Showing posts with label corporation. Show all posts
Showing posts with label corporation. Show all posts

Tuesday, June 16, 2015

US: Face recognition code of conduct confab loses privacy advocates

The National Telecommunications and Information Administration (NTIA) has convened a privacy multistakeholder process regarding the commercial use of facial recognition technology. On December 3, 2013, the NTIA announced that the goal of the second multistakeholder process is to develop a voluntary, enforceable code of conduct that specifies how the Consumer Privacy Bill of Rights applies to facial recognition technology in the commercial context.

Privacy Advocates Walk Out in Protest Over U.S. Facial-Recognition Code of Conduct (The Intercept)
“At a base minimum, people should be able to walk down a public street without fear that companies they’ve never heard of are tracking their every movement — and identifying them by name – using facial recognition technology,” the privacy advocates wrote in a joint statement.
The quoted article is full of links to NTIA online resources.

An "open letter" of resignation on the part of the named privacy advocates lists their concerns here.
Concluding paragraph:
We hope that our withdrawal signals the need to reevaluate the effectiveness of multistakeholder processes in developing effective rules of the road that protect consumer privacy – and that companies will support and implement.
Ultimately, of course, these are political questions rather than technological ones, but the focus on one type of technology (facial recognition) is a little difficult to understand. If it's wrong for a private corporation to track an unsuspecting individual's every movement, identifying them by name, why single out facial recognition (the means) rather than the tracking (the end)?

The privacy advocates, however, have a point in their favor. The effectiveness of confabs of privacy advocates, sub-cabinet-level administrators, and corporate executives in defining a society's scope for privacy in public should be questioned.

Also mentioned in the article is the fact that the states of Texas and Illinois have passed laws limiting the use of facial recognition technology to identify individuals in public without their affirmative consent.

Monday, March 3, 2014

There’s a fine-line between harvesting personal data to assist or to exploit

How To Collect Consumers' Data Without Freaking Them Out (Fast Company) — Five tips for brand leaders to consider when harvesting personal data so consumers feel okay about giving it up.

Monday, May 7, 2012

Hackers Targeting Human Resources (HR) Departments

The Malicious Hacker's Ever-Sharper Eye (Tech News World)

Number one on Georgetown University's Information Security Office list of the  most dangerous things you can do online is opening attachments from unknown senders, which is pretty much a job requirement of many HR staff. Hackers, being the clever lot they are, are seizing on this by targeting HR staff with attachments delivering malicious software.

This development should keep HR executives and corporate officers awake at night.

As this earlier post about privacy, HR and biometrics discusses...

Employers record an employee's:
Legal name
Home address
Government issued tax ID number
Salary and other income information
Performance Reviews and Disciplinary Records

An employer that provides health benefits may also have private information related to the employee's:
Children
Spouse
Sexual identity
Certain medical conditions
Drug and Alcohol counseling

When pay checks are deposited directly to employee bank accounts, the employer also has bank account information.

Employers already have extremely sensitive information that, in the wrong hands, can be used for identity theft, harassment, discrimination and any number of other abuses...

Those who have concerns about the quantity and nature of the personal information maintained by employers might find a privacy ally in biometrics by requiring biometric verification of HR staff as a prerequisite to accessing records containing sensitive personal information.

We have repeatedly suggested (see this) that biometric verification of IT staff with Administrator access to data is a very good idea. Given their increased risk of being hacked and the type of data they manage, conditioning access to employee records upon biometric verification of HR staff is equally important.

Large organization administrators losing control of customer information is bad. Losing control of detailed employee records is awful. I pity the management team that has to manage both crises simultaneously.

If you'd like to protect your organization against this risk, please consider giving SecurLinx a call. We can help.


Thursday, June 2, 2011

Privacy Leadership: What it Takes

Those anxiously awaiting the next installment of our privacy series, might find this interesting.

Today's Threats Require a New Breed of Privacy Officer (GovInfoSecurity.com) via @heidishey
"Privacy's focus is increasingly on transparency now," Herath says. "This is fundamentally creating new challenges for professionals in their approach toward privacy and data protection."

For instance, the new generation of workers blurs the lines of personal and professional communication in their use of social media, and the type of information that is collected by these sites is often not in the control of an organization. Moreover, it can be used to cause reputational or fraudulent damages.