04 July 2013

Mail Covers and Memory

The New York Times notes that the US Postal Service is "Logging All Mail for Law Enforcement" through the "Mail Isolation Control and Tracking program, in which Postal Service computers photograph the exterior of every piece of paper mail that is processed in the United States - about 160 billion pieces last year".

The Times notes that "it is not known how long the government saves the images" and that "postal mail is subject to the same kind of scrutiny that the National Security Agency has given to telephone calls and e-mail".
At the request of law enforcement officials, postal workers record information from the outside of letters and parcels before they are delivered. (Opening the mail would require a warrant.) The information is sent to the law enforcement agency that asked for it. Tens of thousands of pieces of mail each year undergo this scrutiny.
The Mail Isolation Control and Tracking program was created after the anthrax attacks in late 2001 that killed five people, including two postal workers. Highly secret, it seeped into public view last month when the F.B.I. cited it in its investigation of ricin-laced letters sent to President Obama and Mayor Michael R. Bloomberg. It enables the Postal Service to retrace the path of mail at the request of law enforcement. No one disputes that it is sweeping.
“In the past, mail covers were used when you had a reason to suspect someone of a crime,” said Mark D. Rasch, who started a computer crimes unit in the fraud section of the criminal division of the Justice Department and worked on several fraud cases using mail covers. “Now it seems to be, ‘Let’s record everyone’s mail so in the future we might go back and see who you were communicating with.’ Essentially you’ve added mail covers on millions of Americans.”
The Times notes Bruce Schneier's comment that the program is an invasion of privacy, irrespective of whether it involves a postal worker taking down information or a computer taking images.
“Basically they are doing the same thing as the other programs, collecting the information on the outside of your mail, the metadata, if you will, of names, addresses, return addresses and postmark locations, which gives the government a pretty good map of your contacts, even if they aren’t reading the contents,” he said.
... “It’s a treasure trove of information,” said James J. Wedick, a former F.B.I. agent who spent 34 years at the agency and who said he used mail covers in a number of investigations, including one that led to the prosecution of several elected officials in California on corruption charges. “Looking at just the outside of letters and other mail, I can see who you bank with, who you communicate with — all kinds of useful information that gives investigators leads that they can then follow up on with a subpoena.”
But, he said: “It can be easily abused because it’s so easy to use and you don’t have to go through a judge to get the information. You just fill out a form.”
For mail cover requests, law enforcement agencies submit a letter to the Postal Service, which can grant or deny a request without judicial review. Law enforcement officials say the Postal Service rarely denies a request. In other government surveillance programs, like wiretaps, a federal judge must sign off on the requests.
The mail cover surveillance requests are granted for about 30 days, and can be extended for up to 120 days. There are two kinds of mail covers: those related to criminal activity and those requested to protect national security. Criminal activity requests average 15,000 to 20,000 per year, said law enforcement officials, who spoke on the condition of anonymity because they are prohibited by law from discussing them. The number of requests for antiterrorism mail covers has not been made public.
Law enforcement officials need warrants to open the mail, although President George W. Bush asserted in a signing statement in 2007 that the federal government had the authority to open mail without warrants in emergencies or in foreign intelligence cases.
Court challenges to mail covers have generally failed because judges have ruled that there is no reasonable expectation of privacy for information contained on the outside of a letter. Officials in both the Bush and Obama administrations, in fact, have used the mail-cover court rulings to justify the N.S.A.’s surveillance programs, saying the electronic monitoring amounts to the same thing as a mail cover. Congress briefly conducted hearings on mail cover programs in 1976, but has not revisited the issue.
In a forthcoming article in Privacy Law Bulletin I discuss this month's formal Opinion by EU Advocate General Jääskinen regarding case C-131/12 in the European Union Court of Justice (ECJ), i.e. Google Spain and Google Inc. v Agencia Española de Protección de Datos and Mario Costeja González. The dispute concerns interpretation of the European Data Protection Directive 95/46/EC in relation to internet search engines, construed by some as enshrining a 'right to be forgotten'.

The Jääskinen Opinion - which is not binding on the ECJ - follows a preliminary ruling by the Audiencia Nacional (Spain's national high court) regarding proceedings involving Google Inc, Google Spain (its subsidiary),  the Agencia Española de Protección de Datos (AEPD, Spain's national data protection agency) and Mario Costeja González.

Gonzalez - the data subject - had experienced business difficulties and appeared in La Vanguardia (a leading newspaper)  after the government took action to auction his property to cover social security debts. That coverage was factual. Gonzalez sought to have the information removed from the online version of the newspaper. (Unsurprisingly there appears to have been no action to expunge the information in archived print copies or have the newspaper publish a 'supplementary' statement).

Gonzalez separately contacted Google Spain, with the expectation that search results would not display a link to La Vanguardia's coverage (and an abstract of that coverage) whenever someone searched his name. Unsatisfied, he lodged a formal complaint with the AEPD, which called on Google Spain and Google Inc. to 'forget' the information when presenting search results. Google appealed to the Audiencia Nacional,  which referred several questions to the ECJ. Those questions relate to -
  • the territorial scope of and the applicable national law under the Data Protection Directive
  • whether search engine providers are data controllers
  • whether there is a right to be forgotten. 
Jääskinen in advising the ECJ argued that access by people in Spain (and targeting of those consumers by Google Spain) did not trigger the application of Spanish data protection law, which under Article 4 (1) of the Directive is meant to harmonise with law elsewhere in the EU.  The relevant question was instead whether Google carried out data "processing in the context of the activities of an establishment of the controller" in Spain.  Jääskinen argued that Google indeed was a "data controller" under the Act and Directive: it was irrelevant that Google Inc's servers (and the data processing) were located outside Spain, because Google Inc and its subsidiaries should be treated as a single group and because Google Spain acted as the 'bridge' to Spain's advertising market

The Opinion discusses whether a search engine operator should be considered as a "controller" in relation to Article 2(d) of the Directive. Would the copying, caching, indexing and display of content  from La Vanguardia and other sites  (including personal data such as names, contact details, descriptions and images) constitute processing of personal data?

Jääskinen differentiated between the search engine operator merely supplying an automated 'information location tool' - search results from an 'index' that drew on but did not exercise control over third party sites that featured personal data. The operator would accordingly have a protected status similar to that enjoyed by telecommunications providers, having no awareness of the personal data "in any other sense than as a statistical fact". The third party sites, such as a newspaper site, would instead be controllers under the Directive. Jääskinen argued that the "provision of an information tool does not imply any control over the content", consistent with  the Article 29 Working Party Opinion 1/2008 that characterised "a search engine provider" as acting "purely as an intermediary" and indicating that "the principal controllers of personal data are the information providers".

Search engine operators would be controllers in relation to the cache if they chose not to comply with exclusion codes (robot txt/do not follow tag) on a third party page or chose not to update a page in the cache despite a request received from the third party that originated the cached content. In those instances the operators would need to comply with all obligations imposed by the Directive on data controllers, including the Article 6 data quality principles.

Jääskinen considered that provision of internet search engine services meets the legitimate interests criteria outlined in Article 7 of the Directive, with the automated index reflecting notions of adequacy, relevancy, proportionality, accuracy and completeness.

Jääskinen accordingly considered that a national data protection agency such as the AEPD cannot require an search engine operator such as Google to expunge information from its search results, other than instances where the operator has not complied with the exclusion codes or where a request emanating from the website regarding update of cache memory has not been complied with.

Is there a broad right to be forgotten? Jääskinen says no. The Opinion discusses the Directive's provision for erasure or blocking of data and the right to object, arguing that (in the absence of a new unequivocal right under the proposed Data Protection Regulation) there is no general right to be forgotten. Gonzalez as a data subject has no right to require - on a subjective basis - a search engine operator to prevent indexation of information that has been legally published on third party sites.

Jääskinen considered the fundamental right to the protection of personal data under Article 8 of the EU Charter of Fundamental Rights, along with the corresponding provision in the European Convention for the Protection of Human Rights and Fundamental Freedoms. The Opinion argues that the right to protection of personal data and private life is not absolute. Protection must be balanced with other fundamental rights, in particular the freedom of expression, freedom of information and freedom to conduct business. A generalised right to be forgotten would sacrifice these rights, potentially resulting in censorship by private parties on a subjective basis.

The Opinion recommends that the Court decline to accept a "case-by-case" approach to the present case, as it would open up internet search providers to unmanageable numbers of requests.

03 July 2013

Corporate Persona

'Corporate Personhood and Corporate Persona' [PDF] by Margaret Blair in (2013) University of Illinois Law Review 785-820 argues that
In 2010, the U.S. Supreme Court held in Citizens United v. FEC that restrictions on corporate political speech were unconstitutional because of the First Amendment rights granted corporations as a result of their status as “persons” under the law. Following this decision, debate has been rekindled among legal scholars about the meaning of “corporate personhood.” This debate is not new. Over the past two centuries, scholars have considered what corporate personhood means and entails. This debate has resulted in numerous theories about corporate personhood that have come into and out of favor over the years, including the “artificial person” theory, the “contractual” theory, the “real entity” theory, and the “new contractual” theory.
This Article revisits that debate by examining the various functions of corporate personhood including four functions I have identified in previous work: (1) providing continuity and a clear line of succession in property and contract, (2) providing an “identifiable persona” to serve as a central actor in carrying out the business activity, (3) providing a mechanism for separating pools of assets belonging to the corporation from those belonging to the individuals participating in the enterprise, and (4) providing a framework for self-governance of certain business or commercial activity. In this Article, I focus on the historical evolution of the corporate form, and specifically on how and why corporations have tended to develop clearly identifiable corporate personas. This corporate persona function is highly important to today’s corporations and, because of this func-tion, corporations can become more than simply the sum of their parts. This Article suggests that scholars should keep the corporate persona function in mind in evaluating corporate personhood theories, and return to a theory that sees corporations as more than a bundle of contracts.
Blair concludes -
In much of my prior work, I have, in one way or another, explored the idea that successful business corporations are, and should be treated by the law as, more than just bundles of assets that belong to shareholders. While the role of shareholders in corporations is not trivial — without financial capital, few business enterprises could get out of the starting block — it is the efforts and vision of the entrepreneurs, managers, and key employees, as well as business practices that cultivate innovation and collaboration in teams, that create corporations whose value greatly exceeds the value of the financial capital that has been put in them. The real entity theory of corporations provided a vocabulary that embraces and acknowledges these self-evident facts. But numerous legal scholars since the 1980s have rejected the real entity view of corporations in favor of a theory that dismisses the idea that a firm is more than the sum of the contracts it embodies. 
Legal scholars started down this path by adopting the frameworks that had been developed by economic theorists to provide insight into key relationships within firms and by applying these reductionist models to the law of corporations. Beginning in the 1980s, they produced a substantial literature that starts from three simplifying premises that economists had adopted: (1) that shareholders are the “owners” of corporations, which are simply bundles of assets owned collectively by shareholders; (2) that directors and managers are the agents of shareholders and therefore are supposed to apply themselves to maximizing the value of the shares; and (3) that the best way to achieve higher value for shareholders is to give shareholders more power and control rights so that they can compel managers and directors to maximize share value. 
Frank Easterbrook and Daniel Fischel, for example, wrote a series of articles together in which they developed the implications for corporate law of the idea that corporations are essentially a contracting device with no separate existence and embodying no distinct rights and interests apart from the individuals who contracted together through the corporations. They focused especially on what they thought of as the central or most important contract in any corporation, the principal-agent contract between shareholders and directors/managers. 
Other legal scholars followed this lead, and within a few years, the legal literature on corporations as contractual devices and managers as agents of shareholders exploded. In an insightful analysis of this transformation of legal thinking about corporations, William Bratton notes that the real entity theory of the corporation was essentially “managerialist” — it accepted and legitimized the large corporation in which a managerial hierarchy exercised control. The new nexus of contracts theory, by contrast, was antimanagerialist, emphasizing that managerial authority is derived from the agency relationship with shareholders and that managers serve at the behest of shareholders. It is beyond the scope of this Article to explore all of the reasons why corporate law scholarship began to tilt so strongly in an antimanagerialist direction in the 1980s, after having been quiescently managerialist for nearly half a century. But the 1980s was a period in which many leading thinkers in the United States believed that the country was in decline and that the decline probably had to do with the failures of the bureaucratic and sclerotic corporations that dominated so many industries. “[I]n the 1980s national economic decline-revival became one of the foremost domestic issues, a new and uncomfortable prospect for Americans,” wrote historian Otis Graham.  By the latter half of the decade, vigorous public discussion had melded an impressively broad consensus that the erosion of U.S. economic strength was a reality, that it had not been and would not be stemmed by the Reaganite reforms, and that both relative and in some cases absolute decline had continued through even the remarkable years of expansion in 1983–1990. 
Concern about decline manifested itself in a number of ways. The most salient for our purposes was the idea that executives in the corporate sector, on the whole, had become uncreative, unwilling to take risks, self-serving, empire building, and unaccountable. The new antimanagerialist contractual theory of the firm may have been attractive because it offered a framework for thinking about how the law could help to un-seat these executives and bring in new industrial leadership. The new literature on the nexus of contracts theory of the corpora- tion also offered a way to think about the legal and policy issues raised by a phenomenon then sweeping the financial markets — hostile takeo-vers.  According to the theory, corporate managers cannot be expected to always work tirelessly to maximize the value of a corporation’s stock because they are merely hired agents with their own preferences that are not necessarily the same as the preferences of their principals, the shareholders. If managers fail to maximize the value of the shares of their company, however, the stock price of the company will be lower than its potential, and there will be an incentive for an outside investor to buy up a controlling position in the corporation, then proceed to fire manage- ment or otherwise compel the company to cut its costs or redirect its as- sets so that they have a higher value. 
This story line made the investors who were actively bidding for control of numerous corporations in the 1980s into heroes who were adding value, rather than greedy raiders (as corporate executives initially tried to portray them) who were opportunistically stripping value out of the corporations by ending employee pension plans, renegotiating contracts with unions, or closing plants and shipping production overseas — all while paying themselves large bonuses. Not surprisingly, the image of financiers as the heroes rather than the villains was congenial to corporate finance practitioners and scholars, and scholarship exploring and testing these ideas soon dominated the finance literature as well as the corporate law literature. The nexus of contracts/principal-agent model has thus formed the framework for a large part of the theoretical and empirical scholarship of both finance and corporate law over the last three decades. 
This literature includes arguments that corporate boards and man- agers should be required to be passive in the face of hostile offers so that shareholders could take advantage of the opportunity to sell their shares at a higher price. Similar reasoning has been applied to consideration of a long list of takeover defenses, which generated a large body of literature during the 1980s arguing that takeover defenses reduced the value of corporate shares and that they should therefore be disallowed or con- strained. Arguments were also made that managers and directors should be paid in stock options or other equity claims so that their interests would be more closely aligned with the interests of shareholders.  The corporate bar initially defended corporate directors and managers on the question of takeover defenses. But over time, as managers and directors increasingly adopted compensation packages based on stock options, these had the predicted effect of focusing the attention of directors and managers at firms across the economy — so that most directors and managers now say that their primary duty is to maximize the value of the equity shares of the corporations they run. 
The view of corporations as simply contracting devices has also permeated corporate finance, with practitioners and scholars learning to use the corporate form of organization in a whole new way, as a pure asset-partitioning device that does not implicate any of the other three functions of corporate personhood (continuity in property and contract; self-governance; and the development of intangible assets attached to a corporate persona). So called “special purpose vehicles” (SPVs), or sometimes “special purpose entities” (SPEs) or “structured investment vehicles” (SIVs), are corporations that have no employees, no operations, and no products. Their sole purpose is to facilitate “securitization” of financial assets by allowing the sponsoring corporation to isolate a bundle of financial assets, such as mortgages, car loans, other consumer debt, or commercial debt instruments, and issue debt securities that are claims to the cash flow solely from those assets.  By creating a separate corporation to hold the assets and liabilities of the SPE, the sponsoring financial firm that creates the entity attempts to protect itself from default or bankruptcy if the assets behind the securities fail to generate the projected amounts of cash flow. These entities thus resemble pure nexuses of contracts for the purpose of partitioning assets into entities that have none of the elements that we have identified as part of a corporation’s persona. But it turns out that, without a persona component,  the value of these entities nearly collapsed during the financial crisis when the assets that had been isolated in them lost value. In response, many of the financial firms that created these entities stepped up and took responsibility for making good on the debt securities that had been issued by them, although the terms of the contracts that had created them did not require this. Why? Because the sponsoring firms had something to lose, which the individual SPVs did not have, a corporate persona with substantial reputational value at risk. In other words, some of the value that those entities had was due to an asset of the sponsoring firm that was not listed on the balance sheet of either the sponsoring firm or the SPE. That asset could have been badly damaged if the sponsoring firm had, in fact, allowed the SPEs to fail. Theories that try to explain value creating corporations in pure contract terms, without acknowledging the role of reputational and other noncontractual relationship assets that contribute to value and that are tied to the corporate persona, may fail to explain aspects of corporations that matter most. 
The dominant theory of corporations in the last few decades in finance and in law has been a reductionist, finance inspired approach that regards corporations as mere contractual devices, with no truly separate existence, for which it is misleading and even foolish to speak of such things as the goal, reputation, will, or moral duties of the corporation apart from its contracting agents. The effort by financial market players in recent years to create value by simply repackaging the assets and liabilities of corporations without regard to the impact of such maneuvers on reputation and trust in the entity as a whole, let alone on the financial markets as a whole, it seems to me, is one expression of this mentality. 
But while legal and financial scholars seem to have no use for corporations that have any personality, some of the most successful value creating entrepreneurs of the last decade — Larry Page, Sergey Brin, and Eric Schmidt at Google, and Mark Zuckerberg at Facebook, among others — have emphasized the importance of such factors as “culture” and “reputation” and “innovativeness” in the value creating process at their corporations, and have expressed concern that financial markets excessively discount the importance such factors. Perhaps it is time for financial and legal economics to rethink the contractarian theories and models that have been guiding much corporate law scholarship in recent years and reconsider the view that corporations are, or can be, substantially more than the sum of their contractual parts. The idea that corporations can have a separate persona would be a useful part of that inquiry.

01 July 2013

BC Data Breach

Australia's national Data Breach Bill - the Privacy Amendment (Data Alerts) Bill 2013 (Cth) - appears to have got the tick from the Constitutional & Legal Affairs Committee last week but fizzled thereafter amid excitement about 'who gets to play prime minister'. (My submission to the Committee commented that the Bill was overall disappointing but a useful step to a more effective mandatory data breach reporting regime.)

In Canada the British Columbia Privacy Commissioner has meanwhile recommended changes to the BC Ministry of Health’s privacy practices following three data breaches affecting millions of people in that province.

The Commissioner's investigation report assessed the ministry’s response to the breaches and the ministry’s overall data-handling practices in relation to health research. It highlighted "serious deficiencies" in those practices, with the absence of  "operational and technical safeguards" meaning that employees were able to copy a large volume of personal health data onto unencrypted flash drives and share that data with other parties without detection. That absence was contrary to requirements under section 30 of the BC Freedom of Information and Protection of Privacy Act (FIPPA) for "reasonable security" to protect personal information.

The Commissioner has made 11 recommendations to improve the ministry’s privacy practices "to both facilitate access to information for health research and to address the privacy and data security compliance issues".

They are -
R1 The Ministry should develop and implement additions to the BC Government policy on the use of portable storage devices to require the use of other, more secure, forms of information transfer. Portable storage devices should only be used as a last resort and must always be encrypted. 
R2 The Ministry should ensure user privileges are granted and managed based on the need to know and least privilege principles, ensuring that employees have access only to the minimum amount of personal information they require to perform their employment duties. Access permissions should be assigned consistently and kept up to date. 
R3 The Ministry should implement technical security measures to prevent unauthorized transfer of personal information from databases. 
R4 The Ministry executive should implement an effective program for monitoring and auditing compliance by employees with privacy controls, and by contracted researchers and academic researchers with privacy provisions in agreements, to enable proactive detection of unauthorized use and disclosure of Ministry information. 
R5 The Ministry should ensure that all contracts with contracted researchers and research agreements with academic researchers involving the disclosure of personal health information provide for an appropriate level of security, including privacy protection schedules. These requirements should include limiting the use and disclosure of personal information to specified contractual purposes; taking reasonable security measures to protect personal information; requiring compliance with privacy policies and controls with respect to storage, retention and secure disposal; and requiring notice to the Ministry in the event of a privacy related contractual breach. The Ministry also should use information sharing agreements wherever the substance of an agreement is about information sharing, rather than the provision of services to the Ministry. 
R6 The Ministry should develop a comprehensive inventory of all databases containing personal health information. The inventory should be updated regularly and should set out associated information flows relating to collection and disclosure for research purposes. 
R7 The roles and responsibilities for privacy belonging to the OCIO and branches throughout the Ministry should be documented and effective overall leadership for the Ministry’s privacy management program clarified. There is a particular need to enhance the Ministry’s internal privacy resources. 
R8 The Ministry should develop a Ministry privacy policy that establishes the basic principles of privacy for Ministry employees. 
R9 The Ministry should ensure that the Ministry privacy policy specifically incorporates the collection, use and disclosure of health information for research, including addressing when it may be appropriate to release personal information for health research under s. 35 of FIPPA. It should indicate the kind of information that the Ministry can provide to researchers and the security requirements that need to be met. 
R10 The Ministry should continue to streamline its information access request approval and delivery processes to reduce time delays in access to information for health research. 
R11 The Ministry should ensure that employees with access to databases containing personal health information participate in mandatory privacy training sessions and that their participation is documented.
The Commissioner, in noting that "Privacy and research are allies, not adversaries, in the pursuit of better health outcomes", also released Accountable Privacy Management in B.C.’s Public Sector. It is a new guidance document that "provides a blueprint and step-by-step instructions for public bodies to develop comprehensive privacy programs and protect citizens’ personal information".

Bullying

In Swan v Monash Law Book Co-operative (t/as Legibook) [2013] VSC 326 the Supreme Court of Victoria has awarded $592,554 damages to a former retail sales assistant subjected to workplace bullying.

The applicant claimed that she had been subjected to sarcasm, hostility, rudeness, violent behaviour and threat of termination by a manager in the workplace. She alleged that the defendant's negligence caused psychological injury by exposing her to an unsafe workplace in which she was subject to that bullying, harassing, and intimidating conduct. She had for example allegedly needed to duck to avoid being struck on the head by a legal text book thrown at her by a Legibook manager.

The Court found that Legibook failed to properly define the relations between it and its employees and its employees inter se and articulate its expectations concerning conduct in the workplace between employees, by job descriptions, employment contracts and workplace behaviour policies.

Dixon J states that
On the basis of the findings that I have expressed above, I am satisfied that Mr Cowell engaged in an established pattern of workplace bullying as so described. He did so, particularly in the period from August 2002 to April 2003. I am satisfied that his behaviour during that period, as I have found it, would be expected by a reasonable person to humiliate, intimidate, undermine or threaten the plaintiff. The incidents of occupational violence were, from 2003, intermittently reinforced with an expectation that such violence might be repeated, engendered by other conduct that did not involve an immediate apprehension of physical violence throughout the period of the plaintiff’s employment by the defendant until August 2007. 
Although the pattern of Mr Cowell’s behaviour was episodic and, after 2003, not characterised by explicit incidents of occupational violence, his conduct characterised the work environment as one in which the plaintiff was subject to stress and emotional distress, humiliation and belittling conduct, intimidation and aggressive managerial direction. In a restricted and confined workplace environment, such behaviours imposed substantial, and significant, emotional stress and distress on the plaintiff. I find that Mr Cowell’s conduct in the workplace threatened to, and did, damage the mental health and wellbeing of the plaintiff throughout the course of her employment by the defendant. 
The Court went on
I am satisfied that the behaviour of [Legibook] from March 2003 through until August 2007 fell short of the expected standard of an employer in the following respects:
(a) The defendant failed to properly define the relations between it and its employees and its employees inter se and articulate its expectations concerning conduct in the workplace between employees, by job descriptions, employment contracts and workplace behaviour policies.
(b) It was immediately clear to the defendant in March 2003 that a want of written position descriptions, written employment contracts and workplace behaviour policies was contributing to the conflict between their two employees. The defendant’s ongoing failure to put proper job descriptions, employment contracts and workplace behaviour policies in place was never explained. That inexcusable and unjustified conduct breached its duty of care to the plaintiff.
(c) Further, the defendant’s failure to take those steps was exacerbated by its repeated misrepresentations to the plaintiff that employment contracts, written job descriptions and workplace behaviour policies were imminent.
(d) The board failed in 2003 to introduce defined procedures for complaints of inappropriate behaviour in the bookroom, or to appropriately train its employees and its own members to deal appropriately with such behaviour and complaints when it was occurring.
(e) It was inappropriate for the defendant, purporting to act as a reasonable employer, to rely on choices made by its employee as to the employer’s proper response to the employee’s complaint especially when such choices were, at least, induced by those misrepresentations. Seeking assurances from the plaintiff that she was happy with the board’s handling of her complaint in the circumstances constituted an inappropriate response.
(f) In considering the plaintiff’s complaint in March 2003, the board recognised that it had given no direction to Mr Cowell as to his dealings with the plaintiff and that this seemed to have led to Mr Cowell developing some rather arbitrary and brusque work practices in his dealing with her.
(g) The board recognised that Mr Cowell was keen to make a good impression upon it and that appropriate workplace conduct should form part of an employee assessment concerning Mr Cowell. Although conceptually appropriate, the board was negligent in failing to follow through with any employee assessment that included consideration of appropriate workplace conduct.
(h) When determining in 2003 that a formal warning to Mr Cowell was not appropriate, the board failed to give any consideration to informal responses, for example, a direct personal communication with Mr Cowell that was not put in the context of any complaint from the plaintiff, about the nature of workplace conduct, including the way its employees related to each other that the board expected at Legibook.
(i) A reasonable employer ought to have directly investigated what was occurring in the bookroom and intervened appropriately to deal with what had occurred. Dr Wyatt considered that April 2003 was the appropriate occasion for intervention by engaging a workplace mediator or conciliator like Mr Jensen.
(j) The defendant had no formal system enabling employees to seek the assistance of the employer when bullying conduct occurred. This was evidenced in a number of respects. There was no complaints mechanism or system. Although Mr Somers liaised with employees on behalf of the board, the system was ad hoc. Further, there was no evidence that Mr Somers had any relevant training or experience and the board’s response to the complaints in 2003 and 2005 supports the conclusion that he did not. Apart from the failure to conduct any formal investigation of the plaintiff’s complaint, there was, in 2003 and 2005, no informal investigation either. Similarly, the board gave no informal warning and there was no discussion, even at a general level, with Mr Cowell. Consequently, the board never made a simple clear statement to Mr Cowell that it would not tolerate behaviour in the bookroom of a character that could constitute workplace bullying. Mr Cowell never knew of the board’s attitude to conduct as described by the plaintiff, irrespective of any issue about whether such conduct had occurred, or might again occur.
(k) The board did not arrange for, or conduct for itself, any risk assessment, either generally or of the circumstances raised by the complaints in 2003 and 2005. The board failed to assess the risks that it identified in March 2003 could result in Workcover claims by the plaintiff. The board did not properly monitor, on an ongoing basis, the behaviour of its employees inter se. Its expressed intentions to ‘chat regularly’ with its employees resulted at best in occasional conduct mostly initiated by the plaintiff. This failure follows on its failure to implement any policy or process. In the relevant sense, that risk of injury to the plaintiff that the board identified was uncontrolled by it.
(l) A further consequence following on the absence of any policy or process concerning workplace conduct and behaviours was that Legibook’s response to the plaintiff’s complaints was inadequate, and its want of a complaint and grievance process permitted its inadequate response to fail all together, to slip away without appropriate resolution. Although the defendant submitted that the periods of no complaint, or of apparent calm in the workplace between complaints, were significant, I do not agree. To the extent that the submission was put to the existence of a duty, I have rejected it. The periods of apparent functionality in the bookroom did not eradicate or alleviate the risks that had been foreseen. When considering breach, a reasonable employer looking forward to identify what it should have done to avoid injury, having identified a risk, could not simply assume that a continuing absence of complaint, or renewed complaint, meant that the risk had abated. In this regard, the defendant is purporting to rely on aspects of its breach of duty - a want of risk assessment, follow-up procedures, and monitoring - to infer that the foreseen risk had resolved and its failure to take such actions was not in breach of its duty. I reject this contention. The absence of overt continuing behaviour, or complaint about behaviour, is not evidence that the risk of harm to the plaintiff’s mental health identified in March 2003 had abated, or could reasonably be considered by a prudent employer to have abated.
(m) A further aspect of the lack of proper policy and process was that Legibook had no safe return to work procedure. The plaintiff’s return to work process was not competently handled and will be further discussed below.
I am satisfied that the defendant failed to take reasonable care for the safety of the plaintiff, specifically in terms of her mental health, in these particular respects.

29 June 2013

Land Registers, Privacy and the FIRB

The Australian parliamentary Rural & Regional Affairs & Transport References Committee has released its 174 page report on the foreign investment review regime, centred on the Foreign Investment Review Board (FIRB) 'national interest' test and reflecting anxieties about overseas ownership of Australian rural land.

Those anxieties have been evident in calls, for example, for a comprehensive publicly-accessible national land register and populist treatment of agribusiness statistics such as
  • 1.6% ($2.33bn) of foreign direct investment approvals in 2009/10 were in agriculture, forestry and fishing. 
  • half of the 23 licensed wheat exporters in Australia are foreign owned and since 2008 (with deregulation of wheat export arrangements) there has been an increased foreign investment interest in grain bulk handlers and exporters, e.g. Viterra (Canadian) acquiring ABB Grain and Cargill (US) now owning AWB Ltd. 
  • since 2000 (with deregulation of the diary industry) about half of Australian milk production is processed by foreign owned firms (e.g. Fonterra (NZ), Lion (Japan), and Parmalat (France)). 
  • three foreign owned milling groups make up almost 60% of Australia's raw sugar production (the foreign companies involved in sugar refining are Finasure (Belgium), Wilmar (Malaysia, Singapore) and COFCO (China, state owned).
  • around 40% of Australian red meat production is processed by foreign owned firms (based on throughput)
The Foreign Investment and the National Interest report is interest to UC students grappling with questions of access to public and private information, given disagreements about 'who owns what' (and 'how can we tell').

The regime under which foreign interests can invest in Australian businesses and acquire Australian real estate involves the Foreign Acquisitions and Takeovers Act 1975 (Cth) and Foreign Acquisitions and Takeovers Regulations 1989 (Cth), Australia’s Foreign Investment Policy (AFIP) and the Foreign Investment Review Board . The AFIP indicates that 'direct investment' in an enterprise or real estate by a 'foreign government investor' is subject to review by the FIRB. That investor might be a sovereign wealth fund or a state-owned enterprise, with direct investment representing 'investment of an interest of 10 per cent or more', subject to consideration of a stake under 10% where the foreign government investor is "building a strategic stake in the target, or can use that investment to influence or control the target".

Examination by the FIRB centres on whether the proposed investment "will be contrary to the national interest", a notion that is not statutorily defined and instead reflects assessment in relation to
  • national security; 
  • competition; 
  • impact on the economy and community; 
  • Australian government policies such as tax; and 
  • the character of the investor.
The report features 29 recommendations, offering something for almost everyone. The Committee criticised "a lack of transparency" regarding the FIRB national interest test and "information gaps" regarding the type and scale of foreign investment. The report calls for improved access by agricultural businesses to domestic finance, an Independent Commission of Audit into Agribusiness, “an independent and wide-ranging review of Australia's foreign investment regulatory framework” (including strengthening the national interest test) and a national agricultural land register.

In relation to agribusiness investment, the Committee calls for action to ensure that foreign investments in Australian agriculture are
  • genuinely commercial,
  • compete fairly with Australian agribusinesses and
  • do not distort the capital market or trade in agricultural products.
In its fifth recommendation the committee recommends that the Australian Bureau of Statistics not conduct future ABS agricultural surveys on foreign investment, as "the national register for foreign ownership of agricultural land should be the primary mechanism for collecting and publishing information about foreign investment in Australian agriculture".

The report comments that
The most promising development from the government to address the information gaps in foreign investment in agricultural assets was the commitment to, following consultation with stakeholders, establish a national register of foreign ownership of agricultural land. The committee strongly supports its establishment, based on the overwhelming evidence received through submissions and witnesses.
It goes on to state
In November 2012, a discussion paper for public consultation was released by the Treasury [noted in a post here]. The paper sought submissions on the following issues:
  • The scope of the register in terms of information collected and the definition of relevant terms such as agricultural land; 
  • The use of a threshold to exclude small transactions; 
  • The need for an initial stocktake of foreign investment; 
  • The monitoring of divestments as well as investments; 
  • Australia's international obligations; 
  • Compliance issues, including the timeframe for registration; and 
  • Public access to the information.
Submissions under the Treasury consultation process have closed. Treasury received 33 submissions and all but 6 (which remain confidential) are available on the Treasury website. The committee notes that these submitters indicated broad support for a register and that more information about levels of foreign investment would be beneficial. However, some submitters were also concerned about cost, administrative burden, privacy issues and potential disincentives to foreign investment. There were also varying views on the extent to which the information should be collected and made public.
Committee view
The committee strongly supports the development of the register for foreign ownership of agricultural land. The committee also believes that the register should be as streamlined as possible to avoid unnecessary costs and administrative burdens. Where appropriate, it should protect personal privacy and commercial confidentiality.
However, the committee also believes that if established properly, the register will not cause a disincentive to legitimate and commercially orientated foreign investment. Consistent with the issues outlined above regarding the agricultural survey and in later chapters regarding the definition of 'rural land' in the FATA, and the importance of transparent management of water entitlements, the committee recommends that the register incorporate the following recommendations.
Finally, the committee is mindful of the significant lack of information regarding foreign investment in agriculture (discussed in this chapter). The committee also considers that in addition to improving the knowledge of current circumstances, modelling of future circumstances is needed to inform the public debate. To this end, the committee considers that it is essential that the public is provided with modelling that shows the possible costs to the agricultural industry should current arrangements (including current regulation and barriers to domestic investment) regarding foreign investment in Australian agriculture remain unchanged. 
In response the Committee makes several recommendations -
R6  The committee recommends that when establishing the agricultural land register, the government conduct an initial stocktake of foreign ownership of agricultural land, agribusiness and water entitlements. In addition to numbers of businesses, land size and volume of water entitlements, the value of foreign investment acquisitions should be captured. The initial stocktake should be comprehensive, as far as possible consistent across states, and take into account complex company structures including foreign trusts, "shell companies", ownership of agricultural assets by foreign mining companies, and debt structuring and ultimate liability.
Furthermore, on the basis of this initial stocktake, the government should commission independent modelling of the level of foreign investment in Australian agriculture in 20 years' time if current trends and regulatory arrangements are assumed to remain. The modelling should also include estimated costs to the industry over the same period based on current constraints to domestic capital investment in Australian agriculture. Finally, the modelling should have regard to the future opportunities provided by the growing global food task over this period.
R7  The committee recommends that the ongoing information collected in the register include the information that the committee recommended be included as part of the stocktake of foreign ownership (as per recommendation 6).
R8 The committee recommends that the register include divestments as well as investments. This will ensure that the information from the register remains current and can reflect changes over time.
R9 The committee recommends that participation in the register be a legal requirement for foreign investors and that appropriate mechanisms for compliance apply in cases where such participation is avoided.
R10 The committee recommends that the register not use the current definition of 'rural land' in the FATA. Instead the definition adopted should be that which results from the update of 'rural land' as per recommendation 25. This would maintain consistency with the regulatory framework for foreign investment in Australian agriculture.
R11 The committee recommends that there be no minimum threshold for reporting and that all foreign investment should be captured in the agricultural land register. However, this data should be collected in a manner that can clearly delineate foreign investments in terms of value and business size. 3
Although the committee is mindful of privacy and the need for business transactions to be protected by certain levels of commercial confidentiality, it also considers that the information collected be as accessible to public and parliamentary scrutiny as possible. In general, the committee considers that the public debate on this issue will benefit greatly with the availability of significantly more information about the levels and nature of foreign investment in agriculture.
R12 The committee recommends that the register's data be held in a manner that is centralised and can provide comprehensive information about all foreign ownership that is recorded.
R13 The committee recommends that levels and trends of foreign ownership of land, agribusiness and water entitlements should be published annually by the national register for foreign ownership of agricultural land. Aggregate level data about the respective value and level of interest of foreign government investors and private foreign companies should be included. The data should also be made available in categories such as state, sub-industry (ANZSIC levels), water catchment areas, and local shires.
R14 The committee recommends that country of origin of all foreign government investors and specific foreign government investments should be published annually by the national register for foreign ownership of agricultural land.
R15  The committee recommends that, in order to prevent possible disincentives for foreign investment, the country of origin details for private foreign companies should be published by the national register for foreign ownership of agricultural land at aggregate levels only. However, country of origin details for specific private foreign investments should be made available to parliamentarians, parliamentary committees, and any relevant government agency upon request.

28 June 2013

FTC Reclaim Your Name initiative

From the 'Reclaim Your Name' speech [PDF] by US Federal Trade Commissioner Julie Brill at the 23rd Computers Freedom and Privacy conference -
Many consumers have been loath to examine too closely the price we pay, in terms of forfeiting control of our personal data, for all the convenience, communication, and fun of a free-ranging and mostly free cyberspace. We are vaguely aware that cookies attach to us wherever we go, tracking our every click and view. We tell Trip Advisor our travel plans, open our calendars to Google Now, and post our birthdays on Facebook. We broadcast pictures of our newborns on Instagram; ask questions about intimate medical conditions on WebMD; and inform diet sites what we ate that day and how long we spent at the gym. Google Maps, Twitter and Four Square know where we are. Uber, Capital BikeShare, and Metro’s trip planner know where we’re going and how we plan to get there.
We spew data every minute we walk the street, park our cars, or enter a building – the ubiquitous CCTV and security cameras blinking prettily in the background – every time we go online, use a mobile device, or hand a credit card to a merchant who is online or on mobile. We spend most of our days, and a good deal of our nights, surfing the web, tapping at apps, or powering on our smart phones, constantly adding to the already bursting veins from which data miners are pulling pure gold. That’s where the “big” in “big data” comes from.
We send our digital information out into cyberspace and get back access to the magic of our wired lives. We sense this, but it took Snowden to make concrete what exactly the exchange means – that firms or governments or individuals, without our knowledge or consent, and often in surprising ways, may amass private information about us to use in a manner we don’t expect or understand and to which we have not explicitly agreed.
It is disconcerting to face how much of our privacy we have already forfeited. But with that knowledge comes power – the power to review, this time with eyes wide open, what privacy means – or should mean – in the age of the Internet. I believe that’s what President Obama meant last week when he called for a “national conversation…about the general problem of these big data sets because this is not going to be restricted to government entities.”
I’d like to pose two questions that are key to getting this conversation going, and then spend some time today trying to answer them. First, what are the major challenges to privacy posed by big data, particularly in its use in the commercial arena? And second, what steps can we take to meet these challenges? ....
We are awash in data. Estimates are that 1.8 trillion gigabytes of data were created in the year 2011 alone – that’s the equivalent of every U.S. citizen writing 3 tweets per minute for almost 27,000 years. Ninety percent of the world’s data, from the beginning of time until now, has been generated over the past two years, and it is estimated that that total will double every two years from now on. As the costs of storing data plummet and massive computing power becomes widely available, crunching large data sets is no longer the sole purview of gigantic companies or research labs. As Schonberger-Mayer and Cukier write, big data has become democratized.
First Challenge: the Fair Credit Reporting Act
This astounding spread of big data gives birth to its first big challenge: how to educate the growing and highly decentralized community of big data purveyors about the rules already in place governing the ways certain kinds of data can be used. For instance, under the Fair Credit Reporting Act, or “FCRA,” entities collecting information across multiple sources and providing it to those making employment, credit, insurance and housing decisions must do so in a manner that ensures the information is as accurate as possible and used for appropriate purposes.
The Federal Trade Commission has warned marketers of mobile background and criminal screening apps that their products and services may come under the FCRA, requiring them to give consumers notice, access, and correction rights. We’ve also entered into consent decrees that allow us to monitor the activities of other apps and online services that have similarly wandered into FCRA territory. But while we are working hard to educate online service providers and app developers about the rules surrounding collecting and using information for employment, credit, housing, and insurance decisions, it is difficult to reach all of those who may be – perhaps unwittingly – engaged in activities that fall into this category.
Further, there are those who are collecting and using information in ways that fall right on —or just beyond —the boundaries of FCRA and other laws. Take for example the new-fangled lending institutions that forgo traditional credit reports in favor of their own big-data-driven analyses culled from social networks and other online sources. Or eBureau, which prepares rankings of potential customers that look like credit scores on steroids. The New York Times describes this company as analyzing disparate data points, from “occupation, salary and home value to spending on luxury goods or pet food, … with algorithms that their creators say accurately predict spending.” These “e-scores” are marketed to businesses, which use them to decide to whom they will offer their goods and services and on what terms. It can be argued that e-scores don’t yet fall under FCRA because they are used for marketing and not for determinations on ultimate eligibility. But what happens if lenders and other financial service providers do away with their phone banks and storefronts and market their loans and other financial products largely or entirely online? Then, the only offers consumers will see may be those tailored based on their e-scores. ...
Second Challenge: Transparency
The second big challenge to big data is transparency. Consumers don’t know much about either the more traditional credit reporting agencies and data brokers or the newer entrants into the big data space. In fact, most consumers have no idea who is engaged in big data predictive analysis.
To their credit, some data brokers allow consumers to access some of the information in their dossiers, approve their use for marketing purposes, and correct the information for eligibility determinations. In the past, however, even well-educated consumers have had difficulty obtaining meaningful information about what the data brokers know about them. Just yesterday, “the big daddy of all data brokers”, Acxiom, announced that it plans to open its dossiers so that consumers can see the information the company holds about them. This is a welcome step. But since most consumers have no way of knowing who these data brokers are, let alone finding the tools the companies provide, the reality is that current access and correction rights provide only the illusion of transparency.
Third Challenge: Notice and Choice
A third challenge involves those aspects of big data to which the FCRA is irrelevant – circumstances in which data is collected and used for determinations unrelated to credit, employment, housing, and insurance, or other eligibility decisions. We need to consider these cases within the frameworks of the Federal Trade Commission Act, the OECD’s Fair Information Privacy Principles, and the FTC’s 2012 Privacy Report, for it is within those contexts we can see how big data is testing established privacy principles such as notice and choice. ....
Fourth Challenge: Deidentification
The final big challenge of big data that I would like to discuss is one that I’ve been assured by many of its proponents I shouldn’t strain too hard to solve – that of predictive analytics attaching its findings to individuals. Most data brokers and advertisers will tell you they are working with de-identified information, that is, data stripped of a name and address. And that would be great if we didn’t live in a world where more people know us by our user names than our given ones. Our online tracks are tied to a specific smartphone or laptop through UDIDs, IP addresses, “fingerprinting” and other means. Given how closely our smartphones and laptops are associated with each of us, information linked to specific devices is, for all intents and purposes, linked to individuals.
Furthermore, every day we hear how easy it is to reattach identity to data that has been supposedly scrubbed. In an analysis just published in Scientific Reports, researchers found that they could recognize a specific individual with 95 percent accuracy by looking at only four points of so-called “mobility data” tracked by recording the pings cell phones send to towers when we make calls or send texts. NSF-funded research by Alessandro Acquisti has shown that, using publicly available online data and off-the-shelf facial recognition technology, it is possible to predict – with an alarming level of accuracy – identifying information as private as an individual’s social security number from an anonymous snapshot.
In response Brill says
So let’s turn to some ways to solve the challenges big data poses to meaningful notice and choice as well as transparency. A part of the solution will be for companies to build more privacy protections into their products and services, what we at the FTC call “privacy by design”. We have recommended that companies engage in cradle-to-grave review of consumer data as it flows through their servers, perform risk assessments, and minimize and deidentify data wherever possible. Mayer-Schonberger and Cukier have helpfully called for the creation of “algorithmists” – licensed professionals with ethical responsibilities for an organization’s appropriate handling of consumer data. But the algorithmist will only thrive in an environment that thoroughly embraces “privacy by design,” from the C-suite to the engineers to the programmers.
And unfortunately, even if the private sector embraces privacy by design and we license a cadre of algorithmists, we will not have met the fundamental challenge of big data in the marketplace: that is, consumers’ loss of control of their most private and sensitive information.
Changing the law would help. I support legislation that would require data brokers to provide notice, access, and correction rights to consumers scaled to the sensitivity and use of the data at issue. For example, Congress should require data brokers to give consumers the ability to access their information and correct it when it is used for eligibility determinations, and the ability to opt-out of information used for marketing.
But we can begin to address consumers’ loss of control over their most private and sensitive information even before legislation is enacted. I would suggest we need a comprehensive initiative – one I am calling “Reclaim Your Name.” Reclaim Your Name would give consumers the knowledge and the technological tools to reassert some control over their personal data – to be the ones to decide how much to share, with whom, and for what purpose – to reclaim their names.
Reclaim Your Name would empower the consumer to find out how brokers are collecting and using data; give her access to information that data brokers have amassed about her; allow her to opt-out if she learns a data broker is selling her information for marketing purposes; and provide her the opportunity to correct errors in information used for substantive decisions – like credit, insurance, employment, and other benefits.
Over a year ago, I called on the data broker industry to develop a user-friendly, one-stop online shop to achieve these goals. Over the past several months, I have discussed the proposal with a few leaders in the data broker business, and they have expressed some interest in pursuing ideas to achieve greater transparency. I sincerely hope the entire industry will come to the table to help consumers reclaim their names.
In addition, data brokers that participate in Reclaim Your Name would agree to tailor their data handling and notice and choice tools to the sensitivity of the information at issue. As the data they handle or create becomes more sensitive – relating to health conditions, sexual orientation, and financial condition – the data brokers would provide greater transparency and more robust notice and choice to consumers. The credit reporting industry has to do its part, too. There are simply too many errors in traditional credit reports. The credit bureaus need to develop better tools to help consumers more easily obtain and understand their credit reports so they can correct them. I have asked major credit reporting agencies to improve and streamline consumers’ ability to correct information across multiple credit reporting agencies.

Myths

One of the more pernicious myths about sexual affinity is that "all" (or most) LGBT people are 'rich and hip' ... and thereby somehow undeserving of the rights and responsibilities enjoyed by their peers. It is thus refreshing to see 'New Patterns of Poverty in the Lesbian, Gay, and Bisexual Community' [PDF] by M.V. Lee Badgett, Laura E. Durso and Alyssa Schneebaum.

They comment that
As poverty rates for nearly all populations increased during the recession, lesbian, gay, and bisexual (LGB) Americans remained more likely to be poor than heterosexual people. Gender, race, education and geography all influence poverty rates among LGB populations, and children of same-sex couples are particularly vulnerable to poverty.
Yes, not all LGB people are rich, hip and echt californian.

The study draws on data from four datasets to estimate recent poverty rates for US LGB people in all walks of life: same-sex couples (2010 American Community Survey), LGB people aged 18-44 (2006-2010 National Survey of Family Growth), LGB adults in California (2007-2009 California Health Interview Survey) and single LGBT-identified adults (2012 Gallup Daily Tracking Poll).

Key findings include:
  • 7.6% of lesbian couples, compared to 5.7% of married different-sex couples, are in poverty. 
  • African American same-sex couples have poverty rates more than twice the rate of different-sex married African Americans. 
  • One third of lesbian couples and 20.1 % of gay male couples without a high school diploma are in poverty, compared to 18.8% of different-sex married couples. 
  • Lesbian couples who live in rural areas are much more likely to be poor (14.1%), compared to 4.5% of coupled lesbians in large cities. 
  • 10.2% of men in same-sex couples, who live in small metropolitan areas, are poor, compared with only 3.3% of coupled gay men in large metropolitan areas.
  • Almost one in four children living with a male same-sex couple and 19.2% of children living with a female same-sex couple are in poverty, compared to 12.1% of children living with married different-sex couples. African American children in gay male households have the highest poverty rate (52.3%) of any children in any household type. 
  • 14.1% of lesbian couples and 7.7% of gay male couples receive food stamps, compared to 6.5% of different-sex married couples.  
  • 2.2% of women in same-sex couples receive government cash assistance, compared to .8% of women in different sex couples; 1.2% of men in same-sex couples, compared to 0.6% of men in different-sex couples, receive cash assistance.