Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

7 April 2016

Smart Regulation and the General Data Protection Regulation

I recently published an article on smart regulation and the General Data Protection Regulation ("GDPR") on the website of the Society of Computers and Law.  The article will also feature in the next issue of Computers & Law. You can read the full text of the article below.

---------

Data protection and privacy practitioners are waiting anxiously for the official adoption of the GDPR. The latest indication from the European Commission is that the GDPR will officially be adopted in June/July 2016 and in force as from June/July 2018.

Since political agreement was reached on the GDPR in December 2015, we have a fairly good idea of some of the main aspects of the official legislation, such as the statutory recognition of an 'accountability' principle, a risk-based approach to data protection (eg data protection/privacy impact assessments, privacy by design, breach notification), and enhanced individual rights (eg new right of data portability and right to be forgotten). 

Once the GDPR is in force, the litmus test for success will be the consistent implementation, interpretation and enforcement of the Regulation. Many commentators have already warned that the GDPR's promise of harmonization may be more fiction than fact due to the vague and ambiguous provisions of the GDPR (eg legitimate interests provision) as well as the so-called 'open clauses'. 'Open clauses' refer to GDPR provisions where implementation is left to the member-states.
But looking beyond the immediate parapet of the rules, the GDPR is also heralding a move to smart regulation. One aspect of smart regulation is that it involves interactions between diverse stakeholders, such as law-makers, EU DPAs, European Data Protection Board, European Commission, data controllers, data processors, and quasi-regulators (eg third-party certification bodies). Some of these stakeholders, such as EU DPAs and the companies they regulate, used to interact with one another in the pre-GDPR era. However, a move towards smart regulation can often impact on these existing relationships. 

In this article, I explore what smart regulation may mean for the relationships between EU DPAs and the companies they regulate. I draw on some of the findings of my recent empirical research project, where I have analysed how some EU DPAs are starting to embrace smart regulation during their investigations of multinational cloud providers, to suggest four potential key aspects of a smart regulatory relationship between EU DPAs and their regulatees. These four points are mere starting points when reflecting on what smart regulation may look like for the relationships between EU DPAs and the companies they oversee. As noted below, much more work needs to be done to flesh out how such relationships will be developed in practice. 

Active Engagement between EU DPAs and Companies
Companies and EU DPAs will benefit from active, regular, and informal engagement with each other from the very beginning and in any event before a data breach is detected or reported. Opening the dialogue between the regulator and regulatees from an early stage has three key advantages. Firstly, it will enable both parties to build a productive rapport which will be crucial in many cases where there will be a long-term relationship between the regulator and the company. This will, in all likelihood, be the case for multinational companies with a strong European presence and the EU DPAs which will be their lead regulator for their EU operations.  

Secondly, this type of interaction will make it possible for EU DPAs to gain an in-depth knowledge of the processing operations and policies of the companies which fall within their jurisdiction, long before any data breach has been reported. 

Finally, this will provide companies with the opportunity to explain to the regulators their offerings, business drivers, and processing operations. Such engagement means that the regulator will have a detailed understanding of the organisation which can often be useful during enforcement. 

 Organisations can also discuss with EU DPAs the data protection and privacy issues which are potentially raised by their future products or services and tackle such issues head on at the ideation or preliminary design stage rather than after these products or services have been launched. This approach can often not only be cost-effective but also enable companies, especially multinationals, to reduce or avoid negative media coverage which plays a pivotal role in determining the reputation of such organisations. 

This level of engagement between EU DPAs and companies will be problematic if EU DPAs do not develop effective and consistent strategies which will enable them to prioritise tasks in an informed and systematic way. This will be even more crucial for EU DPAs which have limited resources. Unfortunately, the GDPR is silent on how EU DPAs can assess the priority of their activities.  Consequently, one of the tasks ahead before the GDRP is in force will be to formulate consistent guidelines which EU DPAs can use to evaluate which regulatory activity takes precedence over others. 

Compliance Attitudes of Companies
EU DPAs will need to recognize that companies will have different, and often complex, attitudes to compliance. Some organisations may be largely co-operative whilst others may often be recalcitrant. Additionally, the compliance attitudes of companies are likely to change over time for various reasons, including media coverage, reputation, change in management and so on. At times, an otherwise co-operative company can start to object to some of the data protection recommendations which an EU DPA may make. Consequently, EU DPAs need to learn how to deal with and manage the intricate and rapidly evolving compliance attitudes of the organisations they oversee.
Additionally, EU DPAs may often benefit from identifying the reasons why companies may wish to comply with the law. EU DPAs can then often use these reasons as bargaining chips during their interactions with these organisations in order to secure the desired data protection outcome. In many cases, compliance can often be driven by many (rather than one), often interconnected, reasons, such as avoiding reputational damage, generating the trust of customers in the company, avoiding citable binding court decisions, and moral reasons. 

Dynamic Regulatory Styles
EU DPAs may benefit from developing dynamic regulatory styles so that they can respond effectively to the diverse and often shifting compliance attitudes of their regulatees. In particular, in some cases it may be appropriate for EU DPAs to adopt regulatory styles which gradually escalate from soft strategies (eg persuasion, discussion) to harder strategies where the regulatee objects to base line compliance (eg threat to initiate enforcement action) to soft strategies again once the organisation co-operates. 

My recent study highlighted that regulatory styles which can seamlessly move from one end of the spectrum (soft) to the other (hard) and back are often the most effective ones. Additionally, my research also showed that EU DPAs which adopted a 'smarter' approach to regulation by (i) adopting not only dynamic regulatory styles but also recognising the business drivers of companies, (ii) attempting to find mutually convenient solutions, and (iii) not relying heavily on formalistic tools often achieved better outcomes in the longer term. 

This shift in the regulatory styles of EU DPAs will be one of the key challenges ahead when tackling smart regulation. Some EU DPAs may be bound by procedural rules which may prevent them from smoothly moving from soft to hard to soft regulatory styles. Other EU DPAs may need to learn how to regulate in this manner whilst being effective. Thus, we need to bear these points in mind when thinking about how to develop smart regulation when the GDPR is in force. 

Regulatory Relationship Management
Smart regulation also means that companies need to rethink how they approach and manage their relationships with the EU DPAs. In the pre-GDPR era, the regulatory relationship often started on an ex-post basis, for example, when a data breach was detected or when an individual filed a complaint against the company. In many cases, the regulatory relationship would often start on negative note with many companies being on the defensive from the start. 

In the GDPR era, the relationships between many companies (let's say multinationals) and their regulators, especially their lead EU DPAs, may often be from cradle to grave. Such relationships may often start on an ex-ante basis, for example, when a multinational opens a local branch in the territory of the EU DPA. 

In order to develop healthy and productive regulatory relationships, many organisations will have to change how they conceive and manage these relationships. We may need to look at how regulatory relationships in other industries are successfully built in order to learn how companies can build effective and long-term relationships with EU DPAs.

For example, showing the regulators that you want to co-operate (and mean it!), knowing how to negotiate compliance effectively so as to promote innovation whilst complying with the law, keeping the promises made to the regulators may be fruitful ways in which companies can start creating a positive dialogue with their regulators. We also need to consider how SMEs and other companies with a limited budget can cultivate this type of regulatory relationship despite their limited resources.  

Dr Asma Vranaki is an Associate Fellow at the University of Oxford where she investigates the regulation of computer-mediated communication technologies (eg cloud computing, social media). She is a non-practising barrister who specialises in the data protection and privacy law issues raised by the Digital Age.
 
For more see, Vranaki, Asma A.I., 'Cloud Investigations by European Data Protection Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, Forthcoming); Queen Mary School of Law Legal Studies Research Paper No. 195/2015 < http://ssrn.com/abstract=2602216>. The author conducted this research whilst working on the EC-funded 'Accountability for Cloud' research project.

12 May 2015

Cloud Investigations by European Data Protection Authorities

You can find the recent draft of my book chapter entitled 'Cloud Investigations by European Data Protection Authorities: An Empirical View' on SSRN.

The full citation for the chapter is:

Vranaki, Asma A.I., Cloud Investigations by European Data Protection Authorities: An Empirical Account (March 31, 2015). Vranaki Asma, 'Cloud Investigations by European Data Protection Authorities: An Empirical Account,' in Rothchild John A (ed), Research Handbook on Electronic Commerce Law (Edward Elgar, 2016). Available at SSRN: http://ssrn.com/abstract=2602216

Let me know your thoughts!

30 March 2015

Cloud Investigations by EU Data Protection Authorities

I was delighted to present part of my current research on the cloud investigations conducted by European data protection authorities at the recent launch of the Centre for Law and Information Policy at the Institute of Advanced Legal Studies.

My current research forms part of the 'Accountability for Cloud' research project which is a major European research project. I have designed and conducted a qualitative socio-legal research project which investigates how and why investigations of companies offering cloud computing technologies or services ('Cloud Providers') are being conducted by European data protection authorities. 

You can find a copy of my slides here.

4 June 2014

'Rethinking Relations and Regimes of Power in Online Social Networking Sites: Tales of Control, Strife, and Negotiations in Facebook and Youtube.'

For those of you who are interested in my doctoral thesis, I have included the abstract below: 

This doctoral thesis investigates the potentially complex power effects generated in Online Social Networking Sites (‘OSNS’), such as YouTube and Facebook, when legal values, such as copyright and personal data, are protected and/or violated. In order to develop this analysis, in Chapter Two, I critically analyse key academic writings on internet regulation and argue that I need to move away from the dominant ‘regulatory’ lens to my Actor-Network Theory-Foucauldian Power Lens (‘ANT-Foucauldian Power Lens’) in order to be able to capture the potentially complex web of power effects generated in YouTube and Facebook when copyright and personal data are protected and/or violated. In Chapter Three, I develop my ANT-Foucauldian Power Lens and explore how key ANT ideas such as translation can be used in conjunction with Foucauldian ideas such as governmentality. I utilise my ANT-Foucauldian Power Lens in Chapters Four to Seven to analyse how YouTube and Facebook are constructed as heterogeneous, contingent and precarious ‘actor-networks’ and I map in detail the complex power effects generated from specific local connections. I argue five key points. Firstly, I suggest that complex, multiple, and contingent power effects are generated when key social, legal, and technological actants are locally, contingently, and precariously ‘fitted together’ in YouTube and Facebook when copyright and personal data are protected and/or violated. Secondly, I argue that ‘materialities’ play key roles in maintaining the power effects generated by specific local connections. Thirdly, I argue that there are close links between power and ‘spatialities’ through my analysis of the Privacy Settings and Tagging in Facebook. Fourthly, I argue that my relational understandings of YouTube and Facebook generate a more comprehensive view of the power effects of specific legal elements such as how specific territorial laws in YouTube gain their authority by virtue of their durable and heterogeneous connections. Finally, I argue that we can extrapolate from my empirical findings to build a small-scale theory about the power effects generated in OSNS when legal values are protected and/or violated. Here I also consider the contributions made by my research to three distinct fields, namely, internet regulation, socio-legal studies, and actor-network theory.

26 February 2013

Irish Data Protection Commissioner`s audit of Facebook

Dear All

Apologies for the long hiatus in blogging!! Unfortunately, the doctorate and my part-time job are keeping me pretty busy and away from blogging!!

Normal duties will definitely resume once I submit the doctoral thesis later this year!!

For those of you who fervently keep abreast of the privacy issues related to Facebook, my upcoming talk at the Kent Critical Law Society Conference 2013 may be of interest. I will present a paper entitled

15 August 2011

Changes in LinkedIn privacy settings relating to social advertising

I found out today that LinkedIn has changed its privacy settings relating to social advertising without notice. Basically, the default setting for social advertising allows LinkedIn to use the name and picture of LinkedIn users in adverts and promotions. 

You can opt out of this by applying the following steps:

1. In the right corner, select 'Settings' under your name
2. Go to 'Account' and select 'Manage Social Advertising'
3. Disable the box which states 'LinkedIn may use my name & photo in social advertising'

It never ceases to surprise me how sneakily social media platforms such as Facebook change their privacy settings without notifying their users whose data becomes visible to all and sundry until they become aware of this!! Opting out of any changes to the privacy settings of social media platforms should be the default position rather than the converse!

20 July 2011

Beyond RIPA, privacy and hacking: the ramifications of the hacking enquiry by the UK Culture, Media and Sport Select Committee

Yesterday was the day eagerly awaited by all of us following the News Inc phone hacking scandal.
The UK Culture, Media and Sport Select Committee ('the Select Committee') had the difficult task of conducting an inquiry in a case that is still under police investigation. This can, of course, close certain avenues for questioning but could still have been an important forum to ask the key figures caught into the recent phone hacking scandal the key questions. Disappointingly apart from the very good lines of questioning by Tom Watson and Louise Mensch, the rest of the Select Committee failed to pin down the evasive, long-winded answers and the non-answers. But this was perhaps to be expected in many ways. The forthcoming judge-led inquiry and current police investigation will shed more light on the ins and outs of the scandal and whether the current state of affairs is merely the tip of the iceberg or as bad as it will get.


As a lawyer, I am, of course very interested to find out the legal ramifications of any breaches of RIPA 2000 and privacy which will be uncovered in the coming months.  Incidentally, the Guardian provides a quick guide to the RIPA regulatory framework on hacking. Additionally, the evidence given by the Murdochs reveals a wider issue of corporate governance at News International as many crucial actions (e.g. payments of large sums of money, payment of the legal fees of Mulcaire, alleged hacking) fell under the radar of those who are at the very top of the company. To what extent can such vague answers such as 'payments were not within my remit' (a la Rebekah Brooks) or 'I was not aware of this' (in Murdoch senior`s softer tone) or 'this is an interesting question but...' (a la James Murdoch) show that the senior executives at News International exercised the proper level of care required? As much as this scandal has revealed the inextricable links between the various institutions invovled, it has also highlighted that the phone hacking scandal goes much further than RIPA, privacy and Jude Law.

22 March 2011

The right to oblivion in a Facebook world!

I attended the very instructive seminar organised by the Westminster Media Forum today on privacy, social media platforms and the right to be forgotten. The idea of the 'right to be forgotten' has been promoted by Viviene Reding (VP of the EU Commission) recently and has attracted a number of strong and diversion reactions (e.g. Tessa Mayes` recent article on the subject in the Guardian).

There were a number of key actors from different provenance in the hot seat today at the WMF to discuss this very issue such as the Information Commissioner (Christopher Graham), privacy experts such as Caspar Bowden (Microsoft) and Georgina Nelson (Which?), academics such as Dr Chris Pounder, and interested parties such as Jim Killock (ORG) and Tessa Mayes. The full list of speakers can be found here.

Three crucial points emerged from the discussion in my view. Firstly,  privacy (or rather the expectation of privacy) is very much contingent of the specific setting (i.e. the specific SNS) and its technological capabilities (e.g. is the privacy expectation in Twitter the same as the privacy expectation in Facebook?). A second important point emerging from the seminar is the commodification of data and the impact of data monetisation on privacy expectations (i.e. users are foregoing their data for the benefit of enjoying free access to all the services offered by SNS). Finally, the old issue of education surfaced and many speakers argued that a key component of the solution to the privacy issues raised by SNS rested on educating users about privacy issues in SNS (i.e. what should their expectation be? how can they protect their privacy efficiently etc).

CyberPanda thinks that there is a lot of merit in the idea of a right to be forgotten. On a theoretical level, it puts the 'power' (term used loosely here) back in the hands of the users who have more than a mere right to object to data processing and places more evidential burdens on data controllers. However on a practical level, this raises many issues including the old issue of how to enforce EU laws against a US-based company, and also whether the right to be forgotten is enough to deal comprehensively with the whole array of issues raised by SNS (e.g. what is the expectation of privacy for data which the data controller can prove that it needs?).

16 November 2010

16.10.10 Weekly Cyber-Law News Round-Up

Another exciting week in the world of cyber-law with BT & Talk Talk being granted judicial review in relation to the Digital Economy Act, many proposals for legal measures from the Commission/Parliament relating to data protection and privacy, and the Parliament`s objection to the use of trademarks as Adwords. CyberPanda wonders what the impact of this opposition will mean in practice when it comes to the laws relating to keywords. Here is my personal pick of the week:

Copyright
·         Larry Lessig Calls For #WIPO To Lead Overhaul Of #Copyright System | IP Watch http://bit.ly/9qAHtp

·         Court Recognizes That DMCA Process Goes Against Basic Copyright Concepts” http://bit.ly/dos8eu


Digital Economy Act
·         Court grants fourth ground for Digital Economy review http://is.gd/h9rzM

·         Future of Digital Economy Act 'in limbo' until next year, say lawyers http://ow.ly/38j13

·         BT & TalkTalk granted judicial review of Digital Economy Act- what does it mean for file sharers? http://bit.ly/92lvxf
Data Protection & Privacy

·         Call to enforce EC strategy for data protection http://ow.ly/3a3IS #dataprotection #in

·         Summary of Draft Department of Commerce Privacy Green Paper http://ow.ly/3a2RK

·         Facebook, Background Checks and Job Applications http://bit.ly/9yyhN5 #privacy

·         Police recruits screened for digital dirt on Facebook, etc. http://usat.ly/avu0uQ #privacy

·         Swedes' emails to be stored for six months http://ht.ly/38lH2

·         Comparative Chart: Divergencies between Data Protection Laws in the EU. http://bit.ly/c0jbCp

·         Dangers of the Commission`s proposal to include the right to be forgotten in data protection laws http://ow.ly/38J6r

·         European Parliament proposes tough behavioural ad rules http://ow.ly/38j4c

·         Information Commissioner says new laws that impact on privacy should undergo post-legislative scrutiny http://bit.ly/cR1Jdj

·         ECJ holds unqualified legal requirement to disclose personal data on website violates right to privacy and data... http://j.mp/9nXWAC

Censorship

·         Palestinian blogger arrested for criticism of Islam on Facebook - Global Voices Advocacy - http://goo.gl/qUao6 #censorship

Unfair Competition
·         European Parliament joins French traders in opposing use of rival brands as keywords http://ow.ly/39QkR

1 November 2010

Weekly Cyber-Law News Round-Up

What a week it has been!! Here are my personal picks of the highlights of last week`s news which relate to internet law. As always privacy and intellectual property issues are dominating the legal landscape of cyber-law news!

Google
Intellectual Property
· Google clarifies AdWords policy to satisfy French competition regulator http://bit.ly/atAR6g
· Google's 'copied Java code' disowned by Apache #androidlawsuit http://ow.ly/32pPL
· Great and thorough analysis of Viacom v YouTube and impact of safe harbour #copyright #DMCA #Viacom= #YouTube #in http://ow.ly/30Jtk
· Google Goes After YouTubeSocial For #Trademark Infringement
Streetview
· UK MPs question Google over Street View data breaches #privacy #in http://ow.ly/32pV7
· MPs accuse Google on wi-fi data http://bbc.in/aOjlTC
· FTC sends letter to Google - drops Google WiFi case, but tells Google its privacy processes are inadequate #privacy http://bit.ly/aPEQcL
· Google says its cars grabbed e-mails, passwords http://ow.ly/2Zpnj #privacy
· Italy Orders #Google To Clearly Label Street View Cars, Advertise Routes http://ow.ly/2Zpjn
· Regulators closing in on Google http://ow.ly/2ZsLf #StreetView #privacy
· Google investigated over household data privacy breaches by ICO http://ow.ly/2YLpq
YouTube
· Turkey lifts two-year ban on YouTube #censorship #regionalblocking http://ow.ly/32pVY
· Great and thorough analysis of Viacom v YouTube and impact of safe harbour #copyright #DMCA #Viacom= #YouTube #in http://ow.ly/30Jtk
· Google Goes After YouTubeSocial For #Trademark Infringement
Facebook
Privacy
· Facebook app developers sold user info http://ow.ly/32q21 #privacy #in
· Facebook locks down private user data after app controversy #privacy #in http://ow.ly/32pSA
· Court Orders Disclosure of Facebook and MySpace Passwords in Personal Injury Case
· Facebook Allows Users To Turn Off Group Chat http://ow.ly/2ZpvT
· Firesheep Exposes Flaw In #Facebook Log-In Security http://ow.ly/2Zptw #security
Intellectual Property
· Facebook Files for #Patent on Inferential Ad Targeting http://ow.ly/30Jm8
· Facebook comes down hard on Faceporn for #trademark infringement http://ow.ly/2YLk2
Limewire
· As LimeWire Shuts Its Doors, Other P2P Clients See a Surge in Usage #copyright #in #filesharing http://ow.ly/32pWO
· Limewire shuts down after receiving permanent injunction #copyright http://ow.ly/308HB
Other Intellectual Property News
· Twitter Issues New Guidelines for the Tweet Trademark http://ow.ly/32pXh #trademark #in
· Apple sues Motorola over smartphone #patents http://ow.ly/32pQH
· Taiwanese company threatens Apple with legal action over iPad name #trademark http://ow.ly/30J6r
Other Privacy News
· Berlin Privacy Commissioner Dix proposes principle of Anonymization and Pseudonymization. #OECD30 #privacy
· #EFF Urges EU Data Protection Authorities to Call for the Repeal of the EU Data Retention Directive http://ow.ly/2ZpfB #dataretention
Personal Jurisdiction
· Email and phone contacts help to establish personal jurisdiction in US case VEDICSOFT v. MILLENNIUM CONSULTING http://bit.ly/9lTaZ6
Defamation
· Hoteliers Look to Shield Themselves From Dishonest Online Reviews http://ow.ly/2Zpq4
Cyber-Warfare
· Emergency Powers in Cyberspace http://ow.ly/32pRE #cyber-warfare
· US Air Force #cyberwarfare manual goes public http://ow.ly/2ZpiB

24 September 2010

Weekly Cyber-Law News Round

Wow this week has flown by so quickly: where did it all go?!! It has been quite exciting week in terms of legal developments in the area of cyberspace. The usual suspects are in the news: Google Street View, Facebook, piracy, and privacy. But it has also been a week of great significance for copyright laws in the UK (adoption of the Gallo report), and some surprising developments in trademarks law (woman claiming trademark protection for her name).

My pick of the top cyber-law news for this week in descending chronological order:

  • Google's 'Street View' banned for privacy invasion Czech Republic's privacy watchdog says Google http://bit.ly/cgJrA9
  • US Autodesk decision gives software company the tool to prevent the resale of licensed software by unauthorised third parties http://tinyurl.com/33u2bev #in
  • Google's new Transparency Report logs government requests for personal info, takedown requests and blocking: http://bit.ly/dueLKf
  • Lawyers Sued Over Blog Posts Criticizing Referral Hotline for Personal Injury Cases http://is.gd/flsUg
  • Woman Trademarks Her Name, Says No One Can Use It Without Her Permission http://ow.ly/2GSXx
Hope you guys enjoy the new weekly cyber-law news round!

14 May 2010

Facebook: the privacy backlash!

It was only a matter of time before Facebook`s numerous and worrying privacy changes attracted a number of complaints from its users and also from privacy bodies. The EU Privacy watchdog has now added its voice to the growing number of complaints and has stated that the recent Facebook privacy changes are 'unacceptable.' The complaint refers to the privacy changes made by Facebook over the course of the past year. In its statement, the Article 29 Working Party stated that:

"It is unacceptable that the company fundamentally changed the default settings on its social-networking platform to the detriment of a user...Facebook made the change only days after the company and other social networking sites providers participated at a hearing during the Article 29 Working Party’s plenary meeting in November 2009."

In its letter to Facebook, the Article 29 Working Party also added that default settings should protect users rather than expose their data. An interesting article from the New York Times this week showed that currently users have to navigate through 50 different privacy settings with an excess of 170 options to disable the default settings and protect their data.

The Article 29 Working Party has now added its voice to the criticism. It said that in its letter to Facebook it had emphasised that default settings should protect, not expose, users' private information. The Article 29 Working Party also addressed the issue of third party applications having access to users` data and the disclosure of third person data contained in users` profiles to other users.

Additionally, the Electronic Privacy Information Center (EPIC) has made a similar complaint about Facebook to the FTC on the ground that Facebook is engaging in unfair and deceptive trade practices.

As a result of these complaints, Facebook is holding a privacy crisis meeting today although the company is downplaying the significance of the meeting. It remains to see whether the privacy watchdog will have enough clout to compel Facebook to change its privacy policy and whether Facebook acknowledges that it is not feasible for the user to navigate through so many privacy settings before having a decent level of protection for his/her data. In the end it will be a question of the clout of such privacy watchdogs, the extent of their enforcement powers, and whether such powers are enough to prevail over the current company`s business model in which disclosure is the norm as it ensures more revenue for the company via targeted advertising.

8 May 2010

Concerned about your privacy on Facebook: read ahead!

Comprehensive article by ZDNet giving detailed guidelines on how to protect your privacy on Facebook. This is a must read for any Facebook user concerned about his/her privacy since all the privacy changes of the past few months!

2 May 2010

Experiencing Facebook`s connected profiles first-hand: a tale of bewilderment and weariness.

Having just spent the past hour going through the maze of sorting out my Facebook profile page as a result of the introduction of the 'Connected Profiles' function, I am baffled... Baffled by the effort and time it takes to opt-out of any of the connections you do not want to make public (e.g. location, university etc), and baffled by how cumbersome it is to find out what the 'connected profiles' functionality is all about.

The help centre of Facebook has a section on Community Pages and Profile connections which is meant to guide the user gently through it all means and the impact of this new functionality on the privacy of the user. However, the section is not very user-friendly for many reasons. Firstly, you have to click on each question to find out the answer rather than all the answers appearing alongside the questions. This is very cumbersome specially as to find out what it is all about, you really do have to find the answers to most of the questions. Secondly, there is a line which appears time and time in many of the answers, almost as a sort of incantation: 'Connecting to Pages is now the main way to express yourself on your profile.' I have tried to find out what this means but to no avail yet: it sounds quite creepy actually!!!

If like me, you are sceptical of connecting to these community pages (and every user should be aware that many community pages are currently being under construction which means that there are currently no privacy settings for these pages: i.e. your data is out there for all to view!), then you will end up with a very boring profile page as mine: completely empty!! I am not even sure if I have a profile picture anymore!! If my current research did not focus on Facebook in part, this is the time where I would have said: 'Hasta la vista baby' in my best Arnie voice!

Timeline of Facebook`s privacy policy

Interesting article by the EFF on the eroding privacy policy of Facebook over the years @ https://www.eff.org/deeplinks/2010/04/facebook-timeline

29 April 2010

Connected Profiles and Facebook

Certain worrying changes have been announced by Facebook at its f8 developer conference last week. Basically, Facebook is going to introduce a 'Connection Profiles' functionality which means that the information found on your Facebook profile page (e.g. location, interests etc) will be linked to the corresponding pages on Facebook (e.g. if London is your location, you will be connected to the London page on Facebook). Users who choose not to use this functionality will be left with the situation where their profile page will remain empty. Basically, only information which is linked via the 'Connected Profile' functionality will appear on the profile page of the user.

Facebook justifies the introduction of this new functionality on the ground of offering users more connections options and in particular the option to make deeper connections to things which matter to Facebook users such as interests etc. The real reason of course is that it means that Facebook will have access to users` data in a more focussed way (i.e. linked to their interests) and hence can make more revenue through targeted advertising.

There are two main issues raised by the introduction of this new functionality. Firstly, it will be imposed as a default functionality (i.e. if you do not opt out then this will be the default setting of your account). This of course means that users have the burden of having to understand yet again another functionality and evaluate whether or not they want to use this. However as past research has shown, Facebook users tend not to change the default settings for different reasons (e.g. lack of awareness, extra burden of having a specific setting for each type of data etc). So users will be increasingly at risk as they might choose to keep this functionality as a default option without being aware that this means that their data is being furthered distributed across the network.

A second important problem is that of choice. Although users are being given the illusion of having the choice here to opt out of this new functionality, realistically speaking, there is not much choice. If you opt out of the new functionality, then your profile page will be blank.

According to a FAQ from Facebook's Help Center:

"If you don't want to connect to any Pages, the corresponding sections on your Profile will be empty. Connecting to Pages will now be the main way to express yourself on your profile, and you can always edit your profile to remove specific suggested Pages that you don't want to connect to."

This new functionality will be launched fairly soon. It has already been launched in some part of the US. It would be interesting to see how users will react to this new change and whether Facebook will be forced to backtrack due to users` reactions as it has done in the past in relation to the changes to its privacy settings.


9 December 2009

If you thought that only your friends/network could read your status updates, then you will soon be wrong!

It has been reported today that both MySpace and Facebook have signed a deal with Google which will allow its users` publicly available status updates to be fully searchable on the search engine. Google has a similar agreement with Twitter and it is reported that the new agreement with Facebook and MySpace will go live in a few days.

This is a very worrying development for MySpace and Facebook users who have had no say in this matter and will now have their status updates fully searchable and visible on Google to all and sundry if they have not changed their default privacy settings. Past research has shown that most Facebook users use default privacy settings (rather than higher ones) which means that their accounts are fully visible to the rest of Facebook users in their networks. This new deal will also mean now that their updates will be fully indexed and searchable via Google. Cyber Panda thinks that in the new few days, Facebook/MySpace users as well as privacy bodies will raise the alarm bell which will force the companies to either rethink this deal or provide more protection for users` data.

23 June 2009

A new blog is born: FBHive!!

CyberPanda is loving the new blog FBHive which deals with all things related to Facebook: the news, the rumours, and the controversies!! And this new blog has started with a bang as it has disclosed a major security flaw which enables any user to access the basic information of other users even when such information has been protected by its owner (via privacy settings). Amazingly, the blog reports that it took Facebook 15 days to deal with this issue!!!

The flaw has now been fixed but you can still see how it could have been done in the past by checking out the FBHive blog. Amazing footage!!! As a security expert from Sophos has noted, what is worrying is that such a flaw existed and that users` data have been at risk for an unknown period until the flaw was fixed. In addition, users do not whether their data have been 'hacked' into by any other user in this manner. So many privacy issues are raised by this latest Facebook related issue.