Wednesday, July 30, 2014

Sensitive Personal Information

Personally Identifying Information ("PII") is often defined by law. In the U.S., this generally occurs in sectoral law, such as the Health Information Portability and Accountability Act ("HIPAA").

But PII has layers, like an onion a la Shrek. There is your regular everyday PII, such as name, date of birth, and address. Then there is sensitive PII and sometimes even highly sensitive PII. These distinctions are generally found in countries other than the U.S. In addition, where sensitive information is being collected, there are generally laws or rules around having clear consent of the person to collect it as well as how this information can be stored, shared, used, transmitted, and protected. Let's explore these definitions and where they can be found.

For this exercise, I relied heavily on two publicly available resources:
What I am looking at here is what is considered sensitive PII ("sPII"). The laws or rules may not include a category of data called "sensitive personal information." For these purposes, if there are requirements to protect certain data at a higher level, then we will consider it "sensitive."

The typical definition of sPII, if there is such a thing, is: racial and ethnic origin, political opinions, religious, philosophical or moral beliefs, labor union membership, and information concerning health conditions or sexual habits or behavior. 

Most countries with a definition of sPII explicitly include the elements listed above or some statement in the law that anything that would cause discrimination against the person or that the government would consider to be private information. 

The European Union, in general, uses the definition above - they actually set the standard as the strongest multi-national privacy laws in the world. Some of their countries add criminal records, proceedings, and/or investigations to sPII. Switzerland goes a little further and includes social welfare programs along with government identifiers.

Argentina and the Republic of Turkey also use the definition above. Russia and Chile use most of the standard definition, but do not include trade unions.

Australia and Hungary build on the standard plus criminal definition above, but both add membership in a trade association. A trade association is like the American Medical Association, where individuals voluntarily or perhaps are required to join based on their profession. Interestingly, Hungary specifically includes "abnormal addictions" as sPII. Australia adds biometrics.

Speaking of biometrics, two other countries list that as sPII, along with the standard plus criminal elements: the Czech Republic and Azerbaijan. However, Azerbaijan goes on to include social welfare, domestic violence, taxes, marriage or family matters, and child adoption. Likewise, the Philippines take sPII to a more detailed level. In addition to the standard plus criminal definition, the Philippines add taxes, family or marriage matters, age, education, and government issued numbers.

Some of the more economically active Asian countries are strengthening their privacy laws. Commonly, these countries may not define sPII, but they do include general provisions that private data either is prohibited from being collected or deserves greater protection, without necessarily listing examples of sPII.  These nations include China, India, Indonesia, Japan, Malaysia, South Korea, Thailand, Taiwan, and Vietnam. Vietnam includes taxes and financial account information, while Japan includes financial data,  marriage and family matters, social status, and registered domicile. India includes biometrics and passwords. South Korea includes unique identifying numbers, such as passport numbers.

Although respect is a common foundation for privacy, many of the privacy protections in the Asian region are centered on this concept. An individual's personal information is expected to be respected and therefore, protected. So in many cases, sPII is simply afforded the same protection as regular PII.

A few other countries also do not necessarily define sPII, but require a judgment call on private information: Canada, Colombia, Egypt, Israel, and Mexico. Thus, everything discussed in this entry could be considered sensitive. (oh, Israel considers information about one's personality to be sPII.)

And last, keep in mind, in nearly all cases if there is something not specifically listed in the law that would be discriminatory to the individual or disclose highly personal information, you should err on the side of caution and protect that information.








Thursday, July 3, 2014

EU Approves Align Technology, Inc. as BCRs Enter Their "Golden Age."

From the IAPP

Medical device manufacturer one of just a handful to get approval as both controller and processor

June 26, 2014
By Angelique Carson, CIPP/US

With Safe Harbor constantly under fire, the binding corporate rules (BCR) process is becoming an increasingly attractive way for companies to ensure their ability to transfer data out of the European Union. This week, Align Technology, a U.S. medical device company, entered an exclusive club when its BCR application as both a data controller and a data processor was approved by EU data protection authorities.

As K Royal, CIPP/US, CIPP/E, Align’s first dedicated privacy officer, can tell you. It wasn’t an easy process, but she’s confident it’s been time and money well spent.

Despite various champions’ sweat-inducing work to keep Safe Harbor afloat, it’s becoming increasingly difficult to find days of the week that don’t feature headlines from one side of the pond or the other on its impending doom. While the U.S. Department of Commerce and regulators like the Federal Trade Commission’s Julie Brill have indeed invested time and resources in quelling Europeans’ skepticism (at best) or downright distrust (at worst) of the data transfer mechanism, the Snowden revelations’ significant impact on any trust  Europeans had in the U.S. on data protection and privacy can’t be denied by anyone who’s been paying attention.

So while EU Justice Commissioner Viviane Reding and her team conduct a review of Safe Harbor and the European Court of Justice prepares to rule on its scope, companies hoping to seal international deals aren’t taking chances. For that reason among others, BCRs are becoming an increasingly attractive alternative, as promoted recently by Eduardo Ustaran, CIPP/E, in his blog post, “Five Reasons To Do BCRs Now.”  

Align Technology brought on Royal just as the European government was setting forth its plans to update the European data protection regulation. Align had just gone through an internal privacy review and was looking to improve its privacy program. While the U.S.-EU Safe Harbor agreement was the initial plan, Align soon realized a BCR regime would establish compliance with a multitude of privacy laws in one fell swoop—COPPA, HIPAA, etc. With the ability to register as both a controller and a processor under the BCR framework established in 2012, Royal and her team were among the first to wind their way through the process.

Making the Case for BCRs at Your Company

No, it wasn’t easy, Royal admits. It took a year to negotiate the terms, and Royal had to be creative in how she would effect change at Align in order to satisfy the BCR requirements.  Plus, she was new at the company, and she had a lot to learn—from the ground up—about how Align’s processes worked.

The good news was that Royal’s case for BCRs was supported by Align’s executives and board of directors, who understood that while other data transfer mechanisms might be easier to implement, they were looking for the “right” solution, and not necessarily the easiest one.

“Privacy departments typically don’t get big budgets or lots of project time,” said Royal. “If you want a project done or you approach to change a system, privacy is not generally high on the business priority list.”

She had some help, though.

The HITECH Act was in play, for example, which applies to business associates like Align. Couple that with the Snowden revelations and a flurry of massive breach headlines within the last year or so, and Royal had a case. 

“The more bad news other people make, the better it is for those of us trying to get this done,” she said.

Bolstered by the headlines, Royal took sort of a backdoor approach to getting things done. Rather than try to dictate terms from the top down, she jumped on Align’s project team and worked with them from the start.

“Every project that went through, we used that opportunity to leverage or put in place more privacy,” she said. “We kind of built that in; we baked it into the portfolio.” For critical privacy projects, Royal says she had to prioritize projects in order to get the support she needed to get them done.

The BCR process was particularly difficult for Royal because of the company’s youth and aggressive forward march. The focus is innovation, making products better.

“We’re in the technology field, we’re in the medical device field, we’re regulated by the FDA,” she said, adding that the company acts “very much the way one imagines an innovative, technology-focused Silicon Valley company would act. The priorities are centered around the products,” and less about the policies that guide the product development.

But that’s where Royal came in.

She relied heavily on Align’s project engineers, its information security officer and the IT team. The process required weekly meetings, which was a heavy lift. Additionally, Align had previously developed a cross-functional team that serves as the Privacy Working Group.

In late 2012, Royal’s boss, the VP of litigation and regulatory affairs, flew to Europe to meet with the lead data protection regulators in person, feeling it would be a good thing to do early on.

“We said, ‘We want to do BCRs for processors,’ and they said ‘Here’s what to do,’” Royal said, adding that the in-person visit “really went far in helping us when the application came around.”

In the year between the date Align filed the BCR application and it being “closed,” multiple revisions were made to each of the policies submitted. But Royal said the lead European regulators who worked with Align—the Netherlands, as the lead authority, and the UK and Italy—took a very practical approach to the process and understood that the policies and procedures Align would promise to comply with may not be in place from the jump. It was more important to them that the wheels for such processes be in motion, rather than such processes be completely perfect.  

“For example, one policy states that we’ll train toward the BCR policies,” Royal said, but “you can’t train toward them until the policies are approved.”

The Golden Age of BCRs

Phil Lee, CIPP/E, CIPM, partner at law firm Fieldfisher, who counseled Align through the BCR application process, said BCRs are entering a “Golden Age” and for a couple of reasons. First, the Snowden revelations, after which his firm saw an “exponential uptick” in the number of applications for BCRs. Indeed, when Royal started the process for Align, she noted there were 19 companies approved for BCRs. When she’d completed the process, there were 53.

“With Safe Harbor, we’re getting clients who are making deals and having customers refuse to sign unless they do something other than Safe Harbor,” Lee said. “It doesn’t matter that Safe Harbor is still legal, they just don’t like it because they’re nervous about it.” He added that in particular, the cloud industry is reaching for BCRs.

Second, BCRs are so comprehensive, they aren’t only a data export solution, but the foundation for a global privacy program itself, capable of helping firms achieve compliance all over the world—beyond just the EU and U.S.

Want to Apply for BCRs? Take a Deep Breath

“Don’t be daunted,” Lee said. “BCRs are actually a very straight forward process to go through. The guidance is overwhelming and makes it appear far more daunting than it is.”

But the process has become increasingly streamlined as EU regulators have become more familiar with their shape. And besides, for companies who are employing responsible data protection policies, it’s more about capturing those policies in documented form.

Since Align has gained approval, Royal has been focused on doing personal training for every department at the company. Asked what advice she’d give to a company looking to go through this process themselves, Royal said privacy pros should leverage projects that are based on business needs rather than privacy alone.

Royal said BCRs had executive sponsorship and approval from the board, so when there were setbacks, she could leverage that executive approval.

“But you have to use that power sparingly and strategically,” she said. “Most projects were accomplished by finding where privacy fit within those projects based on business needs.”

Sunday, May 18, 2014

Why you should not sign everything put in front of you: HIPAA Business Associate Agreements

courtesy of backstage.com

The Health Insurance Portability and Accountability Act of 1996 and its subsequent amendments ("HIPAA") includes the contractual arrangements between Covered Entities and Business Associates, and now downstream Business Associates, or subcontractors (under the Health Information Technology for Economic and Clinical Health Act "HITECH").

This entry presumes the reader has a basic knowledge of HIPAA, but if not, please see the above link for HIPAA.

Today, we look at the evolving and complicated nature of Business Associate Agreements ("BAAs"). These are the agreements mandated by HIPAA, and now HITECH, although the recent amendments and the preamble make clear that the requirements of HIPAA and the HITECH Act apply to a Subcontractor regardless of whether the Business Associate fails to enter into a contract with the Subcontractor. This is very important below when we cover some of the complications.

First:
HIPAA requires certain provisions to be covered in BAAs. Often, the Covered Entity will put in additional provisions, usually around indemnity, audits, breach notification timelines, and data protection minimums not required by HIPAA, such as encryption.  These provisions are unduly burdensome, especially given the characteristics of most Business Associates - small operations. It is understandable why an entity would want to put these protections in place, but it may may stifle the ability to outsource and place a strain on relationships.

Second:
It is understandable why the government wants to reach further than Covered Entities and have direct oversight of Business Associates. Think about it, Dr. Jones on the neighborhood corner may not have the wherewithal to properly secure data or to respond to breaches. Or given that the new provisions provide for the State Attorneys General to bring civil actions on behalf of state residents for HIPAA violations, for damages or to enjoin further violations. I once had a privacy attorney argue with me via email (which cc'd numerous colleagues) that HIPAA as amended by HITECH absolutely did not provide for a private right of action. Well, duh - but given that the states can now do so on behalf of its citizens...it is practically the same thing. But I understand, in the law, one must be precise.

Third:
Large organizations that are now clearly defined as Business Associates, according to the guidance issued with the final rules, at first stated they would not sign BAAs. Remember above, where the new rules provide for liability whether a BAA is signed or not...?  Well, their refusal did not last long. See a discussion about Amazon Web Services here. What large providers who do not wish to be rolled under HIPAA have done, is placed administrative requirements on the Covered Entities or Business Associates which use their services, such as list all accounts for which they have patient data. Many organizations are unable to fulfill these requirements. So what is the solution - sign something they cannot fulfill or don't sign and HIPAA applies anyway. This is yet to be tested, but it is a popular conundrum.

Organizations should be careful about signing any old BAA placed in front of them. Watch your salespeople, too. They are likely presented individual BAAs when they show -  either the BAA does not apply or the employees are committing the company to a BAA without proper review. And this can be costly given the additional items that are in a BAA as discussed above.  And how can an organization signing tens or hundreds of BAAs possibly manage to push all the same provisions to downstream vendors? They conflict with each other - and Covered Entities need to understand that with the additions of clauses that are not required by HIPAA, they are setting their Business Associates up for failure.

Last, many small business owners that are Covered Entities do not understand HIPAA completely. Heck, neither do I. After a professional conference, Business Associates or potential Business Associates will be deluged with requests to sign BAAs. Sometimes, the exact same template is used, including with various clauses that include internal directions such as [choose one of the two clauses below]. It can be frustrating on all sides. Most individuals, however, are just trying to do the right thing. If a Covered Entity wants an organization to sign a BAA and the relationship does not exist, the organization can easily respond with a tight explanation. If still pushed, adding a line such as "This agreement only applies where the organization acts in the capacity of a Business Associate under HIPAA" will generally satisfy the needs of both sides. This is another untested, yet relatively popular strategy.

The conclusion here is that you should not sign everything put in front of you - or your employees. Educate all individuals to send the BAAs to a central office. Push back, or scale back, non-HIPAA provisions. It will be interesting to see how these natural conflicts play out in the next few years.



Tuesday, April 29, 2014

Hummingbirds and Platypuses: Terminology Matters

In the first grade, I was sent to second grade for math classes. I was five. I was close to the youngest person in my school for first grade (simply due to my birthday being in December), so many of my classmates were already a year older than I was, and second graders were two or more years older than that. One day, the teacher told us "No talking." So I whispered. My verbal logistics were well-rewarded with the only time-out I ever had in school. I explained that whispering is not talking, but she was having none of it. 

In a poorly worded segue, let's transition to a deposition. In 2010, an Ohio Supreme Court case contained a ten-page argument over the meaning of the word "photocopier" from a deposition of the head of IT of a county recorder's officer. You can watch a verbatim reenactment of the transcript here. It is well worth the time, for attorneys, IT, or laymen. Both sides seem slightly ridiculous, but also logical.

Second poor segue alert (but stay with me...it all comes together): That is a problem we have with technology and law. We use terms that when in question can have minute differences that matter. The word makes sense. The concept makes sense. People generally understand what the intent is with the law, but when trying to determine whether a specific technology or its use falls within or outside the law, it becomes quite complicated.

For example, let's play off the transcript above. If there is a rule that a document cannot be photocopied - we know it means, no copying of the document, right? Or does it? Does it mean no photostatic copies - or no digital scanning? or who knows, someone may have an old carbon copying machine lying around just waiting to be used to circumvent the new rule.

Words have meaning and technology is testing the ultimate limits of the words used in our current laws. Courts do their best to interpret law based on its intent, but that intent can usually only be present if the way in which something functions can be imagined (Constitutional wording aside - that is a whole 'nother argument). And sometimes, if the intent can be inferred - or is even explicit - the wording of the law/rule/regulation/guidance is so ambiguous that the courts can do nothing but decide against what seems to be fair to a layman.

This is where data protection and privacy seem to reside. Technology and its resulting misuse far outstrips the incremental changes in law. We're not even talking cigarette boats vs. paddle boats. We're talking hummingbirds vs. platypuses (platypi was incorrect). They exist on the same world and breathe the same air, but they probably do not play well together - seriously, a platypus could squash the hummingbird, but the hummingbird moves too fast for the platypus to catch. Hummingbirds might not even notice the platypus exists! Hummingbirds are stunning to observe and need to keep moving. Platypuses need to be protected and well-grounded. One can absolutely exist without the other, but both need to co-exist with humanity. (wow, this analogy really works all the way through for technology and privacy.)

(and five-year-olds who play with words just might become attorneys.)


Tuesday, April 22, 2014

InBloom: Seeded before its time

Yesterday, inBloom (non-profit education software company) announced its plans to wind down operations over the next few months due to objections by parents and legislators. Adults became concerned about putting in too much information into this database (400 fields), such as students' social security numbers, details about school withdrawals, and family relationships. This month, New York passed legislation prohibiting their department of education from providing data to aggregators (like InBloom).

In mid-November of last year, parents in New York petitioned for a restraining order against the state department of education preventing them from providing student data to inBloom. Parents cited that providing this information was a dramatic departure from the then current practice and seemed to be taking steps backwards in terms of privacy.

inBloom describes its mission and goals as:
"a set of shared technology services that includes a secure, multi-tenant data store and middleware for identity management and data integration . . .  designed to help School Districts and State Educational Agencies provide educators, parents, elementary and secondary school students with learning data from many sources and connect them to relevant instructional resources to support personalized learning through inBloom. The service also helps State Educational Agencies in evaluating federal- and state-supported education programs."

The goal was to provide  "districts and states as a utility for them to more easily synchronize and transfer data, including student personally identifiable information (PII), across the various learning applications they deploy to teachers, students, and families."

So now it ends. inBloom is Out. 

But let's think about this for a few moments...

Is the population of the United States seriously considering the privacy rights of its vulnerable citizens? What?? This turns my privacy meter on its head. Since when did we care what information we share as long as no one gets hurt. What harm can come from this type of data aggregation? It's not like inBloom was going to turn over its education records to the department of child services to show that certain students had certain educational challenges - or home challenges that interfered with education. Data would not be misused or misinterpreted, right? Or shared with watchdog groups or even governmental agents who would put a spin on the data that might adversely affect students, families, school districts, or state funding, right?

Good googli moo

Thursday, April 10, 2014

Privacy: Don't let it go (our take on the ubiquitous song)

Information is shared around the world today
With a few data laws to be seen
One might wish for regulation
So do I, the Privacy Queen

Companies collect data like a swirling storm inside
Couldn’t keep them straight, heaven knows we’ve tried

Don’t let them in, don’t let them see
Be the private person you always want to be
Conceal, don’t reveal, don’t let them know
How much do they know?

Don’t let it go, don’t let it go
We can stop it furthermore
Don’t let it go, don’t let it go
Block cookies and slam the door

Someone should care
What they’re going to say
The argument rages on
Cause breaches don’t bother them anyway

It’s great how some countries protect personal data by law
And the companies that once controlled it can’t get to it at all

It’s time to see what we can do
To test the limits and break through
Do right, not wrong, pass data laws
For all

Don’t let it go, don’t let it go
Pass some laws and rules
Don’t let it go, don’t let it go
Scrap those data tools

Take a stand, the data stays
Let your rights rage on

Big data flurries through the web and into the ground
Information spirals in millions of bits all around
And one thought crystallizes like an icy blast
Data is rarely deleted – the past is never past

Don’t let it go, don’t let it go
New uses rise like the breaking of the dawn
Don’t let it go, don’t let it go
Once given, that data’s gone

Take a stand
In this big data reign
Should data brokers rage on?
Privacy never stopped them anyway



Thursday, April 3, 2014

Job Security?

In 2013 at the IAPP fall conference, Lisa Sotto (a renowned privacy and cybersecurity attorney with Hunton & Williams and member of the Board for IAPP) remarked during an open session to the attendees that if she heard one more person exclaim "Job Security" she might have to punch them - I may be paraphrasing. I think she was kidding. But she was not exaggerating the repetitiveness of the sentiment by the attendees.

Is there job security for privacy professionals?  Probably yes. Oh, what the heck - let's abandon the pretense of being objective: yes. Yes. YES!  The world of privacy and data protection is growing by leaps and bounds. And not just in one area of the globe. Privacy and data protection is growing everywhere.

You may recall the somewhat recent headlines containing words like Snowden, NSA, and leak. These headlines, or rather the actions behind them, have created some additional headlines involving European Union and the U.S. trade. I will not address whether Snowden is a hero or a traitor - or whether what he did is even right or wrong. The end result is that the European Commission and various data protection authorities seemed to question their faith in the U.S./EU Safe Harbor program.

I do not really believe that the EU will completely withdraw it's determination in the adequacy of the Safe Harbor program if only because international trade would suffer tremendously. But on the other hand, I would not brush off their concerns either. Recently, the U.S. FTC Commissioner and the U.K.'s Information Commissioner signed a memorandum of understanding to work together to protect the privacy rights of consumers. Rather contemporaneously, the FTC initiated actions against 13 U.S. companies for violations of their safe harbor certification statements, as this author wrote about in an earlier post. So international cooperation is on the table and probably not disappearing anytime soon although there is a lot of work to be done.

Which segues rather nicely back to job security. Privacy is probably the hottest area of law right now, but privacy professionals can not allow themselves to get cocky or complaisant. We must be strategists and visionaries; we must foster understanding and better understand the business case; and we must see the trees and the forest. Privacy law is growing faster than any one person can track. There are multiple think tanks and watch dog groups dedicated to the topic.

I laugh - usually out loud - when I hear other compliance professionals complain that they run from fire to fire. We all do. It's the nature of compliance. I dream of a day when I am notified that some area is suffering a drought and we can proclaim a high alert for the potential for fire. And even ban burning. Ha. Are you following me in this analogy?  Privacy professionals are like the forest rangers on lookout towers. There is a lot of landscape to watch, we are usually alone, we have to track winds, investigate smoke, and be able to call the troops when needed....but only when needed.

It's not glamorous. It's a hard job, but someone needs to do it. In fact, lots of someones need to do it. 

If I were to counsel someone who was interested in either entering the privacy profession or growing within it, there are three things I recommend:

  • Learn the technical aspect of the job. Yes, there are Information Security Professionals who generally originate in IT, but it would benefit the privacy professional to learn to speak intelligently about the technology.
  • Partner with the Information Security professional. This person should be your other half. They need to respect your knowledge and be able to depend on you and vice-versa.
  • Never think you know it all or that you are an expert. There is simply too much untested in the courts and much too much being changed every day - from laws to technology. 

I would not proclaim job security except when joking. Half the time I am afraid I am failing at the job because there is so much to do. The other half does a victory dance when a co-worker knows what the letters PII mean. It's the small things that make me happy - and the big things that keep me employed.