The conference provided an opportunity for civil society leaders and academic experts to meet with European data protection authorities and explore emerging challenges to the protection of personal privacy. The conference was held in conjunction with the annual meeting of the International Data Protection and Privacy Commissioners. The event was organized by EPIC, Privacy International, and the European Digital Rights Initiative. Conference participants came from fifteen countries, seven of which are New European Union Member States. Several privacy commissioners participated in the conference, including Peter Hustinx, European Data Protection Supervisor; Dr. Ewa Kulesza, Inspector General for Personal Data Protection in Poland; Karel Neuwirt, Data Protection Commissioner for the Czech Republic; Jennifer Stoddart, Privacy Commissioner for Canada; David Loukidales, Privacy Commissioner for British Columbia, Canada; Raymond Tang, Privacy Commissioner for Hong Kong; and Frank Work, Information and Privacy Commissioner for Alberta, Canada. Karel Neuwirt, Data Protection Commissioner for the Czech Republic, spoke about the development of privacy protection, the relevant international instruments, and the establishment of the data protection authority in the Czech Republic. Mr. Neuwirt emphasized the educative role of his office. "Education is an effective tool of enforcement for data protection principles," he said. Gus Hosein of Privacy International discussed the relationship between civil society groups and data protection authorities. Hosein pointed to several successful collaborations as well as important efforts that data protection authorities have taken to safeguard privacy, and recommended that civil society organizations acknowledge these efforts. At the same time, he said, data protection authorities must pursue more campaigns to maintain public support. Professor Arwid Mednis of the University of Wroclaw explored the legal basis of the right to privacy, with a particular emphasis on the development of privacy standards within the Council of Europe and the European Union. Professor Mednis looked in particular at recent developments in privacy law and some of the new challenges resulting from efforts to combat computer crime and to fight terrorism. Bogdan Manolea described how he established the Association for the Best Use of Electronic Services (ABUSE), the first association of information service providers in Romania. He examined the roots of privacy and the current threats to privacy, including the establishment of the Integrated Informational System, a centralized database which may become the electronic arm of the Romanian Intelligence Service. Manolea suggested several strategies for effective privacy protection, including the creation of an independent privacy office, awareness campaigns, and concrete programs in cooperation with civil society organizations. Ivan Székely of the Open Society Archives at Central European University in Hungary candidly assessed the work of civil society groups in the data protection field. He discussed the need to distinguish real civil society organizations from front groups, as well as the complimentary roles of expert privacy groups and radical privacy groups. He made recommendations about how to develop effective public education campaigns, including the need to develop phrases and themes that speak to a broad public. Conference web site: http://www.thepublicvoice.org/events/wroclaw04 The Public Voice: http://www.thepublicvoice.org Privacy International: http://www.privacyinternational.org European Digital Rights Initiative: http://www.edri.org ====================================================================== [2] Gov't Details Secure Flight; Documents Show CAPPS II Mission Creep ====================================================================== The Transportation Security Administration has released more information about Secure Flight, the government's new passenger prescreening initiative which is being developed to replace the controversial second generation Computer Assisted Passenger Prescreening System (CAPPS II). CAPPS II was dropped just months ago due to unresolvable concerns about the program's effectiveness and implications for individual privacy. As described by the TSA, Secure Flight will compare Passenger Name Records (PNRs) against information compiled by the Terrorist Screening Center, which will include expanded "selectee" and "no fly" lists. TSA will also seek to identify "suspicious indicators associated with travel behavior" in passengers' itinerary PNR data. Furthermore, the agency is planning to test the use of commercial databases to verify the accuracy of information provided by travelers. TSA will administer the program, removing all passenger screening responsibility from the airlines. The agency has issued a proposed order that directs airlines to turn over passenger records from June 2004 so that Secure Flight can be tested this fall. Like its predecessor, Secure Flight has been exempted from crucial provisions of the Privacy Act, which will severely limit the rights individuals typically would have in the personal information the government maintains about them. For instance, Secure Flight may collect and use personal information irrelevant and unnecessary for aviation security. Furthermore, passengers will have no judicially enforceable rights to access and correct the personal information maintained about them for the program. TSA assures the public, however, that "upon completion of the testing phase, and before Secure Flight is operational, TSA will establish comprehensive passenger redress procedures and personal data and civil liberties protections for the Secure Flight program." No details about these protections are available, nor information about how long TSA will keep PNR data that it collects for Secure Flight, even though the agency intends to launch the program early next year. In related news, EPIC's Freedom of Information Act litigation with the TSA has revealed three heavily redacted draft privacy impact assessments the agency performed last year for CAPPS II. The drafts, dated April 17, 2003, July 29, 2003, and July 30 2003, reflect a dramatic expansion over just three and a half months in the ways passenger information collected for the program would have been shared. Privacy Act notice for Secure Flight: http://www.epic.org/privacy/airtravel/sf_sorn__9.21.04.pdf Secure Flight privacy impact assessment: http://www.epic.org/privacy/airtravel/sf_pia__9.21.04.pdf Proposed order directing airlines to turn over June 2004 passenger records: http://www.epic.org/privacy/airtravel/sf_pra_9.21.04.pdf Privacy impact assessments obtained through the FOIA showing CAPPS II mission creep: http://www.epic.org/privacy/airtravel/foia/4-17-03.pdf http://www.epic.org/privacy/airtravel/foia/7-29-03.pdf http://www.epic.org/privacy/airtravel/foia/7-30-03.pdf ====================================================================== [3] Wireless Privacy Bill Moves Forward in Senate ====================================================================== The Senate Commerce Committee has approved S. 1963, the Wireless 411 Privacy Act. Authored by Senators Specter (R-PA) and Boxer (D-CA), the legislation would require wireless carriers to obtain consent before listing current subscribers a wireless directory, but new subscribers could be listed on an opt-out basis. The bill prohibits charging for listing or for revoking a listing. Representatives Pitts (R-PA) and Markey (D-MA) have introduced companion legislation in the House as H.R. 3558. Earlier in the week, EPIC Executive Director Marc Rotenberg testified before the Committee on the need to create privacy protections for a wireless phone number directory being created by Qsent for wireless providers, AT&T, Sprint, Cingular, T-Mobile, Nextel, and ALLTEL. While giving individuals a convenient way to find wireless phone numbers, such a directory may subject users to unwanted telemarketing, spam, viruses, junk faxes, and harassing calls. EPIC made the case that opt-in and other legislative protections are needed because many profitable and reputable companies have promised strong privacy safeguards only to renege with the adoption of new business models. Furthermore, although the wireless industry's trade group, CTIA, has promised that the system will be opt-in, their representations are illusory because the carriers themselves will set the privacy practices for the wireless directory. Carriers would be free to adopt opt-out standards, and thus far, the participating carriers have been reticent and were unwilling to testify before the Committee. Not so with Verizon Wireless. In its testimony, the company strongly opposed the creation of a wireless directory, calling it a "dumb idea" and claiming that opt-in is not enough to protect subscribers' privacy rights. It pledged not to participate in the wireless directory, noting that those who wish to be listed can do so free online, and for a small charge in print directories. Qsent, the company tasked to architect the wireless directory, testified that consumers will get to choose to be listed, but stopped short of using the term "opt-in." The company claimed that wireless numbers will only be distributed to those who call "411," and that it will never appear in print or electronic form, nor will it be available on the Internet. The company also promised security safeguards for the wireless directory. However, it is unclear what recourse exists if there is accidental disclosure or security breach. In the wireline context, the disclosure of an unpublished or unlisted number usually results in the carrier issuing a new phone number to affected subscribers. It is unclear whether wireless users will enjoy that benefit. California is on the cusp of creating the strongest protections for wireless directory information. California AB 1733 creates opt-in requirements for wireless directory listing and for the sale of wireless telephone numbers. Individuals can revoke their consent to listing at any time, and carriers could not charge consumers for listing or for revoking a listing. AB 1733 also allows individuals to bring suit against those who deliberately violate the protections. The bill passed the Senate and Assembly and is awaiting Governor Schwarzenegger's signature. EPIC testimony on Wireless Directory Privacy: http://www.epic.org/privacy/wireless/dirtest_904.html Wireless 411 Privacy Act: http://thomas.loc.gov/cgi-bin/bdquery/z?d108:s.1963: California AB 1733: http://www.epic.org/redirect/ab1733.html ====================================================================== [4] EPIC Challenges Dismissal of Privacy Claim Against Northwest ====================================================================== In a petition for review filed this week, EPIC urged the Department of Transportation to reverse its recent decision that Northwest Airlines did not break the law when it disclosed millions of passenger records to NASA. EPIC charged that Northwest Airlines commited an unfair and deceptive trade practice by giving passengers' personal information to the agency in direct violation of its privacy policy. EPIC's petition argued that Northwest's Internet privacy policy assured its customers that their sensitive personal information would remain protected unless the airline had a legal obligation to share the data with the government. The policy promised customers: "As a User of nwa.com Reservations you are in complete control of your travel planning needs. This includes controlling the use of information you provide to Northwest Airlines, its airline affiliates, and WorldPerks partners." According to EPIC's appeal, Northwest violated that agreement when it voluntarily released passenger records to NASA for use in a now-defunct data mining study. In an order dated September 10, the Department of Transportation initially dismissed the complaint. The Department, which has publicly stated that it "encourages self-regulation as the least intrusive and most efficient means of ensuring the privacy of information provided by consumers to airlines," proclaimed that in this case "Northwest has not violated its privacy policy, and . . . if it did, such a violation does not warrant the initiation of enforcement proceedings." In its petition filed September 20, EPIC asserted that that the government blatantly ignored the established test for deceptive trade practices in declining to find that Northwest violated its privacy policy. The petition asks the Department to reverse its dismissal, apply the proper legal standard to the Northwest violation, and enforce the airline's privacy policy. EPIC's petition for review of the Department of Transportation's order: http://www.epic.org/privacy/airtravel/nasa/nwa_petition.pdf The Department of Transportation's order dismissing EPIC's complaint against Northwest: http://www.epic.org/privacy/airtravel/nasa/dot_order.pdf For more information, see EPIC's Northwest disclosure page: http://www.epic.org/privacy/airtravel/nasa ====================================================================== [5] EPIC Testifies on Voting and Privacy ====================================================================== EPIC Senior Policy Analyst Lillie Coney testified before the Election Assistance Commission's Technical Guidelines Development Committee on September 22 on the importance of voter privacy. Coney noted that the delicate balance between the state's right to ensure that intimidation and election fraud are not present in public elections and the voter's right to privacy have resulted in the development of the secret ballot and restricted zones around voting compartments. Because of the documented history of voter intimidation, coercion, and fraud associated with third party knowledge of how individual voters cast their ballots, it is important not to underestimate the importance of voter privacy. However, attempts to address fraud have led to voter intimidation and stringent measures to screen out illegal voters, which result in legitimate voters being denied their right to vote. Coney noted that elections systems rely on voluntary participation of poll workers and voters. The major challenge of election systems is to create ease of use in a process that is done very infrequently. At most the greatest voter participation is seen during presidential election years, which occur once every four years. Recent reports of poll workers struggling to deal with malfunctioning voting technology is not new to paperless DRE voting machines. In the Florida 2000 presidential election poll workers did not take malfunctioning punchcard voting machines out of service. It was reported that 20 [punchcard voting] machines in two Miami-Dade County precincts with the highest rate of discarded punchcard ballots did not show votes for at least some candidates during a test-vote minutes before polls opened on November 7. Poll workers provide the human judgment used in a gatekeeper function to determine who may vote in public elections. There is very little if any due process accorded to voters who are judged to be invalid. Unfortunately, the experience for voters who are in the "out group" -- minorities, new citizens, language minorities, and disabled voters -- are most at risk of being disenfranchised. Those voters not identified with by poll workers often find the hurdles to voting are much higher and problematic. For example, in the State of Florida voters erroneously included on a list of felons, who are prevented by state law to vote, were predominately minority. The subjective nature of the polling operation meant that some poll workers were able to recognize the errors on the list and allowed voters to vote, while others could or would not allow these individuals to vote. As little as possible should rely upon the subjective judgment of poll workers, as gatekeepers to the ballot box, but the focus should be on facilitating participation in the election process. According to the CalTech MIT Study "Voting: What Is What Could Be," between 4 and 6 million votes were lost in the 2000 election. The study attributed the loss to problems with voter registration or polling place practices and problems with ballots. In response to this situation, the Help America Vote Act became law. This legislation made it a priority to making voting more accessible for all voters, especially those with disabilities or who were language minorities. Although the law requires only one accessible voting machine per polling location, many states have interpreted that to mean touchscreen direct recording electronic (DRE) voting machines and have adopted the technology universally for all voters and voting locations used on Election Day. The greatest privacy benefits of DRE voting machines accrue to those who are visually disabled, language minorities, or have literacy challenges. Critics of paperless DRE voting technology acknowledge the apparent usability benefits to some voters, but point to a critical vulnerability in their design. Another privacy concern is presented by the implementation of the voter interface, which on some machines is done at nearly a 75-80-degree angle to the horizontal. Current machine set up in polling locations requires that the machines be in full view of the poll workers. This is done in such a manner that the display screen is exposed to those present in the polling location, including other voters. If the restricted space around DRE voting machines is too small, this would also threaten voter privacy. The hearing was an opportunity for the committee charged with making recommendations on voluntary standards for election systems and voting technology. The committee is expected to make its recommendations to the full Election Assistance Commission board sometime next summer for adoption and implementation in 2006. EPIC's testimony on voting and privacy: http://www.epic.org/privacy/voting/Voting_Statement.pdf National Committee for Voting Integrity: http://www.votingintegrity.org For more information about electronic voting, see EPIC's Voting Page: http://www.epic.org/privacy/voting ====================================================================== [6] News in Brief ====================================================================== EPIC FILES SUIT AGAINST CENSUS, HOMELAND SECURITY EPIC has filed suit against two federal agencies for failing to respond to Freedom of Information Act appeals regarding law enforcement requests for completed census questionnaires or other census data. The Census Bureau responded to EPIC's initial Freedom of Information request with, among other things, a series of emails between Census and the Department of Homeland Security's Customs and Border Protection concerning special tabulations that Census eventually created for Customs concerning people of Arab ancestry. However, at Customs' request, all but one of its communications to Census were blacked out. The disclosure also did not indicate whether any other relevant communications were located but withheld. EPIC appealed the decision to withhold this information to both Census and Customs, and was forced to file suit when it did not receive a determination from either agency within the time frame required by law. EPIC's complaint: http://www.epic.org/privacy/census/foia/complaint.pdf For more information about the documents obtained by EPIC from the Census Bureau, see EPIC's Census FOIA page: http://www.epic.org/privacy/census/foia COURT SAYS GOVERNMENT MUST MAKE ID ARGUMENTS PUBLICLY The Ninth Circuit Court of Appeals rejected the Department of Justice's request to seal from public view its arguments supporting an unpublished federal regulation requiring passengers to show identification before boarding airplanes. The Justice Department filed a motion requesting the court to reconsider, and informed the court that while it intends to file its brief in Gilmore v. Ashcroft by its September 29 deadline, the brief will not contain the information it wishes to keep secret, including whether the federal regulation even exists. The agency sought to make its argument in front of a closed court without appellant John Gilmore or his counsel present. EPIC has filed an amicus brief in the case, arguing that meaningful judicial review is necessary to prevent the government from imposing a secret, vague law upon the public in violation of constitutional due process rights. Gilmore v. Ashcroft web site: http://www.gilmorevashcroft.com EPIC's amicus brief in Gilmore v. Ashcroft: http://www.epic.org/privacy/airtravel/gilmore_amicus.pdf For more information about air travel privacy, see EPIC's Passenger Profiling page: http://www.epic.org/privacy/airtravel/profiling SPYWARE PRIVACY BILL ADVANCES IN SENATE The Senate Commerce Committee has unanimously approved the Software Principles Yielding Better Levels of Consumer Knowledge (SPY BLOCK) Act, an anti-spyware bill which would prohibit the surreptitious installation of software on computers. If approved by the full Senate, the legislation will not allow software vendors to use misleading means to induce consumers to install software, prohibit software that prevents reasonable efforts to uninstall or disable it, and outlaw installing software that automatically collects and transmits information about the user without permission. In June, the House Energy and Commerce Committee passed a similar anti-spyware bill entitled the Securely Protect Yourself Against Cyber Trespass Act (SPY Act). Software Principles Yielding Better Levels of Consumer Knowledge Act: http://thomas.loc.gov/cgi-bin/bdquery/z?d108:s.2145: Securely Protect Yourself Against Cyber Trespass Act: http://thomas.loc.gov/cgi-bin/bdquery/z?d108:h.r.2929: HOUSE PASSES BILL TO CRIMINALIZE INACCURATE DOMAIN REGISTRATIONS The House of Representatives has passed a bill that imposes fines and prison terms of up to seven years upon individuals who intentionally provide inaccurate personal information to register an Internet domain, and then use that information to commit a felony such as spamming or copyright infringement. The legislation would not penalize individuals who provide false registration information simply to keep their identitities anonymous or protect their information from spammers and criminals. The bill now moves to the full Senate for consideration. 