometric Data Without the Big-Brother Angst (American Banker)
At the end of the day, biometric data is really just another type of personal data that banks hold, access and use with the trust of customers and employees. But obtaining consent should not just be seen as merely a bureaucratic necessity. It is part of a process by which banks can maintain and enhance trust — which only becomes more important in the age of big data and virtual relationships.

Wednesday, November 28, 2012

Irish privacy commissioner's report

It's mostly inspired by the Facebook photo tagging affair but it deals with privacy issues and biometrics in a holistic way.

Ireland: Preserving Privacy In The Age Of Biometrics (mondaq)
The Office of the Irish Data Protection Commissioner ('ODPC') recently published its audit report regarding Facebook. The audit was undertaken to determine whether Facebook had implemented recommendations stemming from the ODPC's first audit in 2011. While the audit was largely positive in its findings, the photo tagging feature introduced by Facebook, 'tag suggestion', was deemed by the ODPC to be a step too far for compliance with European data protection rules. This tool used cutting-edge facial recognition technology to automatically suggest the matching of names and pictures, i.e. upon the Facebook user uploading a photo, 'tag suggestion' would prompt the names of the individuals appearing in such image.
Consent, contract and transparency are all discussed in some detail at the link and we've discussed those topics philosophically on this blog in the past. There is also an analysis of proportionality in the linked article. Proportionality is a concept seen a lot in discussions of privacy issues involving European government institutions. It's not a big part of privacy discussions in the United States.

In Europe, governments seem to feel freer to proactively inject themselves into arrangements between private entities than do governments in the United States. The recent French decision re biometrics for time-and-attendance is a good example of the invocation of proportionality to regulate the behavior of private entities.

In the United States, negligence, liability and torts seem to fill some of the roles proportionality plays in Europe. Since the legal system in the United States generally holds that one cannot consent to another party's negligence, negligent parties are exposed to civil suits in the event that a data breach harmful to individuals occurs.

In general, it seems that the European approach is more proactive and government driven while the approach in the United States is more reactive and driven by private interests.

Thursday, October 4, 2012

UK Surveillance Commissioner Speaks

CCTV Technology has ‘Overtaken Ability to Regulate it’ (Wall Street Journal)
“A tiny camera in a dome with a 360-degree view can capture your face in the crowd, and there are now the algorithms that run in the background. I’ve seen the test reviews that show there’s a high success rate of picking out your face against a database of known faces.”

Research into automatic facial recognition being carried out by the Home Office has reached a 90 per cent success rate, he said, and it was “improving by the day”.
The headline quote comes from this more detailed article from The Independent, and might best be taken as a warning rather than a statement of fact. After all, if meant literally, the statement belongs in a resignation letter.

Surveillance Commissioner Andrew Rennison:
Let's have a debate – if the public support it, then fine. If the public don't support it, and we need to increase the regulation, then that's what we need to do."
Sounds like Transparency and Consent to me.

Tuesday, April 10, 2012

EU, Facebook, FaceRec & Consent


Facebook's facial recog bots can't eat your face without your say-so
(The Register)
They can taste it, though...
Social networking sites need to obtain users' "informed consent" before suggesting to other users that those individuals feature in photos that they are uploading to the site, an EU privacy watchdog has said.

The Article 29 Working Party said, though, that the networks can process the images legitimately without the consent of those featured in the photos under EU data protection laws in order to assess whether that consent has been given. However, it said that sites processing images in order to verify consent must delete that information "immediately after" that processing is complete.
The above article makes an interesting technical point and hints at an interesting point about privacy.

In order to biometrically determine whether or not someone is in a particular database — such as the database of people who have given consent to be "tagged" — a biometric search must be undertaken. The Art.29 Data Protection Working Party has acknowledged the difference between the search and enrollment functions and probe vs. database images. This is good because, as implied in the article, to fail to make these distinctions would make it impractical to find out if someone had consented to something in the first place without making them express their consent all over again.

There's also an interesting privacy point — Facebook's knowledge about non-facebook users (such as your humble scribe). The sly "spam your friends" button that sends an email to everyone in a new user's email contact list is one way Facebook collects personal information (email addresses) of non-facebook users and begins to turn that data into information when the same email address turns up in multiple Facebook users' contact lists.

The photo tagging feature also allows/encourages Facebook users to add information about non-users to Facebook's database. The Art.29 Data Protection Working Party has recommended a technical solution to the photo-tagging feature's ability to collect information on non-consenting individuals for Facebook's use, which is great. But a 100% solution is as much social as technological.

There's an etiquette to these things. Facebook makes it very, very easy for users to tell Facebook about people who don't use Facebook, but it seems impossible that Facebook could police its users in such a way as to prevent them from violating the privacy of other people. Facebook collects information on non-users, and Facebook can be used to communicate information about non-users without consent. These are two separate issues.

In a final twist, Facebook's very existence may depend upon its users' discretion and restraint in choosing what to post and tag, and Facebook's agility in handling the information. A user may love the facial recognition tagging feature but hate to be outed as the Key West Spring Break wet T-shirt contest winner.

Tuesday, February 21, 2012

Argentinians concerned about Government Surveillance Overreach

In Argentina the collection of biometric data is drawing criticism (Miami Herald)
Argentina’s police were recently accused of infiltrating and spying on demonstrations against the American company Kraft to collect personal information of protesters through a program called “Project X.” Security Minister Nilda Garré has denied the charges but called for an investigation, even as the chief of the national police agency, Héctor Schenone, confirmed the existence of the program in court documents.

Experts say a biometric database would make the identification of protestors much easier.

“Privacy is particularly crucial for our country since throughout our long history of social and political movements, calls for action have often taken to the streets,” says Beatriz Busaniche of Vía Libre, a local foundation that promotes freedom on the Internet. She stressed the importance of anonymity for demonstrators, “especially when they are at odds with the government.’’

Argentina and other Latin American countries are updating their decades-old national ID systems and moving to biometrics without a public debate on the privacy and data-protection implications of these proposals, according to Katitza Rodriguez, the international rights director for the Electronic Frontier Foundation, a San Francisco-based nonprofit that defends digital rights.
Biometric systems are never deployed in a vacuum. Argentina's political and economic history over the last thirty years has been tumultuous, to say the least.

Everyone is entitled to an open deliberative process leading to the highest possible degree of consensus and transparency before the implementation of such systems, and accountability afterwards.

Argentinians are entitled to such a process before deciding whether or not the potential rewards outweigh the real risks that such a surveillance system will be compromised or abused.

Identity management is about people.

Friday, November 11, 2011

Germany to sue Facebook over face recognition. Facebook to make all sharing privacy settings 'opt-in'

Facebook faces legal action from a German data protection watchdog (thinq_)
"This requires storing a comprehensive database of the biometric features of all users," the organisation wrote. "Facebook has introduced this feature in Europe, without informing the user and without obtaining the required consent. Unequivocal consent of the parties is required by both European and national data protection law."
In other news:

Facebook to make all sharing privacy settings 'opt-in' (ZDNet)
The settlement would require the world’s largest social network, with over 800 million users worldwide, to “express affirmative consent” if it makes “material retroactive changes”, the Wall Street Journal reports. The settlement dates back to an FTC investigation to December 2009, when Facebook radically changed its privacy settings. The changes, at the time, made parts of users’ Facebook pages, such as profile picture and other personal information from birthdays to friends’ lists public.

Friday, June 10, 2011

European Regulators probe Facebook’s facial recognition

A number of European privacy regulators are investigating Facebook (FT.com)
A number of European privacy regulators are investigating Facebook’s facial recognition feature amid mounting concern about the technology, which attempts to identify people in photos uploaded to the website.

The social networking site has come under fire from the German, UK and Irish authorities for introducing the feature without permission from users.
There is a tension in these two paragraphs. "concern about the technology" or "introducing the feature without permission from users"?

The issues are often confused. Technology is neither good nor bad. What people do with technology and how they treat each other can be.

So, where are these mounting concerns best directed: facial recognition technology; the Facebook as a technology; or individual decisions by people in positions of power and trust?

This affair has more to do with transparency and consent than any particular technology.

Identity management is about people.

Thursday, June 9, 2011

Facebook Facial Recognition Implementation Raises Privacy Concerns

Face rec software suggests tags for photos uploaded to its site (TECHNEWSWORLD.com)
Facebook has raised concerns among privacy proponents with Tag Suggestions, a new feature that uses facial recognition technology to connect names to faces in uploaded photos and suggest tags to the uploader. Aside from the general privacy worries the feature has spurred, it's somewhat unclear just how long Facebook has had this feature in play.
Transparency and Consent. Organizations neglect these at their peril because their customers/users value them highly.

Tuesday, April 26, 2011

Part IV: A Framework for the Consideration of Privacy Issues

Introduction
Part I: The Right to Privacy
Part II: The Nature of Consent
Part III: Transparency

Part IV: A Framework for the Consideration of Privacy Issues
As discussed in section one, the right to privacy is an individual right to decide for oneself what information to share. Moreover, the exercise of other fundamental rights requires the individual to sacrifice privacy in the service of what they determine to be a higher value. Anyone who cares to disagree will inadvertently prove this assertion because one cannot maintain absolute privacy while expressing ones thoughts and beliefs. They would have to sacrifice some measure of their privacy in order to exercise their freedom of expression to communicate their disagreement.

Privacy, therefore, is akin to currency. It’s fine for a person to trade it for things they consider to be of higher value. It’s wrong to steal it. Some transactions, in retrospect, are seen to have been a good deal; some may seem less so. One person may be quite willing to engage in transactions that are beyond the comprehension of another person. Consent matters and consent reaches its most fulsome expression when the terms of the exchange are transparent.

Having established a conception of the Right to Privacy, the Nature of Consent, and Transparency, we are in a position to lay out a framework for public debate on privacy issues and, later, the scope for the role of self-appointed third parties in that debate.

All transactions bearing upon an individual’s privacy can be described in terms of the transparency of the exchange and the level of individual consent to the exchange.

(click image to enlarge)

Transparency
-Opaque. The individual has absolutely no knowledge about how the relevant privacy information may be used or by whom it may be used.
-Vague. The information may be used in ways that the person who shares the information would not reasonably suspect.
-Customary. The information may be shared in ways that the person would reasonably suspect.
-Transparent. The terms and conditions stating the exact circumstances under which the information may be shared are published and acknowledged to be understood by both parties.

Consent
-Mandated. An individual has no legal right to withhold information they might wish to keep private. Refusal to cooperate may entail incarceration or fines.
-Contingent. In order to engage in a certain relationship or arrangement or partake of a privilege an individual is required to share information they might otherwise prefer to keep to themselves.
-De facto. Through convention or common acceptance -- so widely understood as not to require explicit codification. Common sense.
-Explicit. Formally accepted -- signified by positive acts such as gestures, speech, oaths, affirmations or contracts.

Although, there is room for disagreement as to the exact character of each individual privacy transaction (which of the chart's boxes it fits into), they can all be placed somewhere on the chart above.

Hopefully, the above framework can start to break Privacy into more manageable pieces in furtherance of enhanced understanding of this issue that is so important to us all.

Next:
Part V: Filling in the framework; Absolute advocacy dos and don'ts
Part VI: Filling in the framework, subjectivity and interpretation

Wednesday, April 13, 2011

Part II: The Nature of Consent

Introduction
Part I: The Right to Privacy

Part II: The Nature of Consent
Consent comes in two main varieties: agreement between/among people; and consent of the People. The former describes voluntary associations and ad hoc arrangements made by individuals or private groups; the latter describes the social contract whereby governments obtain their legitimacy. Individual Consent deals with the individual’s right to form relationships, share information, etc. with other entities as mutually agreed. The Consent of the Governed deals with the collective right of the People to form a system of government and the type of behavior a government may compel of individuals under its jurisdiction.

Both types of consent have dramatic implications for the right to privacy and its free exercise.

Individual Consent
Individual consent fits broadly within the contours of contracts and cultural mores.

Contracts
The contractual form of individual consent relies upon the right of legal entities – adults, corporations, businesses, associations, etc. – to interact with each other, or to refrain from interacting with each other in pursuit of their legal individual aims.

When two private legal entities agree to interact with each other, they are said to consent. Contracts are used where an overt positive act is required in order to communicate consent. Acts such as buying something, getting married, hiring someone, incorporation of a business, forming a club, etc. are contractual.

All contracts impose constraints upon both consenting parties. The breach of these contracts is governed by laws.

Cultural mores
In the absence of an explicit written or oral contract or other sign of consent, cultural mores come to the fore. These customs deal in no small degree with a society’s notions of privacy and usually presume minimal consent. These cultural understandings can be seen as mini-agreements between-and-among individuals sharing a public space.

For individuals, exiting the privacy of one’s home and entering the public signifies an individual’s consent, to do certain things (cover your mouth when you cough, be polite) and to refrain from doing certain things (don’t stare at people, don’t point at people and laugh, etc.).

These cultural agreements also impose multilateral constraints upon the consenting parties. The breach of these agreements is most often governed by giving the supposed offender a nasty look. If nasty looks aren’t doing the trick, someone is sure to suggest a law.

For other legal entities such as corporations, clubs and associations, simple existence places them in the public. They are also obligated to do and refrain from doing certain things. Often the obligations they take on are spelled out in a charter or a mission statement, and an organization that fails to live up to its stated and socially imposed standards loses good will.

Consent of the Governed
Consent of the Governed is the other type of consent. I don’t want to wade too deeply into political theory, but for the sake of this discussion let’s assume that it is possible for the People collectively to consent to things, and that the formation of a democratic government means that they do, in fact, consent to be governed. Arguing in favor of these assumptions, democracies have the additional feature of ratifying that supposed consent periodically through voting processes. Laws come out the other end. But it’s important to distinguish the laws that regulate relations between equal members of society (i.e. contract law) from laws that define the much less equal relationship between individuals and the government.

Consent of the Governed bears significantly upon privacy, because governments require citizens to share information with the government or to make information public that they might otherwise choose to keep to themselves.

The abridgment of the right to privacy in the Individual Consent case is ad hoc, fully within the scope of a unique individual’s assessment of their individual aims and within the individual’s power to regulate within the scope of contract law (or nasty looks). But the sacrifices to privacy the People make under the Consent of the Governed case do not fall on some generic entity called the People, redounding to the People’s supposed benefit, they fall upon individuals to the supposed benefit of the People. The People don’t fill in the census, file their income taxes and become licensed to do things; individuals do.

Government also brings a coercive power to the calculation that is absent in the Individual Consent case. Though they both have a direct bearing on an individual’s right to privacy, the nature of consent in the individual case and the Consent of the Governed case is qualitatively different.

Part III: Transparency

Part IV: A Framework for the Discussion of Privacy Issues
Part V: Filling in the framework; Absolute advocacy dos and don'ts
Part VI: Filling in the framework, subjectivity and interpretation