/2018
-
As recent scandals have illustrated so vividly, privacy is also about the autonomy, dignity, and self-determination of people – and it’s a necessary precondition for democracy.
Frederike Kaltheuner of Privacy International wrote a brilliant op-ed for Politico: "Privacy is power"
-
It's #GDPR day tomorrow and @DataEthicsEUs @mediamocracy and @PernilleT are giving away free PDF downloads of their book Data Ethics - The New Competitive Advantage (2016). #dataethics #dataetik #privacy (also in Danish, just check out the Danish site)
-
A detailed walk-through of the design process behind juro.com's acclaimed attempt to create a user-centered privacy policy document (see here) through a rigorous legal design process.
-
-
Daniel, thank you for your elaborate response to my article on "The Indieweb privacy challenge".
As I explicitly state whenever writing about the GDPR: I am not a lawyer. In recent months, I spent more hours on legal research and debates than many designers ever will, but I always inform readers that I am not formally trained. I put a lot of effort in finding the most reputable sources and put great care in formulating any legal references as the understanding that informed my design work, not universal fact. Therefore, any reader jumping to legal conclusions would be misframing, not me. Alarmism really is not my intention, but I believe it must - especially in the unfortunate absence of definitive rulings - be allowed to explore potentially broad interpretations of the GDPR. Speculative thinking is a powerful tool in design. I, too, see the GDPR as a great opportunity and am excited to see the change it already starts to entail on our society.
From what I have learned, the German judicative's interpretation of privacy laws has traditionally been always amongst the strictest; maybe that, at least to some degree, can explain why my sources tell a different story than the perspective you present. Could such dogmatic differences be the reason why the latest legal commentaries by senior German experts indeed suggest a very restrictive interpretation of Art 2(2) GDPR (Kühling/Buchner, DS-GVO/BDSG 2. Aufl, Art 2 Rn 23+26) and state that Rec 18 GDPR defines the precondition of complete absence of any relation to professional or economical activity (ibid., Art 2 Rn 23)?
Not citing the second sentence of Rec 18(1) in my post was not with the intent to falsify its message, but because several legal commentaries I have analysed explicitly interpret the "social networks" exception as not applicable if personal data is made accessible to an undefined audience (e.g. ibid., Art 2 Rn 25) and define "personal or household activity" as by nature being the opposite of public, "öffentlichkeitsfeindlich" in German (Gola, DSGVO, Art 2 Rn 21; Paal/Pauly/Ernst, DS-GVO, Art 2 Rn 21). Other commentaries, too, state that publishing on a public website would be beyond the boundaries of what is considered "personal" (in this case referring to the similar exception in pre-2018 German privacy law), no matter the subjectively intended target group; herein reliable access control with a limited audience would be a relevant criterion (Plath, BDSG, §1 Rn 30; Simitis/Dammann, BDSG, §1 Rn 151).
A 2016 article in Germany's most prestigeous legal weekly NJW (Schantz, NJW 2016 p.1843) appears to be in almost diametral opposition to the position by van Alsenoy re the ECJ in casa Lindqvist and the interpretation of the GDPR trilogue outcome on Rec18: it claims that, despite an explicit "limited audience" requirement to the Art 2(2) "household exception" not finding its way into the final text as desired by the EP, there "are no signs that there was an intention to loosen this interpretation" (paraphrased translation mine).
These are just to highlight that I did not make up any of my assumptions: everything written about the GDPR in the original article is based directly on - in scientific rigour generally more than one - legal professionals' opinion (being a social scientist myself, I obviously know there are always different schools, but in my world view that does not render one opinion false unless empirically proven). As a lawyer you are no question more qualified to measure these, but neither a legal debate nor legal advice were ever the intent of my article.
I wrote above paragraphs to provide you with some of the requested evidence to support my argumentation (even though unfortunately all German literature, I believe it is good to put out my sources for anybody to verify), and - more importantly - to show that, while we indeed appear to have different standpoints, my presentation is not based on malinformed scaremongering or undue elisions. Admittedly my perspective is potentially biased by chiefly building on German sources only, but I believe to have thoroughly done my homework as far as a non-lawyer possibly needs to, when writing on their design blog and presenting legal assumptions in the subjunctive.
In addition, I want to point out that Germany is the country where a website owner can already get into trouble for a malformed "Impressum" imprint (not its absence, even just omitting f.ex. their snail mail address or publishing their e-mail address as an image file rather than screenreader-accessible HTML text). It is likely only a question of time until the originally well-intended, but today commonly misused, instrument of the "Abmahnung" will be utilized by a certain breed of lawyers to abuse unsuspecting website owners as cash cows starting May 25. This, among other reasons, is why I believe it is not alarmist but only sensible to discuss potentially overseen design-inherent risks with my (to a good share German) blog audience - always with my disclaimer, never sensationalist, but as a worst-case scenario to speculatively assess. Since the imprint requirement of §5 TMG has a (to my knowledge largely similar, though I did not look into the details), "private/household" exception, a pessimist could imply that any website owner who so far considered themselves needing an Impressum might also be subject to the rules of the GDPR - on German Indieweb sites, the Impressum is almost a staple feature, precisely out of fear of the costs incurred by such "Abmahnung".
Ultimately, while I genuinely appreciate that you point out your disagreement with my line of argumentation, above discussion leads - and I take from your intro that you are aware of that - pretty far off the main point of my article: the central question raised is one of ethics and design. And while the GDPR at this point indeed lacks precedents in case law or the ECJ corpus to definitively determine its applicability, the Indieweb community can today start to discuss about ideas to tackle certain implicit, opaque or surprising aspects of the Webmention and backfeed mechanisms. As a designer and concerned citizen, I see the GDPR primarily as a formal manifestation of the universal human right to privacy: its ethical underpinnings should be motivation for everybody to review how we deal with personal data. As the Indieweb community is shaping universal building blocks for the social web of the future, I believe that constructively questioning the "what we do is entirely private" argument is an imperative.
Thank you once again for your comments, I appreciate and respect your point of view. That said, if you have an opportunity, I for my part would be very interested to read about the assessments you mention to have received from the various DPAs regarding Webmentions and backfeed, as that could introduce a welcome specificy to this debate.
-
-
-
One of many GDPR tasks before May 25 is to sign Data Processing Agreements with third-party services you use for your website, newsletter, etc. For an easy start, we created a collaborative online list to provide an easy starting point - please use for your benefit! ...and contribute back?
-
-
-
I was delighted to find this blog post by Econsultancy's Ben Davis, in which he critically reviews recent examples of UX solutions for GDPR-compliant marketing consent. This is the kind of reviews designers concerned with privacy need, in order to generate an industry-wide debate about (slowly emerging) practices and work out optimal solutions over time.
Like Davis, I believe we should have a much broader debate, not only about internal legal compliance efforts, but about well-designed privacy controls that put the users in control of their data - be it consent, privacy policies, or other elements:
These examples are not rocket science, I know. It's the back-of-house stuff that represents the real challenge – how to keep records of all processing, all consent granted by users, how to enable users to take their data to another provider, and so on.
But, as companies should be looking to move towards compliance with the GDPR by 2018, the most visible part of this compliance – the UX of obtaining consent and letting the user know what they're in for – should be a priority soon.
The comment section is an equally great read - opening up a lot of the intricacies of the implementation details when designing for privacy.
PS: It is always great to see articles that highlight how consent is only one of various legal grounds for processing (this is the most-repeated mistake I witness in recent blog posts: complying with the GDPR does not necessarily mean "explicit consent"). At the same time, this is a UK-centred article (re: the references to PECR, a UK law), and in particular the part about marketing consent for non-profiling campaigns may differ under other legislations (as the new ePrivacy regulation, aiming to harmonize these, is delayed and national rules partially remain in force beyond May 25).
-
Frank Chimero's talk about recalibrating digital design speaks to me in many ways. Not only for the reference to the Amish' approach to technology (I talked about that at an IxDA Helsinki meetup in the context of my non-use research a few years ago, and it's always an analogy I enjoy coming back to), but for the difference between the hypercapitalist internet, focused on quick revenues and increasing control, and an internet that is deeply concerned with cultural and societal development.
Facebook, Google, Apple, and Amazon aren’t going anywhere at this point—nor should we expect them to—so it’s best to recalibrate the digital experience by increasing the footprint and mindshare of the kinds of cultural and communal value they can’t provide. The web isn’t like Manhattan real estate—if we want something, we can make space for it.
Different measuring sticks are also in order. If commercial networks on the web measure success by reach and profit, cultural endeavors need to see their successes in terms of resonance and significance. This is the new game, one that elevates both the people who make the work and those who see, use, and enjoy it.
And that's where the Amish enter the picture:
How can the internet, something so obviously technological, seem to be Amish, a set of people resiliently holding out against technology?
It comes down to the idea of the web as a commonwealth. The Amish are not anti-technology. It’s more accurate to say they are only interested in adopting technologies which meet their community-focused criteria. While you or I make individual choices for what technologies we adopt and feel our way through the choice, the Amish collectively make these decisions, so their criteria must be much more clear.
-
-
This analysis of the recent Strava incident (where a global heatmap of GPS workout tracks revealed plenty of potentially secret military sides worldwide) by the EFF is a descriptive explanation of why "anonymization" is not the silver bullet when it comes to dealing with personal data:
Though the revealed information itself was anonymized—meaning map viewers could not easily determine identities of Strava customers with the map alone—when read collectively, the information resulted in a serious breach of privacy.
The blog post broadens the discussion to include non-military users, showing how "social features" of Strava have revealed personal information before: as technology develops, and algorithmic de-anonymisation becomes increasingly easy, the idea that removing personal identifiers from a piece of data makes it "anonymous" is often a false belief.
Often, our understanding of “anonymous” is wrong—invasive database cross-referencing can reveal all sorts of private information, dispelling any efforts at meaningful online anonymity.
This is why, for example when "preparing for the GDPR", it is so important to understand that just anonymising data does not mean it is no longer personal data and that more often than not it needs to be treated with similar care as data that carries individual identifiers (and this applies even more so to "pseudonymised" data---an important consideration too easily forgotten when "just tracking our users based on a randomly assigned ID").
-
issues.a11.rocks is a website project pointing out a11y failures of big web sites.
On their Github page, the authors share their motivation:
On the web platform, technologies and guidelines have been built so we can build a web that includes everyone. By analysing how companies still break accessibility nowadays, our motivation is to educate people on understanding and applying the Four Principles of Accessibility.
While I share that sentiment and understand the motivation, I am not the biggest fan of publicly shaming other people's work (even if, as in this case, we talk about big companies, some even legally obliged to ensure accessibility). Nonetheless, the examples on this site are good showcase examples for just how much there is still to be done – and to illustrate how even apparently "small" omissions can seriously damage the inclusive properties of a website.
Update: On of its co-authors gave a talk at the a11y Berlin meetup in March 2018 (video on YouTube), with a thorough presentation of the four principles, using examples from this project.
-
Following the Strava heatmap debacle, I encountered this study by the University of Toronto's Citizen Lab via Twitter:
Fitness tracking devices monitor heartbeats, measure steps, sleep, and tie into a larger ecosystem of goal setting, diet tracking, and other health activities. Every Step You Fake investigates the privacy and security properties of eight popular wearable fitness tracking systems. We use a variety of technical, policy, and legal methods to understand what data is being collected by fitness tracking devices and their associated mobile applications, what data is sent to remote servers, how the data is secured, with whom it may be shared, and how it might be used by companies.
The report, downloadable in full as PDF, x-rays some of the popular consumer tracking apps and discusses the involved privacy threats.
The key message is that there is a lot to do in terms of transparency and consent when companies deal with people's movement data:
Fitness data can provide detailed insights into people’s lives. It is used in an increasing number of areas such as insurance, corporate wellness, and courts of law. Consumers deserve to be better informed about fitness tracking systems’ privacy and security practices to help them determine whether or not they are comfortable with how their fitness data is being used.
-
Readthedocs.io, a popular platform for creating and publishing software documentation, documents their responsible approach to online ads on their service:
EthicalAds respect users while providing value to advertisers. We don’t track you, sell your data, or anything else. We simply show ads to users, based on the content of the pages you look at. We also give 10% of our ad space to community projects, as our way of saying thanks to the open source community.
Update: As Aral Balkan points out, this message loses some of its credibility as the service quite obviously still uses Google Analytics to subject their visitors to surveillance. While the makers blame this on poor wording and communication that could be improved, this does show that truly responsible design is the sum of many things, not just single actions. It also highlights how even the most responsible "world view" (as they call it in their document) may clash with the realities of today's ubiquitous tracking mindset.
-
-
The Irish Data Protection Commissioner published a brochure with learning materials aimed at secondary schools.
The aim of the resource is to raise awareness amongst young people of their rights to privacy, the importance of taking control of their personal information, the rights they have when it comes to how their personal information may be collected or used and also how they may access their personal information.
From the table of contents:
- What is privacy?
- Privacy as a Human Right
- Rights and Responsibilities
- Technology
…all topped up with a chart on "Rights & Responsibilities".
-