Tag: Data protection

Google fined €50M by the CNIL under the GDPR

This 21 January 2019, the French data protection supervisory authority (Commission Nationale de l’Informatique et des Libertés – the “CNIL“) fined Google LLC 50 million Euros for breach of the General Data Protection Regulation (the “GDPR“).

In today’s communication (in French), the French authority issued the highest fine against Google LLC since 25 May 2018 considering severe infringements of the GDPR by Google for failing to inform properly the users and collecting valid consent for targeted advertising services.

SCOPE OF THIS DECISION. It is worth noting that this decision is solely based on investigations of the CNIL related to configuration of new Android device for the first time by a user. This particular infringement of the GDPR only relates to the privacy notice displayed to users when they create an account and when logging into their new Android phone. However, the full complaint has not yet been examined by the CNIL and goes far beyond that. The complete case is much broader and related to targeted advertising on Youtube, Gmail and Google Search platforms. The CNIL will have to examine how Google may have or not “forced” users to consent to sharing their personal data via Google targeted ads services. So we can expect to hear more from the CNIL in the upcoming months in this case. This is probably only the beginning of a long series for 2019. The two organizations also filed (as explained below) similar complaints against other GAFAM in several jurisdictions.

________________________________

FINDINGS OF THE CNIL

The CNIL considered that Google did not comply with the GDPR for three main reasons: (1) lack of transparency (art. 5 GDPR); (2) insufficient information (art. 12 and 13 GDPR); and (3) invalid consent collection (art. 7 GDPR).  The two complaints were brought by Max Schrems’ non-profit organization called “None Of Your Business” (NOYB) and the association La Quadrature du Net, a French association that regrouped complaints from 9’974 individuals. Those two organizations claimed that Google’ services, including the targeted advertising services on Android OS, did not comply with its obligation to process personal data with the proper legal basis (art. 6 GDPR), forcing users to share massive amount of personal data and therefore compromising their privacy without their consent.

Those complaints have just been confirmed by the CNIL in today’s findings. After that, it is interesting to read on the blog of NOYB, that Google will move its EU headquarters to Ireland with effect to 22 January 2019, with the Irish DPA (Data Protection Authority) as the lead authority.

The French authority adds some interesting considerations to its findings. The CNIL explains that with Google current services, due to the way the data are collected, the volume that can be processed and the type of data collected through those services, it can result in revealing entire parts of someone’s life, which becomes very intrusive. The CNIL also considered the fact that Google’s business model is partially based on those intrusive services.

Finally, the CNIL explains that, essentially, despite Google’s efforts to change its processes, Google is still not compliant. This also means that as long as Google remains non compliant, it may face other complaints and, potentially other fines unless the way Google processes data about individuals changes drastically.

________________________________

HISTORY OF THE CASE

Two massive complaints on 25 and 28 May 2018 for € 7,6 bn

25 May 2018. Max Schrems – the Austrian privacy advocate who provoked the cancellation of the Safe Harbor framework by the European Court of Justice (see judgement here) – founded a not profit organization called “None Of Your Business” (NOYB) to support consumers and data subjects in filing complaints against companies and to authorities to enforce and protect their privacy. Just the day the GDPR became enforceable on 25 May 2018,  Max Schrems sued Instagram (Belgium), WhatsApp (Hamburg, Facebook (Austria) and Android (France) with a massive complaint amounting to € 7,6 bn via its NGO for infringement of the GDPR. Find more details on NOYB’s website here.

28 May 2018. The French Digital Rights Group “La Quadrature du Net” lodged a complaint on 28 May 2018 against Google, Apple, Facebook, Amazon and LinkedIn in front of the CNIL on the behalf of 12,000 individuals for illegal processing of personal data.

The CNIL’s sanction of € 50 millions issued today is only one sanction against one company – Google LLC – and in one juridiction. There is most likely other sanctions to come if other authorities follow the CNIL’s argumentations and considerations.

In terms of procedure, Google can appeal to this sanction and contest the fine (edit 24-janv-2019), which the company announced publicly. Even if the fine remains low compared to the €4bn it can incur in the event of a maximum fine, the amount is high for this case. In its public statement, Google said:

We´ve worked hard to create a GDPR consent process for personalised ads that is as transparent and straightforward as possible, based on regulatory guidance and user experience testing

By appealing against this decision, Google wants initiates the process of a precedent in interpreting the GDPR’s requirements on information, transparency and how to validly obtain consent, particularly in the area of targeted advertising.

Google’s appeal is therefore highly strategic. Not contesting this fine would create room for potential more severe sanctions, especially as the scope of the case is limited. In addition, it could be seen as an indirect acknowledgment of responsibility for using non-compliant practices.

Finally, Google defends itself by arguing that it has worked hard to set up data collection in order to respect transparency, but also said:

We´re also concerned about the impact of this ruling on publishers, original content creators and tech companies in Europe and beyond

We will see if his work has been sufficient or not and how strong this EU Regulation can effectively be in practice.

________________________________

THE CASE IN MORE DETAILS

To get into more details, the CNIL provides the following explanations to justify the sanction against Google:

  • Breach of transparency: the transparency principle refers to how you inform individuals about the processing activities. This usually takes the form of privacy notices. This information is supposed to remain concise, clear, accessible, unambiguous and intelligible by any person.

This was not really the case. Google spread all that information in many separate places through links and buttons which made it very difficult to access, understand and takes ages. At the end, all that information was only accessible after 5 or 6 actions, in any case after several steps to know what data are collected about the individual. The information was not clear enough, vague and described in a too generic way. That means that if nobody takes the time to read that information (why would Google collect your data for what purpose, for how long, what categories of data are used for the targeted advertising, etc.), the obligation of having a clear and easily accessible notice is not achieved. Also, Google failed to inform about the retention period of certain personal data (for how long will Google keep that data).

  • Invalid consent: Google requested the consent of the users to collect the personal data. However, the CNIL considered that this legal basis was not valid for the options of customized advertising for the two following main reasons:

The consent was not informed. This means that users do not understand the scope of use of the data. For example, in the “customized publicity” section, it is not possible to see how many services, sites and applications are related to the processing and there is no information about the volume of personal data that those services will process and combine.

The consent was not specific, nor unambiguous despite the fact that users may have the ability to select several parameters. According to article 7 of the GDPR:

request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

With Google targeted advertising services and options, the users could only access those parameters by clicking “more options”. Also, the option to use “targeted advertising” was already pre-ticked, which forces the user to turn it off. So the option will remain active, if the user does nothing, unless there is an active action from the user to disable the option. Therefore, using pre-ticked boxes is contrary to the principle of privacy by default (art. 25 GDPR), which requires to turn off any settings or parameters by default to apply a maximum protection of privacy to the user. It is only up to the user to decide whether he or she wishes to increase the level of intrusiveness to his or her privacy and agree to share any personal data. Finally, Google only provided one box for the users to click which appeared like this:

“I accept Google’s terms and conditions” and “I accept that my data are used as described above and as detailed in the privacy policy”

Such bundled consent, which is not specific and do not provide any details for each purpose is not compliant with the requirements as set out in the GDPR.  Where several purposes for processing personal data exist, users must have the ability to only consent to those purposes that they wish. Having all the purposes all-in-one, does not work under the GDPR.

________________________________

ARE THOSE REQUIREMENTS NEW UNDER THE GDPR?

Yes and no.

Yes, the requirements to collect a valid consent has been extensively strengthened. It not as easy as before to collect a valid consent and as this case demonstrates, there are individuals and authorities out there that can have a word and ultimately impose fines to your organization.

No,  the principles of consent, collecting personal data with a valid legal basis and informing the individuals via privacy notice, are not new from an EU data protection legislation. The obligation to process personal data with a lawful ground already existed under Directive 95/46/EC and also applies under the Swiss Federal Data Protection Act (DPA), as probably in most of the jurisdiction that have adopted comprehensive data protection framework. A company responsible for collecting and processing personal data has to justify a valid legal reason. As a reminder, the GDPR offers 6 different legal bases to justify the processing of personal data (article 6 GDPR), which are:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protect the vital interests of natural persons;
  • performance of a task carried out in the public interest or in the exercise of official authority; and
  • legitimate interest.

Each of those legal bases have their pros and cons, but where you use the consent, you should remain careful to collect it lawfully, unless the processing becomes illegal. With the GDPR, the consent has become much more difficult to obtain. In particular, you need to inform and explain who shall consent, what you will do with that data, for what reasons and based on what legal basis you process the data, with whom you will share them. And this shall apply for each purpose. If those conditions are not, the consent is not valid illicit and you cannot process the personal data.

And this is what happened to Google LLC in the case of targeted advertising, for this first part of the story.

________________________________

By Gabriel Avigdor | ICT.ch 

Digital Lawyer

30 days before the GDPR – not even Member States are ready

If, as an organization, you think you are alone in the dark 30 days ahead of the GDPR’s worldwide implication, don’t be afraid, you are not.

It is not surprising to read this article that reminds that not only organizations, but also a majority of Member States are not ready for the GDPR. Private and public organizations around the globe falling into the scope of the GDPR have invested many resources to prepare for compliance to Regulation 2016/679 (the ‘GDPR’), each with different approaches and priorities. The situation is similar with Member States. They have to organize their national implementation of the GDPR, decide what provisions may be a matter of national importance with regard to their specific culture and their national legal framework.

Nevertheless, not all countries are as good students as Germany, Austria, Belgium and Slovakia the only 4 countries that have passed a national law before 25 May 2018. In January 2018, Věra Jourová already pointed out that, except 2 countries (Germany and Austria), 26 countries were unprepared to the GDPR. According to the BakerMckenzie Survey 2018, dated January 2018, 20 countries have either published or planned a draft bill to their Parliament, while 5 countries (Bulgaria, Greece, Malta, Portugal and Romania) haven’t demonstrated a strong will to implement the GDPR.

[edit 20.05.2018:] On 18 may 2018, just one week before the GDPR applies, the  “EU Observermentioned ‘eight EU countries would not be ready for the deadline‘. According to this article, some countries are, or are expected to be, ready on time (Austria, Germany, France, Croatia, the Netherlands, Sweden and Slovakia), others will be between end of May and June (Spain, Italy, Portugal, Romania and Latvia),  while the following are not going to be:

  • Belgium;
  • Bulgaria;
  • Cyprus;
  • the Czech Republic;
  • Greece;
  • Hungary;
  • Lithuania; and
  • Slovenia.

________________________________

The GDPR: a fully harmonized
legal framework ?

The GDPR is a Regulation, which means that it has binding legal force throughout every EU Member State and enters into force on a set date in all the Member States. In the case of the GDPR, the text was approved by the European Parliament on 14 April 2016 and entered into force in 24 May 2016. The date for binding effect of this Regulation was set to 25 May 2018, two years afterwards, which is the date that a majority of people remembers.

Although the GDPR is a Regulation that applies without the need for Member States to transpose provisions locally, the content of the GDPR gives room for Member States to do some tailoring with respect to certain provisions. For a Regulation that aims to create a ‘one-stop-shop mechanism for organizations active in more than one EU country, harmonize privacy in the European Union within a single market for data, creating identical rules in EU and beyond, the reality is a bit far from the goal and is not as clear as sought to be achieved, although it raises the bar of the privacy level in and outside EU.

In fact, the GDPR contains many provisions called “opening clauses“, (more than 70!!) imposing or allowing Member States to deviate from the Regulation (with stricter, less strict, or more detailed rules) and adopt exceptions. Some provisions of the GDPR impose Member States to have local provisions, such as personal data and freedom of expression or penalties, and other provisions give the opportunity to Member States to adopt or precise the text of the Regulation. These topics mainly relate to:

  • children consent;
  • employment data;
  • notification obligation relating to data breach;
  • designation of data protection officers (‘DPO’):
  • (non-) recognition of administrative fines;
  • professional secrecy;
  • scientific, historical or statistical purposes;
  • personal data of deceased persons;
  • special rules for special categories of data;
  • rules for genetic, biometric or health data;
  • national identification numbers/any other identifier of general application;
  • etc.

The opening clauses “run the risk of lowering the level of data protection“, said Christian Gemmin from the University Kassel in Germany. And it is worth noting that the famous sanction mechanism under the GDPR, that so many people are talking about, do not apply equally among Member States, both from an enforcement point of view, scope and amount.

For example, in Czech Republik, administrative fines for public authorities may be imposed only up to CZK 10 milion, (approx. EUR 358,000).  Same for Estonia, the Estonian law does not recognize the concept of administrative fines and thus such fines cannot be imposed in the way as set out in GDPR, but through its Data Protection Authority (‘DPA’). For Ireland, public authorities and public bodies will not be liable to administrative fines for breach of the GDPR, except where they are acting as an ‘undertaking’! In January, only Germany and Austria were fully in compliance with the GDPR.

On this website, you can find a very useful document, keeping up to date, compiling an overview of the topics that each EU Member State is implementing in its local law.

________________________________

What does it mean generally for countries that are not ready?

  1. everyone is late, including companies, a majority of Member States and data protection authorities (DPAs). And this is just a practical a reality.
  2. it creates legal uncertainty / insecurity for organizations processing personal data in those countries and or targeting consumers in these countries. These organizations cannot fully prepare to the GDPR until national laws are properly implemented into the national legal framework.
  3. it creates legal insecurity for data subjects. National proceedings may need adjustments to allow data subjects to exerce their rights and to enable enforcement under the GDPR. If not properly adjusted, data subjects would not be able to exerce their rights properly.
  4. this could “slow down the take-off of the harmonious application and the coherent application of the data protection rules throughout the EU” (as explained in this article).
  5. the EU Commission could file a lawsuit Member States that are unprepared (at this stage, all except Germany, Austria, Belgium and Slovakia) to pressure them on that topic, said Věra Jourová in January
  6. without synchronization of their readiness, member States may undermine the consistency mechanism (‘one-stop-shop’) as outlined in article 63 of the GDPR, as is requires cooperation between them to ensure proper application of the Regulation (see an opinion on this here).

________________________________

How to keep track of the changes for each Member States?

Some firms have performed the time consuming task to monitor and compile status of the GDPR implementation in the national laws of each EU Member States. Here are just a few, which I found useful and interesting:

  • Latham and Watkins: they put together a document and a free tracker available online here, which has the advantage to appears in one window. Honestly, this tool is just brilliant.
  • Bird&Bird: they have developed a GDPR tracking page relating to the developments and status of GDPR implementation in national laws country by country.
  • ReedSmith: in this article you can find a chart outlining current and pending changes within national laws and a list of legislative progress country by country.
  • Nymity Inc.: the well-known EU company that helps organizations with privacy tools, software, services and framework has developed and offers access to a tracking tool, which doesn’t appear to be free.
  • Nice Irish blog from Prof. Eoin O’Dell: updated on 25 April 2018, where you also find status of the countries and other links.

__

Article by Gabriel Avigdor | Ntic.ch

GDPR compliance: what if you don’t comply as of 25 May 2018

GDPR COMPLIANCE has been the very hot topic of 2017 and will continue to grow in the next couple of months, as we are reaching 25 May 2018, the famous date where Regulation (EU) 2016/679 will apply to any controller and processor around the world falling into the scope of the Regulation. This topic will increase in importance with general awareness, the importance to “think privacy first” before any processing personal data occurs, and the increasing number privacy pros arising out around the globe advocating about privacy.

In this historic race for data protection compliance, the European Commission published a new website, with extensive guidance on that matter. This site is pretty intelligible, and designed in a simplified and easily accessible manner. It covers important areas of the GDPR indicating, among others:

including an infographic section with a summary of key areas that relate to the GDPR such as rights and duties, and consequences for non-compliance.

Now processors of personal data may have to demonstrate to the authorities that, and how, they comply with the Regulation (‘accountability’ principle).

__________________

WHAT TO EXPECT IF YOU DON’T COMPLY WITH THE GDPR?

On its new website, the Commission reminds the 4 steps process before a supervisory authority may impose an administrative fine (art. 83 of the GDPR) on businesses or organizations for non-compliance. These steps are:

(1) WARNING ⇨ (2) REPRIMAND ⇨ (3) SUSPENSION OF DATA PROCESSING ⇨ (4) FINES

and according to the Regulation, sanctions shall “in each individual case be effective, proportionate and dissuasive ” (art. 83 § 1 GDPR). Therefore, the fine regime allows a supervisory authority to impose a fine in addition to other measures, being (among others):

  • warnings (art. 58 (2) (a) and recital 150 of the GDPR);
  • withdrawal of certifications (art. 58 (2) (h) of the GDPR); or
  • suspension of data flows (art. 58 (2) (j) and 83 (5) (e) of the GDPR).

__________________

WHAT DOES ARTICLE 29 WP SAY ABOUT FINES UNDER THE GDPR?

The Article 29 Working Party (‘A29WP’) just updated its 253rd document called “Guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679” (wp253). This document contains more details on the fine regime and how controller should behave to avoid fines.

The guidelines explains that warnings may already be given to controllers when processing operations are likely to infringe provisions of the Regulation. This means that warnings may be used as a preventive measure against a potential infringement (foot note, page 5 of wp253). Reprimand can, in some cases, replace a fine (page 9 of the guidelines), etc. In addition to this, the A29WP adds an interesting statement about the balance between imposing corrective measures with or without fines:

Fines are an important tool that supervisory authorities should use in appropriate circumstances. The supervisory authorities are encouraged to use a considered and balanced approach in their use of corrective measures, in order to achieve both an effective and dissuasive as well as a proportionate reaction to the breach. The point is to not qualify the fines as last resort, nor to shy away from issuing fines, but on the other hand not to use them in such a way which would devalue their effectiveness as a tool“.

The message is pretty clear, the supervisory authority shall ensure effectiveness through finding the right balance between fines, or measures, or both. Still, fines should not be “devalued” meaning, that a too nice fine may encourage controllers and processors to continue doing business without ensuring compliance.

You can access the guidelines on administrative fines here.

__________________

AUTHORITIES WILL NOT FINE EVERYONE AS OF 25 MAY 2018

It has become popular to hear and read from many people and consulting firms coming out of nowhere, shouting on social media and the internet, that the end of the world is going to happen in May 2018, should you be non-compliant. The reality is a bit more complex, and such statement isn’t true. It is true that after 25 May, there will be no more deadline for GDPR readiness, so sanctions may potentially be quite heavy when a controller is being audited, questionned by an authority or if an individual lodges a complaint against the controller. But this may only happen after the authority performs an assessment of the situation, starting with exchanges of communications, then maybe an audit if a data subject submitting a complaint for an infringement of their rights, or if one claims a the controller is breaching the law. You’d better be working on your GPDR readiness if you are subject to the Regulation and haven’t started yet. But it seems necessary to remind some basic considerations that are a bit less scaremongering on the sanction regime and compliance readiness, just to name a few:

  • Fines are not going to rain on data controllers as of 26 May 2018. This is a myth designed by hungry newly created consulting firms using fear as a marketing tool to sell their GDPR-related services. mid- to large organisations that are aware do not get trapped, but smaller may.
  • An authority will not issue a fine before having found evidence and probably warned the processor of personal data (controllers and to some extent processors) that there is, in their opinion, a breach of the law. It means that the process would require to conduct investigations , including audit of, or by, the controller, its retailers, suppliers or business partners, but also interpreting the GDPR, which is not easy.
  • According to UK ICO Steve Eckersley, “some investigations take 8-12 months to complete”. So it wil take some time. Taking the example of the UK, Steve Eckerley also mentions that “the ICO is now recruiting an additional 100-150 people to work on GDPR aspects and cyber security” predicting that the ICO will receive “30,000 breach notifications a year“. This is not a meaningless number.
  • Authorities are, and will remain, very busy to create their own team, support controllers in providing them guidance and support, help them interpreting the Regulation, implement exceptions to the GDPR into their own local laws (if they chose to do so), examine how to deal with breach notifications, work on DPIA submissions, etc. So the top priority is not to sanction everyone, but more to get ready for having the right staff to support this massive change in the regulatory landscape. GDPR may be a huge project not only for those who process personal data, but every stakeholders, including authorities pressured by the Commission for their own readiness. Being busy, does not mean that no sanction will occur. My sense is that there will be sanctions, but not immediately as everyone will be in a rush.
  • Regulation (UE) 2016/679 does not indicate fines as the first, nor the last measure if failing to comply with the law. In theory, a supervisory authority would warn the controller before a infringement of the law, where it is likely to occur. When a GDPR audit will occur in less clear cases, there will be room for dialogue and exchanges between authorities, legal counsels, appointed DPOs, outside counsels, data processors and other players of this privacy eco-system. It will also be interesting to see if the level of complaints issued by individuals will increase in the future, or if GDPR compliance will build more trust. Some people tend to forget that the GDPR is a formidable opportunity for organizations to advertise their good behavior and willingness to listen to the clients’ needs and respect their rights.
  • Compliance shall be maintained and monitored over time. GDPR compliance is not a one-shot project. It becomes a new behavior for companies vis-à-vis their clients and their business partners and it has to be included in the organisation’s processes. This will continue for as long as the Regulation remains in force, which means that a fine may occur much later. Your organization may be GDPR ready for 25 May 2018, but might not be any more if compliance is not maintained over time.
  • (edit) More than 70 provisions of the GDPR offer room for EU Member States to deviate from the Regulation. This means knowing the GDPR as a general law is not sufficient, and there will be different approaches depending on the countries. Germany being the first country to adopt its own adaptation of the GDPR in its local data protection law. You can access links on another article of this blog to track Member States’ readiness and deviations from the GDPR. As all the provisions of the Regulation are not self-explanatory and contain many provisons subject to interpretation, compliance with the GDPR remains a case-by-case assessment and will be subject to interpretation. As mentioned in this article, it could take around 10 years “before the GDPR might be considered a mature piece of legislation that is well understood“.

__________________

OTHER THREATS AND RISKS THAN FINES

Data processors of personal data (controllers and processors) should not only fear fines. A fine may just constitute an additional bad taste to an already too salted menu.

Personal data processors should take into consideration other risks or threats to their business as a result of GDPR non-compliance than just fines. Here are just a few examples that demonstrate how non-compliance may impact your organization and potentially your business as a whole:

  • reputational damage, financial and customer losses after an incident. Notifications of cybersecurity incidents to the individuals, when a breach is “likely to result in a likely to result in a high risk to the rights and freedoms of natural persons” (art. 34 (1) GDPR), reputational dammage causing loss of business opportunities, loss of customers, potential contractual liabilities, breach of contract, (just to name a few), may be much more damaging than a fine. If you read the news, you probably heard about the Talk-Talk disaster, where the unprepared spokesperson of Talk-Talk gave the worst signal ever to their customers when making a public statement about a data breach incident.
  • business discontinuity and costs recovery due to an incident. Not only a cybersecurity incident may cause the organization to stop being able to conduct its regular business and have reputational consequences on the market, but it will require to spend a lot of money to conduct investigations, fixing the issue, changing the processes where necessary, put in place stronger measures to prevent further incident, etc. A cybersecurity incident does not mean you are in breach of the GDPR, but with the increasing amount of personal data processed through connected networks, it is likely that a breach will also concern personal data of natural persons, which is regulated by the GDPR. This is where putting in place appropriate technical and organizational measures (which I call “ATOM“) plays a crucial role. In the most optimistic scenario, a well equiped and prepared company may not even require to inform the authorities, nor the individuals. In any case, it remains crucial to discuss and implement a cybersecurity preparedness plan and an incident response plan with the relevant people on a senior level.
  • suspension of data flows. While a cybersecurity incident may cause business discontinuity for a relative short period of time, an authority may impose a suspension of data flows. Despite the practical aspects of how an authority may enforce such measure, this might be damaging to the company if there is a business need to process the personal data.
  • competitors taking market share. This is a fear that some organizations should think about if they think non-compliance with EU privacy laws are just an academical topic. This is also where the GDPR is a great opportunity.
  • long-term ability to do business affected. Suspension of data flows may not be a common sanction given by an authority. However, non-compliance may prevent organizations to continue doing business with EU clients and cease to be competitive, losing market share.
  • loss of customer confidence.
  • staff losses and senior executive resignations.
  • allocation of an extra budget on security, data protection, restructuring, new roles and internal audits.
  • etc.

While NOT all organizations around the world falling into the scope of the GDPR will become GDPR compliant as of 25 May 2018, businesses and organizations processing personal data creating particular risks for the data subjects will be in the focus of the authorities. The so-called “Lex Facebook” will motivate authorities to focus on large companies such as the GAFAM and BATX, but also on their providers.

As long as your organization can demonstrate that GDPR readiness is on the top list of priorities and that working hard to achieve full compliance, you may be on the road to safety.

Be prepared, but not scared. Make the GDPR an opportunity, not a blocking point. Don’t fear fines, collaborate, remain transparent, prepare to demonstrate that you are working on compliance and that it is a priority for you. And if you need advice, then hire a specialized law firm.

__________________

By Gabriel Avigdor | NTIC.ch

Safe Harbour

Safe Harbour Episode II: the “UE-U.S. Privacy Shield”

A new hope.  After the invalidation of the Safe Harbour Framework by the European Court of Justice, the “Article 29 Working Party” (WP29) just released a public statement dated February 3rd, 2016 approving that EU and US authorities have met the deadline of end January 2016 to reach an agreement and welcomes the birth of a new text called the “UE – U.S. Privacy Shield” awaiting for the text for its analysis.Read More

Safe harbour - Ntic

Safe Harbor Framework invalidation : recommendations for Switzerland

I.  Introduction

In a decision dated October 6th, 2015, (Case Max Schrems vs Facebook) the European Union Court of Justice invalidated the Safe Harbor Framework, which had permitted U.S. companies to comply with EU restrictions on the transfer of personal data outside the EU.  As a non EU country, Switzerland concluded the “US-Swiss Safe Harbor Framework” (“Swiss SHF”) which is the equivalent to EU safe Harbor. This decision creates a real legal vacuum for around 4,500 companies which were relying on the Safe Harbor Framework to transfer data to the USA, which also applies in Switzerland.

Read this good article that summarizes the context of the decision, the legal issues and the proposed recommendations for multinational companies in EU.

II.  Communication from the Swiss Commissioner

In his latest communication (in French), dated October 22nd, 2015, the Swiss Federal Data Protection and Information Commissioner considers that the Swiss SHF is not a sufficient legal basis any more and recommends to all Swiss companies to amend their contracts with US corporations to include provisions which guarantee an adequate level of data protection.

In addition, the Commissioner recommends to Swiss corporations, by January 2016, to

  • promptly and expressly inform all data subjects of a possible access to their data by US authorities; and
  • include provisions in their agreements to support data subjects in implementing adequate measures to ensure sufficient legal protection, execute corresponding procedures and accept any effective decision from an authority.

The Commissioner reminds that any individual is entitled to require a civil Court to examine the validity of each data transfer.

III.  Conclusion

With this decision, data transfer to the USA is not illegal provided that companies complies with the above mentioned recommendations and update the provisions in their agreements with sufficient guarantees that measures are taken to ensure data security.

However, the United States have been clearly considered as a country where the level of security related to data is not adequate due to US regulations allowing mass-surveillance. This is a direct consequence of the Edward Snowden revelations. Therefore, as long as companies comply with their obligations to ensure adequate protection measures and inform individuals of a potential access of their data by the US authorities, data transfer shall remain valid.

In Europe, Article 29 Group (G29) has required EU institutions to renegotiate a new Safe Harbor Framework, compatible with EU laws, within 3 months from the decision of the European Court. Given the number of companies that are subject to this decision, this would be very interesting to follow.

Tails 1.0 : the amnesic and incognito live system

I.     Tails 1.0

1.1   Version 1.0 released

It is official. Since the 29th of April 2014, the last baby of the Tor Project has ben released and is now available for download : Tails 1.0.

“Privacy for anyone anywhere”

Tails 1.0 is a live operating system that protects you against data gathering and increases your privacy on the Internet. It includes built-in open-source software and is bootable from a USB flash key or a DVD. This software has been used by Edward Snowden to evade the NSA and communicate with Glenn Greenwald in June 2013.

1.2     Specifications

Its little name: the amnesic incognito live system.

Like Tails 1.0 is an amnesic operating system since it doesn’t record your data and erase your traffic information when you close the program. It is also incognito because your Internet traffic is confidential, secure and your data encrypted (files, emails, chat, etc.).

As well as other existing software (Bouldows for example), Tails is a live operating system and works can be launched from a USB flash key, an SD card or a DVD. When installed, Tails includes lots of open-source software usable for the Internet (Tor browser, Firefox, etc.), data encryption tools (such as Truecrypt) or simply office use (Open Office, Gimp, etc.). Tails 1.0 is distributed under a GNU/GPL licence including Creative Commons logos or coming from thenounproject such as the USB logo of Tails 1.0.

The official website says that it helps you to :

  • use the Internet anonymously and circumvent censorship;
    all connections to the Internet are forced to go through 
    the Tor network;
  • leave no trace on the computer you are using unless you ask it explicitly;
  • use state-of-the-art cryptographic tools to encrypt your files, emails and instant messaging.

 II.    Tor Project & Cie

Tor Projects (logo)

Tor Project regroups developpers that advocate for more open-source, security, anonymity, encrypted data and non-trackable, free software. In a few words non-commercial purpose and building software for confidentialiy and full privacy of the users on the Internet. Tor is an acronym for The Onion Router because of it refers to layers of encryption, nested like the layers of an onion, used to anonymize communication. As free software it enables online anonymity and censorship resistance. Tor directs Internet traffic through a free, worldwide, volunteer network consisting of more than five thousand relays to conceal a user’s location or usage from anyone conducting network surveillance or traffic analysis.

Parallel to Tor Project, Guardian Project is a good complementary resource for open-source Smartphone software for the public and developers.

Encrypted email applications, browser working with unique proxys or jumping ones, anonymous and encrypted live chat, coded messages sent though steganography principle, lots of software that are more accessible, more democratical and less elitist.

III.    Tails : for who and for what use? 

3.1    First test of Tails 1.0 (short overview)

When you start it, Tails seems to be accessible to anyone. You can be a Linux, Windows or Mac OS user, you will be guided step-by-step for installing it and use it. You lose a bit of your comfort zone by setting up the starting options and tools (such as keyboard, mouse, Wifi, admin password, etc.), but nothing really mad if know how to install an OS.

Tails desktop

Windows XP users will fatly find their way with an original option : “Windows camouflage” which is simply Tails OS with a Win XP theme.

Mac OS users will have to bite the bullet, because its less intuitive. For my first start, it was impossible to access to the local data on my HDD of my Macbook! In addition, please use a mouse because the use of the Mac touchpad rapidly becomes a nightmare. (Do not forget to press alt key to boot Tails).

Globally, Tails is rather intuitive, with lots of comfortable options such as a persistent volume where some data and new software can be saved as well as your settings (otherwise you’ll have to start all over again every time you start Tails) and can be updated. This option only works with a USB flash key, because a DVD cannot stock and save any more data on it. Connection to the Internet is easy and the jumping system method of Tor lets you surf on Facebook or Gmail without any problem. Even without VLC, Totem video player is rather good and read almost without any problem a .mkv video file including H264 for video codec and AAC for audio with multilingual audio track and subtitles.

At this stage, we can say that Tails 1.0 is intended for a broad audience, not only for those who loves penguins. You don’t know programming or writing code lines in a terminal, it is not a problem. Nevertheless, in my opinion Tails will not be accessible to everyone and lots of patience is needed for a dayly use, especially if you always have to configure the settings again at every starts. But obviously, it is the very principle of a live operating system …

3.2    Multipurpose use

Tails 1.0 includes an interesting list of open-source software such as Iceweasel for the Internet (GNU version of Firefox), Claws mail for emails, Pidgin for chatting, Open office for documents, Gimp (Photoshop’s equivalent) or TrueCrypt for data encryption. But, this Operating System is not foolproof. The user is warned about the limits of the program, especially for data encryption and deciding how to act with the computer and the information spread on social network or the Internet. Choosing a good password and change it from time to time is a must.

Tor Browser is not a standard Internet browser. It is from far slower than any other browser because of its functions. Blocking Ads, scripts, spy software, cookies, run Internet trough jumping proxys or data encryption require times, slow your network and block most websites that do not match with that settings. Most of e-commerce websites, social network or standard websites will not work if specific blocking options are enabled. Same script when you use Firefox with too many add-ons or plugins such as Ghostery, Adblock Plus, Donottrackme, etc.

Thus, running Tails is rather simple and all the built-in software let you have a daily use, but not for everyone or anyhow. Installing more software on your USB flash card and saving settings are an indication of the longevity of the project. Will it be enough for a very broad use? A wide professional use in private or administration sectors is something even more uncertain …

IV.    Conclusion

Other projects like Guardian or Tor are necessary for helping the web community to protect user’s privacy and anonymity and other strong values of tomorrow’s Internet. Recent software developments allow to reach a wider and broader audience. In that context, the massive innovative efforts of the open-source developers must be welcomed. These projects encourage people and governments to promote, use or develop such software. The Swiss Federal Supreme Court is a great example with its project: “OpenJustitia” (only available in French or German).

However, few of these software are really used by a majority of the Internet users. First, these programs are not of public knowledge, and Internet users ofter do not know alternatives exists or do not want to know about. Second, for years these software have not been very “user friendly”. Problems of settings, installation or use may repell the average user motivated by more protection but do not have sufficient knowledge or do not understand the proposed tool. Finally, the very geek design may often rejects users in a media hype world where people think that because it’s nice, it’s better…

Visiting Tor and Guardian Projects websites may be very instructive. Lots of unknown software for PC, Mac OS or Android are available for download. Their use is often simpler as we could have thought and allows you to decrease Internet tracking (see my article about Panopticlic in french) and preserve anonymity.

What about you, have you or will test Tails 1.0 ?

More information and links

  • Tor Browser;
  • guardianproject.org with web apps for a better stay on the Internet;
  • Orweb, Android version of Tor Browser;
  • Orbot : Android app with proxys servers;
  • Startpage : neutral search engine that do not give any information about you to third parties;
  • JonDo and JonDoFox : Tor Browser alternatives;
  • tens of others … !
Google Glass

Google Glass : pros or cons ?

Google Glass is very popular but do not receive general agreement. However this gadget has an incredible industrial value and some revolutionary concepts of use (e.g : e-Health, human interaction in other languages, etc.). However, it is, and will remain a cause of concern for consumer protection and privacy.

This article is intended for taking stock of the actual knowledge through  Internet media and the legal situation in several countries that already initiated preventive prohibitions (like USA, UK, France). Finally, a brief outline of the legal issues in Swiss law will be approached.

________________________________

HIGHLY ANTICIPATED AND CONTROVERSIAL TECHNOLOGY

 

Fans of tech inventions really look forward buying Google Glass (hereinafter : “GG”) to see its real potential of use. In reference to the terms of a letter sent to Larry Page (CEO of Google) questioning him about the risks of GG on privacy, the features of these glasses could be shortly resumed as follows :

Google Glass includes an embedded camera, microphone and GPS, with access to the Internet

Speculations about their use, features, but also about the risks and the legal drifts of the GG are the daily bread of journalists, bloggers and Internet users. The question so far would be : “how far could go Google with this new gadget“. 8’000 Internet users have already worn them for the special amount of $ 1’500.- in several American towns. Wearing these glasses not only was a privilege. It was also a way of asking these lucky users to imagine and offer Google use suggestions. Instead of paying the users for their ideas, the Mountain view firm is reversing the situation into an original concept by making “paid crowdsourcing”, as well as the Ads systems of the GG called « Admented reality ».

While all fans are awaiting Google Glass, the technical possibilities should frighten other people for obvious privacy matters. This sober and futuristic computer, which only stands on the tip of the nose, working with augmented reality deserves to be paid attention to!

Technical specifications

« Google Goggles » was not a success. However Google Glass intends to be its evolution with a lot more advanced features. The introduction page of GG seems to show glasses with a camera, a microphone, an analyzing environment tool with voice or gesture control (e.g. : for the zoom) and would definitely be based on augmented reality technology.

Fields of application

GG potential could be really wide in several area of application as well as for private use or  professional use. The question is : will this tool be efficient enough to stand a full day in order to overcome human weaknesses or vagueness? Here are some of the possibilities we could imagine.

Private or professional use

  • Private use won’t be so different as a Smartphone use. It’s just lighter, it works thanks to the voice control application and it can be used without taking your hands out of the pocket.
  • Professional use should really be challenging and exciting. Any kind of job that would require human work with an extreme precision (clock/watch making, micro technology, medicine, surgery, etc.) or real-time complementary informations could be improved with GG, such as zoom functions, real-time data analyzing functions, more camera angle views displayed on the glass, etc.

Medical applications / e-Health

  • During a Surgery, a doctor could have a real-time access to medical analysis, or could see different angles of view taken from several cameras. The zoom function could also be interesting in this case…
  • E-Health will be one the most lucrative but also promising field of activity in terms of innovation, thus for the industry, IP, IT, medical and legal drifts, especially in Switzerland. You might have read news about the Insight function which is built to identify people by their clothes. A medical application used on GG could be a great advantage during an attempt of rescue (e.g. : road accident, etc.). Imagine a rescue worker or an ambulance man identifying the victim of the accident with the GG and accessing immediately to his medical files (checking the blood type, important disease, allergies, reactions, drug or antibiotic resistance, etc.) and respect self-determination of the patients (according to an advance directive).

That kind of technology should be developed with lots of precautions and this means people must be identifiable at a very great probability to avoid serious medical errors. The technique and the power of these glasses will have to be increased a lot to reach that level of feature in order to have a daily professional use. Furthermore lots of tests and legal agreements would be necessary to integrate them in public health programs, which is not going to happen tomorrow.

Other person like visually impaired could be helped by GG to move in the streets  (GPS navigation system, facial, objects or obstacles automatic recognition, etc.).

Other applications

There will be lots of challenge and opportunities for GG Video games, which could boost industry and friendly use of these glasses. A part from that, international federations of sport already thought about referee wearing those glasses during some match. Porno industry is obviously interested in developing features and Apps for the GG, such as the recent fake porn trailer available on the Internet. Some creative people also thought about wearing the GG during a job interview to analyze the candidate’s behavior and to seek candidate’s profile, past, network, and more… Lots of others ideas such as a nature walk, or getting his car back could also be imagined…

________________________________

PROHIBITION ALREADY STARTED

Fears about GG’s entry on the market

Despite lots of fun features and useful professional uses, people, but also organizations, worry about the entry of GG on the market. Fears are twofold.

  • One one side, there are legitimate worries about consumer and data protection for the active users of the GG. Risks for active users may be focused on targeted ads system (based on environment interaction) and direct or indirect surveillance “under Google glass” from the authorities or giant Internet firms.
  • On the other side, all the passive users of the GG (such as people in public places) will  be concerned about their privacy. Passive users protection would be necessary to prevent “undesirable screenshots” from a pedestrian, as well as undue audio or video recordings. Not only the main thing is that people won’t know they would be recorded or pictured, but also that they won’t be able to agree or not to a recording.

When law comes before technology

GG won’t be tolerated in places where Smartphones, cameras or computer are already prohibited (cinema, banks, casinos, shows, hospitals, etc.). Nothing new under the sun.

Just the once will not hurt, and while GG are still in beta test, several public Organizations, private or little companies try to anticipate the take out of the store to prevent conflict situations. Ten privacy Organizations, including Hanspeter Thür, the Swiss Federal Data Protection and Information Commissioner (FDPIC), and the French IT and Freedom National Commission (CNIL), sent a letter to Larry Page about concern for privacy, and the collect and use of user’s data by Google.

Precautionary prohibitions in a few countries

  • In the United States of America, the Google Glass will be prohibited in Las Vegas, and in every Casino of the city. The Google glass will neither be allowed in Seatle at « 5 Point bar » which is the first bar to consider wearing GG as illegal before they are put on the market.
  • In United Kingdom, the spokesperson of the Britain Transport Minister said that GG will be banned for drivers because it would affect too much traffic behaviors even if their purpose is to help drivers with GPS functions.
  • West Virginia State and Delaware State (USA) are also working on a similar draft legislation to ban GG for drivers. Indeed, after the publication of an article on the website CNET entitled “The truth about driving under the influence of Google Glass“, public and political opinions have strongly reacted. As a result, these two government will probably establish rules to ban this gadget for drivers, but maybe for other use. A women already got ticketed for “distracted driving” because she was wearing the GG during driving.
  • In France, such glasses will automatically be banned for drivers according to article R412-6-2 of the French Road Code. This legislation provides that « Placing an operating device with a screen in the field of vision of the driver of a moving vehicle that do not constitute a driving or navigation aid is prohibited ».
  • A website entitled “Stop the Cyborgoffers to download a “Google Glass Ban” sign (pdf) for private places where the owner wants to ban it (bar, restaurant, etc). You can also check the list of ten places where Google Glass will be banned : on this website.

________________________________

WHAT IS THE SWISS LEGAL FRAMEWORK ?

Goggle Glass in the private or public context

If Google Glass product access the Swiss market, everyone should wear them without any problem in a private context. Private context is when you are with your family or friends. But, as soon as someone will wear the GG, everyone may be screenshot without knowing it and without prior consent. From a privacy perspective, this may become an issue should there be processing of (sensitive) personal data without prior notice or consent.

In a public place (bar, public transport, parc, demonstration, etc.), many sensitive issues will occur related to the use of GG, particularly regarding privacy, data protection and private sphere.

Data protection and privacy

Data gathering location and data processing

First of all, one of the most sensitive issue would be : What use will be made of all the data gathered by Google ? Even if connecting to Internet is a national issue (Internet provider with 3G and 4G and telecommunication providers), most of the information should automatically transit to Google servers to be stocked (at least temporary) which means in the USA. As can be seen with PRISM case, it is not clear whether the local data (in non-US countries) are not scanned by the NSA. But all our data may be if they are sent to USA to Google servers. Maintain control on all your data might possible only if they are kept in your country, encrypted and if they do not transit through the Internet Giants (Google, Yahoo, Facebook, etc.). Hard to tell before having tested these glasses !

Personal data and private sphere

As soon as a image or sound is recorded, this may cause legal problems. One the fundamental principle is the right to self-determination. Consent is the cornerstone of data protection and is a ground of justification which makes lawful a privacy intrusion (such as data gathering and processing). Thus, data gathering without prior consent is illegal. Every GG user sitting in a bus or a metro taking pictures or filming someone would automatically infringe the Swiss Federal Law on Data Protection (article 12 LPD) or to the Swiss Civil Code (article 28 CC).

Swiss Criminal Law (Penal Code) also punishes unauthorized audio recordings (see article 179bis to 179septies  CP). It can lead to a fine or prison.

The Insight Function of the GG may also be very intrusive in everyone’s life, even if the data are gathered from pictures found on the Internet and uploaded by the users themselves.

Intellectual property

Second sensitive theme : Intellectual Property, such as trademarks, copyright (pictures, music, movies, books, etc.). Since prohibition in cinemas will be obvious,  the issue won’t be so easy with concerts, theaters or museums where controls are not systematic. Remember that according to Swiss Copyright Law provides legal private copying if the use is restricted to friends or family. Such right disappears when the source is illegal or if it is shared out of the private circle.

We can be sure that Google will set up copyright detection system, as it already exists with YouTube. We can trust it.

Google Glass in the context of driving

Since it seems to be debated in several countries, it may be interesting to examine this issue in Switzerland. As you would see further, Swiss legislation seems more precise than french legislation about this prohibition.

Phone Call during driving

In Switzerland, cell phones during driving are prohibited. More specifically, the Swiss Federal Road Traffic Act (RTA) provides that « the driver has to remain constantly in control of the vehicle in order to respect all the prudence obligations (article 31 par. 1 RTA). The  driver would have to pay a CHF 100.- fine to have used his mobile without hands-free unit during the course » (article 3 al. 1 OAM).

In addition, the Federal Ordinance of the Trafic Road Act provides that : « the driver must pay attention to the road and to the traffic. He will avoid any activity which could make driving more difficult. He will also ensure that his attention would not be distracted, in particular not by a sound device nor by any communication or information device. It is established by the Federal Swiss Case Law (jurisprudence of the Swiss Supreme Court) that sending an SMS during driving is a severe infringement to Road Traffic Act (6B_666/2009) (article 90 par. 2 RTA) that may lead to a fine or a maximum three years jail sentence. 

What about Google Glass ?

Driving any vehicle require a perfect attention and visual acuity. Google Glass meet several scope of vision with notifications on one of the glasses. In reference to above-mentioned Swiss legislation and jurisprudence, wearing GG will be illegal if it is harder to drive with, which it seems to be most likely possible. The Google Glass drivers could be receive a administrative penalty (withdrawal of the driving licence) and a penal sentence (fine or jail).

It would more secure to let the passenger wear them.

Criminal proceedings

Criminal proceedings and Surveillance legislation deserve also an attention. The Swiss Federal about Surveillance of the Correspondence through Postal services and Telecommunication (LSCPT in french) allow Authorities to follow and monitor both individuals and companies suspected of charged for criminal offenses. Would it be allowed for Authorities to connect to the GG or ask Google data to proceed to a retrospective surveillance?

If the Investigation Authorities can monitor and record communications through Skype, which is the case in Switzerland, it will be technically possible with the GG. The problem is not how to do it, it is about collaboration. Will Google collaborate with the Swiss Criminal Authorities if they ask for it to resolve criminal cases? International mutual legal assistance in criminal matters is often a fatal obstacle when criminal offenses are committed through IT and New Technologies because the process is too slow. Furthermore, data retaining duration is not long enough to let Authorities have access to data before its erased (even if the duration will be lengthen to 12 months,  judgment 1B_128/2013 of the 8th of May 2013).

Other legislation, such as liability of Internet intermediaries, could enter into consideration.

________________________________

FINAL THOUGHTS

After these conceptual and legal considerations, my impressions, but also risks and abuses of those glasses are mixed. If we were living on Thomas Moore’s Island, Google Glass marketing wouldn’t have any bad consequence in a society composed of exemplary and model citizens or benevolent companies.

Are Google Glass and the future competitors of these glasses going to make a technological revolution? Will our daily habits and human interaction drastically change? Will 2014 be a progress year or we are going to go back 30 years later (1984)?

Swiss legislation seems to be well prepared for the arrival of Google Glass and do not really need to be modified for the moment since lots of situations may be solved with actual legal framework. Nevertheless, we don’t really know what to say before they enter into the Swiss market , which should not be before 2015 …

Stay tuned to see what will the USA authorities to when it will be on the market …