October 29th, 2018
The Children’s Online Privacy Protection Act became law in October 1998, and the Federal Trade Commission promulgated its rule concerning the law in the next couple of years. It has been 20 years of ups and downs for privacy protection for children’s data. There continue to be numerous privacy challenges for parents seeking to safeguard their children’s personal information.
As soon as they are born and are issued identification numbers, children face the risk of identity theft. Such thefts can be undetected for years, until a young adult has reason to use her Social Security Number for a loan or credit card. We have schools tracking children (and college students) with camera surveillance systems or RFID-enabled school uniforms or ID cards. Some schools started using biometric ID systems for students to pay for their lunches. There are concerns about tracking apps such as ClassDojo, which can be used by teachers and parents to monitor students’ progress.
The FTC marked the 20th anniversary by noting it has made changes to its Rule over the years: “by amending the Rule to address innovations that affect children’s privacy – social networking, online access via smartphone, and the availability of geolocation information, to name just a few. After hosting a national workshop and considering public comments, we announced changes to the Rule in 2013 that expanded the types of COPPA-covered information to include photos, video, or audio files that contain a child’s image or voice.” Read more »
September 25th, 2018
As people increasingly use personal fitness devices, such as Fitbits, or health-tracking apps, such as Strava, there has been increasing concern about individual medical privacy as the data is gathered and used, sometimes for purposes of which runners or cyclists were unaware. People have questioned where this data collection could lead.
Recently, U.S. life insurance giant John Hancock announced one path for fitness tracking: To cut life insurance rates. Beginning next year, John Hancock, in partnership with Vitality Group, “will stop underwriting traditional life insurance and instead sell only interactive policies that track fitness and health data through wearable devices and smartphones,” Reuters reported. “Policyholders score premium discounts for hitting exercise targets tracked on wearable devices such as a Fitbit or Apple Watch and get gift cards for retail stores and other perks by logging their workouts and healthy food purchases in an app.”
Currently, John Hancock’s program is voluntary and there are numerous other life insurance companies that offer traditional policies, which do not involve constantly tracking individuals’ health and fitness information through wearable devices. But how soon will this change, to where more and more people are pressured to give up such personal data, such daily information, in order to have policies to protect their families? Read more »
July 27th, 2018
Security in school has increasingly included surveillance of schools. Previously, we discussed some schools using RFID-enabled school uniforms or cards to track students. There’s also been discussion of the use of video surveillance systems, also called CCTV for closed-circuit television, in schools. As the installation of such surveillance systems in K-12 grades and colleges and universities became widespread, officials said the systems were for improved security and to be used by school security or police. But video surveillance has begun spreading beyond security in some schools.
Several years ago, ten schools in the United Kingdom began using facial-recognition camera surveillance systems to make sure students “have turned up, records whether they were on time or late and keeps an accurate roll call,” reported the Daily Mail. And earlier this year, India’s capital of Delhi announced that it “said CCTV will be installed in all government schools within three months” and “Parents in India’s capital will soon be able to watch their children in the classroom in real time, using a mobile phone app,” reported BBC News. (And several schools in India have used RFID technology to track students, including for attendance logs.)
But an even more intimate use of camera surveillance in classrooms is being used in China. People’s Daily Online reports:
The “intelligent classroom behavior management system” used at Hangzhou No. 11 High School incorporates a facial recognition camera that scans the classroom every 30 seconds. The camera is designed to log six types of behaviors by the students: reading, writing, hand raising, standing up, listening to the teacher, and leaning on the desk. It also records the facial expressions of the students and logs whether they look happy, upset, angry, fearful or disgusted.
Read more »
June 5th, 2018
There has been an ongoing discussion about how privacy rights can be eroded because laws do not anticipate changing technology. The most prominent example is the Electronic Communications Privacy Act, which was passed in 1986 and remains mired in the technology of that time, which did not include cloud computing, location tracking via always-on mobile devices and other current technology that can reveal our most personal information. (The World Wide Web was invented three years later, in 1989.)
While ECPA includes protection for email and voicemail communications, the 180-day rule is archaic as applied to how the technology is used today. (The rule is: If the email or voicemail message is unopened and has been in storage for 180 days or less, the government must obtain a search warrant. If the message is opened or has been stored unopened for more than 180 days, the government can access your message via a special court order or subpoena.) Thirty-two years ago, people had to download their email to their computers; the download would trigger an automatic deletion of the content from the provider’s servers. The government could not subpoena an Internet Service Provider (ISP) for your email because it did not have them in 1986. Now, copies of your private email remain stored in the cloud for years by third-party service providers (Google, Facebook, Dropbox, etc.)
Privacy and civil liberty advocates have been trying for years to update ECPA. Last year, the U.S. House passed the Email Privacy Act, which would codify the rule set out in 2008’s Sixth Circuit case Warshak v. United States: The government must obtain a warrant before they could seek to compel an ISP or other service providers to hand over a person’s private messages. This year, the Email Privacy Act is part of the House version of the National Defense Authorization Act, a must-pass bill. But the Senate has its own version of the NDAA and it’s unknown whether the privacy legislation will be part of it. Read more »
April 26th, 2018
Two Florida detectives tried to use a dead man’s fingerprints to unlock his phone, the Tampa Bay Times reported, and that act raised privacy questions.
Linus F. Phillip “was shot and killed [by a Largo, Fla., police officer] March 23 at a Wawa gas station after police said he tried to drive away when an officer was about to search him,” the Times reported. Later, two detectives came to the Sylvan Abbey Funeral Home in Clearwater with Phillip’s phone, according to Phillip’s fiancee, Victoria Armstrong. “They were taken to Phillip’s corpse. Then, they tried to unlock the phone by holding the body’s hands up to the phone’s fingerprint sensor,” the Times reported.
Phillip’s fiancee is upset. She was not notified that the detectives would be coming to the funeral home, and the police did not get a warrant for their actions.
Although the detectives’ actions have been criticized as unethical, they are legal because dead people have fewer rights than the living, especially concerning privacy and search and seizure. The courts have split on whether living defendants can be forced to use biometrics such as fingerprints or facial scans to unlock their mobile devices. (Another difference from the Phillips case is that these court cases involved warrants.) Read more »
March 28th, 2018
Recently, an Australian student publicized that Strava, a fitness app, had published online a Global Heat Map that “uses satellite information to map the locations and movements of subscribers to the company’s fitness service over a two-year period, by illuminating areas of activity,” according to the Washington Post. Strava “allows millions of users to time and map their workouts and to post them online for friends to see, and it can track their movements at other times,” the New York Times reports.
The data, culled from Strava’s 27 million users (who own Fitbits and other wearable fitness devices), is not updated in real-time. Yet the map still raised privacy and security questions for Strava’s users.
A similar case in 2011 concerning wearable device Fitbit also raised privacy questions about searchable fitness data. There was an uproar over Fitbit’s privacy settings when people who were logging their sexual activity as a form of exercise learned that the data was showing up in Google searches. And in 2014, Jawbone faced criticism after it published data about how many people wearing its fitness tracker woke up during an earthquake in Northern California. People questioned whether Jawbone’s privacy and data-sharing policies had disclosed such use of their health data.
Fitness devices, including smartwatches, and mobile health or wellness apps are used by tens of millions of people worldwide. There are many such apps available in Apple’s and Google’s app stores. The data gathered can reveal much personal information about individuals. In the case of Strava, you could track patterns of activity over the two years’ worth of data. Read more »