<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Because I am Here &#187; Titus</title>
	<atom:link href="http://www.aarontitus.net/blog/author/titus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.aarontitus.net/blog</link>
	<description>Aaron Titus' Personal Blog</description>
	<lastBuildDate>Tue, 13 Jul 2010 20:45:30 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Draft NSTIC Request</title>
		<link>http://www.aarontitus.net/blog/2010/07/13/draft-nstic-request/</link>
		<comments>http://www.aarontitus.net/blog/2010/07/13/draft-nstic-request/#comments</comments>
		<pubDate>Tue, 13 Jul 2010 19:47:59 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/2010/07/13/draft-nstic-request/</guid>
		<description><![CDATA[The White House and Department of Homeland Security have recently released a public draft of the National Strategy for Trusted Identity in Cyberspace (NSTIC). The NSTIC outlines an ambitious identity management strategy for the United States, but public discussion has been extremely limited. The NSTIC is a very significant policy document which may have an [...]]]></description>
			<content:encoded><![CDATA[<p>The White House and Department of Homeland Security have recently released a public draft of the National Strategy for Trusted Identity in Cyberspace (NSTIC). The NSTIC outlines an ambitious identity management strategy for the United States, but public discussion has been extremely limited. The NSTIC is a very significant policy document which may have an impact on internet commerce, online speech, identity management, identity trust frameworks, and online anonymity. We, the undersigned, are concerned that the current public comment period is insufficient for a policy document of this magnitude and request an extension of the public comment period in order to pursue public dialog.</p>
<p>A policy of this magnitude should be given at least a 90 day public comment period. However, public discussion has been limited and the discussion period is almost over. Therefore, we request that the public comment period be extended for at least 30 days to facilitate more robust public discussion. We also request that subsequent public comment periods on this topic extend for at least 90 days.</p>
<p>We are concerned that the NSTIC is silent on an implementation timeline and other significant details currently missing from the draft. We request clarification on the agency’s proposed timeline and process. We also request an opportunity to convene an in-person discussion with an appropriate White House or DHS official to discuss this important matter and engage in further public discussion.</p>
<p>We look forward to supporting your efforts to engage a robust public discussion on the NSTIC.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/07/13/draft-nstic-request/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Oral and Written Testimony of Aaron Titus Before the Senate Committee on Homeland Security and Governmental Affairs on May 5, 2010</title>
		<link>http://www.aarontitus.net/blog/2010/05/25/oral-and-written-testimony-of-aaron-titus-before-the-senate-committee-on-homeland-security-and-governmental-affairs-on-may-5-2010/</link>
		<comments>http://www.aarontitus.net/blog/2010/05/25/oral-and-written-testimony-of-aaron-titus-before-the-senate-committee-on-homeland-security-and-governmental-affairs-on-may-5-2010/#comments</comments>
		<pubDate>Tue, 25 May 2010 14:32:32 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=195</guid>
		<description><![CDATA[Oral Testimony of
Aaron Titus
Privacy Director, Liberty Coalition
Attorney, J.C. Neu &#038; Associates
before the
Senate Committee on Homeland Security and Governmental Affairs
May 5, 2010
Click here for Aaron Titus&#8217; Written Testimony on S1317 and S2820 [DOC]

C-Span Link
Chairman Lieberman, Ranking Member Collins and Members of the Committee. Thank you for allowing me to be here.
My name is Aaron Titus. I [...]]]></description>
			<content:encoded><![CDATA[<p><center><strong>Oral Testimony of<br />
Aaron Titus<br />
Privacy Director, <a href="http://www.libertycoalition.net/">Liberty Coalition</a><br />
Attorney, <a href="http://www.jeffreyneu.com">J.C. Neu &#038; Associates</a><br />
before the<br />
<a href="http://hsgac.senate.gov/">Senate Committee on Homeland Security and Governmental Affairs</a><br />
May 5, 2010</strong><br />
Click here for <a href='http://www.aarontitus.net/blog/wp-content/uploads/2010/05/Aaron-Titus-Written-Testimony-on-S1317-and-S2820.doc'>Aaron Titus&#8217; Written Testimony on S1317 and S2820</a> [DOC]</p>
<p><object id='cspan-video-player' classid='clsid:d27cdb6eae6d-11cf-96b8-444553540000' codebase='http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,0,0' align='middle' height='500' width='410'><param name='allowScriptAccess' value='true'/><param name='movie' value='http://www.c-spanvideo.org/videoLibrary/assets/swf/CSPANPlayer.swf?pid=293332-2&#038;start=1227&#038;end=1622'/><param name='quality' value='high'/><param name='bgcolor' value='#ffffff'/><param name='allowFullScreen' value='true'/><param name='flashvars' value='system=http://www.c-spanvideo.org/common/services/flashXml.php?programid=223740&#038;style=full&#038;start=1227&#038;end=1622'/><embed name='cspan-video-player' src='http://www.c-spanvideo.org/videoLibrary/assets/swf/CSPANPlayer.swf?pid=293332-2&#038;start=1227&#038;end=1622' base='http://www.c-spanvideo.org/videoLibrary/assets/swf/' allowScriptAccess='always' bgcolor='#ffffff' quality='high' allowFullScreen='true' type='application/x-shockwave-flash' pluginspage='http://www.macromedia.com/go/getflashplayer' flashvars='system=http://www.c-spanvideo.org/common/services/flashXml.php?programid=223740&#038;style=full&#038;start=1227&#038;end=1622' align='middle' height='500' width='410'></embed></object><br />
<a href="http://www.c-spanarchives.org/program/ID/223740&#038;start=1227&#038;end=1622">C-Span Link</a></center></p>
<p>Chairman Lieberman, Ranking Member Collins and Members of the Committee. Thank you for allowing me to be here.</p>
<p>My name is Aaron Titus. I am the Privacy Director for the Liberty Coalition and an attorney at the law firm, J.C. Neu and Associates.  The Liberty Coalition  works with more than 80 partner organizations from across the political spectrum to preserve the Bill of Rights, personal autonomy and individual privacy.  The Liberty Coalition works with, but does not speak on behalf of our partners.</p>
<p>I am aware that many in this audience have been personally affected by gun violence. Managing guns and other weapons is a matter of public concern.  Regardless of one&#8217;s position on gun safety and gun control, the Supreme Court has unambiguously ruled that the Right to Keep and Bear Arms is an individual, Constitutionally enumerated right.  The Second Amendment is not absolute, and the government may regulate the Right to Keep and Bear Arms in a number of ways.</p>
<p>But Senate Bill 1317 goes too far.  The bill should be titled, &#8220;<strong>The Gun Owners Are Probably All Terrorists Act</strong>,&#8221; because it strips citizens of their Constitutional Right to Keep and Bear Arms without any meaningful due process. And Senate Bill 2820 should be called, &#8220;<strong>The National Firearm Registry Act</strong>&#8221; because it creates a national firearms registry, so let&#8217;s call it what it is.</p>
<h2>National Firearms Registry</h2>
<p>If you want to make a National Firearms Registry, then go through the front door, call it what it is, and have a meaningful public discussion.</p>
<p>Senate Bill 2820 creates a massive database of names and detailed personal information of each law-abiding citizen who purchases a gun.</p>
<p>The bill disingenuously purports to target terrorists, but in fact only one ten-thousandth of one percent of these records will belong to people on watch lists.   Every year, only 200 new watch-list records will be created.  But the system will generate more than 14 million new records on law-abiding citizens.  Once collected, there&#8217;s no limit on what the information may be used for, and no legal requirement to ever delete it.</p>
<p>At the very least, we should call this bill what it is: A National Gun Registry Act.</p>
<h2>Senate Bill 1317</h2>
<p>Reading Senate Bill 1317, one would think that convicted terrorists are allowed to own guns. That is simply not true. Convicted terrorists cannot own guns.</p>
<p>Not only that, but today&#8217;s discussion totally misses the point.  This committee shouldn&#8217;t spend time debating whether to take away Terrorists&#8217; guns, bombs, cell phones, or other instruments of terror.  If a person is a dangerous terrorist, then he should be thrown in jail. <strong>The only things a real, convicted terrorist should own are an orange jumpsuit and a pair of leg chains.</strong></p>
<p>Assuming, for a moment, that everyone on a watch list is a terrorist as this bill suggests, then I propose that this committee start throwing every single one of those hundreds of thousands of people in jail, starting today.</p>
<p>But you and I know that the Constitution won&#8217;t let you do that.  And if you can&#8217;t throw citizens in jail for being on a watch list, you can&#8217;t revoke their Second Amendment rights, either.</p>
<h2>How Senate Bill 1317 Works</h2>
<p>Right now, a citizen who is denied a firearms purchase has the right to know exactly why, and appeal.  Senate Bill 1317 changes that.  If a citizen&#8217;s name is on a watch list, the Attorney General doesn&#8217;t have to tell him why he was denied, if he thinks that tipping off the citizen might compromise national security.</p>
<p>If a citizen is able to appeal the decision in court, things only get harder and more confusing. Neither the citizen nor his attorney can see the evidence against him—they can only see summaries or redacted versions.  Not even the judge may consider the unredacted evidence.</p>
<p>A citizen will lose his appeal if the Attorney General can prove, by a preponderance of the evidence, not that the individual poses a risk, or that the person is a terrorist, or even that the person is under investigation; rather, the Attorney General must only demonstrate that the citizen has been placed on a watch list.</p>
<p>Once that has been proven, the appeal is over and the citizen loses his Second Amendment Right to Keep and Bear Arms.  The citizen will not have a chance to introduce evidence of innocence, abuse of Executive discretion or mount any other meaningful defense.</p>
<p>You know, I have heard of this type of judicial system applied to non-citizens (&#8221;enemy combatants&#8221; in Guantanamo Bay), but never to citizens of the United States, especially on a matter of Constitutional importance. Times may have changed, Mr. Chairman, but fortunately the Constitution has not.</p>
<h2>Terror Watch Lists</h2>
<p>Criminal and terrorist investigations must be kept confidential.  But Senate Bill 1317 misunderstands that &#8220;investigation&#8221; is not &#8220;guilt.&#8221;  Suspicion is not a Conviction. And the law has a technical word for people who have not been convicted of a crime: It&#8217;s called &#8220;innocent.&#8221;</p>
<p>Terror watch lists have no meaningful element of due process, and are therefore fundamentally different from other lists scanned by the <em>National Instant Criminal Background Check System</em>.<br />
Terror watch lists, by their nature, are designed to be over-broad.  A name on a terror watch list is evidence of government interest in a person, not proof of terrorism.  The bald allegation of a suspicion of terrorist inclinations is insufficient evidence to overcome an individual&#8217;s Right to Keep and Bear Arms.<br />
Mr. Chairman, suspicion is not a conviction.</p>
<h2>Summary</h2>
<p>Senate Bill 1317 takes away a citizen&#8217;s right to face his accusers. This bill takes away a citizen&#8217;s right to appeal. This bill takes away a citizen&#8217;s right to due process. And if you can&#8217;t throw them in jail because they&#8217;re on a watch list, then you can&#8217;t revoke their Second Amendment rights, either.   Mr. Chairman, this bill is unconstitutional.<br />
I urge this committee to reject Senate Bills 1317 and 2820.  I am happy to respond to questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/05/25/oral-and-written-testimony-of-aaron-titus-before-the-senate-committee-on-homeland-security-and-governmental-affairs-on-may-5-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Letter to VA Board of Bar Examiners</title>
		<link>http://www.aarontitus.net/blog/2010/03/23/letter-to-va-board-of-bar-examiners/</link>
		<comments>http://www.aarontitus.net/blog/2010/03/23/letter-to-va-board-of-bar-examiners/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 12:55:51 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=190</guid>
		<description><![CDATA[I mailed the following letter to the Virginia Board of Bar Examiners on March 22, 2010, after receiving a letter with all of my sensitive information printed on a single sheet of paper.
Robert E. Glenn, President
Virginia Board of Bar Examiners
c/o Julie O’Kelly
2201 W. Broad Street, Suite 101
Richmond, VA 23220
Mr. Glenn:
I recently took the Virginia Bar [...]]]></description>
			<content:encoded><![CDATA[<p>I mailed the following letter to the Virginia Board of Bar Examiners on March 22, 2010, after receiving a letter with all of my sensitive information printed on a single sheet of paper.</p>
<p>Robert E. Glenn, President<br />
Virginia Board of Bar Examiners<br />
c/o Julie O’Kelly<br />
2201 W. Broad Street, Suite 101<br />
Richmond, VA 23220</p>
<p>Mr. Glenn:<br />
I recently took the Virginia Bar Exam. I received a letter dated January 27, 2010 which contained instructions for the February exam. To my horror, I saw that the letter contained my full name, date of birth, social security number, school, MPRE score, results of my Character and Fitness Questionnaire, address, and email address on the form. This single piece of paper contains enough information for someone to impersonate me and commit identity theft. I count myself lucky that someone else didn&#8217;t check my mailbox the day this letter arrived.</p>
<p>I was sure that such an oversight was an isolated error, so I called the Board of Bar Examiners’ office to find out how a mistake like this could happen, to ask for a copy of the board&#8217;s privacy policy, and asked who changed my authorization to put my identity at such substantial risk.</p>
<p>I was informed that the mailing of my sensitive personal information in a single letter was <strong>deliberate</strong>, <strong>the Board has no privacy policy</strong>, and that <strong>the Board authorized this reckless use of my personal information</strong>, against my wishes and authorization.</p>
<p>This letter is to object to some of the Board&#8217;s more dangerous privacy practices as I currently understand them, and request additional information.<br />
Please send a copy of the Board’s privacy policy.  If one does not exist, please send the following information: </p>
<ul>
<li>How long will the Board keep my personal information on file, and for what purposes?</li>
<li>Does the Board store my personal information on encrypted hard drives?</li>
<li>On how many computers does the Board store copies of my personal information, and where do the hard drives go when the computers are retired or replaced?</li>
<li>With what entities does the Board share my personal information, and under what conditions?</li>
<li>What security measures, if any, does the Board use to detect intrusion or improper use by employees?</li>
</ul>
<p>I understand that the Board needs to verify personal information with examinees. However, even minor common-sense steps would substantially increase security.  These may include:</p>
<ul>
<li>Sending separate mailings, each of which lacks a full set of personal information.</li>
<li>Omit digits of the social security number.</li>
<li>Write and disseminate a Privacy Policy, and update your organization’s privacy practices.</li>
</ul>
<p>I hope that the Board takes these matters seriously, and updates its privacy policies and practices immediately.  The Board of Bar Examiners has violated my trust, and I fear that the Board will continue to put me at risk of identity theft and other harms.</p>
<p>I look forward to answers on these most pressing issues.  I also stand ready to assist in your effort to improve your privacy practices.</p>
<p>Sincerely,<br />
Aaron Titus</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/03/23/letter-to-va-board-of-bar-examiners/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to Avoid a Legal 500 Error with your Privacy Policy</title>
		<link>http://www.aarontitus.net/blog/2010/03/17/how-to-avoid-a-legal-500-error-with-your-privacy-policy/</link>
		<comments>http://www.aarontitus.net/blog/2010/03/17/how-to-avoid-a-legal-500-error-with-your-privacy-policy/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 12:59:36 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=179</guid>
		<description><![CDATA[Note: A version of this article originally appeared on the Security Catalyst Blog
Legal Programming
By Aaron Titus
I&#8217;m an awesome programmer. The only thing keeping me from Python, PHP, or Ruby coding awesomeness is knowledge… and skill… and training… and, um practice.  OK, I may not be a Ruby all-star, but I could be if I [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: A version of this article originally appeared on the <a href="http://www.securitycatalyst.com/how-to-avoid-a-legal-500-error-with-your-privacy-policy/">Security Catalyst Blog</a></em><br />
<div id="attachment_184" class="wp-caption alignright" style="width: 310px"><img src="http://www.aarontitus.net/blog/wp-content/uploads/2010/03/500-Legal-Error-cropped-300x206.jpg" alt="Avoid a Legal 500 Error. Debug your privacy policy." title="Legal 500 Error" width="300" height="206"  class="size-medium wp-image-184"/><p class="wp-caption-text">Avoid a Legal 500 Error. Debug your privacy policy.</p></div></p>
<h1>Legal Programming</h1>
<p><strong>By Aaron Titus</strong></p>
<p>I&#8217;m an awesome programmer. The only thing keeping me from Python, PHP, or Ruby coding awesomeness is knowledge… and skill… and training… and, um practice.  OK, I may not be a Ruby all-star, but I could be if I wanted to. Likewise, you can do anything for yourself that an attorney can do for you, including writing legal documents. Lawyers just happen to have knowledge, skill, and training.  And if I wanted an iPhone app, I&#8217;d talk to a programmer.  If I wanted legal documents, I&#8217;d talk to a lawyer.</p>
<p>In fact, <em>lawyers are programmers</em>. Writing legal documents—like privacy policies—is just like writing code.</p>
<p><span id="more-179"></span>Imagine that your boss tells you, &#8220;I need a widget. I&#8217;m sure other people in the open source community have done similar things. Just go grab some code and slap it together by the end of the day.”  Of course, that&#8217;s crazy. You can&#8217;t just slap code together. In what language is the code written? Will it play well with existing code? How complete is the API? What are the requirements? What about security? What about debugging?</p>
<p>Yet this is exactly how we treat privacy policies. We go grab some “open source” or “boilerplate” privacy policy, slap it together with a boilerplate Terms of Service, and think we’re good to go.  But unlike poorly-written code which will cause an error as soon as it is compiled, you won’t know whether you’ve created a Legal 500 error for months or years—long after it’s too late to fix.</p>
<h1>Privacy Policy Principles</h1>
<p>The purposes of a privacy policy are to: 1. Help inform and train your employees about your privacy practices, 2. Inform your customers about your privacy practices, and 3. Avoid liability and FTC action.  As I explained <a href="http://www.securitycatalyst.com/6-things-every-ceo-should-know-about-privacy-policies/">previously</a>, adhering to the following principles will allow you to accomplish all three goals:</p>
<ul>
<li><strong>Be Honest</strong>. Your mamma was right: Honesty is the best (privacy) policy.
<ul>
<li><strong>Don&#8217;t Over-Promise</strong>. Statements like &#8220;privacy is our top priority&#8221; may be enforced by the FTC as a privacy promise. Don&#8217;t box yourself into a corner.</li>
<li><strong>Don&#8217;t Under-Promise</strong>.  Under-promising can violate regulations and more importantly, scare off customers.</li>
<li><strong>Tell the Whole Truth</strong>.  Failure to talk about less-desirable privacy practices may be a misleading business practice.</li>
</ul>
</li>
<li><strong>Be Complete and Conspicuous</strong>.</li>
<li><strong>Adapt to Changing Business Practices</strong>.  A privacy policy which was accurate six months ago may not be today.</li>
<li><strong>Get it Right the First Time</strong>. Allowing yourself room to change will save headaches long-term, as material changes to privacy policies require additional consent.</li>
<li><strong>If you Say it, Do it</strong>.  Generally no magic words are required in privacy policies.  The best approach to avoid liability is to stick to your policy.</li>
<li><strong>It&#8217;s Your Business</strong>. As an executive, it&#8217;s your responsibility to make sure that your privacy policy is accurate and complete.</li>
</ul>
<h1>Custom Programming Your Privacy Policy</h1>
<p><strong>Nobody, especially the legislature, has solved your problems for you</strong>.  If you create an innovative product or service, then it will raise new questions of law, ethics, and privacy which have never been asked or answered.  You can&#8217;t expect that somebody else&#8217;s recycled privacy policy will meet your needs, any more than you can expect that recycling old code will yield innovation.  Imagine for a moment that you have just developed an iPhone app.  The app communicates with a smart scale using Bluetooth technology, then interfaces with the Google Health API to transfer a user&#8217;s weight history to the Weight Watchers website, then optionally posts the summarized results of the user&#8217;s weight loss to his Facebook page and Twitter account.  Which of the following is true:</p>
<ol type="A">
<li>You can adopt HIPPA as your privacy policy. HIPPA privacy rules apply.</li>
<li>The FTC is interested in your privacy policy and practices.</li>
<li> You can later use the weight &amp; contact information to market your next iPhone app, &#8220;Smart Dieter.&#8221;</li>
</ol>
<p>The answers may surprise you:</p>
<ol type="A">
<li><strong>False</strong> on both accounts: 1. HIPPA is not a privacy policy. Nobody, especially Congress has written your privacy policy for you. 2. Your customers are not protected by HIPPA regulations, because they probably don&#8217;t apply to you.</li>
<li><strong>True</strong>.  The FTC is always interested in your privacy policies and practices, and even passing assurances of privacy like &#8220;Privacy is our Number 1 Priority&#8221; may be enforced as a privacy promise.</li>
<li><strong>Probably Not</strong>. Unless you have written a clear privacy policy that puts your customers on notice, you may be prohibited from reusing their personal information for any reason, even if they would have consented to such a use.</li>
</ol>
<p>Your privacy policy must reflect your unique business processes, your unique business model, and your unique user needs.  If you think that Congress (or anybody, for that matter) have answered the new questions of privacy raised by your iPhone app, then I have a bridge in Brooklyn I&#8217;d like to sell you.  Even if HIPPA privacy regulations applied (which they don’t), I can guarantee that they were not written with your app in mind.  Likewise, if you are doing anything truly innovative, any canned privacy will fail to meet your needs.</p>
<p>Boilerplate legal documents can get people and companies in trouble. Although sometimes there <em>are</em> magic words from a statute or regulation that should be quoted to order to protect your rights, <strong>most boilerplate is not magic—it’s lazy</strong>.  Lawyers do a lot of legal debugging, because improper boilerplate language can be downright harmful.  Unless you do your own legal programming to meet your individual needs, you are sure to accidentally waive a right, break the law, incur the ire of the FTC, or create a contradiction and cause a &#8220;Legal 500 Error.&#8221;</p>
<h1>A Living Document</h1>
<p>Because technology, business needs, and information demands constantly change, you must consistently update your privacy policy to reflect those changes. Fortunately, privacy policies are extremely flexible documents, with very few formal legal language or &#8220;magic words&#8221; requirements, so updating them is easy… if you remember to do it. CEOs often find that adapting a business plan to changing market conditions is time-consuming, and privacy policies can fall by the way side.</p>
<p>Before you update your privacy policy, though, keep in mind that there may be consequences to making material changes.  When you revise a policy, information collected under the former policy must still be treated according to the terms of the original Privacy Policy, unless you get some sort of assent from your customers, or face the potential ire of the FTC.  It is always better to get it right the first time.</p>
<h1>Take Charge</h1>
<p>As an executive, do these three things:</p>
<ol>
<li><strong>Read Your Privacy Policy</strong>. First, do you understand what the policy means? Second, how does the privacy policy translate to concrete business practices in each of your departments? Third, does the policy match actual practice? Fourth, what is missing from your privacy policy that a reasonable customer would want to know about? Fifth, what changes must you make to your business practices (or the privacy policy) to make them the same?</li>
<li><strong>Regularly Update Your Privacy Policy</strong>.  Many companies have internal processes to regularly review and update business plans, department objectives, security, and compliance.  Make sure that your privacy policy is on your list of documents to review.</li>
<li><strong>Do a Privacy Policy Legal Review</strong>.  Avoid a &#8220;Legal 500 Error&#8221; by making sure that your privacy policy is complete and compliant.</li>
</ol>
<p><code></code><code></code></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/03/17/how-to-avoid-a-legal-500-error-with-your-privacy-policy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Three Elements of Action</title>
		<link>http://www.aarontitus.net/blog/2010/02/12/the-three-elements-of-action/</link>
		<comments>http://www.aarontitus.net/blog/2010/02/12/the-three-elements-of-action/#comments</comments>
		<pubDate>Fri, 12 Feb 2010 08:30:05 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=170</guid>
		<description><![CDATA[ Note: This article was originally published on the Security Catalyst Blog.
Your meeting was supposed to last just 45 minutes, but the first 35 have been devoted to the first agenda item.  Most eyes have glazed over and you are the only one speaking. Just as tired as everyone else you say, “OK, so [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-2381" src="http://www.securitycatalyst.com/wp-content/uploads/2009/10/Yawn-333-x-500.jpg" alt="Yawn" width="333" height="500" /> <em>Note: This article was originally published on the <a href="http://www.securitycatalyst.com/the-three-elements-of-action/">Security Catalyst Blog</a>.</em></p>
<p>Your meeting was supposed to last just 45 minutes, but the first 35 have been devoted to the first agenda item.  Most eyes have glazed over and you are the only one speaking. Just as tired as everyone else you say, “OK, so we all agree that we’re going to do that?” Hearing no objection, you move on to the next subject.</p>
<p>You are relieved to move on, but don&#8217;t be surprised when you have to rehash the same subject at the next meeting. Do not mistake movement for progress; your discussion was an utter failure because it lacked the fundamental element to any progress: An Action Item.</p>
<p><strong>Every action item is comprised of three things:</strong></p>
<ul><strong> </strong></p>
<li><strong>A Person</strong></li>
<li><strong>A Deliverable</strong></li>
<li><strong>A Date</strong></li>
<p><strong> </strong></ul>
<p>Absent one of these three things, a decision is not an action item. <em>It is a wish.</em> All would-be &#8220;action items,&#8221; &#8220;goals,&#8221; or &#8220;decisions&#8221; which  fail to include one or more of these components were a waste of your breath and their time. Action items must be clear, measurable, and have accountability.  Unless you want to rehash the same issue at the next meeting, never walk away without identifying a person, a deliverable and a date for each action item, regardless of the subject matter. Let’s analyze some would-be “action items” from actual meetings:</p>
<p><strong>Assignment 1</strong>: &#8220;Development of a power point presentation to train staff.&#8221;</p>
<table border="”1”" cellpadding="”2”">
<tbody>
<tr>
<td><strong>Person</strong></td>
<td><em>None</em>.</td>
</tr>
<tr>
<td><strong>Deliverable</strong></td>
<td><em>A powerpoint presentation</em>. However, the subject matter of the presentation is not clear in this context.</td>
</tr>
<tr>
<td><strong>Date</strong></td>
<td><em>None</em>. This presentation will never be late, because it’s never due.</td>
</tr>
<tr>
<td><strong>Outcome</strong></td>
<td><em>Inaction</em>. This is a wish, not an action item.</td>
</tr>
</tbody>
</table>
<hr /><strong>Assignment 2</strong>: &#8220;Staff will take decisive action aimed within the next 30 days at having the new privacy policy ready to be trained upon.&#8221;</p>
<table border="”1”" cellpadding="”2”">
<tbody>
<tr>
<td><strong>Person</strong></td>
<td><em>Nobody</em>, or more specifically, everybody.  Note the excessive use of passive voice.  An action assigned to everybody is nobody’s responsibility.</td>
</tr>
<tr>
<td><strong>Deliverable</strong></td>
<td><em>None</em>. If you can tease a deliverable out of this, you deserve a raise.  What exactly does “decisive action” and “ready to be trained upon” mean?</td>
</tr>
<tr>
<td><strong>Date</strong></td>
<td><em>30 Days</em>. However, this date doesn’t mean much because there’s no deliverable or assignment.</td>
</tr>
<tr>
<td><strong>Outcome</strong></td>
<td><em>Inaction</em>. This is a wish, not an action item.</td>
</tr>
</tbody>
</table>
<hr /><strong>Assignment 3</strong>: &#8220;Jane Davis should work with the Communications Department to discuss the issue of posting the entire training program on the website for free downloading to all visitors.&#8221;</p>
<table border="”1”" cellpadding="”2”">
<tbody>
<tr>
<td><strong>Person</strong></td>
<td><em>Jane Davis</em>.</td>
</tr>
<tr>
<td><strong>Deliverable</strong></td>
<td><em>Hold a discussion</em> with the Communications Department.  Although they probably intend for Jane to post the training program, her only assignment is to have a discussion.  It might have been written better, “coordinate with the Communications department to post the training program in by the end of the month.”</td>
</tr>
<tr>
<td><strong>Date</strong></td>
<td><em>None</em>.</td>
</tr>
<tr>
<td><strong>Outcome</strong></td>
<td><em>Inaction</em>. This is a wish, not an action item.</td>
</tr>
</tbody>
</table>
<hr /><strong>Assignment 4</strong>: &#8220;Kevin Jones will identify key end-users, such as educational and other relevant organizations, and develop a database of end-users, by the end of January.&#8221;</p>
<table border="”1”" cellpadding="”2”">
<tbody>
<tr>
<td><strong>Person</strong></td>
<td><em>Kevin Jones</em>.</td>
</tr>
<tr>
<td><strong>Deliverable</strong></td>
<td><em>Database of end-users</em>.  Of course, with this responsibility, Kevin must also have the authority and resources to execute the assignment.</td>
</tr>
<tr>
<td><strong>Date</strong></td>
<td><em>January 31st</em>.</td>
</tr>
<tr>
<td><strong>Outcome</strong></td>
<td><em>Action</em>. This is an action item.</td>
</tr>
</tbody>
</table>
<p>The three components of action are a <em>person, a deliverable, and a date</em>.  Here&#8217;s your assignment: Next time you lead a meeting, don’t rest until you identify the three elements of action for every assignment. It’s the single most effective thing you can do to shorten meetings and avoid rehashing the same issue again in the future.</p>
<p>So let&#8217;s evaluate my assignment: </p>
<table border="”1”" cellpadding="”2”">
<tbody>
<tr>
<td><strong>Person</strong></td>
<td><em>You</em>.</td>
</tr>
<tr>
<td><strong>Deliverable</strong></td>
<td><em>Require a person, deliverable, and a date for every assignment you make</em>.</td>
</tr>
<tr>
<td><strong>Date</strong></td>
<td><em>Your next meeting</em>.</td>
</tr>
<tr>
<td><strong>Outcome</strong></td>
<td><em>Shorter, more effective meetings, happier employees, and real action.</em>  This is an action item.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/02/12/the-three-elements-of-action/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>6 Things Every CEO Should Know About Privacy Policies</title>
		<link>http://www.aarontitus.net/blog/2010/01/25/6-things-every-ceo-should-know-about-privacy-policies/</link>
		<comments>http://www.aarontitus.net/blog/2010/01/25/6-things-every-ceo-should-know-about-privacy-policies/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 08:17:20 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=138</guid>
		<description><![CDATA[Note: This post originally appeared on The Security Catalyst Blog
Writing a privacy policy is a careful balance: Being realistic about what you can perform, protecting and instilling confidence in your customers, facilitating business growth and adaptation, complying with law, and above all, being honest.
Your privacy policy and security practices are the subject of federal, state [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This post originally appeared on <a href="http://www.securitycatalyst.com/6-things-every-ceo-should-know-about-privacy-policies/">The Security Catalyst</a> Blog</em></p>
<p>Writing a privacy policy is a careful balance: Being realistic about what you can perform, protecting and instilling confidence in your customers, facilitating business growth and adaptation, complying with law, and above all, being honest.</p>
<p>Your privacy policy and security practices are the subject of federal, state and international laws, as well as FTC regulation.  The FTC regulates unfair and deceptive consumer practices, and has a history of privacy policy enforcement actions. In fact, it is currently hosting a series of &#8220;<a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/">Privacy Roundtable</a>&#8221; discussions, focusing on behavioral advertising, social networking, mobile marketing, data aggregation and correlation, data brokering, cloud computing, and other now-common practices.</p>
<p>With increasing scrutiny on privacy policies and practices, here are six things every CEO should know about their company&#8217;s privacy policy.</p>
<h1>Be Honest</h1>
<p><strong>Your mamma was right: Honesty is the best (privacy) policy</strong>. Be up front about what you do (or may do in the future) with your customer&#8217;s personal information. Many privacy policies make one of three &#8220;honesty&#8221; mistakes: 1. Over-Promising, 2. Under-Promising, 3. Omission.  Each carries liability, so it is better to avoid any of the three.</p>
<p><strong>Don&#8217;t over-promise.</strong> Your company may be held responsible for the representations in your privacy policy.  Look out for phrases like &#8220;state-of-the-art,&#8221; &#8220;everything in our power,&#8221; or &#8220;our highest priority.&#8221;  If your company really does use &#8220;state-of-the-art&#8221; technology to protect privacy, good for you. But you probably don&#8217;t, so be honest about it.  While you may think that such phrases are just feel-good fluff, the FTC has brought actions against companies who fail to provide the state-of-the-art consumer protections they promised, even though they used otherwise reasonable practices.</p>
<p><strong>Don&#8217;t under-promise.</strong> FTC guidelines and many state laws require that your company takes reasonable and appropriate measures on a case-by-case basis.  It may be tempting to try and <a href="http://www.nationalidwatch.org/release.php?g=30">disclaim all duties</a> to protect your customers, especially if you&#8217;ve had a breach. But this approach has pitfalls. First, it is impossible to disclaim all duties to your customers&#8217; privacy. Second, you may scare away potential customers, or invite scrutiny (as <a href="http://www.google.com/search?q=facebook+privacy">Facebook</a> well knows).  Third, FTC actions have indicated that businesses cannot take a &#8220;wait-and-see&#8221; approach to consumer privacy.  Instead, companies have a duty to act reasonably and detect problems before they cause loss, particularly if the they have made privacy promises to their employees or customers.</p>
<p><strong>Tell the whole truth.</strong> Another temptation is to remain conveniently silent on a privacy issue you&#8217;d rather not talk about.  This is also a risky strategy, because state laws (such as California, Texas, and soon-to-be Massachusetts, to name a few) impose specific disclosure requirements.  Whether or not required by law, failure to disclose important privacy practices can spark FTC enforcement action as a deceptive consumer practice.</p>
<h1>Be Complete &amp; Conspicuous</h1>
<p>Aside from potential FTC action, California law requires any company which holds personal information about a Californian to identify the types of information it collects about customers, explain how the consumer may change or update the personal information, and identify an effective date.  The law also imposes an affirmative duty to disclose whether information will be disclosed to third parties for marketing purposes.  California law also requires that a link to your company&#8217;s privacy policy be conspicuous.  Most of the time, a link from the home page or in the footer will be sufficient.</p>
<p>A privacy policy is legally <em>compliant</em> when it addresses all of the various legal and regulatory requirements, but it is only <em>complete</em> when it addresses the full range of your unique business practices. For some organizations, that may be broader than you think.  For example, a typical University engages in educational, financial, healthcare, network provider, non-profit, and goods and services activities on behalf of their students.  That&#8217;s why there can be no such thing as a &#8220;boilerplate&#8221; privacy policy.</p>
<h1>Privacy Policy Must Reflect (Changing) Practices</h1>
<p>Like Ying and Yang, privacy Policy and Practice are complementary and inseparable.  One consistent pattern of FTC actions is that updated information security practices are necessary to protect consumers&#8217; privacy.  As <a href="http://www.ftc.gov/opa/2003/11/cybersecurity.shtm">FTC guidelines</a> indicate, &#8220;Good security is an ongoing process of assessing risks and vulnerabilities… Your business practices and privacy policy must be consistently updated to reflect current best practices and available technology.&#8221;</p>
<h1>Get it Right the First Time</h1>
<p>Even though your privacy policy must adapt to changing business needs, privacy policies cannot be retroactively modified.  This issue is important in the following scenario: Suppose that your company decides it wants to sell customer personal information to marketers, but your privacy policy states that personal information &#8220;will not be shared with third parties without [customers'] explicit consent.&#8221;  Changing the policy to allow you to sell personal information may apply prospectively, but new policy provisions will not apply to existing customers, without their consent.  This can even apply to a transfer of personal information in a bankruptcy proceeding.</p>
<p>That&#8217;s why it&#8217;s important to get it right the first time.  Your company&#8217;s privacy policy must allow you enough wiggle-room to adapt to future conditions, be complete, and still protect your customers.  If you need to materially change your policy, make sure that you have the infrastructure to determine which version of your policy applies to which customer.  It matters.</p>
<h1>If You Say it, Do it</h1>
<p>We&#8217;re all familiar with the <em>Miranda</em> phrase, &#8220;anything you say can and will be used against you …&#8221; by the FTC.  If you make a representation in your privacy or security policy, you&#8217;d better be able to live up to it.  FTC enforcement actions demonstrate that website owners must adhere to any statements of privacy or security, whether the statement is made online or offline.</p>
<p>Each representation about privacy or security is treated as a &#8220;privacy promise.&#8221;  Feel-good marketing fluff does not belong in a privacy policy, because even &#8220;fluff&#8221; can create duties or liability, even if the duty is not required by law.  Explicit security-related promises (such as a promise to use &#8220;state-of-the-art technology&#8221;) requires that the company take affirmative and ongoing steps to ensure that sufficient security is provided.</p>
<p>For example, in 2004 Gateway Learning Corp found itself the target of an FTC Deceptive Practice enforcement action for renting its customer list to marketers, even though their privacy policy said they wouldn&#8217;t.  In recent years the FTC has taken similar action against Eli Lilly &amp; Co., Microsoft, Guess, Inc., Tower Records, and Petco.com to name a few.</p>
<p>If your privacy policy says it, then do it.</p>
<h1>It&#8217;s Your Business</h1>
<p>As a soon-to-be attorney, I can say that you should have a lawyer review your privacy policy.  Lawyers help the privacy policy <strong>comply</strong> with legal and regulatory requirements, but it&#8217;s your responsibility to make sure that the policy is <strong>complete</strong>.  In fact, I would go so far as to say that 30% of a privacy policy is compliance, and the other 70% is completeness.</p>
<p>If those numbers are any indication, they mean that your privacy policy should have 70% of its input from the Customer Service Department, the Accounting Department, Sales, Marketing, and perhaps even R&amp;D.  Without their feedback it will be impossible to document your important privacy practices and create a <em>complete</em> privacy policy. Privacy policies are not legalese and magic words. They are a blueprint of vital business processes.  There is one sure way to get in trouble: Relegate your privacy policy to the legal department, and fail to get cross-departmental participation in its drafting.  Banishing your privacy policy just to the lawyers may get you in trouble because the end result may be <em>compliant</em>, but <em>incomplete</em> And ironically, an incomplete privacy policy is a non-compliant policy.</p>
<h1>Take Charge</h1>
<p>As a CEO, COO, or Managing Director, you should do three things:</p>
<ol>
<li><strong>First, read your privacy and security policy</strong>.  If it confuses you, it will confuse your customers. If it confuses your customers, it might be interpreted as deceptive by the FTC.</li>
<li><strong>Second, make sure you can live up to your privacy policy</strong>. Watch out for buzzwords like &#8220;state-of-the-art,&#8221; &#8220;everything within our power,&#8221; &#8220;always,&#8221; and &#8220;never.&#8221;  Make sure that you haven&#8217;t painted yourself, your customers, or your employees into a corner.</li>
<li><strong>Third, update your privacy policy to reflect your business practices</strong>, or update your business practices to match your policy. Being honest and complete about your business practices is tough work, but will pay dividends long-term.</li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/01/25/6-things-every-ceo-should-know-about-privacy-policies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Commons for Government</title>
		<link>http://www.aarontitus.net/blog/2010/01/20/privacy-commons-for-government/</link>
		<comments>http://www.aarontitus.net/blog/2010/01/20/privacy-commons-for-government/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 08:36:48 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Social Media]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=142</guid>
		<description><![CDATA[Note: This article originally appeared on the The Security Catalyst Blog
&#8220;Unconferences&#8221; (hat tip to identitywoman) are great opportunities to network, gather and share information.  They attract bleeding-edge leaders on emerging problems and technologies.  My most recent unconference was Congress Camp 2009, organized by the Open Forum Foundation.  The gathering focused (broadly) on [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.securitycatalyst.com/privacy-commons-for-government/">The Security Catalyst Blog</a></em></p>
<p>&#8220;<a href="http://www.unconference.net">Unconferences</a>&#8221; (hat tip to <a href="http://www.identitywoman.net">identitywoman</a>) are great opportunities to network, gather and share information.  They attract bleeding-edge leaders on emerging problems and technologies.  My most recent unconference was <a title="Congress Camp" href="http://congresscamp.org/" target="_blank">Congress Camp 2009</a>, organized by the <a title="Open Forum Foundation" href="http://openforumfoundation.org/" target="_blank">Open Forum Foundation</a>.  The gathering focused (broadly) on social networking tools and Web 2.0 for government. It was well attended by advocates who want to reach Congress, and over-worked <a title="3121 Professional Network for Hill Staffers and Congress" href="http://3121blog.nationaljournal.com/">hill staffers</a> who use IE6 and must cope with information overload.  We also got a preview of <a title="Gov Luv: Social Media meets Government" href="http://govluv.org/" target="_blank">GovLuv.org</a>.  If you have an interest in social networking and government, I highly recommend looking at some of the <a title="Congress Camp Blog" href="http://congresscamp.org/" target="_blank">blog articles</a>.</p>
<p><span id="more-2330"></span>Here&#8217;s my report: <em>Don&#8217;t hold your breath for Congress to go Social-Web crazy in the immediate future.</em></p>
<p>I hosted a discussion on developing a <a title="Privacy Commons" href="http://wiki.privacycommons.org" target="_blank">Privacy Commons</a> framework for government.  In short, Privacy Commons will be a series of Privacy Policy Frameworks: A list of <em>required</em>, <em>optional, </em>and <em>prohibited </em>subject matter for privacy policies. Each framework will be tailored to particular industries (i.e., medical, financial, goods and services, social media, government, etc.). Adoption of a Privacy Commons Framework will require that your Privacy Policy address all subject matter in the framework, and make certain high-level disclosures in the form of iconography (i.e., a &#8220;$&#8221; symbol to indicate that you sell personal information to third parties).</p>
<p>I already knew that a government Privacy Commons policy would have to include disclosures about how personal information may be transmitted to other federal agencies, for example. But I was surprised to hear from staffers that Congressional privacy policies should also disclose how personal anecdotes may be used.  Many constituents e-mail their elected representatives with poignant personal stories that often support draft legislation.  Staffers must decide whether they can or should use the stories in a press release, on the House or Senate floor, or whether they can use the story and change the names.</p>
<p>A government Privacy Commons framework will also need to address the different rules that elected officials and their campaigns must follow.  Elected officials must follow strict rules governing sharing personal and contact information.  In contrast, campaigns (which may run full-time, even after an official is elected) can do almost anything with personal information.  The distinction between &#8220;Congressman Jones&#8221; and &#8220;Congressman Jones&#8217; Campaign&#8221; may be lost on the average constituent; but the effects on privacy might be substantial.</p>
<p>As I make the transition to <a title="J.C. Neu and Associates" href="http://www.jeffreyneu.com" target="_blank">full-time attorney</a> (after I pass the bar&#8230; wish me luck), I&#8217;ll be able to continue developing Privacy Commons.  In fact, at Congress Camp I hooked up with the <a title="E Citizen Foundation" href="http://ecitizenfoundation.org" target="_blank"> ECitizen Foundation</a>, which might help host Privacy Commons working groups. Stay tuned.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/01/20/privacy-commons-for-government/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC Says Bloggers Must Disclose Freebies</title>
		<link>http://www.aarontitus.net/blog/2010/01/18/ftc-says-bloggers-must-disclose-freebies/</link>
		<comments>http://www.aarontitus.net/blog/2010/01/18/ftc-says-bloggers-must-disclose-freebies/#comments</comments>
		<pubDate>Mon, 18 Jan 2010 17:20:52 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=140</guid>
		<description><![CDATA[Note: This article originally appeared on the The Security Catalyst Blog
The FTC recently announced new guidelines requiring bloggers to disclose when they get freebies in exchange for reviews.  Adopted by a vote of 4-0, this is the first update of the FTC&#8217;s Guides Concerning the Use of Endorsements and Testimonials in Advertising in 29 [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.securitycatalyst.com/ftc-says-bloggers-must-disclose-freebies/">The Security Catalyst Blog</a></em></p>
<p>The FTC recently announced <a href="http://www.ftc.gov/os/2009/10/091005endorsementguidesfnnotice.pdf">new guidelines</a> requiring bloggers to disclose when they get freebies in exchange for reviews.  Adopted by a vote of 4-0, this is the first update of the FTC&#8217;s <a href="http://www.ftc.gov/bcp/guides/endorse.htm"><em>Guides Concerning the Use of Endorsements and Testimonials in Advertising</em></a> in 29 years. The rules go into effect on December 1, 2009.</p>
<p>The FTC <a href="http://www.ftc.gov/opa/2009/10/endortest.shtm">press release</a> emphasizes that under the new rules, &#8220;both advertisers and endorsers may be liable for… failure to disclose material connections between [them].&#8221;  Material connections include payments or free products, which must be disclosed in a &#8220;clear and conspicuous&#8221; manner.  Both bloggers and advertisers may face FTC sanctions without proper disclosure, even if the advertiser contracts with an ad agency.</p>
<p>Here&#8217;s the bottom line: <strong>Bloggers</strong>– Clearly disclose whether you received payment or a free product when giving endorsements. <strong>Advertisers</strong>– Make sure social media marketing plans require your ad agencies and paid bloggers  to disclose whether an endorsement is paid.</p>
<p>But bloggers shouldn&#8217;t worry too much.  Simply saying something good about a product is not enough to break the new rules.  Instead, there must be a &#8220;material connection&#8221; between the advertiser and endorser.  This is generally understood to mean that the advertiser 1. provides consideration (ie, payment or free product), 2. in exchange for an endorsement.  When this happens, the editorial independence of the endorser becomes questionable, and the relationship between the advertiser and blogger must be disclosed.</p>
<p>Simply blogging about a free sample will not break the FTC rules.  For example, blogging positively about a free product you received from a coupon or free store sample is OK because the article is completely independent and outside the control of the advertiser.  In contrast, that same blogger who receives a free product in exchange for a product review must clearly state that he or she has been compensated for their opinion.</p>
<p>The FTC has indicated that they plan to enforce the provisions primarily against advertisers, rather than bloggers.  This creates interesting challenges for advertisers, many of whom are already reeling from social media overload.  Purely consumer-generated reviews will not create liability for advertisers.  However, if the advertiser initiated the process that led to consumer endorsements (for example, by providing free products to bloggers or enrolling word-of-mouth marketing programs), then the advertiser might be liable for whatever those consumers say.</p>
<p>In addition, simply using an ad agency doesn&#8217;t break the chain of liability.  Unless advertisers are careful, they may incur liability if their advertising agency gives a free product to a blogger, who then fails to disclose the gift.  Advertisers should remember that <em>paid bloggers can now incur liability on advertisers</em>, and in this sense, they should treat paid bloggers just like any other employee or company agent.</p>
<p>Tips for Advertisers:</p>
<ol>
<li><strong>Tell Your Bloggers</strong>:  Always require bloggers to include standard language such as &#8220;PAID ADVERTISEMENT,&#8221; &#8220;PAID PRODUCT REVIEW,&#8221; or similar conspicuous and unambiguous language in their posts whenever you send them free products.</li>
<li><strong>Watch Your Bloggers</strong>: Advertisers will be liable for misleading statements from paid bloggers.  However, you may mitigate liability if you &#8220;advise [paid bloggers] of their responsibilities and&#8230; monitor their online behavior.&#8221;</li>
<li><strong>Tell Your Advertising Agency</strong>:  In your advertising agency contract, require them to insist that bloggers disclose gifts.</li>
<li><strong>Ask for Indemnity</strong>: Require indemnity from your advertising agency, should they fail to notify the blogger, and treat paid bloggers like employees for liability purposes.</li>
</ol>
<p>Tips for Advertising Agencies (especially Social Media):</p>
<ol>
<li><strong>Market Your Knowledge</strong>: Advertisers will appreciate that you know about this new regulation.  Let advertisers know that your knowledge puts you in a position to decrease their liability.</li>
<li><strong>Tell Your Bloggers</strong>: See above.</li>
<li><strong>Watch Your Bloggers</strong>: See above.</li>
</ol>
<p>Tips for Bloggers:</p>
<ol>
<li><strong>Be Clear</strong>: If you got paid, or if you got a free product, disclose it up front.  There are no magic words. You may use plain English to describe your relationship with the advertiser in your article. If you would rather opt for the legalese-disclaimer approach, try something catchy like &#8220;I shamelessly took a free widget from Acme Co. in exchange for this review,&#8221; or &#8220;I have sold my soul and this review to Acme Co. And all I got in exchange was a free widget.&#8221; The good standby, &#8220;Paid Product Review,&#8221; should work fine (if you have no personality).</li>
<li><strong>Be Conspicuous</strong>: If you choose to take the legalese-disclaimer approach, your disclosure should be somewhere readers can easily see it, such as the top of the page, or before the first sentence of the article.  While all-caps or bold words may not be necessary in every circumstance, they may aid in making the text stand out.</li>
<li><strong>Don&#8217;t Worry Too Much</strong>: First, ethical bloggers already disclose their connections with advertisers. Second, you won&#8217;t incur liability unless you are actually acting on behalf of a company when you write a product review.  As a truly independent blogger, you can still write anything you want about any product you want (within the limits of the law).  Now you just have to disclose whether you got paid for your opinion.</li>
</ol>
<p>It will be interesting to see how Twitter advertisers react to this new regulation. Perhaps a shorthand for &#8220;Paid Product Review&#8221; will develop in the Twittersphere, much like &#8220;RT&#8221; for Retweet.  May I be the first to suggest, &#8220;PPR,&#8221; &#8220;Paid,&#8221; or my favorite, &#8220;:-$&#8221;</p>
<p><em>Note: The author received no free products or services from the FTC (or anyone else, for that matter) in exchange for this blog article.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/01/18/ftc-says-bloggers-must-disclose-freebies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is Your Tascam US-144 mkII Noisy? Just Sit on it.</title>
		<link>http://www.aarontitus.net/blog/2010/01/09/is-your-tascam-us-144-mkii-noisy-just-sit-on-it/</link>
		<comments>http://www.aarontitus.net/blog/2010/01/09/is-your-tascam-us-144-mkii-noisy-just-sit-on-it/#comments</comments>
		<pubDate>Sat, 09 Jan 2010 15:45:05 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Reviews]]></category>
		<category><![CDATA[Audio]]></category>
		<category><![CDATA[Review]]></category>
		<category><![CDATA[TASCAM US-144 mkII]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=118</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.aarontitus.net/blog/wp-content/uploads/2010/01/US-144-mkII.jpg" alt="The TASCAM US-144 mkII gets noisy when the temperature drops." width=300 height=250 align="right" /><div id="interface_image" class="wp-caption right" style="width: 310px"><p class="wp-caption-text">The TASCAM US-144 mkII's Phantom Power gets very noisy when the temperature drops below 65</p></div>I recently purchased two sets of podcasting gear to record podcasts with someone in another state.  The gear included two <a href="http://www.tascam.com/products/us-144mkII.html">TASCAM US-144 mkII</a> interfaces, two <a href="http://www.audio-technica.com/cms/wired_mics/a0933a662b5ed0e2/index.html">Audio-Technica AT 2020 condenser microphones</a>, two mic cables, two stands, two pop filters, two sets of headphones, etc.  As I recorded I noticed an inconsistent whine in the audio. Sometimes the wine was little more than a vinyl-record-like scratch, other times it was a scream, and still others it disappeared altogether.</p>
<p>To track down the source, I started by changing out the AC power for battery power, switching USB cords, switching mic cords, switching microphones, switching interfaces, turning on and off the wireless network, unplugging my wireless router, changing rooms, and even moving to a location several miles away.  None of these things had any consistent effect on the whine.  After <em>a lot</em> of trial and error, I have narrowed the problem down to two three variables: <strong>Temperature</strong>, <strong>Phantom Power</strong> and the <strong>MIC/LINE-GUITAR select switch</strong>.</p>
<p>The whine appears with the phantom power on, while the interface is cold (ie, less than about 65 degrees Fahrenheit). It gets worse when the <em>MIC/LINE-GUITAR select switch</em> is set to &#8220;Guitar.&#8221; Setting the <em>MIC/LINE-GUITAR select switch</em> to &#8220;Guitar&#8221; makes it act as an unbalanced input jack, which probably explains the noise.  But turning on the phantom power while the interface is cold produces a lot of noise.</p>
<p>The solution: <strong>Sit on the interface</strong> to warm it up.  My home &#8220;studio&#8221; is in a very cold room with two exterior walls, and it&#8217;s the middle of winter.  So in order to warm up the interface&mdash;no joke&mdash;I actually put it under my thigh for a good 10-15 minutes.  I didn&#8217;t read that helpful work-around in the <a href="http://www.tascam.com/i-3850-232-128-0-B307598B.pdf">manual</a>. I thought about using an electric blanket, but I was afraid that might cause some induction damage.</p>
<h2>The Test</h2>
<p>I conducted a test to demonstrate the whine, which I have included <a href="http://www.aarontitus.net/blog/wp-content/uploads/2010/01/Mic_Test.mp3">here</a>.  For the test I had the following setup:  I plugged an Audio-Technica AT 2020 condenser mic into the <em>MIC IN L</em> XLR balanced jack.  I also plugged a crappy old dynamic mic into the <em>LINE IN R/GUITAR IN jack</em> TRS 1/4&#8243; jack.  For the &#8220;Cold&#8221; test, I left the interface in a box in my car for 30 minutes, where the outside temperature is around 25&deg; Fahrenheit.  For the &#8220;Warm&#8221; test, I basically sat on the interface for about 15 minutes until the interface housing was noticeably warmer than room temperature.</p>
<p>I then recorded a systematic test of the phantom power, left and right input levels, and the <em>MIC/LINE-GUITAR select switch</em> in 10-second intervals.  I included the results in a table below, with each numbered setting corresponding to a period of time on the <a href="http://www.aarontitus.net/blog/wp-content/uploads/2010/01/Mic_Test.mp3">non-normalized .mp3 file</a>. You can skip around to compare the different settings if you&#8217;d like.  Please ignore the ambient noise of the HVAC system, as well as the lousy line quality for my crappy dynamic mic.</p>
<p><a name="cold"></a></p>
<table border=1 cellpadding=5 cellspacing=0>
<tr>
<td colspan=7><center><strong>INTERFACE TEMPERATURE: COLD (~30&deg;- ~65&deg; Fahrenheit)</strong></center></td>
</tr>
<tr>
<td><strong>Setting</strong></td>
<td><strong>Time on Tape</strong></td>
<td><strong>Phantom Power</strong></td>
<td><strong>INPUT L Levels<br /> (AT 2020)</strong></td>
<td><strong>INPUT R Levels<br />(Crappy Dynamic)</strong></td>
<td><strong>LINE/MIC- GUITAR <br />Select Switch</strong></td>
<td><strong>Whine</strong></td>
</tr>
<tr>
<td>1</td>
<td>0:00-0:10</td>
<td rowspan = 8>OFF</td>
<td rowspan = 4>Line (Low)</td>
<td>Line (Low)</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>2</td>
<td>0:10-0:20</td>
<td>Mic (High)</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>3</td>
<td>0:20-0:30</td>
<td>Line</td>
<td>Guitar</td>
<td>None</td>
</tr>
<tr>
<td>4</td>
<td>0:30-0:40</td>
<td>Mic</td>
<td>Guitar</td>
<td>None</td>
</tr>
<tr>
<td>5</td>
<td>0:40-0:50</td>
<td rowspan = 4>Mic (High)</td>
<td>Line</td>
<td>Line/Mic</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>6</td>
<td>0:50-1:00</td>
<td>Mic</td>
<td>Line/Mic</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>7</td>
<td>1:00-1:10</td>
<td>Line</td>
<td>Guitar</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>8</td>
<td>1:10-1:20</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>9</td>
<td>1:20-1:30</td>
<td rowspan = 8>ON</td>
<td rowspan = 4>Line</td>
<td>Line</td>
<td>Line/Mic</td>
<td bgcolor=#FFCC00>Whine-Low</td>
</tr>
<tr>
<td>10</td>
<td>1:30-1:40</td>
<td>Mic</td>
<td>Line/Mic</td>
<td bgcolor=#FF9900>Whine-Med</td>
</tr>
<tr>
<td>11</td>
<td>1:40-1:50</td>
<td>Line</td>
<td>Guitar</td>
<td bgcolor=#FF9900>Whine-Med</td>
</tr>
<tr>
<td>12</td>
<td>1:50-2:00</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#FF0000>Whine-Scream</td>
</tr>
<tr>
<td>13</td>
<td>2:00-2:10</td>
<td rowspan = 4>Mic</td>
<td>Line</td>
<td>Line/Mic</td>
<td bgcolor=#CC3300>Whine-Loud</td>
</tr>
<tr>
<td>14</td>
<td>2:10-2:20</td>
<td>Mic</td>
<td>Line/Mic</td>
<td bgcolor=#CC3300>Whine-Loud</td>
</tr>
<tr>
<td>15</td>
<td>2:20-2:30</td>
<td>Line</td>
<td>Guitar</td>
<td bgcolor=#CC3300>Whine-Loud</td>
</tr>
<tr>
<td>16</td>
<td>2:30-2:40</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#FF0000>Whine-Scream</td>
</tr>
</table>
<p><a name="warm"></a></p>
<table border=1 cellpadding=5 cellspacing=0>
<tr>
<td colspan=7><center><strong>INTERFACE TEMPERATURE: WARM (~75&deg;+ Fahrenheit)</strong></center></td>
</tr>
<tr>
<td><strong>Setting</strong></td>
<td><strong>Time on Tape</strong></td>
<td><strong>Phantom Power</strong></td>
<td><strong>INPUT L Levels<br /> (AT 2020)</strong></td>
<td><strong>INPUT R Levels<br />(Crappy Dynamic)</strong></td>
<td><strong>LINE/MIC- GUITAR <br />Select Switch</strong></td>
<td><strong>Whine</strong></td>
</tr>
<tr>
<td>1</td>
<td>2:40-2:50</td>
<td rowspan = 8>OFF</td>
<td rowspan = 4>Line (Low)</td>
<td>Line (Low)</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>2</td>
<td>2:50-3:00</td>
<td>Mic (High)</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>3</td>
<td>3:00-3:10</td>
<td>Line</td>
<td>Guitar</td>
<td>None</td>
</tr>
<tr>
<td>4</td>
<td>3:10-3:20</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>5</td>
<td>3:20-3:30</td>
<td rowspan = 4>Mic (High)</td>
<td>Line</td>
<td>Line/Mic</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>6</td>
<td>3:30-3:40</td>
<td>Mic</td>
<td>Line/Mic</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>7</td>
<td>3:40-3:50</td>
<td>Line</td>
<td>Guitar</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>8</td>
<td>3:50-4:00</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#FFFF66>Scratch</td>
</tr>
<tr>
<td>9</td>
<td>4:00-4:10</td>
<td rowspan = 8>ON</td>
<td rowspan = 4>Line</td>
<td>Line</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>10</td>
<td>4:10-4:20</td>
<td>Mic</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>11</td>
<td>4:20-4:30</td>
<td>Line</td>
<td>Guitar</td>
<td>None</td>
</tr>
<tr>
<td>12</td>
<td>4:30-4:40</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#CC3300>Whine-Loud</td>
</tr>
<tr>
<td>13</td>
<td>4:40-4:50</td>
<td rowspan = 4>Mic</td>
<td>Line</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>14</td>
<td>4:50-5:00</td>
<td>Mic</td>
<td>Line/Mic</td>
<td>None</td>
</tr>
<tr>
<td>15</td>
<td>5:00-5:10</td>
<td>Line</td>
<td>Guitar</td>
<td>None</td>
</tr>
<tr>
<td>16</td>
<td>5:10-5:20</td>
<td>Mic</td>
<td>Guitar</td>
<td bgcolor=#CC3300>Whine-Loud</td>
</tr>
</table>
<p>My home studio is in the basement near an outside wall, so it&#8217;s usually around 65&deg;. Every morning the whine reappears until I physically warm the unit to around 75&deg;+.</p>
<p>At lower temps, the phantom power whines and bleeds over into the 1/4&#8243; inputs, which surprises me because most electronics are happier when they&#8217;re cold.  I&#8217;d chalk it up to a defective unit, except that I purchased two 144 mkII&#8217;s, and both units display the same behavior.  Regardless, I&#8217;m not looking forward to the hassle of returning or exchanging the interface. It&#8217;s going to put me back several weeks.</p>
<p>I wonder if anyone else has experienced these same problems.  The helpful guys at <a href="http://www.sweetwater.com/">Sweetwater</a> didn&#8217;t seem to have bumped into the problem before.</p>
<p><strong>[Update Jan 14, 2010]</strong></p>
<p>I have decided to return the mkII&#8217;s to Sweetwater in favor of another brand, perhaps an M-Audio. I haven&#8217;t decided.  At first I was content to swap them out for non-defective mkIIs, but apparently TASCAM has temporarily stopped shipping the US-144 mkII.  More precisely, they are taking orders without providing a firm ETA. This is apparently quite unusual, and in the estimation of the guy I talked to it likely indicates that they are doing some re-tooling.</p>
<p>I decided that I&#8217;m probably better off not being the guinea pig for the &#8220;fixed&#8221; version (if, in fact they are re-tooling).  And even if they&#8217;re not re-tooling, I don&#8217;t want to wait indefinitely for TASCAM to fill the order.</p>
<p>I am so glad that I purchased from <a href="http://www.sweetwater.com/">Sweetwater</a> instead of <a href="http://www.guitarcenter.com/">Guitar Center</a>.  Sweetwater has much better support.  Let me correct that: Sweetwater offers <em>any</em> type of support.</p>
<p><strong>[Update Jan 25, 2010]</strong></p>
<p>I decided to go with a <a href="http://www.lexiconpro.com/product.php?id=6">Lexicon Omega</a> instead. So far (in some preliminary recordings) I haven&#8217;t had any noise problems, thought the levels are significantly lower than the Tascam 144 mkII.  I&#8217;ll just have to do more post-normalization.  I hope the noise levels stay tolerable.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2010/01/09/is-your-tascam-us-144-mkii-noisy-just-sit-on-it/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
<enclosure url="http://www.aarontitus.net/blog/wp-content/uploads/2010/01/Mic_Test.mp3" length="5128024" type="audio/mpeg" />
		</item>
		<item>
		<title>Highlights From the FTC&#8217;s Privacy Roundtable Part 3</title>
		<link>http://www.aarontitus.net/blog/2009/12/15/highlights-from-the-ftcs-privacy-roundtable-part-3/</link>
		<comments>http://www.aarontitus.net/blog/2009/12/15/highlights-from-the-ftcs-privacy-roundtable-part-3/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 08:53:42 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=157</guid>
		<description><![CDATA[Note: This article originally appeared on the J.C. Neu &#38; Associates Blog
This is part 3 of highlights from the FTC&#8217;s December 7th Privacy Roundtable. Part 1 covered the panel on &#34;Exploring Existing Regulatory Frameworks,&#34; and Part 2 covered the panel on &#34;Benefits and Risks of Collecting, Using, and Retaining Consumer Data&#34; This post highlights comments [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.jeffreyneu.com/20091215246/Highlights-From-the-FTC-s-Privacy-Roundtable-Part-3.html">J.C. Neu &amp; Associates Blog</a></em></p>
<p>This is part 3 of highlights from the FTC&rsquo;s December 7th <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">Privacy Roundtable</a>. <a href="http://jeffreyneu.com/20091208244/Highlights-From-the-FTC-s-Privacy-Roundtable-Part-1.html">Part 1</a> covered the panel on &quot;Exploring Existing Regulatory Frameworks,&quot; and <a href="/245-highlights-from-the-ftcs-privacy-roundtable-part-2.html">Part 2</a> covered the panel on &quot;Benefits and Risks of Collecting, Using, and Retaining Consumer Data&quot; This post highlights comments from &quot;Consumer Expectations and Disclosures&quot; and &quot;Information Brokers.&quot;</p>
<p>Disclaimer: I took notes using <a href="http://www.twitter.com/aarontitus/">my Twitter account</a>. About halfway through the &quot;Benefits and Risks&quot; panel, Twitter decided that I was a spammer, and shut down my account. I was mad, and it meant that I did not cover the whole session.</p>
<h2>Benefits and Risks of Collecting, Using, and Retaining Consumer Data </h2>
<ul>
<li><strong>Lorrie Faith Cranor</strong>,Associate Professor of <a href="http://www.cs.cmu.edu/">Computer Science, Carnegie Mellon University</a> commented on consumers&#8217; state of ignorance regarding how information flows, much like an unseen underground river.   &quot;Most people do not understand how information flows,&quot; or &quot;what a third-party cookie is.&quot;</li>
<li><strong>Alan Westin</strong> Professor Emeritus of Public Law and Government, <a href="http://www.columbia.edu/">Columbia University</a> referenced several of his studies which indicated that &quot;&hellip;people are not prepared to equate [the need for] behavioral marketing with [funding] free services, and that &quot;most people believe that they&#8217;re being abused,&quot; but there was general consensuses that  most people surveyed also believed that they were protected by law and regulations that do not actually exist.  In the meantime, Mr. Westin&#8217;s research also indicates that most people are no longer willing to trade privacy for freebies on the internet, because of the disconnect between &quot;free&quot; services and the fact that personal information pays for most of it.</li>
<li><strong>Alan Davidson</strong>, Director of U.S. Public Policy and Government Affairs for <a href="http://www.google.com">Google</a> emphasized that the industry is trying to educate consumers and give them the tools they need in order to control their privacy, as evidenced by Google&#8217;s dashboard, for instance. He suggested that the audience <a href="http://www.bing.com/search?q=google+dashboard&amp;go=&amp;form=QBLH&amp;qs=n">Bing</a> &quot;Google Dashboard&quot; for more information.</li>
<li><strong>Jules Polonetsky</strong> Co‐Chair and Director of the <a href="http://www.futureofprivacy.org/">Future of Privacy Forum</a> made reference to the results of several large surveys conducted by his organization.  For instance, one indicated that there is a substantial public misconception about what &quot;Behavioral Advertising&quot; is.  Among the handful of survey respondents who had heard the term, all of them mistook &quot;Behavioral Advertising&quot; for the concept of subliminal advertising.  His organization is also attempting to generate symbols explaining how personal information is used, an approach endorsed by <a href="http://wiki.privacycommons.org">Privacy Commons</a> and other groups.</li>
<li>My apologies to <strong>Joel Kelsey</strong>, Policy Analyst for the <a href="http://www.consumersunion.org/">Consumers Union</a>, and  <strong>Adam Thierer</strong>, President of <a href="http://www.asc.upenn.edu/">University of Pennsylvania, Annenberg School for Communication</a>.  Each of these individuals actively participated, but unfortunately I was unable to capture their thoughts because I was under a temporary Twitter ban at the time.</li>
</ul>
<h2>Information Brokers</h2>
<p><em>Short editorial: This session was by far the least enlightening. </em></p>
<ul>
<li><strong>Jennifer Barrett</strong>, Global Privacy and Public Policy Officer for <a href="http://www.acxiom.com/Pages/Home.aspx">Acxiom</a> started off the panel by discussing what  constituted &quot;sensitive personal information.&quot; She replied that Acxiom classifies &quot;sensitive information&quot; is any information which could contribute to identity theft, whereas &quot;restricted information&quot; is an unlisted phone number, for example.</li>
<li><strong>Rick Erwin</strong>, President of <a href="http://www.experianmarketingservices.com/">Experian Marketing Services</a> explained that they consider information on children, older Americans, and self-reported ailment data to be &quot;sensitive,&quot; adding that Experian has &quot;three decades of experience using sensitive information for marketing,&quot; and is able to adequately balance the interests of marketers and consumers.  Mr. Erwin also discounted the harms of marketing, saying &quot;we can&#8217;t point to deep consumer harm based on bad advertising.&quot;</li>
<li><strong>Pam Dixon</strong>, Executive Director of the <a href="http://www.worldprivacyforum.org/">World Privacy Forum</a> disagreed.  She contended that the definition of &quot;sensitive information&quot; is difficult at best because otherwise benign information can be aggregated to create sensitive information. In regards to health information, getting consent from consumers is almost illusory because consumers have no way of knowing how the information will be used in the future.  Informed consent is impossible without telling consumers what &quot;boxes&quot; they will be put in.  Consumers need the right to know on what lists they will appear, for how long, and they must have the right to revoke their consent. Pam Dixon contended that &quot;we need to make Opt Out work for consumers,&quot; and that opting out should always be free.</li>
<li>In response, <strong>Jennifer Barrett</strong> insisted that the Information Broker industry needs no further regulation: &quot;We&#8217;re already <em>very</em> regulated,&quot; she said.</li>
<li><strong>Jim Adler</strong>, Chief Privacy Officer and General Manager of Systems for <a href="http://www.intelius.com/">Intelius</a> explained that they offer special opt-out services to government officials.</li>
<li><strong>Chris Jay Hoofnagle</strong>, Lecturer in Residence at the <a href="http://www.law.berkeley.edu/">University of California Berkeley School of Law</a> was scheduled to participate but was unable due to technical difficulties.</li>
</ul>
<p>The FTC has <a href="http://http.earthcache.net/htc-01.media.qualitytech.com/COMP008760MOD1/FTC2/120709_ftc_sess1live/index.htm">posted the webcast </a> if you missed it.&nbsp; The next Roundtable is scheduled for <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">January 28, 2010</a> in Berkeley, CA and will also be broadcast online.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/12/15/highlights-from-the-ftcs-privacy-roundtable-part-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Highlights From the FTC&#8217;s Privacy Roundtable: Part 2</title>
		<link>http://www.aarontitus.net/blog/2009/12/09/highlights-from-the-ftcs-privacy-roundtable-part-2/</link>
		<comments>http://www.aarontitus.net/blog/2009/12/09/highlights-from-the-ftcs-privacy-roundtable-part-2/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 08:51:49 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=155</guid>
		<description><![CDATA[Note: This article originally appeared on the J.C. Neu &#38; Associates Blog
This is part 2 of highlights from the FTC&#8217;s December 7th Privacy Roundtable. Part 1 covered the panel on &#34;Exploring Existing Regulatory Frameworks.&#34; This post highlights comments from &#34;Benefits and Risks of Collecting, Using, and Retaining Consumer Data.&#34;  This session was moderated by [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.jeffreyneu.com/20091209245/Highlights-From-the-FTC-s-Privacy-Roundtable-Part-2.html">J.C. Neu &amp; Associates Blog</a></em></p>
<p>This is part 2 of highlights from the FTC&rsquo;s December 7th <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">Privacy Roundtable</a>. <a href="http://jeffreyneu.com/20091208244/Highlights-From-the-FTC-s-Privacy-Roundtable-Part-1.html">Part 1</a> covered the panel on &quot;Exploring Existing Regulatory Frameworks.&quot; This post highlights comments from &quot;Benefits and Risks of Collecting, Using, and Retaining Consumer Data.&quot;  This session was moderated by Jeffrey Rosen of The <a href="http://www.law.gwu.edu">George Washington University Law School</a> and Chris Olsen, of the FTC&#8217;s <a href="http://www.ftc.gov/bcp/bcppip.shtm">Division of Privacy and Identity Protection</a>. </p>
<ul>
<li><strong>Leslie Harris</strong>, President and CEO of the <a href="http://www.cdt.org">Center for Democracy &amp; Technology</a> emphasized that information taken out of context can be used to unfairly judge a person, such as a search for &quot;marijuana&quot; or a medical condition. The danger increases when a rich profile of search terms and surfing data is constructed over time. </li>
<li><strong>Susan Grant</strong>, Director of Consumer Protection for the <a href="http://www.consumerfed.org/">Consumer Federation of America</a>, said that &quot;privacy is a fundamental human right.&quot;</li>
<li><strong>Alessandro Acquisti</strong> of <a href="http://www.heinz.cmu.edu/index.aspx">Carnegie Mellon University, Heinz College</a>, explained that the definition of &quot;sensitive information&quot; continues to change with technology, new uses for information, and new ways to correlate and aggregate personal information. Technology cannot stop re-identification or de-anonymization, but should be used to increase the transaction costs for re-identifying personal information.  He also spoke about how companies are bypassing consumer efforts to maintain privacy and anonymity through technologies such as flash cookies.</li>
<li><strong>Richard Purcell</strong>, CEO of the  <a href="http://www.corporateprivacygroup.com/">Corporate Privacy Group</a>, emphasized that citizens&#8217; health depends on anonymized health data used for research, and that privacy must be weighed using a cost-benefit analysis.  He further</li>
<li><strong>Michael Hintze</strong>, Associate General Counsel for <a href="http://www.microsoft.com">Microsoft</a>, explained that companies use log and use information for a number of legitimate reasons, such as security analysis, and search result optimization.  However, he admitted that search terms can reveal individuals&#8217; &quot;innermost thoughts,&quot; and that anonymization is not a silver bullet to protecting users.  Instead, retention and deletion policies such as Microsoft&#8217;s policy of deleting IP addresses and cross-cookie session information is designed to truly anonymize search data.</li>
<li><strong>David Hoffman</strong>, Director of Security Policy and Global Privacy Officer for <a href="http://www.intel.com">Intel</a>, stressed that we should focus on data minimization. &quot;We have wasted time arguing about what constitutes PII,&quot; when the question should be, &quot;what information will have an impact on an individual?&quot;</li>
<li><strong>Jim Harper</strong>, Director of Information Policy Studies for <a href="http://www.cato.org/">The Cato Institute</a>, argued that regulating too early can stifle innovation and prevent consumers from determining what they want themselves.  Instead, we should attempt to define the problem set first.  Mr. Harper explained that &quot;there is a role for trial and error in determining what the real problems are,&quot; and that intellectualizing what consumers really want can lead to problems.  Instead, we should &quot;let a thousand flowers bloom&quot; and let the social systems and advocacy draw out and solve the real issues.</li>
<li><strong>David Hoffman</strong> generally agreed that we don&#8217;t want to frustrate innovation, and that we are not currently in a position to understand all of the problems ourselves. He explained that it took a room full of experts the better part of a day to map out data flows. &quot;We can&#8217;t expect consumers to understand how the data flows if experts can&#8217;t understand it now.&quot;</li>
<li><strong>Leslie Harris</strong> and <strong>Alessandro Acquisti</strong> said that Notification and transparency is necessary but not sufficient. Mr. Acquisti noted that consumers make decisions which are harmful to long-term privacy because humans are bad at making decisions when the benefits are short-term but harm is long-term.  He compared privacy erosive behavior to smoking, since each smoker realizes that smoking causes cancer, but any individual cigarette doesn&#8217;t hurt much.</li>
<li> </li>
<li><strong>Susan Grant </strong>explained that consumers don&#8217;t realize that their information can be used for other purposes, and that the benefits of marketing do not outweigh privacy concerns and fraud and abuse. <strong>Jim Harper</strong> countered that advertisers can introduce a new medication to vulnerable populations, and that denying them that opportunity can create silent harms. <strong>Michael Hintze</strong> added that niche ads aren&#8217;t good or bad- they&#8217;re responsible or irresponsible </li>
<li><strong>Richard Purcell</strong> also argued that companies should spend the time and money to train their customers, and create &quot;privacy by design&quot; rather than &quot;privacy by default.&quot;  Finally, the FTC should &quot;regulate the hell out of&quot; lazy companies and bad actors.</li>
<li><strong>Richard Purcell</strong> further emphasized that we lack a cohesive taxonomy for discussing privacy, and that we need to better define concepts such as &quot;anonymity,&quot; &quot;deidentification,&quot; and &quot;sensitive data.&quot;</li>
<li>The panel was asked to consider widespread customer blacklisting. <strong>Susan Grant</strong> said that consumers need tools to discover and amend secret &quot;bad customer&quot; lists, since they have none now. Distinctions based upon invisible information is bad for consumers.  <strong>Leslie Harris</strong> agreed, saying that we need a law that provides access and correction for data brokers as well.  She also criticized the FTC for failing to investigate privacy violations, saying that all of our bad examples are &quot;accidental,&quot; not intentional long-term decisions to violate privacy, outed by the FTC.</li>
<li>In the larger context, <strong>Jim Harper</strong> said that Government access to personal information is the elephant in the room that nobody has yet addressed.  Governments are beginning to discover &quot;the cloud&quot; for their own purposes, and when data is available to government on the current terms, it constitutes surveillance on a massive scale.</li>
</ul>
<p> I&#8217;ll do a few more installments in the coming days.
<p>The FTC has <a href="http://http.earthcache.net/htc-01.media.qualitytech.com/COMP008760MOD1/FTC2/120709_ftc_sess1live/index.htm">posted the webcast </a> if you missed it.&nbsp; The next Roundtable is scheduled for <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">January 28, 2010</a> in Berkeley, CA and will also be broadcast online.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/12/09/highlights-from-the-ftcs-privacy-roundtable-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Highlights From the FTC&#8217;s Privacy Roundtable: Part 1</title>
		<link>http://www.aarontitus.net/blog/2009/12/08/highlights-from-the-ftcs-privacy-roundtable-part-1/</link>
		<comments>http://www.aarontitus.net/blog/2009/12/08/highlights-from-the-ftcs-privacy-roundtable-part-1/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 08:49:49 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=153</guid>
		<description><![CDATA[Note: This article originally appeared on the J.C. Neu &#38; Associates Blog
The FTC&#8217;s December 7th Privacy Roundtable assembled a Who&#8217;s Who of privacy luminaries, academics, advocates, and industry players.  This post highlights some of the more interesting comments from the meeting.  I also tweeted the event (@aarontitus, #FTC #Privacy or #ftcpriv) and the [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.jeffreyneu.com/20091208244/Highlights-From-the-FTC-s-Privacy-Roundtable-Part-1.html">J.C. Neu &amp; Associates Blog</a></em></p>
<p>The FTC&rsquo;s December 7th <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">Privacy Roundtable</a> assembled a Who&rsquo;s Who of privacy luminaries, academics, advocates, and industry players.  This post highlights some of the more interesting comments from the meeting.  I also tweeted the event (<a href="http://twitter.com/aarontitus">@aarontitus</a>, <a href="http://search.twitter.com/search?q=#FTC+#Privacy">#FTC #Privacy</a> or <a href="http://search.twitter.com/search?q=#ftcpriv">#ftcpriv</a>) and the FTC has <a href="http://http.earthcache.net/htc-01.media.qualitytech.com/COMP008760MOD1/FTC2/120709_ftc_sess1live/index.htm">posted the webcast </a> if you missed it.&nbsp; The next Roundtable is scheduled for <a href="http://www.ftc.gov/bcp/workshops/privacyroundtables/index.shtml">January 28, 2010</a> in Berkeley, CA and will also be broadcast online.</p>
<p>The meeting consisted of five panels. This posts highlights &quot;Panel 5: Exploring Existing Regulatory Frameworks:&quot; </p>
<ul>
<li>During Session 5, <a href="http://www.intuit.com/">Intuit&#8217;s</a> Chief Privacy Officer <strong> Barbara Lawler</strong> posited that existing regulatory frameworks unfairly place the entire burden on consumers to protect themselves.  &quot;Consumers should expect a safe marketplace. They shouldn&#8217;t be the ones to police the marketplace,&quot; she said.</li>
<li><strong> Barbara Lawler</strong> also noted that &quot;Data is never really at rest,&quot; because it&#8217;s moving between data centers and backups in multiple locations throughout the globe.  It is therefore incorrect to think of data, especially Cloud data, as being in one place.  Instead, &quot;data is in one place and many places at the same time,&quot; potentially in multiple jurisdictions.</li>
<li><strong> Evan Hendricks</strong> of <a href="http://www.privacytimes.com/"><em>Privacy Times</em></a> and <strong>Marc Rotenberg</strong> of <a href="http://www.epic.org">EPIC</a> suggested that the current model of &quot;Notice and Consent&quot; has failed to protect consumers, and that the FTC (and legislation in general) should return to well-established Fair Information Practices (FIPs), including a prohibition on &quot;secret databases.&quot; Mr. Rotenberg went so far as to conclude that Notice and Choice principles are not a subset of FIPs, but instead &quot;stand in opposition to fair information practices.&quot;  He also joked that &quot;the best part of Graham-Leach-Bliley  Act is that you get paper notices you can tape on your window and get more privacy.&quot;</li>
<li><strong>Ira Rubinstein</strong> of <a href="http://www.law.nyu.edu/index.htm">New York University School of Law</a> proposed that self-regulation is not binary or &quot;monolithic,&quot; and that a self-regulatory scheme would be preferable, especially if viewed as a &quot;continuum, based on government intervention.&quot;  He argued that self-regulation would be especially appropriate in the United States, which has traditionally been very friendly to e-commerce.</li>
<li><strong>Michael Donohue</strong> of <a href="http://www.oecd.org/">OECD</a> gave an overview of international legal concepts of privacy which generally agreeing with Marc Rotenberg&#8217;s observation that &quot;most countries have come to surprisingly similar conclusions about privacy.&quot;</li>
<li><strong>J. Howard Beales</strong> of the <a href="http://business.gwu.edu/index.cfm">GWU School of Business</a> argued in favor of a &quot;harm-based model,&quot; because it is impossible to reach the best solution without first defining the harm.  Marc Rotenberg responded that privacy harms are almost never financial. </li>
<li>Several panelists emphasized that privacy can be highly (and appropriately) subjective. One cited an example from a balding friend of his, &quot;I don&#8217;t care if anyone knows that I use Rogaine, but my 70-year-old grandmother would.&quot;</li>
<li><strong>Fred Cate</strong> of the <a href="http://cacr.iu.edu/">Center for Applied Cybersecurity Research</a> emphasized that the Notice and Consent model is flawed because some activities should not be consentable.  For example, one may not &quot;consent&quot; to be served fraudulent or misleading advertising. Likewise, some uses of personal information should be prohibited and non-consentable. Most importantly, Notice and Choice are only <em>tools</em>- not the goal of privacy.</li>
<li>After Panel 5 was done, Bureau of Consumer Protection Director <strong>David C. Vladeck</strong> said the FTC would investigate whether it is better to give consumers notice how their personal information may be used: 1. At the time of collection, or 2. At the time of use.</li>
<li><strong>David C. Vladeck</strong> also said that the data broker industry warranted FTC attention because it is &quot;largely invisible to the consumer.&quot; </li>
</ul>
<p>More highlights on the other sessions to come.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/12/08/highlights-from-the-ftcs-privacy-roundtable-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Thoughts About Privacy Commons</title>
		<link>http://www.aarontitus.net/blog/2009/12/06/my-thoughts-about-privacy-commons/</link>
		<comments>http://www.aarontitus.net/blog/2009/12/06/my-thoughts-about-privacy-commons/#comments</comments>
		<pubDate>Mon, 07 Dec 2009 02:38:54 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=109</guid>
		<description><![CDATA[I spend most of my free time working on Privacy Commons, and so I was excited to see Christopher&#8217;s post and critique on the subject. Thanks as usual, Christopher, for your thought-provoking questions and observations.  Likewise, Aza, CUPS, and Ralf Bendrath.  Great work&#8212;each of you.  I want to pick each of your [...]]]></description>
			<content:encoded><![CDATA[<p>I spend most of my free time working on <a href="http://wiki.privacycommons.org">Privacy Commons</a>, and so I was excited to see <a href="http://www.christopher-parsons.com/blog/thoughts/thinking-about-a-privacy-commons/">Christopher&#8217;s post and critique</a> on the subject. Thanks as usual, Christopher, for your thought-provoking questions and observations.  Likewise, <a href="http://www.azarask.in/blog/post/making-privacy-policies-not-suck/">Aza</a>, <a href="http://cups.cs.cmu.edu/blog/?p=175">CUPS</a>, and <a href="http://bendrath.blogspot.com/2007/05/icons-of-privacy.html">Ralf Bendrath</a>.  Great work&mdash;each of you.  I want to pick each of your brains sometime.  I also want to apologize in advance for any incomplete sentences or thoughts. This is a slapped-up post.</p>
<h1>Some Problems With Privacy Policies</h1>
<p>As Christopher, myself, and many others have pointed out, the problems with privacy policies are myriad.  Here are a few:</p>
<ul>
<li><strong>Inaccessible or Unintelligible</strong>. many privacy policies are not easily understood or even physically accessible; so complicated and wrapped in legalese that they are &#8220;nigh useless&#8221; to the average consumer.</li>
<li><strong>Complicated Solution</strong>. Unless we&#8217;re careful, a Privacy Commons may end up equally or more complicated than the status quo.</li>
<li><strong>Non-Standard</strong>. Privacy Policies are not standardized, making it impossible to compare apples-to-apples.</li>
<li><strong>Incomplete</strong>. They often fail to address important privacy issues or fail to consider all potential parties</li>
<li><strong>Unsophisticated</strong>. Many boilerplate privacy policies demonstrate a fundamental lack of understanding of how privacy policies translate to privacy and business practices.  Some simply don&#8217;t address the most salient issues, which may be unique to their industry.  Consequently, many of the policies never translate to practice.</li>
<li><strong>Treated as Only Legal Documents</strong>. Privacy policies are often treated as &#8220;compliance&#8221; documents and relegated to the legal department.  Consequently, many fail to address or actually contradict field practices.</li>
<li><strong>Privacy Waiver</strong>. Many privacy policies waive, rather than confer, privacy rights.  The medical industry is extremely efficient at this practice.</li>
<li><strong>Technology-Dependent</strong>. Privacy policies which strictly enumerate technologies quickly become outdated in the face of emerging technologies.</li>
<li><strong>Non-Binding</strong>. Most importantly, US courts have consistently interpreted privacy policies to be unbinding notices, rather than contracts.  As a result, privacy policies generally create no enforceable rights or enforceable expectations of privacy. In this sense, privacy policies can create a false expectation of confidentiality, privacy, or even fiduciary responsibility.</li>
</ul>
<h1>Some Assumptions About Privacy Policies</h1>
<p>Based on my experience in technology, advocacy, and the law, I want to air some of my basic assumptions about Privacy Policies. Of course, I invite challenges to these assumptions:</p>
<ol>
<li><strong>Mitigate Liability</strong>. Privacy is the subject of dozens of laws and regulations. The present primary business case for developing, maintaining, and conforming to a privacy policy is to mitigate liability.</li>
<li><strong>Inform Data Subjects</strong>. Data Subjects include consumers, employees, or any individual about whom information is collected, stored, or aggregated.</li>
<li><strong>Empower Data Subjects</strong>. Mere information is not enough. A privacy policy which produces information overload without <em>actionable intelligence</em> is counter-productive.</li>
<li><strong>Articulate Privacy Practices</strong>. For the benefit of both data subjects and the data stewards who must execute the privacy policy, it must explain and reflect real business practices.</li>
<li><strong>People Don&#8217;t Read</strong>. Anything more than about two paragraphs will never be read.  That&#8217;s why high-level iconography is so appealing (and achievable).</li>
<li><strong>Must Be Easy-to Understand</strong>. Because people don&#8217;t read.  Fewer words and easy-to-grasp iconography are better.</li>
<li><strong>Short Policies Are Inherently Incomplete</strong>. Two paragraphs and pretty pictures may be sufficient to inform consumers on the portions of the privacy policy they find most important, but will always be incomplete.  More on this <a href="#incomplete">below</a>.</li>
<li><strong>Adoption &amp; Enforcement</strong>. A Privacy Commons must be optimized for adoption, rather than enforcement. That&#8217;s simply because despite the Federal Government, the states and the FTC&#8217;s regulation in the area, a privacy commons must be market-driven to be successful.</li>
<li><strong>Sector-Specific</strong>. Different sectors/activities collect different sets of personal information, are regulated differently. In order to ensure that privacy policies are relevant, they must be taylored to specific <a href="http://wiki.privacycommons.org">activities</a>.</li>
<li><strong>Living Documents</strong>. A privacy policy which was correct six months ago may not be correct today.</li>
<li><strong>Privacy Policies are Complex. Deal with it</strong>. Privacy Policies are complex, just like Creative Commons or the Telephone.  More on that <a href="incomplete">below</a>.</li>
<li><strong>Business Documents</strong>. Privacy Policies are business documents with legal, practical, business, and  ramifications for corporations, their agents and employees, and data subjects.</li>
</ol>
<p><a name="incomplete"></a><br />
Thinkers like Christopher Parsons worry that a Privacy Commons will be unnecessarily complex.  Non-attorneys are often (justifiably) baffled at why lawyers take 3,000 words to say what can be said in 300 and a handshake. It turns out that a simple handshake is not as simple as most people think.  Behind each handshake there is a wide range of assumptions which are not as standard as one might believe.  Many (if not most) disputes arise when there is a misunderstanding about an unspoken assumption&mdash;the meaning of a word, or silence on a particular issue.  That&#8217;s why it takes lawyers so many words to say something so simple; simple things are not as simple as we thought.</p>
<p>To demonstrate this point, we need look no further than Creative Commons.  While the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">human-readable version</a> of the &#8220;Attribution Non-Commercial Share Alike&#8221; creative commons license consists of 5 images and 286 words, the <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/legalcode">legal version</a> contains <strong>3,384 words</strong>.  Clearly the unnecessary work of a verbose lawyer who needed to justify his existence, right?</p>
<p>Not so fast.  The full Attribution Non-Commercial Share Alike license covers a whole bunch of other stuff that consumers don&#8217;t usually take time to think about, unless of course there is a dispute.  It&#8217;s only at that point that we&#8217;re glad we included it.  The legalese version covers essential topics like media and language translation, public performance, DRM, collections of works, waiver of compulsory license fees, preservation of moral rights, representations and warranties, limitation on author&#8217;s liability, termination, severability, waiver, and entire agreement, just to name a few.  Consumers don&#8217;t (and shouldn&#8217;t) think about this kind of stuff when they proverbially &#8220;shake hands&#8221; with a licensee.  Creative Commons is simple on the surface, but look under the hood and you&#8217;ll see the complexity necessary to create the elegance that most people associate with the CC licenses. Saying that the legalese version of a Creative Commons License (or Privacy Commons Policy) is a &#8220;necessary evil&#8221; is incorrect and misses the point. It&#8217;s not evil at all; it&#8217;s just necessary.</p>
<p>It&#8217;s like a telephone&mdash;an elegant piece of equipment which is exceedingly easy to use.  The end-user only cares about a few things: Connectivity, line quality, cost, and accessibility.  Yet the infrastructure and technology supporting telephony and networking is extremely robust and complex.  Consumers pay the telcos to worry about all of the other stuff so they can focus on the four or five things that consumers care about.  The millions of miles of copper, routers, substations and central offices aren&#8217;t a &#8220;necessary evil,&#8221; they&#8217;re just necessary.</p>
<h1>Some Conclusions About Privacy Policies</h1>
<p>We&#8217;re just going to have to deal with the fact that privacy policies are complex, and will continue to be complex.  The best solution (as I see it) is to do three things:  ID c.</p>
<ul>
<li><strong>Require Thoroughness</strong>. A Privacy Commons-compliant policy is thorough</li>
<li><strong>Identify Cultural Notions of Privacy</strong>. Identify culturally important notions of privacy, and embody them in easy-to-understand iconography.  <a href="http://www.christopher-parsons.com/blog/thoughts/thinking-about-a-privacy-commons/">Christopher Parsons</a> suggests these notions might center on <strong>Data Collection, Data Sharing, Data Identification, Data Tracking, Data Deletion, and Aggregation</strong>, which I think is a good start. And Ralf Bendrath offers <a href="http://bendrath.blogspot.com/2007/05/icons-of-privacy.html">these excellent icons</a>, which are more elegant than any I&#8217;ve seen.</li>
<li><strong>Embody the Cultural Notions of Privacy in Iconography</strong>. Then let the legalese version fill in the (necessary) gaps.</li>
</ul>
<p>A privacy policy which conforms to Privacy Commons requirements will be complete, informative, easy to understand, and easy to adopt.  Like Creative Commons, Privacy Commons seeks to identify common cultural notions of privacy, and embody them in easy-to-understand policy frameworks, with simple high-level iconography.</p>
<p><em>Note: I usually blog on <a href="http://www.securitycatalyst.com">securitycatalyst.com</a> and <a href="http://www.jeffreyneu.com">jeffreyneu.com</a>, but this post doesn&#8217;t fit very well on either.</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/12/06/my-thoughts-about-privacy-commons/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>NJ Supreme Court: Attorney-Client Privilege in Personal Email at Work</title>
		<link>http://www.aarontitus.net/blog/2009/12/03/nj-supreme-court-attorney-client-privilege-in-personal-email-at-work/</link>
		<comments>http://www.aarontitus.net/blog/2009/12/03/nj-supreme-court-attorney-client-privilege-in-personal-email-at-work/#comments</comments>
		<pubDate>Thu, 03 Dec 2009 08:47:31 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=150</guid>
		<description><![CDATA[Note: This article originally appeared on the J.C. Neu &#38; Associates Blog
Yesterday the New Jersey Supreme Court heard arguments in the Stengart v. Loving Care Agency, Inc. case.  The issue is whether the New Jersey attorney-client privilege is preserved, when an employee e-mails her attorney from a personal email account, on a company computer.
The [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.jeffreyneu.com/20091203243/NJ-Supreme-Court-Attorney-Client-Privilege-in-Personal-Email-at-Work.html">J.C. Neu &amp; Associates Blog</a></em></p>
<p>Yesterday the New Jersey Supreme Court heard arguments in the <em>Stengart v. Loving Care Agency, Inc.</em> case.  The issue is whether the New Jersey attorney-client privilege is preserved, when an employee e-mails her attorney from a personal email account, on a company computer.</p>
<p>The first reaction from most lawyers is, &quot;yikes, I hope so.&quot;</p>
<p>Maria Stengart was a senior employee at Loving Care, which provides Home Care Services for children and adults. Among other things, Loving Care&rsquo;s employee handbook states that &ldquo;Email and voice mail messages, internet use and communication, and computer files are considered part of the company&rsquo;s business and client records. Such communications are not to be considered private or personal to any individual employee.&rdquo;   Stengart was issued a company laptop, on which she occasionally accessed her personal Yahoo account.  She resigned in December, 2007 and shortly thereafter filed suit against Loving Care alleging constructive discharge due to sexual harassment and ethnic discrimination.</p>
<p>In April 2008 Loving Care sent an image of her laptop hard drive to a data recovery company, which recovered at least one personal Yahoo email between Stangart and her attorney, presumably from a recovered browser cache.  Of course, this prompted Stengart to assert attorney-client privilege, demanding that all attorney communications be returned or destroyed. The company balked, and in essence argued that Stengart had waived the privilege by using a company computer.</p>
<p>The trial court found in favor of the employer, but the appellate court reversed.</p>
<p>If I were to play armchair quarterback for a second, I think that the New Jersey Supreme Court will probably find in favor of Stengart as a substantive matter, but the case raises several issues of legal, policy, and practical significance, with no apparent easy answers.</p>
<p> In general, employees have a diminished (ie, nearly zero) expectation of privacy on an employer&rsquo;s network, especially when the employer has put the employee on notice of that fact.  The trial court merely extended this well-established principle to attorney-client communications.   After all, an employer must be able to control, protect, and secure its network against a range of threats.</p>
<p>On the other hand, most employers allow company computers to be used for personal reasons. It seems to be bad public policy that an employee would waive the attorney-client privilege simply because she uses a browser on her company computer during her lunch break, rather than a home browser. This is especially true if she happens to e-mail her lawyer about an action against the employer.  It seems absurd that a distinction so technical should allow the employer to &quot;rummage through and retain the employee&rsquo;s e-mails to her attorney,&quot; as the appellate court put it.</p>
<p>But if an employee does enjoy some expectation of privacy in personal communications over a company network, how much, and how does an employer write a policy to manage it? Does an employee enjoy the same expectation of privacy for personal email transferred via POP3 or IMAP to a local company version of Outlook, compared to a email recovered from an HTTP browser cache?  Does the employer have a duty to not attempt to recover deleted personal emails? Are employers allowed to snoop unless communication appears privileged?  I don&rsquo;t have a good answer, and it will be interesting to see what answer the court comes up with.</p>
<p>Surely an employee cannot enjoy an unqualified expectation of privacy by simply using non-company communications, because employers still have an interest in making sure that employees do not use personal accounts to transfer trade secrets, compete against the company, or download a virus.</p>
<p>We&rsquo;ll keep an eye on this one.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/12/03/nj-supreme-court-attorney-client-privilege-in-personal-email-at-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aaron Titus Speaking at ICAMISS</title>
		<link>http://www.aarontitus.net/blog/2009/10/07/aaron-titus-speaking-at-icamiss/</link>
		<comments>http://www.aarontitus.net/blog/2009/10/07/aaron-titus-speaking-at-icamiss/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 08:44:50 +0000</pubDate>
		<dc:creator>Titus</dc:creator>
				<category><![CDATA[Law and Politics]]></category>

		<guid isPermaLink="false">http://www.aarontitus.net/blog/?p=148</guid>
		<description><![CDATA[Note: This article originally appeared on the J.C. Neu &#38; Associates Blog
Aaron Titus will be presenting at the International Conference on Applied Modeling &#38; Information Security Systems (ICAMISS) on October 10, 2009 at the University of Alabama, Birmingham.
The speech will focus on the risks associated with personal information management, especially in an institution of higher [...]]]></description>
			<content:encoded><![CDATA[<p><em>Note: This article originally appeared on the <a href="http://www.jeffreyneu.com/20091007237/Aaron-Titus-Speaking-at-ICAMISS.html">J.C. Neu &amp; Associates Blog</a></em></p>
<p>Aaron Titus will be presenting at the International Conference on Applied Modeling &amp; Information Security Systems (<a href="http://www.eiu.edu/~iasc/agenda.pdf" target="_blank" title="ICAMISS Schedule">ICAMISS</a>) on October 10, 2009 at the University of Alabama, Birmingham.</p>
<p>The speech will focus on the risks associated with personal information management, especially in an institution of higher education, where information is supposed to flow freely.&nbsp; These are among the policies and behaviors that put information at risk:</p>
<ul>
<li>Administrative Decentralization</li>
<li>Naive Office Culture</li>
<li>Unprotected &ldquo;Old&rdquo; Data</li>
<li>Shadow Systems</li>
<li>Unregulated Servers</li>
<li>Unsophisticated Privacy Policies</li>
<li>Improper Use of the SSN</li>
<li>Unsanitized Hard Drives and Insecure Laptops</li>
</ul>
<p>The International Conference on Applied Modeling &amp; Information Security Systems is sponsored by the Department of Defense, Krell Institute, NASA-Ames Research Center, Institute of Applied Science &amp; Computation, Eastern Illinois University and University of Alabama at Birmingham.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.aarontitus.net/blog/2009/10/07/aaron-titus-speaking-at-icamiss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
