Showing posts with label Social Media Privacy Law. Show all posts
Showing posts with label Social Media Privacy Law. Show all posts

Friday, July 15, 2016

Playboy Playmate Under Criminal Investigation For Snapchat Photo

According to Entertainment Tonight, the LA Police Department has opened an investigation into 2015 Playmate of the Year Dani Mathers' Snapchat activity after it received a complaint from LA Fitness. It appears that the investigation is centered around an alleged illegally disseminated private image Ms. Mathers took of a fellow gym member inside an LA Fitness club. While Ms. Mathers was in the bathroom/shower area of an LA Fitness gym she took a naked photo of another person and posted it on Snapchat with some negative comments.  

Subsequently, the naked photo Ms. Mathers posted went viral and she has gone from being the bully who body shamed a fellow gym member for personal pleasure to a target herself.    If the person in the photo comes forward Ms. Mathers could face up to six months in prison for her behavior.

Since Ms. Mathers published the naked photo, she has been suspended from her radio show and banned from all LA Fitness gyms.  Online, thousands of people have also stated how disgusted they are about Ms. Mathers' actions.      

Ms. Mathers' behavior demonstrates she didn't even realize what she had done was wrong. Her apology shows she doesn't have a clue about the law or proper digital behavior.  Ms. Mathers only apologized for posting the photo on Snapchat.  She admits in her so called apology that she had the intent to take the naked photo of stranger and share it with her friends.  This demonstrates a lack of remorse and understanding of the seriousness of the situation.

People have an expectation of privacy in bathrooms whether they are in a public restroom or a private club.  Those who violate this expectation of privacy should be held legally accountable. If Ms. Mathers is sued by the person whom she photographed I wouldn't be surprised if a settlement or judgement is either six or seven figures. The Erin Andrews jury verdict and subsequent settlement is the benchmark to measure these types of privacy violations.  

The bottom line is that companies need to better train their employees about these issues because one dumb Snap, Tweet, or Post can create millions in legal liability.

Copyright 2016 by Bradley S. Shear, Esq. All rights reserved.

Thursday, July 14, 2016

Microsoft Wins Major Data Privacy Decision For Users

Microsoft won a major privacy legal victory for users today when the 2nd U.S. Circuit Court of Appeals ruled that the Department of Justice (DOJ) can't use a U.S. search warrant to access customer data stored overseas.  The unanimous 3-0 ruling is a victory for the rule of law, privacy, and the usage of new technologies such as the cloud.

The case started in 2013 when a New York federal judge issued a warrant for the emails of a drug trafficking suspect.  Some of the requested content was stored in Microsoft's computers in Ireland so the company refused to turn the data over unless the U.S. government followed well established international rules on obtaining evidence in a foreign country. 

In 2014, the U.S. Southern District of New York ruled that search warrants issued under the Stored Communications Act (SCA) enable the government to access data stored anywhere in the world. This ruling had affirmed a magistrate judge's decision that focused on who controls the data and not the location of the data.  The 2nd U.S. Circuit Court of Appeals unanimous ruling clearly demonstrates that the lower courts misinterpreted the SCA and Congress' intent on digital privacy.

During the past several years, I have attended numerous conferences and congressional hearings on the issues surrounding this case.  I have listened to many of the legal and public policy arguments as to why the lower courts' rulings must stand or be reversed. Today's ruling is a victory for privacy rights in the Digital Age, democracy, and technology public policy.  In short, the general legal protections that apply to the physical world have been extended to the digital world.

My hope is that other courts focused on similar privacy issues take notice of this decision and that Congress sooner rather than later enacts common sense data privacy laws for the Digital Age. The U.S. must be a leader in technology public policy and the 2nd U.S. Circuit Court of Appeals has taken our country a step in the right direction.  

Copyright 2016 by Bradley S. Shear, Esq. All rights reserved.     

Friday, June 24, 2016

BREXIT Will Alter Technology Public Policy, Privacy, and the Law

The votes have been counted regarding the BREXIT which was the referendum on whether Great Britain would stay in the European Union or leave and the result is that the UK will exit the EU.  The vote to leave won by more than a million votes (52%-48%; 17,410,742-16,141,241).

In the short term, stock markets around the world are plunging due to the uncertainty. However, when the dust has settled the legal and regulatory work on how to adjust to this change in relationship will begin. While the vote will have a tremendous effect on many international issues, it appears that the UK's data protection rules may be unaffected.  In the short term, this appears so; however, in the long term this may change.

The vote was a surprise to many lawyers and technology public policy analysts and this is demonstrated by the lack of planning in the event that the UK voted to leave the EU. Will other countries follow the UK's lead and will this create new alliances? While current trade deals may not be affected by the vote, new rules and regulations will be needed and future trade deals involving the UK and the EU will need to account for this result.  

Change is generally hard.  The people of the UK have spoken and in a democracy the will of the people must be followed.  Even though it is too soon to speculate on how this vote will ultimately affect technology public policy and privacy issues there are a lot of unanswered legal issues surrounding the process in which the UK will leave the EU.

 Copyright 2016 by Bradley S. Shear, Esq.  All rights reserved. 

Wednesday, June 22, 2016

FTC Fines Advertising Network For Illegal Mobile Tracking

The Federal Trade Commission has announced that mobile advertising company InMobi will pay a $950,000 civil penalty and implement a comprehensive privacy program to settle FTC charges it deceptively tracked the locations of hundreds of millions of consumers, including children, without their knowledge or consent to serve them geo-targeted advertising.

According to the FTC, InMobi misrepresented that its advertising software would only track user locations when they opted in. However, InMobi was tracking user locations whether users opted in or refused to provide permission. InMobi's advertising network has a reach of more than one billion devices via thousands of apps so there is a staggering amount of data that the company has illegally obtained. 

Under the terms of its settlement with the FTC, InMobi is subject to a $4 million civil penalty, which is suspended to $950,000 due to the company's financial position. The company will be required to delete all information it collected from users and it is prohibited from collecting consumers’ location information without their affirmative express consent. InMobi must also institute a comprehensive privacy program that will be independently audited every two years for the next 20 years.

How much money did InMobi make by intentionally deceiving consumers?  This deception demonstrates why there needs to be stronger laws and greater enforcement mechanisms in place to deter and stop illegal behavior. 

Copyright 2016 by Bradley S. Shear, Esq. All rights reserved. 

Monday, December 7, 2015

Canadian Cable Company Facebook Shames Late Paying Customers

There is a valid reason why people are "cutting the cord" and getting rid of their cable subscriptions.  Some cable companies don't have a clue about customer service.  In a very troubling report, Canadian cable company Senga Services has been publicly shaming on Facebook its customers who are in arrears.

Senga Services' behavior was deemed so troubling that Canada's Office of the Privacy Commissioner asked the company to delete its customer shaming Facebook posts.  Do any of the publicly shamed customers have potential legal claims under Canadian law?  What if some of the customers that Senga publicly shamed had a bona fide billing dispute that Senga refused to addressed?  What if some customers were not properly notified of the billing issue due to a move?

Earlier this year, I switched my cable company because I had a major billing dispute.  My now former cable company had lied to me for years and over charged me hundreds of dollars.  Only after I wrote multiple letters to the company and threatened to file FTC and state attorney general complaints was I finally refunded several hundred dollars.

My matter was most likely only settled by the cable company because I am an attorney who has the knowledge and means to easily utilize the proper judicial or regulatory process to obtain the money I was owed.  Most people don't have this luxury.

Companies should tread very carefully when utilizing social media to reach their goals.  Too often organizations empower employees and/or agents to act on their behalf online who don't understand that their digital actions may have legal repercussions.  The bottom line is that its imperative to think before you post.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Monday, November 30, 2015

Email Privacy Act: Much Needed Reform

In general, the government should be required to obtain a warrant in order to access the private password protected digital accounts of its citizens.  Unfortunately, due to an outdated law, the Electronic Communications Privacy Act of 1986 (ECPA) this is not the case.

The ubiquitous nature of online communications has made updating the law to account for how technology has changed over the past 30 years a necessity to ensure that our 4th amendment rights in the virtual world equal our 4th amendment rights in the physical world.  A Congressional hearing on the Email Privacy Act will be held this week to try to update the woefully out of date ECPA statute.  Multiple efforts over the years have failed so I am cautiously optimistic that this effort and others such as the LEADS Act which complement this bill will be passed this term.

The Email Privacy Act has more than 300 cosponsors in the House of Representatives and it would close a glaring loophole in ECPA which enables the government to utilize a subpoena instead of a warrant to require digital service providers to provide their customer's digital communications if they are greater than 180 days old.  When ECPA was enacted in 1986, this loophole wasn't concerning because our technology wasn't such that we could hold years of personal communications in an email account stored in the cloud around the world.

According to a recent poll by Vox Populi, 77% of 1000 registered voters said "a warrant should be required to access emails, photos and other private communications stored online." This super majority demonstrates the importance of this issue and that Congress should listen to the voters to rectify this glaring hole in our 4th amendment protections.

In order for the Email Privacy Act to became law, it is imperative to contact your local members of Congress to tell them about the importance of this issue.  Absent public support, Congress doesn't act. Therefore, if you believe that our 4th amendment protections should extend to our digital activities please take a stand and urge your representatives and senators to support the much needed Email Privacy Act.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Tuesday, November 10, 2015

Belgian Court Says Facebook Must Stop Tracking Non-Users

In a very promising development, a Belgian court has ruled that Facebook may no longer collect information about non-users. According to The New York Times, the court ruled that Facebook may no longer collect and store digital information from Belgians who do not have a Facebook account due to a lack of consent.

Facebook will appeal the ruling because it wants the right to track everyone on the Internet for monetary purposes.  However, if Facebook loses and fails to abide by the court's decision it may be fined up to $270,000 per day.

I do not trust Facebook with my personal information. Even though I have a personal Facebook account, my profile photo shows my "favorite social media titan," and I have intentionally included incorrect personal information about myself.  I do not utilize the platform to share my personal thoughts or activities because the data is sent to data brokers.  Furthermore, Facebook is not transparent regarding how personal user information is utilized by its business partners.

Its too early to speculate on whether Facebook will ultimately win the case; however, my hope is that other countries around the world including the U.S. require Facebook, Google, etc... to become more transparent about their data collection and utilization practices. Those who do not use Facebook have an expectation that it will not destroy non-users' privacy. We may soon find out if the Belgian judiciary agrees.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Monday, November 9, 2015

Supreme Court Declines Cell Phone Privacy Case

Earlier today, the Supreme Court declined to hear a case regarding whether law enforcement needs a warrant to access the location information of cell phone users.  While the decision to turn down the case may disappoint some privacy advocates it is not surprising.

Earlier this year in Davis v. U.S., the 11th Circuit Court of Appeals determined that it was not necessary for the police to obtain a warrant before accessing cell phone location records.  The defendant was convicted of armed robbery based in part by his cell phone location data. The appeals court opinion compared cell phone location data to security camera surveillance images (page 27 of the opinion) which is an interesting analogy.

In general, absent exigent circumstances (legal jargon for an emergency), a warrant should be required to access the content and meta data associated with one's digital devices.  In the physical world, law enforcement is generally required to obtain a warrant to search one's home or car.  A home or car may contain physical information (i.e. clothing, hard copy paper records, etc...) that may indicate an investigatory target's location history or other relevant data.

Since a warrant is generally required for physical world evidence, a warrant should generally be required for digital world evidence including location information, meta data, etc...I am hoping that the court declined this matter because it is waiting for a test case that will more easily enable them to strengthen our privacy laws.

This denial of cert demonstrates that it is imperative for the privacy community to increase its efforts to better educate the judiciary, state and federal lawmakers, and other stakeholders about digital privacy issues.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Sunday, November 8, 2015

Stevenson University Caught Requiring Access To Private Student Facebook Accounts

Playing college athletics is a privilege and not a right. However, student-athletes do not lose their civil rights when they enter the locker room.  In an insightful and troubling ESPN Outside the Lines Report, it was uncovered that a now former student-athlete at Stevenson University was forced to quit her school's athletic team because she refused to abide by an illegal and discriminatory social media policy. The policy required the women's ice hockey student-athletes to provide their coaches access to their personal social media accounts.

Requiring students to provide coaches and administrators access to personal digital accounts is not just a privacy issue but also a personal safety, cyber security, and civil rights matter.  Does a coach have a legal right to demand to see what political candidate a student-athlete supports?  Does a college administrator have a legal right to see if a student-athlete likes a page that may indicate their sexual preference?  Does a coach have a legal right to see all of your personal messages to your friends and family?  

Maryland was the first state in 2012 to enact legislation to generally ban employers from demanding access to personal social media accounts and it was also the first state to introduce legislation to protect students from being required to turn over the same information to schools. While Maryland was the first state to introduce legislation to protect personal student social media accounts it wasn't able to enact a state law on the matter until earlier this year when it became the 13th state to do so.  

While the student-athlete who was profiled by ESPN was harmed by Stevenson University's clearly unethical and illegal social media policy, it doesn't appear she has a claim under Maryland's new student social media privacy law that went into effect on June 1, 2015. However, she may have a claim under the 2012 employee social media privacy law if she worked in some type of capacity for the university. On the federal level, there may be potential Title IX, federal computer crime law (i.e. the Stored Communications Act), Office of Civil Rights claims, etc... If Stevenson University's illegal social media policy was in effect after June 1, 2015 the school may have additional legal challenges on the horizon.

The bar to settle this type of matter was set at $70,000 per student last year when a Minnesota student received this amount to settle a similar situation.  Since the student profiled in the ESPN piece appears to have been clearly harmed by her university's illegal policy her damages may be significantly higher than $70,000. Every student who was told they must provide access to their personal social media account to participate in a school sponsored activity may also be entitled to at least $70,000.

There appears to be approximately 24 students on the Stevenson University Women's ice hockey team this year.  If 24 students participated on last year's team and they were required to provide access to their personal social media accounts, Stevenson University may be on the hook to compensate each student-athlete at least $70,000.  For example, 24*$70,000=$1,680,000 in potential damages just for last year's team.

If last year's social media policy was in effect this year that could cause additional trouble for Stevenson. While the new Maryland law caps state damages at $1,000 per student plus reasonable attorney fees and court costs, this law doesn't affect potential damages under federal law. If the student-athletes band together and obtain joint legal representation they may be able to file a class action lawsuit and the total damages against the university could theoretically reach $2,000,000+.  

Stevenson needs to become transparent about this matter and held accountable.  How long has their illegal and discriminatory social media policy be in effect?  How many students were required to abide by this policy?  Did the policy just apply to female ice hockey players?  If not, who else. These are just some of the many questions that Stevenson must answer.

The bottom line is that universities need to better understand the legal ramifications of their social media policies and engage those who actually understand best practices. The legal issues involved are very serious and trump the personal/university branding issues that many schools focus on.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Friday, October 30, 2015

UK Police May Soon Have Power To View All Users Web History

Privacy is something you don't know you have until you lose it.  Unfortunately, the Internet has gone from the world's greatest communication and knowledge spreading platform to the best surveillance tool ever invented.

According to The Independent, UK police may soon be granted the power to view the web browsing history of everyone in the country.   The alleged bill would require communication companies to retain all web browsing history of its customers for 12 months in case the police or spy agencies want access.  The article claims that the police will still need to go through some type of judicial process to obtain the data.

A user's Internet search history may be very useful for law enforcement.  For example, in the United States, it appears that in the infamous disappearance of Caylee Anthony the police may have forgotten to check all of the Internet browsing history of a computer that was searched.  If all of the browsing history of the computer that was checked was readily accessible in one dashboard would it have changed the outcome of the case?

This potential new UK law is very troubling.  Will phone companies soon be required to tape record every phone call that is made?  Will people soon be required to tape record every personal voice conversation and keep a physical copy of every pen and paper interaction they have?  Will librarians soon be required to track every request by every user and keep it on file for 12 months?

The potential for abuse is tremendous.  Will one be prosecuted for just doing an Internet search about a topic?  Who will have access to it?  Will the proper cyber security and privacy safeguards be implemented to protect the data?  What happens when multiple people utilize a device?  Will everyone eventually be forced to have their own Internet ID # to track everything they do online? How much compensation will one be able to obtain after their browsing history is illegally leaked to the media?   These are just some of the many questions that need to be answered.    

Unfortunately, it sounds as though George Orwell's Nineteen Eighty-Four surveillance society is coming true in the U.K.  Which country will be next?  

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.   

Thursday, October 29, 2015

Snapchat's Troubling New Terms Destroy User Privacy and Safety

Snapchat is an ephemeral messaging app that has become popular with millions of people due to its claim that the content users send using its platform is permanently erased after a certain period of time. This sounds great; however, federal regulators have found otherwise.

According to the FTC, in 2014 Snapchat was caught making false promises to consumers about the amount of content it was collecting and saving about them. This deception led to an FTC settlement that was announced in December of 2014 that prohibits Snapchat from misrepresenting the extent to which it maintains the privacy, security, or confidentiality of users' information.  

Unfortunately, this settlement has not yet encouraged Snapchat to become a company that actually cares about user privacy and personal safety.  For example, Marketwatch.com has reported that Snapchat recently changed its terms of service and the update appears to be very similar to Facebook's terms. Snapchat's new policy states, 

"But you grant Snapchat a worldwide, perpetual, royalty-free, sublicensable, and transferable license to host, store, use, display, reproduce, modify, adapt, edit, publish, create derivative works from, publicly perform, broadcast, distribute, syndicate, promote, exhibit, and publicly display that content in any form and in any and all media or distribution methods (now known or later developed)." 

and

"To the extent it’s necessary, you also grant Snapchat and our business partners the unrestricted, worldwide, perpetual right and license to use your name, likeness, and voice in any and all media and distribution channels (now known or later developed) in connection with any Live Story or other crowd-sourced content you create, upload, post, send, or appear in. This means, among other things, that you will not be entitled to any compensation from Snapchat or our business partners if your name, likeness, or voice is conveyed through the Services."

In other words, these terms allow Snapchat to publicly display user content and utilize personal data in ways many users most likely do not understand nor would they knowingly agree to. Will Snapchat soon include a clear warning message in front of its app stating that its new terms harm user privacy and safety?  I highly doubt it....:)

I do not trust services that contain the above or similar terms.  Whether its words, photos, or videos, your content is not private nor safe when the above terms govern.  If you don't trust Facebook because of its privacy killing agreements with data brokers you shouldn't trust Snapchat.  It appears not to be a question of if, but when Snapchat enters into similar privacy killing agreements with data brokers.  Will the FTC soon open an investigation into these new terms?

The bottom line is that if you care about your personal privacy and safety you should avoid utilizing Snapchat.  

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.   

Wednesday, October 21, 2015

U.S. Must Pass Judicial Redress Act To Demonstrate International Privacy Leadership

The recent invalidation of the U.S.-E.U. Safe Harbor Agreement by the European Union Court of Justice has demonstrated that the U.S. must enact privacy laws that protect non-U.S. citizens from law enforcement over reach.  The Snowden NSA revelations that were first revealed in 2013 not only angered many American citizens and civil rights advocates, but they also created a schism with Europe regarding government surveillance and digital privacy.
   
For the past 15 years, companies that do business across the Atlantic have relied on the U.S.-E.U.Safe Harbor Agreement to transfer personal data from the E.U. to the U.S. While this agreement was not perfect, it created a mechanism that was consistent with E.U. data protection directives that enabled companies to process and utilize personal digital data without running afoul of E.U. privacy laws.

Austrian privacy advocate Max Schrems' challenge against Facebook regarding how it handles the data it collects from E.U. users was the catalyst behind the demise of Safe Harbor.  E.U.data protection authorities have given lawmakers in the U.S. and the E.U. three months to negotiate a new treaty to replace the Safe Harbor’s data privacy protocols.  Under E.U. law, personal information may be exported if it is provided the same protections that are offered in the E.U. 

U.S. digital privacy protections are generally stuck in the 1980’s and many of our laws did not anticipate how technology would change over time.  While privacy has been a fundamental human right in the E.U. since 1950, U.S. digital privacy rights have been slow to evolve to catch up with how we are utilizing the many life changing services and devices that are now being deployed. 

Congress is working on strengthening our digital privacy rights but the process has been slow and arduous.  Fortunately, yesterday’s passage of the Judicial Redress Act in the U.S. House of Representatives which will enable foreign citizens to have the same legal rights as U.S. citizens if law enforcement violates their personal privacy rights is a step in the right direction.  While the bill still must be passed in the Senate and signed by the President to become law, this development demonstrates that we are on the right track and hopefully this will help lead to a new U.S.-E.U. Safe Harbor data agreement.  

This legislation and others such as ECPA reform, and the Law Enforcement Access To Data Stored Abroad Act (LEADS) are much needed bills that must be enacted to demonstrate that we will be a beacon for digital privacy rights.  We can have both privacy and security while respecting fundamental human rights.  However, we must showcase this leadership by enacting digital privacy laws that equally protect both U.S. and foreign citizens.  

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.   

Thursday, July 30, 2015

Facebook User To Be Fined Under Spanish Social Media Gag Law For Police Comments

Social Media in its infancy was hailed as a great equalizer for everyone's voice to be heard. Years ago, at conference after conference, I heard so called "futurists" and other "prognosticators" proclaim social media as the best invention since air conditioning or the microwave.

So many social media "evangelists" (a fancy term for some consultants who are full of s*#t) shouted from the roof tops how digital platforms would make the world a safer and freer place to exchange ideas and increase the freedom of speech.  Unfortunately, many of these "evangelists" don't understand how some governments and private companies are using social media to digitally follow and keep tabs on what people are doing.  Some of these new activities are actually a huge threat to democracy and our personal freedoms.  

Earlier this year, the government in Spain enacted its "Citizen Security Law" which appears to restrict what its citizens may say online about some government officials.  On July 22nd, the law was apparently utilized when local police in Spain accused one of its citizens of "making comments on social media that showed a lack of respect and consideration for Gumar's (a town in Spain) local police.  The accused may be fined hundreds of Euros and has hired a lawyer to fight the charges.  

Spain isn't the first country to enact and/or enforce laws specifically designed to stop its citizens from criticizing its government online and it will not be the last country to do so.  Therefore, it is imperative to be vigilant about digital freedom of speech and privacy.  You don't know how important these rights are until you lose them.  

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Friday, July 24, 2015

Hulk Hogan Tries To Pre-Empt the Wrath of Social Media Via An Apology

Reacting appropriately during a crisis in the Social Media Age is extremely important.  In fact, its a must for corporate executives, small and large companies/organizations, politicians, celebrities, professional athletes, amateur athletes, etc...  Its imperative to understand the importance of properly reacting to a situation that has not just public relations implications but also major legal ramifications as well.

In the Social Media Age, the right reaction may determine whether your brand is permanently damaged like Paula Deen's or Anthony Weiner's or if you can  make a comeback like Charlie Sheen (a little contrition mixed in with talent, luck, and a "wining attitude").  Americans have always loved great comebacks.  The biggest in recent memory (the last 20 years) was Bill Clinton's come back from impeachment proceedings. 

The latest high profile person to incur a major negative personal/professional event (actually multiple matters) is former pro-wrestler Hulk Hogan.  The National Enquirer recently published a private racist rant Hogan made years ago.  The leaking of this information to the media may be connected to a $100 million dollar lawsuit Hogan commenced against the digital platform Gawker for publicizing a private sex tape that he may have unknowingly participated in.   

It appears that right before Hogan's behavior became public knowledge the WWE (Hogan's employer) scrubbed him from their website and cut ties with him. Within hours of the world learning about his racist rant, Hogan issued to People Magazine a full apology and took full responsibility for his actions.

Will Social Media, the WWE, his fans, etc... forgive Hogan for his behavior?  As long as Hogan's team doesn't follow the missteps of of others, he has an opportunity for redemption.  A good first step was a quick apology.  Will Hogan's next step on his road to redemption be an appearance on The Today Show or other media outlets?

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Friday, July 10, 2015

Google Forced to Change Its Privacy Policy in the Netherlands

According to Telecompaper, Google has changed its privacy policy in the Netherlands to comply with its data protection laws.  The Dutch privacy regulator (the "CBP") determined last year that Google combines and uses the personal data of internet users without first obtaining permission according to its laws.  Google acquires personal information about its users when they are logged into Google and from other data sources, such as Internet searches, location data, videos, and emails.

While this is a welcome development, why did the CBP have to threaten Google with a multi-million dollar fine before it agreed to change its privacy policy?  Will Google soon change its U.S. privacy policy to actually protect the personal privacy of its users?  Since Google led the charge to gut Maryland's student privacy law earlier this year, I doubt it will do so.

The bottom line is that the U.S. FTC and state attorney generals should follow the E.U.'s lead when it comes to protecting our digital privacy.  The more data that companies such as Google, Facebook, data brokers, etc... are allowed to collect and utilize the less safe we become since privacy and security are bedrocks of a democratic society.

Troubling practices and antiquated thoughts about data privacy continue to be a national security threat.  My hope is that our regulators and elected leaders will soon take the appropriate actions necessary to enforce and update our data privacy laws to better protect us and our children.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Tuesday, June 16, 2015

Facial Recognition Privacy Talks Collapse Due to Inadequate Consumer Safeguards

According to The New York Times, nine civil rights and other advocacy organizations announced today that they are withdrawing from "talks with trade associations over how to write guidelines for the fair commercial use of face recognition technology for consumers."

Why are these talks so important?  Because every time you walk into a fast food restaurant instead of a health food store you will be tracked and this information will be sent to data brokers who will insert it into your digital dossier.  You will be penalized for who you talk to in public (whether its a friend, business associate, or a stranger on the street) and this data will be tied to you forever.  What stores you visit and when you visit them will be collected and available to interested parties.

Should private companies have the right to know if you attend weekly religious functions and what faith you practice based upon your comings and goings?  What about whether you are seen visiting a bar or other gathering known for particular social or political characteristics?  Do you want others to know whether you frequent casinos, liquor stores, cigar shops, or certain specialty retailers?  Visiting these places and making purchases are perfectly legal.  However, when each of these individual activities are taken together it can paint a picture of our lives.  This is why John Hancock has created a new life insurance product that tracks your every move.  These are just a few examples of why stronger privacy protections are needed for biometrics.

Privacy is a civil right.  The potential for discrimination is high.  The more data that is being collected about us the greater the risk of the information falling into the wrong hands.  For example, the recent cyber attack on federal databases by Chinese hackers is a serious threat to national security and personal safety.  The systems compromised housed information on federal workers, their families, and those who interact with them.  The type of data contained in these files may be utilized for strategic national and economic security, blackmail, and who knows what else.

Absent participation by civil rights groups and privacy advocates, the facial recognition talks are worthless.  Its time for more technology companies to take a public stand for greater privacy protections.  The 4th amendment has protected us against unreasonable government searches and seizures for more than 200 years.  Its time for us to demand that our government extend this principle to protect us against unreasonable data collection and usage by private companies.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.

Monday, June 15, 2015

Belgium Sues Facebook Over Its Troubling Privacy Practices

According to The Wall Street Journal, Belgium's Privacy Commission is taking Facebook to court over its very troubling privacy practices.  Last month, the Commission publicly chastised Facebook for the way it handles the personal data of Internet users.  The Commission has focused on "how Facebook tracks Internet users on external websites through the use of “like” and “share” buttons".

In general, I avoid using Facebook's "like" or "share" button because for years the company has demonstrated via its privacy policy and agreements with data brokers that it has does not care about the privacy of its users.  The New York Times recently shed some light on how Facebook's Mark Zuckerberg is a privacy hypocrite.  Mr. Zuckerberg's business practices demonstrate that he doesn't believe his users deserve to have their personal data kept private but he wants those who are working with him personally to sign non-disclosure agreements (NDA) to protect his personal information.  This behavior appears to demonstrates that Mr. Zuckerberg believes privacy is only for the super-rich and not the Average Joe or Facebook user.

My hope is that U.S. lawmakers, regulators, and state attorney generals closely watch how the European Union (EU) deals with digital privacy issues.  While I don't agree with every public policy decision that the EU makes regarding the digital ecosystem, when it comes to holding companies such as Facebook and Google accountable for the way they handle and utilize the personal information of Internet users', the U.S. should closely explore emulating the EU's thought process on these matters. 

Privacy is one of the hallmarks of a democratic society and we must protect it before some members of the technology community permanently destroy it to maximize their corporate profits.  While Facebook and Google talk the talk regarding privacy they have failed to walk the walk and refrain from abusing their access to the data they are collecting about all of us.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.        

Wednesday, June 3, 2015

Apple CEO Blasts Facebook and Google For Privacy and Security Practices

Earlier this week, I attended the Electronic Privacy Information Center's (EPIC) annual Champions of Freedom Awards Dinner.  According to its website, "EPIC is an independent non-profit research center in Washington, DC. EPIC works to protect privacy, freedom of expression, democratic values, and to promote the Public Voice in decisions concerning the future of the Internet."  The event honored those who have made a significant contribution to protecting our personal digital privacy and cyber security.

This year, Richard Clarke, Tim Cook, Kamala Harris, and Susan Linn were honored.  Each of these honorees have performed excellent work in furtherance of protecting our personal privacy and safety from online and offline threats.  Richard Clarke and Susan Linn were in attendance while Tim Cook and Kamala Harris who both live in California spoke to the audience remotely.

The most passionate remarks of the evening came from Apple CEO Tim Cook. He discussed the importance of strong privacy protections in digital products and services and blasted those companies (i.e. Facebook and Google) that provide free services in exchange for selling their customers' personal information to data brokers.     

I do not utilize Facebook or Google products/services for any private communications and I do not recommend anyone who values their digital privacy and safety to do so either because the practices of these companies enable very troubling data mining that may lead to discrimination when applying to college, applying for credit, and when applying for a new job.  For several years, it has been known that Facebook sells its users' personal information to data brokers; however, Google's troubling data broker agreements were not as well known until The Wall Street Journal recently reported that Google is combining users' offline purchases with their digital activity.

Privacy is a civil rights issue and in order to stay a free society we must ensure that no private or public entity is allowed to destroy it.  The bottom line is that digital privacy and cyber safety go hand and hand and organizations such as EPIC work to better protect us from companies such as Facebook and Google that have troubling privacy policies and practices.

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.         

Friday, May 22, 2015

Adult Sex Website Hacked, Personal Data At Risk

The Internet and apps may be utilized for many productive and interesting activities.  For example, users and companies may engage in Business to Business (B to B), Business to Consumer (B to C) commerce, general digital marketing/branding, etc....  However, some of the most popular digital activities include viewing porn and cheating on one's spouse. 

In 2013, The Huffington Post reported that porn sites receive more traffic than Netflix, Amazon, and Twitter combined.  Internet porn is ingrained in popular culture.  Who can forget Avenue Q's catchy number, "The Internet is For Porn"?  In addition to porn, many people utilize the Internet and apps to cheat on their spouses and significant others.  For example, near the area where I live and work (in Bethesda), cheating website Ashleymadison.com ranked the Washington, DC area #1 for usage for the third year in a row.  This distinction is nothing to brag about. 

What many people may not realize is that when utilizing a website or app to find a sexual partner, you create a digital trail that puts your personal information at risk. For example, a married pastor in Michigan was recently exposed while utilizing a "hook up" app.  He uploaded photos of himself and other personal information that appears to have led to his identification. 

CNN is reporting that the website Adultfriendfinder.com was hacked in March and this incident appears to have exposed the personal information of millions of users.  The data leaked may include very intimate details about users.  The information exposed may be utilized to destroy personal lives, professional careers, and/or blackmail users.

The bottom line is that when using the Internet and apps it is very important to be cautious about the data you upload.  To protect your personal privacy and safety (and your family's), its imperative to limit the personal information that you post about yourself and your family.   

Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.    

Friday, May 1, 2015

Facebook Threatens European Regulators Over Stronger Privacy Laws

In a very troubling development that shows Facebook's true colors, one of its corporate executives stated that if European regulators continue to scrutinize Facebook's data collection and utilization practices its citizens will not be provided certain features in a timely manner.  This veiled threat to European regulators demonstrates that the EU is on the right track in questioning the data privacy policies and practices of Facebook and other Internet companies.  

Manufacturers of cars and heavy machinery, pharmaceutical companies, banks, chemical companies, etc.. are required to follow appropriate safety regulations in Europe and around the world.  Data collection and usage laws are nothing more than safety regulations and it is time for Facebook and the entire digital ecosystem to get on board with regulations that will enhance user trust of their platforms. 

An Austrian class action lawsuit about Facebook's data usage practices, the ongoing Netherlands privacy regulator investigation into Facebook's activities, and the possibility that Europe will enact stronger data protection laws that will provide greater regulatory tools to protect citizens from some of Facebook's troubling data collection and usage practices appears to worry the company.  These developments demonstrate the importance of baking privacy into your platform's design and the need for Facebook to change its data collection and usage practices and its policies.   

The bottom line is that data privacy is a safety issue.  My hope is that U.S. lawmakers and regulators soon follow Europe's lead in understanding that unfettered data collection and usage is a clear and present danger to its citizens and that more robust privacy laws are a must in the Big Data Age.

 Copyright 2015 by The Law Office of Bradley S. Shear, LLC All rights reserved.