显示标签为“Privacy”的博文。显示所有博文
显示标签为“Privacy”的博文。显示所有博文

2011年5月5日星期四

Europe Leads in Pushing for Privacy of User Data

BRUSSELS — As pressure grows for technology companies like Apple and Google to adjust how their phones and devices gather data, Europe seems to be where the new rules are being determined.


Last year, Google generated a storm of controversy in Germany when it had to acknowledge it had been recording information from unsecured wireless networks while compiling its Street View mapping service.


Then, last week, regulators in France, Germany and Italy said they would examine whether Apple’s iPhone and iPad violated privacy rules by tracking the location of users.


Also, reports emerged last month that the Dutch police had obtained information from TomTom, a maker of popular satellite navigation devices, while setting up speed traps, prompting concerns by users and an apology from TomTom.


The companies all said there was nothing sinister about their activities, though Apple said it would issue a software update limiting the time that location data was kept to seven days. None of the information, the companies said, is particularly sensitive from the point of view of personal privacy, and they claim it will help them to deliver better services in many cases.


To address concerns about data protection, Viviane Reding, the European justice commissioner, said in a speech Tuesday that she would propose extending unionwide rules about breaches of privacy to online banking, video games, shopping and social media.


The rules require phone companies and Internet service providers to inform customers of any data breach “without undue delay.”


“European citizens care deeply about protecting their privacy and data protection rights,” Ms. Reding said in a separate statement.


“Any company operating in the E.U. market or any online product that is targeted at E.U. consumers should comply with E.U. rules.”


Ms. Reding made her remarks shortly after Sony apologized for a data theft involving 77 million account holders of the PlayStation Network, and a week after Apple said it would change the software that logs the location of users of its iPhone and iPad tablet computer.


“Seven days is too late,” Ms. Reding said Tuesday, referring to how long it took Sony to inform account holders.


Regarding Apple, she said she understood how the discovery that the iPhone collected location data had eroded “the trust of our citizens.”


Abraham L. Newman, an assistant professor at Georgetown University and a specialist in European privacy issues, said Europe’s spotlight on privacy could offer companies like Apple and Google the chance to reorganize the way they handled policies worldwide, using European standards in their corporate strategy.


Alternatively, he said, the companies could develop policies to ensure that data gathered in Europe was sufficiently “quarantined” to comply with rules, but limit changes in the rest of the world.


“Apple is entering a political dynamic in Europe which is similar to Google’s experience,” Mr. Newman said. “Authorities in Europe have decided that consumers better not be duped in a world of unlimited location data where companies know literally every step you take.”


What particularly distinguishes Europe is the strong role played by so-called national data protection authorities in keeping tabs on privacy issues, he said.


In the United States, there is no single agency dedicated to privacy, and while the Federal Trade Commission and the Federal Communications Commission can deal with violations of privacy, those agencies are mainly focused on enforcing fair business practices.


But Ms. Reding said the differences between Europe and the United States should not overshadow signs of convergence, like the work by the Obama administration and Congress to pass a privacy bill of rights that would stop companies from collecting or sharing personal information without an Internet user’s consent.


“Until recently, there was a common belief that the E.U. and U.S. have different approaches on privacy and that it would be difficult to work together,” Ms. Reding said.


“This can no longer be argued in such simple terms.”


 

2011年5月2日星期一

Slipstream: Data Privacy, Put to the Test

To the catalog of corporate “bigs” that worry a lot of us little people, add this: Big Data.


It was not a good week for those who guard their privacy. First, we learned that Apple and Google have been using our smartphones to collect location data. Then Sony acknowledged that its PlayStation network had been hacked — the latest in a string of troubling data breaches.


You’d have to be living off the grid not to realize that just about everything there is to know about you — what you buy, where you go — is worth something to someone. And the more we live online, the more companies learn about us.


But to what extent do others have a right to share and sell that information? That is the crux of a data-mining case that had arguments last Tuesday before the Supreme Court.


The case, Sorrell v. IMS Health, is ostensibly about medical privacy: Vermont passed a law in 2007 that lets each doctor decide whether pharmacies can, for marketing purposes, sell prescription records linking him or her by name to the kinds and amounts of drugs prescribed. State legislators passed the law after the Vermont Medical Society said that such marketing intruded on doctors and could exert too much influence on prescriptions.


But three health information firms, including IMS Health and Verispan, along with a pharmaceutical industry trade group, challenged the law, saying it restricted commercial free speech. Access to prescription records, IMS Health says, helps pharmaceutical companies market efficiently to doctors whose patients would most benefit from specific drugs.


Now the justices are to decide whether the Vermont law is constitutional.


But with the recent headlines about privacy invasion — the PlayStation hack followed a recent breach at the online marketing company Epsilon that exposed e-mail addresses of customers of Citibank, Walgreens, Target and other companies — the Vermont case is tapping into a much broader conversation about consumer protection and informed consent.


The case raises questions about who is collecting, managing, storing, sharing and selling all that data. Just as important, privacy advocates say, it raises questions about whether data brokers are adequately safeguarding it.


People generally don’t have much control over who collects and sells information about them. Moreover, says Christopher Calabrese, a legislative counsel at the American Civil Liberties Union, they also don’t even know the names of the data brokers who compile those electronic profiles.


And, so, consumer advocates are setting their sights on Big Data.


“Without government intervention, we may soon find the Internet has been transformed from a library and playground to a fishbowl,” Mr. Calabrese testified in March during a Senate hearing on consumer privacy, “and that we have unwittingly ceded core values of privacy and autonomy.”


There are a few laws, like the Video Privacy Protection Act, that prohibit businesses from releasing personally identifiable records, like video rental histories, without customer consent. The Digital Advertising Alliance, a coalition of online marketing groups, introduced a program last year that notifies consumers about online tracking and allows them to opt out of advertising tailored to them.


The Vermont law amounts to a kind of do-not-call option for doctors who may welcome visits from pharmaceutical sales reps but don’t want drug marketing based on their own prescription records.


That marketing practice is possible because pharmacies, which are required by law to collect detailed information about prescriptions they fill, can sell doctor-specific prescription records to data brokers. (According to federal privacy regulations, personal information about patients, like names and addresses, must be removed before the records can be sold for marketing.) Firms like IMS Health then combine the records, and pharmaceutical reps often use them to tailor presentations to individual doctors.


The central concern is privacy — of both doctors and their patients. While pharmacies remove the names of patients before selling the records, those names are replaced with unique codes that track patients over time from doctor to doctor, according to the Vermont complaint. That means data firms could create a profile that includes a person’s prescriptions as well as the names of the pharmacies and dates at which the person picked up the medications, says Latanya Sweeney, a visiting professor of computer science at Harvard.


“It ends up building a detailed prescription profile of individuals,” says Professor Sweeney, whose research on data re-identification was cited by several briefs in the case. “Those extended profiles tend to be very unique.”


The concern, she says, particularly in a small state like Vermont, is that a nameless prescription record could theoretically be enough to identify someone who might not want others to know that he takes, say, anti-depressants. Moreover, Professor Sweeney argues, data miners could collate those files with public information, like voter registration and hospital discharge records, to link prescriptions to specific people.


Federal health privacy regulation, she says, does not protect patient records once they have been de-identified. Nor does the law prohibit re-identification.


But IMS Health says it isn’t aware of any case of re-identifying patients whose prescription records were de-identified in accordance with federal rules. The company says it doubly encrypts each patient’s identity and gives the encryption keys to several third parties — meaning that no single entity can decode a file by itself, says Kimberly Gray, chief privacy officer at IMS Health.


The company typically sells combined reports that show how many patients received a certain drug from a certain doctor, but not the specific drugstores those patients frequent, Ms. Gray says. IMS never uses public information or outside data sets to try to re-identify patients, she says, and when it does provide encoded patient histories to others for research purposes, it prohibits those third parties from making such attempts.


“We would never want to re-identify someone,” Ms. Gray says. “No good can come from that.”


Still, it is hard to prevent people from trying to re-identify patients, says Lee Tien, a staff lawyer at the Electronic Frontier Foundation, a digital civil liberties group that filed a brief in support of Vermont. It would be easier, he says, if Congress passed a law that went further than Vermont’s, giving people the right to consent before their encrypted prescription records were sold for marketing purposes.


“In Vermont, the doctor can decide,” Mr. Tien says. “But we’d prefer it if the patient were able to say, ‘Don’t sell my data.’?”?


 

2011年4月28日星期四

Vital Statistics: For a Sex Survey, Privacy Goes a Long Way

It is not easy to ask people about their sex lives, and getting honest answers may be even harder. But there are ways to do it. One good method is to have a computer ask the questions, while the interviewee listens through earphones and enters the answers on the screen — without the intervention, or even the presence, of another human.

Share your thoughts on this column at the Well blog.

Go to Well ?


Last month the Centers for Disease Control and Prevention published a report on sexual behavior that used this technique with laptops to gather data on Americans’ sexual behavior, attraction and identity by age, marital status, education and race. Anjani Chandra, the lead author, said the process was developed to assure total anonymity for the respondents.


Dr. Chandra, a demographer with the agency, explained: “The computer tells the interviewees what key to press to lock away the responses. When they return the laptop to the interviewers, they can’t get in. It’s transmitted to a central place where the data processing happens without names or addresses. We get a file that can’t be linked back to the person.”


The researchers got a 75 percent response rate, very high for a household survey, when they interviewed more than 13,000 people ages 15 to 44 from 2006 to 2008.


They found a large reduction in sexual activity among young adults ages 15 to 24. According to the survey, about 29 percent of women and 27 percent of men had not had sexual contact with the opposite sex. This was a sharp increase from 2002, when about 23 percent of young adults had never had sex.


Among men and women older than 25, about 99 percent had had vaginal intercourse. About 90 percent of men and 89 percent of women had had heterosexual oral sex, and 44 percent of men and 36 percent of women had had anal sex with an opposite-sex partner.


Forty-year-old virgins were rare: In the 40-to-44 age group, only 1 percent of men and even fewer women had never had relations with the opposite sex. But in the 15-to-19-year-old group, 43 percent of males and 48 percent of females reported never having an opposite-sex partner.


Over all, about 13 percent of women and 5 percent of men reported same-sex sexual behavior. ??NICHOLAS BAKALAR


 

2011年4月27日星期三

Justices’ Debate Turns to Privacy for Doctors

 

In assessing the Vermont law at issue Tuesday (Sorrell v. IMS Health, No. 10-779), which bars some but not all uses of prescription drug data, several justices indicated that they viewed government efforts to alter the mix of available information as constitutionally problematic.


That principle animated last term’s decision in Citizens United, which struck down part of a federal law regulating speech about politics by corporations and unions. The tenor of Tuesday’s arguments suggested that a majority of the justices had similar concerns about the Vermont law, which regulates the use of information collected about doctors by records kept by pharmacies.


The case is not about patients’ privacy rights, as individual information about them is meant to be stripped from the data. Rather, the Vermont law restricts tailored efforts to market drugs to doctors aided by databases showing what medicines they have been prescribing.


The state law forbids the sale of prescription data to market drugs and bars drug companies from using the data to market drugs, unless the prescribing doctor consents. But other uses of the same data are allowed, including ones by law enforcement, insurance companies and journalists. And drug companies remain free to market their drugs in a more indiscriminate fashion, without knowing the prescribing habits of individual doctors.


Bridget C. Asay, an assistant state attorney general defending the law, tried to frame it as one meant to protect doctors’ privacy. But the argument gained little traction, and several justices noted that the law permitted uses that seemed to invade doctors’ privacy as much as the forbidden ones, and in any event doctors remain free to decline to meet with marketers.


Some of the justices also seemed concerned about what the law meant to achieve, as reflected in legislative findings justifying the law.


There is, the state Legislature said, a “massive imbalance in information presented to doctors” and “the marketplace for ideas on medicine safety and effectiveness is frequently one-sided.” The point of the law, several justices suggested, was therefore to protect doctors from hearing from drug marketers that might suggest more expensive drugs even as the state pushed cheaper generic drugs.


“You want to lower your health care costs, not by direct regulation, but by restricting the flow of information to the doctors,” Chief Justice John G. Roberts Jr. told Ms. Asay. “To use a pejorative word,” he went on, the state is “censoring what they can hear to make sure they don’t have full information.”


The chief justice’s two most senior colleagues, Justices Antonin Scalia and Anthony M. Kennedy, forcefully made similar points. The three justices sit at the center of the Supreme Court bench and at times they seemed a juggernaut bearing down on Ms. Asay.


Other members of the court were also skeptical about the way Vermont had chosen to regulate the distribution of prescription data.


Justice Ruth Bader Ginsburg said the state “is interested in promoting the sale of generic drugs and correspondingly to reduce the sale of brand-name drugs.” But she said that goal ran up against a basic First Amendment problem.


“You can’t lower the decibel level of one speaker,” she said, “so that another speaker, in this case the generics, can be heard better.”


Thomas C. Goldstein, a lawyer for several data mining companies challenging the law, said that sort of government manipulation of information is impermissible.


“The way the First Amendment works in the marketplace of ideas that so upsets Vermont is that both sides get to tell their story,” he said. “The thing that is supposed to be biased here is that the drug companies have too much money. That is not a basis for restricting speech.”


New Hampshire and Maine have laws similar to the one in Vermont, and those have been upheld by the federal appeals court in Boston. The Vermont law at issue in Tuesday’s case was struck down last year by a divided panel of the federal appeals court in New York.


 

2011年4月23日星期六

Bits: Location Apps Generate Privacy Concerns, Report Says

 Nielsen The report by Nielsen found that women are more concerned with privacy and location than men.

A day after a report that the Apple iPhone and iPad 3G are storing data about users’ locations, a new report from the market research firm Nielsen said many Americans have strong concerns about losing some privacy by using location-based mobile services.


Authors of the report said that although some Americans happily engage with a new crop of location-based applications, many “are reticent to share information about their geographic location.”


Location-based services, including Foursquare, Gowalla and Facebook Places, have seen heavy adoption in recent years as more?Americans?have moved from standard mobile phones to smartphones that come?with GPS.?But not everyone is persuaded of their benefits.


Nielsen said women who download at least one mobile application to their phone each month showed the highest concern about? location apps. The report says that 59 percent of women reported having privacy concerns with these services; 52 percent of men reported the same concerns. Only 8 percent of women and 12 percent of men were not concerned with location-based services and happily engage with them. The remaining people surveyed said they were indifferent.


Age also played a factor in the research. “Mobile app downloaders between the ages of 25-34 were the least likely to have privacy concerns,” Nielsen said. “Privacy concerns were considerably higher among those over the age of 45.”


The report, which was made public on Thursday, will be presented in full?at an app conference in San Francisco next week.