Showing posts with label facebook apps privacy. Show all posts
Showing posts with label facebook apps privacy. Show all posts

Thursday, August 27, 2009

Canada Forces Facebook to make Privacy Changes

(via Ian Brown)

In a remarkable turn of events, Facebook has agreed to add significant new privacy safeguards and make other changes in response to the Privacy Commissioner of Canada’s recent investigation into the popular social networking site’s privacy policies and practices.

"The following is an overview of key issues raised during the investigation and Facebook’s response:

1. Third-party Application Developers

Issue: The sharing of personal information with third-party developers creating Facebook applications such as games and quizzes raises serious privacy risks. With more than one million developers around the globe, the Commissioner is concerned about a lack of adequate safeguards to effectively restrict those developers from accessing users’ personal information, along with information about their online “friends.”

Response: Facebook has agreed to retrofit its application platform in a way that will prevent any application from accessing information until it obtains express consent for each category of personal information it wishes to access. Under this new permissions model, users adding an application will be advised that the application wants access to specific categories of information. The user will be able to control which categories of information an application is permitted to access. There will also be a link to a statement by the developer to explain how it will use the data.

This change will require significant technological changes. Developers using the platform will also need to adapt their applications and Facebook expects the entire process to take one year to implement.

2. Deactivation of Accounts

Issue: Facebook provides confusing information about the distinction between account deactivation – whereby personal information is held in digital storage – and deletion – whereby personal information is actually erased from Facebook servers. As well, Facebook should implement a retention policy under which the personal information of users who have deactivated their accounts will be deleted from the site’s servers after a reasonable length of time.

Response: Facebook has agreed to make it clear to users that they have the option of either deactivating their account or deleting their account. This distinction will be explained in Facebook’s privacy policy and users will receive a notice about the delete option during the deactivation process.

While we asked for a retention policy, we looked at the issue again and considered what Facebook was proposing. We determined the company’s approach – providing clarity about the options, offering a clear choice, and alleviating the confusion – is acceptable because it will allow users to make informed decisions about how their personal information is to be handled.

....

4. Accounts of Deceased Users

Issue: People should have a better way to provide meaningful consent to have their account “memorialized” after their death. As such, Facebook should be clear in its privacy policy that it will keep a user’s profile online after death so that friends can post comments and pay tribute.

Response: Facebook agreed to change the wording in its privacy policy to explain what will happen in the event of a user’s death."

Pangloss is mildly amused that only two years after she, Ian Brown and Chris Marsden presented a paper highlighting the privacy and security issues around the use of third party apps on Facebook, changes are finally being made.

The interesting issue will be if these changes are only made for Facebook in Canada or applied worldwide; similar legal pressure has not, it seems, being exerted in other jurisdictions such as the UK and the US - but there has certainly been concern over the repeated use of third party apps as an easy way to collect personal data for fraudulent or criminal purposes, or to spread malware. One might speculate that if FB are investing in developing new more privacy-compliant code it might as well install it system-wide given the PR advantages and the fact that FB's growth appears to have peaked (the rate of growth has been declining since about January 08). Chris Soghoian on Twitter seems to indicate the changes will be worldwide. If so, the Canadians have certainly done us all a favour.

Pangloss is also intrigued by the Canadian concern over Facebook's treatment of profiles on death. While the matter is certainly a pressing one (with 200 million users, not all young, FB profiles are, sadly, often a major concern to relatives after death) in fact FB has been pretty much in the vanguard in the area of transmision of digital assets, in at least providing a clear and accessible way for relatives to ask for profiles to be "memorialised" after death.

Other sites where digital "assets" remain after death (eg eBay, Flickr, et al) are in general much less clear about what rights they offer relativesafter death, have hard to penetrate procedures on the matter, or actively refuse to allow relatives control after death (see the famous Yahoo! case where relatives of a US marine were initially refused access to his emails after death because the privacy policy forbade passing on information to any third party. At least in the US, the privacy policy remains unchanged to date.)

However in my recent talk on this subject, I also suggested that it would be easy for FB in its various preference suggestions to allow users themselves to indicate what they would like done with their profiles after death. Not all want their profiles left open for comments after death ; some would like them closed down; others might like a friend or relatives to make the decision what to do. One size does not fit all and a solution should also consider and balance the interests of both the profile owner and the relatives. However if FB take a lead here under Canadian persuasion, they may well benefit all by becoming a good practice example in a rather under-considered part of the web 2.0 field.

Thursday, June 18, 2009

Facebook, DP and Apps

According to this article in the FT, the Art 29 Working party on Data Protection has produced an unpublished opinion which, if I read it correctly, seems to suggest that they way FB shares data with, and encourages its users to share data with, unknown and unpoliced third party "apps", needs stricter DP regulation.

According to FT,

"regulators say tighter rules are needed to protect personal data given to these third-party developers. In particular, they believe developers should be subject to tough European Union privacy and data protection rules, even when the companies concerned are located far from Europe.

At the same time, they argue that many corporate marketers who have turned to new forms of social media as a way to reach consumers should also be subjected to stiffer regulations."


Which is pretty much what Ian Brown and I suggested only two years ago :) (Incidentally that piece is finally seeing the published light of say shortly in Andrea Matwyshwn's great edited collection, Harbouring Data (Stanford U Press).

I'm not finding this opinion on the usual Art 29 page: if anyone has it in advance, I would very much like to see it.

Along with various recent reports suggesting that privacy defaults on social networking sites need tighter attention, for everyone not just children, it does seem the privacy and security risks of SNSs are finally getting the serious attention they deserve. (Is it just a coincidence btw that this happens as the Iranian situation shows more clearly than ever the power wielded by social networks these days??)

Tuesday, June 17, 2008

It's amazing..

.. what you see on TV these days.

The local news just had this story about a shopping mall in Portsmouth where mobile tracking technology by Path Engineering has been installed - which I have tracked to this story from the Register.

"By installing receivers around a shopping centre the company can pick up communication between handsets and base stations, enabling them to track shoppers to within a metre or two - enough to spot the order in which shops are visited. Two UK shopping centres are already using the tech, with three more deploying in the next few months."

As far as one can tell, the tracking is completely non-identifying ; the shopping centre and path both do not know personal mobile phone numbers nor corresponding user names. The TV report showed predictable reactions: why weren't we told; I don't like it; I've got nothing to hide; etc.

So what do people think? Despite the obvious knee jerk reaction, as the info is completely non attributable to identified individuals, I really can't see a problem. You could get exactly the same results (at greater cost) by posting tellers at each shop or destination in the shopping centre to do counts all day, every day - would anyone object to that on privacy grounds?

(Hmm - I suppose yes, if they could identify the shoppers. Technology actually has the privacy advantage here of being blind. Here we're pre supposing CCTV isn't used in some way to identify the mobile shoppers - which despite what El Reg suggests would be extremely difficult to arrange in real time.)

I think it's important here to seperate technophobic squeamishness from real privacy concerns. (This is also not like Phorm where anonymity had been artificially imposed and could easily be "broken". Here the mobile tracking system simply doesn't know your personal phone number or your name.)

Of course you need to seperate it too from a consent-based tracking system which can be abused by forced or mistaken consent to reval significant personal data, like Sniff. Which I'm sure everyone else has blogged enough about by now.


And completely off-topic, in the Guardian today, I nearly choked on my post-swim coffee at the ostensible discovery that gay men and heterosexual women (and straight men and lesbians)apparently have similar shaped brains. If true this could destroy several decades of careful academic work on cultural construction :)

And now Newsnight is trying to tell me that Obama will be made or broken by Internet bloggers. Possibly time to turn off the TV and write some more of the third edition of Law and the Internet instead :)

Friday, May 02, 2008

Facebook app privacy meltdown deja vu

..or beware! that Facebook app you just downloaded might be stealing your data and all of your friends!

Is this really still news? PG has said it at at least a dozen talks by now (most recently to Ofcom and the OxII).. however the BBC has helpfully written an app to prove the point, and it is a nice clip. Here's their clip.