Tuesday, April 29, 2014

Hummingbirds and Platypuses: Terminology Matters

In the first grade, I was sent to second grade for math classes. I was five. I was close to the youngest person in my school for first grade (simply due to my birthday being in December), so many of my classmates were already a year older than I was, and second graders were two or more years older than that. One day, the teacher told us "No talking." So I whispered. My verbal logistics were well-rewarded with the only time-out I ever had in school. I explained that whispering is not talking, but she was having none of it. 

In a poorly worded segue, let's transition to a deposition. In 2010, an Ohio Supreme Court case contained a ten-page argument over the meaning of the word "photocopier" from a deposition of the head of IT of a county recorder's officer. You can watch a verbatim reenactment of the transcript here. It is well worth the time, for attorneys, IT, or laymen. Both sides seem slightly ridiculous, but also logical.

Second poor segue alert (but stay with me...it all comes together): That is a problem we have with technology and law. We use terms that when in question can have minute differences that matter. The word makes sense. The concept makes sense. People generally understand what the intent is with the law, but when trying to determine whether a specific technology or its use falls within or outside the law, it becomes quite complicated.

For example, let's play off the transcript above. If there is a rule that a document cannot be photocopied - we know it means, no copying of the document, right? Or does it? Does it mean no photostatic copies - or no digital scanning? or who knows, someone may have an old carbon copying machine lying around just waiting to be used to circumvent the new rule.

Words have meaning and technology is testing the ultimate limits of the words used in our current laws. Courts do their best to interpret law based on its intent, but that intent can usually only be present if the way in which something functions can be imagined (Constitutional wording aside - that is a whole 'nother argument). And sometimes, if the intent can be inferred - or is even explicit - the wording of the law/rule/regulation/guidance is so ambiguous that the courts can do nothing but decide against what seems to be fair to a layman.

This is where data protection and privacy seem to reside. Technology and its resulting misuse far outstrips the incremental changes in law. We're not even talking cigarette boats vs. paddle boats. We're talking hummingbirds vs. platypuses (platypi was incorrect). They exist on the same world and breathe the same air, but they probably do not play well together - seriously, a platypus could squash the hummingbird, but the hummingbird moves too fast for the platypus to catch. Hummingbirds might not even notice the platypus exists! Hummingbirds are stunning to observe and need to keep moving. Platypuses need to be protected and well-grounded. One can absolutely exist without the other, but both need to co-exist with humanity. (wow, this analogy really works all the way through for technology and privacy.)

(and five-year-olds who play with words just might become attorneys.)


Tuesday, April 22, 2014

InBloom: Seeded before its time

Yesterday, inBloom (non-profit education software company) announced its plans to wind down operations over the next few months due to objections by parents and legislators. Adults became concerned about putting in too much information into this database (400 fields), such as students' social security numbers, details about school withdrawals, and family relationships. This month, New York passed legislation prohibiting their department of education from providing data to aggregators (like InBloom).

In mid-November of last year, parents in New York petitioned for a restraining order against the state department of education preventing them from providing student data to inBloom. Parents cited that providing this information was a dramatic departure from the then current practice and seemed to be taking steps backwards in terms of privacy.

inBloom describes its mission and goals as:
"a set of shared technology services that includes a secure, multi-tenant data store and middleware for identity management and data integration . . .  designed to help School Districts and State Educational Agencies provide educators, parents, elementary and secondary school students with learning data from many sources and connect them to relevant instructional resources to support personalized learning through inBloom. The service also helps State Educational Agencies in evaluating federal- and state-supported education programs."

The goal was to provide  "districts and states as a utility for them to more easily synchronize and transfer data, including student personally identifiable information (PII), across the various learning applications they deploy to teachers, students, and families."

So now it ends. inBloom is Out. 

But let's think about this for a few moments...

Is the population of the United States seriously considering the privacy rights of its vulnerable citizens? What?? This turns my privacy meter on its head. Since when did we care what information we share as long as no one gets hurt. What harm can come from this type of data aggregation? It's not like inBloom was going to turn over its education records to the department of child services to show that certain students had certain educational challenges - or home challenges that interfered with education. Data would not be misused or misinterpreted, right? Or shared with watchdog groups or even governmental agents who would put a spin on the data that might adversely affect students, families, school districts, or state funding, right?

Good googli moo

Thursday, April 10, 2014

Privacy: Don't let it go (our take on the ubiquitous song)

Information is shared around the world today
With a few data laws to be seen
One might wish for regulation
So do I, the Privacy Queen

Companies collect data like a swirling storm inside
Couldn’t keep them straight, heaven knows we’ve tried

Don’t let them in, don’t let them see
Be the private person you always want to be
Conceal, don’t reveal, don’t let them know
How much do they know?

Don’t let it go, don’t let it go
We can stop it furthermore
Don’t let it go, don’t let it go
Block cookies and slam the door

Someone should care
What they’re going to say
The argument rages on
Cause breaches don’t bother them anyway

It’s great how some countries protect personal data by law
And the companies that once controlled it can’t get to it at all

It’s time to see what we can do
To test the limits and break through
Do right, not wrong, pass data laws
For all

Don’t let it go, don’t let it go
Pass some laws and rules
Don’t let it go, don’t let it go
Scrap those data tools

Take a stand, the data stays
Let your rights rage on

Big data flurries through the web and into the ground
Information spirals in millions of bits all around
And one thought crystallizes like an icy blast
Data is rarely deleted – the past is never past

Don’t let it go, don’t let it go
New uses rise like the breaking of the dawn
Don’t let it go, don’t let it go
Once given, that data’s gone

Take a stand
In this big data reign
Should data brokers rage on?
Privacy never stopped them anyway



Thursday, April 3, 2014

Job Security?

In 2013 at the IAPP fall conference, Lisa Sotto (a renowned privacy and cybersecurity attorney with Hunton & Williams and member of the Board for IAPP) remarked during an open session to the attendees that if she heard one more person exclaim "Job Security" she might have to punch them - I may be paraphrasing. I think she was kidding. But she was not exaggerating the repetitiveness of the sentiment by the attendees.

Is there job security for privacy professionals?  Probably yes. Oh, what the heck - let's abandon the pretense of being objective: yes. Yes. YES!  The world of privacy and data protection is growing by leaps and bounds. And not just in one area of the globe. Privacy and data protection is growing everywhere.

You may recall the somewhat recent headlines containing words like Snowden, NSA, and leak. These headlines, or rather the actions behind them, have created some additional headlines involving European Union and the U.S. trade. I will not address whether Snowden is a hero or a traitor - or whether what he did is even right or wrong. The end result is that the European Commission and various data protection authorities seemed to question their faith in the U.S./EU Safe Harbor program.

I do not really believe that the EU will completely withdraw it's determination in the adequacy of the Safe Harbor program if only because international trade would suffer tremendously. But on the other hand, I would not brush off their concerns either. Recently, the U.S. FTC Commissioner and the U.K.'s Information Commissioner signed a memorandum of understanding to work together to protect the privacy rights of consumers. Rather contemporaneously, the FTC initiated actions against 13 U.S. companies for violations of their safe harbor certification statements, as this author wrote about in an earlier post. So international cooperation is on the table and probably not disappearing anytime soon although there is a lot of work to be done.

Which segues rather nicely back to job security. Privacy is probably the hottest area of law right now, but privacy professionals can not allow themselves to get cocky or complaisant. We must be strategists and visionaries; we must foster understanding and better understand the business case; and we must see the trees and the forest. Privacy law is growing faster than any one person can track. There are multiple think tanks and watch dog groups dedicated to the topic.

I laugh - usually out loud - when I hear other compliance professionals complain that they run from fire to fire. We all do. It's the nature of compliance. I dream of a day when I am notified that some area is suffering a drought and we can proclaim a high alert for the potential for fire. And even ban burning. Ha. Are you following me in this analogy?  Privacy professionals are like the forest rangers on lookout towers. There is a lot of landscape to watch, we are usually alone, we have to track winds, investigate smoke, and be able to call the troops when needed....but only when needed.

It's not glamorous. It's a hard job, but someone needs to do it. In fact, lots of someones need to do it. 

If I were to counsel someone who was interested in either entering the privacy profession or growing within it, there are three things I recommend:

  • Learn the technical aspect of the job. Yes, there are Information Security Professionals who generally originate in IT, but it would benefit the privacy professional to learn to speak intelligently about the technology.
  • Partner with the Information Security professional. This person should be your other half. They need to respect your knowledge and be able to depend on you and vice-versa.
  • Never think you know it all or that you are an expert. There is simply too much untested in the courts and much too much being changed every day - from laws to technology. 

I would not proclaim job security except when joking. Half the time I am afraid I am failing at the job because there is so much to do. The other half does a victory dance when a co-worker knows what the letters PII mean. It's the small things that make me happy - and the big things that keep me employed.

Thursday, March 27, 2014

Lessons from The Butler

Recently, we watched Lee Daniels' The Butler.

This was one of those movies I knew I could not watch in a theater, so I had planned to watch it at home. It was worth the wait. Forest Whitaker was the lead playing Cecil Gaines. At a young age in the cottonfields of Mississippi (1926), he watched his mother pulled into a shed by the farm owner, a Caucasian guy. Cecil's father objected after screams were heard from the shed and was shot for his insolence. The elderly white landowner took Cecil into the house to train him as a house worker (not even for the purposes of this blog will I use the horrible word I heard so much growing up). He was told that when he was in a room, it should feel empty.  After a few years, he left. He wound up working in a bar/restaurant who taught him to see what the customers want and provide it. Never be political. Never have an opinion. He then moved to a hotel in DC. Eventually, he was recruited for the White House during Eisenhower's term. He served through the Reagan term.

Throughout the movie, we also see the personal interactions with friends and family - his wife (played by Oprah Winfrey) who drank to cope, his oldest son who was a civil rights activist and often in and out of jail, and his youngest son who died in the Vietnam war.

So what lessons can we learn from the Butler?

Let's start with the premise of servants not existing - the room should feel empty. Many workers are unobtrusive. In fact, it does not even need to be a worker - people can be unobtrusive. Eventually, others forget or do not even notice they are there. It is an incredibly effective way to gain information. "Don't mind me...no one here....just discuss your deepest secrets." Can you imagine what this man learned serving the presidents, their wives, kids, the other politicians?  wow.

Some people perfect the art of listening and watching. Cecil learned to identify what the customers want and provide it before they themselves knew they wanted it. Discerning based on person, activity, mood, etc.

Gaines had issues with his wife who sometimes asked just for some little tidbit of inside information, like ho many shoes Jackie Kennedy had. Gaines would not tell her. However, it came out that one of the other butlers did tell his wife small things. Gaines seemed to have an issue with that sharing, but there was no evidence that these "breaches" were reported. And later in the movie, he did tell his wife that Mrs. Kennedy had about 125 pairs of shoes.

One thing Gaines learned from the bar.restaurant was to have two faces: one you showed when at work and one for your personal life. As a butler, he was expected to show no emotion, preference, or opinion. Two faces. He came face-to-face with that effect, if you'll forgive both the pun and the redundancy, when he was a guest at a state dinner at the Reagan's behest. He was served by his co-workers and saw the face directed towards him. He did not like facing the reality of who he was and/or what others saw him as. He was forced to hide himself in order to work. Rather than a public face and a private face, he had a private face for work and a real face for private.

Gaines took pride in his work. From the shoes he polished to the people he served and protected. And he was humble as a person, proud of his work, and willing to stand up for the right thing. He made mistakes and learned from them.

So there were some lessons to learn in The Butler. Perhaps some of the greatest events of our history occurred or were made in the presence of some very discrete individuals, who might not have even been noticed or even considered persons with equal rights.

Interesting movie. Interesting times. Interesting.

Thursday, March 13, 2014

My Privacy Heroes

I haven't written in a while, so please forgive me. Privacy issues remain daily headliners and I have no excuse for not writing. First, last week, I was at the International Association of privacy Professionals' Global Summit. It was sold out, which I think means a total of 3000 people attended. Wow.

I know, right? 3000 people from around the globe care about privacy. Yes, we are all dorks. But we're really cool dorks and have our own set of heroes and villains. Some of my own personal privacy heroes are listed below.

Dan Solove, John Marshall Harlan Research Professor of Law at the George Washington University Law School. He is a Senior Policy Advisor at Hogan Lovells. He is also the founder of TeachPrivacy, a company that provides privacy and data security training programs to businesses, schools, healthcare institutions, and other organizations. I had the privilege of getting to know Dan a little over the past two years and still have that little piece inside me that still squeals like a little girl simply because my privacy hero talks to me. The IAPP did a little blurb on me once (the link only works for those who log into IAPP, sorry) and soon thereafter, Dan sent me an email. Please understand that at the time, I probably had 5 articles and three books of his sitting on my desk. So I did a little happy dance before I calmly replied to him. I am happy to say that we have maintained a friendly relationship and I hope - I pray - to one day be on his level of competency.

Kirk Nahra a partner with Wiley Rein, LLC. Kirk has been involved with IAPP, I think since its inception. He has been on the IAPP's Board of Directors several times and currently serves as editor of the publications. I do not remember if I met him at a Blue Cross forum in Colorado or at an IAPP event, but either way, we seem to cross paths often, just not often enough. He sends out privacy law updates and observations - and frankly, is simply my most favorite U.S. privacy attorney.

Cass Sunstein is currently a professor at Harvard Law School and is a scholar beyond reproach. This is the only privacy hero I have that I do not know personally and have not met. I was supposed to hear him last year at a conference that my travel was cancelled due to weather. Oddly, I know more of him through my PhD program in Public Affairs than I do my privacy work. I would probably give my right kidney to talk with him for a hour or so (my right kidney is pretty shot, so that might not be a high enough payment).

So there is my list of heroes. I am not currently providing a list of villains, but let's just agree that most of them are corporate level, not individuals.

Tuesday, February 25, 2014

Cross-posted on IAPP
https://www.privacyassociation.org/publications/its_complicated_the_social_lives_of_networked_teens_does_not_shy_away_from 

How often have we heard or uttered the refrain that the newer generations—“Millennials” or “Generation Zs”—have no concept of privacy, that they live a life online devoid of personal restraint? I confess I have had that thought myself. So when asked to review danah boyd’s new book It’s Complicated: The Social Lives of Networked Teens, available through Yale University Press, I was delighted to do so.

This book was 10 years in the making and is dedicated to boyd’s friend, mentor and former professor, Peter Lyman. It is obvious throughout the book that boyd discusses some technological aspects that society may consider outdated, such as the social network MySpace, but boyd addresses this upfront. She disclaims early on, “The technical shifts that have taken place since I began this project—and in the time between me writing this book and you reading it—are important, but many of the arguments made in the following pages transcend particular technical moments, even if the specific examples used to illustrate those issues are locked in time.”

Boyd does not shy away from the tough subjects. It is apparent that she observed teenagers in their natural setting over a period of time. She also observed those people around teenagers and drew observations not only on the behavior or expectations of the youths but also the behavior and expectations of other youths and adults who interact with teenagers. In this book, boyd combines her personal observations with her research into technology, the Internet and social media to present a broad and insightful view of teenagers that might clash with the generally held belief about youth.

This book contains eight chapters, along with a hearty introduction. The chapters are presented topically and boyd skillfully weaves certain characters throughout the book, which provides a stabilizing effect. The chapters, which are bold incursions into topics many shy away from truly contemplating or speak about without true knowledge, are presented in a logical order.

Boyd first discusses teens’ search for identity online, which does not differ from their need to find their identity—only nowadays, a teen’s world is technology. She draws us into a world where teens’ identities are taken out of context because they do not necessarily create identities to satisfy all possible audiences. boyd writes, “Unlike face-to-face settings in which people took their bodies for granted, people who went online had to consciously create their digital presence.” She skillfully introduces us to the world of creating identities and managing impressions.

Next, boyd tackles the topic of privacy. Adults seem dismissive of teens’ awareness of the need for privacy, and, boyd writes, teens “have little patience for adults’ simplistic views about teen privacy.” She instructs us that teens achieve privacy by controlling their social situations and describes how they have learned to live with surveillance. boyd explains the concept of “social steganography,” in which teens conduct conversations and send messages in plain sight encoded to hide from adults or other teens. This segues nicely into the next chapter on social media, which boyd titles “addiction,” yet explains it is more of a necessary outlet that adults view as an unhealthy addiction due to its time demands.

Moving beyond the first three chapters, which provide a foundation upon which to explain and explore teens and social media, boyd examines the more controversial topics of teens online: dangers of being online, bullying and social inequality. She discusses these dangers frankly, without shying from the realities. She recommends that to keep our youth safe online, society needs to patrol digital streets with the same determination that is used to patrol real streets.

The last two chapters of the book are dedicated to understanding the world that teens now live in. She starts with examining the concept of “digital natives.” Boyd exhorts us all to be media-savvy, writing, “Learning is a lifelong process.” She concludes the book with a caution that media is not bad, it is a technology. It merely “mirrors and magnifies” the world we live in; it does not create it.

It’s Complicated: The Social Lives of Networked Teens was easy to read, applicable to the privacy field and full of interesting, well-considered research. The material was presented well and would appeal not only to those of us in the privacy profession but to some of the general public. I do not feel that it would appeal to all of the public, but what book does? My perspective stems from the depth of the material into which a reader sinks until some readers may be over their heads. But the material is so smooth that some readers might not realize they are over their heads until they turn a few pages and realize how deep they have gotten. However, as a past youth counselor, mother of teens and current privacy professional, I found the book riveting. And even I had to read it twice because the material is so rich. I did find the conclusion to be a little too cavalier given the seriousness that came before it. Agreed, our world is a technological one and we should approach its dangers and its benefits with our eyes wide open, but online there are challenges that require different approaches to those dangers and benefits. Yet, it is a remarkable feat boyd accomplished to link tangible experiences to digital ones and to enable us to relate teens’ current experiences with those of our youth. This takes the book to a new level of triumph.

I can do nothing less than highly recommend this book for those who have an interest in such fields—whether teens’ issues or privacy.

K Royal, CIPP/US, CIPP/E, is privacy counsel at Align Technology and has over 20 years of professional experience in the legal and health-related fields.

Read more by K Royal:
Book Review: The Future of Privacy