Friday, January 24, 2014

Open Letter Calling for U.S. Government Surveillance Reform

Check out this website:

http://reformgovernmentsurveillance.com/


The website is an open letter from certain U.S. corporations calling for global government surveillance reform and state "The undersigned companies believe that it is time for the world’s governments to address the practices and laws regulating government surveillance of individuals and access to their information." Do you see what companies there are? - Facebook, Google, LinkedIn, AOL, Apple, Microsoft, Twitter, and Yahoo. We have seen a few of these companies in the news highlighting someone's concerns about the companies' lack of data protection or respect for individual privacy.

I am not here to knock their privacy practices. In fact, judging by the jobs either filled or recently opened for these companies to hire privacy professionals, it looks like they are trying to improve any alleged deficiencies (we won't discuss any enforcement action that may have been against any of these companies - we are looking forward, not back).

However, keep reading the page. The companies support five principles:
1.     Limiting Governments’ Authority to Collect Users’ Information;
2.     Oversight and Accountability;
3      Transparency About Government Demands;
4.     Respecting the Free Flow of Information; and
5.     Avoiding Conflicts Among Governments.

So this is all about former National Security Agen­­cy contractor Edward Snowden's surveillance and the European Union's reaction. These are global companies and do not want to suffer any potential repercussions due to the actions of the government. It is admirable for them publicly call for reform of government surveillance. Consider this quote from Marissa Mayer, CEO of Yahoo, which sums up the concerns nicely:

“Protecting the privacy of our users is incredibly important to Yahoo. Recent revelations about       government surveillance activities have shaken the trust of our users, and it is time for the United States government to act to restore the confidence of citizens around the world. Today we join our colleagues in the tech industry calling on the United States Congress to change surveillance laws in order to ensure transparency and accountability for government actions.”

I am particularly intrigued by the goal of enabling the free flow of information. Under this principle, the letter states that

"[t]he ability of data to flow or be accessed across borders is essential to a robust 21st century global economy. Governments should permit the transfer of data and should not inhibit access by companies or individuals to lawfully available information that is stored outside of the country. Governments should not require service providers to locate infrastructure within a country’s borders or operate locally."


Is this a denunciation of data protection laws of other nations that prohibit data on individuals to be exported out of the nation unless the data exporter has proper controls in place...or their governing nation has proper laws in place? The U.S. clearly does not have national data protection controls in place. The EU clearly prohibits data transfers without said proper controls in place (which there are more options than the governing law of the importing nation). This point segues nicely into the last principle of avoiding conflicts among governments.

Skeptics might say that the endeavor is merely to protect these companies.

So what? If the end result is that the U.S. congress passes legislation to protect information on individuals, are we not all better off?

Thursday, January 23, 2014

FTC enforcement actions against 12 companies for deceptive practices re: EU/US safe harbor certifications

On January 21, the FTC issued proposed settlement agreements against 12 US companies for deceptive claims that the companies were in compliance with the EU/US safe harbor data protection self-certification program. The public has 30 days to comment on these proposed settlements. (see far below for instructions and links, or just read through the release by the FTC linked above).

What does this mean? In simple terms, the European Union has constitutional data protection rights that the U.S. does not. Some states in the U.S. include the right to privacy in their constitutions, but as a nation - we do not. Please do not get sidetracked on the belief that the U.S. does have a right to privacy in its constitution (which is a common misconception) - I can cover that in more detail in another post, but for now, just accept that the U.S. does not have an explicit constitutional right to privacy even though the U.S. Supreme Court held that the constitution has penumbras, one of which is the right to privacy. Back to topic.

The U.S. also does not have general federal data protection laws. We have sectoral laws - financial, health, education, etc. and states have laws - notably, Massachusetts, California, and Texas. Because of this, the U.S. does not meet the EU standards for data protection, yet many U.S. companies are global and collect data on EU individuals. Unless there is some mechanism recognized by the EU to protect the data on these individuals, the U.S. companies are not permitted to export that data from the EU (and in fact, some EU countries have very strict standards). Let's stick to just the EU in general and not delve into the spiderweb of regulations and laws generated by the various member states.

Did you catch the point above about exporting data on EU individuals? Exporting data does not mean merely putting data in a box and mailing it. It also means electronic access to data from outside the EU borders. Thus, the issue at hand with the FTC.

Approximately 3000 U.S. companies have self-certified to the EU/US safe harbor - a set of principles put in place, overseen by the U.S. Department of Commerce to enable these companies to legally export data from the EU to the U.S.  The FTC enters the fray when companies state on their websites that they adhere to the safe harbor and yet do not do so. Then it becomes deceptive or false claims.

Between 2009 - 2012, only 10 companies faced enforcement by the FTC. 4 years. Now, in one fell swoop, 12 actions. It may be in response to the current scandals about U.S. data leaks or the current proposed EU data protection laws...or a combination of many things. The point is - the FTC is taking affirmative action in this regard. The proposed settlements may not seem incredibly meaningful, but there are one step in the right direction and may be a guidepost for the future. Perhaps U.S. companies will be held accountable. Perhaps the U.S. will pay more attention to protecting the information of its citizens. Perhaps. Perhaps. Perhaps.

Perhaps you will read the proposed settlements and let the FTC know what you think about them. Links below.

Comments in electronic form should be submitted using the following web links:
Apperian, Inc.: Company specializing in mobile applications for business enterprises and security;
Atlanta Falcons Football Club, LLC: National Football League team;
Baker Tilly Virchow Krause, LLP: Accounting firm;
BitTorrent, Inc.: Provider of peer-to-peer (P2P) file sharing protocol;
Charles River Laboratories International, Inc.: Global developer of early-stage drug discovery processes;
DataMotion, Inc.: Provider of platform for encrypted email and secure file transport;
DDC Laboratories, Inc.: DNA testing lab and the world’s largest paternity testing company;
Level 3 Communications, LLC: One of the six largest ISPs in the world;
PDB Sports, Ltd., d/b/a Denver Broncos Football Club: National Football League team;
Reynolds Consumer Products Inc.: Maker of foil and other consumer products;
Receivable Management Services Corporation: Global provider of accounts receivable, third-party recovery, bankruptcy and other services; and
Tennessee Football, Inc.: National Football League team.

Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113, 600 Pennsylvania Avenue, N.W., Washington, DC 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.



Wednesday, January 22, 2014

Goals - SMART ones

Goals. Many people write goals every time they start a new year. They are called resolutions. And it is a running joke that people break resolutions frequently (and pardon the pun for "running joke" as many resolutions are around exercise and weight loss).

Let's examine goals and resolutions. No. let's just examine goals.

Goals are easier to achieve when they are smart goals - Specific, Measurable, Attainable, Relevant, and Time-bound. SMART. Even large goals can be broken down into smaller goals based on the SMART formula.

Specific: a goal should be specific not general. Be clear and decisive what needs to be achieved.
Measurable: make sure your goal can clearly be determined when it is achieved. Don't say "better" - say "10% over last year better." Don't say "get fit" - say able to run one mile in under 9 minutes three times a week. (specific and measurable often work together).
Attainable: don't set yourself up for failure. If you are a couch potato and eighty pounds overweight, the right goal for you may not be losing fifty pound in six months. Make your goal to lose five pounds in three months. If you lose five pounds in one month YEA! then set the next attainable goal. Meanwhile, you are achieving goals and succeeding wildly, making for a much better mindset.
Relevant: your goals should be relevant for you. Do not set goals for yourself to please someone else, unless that directly relates to what you need to be successful in the endeavor. Choose goals that matter. Sure you can set a goal to knit thirteen socks in one month...but do you know how to knit, do you wear hand-knit socks, does this satisfy something in you or achieve something that matters?
Time-bound: this one is pretty self-explanatory and included in examples above. Set a time limit. Call a goal achieved, partially achieved, or failed. Then reset.

My goals are to finish my PhD. This might not even be smart, much less SMART. I am one of the few who wants a doctoral degree in order to earn less money....I am an attorney now and I want to teach, or be involved in education in some forum and felt I needed a PhD to do so. I have completed all my coursework and been approved in most part for my dissertation topic. But I am changing methodology for the study. Thus, I am breaking down the dissertation process into SMART chunks. First, I need to complete the methodology proposal by this May. Then I need to get permissions and arrange for the study. Then I need to write. write. write. revise. revise. revise. It's a long process. My long-term goal is to complete the dissertation in 2015. By breaking it into SMART goals, I just might be able to do it.

This blog is another goal. I have committed to posting one entry per week for three months. I have heard that it takes three months to form a habit, so I am trying to form a habit.

Another goal - as with so many others is to lose weight. My goal is specific to a size, as opposed to weight, but the process is the same. This is another large goal that I have to break down into smaller goals, including activity, food, and some other things.

I have personal goals, professional goals, goals at work and at home, goals purely for me and goals involving others. But in every case, I am working on SMART goals. Periodically, I will come back and report on the goals - part of my blog goals - and you can keep me honest here.

Put this into practice for your own goals. Hold yourself accountable and see how it works. Any goal fits into this systematic process.

Tuesday, January 21, 2014

Lost 2013

2013 was an interesting year. It was no more interesting than 2012, hopefully less interesting than 2014. I took the year off to do some deep introspection and change some things in my life. I needed to see where I want a blog to go and what I want it to accomplish. Over this time, my friends, fans, and family helped me solidify these plans which fall into several categories: 1) privacy knowledge and awareness, 2) life views and experiences (including getting a PhD and becoming an empty nester, 3) social elements: diversity, leadership, civic education, and career stuff, and 4) culture through the eyes of a redneck. So I make a promise to each of you that I will force myself to blog once a week and provide the information you need. It will be a growth and dedication experience for me - a patient one for you, perhaps.

So today, we'll talk merely about what it takes to make a habit. A habit, by definition, is something one does repetitively over time. You cannot form a habit by doing it once and in some case, having a behavior that is a habit can be proof of a behavior occurring - like fastening a seatbelt or locking a car door. Habits are often performed without active thought - and some are bad and some habits are good. I started fastening my seatbelt consistently in 1990 when I discovered I was pregnant with my oldest child. It is now a habit. I cannot conceive sitting in a car without wearing a seatbelt.

Thus, the plan to is make this blog a habit. I cannot focus enough to make it about one thing - just one thing and I truly admire the people who do. I have a friend who blogs on being an in-house counsel and another who has two blogs - one on being a single male parent and another on movie reviews. All of these are successful and I do not have what they have. Discipline. I recognize this and will try to embrace this to make this blog what you and I need it to be.

We are embarking on a journey to become structurally undisciplined - and to turn this awareness into art. Hold me accountable.

Thursday, September 27, 2012

HIPAA to the BA

Today's issue is HIPAA and Business Associate Agreements.

Under the HITECH Act, HIPAA will apply to Business Associates like it currently applies to Covered Entities. There is a proposed rule to implement this, which was expected to be finalized this past summer. It was not.  If Obama wins, there is no telling when the final rule will be issued.  If he loses, it is a safe bet that his regime will push to have the final rule issued before the end of the year in order to forestall its complete death.

The key to these proposed rules is that Covered Entities are trying to build in the elements of the proposed rules to their current Business Associate Agreements.  At present, certain elements are not expected out of Business Associates, but certainly Covered Entities would love to have these elements present now - like downstream enforcement to subcontractors of the Business Associates, audit trails, and the physical, administrative, and technical safeguards of the security rule.

There is a hope and a prayer that reasoning will overcome our Congress and some pieces of the HITECH Act will get repealed. But it's only a hope. and LOTS of prayer.

Monday, September 10, 2012

Leadership, part III


Let's abandon the academic discussions of leadership and enter the realm of personal advice.  

I have been called a leader. I have been recognized as a leader (Phoenix 40 under 40, FBI Citizens Academy, State Bar of Arizona leadership academy, YWCA educational leader, etc.). I have held leadership positions from school groups, to non-profit boards, to jobs. I share this so you have some idea of my authority to speak on this topic. So yes, time to pat myself on the back.

But I do not engage in this post to self-congratulate, I embark on this discussion to share my views on what it takes to be a leader when one deliberately desires to be a leader. Below I share my top five elements of great leaders.

My first and perhaps most important point is: serve others.  Do not seek to elevate yourself, seek to serve others. If you have a talent or skill that can benefit someone else, use it for their benefit.  If this happens to serve a large group of people, great. If it serves one person, great. 

Listen.  Leaders typically solve problems. Listen. Figure out the problem. Listen. Figure out the solution.

Be true to yourself.  Pretending or trying to be someone you are not will guarantee failure at some point. Your palace of success will be built on a flimsy base of cards.  Be you. Be the best you possible and always strive to improve. You are not perfect. Accept it. Get as close to it as possible. But remain humble.  There is always someone out there a little smarter, a little better, a little more ambitious, a little more than whatever you are.

Ethics. Honesty. Morals. Integrity. All words describing a solid foundation of truth.

A leader is only truly as good as his/her team: be it supporters, followers, colleagues, or customers.  Very little is accomplished in a vacuum. The world is about people. Life is about people.

Friday, September 7, 2012

Leadership, part II

Looking at the examples of leaders provided in the previous entry seems to make the definition of leadership even more confusing.  Hitler as a leader? In the same category as Mother Teresa?  Yes. and No.

Both "good" and "bad" leaders are leaders in the sense that they effect change on some level.  In Hitler's case, it was on a massive, global level impacting hundreds of thousands of individuals either directly or in the efforts to stop him.  By all accounts he was charismatic, intelligent, talented, and personable.  And while we will discuss toxic leaders in another entry, would not necessarily qualify as a toxic leader.  Apparently, he was an effective leader, able to motivate an entire generation and the next one.  In this case, his goals were suspect and in a historical perspective - bad.

Mother Teresa, on the other hand, sought neither fame nor fortune.  She selflessly gave of herself, her efforts, her time to provide for others.  She raised no army. She had few if any direct followers.  She was not known to be charismatic or particularly intelligent (in this regard, I offer no insult, merely indicating that of the traits she is known for, no one discusses her intelligence). She is known to be humble, enduring, giving, selfless, kind, faithful.

So why are both leaders?  Is leadership linked to quality of one's goals, results, position, followers, or what? Yes.  Leadership is one of those nebulous concepts that defeats decades of efforts to nail it down, but simultaneously everyone knows what leadership is.  The trouble comes when one wants to be a leader and is looking for that recipe of traits to have or things to do.  Those that are natural leaders may not ever engage in this effort, but they also may not agree that they are leaders. This depends on how they qualify as leaders.  Mother Teresa would probably never have stated she was a leader. Hitler proclaimed it to the world.

Some leaders may not ever realize it, until one day they look behind them and see a river of followers.

What about those who want to be leaders? Who want that recipe to follow?  We'll address this next time.