• Sc chevron_right

      Dan Solove on Privacy Regulation

      news.movim.eu / Schneier · 3 days ago - 03:28 · 2 minutes

    Law professor Dan Solove has a new article on privacy regulation. In his email to me, he writes: “I’ve been pondering privacy consent for more than a decade, and I think I finally made a breakthrough with this article.” His mini-abstract:

    In this Article I argue that most of the time, privacy consent is fictitious. Instead of futile efforts to try to turn privacy consent from fiction to fact, the better approach is to lean into the fictions. The law can’t stop privacy consent from being a fairy tale, but the law can ensure that the story ends well. I argue that privacy consent should confer less legitimacy and power and that it be backstopped by a set of duties on organizations that process personal data based on consent.

    Full abstract:

    Consent plays a profound role in nearly all privacy laws. As Professor Heidi Hurd aptly said, consent works “moral magic”—it transforms things that would be illegal and immoral into lawful and legitimate activities. As to privacy, consent authorizes and legitimizes a wide range of data collection and processing.

    There are generally two approaches to consent in privacy law. In the United States, the notice-and-choice approach predominates; organizations post a notice of their privacy practices and people are deemed to consent if they continue to do business with the organization or fail to opt out. In the European Union, the General Data Protection Regulation (GDPR) uses the express consent approach, where people must voluntarily and affirmatively consent.

    Both approaches fail. The evidence of actual consent is non-existent under the notice-and-choice approach. Individuals are often pressured or manipulated, undermining the validity of their consent. The express consent approach also suffers from these problems ­ people are ill-equipped to decide about their privacy, and even experts cannot fully understand what algorithms will do with personal data. Express consent also is highly impractical; it inundates individuals with consent requests from thousands of organizations. Express consent cannot scale.

    In this Article, I contend that most of the time, privacy consent is fictitious. Privacy law should take a new approach to consent that I call “murky consent.” Traditionally, consent has been binary—an on/off switch—but murky consent exists in the shadowy middle ground between full consent and no consent. Murky consent embraces the fact that consent in privacy is largely a set of fictions and is at best highly dubious.

    Because it conceptualizes consent as mostly fictional, murky consent recognizes its lack of legitimacy. To return to Hurd’s analogy, murky consent is consent without magic. Rather than provide extensive legitimacy and power, murky consent should authorize only a very restricted and weak license to use data. Murky consent should be subject to extensive regulatory oversight with an ever-present risk that it could be deemed invalid. Murky consent should rest on shaky ground. Because the law pretends people are consenting, the law’s goal should be to ensure that what people are consenting to is good. Doing so promotes the integrity of the fictions of consent. I propose four duties to achieve this end: (1) duty to obtain consent appropriately; (2) duty to avoid thwarting reasonable expectations; (3) duty of loyalty; and (4) duty to avoid unreasonable risk. The law can’t make the tale of privacy consent less fictional, but with these duties, the law can ensure the story ends well.

    • chevron_right

      Facebook, Instagram may cut fees by nearly 50% in scramble for DMA compliance

      news.movim.eu / ArsTechnica · Tuesday, 19 March - 16:42

    Facebook, Instagram may cut fees by nearly 50% in scramble for DMA compliance

    Enlarge (credit: NurPhoto / Contributor | NurPhoto )

    Meta is considering cutting monthly subscription fees for Facebook and Instagram users in the European Union nearly in half to comply with the Digital Market Act (DMA), Reuters reported .

    During a day-long public workshop on Meta's DMA compliance, Meta's competition and regulatory director, Tim Lamb, told the European Commission (EC) that individual subscriber fees could be slashed from 9.99 euros to 5.99 euros. Meta is hoping that reducing fees will help to speed up the EC's process for resolving Meta's compliance issues. If Meta's offer is accepted, any additional accounts would then cost 4 euros instead of 6 euros.

    Lamb said that these prices are "by far the lowest end of the range that any reasonable person should be paying for services of these quality," calling it a "serious offer."

    Read 22 remaining paragraphs | Comments

    • chevron_right

      Vending machine error reveals secret face image database of college students

      news.movim.eu / ArsTechnica · Friday, 23 February - 22:02

    Vending machine error reveals secret face image database of college students

    Enlarge (credit: Aurich Lawson | Mars | Getty Images)

    Canada-based University of Waterloo is racing to remove M&M-branded smart vending machines from campus after outraged students discovered the machines were covertly collecting facial-recognition data without their consent.

    The scandal started when a student using the alias SquidKid47 posted an image on Reddit showing a campus vending machine error message, "Invenda.Vending.FacialRecognitionApp.exe," displayed after the machine failed to launch a facial recognition application that nobody expected to be part of the process of using a vending machine.

    "Hey, so why do the stupid M&M machines have facial recognition?" SquidKid47 pondered.

    Read 17 remaining paragraphs | Comments

    • chevron_right

      Meta relents to EU, allows unlinking of Facebook and Instagram accounts

      news.movim.eu / ArsTechnica · Monday, 22 January - 18:56

    Meta relents to EU, allows unlinking of Facebook and Instagram accounts

    Enlarge (credit: Anadolu / Contributor | Anadolu )

    Meta will allow some Facebook and Instagram users to unlink their accounts as part of the platform's efforts to comply with the European Union's Digital Markets Act (DMA) ahead of enforcement starting March 1.

    In a blog , Meta's competition and regulatory director, Tim Lamb, wrote that Instagram and Facebook users in the EU, the European Economic Area, and Switzerland would be notified in the "next few weeks" about "more choices about how they can use" Meta's services and features, including new opportunities to limit data-sharing across apps and services.

    Most significantly, users can choose to either keep their accounts linked or "manage their Instagram and Facebook accounts separately so that their information is no longer used across accounts." Up to this point, linking user accounts had provided Meta with more data to more effectively target ads to more users. The perk of accessing data on Instagram's widening younger user base, TechCrunch noted , was arguably the $1 billion selling point explaining why Facebook acquired Instagram in 2012 .

    Read 15 remaining paragraphs | Comments

    • chevron_right

      Meta’s “overpriced” ad-free subscriptions make privacy a “luxury good”: EU suit

      news.movim.eu / ArsTechnica · Thursday, 30 November - 18:37

    Meta’s “overpriced” ad-free subscriptions make privacy a “luxury good”: EU suit

    Enlarge (credit: NurPhoto / Contributor | NurPhoto )

    Backlash over Meta's ad-free subscription model in the European Union has begun just one month into its launch.

    On Thursday, Europe's largest consumer group, the European Consumer Organization (BEUC), filed a complaint with the network of consumer protection authorities. In a press release , BEUC alleges that Meta's subscription fees for ad-free access to Facebook and Instagram are so unreasonably high that they breach laws designed to protect user privacy as a fundamental right.

    "Meta has been rolling out changes to its service in the EU in November 2023, which require Facebook and Instagram users to either consent to the processing of their data for advertising purposes by the company or pay in order not to be shown advertisements," BEUC's press release said. "The tech giant’s pay-or-consent approach is unfair and must be stopped."

    Read 22 remaining paragraphs | Comments

    • chevron_right

      Disclosure of Pirates’ Identities “Compatible With EU Privacy Laws”

      news.movim.eu / TorrentFreak · Friday, 29 September, 2023 - 07:00 · 6 minutes

    EU Copyright Following the creation of its Hadopi anti-piracy agency over 13 years ago, France monitored and stored data on millions of users suspected of infringing copyrights.

    The majority were BitTorrent users and the plan was to use evidence of their piracy activities as a basis for escalating actions including warnings, fines, and ultimately, internet disconnections.

    Operating the program for a decade cost French taxpayers 82 million euros ($86.5 million) but according to digital rights group La Quadrature du Net, Hadopi’s “mass internet surveillance” destroyed citizens’ fundamental right to privacy.

    In its quest to hold Hadopi to account, La Quadrature du Net highlighted one of the program’s implementing decrees, which authorizes the creation of files containing internet users’ IP addresses plus personal identification data obtained from their internet service providers.

    In the belief that represents a breach of EU data protection laws, the digital rights group, ISPs, and other like-minded supporters, took their fight to the French legal system.

    Referral to the EU’s Highest Court

    In the vast majority of cases, senior judges in EU member states have little need to consult Europe’s highest court. At least in theory, all countries are already in compliance with EU law but every now and again, the gravity of specific cases becomes apparent, resulting in a referral seeking clarification on how EU law should be interpreted.

    In advance of a full ruling, the conundrum posed by the French referral was evident in a non-binding opinion handed down last October by CJEU Advocate General Maciej Szpunar.

    Under EU law, member states may not pass national laws that allow for the general and indiscriminate retention of citizens’ traffic and location data. Retention of such data is permitted on a targeted basis, but only as a “preventative measure” for the purposes of fighting “serious crime.” In respect of the information held by Hadopi, the Advocate General found that when the data points are combined, it’s possible to link French citizens’ identities with the content they access.

    The CJEU’s top legal advisor described the Hadopi situation as “serious interference with fundamental rights” but short of accepting “general impunity for offenses committed exclusively online,” something would have to give. The compromise suggested last year would require “readjustment of the case-law of the Court” to allow rightsholders to enforce their rights when an IP address is the only means by which an infringer can be identified (CJEU, pdf ) .

    Advocate General Delivers Opinion (Case C-470/21)

    The opinion delivered Thursday begins with an overview of Hadopi and the methods it uses to deter online piracy. By monitoring initial and subsequent acts of infringement and maintaining relevant databases, it’s possible to identify repeat infringers eligible for the next deterrent steps. A decree adopted in 2010 allows Hadopi to request subscriber information from ISPs in response to the provision of IP addresses, mostly obtained from BitTorrent swarms.

    The legal proceedings brought by La Quadrature du Net and the Federation of Associative Internet Service Providers, French Data Network, and Franciliens.net, seek to establish whether the collection of civil identity data corresponding to IP addresses, and subsequent automated processing of data to protect of intellectual property, are compatible with EU law absent a review by a court or independent administrative body.

    The short answer from the AG’s opinion is that Article 15(1) of Directive 2002/58 ( pdf ) must be interpreted as not precluding national legislation which allows ISPs and other electronic communications services to retain, and an administrative authority such as Hadopi to access, civil identity data corresponding to IP addresses for the purposes of identifying suspected infringers.

    No court or review body needs to be involved, but use of such data is only permitted when it is the only means of investigation that can enable a suspected infringer to be identified.

    Discussion and Reasoning

    In the opinion of AG Szpunar, there is a need to reconcile the rights at issue; the protection of private life and personal data on one hand, and the right to property enshrined in Article 17 of the Charter , which the graduated response mechanism seeks to uphold by protecting copyright and related rights.

    The opinion notes that “the great majority” of the IP addresses communicated by Hadopi are dynamic IP addresses, which only correspond to a specific identity at a single moment, which preclude any exhaustive tracking.

    “I must emphasise that the protection of fundamental rights on the internet does not in my view justify access to the data relating solely to the IP address, the content of a work and the identity of the person who made it available in breach of copyright not being permitted, but means only that the retention of and access to those data must be accompanied by guarantees,” his opinion continues.

    “To my mind, an analogy with the real world is telling: a person suspected of having committed theft cannot rely on his or her right to protection of his or her private life to prevent those responsible for prosecuting that offense from ascertaining what the content stolen is. On the other hand, that person may rightly rely on his or her fundamental rights to ensure that, during the proceedings, access will not be provided to more extensive data than just the data necessary for the classification of the alleged offense.”

    No Mass Surveillance But a Proportionate Response

    The digital rights groups’ legal action characterizes the Hadopi program as a general surveillance and data retention scheme, operating contrary to fundamental rights. AG Szpunar finds otherwise, noting that there doesn’t even appear to be general surveillance of the users present in peer-to-peer networks.

    “That procedure does not involve monitoring their entire activity on a given network in order to determine whether they have made a work available in breach of copyright, but rather determining, on the basis of a file identified as counterfeit, the holder of the internet access through which the user made the content available,” his opinion reads.

    “[I]t is not a question of monitoring the activity of all users of peer-to-peer networks, but only that of persons uploading infringing files, as the uploading of those files reveals much less information about the person’s private life because files may be uploaded for the sole purpose of enabling those users then to download other files.”

    Inevitable Outcome in Favor of Rightsholders

    The overall conclusion reached by the Attorney General considers the purpose for which the data is harvested and the challenges of identifying suspected online infringers by other means. The inability to establish a detailed profile of a person’s private life via a dynamic IP address is cited on one hand, while the critical value of an IP address in an investigation sits somewhat uncomfortably on the other.

    “[I]t follows from the actual case-law of the Court that, where an offense is committed exclusively online, such as an infringement of copyright on a peer-to-peer network, the IP address may be the only means of investigation enabling the person to whom that address was assigned at the time of the commission of the infringement to be identified,” the AG continues.

    In closing, the retention and access to civil identifying data, corresponding to an IP address for the purposes of prosecuting online infringements, is described as “strictly necessary” and “wholly proportionate” to the objective pursued

    “Such an interpretation is in my view inevitable,” the AG notes, “unless it is accepted that a whole range of criminal offenses may evade prosecution entirely.”

    The CJEU’s summary and AG Szpunar’s full opinion are available here ( pdf ) and here .

    CJEU note: The Advocate General’s Opinion is not binding on the Court of Justice. It is the role of the Advocates General to propose to the Court, in complete independence, a legal solution to the cases for which they are responsible. The Judges of the Court are now beginning their deliberations in this case. Judgment will be given at a later date

    From: TF , for the latest news on copyright battles, piracy and more.

    • chevron_right

      Meta loses battle in EU, will ask for consent to show personalized ads

      news.movim.eu / ArsTechnica · Tuesday, 1 August, 2023 - 20:20

    Meta loses battle in EU, will ask for consent to show personalized ads

    Enlarge (credit: NurPhoto / Contributor | NurPhoto )

    After five years of fighting legal battles to prevent this undesirable outcome, Meta has finally agreed to ask Instagram and Facebook users in the European Union for consent before targeting them with highly personalized ads, a Wall Street Journal report has revealed.

    This means that instead of requiring Meta app users in the EU to agree to invasive data collection used for personalized ads at sign-up, or else fill out a long form to request to opt out , EU users will soon be able to opt in or out by clicking simply yes or no.

    The Journal spoke to sources familiar with Meta's dealings who confirmed that Meta sent a proposal to EU privacy regulators agreeing to shift to this consent legal basis for data collection as early as the end of October.

    Read 12 remaining paragraphs | Comments

    • chevron_right

      Norway has had it with Meta, threatens $100K fines for data violations

      news.movim.eu / ArsTechnica · Tuesday, 18 July, 2023 - 16:52

    Norway has had it with Meta, threatens $100K fines for data violations

    Enlarge (credit: NurPhoto / Contributor | NurPhoto )

    Meta's data privacy woes in Europe continue as Norway has announced an immediate ban on "behavioral advertising" on Facebook and Instagram. Until Meta makes some big changes, it will be fined $100,000 daily for Norwegian user privacy breaches, the Norwegian Data Protection Authority, Datatilsynet, said yesterday.

    "Meta tracks in detail the activity of users of its Facebook and Instagram platforms," Datatilsynet's press release said. "Users are profiled based on where they are, what type of content they show interest in, and what they publish, amongst others. These personal profiles are used for marketing purposes—so called behavioral advertising. The Norwegian Data Protection Authority considers that the practice of Meta is illegal and is therefore imposing a temporary ban of behavioral advertising on Facebook and Instagram."

    Norway has not banned the apps. Its ban is focused on restricting data collection for behavioral advertising and starts August 4. The temporary ban could drag on for three months unless Meta takes remedial action sooner.

    Read 11 remaining paragraphs | Comments

    • chevron_right

      Meta blocking VPN access to Threads in EU

      news.movim.eu / ArsTechnica · Friday, 14 July, 2023 - 15:54

    Meta blocking VPN access to Threads in EU

    Enlarge (credit: Bloomberg / Contributor | Bloomberg )

    This month, Meta's new Twitter-alternative Threads launched in 100 countries , but not in the European Union, due to potential conflicts between the app's vast data collection and the EU's strict data privacy laws. Immediately, reports emerged that some EU users persisted in downloading Threads anyway—by hiding their location and accessing the app via a virtual private network, or VPN.

    Now, Meta has confirmed that it has taken measures to block VPN access to Threads in the EU.

    "Threads is not currently available in most countries in Europe, and we’ve taken additional steps to prevent people based there from accessing it at this time," a Meta spokesperson told TechCrunch . "Europe continues to be an incredibly important market for Meta, and we hope to make Threads available here in the future."

    Read 12 remaining paragraphs | Comments