web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit /...

96
web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal July 10th, 2009 chaire en droit de la sécurité et des affaires électroniques /

Post on 19-Dec-2015

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

web 2.0 + privacyvincent gautrais

professeur agrégé /associate professor faculté de droit / faculty of law

université de Montréal /university of montreal

July 10th, 2009

chaire en droit de la sécurité et des affaires électroniques / udm chair in e-Security and e-Business law

www.gautrais.com

Page 2: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

2

plan

• intro

• what is personal info ?

• who is in charge to control it ?

• how to control it ?

Page 3: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

3

je me souviens …

remember …

Page 4: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

4

que né sous le lys …

that born under the lily …

Page 5: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

5

... je crois sous la rose.

… I grow under the rose.

(Eugène-Étienne Taché)

Page 6: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

61

Page 7: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

7

souvenons-nous que nés sous le papier …

remember that born under paper …

2

Page 8: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

8

... nous croissons sous l’électronique.

… we grow under electronic.

(Vincent Gautrais)

Page 9: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

9

law is under influence

Page 10: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

10

techno

business

culture

legal culture

Privacy is influenced

Page 11: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

11

1 - privacy influenced by legal culture

Page 12: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

12

2 - privacy influenced by culture

Page 13: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

13

immigrants v. natives(Mark Prensky, Digital natives, Digital immigrants, 2001)

Page 14: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

14

3 - privacy influenced by business

Page 15: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

15

4 - privacy influenced by techno

Page 17: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

17

Michel Serres

« when the support / information conbinaison is changing, everything is changing !»

Page 18: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

18

- 5000

- 4000

- 3000

- 2000

0

- 1000

2000

1000

writin

g

prin

ting

intern

et

Page 19: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

19

Michel Serres« today a pure science professor teaches 60 to 70% of content that he or she doesn’t learn him(her)self in the university».

Page 20: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

20

Hyperlink first generation

Web 2.0 second generation

Page 21: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

21

Page 22: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

22

what is the consequence on law?

did we need

some new laws ?

Are we OK

with old laws ?

Page 23: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

23

technological neutrality

on one side, some people said …

Page 24: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

24

technological neutrality definition ?

Page 25: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

25

law doesn’t favour one technology

Definition 1

Page 26: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

26

technologies are similarly manageable

Definition 2

Page 27: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

27

RAND report (May 2009)

review of the european data protection directive

(sponsored by UK information commissioner’s office)

http://www.rand.org/pubs/technical_reports/TR710/

Page 28: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

28

RAND report (page 24)

Page 29: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

29

person in charge of personal information is responsible of its protection

Page 30: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

30

are you sure that the directive is technological neutral ?

Page 31: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

31

privacy laws were create (during seventies and +) under a different

technology

Page 32: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

32

old electronic technology

company (or gov.) needs to control personal information

Page 33: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

33

old electronic technology

ex: medical file must be stored

in the doctor’s office

Page 34: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

34

differences of new electronic technologies

• protection = circulation

• place of detention

• initiative of circulation

• enhancement of circulation

• etc.

Page 35: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

35

are you sure that the technological neutral approach is the better one?

Page 36: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

36

Chris Reed ? (UK) no

Bert-Jaap Koops ? (Netherland) no

Lyria Bennett Moses ? (Australia) no

Vincent Gautrais ? (Canada) no

Page 37: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

37

1) poor definition

2) not sure that laws are techno neutral

3) not sure that it is the best approach

Page 38: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

38

we need to consider this (r)evolution of

facts

on the other side, some others said …

Page 39: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

39

we need to consider this (r)evolution of

law

on the other side, some others said …

Page 40: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

40

we need to propose a broadest approach considering

1 – purpose of privacy law

2 – more or less danger

3 – new balance between more circulation and more danger

on the other side, some others said …

Page 41: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

41

there are some proposed solutions to very basic questions

1 – what

2 - who

3 - how

Page 42: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

42

-1-

what ?

Page 43: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

43

personal information ?

Page 44: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

44

2 – “personal information” means information about an identifiable

individual, but does not include the name, title or business address or telephone

number of an employee of an organization

PIPEDA (federal act - S.C. 2000, c. 5)

Page 45: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

45

2 – Personal information is any information which relates to a natural person and allows that person to be identified.

provincial act - R.S.Q. c. P-39.1

Page 46: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

46

ex 1: IP address ?

Page 47: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

47

france

ex 2: note2be.com ?

(06/2008: appeal court - France)

=

Privacy infrigement

Page 48: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

48

canada

ex 2: note2be in Canada ?

intermediaries liability ?

is it a PI ?

constitutionalrights balance ? is it a

collection ?

legitimacyof the website ?

Page 49: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

49

germany

Spickmich in Germany (June 23, 2009)

=

no privacy infringement

Page 50: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

50

europe

direct or indirect personal information ?

Page 51: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

51

usa / uk

• taxonomy of harms from Daniel Solove (understanding privacy)

• RAND report

• google

Page 52: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

52

RAND report (May 2009)

review of the european data protection directive

(sponsored by UK information commissioner’s office)

http://www.rand.org/pubs/technical_reports/TR710/

Page 53: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

53

RAND report (page 41)

“Overall, we found that as we move toward an increasingly global, networked environment, the Directive as it stands will not suffice in the long term. The widely applauded principles of the Directive will remain as a useful front-end, yet will need to be supported with a harms-based back-end in due course, in order to be able to cope with the challenges of globalisation and flows of personal data.”

Page 54: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

54

-2-

who?

Page 55: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

55

aristotle versus plato

Page 56: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

56

substance versus process

Page 57: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

57

PIPEDA4.1 Principle 1 — AccountabilityAn organization is responsible for personal information under its control and shall designate an individual or individuals who are accountable for the organization’s compliance with the following principles.(…)4.1.4Organizations shall implement policies and practices to give effect to the principles, including

• (a) implementing procedures to protect personal information;• (b) establishing procedures to receive and respond to complaints

and inquiries;• (c) training staff and communicating to staff information about the

organization’s policies and practices; and• (d) developing information to explain the organization’s policies and

procedures.

Page 58: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

58

Daniel J. Weitzner, Harold Abelson, Tim Berners-Lee, Joan Feigenbaum, James Hendler, and Gerald Jay Sussman, Information Accountability, (2007)

Page 59: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

59

“information. Privacy is protected not by limiting collection of data, but rather by placing strict rules on how the data may be used”

Page 60: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

60

  “In many cases it is only by making better use of the information that is collected, and by retaining what is necessary to hold data users responsible for policy compliance that we can actually achieve greater information accountability”

Page 61: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

61

more and more regulations on risk assessment (federal + Quebec)

Page 62: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

62

federal (2002)

Privacy Impact Assessment Guidelines: A Framework to Manage Privacy Risks

Page 63: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

63

quebec (2009)

Décret sur la diffusion de l’information et sur la protection des renseignements

personnels

Page 64: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

64

ex: Chris Kelly = FB chief privacy officer

« We’ve always seen ourselves as a leader in reflecting in what users want online and learning what they’re looking for. We saw that in news feed, we saw that in [Facebook] Beacon and we’ve returned to our principle of user control. »

Page 65: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

65

ex: Chris Kelly = FB chief privacy officer

« We’re constantly looking at ways to make sure that people can get the information they want and they need about their friends in their real world social networks. Sure, we will be working on improving the privacy interface on simplifying it to give people the control that they need. »

Page 66: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

66

but be careful …

SOX (Sarbanes Oxley Act - 2002) mess

Page 67: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

67

sox

section 404: Management Assessment of Internal Controls

« Rules Required. The Commission shall prescribe rules requiring each annual report required by section 13(a) or 15(d) of the Securities Exchange Act of 1934 to contain an internal control report, which shall:

• state the responsibility of management for establishing and maintaining an adequate internal control structure and procedures for financial reporting; and

• contain an assessment, as of the end of the most recent fiscal year of the issuer, of the effectiveness of the internal control structure and procedures of the issuer for financial reporting ».

Page 68: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

68

individual

government

company

Page 69: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

69

-3-

how?

Page 70: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

70

new or old laws ?

as already mentioned …

Page 71: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

71

neutral or “un-neutral” laws?

Page 72: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

72

changing or interpretating laws?

Page 73: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

73

interpretation

communication ? retention ?

collection ?

use ?

Page 74: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

74

ex 1: clicsequr

Page 75: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

75

3 – identification

service

1 – citizen

4 – minister 2

2 – minister

Service to the public

Page 76: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

76

communication ?

Page 77: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

77

no because no control on information it self (content)

Page 78: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

78

ex 2: tourism website

Page 79: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

79

Page 80: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

80

Page 81: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

81

collection ?

Page 82: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

82

no because 1) no control on info, 2) no knowledge of PI and 3) ability to erase on demand problematic information

Page 83: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

83

consent ?

Page 84: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

84

example

Additionally, users should be aware that when they voluntarily disclose personally identifiable information (e.g., user name, e-mail address) on the forums or in the chat areas of the Spain-Info.com sites, that information, along with any substantive information disclosed in the user's communication, can be collected and correlated and used by third parties and may result in unsolicited messages from other posters or third parties. Such activities are beyond the control of Spain-Info.com

Page 85: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

85

 Aleecia M. McDonald and Lorrie Faith Cranor (Carnegie Mellon University)

« The Cost of Reading Privacy Policies » (pdf)

20 hours each month

Page 86: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

86

ex 3: google street view

Page 87: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

87

Page 88: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

88

retention ?

Page 89: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

89

no because no control on information it self (content)

Page 90: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

90

where come from this control criteria ?

Page 91: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

91

inherent to privacy protection

Page 92: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

92

ex: R. v. Patrick, 2009 SCC 17

Page 93: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

93

[62] Nevertheless, until the garbage is placed at or within reach of the lot line, the householder retains an element of control over its disposition and cannot be said to have unequivocally abandoned it, particularly if it is placed on a porch or in a garage or within the immediate vicinity of the dwelling where the principles set out in the “perimeter” cases such as Kokesch, Grant and Wiley apply.

[63] In municipalities (if there are any left) where garbage collectors come to the garage or porch and carry the garbage to the street, they are operating under (at least) an implied licence from the householder to come onto the property.  The licence does not extend to the police.  However, when the garbage is placed at the lot line for collection, I believe the householder has sufficiently abandoned his interest and control to eliminate any objectively reasonable privacy interest.

R. v. Patrick, 2009 SCC 17

Page 94: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

94

conclusion

in some cases, need for new legislations in concordance with electronic huge

changes but …

Page 95: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

95

conclusion

i love interpretation too !

Page 96: Web 2.0 + privacy vincent gautrais professeur agrégé /associate professor faculté de droit / faculty of law université de Montréal /university of montreal

web 2.0 + privacyvincent gautrais

professeur agrégé /associate professor faculté de droit / faculty of law

université de Montréal /university of montreal

July 10th, 2009

chaire en droit de la sécurité et des affaires électroniques / udm chair in e-Security and e-Business law

www.gautrais.com