<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SIIA Digital Discourse&#187; Policy &#8211; Privacy</title>
	<atom:link href="http://www.siia.net/blog/index.php/category/public-policy/privacy-policy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.siia.net/blog</link>
	<description>SIIA Blog</description>
	<lastBuildDate>Fri, 01 Mar 2013 21:44:20 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.2</generator>
		<item>
		<title>FTC: Don&#8217;t Confuse Mobile with Personal</title>
		<link>http://www.siia.net/blog/index.php/2013/02/ftc-dont-confuse-mobile-with-personal/</link>
		<comments>http://www.siia.net/blog/index.php/2013/02/ftc-dont-confuse-mobile-with-personal/#comments</comments>
		<pubDate>Fri, 01 Feb 2013 21:57:33 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Mobility]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9972</guid>
		<description><![CDATA[SIIA is supportive of the FTC’s effort to provide guidance for the multistakeholder approach to mobile privacy protection being led by the NTIA. Today’s mobile guidance report from the FTC provides some useful input to that end. However, SIIA continues to strongly disagree with some of the high-level conclusions reached by the Commission. Particularly, SIIA [...]]]></description>
			<content:encoded><![CDATA[<p>SIIA is supportive of the FTC’s effort to provide guidance for the multistakeholder approach to mobile privacy protection being led by the NTIA.</p>
<p>Today’s <a href="http://www.ftc.gov/os/2013/02/130201mobileprivacyreport.pdf">mobile guidance report</a> from the FTC provides some useful input to that end. However, SIIA continues to strongly disagree with some of the high-level conclusions reached by the Commission. Particularly, SIIA strongly disagrees with the FTC’s conclusion that “[m]ore than other types of technology, mobile devices are typically personal to an individual, almost always on, and with the user.”</p>
<p>While this may be true when applied to smartphones and the model for their use today, SIIA strongly believes that this vision misses the mark for tablets, and it most certainly inaccurately portrays the evolving nature of Internet-based technology and new-age devices. On the contrary, SIIA is confident that the larger trend in technology with products and services offered seamlessly across a wide range of platforms and devices, coupled with the increasing saturation of Internet-powered devices reflects the shift to an environment where devices are less “personal” and less linked to a particular individual than personal computers.</p>
<p>For instance, just several years after the introduction of the tablet computer, and less than a decade after the introduction of the the modern smartphone, it is not uncommon for a household to have a wide range of internet-connected devices, with perhaps the majority of those devices being mobile devices shared by numerous users.</p>
<p>SIIA believes that the FTC’s fundamental misunderstanding about the increasing personalization of devices sets an inappropriate basis on which to build a foundation of privacy practices, either voluntary or mandatory. In order to develop an effective privacy framework for rapidly evolving technology, it is critical that we fully understand how this evolution is taking place, and all the opportunities that this innovation brings.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy. Follow the SIIA public policy team on Twitter at <a href="http://www.twitter.com/siiapubpolicy">@SIIAPubPolicy</a>. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/02/ftc-dont-confuse-mobile-with-personal/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ECPA Reform in 2013, or Bust!</title>
		<link>http://www.siia.net/blog/index.php/2013/01/ecpa-reform-in-2013-or-bust/</link>
		<comments>http://www.siia.net/blog/index.php/2013/01/ecpa-reform-in-2013-or-bust/#comments</comments>
		<pubDate>Mon, 28 Jan 2013 15:42:12 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9889</guid>
		<description><![CDATA[There is no better day in 2013 to focus on the need to reform the Electronic Communications Privacy Act (ECPA) than today, Jan. 28, Data Privacy Day.  There is much talk about privacy legislation in this new Congress. No current law is as outdated and in need of reform than ECPA, and no proposal enjoys [...]]]></description>
			<content:encoded><![CDATA[<p>There is no better day in 2013 to focus on the need to reform the Electronic Communications Privacy Act (ECPA) than today, Jan. 28, Data Privacy Day.  There is much talk about privacy legislation in this new Congress. No current law is as outdated and in need of reform than ECPA, and no proposal enjoys such a level of broad support among industry and consumer advocates alike.</p>
<p>Originally enacted in 1986, ECPA is failing miserably to provide a legal framework for the 21<sup>st</sup> Century. Back in the mid-80s, electronic communications were quite different than they are today. Email didn’t even exist, let alone “cloud-based” email. One example of how the current law fails protect citizen’s privacy in the current era: Google‘s <a href="http://googleblog.blogspot.com/2013/01/transparency-report-what-it-takes-for.html">Transparency Report</a>, released last week, which highlights the steady increase in government requests for users’ data.</p>
<p>Notably, the Report breaks out the types of requests that Governments entities use when compelling the company to hand over users’ information.  In summary, 68 percent of the requests Google received from government entities in the U.S. were made through subpoenas. These are requests for user-identifying information, issued under ECPA, and they are the easiest to get because they typically don’t involve judges. Only 22 percent were through ECPA search warrants. These warrants are, generally speaking, orders issued by judges under ECPA, based on a demonstration of “probable cause” to believe that certain information related to a crime is presently in the place to be searched.</p>
<p>The conclusion here is very clear, and very disturbing.  The privacy playing field is not level; and it’s a concern for citizens and companies alike.  If government entities want to access your email and communications on your computer in your house, they need to get a warrant, but if they want to access the same information stored remotely by a company like Google, Facebook or others, the standard is MUCH lower.  That’s not good for citizens, and it’s not good for the continued technological evolution towards “cloud computing,” and therefore it’s an impediment to innovation and economic growth.</p>
<p>Support for ECPA reform is extremely broad.  The <a href="http://www.digitaldueprocess.org">Digital Due Process Coalition</a> represents a diverse set of nearly 80 privacy advocates, major companies, industry trade associations, and think tanks working together to ensure that private electronic correspondence stored with an Internet company in the “cloud” receive the same protection afforded letters, photos and other private material stored in a drawer or filing cabinet, or on a computer at home.</p>
<p>As a result of this outpouring of support for ECPA reform, there was substantial progress in 2012.  As one of the final acts of the last Congress, Senate Judiciary Chairman Patrick Leahy (D-VT), the champion of legislation to reform ECPA in the last Congress, <a href="http://www.nationaljournal.com/tech/senate-panel-takes-up-e-privacy-issues-20121129">won approval</a> of his proposal by the Committee in November.  In a nutshell, the law would require law enforcement officials to get a search warrant from a judge in order to obtain content from a communications service provider that holds private electronic messages, photos and other personal records, like Gmail or Facebook. This means having to show the court there is probable cause to believe that the sought-after records may reveal evidence of wronging.</p>
<p>While the clock ran out on the last Congress before the proposed ECPA fix could be enacted, Sen. Leahy has deemed this one of his top priorities for 2013, and House Judiciary Chairman Bob Goodlatte (R-VA) has indicated he will consider this issue this year, too.  So Congress has one clear privacy priority for 2013, and that’s to pass this long-overdue update to ECPA to level the playing field for online communications.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy. Follow the SIIA public policy team on Twitter at <a href="http://www.twitter.com/siiapubpolicy">@SIIAPubPolicy</a>. </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/01/ecpa-reform-in-2013-or-bust/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reed Elsevier and Intel Offer Free Data Privacy Resource for Teens in Honor of Data Privacy Day</title>
		<link>http://www.siia.net/blog/index.php/2013/01/reed-elsevier-and-intel-offer-free-data-privacy-resource-for-teens-in-honor-of-data-privacy-day/</link>
		<comments>http://www.siia.net/blog/index.php/2013/01/reed-elsevier-and-intel-offer-free-data-privacy-resource-for-teens-in-honor-of-data-privacy-day/#comments</comments>
		<pubDate>Thu, 24 Jan 2013 22:25:12 +0000</pubDate>
		<dc:creator>Laura Greenback</dc:creator>
				<category><![CDATA[Education]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[data privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9885</guid>
		<description><![CDATA[SIIA member companies Reed Elsevier and Intel are supporting privacy education by offering free downloads of a data privacy book for teens. The book, &#8220;LOLOMG,&#8221; will be available for free from January 25-29, in honor of Data Privacy Day (January 28). The book, available here, teaches high school students what they need to know about [...]]]></description>
			<content:encoded><![CDATA[<p>SIIA member companies Reed Elsevier and Intel are supporting privacy education by offering free downloads of a data privacy book for teens. The book, &#8220;LOLOMG,&#8221; will be available for free from January 25-29, in honor of <a href="http://www.staysafeonline.org/data-privacy-day/">Data Privacy Day</a> (January 28).</p>
<p>The book, available <a href="http://www.lolomgfree.com/">here</a>, teaches high school students what they need to know about online reputation management, digital citizenship and cyberbullying. It describes the various privacy risks young people face online, and helps them take steps to protect themselves.</p>
<p>Data Privacy Day is an effort to empower people to protect their privacy and control their digital footprint. It is spearheaded by the National Cybersecurity Alliance and its partners.</p>
<p>Read more about Data Privacy Day and <a href="http://www.staysafeonline.org/data-privacy-day/teen-and-young-adult-resources">online privacy protection for teens</a>.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/greenback.jpg" alt="" width="100" align="left" /> <em>Laura Greenback is Communications Director at SIIA. Follow the SIIA Public Policy team at <a href="http://www.twitter.com/siiapolicy">@SIIAPolicy</a>.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/01/reed-elsevier-and-intel-offer-free-data-privacy-resource-for-teens-in-honor-of-data-privacy-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIIA Announces Commitment to Data-Driven Innovation as a Top Policy Priority in 2013</title>
		<link>http://www.siia.net/blog/index.php/2013/01/siia-announces-commitment-to-data-driven-innovation-as-a-top-policy-priority-in-2013/</link>
		<comments>http://www.siia.net/blog/index.php/2013/01/siia-announces-commitment-to-data-driven-innovation-as-a-top-policy-priority-in-2013/#comments</comments>
		<pubDate>Thu, 17 Jan 2013 14:34:35 +0000</pubDate>
		<dc:creator>Ken Wasch</dc:creator>
				<category><![CDATA[Cloud/Gov]]></category>
		<category><![CDATA[Content]]></category>
		<category><![CDATA[Education]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Cloud Computing]]></category>
		<category><![CDATA[Policy - Cybersecurity]]></category>
		<category><![CDATA[Policy - Intellectual Property]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[PSIG]]></category>
		<category><![CDATA[SIIA News]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[Software Events]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9693</guid>
		<description><![CDATA[The SIIA Government Affairs Council met Wednesday to outline the organization’s policy priorities for 2013.  In addition to identifying the specific initiatives it will pursue in the year ahead, SIIA and its member companies expressed a commitment to making data-driven innovation a top policy priority in the year ahead.  The SIIA Government Affairs Council includes: [...]]]></description>
			<content:encoded><![CDATA[<p>The SIIA Government Affairs Council met Wednesday to outline the organization’s policy priorities for 2013.  In addition to identifying the specific initiatives it will pursue in the year ahead, SIIA and its member companies expressed a commitment to making data-driven innovation a top policy priority in the year ahead.  The SIIA Government Affairs Council includes: Reed Elsevier, IBM, Adobe, Cengage, Dow Jones, Intuit,  Kaplan, Kiplinger, Google, McGraw Hill Education, McGraw Hill Financial, Oracle, Pearson, Red Hat, SAS, and Thomson Reuters.</p>
<p>A key theme unifying the work of SIIA on behalf of its members is an increased focus on advancing the effective collection and positive use of data. It is essential that public policy recognizes that innovation and business strategies are increasingly driven by data. Importantly, data-driven innovation not only holds the promise of advancing economic opportunity and jobs, but of providing tremendous consumer and societal benefits.</p>
<p>With so much at stake, SIIA is committed to actively promoting the economic and social value of data-driven innovation. Our efforts will involve direct outreach to legislators, along with a White Paper that includes recommendations for policymakers and governments. Our goal is to make certain that public policy helps enable the tremendous societal and economic benefits of data-driven innovation.</p>
<p>With members in both technology and information services, SIIA is uniquely positioned to highlight and address the public policy issues that arise from the increased salience of data-driven innovation. We began to focus more strongly on this issue in 2012, and it will be an even more important part of our work in 2013.</p>
<p>SIIA also announced its general tech policy priorities for 2013, along with policy priorities in the areas of: intellectual property; public sector IT, and; education technology.<span id="more-9693"></span></p>
<p><strong>Technology Policy Priorities</strong></p>
<ul>
<li>Promote and enable the economic and social value of data-driven innovation, including through a White Paper with recommendations for policymakers and governments.</li>
<li>Actively support voluntary, enforceable codes of conduct to provide enhanced data privacy protections, and oppose legislative and regulatory proposals that lack the flexibility to accommodate rapid technological innovation.</li>
<li>Promote policies around the world that facilitate cross-border data flows, and develop interoperable legal frameworks that help to advance global implementation of cloud computing.</li>
<li>Promote critical cybersecurity policies, in the U.S. and around the world, that will help the public and private sectors work together to more effectively mitigate this threat, without stifling innovation.</li>
</ul>
<p><strong>Intellectual Property Priorities</strong></p>
<ul>
<li>Protect the economic interests and creative rights of software and content publishers by responding as appropriate to the Supreme Court opinion in Kirtsaeng v. John Wiley &amp; Sons Inc. and any other cases, policies or legislation relating to the copyright law’s first sale exception/exhaustion principle that may unduly limit their ability to license and control the distribution of their software and content products</li>
<li>Encourage economic growth and innovation by working for further reform of the patent system to address the ongoing problem of patent trolls, including measures to restrict asymmetric discovery burdens.</li>
<li>Monitor the ICANN’s domain name expansion process with the goal of enhancing and strengthening online transparency and accountability by working to ensure that domain name and IP address Whois databases remain publicly accessible, accurate, and reliable, as key tools to combat online infringement of copyrights and trademarks, and other fraudulent or criminal acts online.</li>
<li>Actively monitor for, and act upon as necessary, hearings, legislative or regulatory copyright reform proposals in the United States and abroad, such as issues relating to orphan works, library exceptions and piracy, to ensure that they advance and do not adversely affect the copyright interests of SIIA members.</li>
<li>Oppose changes to the CFAA that would unduly limit the ability of SIIA members to deter and prevent unauthorized access – and access that exceeds authorized access to databases, subscription services and cloud services.</li>
<li>Ensure that any international treaty relating to copyright exceptions for the blind and visually impaired that may be adopted by WIPO includes adequate safeguards to protect the copyright interests of SIIA’s publishers.</li>
</ul>
<p><strong>Public Sector IT Priorities</strong></p>
<ul>
<li>Encourage Administration IT initiatives for federal agencies to be more open, transparent and efficient, delivering better services to citizens, while reducing the overall cost of government. Information Technology has and will continue to play a role in the Federal government’s effort to deliver better services to citizens, while reducing the overall cost of government.</li>
<li>Support a continuation of the effort to move agencies to cloud, consolidate the existing data center infrastructure and better leverage government data.</li>
<li>Advocate for key administration initiatives that support the overall mission of the SIIA Public Sector Innovation Group including: Cloud First, Big Data, Data Center Consolidation, Digital Government/Mobile, and FedRAMP.</li>
<li>Support reasonable reform of the Federal acquisition process, which needs to change to keep pace with the rapid pace of technology.</li>
<li>Intervene to support member interest in the legislative consideration of the proposal by Chairman Daryl Issa to reform federal IT acquisition, which will serve as a basis for a broader discussion around the need to improve IT acquisition to keep pace with technology in 2013.</li>
</ul>
<p><strong>Ed Tech Priorities</strong></p>
<ul>
<li>Seek increased investment in education technology and its integration into teaching and learning, including to personalize learning for each student.</li>
<li>Reform outdated regulations in favor of 21st Century e-learning policies, especially the shift from seat-time to anytime, everywhere competency-based learning.</li>
<li>Support education technology research and development through government-industry partnership, not government competition with the private sector.</li>
<li>Support the value of the for-profit sector in providing education products and services to public schools, agencies and institutions.</li>
<li>Encourage targeted STEM education, training and other workforce development policies to meet the economy’s needs for a skilled high-tech workforce.</li>
<li>Actively translate public policies, programs and regulations into actionable market intelligence for SIIA members.</li>
</ul>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/staff/wasch_tn.jpg" alt="Ken Wasch" width="100" align="left" /><em>Ken Wasch is President of SIIA.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2013/01/siia-announces-commitment-to-data-driven-innovation-as-a-top-policy-priority-in-2013/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Data Broker Briefing Reveals Complex Data Ecosystem</title>
		<link>http://www.siia.net/blog/index.php/2012/12/data-broker-briefing-reveals-complex-data-ecosystem/</link>
		<comments>http://www.siia.net/blog/index.php/2012/12/data-broker-briefing-reveals-complex-data-ecosystem/#comments</comments>
		<pubDate>Tue, 18 Dec 2012 21:01:54 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9519</guid>
		<description><![CDATA[In a briefing convened by the Congressional Privacy Caucus last week, co-chairs Ed Markey (D-MA) and Joe Barton (R-TX) explored the roles of “data brokers,” along with two chief regulators from the FTC, Chairman Jon Leibowitz and Commissioner Julie Brill. The briefing and discussion was wide-ranging, and if anything, it seemed to raise more questions [...]]]></description>
			<content:encoded><![CDATA[<p>In a briefing convened by the <a href="http://markey.house.gov/press-release/advisory-markey-barton-host-bi-partisan-congressional-briefing-data-brokers-ftc">Congressional Privacy Caucus last week</a>, co-chairs Ed Markey (D-MA) and Joe Barton (R-TX) explored the roles of “data brokers,” along with two chief regulators from the FTC, Chairman Jon Leibowitz and Commissioner Julie Brill. The briefing and discussion was wide-ranging, and if anything, it seemed to raise more questions than provide answers.  </p>
<p>If there was one single over-arching takeaway for me, it was that there exists a very complex data ecosystem that includes consumers, businesses and governments, and it’s increasingly difficult to label entities for purposes of creating new laws and regulations.  Following is a summary of key themes I took out of this briefing:</p>
<p><strong>(1) There’s no broad agreement on the definition of “data broker.”  </strong>The discussion did not include a clear articulation of what the lawmakers and regulators believe to be a data broker definition of exactly what is a “data broker,” which seems to be the key question before deciding on new policies.  The best articulation was “an entity that collects data but which has no intersection w/ consumers directly.”  While this may make sense on the surface, it quickly breaks-down when moving forward to craft rules for data brokers, because it clearly leaves open a wide range of entities that openly characterize themselves as brokers but also provide for direct interaction with consumers.  </p>
<p>I wish we could put any discussion about new policies on hold until we can at least clearly know what we’re talking about as a “data broker.” </p>
<p><strong>(2) It’s the “use” stupid.</strong>  I was constantly reminded of the old refrain, “it’s the economy, stupid,” the now infamous phrase that explained ultimately why Bill Clinton would ultimately be elected President in 1992. If there is one thing that seems to enjoy broad agreement around data privacy, it’s that it is more important &#8212;  and useful— to look at how a data is used, and the potential for harm, than it is to single out ill-defined entities and try to craft specific legal and regulatory roadmaps for their behavior.  While, this was my takeaway and was surely shared by many other present at the briefing, it is the opposite of what leading lawmakers and regulators are thinking.  </p>
<p><strong>(3) The FTC will maintain a steady focus on “data brokers.” </strong> Regardless of the challenge in clearly defining data brokers, the FTC is sure they don’t like ‘em.  As clearly articulated by Commissioners Leibowitz and Brill, the FTC will maintain a heavy focus on “data brokers” – as was a unanimous recommendation from the <a href="http://ftc.gov/os/2012/03/120326privacyreport.pdf">FTC’s Privacy Paper</a> issued earlier this year.  While they did recognize there are significant benefits provided by “data brokers,” they made the following pronouncements:  (1)  much more needs to be done on the transparency front, (2) industry needs to do more to articulate existing transparency mechanisms; and (3) the Commission is exploring “what can and should be done beyond merely enforcement” of existing laws.</p>
<p><strong>(4) Reps. Markey and Barton will focus this conversation on children, then expand – </strong>As the bipartisan team leaders for increased privacy protection for consumers, Reps. Markey and Barton reiterated their commitment to continue moving forward with all deliberate speed in the next Congress, reintroducing their <a href="http://www.gpo.gov/fdsys/pkg/BILLS-112hr1895ih/pdf/BILLS-112hr1895ih.pdf">Do Not Track Kids Act (H.R. 1895)</a> and promising to sign-on even more than the 45 cosponsors from the current bill.  .  While that is surely no surprise to anyone, they went further to effectively outline their strategy to use the conversation on children’s privacy, expand the current age qualification in COPPA, and use this as a gateway to adopting privacy laws more broadly <a href="http://www.dataprivacymonitor.com/online-privacy/rep-markey-to-data-brokers-lets-start-with-kids-then-tackle-data-privacy-for-the-rest/">beyond children</a>.  </p>
<p><strong>(5) Transparency and industry leadership are key – </strong>Another theme that keeps coming up is the need for greater transparency and industry leadership in this area.  Similar to the ongoing discussions regarding “mobile transparency,” industry can and will surely continue to improve practices in this area, or we’ll be building the case for regulators and legislators to step in.</p>
<hr /><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2012/12/data-broker-briefing-reveals-complex-data-ecosystem/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SIIA Welcomes State Department’s Interventions on Cloud Computing and Privacy</title>
		<link>http://www.siia.net/blog/index.php/2012/12/siia-welcomes-state-departments-interventions-on-cloud-computing-and-privacy/</link>
		<comments>http://www.siia.net/blog/index.php/2012/12/siia-welcomes-state-departments-interventions-on-cloud-computing-and-privacy/#comments</comments>
		<pubDate>Fri, 14 Dec 2012 20:26:37 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Cloud Computing]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[europe]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9501</guid>
		<description><![CDATA[Last week U.S. Ambassador to the European Union, William Kennard, addressed Forum Europe’s 3rd Annual European Data Protection and Privacy Conference, and responded to the myth that the U. S. system of government access to information is a threat to the privacy rights of citizens of the other countries. He was especially effective in rebutting [...]]]></description>
			<content:encoded><![CDATA[<p>Last week U.S. Ambassador to the European Union, William Kennard, <a href="http://useu.usmission.gov/kennard_120412.html">addressed</a> Forum Europe’s 3rd Annual European Data Protection and Privacy Conference, and responded to the myth that the U. S. system of government access to information is a threat to the privacy rights of citizens of the other countries. He was especially effective in rebutting concerns directed at cloud computing, where the misconception has developed that information stored in cloud computing servers can be accessed by the U.S. government without any effective privacy controls.</p>
<p>His intervention is a welcome attempt to set the record straight before these erroneous beliefs become widespread and entrenched.  It was accompanied the release of State Department <a href="http://photos.state.gov/libraries/useu/231771/PDFs/Five%20Myths%20Regarding%20Privacy%20and%20Law%20Enforcement_October%209_2012_pdf.pdf">white paper</a> that dispels the misconceptions about the U.S. legal system and government access to information.</p>
<p>The fact is that the U.S. has a well-developed and established system to protect individual liberties from government intrusion.  We have a general distrust of a powerful government and are suspicious of anything that advances the growth of government power.  Our bias is in favor of a limited government that lets people chose their own good in their own way.  As a result we are far less tolerant of government intrusion into our private lives than other countries, and have set up a system whereby the U.S. extends privacy protections to non-U.S. citizens as well.</p>
<p>At the same time, the U.S. is more tolerant of the use of information for innovative and productive use by businesses than other countries, to our great advantage in the race for economic growth, business development and job creation.  Our system of protecting the individual privacy in the business context shows that this can be done while maintaining strong and effective protections for consumer privacy. This system also respects the rights of non-U.S. consumers established in other privacy regimes.</p>
<p>None of this means that the U.S. system is perfect.  We think that steps can be taken to improve the consumer privacy system for mobile app notifications and are actively working with the <a href="http://www.ntia.doc.gov/other-publication/2012/privacy-multistakeholder-process-mobile-application-transparency">U.S. Commerce Department</a> and other stakeholders on a voluntary code of conduct and an effective system of screen notices.  We have joined with others in the <a href="http://digitaldueprocess.org/index.cfm?objectid=37940370-2551-11DF-8E02000C296BA163">Digital Due Process Coalition</a> to modernize the 1986 U.S. Electronic Communications Privacy Act, which needs updating to fit the realities of email and document storage in the cloud.</p>
<p>But the need for these reforms does not suggest that the current U.S. system is a threat to privacy or justifies a move away from cloud computing as a way to avoid government scrutiny.  Ambassador Kennard is to be commended for his strong defense of the U.S. approach to privacy in the cloud.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow the SIIA Public Policy team on Twitter at <a href="http://www.twitter.com/siiapolicy">@SIIAPolicy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2012/12/siia-welcomes-state-departments-interventions-on-cloud-computing-and-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mobile Privacy: Congress Should Give Multistakeholder Discussions More time</title>
		<link>http://www.siia.net/blog/index.php/2012/12/mobile-privacy-congress-should-give-multistakeholder-discussions-more-time/</link>
		<comments>http://www.siia.net/blog/index.php/2012/12/mobile-privacy-congress-should-give-multistakeholder-discussions-more-time/#comments</comments>
		<pubDate>Thu, 06 Dec 2012 14:19:59 +0000</pubDate>
		<dc:creator>David LeDuc</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[Mobility]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=9348</guid>
		<description><![CDATA[Today,  the Senate Judiciary Committee is scheduled to consider legislation sponsored by Senator Al Franken (D-MN), the Location Privacy Protection Act of 2011 (S.1223), that would require app providers to seek affirmative &#8220;opt-in&#8221; consent from consumers before using their location information. As with all consumer privacy issues, users trust in mobile app privacy is absolutely [...]]]></description>
			<content:encoded><![CDATA[<p>Today,  the Senate Judiciary Committee is scheduled to consider legislation sponsored by Senator Al Franken (D-MN), the Location Privacy Protection Act of 2011 (S.1223), that would require app providers to seek affirmative &#8220;opt-in&#8221; consent from consumers before using their location information.</p>
<p>As with all consumer privacy issues, users trust in mobile app privacy is absolutely critical.  Without consumer trust, demand stalls, innovations is stifled and neither businesses nor users interests are served.  Straight-up, a lack of trust is a lose-lose. However, multistakeholder discussions have been ongoing since June of this year, engaging a wide range of industry and civil society in an <a href="http://www.ntia.doc.gov/other-publication/2012/privacy-multistakeholder-process-mobile-application-transparency">effort, led by the Department of Commerce NTIA</a>, to develop a voluntary code of conduct for mobile app transparency in information collecting.</p>
<p>This flexible, consensus process is also better able to ensure that policies are not technology or platform specific.  That is, at a time of increasing convergence, where “applications” are seamlessly offered across a wide range of devices, fixed laws such as this would stifle technological evolution by creating a distinct privacy regime based on a specific type of device.</p>
<p>SIIA is very supportive of the effort and confident that it can succeed if given time.  Consumers and businesses are in this together, dependent on each other as this new mobile ecosystem continues to evolve.  With the right consensus-driven framework, mobile app privacy can be a win-win for users and businesses.</p>
<p>Rather than considering rigid legislative mandates on the mobile app industry, Congress should continue to explore how to support this industry.  The House Energy and Commerce Committee did just that earlier this year by holding a <a href="http://energycommerce.house.gov/hearing/where-jobs-are-there%E2%80%99s-app">hearing</a> focused on this innovative industry and how it can spur economic and job growth.</p>
<p>Recommendations are good.  Consumer self-help is good.  But the world is looking to us to show that self-regulation can work as a viable alternative to government mandates.  To allow the multistakeholder efforts on mobile transparency to falter now would confirm their belief that only the government can set the rules of the road in this area.  It is time for the industry to step up and make progress on setting its own rules of the road. If we don’t we have only ourselves to blame if state, national or international governments feel compelled to step in to protect the public.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/david.jpg" alt="" width="100" align="left" /> <em>David LeDuc is Senior Director, Public Policy at SIIA. He focuses on e-commerce, privacy, cyber security, cloud computing, open standards, e-government and information policy.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2012/12/mobile-privacy-congress-should-give-multistakeholder-discussions-more-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do Not Track: Time for DAA to Move Forward</title>
		<link>http://www.siia.net/blog/index.php/2012/10/do-not-track-time-for-daa-to-move-forward/</link>
		<comments>http://www.siia.net/blog/index.php/2012/10/do-not-track-time-for-daa-to-move-forward/#comments</comments>
		<pubDate>Tue, 02 Oct 2012 17:44:50 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[DAA]]></category>
		<category><![CDATA[do not track]]></category>
		<category><![CDATA[WC3]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=8831</guid>
		<description><![CDATA[It is increasingly likely that the W3C process for Do Not Track will reach an impasse.  In a recent note to Federal Trade Commission Chairman Jon Leibowitz several consumer groups described their sense that the process is deadlocked, and asked the Chairman to intervene.  FTC officials are usually at the discussion, which are set to [...]]]></description>
			<content:encoded><![CDATA[<p>It is increasingly likely that the W3C process for Do Not Track will reach an impasse.  In a recent note to Federal Trade Commission Chairman Jon Leibowitz several consumer groups described their sense that the process is deadlocked, and asked the Chairman to intervene.  FTC officials are usually at the discussion, which are set to resume in Amsterdam this week, but in his <a href="http://www.mediapost.com/publications/article/183963/ftc-defends-w3cs-do-not-track-initiative-to-congr.html">letter</a> to Congress last week Chairman Leibowitz made it clear that it is the private sector group not the government that will adopt any Do Not Track standard.  Even with more direct FTC intervention, however, it is unlikely that parties will act contrary to their perceived fundamental interests.</p>
<p>The key disagreement is an understanding of what the Do Not Track flag means and what actions users can expect from websites and service providers if they turn it on.  Without this, the Do Not Track standard is incompletely specified, and provides less than comprehensive guidance for browser providers, websites and their service providers, and the general public.</p>
<p>If the W3C cannot reach a common understanding, perhaps the industry can.  The Digital Advertising Alliance has been looking at this issue for some time.  Indeed, back in February it <a href="https://www.aboutads.info/resource/download/DAA_Commitment.pdf">indicated</a> to the White House that it was going to address it:</p>
<p>“…the DAA intends to begin work immediately with browser providers to develop the consistent language across browsers regarding the browser based header signal uniform consumer choice mechanism that is simple to use and in a clear manner that describes to consumers the effect of exercising such choice.”</p>
<p>Mozilla <a href="http://blog.sidstamm.com/2011/01/opting-out-of-behavioral-ads.html">proposed</a> an easy-to-understand focused definition of Do Not Track back at the beginning of 2011:  “Tracking is the accumulation and use of a profile by advertising networks through invisible or subtle noting of which sites an individual visits, and the use of the profile data to customize advertisements displayed.”  Or, more succinctly, DNT means “<a href="http://web.archive.org/web/20110214122021/http:/firstpersoncookie.wordpress.com/2011/01/23/more-choice-and-control-over-online-tracking/">a way for people to opt-out of online behavioral advertising (OBA)</a>.”</p>
<p>These definitions make sense.  They focus on the issue that appears to be of most concern to the public and policymakers: cross-site tracking for the purpose of advertising profiling and targeting.  We need to give consumers another mechanism to say no to OBA if they wish.  Of course, the DAA definition should incorporate the current W3C consensus that DNT “on” imposes no obligation on first parties, except that first parties may not help third parties circumvent DNT.</p>
<p>Other uses of tracking should be permitted.  For example, if a website is doing standard analytics, such as keeping track of where their visitors come from and where they go, market research, product debugging and improvements, investigating possible fraud or intellectual property violations or security risks.</p>
<p>DAA is doing great work on OBA. <a href="http://www.aboutads.info/">Its AdChoices program</a> already gives consumers a cookie-based mechanism to opt out of OBA.  With DNT, DAA can do the industry and the public a service by bridging the browser DNT flag with the existing AdChoices program.</p>
<p>Customers should be told clearly that they can decline online behavioral advertising and how to do it.  DAA is in a unique position to move forward and break the logjam that is threatening to derail the promising initiative that is DNT.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow the SIIA Public Policy team on Twitter at <a href="http://www.twitter.com/siiapolicy">@SIIAPolicy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2012/10/do-not-track-time-for-daa-to-move-forward/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>COPPA Rulemaking Goes Far Beyond Congressional Intent; Will Harm American Innovation</title>
		<link>http://www.siia.net/blog/index.php/2012/09/siia-says-coppa-rulemaking-goes-far-beyond-congressional-intent-will-harm-american-innovation/</link>
		<comments>http://www.siia.net/blog/index.php/2012/09/siia-says-coppa-rulemaking-goes-far-beyond-congressional-intent-will-harm-american-innovation/#comments</comments>
		<pubDate>Mon, 24 Sep 2012 21:38:38 +0000</pubDate>
		<dc:creator>Ken Wasch</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[COPPA]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=8775</guid>
		<description><![CDATA[SIIA today filed comments with the Federal Trade Commission regarding its notice of proposed rulemaking on the Children&#8217;s Online Privacy Protection Act (COPPA). SIIA expressed significant concern that the FTC is creating a burdensome regulatory framework that goes well beyond congressional intent. The FTC&#8217;s proposed COPPA rulemaking takes the effort to protect online privacy and [...]]]></description>
			<content:encoded><![CDATA[<p>SIIA today filed comments with the Federal Trade Commission regarding its notice of proposed rulemaking on the Children&#8217;s Online Privacy Protection Act (COPPA). SIIA expressed significant concern that the FTC is creating a burdensome regulatory framework that goes well beyond congressional intent.</p>
<p>The FTC&#8217;s proposed COPPA rulemaking takes the effort to protect online privacy and turns it into a harmful barrier to American innovation. For years, we&#8217;ve worked closely with industry and government to advance online privacy and security. We&#8217;re confident that, with smart regulation and public-private cooperation, both the goal of protecting online privacy of children and the goal of business innovation can be served. Unfortunately, what we&#8217;re currently seeing from the FTC is an overly broad and unworkable regulatory framework for implementing COPPA.</p>
<p>To read SIIA&#8217;s full comments, please <a href="https://www.siia.net/index.php?option=com_docman&amp;task=doc_download&amp;gid=3716&amp;Itemid=318">click here</a>. In its comments, SIIA states:</p>
<blockquote><p>&#8220;We are supportive of the goals of the Commission to protect children from third-party plug-ins, social networks and any other third party service that collects personal information.</p>
<p>&#8220;However, the inappropriately broad expansion of the statute&#8217;s definition of personal information, combined with the increasingly broad definitions of ‘operator&#8217; and ‘web site or online service directed to children&#8217;&#8230; create a broad regulatory framework that dramatically exceeds the scope of COPPA and will most certainly stifle innovative Internet-based offerings-not just for sites and services directed at children under 13, but much more broadly.&#8221;</p></blockquote>
<p><strong>SIIA addresses six specific areas of concern:</strong></p>
<p>1. Expansion of &#8220;Personal Information&#8221; to include persistent identifiers creates an unworkable regulatory construct.</p>
<p>2. Modification to the rule&#8217;s definition of &#8220;operator&#8221; is overly-broad, and it places an unworkable responsibility on operators of sites and services well beyond the scope of COPPA.</p>
<p>3. Proposal to make third parties qualify as &#8220;operators&#8221; under COPPA by creating a &#8220;reason to know&#8221; standards is an inappropriately broad expansion of the statute and impractical.</p>
<p>4. Requirement for operators of &#8220;child-friendly mixed audience sites&#8221; to take an affirmative step to attain actual knowledge of child users would inappropriately expand the scope of COPPA.</p>
<p>5. Application platforms should not be characterized as &#8220;operators&#8221; under COPPA, but the Revised NPRM leaves this unclear.</p>
<p>6. The broad regulatory construct proposed in the Revised NPRM is likely to challenge application of COPPA to Internet-based educational materials and services.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/staff/wasch_tn.jpg" alt="Ken Wasch" width="100" align="left" /><em>Ken Wasch is President of SIIA.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2012/09/siia-says-coppa-rulemaking-goes-far-beyond-congressional-intent-will-harm-american-innovation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Do Not Track is at a Crossroad</title>
		<link>http://www.siia.net/blog/index.php/2012/09/do-not-track-is-at-a-cross-road/</link>
		<comments>http://www.siia.net/blog/index.php/2012/09/do-not-track-is-at-a-cross-road/#comments</comments>
		<pubDate>Mon, 17 Sep 2012 20:58:30 +0000</pubDate>
		<dc:creator>Mark MacCarthy</dc:creator>
				<category><![CDATA[Policy]]></category>
		<category><![CDATA[Policy - Privacy]]></category>
		<category><![CDATA[consumers]]></category>
		<category><![CDATA[do not track]]></category>

		<guid isPermaLink="false">http://www.siia.net/blog/?p=8617</guid>
		<description><![CDATA[The New York Times weekend piece on Do Not Track revived the debate on what the industry should do when users’ online privacy choices are made for them. Our view is that the choice should be left to the user, and not imposed by any platform or service provider. Last week, Google announced that it [...]]]></description>
			<content:encoded><![CDATA[<p>The New York Times weekend <a href="http://www.nytimes.com/2012/09/16/technology/in-microsofts-new-browser-the-privacy-light-is-already-on.html?ref=technology&amp;_moc.semityn.www">piece</a> on Do Not Track revived the debate on what the industry should do when users’ online privacy choices are made for them. Our view is that the choice should be left to the user, and not imposed by any platform or service provider. Last week, Google <a href="http://www.latimes.com/business/technology/la-fi-tn-google-do-not-track-option-coming-to-chrome-by-end-of-2012-20120914,0,4733827.story?track=rss">announced</a> that it would make available this user-controlled feature in its Chrome browsers by the end of the year.</p>
<p>In June Microsoft disrupted the industry discussions about how to provide a workable mechanism to empower users to make choices about online privacy and personalization. It announced that it would turn on the Do Not Track (DNT for short) signal in Internet Explorer 10 by default.  Mozilla, the maker of the competing browser, Firefox, was <a href="https://blog.mozilla.org/privacy/2012/05/31/do-not-track-its-the-users-voice-that-matters/">critical</a>. SIIA objected.  Advertisers announced that this decision ran counter to an agreement struck between the industry and the White House around opt-out as a <a href="http://www.aboutads.info/resource/download/DAA_Commitment.pdf">genuine consumer choice</a>.</p>
<p>Last week, Apache <a href="http://news.cnet.com/8301-1023_3-57508351-93/apache-web-software-overrides-ie10-do-not-track-setting/">revealed</a> that it will disable the DNT signals coming from Internet Explorer 10.  Roy Fielding, an author of the DNT standard and principal scientist at Adobe Systems, wrote a patch for Apache that sets the Web server to disable DNT if the browser reaching it is Internet Explorer 10.</p>
<p>The message is that a unilateral action forced on users by one industry player is not a sustainable solution.  We as an industry have to do it together, or not at all. If websites powered by Apache do not accept the IE10 DNT signal, it simply won’t reach critical mass.  Consumers, mislead by industry announcements and superficial stories from the trade press, might think their browers are giving them privacy over personalization&#8211;but the reality will be very different.</p>
<p>The danger is that the collaborative effort that has been building toward real privacy protection collapses. As Peter Bight <a href="http://arstechnica.com/information-technology/2012/08/microsoft-sticks-to-its-guns-keeps-do-not-track-on-by-default-in-ie10/">said</a> in ArsTechnica in August,” …there&#8217;s a very real prospect that the Do Not Track header will be both widely used, and widely ignored. In this situation, it would be difficult to describe it as anything other than a failure.”</p>
<p>Do not track is at a crossroad. Now it is up to the  industry to create a a simple, easy to use, consumer activated Do Not Track system that all parties can respect.</p>
<hr />
<p><img style="padding: 5px;" src="http://siia.net/images/stories/atrticles_images/10301_6_34507_photo.jpg" alt="" width="100" align="left" /> <em>Mark MacCarthy, Vice President, Public Policy at SIIA, directs SIIA’s public policy initiatives in the areas of intellectual property enforcement, information privacy, cybersecurity, cloud computing and the promotion of educational technology. Follow the SIIA Public Policy team on Twitter at <a href="http://www.twitter.com/siiapolicy">@SIIAPolicy</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.siia.net/blog/index.php/2012/09/do-not-track-is-at-a-cross-road/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>