personal data ecosystem - nstic privacy workshop

46
Kaliya Hamlin, Executive Director ) identitycommons Presentation at the NSTIC Privacy Workshop June 28, 2011 Boston, Massachusetts PERSONAL DATA ECOSYSTEM CONSORTIUM PERSONAL DATA ECOSYSTEM CONSORTIUM NSTIC Privacy Workshop, June 28, 2011

Upload: kaliya-hamlin

Post on 08-May-2015

6.687 views

Category:

Technology


2 download

DESCRIPTION

Kaliya Hamin, Executive Director of PDEC's Presentation to the National Strategy on Trusted Identities in Cyberspace Privacy and Usability Workshop.

TRANSCRIPT

Page 1: Personal Data Ecosystem - NSTIC Privacy Workshop

Kaliya Hamlin, Executive Director

) identitycommons

Presentation at the NSTIC Privacy Workshop

June 28, 2011

Boston, Massachusetts

PERSONAL DATA ECOSYSTEM CONSORTIUM

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 2: Personal Data Ecosystem - NSTIC Privacy Workshop

End user advocate since 2003 with the handle:

Co-Founder, Co-Producer, Co-Facilitator

Internet Identity Workshop

A hub of innovation focused on user-centric identity.

Began in 2005 & # 13 is this October.) identitycommons

Saving the World with User-Centric Identity

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 3: Personal Data Ecosystem - NSTIC Privacy Workshop

Fair Information Practice PrinciplesTransparency

Individual Participation

Purpose Specification

Data Minimization

Use Limitation

Data Quality and Integrity

Security

Accountability and Auditing

1973

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 4: Personal Data Ecosystem - NSTIC Privacy Workshop

Can new and emerging technologies can be applied towards making FIPPs real today?

PersonalNetwork

NodesBlogs

MicroBlogsProfiles:

*Professional*Personal

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 5: Personal Data Ecosystem - NSTIC Privacy Workshop

http://www.ftc.gov/bcp/workshops/privacyroundtables/personalDataEcosystem.pdf

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

from a submission to FTC

Page 6: Personal Data Ecosystem - NSTIC Privacy Workshop

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 7: Personal Data Ecosystem - NSTIC Privacy Workshop

Track

Do Not Track

Track

Do Not Track

Privacy

Business as Usual

Privacy

Business as Usual

Privacy & Civil

Liberty

Advocacy Grou

ps

Online Service Providers,

Advertising NetworksData Mining Co’s

Do Not Track

Do Not Track

Track

TrackBusiness as Usual

Privacy

Business as Usual

Privacy

Service Providers Web/Telcom Advertising NetworksData Mining Co’sPERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 8: Personal Data Ecosystem - NSTIC Privacy Workshop

Do Not Track & Privacy

New Business Opportunities

+Middle Way

PERSONAL DATA ECOSYSTEM CONSORTIUM

Page 9: Personal Data Ecosystem - NSTIC Privacy Workshop

People can track themselves andgain value from their own data.

Leveraging Personal Devices &

Network Nodes

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 10: Personal Data Ecosystem - NSTIC Privacy Workshop

Individuals must be at the center of their

own data lives.

Diagram fromPersonal Data: The Emergence of a New Asset ClassA World Economic Forum Report, February 2011

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 11: Personal Data Ecosystem - NSTIC Privacy Workshop

Individuals move across contexts.Why Does this Matter?

Contexts the Individual does not want linked (without their knowledge andconsent).

http://cmykern.com/?p=1112

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 12: Personal Data Ecosystem - NSTIC Privacy Workshop

Women having the freedom not to present as women.

http://www.copyblogger.com/james-chartrand-underpants/

Why James Chartrand Wears Women’s

Underpants

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

“James” is a women who resorted to a male persona to get work as a copy editor. Originally she had presented as herself, a woman,but was unable to get copy editing jobs. Faced with the need to feed her family she resorted to create a male persona and the site Men with Pens (http://menwithpens.ca/) and got lots of good paying work. After 2 years James “came out” about really being a woman.

Page 13: Personal Data Ecosystem - NSTIC Privacy Workshop

1. Live Journal Friends2. Professional ID3. Feminist Identity

1. Totally Professional on Domain, GMail, LinkedIN2. Social but me on Facebook3. Spiritual under pseudonym on Live Journal

1. Me linked to real name2. Spiritual3. Gaming

Real examples of personae separation by womenattending my She’s Geeky conference.

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 14: Personal Data Ecosystem - NSTIC Privacy Workshop

Buddhist in Tennessee

http://wwp.greenwichmeantime.com/time-zone/usa/tennessee/map.htm

http://religions.iloveindia.com/buddhism.html

Religious Expression

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 15: Personal Data Ecosystem - NSTIC Privacy Workshop

Ethnic and Racial Minorities

http://www.hhs.state.ne.us/healthdisparities/MHfocusgroups.htm

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 16: Personal Data Ecosystem - NSTIC Privacy Workshop

Sexual Minorities

http://rowantinne.tripod.com/id28.html

http://en.wikipedia.org/wiki/Sexual_minority

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 17: Personal Data Ecosystem - NSTIC Privacy Workshop

Political Expression

Personal ExpressionPERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 18: Personal Data Ecosystem - NSTIC Privacy Workshop

Medical Issues

Mental Health IssuesFamily Issues http://huehueteotl.wordpress.com/2009/11/24/mental-health-32-times-more-cost-effective-at-increasing-happiness-than-money/

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 19: Personal Data Ecosystem - NSTIC Privacy Workshop

Goofy Habits or Hobbies

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Goofy Hobbies and Habits

Page 20: Personal Data Ecosystem - NSTIC Privacy Workshop

Teachers being able to drink socially when on own time.

Gammers: Blizzard WoW in game ID

vs “RealID” change.

Young people free to explore themselves

Freedom of Action

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 21: Personal Data Ecosystem - NSTIC Privacy Workshop

People need tools to manage:

• Contexts

• Personae

• Linking and data sharing

• Control inferences made from data

• Rights to use and share specific data

• Allowing data to be a part of aggregate sets

Business models and opportunities thatincentivize these capabilities are needed.

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 22: Personal Data Ecosystem - NSTIC Privacy Workshop

The Value of Personal Data is High

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 23: Personal Data Ecosystem - NSTIC Privacy Workshop

Today’s data brokers admit:“50% of our data is inaccurate.

We don’t know which 50%.”

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 24: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge. 

World Economic Forum ReportPersonal Data: The Emergence of a New Asset Class

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 25: Personal Data Ecosystem - NSTIC Privacy Workshop

Personal data types in this diagram are drawn from the types identified in Rethinking Personal Data Pre-Read Document published by the World Economic Forum written by Marc Davis et al published in June, 2010.

Types of Personal Data

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 26: Personal Data Ecosystem - NSTIC Privacy Workshop

People are the only ethical integrators

of their own diversedata streams.

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 27: Personal Data Ecosystem - NSTIC Privacy Workshop

Key operational roles:•subjects•relying parties• identity providers•attribute providers•accreditation authorities

Vision of Self Sustaining Ecosystem “will require new business models each of the service provider roles”

From NSTIC

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

My question: What about the individual’s (the subject’s) business model?

Page 28: Personal Data Ecosystem - NSTIC Privacy Workshop

We need business and market models

for business agents that work on the users behalf.

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 29: Personal Data Ecosystem - NSTIC Privacy Workshop

Tools for individuals to manage their own information and collect their own data

and get value from that in new markets.

Personal Data Stores BanksLockersServices

Vaults

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 30: Personal Data Ecosystem - NSTIC Privacy Workshop

One example of a market model with user business agents.PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 32: Personal Data Ecosystem - NSTIC Privacy Workshop

Adoption of OAuthData Representation JSON

Considering Federated Social Web OStatus, Activity Streams

Debates about semantic options and tools RDF, Linked Data, XRI/XDI

Innovation to solve new things: TeleHash

Open Standards & Interoperability

STA

RTU

P CIRCLE

PDEC

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 33: Personal Data Ecosystem - NSTIC Privacy Workshop

Legal InnovationInformation

Sharing Work Group

• You Own Your Data. You contractually own all your data.• Data You Grant Access To Is Legally Protected. Personal will never

share or use your data. Only you can grant access to your data or request access to data from others.

• You Control Who Gets Access. Personal will never share or use your data. Only you can grant access to your data or request access to data from others

• Take Your Data With You. You can easily export your data and permanently delete it from Personal.

Trust Framework

STA

RTU

P CIRCLE

PDEC

Owner Agreement Highlights

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 34: Personal Data Ecosystem - NSTIC Privacy Workshop

http://www.unisyssecurityindex.com/usi/us

Some say people “don’t care”......

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 35: Personal Data Ecosystem - NSTIC Privacy Workshop

Questions to be considered include: How personal data

stores and services make money and not turn against the interest of the end user?

Project 1: Exploring overall market models using Value Network

Mapping and Analysis.

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

C

OLLABORATIVE

PDEC IND

USTRY

Page 36: Personal Data Ecosystem - NSTIC Privacy Workshop

STA

RTU

P CIRCLE

PDEC

Screen Shots

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

Page 40: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge.

STA

RTU

P CIRCLE

PDEC

Screen Shot

Page 41: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge.

STA

RTU

P CIRCLE

PDEC

Screen ShotScreen Shot

Page 42: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge.

STA

RTU

P CIRCLE

PDEC

Screen Shot

Page 43: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge.

STA

RTU

P CIRCLE

PDEC

Screen ShotScreen Shot

Page 44: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge.

STA

RTU

P CIRCLE

PDEC

Screen Shot

Page 45: Personal Data Ecosystem - NSTIC Privacy Workshop

1) Innovate around user-centricity and trust. 

2) Define global principles for using and sharing personal data.

3) Strengthen the dialogue between regulators and the private sector. 

4) Focus on interoperability and open standards.

5) Continually share knowledge.

STA

RTU

P CIRCLE

PDEC

Screen Shot

Page 46: Personal Data Ecosystem - NSTIC Privacy Workshop

Kaliya HamlinExecutive Director

) identitycommons

[email protected]

identitywoman.net@identitywoman

(650) 260-4491

Internet Identity Workshop #13 October 18-20

PERSONAL DATA ECOSYSTEM CONSORTIUMNSTIC Privacy Workshop, June 28, 2011

PERSONAL DATA ECOSYSTEM CONSORTIUM