DQ
18 C O M M U N I C AT I O N S O F T H E A C M | F E B R U A R Y 2 0 1 5 | V O L . 5 8 | N O . 2
news
P H
O T
O B
Y B
I L
L C
L A
R K
/C Q
R O
L L
C A
L L
/G E
T T
Y I
M A
G E
S
Technology | DOI:10.1145/2693474 Logan Kugler
Online Privacy: Regional Differences How do the U.S., Europe, and Japan differ in their approaches to data protection — and what are they doing about it?
acknowledgment of the issue’s impor- tance and of the difficulties U.S. busi- nesses can face, the U.S. Department of Commerce has established “Safe Harbor” frameworks with the Europe- an Commission and with Switzerland to streamline efforts to comply with those regions’ privacy laws. After mak- ing certain its data protection practices adhere to the frameworks’ standards, a company can self-certify its compli- ance, which creates an “enforceable representation” that it is following rec- ommended practices.
Data Privacy in the U.S. EFF’s Rodriguez describes data protec- tion in the U.S. as “sectorial.” The 1996 Health Insurance Portability and Ac- countability Act (HIPAA), for example, applies to medical records and other health-related information, but noth- ing beyond that. “In Europe, they have general principles that apply to any sector,” she says.
The U.S. relies more on a self-regula- tory model, while Europe favors explicit
O N E O F T H E most controver- sial topics in our always- online, always-connected world is privacy. Even casu- al computer users have be-
come aware of how much “they” know about our online activities, whether re- ferring to the National Security Agency spying on U.S. citizens, or the constant barrage of ads related to something we once purchased.
Concerns over online privacy have brought different responses in differ- ent parts of the world. In the U.S., for example, many Web browsers let us- ers enable a Do Not Track option that tells advertisers not to set the cookies through which those advertisers track their Web use. Compliance is volun- tary, though, and many parties have de- clined to support it. On the other hand, European websites, since 2012, have been required by law to obtain visitors’ “informed consent” before setting a cookie, which usually means there is a notice on the page saying something like “by continuing to use this site, you consent to the placing of a cookie on your computer.” Why are these ap- proaches so different?
A Short History As the use of computers to store, cross- reference, and share data among cor- porations and government agencies grew through the 1960s and 1970s, so did concern about proper use and pro- tection of personal data. The first data privacy law in the world was passed in the German region of Hesse in 1970. That same year, the U.S. implemented its Fair Credit Reporting Act, which also contained some data privacy ele- ments. Since that time, new laws have been passed in the U.S., Europe, Japan, and elsewhere to try and keep up with technology and citizens’ concerns. Re- search by Graham Greenleaf of the Uni- versity of New South Wales published in
June 2013 (http://bit.ly/ZAygX7) found 99 countries with data privacy laws and another 21 countries with relevant bills under consideration.
There remain fundamental differ- ences in the approaches taken by the U.S., Europe, and Japan, however. One big reason for this, according to Katitza Rodriguez, international rights director of the Electronic Frontier Foundation (EFF), is that most countries around the world regard data protection and priva- cy as a fundamental right—that is writ- ten into the European Constitution, and is a part of the Japanese Act Con- cerning Protection of Personal Infor- mation. No such universal foundation exists in the U.S., although the Obama administration is trying to change that.
These differences create a compli- ance challenge for international com- panies, especially for U.S. companies doing business in regions with tighter privacy restrictions. Several major U.S. firms—most famously Google—have run afoul of EU regulators because of their data collection practices. In an
Protesters marching in Washington, D.C., in 2013 in opposition to governmental surveillance of telephone conversations and online activity.
F E B R U A R Y 2 0 1 5 | V O L . 5 8 | N O . 2 | C O M M U N I C AT I O N S O F T H E A C M 19
news
simpler for consumers and easier to ne- gotiate for international business.
There has been little progress on the CPBR since its introduction. Congress has shown little appetite for address- ing online privacy, before or after the administration’s proposal. Senators John Kerry (now U.S. Secretary of State, then D-MA) and John McCain (R-AZ) introduced the Commercial Privacy Bill of Rights Act of 2011, and Senator John D. Rockefeller IV (D-WV) intro- duced the Do-Not-Track Online Act of 2013; neither bill made it out of com- mittee. At present, the online privacy situation in the U.S. remains a mix of self-regulation and specific laws ad- dressing specific kinds of information.
Data Privacy in Europe As EFF’s Rodriguez pointed out, the 2000 Charter of Fundamental Rights of the European Union has explicit provisions regarding data protection. Article 8 says,
“Everyone has the right to the protec- tion of personal data concerning him or her. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.”
Even before the Charter’s adoption, a 1995 directive of the European Parlia- ment and the Council of the European Union read, “Whereas data-processing systems are designed to serve man; whereas they must, whatever the na- tionality or residence of natural per- sons, respect their fundamental rights and freedoms.” These documents es- tablish the EU-wide framework and
foundation for online privacy rights. The roots of the concern, says Rodri-
guez, lie in the countries’ memory of what happened under Nazi rule. “They understand that state surveillance is not only a matter of what the govern- ment does, but that a private company that holds the data can give it to the gov- ernment,” she says. Consequently, the EU is concerned with anyone that col- lects and tracks data, while in the U.S. the larger concern is government sur- veillance rather than corporate surveil- lance, “though I think that’s changing.”
The EU’s principles cover the entire Union, but it is up to individual coun- tries to carry them out in practice. “Im- plementation and enforcement varies from country to country,” explains Ro- driguez. “In Spain, Google is suffering a lot, but it’s not happening so much in Ireland. It’s not uniform.”
In December 2013, the Spanish Agency for Data Protection fined Google more than $1 million for mismanaging user data. In May 2014, the European Court of Justice upheld a decision by the same agency that Google had to remove a link to obsolete but damaging infor- mation about a user from its results; in response, Google set up a website to pro- cess requests for information removal, and by the end of that month claimed to have received thousands of requests.
Online Privacy in Japan The legal framework currently govern- ing data privacy in Japan is the 2003 Act Concerning Protection of Personal Information. The Act requires busi- nesses handling personal information to specify the reason and purpose for which they are collecting it. It forbids businesses from changing the infor- mation past the point where it still has a substantial relationship to the stated use and prohibits the data collector from using personal information more than is necessary for achieving the stat- ed use without the user’s consent. The Act stipulates exceptions for public health reasons, among others.
Takashi Omamyuda, a staff writer for Japanese Information Technology (IT) publication Nikkei Computer, says the Japanese government was expected to revise the 2003 law this year, “due to the fact that new technologies have weakened its protections.” Changes probably will be influenced by both the
laws. An example of the self-regulatory model is the Advertising Self-Regulato- ry Council (ASRC) administered by the Council of Better Business Bureaus. The ASRC suggests placing an icon near an ad on a Web page that would link to an explanation of what information is being collected and allow consumers to opt out; however, there is no force of law behind the suggestion. Oddly, Rodri- guez points out, while the formal U.S. regulatory system is much less restric- tive than the European approach, the fines handed down by the U.S. Federal Trade Commission—which is charged with overseeing what privacy regula- tions there are—are much harsher than similar fines assessed in Europe.
The Obama administration, in a January 2012 white paper titled Con- sumer Data Privacy in a Networked World: A Framework for Protecting Pri- vacy and Promoting Innovation in the Global Digital Economy, outlined seven privacy principles and proposed a Con- sumer Privacy Bill of Rights (CPBR). It stated that consumers have a right:
˲ to expect that data collection and use will be consistent with the context in which consumers provide the data,
˲ to secure and responsible han- dling of personal data,
˲ to reasonable limits on the personal data that companies collect and retain,
˲ to have their data handled in ways that adhere to the CPBR,
˲ to individual control over what personal data companies collect from them and how they use it,
˲ to easily understandable and ac- cessible information about privacy and security practices, and
˲ to access and correct personal data in usable formats.
The CPBR itself takes a two-pronged approach to the problem: it estab- lishes obligations for data collectors and holders, which should be in effect whether the consumer does anything or even knows about them, and “em- powerments” for the consumer. The obligations address the first four prin- ciples in the list, while the empower- ments address the last three.
Part of the impetus for the CPBR is to allay some EU concerns over U.S. data protection. The framework calls for working with “international partners” on making the multiple privacy schemes interoperable, which will make things
The EU is concerned with anyone that collects and tracks data, while in the U.S. the larger concern is government surveillance.
20 C O M M U N I C AT I O N S O F T H E A C M | F E B R U A R Y 2 0 1 5 | V O L . 5 8 | N O . 2
news
body charged with data protection. “No one is sure whether this amendment would fill the gap between current poli- cy and the regulatory approaches to on- line privacy in the EU and U.S.”
The Japanese government gathered public comments, including a sup- portive white paper from the Ameri- can Chamber of Commerce in Japan which, unsurprisingly, urged that any reforms “take the least restrictive ap- proach, respect due process, [and] lim- it compliance costs.”
Conclusion With the world’s data borders becoming ever more permeable even as companies and governments collect more and more data, it is increasingly important that different regions are on the same page about these issues. With the U.S. trying to satisfy EU requirements for data protec- tion, and proposed reforms in Japan us- ing the EU’s principles and the proposed U.S. CPBR as models, policies appear to be moving in that direction.
Further Reading
2014 Japanese Privacy Law Revision Public Comments, Keio University International Project for the Internet & Society http://bit.ly/1E8X3kR
Act Concerning Protection of Personal Information (Japan Law No. 57, 2003) http://bit.ly/1rIjZ3M
Charter of Fundamental Rights of the European Union http://bit.ly/1oGRu37
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data http://bit.ly/1E8UxuT
Greenleaf, G. Global Tables of Data Privacy Laws and Bills http://bit.ly/ZAygX7
Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in the Global Digital Economy, Obama Administration White Paper, February 2012, http://1.usa.gov/1rRdMUw
The OECD Privacy Framework, Organization for Economic Co-operation and Development, http://bit.ly/1tnkiil
Logan Kugler is a freelance technology writer based in Clearwater, FL. He has written for over 60 major publications.
© 2015 ACM 0001-0782/15/02 $15.00
European Commission’s Data Protec- tion Directive and the U.S. Consumer Privacy Bill of Rights (as outlined in the Obama administration white paper), as well as by the Organization for Eco- nomic Co-operation and Development (OECD) 2013 privacy framework.
In preparation for such revisions, the Japanese government established a Personal Information Review Work- ing Group. “Some Japanese privacy ex- perts advocate that the U.S. Consumer Privacy Bill of Rights and FTC (Federal Trade Commission) staff reports can be applied in the revision,” says Omam- yuda, “but for now these attempts have failed.” Meanwhile, Japanese Internet companies are arguing for voluntary regulation rather than legal restrictions, asserting such an approach is necessary for them to be able to utilize big data and other innovative technologies and to support international data transfer.
As one step in this process, the Japa- nese government announced a “policy outline” for the amendment of these laws in June 2014. “The main issue up for revision,” says Omamyuda, “is per- mitting the transfer of de-identified data to third parties under the new ‘third-party authority.’” The third-party authority would be an independent
U.S. President Barack Obama recently presented computer technology pioneer, data architect, and ACM A.M. Turing Award recipient Charles W. Bachman with the National Medal of Technology and Innovation for fundamental inventions in database management, transaction processing, and software engineering, for his work designing the first computer database.
The ceremony at the White House was followed by a gala celebrating the achievements and contributions to society of Bachman and other pioneers in science and technology.
Bachman received his bachelor’s degree in mechanical engineering from Michigan State University, and a master’s degree in that discipline from the University of Pennsylvania.
He went to work for Dow Chemical in 1950, eventually becoming that company’s first data processing manager. He joined General Electric, where in 1963 he developed the Integrated Data Store (IDS), one of the first database management systems.
He received the ACM A.M. Turing Award in 1973 for “his outstanding contributions to database technology.” Thomas Haigh, an associate professor of information studies at the University of Wisconsin, Milwaukee, and chair of the SIGCIS group for historians of computing, wrote at the time, “Bachman was the first Turing Award winner without a Ph.D., the first to be trained in engineering rather than science, the first to win for the application of computers to business administration, the first to win for a specific piece of software,
and the first who would spend his whole career in industry.”
On being presented with the National Medal of Technology and Innovation, Bachman said, “As a boy growing up in Michigan making Soap Box Derby racers, I knew that all I wanted to do when I grew up was to build things. I wanted to be an engineer. And I wanted to make the world a better place. An honor like this is something I never expected, so I’m deeply grateful to the President, Senator Edward J. Markey, and everyone at the Department of Commerce who voted for the recognition.”
He added, “It is important for me to credit my late wife, Connie, who was my partner in creativity, in business, and in life. There are a lot of friends, family and colleagues who helped along the way, of course.
I’d really like to thank them all, and especially those at General Electric who gave me the creative opportunities to invent. It is amazing how much faith GE had in our team with no guarantee of a useful result.
“I hope that young people just starting out can look at an honor like this and see all of the new creative opportunities that lay before them today, and the differences they can make for their generation and for future generations.”
President Obama said Bachman and the other scientists honored with the National Medal of Science and the National Medal of Technology and Innovation embody the spirit of the nation and its “sense that we push against limits and that we’re not afraid to ask questions.”
—Lawrence M. Fisher
Milestones
U.S. Honors Creator of 1st Computer Database
Copyright of Communications of the ACM is the property of Association for Computing Machinery and its content may not be copied or emailed to multiple sites or posted to a listserv without the copyright holder's express written permission. However, users may print, download, or email articles for individual use.