28 February 2014

Privacy Enforcement

A recent post noted the Compliance & Enforcement Priorities statement by the Australian Competition & Consumer Commission, a useful tool for business, consumers and scholars of regulation.

The Office of the Australian Information Commissioner has today released a statement on its "enforcement approach" (implicitly its priorities.)

As you might expect, given that agency's performance, it is vague but the OAIC is to be commended for actually making a statement after years in which its priorities weren't clear.

Key passages are -
The Office of the Australian Information Commissioner (OAIC) has adopted an enforcement approach to the reforms which recognises that Australian Government agencies and businesses are working hard to implement the new requirements. Our compliance focus in the months following 12 March 2014 will be on working with entities to ensure that they understand the new requirements and have the systems in place to meet them. In resolving matters brought to the attention of the OAIC we will take into account the steps taken by entities to genuinely prepare for the changes and to comply with the new legal requirements. 
Central to the OAIC’s enforcement approach is an escalation model that includes a range of regulatory responses. 
Individuals will continue to have the right to make a complaint to the OAIC and we will deal with these according to our usual processes. That is, in the first instance, in the case of individual complaints we would expect to see a person try to resolve a matter with the organisation or agency first. If the respondent is a member of a recognised External Dispute Resolution scheme, we would also expect the individual to have first accessed that scheme. If a matter is accepted by us, we will always attempt to resolve issues through conciliation. In relation to Commissioner initiated investigations the OAIC will work with respondent organisations and agencies to resolve the matter. 
However, where conciliation or working with entities is not effective, we may use our other tools, including determinations, enforceable undertakings or in the case of serious or repeated breaches, initiating court proceedings for civil penalties. This is consistent with our current practices and the approach of the OAIC for some time.
Indeed, business as usual. No indication about timeliness of response. No indication about vigorous investigation and commitment to publishing reports on inadequate performance by entities that hold personal information. No indication that the OAIC will be proactive rather than reactive.

In practice the statement doesn't go beyond what appears in the Act or in previous indications by the OAIC.  It enshrines, as the OAIC indicates, "our current practices and … approach".

From a regulatory perspective it is the sort of prioritisation that you have when you don't have much sense of priorities and - to be fair - don't have major resources, although the OAIC might perhaps spend less time and money on promo and more in actively dealing with problems.

A more useful approach would be for the agency to indicate that the OAIC will be concentrating on areas of particular concern, whether on an ongoing or one-off basis. That would require more energy and creativity but we do, after all, pay the OAIC for initiative and smarts rather than corporate self-congratulation.

Surveillance and Privacy Impact Notices

'Regulating Mass Surveillance as Privacy Pollution: Learning from Environmental Impact Statements' by A. Michael Froomkin argues
 US law has remarkably little to say about mass surveillance in public, a failure which has allowed the surveillance to grow at an alarming rate -- a rate that is only set to increase. This article proposes 'Privacy Impact Notices' (PINS) -- modeled on Environmental Impact Statements -- as an initial solution to this problem. 
Data collection in public (and in the home via public spaces) resembles an externality imposed on the person whose privacy is reduced involuntarily; it can also be seen as a market failure caused by an information asymmetry. Current doctrinal legal tools available to respond to the deployment of mass surveillance technologies are limited and inadequate. The article proposes that -- as a first step towards figuring out how to understand, value, and ultimately regulate this mass-privacy-destroying behavior -- we should borrow from the environmental movement and require anyone planning a large-scale public data collection program to file a Privacy Impact Notice (PIN). The PIN proposal is contrasted to the existing much more limited federal privacy analysis requirement, known as Privacy Impact Assessments. The bulk of the article then explains how PINs would work and defends the idea against three predictable critiques (the claim that there is a First Amendment right to data collection, the claim that EISs are a poor policy tool not worthy of emulation, and the claim that notice-based regimes are in general worthless). It argues that PINs have applications to surveillance and data-collection in online public spaces such as Facebook, Twitter, and other virtual spaces. It also considers what the PINs proposal would have to offer towards addressing the now-notorious problem of the NSA’s drift-net surveillance of telephone conversations, emails, and web-based communications. 
Modeling mass surveillance disclosure regulations on an updated form of environmental impact statement will help protect everyone’s privacy: Mandating disclosure and impact analysis by those proposing to watch us in and through public spaces will enable an informed conversation about privacy in public. Additionally, the need to build consideration of the consequences of surveillance into project planning, as well as the danger of bad publicity arising from excessive surveillance proposals, will act as a counterweight to the adoption of mass data collection projects, just as it did in the environmental context. In the long run, well-crafted disclosure and analysis rules could pave the way for more systematic protection for privacy -- as it did in the environmental context. Effective US regulation of mass surveillance will require that we know a great deal about who and what is being recorded and about the costs and benefits of personal information acquisition and uses. At present we know relatively little about how to measure these; a privacy equivalent of environmental impact statements will not only provide case studies, but occasions to grow expertise.

De-extinction and the Technological Sublime

Last year I noted several items (here and here) on increasingly fashionable plans for de-extinction, e.g. using molecular genetics to engineer the Dodo, Great Auk, Carolina Parakeet, Tasmanian Tiger or the Mammoth.

The New York Times, in a somewhat breathless piece about revival of the Passenger Pigeon and Mammoth, notes the vision by cyber-utopisan Stewart Brand that resurrection of the Mammoth would be good for the environment -
 Just as the loss of a species decreases the richness of an ecosystem, the addition of new animals could achieve the opposite effect. The grazing habits of mammoths, for instance, might encourage the growth of a variety of grasses, which could help to protect the Arctic permafrost from melting — a benefit with global significance, as the Arctic permafrost contains two to three times as much carbon as the world’s rain forests. “We’ve framed it in terms of conservation,” Brand told me. “We’re bringing back the mammoth to restore the steppe in the Arctic. One or two mammoths is not a success. 100,000 mammoths is a success.” 
Resurrection of the Pigeon project would supposedly provide “a beacon of hope for conservation”, although in my opinion it might have the opposite effect - blithely disregard environmental problems in the here and now because the geeks at Pleistocene Park Inc can bring the defunct species back from the grave whenever they want.

The NYT goes on to state that
A less scientific, if more persuasive, argument was advanced by the ethicist Hank Greely and the law professor Jacob Sherkow, both of Stanford. De-extinction should be pursued, they argued in a paper published in Science, because it would be really cool. “This may be the biggest attraction and possibly the biggest benefit of de-extinction. It would surely be very cool to see a living woolly mammoth.” 
Ah, cool. Cool in the same way that gigantic explosions would be cool - the technological sublime where bigness and badness is best?

With apologies to Richard Barbrook, in the future the right people will be rich, hip, Californian and cool … with a private Sabre tooth, Dodo, Mammoth or other retroDNA-ware!

'What If Extinction Is Not Forever?' by Jacob S. Sherkow and  Henry T. Greeley in (2013) 340(6128) Science 32-33 argues that -
Objections to bringing back extinct animals fall into five categories: animal welfare, health, environment, political, and moral. 
Animals created in the de-extinction process could end up suffering, either as a result of the processes used or because of their particular genomic variations. We know, for example, that SCNT can lead to high levels of deformity and early death. The Animal Welfare Act and its institutional animal care and use committees limit precisely this kind of suffering. Beyond physical suffering, some animal advocates might oppose de-extinction as they oppose zoos—on the grounds that they exploit animals for unimportant human purposes, like entertainment. Newly de-extinct creatures might prove excellent vectors for pathogens. An extinct animal's genome could also conceivably harbor unrecognized, harmful endogenous retroviruses. 
If the species either is released or escapes into the general environment, it might do substantial damage. Even extinct species that were not pests in their past environments could be today. For example, less than 200 years ago, billions of passenger pigeons migrated each year between the eastern United States and Canada. Today, those regions have far more humans, far larger urban centers, very different agriculture, and largely transformed ecosystems. The American chestnut, a main food source for the passenger pigeon, is now nearly extinct in the wild. Even in the same location, the passenger pigeon would today be an alien, and potentially invasive, species—perhaps another starling or even an avian kudzu. 
The political risks are considerable, too. Current protection of endangered and threatened species owes much to the argument of irreversibility. If extinctions—particularly extinctions where tissue samples are readily available—are not forever, preservation of today's species may not seem as important. Also, genetics and, more broadly, modern bioscience, could face a backlash if citizens perceive public investments in bioscience as being used to revive species rather than cure human disease. 
Finally, some people will complain that, whatever its consequences, de-extinction is just wrong—it is “playing god,” “reversing natural selection,” or an act of hubris. Others may argue that we cannot know enough about the consequences to re-introduce a species. But neither do we know the full consequences of its extinction or its continuing nonexistence.
The supposed benefits are
 Like the risks or objections to de-extinction, we see the benefits falling into five categories: scientific knowledge, technological advancement, concrete environmental benefits, justice, and “wonder.” These benefits are quite similar to the arguments made for preserving currently endangered or threatened species. 
De-extinction could allow scientists the unique opportunity to study living members of previously extinct species (or, at least, close approximations to those species), providing insights into their functioning and evolution. Some revived species may be translated into useful products; for example, it is conceivable that new drugs may be derived from extinct plants. 
De-extinction could lead to technological advances. The most likely would be improvements in genetic engineering, such as the targeted replacement of large stretches of genomic DNA. 
Some researchers argue that “re-wilding” with existing species, locally extinct in particular habitats, can help restore extinct or threatened ecosystems. The same can be argued about the restoration of extinct species. The revival of the wooly mammoth as a major grazing animal in the Arctic, for example, might provide substantial benefits by helping restore an arctic steppe in the place of the less ecologically rich tundra. 
Justice is a viscerally attractive argument for de-extinction, at least for species that humans drove to extinction: We killed them. We have the power to revive them. We have a duty to do so. But to whom or what do we owe that duty? Would it apply to all species in whose extinction humans played the sole, the leading, or a substantial role? 
The last benefit might be called “wonder,” or, more colloquially “coolness.” This may be the biggest attraction, and possibly the biggest benefit, of de-extinction. It would surely be very cool to see a living wooly mammoth. And while this is rarely viewed as a substantial benefit, much of what we do as individuals—even many aspects of science—we do because it's “cool.”
 They go on to comment -
The answer to the question—What to do about de-extinction?—depends in part on closely defining the question. Consider three different “bottom-line” questions. 
First, should de-extinction be publicly funded? This answer seems, to us, “largely no.” The potential tangible benefits from de-extinction are too small and the potential objections are too serious to justify substantial government expenditure. One might argue that governments fund science projects with similarly small practical relevance, but those “cool” projects, like the Mars rovers, present fewer risks and objections. 
Second, should de-extinction be categorically banned? Here the answer seems a fairly clear “no.” The risks look fairly small and probably manageable. If people want to devote their own time, money, and efforts to the endeavor, the risks to the world do not seem to justify complete prohibition. 
Third, should de-extinction be regulated? Here, we think the answer is “Yes—somewhat.” The animal welfare and environmental concerns are real. They could be mitigated by protective action but only if the law requires it. Bringing all de-extinction efforts under something like the Animal Welfare Act and requiring careful environmental assessments before any planned releases (as well as approved precautions against inadvertent release) do seem appropriate. Whether other kinds of regulation are needed is less clear, although there may be some cases, like any attempted revival of extinct hominid species, where special controls, or bans, would be appropriate.

Copyright Litigation

'Copyright's Topography: An Empirical Study of Copyright Litigation' by Christopher Anthony Cotropia and James Gibson in (2014) Texas Law Review comments
 One of the most important ways to measure the impact of copyright law is through empirical examination of actual copyright infringement cases. Yet scholars have universally overlooked this rich source of data. This study fills that gap through a comprehensive empirical analysis of copyright infringement litigation, examining the pleadings, motions, and dockets from more than nine hundred copyright lawsuits filed from 2005 through 2008. The data we collect allow us to examine a wide variety of copyright issues, such as the rate of settlements versus judgments; the incidence of litigation between major media companies, small firms, and individuals; the kinds of industries and works involved in litigation; the nature of the alleged infringement; the success rates of particular parties and claims; and the nature of remedies sought and awarded. We also analyze the data to identify ways in which copyright litigation differs from other civil suits and to show that certain plaintiff characteristics are more predictive of success.

Citizenship

'The Rights and Responsibilities of Australian Citizenship' by Sangeetha Pillai in (2014) 37(3) Melbourne University Law Review indicates that
The Preamble to the Australian Citizenship Act 2007 (Cth) makes three broad claims about Australian statutory citizenship: that it signifies ‘full and formal membership of the Australian community’; that it is characterised by the possession of ‘reciprocal rights and obligations’; and that it is a ‘bond’ that ‘unites all Australians’. This article examines the extent to which these claims accurately describe the legal implications of citizenship in Australia. In doing so, it looks in detail at the degree to which holding Australian statutory citizenship impacts upon the rights a person possesses in four broad categories that are intrinsically connected with citizenship: status protection rights, rights to entry and abode, rights to protection, and political rights.
 Pillai comments that
The Parliament recognises that Australian citizenship represents full and formal membership of the community of the Commonwealth of Australia, and Australian citizenship is a bond, involving reciprocal rights and obligations, uniting all Australians while respecting their diversity. 
The Parliament recognises that persons conferred Australian citizenship enjoy these rights and undertake to accept these obligations: 
(a) by pledging loyalty to Australia and its people; and 
(b) by sharing their democratic beliefs; and 
(c) by respecting their rights and liberties; and 
(d) by upholding and obeying the laws of Australia. 
— Preamble, Australian Citizenship Act 2007 (Cth)
Unpacking the legal implications of citizenship in Australia requires an inquiry on at least two levels. First, the statutory citizenship regime set up by the Australian Citizenship Act 2007 (Cth) (‘ACA 2007 ’) and associated legislation must be understood. Secondly, this legislative regime must be situated within the parameters of the broader framework established by the Australian Constitution. 
The constitutional framework for Australian citizenship has received sig- nificant attention in a number of recent scholarly papers. Accordingly, this article directs its focus towards the first limb of inquiry: the question of what legal consequences flow from the possession of statutory citizenship in Australia. This is an issue which has escaped substantial consideration for over 10 years, despite the fact that during this time the ACA 2007 was introduced to replace the previous citizenship legislation, the Australian Citizenship Act 1948 (Cth) (‘ACA 1948’). 
In particular, this article seeks to test claims about the legal significance of possessing Australian citizenship against the legal reality. The above Preamble serves as a useful source of such claims. The Preamble was first introduced, albeit with slightly different wording, into the Australian Citizenship Act 1948 by amendment in 1993. In the second reading speech for the amending legislation, Senator John Faulkner stated that the Preamble would ‘defin[e] the meaning which the Parliament and the people of Australia accord to citizenship’. 
The Preamble suggests that three broad implications flow from the posses- sion of statutory citizenship in Australia. First, it claims that, unlike non- citizens, citizens under the Act are ‘full and formal members’ of the Australian community. Secondly, it suggests that citizenship is characterised by the possession of ‘reciprocal rights and obligations’ that are not held by non-citizens. Finally, the Preamble describes statutory citizenship as a ‘bond’ that ‘unite[s] all Australians while respecting their diversity’, suggesting that citizenship is underpinned by principles of equality. In Roach v Electoral Commissioner (‘Roach’), Gleeson CJ drew directly on the ‘reference to the reciprocity of rights and obligations’ in the Preamble. His Honour stated that this notion of reciprocity is ‘important in the context of membership of the community’, and that breaching the obligations of mem- bership (for example, through serious criminal activity) may warrant temporary suspension of legal rights associated with citizenship. Gleeson CJ’s statement suggests that the citizenship rights and obligations referred to in the Preamble are not purely moral or social in nature; to at least some extent, they give rise to legal implications. This article analyses the extent of these implications via an examination of the most significant differences between the rights of citizens and non-citizens under Commonwealth legislation. This question has previously been considered by Kim Rubenstein in her 2002 text, Australian Citizenship Law in Context, which comprehensively surveys the extent to which Commonwealth legislation discriminates on the basis of statutory citizenship. 
Rubenstein’s study reached two broad conclusions: first, that statutes far more commonly discriminate on the basis of residence in Australia than on the basis of citizenship; and secondly, that where citizenship-based discrimination does exist in Commonwealth legislation, this discrimination lacks any ‘consistent basis’. Though over a decade has elapsed, and the citizenship legislation in force in 2002 has been replaced, these conclusions remain broadly true today. Accordingly, this article adopts a more targeted analysis. Rather than cataloguing every legislative distinction that separates citizens and non-citizens, it looks in-depth at the extent to which holding statutory citizenship impacts upon the possession of rights in four broad categories: status protection rights, rights to entry and abode, rights to protection, and political rights. 
These categories are intrinsically connected with citizenship. Each enshrines rights which were fundamental to very early configurations of the state–citizen relationship. Moreover, they have not lost relevance over time; internationally, the codification of express citizenship rights in each of the four areas is very common, both constitutionally and in statute. To a certain extent, Australian legislation reflects this trend. In each category, possession of Australian citizenship materially affects the extent to which rights protection exists. This is in contrast to most rights in Australia, which are not predicated upon possession of citizenship. However, the extent to which citizens’ rights protection in these areas is achieved through statutory codification varies somewhat. Moreover, legal protection is not always equal for all citizens, calling into question the notion of equality between citizens alluded to in the Preamble to the ACA 2007. 
This article is divided into five parts. Part II contextualises the ACA 2007, providing an overview of its substance, and explaining its constitutional basis and evolution from historical citizenship legislation in Australia. Part III examines the question of what rights flow from the possession of statutory Australian citizenship in each of the categories outlined above. In doing so, it compares the rights that arise in Australia with those in overseas jurisdictions. Particular emphasis is placed on the citizenship rights that exist in the United Kingdom, Canada and New Zealand. These countries emerge as natural comparators for Australia for two reasons. First, all four countries share a historical connection, in the sense that their concepts of citizenship have roots in the common law concept of ‘British subject’ status. Secondly, like Australia but unlike a large number of countries worldwide, legal citizenship in the UK, Canada and New Zealand is primarily developed through statute, rather than constitutionally. Part IV examines the question of which obligations, if any, can be said to arise reciprocally to the rights considered in Part III. Part V concludes by considering whether the Preamble’s three claims about the nature of Australian citizenship are borne out by Australian law, based on the analysis in Parts III and IV.

27 February 2014

UK Hospital Data

Amid increasing controversy over the ambitious UK care.data program noted elsewhere in this blog the Guardian reports
Less than a week after the NHS was forced to postpone its huge GP and hospital record-sharing plan, it has emerged that a major insurance body bought more than a decade's worth of hospital data covering 47 million patients which, it was claimed, is to be used to help insurers refine their premiums. 
The Staple Inn Actuarial Society [SIAS] said that data covering all hospital in-patient stays between 1997 and 2010 was used to track patients' medical histories, identified by date of birth and postcode, according to the Daily Telegraph. 
The details were then reportedly combined with information from credit ratings agencies and used to advise insurance companies, resulting in increased premiums for most customers below the age of 50. 
The newly formed Health & Social Care Information Centre (HSCIC), which collects national health and social care data, said that the records referred to by the Staple Inn Actuarial Society had been provided by a predecessor body, the NHS Information Centre.
It insisted that the records were not used to analyse individual insurance premiums but to analyse general variances in critical illness. 
"The newly formed HSCIC can now only provide HES [hospital episode statistics] data to organisations that are looking to improve the way they are run for the benefit of their patients," it said in a statement. "This data is completely protected and does not identify individuals."
The Daily Mail meanwhile reports
Hospital records of every NHS patient have been sold to insurers, it has emerged. 
A major UK insurance society claims it was able to access records of 47 million patients over 13 years to help it decide premiums for customers. 
The Staple Inn Actuarial Society said in a report that it used NHS data covering all hospital in-patient stays between 1997 and 2010 to track the medical histories of patients, identified by date of birth and postcode. ... The group – which works on behalf of insurance companies and actuaries – used the information to recommend an increase in the price of policies for thousands of customers last year. 
Concerns over use of patient data have been heightened in recent days after plans to roll out a new NHS data-sharing scheme were put on hold amid concerns over privacy and patients not being properly informed over the changes. 
The central database would involve taking records from GP practices and linking them with hospital records. 
Those promoting the scheme insist that it would be illegal for information held in GP records to be sold to insurers. 
The Staple Inn Actuarial Society report said it was able to combine hospital patient data with credit ratings agencies to advise companies, which led to increased premiums for most customers over the age of 50. 
The society said it was able to better calculate forecasts for certain diseases, such as lung cancer.
In discussing care.data I've suggested that, privacy to one side, a key issue is the big data hubris that leads health administrators and ICT enthusiasts to disregard the need to adequately explain what is going on and thereby foster trust.

The UK Institute & Faculty of Actuaries has responded that the Daily Telegraph has got the story wrong. Trust however isn't encouraged by looking at the Institute's own site, where point slides for example enthuse -
Hospital Episodes Statistics data set
• Seriatim data of all finished consultant episodes in NHS hospitals – Inpatient and outpatient data 
• Data years 1989/90 to 2009/10 received – 1997/98 to 2009/10 are coded with unique patient identifiers 
• 18 million records for 2009/10 alone!
and
What the HES data looks like 
• Patient Identifier - Unique identifier by patient – 47m of these 
• Basic Patient Information - Age, gender 
• Basic Episode Information - Date started, date finished, admission method, current status etc 
• Diagnosis Information - Up to 20 different diagnoses 
• Procedure Information - Up to 20 different operations, with date of operation 
• Geographical Information - Postal district, Lower Super Output Area, IMD Rank, Mosaic Type, ACORN Type, Health ACORN type
Reidentification might not be that difficult, irrespective of whether there is a data breach prior ro pseudonymisation.

The Institute states that
“In a story published by the Daily Telegraph today research by the IFoA was represented as “NHS data sold to insurers”. This is not the case. The research referenced in this story considered critical illness in the UK and was presented to members of the Staple Inn Actuarial Society (SIAS) in December 2013 and was made publically available on our website. 
“The IFoA is a not for profit professional body. The research paper – Extending the Critical Path – offered actuaries, working in critical illness pricing, information that would help them to ask the right questions of their own data. The aim of providing context in this way is to help improve the accuracy of pricing. Accurate pricing is considered fairer by many consumers and leads to better reserving by insurance companies. 
“Nowhere in this paper does the IFoA recommend a change in insurance pricing.” 
The research referenced in the Telegraph story was produced by the Institute and Faculty of Actuaries (IFoA), an independent, not for profit professional body. It was published in December 2013 and in the same month was presented to SIAS members. 
SIAS is a non-commercial body with over 5,000 members around the world, representing and serving the interests of younger members of the actuarial profession, whilst also acting as the London region actuarial society. 
The research “Extending the critical path”, was produced to provide a clearer picture of critical illness in the UK. 
The research makes no pricing recommendations. It provides information for actuaries, enabling them to look at the broader experience of critical illness in the UK against their own data. It is a reference point rather than a tool used to set pricing. It is also available to any organisation or body interested in critical illness in the UK. 
The research used anonymised data from the NHS that was available to organisations looking to further critical illness research. Individuals cannot be recognised from this data. The source data for this research was not made available by us to our membership or to other organisations, our analysis of this data is.

Haters

'Should Hate Speech Be Protected? Group Defamation, Party Bans, Holocaust Denial and the Divide between (France) Europe and the United States' by Ioanna Tourkochoriti in (2014) 45 Columbia Human Rights Law Review comments
 The 2011 legislative proposal by the French Government to criminalize denial of the Armenian Genocide — and the legislation’s invalidation by the French Constitutional Council on rule of law grounds without seriously addressing the free speech concerns underlying the case — raised once more the question of the limits of hate speech protection and of political tolerance in a democratic society. Is it legitimate for the state to intervene in order to protect its citizens from offensive speech or from the danger of arriving at erroneous opinions? Hate speech manifests itself today in various forms, but in general, European law is more restrictive of hate speech than U.S. law. This Article presents the different legal responses in Europe and the United States and evaluates them. Whereas most analysts take an "all or nothing" approach to these issues — believing that, if limits are placed on hate speech, then those limits should apply broadly to hate speech in all of its manifestations — the analysis in this Article shows why we should distinguish between different types of hate speech for philosophical reasons grounded within liberalism. The Article proposes a philosophical approach that justifies the punishment of group defamation while opposing bans of certain political parties and the criminalization of the contestation of historical facts.