Category: Security

Quit-Facebook-WhatsApp-NTIC-2021

WhatsApp forces users sharing data with Facebook: False alarm?

On 4 January 2021, WhatsApp pushed to all its users a notification screen to ACCEPT its updated terms of service (terms of use) and privacy policy (read “privacy notice”). The text displayed on users’ phone is pretty clear: accept to continue using the app or decline and stop using our service. For the time being, users can still say “not now” or continue using the App.

What are the deadlines?

WhatsApp first gave users until 8 February 2021 to decide to continue or quit the App, which was a very tight deadline. The text displayed on the user’s screen mentioned that the new terms would include sharing data with Facebook. As a result, millions of users switched to other so-called more “privacy friendly” apps. Some of them are Signal, Viber, Telegram (US), Olvid (FR) or Threema (CH) among others. After this event and huge users’ reactions, WhatsApp decided to offer a extended deadline until 15 May 2021. This would allow users to take more time to decide to continue or stop using the App.

So, what is this update all about? What are really the changes? Why would users switch or stay with WhatsApp? Are there really any privacy concerns? I will try to provide some response in this blog as a Q&A to make information easily accessible, concise, unambiguous, fair and transparent…Note that I recently moderated a webinar with international experts to discuss the changes to WhatsApp terms of service and privacy policy. Once online, I will share the link at the end of this article.

street-ads-ntic

Out of Control: a deep dive into the digital advertising and data sharing practices

An expected, but scary report on digital advertising through dating mobile applications run under Google Android OS.

On 14 January 2020, Forbrukerradet, the Norwegian Consumer Council (“NCC”) released on its designated web page a 186 pages study report called “OUT OF CONTROL: How consumers are exploited by the online advertising industry“. Supported by a 93 pages technical report, it explains how the industry of digital advertising (“AdTech” industry) is exploiting personal data of consumers through dating mobile applications to use and monetize such data for their business interest and the ones of “shadow companies”, giving no choice to consumers other than not using the App to avoid profiling and use of their information.

The AdTech players usually conduct tracking and profiling activities, such as behavioral targeted advertising, while sharing and transmitting and communicating electronic information to a wide range of third parties. Nothing new under the sun with this report. Except that the reading provides a lot more clarity about the transmission mechanisms between App providers and third parties active in the advertising industry and real-time bidding (defined below). Some of those mobile application editors use anonymized or aggregate data to conduct segmentation for specific targeted audiences, whereas others just collect personal data “in clear”, without the end-user knowing it, nor agreeing to such practices.

The Norwegian Consumer Council filed three complaints to the Data Protection Authority for breach of the GDPR. And because this report shows that it affects people globally, it is likely that we will hear more actions around the world (even class actions). To read more on the complaints filed against Grindr & Cie, click below:

_______________________________

ICO UK WARNS ADTECH COMPANIES TO EXPECT ENFORCEMENT ACTIONS

In the meanwhile, further to the report, Simon MacDougall, Executive Director for Technology and Innovation at the ICO (UK Information Commissioner’s Office), issued a clear message to the AdTech industry on its blog on 17 January 2020:

“There is a significant lack of transparency due to the nature of the supply chain and the role different actors play. Our June 2019 report identified a range of issues. We are confident that any organisation that has not properly addressed these issues risks operating in breach of data protection law. […]We gave industry six months to work on the points we raised, and offered to continue to engage with stakeholders. If these measures are fully implemented they will result in real improvements to the handling of personal data within the adtech industry. […] We will continue to engage with industry where we think engagement will deliver the most effective outcome for data subjects. […] Those who have ignored the window of opportunity to engage and transform [the ICO gave 6 months from september 2019] must now prepare for the ICO to utilise its wider powers.”

A very good timing for issuing this warning to the industry. In march 2020, once the given 6 month period expires, we should expect further guidance and more enforcement actions if the industry has not convinced the authority to change its doubtful practices.

The ICO UK is one the most active and productive data protection authority in the EU. Together with the CNIL, it issued guidance for this adtech industry, which you can find at the end of this article for more information and references.

_______________________________

UNDERSTANDING THE HARM TO INDIVIDUALS

The study offers a deep dive analysis into the data-sharing practices of AdTech companies communicating via mobile applications. In such cases, unless manufacturers includes built-in easily understandable opt-in consent or opt-out mechanisms associated with clear information about the use of personal data and what it means for them, consumers are unlikely to understand anything of what is going on through the App. This is even more true, when those Apps are used by teenagers or kids.

Out-of-control describes, with examples, how tracking and profiling activities can be used for data-driven persuasion, in particular with the collection of sensitive information. Data-driven models may not only serve dark patterns for commercial purposes aiming at influencing consumers so that they can decide to buy stuff that they initially didn’t want to. According to the report, persuasion based on personal data and profiling may lead to (among others):

  • discrimination
  • harassment
  • manipulation of information and influences of opinions
  • can impair freedom of expression through the “chilling effect” (the effect of not being free to express herself or himself due to the perception of being spied or under surveillance)
  • fraud

which can create other serious harm to individuals if the data goes into the wrong hands. To summarize, when in the wrong hands:

Companies can use tracking and profiling activities for data-driven persuasion, which can lead to serious harm to consumers, whose personal data are collected, including discrimination, fraud, manipulation, same as observed in the Cambridge Analytica’s case.

This is where the real danger is.

Such collection by shadow companies can contribute to the absence of trust about information, opinions, and impair how we all perceive today’s society based on information quickly consumed through information pushed to anyone’s eyes and mind unconsciously storing and memorizing information through data-driven persuasion. Reality becomes the one others want us to believe. According to an Amnesty International report (p. 43 of the out-of-control report), the technology used can dramatically impair fundamental human rights of people and it says:

These capabilities mean there is a high risk that the companies could directly harm the rights to freedom of thought, conscience and religion and freedom of opinion and expression through their use of algorithmic systems.

The study shows that some mobile applications (such as Perfect 365) can even communicate and exchange data with more than 70 external third parties and vendors, including social media platforms, such as Facebook and Twitter, which demonstrates how broad this can be.

Looking at the data flow and the complexity of this ecosystem, it becomes clear that consumers have no more control over their personal data.

_______________________________

EXAMINED MOBILE APPLICATIONS

The study was conducted by the NCC together with 10 other non-profit organizations, including the FRC, the French speaking division of the Swiss Consumer Federation, outlining the width and scope of data-sharing practices through selected mobile applications on Google Android mobile OS operating system. This study focuses on online dating platforms, such as Grindr (subject to 3 formal complaint to the Norwegian data protection authority), OkCupid and Tinder). A lot of information is processed through those applications, including location data, e-mail addresses, and other sensitive personal data such as sexual preferences, health-related information, such as HIV status.

Other mobile applications are included in the study.

For example, it analyses MakeUp Apps (such as Perfect365, based on augmented reality), allowing live photo editing before sharing on social media, Ovulation Calendar & Period Tracker, such as MyDays (which may be considered as a medical device as standalone medical software), Religious Apps, which can be used to receive reminders of events tied to religious matters (Muslim) and Apps for children (My Talking Tom 2) among others. For most of those applications, users have downloaded them million times, with a huge community of consumers, including minors. The study observes how publishers (software editor of the App – see below) share personal data with a range of third parties in the AdTech ecosystem built to monetize personal data.

_______________________________

GETTING INTO MORE DETAILS: PLAYERS OF THE ADTECH INDUSTRY

The online advertising industry uses different ways for marketers to publish their content online.

A company can either pay (alone or through a third party broker) for a space on an internet page or display an add in a mobile App with a fixed price. When a company displays its ad, it will either pay a fixed fee or a variable amount, based on the value of placing an advertisement at a certain period of time (lunch time, night) or to a certain segmented audience (type of audience, territory, etc.). It can decide to place its ads up for the value of the key word. The value of such keyword is constantly evolving based based on an algorithm. For example, such algorithms are used by Google on search engines to display advertisements. The costs can go up to a certain price if it is popular or lower if few people want to search this keyword. After this, online users can see sponsored content (content pushed to the public at a certain place on the website) in relation to the keyword entered into the search engine, where the marketer will pay Google on a per-click basis.

A company can also use real-time bidding (RTB), consisting of an instantaneous online auction. Real-time bidding means that advertising buyers bid on an impression (= number of times a content appears in someone’s feed; A viewer doesn’t have to engage with the post in order for it to count as an impression). If the bid is won, the content of the person buying the ad will instantly display on the publisher’s site, page, network or App. This is one of the standard business models for companies sponsoring their content online.  The ad will display and the marketer shall pay an amount subject to value of the won bid and the allocated budget. See the ICO UK’s guidance for more information or privacy in RTB (link at the end of the article).

The different stakeholders of the AdTech market usually are:

  • Publishers provide information and interactive services to users. The publisher is the editor of the mobile application and offers locations in the App, for advertisers to display their ads. Publishers are paid by the number of clicks on an ads, but often, publishers cannot know which ads will display because as it out of their control.–> App providers (publishers) are data controllers.
  • Marketers are entities that want to acquire and retain valuable customers, find and influence users across the digital world. This can include retailers, grocery stores, consumer goods brands, device makers, car vendors, the travel and hospitality industry, telecom and financial services providers, and many other providers of products and services.–> Marketers involved in the purchase of targeted advertising can be considered joint controllers, even if they do not actually process personal data themselves, as long as they define the means purposes of the processing.
  • Advertising networksanalytics vendors, and data brokers. These other third party vendors is another category that includes a number of actors in the digital marketing and AdTech industry, which is normally hidden from consumers. Unlike publishers and marketers, third party vendors mostly do not have any direct relationships with users.–> Those third party vendors, which are receiving personal data from the apps are either processors, separate controllers, or joint controllers, depending on how and under what terms they use the personal data;
  • Major platforms such as Google and Facebook are involved, for the large part, in the AdTech industry. They offer services and play an important role to either: (a) sell digital advertising based on user data (YouTube as a publisher of ads on video content); or (b) sell sponsored posts on their platforms (Facebook, Twitter, LinkedIn). Those major platforms also act as third party vendors to provide digital advertising services through their other entities and other divisions with other brand names.–> Major platforms can either be data controllers, processors or joint controllers depending on the types of services that they offer.
  • Consumers are the last players of this economy, called data subjects under the GDPR.

_______________________________

WHAT DATA IS SHARED AND WITH WHOM

The technical report is a supporting document for the complaints filed to the Norwegian data protection authority. It shows data flows, where third parties are involved in this massive data-sharing ecosystem. We read what categories of personal data are constantly collected by the publishers and communicated to, or accessible by their, business partners. The parameters analyzed in the technical report include: Advertising ID, IP address, MAC address, GPS location, device information, device configuration, Wifi networks, App name making the requests, account information, and user data, such as age and gender. It can also include e-mail addresses and sensitive personal data.

Android Advertising ID’s example

Out of control report and its supporting technical document underline what identifiers are used to track users information, especially the Android Advertising ID (“AAID”).

The AAID provides a user-specific, unique, resettable ID to be used for advertising and provides linkability, in the sense that it gives advertisers an easy way to connect the dots between multiple apps or multiple sources.

This AAID is embeded is any device. As a so-called “anonymous” ID, it provides advertising companies a unique device identifier for advertising and tracking, which can be used to correlate data from multiple sources (technical report p 12) and services. Although Android smartphones users may reset their Android Advertising ID, the report shows that combined with other unique identifiers, resetting the Android Ads ID may become useless, because third parties will often be able to re-identify users. Finally, the interesting part linking to privacy settings is the following (p. 13):

“There is an option in the Android system settings to opt out of targeted advertising based on the advertising ID, but this mechanism appears to be largely trust-based, as it requires the app developers to actively check for and honour an opt-out, rather than supporting the opt-out natively in the platform. At the same time, end users have no way to evaluate whether a given app is respecting Android’s privacy controls, and may believe that the control is effective even if they are not”.

The conclusion is clear: there is no way for an Android user to have the guarantee from Google’Android that even when deactivating the AAID, other companies will not use the ID to target them with online content!

Wide range of personal data shared with a wide range of third parties

Usually, most of the data that is communicated to third parties, relate to GPS location, names and surnames, contact details, and preferences. However, in other cases, the report shows that very intrusive personal data is collected and shared with third parties, such as questions, where the company shall have no valid purpose to hold such data. Questions asked in the OkCupid App shared the answers with Braze (an marketing agency), included information from:

  • Do you have student debt?
  • Do you prefer hardcore or softcore when it comes to your porn?
  • Are you jewish?
  • How does the idea of being slapped hard in the face during sex make you feel?
  • Is it easy for you to achieve orgasm?
  • Do you enjoy exercise?
  • Generally, do you enjoy being drunk?
  • Is climate change real?
  • Is the US educational system designed to benefit the rich?
  • Would you ever date someone that is hiv positive?

Such data is extremely sensitive and can lead to a serious harm for persons whose personal data may come in the wrong hands. In another scandal arose in 2018, where Grindr was found to share HIV status data with 2 other Apps being Apptimize and Localytics (p. 23 of the technical report).

_______________________________

INTRUSIVE AND NON-INTRUSIVE BUSINESS MODELS 

Although some sectors are regulated and prohibit publicity to protect consumers (doctors, alcool, tobacco, pharma and other sectors), advertising companies can conduct their business legally to the extent they follow relevant legislation, including at least: data privacy and consumer protection rules. In this regard, data protection laws (including ePrivacy Directive) and consumer protection laws mean the laws of each country, where users are residing (except that the GDPR applies everywhere, when in-scope), which can become a challenge to implement. In the AdTech sector, given the intrusiveness of the processing activity, Codes of conducts (IAB codes of conduct) and principles of ethics are emerging (see the Principles and practices for advertising ethics). Although those texts are not considered as law, they help companies using advertising practices that are fair and ethical. This is a growing area that any company, not only the AdTech sector, should have a look at to embed those principles in their culture. In a world, where data collection and sharing practices are commonly performed without transparency, ethics can help build trust of consumers again.

An interesting part of the study explains that several business models are available, which can involve or not the processing of personal data of consumers using an App. In reality, the more personal the profile is, the more companies can accurately target users, with content that may interest them. And there is still a large number of companies operating in the shadow of users taking advantage of the data business tracking and profiling  with debatable legitimate purpose to hold such information (report p. 5 and 45).

The consequences for a company to use personal data or not are massive. Let’s use an example for the use of personal data:

Does a third party, used by the data controller to backup information on hosting servers, really need to access political views, sexual preferences and orientations or religious believes? Using a subcontractor to store personal data on its server is perfectly okay, even if it leaves the EU. The cloud vendor should however, as data processor (subcontractor), follow all instructions of the data controller and comply at least with all art. 28 (data processing agreement) and art. 32 (appropriate security measures in place) requirements of the GDPR. If this backup company uses personal data for its own purpose, and let’s say it will make profit from it, this cloud provider becomes a data controller – i.e: responsible for handling personal data – and will have to comply all data protection laws, including the all GDPR requirements.

This means that any third party holding personal data of consumers through the App, deciding about what to do with the data (“for its own purpose”), such as making money of it, should inform the user about the processing, explaining why it holds the data, base such processing activity on a valid legal justification, such as consent or a legitimate interest, and comply with all other obligations under data privacy laws.

This is unlikely to be the case for shadow companies using personal data that is not anonymized, in order to take their own decisions.

Alternative business models vs the sad reality

The reports reminds that companies can use non-intrusive business models to conduct advertising on mobile applications.

This is the case for Subscription services. Subscription-based models, often used by online media and newspapers, require users to pay for the work done by journalists. Also, donation – which is the Wikipedia and TheGuardian business models, can also work. As opposed to behavioral targeted advertising, which requires to create user profiles, companies can chose contextual advertising as business model, where targeting ads can be based on the content that the consumer is looking at, rather than on the profile of the consumer her- or himself.

The problem for players of the AdTech industry, is that using less intrusive technologies may lead to a “race to the bottom” with the side-effect of “depressing the value of data, which may fuel further extensive sharing of personal data, leading to market inefficiencies from a competition point of view” (p. 53 and 54 of the report).

In practice of mobile Apps and social networks, sharing personal data is often the counterpart of using the free version of an App. In the mobile gaming industry, the use of a free game almost always includes other ways to monetize the App: just think about Candy Crush. It can include: (a) forcing the user to watch a video, (b) to share with friends the results of a game; or (c) share its personal data with third parties, or (d) offer direct purchase of items, which will make you progress in your game journey. A free version of an App usually forces the consumer to give something in return to its free use, therefore making this App not really “free” anymore. Many initiatives are emerging to monetize personal data, but in a transparent manner. In the case of companies doing market researches or surveys, the publishers remunerates consumers in exchanges of answers to certain questions. It can also be based on the physical performance displayed in the App owned by a insurance provider which the consumer is already a client of.

Often, even with paid Apps, subscription-based models or other less intrusive business models still use tracking and profiling activities of users. Those practices are very often done without the knowledge of the users; with very low transparency and consent-based mechanism to the users.

_______________________________

FREE VS PAID: REASONABLE EXPECTATIONS OR DATA HOLD-UP?

Should the out-of-control report be a surprise to the general public? Absolutely not! The subject is not new and those business models are already dated. However, the technology is evolving and with machine learning and other more clever algorithms, it will become less easy to understand the consequences for one’s privacy when using an online service through a mobile application.

Consumers can expect ads in free or even paid versions.

Users of mobile Apps, in particular social networks, should expect a difference in the business models between free and paid Apps. To run mobile applications consisting in any kind of social networks, it requires a connection. Thus, by design, it is not possible to use a social network without opening your phone to the external world, for games this might be different, but the publisher will often deny the game if the internet connection is not active. Now, when a user decides to use a free version, compared to a paid version, users can assume and expect that, with no money, the App will not be maintained or will just disappear from the market and App stores. Remember old times when using video games decades ago; a one-off payment would allow anyone to own the game and play ad eternam without any connection.

When we think of the current business models, Facebook is the best example of the next generation business models. According to a study, Facebook’s revenues in 2018 were almost only based on advertising (98%). This means how lucrative it is when the publisher offers a platform with millions of consumers, earning money with a pay-per-click model. In the case of Grindr, the App has been downloaded more than 100 million times. In this sense, consumers can expect to see ads when using free versions of a platform or a service, because this model has become mainstream. Compared to premium, subscription-based or paid versions, free versions almost always use advertisements. Advertising business models can be based on personal data or not, but it almost always requires a connection to the Internet or the transmission of information via the App.

Learning from the cookie wall debate?

The next question is: does consumer has to accept to be targeted with ads to use a free (or even paid) service? The answer is not  clear from a legal point of view.

Although this is a different situation, one may compare free Apps and choice, to the cookies and tracking technologies’ discussion in the EU (i.e:  article 5(3) of the ePrivacy Directive). As a reminder, the cookie wall debate relate to granting or denying access to an internet user depending whether she or he decides to accept to place cookies on its device or not. If the user says yes, which allows online tracking and potentially creating profiles, users can pass the wall and access the site. If the user says no, I don’t want to be tracked on your site, then the user cannot access the website. In my opinion, the situation is similar with free mobile Apps and social networks.

The cookie wall debate is still on and a court has not judged yet, whether a website can ban users if they don’t agree to be tracked. In the context of cookies at least, we know now that, further to most data protection authority’s recent guidance and approach (CNIL and ICO UK), there is no exception to consent, other than when the tracking technology is necessary for the performance of the services. Therefore, consent is almost always required. Cookies are regulated by the ePrivacy Directive principles, but consent and transparency obligations rules have to follow the GDPR (as seen in the recent CJUE Planet49 case).

The out-of-control report explains that Grindr and its third parties, go far beyond such practices. It involves tracking, profiling and transmission of sensitive personal data to external companies that may not have any valid ground to hold the data and do not inform individuals properly. Also there is almost not valid legal justification as consent and explicit consent are not properly included in the App.

When a user knows in advance what company is going to do what, with what data, and if the user can easily choose what to do and decide to continue to use the service or not, this could be fine (subject to the view that a cookie wall may not be lawful). This could be fine if you follow the argument of pro cookie walls, who argue that nobody is forced to use an App or a service. It is always possible to choose to use another one if the user is not happy. This apply as long as the choice for the user to leave the website or the App comes before the cookie is placed on the device. On the contrary, people not supporting the cookie wall concept, claim that such mechanism does not give the user a real choice, because it should be possible to use the service without detriment to the user and allow them to use read the content by refusing the placement of cookies as a counterpart of entering the website.

Although both arguments are arguable and valid, banning cookie walls means that it requires to find other ways to monetize the use of online services, especially in an data-driven economy.

In any case, if a user has no information and no choice, and uses a service that collects such amount of data, sharing with them with so many other companies, this is not just unethical anymore, it constitutes a sneaky and severe violation of someone’s privacy.

_______________________________

COMPLAINTS TO AUTHORITIES: NORWAY VS SWITZERLAND APPROACH

NORWAY – A GDPR COUNTRY

Norway is a GDPR country. As an EU country, it has implemented a sanction mechanism based on Regulation 2016/679, better known as the GDPR. This action includes appointing a data protection authority capable of taking enforcement actions for violations of data protection laws, which is the case of all EU countries. The fines can go up to 2% or 4% of the annual worldwide turnover for private companies. As a reminder, the GDPR applies regardless of the location of the data controller, if it uses personal data of individuals located in the EU. The controller is the company deciding about the purpose and the means for the processing of personal data. In this sense, the GDPR is very powerful to most companies (compared to tech giants that can easily survive to fines) because companies cannot exit the EU to escape the application of this law. Also, due to its sanction mechanisms, it can be used as a preventive and dissuasive tool.

The NCC filed 3 complaints to the Norwegian Data Protection Agency against Grindr and companies accessing personal data of consumers through the App. The content of the 3 complaints is very similar to each other. The main focus is on the absence of valid consent as the legal justification to use the data. It also mentions the Dominant Market Position of Grindr. This is interesting, because we start to see an interplay between privacy and anti-trust laws, where data controllers may abuse from their dominant positions.

In this article, I previously discussed Google’s €50M fine by the CNIL. I also analyzed the first GDPR enforcement cases to understand the level of fines under this EU data privacy law, where in this other article, I compared the legal regime in force before the GDPR, mentionning Equifax and Cambridge Analytica’s cases.

SWITZERLAND – A NON GDPR COUNTRY

The situation is slightly different in Switzerland.

The Swiss French speaking division of the Consumer Federation (FRC) also requested the Swiss Federal Data Protection Commissioner (Swiss Commissioner) to take further actions. This request will be very limited given the Swiss Commissioner can only issue non-binding recommendation, go in front of the federal administrative court to have a conceptual judgement. As such, the there is still no direct enforcement, nor sanction power for the Commissioner.  Therefore the Swiss complaint will lead to a statement or recommendation, under the means available under the Swiss Data Protection Act.

Further to a massive data breach to Swisscom, I commented (in French) the weakness of the Swiss Data Protection Act (“Swiss DPA”) in terms of enforcement. Although Switzerland benefits from an adequacy decision from the EU Commission and its law is comprehensive and solid, it lacks from enforcement and direct sanction mechanism compared to EU legislation to dissuade bad players exploiting data with no further consequences. Currently, the Swiss DPA only allows someone to initiate a criminal trial with a maximum criminal fine of CHF 10K. The currently revised text of the Swiss DPA will not grant anymore sanction powers for the Commissioner in case of infringement of the Swiss Federal Data Protection Act, but will increase the individual responsibility criminal offences up to CHF 250K.

Data protection is a balance between the fundamental rights of individuals against the rights of others to use such information for their own purpose.

Swiss politicians have chosen their side. To date, the legislator clearly gives more importance to the rights of companies to process personal data instead of protecting the fundamental rights and freedoms of Swiss citizen. AS a result, claiming more control in Switzerland, will always remain weak if companies decides not to apply privacy rules to Swiss citizen so that they can claim more control over their personal data. This remains a political choice.

_______________________________

TOP 5 PRIVACY RECOMMENDATIONS FOR THE ADTECH INDUSTRY

The following recommendations can apply to Adtech players, including manufacturers of mobile applications, but also to other industries.

1. DETERMINE YOUR ROLE

You should first understand whether your company acts as data controller, data processor or as joint controller. Your role is based on each processing activity. This first step is absolutely key and will determine the level of responsibility of your company and regulate how to act with your business partners, especially fulfilling other compliance obligations, having the right contracts in place (art. 28 GDPR), limiting your liability and indemnity obligations, and determine the roles and responsibilities of your counterparts for the processing of personal data in each situation.

2. KNOW WHAT DATA YOU HOLD, WHY AND WITH WHOM YOU SHARE IT

WHAT. Consumer data (B2C) requires the same care as B2B information. However, when is comes to involve children’s privacy or with sensitive data, it requires due care. On social networks, is will very often if not always involve sensitive personal data. Except where other rules may apply, such as consumer protection, age verification and authorization from parents may be of importance. When you determine what information your company collects, you can then apply data minimization principle (don’t collect more than what you need for what you want to achieve = only collect what is strictly necessary). Once you know the categories of data you have about whom, you can apply the appropriate security measures, assessing the risk associated to such data in case you suffer a breach, and data minimisation.

WHY. You need a purpose to process personal data and inform people about it. If you just collect personal data to hold it, sell it or for a future use, this might be against the GDPR and generally a lot of other data privacy laws around the world. The purpose needs to be explained to the data subjects (users/consumers) though privacy notices for each processing activities and with the right justifications and for each purpose.

WITH WHOM. Ensure you have all appropriate safeguards and legal mechanisms to share personal data with others, including knowing if the other party acts as your data processor or another controller. Collecting and sharing data with other vendors is part of the connected world. Nowadays, data and personal data are transferred to many third parties, including to countries with less data protection standard as in the EU or Switzerland, such as India or the USA. When transferring data that is personal, your company must ensure to have the right to pass it to third parties If you have to rely on consent, you cannot pass and transfer the consent to your third party if the third party becomes a controller. In this case, the other party will have to inform consumers and collect the consent or explicit consent. If not, any such practice will infringe data privacy laws.

3. USE THE RIGHT LEGAL BASIS AND COMPLY WITH IT

Still check whether you can rely on any exemption or exception to consent under art. 6 GDPR (among the 6 other legal bases) and/or under art. 9 GDPR (explicit consent if you hold sensitive personal data). The ICO UK stated in June 2019 that, in the case of marketers, it is unlikely that another legal basis than consent can be used. Also, tracking technologies are subject to the ePrivacy Directive, which now is clear to require consent each time the placement of a tracking technology on a device is not necessary for the performance of the service. The ICO states for sensitive data: “market participants must modify existing consent mechanisms to collect explicit consent, or they should not process this data at all” (guidance June 2019 p. 16). Therefore, you’d better use the appropriate consent mechanism (not bundled, freely-given, informed, unambiguous, etc.) if you do not want to hear from authorities or data subjects lodging a complaint.

4. USE TRANSPARENT PRACTICES TO BUILD TRUST

Privacy notices, not only support consent compliance, but allows to inform people about what exactly you hold about them. It explains what you will do with the data, how you protect it and with whom you share it (among others). Adtech companies operating as data controllers, need to find creative ways to draft (concisely, clearly, etc.) and display their privacy notices in a easily understandable way which will not discourage the user from reading, nor understanding, nor … using the App! Hiring pragmatic, business-oriented and creative privacy lawyers might be worth the price, as privacy on mobile applications is more difficult to achieve given the smaller screen of the devices. Demonstrating a valid consent is still, and will remain, a challenge.

5. APPLY PRIVACY BY DESIGN AND BY DEFAULT 

The architecture and the data flows in mobile applications and social networks can become extremely complex. Building and maintaining software, taking into account data lifecycle (data retention and data minimization) with built-in opt-in consent, privacy notices, appropriate security measures, features and technology to give the control to users and always apply the less intrusive parameter (turned off if not strictly necessary) to start using the service.

AND … FOLLOW INDUSTRY-SPECIFIC GUIDANCE (IBA, ISBA, ICO UK), DON’T FORGET EPRIVACY AND THINK ABOUT DATA ETHICS!

Future will tell if privacy laws will influence business models in the field of digital advertising…

To go further with authorities guidance:

By Gabriel Avigdor | NTIC.ch | datalex.ch | penalex.ch

GDPR compliance: what if you don’t comply as of 25 May 2018

GDPR COMPLIANCE has been the very hot topic of 2017 and will continue to grow in the next couple of months, as we are reaching 25 May 2018, the famous date where Regulation (EU) 2016/679 will apply to any controller and processor around the world falling into the scope of the Regulation. This topic will increase in importance with general awareness, the importance to “think privacy first” before any processing personal data occurs, and the increasing number privacy pros arising out around the globe advocating about privacy.

In this historic race for data protection compliance, the European Commission published a new website, with extensive guidance on that matter. This site is pretty intelligible, and designed in a simplified and easily accessible manner. It covers important areas of the GDPR indicating, among others:

including an infographic section with a summary of key areas that relate to the GDPR such as rights and duties, and consequences for non-compliance.

Now processors of personal data may have to demonstrate to the authorities that, and how, they comply with the Regulation (‘accountability’ principle).

__________________

WHAT TO EXPECT IF YOU DON’T COMPLY WITH THE GDPR?

On its new website, the Commission reminds the 4 steps process before a supervisory authority may impose an administrative fine (art. 83 of the GDPR) on businesses or organizations for non-compliance. These steps are:

(1) WARNING ⇨ (2) REPRIMAND ⇨ (3) SUSPENSION OF DATA PROCESSING ⇨ (4) FINES

and according to the Regulation, sanctions shall “in each individual case be effective, proportionate and dissuasive ” (art. 83 § 1 GDPR). Therefore, the fine regime allows a supervisory authority to impose a fine in addition to other measures, being (among others):

  • warnings (art. 58 (2) (a) and recital 150 of the GDPR);
  • withdrawal of certifications (art. 58 (2) (h) of the GDPR); or
  • suspension of data flows (art. 58 (2) (j) and 83 (5) (e) of the GDPR).

__________________

WHAT DOES ARTICLE 29 WP SAY ABOUT FINES UNDER THE GDPR?

The Article 29 Working Party (‘A29WP’) just updated its 253rd document called “Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679” (wp253). This document contains more details on the fine regime and how controller should behave to avoid fines.

The guidelines explains that warnings may already be given to controllers when processing operations are likely to infringe provisions of the Regulation. This means that warnings may be used as a preventive measure against a potential infringement (foot note, page 5 of wp253). Reprimand can, in some cases, replace a fine (page 9 of the guidelines), etc. In addition to this, the A29WP adds an interesting statement about the balance between imposing corrective measures with or without fines:

Fines are an important tool that supervisory authorities should use in appropriate circumstances. The supervisory authorities are encouraged to use a considered and balanced approach in their use of corrective measures, in order to achieve both an effective and dissuasive as well as a proportionate reaction to the breach. The point is to not qualify the fines as last resort, nor to shy away from issuing fines, but on the other hand not to use them in such a way which would devalue their effectiveness as a tool“.

The message is pretty clear, the supervisory authority shall ensure effectiveness through finding the right balance between fines, or measures, or both. Still, fines should not be “devalued” meaning, that a too nice fine may encourage controllers and processors to continue doing business without ensuring compliance.

You can access the guidelines on administrative fines here.

__________________

AUTHORITIES WILL NOT FINE EVERYONE AS OF 25 MAY 2018

It has become popular to hear and read from many people and consulting firms coming out of nowhere, shouting on social media and the internet, that the end of the world is going to happen in May 2018, should you be non-compliant. The reality is a bit more complex, and such statement isn’t true. It is true that after 25 May, there will be no more deadline for GDPR readiness, so sanctions may potentially be quite heavy when a controller is being audited, questionned by an authority or if an individual lodges a complaint against the controller. But this may only happen after the authority performs an assessment of the situation, starting with exchanges of communications, then maybe an audit if a data subject submitting a complaint for an infringement of their rights, or if one claims a the controller is breaching the law. You’d better be working on your GPDR readiness if you are subject to the Regulation and haven’t started yet. But it seems necessary to remind some basic considerations that are a bit less scaremongering on the sanction regime and compliance readiness, just to name a few:

  • Fines are not going to rain on data controllers as of 26 May 2018. This is a myth designed by hungry newly created consulting firms using fear as a marketing tool to sell their GDPR-related services. mid- to large organisations that are aware do not get trapped, but smaller may.
  • An authority will not issue a fine before having found evidence and probably warned the processor of personal data (controllers and to some extent processors) that there is, in their opinion, a breach of the law. It means that the process would require to conduct investigations , including audit of, or by, the controller, its retailers, suppliers or business partners, but also interpreting the GDPR, which is not easy.
  • According to UK ICO Steve Eckersley, “some investigations take 8-12 months to complete”. So it wil take some time. Taking the example of the UK, Steve Eckerley also mentions that “the ICO is now recruiting an additional 100-150 people to work on GDPR aspects and cyber security” predicting that the ICO will receive “30,000 breach notifications a year“. This is not a meaningless number.
  • Authorities are, and will remain, very busy to create their own team, support controllers in providing them guidance and support, help them interpreting the Regulation, implement exceptions to the GDPR into their own local laws (if they chose to do so), examine how to deal with breach notifications, work on DPIA submissions, etc. So the top priority is not to sanction everyone, but more to get ready for having the right staff to support this massive change in the regulatory landscape. GDPR may be a huge project not only for those who process personal data, but every stakeholders, including authorities pressured by the Commission for their own readiness. Being busy, does not mean that no sanction will occur. My sense is that there will be sanctions, but not immediately as everyone will be in a rush.
  • Regulation (UE) 2016/679 does not indicate fines as the first, nor the last measure if failing to comply with the law. In theory, a supervisory authority would warn the controller before a infringement of the law, where it is likely to occur. When a GDPR audit will occur in less clear cases, there will be room for dialogue and exchanges between authorities, legal counsels, appointed DPOs, outside counsels, data processors and other players of this privacy eco-system. It will also be interesting to see if the level of complaints issued by individuals will increase in the future, or if GDPR compliance will build more trust. Some people tend to forget that the GDPR is a formidable opportunity for organizations to advertise their good behavior and willingness to listen to the clients’ needs and respect their rights.
  • Compliance shall be maintained and monitored over time. GDPR compliance is not a one-shot project. It becomes a new behavior for companies vis-à-vis their clients and their business partners and it has to be included in the organisation’s processes. This will continue for as long as the Regulation remains in force, which means that a fine may occur much later. Your organization may be GDPR ready for 25 May 2018, but might not be any more if compliance is not maintained over time.
  • (edit) More than 70 provisions of the GDPR offer room for EU Member States to deviate from the Regulation. This means knowing the GDPR as a general law is not sufficient, and there will be different approaches depending on the countries. Germany being the first country to adopt its own adaptation of the GDPR in its local data protection law. You can access links on another article of this blog to track Member States’ readiness and deviations from the GDPR. As all the provisions of the Regulation are not self-explanatory and contain many provisons subject to interpretation, compliance with the GDPR remains a case-by-case assessment and will be subject to interpretation. As mentioned in this article, it could take around 10 years “before the GDPR might be considered a mature piece of legislation that is well understood“.

__________________

OTHER THREATS AND RISKS THAN FINES

Data processors of personal data (controllers and processors) should not only fear fines. A fine may just constitute an additional bad taste to an already too salted menu.

Personal data processors should take into consideration other risks or threats to their business as a result of GDPR non-compliance than just fines. Here are just a few examples that demonstrate how non-compliance may impact your organization and potentially your business as a whole:

  • reputational damage, financial and customer losses after an incident. Notifications of cybersecurity incidents to the individuals, when a breach is “likely to result in a likely to result in a high risk to the rights and freedoms of natural persons” (art. 34 (1) GDPR), reputational dammage causing loss of business opportunities, loss of customers, potential contractual liabilities, breach of contract, (just to name a few), may be much more damaging than a fine. If you read the news, you probably heard about the Talk-Talk disaster, where the unprepared spokesperson of Talk-Talk gave the worst signal ever to their customers when making a public statement about a data breach incident.
  • business discontinuity and costs recovery due to an incident. Not only a cybersecurity incident may cause the organization to stop being able to conduct its regular business and have reputational consequences on the market, but it will require to spend a lot of money to conduct investigations, fixing the issue, changing the processes where necessary, put in place stronger measures to prevent further incident, etc. A cybersecurity incident does not mean you are in breach of the GDPR, but with the increasing amount of personal data processed through connected networks, it is likely that a breach will also concern personal data of natural persons, which is regulated by the GDPR. This is where putting in place appropriate technical and organizational measures (which I call “ATOM“) plays a crucial role. In the most optimistic scenario, a well equiped and prepared company may not even require to inform the authorities, nor the individuals. In any case, it remains crucial to discuss and implement a cybersecurity preparedness plan and an incident response plan with the relevant people on a senior level.
  • suspension of data flows. While a cybersecurity incident may cause business discontinuity for a relative short period of time, an authority may impose a suspension of data flows. Despite the practical aspects of how an authority may enforce such measure, this might be damaging to the company if there is a business need to process the personal data.
  • competitors taking market share. This is a fear that some organizations should think about if they think non-compliance with EU privacy laws are just an academical topic. This is also where the GDPR is a great opportunity.
  • long-term ability to do business affected. Suspension of data flows may not be a common sanction given by an authority. However, non-compliance may prevent organizations to continue doing business with EU clients and cease to be competitive, losing market share.
  • loss of customer confidence.
  • staff losses and senior executive resignations.
  • allocation of an extra budget on security, data protection, restructuring, new roles and internal audits.
  • etc.

While NOT all organizations around the world falling into the scope of the GDPR will become GDPR compliant as of 25 May 2018, businesses and organizations processing personal data creating particular risks for the data subjects will be in the focus of the authorities. The so-called “Lex Facebook” will motivate authorities to focus on large companies such as the GAFAM and BATX, but also on their providers.

As long as your organization can demonstrate that GDPR readiness is on the top list of priorities and that working hard to achieve full compliance, you may be on the road to safety.

Be prepared, but not scared. Make the GDPR an opportunity, not a blocking point. Don’t fear fines, collaborate, remain transparent, prepare to demonstrate that you are working on compliance and that it is a priority for you. And if you need advice, then hire a specialized law firm.

__________________

By Gabriel Avigdor | NTIC.ch

Abilify connected pill: ethics and privacy aspects of Personal Health Monitoring

ABILIFY MYCITE: A FIRST FDA APPROVAL FOR mHEALTH AND CONNECTED MEDICAL DEVICES

On 13 November 2017, we have probably reached a historical new step in digital health (and mHealth) with this market approval from the FDA for “Abilify MyCite“, the first digital tracking-pill which sends data to your doctor. This connected pill is used to track whether patients sufferring from schizophrenia, bipolar I disorder, and depression have taken their medication, which is used for Personal Health Monitoring (‘PHM‘).

As mentionned by Pharmacytimes:

the approval of the pill and the sensor together represents a first for the FDA

even if the sensor itself that is used along with aripiprazole (substance used for patient suffering from schizophrenia) was first cleared for use by the FDA in 2012. As secondary or side effects, the clinical trials revealed adverse events such as nausea, vomiting, constipation, headache, dizziness, uncontrollable limb and body movements (akathisia), anxiety, insomnia, and restlessness. However, the common adverse events associated with the sensor were related to the patch, and were predominantly skin irritation.

Find more information on the website of the FDA.

________________________________

TECHNOLOGY AND FUNCTIONALITIES – How it works

On the technology side, the sensor embedded into the Ability MyCite pill syncs with a smartphone and sends an alert to the patient’s smartphone. The doctor receives also a notification through the App when the medication is ingested via a patch that is worn on the surface of the skin of the patient. If the patient shares its data with his practitioner, the latter has the ability to monitor whether the patient has ingested properly. According to the US TV channel PBS, researchers are also trying to manufacture ePills that collect and process other body-related data by monitoring internal heat of the body for several days long.

________________________________

TECHNICAL ASPECTS OF THE DEVICE

According to LiveScience, the technical aspects are as follows:

“It’s a partial power source, “the patient becomes the battery”. The pill integrates a silicon chip with a logic circuit and contains copper and magnesium.  The chip’s logic circuit makes a small modulated current — a graph of the current levels would look like a sine wave. Since the human body is conductive, the wearable sensor can pick up the changes. The modulated current can encode ones and zeroes, similar to an FM signal. “It works in a similar way as an EKG,” or electrocardiogram. These machines pick up on changes in electrical current in the body to monitor heartbeats. The wearable sensor does the same thing, though the current is smaller.” The pill is designed to work for only about 3 minutes. That’s just enough time for it to send a signal to the wearable sensor that it should wake up and start gathering data. That saves battery power and allows the wearable sensor to work for a week at a time.

The patch and sensor is manufactured by the company Proteus Digital Health and aripiprazole marketed by Otsuka Pharmaceutical.

________________________________

ETHICS AND LEGAL ISSUES

PATIENT MONITORING AND REDUCING HEALTH COSTS

Personal Health Monitoring (‘PHM ) contains at least two major advantages.

MEDICAL COMPLIANCE – being the “consistency and accuracy with which someone follows the regimen prescribed by a physician or other health professional“. In the context of mental disability, the physician must ensure that the patient suffering from a mental disorder takes the prescribed medication on a regular basis. This may be particularly interesting for patients who may find themselves incapable of making a proper judgement (such as elder people). In the USA, a study from the National center for biotechnology information showed that “an estimated 50% of those who respond well to medications are nonadherent to their treatment regime“. Therefore, medical compliance is also a important challenge for patients who are suffering from a mental illness; and

HEALTHCARE COSTS – which could be reduced if more patients would take their pill properly. Consequences are both medical and financial. When a patient do not or, forgets to, take a pill, or do not follow the treatment as prescribed, his/her health may be worsened and this person may require treatment adjustment, more medicine, another hospitalisation or even a further surgery should there be a need to. In particular, this article indicates that the “loss that the taxpayer incurs when patients fail to take their medication, the cost of which is assumed to be at least $100 billion. According to an American report, these numbers could even be between $100 et $300 billion.

*  *  *
TECHNOLOGICAL ADVANCEMENT: YES.  BUT AT WHAT COST AND
TO WHAT EXTENT DOES THIS REMAIN A PROGRESS?

Although such technological advancement (connected pill to track patient’s medical compliance) is remarkable for healthcare costs reduction, not everybody agrees to it, especially within the medical profession. Moreover, it is legitimate to ask to what extent such technology can constitute a practical improvement, not just a scientific progress.

What value does this progress add for patients, the healthcare system and the society in general? What does it improve, is it better than before? If yes, how and what are the bad sides of it? What is the balance between the bad and good sides of this? Will the benefits for the patient override financial benefits?

Some people already rose their voice and expressed reluctance to Personal Health Monitoring (‘PHM’), which scientists have already looked into and published on this complex topic. (see additional notes on that topic at the end of this article).

Altough a few have called this practice “medical Big Brother (or biomedical Big Brother according to the New York Times), PHM raises a number of ethical questions, which can lead to at least 8 key  points and interrogations:

1. Privacy – for personal health monitoring, two types of privacy aspects can emerge, which are personal privacy and data privacy. This also relates to risk of interference in the private life of the patient by collecting and processing health (sensitive or even biometric) patient data. Is such data processing in compliance with explicit consent of the patient, who may not able to make a proper judgement?  This article describes very well some privacy aspects  that personal health monitoring are raising.

2. Visibility or  obstrusiveness – Visibility appears to refer to “the degree to which a PHM device is noticeable by the user and other individuals, both at home and in public“. In accepting the use of tracking devices for dementia patients, cognitively intact older adults identified ease of use, size and weight as important in accepting a tracking technology. One consider the patient differently, being seen as an ill human being. This may create a risk of discrimination by the society and the person might be more vulnerable;

3. (over)Medicalization – the devices have the effect of reminding the user or occupants of a medical condition in a non-medical environment. The home could be turned into a medical environment or “de facto intensive care unit” as well as creating stigmatization linked to the fact that the person feels under surveillance;

4. Social isolation – the patient monitored will reduce or cease going to the hospital or to see the physician for regular check-ups. Therefore, this could increase patient’s loneliness and social isolation with psychological and medical consequences with a lack of motivation and reduction of the mentality;

5. Autonomy what room remains to the patient with PHM to decide how to take the pill or not? What if the patient wishes to stop taking the pill, for good reasons? Where are we talking about pressure on the patient will?

6. Shame et identity – what consequences could there be on the personality of the patient, who may be perceived by the society as marginal human being, in particular when the treatment is visible?

7. Providing healthcare – with remote care, to what extent does this improve or reduce its effectiveness, especially when the patient does not move him/herself anymore? Is this an efficient manner to treat a patient, shall this remain the exclusive way of doing it or should we combine it with physical appointments?

8. Security and reliability of the technology. This element is obviously central for both privacy and health reasons.

Do these aspects reduce or delete the patient’s responsibility or does it create an over-responsibility? With or without benefits?

How about from an insurance point of view if the patient do not takes the pill while he/she is being monitored with or without worsening of his/her health? Suspension, reduction, cessation of the payment by the insurance or the medical measures? To what extent can the insurance have access to such information or personal health-related data?

________________________________

A PRIVACY PERSPECTIVE?

As this article pointed out, despite huge costs reductions (around 100 billion) and health benefits of this mHealth technology for the healthcare system and patients, patient’s privacy is an area of concern which is even more related to medtech technologies with Big data and IoT (Internet of Things) in the healthcare sector. Combined with the patch worn by the patient, the sensors that are embedded into the pill may provide far more data about the patient than just taking a pill or not.  The device may be used in a way to gather data from the patient’s body, such as the heart rate, how much the patient sleeps, how fit the patient is, etc.

The major concern is the misuse of such sensitive data, which could be used by corporations or government to collect more personal and biometric information about citizens that they had consented to revealing. Furthermore, since the technology has only recently come into the public domain, very few regulations exist to police it, says this article. Misuse for marketing purposes, is one thing. Data breach, criminal intents, or cyberattack on the device itself are another thing with severe consequences for both patients’ health, privacy and reputations of tech and pharma organizations. Further, another study explains that it appears impossible to obtain informed consent from recipients of PHM because full understanding of the implications of using PHM cannot be gained without actually using the technology. Therefore, using the technology without informed consent, may be considered as illegal processing, which creates a vicious circle. This article suggests that piloting methods such as storytelling and prototyping may present a possible solution to this problem and avoid collecting personal data without the proper legal basis for processing.

________________________________

PRIVACY AND INFORMATION SECURITY 

From an EU and Swiss perspective, health-related data (health or biometric) is considered as a special category of personal data that we call “sensitive data“, where the processing is generally prohibited, unless the controller can demonstrate a legal ground for the processing, such as the patient’s explicit consent (art. 9 §2 (a) GDPR, art. 4 al. 5 and 13 al. 1 of the Swiss DPA), the provision of medical services by a health professional tied by a secrecy obligation (art. 9 §2 (h) and 9 §3 of the GDPR) or private overriding interests (art. 13 al. 2 of the Swiss DPA). As one can read in the press almost everyday now, cyberattacks can happen, and a data breach may lead authorities to impose hefty fines, with 4% of worldwide annual turnover according to article 83 of the GDPR, although fines should remain a last resort in the sanction mechanism applied by the authorities. I wrote a note in this article about the envisaged approach with fines and sanction pursuant to the GDPR.

In addition, the doctor would also have to require the patient’s prior explicit consent before sharing, or allowing any third party to access, any sensitive data . See my previous note on recommendations for outsourcing in the context of medical billing for healthcare professionnals.

There are many other obligations under these regulations, which this article does not intend to cover.

________________________________

CONCLUSION

This FDA approval sounds like a very good “signal” to pharmaceutical companies developing connected drugs and advanced digital life science technologies, mHealth and medical devices.  This can improve the life of many patients, while saving costs and improving efficiencies in the treatment.

There is no need for scaremongering. However, remaining careful using the device for the purpose of the treatment, informing the patient and gathering explicit consent, processing only the data that is necessary for the purpose of the treatment, working with ethics and respect for the individual, especially if these patients have a reduced of discernment, are some good steps to ensure the individual’s privacy.

_____________________

To read more on this topic:

  • Mittelstadt, Brent, Ben Fairweather, Mark Shaw and Neil McBride. “The Ethical Implications of Personal Health Monitoring.” IJT 5.2 (2014): 37-60.Web.4Feb.2018.doi:10.4018/ijt.2014070104.
  • Mittelstadt, B., Fairweather, N.B., McBride, N., Shaw, M., 2011. Ethical Issues of Personal Health Monitoring: A Literature Review, in: ETHICOMP 2011 Conference Proceedings, ETHICOMP 2011, Sheffield, UK.
  • Elin Palm, Anders Nordgren, Marcel Verweij and Göran Collste, Ethically Sound Technology? Guidelines for Interactive Ethical Assessment of Personal Health Monitoring, 2013, Interdisciplinary Assessment of Personal Health Monitoring, 105-114.
  • Nordgren, Anders. (2013). Privacy by Design in Personal Health Monitoring. Health care analysis : HCA : journal of health philosophy and policy. 23. . 10.1007/s10728-013-0262-3.
  • Data protection and privacy in connected health, an article from a blog for research and innovation relating to emerging technologies.
  • Information notice  from “Otsuka Pharmaceutical”, the manufacturer of Abilify Mycite.

By Gabriel Avigdor | NTIC.ch

Safe harbour - Ntic

Safe Harbor Framework invalidation : recommendations for Switzerland

I.  Introduction

In a decision dated October 6th, 2015, (Case Max Schrems vs Facebook) the European Union Court of Justice invalidated the Safe Harbor Framework, which had permitted U.S. companies to comply with EU restrictions on the transfer of personal data outside the EU.  As a non EU country, Switzerland concluded the “US-Swiss Safe Harbor Framework” (“Swiss SHF”) which is the equivalent to EU safe Harbor. This decision creates a real legal vacuum for around 4,500 companies which were relying on the Safe Harbor Framework to transfer data to the USA, which also applies in Switzerland.

Read this good article that summarizes the context of the decision, the legal issues and the proposed recommendations for multinational companies in EU.

II.  Communication from the Swiss Commissioner

In his latest communication (in French), dated October 22nd, 2015, the Swiss Federal Data Protection and Information Commissioner considers that the Swiss SHF is not a sufficient legal basis any more and recommends to all Swiss companies to amend their contracts with US corporations to include provisions which guarantee an adequate level of data protection.

In addition, the Commissioner recommends to Swiss corporations, by January 2016, to

  • promptly and expressly inform all data subjects of a possible access to their data by US authorities; and
  • include provisions in their agreements to support data subjects in implementing adequate measures to ensure sufficient legal protection, execute corresponding procedures and accept any effective decision from an authority.

The Commissioner reminds that any individual is entitled to require a civil Court to examine the validity of each data transfer.

III.  Conclusion

With this decision, data transfer to the USA is not illegal provided that companies complies with the above mentioned recommendations and update the provisions in their agreements with sufficient guarantees that measures are taken to ensure data security.

However, the United States have been clearly considered as a country where the level of security related to data is not adequate due to US regulations allowing mass-surveillance. This is a direct consequence of the Edward Snowden revelations. Therefore, as long as companies comply with their obligations to ensure adequate protection measures and inform individuals of a potential access of their data by the US authorities, data transfer shall remain valid.

In Europe, Article 29 Group (G29) has required EU institutions to renegotiate a new Safe Harbor Framework, compatible with EU laws, within 3 months from the decision of the European Court. Given the number of companies that are subject to this decision, this would be very interesting to follow.

Tails 1.0 : the amnesic and incognito live system

I.     Tails 1.0

1.1   Version 1.0 released

It is official. Since the 29th of April 2014, the last baby of the Tor Project has ben released and is now available for download : Tails 1.0.

“Privacy for anyone anywhere”

Tails 1.0 is a live operating system that protects you against data gathering and increases your privacy on the Internet. It includes built-in open-source software and is bootable from a USB flash key or a DVD. This software has been used by Edward Snowden to evade the NSA and communicate with Glenn Greenwald in June 2013.

1.2     Specifications

Its little name: the amnesic incognito live system.

Like Tails 1.0 is an amnesic operating system since it doesn’t record your data and erase your traffic information when you close the program. It is also incognito because your Internet traffic is confidential, secure and your data encrypted (files, emails, chat, etc.).

As well as other existing software (Bouldows for example), Tails is a live operating system and works can be launched from a USB flash key, an SD card or a DVD. When installed, Tails includes lots of open-source software usable for the Internet (Tor browser, Firefox, etc.), data encryption tools (such as Truecrypt) or simply office use (Open Office, Gimp, etc.). Tails 1.0 is distributed under a GNU/GPL licence including Creative Commons logos or coming from thenounproject such as the USB logo of Tails 1.0.

The official website says that it helps you to :

  • use the Internet anonymously and circumvent censorship;
    all connections to the Internet are forced to go through 
    the Tor network;
  • leave no trace on the computer you are using unless you ask it explicitly;
  • use state-of-the-art cryptographic tools to encrypt your files, emails and instant messaging.

 II.    Tor Project & Cie

Tor Projects (logo)

Tor Project regroups developpers that advocate for more open-source, security, anonymity, encrypted data and non-trackable, free software. In a few words non-commercial purpose and building software for confidentialiy and full privacy of the users on the Internet. Tor is an acronym for The Onion Router because of it refers to layers of encryption, nested like the layers of an onion, used to anonymize communication. As free software it enables online anonymity and censorship resistance. Tor directs Internet traffic through a free, worldwide, volunteer network consisting of more than five thousand relays to conceal a user’s location or usage from anyone conducting network surveillance or traffic analysis.

Parallel to Tor Project, Guardian Project is a good complementary resource for open-source Smartphone software for the public and developers.

Encrypted email applications, browser working with unique proxys or jumping ones, anonymous and encrypted live chat, coded messages sent though steganography principle, lots of software that are more accessible, more democratical and less elitist.

III.    Tails : for who and for what use? 

3.1    First test of Tails 1.0 (short overview)

When you start it, Tails seems to be accessible to anyone. You can be a Linux, Windows or Mac OS user, you will be guided step-by-step for installing it and use it. You lose a bit of your comfort zone by setting up the starting options and tools (such as keyboard, mouse, Wifi, admin password, etc.), but nothing really mad if know how to install an OS.

Tails desktop

Windows XP users will fatly find their way with an original option : “Windows camouflage” which is simply Tails OS with a Win XP theme.

Mac OS users will have to bite the bullet, because its less intuitive. For my first start, it was impossible to access to the local data on my HDD of my Macbook! In addition, please use a mouse because the use of the Mac touchpad rapidly becomes a nightmare. (Do not forget to press alt key to boot Tails).

Globally, Tails is rather intuitive, with lots of comfortable options such as a persistent volume where some data and new software can be saved as well as your settings (otherwise you’ll have to start all over again every time you start Tails) and can be updated. This option only works with a USB flash key, because a DVD cannot stock and save any more data on it. Connection to the Internet is easy and the jumping system method of Tor lets you surf on Facebook or Gmail without any problem. Even without VLC, Totem video player is rather good and read almost without any problem a .mkv video file including H264 for video codec and AAC for audio with multilingual audio track and subtitles.

At this stage, we can say that Tails 1.0 is intended for a broad audience, not only for those who loves penguins. You don’t know programming or writing code lines in a terminal, it is not a problem. Nevertheless, in my opinion Tails will not be accessible to everyone and lots of patience is needed for a dayly use, especially if you always have to configure the settings again at every starts. But obviously, it is the very principle of a live operating system …

3.2    Multipurpose use

Tails 1.0 includes an interesting list of open-source software such as Iceweasel for the Internet (GNU version of Firefox), Claws mail for emails, Pidgin for chatting, Open office for documents, Gimp (Photoshop’s equivalent) or TrueCrypt for data encryption. But, this Operating System is not foolproof. The user is warned about the limits of the program, especially for data encryption and deciding how to act with the computer and the information spread on social network or the Internet. Choosing a good password and change it from time to time is a must.

Tor Browser is not a standard Internet browser. It is from far slower than any other browser because of its functions. Blocking Ads, scripts, spy software, cookies, run Internet trough jumping proxys or data encryption require times, slow your network and block most websites that do not match with that settings. Most of e-commerce websites, social network or standard websites will not work if specific blocking options are enabled. Same script when you use Firefox with too many add-ons or plugins such as Ghostery, Adblock Plus, Donottrackme, etc.

Thus, running Tails is rather simple and all the built-in software let you have a daily use, but not for everyone or anyhow. Installing more software on your USB flash card and saving settings are an indication of the longevity of the project. Will it be enough for a very broad use? A wide professional use in private or administration sectors is something even more uncertain …

IV.    Conclusion

Other projects like Guardian or Tor are necessary for helping the web community to protect user’s privacy and anonymity and other strong values of tomorrow’s Internet. Recent software developments allow to reach a wider and broader audience. In that context, the massive innovative efforts of the open-source developers must be welcomed. These projects encourage people and governments to promote, use or develop such software. The Swiss Federal Supreme Court is a great example with its project: “OpenJustitia” (only available in French or German).

However, few of these software are really used by a majority of the Internet users. First, these programs are not of public knowledge, and Internet users ofter do not know alternatives exists or do not want to know about. Second, for years these software have not been very “user friendly”. Problems of settings, installation or use may repell the average user motivated by more protection but do not have sufficient knowledge or do not understand the proposed tool. Finally, the very geek design may often rejects users in a media hype world where people think that because it’s nice, it’s better…

Visiting Tor and Guardian Projects websites may be very instructive. Lots of unknown software for PC, Mac OS or Android are available for download. Their use is often simpler as we could have thought and allows you to decrease Internet tracking (see my article about Panopticlic in french) and preserve anonymity.

What about you, have you or will test Tails 1.0 ?

More information and links

  • Tor Browser;
  • guardianproject.org with web apps for a better stay on the Internet;
  • Orweb, Android version of Tor Browser;
  • Orbot : Android app with proxys servers;
  • Startpage : neutral search engine that do not give any information about you to third parties;
  • JonDo and JonDoFox : Tor Browser alternatives;
  • tens of others … !
Ntic Sao Paolo

Net Mundial : (extra)ordinary conference?

Next topic to come : Internet governance discussed in Sao Polo

During these 23rd and 24th of April 2014 took place the NETmundial Multistakeholder conference in Sao Paulo, Brazil for a debate regarding Internet governance. Not less than eighty seven representants from all over the world countries have been participating. All the participants came from all interested sectors such as governments, non-profit organizations, citizens of the civil society and also from academic, technical and research institutions or private sectors.

This meeting have focused on the elaboration of principles of Internet governance and the proposal for a roadmap for future development of this ecosystem. The goal is to consolidateproposals based on these two topics. NETmundial represents the beginning of a process for the construction of such policies in the global context, following a model of participatory plurality.

Parallel to these topics, the debate was also focused on security, privacy and of course surveillance matters due to the Snowden case and the massive surveillance revelations thank to PRISM by the NSA.

The outcome of this conference is a non-binding document with large principles, which will be discussed as well as the future of Internet governance in the full article coming in the next couple of days on this website.

In advance, I thank you for your patience, loyalty and stay tuned on www.ntic.ch to read the full article.

The editor.