Showing posts with label Privacy Law Expert. Show all posts
Showing posts with label Privacy Law Expert. Show all posts

Thursday, July 14, 2016

Microsoft Wins Major Data Privacy Decision For Users

Microsoft won a major privacy legal victory for users today when the 2nd U.S. Circuit Court of Appeals ruled that the Department of Justice (DOJ) can't use a U.S. search warrant to access customer data stored overseas.  The unanimous 3-0 ruling is a victory for the rule of law, privacy, and the usage of new technologies such as the cloud.

The case started in 2013 when a New York federal judge issued a warrant for the emails of a drug trafficking suspect.  Some of the requested content was stored in Microsoft's computers in Ireland so the company refused to turn the data over unless the U.S. government followed well established international rules on obtaining evidence in a foreign country. 

In 2014, the U.S. Southern District of New York ruled that search warrants issued under the Stored Communications Act (SCA) enable the government to access data stored anywhere in the world. This ruling had affirmed a magistrate judge's decision that focused on who controls the data and not the location of the data.  The 2nd U.S. Circuit Court of Appeals unanimous ruling clearly demonstrates that the lower courts misinterpreted the SCA and Congress' intent on digital privacy.

During the past several years, I have attended numerous conferences and congressional hearings on the issues surrounding this case.  I have listened to many of the legal and public policy arguments as to why the lower courts' rulings must stand or be reversed. Today's ruling is a victory for privacy rights in the Digital Age, democracy, and technology public policy.  In short, the general legal protections that apply to the physical world have been extended to the digital world.

My hope is that other courts focused on similar privacy issues take notice of this decision and that Congress sooner rather than later enacts common sense data privacy laws for the Digital Age. The U.S. must be a leader in technology public policy and the 2nd U.S. Circuit Court of Appeals has taken our country a step in the right direction.  

Copyright 2016 by Bradley S. Shear, Esq. All rights reserved.     

Monday, November 9, 2015

Supreme Court Declines Cell Phone Privacy Case

Earlier today, the Supreme Court declined to hear a case regarding whether law enforcement needs a warrant to access the location information of cell phone users.  While the decision to turn down the case may disappoint some privacy advocates it is not surprising.

Earlier this year in Davis v. U.S., the 11th Circuit Court of Appeals determined that it was not necessary for the police to obtain a warrant before accessing cell phone location records.  The defendant was convicted of armed robbery based in part by his cell phone location data. The appeals court opinion compared cell phone location data to security camera surveillance images (page 27 of the opinion) which is an interesting analogy.

In general, absent exigent circumstances (legal jargon for an emergency), a warrant should be required to access the content and meta data associated with one's digital devices.  In the physical world, law enforcement is generally required to obtain a warrant to search one's home or car.  A home or car may contain physical information (i.e. clothing, hard copy paper records, etc...) that may indicate an investigatory target's location history or other relevant data.

Since a warrant is generally required for physical world evidence, a warrant should generally be required for digital world evidence including location information, meta data, etc...I am hoping that the court declined this matter because it is waiting for a test case that will more easily enable them to strengthen our privacy laws.

This denial of cert demonstrates that it is imperative for the privacy community to increase its efforts to better educate the judiciary, state and federal lawmakers, and other stakeholders about digital privacy issues.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Friday, October 30, 2015

UK Police May Soon Have Power To View All Users Web History

Privacy is something you don't know you have until you lose it.  Unfortunately, the Internet has gone from the world's greatest communication and knowledge spreading platform to the best surveillance tool ever invented.

According to The Independent, UK police may soon be granted the power to view the web browsing history of everyone in the country.   The alleged bill would require communication companies to retain all web browsing history of its customers for 12 months in case the police or spy agencies want access.  The article claims that the police will still need to go through some type of judicial process to obtain the data.

A user's Internet search history may be very useful for law enforcement.  For example, in the United States, it appears that in the infamous disappearance of Caylee Anthony the police may have forgotten to check all of the Internet browsing history of a computer that was searched.  If all of the browsing history of the computer that was checked was readily accessible in one dashboard would it have changed the outcome of the case?

This potential new UK law is very troubling.  Will phone companies soon be required to tape record every phone call that is made?  Will people soon be required to tape record every personal voice conversation and keep a physical copy of every pen and paper interaction they have?  Will librarians soon be required to track every request by every user and keep it on file for 12 months?

The potential for abuse is tremendous.  Will one be prosecuted for just doing an Internet search about a topic?  Who will have access to it?  Will the proper cyber security and privacy safeguards be implemented to protect the data?  What happens when multiple people utilize a device?  Will everyone eventually be forced to have their own Internet ID # to track everything they do online? How much compensation will one be able to obtain after their browsing history is illegally leaked to the media?   These are just some of the many questions that need to be answered.    

Unfortunately, it sounds as though George Orwell's Nineteen Eighty-Four surveillance society is coming true in the U.K.  Which country will be next?  

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.   

Thursday, October 29, 2015

Snapchat's Troubling New Terms Destroy User Privacy and Safety

Snapchat is an ephemeral messaging app that has become popular with millions of people due to its claim that the content users send using its platform is permanently erased after a certain period of time. This sounds great; however, federal regulators have found otherwise.

According to the FTC, in 2014 Snapchat was caught making false promises to consumers about the amount of content it was collecting and saving about them. This deception led to an FTC settlement that was announced in December of 2014 that prohibits Snapchat from misrepresenting the extent to which it maintains the privacy, security, or confidentiality of users' information.  

Unfortunately, this settlement has not yet encouraged Snapchat to become a company that actually cares about user privacy and personal safety.  For example, Marketwatch.com has reported that Snapchat recently changed its terms of service and the update appears to be very similar to Facebook's terms. Snapchat's new policy states, 

"But you grant Snapchat a worldwide, perpetual, royalty-free, sublicensable, and transferable license to host, store, use, display, reproduce, modify, adapt, edit, publish, create derivative works from, publicly perform, broadcast, distribute, syndicate, promote, exhibit, and publicly display that content in any form and in any and all media or distribution methods (now known or later developed)." 

and

"To the extent it’s necessary, you also grant Snapchat and our business partners the unrestricted, worldwide, perpetual right and license to use your name, likeness, and voice in any and all media and distribution channels (now known or later developed) in connection with any Live Story or other crowd-sourced content you create, upload, post, send, or appear in. This means, among other things, that you will not be entitled to any compensation from Snapchat or our business partners if your name, likeness, or voice is conveyed through the Services."

In other words, these terms allow Snapchat to publicly display user content and utilize personal data in ways many users most likely do not understand nor would they knowingly agree to. Will Snapchat soon include a clear warning message in front of its app stating that its new terms harm user privacy and safety?  I highly doubt it....:)

I do not trust services that contain the above or similar terms.  Whether its words, photos, or videos, your content is not private nor safe when the above terms govern.  If you don't trust Facebook because of its privacy killing agreements with data brokers you shouldn't trust Snapchat.  It appears not to be a question of if, but when Snapchat enters into similar privacy killing agreements with data brokers.  Will the FTC soon open an investigation into these new terms?

The bottom line is that if you care about your personal privacy and safety you should avoid utilizing Snapchat.  

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.   

Friday, August 28, 2015

FTC Announces PrivacyCon Symposium

Earlier today, I received notification from the FTC announcing that on January 14, 2016 it will hold an event called PrivacyCon. According the FTC's website, the conference is designed "to bring together a diverse group of stakeholders, including whitehat researchers, academics, industry representatives, consumer advocates, academics, and a range of government regulators, to discuss the latest research and trends related to consumer privacy and data security."

The FTC has done some great work in privacy and cybersecurity and just like previous events, this event will bring together some of the world's most knowledgeable experts in the field.  FTC Chairwoman Ramirez published an excellent op-ed earlier today about the need for this symposium. In her piece, she stated, "[p]olicymakers need to ensure that privacy is respected while innovation flourishes, and technology academics and researchers are crucial to hitting that sweet spot."  

Previous FTC symposiums I have attended were well worth my time so if you are interested in learning about some of the most cutting edge regulatory issues in privacy and cybersecurity this event is a must.  

Copyright 2015 by the Law Office of Bradley S. Shear, LLC. All rights reserved.   

Thursday, August 27, 2015

The Ashley Madison Hack, Cybersecurity, Privacy, and Legal Liability

Privacy and cyber security go hand and hand.  If the platform you are utilizing has weak and/or misleading privacy policies and/or weak cyber security your safety is at risk.  The ongoing issues related to the Ashley Madison hack (and Adult Friend Finder) should be a wake call to everyone who accesses the Internet and digital services.

While this latest hack along with previous major data breaches is very concerning, I find it very troubling that Ashely Madison intentionally misled clients about its alleged "Delete" service.  For $19, its users were intentionally misled that their personal information would be removed from Ashely Madison's records.  Obviously this was not the case.  Therefore, from a legal perspective, those who paid $19 to have their personal data deleted but didn't receive what was promised to them may be in the greatest position to win damages.

Even though Ashely Madison is based in Canada, the U.S. FTC may get involved since the company did business in the United States.  Since a U.S. federal appeals court recently affirmed that the FTC has the power to regulate cyber security it  would not surprise me if the FTC gets involved due to Ashley Madison's alleged weak cyber security and/or because it misled their clients about its so called "Delete" service.

The bottom line is that Ashely Madison faces tens of millions (or more) of dollars in potential legal liability either from class action lawsuits and/or regulators.  While this situation may take years to sort out, the lesson for all is to be careful what you post online and what digital platforms you trust.

Copyright 2015 by the Law Office of Bradley S. Shear, LLC. All rights reserved.

Thursday, June 18, 2015

IACP Releases Updated Guidance On Police Bodyworn Camera Video Data Storage

Privacy and cybersecurity go hand and hand.  Therefore, it is imperative that policy makers on the local, state, and federal level adopt policies and enforce practices that promote these principles.  This is especially important due to the increased amount of data that governments are collecting.

During the past decade, law enforcement agencies around the world have begun to implement police body cameras to assist in evidence gathering, transparency, and accountability.  In the United States, several incidents during the past year have prompted local police departments to test and begin utilizing body cameras.  While this technology brings great promise it also creates new privacy and cyber security challenges. 

To help alleviate these concerns, the International Association of Chiefs of Police (IACP) recently published their "Guiding Principles on Cloud Computing in Law Enforcement".  These principles are much needed because as more digital video evidence is created by law enforcement, the proper safeguards must be in place to ensure that the data is stored in an appropriate manner for the legal justice system.

The IACP's principles state: 

1)  FBI CJIS Security Policy Compliance Services provided by a cloud service provider must comply with the requirements of the Criminal Justice Information Services (CJIS) Security Policy (current version 5.3, dated August 4, 2014), as it may be amended.  

2)  All Data Storage Systems Should Meet the Highest Common Denominator of Security.

3)  Data Storage Technology Can Be Disaggregated From Collection.

4)  Data Ownership-Law enforcement agencies should ensure that they retain ownership of all data.

5)   Impermissibility of data mining-Law enforcement agencies should ensure that the cloud service provider does not mine or otherwise process or analyze data for any purpose not explicitly authorized by the law enforcement agency.

6)   Auditing - Upon request, or at regularly scheduled intervals mutually agreed, the cloud service provider should conduct, or allow the law enforcement agency to conduct audits of the cloud service provider's performance, use, access, and compliance with the terms of any agreement.

7)  Portability and interoperability - The cloud service provider should ensure that that CJI maintained by the providers is portable to other systems and interoperable with other operating systems to an extent that does not compromise the security and integrity of the data.

8)  Integrity - The cloud service provider must maintain the physical or logical integrity of CJI.

9)  Survivability - The terms of any agreement with cloud service providers should recognize potential changes in business structure, operations, and/or organization of the cloud service provider, and ensure continuity of operations and the security, confidentiality, integrity, access and utility of the data.

10)  Confidentiality - The cloud service provider should ensure the confidentiality of CJI it maintains on behalf of a law enforcement agency.

11)  Availability, Reliability, and Performance - The cloud service provider must ensure that CJI will be available to the law enforcement agency when it is required within agreed performance metrics.

12)  Cost - Law enforcement agencies should focus cloud acquisition decisions on the Total Cost of Ownership model.

The recent multiple hacks into the federal government's networks have demonstrated the importance of updating and implementing the proper digital policies and technologies.  With access comes responsibility.  It is imperative that law enforcement agencies that utilize bodyworn cameras and other digital data collection technologies follow these principles to protect law enforcement agencies, the general public, and the criminal justice system.  The IACP's cloud computing principles will help ensure that justice stays blind in the age of police body cameras.

 Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.