UK Information Commissioner issues recommendations for bring your own devices

January 9, 2014

The UK Information Commissioner’s office has issued recommendations on the use of bring your own devices (“BYOD”).  Poor practices regarding BYODs have caused significant privacy breaches.  The Information Commissioner has taken action against government and private organisations in the last 12 months.  The recommendations are found here.

The recommendations and media release provides:

A survey before Christmas showed that sixty per cent of the UK population now own a smart phone and 20% a tablet. This is no doubt even higher as smart phones and tablets topped many people’s Christmas gift lists, and an increasing number want to use their personal devices at work.

Known as ‘bring your own device’ this trend has Read the rest of this entry »

The article that says it all: Are you prepared for the March 2014 Privacy Act changes?

January 8, 2014

On 5 December 2013 the Age ran a piece titled Are you prepared for the March 2014 Privacy Act changes?  It is a piece, with helpful links to business.gov.au and the Privacy Commissioner’s site, that sets out directly and pithily the key issues that every organisation and agency needs to address now rather than in March 2014.

It provides:
From 12 March 2014, there will be many changes to the Privacy Act.
Although this seems a while away, if the Privacy Act applies to your business, it’s a good idea to start preparing for the changes now.

Does the Act apply to my business?

The Privacy Act protects Read the rest of this entry »

White hat hacks into Public Transport Victoria website

The Age reports in Schoolboy hacks Public Transport Victoria website how a 16 year old, Joshua Rogers, hacked into the Public Transport Victoria (“PTV”) website. The article notes that after Joshua notified the PTV of the security flaws it kindly notified the police and the Privacy Commissioner.  The reasons were not provided.  It will be interesting to see how both guardians, one of law and order and the other of privacy, will respond to the challenge.  Given PTV’s database contains vast amounts of personal information, including credit card details,the reported inadequacy of its on line security is a major concern.  Hopefully the Privacy Commissioner will take a robust approach when investigating this alleged failing. It would be fascinating to see what the results of a Privacy Impact Assessment by the PTV will reveal. Of course that won’t be made public.  Assuming it happens.

The article provides:

Personal information Read the rest of this entry »

Another App suffers privacy problems – this time Evernote

January 6, 2014

Evernote is app royalty.  A huge following and a very practical app.  I have Evernote.  But, as I have posted earlier, apps are prone to privacy breaches.  App developers and managers commonly fail to develop privacy protections, protocols and means of handling personal information.  The BBC in Evernote to focus on fixing bugs after complaints highlights how even the established and well regarded apps fall down in the privacy department. The constant challenge Read the rest of this entry »

Google glass and more privacy issues

Google and privacy.  Rarely a good fit, whether as a noun or adjective.  In Glass, Hats and Persistent Privacy Violations Wired reports on the privacy invasive actuality (not potential) of google caps/hats/glasses.  This technology, like drones, highlight the lacuna in the law.  Inadequate common law protections, a Privacy Act which would not be applicable for vast majority of users and no statutory right of privacy.

The article provides:

HAMBURG – In a perfect future, Stephen Balaban wants plenty of people to be wearing his Lambda Hat, a soon-to-be-released baseball-hat version of Google Glass. But even he has mixed feelings about the results.

Speaking here at the 30th annual Chaos Communication Congress, a conference that puts the highest premium possible on privacy, Balaban offered an uncomfortable reminder of the tradeoffs associated with the rise of ubiquitous computing, including his own use of his own product’s prototype.

“The sheer amount of data Read the rest of this entry »

Mobile Apps provide a significant privacy risk in Australia and overseas. Snapchat breaches provide another example

Mobile Apps are privacy invasive time bombs.  That unfortunately go off way too often.  This issue is now on the radar of information commissioner’s around the world.  And not before time.

The Privacy Commissioner has issued a guide on Mobile apps (found here)  and a check list (found here). The Warsaw declaration at the 35th international conference of data protection and privacy commissioners on the appification of society stated:

Nowadays, mobile applications (apps) are ubiquitous. On our smart phones and tablets, in cars, in and around the house: a growing number of items have user interfaces connected to the internet. Currently, over 6 million apps are available in both the public and private sector. This number is growing by over 30.000 a day. Apps are making many parts of our day-­to-­day lives more Read the rest of this entry »

Facebook sued for privacy related actions…..for a change

January 3, 2014

The Age in Facebook sued over alleged scanning of users’ private messages reports on yet another allegation of Facebook interfering with its users privacy.  Here scanning messages of its users.  The allegations are just that but Facebook has been so contemptuous of privacy in the past Read the rest of this entry »

Interesting view on what it is the greatest threat to privacy

In The biggest threats to our privacy the Demoines Register looks at the real and more mundane threats to privacy Read the rest of this entry »

Massive data breach in the US highlights the need for mandatory data breach notification regime in Australia.

December 30, 2013

Australia has no mandatory data breach notification regime.  The previous Parliament almost passed the Privacy Alert Bill 2013 earlier this year. The Bill passed the House of Representative and was awaiting the debate after the Second Reading speech in 2013.  That Australia does not have some form of mandatory Read the rest of this entry »

Apps and privacy

December 29, 2013

Privacy and apps are becoming strangers.  It has been an issue that has been growing for some time.  Privacy regulators around the world have started taking notice and issued the Warsaw declaration on the “appification” of society (found here). The Atlantic in highlights the issue in Study: Consumers Will Pay $5 for an App That Respects Their Privacy. The reality is that consumers want apps to protect their privacy.

The article provides:

Ever since the iPhone came out in 2007, the going rate for many of the most popular apps has been exactly $0.00. Consumers pay nothing.

But of course, nothing is free. Instead, consumers pay with their data, that’s sold to marketers, or with screenspace, which is forked over to make room for ads. It’s a trade consumers are happy to make.

But are they?

A new study from economists at the University of Colorado finds otherwise. It shows Read the rest of this entry »