320 likes | 411 Views
Privacy CSC385. Kutztown University Fall 2009 Oskars J. Rieksts. Notes on Privacy. Based on Lawrence Snyder Fluency in Information Technology Augmented with my notes See also: http://faculty.kutztown.edu/rieksts/385/topics/privacy/notes.html. Outline. Privacy basics
E N D
PrivacyCSC385 Kutztown University Fall 2009 Oskars J. Rieksts
Notes on Privacy • Based on Lawrence Snyder • Fluency in Information Technology • Augmented with my notes • See also: http://faculty.kutztown.edu/rieksts/385/topics/privacy/notes.html Kutztown University
Outline • Privacy basics • Threats to privacy • Personal information control • FIP principles • Privacy practices • Cookies • Cryptography • Data mining Kutztown University
Privacy Basics • Definition – “The right of people to choose freely under what circumstances and to what extent they will reveal themselves to others.” – p. 481 • Rieksts: Privacy is the cornerstone of selfhood • Modern devices & privacy • Chief Justice, Louis Brandeis Kutztown University
Basis of Privacy Conflict • Modern life requires • Revelation of information • Financial transactions • Applications • Medical services • Etc. Kutztown University
Basic Privacy Issue • Ownership of information • Related IT ownership issue • Your machine • Contents of your machine • Files • Software Kutztown University
Threats to Privacy • Criminal element • Identity theft • Cyber-stalking • Organized crime • Business & industry • Marketing • Employment Kutztown University
Threats to Privacy • Enemies of public safety • Governments • Totalitarian regimes • Overzealous public servants • Social engineers Kutztown University
Spectrum of Personal Information Control • The lens • Transaction produces information • Basic categories • No uses • Opt-In or Approval • Opt-Out or Objection • Internal use only • No limits Kutztown University
Storage & Usebeyond transactional necessity • No uses • Delete information • Upon completion of transaction • Opt-In • Permission must be requested • Explicit approval required Kutztown University
Storage & Usebeyond transactional necessity • Opt-Out • S&U is OK • Unless specifically objected to • Internal use only • S&U OK • Only for business itself • No limits Kutztown University
FIP Principles • FIP = fair information practices • Standard 8 point list • Developed in 1980 by OECD • OECD = Organization of Economic Cooperation and Development Kutztown University
Eight FIP Principles • Limited Collection • Quality • Purpose • Use Limitation • Security • Openness • Participation • Accountability Kutztown University
Limited Collection Principle • Limits to data collected • Collection by • Fair means • Lawful means • Knowledge & consent required • If possible • When appropriate Kutztown University
Quality Principle • Relevance • Data must be relevant • to collection purpose • Data must be • Accurate • Complete • Up to date Kutztown University
Purpose Principle • Purpose of collection stated • Use limitation • Use limited to . . • stated purpose Kutztown University
Use Limitation Principle • Data not to be disclosed • No use for other purposes • Unless . . • Consent given by individual • Authority granted by law Kutztown University
Security Principle • Data controller must . . • Exercise reasonable security measures Kutztown University
Openness Principle • Data collection policies & practices . . • Open to the public • Public knowledge of . . • Existence of data • Kind of data • Purpose/use of data • Identity & contact information of • Data controller Kutztown University
Participation Principle • Individual able to determine . . • Whether data controller has information • What the information is • Denial of access can be challenged • Information can be challenged Kutztown University
Accountability Principle • Data controller accountable . . • for FIP Principles compliance Kutztown University
Privacy Practices – EU • European Union • Accepts OECD FIP principles • Has European Data Protection Directive • EU citizen protection standard • Extends beyond EU borders Kutztown University
Privacy Practices – U.S.A. • Sectoral approach • Freedom of Information Act – 1966 • Privacy Act of 1974 (wrt government) • Electronics Communication Privacy Act – 1986 • Video Privacy Protection Act – 1988 • Telephone Consumer Protection Act – 1991 • Drivers Privacy Protection Act – 1994 Kutztown University
Freedom of Information Act – Links • One • Two • Three • Four Kutztown University
Privacy Act of 1974 – Links • One • Two • Three Kutztown University
Electronic Communications Privacy Act • One • Two • Three • Efforts to update Kutztown University
Video Privacy Protection Act • One • Two • Three Kutztown University
Telephone Consumer Protection Act • One • Two • Three Kutztown University
Driver Privacy Protection Act • One • Two • Three • Four Kutztown University
Privacy Advocacy • EPIC • Electronic Privacy Information Center • About • Home Page • Privacy Rights Clearinghouse • Electronic Frontier Foundation • About • Wikipedia Kutztown University
Cookies • 7-field record • Uniquely identifies . . • customer session on website Kutztown University
Cookies – 3rd Party Problem • Advertiser on contacted website • Client/server relationship with customer • Allows 3rd party cookies • Placed • Accessed • from various sites • Discussion Kutztown University