Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts
By Trevor Schmitt

China’s Great Firewall will remain closed to companies which choose not to conform to China’s online censorship and oversight laws. Chinese regulators announced last month at a conference in Geneva that Google and Facebook must adhere to local law if they want access to all 751 million of mainland China’s internet users. Google, Facebook, and Twitter are among the companies currently blocked from providing services in mainland China.

According to Qi Xiaoxia, Director of the Bureau of International Cooperation at the Cyberspace Administration of China, if the companies choose to comply with Chinese law, they will be allowed access to the county’s massive online market. Speaking before the Internet Governance forum at the U.N.’s European headquarters, Qi Xiaoxia went on to note that “[t]he condition is that they have to abide by Chinese law and regulations. That is the bottom line. And also, that they would not do any harm to Chinese national security and national consumers’ interests.”

Considered one of the most comprehensive legislative acts in Chinese history, mainland China’s cybersecurity law went into effect just six months ago. The law’s primary purpose is to allow Chinese officials unfettered access into the digital lives of their population. Among the law’s many provisions, tech companies must store Chinese data locally, submit to data surveillance, and provide censorship tools to prevent users from subverting the government’s sovereignty over expression.

The law also provides Chinese officials with the power to conduct “national security reviews” of technology that companies want to use or sell in the Chinese market. These security reviews may allow China to identify weaknesses in foreign technology security to exploit in their own intelligence gathering, according to a report by the Insikt Group.

Violators of the law face fines of up to 1 million Yuan (~$150,000) or even potential criminal charges.

Reactions among U.S. technology executives haven been overtly negative according to a new survey conducted by the U.S.-China Business Council. Of the respondents surveyed, 82% noted that they “are concerned about the impact of China’s cyber and data regulations.”

Driving this concern is the fear that Chinese oversight may put their intellectual property at risk. Early in December, at China’s state-sponsored World Internet Conference in Wuzhen, representatives from 60 foreign technology companies and trade groups expressed concerns over China’s “national security reviews.” According to the representatives, extensive review of their network equipment could reveal proprietary source code putting their trade secrets at risk.

In 2016, internet watchdog firm Freedom House placed China as the world’s “worst abuser of internet freedom” for the second consecutive year.

Despite these concerns, some companies are moving forward with compliance. Shortly after the law went into effect, Apple Inc. announced plans to build a new data center in mainland China in order to conform with the law’s data localization requirements. Since that announcement, Apple has taken down hundreds of apps at the request of Chinese officials, including Microsoft’s Skype, from its online store. Many of the removed apps enabled users in mainland China to access virtual private networks (VPNs), a means of evading censorship.

Apple’s close relationship with Chinese regulators has not gone unnoticed. In an open letter following Apple’s removal of the VPN apps, U.S. Senators Patrick Leahy (D-Vermont) and Ted Cruz (R-Texas) asked the iPhone giant to “push back” on China’s control over free expression. According to the letter, companies like apple “have both an opportunity and a moral obligation to promote freedom of expression and other basic human rights.”

In any event, the position of Chinese regulators remains clear. According to Qi Xiaoxia, “[w]e are of the idea that cyberspace is not a space that is ungoverned. We need to administer, or supervise, or manage, the internet according to law.” And if foreign tech companies want access to mainland China’s digital market, they will have to comply with China’s laws. 
By Trevor Schmitt


On October 4-6th, 2017, The George Washington University Law School hosted the 3rd annual Privacy + Security Forum. The event, organized by GW Law’s Daniel Solove and Berkeley’s Paul Schwartz, is a veritable who’s who of the global privacy and data protection law landscape with hundreds of speakers addressing a range of topics. As with any privacy and data protection event held in the last five years, the General Data Protection Regulation (“GDPR”) was a primary focus of panel discussions.

For those unfamiliar with the massive European Union (“EU”) regulation, the GDPR is a privacy and data protection law going into effect May, 2018. As a replacement for the EU’s current data protection law, the GDPR regulates the collection, use, and storage of personal information related to individuals in the EU. Key to this regulation is its inclusion of non-EU organizations that offer goods or services to individuals in the EU. This means that organization with any identifiable information related to individuals in the EU should be worried about the GDPR. And with fines up to €20 million or 4 percent of global annual turnover (whichever is higher) for non-compliance, that concern seems justified.

The event continued many of the ongoing conversations relating to issues involved in private sector efforts toward compliance. But that’s not all. Among these issues several overarching themes rose above the normal fray of navigating technical GDPR compliance. Those charged with conforming to the GDPR should be aware of these emerging perspectives: 

“Do what you say. Say what you do. Be able to prove it.” This quote, brought to light by Constantine Karbaliotis, exemplifies the need for entities regulated by the GDPR to provide extensive documentation of their compliance efforts. Doing the right thing is great. But show your work. Not being able to prove compliance with the GDPR is just as damaging as not being compliant at all.

The GDPR is not going away. May 2018 marks the beginning—not the end—of GDPR compliance. The regulation contains a myriad of requirements associated with individual personal information that fundamentally changes how technology will operate. These include the right to erasure (to have one’s data deleted from an entire system), data portability (to move data from one service to another), and privacy by design (keeping privacy involved in every step of engineering data systems) to name a few. Many organizations will need to overhaul their systems to become compliant. These provisions, as well as others contained in the GDPR, promise a transformation of how technology will handle personal data on a global scale.

The most obvious nails will be hammered first. The governmental organizations (Data Protection Authorities) charged with GDPR enforcement have limited resources. They cannot investigate every organization who handles EU personal data. So unless an organization falls into the spotlight realm of GAFA (Google, Apple, Facebook, Amazon), chances are it will not be an initial target of investigation. This leeway, however, only goes so far. Outdated privacy policies, overt non-compliance indicators, and massive data breaches will raise flags to regulators that an organization may not be compliant.

Brexit might leave the UK out in the cold. As of March 29th, 2019, the United Kingdom (“UK”) will no longer be part of the EU. This means that the UK will become a third country according the the GDPR. Under the GDPR, third countries must undergo a verification process to determine if municipal data laws provide adequate protection for handling personal data related to individuals in the EU. And while lawmakers have announced their intention to adopt an almost exact copy of GDPR regulations, the former EU State must still apply for adequacy following its official exit from the EU. These means that, at least for a time, the UK will not have free flowing data from the EU.


Despite these additional perspectives on the global concerns over GDPR compliance, much is still unknown about how the regulation will impact organizations at scale. What is clear, however, is that organizations who want continued access to EU markets must be compliant or face potentially debilitating fines. These issues will continue to be explored in the Privacy + Security Forum’s internationally-focused sister event early next year. 
By Kelley Chittenden

Two sources with direct knowledge of Facebook’s discussions with Egypt over its Free Basics service said the Egyptian government blocked it because Facebook refused to allow the government to circumvent security and conduct surveillance on its citizens, Reuters reports. Free Basics, which allows anyone with a computer or smartphone to access a limited set of free Internet services was launched in Egypt in October 2015 and used by over three million Egyptians, one third of whom had never previously had Internet access. Facebook strengthened security protections in September, allowing users to connect seamlessly with secured sites.
By Kelley Chittenden 

Mark Zuckerberg’s plans to “connect the entire world” hit a speed bump the first week of February when Indian regulators blocked Free Basics, his free mobile data program. The Telecom Regulatory Authority of India (TRAI) issued regulations banning differential pricing for data services in order to restrict the ability of mobile phone companies to “shape the users’ Internet experience” by offering free access to certain services. According to The Guardian, the process began in March of 2015 with a consultation paper recommending telecom operators be allowed to charge extra for third-party apps and services such as WhatsApp, Facebook and Twitter. TRAI sought public comment on twenty questions, which led to a “spirited, pro-net-neutrality campaign” called Save The Internet and 1.1 million responses against differential pricing by late April.
By Kelley Chittenden

Facebook CEO Mark Zuckerberg said hate speech “has no place on Facebook” while speaking at a town hall in Berlin.  After online racism increased due to the influx of migrants in 2015, Facebook, Google, and Twitter made a deal with Germany that they would remove hate speech posts within twenty-four hours. Zuckerberg credits learning more about German law as the catalyst for Facebook’s expanded view of protected groups (to now include migrants). Reuters reports that Facebook has hired a Bertelsmann business services unit to monitor the German platform for racist posts.
By Kelley Chittenden

A Belgian court order threatened Facebook with fines of up to €250,000 per day if the social network did not stop tracking Internet users without Facebook accounts. Research reveals Facebook tracks users that visit its page regardless of whether the user has an account or has opted out of tracking in the EU. The cookie placed on the user’s device allegedly allows Facebook to access information whenever the user visits Facebook pages or pages that include “like” or “share” links. Facebook claims the cookie protects user security, and the social network is appealing the order in part due to its inclusion of English words such as “cookie” and “web browser” to describe its tracking technology. Although Belgian law requires rulings be made in Dutch, French, or German, “web browser” in Dutch is “webbrowser,” and an Internet cookie is “cookie” in each language—Facebook appears to have a weak argument in this respect.
By Matt Klinger

In October, the European Commission's official data protection advisory group, the Article 29 Working Party, issued its latest guidance for complying with the EU's e-Privacy Directive (affectionately known as the "Cookie Directive").

Among other provisions the new guidance provides that when accessing a website, users must have access to "all necessary information" about the types and purposes of cookies used by the site.  In addition, the guidance clarifies that a user's consent to place cookies on a device, which is required by the Cookie Directive, must be sought before cookies are set or read.  Meanwhile, the Wall Street Journal reports that Google, Microsoft, and Facebook are each developing online tracking methods that could eventually make cookies, and the new guidance, obsolete.
By Sam Obenhaus

While the United States has one of the highest corporate tax rates in the developed world, it is often pointed out that the effective tax rate – what corporations actually pay – is significantly lower than the official rate.  For a number of tech companies, this is largely due to one man: Feargal O’Rourke, the head of PricewaterhouseCoopers’ tax practice in Ireland.

Ireland, of course, is at the center of many tech companies tax strategies.  O’Rorke is a chief architect of many of these plans, including those used by Google, LinkedIn, and Facebook.  Each of those companies funnels its profits through Ireland on their way to other tax havens, such as Grand Cayman and the Isle of Man.  These strategies are estimated to cost the U.S. federal government and its European counterparts an estimated $100 billion per year in lost revenue.

With austerity gripping much of Europe and sequestration in the United States, Ireland has found itself in the middle of a controversy.  Governments need more revenue, and some U.S. lawmakers have started calling Ireland a tax haven.  But O’Rourke – perhaps Ireland’s biggest defender – is undeterred. 

He points out that Ireland’s tax strategies have led many multinational corporations to set up offices in Ireland.  These operations are estimated to employee approximately 100,000 people.  Further, he notes that the United States and other countries could tip the balance overnight by simply changing their own tax laws.  What O’Rourke may be less willing to discuss is his role in shaping Ireland’s tax policies. 

Bloomberg has more on O’Rourke, while Reuters reports on Ireland’s recent moves to shed its image as a tax haven.
By Elizabeth Gibson
 

Under pressure from European regulators, Facebook stopped using facial recognition in Europe last year and deleted existing data on European users. However, PC World and the Washington Post are reporting that the issue may be resurfacing.

Facebook released proposed changes to its privacy policy last week, and German regulators told PC World that they are concerned that the policy mentions facial recognition. For now, Irish regulators said they have confirmed with Facebook that the feature is still disabled in Europe.

Read more at PC World and the Washington Post