Showing posts with label law. Show all posts
Showing posts with label law. Show all posts

Tuesday, September 8, 2015

Another Illinois Facebook face recognition lawsuit

Gillen v Facebook (Scribd)

Note: BIPA = Biometric Information Privacy Act

I have removed two footnotes in original.
NATURE OF ACTION

1. Plaintiff brings this action for damages and other legal and equitable remedies resulting from the illegal actions of Facebook in collecting, storing and using Plaintiff’s and other similarly situated individuals’ biometric identifiers and biometric information (referred to collectively at times as “biometrics”) without informed written consent in violation of the BIPA.

2. The Illinois Legislature has found that “[b]iometrics are unlike other unique identifiers that are used to access finances or other sensitive information.” 740 ILCS 14/5(c). “For example, social security numbers, when compromised, can be changed. Biometrics, however, are biologically unique to the individual; therefore, once compromised, the individual has no recourse, is at heightened risk for identity theft, and is likely to withdraw from biometric-facilitated transactions.”

3. In recognition of these concerns over the security of individuals’ biometrics – particularly in the City of Chicago, which was recently selected by major national corporations as a “pilot testing site[] for new applications of biometric-facilitated financial transactions, including finger-scan technologies at grocery stores, gas stations, and school cafeterias,” 740 ILCS 14/5(b) – the Illinois Legislature enacted the BIPA, which provides, inter alia, that a private entity like Facebook may not obtain or possess an individual’s biometrics unless it: (1) informs that person in writing that biometric identifiers or information will be collected or stored, see id.; (2) informs that person in writing of the specific purpose and length of term for which such biometric identifiers or biometric information is being collected, stored and used, see id.; (3) receives a written release from the person for the collection of his or her biometric identifiers or formation, see id.; and (4) publishes publically available written retention schedules and guidelines for permanently destroying biometric identifiers and biometric information, see 740 ILCS 14/15(a).

4. In direct violation of each of the foregoing provisions of § 15(a) and § 15(b) of the BIPA, Facebook is actively collecting, storing, and using – without providing notice, obtaining informed written consent or publishing data retention policies – the biometrics of its users and unwitting non-users.

5. Specifically, Facebook has created, collected and stored over a billion “face templates” (or “face prints”) – highly detailed geometric maps of the face – from over a billion individuals, millions of whom reside in the State of Illinois. Facebook creates these templates using sophisticated facial recognition technology that extracts and analyzes data from the points and contours of faces appearing in photos uploaded by their users. Each face template is unique to a particular individual, in the same way that a fingerprint or voiceprint uniquely identifies one and only one person.

6. Plaintiff brings this action individually and on behalf of all others similarly situated to prevent Facebook from further violating the privacy rights of Illinois residents, and to recover statutory damages for Facebook’s unauthorized collection, storage and use of unwitting non-users’ biometrics in violation of the BIPA.
A wrinkle in this lawsuit is that the plaintiff is not, and never has been, a registered Facebook user and therefore could not have agreed to Facebook's terms of service.

Monday, April 13, 2015

The attorney suing Facebook

A lawyer Silicon Valley loves to hate (Seattle Times)
Though one tech financier calls Jay Edelson “a leech tarted up as a freedom fighter,” the Chicago class-action lawyer has had an impact on the privacy issues that the Internet has made so pervasive.

Thursday, December 4, 2014

Tech firms developing privacy expertise

Eid Passport Lawyers Up On Biometric, Data Issues (findBIOMETRICS)
To those outside the industry it may seem like an odd thing to announce, but those in the fields of identity management and biometrics are likely well aware of the anxieties percolating as data-collecting technology steadily creeps into many facets of contemporary life...

Monday, November 3, 2014

Virginia court rules fingerprint security not protected by 5th Amendment

Police can demand fingerprints but not passcodes to unlock phones, rules judge (Naked Security)
Cops can force you to unlock your phone with your fingerprint, but not with your passcode, according to a judge in the US state of Virginia.
We touched on this in early 2012 in United States: ID Technology & the Bill of Rights which drew inspiration from a bank fraud case in Colorado.

I still think that voice-based technologies may still exist in the legal gray area this case attempts to clear up.

As for fingerprints, those may be taken from persons at the time of their arrest, so it's hard to argue that they are somehow out of bounds for investigative purposes. One may be forgiven, however for wondering what's the big deal. After all, I've been reading for years that finding a latent fingerprint and using it to hack biometric security systems is child's play. So, either the police would rather go to court than use such a simple workaround, or the rubber finger trick is much harder to pull off than some suggest.

Wednesday, March 13, 2013

Keeping school lunch biometrics in perspective

Maryland: Bill from Carroll senator would ban collection of students' biometric data (Baltimore Sun)
Earlier this school year, Carroll County Public Schools had biometric scanners in place in about 10 school cafeterias, where they were used to help expedite the process of paying for school meals. Officials said the scanners would be more efficient than processing cash transactions or using a PIN keypad system.

But officials fielded complaints from some parents who felt the scanners were an invasion of privacy.
If you think biometrics for school lunch payment are bad, you're not going to like this:

Joy Pullmann: Data mining kids crosses line (Orange County Register)
The U.S. Department of Education is investigating how public schools can collect information on "non-cognitive" student attributes, after granting itself the power to share student data across agencies without parents' knowledge.

The feds want to use schools to catalogue "attributes, dispositions, social skills, attitudes and intrapersonal resources – independent of intellectual ability," according to a February DOE report, all under the guise of education.
Read the whole thing.

Like we've said before, "If schools are unable to keep data secure, biometric template information is the last thing that should concern parents." "Secure" doesn't really apply in the situation described above but the observation that schools already possess very detailed information about students stands.

For the curious: This is an actual biometric template created using one finger, an off-the-shelf fingerprint reader and their freely-circulated software development kit (SDK). It consists of 800 hexadecimal characters.
2aba08229b3b2a44e72c8f14da168a560a3caf2257add068a7fc1636215bff53152546da3fc8071ea84433a42261f4ff7bc3b455199be8980eea2bb1e922f18aa309e050130d72ca124ecd6e9e86459e60858ff44f71d0c1c4e23b97a9a6554619543e8d347f79ea8fa70db87eaea7f37bf2cac4e697d5525479cc72fb653b5d32089e7b3cbcd01f8dba60eda95a50a31b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c1b2dc9ebaf0d5f602a64ff47f06cf97c
Something similar could be used instead of a PIN number for lunch purchases in Maryland schools unless the state bans the technology.

Now which is more risky to student privacy, those 800 characters which I've freely put online and made public, or other types of records schools routinely and uncontroversially* keep?





*Ms. Pullmann seems to find the potential sharing of information without parental knowledge and the chipping away of existing privacy protections that prevented sharing of non-academic information (including biometric information) more problematic than the fact that schools know a lot of non-cognitive details about students.

On another note the mention of "a biometric wrap on kids' wrists" caught my eye. Within the large and growing list of biometric modalities, I've never heard of wrist biometrics. I suspect that this is another example of confusion that arises when "biometrics" and "biostatistics" are needlessly lumped together, a subject we have covered in some detail.

Wednesday, January 30, 2013

US: Biometrics figure in President's immigration policy overhaul

A plan to fix immigration system (Record Online)
Obama's plan requires people living in the U.S. illegally to register, submit biometric data, pass criminal background and national security checks, and pay fees and taxes before becoming eligible for legal status. After eight years, they would be eligible for legal permanent resident status and five years later could apply for citizenship. They enter the green card application system behind everyone else already waiting for permits. Children brought to the country illegally by their parents would be eligible for expedited citizenship if they attend college or complete two years of military service. The president also supports equal treatment of same-sex couples when one partner is from outside the U.S. That provision isn't included in the Senate framework and may be a flash point with Republicans who oppose offering equal rights to same-sex couples.

Friday, January 25, 2013

US: Iowa bank adds biometrics into customer ID mix

Bridge Community Bank introduces in-branch biometric security (Finextra)
...[C]ustomers submit fingerprint and facial biometric data as well as their name, address, date and country of birth and gender. Tascet uses this data to generate a 16-digit 'financial security number' which is linked to the customer account. To identify themselves in a branch and carry out transactions, customers then provide their name and fingerprint.
This is exactly the kind of thing we predicted in the wake of Patco Construction v People's United Bank.
[B]anks [now] have more responsibility to shield their business customers from fraud. That responsibility, however, will entail a cost that will ultimately be borne by customers in higher fees — applied directly to this this case, wiring fees. But if not appealed and/or upheld, it means banks will be offering customers more security and charging higher prices, part of which will flow to security providers including biometric ID management providers.
Bridge Community Bank is in Iowa.

Wednesday, January 9, 2013

Court: Students cannot opt out of ID badge policy

Student Suspended for Refusing to Wear RFID Tracker Loses Lawsuit (Wired)
Sophomore Andrea Hernandez was notified in November by the Northside Independent School District in San Antonio that she won’t be able to continue attending John Jay High School unless she wears the badge around her neck. The district said the girl, who objects largely on religious grounds, would have to attend another high school that does not employ the RFID tags.

She sued, a judge tentatively halted the suspension, but changed course Tuesday after concluding that the 15-year-old’s right of religion was not breached. That’s because the district eventually agreed to accommodate the girl and allow her to remove the RFID chip while still demanding that she wear the identification like the other students.

The Hernandez family claims the badge and its chip signifies Satan, or the “Mark of the Beast” warning in Revelations 13:16-18. The girl refused the district’s offer, sued, and was represented by the Rutherford Institute.
It is clear that the public hasn't quite come to grips with the use ID technology technology in the administration of (more-or-less compulsory) public services involving children.

Tuesday, November 13, 2012

France severely limits biometrics for time-and-attendance

No biometrics to control working hours (CNIL)
October 23, 2012
In recent years, the control techniques employed in their workplaces have experienced unprecedented growth, including through the use of biometric devices. Therefore, the CNIL wished to obtain the opinion of trade unions and employers, the General Directorate of Labour as well as some professionals, the use of this technology. The issue of biometrics as a tool for management and control of attendance zones has been analyzed under the Data Protection Act and in accordance with the Labour Code.
The Commission has always been vigilant about biometrics. They have the peculiarity of being unique and permanent, because they identify an individual from its physical, biological or behavioral (eg fingerprint, hand contour). They are not assigned by a third party or by the person chosen. They are produced by the body itself and the means permanently thereby allowing the "tracing" of individuals and their identification.

The sensitive nature of these data that explains the Data Protection Act provides a specific control of the CNIL essentially based on the proportionality of the device in relation to the objective sought, such as time management.

On 27 April 2006, the Commission adopted a single authorization for the implementation of biometric recognition based on the contour of the hand with the purpose of access control and time management and restoration of the site work (AU-007).

Following more than a dozen hearings, consensus is clearly expressed to consider the disproportionate use of biometrics for control schedules.

Therefore, the Commission has decided to modify the TO-007 in that it allowed the use of the hand contour for time management. now, no single authorization are used to control the schedules of employees by a biometric device.

Transitional measures
Organizations that already use this device to control schedules and staff who have made ​​a commitment to comply before the publication of this new debate will continue to use it for a period of five years. After this time, they will stop using the biometric feature, which will not involve systematically changing hardware. Organizations can indeed set the system to inhibit the function and use biometric instead, codes, cards and / or badges without biometrics. The CNIL has informed individually organizations having previously sent a commitment to comply with the AU-007.

However, devices contour of the hand can still be used to control access to the premises or manage the restoration of the workplace. These treatments will continue to be a commitment to comply with the AT-007
The fact install a biometric device for purposes other than those covered by the AU-007 will give rise to requests for specific permission, which will be considered on a case by case basis by the Commission. [ed. Translation by Google; Emphasis in original]
See also: No more single authorization of the CNIL can now monitor employee schedules by a biometric hand recognition.

It seems that France has placed some limits on biometrics for time-and-attendance, preventing new adoption   and requiring a five-year phaseout for those who are currently using the technology.

CNIL explicitly okays biometrics for physical access control.

No example of actual "tracing" or violation of privacy is mentioned in the statement.

It appears the CNIL has preserved by law a certain degree inefficiency in the French labor market — inefficiency that biometric technology can help reduce. So far, this is the only case of its kind that I'm aware of.

Oh well, vive la différence.

h/t:
PogoWasRight.org
@M2SYS

Thursday, October 4, 2012

New European Data Protection Supervisor Opinion on Data Privacy & Biometrics

Privacy guardian wants one EU rulebook on ID databases (The Register)
"The EDPS [ed. European Data Protection Supervisor] considers that the proposed Regulation should establish a minimum set of requirements, in particular with respect to the circumstances, formats and procedures associated to security as well as the criteria, conditions and requirements, including the determination of what constitutes the state of the art in terms of security for electronic trust services," it said.

The watchdog said that if common security requirements are not to be set out in the new laws, then provision should be put in place to allow the European Commission to "define where needed, through a selective use of delegated acts or implementing measures, the criteria, conditions and requirements for security in electronic trust services and identification schemes".

Assistant EDPS Giovanni Buttarelli, who signed the opinion, said that the proposed new law should set out a requirement that trust service providers and electronic identification issuers should have to provide individuals who use their services with "appropriate information on the collection, communication, and retention of their data". He added that those organisations should also have to provide individuals with "a means to control their personal data and exercise their data protection rights".
The world can always use more Transparency and Consent.

Special attention for biometric data follows the section quoted above.

The pdf of the Supervisors report can be found here:
Opinion of the European Data Protection Supervisor on the Commission proposal for a Regulation of the European Parliament and of the Council on trust and confidence in electronic transactions in the internal market (Electronic Trust Services Regulation)

Thursday, September 20, 2012

The legal status of non-scientists processing DNA

Legal hurdles threaten to slow FBI's 'Rapid DNA' revolution ()PC Advisor)
What's more, the DNA Identification Act of 1994 passed by Congress gave the FBI the authority to establish its DNA index system, but didn't envision that DNA information would be uploaded to the FBI database from a police station using Internet-connected Rapid DNA equipment. The law covers only accredited DNA labs in use today, not the mobile Rapid DNA equipment that can be operated by non-technical personnel anywhere, according to Clark Jaw, an auditor at the FBI Laboratory for the Combined DNA Index System (CODIS). It appears there needs to be a change to the DNA Identification Act to accommodate use of the new technology, he says.
See also: "Rapid" DNA: Not super rapid. Still really cool. More steak than sizzle.

Wednesday, August 15, 2012

The Facebook Face Rec Saga Continues as EU Reopens Inquiry

Germans Reopen Facebook Privacy Inquiry (NY Times)
Data protection officials in Germany reopened an investigation into Facebook’s facial recognition technology Wednesday, saying the social networking giant was illegally compiling a vast photo database of users without their consent.

Tuesday, July 24, 2012

Israel High Court of Justice on Biometric Database Pilot

Hight Court: Biometric database should be changed (Jerusalem Post)
The petitioners said the ministry should examine whether a central database was in fact needed and whether there were other options that could prevent data leaks or information theft.

Though the court rejected the petition as premature because the pilot has not yet run, Justices Miriam Naor, Hanan Melcer and Isaac Amit also accepted the petitioners’ arguments that the state must rework its planned pilot of the program to evaluate whether it is necessary to store the population’s biometric data in a single, centralized database.

The Interior Ministry has been planning for years to replace existing ID cards with ones containing biometric data, and in 2009, the Knesset approved the biometric data law that allowed the initiative to move forward.

Monday, July 16, 2012

Patco Construction v People's United Bank is a Big Deal

Court Rules Bank's Security Procedures Were Not Commercially Reasonable (Day Pitney LLP)
In an important decision last week, the U.S. Court of Appeals for the First Circuit held, as a matter of law, that People's United Bank's online banking security procedures were not commercially reasonable, even though its selected authentication technology fully complied with the Federal Financial Institutions Examination Council (FFIEC) guidelines for Authentication in an Internet Banking Environment.
This case of PATCO CONSTRUCTION COMPANY, INC. v. PEOPLE'S UNITED BANK is a really big deal but a little outside the scope of what we usually deal with around here.

The gist is that with today's decision, banks have more responsibility to shield their business customers from fraud. That responsibility, however, will entail a cost that will ultimately be borne by customers in higher fees — applied directly to this this case, wiring fees. But if not appealed and/or upheld, it means banks will be offering customers more security and charging higher prices, part of which will flow to security providers including biometric ID management providers.

A couple of good blog posts already exist out there to bring interested readers up to speed:

Technology & Marketing Law Blog: Bank ACH Fraud Victims Get Mixed Rulings (Venkat Balasubramani - June 18, 2011). This one covers the first round and mixed decisions in two different but related cases.

Thinking About Security: Decision on Appeal of Patco v. Ocean Bank (Bill Murray - July 11, 2012). This one covers more recent news.


Thursday, May 3, 2012

UK Political Process Yields Biometric Guidelines

Protection of Freedoms Act comes into force and lays out new laws on DNA retention and surveillance cameras (Out Law)

The new law touches upon CCTV, surveillance, fingerprints, DNA, schools, law enforcement, national security and sets guidelines for the proper handling of biometric information for different combinations of the above.

A new technology is never either entirely good or entirely bad, though by helping people to accomplish more with less effort, successful technologies will, by making the people who adopt them more productive, do more good than harm.

The UK's new law seems to strike a balance that attempts to allow people to capture the productivity gains offered by biometric technologies while mitigating the potential for the abridgment of individual rights either through abuse or unforeseen circumstances. This is as it should be.

The passage of the Protection of Freedoms Act is an important "Biometrics in Society" event and the Out Law article linked above does an excellent job of conveying its breadth.

Monday, March 5, 2012

New Statistical Model Assigns Probability to Fingerprint Evidence

Statistical model removes barriers to using fingerprint evidence in court (Homeland Security NewsWire)
Potentially important fingerprint evidence is currently not being considered in legal proceedings owing to shortcomings in the way it is reported, according to a report published Wednesday in Significance, the magazine of the Royal Statistical Society and the American Statistical Association. Researchers involved in the study have devised a statistical model to enable the weight of fingerprint evidence to be quantified, paving the way for its full inclusion in the criminal identification process.

A Wiley release reports that fingerprints have been used for over a century as a way of identifying criminals. Fingerprint evidence, however, is not currently permitted to be reported in court unless examiners claim absolute certainty that a mark has been left by a particular suspect. This courtroom certainty is based purely on categorical personal opinion, formed through years of training and experience, but not on logic or scientific data. Less-than-certain fingerprint evidence is not reported at all, irrespective of the potential weight and relevance of this evidence in a case.
It may come as a surprise that fingerprint evidence in court cases depends upon expert witness testimony. It is only admitted if an expert claims absolute certainty of a match.

The shortcomings (error rates) of the current system are well described by Cognitive Consultants International (CCI) in their study of actual professional examiners [pdf]. Since the evidence is collected from the chaotic environment of a crime scene and frequently consists of partial fingerprints, a heavy burden falls upon professional examiners and the methods used by examiners open the door to errors related to the way humans process information. The team found statistically significant unevenness among examiners and even within the same examiner.

Abstract:
Deciding whether two fingerprint marks originate from the same source requires examination and comparison of their features. Many cognitive factors play a major role in such information processing. In this paper we examined the consistency (both between- and within-experts) in the analysis of latent marks, and whether the presence of a ‘target’ comparison print affects this analysis. Our findings showed that the context of a comparison print affected analysis of the latent mark, possibly influencing allocation of attention, visual search, and threshold for determining a ‘signal’. We also found that even without the context of the comparison print there was still a lack of consistency in analysing latent marks. Not only was this reflected by inconsistency between different experts, but the same experts at different times were inconsistent with their own analysis. However, the characterization of these inconsistencies depends on the standard and definition of what constitutes inconsistent. Furthermore, these effects were not uniform; the lack of consistency varied across fingerprints and experts. We propose solutions to mediate variability in the analysis of friction ridge skin.
Cognitive Solutions has quantified the error rates of the current system and have made proposals to reduce those error rates. They propose a reassessment of how examiners are recruited and trained; And since different types of latent print lead to different error rates, they recommend further research into the categorization of latent fingerprints.

Alternatively, in Fingerprints at the crime-scene: Statistically certain, or probable? [pdf], Cedric Neumann and Julian Champkin propose a statistical error-checking method applied to the minutiae used by examiners in order to generate a probability score for the match, arguing that "DNA experts are required to give probabilities for their evidence of matching; fingerprint expert are forbidden to. This bizarre situation ought to be ended, in the interests of justice as well as of common sense." This is how they do it:

Figure 2, slightly edited, from Significance. Fingerprints at the Crime Scene.



Historically, in most countries, 12 minutiae that matched each other in type, orientation and position have generally been considered sufficient to identify the source of the mark. Until 2001 the UK required 16 correspondences to establish proof of identity. Both these numbers arose through experience rather than statistical analysis.

The reasoning that currently leads experts from minutiae to identification is essentially a psychological one that cannot be rationalized and rendered explicit. The method that my colleagues and I have presented also relies on those minutiae; but numbers are derived from them.

On any given finger impression, the most prominent minutiae – say six – can be selected and joined up, in a clockwise direction (see Figure 2). They will form a pattern – essentially a six-sided polygon around a centre. (The centre can be defined as the arithmetic mean of the Cartesian co-ordinates of our six points.) A polygon is a much simpler pattern than the whirling lines of a full print or mark. It is also much easier to analyse numerically. The basis of the method is to describe that polygon with a set of variables.


h/t @MDKConsulting

Tuesday, February 28, 2012

Canada: Strange Things Afoot at the British Columbia Privacy Commissioner's Office

Canada: British Columbia Privacy Commissioner Says No Drivers License Facial Recognition Searches for Law Enforcement Without Court Order

First some background:

From Wikipedia:
The 2011 Vancouver Stanley Cup riot was a public disturbance that broke out in the downtown core of Vancouver, British Columbia, Canada on Wednesday, June 15, 2011. The riots happened immediately after the conclusion of the Boston Bruins' win over the Vancouver Canucks in game seven of the Stanley Cup Finals, which won the Stanley Cup for Boston. At least 140 people were reported as injured during the incident, one critically; at least four people were stabbed, nine police officers were injured, and 101 people were arrested that night, with 16 further arrests following the event.
Dramatic Photos Here

Enter the Insurance Corporation of British Columbia (ICBC), which administers the province's drivers license aparatus:

Insurance corporation offers to help ID rioters (CBC - June 18, 2011)
The Insurance Corporation of B.C. is offering Vancouver police the use of its facial recognition software to aid in the investigation into Wednesday night's riot.
Troubled by the ICBC's offer, the British Columbia privacy commissioner launched an investigation. The Office of the Information and Privacy Commissioner (OIPC) is independent from government and monitors and enforces British Columbia's Freedom of Information and Protection of Privacy Act (FIPPA) and Personal Information Protection Act (PIPA).

That's the background and the primary actors.

The BC privacy commissioner has now issued a press release of her findings:

ICBC cannot use facial recognition to identify Stanley Cup rioters without a court order, says B.C.’s Privacy Commissioner (OIPC Press Release - pdf)
The Insurance Corp. of British Columbia cannot use facial recognition to identify Stanley Cup rioters without a court order, B.C.'s privacy commissioner said in a report released Friday.
A passage of critical importance states:
Next, the commissioner reviewed ICBC’s offer to Vancouver Police, and found that using the database in this manner is not authorized under FIPPA.

“A public body can only use personal information for the original purpose it was collected, except in very limited circumstances. ICBC’s offer to use its database to check police-submitted images is clearly a different purpose,” said Denham.

The commissioner’s findings do not alter the power of police to request personal information from public bodies to assist in a specific investigation, or through the use of a subpoena, warrant or court order, as per section 33 of the act.
The part of the FIPPA law the privacy commissioner cites in support of her finding that the ICBC can't cooperate with the police without a court order actually says:

Section 33 - A public body may disclose personal information in its custody or under its control only as permitted under section 33.1, 33.2 or 33.3.
Section 33.2 A public body may disclose personal information referred to in section 33 inside Canada as follows:
Section 32.2(i) to a public body or a law enforcement agency in Canada to assist in a specific investigation
Section 32.2(i)(i) undertaken with a view to a law enforcement proceeding, or
Section 32.2(i)(ii) from which a law enforcement proceeding is likely to result;
To summarize, the law states that: A public body may disclose personal information inside Canada to a law enforcement agency in Canada to assist in a specific investigation undertaken with a view to a law enforcement proceeding, or from which a law enforcement proceeding is likely to result.

So, a public body can only use personal information for the original purpose it was collected, except in very limited circumstances; those circumstances are described in section 33 of the act which clearly permits the sharing of information with police (and, really, any other government official for nearly any reason; see for yourself), yet here is precisely where the OIPC "finds" that the ICBC is prevented from cooperating without a court order when the term "court order" is never used in either of the two acts that give the OIPC its power.

As stated earlier, the OIPC is independent from government and monitors and enforces British Columbia's Freedom of Information and Protection of Privacy Act (FIPPA) and Personal Information Protection Act (PIPA).

The PIPA (Sections 52 & 53) gives the OIPC the power to issue orders which are binding unless they are appealed within thirty days.

But the OIPC's news release never asserts that the OIPC is ordering anything. The OIPC writes:
In a public report released today, Information and Privacy Commissioner Elizabeth Denham found that any use of ICBC’s facial recognition technology to identify criminal suspects requires a warrant or court order. [Emphasis mine].
Either of the bolded portions could have used the order/ordered terminology if that was what was intended by the British Columbia privacy commissioner, but they didn't.

So what exactly is going on here?

Is the OIPC ignoring its stated powers because issuing an order would lead to an appeal that the OIPC would, in the plain reading of the Act, be certain to lose?

Is the OIPC trying to take the position that if the police ask, the ICBC can co-operate, but that the ICBC can't preemptively offer help?

The OIPC's Summary of Recommendations in the document is rather telling.
1. ICBC should clearly notify customers that facial recognition technology is in use for the purposes of detecting and preventing driver’s licence fraud...
2. ICBC should immediately cease using their facial recognition database to identify persons in images provided by police, unless authorized by a subpoena, warrant or court order.
3. ICBC should establish accountability and leadership on privacy within the corporation, to ensure that privacy is taken into account in decision-making at the executive level.
4. ICBC should implement a privacy impact assessment policy, to set out when and how a privacy impact assessment is completed and reviewed. Technology projects should be reviewed at the conceptual, design AND implementation phases.
5. ICBC should develop a schedule for periodic review of its privacy policies. [Point 1 truncated, bold emphasis mine.]
If the OIPC believes that the ICBC is or was in violation of either the PIPA or FIPPA laws, doesn't it have a duty to order the ICBC to comply with the two acts and be prepared to go to court over its stance?

Perhaps another portion of the FIPPA law has more bearing in this case.

Part 2 - Division 4 states:
Information must be disclosed if in the public interest [emph. in orig.]

25 (1) Whether or not a request for access is made, the head of a public body must, without delay, disclose to the public, to an affected group of people or to an applicant, information
(a) about a risk of significant harm to the environment or to the health or safety of the public or a group of people, or
(b) the disclosure of which is, for any other reason, clearly in the public interest. [emph. mine]
The ICBC would be expected to make the argument that informing the police of its capabilities to assist them in quelling riots is not prohibited by the FIPPA law, but rather it is required by it.

Monday, February 13, 2012

UPDATE - United States: ID Technology & the Bill of Rights

I made some slight edits to the ending of the original post for clarification and to make the original more smoothly flow into the update. The original post is here.

The Fifth Amendment in the Digital Age (ZDNet - Identity Matters Blog)
Basically, if the password is a physical thing she has, than the Fifth Amendment does not protect it. But if the password is deemed to be something the defendant knows, it is protected.
...
To illustrate the principle, the Supreme Court has previously explained that a witness might be “forced to surrender a key to a strongbox containing incriminating documents,” but not “compelled to reveal the combination to a wall safe.”
As the post points out, biometric technologies complicate this further.

The Fifth Amendment guaranty that "No person shall... be compelled in any criminal case to be a witness against himself," applies (outside the military) to those who have already been indicted by a grand jury, are standing trial, and are being asked to assist in their prosecution. The example above doesn't seem to prevent the police from hiring a locksmith to open the wall safe; it merely prevents the police from compelling the accused to help them.

The Fourth Amendment is much more relevant to privacy in the ordinary sense.

The Fourth Amendment guarantees that:
"The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."

"Warrantless mobile device searches" (Google search) are a much hotter digital age privacy issue and it's the Fourth Amendment that seems to apply to those searches, though not necessarily to this case as I'm pretty sure they have a warrant for the laptop.

UPDATE: The attorney for the defense, having lost on the Fifth Amendment is appealing the Fifth Amendment ruling and seeking refuge in the Fourth Amendment.

Woman who pleaded Fifth in password case now citing Fourth
He said the Fourth Amendment is a better argument “for us and for the public in general.”

Fricosu’s case drew interest from civil rights groups who argued that current law needs to evolve to meet the nuances of the digital age. The prosecution, however, argued that hiding behind a password and encrypted data would make prosecution impossible in the future.

Dubois says the Fourth Amendment argument ties into the Fifth Amendment, which is also “about due process of law and fundamental fairness. ”


The court rejected the Fifth Amendment argument that focused on the password, an identity management technology, saying that the password is more akin to a physical key than a safe's combination (see above). The defense appeal of this judgement keeps the identity management issues in this case alive. The Fourth Amendment question seems to focus on the contents of the laptop and not access to them.

Still, it seems like this case has a long way to run.

Monday, February 6, 2012

Europe Moves to Protect Online Privacy

Should Personal Data Be Personal? (New York Times)
Mr. Schrems’s sentiment is emblematic of the discomfort sweeping through Europe about the ways in which Internet companies treat personal information. That discomfort has, in turn, prompted proposals for stricter regulation of online data across the continent. And Europe’s moves to protect Internet privacy — something Americans have not, as yet, actively agitated for — have given rise to a thorny question: How do the laws and mores of different nations manage, if at all, the multinational companies that now govern our digital lives?
It's a good article.


h/t @francesIDexpert