<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SIIA Digital Discourse&#187; Policy &#8211; Privacy</title>
	<atom:link href="http://www.siia.net/blog/index.php/category/public-policy/privacy-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.siia.net/blog</link>
	<description>SIIA Blog</description>
	<lastBuildDate>Wed, 02 Oct 2013 20:37:09 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>SIIA Makes Policy Recommendations to Realize the Economic and Social Value of the Internet of Things</title>
		<link>http://www.siia.net/blog/index.php/2013/10/siia-makes-policy-recommendations-to-realize-the-economic-and-social-value-of-the-internet-of-things/</link>
		<comments>http://www.siia.net/blog/index.php/2013/10/siia-makes-policy-recommendations-to-realize-the-economic-and-social-value-of-the-internet-of-things/#comments</comments>
		<pubDate>Tue, 01 Oct 2013 13:03:30 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[internet of things]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14645</guid>
		<description><![CDATA[We are at a key inflection point in the history of information technology (IT).  The last decade has brought about significant advances in IT, representing an evolution for IT from a specialized tool into a pervasive influence on nearly every aspect of everyday life. This new Internet-enabled environment, often referred to as the “Internet of [...]]]></description>
			<content:encoded><![CDATA[<p>We are at a key inflection point in the history of information technology (IT).  The last decade has brought about significant advances in IT, representing an evolution for IT from a specialized tool into a pervasive influence on nearly every aspect of everyday life.</p>
<p>This new Internet-enabled environment, often referred to as the “Internet of Things,” presents tremendous economic and social value, and is capable of transforming the way we work, communicate, learn and live our lives. Consumers, citizens and society as a whole stand to benefit greatly from innovative uses of data to improve health outcomes, streamlining and enhancing financial services, enhancing education and learning, and improving and maximizing our physical infrastructure.</p>
<p>SIIA proposes the following five recommendations for policymakers to maximize the beneficial outcomes of the Internet of Things:</p>
<blockquote>
<ol>
<li>Policymakers should promote technology neutrality and avoid technology mandates.</li>
<li>De-identification often provides an opportunity way to balance the needs of DDI and privacy protection.</li>
<li>Uniform rules cannot be applied broadly to the role of notice and choice.</li>
<li>The principle of data minimization should be re-interpreted.</li>
<li>The Internet of Things requires a policy framework that provides for an evolving view of privacy rights based on risk and societal benefits.</li>
</ol>
</blockquote>
<p>I will participate in a panel discussion at the National Press Club today about building trust and confidence with regard to the Internet of Things.  The <a href="http://eu-ems.com/summary.asp?event_id=173&amp;page_id=1432">2013 M2M &amp; Internet of Things Global Summit</a>, hosted by Forum Europe, will take place in Washington DC today and tomorrow.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy. Follow the SIIA public policy team on Twitter at <a href="http://www.twitter.com/siiapubpolicy">@SIIAPubPolicy</a>. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/10/siia-makes-policy-recommendations-to-realize-the-economic-and-social-value-of-the-internet-of-things/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIIA Joins Tech Companies, Civil Rights Groups in Support of Surveillance Transparency Legislation</title>
		<link>http://www.siia.net/blog/index.php/2013/09/siia-joins-tech-companies-civil-rights-groups-in-support-of-surveillance-transparency-legislation/</link>
		<comments>http://www.siia.net/blog/index.php/2013/09/siia-joins-tech-companies-civil-rights-groups-in-support-of-surveillance-transparency-legislation/#comments</comments>
		<pubDate>Mon, 30 Sep 2013 18:43:58 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14632</guid>
		<description><![CDATA[SIIA today joined tech companies and civil rights groups including Google, Apple, Twitter and the ACLU in support of legislation that would improve transparency around government surveillance of the Internet. In a letter to Senate and House Judiciary Committee leaders, SIIA joined dozens of tech companies and civil rights and technology groups in support of [...]]]></description>
			<content:encoded><![CDATA[<p>SIIA today joined tech companies and civil rights groups including Google, Apple, Twitter and the ACLU in support of legislation that would improve transparency around government surveillance of the Internet.</p>
<p>In a <a href="https://www.cdt.org/files/pdfs/weneedtoknow-transparency-letter.pdf">letter</a> to Senate and House Judiciary Committee leaders, SIIA joined dozens of tech companies and civil rights and technology groups in support of Sen. Al Franken’s (D-MN) Surveillance Transparency Act of 2013, and Rep. Zoe Lofgren’s (D-CA)Surveillance Order Reporting Act of 2013. The bills would clarify that companies have the right to publish basic statistics about government demands for user data that they receive.</p>
<p>The letter states:</p>
<blockquote><p>“Such transparency is important not only for the American people, who are entitled to have an informed public debate about the appropriateness of that surveillance, but also for international users of U.S.-based service providers who are concerned about privacy and security.”</p></blockquote>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy. Follow the SIIA public policy team on Twitter at <a href="http://www.twitter.com/siiapubpolicy">@SIIAPubPolicy</a>. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/09/siia-joins-tech-companies-civil-rights-groups-in-support-of-surveillance-transparency-legislation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How NSA Revelations are Affecting the Tech Industry</title>
		<link>http://www.siia.net/blog/index.php/2013/09/how-nsa-revelations-are-affecting-the-tech-industry/</link>
		<comments>http://www.siia.net/blog/index.php/2013/09/how-nsa-revelations-are-affecting-the-tech-industry/#comments</comments>
		<pubDate>Tue, 24 Sep 2013 19:35:33 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[brazil]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[tech]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14565</guid>
		<description><![CDATA[Revelations about the National Security Agency&#8217;s (NSA) surveillance efforts are continuing to pose serious business challenges for the tech sector. SIIA is tracking the repercussions closely. Here are a few important developments to note: Market Backlash: Studies and surveys have suggested a possible backlash against cloud providers and technology companies generally.  Here’s a summary of [...]]]></description>
			<content:encoded><![CDATA[<p>Revelations about the National Security Agency&#8217;s (NSA) surveillance efforts are continuing to pose serious business challenges for the tech sector. SIIA is tracking the repercussions closely. Here are a few important developments to note:</p>
<p><strong>Market Backlash:</strong> Studies and surveys have suggested a possible backlash against cloud providers and technology companies generally.  Here’s a summary of some of them:</p>
<ul>
<li><a href="http://www.computerworld.com/s/article/9241003/U.S._cloud_firms_face_backlash_from_NSA_spy_programs?pageNumber=1">CSA Survey</a>: In July a survey from the Cloud Security Alliance reported  that  “10% of 207 officials at non-U.S. companies have canceled contracts with U.S. service providers following the revelation of the NSA spy program last month…the survey also found that 56% of non-U.S. respondents are now hesitant to work with any U.S.-based cloud service providers.”</li>
<li><a href="http://www2.itif.org/2013-cloud-computing-costs.pdf">ITIF Study</a>: By comparing projected growth of US cloud computing sales with a variety of hypothetical sales losses, ITIF suggests that US cloud companies could miss out on as much as $35 billion in additional overseas sales over the next three years.</li>
<li><a href="http://blogs.forrester.com/james_staten/13-08-14-the_cost_of_prism_will_be_larger_than_itif_projects?utm_content=buffer1b6d2&amp;utm_source=buffer&amp;utm_medium=twitter&amp;utm_campaign=Buffer">Forrester Study</a>: Forrester thinks the potential impact could be as high as $180 billion by 2016, taking into account the reactions of U.S. and non-US companies, the impact on non-US cloud providers and the effects on the rest of the hosting and outsourcing market.</li>
</ul>
<p><strong>Repercussions for Tech:</strong> The NSA revelations continue to have larger repercussions for tech companies in the form of localization requirements and new challenges to the multi-stakeholder form of Internet governance.  Here are updates on several of these challenges:</p>
<ul>
<li>Brazil’s controversial <a href="http://www.theguardian.com/world/2013/sep/20/brazil-dilma-rousseff-internet-us-control   ">new internet plans</a>, calling for server and data localization, a local encrypted email service and a separate transatlantic cable connection to Europe that bypasses the US.</li>
<li>UN General Assembly Address: After canceling a US state visit over NSA spying, Brazil&#8217;s Dilma Rousseff issued an announcement called the interception of Brazilian communications “illegal” and said such a “grave fact” was an “assault” on sovereignty and “incompatible with a democratic coexistence between friendly countries.”  She then delivered the opening speech at the UN General Assembly today, rejecting U.S. government surveillance programs as inconsistent with human rights and a violation of national sovereignty, and calling for “multilateral mechanisms for the worldwide network that are capable of ensuring principles such as:</li>
</ul>
<blockquote>
<ol>
<li>Freedom of expression, privacy of the individual and respect for human rights.</li>
<li>Open, multilateral and democratic governance, carried out with transparency by stimulating collective creativity and the participation of society, Governments and the private sector</li>
<li>Universality that ensures the social and human development and the construction of inclusive and non-discriminatory societies</li>
<li>Cultural diversity, without the imposition of beliefs, customs and values.</li>
<li>Neutrality of the network, guided only by technical and ethical criteria, rendering it inadmissible to restrict it for political, commercial, religious or any other purposes.</li>
</ol>
</blockquote>
<p>She <a href="http://gadebate.un.org/sites/default/files/gastatements/68/BR_en.pdf">concludes</a>: “Harnessing the full potential of the Internet requires, therefore, responsible regulation, which ensures at the same time freedom of expression, security and respect for human rights.”</p>
<p><strong>Civil Society Calls for Principles:</strong> International civil society groups have issued a <a href="https://www.eff.org/deeplinks/2013/09/united-nations-meets-thirteen-principles-against-unchecked-surveillance">call for government surveillance principles</a> consistent with human rights.</p>
<p><strong>EU Response: </strong>Viviane Reding’s <a href="http://europa.eu/rapid/press-release_SPEECH-13-720_en.htm?locale=en">address in Brussels</a> last week held up the Data Protection regulation as the EU’s response to the fear of US government surveillance, explicitly took privacy issues off the table for discussion in TTIP, and suggested the formation of an EU-area cloud that would compete globally on the basis of better privacy rules and streamlined government regulation.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow Mark on Twitter at <a href="http://www.twitter.com/Mark_MacCarthy">@Mark_MacCarthy</a></em></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/09/how-nsa-revelations-are-affecting-the-tech-industry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do Not Track is on Track at W3C</title>
		<link>http://www.siia.net/blog/index.php/2013/09/do-not-track-is-on-track-at-w3c/</link>
		<comments>http://www.siia.net/blog/index.php/2013/09/do-not-track-is-on-track-at-w3c/#comments</comments>
		<pubDate>Wed, 18 Sep 2013 20:07:06 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[do not track]]></category>
		<category><![CDATA[WC3]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14482</guid>
		<description><![CDATA[The W3C Tracking Protection Working Group announced today that it would appoint Carl Cargill, from Adobe, and Justin Brookman, from the Center for Democracy and Technology (CDT), to join Intel’s Matthias Schunter as co-chairs of the group’s effort to forge a multi-stakeholder consensus on creating a standard to address Tracking Protection.  The group’s standard setting [...]]]></description>
			<content:encoded><![CDATA[<p>The W3C Tracking Protection Working Group <a href="http://thehill.com/blogs/hillicon-valley/technology/323015-privacy-advocate-adobe-director-to-lead-do-not-track-talks">announced</a> today that it would appoint Carl Cargill, from Adobe, and Justin Brookman, from the Center for Democracy and Technology (CDT), to join Intel’s Matthias Schunter as co-chairs of the group’s effort to forge a multi-stakeholder consensus on creating a standard to address Tracking Protection.  The group’s standard setting activity will continue, despite the withdrawal of the Digital Advertising Alliance earlier this week, under the leadership of these three well-qualified experts.</p>
<p>SIIA welcomes this development.  Internet users, the industry, and policymakers here and around the world are looking for a workable standard to address Tracking Protection that can be easily and effectively implemented.  All parties share the goal of creating an effective framework to enable users to express their tracking preferences in a transparent and meaningful fashion with the understanding that these preferences will be respected by the relevant Internet participants. The continuation of this W3C process and the momentum created by the naming of additional co-chairs provide the opportunity to adopt a workable standard that is broadly acceptable to all stakeholders.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow Mark on Twitter at <a href="http://www.twitter.com/Mark_MacCarthy">@Mark_MacCarthy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/09/do-not-track-is-on-track-at-w3c/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Saving the Safe Harbor: Commissioner Julie Brill to the Rescue!</title>
		<link>http://www.siia.net/blog/index.php/2013/09/saving-the-safe-harbor-commissioner-julie-brill-to-the-rescue/</link>
		<comments>http://www.siia.net/blog/index.php/2013/09/saving-the-safe-harbor-commissioner-julie-brill-to-the-rescue/#comments</comments>
		<pubDate>Tue, 17 Sep 2013 19:45:30 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[EU]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14399</guid>
		<description><![CDATA[At the EU Data Protection and Privacy Conference today in Brussels, FTC Commissioner Julie Brill delivered a powerful speech about the way the U.S. protects consumer privacy. Along the way she offered a strong defense of the U.S. Safe Harbor Framework for European privacy: “In the commercial space, the Safe Harbor Framework facilitates the FTC’s [...]]]></description>
			<content:encoded><![CDATA[<p>At the EU Data Protection and Privacy Conference today in Brussels, FTC Commissioner Julie Brill delivered a powerful <a href="http://www.ftc.gov/speeches/brill/130917eudataprivacy.pdf">speech</a> about the way the U.S. protects consumer privacy. Along the way she offered a strong defense of the U.S. Safe Harbor Framework for European privacy:</p>
<blockquote><p>“In the commercial space, the Safe Harbor Framework facilitates the FTC’s ability to protect the privacy of EU consumers. Without the Safe Harbor, my job to protect EU consumers’ privacy, where appropriate, would be much harder. In an era where we face many threats to privacy, Safe Harbor has been an effective solution, not the problem.”</p></blockquote>
<p>In the face of so many challenges to the Safe Harbor Framework coming from European public officials, this speech from a prominent U.S. consumer protection official is a crucial reminder of the importance of this cross-border framework for international privacy protection.</p>
<p>Her remarks are also notable for the clear distinction she makes between government surveillance and commercial privacy:</p>
<blockquote><p>“The issue of the proper scope of government surveillance is a conversation that should happen – and will happen – on both sides of the Atlantic. But it is a conversation that should proceed outside out of the commercial privacy context.”</p></blockquote>
<p>As I’ve noted in previous blogs, the conflation of the two is damaging to both the need to protect citizens from intrusive government surveillance and in finding the right sort of fair information practices that provides for commercial enterprise, innovation and the preservation of consumer privacy.  Commissioner Brill is exactly right when she insists on keeping these issues separate.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow Mark on Twitter at <a href="http://www.twitter.com/Mark_MacCarthy">@Mark_MacCarthy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/09/saving-the-safe-harbor-commissioner-julie-brill-to-the-rescue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Keep the World Safe for Data Driven Innovation and Cross Border Data Flows</title>
		<link>http://www.siia.net/blog/index.php/2013/08/how-to-keep-the-world-safe-for-data-driven-innovation-and-cross-border-data-flows/</link>
		<comments>http://www.siia.net/blog/index.php/2013/08/how-to-keep-the-world-safe-for-data-driven-innovation-and-cross-border-data-flows/#comments</comments>
		<pubDate>Thu, 29 Aug 2013 16:04:38 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Data-Driven Innovation]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14136</guid>
		<description><![CDATA[In a major address to the German Marshall Fund yesterday, outgoing Commerce Department General Counsel Cameron Kerry brought some refreshing clarity to the current discussions of privacy and government surveillance. He started in the right place with a ringing endorsement of the progressive use of big data as a tool for economic and social improvement.  [...]]]></description>
			<content:encoded><![CDATA[<p>In a major <a href="http://www.commerce.gov/news/speech/2013/08/28/us-commerce-department-general-counsel-cameron-f-kerry-keynote-address-german">address</a> to the German Marshall Fund yesterday, outgoing Commerce Department General Counsel Cameron Kerry brought some refreshing clarity to the current discussions of privacy and government surveillance.</p>
<p class="MsoNormal">He started in the right place with a ringing endorsement of the progressive use of big data as a tool for economic and social improvement.<span style="mso-spacerun: yes;">  </span>He referred favorably to “breakthroughs in medical research from aggregated health care records that can produce information far more robust than the limited populations of medical trials,&#8221; and cited a recent example: <span style="mso-spacerun: yes;">   </span></p>
<blockquote>
<p class="MsoNormal">“The drug Herceptin was developed through identification of the HER-2 oncogene from records of 9,000 breast cancer patients. IBM is working with hospitals and the IBM-WATSON natural language system to collect anonymized medical records in ways that protect privacy and analyze unstructured data applying the power of new analytic technologies across many different text-based medical records previously unintelligible to computers.”</p>
</blockquote>
<p class="MsoNormal">As SIIA noted in a recent <a href="https://www.siia.net/index.php?option=com_docman&amp;task=doc_download&amp;gid=4279&amp;Itemid=318">whitepaper</a>, the seamless flow of data across borders is important to the growth of data-driven innovation and the global economy. Kerry underscored the economic importance of cross-border data flow:</p>
<blockquote>
<p class="MsoNormal"><span style="mso-spacerun: yes;"> </span>“Trans-border trade – and especially transatlantic trade – now relies on the continued open flow of data, and cutting off these flows would cause significant and immediate economic damage. Moreover, it would lead to loss of competitiveness on both sides as other economies around the world that embrace open Internet architectures and freedom to experiment with data analytics offer havens for innovators. Our economic future is at stake in our international engagement.”</p>
</blockquote>
<p class="MsoNormal">Then he noted the importance to transatlantic trade of the Safe Harbor arrangement that has governed transfers of information from the European Union to the United States for well over a decade. He warned of the dangers a weakening of this framework would pose to transatlantic trade:</p>
<blockquote>
<p class="MsoNormal">“Today, more than 4,000 companies have subscribed to the Safe Harbor Framework. Many of these are U.S. subsidiaries of EU companies that also rely on the framework…Safe Harbor is a fundamental building block of the trade relationship between the United States and Europe…Any step back from Safe Harbor would send the trading relationship between the U.S. and the EU backward.”</p>
</blockquote>
<p class="MsoNormal">This worry about a threat to the Safe Harbor Framework is not idle. On July 19, 2013 Viviane Reding, European Commission Vice President, issued a <a href="http://europa.eu/rapid/press-release_MEMO-13-710_en.htm">statement</a> <span style="mso-spacerun: yes;"> </span>saying, “The Safe Harbour agreement may not be so safe after all.” On July 24, 2013, a <a href="http://www.bfdi.bund.de/SharedDocs/Publikationen/Entschliessungssammlung/ErgaenzendeDokumente/PMDSK_SafeHarbor_Eng.pdf?__blob=publicationFile%20.">statement</a> from the Conference of German Data Protection Commissioners indicated that it would examine whether transatlantic data transfers “should be suspended on the basis of the Safe Harbour framework.”<span style="mso-spacerun: yes;">  </span></p>
<p class="MsoNormal">The basis for this threat to the Safe Harbor in both cases is the NSA revelations regarding government surveillance&#8211;but this is mixing up apples and oranges.</p>
<p class="MsoNormal">The EU Data Protection Directive and the Safe Harbor both provide an exception for national security purposes.<span style="mso-spacerun: yes;">  </span>In the US and EU regime, the law, regulation, and policy considerations that relate to protecting consumer privacy in a commercial context are completely different from the law and policy and constitutional considerations that govern government surveillance.<span style="mso-spacerun: yes;">  </span></p>
<p class="MsoNormal">Moreover, putting onerous burdens on the commercial transfer of information as a backdoor way to control government surveillance is self-defeating and counterproductive.<span style="mso-spacerun: yes;">  </span>It distracts from real measures that might protect citizens from overly intrusive government surveillance and it puts an unnecessary burden on commerce that is not justified by the need to preserve and protect consumer privacy in a commercial context.</p>
<p class="MsoNormal">Kerry’s remarks yesterday show he grasps these issues clearly.<span style="mso-spacerun: yes;">  </span>It might have been his last public statement before leaving his current post at the Commerce Department, but it sets a promising roadmap for Obama administration policy in this area.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow the SIIA Public Policy team on Twitter at <a href="http://www.twitter.com/Mark_MacCarthy">@Mark_MacCarthy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/08/how-to-keep-the-world-safe-for-data-driven-innovation-and-cross-border-data-flows/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIIA Op-Ed: New Mobile App Transparency Efforts Give Hope for Privacy Progress without Regulatory Mandates</title>
		<link>http://www.siia.net/blog/index.php/2013/08/siia-op-ed-new-mobile-app-transparency-efforts-give-hope-for-privacy-progress-without-regulatory-mandates/</link>
		<comments>http://www.siia.net/blog/index.php/2013/08/siia-op-ed-new-mobile-app-transparency-efforts-give-hope-for-privacy-progress-without-regulatory-mandates/#comments</comments>
		<pubDate>Wed, 28 Aug 2013 19:05:58 +0000</pubDate>
		<dc:creator>Laura Greenback</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=14086</guid>
		<description><![CDATA[In a TheHill.com op/ed today, Ken Wasch praised the multi-stakeholder process that led to a voluntary code of conduct for mobile app transparency. The tech industry worked with the Department of Commerce to meet the public need for privacy protection&#8211;without the need for draconian legislation or regulation. The code of conduct will make privacy policies [...]]]></description>
			<content:encoded><![CDATA[<p>In a <a href="http://thehill.com/blogs/congress-blog/technology/318973-new-mobile-app-privacy-efforts-give-hope-for-progress-over-regulatory-mandates#ixzz2dHDwOZdt">TheHill.com op/ed</a> today, Ken Wasch praised the multi-stakeholder process that led to a voluntary code of conduct for mobile app transparency. The tech industry worked with the Department of Commerce to meet the public need for privacy protection&#8211;without the need for draconian legislation or regulation.</p>
<p>The code of conduct will make privacy policies for mobile apps simpler and easier to understand. Ken says:</p>
<blockquote><p>&#8220;[We] live in a world where privacy policies are long and complex; they are documents written by lawyers for lawyers.  The new Code, which will lead to clearer, simpler notices, represents a fundamental shift in the paradigm of privacy transparency.&#8221;</p></blockquote>
<p>The companies that sign on to the code will help their users make informed decisions about which apps they want to use by:</p>
<ul>
<li>Providing a list of key data elements collected by apps</li>
<li>Offering a notice about relevant third party sharing</li>
</ul>
<p>These enhanced privacy tools will be a selling point for companies competing in the mobile app arena. Beyond that, they are an important step toward a win-win approach to privacy protection that protects consumers while leaving room for new ideas and apps. The code of conduct shows we can move forward on privacy protection without burdensome, costly regulation that stifles innovative growth.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/greenback.jpg" alt="" width="100" align="left" /> <em>Laura Greenback is Communications Director at SIIA. Follow the SIIA Public Policy Team at <a href="http://www.twitter.com/siiapolicy">@SIIAPolicy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/08/siia-op-ed-new-mobile-app-transparency-efforts-give-hope-for-privacy-progress-without-regulatory-mandates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Serious Business Challenges Posed by NSA Surveillance Revelations</title>
		<link>http://www.siia.net/blog/index.php/2013/08/siia-member-update-serious-business-challenges-posed-by-nsa-surveillance-revelations/</link>
		<comments>http://www.siia.net/blog/index.php/2013/08/siia-member-update-serious-business-challenges-posed-by-nsa-surveillance-revelations/#comments</comments>
		<pubDate>Tue, 20 Aug 2013 17:52:44 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Education Policy]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[PSIG]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[NSA]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[surveillance]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=13981</guid>
		<description><![CDATA[Recent revelations about the National Security Agency’s (NSA) surveillance efforts have clearly changed the privacy landscape for the remainder of 2013, if not much longer. This is a complex policy issue with very broad implications. Importantly for SIIA members, it is one that poses the following serious business challenges:  (1) enhanced privacy concerns among customers [...]]]></description>
			<content:encoded><![CDATA[<p>Recent revelations about the National Security Agency’s (NSA) surveillance efforts have clearly changed the privacy landscape for the remainder of 2013, if not much longer. This is a complex policy issue with very broad implications.</p>
<p>Importantly for SIIA members, it is one that poses the following serious business challenges:  (1) enhanced privacy concerns among customers around the world, (2) policymakers around the world seeking to restrict the cross-border flow of data and enact technology localization requirements, and (3) conflation of private sector data collection with government surveillance as an inseparable public-private partnership that necessitates strict new commercial privacy legislation or regulations—FTC Commission Julie Brill has recently <a href="http://www.washingtonpost.com/opinions/demanding-transparency-from-data-brokers/2013/08/15/00609680-0382-11e3-9259-e2aafe5a5f84_story.html">made this connection in an op-ed</a>, which has also come from influential thought-leaders such as former White House Chief of Staff <a href="http://www.americanprogressaction.org/issues/civil-liberties/news/2013/07/23/70427/domestic-data-collection-and-privacy-rights/">John Podesta</a>.</p>
<p>As a preliminary assessment, the Information Technology Innovation Foundation (ITIF) <a href="http://www2.itif.org/2013-cloud-computing-costs.pdf">estimates</a> that the U.S. cloud computing industry alone could lose up to $35 billion over the next three years if foreign customers decide the risks of storing data with a U.S. company outweigh the benefits.</p>
<p>SIIA has been very engaged in policy debates surrounding this issue for several months, and we expect to remain highly engaged to combat these challenges for months to come.  Recently, SIIA President Ken Wash was invited to a meeting at the White House in early August, which was one of several consultations leading up to the President’s <a href="http://www.whitehouse.gov/the-press-office/2013/08/09/background-president-s-statement-reforms-nsa-programs">call for reforms to NSA programs on August 9</a>.</p>
<p>As a follow-up to the discussion with Administration officials and the SIIA this week joined with other leading technology trade associations in sending a <a href="http://siia.net/govit/techprotectcivlib.pdf">letter</a> to Administration officials urging that discussions about national security must be kept separate from conversations about commercial privacy issues, as the policy considerations in these two areas are distinct. In the letter, SIIA and industry partner organizations made the following recommendations for action that are likely to frame our priorities for the remainder of 2013:</p>
<ol>
<li><strong>Implement transparency with respect to national security programs</strong> – in order to separate fact from fiction regarding the intersection of private sector IT companies and the U.S. Government, it is critical that the Administration enhance transparency and enable companies to share information publicly about the scope and frequency of Government inquiries;</li>
<li><strong>Promote policies that allow for unimpeded cross-border data flows such as the U.S.-EU Safe Harbor Framework</strong> – We are already seeing that longstanding and effective cross-border data mechanisms are being questioned in light of the recent disclosures about the U.S. government surveillance programs. For instance, recent statements by government officials in the EU indicate a lack of “trust” in the U.S.-EU Safe Harbor framework, which allows for the transfer of information from the EU to the U.S. for participating companies. This is one of many critical policies that facilitate digital trade for U.S. companies, and it is critical that U.S. government must vigorously engage with the international community to promote cross-border data flows while addressing privacy and civil liberties concerns; and</li>
<li><strong>Support reforming the Electronic Communications Privacy Act (ECPA) to enhance privacy in law enforcement investigations</strong> – SIIA has been a leading supporter of ECPA, seeking to update the outdated statue by correcting the double-standard that inappropriately provides for a lower level of privacy for communications stored remotely, or “in the cloud.” Currently, the law provides for a challenging legal environment for industry and a disincentive for customers to embrace hosted information and communications technology solutions as an alternative to on-premise solutions.</li>
</ol>
<p>SIIA believes that these are critical steps to ensuring that concerns about U.S. Government surveillance do not impose an unnecessary impediment to U.S. information technology businesses.  We are also closely monitoring a range of proposals in Congress that would seek to enhance transparency surrounding U.S. Government surveilance.  The  Surveillance Transparency Act of 2013 (S.1452) was introduced by <a href="https://www.cdt.org/files/file/surveillance-transparency-act-2013.pdf">Senator Al Franken</a> on August 1<sup>st</sup>, 2013, and the Surveillance Order Reporting Act of 2013 (H.R.3035) was introduced by <a href="http://lofgren.house.gov/images/stories/pdf/surveillance%20order%20reporting%20act%20-%20lofgren%20-%20080113.pdf">Congresswoman Zoe Lofgren</a> on August 2<sup>nd</sup>, 2013.  SIIA has not endorsed any bill at this point, but the Lofgren-Franken approach goes in the right direction by allowing companies to reveal how many national security requests they have received, how many they have complied with and how many users or accounts are affected.</p>
<p>We will continue to focus heavily on this critical issue to promote the ability of U.S. businesses to thrive in the U.S. and markets around the world.  To that end, we will provide further updates regarding new developments.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy. Follow the SIIA public policy team on Twitter at <a href="http://www.twitter.com/siiapubpolicy">@SIIAPubPolicy</a>. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/08/siia-member-update-serious-business-challenges-posed-by-nsa-surveillance-revelations/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIIA Supports Mobile App Code of Conduct</title>
		<link>http://www.siia.net/blog/index.php/2013/07/siia-supports-mobile-app-code-of-conduct/</link>
		<comments>http://www.siia.net/blog/index.php/2013/07/siia-supports-mobile-app-code-of-conduct/#comments</comments>
		<pubDate>Thu, 25 Jul 2013 15:00:37 +0000</pubDate>
		<dc:creator>Ken Wasch</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=13704</guid>
		<description><![CDATA[SIIA today voted in favor of the Short Form Notice Code of Conduct developed as part of the U.S. Department of Commerce’s Privacy Multi-stakeholder Process on Mobile Application Transparency. With the passage of this Code of Conduct, consumers will have more information about how their data is being used by mobile apps, and a greater [...]]]></description>
			<content:encoded><![CDATA[<p>SIIA today voted in favor of the Short Form Notice Code of Conduct developed as part of the U.S. Department of Commerce’s Privacy Multi-stakeholder Process on Mobile Application Transparency. </p>
<p>With the passage of this Code of Conduct, consumers will have more information about how their data is being used by mobile apps, and a greater ability to protect their privacy.</p>
<p>We don’t agree completely with all of the elements of the code, and we will continue to work to ensure that companies have substantial flexibility in providing privacy notices.  However, this Code of Conduct empowers consumers and provides an important roadmap for developers to create ‘short form’ privacy notices for consumer apps. We look forward to working with our members and the industry to encourage implementation of the guidelines set out by this Code of Conduct.</p>
<p>In a time of rapidly evolving technology, industry self-regulation is the most effective way to maintain the right balance between consumer confidence and continued innovation.  Without collaborative, voluntary efforts such as this mobile privacy code, we risk heavy-handed legislation or government regulation that would harm tech innovation, job creation and economic progress.</p>
<p>SIIA continues to strongly support the Obama Administration’s commitment to creating voluntary privacy codes of conduct through multistakeholder collaboration, and we look forward to engaging in future initiatives to this end.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/staff/wasch_tn.jpg" alt="Ken Wasch" width="100" align="left" /><em>Ken Wasch is President of SIIA. Follow the SIIA Software team on twitter at <a href="http://www.twitter.com/siiasoftware">@SIIASoftware</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/07/siia-supports-mobile-app-code-of-conduct/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIIA to FTC:  Internet of Things Requires Technology Neutral Policies and Flexible Privacy Framework</title>
		<link>http://www.siia.net/blog/index.php/2013/06/siia-to-ftc-internet-of-things-requires-technology-neutral-policies-and-flexible-privacy-framework/</link>
		<comments>http://www.siia.net/blog/index.php/2013/06/siia-to-ftc-internet-of-things-requires-technology-neutral-policies-and-flexible-privacy-framework/#comments</comments>
		<pubDate>Mon, 03 Jun 2013 19:38:49 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=12282</guid>
		<description><![CDATA[SIIA on Friday encouraged the FTC to be careful in its analysis of the “Internet of Things”—the growing supply of data inputs, sensors and interfaces that are embedded in our vehicles, household appliances, and beyond. SIIA agrees with the FTC that privacy and security are critical to unleashing the full potential of the growing supply [...]]]></description>
			<content:encoded><![CDATA[<p>SIIA on Friday encouraged the FTC to be careful in its analysis of the “Internet of Things”—the growing supply of data inputs, sensors and interfaces that are embedded in our vehicles, household appliances, and beyond. SIIA agrees with the FTC that privacy and security are critical to unleashing the full potential of the growing supply of data inputs from the new sensors and interfaces that are becoming part of our everyday lives. However, in our comments to the Commission, we asked that the FTC proceed cautiously if formulating any new policies, as these are likely to steer the future of DDI and the scope of what is possible for American innovation for decades to come.</p>
<p>Software and apps are now rapidly evolving as new services are offered seamlessly across our devices and appliances. As we recently identified in our white paper on <a href="http://siia.net/index.php?option=com_docman&#038;task=doc_download&#038;gid=4279&#038;Itemid=318">“<span style="text-decoration: underline;">Data Driven Innovation,”</span></a> the new Internet-enabled IT ecosystem has unleashed tremendous opportunities for economic growth and social innovation.</p>
<p>First and foremost, SIIA urged the Commission to promote technology neutral policies and avoid technology mandates.  For example, given the range of devices that lead to the collection and utilization of data, it is impractical and ineffective to create policies based solely on a specific type of device, or an arbitrary characteristic of a device, like whether it is mobile like a smartphone or automobile sensor, or whether it is stationary, such as a computer or a refrigerator. While it might seem practical to target specific devices or platforms, this approach is likely to become dated within a matter of months or years due to the rapid evolution of IT.</p>
<p>With respect to privacy, SIIA urged the FTC to support a policy framework that provides for an evolving view of privacy rights based on risk and societal benefits, re-assess long standing principles such as data minimization and encourage de-identification without creating broad mandates to that end.   Read the full comments <a href="http://www.siia.net/index.php?option=com_docman&amp;task=doc_download&amp;gid=4325&amp;Itemid=318">here</a>.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy. Follow the SIIA public policy team on Twitter at <a href="http://www.twitter.com/siiapubpolicy">@SIIAPubPolicy</a>. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/06/siia-to-ftc-internet-of-things-requires-technology-neutral-policies-and-flexible-privacy-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>