<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sitrof Technologies &#187; Data Protection</title>
	<atom:link href="http://sitrof.com/tag/data-protection/feed/" rel="self" type="application/rss+xml" />
	<link>http://sitrof.com</link>
	<description></description>
	<lastBuildDate>Thu, 02 Feb 2012 13:19:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Geolocation services: a five country survey</title>
		<link>http://sitrof.com/industry-trends/geolocation-services-a-five-country-survey/</link>
		<comments>http://sitrof.com/industry-trends/geolocation-services-a-five-country-survey/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 12:51:43 +0000</pubDate>
		<dc:creator>Winston Maxwell</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2011/11/articles/international-eu-privacy/geolocation-services-a-five-country-survey/</guid>
		<description><![CDATA[Hogan Lovells privacy attorneys&#160;examine the challenges of deploying geolocation services in five jurisdictions, including France, Spain, Germany, the United States and Hong Kong. &#160;Privacy laws in each jurisdiction differ, including on&#160;th...]]></description>
			<content:encoded><![CDATA[<p>Hogan Lovells privacy attorneys&nbsp;examine the challenges of deploying geolocation services in five jurisdictions, including France, Spain, Germany, the United States and Hong Kong. &nbsp;Privacy laws in each jurisdiction differ, including on&nbsp;the&nbsp;definition of &quot;personal data,&quot; and on&nbsp;the degree of user consent that is required.&nbsp; The article also examines the WP Art. 29 opinion 13/2011 on &quot;Geolocation services on smart mobile devices.&quot; &nbsp;See the <a href="http://ehoganlovells.com/ve/ZZlB91V81CI59F85wc/VT=0/page=31">full article here</a>.&nbsp;</p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/O3VAhjQBS_Q" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/geolocation-services-a-five-country-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Geolocation services: a five country survey</title>
		<link>http://sitrof.com/industry-trends/geolocation-services-a-five-country-survey/</link>
		<comments>http://sitrof.com/industry-trends/geolocation-services-a-five-country-survey/#comments</comments>
		<pubDate>Mon, 28 Nov 2011 12:51:43 +0000</pubDate>
		<dc:creator>Winston Maxwell</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2011/11/articles/international-eu-privacy/geolocation-services-a-five-country-survey/</guid>
		<description><![CDATA[Hogan Lovells privacy attorneys&#160;examine the challenges of deploying geolocation services in five jurisdictions, including France, Spain, Germany, the United States and Hong Kong. &#160;Privacy laws in each jurisdiction differ, including on&#160;th...]]></description>
			<content:encoded><![CDATA[<p>Hogan Lovells privacy attorneys&nbsp;examine the challenges of deploying geolocation services in five jurisdictions, including France, Spain, Germany, the United States and Hong Kong. &nbsp;Privacy laws in each jurisdiction differ, including on&nbsp;the&nbsp;definition of &quot;personal data,&quot; and on&nbsp;the degree of user consent that is required.&nbsp; The article also examines the WP Art. 29 opinion 13/2011 on &quot;Geolocation services on smart mobile devices.&quot; &nbsp;See the <a href="http://ehoganlovells.com/ve/ZZlB91V81CI59F85wc/VT=0/page=31">full article here</a>.&nbsp;</p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/O3VAhjQBS_Q" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/geolocation-services-a-five-country-survey/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CNIL Cites French Yellow Pages Operator for Illegal Use of Social Media Data</title>
		<link>http://sitrof.com/industry-trends/cnil-cites-french-yellow-pages-operator-for-illegal-use-of-social-media-data/</link>
		<comments>http://sitrof.com/industry-trends/cnil-cites-french-yellow-pages-operator-for-illegal-use-of-social-media-data/#comments</comments>
		<pubDate>Mon, 26 Sep 2011 06:10:16 +0000</pubDate>
		<dc:creator>Winston Maxwell</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2011/09/articles/international-eu-privacy/cnil-cites-french-yellow-pages-operator-for-illegal-use-of-social-media-data/</guid>
		<description><![CDATA[
France's Data Protection Authority, the&#160;Commission Nationale de l&#8217;Informatique et des Libert&#233;s (CNIL) announced on September&#160;23, 2011 that it had found the French provider of universal telephone directory services, &#8220;Pages ...]]></description>
			<content:encoded><![CDATA[<p><img hspace="4" vspace="4" align="left" width="100" height="100" alt="" src="http://www.hldataprotection.com/uploads/image/logo-pagesjaunes.jpg" /></p>
<p>France's Data Protection Authority, the&nbsp;<i>Commission Nationale de l&rsquo;Informatique et des Libert&eacute;s</i> (CNIL) announced on September&nbsp;23, 2011 that it had found the French provider of universal telephone directory services, &ldquo;<i>Pages Jaunes,</i>&rdquo; guilty of violating several provisions of the French data protection law.&nbsp;The CNIL did not fine <i>Pages Jaunes</i>, but published a detailed warning, listing each privacy violation that the CNIL had identified during its investigation of <i>Pages Jaunes&rsquo;s</i> activities.&nbsp;</p>
<p>At issue was <i>Pages Jaunes&rsquo;s</i> web crawler function, which <i>Pages Jaunes</i> has discontinued.&nbsp;The crawler captured information contained in Facebook, Twitter and LinkedIn profiles of persons having the same name as the person being looked up in the directory service.&nbsp;For example, if someone were to look up the telephone number of Pierre Dupont.&nbsp;<i>Pages Jaunes</i> would show Mr. Dupont&rsquo;s phone number, and would also show information on social media sites relating to persons named Pierre Dupont.&nbsp;The information may include photos, the name of Dupont&rsquo;s employer, the schools he attended, his geographic location, his profession, etc.</p>
<p><i>Pages Jaunes</i> argued that the persons whose profiles were copied had been duly informed and consented, because the general terms and conditions of the social media sites indicate that information posted on public profiles may be accessible to search engines.&nbsp;</p>
<p>The CNIL dismissed this argument.&nbsp;First, a number of the profiles that were being accessed were profiles of minors, and the informed consent of minors for this type of activity cannot be deemed to exist in these circumstances.&nbsp;Second, the reference to &ldquo;search engines&rdquo; in the social media sites&rsquo; general terms and conditions cannot be deemed to extend to companies whose principal activities are <u>not</u> that of a search engine.&nbsp;The CNIL pointed out that <i>Pages Jaunes</i> is a telephone directory and not a search engine.&nbsp;According to the CNIL, if the terms of use of the social media sites expressly mentioned that data in public profiles could be re-used by <i>Pages Jaunes</i>, that might constitute sufficient information and consent to allow <i>Pages Jaunes</i> to extract data from those sites.&nbsp;The CNIL pointed out that <i>Pages Jaunes</i> had entered into an agreement with one social media site called Trombi pursuant to which Trombi expressly mentioned on its site that data could be accessed and used by <i>Pages Jaunes</i>.&nbsp;For the major social media sites, however, no such agreement with <i>Pages Jaunes</i> existed.&nbsp;</p>
<p>The CNIL also found that <i>Pages Jaunes</i> had breached its obligation to ensure that only accurate and updated data are processed.&nbsp;According to the CNIL, the profile data that was presented by <i>Pages Jaunes</i> was in many cases outdated by 4 to 12&nbsp;months.</p>
<p><i>Pages Jaunes</i> argued that it provided data subjects with the ability, on the <i>Pages Jaunes</i> website, to ask that their profile data not be accessed by <i>Pages Jaunes</i>, but the CNIL found that the procedures put in place by <i>Pages Jaunes</i> were too burdensome.&nbsp;A person must fill out a form and submit to <i>Pages Jaunes</i> proof of his or her identity for each social media site that the person wants to block. The CNIL also criticized <i>Pages Jaunes</i> for keeping logs of IP addresses and the time and date of queries made on the <i>Pages Jaunes</i> site.&nbsp;According to the CNIL, the retention of these data is excessive and not required under French law because <i>Pages Jaunes</i> is neither a telecommunications operator nor a hosting provider.&nbsp;Finally, the CNIL found that <i>Pages Jaunes</i> had violated its obligations with respect to the telephone directory data that it processes, because <i>Pages Jaunes</i> used that data to help refine the results of the social media profile searches.&nbsp;Under French law, universal directory providers are prohibited from using telephone directory data for any purpose other than providing a universal directory service.&nbsp;<i>Pages Jaunes&rsquo;s</i> use of these data exceeded the scope permitted under French law.</p>
<p>The CNIL&rsquo;s decision is a useful analysis of issues that are arising when collecting data publicly available on social media sites.</p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/-VH82FqAxWA" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/cnil-cites-french-yellow-pages-operator-for-illegal-use-of-social-media-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>France Implements EU Requirements for Data Breach Notification, Audits and Cookies Applicable to Electronic Communications Service Providers</title>
		<link>http://sitrof.com/industry-trends/france-implements-eu-requirements-for-data-breach-notification-audits-and-cookies-applicable-to-electronic-communications-service-providers/</link>
		<comments>http://sitrof.com/industry-trends/france-implements-eu-requirements-for-data-breach-notification-audits-and-cookies-applicable-to-electronic-communications-service-providers/#comments</comments>
		<pubDate>Mon, 29 Aug 2011 14:28:18 +0000</pubDate>
		<dc:creator>Winston Maxwell</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2011/08/articles/international-eu-privacy/france-implements-eu-requirements-for-data-breach-notification-audits-and-cookies-applicable-to-electronic-communications-service-providers/</guid>
		<description><![CDATA[This entry was drafted by Winston Maxwell and Lionel de Souza.
On August 26th, &#160;France published a Presidential Order (Ordonnance) that implements the November 25, 2009 package of EU telecoms directives.&#160;The Ordonnance contains measures on da...]]></description>
			<content:encoded><![CDATA[<p><em>This entry was drafted by Winston Maxwell and Lionel de Souza.</em></p>
<p>On August 26th, &nbsp;France published a Presidential Order (<i>Ordonnance</i>) that implements the November 25, 2009 package of EU telecoms directives.&nbsp;The Ordonnance contains measures on data breach notifications, data security audits and cookies.&nbsp;These measures are&nbsp; limited to providers of electronic communications services and therefore are&nbsp;not, for the time being, applicable to all data controllers.</p>
<p><u>Data Security Breaches</u>.<span>&nbsp;&nbsp;&nbsp; All providers of public electronic communications services are required immediately to inform the French data protection authority, the <i>Commission Nationale de l'Informatique et des Libert&eacute;s</i> (CNIL) of any data security breach. &nbsp;A data security breach is defined as &quot;any security breach that results accidentally or in an illicit manner in the destruction, loss, alteration, disclosure or unauthorized access to personal data which is processed in the context of the supply to the public of electronic communications services.&quot;&nbsp;The <i>Ordonnance</i> does not contain any materiality threshold.&nbsp;Consequently <em>each and every breach</em>, no matter how small, must be&nbsp;reported to the CNIL.&nbsp;Every provider of public electronic communications services must also keep a journal of data breaches, indicating the details of the breach, its effect and the remedial measures taken.&nbsp;The journal must be shown to the CNIL on request.&nbsp;</span></p>
<p><u>Notification to data subjects</u>: if the data breach &quot;can adversely affect the personal data or privacy of a subscriber or other individual, the operator must also immediately inform the interested party.&quot;&nbsp;However, this notification requirement can be waived if the CNIL finds that &quot;appropriate protection measures were taken by the provider to ensure that the data are incomprehensible to any unauthorized person and such measures were applied to the data concerned by the breach.&quot;&nbsp;The <i>Ordonnance</i> contains no materiality threshold here either.&nbsp;Yet the <i>Ordonnance</i> states that the CNIL can, &quot;after examining the seriousness of the breach, order the provider also to inform the interested party.&quot;&nbsp;This provision suggests that there may in fact be a &quot;seriousness&quot; threshold after all in connection with notifications to data subjects, but that the decision would be the CNIL's and will certainly depend on the reactivity and containment measures demonstrated by the service provider.</p>
<p><u>Sanctions</u>: The criminal sanction for failing to notify data breaches is up to 5 years in prison and three hundred thousand euro (300,000 &euro;) fine. The sanction is in line with other criminal sanctions for failure to comply with French data protection legislation.&nbsp;With regards to the fine, it should be noted that the maximum sanction for companies is multiplied by five (5), thus bringing the maximum sanction to up to one and a half million euro (1,500,000 &euro;). &nbsp;</p>
<p><u>Security Audits</u>.&nbsp;The <i>Ordonnance</i> empowers the French government to order security audits of any operator's networks, systems and services.&nbsp;The operator must bear the cost of the audit, and must give the government approved auditors access to all relevant equipment and to the operator's &quot;documents relating to its security policy.&quot;&nbsp;A future decree will be adopted to provide details on these requirements.&nbsp;However, one takeaway from this new provision is that operators should probably conduct preventive data and network security audits and make sure their security policies are up to date and applied.</p>
<p><u>Cookies</u>.&nbsp;Implementing the revised ePrivacy Directive, the <i>Ordonnance</i> provides that users of electronic communications services must not only receive clear information about the use of cookies and tools available to block them (this was already a requirement under French law), but also that users give their consent <i>before</i> the cookies or similar measures are implemented.&nbsp;The <i>Ordonnance</i> states that &quot;the consent can result from appropriate parameters in [the user's or subscriber's] connection system or any other system under [the user's or subscriber's] control.&quot;&nbsp;This suggests that browser settings might constitute sufficient prior consent, although the recent Article 29 Working Party opinion on consent (Opinion 15/2011) appears to take a different view.</p>
<p>As before, an exception exists for cookies that are designed to facilitate the communication, or that are strictly necessary for the provision of the Internet application or service requested by the user.</p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/UuD32A9pgjE" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/france-implements-eu-requirements-for-data-breach-notification-audits-and-cookies-applicable-to-electronic-communications-service-providers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Financial Services Industry Group Issues Social Media Guidance</title>
		<link>http://sitrof.com/industry-trends/financial-services-industry-group-issues-social-media-guidance/</link>
		<comments>http://sitrof.com/industry-trends/financial-services-industry-group-issues-social-media-guidance/#comments</comments>
		<pubDate>Fri, 15 Jul 2011 07:02:22 +0000</pubDate>
		<dc:creator>Elizabeth Khalil</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2011/07/articles/financial-privacy/financial-services-industry-group-issues-social-media-guidance/</guid>
		<description><![CDATA[A financial services industry group released guidance this week on managing the risks associated with using social media, including data protection concerns.&#160; The guidance, titled &#34;Social Media Risks and Mitigation,&#34;&#160;was released th...]]></description>
			<content:encoded><![CDATA[<p>A financial services industry group released guidance this week on managing the risks associated with using social media, including data protection concerns.&nbsp; The guidance, titled <a href="http://pub.bna.com/eclr/bitsmedia.pdf">&quot;Social Media Risks and Mitigation,&quot;</a>&nbsp;was released this week by <a href="http://www.bits.org/">BITS</a>, a division of the <a href="http://www.fsround.org/">Financial Services Roundtable</a>, which represents 100 of the largest financial services companies.&nbsp; The 71-page report details numerous risks that banks and other financial companies may face when using social media, including compliance, legal, operational and reputational risks.&nbsp; These risks are discussed in the context of three types of social media use:</p>
<ul>
<li>By a financial institution to communicate with or service the financial institution's customers</li>
<li>By the financial institution's employees in their personal or professional capacities</li>
<li>By the financial institution's employees or contractors outside the office</li>
</ul>
<p>The guidance thus addresses sector-specific&nbsp;regulatory requirements, such as <a href="http://www.ftc.gov/privacy/glbact/glbsub1.htm">Gramm-Leach-Bliley Act </a>compliance and <a href="http://www.finra.org/">FINRA&nbsp;</a>rules applicable to securities firms.&nbsp;&nbsp;It also addresses&nbsp;concerns that are relevant to financial institutions as employers, such as bank employees' personal&nbsp;use of social media.</p>
<p>The BITS&nbsp;report is particularly significant because it responds to a need for guidance in an industry that is increasingly using social media, but still lacks clear rules from regulators regarding such activities.&nbsp; While FINRA&nbsp;has issued&nbsp;<a href="http://www.finra.org/web/groups/industry/@ip/@reg/@notice/documents/notices/p120779.pdf">guidance </a>on use of social&nbsp;media by firms subject to FINRA's oversight,&nbsp;the federal banking agencies have not , to date, issued detailed guidance to the banking industry on banking compliance issues raised by use of social media.&nbsp;&nbsp;</p>
<p>Also, while targeted at the financial services sector, the report also has relevance to many other types of users of social media.&nbsp; It gives guidance, for instance, on coordinating a company's social media policies with its other policies, and performing a risk assessment to determine the risks a company's social media activities could pose.</p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/sC636-hMbLk" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/financial-services-industry-group-issues-social-media-guidance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Europe&#8217;s Article 29 Working Party issues smart meter guidelines</title>
		<link>http://sitrof.com/industry-trends/europes-article-29-working-party-issues-smart-meter-guidelines/</link>
		<comments>http://sitrof.com/industry-trends/europes-article-29-working-party-issues-smart-meter-guidelines/#comments</comments>
		<pubDate>Mon, 18 Apr 2011 12:43:39 +0000</pubDate>
		<dc:creator>Winston Maxwell</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2011/04/articles/international-eu-privacy/europes-article-29-working-party-issues-smart-meter-guidelines/</guid>
		<description><![CDATA[By Winston Maxwell (Paris) and Marco Berliri (Rome)
The European Union's Article 29 Working Party published on April 11, 2011 an opinion on smart metering, recommending Privacy by Design, data minimization, and consumer interface options that give cust...]]></description>
			<content:encoded><![CDATA[<p>By Winston Maxwell (Paris) and Marco Berliri (Rome)</p>
<p align="left">The European Union's Article 29 Working Party published on April 11, 2011 an <a href="http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2011/wp183_en.pdf">opinion on smart metering</a>, recommending Privacy by Design, data minimization, and consumer interface options that give customers increased control over their data and privacy settings.</p>
<p align="left">The opinion indicates that most data collected by smart meters will be considered &quot;personal data&quot; under the Data Protection Directive because the data will be associated with a unique identifier such as a meter identification number, which in turn can be linked to a living individual.&nbsp;The opinion states that the &quot;data controller&quot; will in most cases be the energy supplier, but that the grid operator may also be controller, as may be the third party service provider (so-called Energy Service Companies, or ESCOs).&nbsp;As mentioned in the <a href="http://ec.europa.eu/justice/policies/privacy/docs/wpdocs/2010/wp169_en.pdf">Art 29 WP's opinion 1/2010 on data controllers and processors</a>, it is not infrequent for there to be more than one controller.</p>
<p align="left">Data collected by smart meters may be processed based on consent, but the opinion warns that consent must be made on a &quot;fully-informed&quot; basis.&nbsp;The Art 29 WP recommends that the household control panel for smart meters include a push button consent option to help consumers exercise their consent options, and change the options over time.&nbsp;</p>
<p align="left">The opinion goes into considerable detail on some issues, commenting for example that a smart meter with a small, text only, user interface would provide consumers with insufficient access to their own data, in particular to&nbsp;load graphs.&nbsp; The opinion also describes how the collection of data from the smart meter should be minimized, for example by keeping load graph data within the smart meter until the data actually needed by the energy supplier.&nbsp; Many of the recommendations resemble existing practices in the telecoms industry for the handling of traffic data and location data.&nbsp; For example, smart meter data should be deleted as soon as they are no longer needed.&nbsp;Controllers should develop written policies on data retention and evaluate each purpose for which smart data are needed and ensure that only the minimum data necessary for that purpose are retained, while other data are deleted.&nbsp;For example, some customers may request historic year-to-year consumption comparisons. For those customers, and those customers only, the controller may retain historic consumption data.</p>
<p align="left">The opinion strongly recommends the implementation of Privacy by Design, including privacy impact assessments, security and privacy audits.</p>
<p align="left">See the authors' <a href="http://www.hldataprotection.com/2010/09/articles/international-eu-privacy/privacy-by-design-for-italian-smart-grid/">previous blog entry on smart meters and privacy on design</a>.</p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/fmlc07kVt0I" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/europes-article-29-working-party-issues-smart-meter-guidelines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Collection and use of personal data for direct marketing &#8212; Lessons from the Octopus Case in Hong Kong</title>
		<link>http://sitrof.com/industry-trends/collection-and-use-of-personal-data-for-direct-marketing-lessons-from-the-octopus-case-in-hong-kong-2/</link>
		<comments>http://sitrof.com/industry-trends/collection-and-use-of-personal-data-for-direct-marketing-lessons-from-the-octopus-case-in-hong-kong-2/#comments</comments>
		<pubDate>Wed, 15 Dec 2010 07:50:18 +0000</pubDate>
		<dc:creator>Gabriela Kennedy</dc:creator>
				<category><![CDATA[Industry Trends]]></category>
		<category><![CDATA[Data Protection]]></category>

		<guid isPermaLink="false">http://www.hldataprotection.com/2010/12/articles/data-security-breaches/collection-and-use-of-personal-data-for-direct-marketing-lessons-from-the-octopus-case-in-hong-kong/</guid>
		<description><![CDATA[Hong Kong&#160;&#160; Data protection is currently a hot topic in Hong Kong. This is largely due to the furor caused by the discovery of the large scale sale of personal data by Hong Kong's Octopus Rewards Limited (a company owned by Octopus Holdings L...]]></description>
			<content:encoded><![CDATA[<p><strong>Hong Kong&nbsp;&nbsp; </strong>Data protection is currently a hot topic in Hong Kong. This is largely due to the furor caused by the discovery of the large scale sale of personal data by Hong Kong's Octopus Rewards Limited (a company owned by Octopus Holdings Limited) over a number of years. We reported previously that the Hong Kong Privacy Commissioner launched an investigation into Octopus Rewards Limited and Octopus Holdings Limited. In October the Hong Kong Privacy Commissioner issued his final report on the sale of personal data by Octopus for the purposes of direct marketing. A Guidance Note providing practical guidance on compliance with the requirements under the Personal Data (Privacy) Ordinance (the &quot;<b>Ordinance</b>&quot;) relating to use of personal data for direct marketing was published on the same day.</p>
<p>On 18 October 2010 the Constitutional and Mainland Affairs Bureau (the <b>&quot;CMAB&quot;</b>) published a consultation paper which summarises the responses to the consultation of the review of the Ordinance undertaken last year and puts forward the current proposals for reform. The CMAB has proposed 37 amendments to the Ordinance and the public are invited to comment on the proposals until 31 December 2010.</p>
<p><b>The Octopus case</b></p>
<p>As outlined previously in this blog, Octopus Holdings Ltd. and its related companies including Octopus Rewards Limited (collectively referred to as &quot;<b>Octopus</b>&quot;) operate the Octopus card, which is an electronic stored-value payment card used by Hong Kong residents for public transport, fast-food restaurants, parking, convenience stores and supermarkets.</p>
<p>The Privacy Commissioner's investigation was focussed on the use and collection of personal data in relation to a rewards program that is linked to the Octopus card, whereby card holders may earn reward cash every time they make purchases with their Octopus cards at selected business partners (<b>&quot;Rewards Program&quot;</b>). Card holders must register with Octopus in order to take advantage of the Rewards Program and were requested to supply a broad range of personal information on the registration form (some of which was required for the application to proceed).</p>
<p>Octopus provided the personal information of almost 2 million card holders to six business partners for direct-marketing over nearly eight years, earning the company HK$44 million in revenue.</p>
<p><b>Findings of the Privacy Commissioner</b></p>
<p>On 18 October 2010, the Privacy Commissioner issued his final determination on the matter. In his report, the Privacy Commissioner found that as the personal data was collected in connection with a rewards program whereby customers benefit from redemption of goods and services in addition to direct marketing offers, the purposes of collection of personal data under the Rewards Program was lawful. However, the Privacy Commissioner found that Octopus had breached two of the six Data Protection Principles set out in the Ordinance.</p>
<p>Data Protection Principle 1 (&quot;<b>DPP1</b>&quot;) relates to the purpose and manner of collection of personal data and clearly states that data should only be collected if it is necessary and not excessive for a lawful purpose directly related to the activity of the data user. DPP1 also requires that where personal data is collected from the data subject, he or she should be informed of: (i) the purpose of collection; (ii) the classes of persons to whom the data may be transferred; (iii) the right to, and practicalities of, access to the data; (iv) whether it is obligatory to supply the data; and (v) if so, the consequences of not doing so.</p>
<p>The Privacy Commissioner found that while the data was collected by Octopus for a lawful purpose, the collection of data such as Hong Kong identity card number, passport number, birth certificate number as well as month and year or birth was excessive for the purpose of customer identification. It was found that Octopus could have conducted customer authentication using less intrusive data (e.g. name, telephone numbers and home address) and accordingly Octopus was held to have contravened DPP1.</p>
<p>Further, the Privacy Commissioner found that Octopus did not take all reasonable steps to inform its customers of the classes of persons to whom the personal data may be transferred (thereby contravening DPP1). This was partly attributable to the fact that classes of transferees were referred to in vague terms such as <i>&quot;any person who is under a duty of confidentiality to us&quot;</i>, and partly because the Personal Information Collection Statement (&quot;<b>PICS</b>&quot;) was printed in unreasonably small font.</p>
<p>The Privacy Commissioner also held that Octopus contravened Data Protection Principle 3 (&quot;<b>DPP3</b>&quot;). DPP3 relates to the use of personal data and requires that personal data should only be used for a purpose directly related to the purpose for which it was collected, unless the data subject expressly consents to another use. DPP3 was breached because customers' personal data was shared with business partners for monetary gain without the consent of Octopus's customers, as the sale of personal data was not stated as a purpose of data collection in the PICS published by Octopus in relation to the Rewards Program. The sale of personal data is not prohibited by the Ordinance as such and can be a legitimate purpose for which data is collected but this has to be made clear at the time the data is collected. In the present case the Privacy Commissioner held that the &quot;sale of data&quot; may not be considered to be the purpose of the data collection (or a directly related purpose). Therefore Octopus was found to be in breach of DPP3.</p>
<p>A further interesting finding as a result of the investigation was that Octopus Holding was held liable for the acts of its subsidiary Octopus Rewards which is the Octopus entity that operated the Rewards Program.</p>
<p>Under the Ordinance as it currently stands, a breach of a data protection principle is not an offence and the only action the Privacy Commissioner may take is to serve an enforcement notice on a party that is found to be contravening the Ordinance. Only in the event that a party contravenes an enforcement notice will they be penalised.&nbsp;The Privacy Commissioner however found that it could not issue an enforcement notice as Octopus had ceased or suspended all arrangements with business partners to sell customers' personal data and had undertaken to implement various changes to its practices in relation to the collection and use of personal data, in order to comply with the requirements of the Ordinance.</p>
<p><b>Proposals for reform</b></p>
<p>As we reported previously in this blog, the CMAB published the Consultation Document on the Review of the Personal Data (Privacy) Ordinance (the &quot;<b>Consultation Document</b>&quot;) on 28 August 2009, and received public comments on the proposed amendments until 30 November 2009.&nbsp;</p>
<p>The CMAB published the Report on Public Consultation on Review of the Personal Data (Privacy) Ordinance (the &quot;<b>Report on Public Consultation</b>&quot;) on 18 October 2010 and the public are invited to provide comments on the proposed amendments until 31 December 2010. The Report revealed that the Government has adopted 37 of the 55 amendments proposed in the initial Consultation Document, including amendments relating to direct marketing, data security, statutory powers and functions of the Privacy Commissioner, offences and sanctions and rights of data subjects.</p>
<p>As a result of the Octopus case, a number of further amendments have been proposed specifically dealing with the transfer of personal data for direct marketing purposes, requiring a data user to communicate a clear Personal information Collection Statement outlining its intent to use the personal information for direct marketing and clearly identifying the class of transferees and the kinds of data to be transferred, as well as requiring the data user to provide an opt-out function for people who do not wish their personal information to be used for direct marketing. A further amendment is proposed which would make it an offence if a data user failed to comply with the requirements of the Ordinance in relation to direct marketing and subsequently used the personal information for direct marketing.</p>
<p><b>Guidance Note</b></p>
<p>On the same day the final report came out, the Privacy Commissioner issued a guidance note entitled &quot;Guidance on the Collection and Use of Personal Data in Direct Marketing (&quot;<b>Guidance Note</b>&quot;). The Guidance Note is designed to provide practical guidance on direct marketing.</p>
<p>The Guidance note replaces the Fact Sheet on &quot;Guidelines on Cold-Calling&quot; and the Guidance Note on &quot;Cross-Marketing Activities&quot; previously published by the Privacy Commissioner. The Guidance Note covers a number of issues which have been included in the latest round of proposed amendments to the Ordinance but also provides guidance on compliance with the Ordinance as it currently stands. It is expected that the Privacy Commissioner will either revise the Guidance Note or replace it with a new Code of Practice, if and when the proposed amendments are adopted.</p>
<p>The Guidance Note sets out, among other things, the following requirements:</p>
<ul>
<li>Collection of personal data for direct marketing should be related to the original purpose of data collection</li>
<li>Personal data should not be excessively collected (name and contact details should generally be sufficient for the purposes of direct marketing)</li>
<li>Collection of additional personal data for direct marketing should be voluntary (and the data subject should be informed of the voluntary nature of collection)</li>
<li>Personal data should not be collected using deceptive/misleading means (e.g. bundled consent)</li>
<li>The PICS should be effectively communicated to the data subject (taking into account layout, presentation, language etc.)</li>
<li>The purpose of use of personal data and the classes of transferees should be clearly defined using specific terms. Terms such as <i>&quot;such other purposes as the Company may from time to time prescribe&quot; </i>should not be relied upon to cover direct marketing as a purpose of collection. Similarly, terms such as <i>&quot;such other agents as the Company may from time to time appoint&quot; </i>or <i>&quot;all business partners&quot;</i> should not be used when defining the classes of transferees.</li>
</ul>
<p>The Guidance Note also contains recommendations relating to the use of personal data from public registers; managing and maintaining opt-out requests; direct marketing activities conducted by agents, contractors and business partners; and the sale of personal data to third parties for direct marketing purposes.</p>
<p>The Octopus case has exposed dubious and lax practices in relation to data protection adopted by many companies in Hong Kong.&nbsp;In response to a request from the Privacy Commissioner, the financial regulator, the Hong Kong Monetary Authority, has issued three circulars between 12&nbsp;August 2010 and 25 October 2010.&nbsp;The circulars restate recommendations made by the Privacy Commissioner in relation to the collection and use of personal data, in the wake of the Octopus case.&nbsp;HKMA has requested that all approved financial institutions in Hong Kong undertake reviews of their privacy policies and that they suspend all transfer of data to unconnected third parties for marketing purposes, until legal advice on this is sought and discussed with and approved by the authorities.</p>
<p>So where to now?&nbsp;The Ordinance is set for a review, and for now all data users in Hong Kong are advised to revamp their personal data polices and take heed of the advice provided in the Guidance Note if they use such data for direct marketing.</p>
<p><i>Gabriela Kennedy (Partner) (<a href="mailto:gabriela.kennedy@hoganlovells.com">gabriela.kennedy@hoganlovells.com</a>) and Heidi Gleeson (Registered Foreign Lawyer), Hogan Lovells, Hong Kong.</i></p>
<p><img src="http://feeds.feedburner.com/~r/ChronicleOfDataProtection/~4/KLl9OWL-gZg" height="1" width="1"/></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/industry-trends/collection-and-use-of-personal-data-for-direct-marketing-lessons-from-the-octopus-case-in-hong-kong-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WikiLeaks &#8211; Data Encryption to prevent the Sneaker-net threat</title>
		<link>http://sitrof.com/resources/insights/wikileaks-data-encryption-to-prevent-the-sneaker-net-threat/</link>
		<comments>http://sitrof.com/resources/insights/wikileaks-data-encryption-to-prevent-the-sneaker-net-threat/#comments</comments>
		<pubDate>Fri, 10 Dec 2010 21:48:21 +0000</pubDate>
		<dc:creator>Sitrof</dc:creator>
				<category><![CDATA[Insights]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Enterprise Rights Management]]></category>
		<category><![CDATA[Enterprise Risk Management]]></category>

		<guid isPermaLink="false">http://sitrof.com/?p=2359</guid>
		<description><![CDATA[It's all over the news - WikiLeaks.  It may be hard to believe, but we have been deploying technology that would have prevented the misuse of these top-secret government cables for years. It is vital for all organizations (government and industry) to recognize that the most leak-proof firewall in the world would not have prevented [...]]]></description>
			<content:encoded><![CDATA[<h3>It's all over the news - WikiLeaks.  It may be hard to believe, but we have been deploying technology that would have prevented the misuse of these top-secret government cables for years.</h3>
<p>It is vital for all organizations (government and industry) to recognize that the most leak-proof firewall in the world would not have prevented the recent top-secret government cables from walking out the door on a CD.  The biggest security threats to your organization are internal.  Proper data protection--meaning encryption at the file level-- is the only way to prevent the "sneaker-net" threat.</p>
<p>Recently a top research scientist with a US pharmaceutical company walked out the door with all of his company confidential research on a flash drive and moved to China to produce the drug. I am sure he made himself a pretty penny.  Again, the tightest firewall could not have prevented this corporate espionage.</p>
<blockquote><p>The US Chamber of Commerce estimates the cost to organizations of the negative consequences of security breaches or intellectual property loss,at $250 billion per year.</p>
</blockquote>
<p><a href="http://sitrof.com/solutions/data-protection/enterprise-rights-management/" target="_self">Enterprise Rights Management (ERM)</a> enables organizations to manage, monitor, and enforce policies governing the access and use of data at rest, in motion, and in use. Security policies for access and use are embedded directly into the information itself, providing companies with the security they need and where they need it. According to CIO/Insight, no legacy solutions have been able to address the ‘unstructured data’ security dilemma like enterprise rights management.  <a href="http://sitrof.com/resources/security-getting-data-protection-right/" target="_self">Click here to read more on Getting Data Protection Right.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/resources/insights/wikileaks-data-encryption-to-prevent-the-sneaker-net-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CMS Wire Agrees &#8211; We&#8217;re Onto Something</title>
		<link>http://sitrof.com/resources/insights/cms-wire-agrees-were-onto-something/</link>
		<comments>http://sitrof.com/resources/insights/cms-wire-agrees-were-onto-something/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 14:57:50 +0000</pubDate>
		<dc:creator>Sitrof</dc:creator>
				<category><![CDATA[Insights]]></category>
		<category><![CDATA[Published Articles]]></category>
		<category><![CDATA[21 CFR Part 11]]></category>
		<category><![CDATA[cloud computing]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[DocExchange]]></category>
		<category><![CDATA[linkedin]]></category>
		<category><![CDATA[Microsoft SharePoint]]></category>
		<category><![CDATA[Peer to Peer Collaboration]]></category>
		<category><![CDATA[secure document exchange]]></category>

		<guid isPermaLink="false">http://sitrof.com/?p=1375</guid>
		<description><![CDATA[CMS Wire writes, "Sitrof Technologies and Content Circles recently combined forces and kicked out a tool that packs both peer-to-peer sharing and compliance solutions." "Aptly named DocExchange, the solution enables users to securely share large amounts of information across firewalls."  We are thrilled that they get it!!  They continue with... Complete Privacy and Security "Sitrof [...]]]></description>
			<content:encoded><![CDATA[<h3><a href="http://www.cmswire.com/cms/document-management/sitrof-and-content-circles-offer-peertopeer-doc-exchange--007824.php" target="_blank">CMS Wire</a> writes, "Sitrof Technologies  and Content Circles recently combined forces and kicked out a tool that packs both peer-to-peer sharing and compliance solutions."</h3>
<p>"Aptly named <a href="http://sitrof.com/products/docexchange/" target="_self">DocExchange</a>, the solution enables users to securely share large amounts of information across firewalls."  We are thrilled that they get it!!  They continue with...</p>
<h4>Complete Privacy and Security</h4>
<blockquote><p>"Sitrof has taken this technology and laced in its own regulated data  protection and interface with Microsoft SharePoint for the DocExchange  tool."<br />
-- Chelsi Nakano, CMS Wire</p>
</blockquote>
<p><a href="http://www.contentcircles.com/" target="_blank">Content Circles</a> has really blossomed since we first noted their server-free collaboration tool in January of last year. Designed to help distributed teams work collaboratively and securely, their platform connects people regardless of their location, allowing them to pass encrypted blocks of content back and forth from desktop to desktop. Though there is a central, Internet-accessible Content Circles server maintained by the company, it's only used to provide directory, policy, auditing and related services.</p>
<h4>+ Sitrof</h4>
<p>Sitrof has taken this technology and laced in its own regulated data protection and interface with Microsoft SharePoint for the DocExchange tool. This allows collaboration across firewalls and the tracking of content, which again, is never stored anywhere other than member computers. This also means that space isn't a problem, as there are no file-size limits.</p>
<h4><a href="http://www.cmswire.com/cms/document-management/sitrof-and-content-circles-offer-peertopeer-doc-exchange--007824.php" target="_blank">Read the entire article  on CMS Wire By Chelsi Nakano   | Published Jun 16, 2010</a></h4>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"><span class="by-line">By <span class="author"><a href="http://www.cmswire.com/author/chelsi-nakano/">Chelsi Nakano</a></span> | Published Jun 16, 2010 </span>By Chelsi Nakano   | Published Jun 16, 2010By Chelsi Nakano   | Published Jun 16, 2010</div>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/resources/insights/cms-wire-agrees-were-onto-something/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sitrof Managing Partner Dan Wheeler Pens Article in Applied Clinical Trials</title>
		<link>http://sitrof.com/resources/news/sitrof-president-dan-wheeler-pens-article-in-applied-clinical-trials/</link>
		<comments>http://sitrof.com/resources/news/sitrof-president-dan-wheeler-pens-article-in-applied-clinical-trials/#comments</comments>
		<pubDate>Tue, 06 Apr 2010 20:59:49 +0000</pubDate>
		<dc:creator>Sitrof</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Published Articles]]></category>
		<category><![CDATA[21 CFR Part 11]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Data Protection]]></category>
		<category><![CDATA[Peer to Peer Collaboration]]></category>

		<guid isPermaLink="false">http://sitrof.com/?p=725</guid>
		<description><![CDATA[Rethinking Document Sharing, Applied Clinical Trials, March 2010 The benefits of peer-to-peer networking over email, fax, FTP, and hosted solutions The need for sponsors to collaborate with external partners, whether it's legal counsel, CROs, or manufacturers has become a daily occurrence. Documents such as contracts, informed consent, and protocols require authoring, review, and approval from [...]]]></description>
			<content:encoded><![CDATA[<h3>Rethinking Document Sharing, Applied Clinical Trials, March 2010</h3>
<h4>The benefits of peer-to-peer networking over email, fax, FTP, and hosted solutions</h4>
<p><a href="http://appliedclinicaltrialsonline.findpharma.com/appliedclinicaltrials/CRO%2FSponsor/Rethinking-Document-Sharing/ArticleStandard/Article/detail/660941?ref=25"><img class="alignleft size-full wp-image-3150" title="act0810_cover_19348" src="http://sitrof.com/wp-content/uploads/2010/04/act0810_cover_19348.jpg" alt="" width="108" height="145" /></a>The need for sponsors to collaborate with external partners, whether it's legal counsel, CROs, or manufacturers has become a daily occurrence. Documents such as contracts, informed consent, and protocols require authoring, review, and approval from individuals inside and outside the company. This trend will continue, as industry increases outsourcing efforts at the same time the amount of unstructured content generated skyrockets. There are many different use cases in the clinical trial process that require this type of data exchange. For example, Investigator's Brochures are exchanged between sponsors, investigators, and Institutional Review Boards (IRBs). These are not static documents, thus requiring collaboration as updates are needed. Creating, reviewing, and approving informed consent language requires a collaborative process that involves input from investigators and IRBs.  <a href="http://appliedclinicaltrialsonline.findpharma.com/appliedclinicaltrials/CRO%2FSponsor/Rethinking-Document-Sharing/ArticleStandard/Article/detail/660941?ref=25" target="_blank"><strong>Click here to view entire article in Applied Clinical Trials, March 2010</strong></a></p>
]]></content:encoded>
			<wfw:commentRss>http://sitrof.com/resources/news/sitrof-president-dan-wheeler-pens-article-in-applied-clinical-trials/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

