Privacy Seminar - Social Networks



Similar documents
Briefly summarised, SURFmarket has submitted the following questions to the Dutch DPA:

ON MUTUAL COOPERATION AND THE EXCHANGE OF INFORMATION RELATED TO THE OVERSIGHT OF AUDITORS

Behavioral Targeting Legal Developments in Europe and the Netherlands

AlixPartners, LLP. General Data Protection Statement

Binding Corporate Rules ( BCR ) Summary of Third Party Rights

Data Processing Agreement for Oracle Cloud Services

Corporate Guidelines for Subsidiaries (in Third Countries ) *) for the Protection of Personal Data

GUIDE TO THE ISLE OF MAN DATA PROTECTION ACT. CONTENTS PREFACE 1 1. Background 2 2. Data Protections Principles 3 3. Notification Requirements 4

Data Protection. Processing and Transfer of Personal Data in Kvaerner. Binding Corporate Rules Public Document

Processor Binding Corporate Rules (BCRs), for intra-group transfers of personal data to non EEA countries

Guidelines on Data Protection. Draft. Version 3.1. Published by

Johnson Controls Privacy Notice

APPMACHINE MOBILE PRIVACY STATEMENT. Version, May 29, 2015

CLOUD COMPUTING FOR ehealth DATA PROTECTION ISSUES

How To Protect Your Data In European Law

Article 29 Working Party Issues Opinion on Cloud Computing

CCBE RESPONSE REGARDING THE EUROPEAN COMMISSION PUBLIC CONSULTATION ON CLOUD COMPUTING

We use such personal information collected through this Site for the purposes of:

Data protection policy

The eighth data protection principle and international data transfers

How To Understand The Data Protection Act

Proposal of regulation Com /4 Directive 95/46/EC Conclusion

FIRST DATA CORPORATION PROCESSOR DATA PROTECTION STANDARDS

RAYSAFE S1 SECURITY WHITEPAPER VERSION B. RaySafe S1 SECURITY WHITEPAPER

Privacy Policy documents for

PRIVACY POLICY. What Information Is Collected

Adaptive Business Management Systems Privacy Policy

Data Protection Standard

AMENDMENTS TO THE DRAFT DATA PROTECTION REGULATION PROPOSED BY BITS OF FREEDOM

GlobalSign Data Protection Policy

Online Ads: A new challenge for privacy? Jörg Polakiewicz*

Overview. Data protection in a swirl of change Cloud computing. Software as a service. Infrastructure as a service. Platform as a service

Elo Touch Solutions Privacy Policy

DentalTek Privacy Statement

INXPO Privacy Policy

OVERVIEW. stakeholder engagement mechanisms and WP29 consultation mechanisms respectively.

CPA Global North America LLC SAFE HARBOR PRIVACY POLICY. Introduction

Data Sharing Protocol

HIPSSA Project. Support for Harmonization of the ICT Policies in Sub-Sahara Africa, Second Mission -Namibia

Office of the Data Protection Commissioner of The Bahamas. Data Protection (Privacy of Personal Information) Act, A Guide for Data Controllers

on the transfer of personal data from the European Union

ESTRO PRIVACY AND DATA SECURITY NOTICE

Privacy vs Data Protection. PRESENTATION TITLE GOES HERE Eric A. Hibbard, CISSP, CISA Hitachi Data Systems

AIRBUS GROUP BINDING CORPORATE RULES

I. Introduction to Privacy: Common Principles and Approaches

ESOMAR PRACTICAL GUIDE ON COOKIES JULY 2012

Corporate ICT & Data Management. Data Protection Policy

Information Collected. Type of Information Collected. We may collect two general types of information when you use the Site:

Dutch Data Protection Authority - Annual Report 2014

Tilburg University. U.S. Subpoenas and European data protection legislation Moerel, Lokke; Jansen, Nani; Koëter, Jeroen

LEGISLATION COMMITTEE OF THE CROATIAN PARLIAMENT

SAFE HARBOR PRIVACY NOTICE EFFECTIVE: July 1, 2005 AMENDED: July 15, 2014

UNILEVER PRIVACY PRINCIPLES UNILEVER PRIVACY POLICY

PRESIDENT S DECISION No. 40. of 27 August Regarding Data Protection at the European University Institute. (EUI Data Protection Policy)

Trusted Personal Data Management A User-Centric Approach

Corporate Policy. Data Protection for Data of Customers & Partners.

WEBSITE PRIVACY POLICY. Last modified 10/20/11

technical factsheet 176

ECSA EuroCloud Star Audit Data Privacy Audit Guide

Estée Lauder Companies Global Jobs Website Privacy Policy

European Union Data Protection Law and The Friend Finder Service in Social Networks

AN INTRODUCTION TO THE EU DIRECTIVE ON THE PROTECTION OF PERSONAL DATA

EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update. By Stephen H. LaCount, Esq.

Data Compliance. And. Your Obligations

LIFE INSURANCE ASSOCIATION IRELAND LIMITED MEMBERSHIP TERMS AND CONDITIONS

DISASTER RECOVERY INSTITUTE CANADA WEBSITE PRIVACY POLICY (DRIC) UPDATED APRIL 2004

Data and Cyber Laws Up-date 9 July 2015

IOM Data Privacy and Accuracy Policy

eprivacyseal GmbH Criteria catalogue EU November 2013

RPM INTERNATIONAL INC. AND ITS SUBSIDIARIES AND OPERATING COMPANIES SAFE HARBOR PRIVACY NOTICE. EFFECTIVE AS OF: August 12, 2015

Transcription:

Privacy Seminar - Social Networks Robert Kleinpenning & Judith van Stegeren 5th June 2015

Defining social networks What is a social network anyway?

Defining social networks What is a social network anyway?

Defining social networks What is a social network anyway?

Defining social networks What is a social network anyway?

Issues surrounding social networks Sharing is caring If it s free, you re the product. Many different adversaries....and many others.

Issues surrounding social networks Metadata & manipulation

Issues surrounding social networks Metadata & manipulation

Issues surrounding social networks Some social networks provide privacy controls. But are these effective?

Issues surrounding social networks Some data brokers anonymize the data before sharing it with third parties. Is this enough?

Issues surrounding social networks Some social networks have a business model based on selling user data. Is this legal?

Legal aspects: NL Recap of privacy legislation in The Netherlands Wet Bescherming Persoonsgegevens (WPB) implementation of Data Protection Directive (95/46/EG) College Bescherming Persoonsgegevens (CBP)

Legal aspects: NL Contents of Dutch privacy law Specification of purpose collected for the fulfillment of the purpose only relevant data ground for processing (consent, contract, public task,...) report to CBP

Legal aspects: EU Recap of privacy legislation in The European Union European Convention on Human Rights (ECHR) Charter of Fundamental Rights of the European Union Data Protection Directive (95/46/EG) eprivacy Directive (2002/58/EC) Cookie Directive (2009/136/EC)

Legal aspects: EU Article 8 from Charter of Fundamental Rights of the European Union Everyone has the right to the protection of personal data concerning him or her. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.

Legal aspects: EU Definitions from the Data Protection Directive Article 2a: personal data Any information relating to an identified or identifiable natural person (one who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his physical, physiological, mental, economic, cultural or social identity) Article 2b: processing Any operation or set of operations which is performed upon personal data, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction.

Legal aspects: EU European Court of Justice Lindqvist case processing without reporting to DPA transborder flow processing sensitive personal data without consent Advice of European Court is binding

Legal aspects: EU Article 29 working party Representatives of member state Data Protection Authorities Opinion on Social Networks (2009) Influential on European and national level

Legal aspects: EU Highlights from Opinion on Social Networks Sometimes the user is also data controller SNS should provide clear information regarding purpose of data collection, prior to processing. SNS should provide privacy-friendly settings by default. SNS must set maximum periods to retain data on inactive users. Abandoned accounts must be deleted. Users should, in general, be allowed to adopt a pseudonym. The Data Protection Directive generally applies to the processing of personal data by SNS, even when their headquarters are outside of the EEA.

Legal aspects: EU

Legal aspects: EU Highlights from Opinion on Social Networks Sometimes the user is also data controller SNS should provide clear information regarding purpose of data collection, prior to processing. SNS should provide privacy-friendly settings by default. SNS must set maximum periods to retain data on inactive users. Abandoned accounts must be deleted. Users should, in general, be allowed to adopt a pseudonym. The Data Protection Directive generally applies to the processing of personal data by SNS, even when their headquarters are outside of the EEA.

Legal aspects: EU Transborder flow of personal data Distinction: EU and non-eu EU and EEA: Data Protection Directive implementations Non-EU: guarantee adequacy of data protection

Legal aspects: EU Safe Harbor Principles USA: no adequate protection Department of Commerce made Safe Harbor list Facebook promises to adhere to the rules of the European countries.

Legal aspects: EU Does Facebook follow the European/Dutch legislation? Investigations into Safe Harbor Framework Investigations into compliance with WBP

Break

Privacy Enhancing Technologies Diaspora* ShadowCrypt Multi-Party Privacy

Diaspora* servers not owned by a single company but by multiple ordinary people this changes applicability of certain laws no (big) data mining remain data owner

Diaspora* allow users to post to their other social networks (cross posting) you can just select a random pod, and sign up it has basic features of social networks aspects deleted = deleted no tampering with the stream no business model

Diaspora*

Diaspora* a pod can be difficult to setup facebook makes it difficult to give your pod access. slow development lacks features has bugs

Diaspora* your friends are probably not there

Diaspora* no big data mining decentralized no business model

ShadowCrypt https://github.com/sunblaze-ucb/shadowcrypt browser plugin prototype

ShadowCrypt

ShadowCrypt

ShadowCrypt

ShadowCrypt

ShadowCrypt symmetric key encryption manually share key with friends using export string uses a Shadow DOM

Shadow DOM upcoming w3c standard a second DOM outside the normal DOM original DOM and javascript cannot access the Shadow DOM ShadowCrypt stops keystroke event propagation supports multiple keys for the same domain for decryption users can only select 1 key for encryption

Multi-Party Privacy different modes of sharing My facebook is completely closed off! audiances privacy conflicts friendship wallposts and tagging group membership fan pages event attendance

Example case Alice uploads a picture of (Alice and) Bob on her own timeline and Eve tags Bob Both the audiances of Alice and Bob can now see the image Bob doesn t want this What are his options?

Formalizing Privacy Conflicts

Formalizing Privacy Conflicts Privacy conflicts

Formalizing Privacy Conflicts Mutual privacy policy

Formalizing Privacy Conflicts Unreleased prototype hides posts names friendships

Questions?