Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, 13 March 2017

Consumers and the Internet of Things: one connection too many?

Liz Coll, Head of Digital Advocacy at Consumers International, takes a look at recent trends in the global uptake of connected devices and considers what these trends can tell us about consumer attitudes towards the Internet of Things.  



Last year our report on ‘Connection and Protection in the digital age’ explored the impact of the rapidly expanding trend of the Internet of Things (IoT) – with more and more everyday objects connecting to the internet. As with any ‘next big thing’ topic, the figures looked astounding with some commentators predicting 50 billion IoT devices to be connected by 2020.

New reports in 2017 have not been quite so bold with their predictions. According to analyst firm Gartner, the total number of IoT devices deployed by 2020 is more likely to be just over 20 billion. As with any forecast about the future of the digital economy, there are no certainties – but this drop feels significant. Could it be that consumer attitudes and concerns about connected devices are, at least partly, behind these more reserved predictions in 2017?

Our 2016 report suggested that security concerns and the invasive nature of connected technology would potentially hold back consumer engagement in this next deeper, more personal phase of digital technology. The focus of our work with G20 governments to help ‘Build a Digital World Consumers can Trust’ makes the case that unless consumers can trust digital technology, they won’t readily accept it into their everyday lives.  Getting trust right is therefore a key part of creating a vibrant demand side for the market.

So does it look like this is the case for the consumer market for IoT devices? A report released by Deloitte in 2016 points to an uneven uptake of consumer IoT devices in more developed economies. Connected entertainment devices such as games consoles and smart TVs have maintained a steady growth but sales of Fitbit devices failed to meet expectations.

Some research indicates that this limited take off is because of a failure to meet people’s needs, both in terms of pricing and also the difficulty of use and maintenance. As shown in the MEF Global Consumer Survey from April 2016, the levels of privacy and security were also problematic for consumers, with 62% and 52% of those surveyed reporting these as the biggest concerns, respectively.

Another example of the noticeable consumer resistance to connected devices has been the move by some Fitbit users to turn off the smart elements of their devices off only months after purchasing the products. With novelty seemingly wearing off so quickly, does this mean that penetration of IoT devices won’t happen as all those excited articles predicted?

In reality, it is hard to prove or predict that people won’t buy internet of things products because of a lack of trust. As privacy and technology expert Gilad Rosner somewhat ominously predicted that business momentum will mean that “The Internet of Things will happily march along with lousy privacy and security, and we will be the poorer for it”. 

Connected technology seems to be one of those things that creeps into products – an alarm clock on a smart phone that suddenly wants to become a ‘sleep tool’ to help you enjoy a restful night. An insurance provider that offers a subsidised fitness trackers, for as long as you keep active.

But with high profile internet of things problems such as the #Toyfail and the development of devices such as fertility trackers collecting and analysing sensitive information about one of the most private aspects of people’s lives, perhaps people will start to demand technology that is not just helpful but safe, ethical and human-centered.

How can consumer organisations play a leading role by working with businesses to ensure that connected devices can be safer, less invasive and prioritise consumer interests? Our member Consumer Reports’ new digital standard initiative is an excellent example of how the global consumer movement can evaluate and test the safety of digital products and services, empowering consumers to make informed choices about whether they want to invest in IoT devices. This week, Maria Rerecich of Consumer Reports will speak at an SXSW event that considers how a consumer organisation can include privacy, security, and data practices in its testing protocols.

As consumer organisations continue to monitor ongoing developments in the connected world, it’s vital that the global consumer movement advocates for businesses to build security and privacy in at the design stage. It’s not just the right thing to do but could be a smart business move as consumers look for products they’re sure they can trust  – for your child’s next birthday would you buy a smart toy classed as ‘espionage equipment’?

We are co-hosting the G20 Consumer Summit in Berlin on WCRD this week which will provide an excellent opportunity to engage in a dialogue with governments, business leaders and key stakeholders about the most pressing concerns that consumers face and how to work together to create a better digital world.


Tuesday, 28 February 2017

Digital Identity - what could it mean for consumers?

In our latest blog post Amanda Long, Director General at Consumers International, discusses the topic of digital identity and the potential benefits and threats for consumers.



The idea of people having an easy way to prove their identity online through a digital identity is not new, but has so far been used mainly by governments enabling citizens’ access to public services. Austrian citizens can use an approved app on their smart phone, or a smart card to apply for benefits, do tax returns or access healthcare. 

A digital identity is a means by which individuals can prove their identity online - for example, job applicants needing to prove their residency status, or even qualifications.  It links up to an identity checking system which can verify that the person with that identity is who they say they are – both online and in person. This means people can use their digital identity credentials to access services or products without having to physically present valuable documents, such as passports, birth certificates, driving licenses or a handful of utility bills.

Digital identity could represent a comprehensive solution to many millions of people who are effectively barred from entry to many things that could improve their quality of life. Without traditional forms of documentation, transactions like renting accommodation, setting up a bank account or getting a mobile phone contract become impossible.

It could also solve problems for consumers in more developed markets, wherever identity is a problem. According to a start-up digital identity provider: “Age verification online would prevent underage users from opening inappropriate social media accounts, and ensure that minors cannot access adult content. It would also help online retailed to confirm that someone is eligible to buy age restricted goods like DVDs, computer games, alcohol, cigarettes and knives” (YOTI)

Digital identity could potentially deliver financial inclusion, seen as a strong route out of poverty - or at the very least accelerates us towards it. The World Bank has a programme dedicated to identity and financial inclusion, ID4D – which “helps countries analyse problems, design solutions, and implement new systems to increase the number of people with official identification and the development impact of the overall identification system.

Of course for some people, the scope that any kind of centralised identity system has for government surveillance and discrimination will be cautious about the implications of digital identity systems. With this large caveat in mind, what is there that we learn from the pioneering steps governments have taken in exploring digital identity that might be useful for budding consumer applications? The UK digital identity verification programme has developed a set of Consumer and Privacy principles to guide practice. 

These types of frameworks will be important as the implications of this technology could be significant. If it is not designed with protection in mind and regulated accordingly:

-          Individuals’ privacy could be at risk, with the potential for personal data for all parts of your digital existence being held by digital ID verification services, as a means to authenticate who you are, with you having little or no control of what’s collected and stored or how it is being used to make decisions about you.  If alternative income streams to monetising consumers’ personal data aren’t identified then the risks to privacy will continue.

-          There is a threat of lack of consumer choice. It is very possible that a critical mass could form of people using a particular digital identity service that means it is effectively forced onto everyone.  This could mean less competition between digital ID verification providers and also a weakening of consumers’ rights to protection. In this scenario, the speed at which a particular service is adopted by a mass of people may mean that the opportunity to check, challenge and reform terms and conditions of the service are reduced. An individual who is swept up with this, who sees it as the only way to continue access to a product, may agree to terms and conditions that if given more time or choice they would not.

-          We might also see a situation where one person would need multiple digital identities, in order to access a variety of services as companies may not recognise the same identity providers.

-          The liability model for digital identity is also complex. For example, should digital identity providers be responsible for actions done based on the authentication they give?

With so much potential for consumer benefit and significant threats at play, consumer organisations must build up their expertise on this issue so they can influence the private sector as it develops digital identity systems. Consumer organisations are in a strong position to draw upon existing public sector practice, and the need for trust, confidence and consumer protection in digital systems to influence this nascent industry for the better.


Friday, 9 December 2016

Internet-connected toys: A #ToyFail with global implications


Amanda Long, Director General at Consumers International, discusses the failure of My Friend Cayla and i-Que dolls to protect consumer privacy and considers what this means for consumers globally. 



The way in which consumers are interacting with the digital world is constantly evolving. With more than 3 billion people now connected to the internet worldwide, there is a growing opportunity for everyday objects to be synced with the web. By 2020, it is forecasted that the number of connected devices will reach 50.1 billion and children’s toys are no exception to this trend.

In the wake of the Norwegian Consumer Council’s #ToyFail report, Consumers International and several of our Members have condemned the miserable failure of My Friend Cayla and i-Que toys to protect consumer data, security and privacy. Not only are these toys dangerously easy for others to gain access to, they are also able to record everything the child says and transfer the recordings to a company that can sell the information on the third parties. 

This irresponsible lapse in consumer protection raises a number of important questions. How has this failure impacted on consumers across the world? What can it tell us about the current gaps between rapid digital innovation and the policies in place to protect consumer privacy and data? How can the global consumer movement use its collective voice to call for change? 

By looking at the manufacturing and distribution network of these toys, it is easy to see that the reach of this issue has no borders. Genesis Toys, the company that produces and develops both the Cayla and i-Que dolls, are based in Los Angeles, California. The products are then manufactured in Hong Kong before being distributed to retailers in the U.S, South Africa, the Middle East, Australia and Scandinavia. British toy company Vivid also distribute the toys to markets in Europe, including the UK, France and Germany. The companion app for the toys is developed by ToyQuest, who have offices across the globe and are partnered with a wide range of licensors including Disney, Nickelodeon and DreamWorks. 

The international reach of these companies is hugely significant. The availability of the toys in a wide range of markets maximises the number of consumers affected by the breaches in security and privacy. The capacity of national consumer protection policies in each market will also differ from country to country, leaving some consumers more exposed than others. 

Digital innovation is undoubtedly a key driver of progress and has the potential to create many opportunities for consumers. The benefits should not, however, come at the expense of the rights of individuals. Consumers must feel that they can use their products safely and securely without concerns that their thoughts, opinions and feelings will be passed on to the highest bidder. Trust should be at the forefront of every relationship between digital providers and consumers. In this case, it would seem that the trust of parents and children using the toys has been undermined. 

It is also essential that companies adopt a design-philosophy that puts safety, privacy and security at the top of their priority list when developing new products. As the speed with which the creation of new technologies and devices accelerates, manufacturers and governments must make sure that their safeguarding of consumer interests keeps up the pace. 

As this story continues to develop, we must ensure that the collective voice of consumers across the globe is heard. Working together with our Members, Consumers International has acted quickly to brief and share engagement tools with consumer organisations in affected markets outside of Europe, enabling them to liaise with the relevant national authorities and media outlets. Regardless of where consumers are based in the world, we are calling for the manufacturers to:

  • Not collect more data than necessary for the functionality of the service
  • Prevent these kind of issues resurfacing by adopting a design-philosophy of privacy and security by design.
  • Make these toys safer by increasing security features in how devices are paired, to stop unauthorised people from connecting to the toy.
  • Stop all direct marketing to children through to apps

By following these guidelines and prioritising consumer protection, digital providers can begin to move towards a world in which consumers can fully benefit from advances in technology without the fear of their rights being eroded.

Sources
- #Toyfail: An analysis of consumer and privacy issues in three internet-connected toys, Norweigan Consumer Council
- Here’s How Many Internet Users There Are, TIME
- IoT: number of connected devices worldwide from 2012 to 2020, Statista

Tuesday, 6 August 2013

New human rights goals to combat surveillance onslaught

Jeremy Malcolm blogs on new demands for humans rights sparked by a growing global consensus which thinks modern surveillance has gone too far. 

For some time now there has been a need to update understandings of existing human rights law to reflect modern surveillance technologies and techniques.

Nothing could demonstrate the urgency of this situation more than the revelations confirming the mass surveillance of innocent individuals around the world.

That is why the International Principles on the Application of Human Rights to Communications Surveillance have been launched.

The principles articulate what international human rights law "which binds every country across the globe" require of governments in the digital age.

They speak to a growing global consensus that modern surveillance has gone too far and needs to be restrained.

They also give benchmarks that people around the world can use to evaluate and push for changes in their own legal systems.

The product of over a year of consultation among civil society, privacy and technology experts (read here and here), the principles have already been co-signed by over hundred organisations from around the world.

The process was led by Privacy International, Access, and the Electronic Frontier Foundation and has been supported by Consumers International.

The release of the principles comes on the heels of a landmark report from the United Nations Special Rapporteur on the right to Freedom of Opinion and Expression, which details the widespread use of state surveillance of communications, stating that such surveillance severely undermines citizens' ability to enjoy a private life, freely express themselves and enjoy their other fundamental human rights.

And recently, the UN High Commissioner for Human Rights, Nivay Pillay, emphasised the importance of applying human right standards and democratic safeguards to surveillance and law enforcement activities.

"While concerns about national security and criminal activity may justify the exceptional and narrowly-tailored use of surveillance programmes, surveillance without adequate safeguards to protect the right to privacy actually risk impacting negatively on the enjoyment of human rights and fundamental freedoms," Pillay said.

Over the next year and beyond, groups around the world will be using them to advocate for changes in how present laws are interpreted and how new laws are crafted.

We encourage privacy advocates, rights organisations, scholars from legal and academic communities, and other members of civil society to support the principles by adding their signature.

To sign, please send an email to rights@eff.org, or visit this website. 

Summary of the Rights


  •  Legality: Any limitation on the right to privacy must be prescribed by law.
  •  Legitimate Aim: Laws should only permit communications surveillance by specified State authorities to achieve a legitimate aim that corresponds to a predominantly important legal interest that is necessary in a democratic society.
  •  Necessity: Laws permitting communications surveillance by the State must limit surveillance to that which is strictly and demonstrably necessary to achieve a legitimate aim.
  •  Adequacy: Any instance of communications surveillance authorised by law must be appropriate to fulfill the specific legitimate aim identified.
  •  Proportionality: Decisions about communications surveillance must be made by weighing the benefit sought to be achieved against the harm that would be caused to users' rights and to other competing interests.
  •  Competent judicial authority: Determinations related to communications surveillance must be made by a competent judicial authority that is impartial and independent.
  •  Due process: States must respect and guarantee individuals' human rights by ensuring that lawful procedures that govern any interference with human rights are properly enumerated in law, consistently practiced, and available to the general public.
  •  User notification: Individuals should be notified of a decision authorising communications surveillance with enough time and information to enable them to appeal the decision, and should have access to the materials presented in support of the application for authorisation.
  •  Transparency: States should be transparent about the use and scope of communications surveillance techniques and powers.
  •  Public oversight: States should establish independent oversight mechanisms to ensure transparency and accountability of communications surveillance.
  •  Integrity of communications and systems: States should not compel service providers, or hardware or software vendors to build surveillance or monitoring capabilities into their systems, or to collect or retain information.

Saturday, 22 June 2013

PRISM surveillance: Unpicking the myths and identifying the threats

Revelations about surveillance methods used by the US Government, prompted by leaks from intelligence operative Edward Snowden, are analysed by CI's digital expert, senior policy officer Jeremy Malcolm. 

Although the basics have been widely reported, there is still a lot of confusion out there about how all the pieces of the PRISM surveillance scandal fit together, so here's the rundown.

First, on Thursday 6 June, came the revelation in the Guardian of a secret court order requiring US phone carrier Verizon to disclose a complete set of records of telephone calls made over a three-month period.

Less than a day later the Guardian and Washington Post claimed that under a separate secret US government programme, named PRISM, the National Security Agency had direct access to the servers of major Internet companies including Google, Facebook, and Yahoo, enabling it to obtain content ranging from emails to chat transcripts, voice calls, photos and videos.

By Friday, all of the Internet companies concerned had denied knowledge of the PRISM programme, and President Obama defended both that programme and the secret court order to Verizon as modest encroachments on privacy. 

It was on Sunday 9 June that 29-year-old former NSA-contractor Snowden came forward as the informant, for which he had released a set of Powerpoint slides as evidence.

Although the initial reports suggested a broader scope, we now know that PRISM isn't really a separate surveillance programme in its own right, but just an NSA system which facilitates the transfer of information from Internet companies under various other programmes for the use of NSA operatives.

The affected companies' denial of knowledge of PRISM is therefore most probably true.

But those other programmes are bad enough. In addition to those already mentioned, a programme similar to that used to obtain the Verizon call data is used to obtain metadata about Internet communications.

This programme, called BLARNEY, gathers and stores metadata as it flows along Internet network backbones. Another Patriot Act amendment authorises the interception of the content of foreign-to-foreign communications that transit through the United States.

This is what we think we know, but it is difficult to know how much of the truth has yet been told.

On March 12, 2013, the NSA's James Clapper had told the United States Senate Select Committee on Intelligence that the NSA does not wittingly collect any type of data on millions or hundreds of millions of Americans. In the light of subsequent revelations, there is no way around it – that was a lie.

A sour taste was also left in the mouths of many around the world when President Obama's response to the recent revelations was, “This does not apply to US citizens and it does not apply to people living in the United States”, discounting the effect on the privacy of most innocent citizens of the world who happen to use US-based Internet services.

As part of the Best Bits civil society coalition that CI co-founded last year, a group of NGOs and individuals from around the world wrote a letter to the United Nations Human Rights Council last week condemning the surveillance as an abuse of human rights.

This letter now has over 300 endorsements, and has been followed up with a letter to the US Congress which was delivered today, and which has over 250 endorsements so far. A key paragraph of the letter to Congress states:

We are also extremely disappointed that, in all the post ‘disclosures’ statements, US authorities have only insisted that there was no access obtained to content related to US citizens, and just their communication meta-data was collected.

There has not been a word on the issue of large-scale access to content related to non US citizens, which constitute an almost certain human rights violation.

The focusing of the US authorities on the difference between treatment of US citizens and non-citizens on an issue which essentially relates to violation of human rights is very problematic.

Human rights are universal, and every government must refrain from violating them for all people, and not merely for its citizens.

We strongly advocate that current and future legal provisions and practices take this fact into due consideration.






Monday, 18 March 2013

An end to online autonomy?


In Part 2 of her blog on digital data ownership, Liz Coll, senior policy advocate with CI member Consumer Focus, asks: Does being part of social and economic activity online mean giving up autonomy over our personal data, or withdrawing from the online world altogether?

In my last blog post I talked about the big contrast between the importance that external agencies attach to consumer data, and the significance consumers themselves assign.

Now I turn to look at if the digital economy runs on personal data, and consumers are the primary source of this new commodity, will consumers seek to exploit its potential, or continue to be exploited for it?

The challenge

The challenge for those working in the consumer interest is to find a way to transform the current scenario into a mutually beneficial one. This could involve helping consumers develop a stronger understanding of the potential value of their data, and getting them ready to engage with new opportunities.

If consumers are able to exert more control over how their data is used, there is much to gain. We are starting to see initiatives such as midata in the UK, or Green Button in the USA which offer consumers opportunities to have access to, and benefit from, the data that companies currently hold.

Despite attracting some controversy because of security and privacy concerns, they are an indication of how personal data is becoming a market in which consumers could take a bigger share.

Our research

As discussed previously, we commissioned ICM to survey 2,002 adults aged over 18 so we could develop a better appreciation of consumers’ understanding of the issue.

One of the things we wanted to test was how consumers felt about some of the new thinking around terms and conditions which effectively reverses the current provider-dominated relationship.

It works by getting providers to agree to terms and conditions that are set by an intermediary on behalf of the individual, prior to them taking up the service.

Only 8% of respondents were keen on this option, perhaps seeing it as impractical. The preferred option was shorter terms and conditions in plain English and equivalent to no more than two sides of paper (47%).

Forty per cent of respondents wanted to use a set of more consumer-friendly generic terms and conditions developed by an independent body. Perhaps personalised terms and conditions are only for the early adopters, but the support for conditions written in the consumer interest is strong.

Want control, but don’t use it

The vast majority of consumers think they should have more control over their data, but only a few use existing controls: Despite limited understanding of what is collected and why, 84 per cent of people want more control over what information organisations collect about them and how it is used.

This also came through strongly in Demos’ recent research on public attitudes  towards personal information and data sharing.

They found that people would welcome measures to give them more control over personal information, in terms of knowing what is held on them and having the ability to withdraw it.

Generally consumers wanted to have a more honest and open dialogue about how their data is used and on what terms.

However, only one in eight consumers say they currently use any form of control panel or dashboard (for example, http://adblockplus.org/en/features) to set their online privacy and personal information collection preferences; most do not know they exist.

This could reflect the visibility, accessibility and usability of the tools as well as people’s awareness of them. (The survey took place before regulations requiring cookie consent notices on websites were introduced in May 2012, it is likely that awareness is higher now.)

Mutually beneficial

Earlier I set a challenge to those working in the consumer interest to find a way to transform the current one-sided scenario into a more mutually beneficial one.

To start to do this, consumer groups could take a bigger role in enabling people to engage with new opportunities and tools in the personal data economy.

These have the potential to shift the relationship between providers and consumers onto a more balanced footing. Whilst data protection should always be at the heart of consumer advocacy and empowerment, the status of personal data as such a major new commodity also demands additional attention.

There are question marks over whether the usual routes to protection are still able to adequately regulate the actions of global companies. Think, for example of the threatened fine to Facebook chief Mark Zuckerberg of €20,000 over privacy concerns by the German data protection agency.

There are similar doubts as to how effectively regulation can keep up with the fast pace of change online, and how national law can be imposed on a global network.

Danger of stifling advantages

Too hard a clampdown may well stifle the advantages to be had from effective, consensual sharing of personal data and would almost certainly alienate the large numbers who are comfortable with, and feel they benefit from, sharing.

Not to mention very quickly infuriating almost all online users with the possibility of bringing free-to-use services to an end!

So, are we left with the alternative of accepting that being part of social and economic activity online means giving up autonomy over our personal data, or withdrawing from the online world altogether?

None of these seem particularly productive, and all fail to make possible the benefits of using personal data in a more mutually beneficial way.

Doing things differently has potential benefits for consumers. For example using personal data more intelligently could mean personalised, and more responsive, products and services.

There are advantages for business too, particularly if they can be part of a more balanced, permissions-based relationship with consumers.

New opportunities

Taking up opportunities, including but moving beyond data protection, will depend on consumers and consumer groups quickly building a more critical understanding of the:
  •  current relationship that we are part of online with regards to our personal data, based on a much fuller understanding on what we give up in exchange for what. As part of streamlining consumer protection laws, BIS is considering (see page 21 point 62) whether consumers should have the right to remedies for ‘free’ digital content (eg download/streaming/games) which are supplied without payment of money, but in exchange for something of value other than money such as personal data or virtual currency.
  • scale at which personal data is used, and to what end by providers. As well as concerns about an individuals’ personal data and its use, the large scale data and analysis available to providers and the potential for this to shape markets will be a major issue for consumers.
  • growth of consumer empowerment and personal data as an emerging market, and how new services and developments via intermediary bodies may work. Helping individuals protect and manage their own data is fast becoming a market in its own right, leading to a growth of business which can help consumers negotiate services and products to their advantage, such as personal information management systems.

Such developments enable consumers to have access to their data and share it with parties that put it to work for them.

The increased influence that consumers have due to the potential of digital technology to cheaply and quickly facilitate collaboration and joint action. The web has made possible a more effective way for consumers to participate and achieve goals together.

This bypasses the need for traditional institutions and enables consumers to counter powerful interests and exert more control – see previous Consumer Focus research on things like collective switching, using mapping software to identify and fix problems, online feedback and the theory and practice of online collaboration and consumer co-operation.

Understanding these new dynamics will require digital literacy in the widest possible sense, what Rheingold would describe as knowing how to participate online for both individual advantage and collective influence.

Increased control

Certainly, our research and the Demos survey both point to consumers wanting to have more control over their personal information. Contrasts (such as wanting more control, despite not using existing controls) could be explained by the lack of tools, services and motivation to do things differently online.

What is not yet clear is what the catalyst will be that prompts the majority of consumer to take an active interest in their data. Here are a few suggestions for what might spur on more collective and collaborative action to rebalance the personal data equation:
  • Further high profile examples of forcing through changes to terms and conditions changes such as the new terms imposed by Facebook might be the start of the turning point. Instagram’s reversal of a decision to suddenly change its terms and conditions on privacy is also a good example of consumers showing their collectively powerful hand.
  • The availability of alternatives such as midata, which is now starting to gain traction as the UK Government looks to put it on a statutory footing may be able to demonstrate what a more balanced personal data relationship looks like in practice. Companies such as Tesco in the UK are planning to release back their Clubcard data to customers to enable them to see and make plans on the basis of their shopping habits – just as Tesco have done behind the scenes.
  • Greater awareness of the outcome for consumers of businesses applying personal data inferences to prices. In the UK, the Office of Fair Trading is investigating personalised pricing, where inferences about our personal habits and data affect what price we are charged.
 Forecasting the potential and impact of digital technology is common practice on the web, with new scenarios and ideas regularly emerging.

When considering predictions for personal data (central to so many future developments), we must remember that the way we use digital technology is still in a period of negotiation and development.

Certainly, powerful interests have consolidated some control, and are moving to take more, but users and consumers still have a stake in how things develop and an opportunity to influence ways in which they can exert more control over their fate.

There is much to play for if consumers want to make the most of the prized commodity that derives from them, and there is a critical role for consumer advocates to support them. Are you ready for the challenge?

Wednesday, 13 March 2013

Who’s policing the Internet? – Part 3

As governments try to impose their rule on the Internet, digital rights activist strive to keep Internet governance open, inclusive and controlled by the many. In Part 3 in the series, CI’s Digital Rights Senior Policy Officer Jeremy Malcolm warns against ignoring proposals for the evolution of Internet governance arrangements on the false assumption that the status quo is sustainable.

There is a real opportunity here to influence the evolution of existing Internet governance arrangements. Last December – in fact at the same time as the World Conference on International Telecommunications (WCIT) meeting was taking place in Dubai – the UN General Assembly in New York passed a resolution that set the scene for this, and was actually much more significant for the future of Internet governance than WCIT, although it was overlooked by most.

The resolution:
Invites the Chair of the Commission on Science and Technology for Development to establish a working group on enhanced cooperation to examine the mandate of the World Summit on the Information Society regarding enhanced cooperation as contained in the Tunis Agenda, through seeking, compiling and reviewing inputs from all Member States and all other stakeholders...
This resolution didn't come out of the blue; in fact, it has been in train since 2005, in the final output document of the World Summit on the Information Society, the Tunis Agenda.

From the starting point “that there are many cross-cutting international public policy issues that require attention and are not adequately addressed by the current mechanisms,” the Tunis Agenda called for creation of the Internet Governance Forum as a multi-stakeholder discussion forum to address these issues, together with a broader:
“...process towards enhanced cooperation involving all stakeholders, proceeding as quickly as possible and responsive to innovation … [which would] enable governments, on an equal footing, to carry out their roles and responsibilities, in international public policy issues pertaining to the Internet, but not in the day-to-day technical and operational matters, that do not impact on international public policy issues.”
The need for a concrete proposal


In January this year the chair of the UN Commission on Science and Technology for Development (CSTD) outlined the process that is already in train to convene a Working Group on Enhanced Cooperation that will help to determine, one way or another, how the enhanced cooperation mandate will be expressed through the evolution of Internet governance arrangements.

The next steps are up to us. Will we participate productively to provide a firmer institutional foundation for the representation of the public interest in global Internet governance arrangements, or will we dig in our heels and insist that those arrangements remain forever stuck in the same mould as in 1998?

An evolutionary extension to existing Internet governance arrangements will, if it is sufficiently deliberative and transparent, expose and eliminate proposals from states that are based upon repression and control, since these would never pass muster in a multi-stakeholder environment – though at the same time, its authority should be limited to the development of principles, rather than their implementation or enforcement.

It may also help preclude the emergence of new exclusionary processes such as the Anti-Counterfeiting Trade Agreement and the Trans Pacific Partnership in the future, and even if it doesn't, it will at least drain them of their claimed legitimacy and arm us to defeat them more easily.

For as long as we remain blind to this, rejecting or ignoring proposals for the evolution of Internet governance arrangements on the false assumption that the status quo is sustainable, we risk assuring the International Telecommunications Union's future as the only global body capable of authoritatively developing globally-applicable public policy principles for the Internet.

This blog was first published on Digital Asia News

Dr Jeremy Malcolm is an Internet and Open Source lawyer, consumer advocate and geek. He is also a senior policy officer at Consumers International and can be found on Twitter and LinkedIn.

Friday, 1 March 2013

Who’s policing the Internet? - part two

As governments try to impose their rule on the Internet, digital rights activist strive to keep Internet governance open, inclusive and controlled by the many. In Part 2 in the series, CI’s Digital Rights Senior Policy Officer Jeremy Malcolm looks at internet governance at the global level and explains the need for institutional evolution.

If governments do sometimes need to involve themselves in Internet governance, it should only ever be at the national level.

But how can this be true - because the decisions that governments make at the national level (for which most of us would accept the need in certain cases) have an invariable tendency to spill outside the country’s borders.

This occurs because the Internet itself is borderless, and so policies made in one country, whether by governments or by private actors, can affect users anywhere in the world, over whom the policy-maker has no legitimate claim of authority.

For example, in 2011 US authorities seized the domain names rojedirecta.com and rojedirecta.org claiming authority to do so under US law, although the domains were owned by a Spanish company and had been ruled legal under Spanish law (the domains were later returned).

Similarly, when content is taken down under authority of the US Digital Millennium Copyright Act (DMCA), it affects users throughout the world. Why shouldn’t those users have any say in that?

Whilst direct action through grassroots groups such as Anonymous is valuable as a last resort, it should never become our primary means to shape Internet policy.  As security specialist and author Bruce Schneier recently wrote :
 
The masses can occasionally organize around a specific issue – SOPA/PIPA, the Arab Spring, and so on – and can block some actions by the powerful. But it doesn't last. The unorganized go back to being unorganized, and powerful interests take back the reins.

To be organized at the global level, in a way that is effective to curb the rights abuses of governments and corporations, implies sitting at the table with them to manage the cross-border implications of Internet-related public policies.

Currently, this means sitting on the sidelines of the secret negotiations at the TPP (Trans-Pacific Partnership), or in the back row of the auditorium at WIPO (the World Intellectual Property Organization). And that’s if we're lucky.

On other issues, it means we have no say at all because there is no global forum dealing with these issues.

The need for institutional evolution

So we should at least consider whether a more formally institutionalized means of engagement of online activists in Internet policy discussions at the global level might bridge the gap that exists after self-regulatory, technology-based and grassroots-led initiatives have failed.

For some issue areas, this may be seldom; for example, we already have strong global mechanisms for the participation of all stakeholders in Internet standards development, and in the allocation of IP addresses and domain names, through institutions such as the IETF, the W3C and ICANN.

But in other areas, such as security and cybercrime, intellectual property enforcement, consumer protection, data protection and privacy, and online freedom of expression, we do need to look at the evolution of current institutional arrangements.

This moves us to the third assumption highlighted above, to the effect that there is no need for any reform to Internet governance arrangements. If only that were true.

There are global discussions of these issues, of course – but they are either too weak to have a tangible impact on actual policy outcomes (this is the case of the Internet Governance Forum or IGF), or they do not offer the opportunity for meaningful participation from all affected stakeholders (a much longer list, including the ITU itself, as well as the OECD, APEC, WIPO, the CSTD and the TPP).

Often it is civil society that is excluded from these existing arrangements – as was the case with ACTA, and now the TPP – but in other cases it is the governments from developing countries, which see developed-country groupings such as the G8 and OECD taking the lead, whilst their own interests are sidelined.

Therefore it is hypocritical for US policy-makers to label developing countries sidelined by US-driven initiatives such as these, and turning to the more inclusive (of governments) ITU, as Internet freedom's foes. 

Thus outside of narrow technical areas, what we find is that far from being an inclusive multi-stakeholder regime, powerful governments and companies are making their own rules for the Internet and then seeking to impose them on the rest of the world.

We saw it with ACTA, SOPA and PIPA, we see it in progress at the TPP, and we see the potential for similar exclusionary rule-making at the ITU and even the OECD. This is the true face of the status quo of Internet governance, and it is unsustainable.

Part 3 in this blog series, outlining the need for Internet principles and the need for a concrete proposal, will be available next week.

Friday, 15 February 2013

What’s the value of your personal data?

Liz Coll, senior policy advocate with CI member Consumer Focus, explains that consumers, despite being the originators of their own digital data, are in the dark about its value.

In the digital economy personal data is a growth business. The volume of personal data gathered by smart devices, searches, site visits, purchases, recommendations, likes, tweets and status updates is on the rise.

Growing too is the value of this data to companies who capture, store, analyse and sell it on.

They use the data to predict consumer behaviour, target advertising and increase profits. While trading personal data may not have been the original core mission of digital giants such as Google and Facebook, they now get significant revenue from the personal data trails left by service users.

The services are free to use but, as the social media phrase goes, ‘if the service is free, then you’re the product.’

The major commodity of the age

Such is the potential for personal data to transform business models and underpin new services that some people now talk about personal data as the ‘new oil’ in the connected digital economy.

Commentators claim it is set to become the major commodity of the age, a critical resource from which new innovations and value will flow.

Markets such as banking are rapidly rethinking how to better mine the data they hold, or obtain additional information in order to increase the value they can derive from customers.

Yet consumer understanding of what happens to this valuable data does not appear to be growing at the same pace, even though the commodity originates with them.

We are far from naïve – our intuition tells us that a lot is being collected but we are somewhat vague about why and what the long term implications of this might be.

Despite our concerns, we still don’t engage with the existing opportunities to take control over our information. We sign our data over by agreeing to (but rarely comprehending) terms and conditions of sometimes epic length.

Open to exploitation

There’s a big contrast here between the importance that external agencies now attach to consumer data, and the significance consumers themselves assign.

The response from consumers is mixed; they are concerned and aware but are not making moves to protect themselves. This suggests a scenario where consumers, by not exerting control over their digital footprint, could be left open to exploitation.

Consumer understanding

Consumer Focus wanted to develop a better appreciation of the extent to which consumers know their data is being collected and controlled, and understand the ways in which it is being exploited.

We also wanted to find out what controls consumers put in place to protect themselves, and what value they put on the data that they impart, knowingly or unknowingly, about themselves.

We commissioned ICM to survey 2,002 adults aged over 18, with results weighted to provide a representative sample. Respondents included online service users and loyalty card holders. Full details of the research findings (PDF 582KB) are available.

Headline research findings

The findings show a conflict and contrast in consumer behaviour and sentiment regarding personal data:

Suprisingly high levels of trust

Some consumers are pretty trusting of online providers’ data collection motives, despite a general impression that they were not to be trusted: one in 10 consumers had not realised any data was collected on them via online services.

And a further fifth thought that the provider only collected the minimum amount required to make the service work better.

That means almost two fifths of respondents (39 per cent) have a benign interpretation of online organisations’ intentions.

This is surprisingly high given that online providers were ranked lower in trust terms than any other type of organisation, including banks (for managing current accounts), the police and supermarkets.

Similarly, four out of five loyalty card holders acknowledge that the card provider gathers data about them, but just under a third recognise that the card provider then packages this up and sells it on as anonymised data, or uses it to segment its customer base and target offers, etc.

Tick, click and hope for the best

Despite concerns about the implications of terms and conditions, people generally tend to tick, click and hope for the best: attitudes and behaviour around terms and conditions and license agreements throw up some interesting insights.

We were surprised to find that almost a third of consumers claim they always read terms and conditions online.

Over half told us they rarely do and one in seven never do so. For this group, the length of terms and conditions are off putting, and the desire to access the product or service would appear to override any concerns about data exchange.

A few also believed that nothing bad could come from not reading them.

Having said that, three out of five consumers who do not read the small print still have concerns about assenting without reading the details.

Unknown financial implications were the top concern for a third of people, with just over half (52 per cent) mentioning personal data concerns as a top issue.

Of the third that do claim to read terms and conditions, only one in five feel they fully understand the implications when they tick the ‘I agree’ box. That makes a mere 16th of the total sample who claim to fully comprehend the implications of terms and conditions.

Declining services

When it comes to using online services, only 18 per cent of those who always read terms and conditions mentioned how information is gathered and used as the main reason for checking on provider’s terms and conditions.

Of those who end up declining online services and products, it is a small number – 13 per cent – who pull out because of privacy concerns, and 7 per cent say that it was because too much personal information was demanded.

Low understanding of value

In an age where our personal data is conceived of as the commodity which will drive the digital economy, we as originators of the data are in the dark about its value.

When asked to guess the value of the personal data collected about them via their most frequently used service, 61 per cent of people did not attempt to volunteer a figure.

Of those who did try to value it, 15 per cent thought it had no value at all – the largest proportion of the respondents who attempted to give an estimate of the value.

For consumers that suggested a value above zero, there was no consensus, with some suggesting it is worth only up to £50 or £100 a year and others opting for many hundreds of pounds. It’s not only consumers who can’t agree – many digital and business experts differ greatly on what the value of data actually is.

Nevertheless, when asked to rate whether their data has a commercial value that organisations should pay a fee to use – three-fifths of consumers agree and only one in six disagree.

Consumers do not yet have a well-developed sense of what a fair exchange between a service provider and consumer looks like: when asked what they would be prepared to pay to use their favourite, free-to-use online service, fewer than one in 10 suggested a figure, and two-thirds said they were not prepared to pay at all.

What does it all mean?

The research results show some conflicting attitudes and behaviours that can be explained in part by differences of opinion between people – with age being a major factor.

The Demos Data Dialogue survey puts the public into five categories, of which 27 per cent recognise the value of sharing data, see key benefits and are comfortable with sharing. That’s just under a third of people who are not overly concerned about the risks of sharing personal info and who see the benefits of the value exchange.

Attitudes towards terms and conditions suggest an acceptance of exchanges weighted heavily towards the provider which consumers feel compelled to go along with in order to access services.

But surely if more consumers knew the value of their personal data they wouldn’t be so happy to stick to the status quo?