Advertise On EU-Digest

Annual Advertising Rates
Showing posts with label Privacy Rights. Show all posts
Showing posts with label Privacy Rights. Show all posts

2/25/18

USA: IS US Government Spyware Breaching Foreign Privacy Laws? Revealed: Two Secret Cogs In The FBI National Surveillance Machine - by Thomas Fox-Brewster

After 9/11, federal law enforcement and intelligence agencies were roundly criticized for failing to coordinate information that, in the aggregate, might have allowed the government to stop the attacks before they happened. Since then, the pendulum has swung in the opposite direction. The FBI has built a secretive and guarded intelligence operation, the tentacles of which stretch beyond its core task of domestic law enforcement and into the construction of the great American panopticon.

Despite the almost complete lack of transparency surrounding that effort, Forbes has uncovered two previously-undisclosed units that sources say form crucial parts of the FBI's surveillance machinery.

Known as the FBI Collections Operations Group and the FBI WiFi Group, they appear in virtually no public records. Google searches for the names return nothing. Not a single LinkedIn profile contains a reference to either.

And with the unearthing of these two units, civil liberties activists, legal experts and even former intelligence analysts are crying foul about the possibility of widespread domestic surveillance occurring across America with zero oversight.

Forbes learned about the existence of the furtive Collections Operations Group (insiders call it "the COG") from the results of a freedom of information act request filed with the FBI in 2017. That FOIA filing concerned a deal signed last year between tech contractor CDW Government and the Data Intercept Technology Unit (DITU, pronounced "dee-too") for $1.1 million in services. DITU, part of the Operational Technology Division in Quantico, Virginia, is one of the most clandestine divisions within the FBI, helping gather crucial data for investigations and intelligence. The OTD is the overarching body that oversees bleeding edge tech development for the entire FBI.

The FBI confirmed to Forbes that the COG is a sub-unit within DITU. The agency refused to comment on the specific nature of the group and its operations. But there's some tantalizing new information nonetheless: according to the FOIA response, the COG's mission "is to provide tools, expertise and solutions to effect lawfully-authorized electronic surveillance of data communications on today's evolving local area network and internet technologies. The COG is responsible for the procurement, development and deployment of network equipment to assist in electronic surveillance to various field offices and OGAs."

OGA stands for “other government agency.” As previously revealed in NSA files leaked by Edward Snowden in 2013 detailing the now-infamous PRISM espionage initiative, one of DITU's roles sees it collect data from technology and telecom companies (whether that's Facebook, Google, Microsoft or your phone and internet provider) before turning it over to intelligence agencies (which could be the DIA, CIA and NSA).

The COG is core to that intelligence sharing both within the FBI and outside the agency. Sources tell Forbes the COG is a go-between surveillance shop, setting up spy tools and associated networking across the FBI or whatever agency demands its services, and helping shift intel between them. Forbes spoke with multiple sources in the security and intelligence fields who claimed knowledge of DITU and its sub-units. All asked to remain anonymous.

"Think of it like this: it's a technical group that oversees technical capabilities so that when lawful requests are issued on providers, and the data they return needs to be analyzed, it can be converted to human-readable formats," said a person with knowledge of the COG. “Often, raw network data comes back in many forms and these teams work to make sure that the special agents and investigative teams can properly interpret the data."

What kinds of equipment does the COG build and deploy in order to capture data? Sources who previously worked in the national intelligence community say it was probably technology such as pole-mounted boxes that capture wireless network traffic, or devices installed at ISPs that vacuum up data.

As for the WiFi Group, it's another DITU sub-unit "responsible for the deployment and installation of communications equipment to support ongoing criminal, counter-terrorism and foreign counter-intelligence investigations," according to a FOIA response for another CDW contract. That 2014 deal, for unspecified surveillance equipment, was worth just $26,571.

It's easy to see why the FBI would want such capabilities. But, looking at the COG, cross-agency sharing of intelligence and surveillance resources conducted by a group unknown to the public (until now) has civil liberties folk worried.

"Unfortunately law enforcement agencies spying on their own citizens' communications is a trend that is steadily increasing around the world. When these groups operate in secret there is no way for the public to confirm that they are operating with all due legal restraint as required by their nation's laws," said Cooper Quintin, security researcher and technologist at the Electronic Frontier Foundation.

"There's far too much secrecy when it comes to the FBI's spying on Americans' internet activities. This surveillance has the potential to be very broad, putting large amounts of sensitive information in the hands of an agency responsible for domestic criminal investigations. Americans need to know more about the reach of this surveillance, how it affects them and how it is legally justified," added Patrick Toomey, staff attorney at the American Civil Liberties Union's National Security Project.

One former intelligence agency analyst who reviewed the information Forbes gathered on the COG and DITU said it appeared they were carrying out signals intelligence (SIGINT), the collection and analysis of traffic as it crosses the internet. This, intelligence geeks know, falls under the charter and thus is typically the domain of the NSA, not the FBI. (This may simply come down to semantics; SIGINT could apply to any form of data collection and analysis. Some disagree the FBI is collecting and analyzing giant sets of internet data like other government intel agencies. As one source put it: "They are not doing hardcore, NSA-type SIGINT").

"The fact that the FBI operates in multiple spaces makes this SIGINT capability extremely concerning for civil rights," the ex-analyst said. "The concerns were much less when they had the wall between intel and law enforcement… Now that there's no 'wall' separating the two, you're left to trust that information gained from intelligence activities is not being used for law enforcement."

And there's more to worry about than parallel construction. "Simply making it easier to share this data and information also worries us as in this era of big data," Joseph Lorenzo-Hall, chief technologist at the Center for Democracy & Technology, told Forbes. "There are very few assurances that the data is protected well and won't essentially be used at some point in a panopticon-like mechanism that we're seeing in places like China, where every little detail controls opportunities available to certain segments of society."

If it's to stick to the letter of the law, government agencies must obtain court approval prior to spying on targets in a criminal investigation, whether or not that investigation is borne on the back of snooping in another probe. "To put it conceptually, the government needs to have shown probable cause to obtain the court’s approval for each criminal investigation it is conducting against the individual," said a legal representative for a major technology company.

Whatever the ethical quandaries at play, the nature of DITU and its sub-units' work is, on the face of it, entirely legal. "It's certainly true that pursuant to law, the bureau can and does collect a broad range of metadata for use in both criminal cases and domestic intelligence work," said Daniel Richman, professor of law at Columbia Law School. Richman is a confidant of former FBI director James Comey, as revealed last year when he leaked memos detailing conversations Comey had with President Trump.

Richman added: "And pursuant to warrants, it has engaged in various network exploitations, what some call 'legal hacking'. Whether or not you call that collection SIGINT, the Bureau is the primary domestic intelligence agency."

The FBI declined to comment for this Forbes article.

For the complete Forbes report click here: Revealed: Two Secret Cogs In The FBI National Surveillance Machine

6/3/15

USA - Privacy Rights - NSA: Obama signs landmark bill reforming NSA surveillance

US President Barack Obama signed into law on Tuesday landmark legislation passed by Congress just hours earlier putting an end to the government's bulk telephone data dragnet. US President Barack Obama signed into law on Tuesday legislation passed by Congress earlier in the day reforming a government surveillance programme that swept up millions of Americans’ telephone records.

Reversing security policy in place since shortly after the Sept. 11, 2001 attacks, the bill ends a system exposed by former National Security Agency contractor Edward Snowden. The spy agency collected and searched records of phone calls looking for terrorism leads but was not allowed to listen to their content.

Passage of the USA Freedom Act, the result of an alliance between Senate Democrats and some of the chamber’s most conservative Republicans, was a victory for Obama, a Democrat, and a setback for Senate Republican Majority Leader Mitch McConnell.

Read more: Americas - Obama signs landmark bill reforming NSA surveillance - France 24

2/4/15

Privacy Rights versus Corporate Objectives: Europe’s Expanding ‘Right to Be Forgotten’ - "Mixing Apples and Pears"

European officials are pushing an idea that will encourage autocrats everywhere to demand greater censorship on the Internet. They want companies like Google and Microsoft to abide by the European Union’s recently recognized legal principle of a “right to be forgotten” not just in the 28 countries of the union but everywhere.

In May, the European Court of Justice ruled that individuals could ask Internet search sites to remove links to web pages that contained “inadequate, irrelevant or no longer relevant” information about them in the results page for searches of their names. Google, which is the dominant search engine in Europe, has removed more than 250,000 links since that ruling.

But the company says it only removes links from results displayed on its websites for European countries like Google.fr in France or Google.de in Germany but not from results on its non-European sites, including Google.com, the primary site in the United States.

European policy makers say this approach fails to protect the “right to be forgotten” because it is easy for people to search on Google.com or using virtual private networks to find links that are not displayed in their countries.

As a result, European regulators and judges are demanding that Google and other companies remove links covered by the right-to-be-forgotten principle from all results pages in all countries and regardless of where the search takes place.

This would allow Europeans to decide what information citizens of every other nation can access. Google has, so far, refused to comply with these demands, but it may find it harder to resist once European officials enshrine the right to be forgotten into law, which officials are negotiating now.

The European position is deeply troubling because it could lead to censorship by public officials who want to whitewash the past. It also sets a terrible example for officials in other countries who might also want to demand that Internet companies remove links they don’t like.

For example, the military government of Thailand could decide that it wants Facebook and Twitter to remove content that runs afoul of that country’s strict lèse-majesté law everywhere in the world. Autocratic leaders like Vladimir Putin of Russia and Recep Tayyip Erdogan of Turkey might feel emboldened to try to silence critics not just in their own countries but elsewhere by levying fines on Internet businesses or blocking their websites entirely.

European officials argue that it is unfair to liken the right to be forgotten to attempts to muzzle free speech in other countries. After all, the European Union is trying to protect the privacy of individuals, not squelch public debate.

But if European regulators get their way, Internet companies would be left in the awkward position of determining when government requests to censor information universally are legitimate and when it is not. No business should have that power.

Note EU-Digest: The New York Times is mixing Apples and Pears - what is in question are individual privacy right's of European Citizens, not the right of Censorship by Governments, as the New York Times implies. In other words, if an individual in Europe does a search on Google, that information should not be used by Google, or anyone else for commercial purposes, or any other other purpose, for which the individual did not give any prior approval. Pretty straight-forward
.
Read more: Europe’s Expanding ‘Right to Be Forgotten’ - NYTimes.com

11/27/14

Is Google Too Big? Google should be broken up, say European MPs

The European Parliament has voted in favour of breaking Google up, as a solution to complaints that it favours is own services in search results.
Politicians have no power to enforce a break-up, but the landmark vote sends a clear message to European regulators to get tough on the net giant.

US politicians and trade bodies have voiced their dismay at the vote.

The ultimate decision will rest with EU competition commissioner Margrethe Vestager.

She has inherited the anti-competitive case lodged by Google's rivals in 2010.
Google has around 90% market share for search in Europe and rivals asked the commission to investigate four areas:
  • The manner in which Google displays its own vertical search services compared with other, competing products
  • How Google copies content from other websites - such as restaurant reviews - to include within its own services
  • The exclusivity Google has to sell advertising around the search terms people use
  • Restrictions on advertisers from moving their online ad campaigns to rival search engines
Predecessor Joaquin Almunia tried and failed to settle the case. A series of concessions made by Google were rejected, leading Mr Almunia to suggest that the only option was a fine. This could be up to $5bn.

The EU Commission has never before ordered the break-up of any company, and many believe it is unlikely to do so now.

Note EU-Digest: but the EU Commission better do something to give smaller European search engines and similar companies as Google at least a fair chance to succeed.  Right now Google certainly has become a "Big Untouchable Brother" collecting a lot of private and personal date and selling this information to companies which not always have the best interest in mind for the well-being of private European citizens.

Read more: BBC News - Google should be broken up, say European MPs

3/10/14

Government Spying: Snowden Says Technology Companies Should Lead on Data Encryption - by Adam Satariano

Edward Snowden, who leaked classified documents revealing the surveillance activities of the National Security Agency, said technology companies need to take a leadership role in improving encryption tools.

“There’s a technical response that needs to occur,” said Snowden, speaking through a video feed to a packed room of more than 3,000 people today at the South by Southwest Interactive conference in Austin, Texas. Technology companies can add layers of security that make it harder for intelligence agencies to scour for data, and can do it faster than new surveillance-oversight laws can be implemented, he said.

Snowden is now a fugitive in Russia to avoid arrest following last year’s release of the documents, which disclosed how global spy agencies collect vast amounts of data about phone calls and online activities. The revelations frayed U.S. relationships with countries such as Brazil and Germany and set off a global debate about whether the government is overstepping its authority and violating privacy to bolster security.

The leaks from Snowden, a former NSA contractor, showed that the U.S. had been collecting phone records as well as data from companies such as Google Inc. (GOOG), Facebook Inc. and Apple Inc. The disclosures made Snowden a hero to some people who want to see government activities reined in, while others, including U.S. President Barack Obama, say his actions compromised efforts to combat terrorism.

Security and privacy have been main themes of South by Southwest this year. Known as the conference that helped catapult Twitter Inc. to popularity, the gathering typically focuses on the discovery of new social-networking companies. Instead, this year’s event has focused more on the drawbacks and consequences of sharing personal information online.

Wikileaks founder Julian Assange spoke at the conference on March 8 and said the group would soon release a new trove of classified information. He didn’t disclose the timing or the topic of the material because he said he didn’t want to give the subjects a chance to prepare.

Other speakers, including Google Chairman Eric Schmidt, have discussed the impact of Snowden’s leaks. Schmidt said the material alerted his company to the fact the U.S. government was intercepting data from Google’s servers. Schmidt said the company has since enhanced its encryption and is “pretty sure” the government can’t access the data.

Still, he said the company must comply with court orders for information. Schmidt said there must be a balance between transparency and security, because the government data being disclosed could put lives at risk. Assange and Snowden’s release of classified information have made them “celebrities,” Schmidt said, and may spawn copycat efforts, increasing the risk for harm if the disclosures aren’t done carefully.

Read more: Snowden Says Technology Companies Should Lead on Data Encryption - Bloomberg

12/28/13

EU-US Trade Negotiations: The lies behind this transatlantic trade deal-by George Monbiot

Panic spreads through the European commission like ferrets in a rabbit warren. Its plans to create a single market incorporating Europe and the United States, progressing so nicely when hardly anyone knew, have been blown wide open. All over Europe people are asking why this is happening; why we were not consulted; for whom it is being done.

They have good reason to ask. The commission insists that its Transatlantic Trade and Investment Partnership should include a toxic mechanism called investor-state dispute settlement. Where this has been forced into other trade agreements, it has allowed big corporations to sue governments before secretive arbitration panels composed of corporate lawyers, which bypass domestic courts and override the will of parliaments.

This mechanism could threaten almost any means by which governments might seek to defend their citi
zens or protect the natural world. Already it is being used by mining companies to sue governments trying to keep them out of protected areas; by banks fighting financial regulation; by a nuclear company contesting Germany's decision to switch off atomic power. After a big political fight we've now been promised plain packaging for cigarettes. But it could be nixed by an offshore arbitration panel. The tobacco company Philip Morris is currently suing Australia through the same mechanism in another treaty.

No longer able to keep this process quiet, the European commission has instead devised a strategy for lying to us. A few days ago an internal document was leaked. This reveals that a "dedicated communications operation" is being "co-ordinated across the commission". It involves, to use the commission's chilling phrase, the "management of stakeholders, social media and transparency". Managing transparency should be adopted as its motto.

The message is that the trade deal is about "delivering growth and jobs" and will not "undermine regulation and existing levels of protection in areas like health, safety and the environment". Just one problem: it's not true.

From the outset, the transatlantic partnership has been driven by corporations and their lobby groups, who boast of being able to "co-write" it. Persistent digging by the Corporate Europe Observatory reveals that the commission has held eight meetings on the issue with civil society groups, and 119 with corporations and their lobbyists. Unlike the civil society meetings, these have taken place behind closed doors and have not been disclosed online.

Though the commission now tells the public that it will protect "the state's right to regulate", this isn't the message the corporations have been hearing. In an interview last week, Stuart Eizenstat, co-chair of the Transatlantic Business Council – instrumental in driving the process – was asked if companies whose products had been banned by regulators would be able to sue.

Yes. "If a suit like that was brought and was successful, it would mean that the country banning the product would have to pay compensation to the industry involved or let the product in." Would that apply to the European ban on chicken carcasses washed with chlorine, a controversial practice permitted in the US? "That's one example where it might."

What the commission and its member governments fail to explain is why we need offshore arbitration at all. It insists that domestic courts "might be biased or lack independence", but which courts is it talking about? It won't say. Last month, while trying to defend the treaty, the British minister Kenneth Clarke said something revealing: "Investor protection is a standard part of free-trade agreements – it was designed to support businesses investing in countries where the rule of law is unpredictable, to say the least." So what is it doing in an EU-US deal?

Why are we using measures designed to protect corporate interests in failed states in countries with a functioning judicial system? Perhaps it's because functioning courts are less useful to corporations than opaque and unjust arbitration by corporate lawyers.

As for the commission's claim that the trade deal will produce growth and jobs, this is also likely to be false. Barack Obama promised that the US-Korea Free Trade Agreement would increase US exports by $10bn. They immediately fell by $3.5bn. The 70,000 jobs it would deliver? Er, 40,000 were lost. Bill Clinton promised that the North American Free Trade Agreement would create 200,000 new jobs for the US; 680,000 went down the pan. As the commentator Glyn Moody says: "The benefits are slight and illusory, while the risks are very real."

So where are our elected representatives? Fast asleep. Labour MEPs, now frantically trying to keep investor-state dispute mechanisms out of the agreement, are the exception; the rest are in Neverland. The Lib Dem MEP Graham Watson wrote in his newsletter, before dismissing the idea: "I am told that columnists on the Guardian and the Independent claim it will hugely advantage US multinational companies to the detriment of Europe." We said no such thing, as he would know had he read the articles, rather than idiotically relying on hearsay. The treaty is likely to advantage the corporations of both the US and the EU, while disadvantaging their people. It presents a danger to democracy and public protection throughout the trading area.
 
Caroline Lucas, one of the few MPs interested in the sovereignty of parliament, has published an early-day motion on the issue. It has so far been signed by seven MPs. For the government, Clarke argues that to ignore the potential economic gains "in favour of blowing up a controversy around one small part of the negotiations, known as investor protection, seems to me positively Scrooge-like".

Quite right too. Overriding our laws, stripping away our rights, making parliament redundant: these are trivial and irrelevant beside the issue of how much money could be made. Don't worry your little heads about it.

Read more: The lies behind this transatlantic trade deal | George Monbiot | Comment is free | The Guardian

11/4/13

EU-US to resume free trade talks despite NSA tension - data protection and online privacy rights questions major stumbling block - by Juergen Baetz

The United States and the European Union will resume free trade negotiations next week despite heightened tension between the two over the alleged spying activities of the U.S. National Security Agency.

The second round of the trans-Atlantic talks will have to make up ground lost when a previous session was canceled because of the partial shutdown of the U.S. government.

The European Commission, the 28-nation bloc's executive arm, said Monday that the talks will go ahead and that next week's round in Brussels is set to focus on services, investment, energy and regulatory issues.

A broad EU-US trade deal could provide a boost to growth and jobs on both sides of the Atlantic by eliminating tariffs and regulatory barriers that are hampering business. The trade volume in goods and services between the two economies — representing almost half of global output — totaled 800 billion euros ($1.08 trillion) last year.

While data protection and online privacy rights aren't officially on the agenda of the talks, top EU officials have made it clear that they will push for tougher rules in the U.S. in parallel to the trade negotiations.

Both sides had hoped initially to reach a broad agreement by the end of 2014, but that schedule is now considered highly ambitious as significant hurdles remain on issues like agriculture, industry regulation and other fields.

Read more: BRUSSELS: EU, US to resume free trade talks despite tension | Business | NewsObserver.com

10/22/13

The Netherlands-Privacy Rights Violations:US taps 1.8 million Dutch phone numbers-very few taps related to terrorism

DutchNews NL reports that the American National Security Agency tapped 1.8 million Dutch telephones in one month alone as part of its Boundless Informant surveillance program..

The raw information was first published by Der Spiegel in June but has now been interpreted by Dutch technology website Tweakers following publication in Le Monde.

Between the beginning of December and beginning of January, 1.8 million Dutch phone numbers were tapped into by the NSA, recording information about number and possibly location, Tweakers said.

The numbers were compared against a database of suspect numbers and, Tweakers says, if a number was on the list, calls to and from the number were listened in to.

In Germany, 500 million numbers were picked up by the NSA and in France 70 million. Paris has now summoned the US ambassador to explain events. According to Le Monde, documents show the NSA was allegedly targeting not only terrorist suspects but politicians, business people and others.

The raw information comes from whistleblower Edward Snowden. VVD parliamentarian Klaas Dijkhoff said the news that the US is obtaining telephone information in the Netherlands on such a broad scale is ‘disappointing’.

'If it was the Chinese or the Russians, then no-one would be surprised,’ he is quoted as saying by Tweakers ‘But this is an ally and that makes it extra disappointing.’

The Netherlands is already the most heavily phone-tapped country in the world. The number of phone taps rose 3% to nearly 25,500 last year, according to justice ministry figures. And the number of requests for information about phone calls - such as the location calls were made from - reached almost 57,000, up 10% on 2011.

The above  figures do not include taps by the Dutch security services.

The question the EU Commission and Parliament should pose, and so far have not ; "why would the EU want to negotiate a comprehensive and  far reaching trade agreement with the US when they can't be trusted and as a matter of fact even have been caught bugging offices of the EU in Bruxelles and  the US ?"

The Finance Tracking Program (TFTP) of 2010 agreed on by the EU and US, which supplies bank and credit card transaction information to the U.S. treasury in an apparent effort to trace funding to terrorist groups, should probably also be scrapped now it has became evident the Americans have been abusing the agreement. 

Almere-Digest

6/9/13

Privacy Protection: How to secure and encrypt your email and other communications from PRISM and the NSA. - by Ryan Gallagher

Not every communication can be tracked and eavesdropped on by the government, however, and there are ways to reduce the chances of being snooped on. First, instead of browsing the Internet in a way that reveals your IP address, you can mask your identity by using an anonymizing tool like Tor or by connecting to the Web using a Virtual Private Network. Additionally, you can avoid Google search by using an alternative like Ixquick, which has solid privacy credentials and says it does not log any IP addresses or search terms or share information with third parties.

When it comes to sending emails, if you are using a commercial provider that has been linked to the PRISM spy initiative, you can throw a spanner in the NSA’s works by learning how to send and receive encrypted emails. PGP or its free cousin GPG are considered the standard for email security, and these can be used to both encrypt and decrypt messages—meaning you can thwart surveillance unless you are unlucky enough to have Trojan spyware installed on your computer.

Novice computer users learning how to use PGP or GPG may find it a daunting prospect at first, but there are plenty of tutorials online for both Mac and Windows users that can help guide you through the process. For journalists working with confidential sources, attorneys seeking to ensure attorney–client privilege, or others whose work requires secure communications, learning how to use PGP or GPG is an absolute necessity in 2013. Organizations seeking to protect themselves from email grabs could go one step further: They could take more control of their messages by setting up their own email server instead of relying on a third-party service, helping ensure no secret court orders can be filed to gain covert access to confidential files. And if you need to store private documents online, you can use Cloudfogger in conjunction with Dropbox.

For instant messaging and online phone or video chats, you can avoid Microsoft and Google services like Skype and Gchat by adopting more secure alternatives. Jitsi can be used for peer-to-peer encrypted video calls, and for encrypted instant message chats you can try using an “off the record” plugin with Pidgin for Windows users or Adium for Mac. Like using PGP encryption, both Pidgin and Adium can take a little bit of work to set up—but there are tutorials to help ease the pain, like this for setting up Adium and this tutorial for Pidgin.

As for phone calls, if you want to shield against eavesdropping or stop the NSA obtaining records of who you are calling and when, there are a few options. You could use an encryption app like Silent Circle to make and receive encrypted calls and send encrypted texts and files, though your communications will be fully secure only if both parties to the call, text or file transfer are using the app. Other than Silent Circle, you could try RedPhone for making encrypted calls or TextSecure for sending encrypted texts.

Read more: How to secure and encrypt your email and other communications from PRISM and the NSA.

8/2/12

EU investigates and - "Oops: Google admits it didn’t delete Street View data after all" - by Cassandra Vinnograd and Raphael Satter

After being caught spying on people across Europe and Australia with its Wi-Fi-slurping Street View cars, Google had told angry regulators that it would delete the ill-gotten data.

Google broke its promise.

Britain’s Information Commissioner’s Office (ICO) received a letter from Google in which the company admits it kept a “small portion” of the electronic information it had been meant to get rid of.

“Google apologizes for this error,” Peter Fleischer, Google’s global privacy counsel, said in the letter, which the ICO published on its website.

The ICO said in a statement that Google Inc. had agreed to delete all that data nearly two years ago, adding that its failure to do so “is cause for concern.”

Other regulators were less diplomatic, with Ireland’s deputy commissioner for data protection, Gary Davis, calling Google’s failure “clearly unacceptable.” Mr. Davis said his organization had conveyed its “deep unhappiness” to Google and wants answers by Wednesday.

Google said that other countries affected included France, Belgium, the Netherlands, Norway, Sweden, Finland, Switzerland, Austria and Australia. Attempts to reach regulators in several of those countries weren’t immediately successful Friday.

Google Inc. also admitted for the first time its "Street View" cars around the world accidentally collected more personal data than previously disclosed - including complete e-mails and passwords - potentially breathing new life into probes in various countries.

Note EU-Digest: "Interestingly U.S. regulators looking at Google Inc's data grab by "Street View" cars have decided to end their inquiry, noting "improvements that the search company has made to build consumer privacy into its corporate structure."

Read more: Oops: Google admits it didn’t delete Street View data after all - The Globe and Mail

4/19/12

EU Parliament to vote over sharing data with US - "EU Citizens fundamental right to data protection in jeopardy" says Commission

The European Parliament will today vote on new legislation which would give US authorities access to information about airline passengers.

MEPs meeting in Strasbourg will decide whether they will allow the US Department of Homeland Security to see data "routinely" collected by airlines including passenger names, addresses, credit card details and seat numbers.

Sensitive data such as a person's religious beliefs, sexual orientation and racial origin could also be used in "exceptional" circumstances.

The controversial Bill on Passenger Name Records (PNR) data would cover all flights to or from the US and under the proposed agreement US authorities would retain the data for up to 15 years.

The European commission’s own lawyers noted last year that the agreement is unlawful and expressed "grave doubts" that the deal would comply with the fundamental right to data protection.

For more EU to vote over sharing data - The Irish Times - Thu, Apr 19, 2012

9/3/11

Google Confirms It Aims to Own Your Online ID - by Mathew Ingram

Ever since Google (GOOG) launched its new Google+ social network, we and others have pointed out that the search giant clearly has more in mind than just providing a nice place for people to share photos of their pets. For one thing, Google needs to tap into the “social signals” that people provide through networks such as Facebook so it can improve its search results. There’s a larger motive, too: As Chairman and former Chief Executive Officer Eric Schmidt admitted during an interview in Edinburgh over the weekend, Google is taking a hard line on the real-name issue because it sees Google+ as an “identity service” or platform on which it can build other products.

Schmidt’s comments came during an interview with Andy Carvin, the National Public Radio digital editor who has become a one-man newswire during the Arab Spring revolutions. Carvin asked the Google chairman about the company’s reasoning for pushing its real-name policies on Google+—a policy that many have criticized (including us) because it excludes potentially valuable viewpoints that might be expressed by political dissidents and others who prefer to remain anonymous. In effect, Schmidt said Google isn’t interested in changing its policies to accommodate those kinds of users: If people want to remain anonymous, he said, then they shouldn’t use Google+.

Whatever its specific interests, Google clearly sees Facebook as a competitive threat, not just because it has developed a gigantic social network with hundreds of millions of devoted users, but because it has also become a kind of identity gatekeeper—with tens of millions of those devoted users happily logging into other websites and services with their Facebook credentials, thus sending Facebook valuable data about what they are doing and where they are doing it. The ubiquitous “like” button provides even further data, something Google is also trying to mimic with its +1 buttons.Whatever its specific interests, Google clearly sees

Facebook as a competitive threat, not just because it has developed a gigantic social network with hundreds of millions of devoted users, but because it has also become a kind of identity gatekeeper—with tens of millions of those devoted users happily logging into other websites and services with their Facebook credentials, thus sending Facebook valuable data about what they are doing and where they are doing it. The ubiquitous “like” button provides even further data, something Google is also trying to mimic with its +1 buttons.
For more: Google Confirms It Aims to Own Your Online ID - BusinessWeek

10/23/10

Italy-Britain-Germany: Google admits Street View cars collected e-mails, passwords

After analyzing the unencrypted WiFi payload data captured by its Street View cars, Google now admits that the system captured entire e-mails, URLs and even user passwords. The admission came in the form of a blog post by Alan Eustace, senior vice president of engineering and research at Google


For more: Google admits Street View cars collected e-mails, passwords | ZDNet

7/8/10

EU capitulating on "anti-terror" finance information deal with US

The European parliament was poised Thursday to approve a bank data sharing scheme that the United States says is crucial to fight terrorism after securing safeguards to protect the privacy of Europeans.
The United States will again have access to the banking information from August 1 after European MPs, as expected, approve a new deal that was signed by Brussels and Washington last week. European lawmakers' main concern was that personal information, including data from electronic bank payments, would be used by US authorities, held for too long and handed on to other governments (or to the private sector).
Under the new deal, Europol, the European police organisation, will check the validity of US requests.

The United States also agreed to allow the presence of an EU official in Washington who will be able to monitor the use of banking data of EU citizens by US authorities. EU citizens will also be able to contest the use of their data before US courts.
But the head of Europe's privacy watchdog, the European Data Protection Supervisory, said he still had reservations. The main problem is that Washington receives large chunks of data because it is technologically impossible to select bits of information, Hustinx said.
"We are presently accepting an arrangement which allows for much more information than is necessary because we simply cannot focus better," he said.

The EU wants to set up its own Terrorist Finance Tracking Programme, which would enable it to sift through data on its own and select what to send to Washington. Cecilia Malmstroem, the EU commissioner for home affairs, said she would make proposals by early 2011. Officials said a European programme could be operational in three to five years.

Note EU-Digest:  This agreement is a capitulation by the EU to US demands. The US argument of increased security risks if this agreement is not signed is a complete farce. Security experts claim the whole US security system is riddled with problems. These problems are far more dangerous than the lack of having EU citizen's Privacy data. There also is no reciprocity clause in this new proposed agreement, whereby the EU could get similar data about US citizens. These kinds of agreements which directly affect EU citizens in reality require either a referendum in the EU or approval by each EU members parliament. The EU parliament should reject it regardless of what they have been told by Mr. Joe Bidden. This proposed agreement which is being sneaked into the EU parliament during its summer recess is not only a capitulation to US demands, but also a flagrant infringement on EU sovereign citizens privacy rights. It should be rejected.

EU to approve anti-terror finance deal with US - Latest news around the world and developments close to home - MSN Malaysia News

5/24/10

EU Parliament: - plenary session says proposal bank and airplane passenger data transfer from EU to US not acceptable in its present form

Any new agreement on providing bank data to the United States - for example via the SWIFT system - must avoid "bulk data" transfers until they can be processed within the EU, warned MEPs on Wednesday. As for Passenger Name Records, Parliament opted to postpone its vote on the existing agreements with the United States and Australia and called for those accords be renegotiated on the basis of new criteria.

On the issue of bank data transfers, Parliament argues in a resolution adopted by show of hands, that bulk data transfers infringe EU legislation. It urges the Council and Commission to "address this issue properly in the negotiations". In addition, the new agreement should include "strict implementation and supervision safeguards, monitored by an appropriate EU-appointed authority" on the day-to-day extraction of and use by the US authorities of all such data. The maximum storage period must not exceed five years and the data may not be disclosed to third countries.

n the medium term, an EU judicial authority should oversee the extraction of data in the EU. Meanwhile, select EU personnel should take part in the oversight of the extraction process in the USA. Reciprocity would require the Americans to allow EU authorities to obtain and use data stored in servers in the US.

For more: Brussels plenary session - 5-6 May, 2010

8/13/09

American Civil Liberties Union : US Government Proposes Massive Shift In Online Privacy Policy

For the complete report from the American Civil Liberties Union click on this link

The American Civil Liberties Union submitted comments today to the Office of Management and Budget (OMB) opposing its recent proposal to reverse current federal policy and allow the use of web tracking technologies, like cookies, on federal government websites. Cookies can be used to track an Internet user’s every click and are often linked across multiple websites; they frequently identify particular people. The use of cookies allows a website to differentiate between users and build a database of each user’s viewing habits and the information they share with the site. Since web surfers frequently share information like their name or email address (if they’ve signed up for a service) or search request terms, the use of cookies frequently allows a user’s identity and web surfing habits to be linked. In addition, websites can allow third parties, such as advertisers, to also place cookies on a user’s computer.