Wednesday, 9 March 2011
EU police report shows holes in US data deal
Read more here: http://euobserver.com/9/31947/?rk=1
Friday, 5 November 2010
EU to press for 'right to be forgotten' online
The Facebook generation knows it. Everything you've posted online can and will be used against you at some point. People have been fired for the party pictures or unthoughtful jokes they've posted online.
Deleting a Facebook account does not help. According to the popular website, users can "reactivate" their accounts at any time: Facebook does not erase your data, its simply hides it from others.
In a bid to stem these developments, the commission is now revising a 15-year-old "Data Protection Directive," drafted before the Google and Facebook booms. New legislative proposals are set to be put forward mid-2011, but the commission has already adopted a "strategy" on how to go about the changes.
One of the principles mentioned is the "right to be forgotten" online, meaning that people who want their online profiles deleted "should be able to rely on the service provider to remove personal data, such as photos, completely
Seen from the American perspective, businesses find it difficult to navigate between the EU laws and the patchwork of national data protection requirements, one US official familiar with this dossier told EUobserver.
"The lack of harmonisation among the member states in terms of interpreting the directive and transposing the directive into national laws led to uncertainty among compliance officers, privacy officers, and legal counsel. These ambiguities result in confusion and a lack of clarity with regard to obligations the business community must meet," said the official, who requested not to be named.
Read the full article here: http://euobserver.com/9/31200/?rk=1
Friday, 13 November 2009
EU stalls bank data deal with US ahead of Lisbon Treaty
Citing data privacy concerns, Germany, Austria, France and Finland are opposing the text negotiated by the Swedish EU presidency and the European Commission allowing American authorities access to information from the Society for Worldwide Interbank Financial Telecommunication (Swift) - the interbank transfer service.
Read the article here: http://euobserver.com/9/28984/?rk=1
Wednesday, 15 April 2009
"Personal data - more use, more protection?", 19-20 May 2009
How should personal data be protected in a globalised world with increased mobility and in the wake of modern communication and information technologies and new policies? Which data is accessed and exchanged by public authorities and private companies? How well are current rules on international transfers of personal data working in a time of “cloud computing”? What are the expectations of individuals and business and society as a whole? These and other topical questions will be addressed by a conference on the use, exchange and protection of personal data in the EU, organised by the European Commission, which will take place in Brussels on 19 and 20 May 2009.
Interested individuals, business leaders, consumer associations, academics, data protection supervisors and public authorities from both the EU and third countries are invited to take part.
Among the speakers will be the Vice-president of the European Commission in charge of Justice, Freedom and Security, Mr Jacques Barrot.
The conference will give the opportunity to various stakeholders to express their views and questions on the new challenges for data protection and the need for an effective information management strategy in the EU. The conference is part of the Commission’s open consultation on how the fundamental right to protection of personal data can be further developed and effectively respected, in particular in the area of freedom, justice and security.
Interpretation will be provided in English, French and German.
http://ec.europa.eu/justice_home/news/events/news_events_en.htm
Wednesday, 1 April 2009
EU must get tough on data protection says commissioner
Speaking in Brussels on Tuesday, she said her hardline comments should be seen as a last chance warning to the industry to clean up its act.
She told an audience there was a "much-needed" debate on the increasing ability to profile consumers and then use their details for commercial purposes.
Research showed that young people - "the most confident of internet users" - use the internet in spite of the fact that they generally do not trust it, she said.
She told the meeting, "Let me be very clear from the start [that] I believe the internet and the new generation of digital communications offer immense possibilities to consumers."The regulatory protection we have in Europe is extensive and far-reaching [although] there is a huge task ahead of us in terms of enforcement of the rules.
"The Bulgarian official predicted that "behavioural targeting" online "become increasingly pervasive and consumers understandably feel uncomfortable".
"Today, I want to send a very clear message to those involved in all aspects of the digital world - consumer rights must adapt to technology, not be crushed by it," she added.
"The current situation with regard to privacy, profiling and targeting is not satisfactory."Kuneva added, "It is regulators that bear the ultimate responsibility of ensuring markets work well and develop their greatest potential with the interest of citizens at heart.
"I want to send a warning signal that we cannot afford foot dragging in this area. If we fail to see an adequate response to consumers' concerns on the issue of data collection and profiling, as a regulator, we will not shy away from out duties nor wait for a cataclysm to wake us up.
"The commissioner was the keynote speaker at a roundtable debate in Brussels on the issue of online data collection and profiling.
Kuneva later appeared before a conference in parliament on "EU consumer protection policies - market or regulation?" The event, co-hosted by ALDE MEP Silvana Koch- Mehrin, focused on the expansion of consumer protection rules.
Source: TheParliament.com
Friday, 20 March 2009
Frequently asked questions relating to transfers of personal data from the EU/EEA to third countries
Download the document here: http://ec.europa.eu/justice_home/fsj/privacy/docs/international_transfers_faq/international_transfers_faq.pdf
Tuesday, 17 March 2009
EDPS second Opinion on ePrivacy Directive review and security breach
This Second Opinion comes as a response to the Council's Common Position which, on a number of critical points, fails to endorse some of the data protection safeguards proposed by the European Parliament and the European Commission, or previously recommended by the EDPS.
The Opinion particularly focuses on the provisions relating to the setting up of a mandatory security breach notification system for which the Supervisor believes there is still some room for improvement. It also includes a number of recommendations covering the following issues:
scope of application : the EDPS supports the Parliament's approach to broaden the scope of application of the Directive to include publicly accessible private networks in the Community. He recommends to further clarify the types of services that would be covered by the broadened scope; processing of traffic data for security purposes : the EDPS considers the new article introduced by the Parliament - and maintained by the Council's Common Position and the Commission's Amended Proposal - legitimising the collection of traffic data for security purpose as being unnecessary. In the EDPS view, such a provision may be subject to risk of abuse, especially if adopted in a form that does not include the necessary data protection safeguards;
right of action against infringements to the Directive : the EDPS calls upon the Commission and the Council to endorse the provision introduced by the Parliament that gives the possibility to legal entities, such as consumer associations, to bring legal action against infringements of any provisions of the Directive.
> EDPS Opinion (pdf)
New mandate for the EDPS: Peter Hustinx reappointed as Supervisor, Giovanni Buttarelli appointed as Assistant Supervisor
The new EDPS and Assistant EDPS formally took office on 17 January 2009.
Peter Hustinx has served as EDPS since January 2004, contributing to the building of the new supervisory authority and developing its role at Community level. Information on Peter Hustinx's background is available on the EDPS website.
Giovanni Buttarelli has been a member of the Italian judiciary since 1986, and Secretary General of the Italian Data Protection Authority since 1997. In 2002-2003, he served as President of the Joint Supervisory Authority set up in pursuance of the Schengen Agreement, after being its Vice-President in 2000-2001. He has represented Italy in many committees and working groups operating in the field of data protection, both at the level of the European Union (EU) and at the Council of Europe.
> EDPS press release (pdf)
Wednesday, 18 February 2009
EU Data protection group publishes pre-trial discovery guidance
This working document provides guidance to data controllers subject to EU Law in dealing
with requests to transfer personal data to another jurisdiction for use in civil litigation. The
Working Party has issued this document to address its concern that there are different applications of Directive 95/46 (Data Protection Directive) in part as a result of the variety of approaches to civil litigation across the Member States.
In the first section of this document the Working Party briefly sets out the differences in
attitudes to litigation and in particular the pre-trial discovery process between common law
jurisdictions such as the United States and the United Kingdom and civil code jurisdictions.
The document goes on to set out guidelines for EU data controllers when trying to reconcile the demands of the litigation process in a foreign jurisdiction with the data protection obligations of Directive 95/46.
Download the full document here: http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2009/wp158_en.pdf
Thursday, 12 February 2009
Commission dismantles data watchdog group
The European Commission has disbanded a group of experts that was supposed to review EU data protection legislation, following complaints in the French parliament that the body comprised people “representing American interests”.
The group of five experts, one of whom works for Google and another for Intel, was disbanded at the end of January – just over a month after the group first met – despite having been set up for a one-year renewable term. Alex Türk, a French senator and the chairman of data protection supervisors from the 27 member states, is understood to have complained about the group to Jacques Barrot, his compatriot, who is the European commissioner for justice, freedom and security.
French senate
Türk had raised the matter on 25 November in the French national assembly's European affairs committee and then raised it again in the French senate's equivalent committee last week (3 February). The senate committee was told that the group of experts was “composed of four-fifths of personalities representing American interests in order to reflect on the revision of the European directive of 1995 relating to the protection of personal data”, according to a report from the hearing on the French senate's website.
The committee proposed a resolution stating that it was “unacceptable” that four members of the group “are either from American companies or law firms whose principal establishment is in the US”.
Working language
The resolution also said that it was unacceptable that the working language of the group was English, as set down in its terms of reference.
Türk told the senate committee that he had spoken to Barrot about the group and he had admitted the “situation was abnormal”. Barrot had suggested forming a larger group of experts, but had yet to confirm if this could be done, Türk added. “Europeans must note that the gap is big between the American vision and the European vision,” Türk told the committee.
A spokesman for Barrot denied that any pressure was put on the commissioner to disband the group. He said that Barrot had wanted to broaden the consultation on the review of data protection laws beyond a small group of experts. “We were happy with passing on to the next level and a broader dimension was clearly seen. It's in the sense of having a broader approach,” he said. A letter dated 23 January from Barrot to Türk refers to the broader consultation and a series of conferences, adding that the expert group “will not last beyond the launch” of such a consultation.
Barrot's spokesman said that it was not unusual for an expert group set up by the Commission with a one-year mandate to be disbanded after one meeting.
‘No nationality issue'
The spokesman also denied the composition of the group and the nationality of the experts had any bearing on the decision to disband it. “You have to gather expertise in this globalised technical field and have people that can reflect and have knowledge of new technology,” he said.
The group's experts, who were not paid for their services, were selected after a tendering process and included: Peter Fleischer, global privacy counsel for Google; David Hoffman, director of security policy and global privacy officer for Intel; Henriette Tielemans a privacy lawyer with Covington and Burling, a US law firm; Christopher Kuner, a privacy lawyer with Hunton and Williams, a US law firm; and Jacob Kohnstamm, chairman of the Dutch data protection authority.
Information listing the members of the group and the text of the tendering process were taken off the Commission's website this week without any mention that the group had been disbanded.
Source: European Voice
Thursday, 29 January 2009
EU mulls new data protection initiatives
As Europe celebrated its third 'data protection day' yesterday (28 January), the European Commission announced plans to tighten the relevant rules. Meanwhile, EU privacy authorities are focusing on Internet search engines' data storage and street viewing software.
Brussels will launch a Europe-wide public consultation by April on how to reinforce data protection. "We have to reflect on the possible necessity of modernising the existing legal framework to respond to the challenges posed by new technologies," said EU Justice and Home Affairs Commissioner Jacques Barrot during a conference in the European Parliament yesterday (28 January).
An expert group set up by the Commission is currently studying possible innovations that could help update the Data Protection Directive , which dates back to 1995. Many issues are at stake, including extending the concept of personal data to IP addresses and cookies, which allow very detailed profiles of Internet surfers to be created, although they only provide indirect identification of users (EurActiv 05/12/08).
National privacy regulators have already issued an opinion in favour of broadening the list of personal data to include IP addresses and cookies. They will further discuss the issue at their next meeting on 10-11 February, when they will also address the duration of data retention by search engines.
Google, Yahoo, and MSN store information (cookies) on Web users' computers. By retrieving the cookies, they put together detailed profiles of users every time they access the Web. This improves the quality of services offered: thanks to cookies, there is no need to retype passwords in accessing a restricted area, for example. However, such data reveals much about the user, and it is often used for sending unsolicited and targeted advertising.
EU data protection authorities, brought together in the 'Article 29 Working Party', proposed a six-month retention period for cookies. Search engines offered various reactions to the plans. Google, whose business model is highly reliant on personal data, voluntarily cut its retention period from 18 to nine months. Microsoft abided by the six-month proposal, seizing upon it as a possible standard for the industry (EurActiv 10/09/08).
Representatives of the two US giants will participate in the data protection meeting in February, together with delegates from Yahoo, and Ixquick. No decisions are expected to be taken at the meeting, but a new opinion on the issue from the Article 29 Working Party is expected in the coming months, according to sources close to the dossier.
The other delicate subject on EU privacy authorities' table in the coming months is the potential risks posed by "panoramic street-level view services," made famous by the Google's successful Street View. Such software makes it possible to look at cities right down to street level, with cars, people and shops.
First introduced in the US, Street View has already been launched in France, Italy and Spain. EU regulators discussed the service, "as it raises privacy and data protection concerns," according to a press release recently issued by the Article 29 Working Party.
Google blurs faces, car plates and other features that could allow the identification of people, but problems could arise from the storage of the massive amount of pictures required to enable the service and which Google has already collected. "Data protection rules might be applicable," the European data protection supervisor, Peter Hustinx told EurActiv.
In such a case, Google must ask the prior consent of those who appear in the pictures, even if blurred. The service could thus find itself hit heavily. "We will work with all relevant institutions and authorities and we look forward to providing any additional information that may be requested," commented Peter Fleischer, global privacy counsel at Google.
To celebrate the third data protection day, a conference was held yesterday (28 January) in the European Parliament to raise awareness among young people of the privacy and security risks hidden in the Internet.
As underlined by Barrot, "in the 15-24 age group, only 33% are aware of their rights in relation to their own personal data," despite being the main users of the Internet and social networking websites, such as MySpace or Facebook. "They are exposing their everyday lives online without being aware of the risks the online activities could entail," he said.
Thursday, 15 January 2009
EU to launch biometric passports by summer
MEPs on Wednesday (14 January) backed new rules on the introduction of biometric passports throughout the EU later this year, while exempting children under 12 years from having fingerprints included in their passports.
The rules were approved at a first reading by an overwhelming majority of MEPs – 594 against 51, while 37 abstained.
The parliamentarians underlined the need to improve document security in the EU by introducing "more reliable biometric data, namely fingerprints," and highlighted the different criteria member states currently apply when checking the passport applicants' identity.
Continue reading here: http://euobserver.com/9/27407/?rk=1
Thursday, 20 November 2008
ARMA's 3rd Brussels Roundtable brings together top policy makers, stakeholders and RIM professionals
Douglas Allen, President-Elect of ARMA International, opened the roundtable by addressing the need for good records management in view of the financial crisis which was in large part due to lack of transparency. He mentioned recent security breaches in Europe to underline that information have become corporate assets of critical importance and growing risk areas and that sound records management should be the responsibility of all individuals within an organisation.
Towards a European Freedom of Information Act
Mr. Marc Maes from the Secretariat-General of the European Commission gave first a short presentation of the history of the right of access to documents. He provided an overview of the current version of the Regulation 1049/2001 regarding the beneficiaries, scope and limits of the right of access to documents.
He also presented the situation of third party documents that should be transmitted after the consultation of the author unless it is clear that the document should be transmitted. He stressed that the institutions who received a request should decide on the basis of the exceptions to this right and other institutions are consulted under a memorandum of understanding.
Mr Maes gave an overview of the proposal to review the Regulation 1049/2001 that was published on 30 April 2008 on which ARMA replied to a consultation following the publication of a Green Paper and drafted a position paper. He pointed out in particular the main features of the definition of the term document and presented the main limitations to the scope of the Regulation. Finally, he mentioned the latest case laws on access to documents.
Mr. Fergal O’Regan, Head of Legal Unit at the European Ombudsman’s office addressed the main concerns of this organisation regarding the review of the Regulation 1049/2001.
He pointed out that the wording used in the definition of the term document is the main concern of the Ombudsman. He wondered if the term “formally transmitted” means documents transmitted within or outside the institutions or if this definition should be understood as including informal transmission. In its position paper on the review of the Regulation 1049/2001 ARMA International expressed that this definition should be revised to be more in line with document and records definitions included in international recognized standards in information management such as ISO 15489.
Mr. Hielke Hijmans from the European Data Protection Supervisor (EDPS) office explained the role of the EDPS in case law related to access to documents. He stressed that the fundamental right of access to documents sometimes clashes with the fundamental right to privacy. He pointed out that the review of the Regulation 1049/2001 does not find the right balance between access to documents and privacy as its provisions does not ensure that disclosure can only be denied if the privacy or the integrity of a person would be undermined.
The Markets in Financial Instruments Directive (MiFID)
Mr. Salvatore Gnoni from the Directorate-General Internal Market and Services of the European Commission gave a wide overview of MiFID. He also discussed the MiFID provisions regarding transparency, transactions reporting and record keeping.
As regards transparency requirements, he explained that the market transparency regime concerns pre- and post-trade information and covers shares admitted on a regulated market while the transaction reporting regime covers all securities and derivative contracts admitted on a regulated market.
He stressed that investment firms should report details of their transactions to their national authorities and that these authorities should share information among themselves.
Investment firms should keep records of their transactions for a general period of 5 years in order to keep them at the disposal of the competent authorities. He quoted a recommendation from the CESR (Committee of European Securities Regulators) which provides a list of minimum records and explained that Member States can keep records of telephone conversation or electronic communications which can be used in order to show that investment firms comply with record keeping requirements.
Mr. Jitz Desai, Director of JWG-IT, pointed out the difficulties of firms to comply with MiFID requirements regarding record keeping as these new obligations are among the EU implementation priorities. Consequently, a short period of time is at the disposal of firms to comply with the Directive.
He stressed that firms need to know exactly their data in order to prove that they comply with this Directive. But some requirements such as proving best execution will make compliance difficult. It will be also difficult for firms to assess the costs to gather the relevant information.
e-Health Interoperability
Ms. Linda Mauperon, member of the Cabinet of European Commissioner Viviane Reding, insisted first on the benefits of eHealth for healthcare services and for citizens, and on the importance of the eHealth market compared to others health markets.
She stressed that the lack of interoperability is the most important obstacle to the development of eHealth. However, she pointed out that a growing will exists among Member States and stakeholders to solve this problem. The Commission is also committed to improve interoperability of eHealth services as it published a Recommendation containing guidelines and principles to provide interoperability in a cross-border context in July 2008. She quoted other initiatives such as the epSOS project whose goal is to reach a situation where doctors have access to information on a patient without taking into account the country in which they were created. She also stressed that industry is committed to interoperability and that all these initiatives will contribute to make interoperability a reality
Ms. Angelika Haendel from AHIMA explained on the fact that eHealth is a growing sector but interoperability is a prerequisite to its development. She stressed that interoperability is a necessity because trends such as international travel or multinational companies make boundaries less relevant.
Mrs Haendel pointed out that eHealth will become an important area as it represents 5% of the EU GDP and because the EU provides more funds to eHealth projects. However, there are several challenges eHealth projects have to challenge: the intervention of several Member States in an area of national competence, the fragmentation of health organisations in Europe and the growth of electronic data. She presented several eHealth projects such as the integrated care project or the Siemens Soarian Integrated Care.
The Internet of the Future
Dr. Florent Frederix, Head of Sector Networked Enterprise & Radio Frequency Identification unit at the European Commission, presented past and future actions of the Commission on RFID. Regarding future actions, the Commission will adopt a Recommendation on RFID in Autumn 2008 and will publish a staff working paper and a Communication on the Internet of Things in winter 2008/2009.
He stressed that a secure and privacy friendly use of RFID is one of the objective of the Recommendation. He pointed out that RFID chips can become more intelligent and will be able not only to identify things but also to collect information.
The main challenges of the consultation on RFID that close on 28 November 2008 were also put forward: security, privacy and data protection, control of critical global resources, governance of resources, standard settings and interoperability and social and human impact.
The different applications of RFID were promoted in areas such as health, transport, environment monitoring and disaster management.
During this session it appeared that RFID will entail important challenges for records management regarding privacy or security for instance as through this technology an important amount of information will be created and will have to be managed in compliance with EU requirements. However, the way record managers will have to manage these data did not appear clearly.
Mr; Laurent Beslay, Technology Adviser at the European Data Protection supervisor (EDPS) office, stressed the role of the EDPS and data protection principles applicable to RFID and explained that the EDPS office analyses the impact of new technologies on these principles.
He pointed out that privacy challenges are related to RFID as this technology will concern not only the industry but also citizens. If citizens store their data at home they will benefit from a legal protection as home is considered as a legal sanctuary but data are now spread everywhere. He also mentioned the trend of cloud computing where end users store their data on a server outside their hope but do not know where these data are stored exactly. He wondered if end users will benefit from a legal protection if there data are stored by a company.
He stressed that to implement successfully RFID applications security and data protection considerations should be introduced as soon as possible in the creation of new applications. Moreover, best techniques, i.e. the way a technology is implemented, should be used and the way security breaches will be managed should be taken into account.
Tuesday, 28 October 2008
Updated Agenda ARMA EU Roundtable
This exclusive event will involve key policy makers from the European Union institutions as well as relevant stakeholders and will include presentations by noted experts in the Information Management field, with open dialogue by participants. Issues which will be addressed include:
· Transparency: The review of the Regulation 1049/2001 on access to documents - Access to third party documents and information
· The Markets in Financial Instruments Directive (MiFID): Records Management Compliance for multinationals
· E-Health Interoperability - Challenges for records and information management
· The Internet of the Future - The internet of "things" and privacy considerations
Thursday, 9 October 2008
EDPS decision on the right of access to and rectification of medical file
On 14 November 2007, an employee of the European Parliament submitted a complaint to the European Data Protection Supervisor (EDPS) claiming that she was denied to exercise her right of access and rectification to her medical file by the Sick Leave Management Unit of the Parliament.
In his legal analysis, the EDPS gave inter alia a non-restrictive interpretation of Article 13 of Regulation (EC) No. 45/2001 (right of access) and held that the complainant did not only have the right of access to her medical file but also the right to obtain a copy or photocopy without any limitation in terms of copies of her own medical data. With regard to the right of rectification of her data, the EDPS stressed that although it is impossible to rectify medical appreciations, the complainant should have the right to keep her medical file up to date by adding other medical opinions. As to the complainant's request to transfer her medical file to the doctor appointed by her, the EDPS considered that the necessity of such transfer was demonstrated by her explicit consent, which also proved that it could not have prejudiced the data subject's legitimate interests.
The EDPS concluded that the Parliament:
- had not respected the 3 month deadline foreseen in Article 13 of the Regulation according to which the complainant should have been granted access to her medical file;
- had refused to allow the complainant to make photocopies of her medical file without a legal basis contrary to Article 13;
- had not granted the complainant the right to rectify her data so that all data in her medical file are complete and kept up to date, in violation of Articles 14 and 4(d); and
- had refused to transfer the complainant's complete medical file to the doctor appointed by her in infringement of Article 8 (transfer of data).
In the light of the above, the EDPS urged the Parliament to ensure that the complainant's rights are fully respected. The EDPS decision on this complaint was of a particular interest for the Parliament's trade union SFIE which sent an e-mail to the staff of the European Parliament citing the EDPS recommendations.
For more, go to http://www.edps.europa.eu/
Tuesday, 7 October 2008
EU privacy advisory body looking at e-discovery
The Article 29 Working Party on the Protection of Individuals with regard to the Processing of Personal Data is an independent advisory body on data protection and privacy, set up under Article 29 of the Data Protection Directive 95/46/EC. It is composed of representatives from the national data protection authorities of the EU Member States, the European Data Protection Supervisor and the European Commission. Its tasks are described in Article 30 of Directive 95/46/EC and Article 15 of Directive 2002/58/EC. The WP is competent to examine questions covering the application of the national measures adopted under the data protection directives in order to contribute to the uniform application of the directives. It carries out this task by issuing recommendations, opinions and working documents.
http://ec.europa.eu/justice_home/fsj/privacy/workinggroup/index_en.htm
Monday, 6 October 2008
EU to pave way for deployment of smart tags
The French EU Presidency will today (6 October) hold a high-level conference dedicated to building the so-called 'Internet of Things'. The meeting comes as the Commission prepares to present measures aimed at overcoming privacy concerns related to the use of the Radio Frequency Identification (RFID) microchips that are expected to lead the technological revolution.
Brussels considers the creation of the 'Internet of Things' as a key priority as it could provide solutions for a wide range of societal problems, such as ageing populations.
In a future world where ubiquitous tags and sensors would be attached to everything from letters to walls or clothes, the Commission believes many things will be possible. "A blind person might see," said one information society expert at the EU executive.
Indeed, according to the 'Internet of Things' vision, objects could communicate among themselves, for instance allowing a blind person to walk down a street knowing exactly what is around him. "This would be done by using a tag reader, able to detect and read the information contained in tags disseminated everywhere," added the expert.
Elderly people could also benefit from household goods that anticipate their needs and requests, such a fridge which orders more eggs from the supermarket once they have run out, or clothes capable of constantly measuring key health indicators, like blood pressure or heartbeat.
However, the use of RFID chips also raises concerns regarding the privacy and security of carried information, as tags could contain personal details potentially exploitable by anyone equipped with a tag reader.
To address these concerns, the Commission will present, in November, a recommendation to member states encouraging them to adopt initial measures to make people more aware of the existence of RFID embedded in objects or rooms, and to avoid misuse of the new technology.
According to the upcoming recommendation, a draft of which has been circulating since April 2008 (EurActiv 26/02/08), all companies interested in using RFID, from airlines to retailers, will have to draw up a 'privacy impact assessment' to verify the potential privacy-related risks of the devices they are using.
What's more, retailers, such as Carrefour or Metro, will be required to de-activate any tags attached to items they sell once the buyer leaves their stores. However, retailers are already resisting such a measure for fear that it will push up their costs and act as a disincentive to the deployment of tags, EurActiv has learnt.
The Commission will also propose two harmonised logos to indicate the presence of RFID in products and tag-filled environments. Awareness-raising campaigns will also be organised and funding is envisaged for projects aimed at developing privacy and security-friendly tag designs.
But the RFID revolution still appears distant, hampered not only by privacy and security concerns but also by a lack of international standards. Technical skills are also lacking, with the software industry pointing out that Europe would be incapable of coping with massive deployment of RFID due to a lack of qualified engineers to deal with tags.
In September, the EU executive launched a public consultation on the "early challenges of the Internet of Things," which is expected to result in the publication of an official document in the second quarter of 2009.
For more, go to http://www.euractiv.com/en/infosociety/eu-pave-way-deployment-smart-tags/article-175998
Saturday, 4 October 2008
Deutsche Telekom Says Data From 17 Million Customers Was Stolen
Deutsche Telekom said the stolen data includes customer mobile phone numbers, addresses, dates of birth and, in some cases, email addresses. Bank information or credit card numbers were not accessed, said the Bonn-based firm.
There has reportedly been no indication that the data has been misused, though the Telekom said "extreme criminal energy" was behind the theft.
German newsmagazine Spiegel reported on Saturday, Oct. 4, that is had obtained access to the missing information via a third party. The news apparently came as a surprise to Deutsche Telekom, where the case was considered closed.
"We had assumed that this data had been fully secured as part of an investigation by the district attorney," Philipp Humm, director of Deutsche Telekom's mobile phone division T-Mobile, said in a statement. Data security measures had been fortified since 2006, he added.
According to media reports Saturday, Oct. 4, Telekom had contacted the appropriate authorities as soon as the data was stolen in 2006 and an investigation has since been underway.
Telekom said it had conducted research after the theft and discovered that copies of the data had been offered on the black market but had apparently not been bought. Few customers brought complaints pertaining to the data mishap, though a special hotline telephone number was set-up.
The public prosecutor's office in Bonn told reporters that pieces of data had been confiscated from private homes, but that the thieves themselves had not yet been detained.
Celebrity customers, including comedian Hape Kerkeling and television moderator Guenther Jauch, high-ranking politicians, billionaires and clergymen were reportedly among those affected by the data breach.
For some of them, it could represent a threat to their security if their secret personal telephone numbers landed in the hands of criminals.
Saturday's revelation is not Telekom's first brush with data scandals. Earlier this year, the firm admitted that calls between journalists and board members had been illegally monitored in 2005 and 2006.
From http://www.dw-world.de/dw/article/0,2144,3690132,00.html
Monday, 29 September 2008
Workshop"International Transfers of Personal Data", Brussels
This Workshop is a follow up of the previous Conferences held in Brussels in October 2006 and in Washington in October 2007 organised by the European Commission, the Working Party and the US Department of Commerce.
More information on the programme. (PDF File 69 KB)
For further information, please contact: JLS-DP-CONFERENCE@ec.europa.eu.
Thursday, 25 September 2008
Article 29 Data Protection Working Party reacts to Google's reply to the Opinion on data protection issues related to search engines
__________________
On April 4, 2008, the Article 29 Working Party published an opinion on search engines,reaffirming the applicability of the European data protection law, recommending a maximumretention period of 6 months and indicating that web users must be able to provide consent to the exploitation of their data in particular for profiling purposes.Google answered to this opinion on September 8, 2008, by reaffirming its interest for a better consideration of data protection. Two significant modifications were announced on thisoccasion:
1. From now on, IP addresses associated with the requests carried out on the searchengine will be anonymized after 9 months (instead of 18 as it is now the case) ;
2. A link to Google’s privacy policy appears on its homepage.
Alex TÜRK, Chairman of the Article 29 Working Party and the French Data Protection Authority (CNIL), takes note of this improvement with satisfaction. M. TÜRK also notes thecommitment of Google to collaborate with data protection authorities and its efforts to inform its users about data protection issues using clear and innovative tools.
However, he considers that strong disagreements remain. In particular, Google:
- considers that the European law on data protection is not applicable to itself, even though Google has servers and establishments in Europe;
- wishes to retain personal data of users beyond the 6 months period requested by the Article 29 Working Party, without any justification;
- does not make any improvement to its anonymization mechanisms, which are still insufficient;
- considers that IP addresses are confidential data but not personal data, which prevents granting certain rights to its users,
- does not express the willingness to improve and clarify the methods that are used to gather the consent of its users.
In conclusion, despite some progress, significant work must still be carried out to guarantee the rights of internet users and to ensure the respect of their privacy. In this perspective, theArticle 29 Working Party will lead hearings with Google to discuss the points of dissension.
For the press release, go to: http://ec.europa.eu/justice_home/fsj/privacy/news/docs/pr_16_09_08_en.pdf
For more on EU data protection, go to: http://ec.europa.eu/justice_home/fsj/privacy/news/index_en.htm