=======================================================================                          E P I C   A l e r t=======================================================================Volume 16.21                                          November 9, 2009 On November 3, EPIC filed a friend of the court brief with the FifthCircuit Court of Appeals, urging the Court to enforce federal privacyprotections for Facebook users who rented videos from Blockbuster, aFacebook business partner.Congress passed the Video Privacy Protection Act of 1988 to prevent thewrongful disclosure of video rental information by companies thatcollect detailed personal information from customers. To achieve thisgoal, Congress established a private right of action to ensure thatthere would be a meaningful remedy when companies failed to safeguardthe data they collected. A private right of action is a statutoryclause that gives individual citizens the right to sue companies whoviolate the individual's rights under the law.Accordingly, Cathryn Harris and other Facebook users filed suit underthe Act after Blockbuster made public their private video rentalinformation. Blockbuster made the information public as part of itsparticipation in Facebook's Beacon program, which revealed the privateinformation on the news feeds of other users. To achieve thisgoal, Congress established a private right of action to ensure thatthere would be a meaningful remedy when companies failed to safeguardthe data they collected. A private right of action is a statutoryclause that gives individual citizens the right to sue companies whoviolate the individual's rights under the law.Accordingly, Cathryn Harris and other Facebook users filed suit underthe Act after Blockbuster made public their private video rentalinformation. Blockbuster made the information public as part of itsparticipation in Facebook's Beacon program, which revealed the privateinformation on the news feeds of other users. In response to thelawsuit, Blockbuster claimed that, under the "clickwrap" agreement thatconsumers clicked through while signing up for Blockbuster's onlineservice, consumers could not sue the company and had to submit tomandatory arbitration.EPIC wrote that "absent a private right of action, there would be noeffective enforcement, no remedy for violations, and no way to ensurethat companies complied with the intent of the Act." EPIC's brief,which includes a detailed history of the video privacy law, urges theappeals court to uphold a lower court ruling, which held that theplaintiffs are allowed to pursue their claim that a federal law wasviolated.EPIC Amicus Brief:   http://epic.org/amicus/blockbuster/Blockbuster_amicus.pdfEPIC: Harris v. Blockbuster:   http://epic.org/amicus/blockbuster/default.htmlEPIC: The Video Privacy Protection Act:   http://epic.org/privacy/vppa/EPIC: Facebook Privacy:   http://epic.org/privacy/facebook/=======================================================================[2] Study Finds Privacy of Nation's School Children At Risk=======================================================================A Fordham Law School study found that state educational databasesacross the country ignore key privacy protections for the nation'sschool children. The study, prepared by the Center on Law andInformation Policy, reports that at least 32% of states warehousechildren's social security numbers; at least 22% of states recordstudent pregnancies; and at least 46% of the states track mentalhealth, illness, and jail sentences as part of the children'seducational records. Almost all states with known programs collectfamily wealth indicators.Moreover, most states use third party vendors for at least part oftheir data collecting and reporting needs. Some states outsource thedata processing without any restrictions on use or confidentiality forchildren's information. The study therefore recommended that stateswhich outsource data processing have comprehensive agreementsexplicitly addressing the privacy obligations of the third partyvendors. Furthermore, access to the information and the disclosure ofpersonal data may occur for decades and follow children well into theiradult lives. More than 80% of states fail to have data-retentionpolicies and may retain the information indefinitely. Thus, the studyrecommended that states should limit data collection to necessaryinformation and should have specific data retention policies andprocedures.The Fordham report also recommended that data at the state level bemade anonymous, that the collection of information by the state beminimized and specifically tied to an articulated audit or evaluationpurpose, and that states should have a Chief Privacy Officer in thedepartment of education who monitors the privacy protections ofeducational record databases and who publicly reports privacy impactassessments.These findings come as Congress is considering the Student Aid andFinancial Responsibility Act, which would expand and integrate the 43existing state databases without taking into account the criticalprivacy failures in the states' electronic warehouses of children'sinformation.Study Website:   http://law.fordham.edu/childrensprivacyFordham Law School, Center on Law and Information Policy:   http://www.epic.org/redirect/110609fordhamstudy.htmlStudent Aid and Financial Responsibility Act:   http://www.epic.org/redirect/110609studentaidact.htmlEPIC: Children's Online Privacy Protection Act:   http://epic.org/privacy/kids/EPIC: DOD Recruiting Database:   http://epic.org/privacy/student/doddatabase.html=======================================================================[3] Public Voice Hosts Madrid Civil Society Conference=======================================================================Almost two hundred privacy experts, advocates, and government officialsfrom around the world gathered in Madrid for the "Global PrivacyStandards" conference, organized by the Public Voice, and held inconjunction with the International Conference for Data Protection andPrivacy.The event featured five panel discussions. The "Privacy and HumanRights: The Year in Review" panel, which released the most currentedition of the Privacy and Human Rights report, focused on recentdevelopments in privacy law. "Privacy Activism: Major Campaigns"featured a discussion on privacy and data protection campaigns aroundthe world, concentrating on the role of public education. The thirdpanel, "Your Data in the Cloud: What if it Rains?" discussed theprivacy implications of cloud computing for internet users."Transborder Data Flow: Bridges, Channels or Walls?," centered on adiscussion of when data flows should be facilitated and when theyshould be blocked.  Finally, in the "Toward International PrivacyStandards" discussion, Marc Rotenberg offered a presentation of theMadrid Civil Society Declaration on Global Privacy Standards, andrespondents from four different countries reacted to his statements.Leading privacy officials from Spain, the European Union, the EuropeanParliament, the OECD, and Canada all participated. Each panel featuredrepresentatives from at least three different countries. Openingremarks were made by Marc Rotenberg, President, EPIC; Mr. AlejandroPerales, President, Asociación de Usuarios de la Comunicación; and Mr.Artemi Rallo Lombarte, Director, Agencia Española de Protección deDatos. Conference attendees heard closing remarks from Mr. StavrosLambrinidis, Vice President, European Parliament; and Mr. PeterHustinx, Supervisor, European Data Protection Supervisor (Netherlands).The privacy commissioner's conference drew more than 1,000 participantsfrom over fifty countries.Global Privacy Standards Conference:   http://thepublicvoice.org/events/madrid09/International Conference of Data Protection and Privacy:   http://www.privacyconference2009.org/Public Voice:   http://thepublicvoice.org/Conference Cybercast:   http://community.thepublicvoice.org/=======================================================================[4] Civil Society Groups Issue Privacy Declaration in Madrid=======================================================================In a crisply worded declaration, over 100 civil society organizationsand privacy experts from more than 40 countries have set out anexpansive statement on the future of privacy. The Madrid PrivacyDeclaration was released at the Public Voice conference in Madrid onGlobal Privacy Standards.The Madrid Declaration affirms that privacy is a fundamental humanright. The declaration reminds the European Union member countries andOrganization for Economic Co-operation and Development member countriesof their obligations to protect the civil rights of their citizensunder national constitutions and laws.  Noting the increase in secretsurveillance and lack of independent oversight in corporations' datacollection practices, the Madrid Declaration sets forth warnings andurges action on the part of the European Union countries.The Madrid Declaration warns that "privacy law and privacy institutionshave failed to take full account of new surveillance practices." Suchfailures to protect the privacy interests of citizens "jeopardize[]associated freedoms . . . and ultimately the stability ofconstitutional democracies."The Madrid Privacy Declaration urges countries who have not done so toratify the Council of Europe Convention 108, establish a comprehensiveframework for privacy protection, develop means of properlyimplementing and enforcing such legal frameworks, and ensure thatindividuals are notified after a data breach has occurred. Furthermore,the Declaration encourages research into the effectiveness of dataanonymization techniques, in an effort to determine whether suchpractices properly safeguard personal information.The civil society groups and experts recommend a "moratorium on thedevelopment or implementation of new systems of mass surveillance."Finally, the Declaration calls for the "establishment of a newinternational framework for privacy protection, with the fullparticipation of civil society, that is based on the rule of law,respect for fundamental human rights, and support for democraticinstitutions."Madrid Declaration:   http://thepublicvoice.org/madrid-declaration/ GlobalPrivacy Standards Conference:   http://thepublicvoice.org/events/madrid09/Translations of Madrid Declaration:   http://thepublicvoice.org/events/madrid09/ Council of Europe Convention 108:   http://conventions.coe.int/treaty/EN/Treaties/Html/108.htmEPIC Reidentification:   http://epic.org/privacy/reidentification/=======================================================================[5] EPIC Audits First Public Election to use Scantagrity Voting System=======================================================================The city of Takoma Park Maryland’s Clerk of Elections sought EPIC'sassistance in conducting a manual audit of their November 3, 2009election. The city chose the Scantagrity voting system for its biannualelection for mayor and city council. Scantagrity is an original conceptdeveloped by David Chaum and has been refined for use in electionsthrough the collaboration of Ron Rivest, MIT and Poorvi Vora, ComputingScience Department at George Washington University.Scantagrity’s implementation for the Takoma Park election allowedvoters the option of performing a post-voting verification of thecapture of their ballots for the tabulation phase of the election.Takoma Park voters also had the option of second chance voting, whichallowed the selection of primary and secondary choice for the publicoffices on Tuesday’s ballot.This marked the first time in the U.S. that voters had the option tocheck that their private votes are correctly recorded and included inthe election results. Selections on each ballot used unique codes foreach possible selection on the ballot. The codes correspond to theballot number. It is important to note, however, that ballots are notassociated with a specific voter. Poll book registration logging ofvoters participating in the election was separate from the issuance ofballots to voters.Voters were given ballots in a privacy sleeve. They then voted usingoptical scan ballots behind privacy screens, which allowed voters theoption of noting the codes and ballot numbers on a form they could takewith them. Voters then deposited completed ballots into one of twoscanners. Later, voters could verify that their ballot was included inthe final results by going to the City Election Office’s web site andentering the ballot number. The process was not as accessible forunassisted voting for persons vision related disabilities, whencompared with touch screen voting systems. However, the ability ofvoters with a wide range of disability challenges were able to voteindependently, or with little assistance with their privacy sleeveenclosed ballot’s insertion in the scanner.EPIC was asked to randomly select ballots from the choice of ballotsprovided to voters from each of the 6 wards. Over 1600 Takoma Parkvoters participated in the election. The audit ballots were selectedat varying times throughout the Election Day, under the supervision ofelection officials. Takoma Park elections officials voided each auditballot and marked ballots stubs to indicate that they were part of themanual audit. Then EPIC processed each manual audit ballot by revealingall possible selections for each ballot, then a copy of the originalmanual audit ballot was made. The original ballots were placed in aspoiled manual audit ballot envelope held by another election officialstationed in the polling location. Each ballot copy was then endorsedby the Chief Election Judge, which will aid in authentication of thecopies when they are submitted to the City Clerk’s office. The manualaudit ballots and their selections will be verified and the resultsreported to the Takoma Park Clerk’s office.Scantagrity:   http://www.scantegrity.org/Links: Takoma Park Election’s Office:   http://www.takomaparkmd.gov/clerk/election/2009/index.htmlTakoma Ballot verification Web page:   http://scantegrity.org/takoma/checkcodesEPIC’s Voting Privacy Page:   http://epic.org/privacy/voting/=======================================================================[6] News in Brief=======================================================================European Commission Takes Action Against United KingdomThe European Commission announced that the United Kingdom governmenthas failed to comply with Europe's ePrivacy Directive and DataProtection Directive. European laws state that European Union countriesmust ensure the confidentiality of electronic communications byprohibiting unlawful interception and surveillance. The Commission'sstatement specifically cited unlawful interception under the UnitedKingdom Regulation of Information Powers Act. This marks the secondphase of an infringement proceeding that was filed earlier this yearagainst the United Kingdom. The case follows complaints about the useof Phorm's Deep Packet Inspection technology.European Commission Statement:   http://www.epic.org/redirect/110609commstmt.htmlPress Release on theInfringement Proceeding:   http://www.epic.org/redirect/110609prelease.htmlePrivacy Directive:   http://www.epic.org/redirect/110609eprivacy.htmlEurope's Data Protection Directive:   http://www.epic.org/redirect/110609dataprotdir.htmlEPIC: Deep Packet Inspection:   http://epic.org/privacy/dpi/default.htmlEPIC: Privacy and Human Rights Report:   http://epic.org/phr06/Privacy Groups Urge Government to Ensure OpenInternetEPIC has signed on to a letter from Public Knowledge to the FederalCommunications Commission supporting the Commission's decision to beginpublic proceedings on preserving an open internet. EPIC joins manyother public interest groups who have also expressed support for theFCC's initiative. The Commission's proceedings will focus on proposedrulemaking policies that would preserve open internet. EPIC favors thegeneral principles of "network neutrality" and has called on theCommission to preserve privacy safeguards against measures thatInternet Service Providers may use to limit access to the internet. Formore information, see also EPIC Deep Packet Inspection.FCC Letter:   http://www.publicknowledge.org/node/2711Public Knowledge:   http://www.publicknowledge.org/FCC Proceedings:   http://hraunfoss.fcc.gov/edocs_public/attachmatch/DOC-293997A1.pdfEPIC Deep Packet Inspection:    http://epic.org/privacy/dpi/HHS Changes Breach Notification RulesThe Department of Health and Human Services issued new breachnotification regulations that require health care providers, healthplans, and business associates of covered entities, to notifyindividuals when their health information is breached. As an effort tostrengthen the Health Insurance Portability and Accountability Act, thenew rules subject business associates of covered entities to federallaw in this area for the first time. The Department also included aprovision that states a breach only occurs when access, use, ordisclosure of the data poses a significant risk of financial or otherharm to an individual, as determined by covered entities. These rulesimplement provisions of the Health Information Technology for Economicand Clinical Health Act, which was passed as part of the AmericanRecovery and Reinvestment Act.Department of Health and Human Services:   http://hhs.gov/HITECH Breach Notification Interim Final Rule:   http://edocket.access.gpo.gov/2009/pdf/E9-20169.pdfHHS Breach Notification Rule Page:   http://www.epic.org/redirect/110609brnotif.htmlHIPAA:   http://www.hhs.gov/ocr/privacy/hipaa/administrative/index.htmlHITECH Act:   http://www.hitech-act.com/uploads/HITECH_Act_from_PL_111-005.pdfEPIC Medical Record Privacy:   http://epic.org/privacy/medical/EPIC Submits Letter Requesting Participation in Privacy RoundtableThe Federal Trade Commission announced a series of roundtables onconsumer privacy, beginning December 7, 2009. These discussions willexplore many issues, including consumer information collection,information management practices, new business practices, and theadequacy of existing privacy laws. EPIC submitted a letter to theCommission requesting to participate in the first privacy roundtablediscussion. In its letter, EPIC made several recommendations to theCommission as it explores new internet consumer protection strategies.The recommendations include treating fair information practices as afundamental requirement for companies collecting personal data,focusing more attention on the major Internet firms that are shapingbusiness practices in the online environment, and investigating theextent to which security breaches contribute to identity theft.EPIC: Letter to the FTC:   http://epic.org/privacy/ftc/Participation_Request.pdfFederal Trade Commission:   http://www.ftc.govFTC Press Release:   http://www.ftc.gov/opa/2009/09/privacyrt.shtmFTC Privacy Roundtable:   https://public.commentworks.com/ftc/privacyroundtable1/EPIC FTC:   http://epic.org/privacy/internet/ftc/FB Updates Privacy Policy in Response to Canadian InvestigationIn response to a September ruling by the Canadian Privacy Commissionerthat Facebook's business practices violated Canadian law, Facebookannounced a new privacy policy this week. In order to comply withCanada's Personal Information Protection and Electronic Documents Act,the new Facebook policy provides a more concise description of theprivacy practices of the developers of third-party applications. Italso explains more clearly what data Facebook retains and whatabilities users do and do not have to control their data stored onFacebook. The new policy was open to comments for one week and willpresumably be implemented sitewide soon.Facebook: New Privacy Policy:	http://www.facebook.com/note.php?note_id=322194465300Facebook: Current Privacy Policy:	http://www.facebook.com/policy.phpFacebook: New Third-Party Developer Policies:	http://developers.facebook.com/policyEPIC: Facebook Privacy:	http://epic.org/privacy/facebook/Office of the Privacy Commissioner of Canada: Facebook Findings:	http://www.priv.gc.ca/cf-dc/2009/2009_008_0716_e.cfmReporter Confidentiality Law Moves Forward in SenateA revised version of the proposed federal media shield law movedforward in the Senate this week. The Free Flow of Information Act of2009 will make it more difficult for the government to compeljournalists to disclose information, including the identities of theirsources. The White House, which had previously endorsed a much weakerversion, has come out in favor of stronger statutory text whichrequires the government or other party requesting disclosure todemonstrate that the information sought is "essential" to a case andall reasonable alternatives have been exhausted. A judge would thenbalance the case for disclosure against the public interest ineffective journalism. 