Showing posts with label connected devices. Show all posts
Showing posts with label connected devices. Show all posts

Tuesday, 28 March 2017

Hacking the playroom: How can children be safe and protected in the digital world?

This year, the digital world will reach a significant milestone – Almost 50% of the world’s estimated 7.4 billion population will be online. And, according to research by UNICEF Innocenti, one-third of these will be children.

So what are the particular risks or harms that children face in an increasingly connected world? In this blog, children’s online rights expert Dr Rachel O’Connell will examine the issues  through the perspective of recent reports about connected toys. She will then consider the new European Union data protection rules, which come into force in 2018 and how these and other developments might help to provide more security, privacy and safety.



Toys that talk and listen
As connected and smart toys are being utilised by companies as marketing tools, advertising, product placement and sponsoring are increasing. For example, Cayla “the world’s first interactive doll” came in for criticism, when she was found to have in-built audio tools designed to market foods high in sugar or fat to children. You can see the video here from BEUC the European Consumer’s organisation.

Cayla was also in trouble for failing to protect children’s data and privacy. The blue-tooth enabled doll comes with a microphone to capture children’s speech which can then be analysed using a third party app.  So concerned was Germany's network watchdog by what they deemed the unlawful surveillance capability of the doll that they urged parents to destroy her:

Any toy capable of transmitting signals and surreptitiously recording audio or video without detection is unlawful. The danger, the agency claims, is that anything a child or someone else says in the vicinity of the doll can be transmitted without parents' knowledge. Also, lack of network security could allow the toy to be turned into a listening device, the agency suggests.

To be clear…
The company that produced the Cayla doll would have had numerous contractual relationships between a range of third parties, which include data processors, app platforms, marketing technology and advertising platforms, data management platforms, data analytics, and speech recognition software.

While blanket permission for these businesses to process a child’s data will have been given, when a parent clicks ‘I Agree’ to the Terms of Service and Privacy Policy, the limits to this approach to informed consent have been well documented

Rights of the child
As well as advertising and security, regulators are concerned by violations of the legal protection of children’s rights afforded under the UN Convention of the rights of the child , including Article 16:  

·         No child shall be subjected to arbitrary or unlawful interference with his or her privacy, family, or correspondence, nor to unlawful attacks on his or her honour and reputation.
·         The child has the right to the protection of the law against such interference or attacks.

However, as the UK Information Commissioner's Office (ICO) highlighted, under existing data protection legislation there was ‘little that could be done to prevent unscrupulous third parties from harvesting a child’s data and using it for inappropriate purposes’[1].

The new General Data Protection Regulation (GDPR), which comes into force in May 2018 stipulates why children’s rights merit specific protection with regards to their personal data:

“Children may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child.”

Article 8 of GDPR also states that where a child is below the age of 16 years, processing of their personal data is only lawful if consent is given or authorised by the holder of parental responsibility over the child. Member states can choose to lower the age at which parental permission is required to 13 years of age, but no lower.

The GDPR specifically states that separate consent will be needed for different processing operations – this means that in the future it will not only be a requirement to inform consumers of who the data processors are and obtain consent, they must also enable consumers to withdraw this permission at any point.

Privacy by design
 A key principle underpinning  GDPR is that businesses will need to adhere to the principle of Privacy by Design, which requires privacy and data protection compliance during the product or service design stage, instead of bolting them onto the end. These rules will have a reach far beyond the EU as any business processing EU citizens’ data will have to abide by them.

New rules, new tools
What is beginning to emerge, driven primarily by regulation, is a raft of technical standards which detail how businesses can develop Privacy Enhancing Technologies (PETs) that provide consumers with greater control over their personal data. For example

·         The PAS 1296 Age Checking code of practice is due for publication by the British Standards Institution next month, provides guidance for businesses mandated to check the age-related eligibility of consumers and to obtain verified parental consent before processing children’s data.
·         Kantara’s consent receipt specification enables consumers, to communicate and manage the personal data they have shared.

·         User-Managed Access protocol (UMA) is an access management protocol standard, which will enable end users to better protect their data no matter which platform they are on.

The global consumer movement has a duty to advocate for the adoption of best-practice tools and ensure that existing and new digital services are built with consumer protection in mind. Educating consumers about the choices they have available to them will also help pave the way for a digital world that is safer and more secure for people of all ages.





Monday, 13 March 2017

Consumers and the Internet of Things: one connection too many?

Liz Coll, Head of Digital Advocacy at Consumers International, takes a look at recent trends in the global uptake of connected devices and considers what these trends can tell us about consumer attitudes towards the Internet of Things.  



Last year our report on ‘Connection and Protection in the digital age’ explored the impact of the rapidly expanding trend of the Internet of Things (IoT) – with more and more everyday objects connecting to the internet. As with any ‘next big thing’ topic, the figures looked astounding with some commentators predicting 50 billion IoT devices to be connected by 2020.

New reports in 2017 have not been quite so bold with their predictions. According to analyst firm Gartner, the total number of IoT devices deployed by 2020 is more likely to be just over 20 billion. As with any forecast about the future of the digital economy, there are no certainties – but this drop feels significant. Could it be that consumer attitudes and concerns about connected devices are, at least partly, behind these more reserved predictions in 2017?

Our 2016 report suggested that security concerns and the invasive nature of connected technology would potentially hold back consumer engagement in this next deeper, more personal phase of digital technology. The focus of our work with G20 governments to help ‘Build a Digital World Consumers can Trust’ makes the case that unless consumers can trust digital technology, they won’t readily accept it into their everyday lives.  Getting trust right is therefore a key part of creating a vibrant demand side for the market.

So does it look like this is the case for the consumer market for IoT devices? A report released by Deloitte in 2016 points to an uneven uptake of consumer IoT devices in more developed economies. Connected entertainment devices such as games consoles and smart TVs have maintained a steady growth but sales of Fitbit devices failed to meet expectations.

Some research indicates that this limited take off is because of a failure to meet people’s needs, both in terms of pricing and also the difficulty of use and maintenance. As shown in the MEF Global Consumer Survey from April 2016, the levels of privacy and security were also problematic for consumers, with 62% and 52% of those surveyed reporting these as the biggest concerns, respectively.

Another example of the noticeable consumer resistance to connected devices has been the move by some Fitbit users to turn off the smart elements of their devices off only months after purchasing the products. With novelty seemingly wearing off so quickly, does this mean that penetration of IoT devices won’t happen as all those excited articles predicted?

In reality, it is hard to prove or predict that people won’t buy internet of things products because of a lack of trust. As privacy and technology expert Gilad Rosner somewhat ominously predicted that business momentum will mean that “The Internet of Things will happily march along with lousy privacy and security, and we will be the poorer for it”. 

Connected technology seems to be one of those things that creeps into products – an alarm clock on a smart phone that suddenly wants to become a ‘sleep tool’ to help you enjoy a restful night. An insurance provider that offers a subsidised fitness trackers, for as long as you keep active.

But with high profile internet of things problems such as the #Toyfail and the development of devices such as fertility trackers collecting and analysing sensitive information about one of the most private aspects of people’s lives, perhaps people will start to demand technology that is not just helpful but safe, ethical and human-centered.

How can consumer organisations play a leading role by working with businesses to ensure that connected devices can be safer, less invasive and prioritise consumer interests? Our member Consumer Reports’ new digital standard initiative is an excellent example of how the global consumer movement can evaluate and test the safety of digital products and services, empowering consumers to make informed choices about whether they want to invest in IoT devices. This week, Maria Rerecich of Consumer Reports will speak at an SXSW event that considers how a consumer organisation can include privacy, security, and data practices in its testing protocols.

As consumer organisations continue to monitor ongoing developments in the connected world, it’s vital that the global consumer movement advocates for businesses to build security and privacy in at the design stage. It’s not just the right thing to do but could be a smart business move as consumers look for products they’re sure they can trust  – for your child’s next birthday would you buy a smart toy classed as ‘espionage equipment’?

We are co-hosting the G20 Consumer Summit in Berlin on WCRD this week which will provide an excellent opportunity to engage in a dialogue with governments, business leaders and key stakeholders about the most pressing concerns that consumers face and how to work together to create a better digital world.