Privacy#

WhatsApp and Privacy#

WhatsApp was originally known for strongly protecting user privacy. It used end-to-end encryption and resisted government data requests.

Facebook acquired WhatsApp for $22 billion in 2014. In 2016, WhatsApp announced that it would share phone numbers, usage data, and device information. The information would be shared with Facebook and affiliated companies.

WhatsApp stated that data sharing would help improve services, advertising, and business communications.

Key Issue

The change raised concerns among users who valued WhatsApp’s privacy practices.

Privacy Protection and the Law#

Information technology allows organizations to gather, store, analyze, and report information about people. Organizations use this information to make decisions. Examples include hiring job candidates, approving loans, and offering scholarships. Companies use consumer information to understand purchasing habits and target marketing. Organizations also need customer information to provide better services.

Main Issue

Balancing organizational information needs with individual privacy rights.

How Can Privacy Be Protected?#

A combination of approaches is required:

New laws

Technical solutions

Privacy policies

Education and communication

Legal Protection

The U.S. Consitution does not explicitly mention “privacy”.

The Fourth Amendment has been interpreted to protect against unreasonable searches and seizures.

This protection is connected to the concept of reasonable expectation of privacy.

Information Privacy#

Communication Privacy

Ability to communicate without communications being monitored.

Data Privacy

Ability to limit access to personal data.

Ability to exercise control over personal data and its use.

Legal Landscape

The United States does not have one overarching national data privacy policy.

Many privacy laws focus on government intrusion.

Protection against corporate misuse of personal data has historically been limited.

Personal Information#

What Information Can Be Collected?

Organizations and systems can gather information such as work history, police history, medical data, location data, financial records, educational records, driving history, associates and affiliations, web-browsing behavior, and sexual orientation.

Why Is This Important?

The collection and combination of these types of information can provide organizations with detailed information about individuals.

Privacy of Financial Data#

Fair Credit Reporting Act (1970)

Regulates credit bureaus.

Promotes accuracy, fairness, and privacy.

Restricts sharing credit information with employers without written consent.

Gramm-Leach-Bliley Act (1999)

Includes:

Financial Privacy Rules

Safeguards Rule

Pretexting Rule

Right To Financial Privacy Act (1978)

Protects customer records from unauthorized federal government scrutiny.

Requires notice, purpose disclosure, and legal authorization.

Fair And Accurate Credit Transactions Act (2003)

Provides consumers with one free credit report annually from each major bureau.

Establishes the National Fraud Alert system.

Health Information Privacy#

Health Insurance Portability And Accountability Act (HIPAA) – 1996

Protects the privacy of medical information.

Requires patient consent before certain disclosures.

Requires tracking of recipients.

Requires privacy officers.

Healthcare organizations are responsible for their business partners’ compliance.

Health Information Technology For Economic And Clinical Health Act (HITECH) / American Recovery And Reinvestment Act – 2009

Strengthened electronic health record privacy.

Banned selling health information.

Required audit trails and encryption.

Required breach notifications within 60 days.

Children’s And Educational Data#

Family Educational Rights And Privacy Act (FERPA) – 1974

Protects student educational records.

Provides rights to:

  • Access records

  • Amend records

  • Restrict sharing of records

Children’s Online Privacy Protection Act (COPPA) – 1998

Applies to websites targeting children under 13.

Requires clear privacy policies, and verifiable parental consent before collecting personal data.

Electronic Surveillance#

Government Surveillance

Advances in technology have expanded government surveillance.

Surveillance has moved from targeting specific individuals toward collecting information from large numbers of people.

The Privacy Debate
Concern

Widespread surveillance may vioalte Fourth Amendment protections.

It may affect freedom of expression.

Counterargument

Supporters argue that expanded surveillance can be justified by security needs.

Title III / Wiretap Act#

Title III of the Omnibus Crime Control and Safe Streets Act – 1968, also known as the Wiretap Act.

Purpose

Regulates interception of wire and oral communications by federal and state law enforcement.

Requirements

Law enforcement generally must obtain a judicial warrant, probably cause, and an evidence that normal investigative methods have failed or are too dangerous.

Important Case

Katz v. United States (1967)

Established the concept of reasonable expectation of privacy in electronic surveillance.

Foreign Intelligence Surveillance Act – 1978#

Purpose

Establishes procedures for collecting foreign intelligence.

Covers communications involving foreign powers and their agents.

FISA Court

Reviews surveillance applications.

Provides judicial authorization for certain surveillance activities.

Key Point

Surveillance involving U.S. persons requires judicial authorization under specified circumstances.

Executive Order 12333 – 1981#

Issued by President Ronald Reagan.

Identifies U.S. Intelligence agencies.

Establishes rules for collecting, retaining, and sharing infomraiton.

Allows collection during lawful:

  • Foreign intelligence investigations

  • Counterintelligence investigations

  • International terrorism investigations

Privacy Issue

Executive Order 12333 permits certain intelligence collection outside the FISA framework, including incidental collection of information about U.S. persons.

Electronic Communications Privacy Act – 1986#

The ECPA expanded privacy protections to electronic communications.

Title I

Protects electronic communications such sa e-mails, faxes, and texts.

Government interception generally requires a probable-cause court order.

Title II – Stored Communications Act

Protects privately stored electronic communications from unauthorized access.

National Security Letts

Allow the FBI to obtain certain subscriber information and records from Internet Service Providers.

Post-9/11 Surveillance#

Communications Assistance for Law Enforcement Act (CALEA) – 1994

Expanded electronic surveillance capabilities.

Required telecommunications and VoIP providers to support wiretapping capabilities.

USA Patriot Act – 2001

Expanded government intelligence and investigative powers.

Expanded the use of National Security Letters.

FISA Amendments Act – 2008

Expanded authority for monitoring certain international communications.

USA Freedom Act – 2015

Ended the NSA’s bulk collection of telephone metadata.

Shifted data retention to telecommunications providers.

Restored certain surveillance authorities.

Fair Inforamtion Practices#

A set of guidelines designed to:
  • Prevent unlawful data storage

  • Reduce inaccurate information

  • Prevent unauthorized disclosure

  • Manage transborder data flows

  • OECD Guidelines – 1980

Eight principles:
  • Collection limitation

  • Data quality

  • Purpose specification

  • Use limitation

  • Security safeguards

  • Openness

  • Individual participation

  • Accountability

International Data Privacy#

EU Data Protection Directive – 1995

Established pinciples involving notce, choice, use, security, correction, and enforcement.

Privacy Shield

Replaced the previous Safe Harbor arrangement.

Placed additional obligations on U.S. companies handling EU personal data.

General Data Protection Regulation (GDPR) – 2016

Created unified data protection rules sacross the EU.

Applies to organizations worldwide that handle EU citizens’ data.

Includes a “right to be forgotten”.

Government Records#

Freedom of Information Act – FOIA

Gives the public and journalists the right to request government records.

Requests generally must follow agency procedures.

Agencies may deny requests under specific exemptions.

Exemptions include information involving national security, confidential business information, and personal or medical information.

Privacy Act – 1974

Establishes fair information practices for federal agencies.

Regulates the collection, maintenance, and use of personal data.

Prohibits secret personal-data record-keeping systems.

The Target Data Breach – 2013#

Affected 40 million credit and debit card accounts.

Up to 70 million customers’ personal information was afffected.

Target incurred more than $248 million in costs.

Target experienced an $800 million decline in fourth-quarter sales.

Banks and credit unions incurred more than $200 million in replacement-card costs.

Identity Theft#

Unauthorized use of personal information to commit fraud or crimes.

Information can include Social Security numbers, credit card numbers, and other identifying information.

Identity Theft and Assumption Deterrence Act

Made identity theft a federal crime.

Provides penalties of up to 15 years in prison, and $250,000 in fines.

Breach Reporting

Publicly traded companies must report material data breaches to the SEC.

State laws may require timely consumer notification.

Consumer Profiling#

How Companies Collect Information
  • Website registration

  • Surveys and online forms

  • Social media activity

  • Online contests

  • Cookies

  • Tracking software

How It Is Used
  • Analyze browsing habits

  • Identify interests and preferences

  • Personalize websites and advertising

Privacy Concern

Companies may collect information without explicit permission.

Consumers may not know how their information is being collected or used.

Electronic Discovery#

The collection, preparation, review, and production of electronically stored information (ESI) for use in criminal and civil actions and proceedings.

Challenges

Large amounts of electronic data

Multiple versions of files

Data stored in different locations

Expensive and time-consuming review

Predictive Coding Uses:

Human guidance

Computer algorithms

To identify relevant documents and reduce large datasets to the most pertinent files.

Workplace Monitoring#

Employers may monitor communications, web activity, company devices, and network activity.

Why?

Maintain productivity

Reduce misuse of IT resources

Prevent workplace harassment

Reduce legal liability

Cyberloafing

The use of workplace Internet resources for non-work-related activities.

Employee Privacy#

Employer Concerns

Productivity

IT resource protection

Workplace conduct

Legal liability

Employee Concerns

Privacy

Monitoring of communications

Monitoring of Internet activity

Use of personal information

Advanced Surveillance Technology#

Used for intelligence gathering. Helps prevent and investigate crime. Raises concerns about civil liberties. Can raise concerns about individual privacy and inaccurate identification.

Examples

Camera surveillance

Vehicle Event Data Recorders (EDRs)

Stalking apps

Satellite-based location systems

Vehicle Event Data Recorders#

Record information such as speed, braking, and seatbelt use. Used for safety analysis, and legal evidence.

Stalking Apps#

Commercial spyware can allow remote location tracking, text monitoring, call monitoring, and microphone activation.

Privacy Concern

Installing such software without permission is illegal.

However, the software itself can remain easily accessible online.