Discussions between Facebook Inc. and the Office of the Privacy Commissioner of Canada (OPC) over the social networking siteโs compliance with Canadian federal privacy law are moving along smoothly, according to spokespersons from both sides.
The OPC released the findings of an extensive investigation into Facebookโs privacy policy and practices last month, which began as a response to a complaint filed by the Ottawa-based Canadian Internet Policy and Public Internet Clinic (CIPPIC) in May 2008.
Privacy Commissioner Jennifer Stoddart found Facebook in violation of the Personal Information Protection and Electronic Documents Act (PIPEDA). Canada is now recognized as the first country in the world to issue legally binding recommendations to the social networking site.
Facebookโs 30-day period to review the OPCโs recommendations and submit a formal response outlining its plans for action ended on Aug. 17. Stoddart has 15 days to review the response and determine whether to refer the matter to Canadaโs federal court.
โWe received from [Facebook] their undertakings and we are in the midst of reviewing those undertakings to determine whether or not they are sufficient,โ said Anne-Marie Hayden, spokesperson for the OPC.
Hayden indicated the discussions are going well. โWe continue to have positive discussions with Facebook,โ she said.
The OPC will make the outcomes of its discussions with Facebook public, but needs time to review and assess the undertakings first, she explained. โWe need to do a thorough review and look at it carefully and once weโve done so, we will determine the next steps,โ said Hayden.
Talks began when the original complaint was filed and have carried on for 14 months now, said Facebook spokesperson Alexandra Brown. โThey will continue for the next 15 days,โ she said.
Further details on the discussions have not been provided, but an issued statement from Facebook to the press suggests minimal conflict lies ahead:
โFrom our many discussions with the OPC, it is clear that we share the same goals of ensuring people have control over their information and that they are able to make informed choices about privacy. Many of the recommendations in their Report provide an excellent opportunity to clarify and enhance our privacy practices in a way that is consistent with our companyโs values and our usersโ expectations.โ
Tamir Israel, a staff lawyer at CIPPIC, doubts the matter will escalate to the federal court level. โGenerally speaking, recommendations are fairly authoritative interpretations of the law. Itโs very rare that these things get challenged,โ he said.
CIPPIC supports the OPCโs decisions. โWe are happy with it and we are hoping that Facebook does comply. We are pretty confident that the solutions they come up with will be reasonable and address the concerns of the Privacy Commissioner,โ said Israel.
David Young, lawyer and co-chair of Lang Michener LLPโs privacy group in Toronto, expects both parties are interested in finding a โproductive, constructiveโ result. โThey seem to be in active negotiations and everythingโs pointing to the fact that they probably will resolve them this week or next,โ he said.
Tim Hickernell, lead analyst at Info-Tech Research Group Ltd., imagines Facebook would find a way to settle the issue, given the large number of Facebook users in Canada and the amount of associated advertising dollars.
While Canadians represent only 12 million of Facebookโs 250 million users around the world, with a national population of 33 million, we continue to rank among the top in terms of per capita use.
Hickernell suspects Facebook has a number of adjustments already in the works. โIt wouldnโt surprise me if half the things they put in their response were citing things that they were already working on and planning to release,โ he said.
But this is no run-of-the-mill privacy issue, Hickernell pointed out, and other larger countries may follow suit. โI think the most successful will be the European Union, for the simple reason that they have a large, well-organized, within-the-EU-level privacy organization,โ he said.
โThereโs a fine line here as to how much privacy officials are going to be able to push back globally. The larger countries with the larger advertising bases are obviously going to be the countries Facebook is more likely to deal with,โ said Hickernell.
First-generation privacy regulations written before social networks became popular are trying to play catch-up, but they are โa bit behind the times in not really understanding that the entire value in social networking is the ability to intentionally see the demographics of a network at any given time,โ he said.
โBeing able to not just know about the person, but to know something about the personโs friends through their network โ thatโs where all the value is being derived from and why the advertising value as well as those who are building applications is different than they would get if they were doing say just a traditional Yahoo or MSN portal,โ he said.
This is why it is necessary for applications to access peopleโs basic information, according to Hickernell. โTo cut all that off at some point really diminishes the value of the social network,โ he said.
โI would caution government not to try to treat these emerging technologies as they would traditional online portals circa 1996. They need to update the privacy laws as well as the technology,โ said Hickernell.
Establishing a privacy policy that satisfies privacy laws in multiple countries is โquite doable,โ according to Young. โThere are cases where Iโve certainly advised on privacy policies that are international and sometimes there is something very specific to one country, but typically, the policies tend to cover applications in all countries,โ he said.
As the Canadian federal governmentโs privacy regulations have the potential to effect an internal organization operating in a number of countries, Stoddart is in a unique position of power.
โYou could argue to some extent that the Privacy Commissioner is having an impact on Facebook disproportionate to Canadaโs place in the Facebook community, even though it is supposedly quite large,โ said Young.
โThe reason (is) that Facebook doesnโt want to be seen in its general international community as not according to standards that are set by a government regulatory in Canada, where there is a national privacy law,โ he said.
The U.S., by contrast, doesnโt have a single federal privacy regulator, he said. โI think the Commissioner is having extra leverage in achieving a good result here,โ said Young.
This isnโt the first time Canada has had an influence on Facebook privacy issues. The Office of the Privacy Commissioner of Ontario played a key role when the social networking site was just starting to circulate among the college student crowd.
Anne Cavoukianโs relationship with Facebook began five years ago when Chris Kelly and Mozelle Thompson called upon her for consultation in regards to Facebookโs privacy settings. โI was intrigued by the concept,โ she said.
Cavoukian gathered a focus group of 20 students from universities across Canada to determine whether Facebook was an area of interest and growing concern. During the meeting, Cavoukian found several students had used other social networking sites and didnโt like them. All the students had used Facebook, she said.
โI was floored โฆ they all loved Facebook,โ said Cavoukian.
At the end of the discussion, Cavoukian asked the students if they were using the privacy settings available on Facebook at the time. โZero, not one hand goes up,โ she said. She also asked how many knew about the privacy settings. โZero, not one hand goes up.โ
Cavoukianโs suggestion to Kelly was to educate the public, especially kids, on what they should be concerned about and why they should care about their privacy online.
The Ontario Privacy Commissionerโs work with Facebook included reviewing the existing privacy settings, trying to strengthen them in certain areas and putting out publications. Two brochures, a DVD and tip sheet with a step-by-step guide on how to protect your privacy on Facebook were developed.
โThe most important thing about working with Facebook has been their openness to be willing to educate their users about the privacy settings, and then of course it has to be the userโs decision to exercise control and set their privacy settings at what they think should be the right setting,โ said Cavoukian.
โYouโve got privacy controls on Facebook, use them. I think thatโs the most important message. Education is so important in this area and thatโs where we play a role,โ she said.
Social networking developed at a very rapid pace and wasnโt really on the horizon five years ago, Israel pointed out. โBecause it is such a new medium, there are a lot of issues to be worked out, especially in the privacy realm,โ he said.
Education is a component, said Israel. โUsers just donโt have the right perception of whatโs happening when they put information on Facebook,โ he said.
The basis of CIPPICโs complaint was to apply existing legislation norms to this new medium with the ultimate goal of โmaking sure Canadians have more control and knowledge of how their information is being used on the site,โ said Israel.
Facebook is the first social networking site CIPPIC has filed a complaint against, partly because of its large exposure in Canada and partly because privacy is something Facebook seems to care about, said Israel.
โWe thought they would be more responsible to these types of things and would actually make good efforts to address any concerns that were raised, but the ultimate goal was to start creating a set of standards that Facebook as well as other social networking sites could apply to the way that they run their applications,โ he said.
The OPCโs 113-page report is one of the longest decisions by any privacy data body in the world, according to Israel. โI think the decision does set the framework, for a while at least,โ he said.
Twelve issues were raised in CIPPICโs original complaint. The OPC dismissed four as โnot well founded,โ considered another four resolved โafter Facebook agreed to make specific changes to its policies or practicesโ and issued recommendations to address the remaining four โwell foundedโ aspects.
Facebookโs current practice of keeping a database of e-mail addresses on individuals who donโt have a Facebook account and requiring non-users to sign up for an account in order to untag their name from a photo are in question.
Confusion over how to delete a Facebook account and how long Facebook retains user information are other areas of concern.
Facebookโs two-tier process includes the option of either deactivating or deleting an account, but doesnโt provide clear instructions on how to perform the second action. Facebook also retains user information on its servers for an indefinite period of time after an account is cancelled and reserves the right to keep a userโs profile active after their death.
But the main issue concerns third-party applications, according to Israel. These applications not only have access to a wide range of information from your Facebook account, but they also get access to all of your friendsโ information, he said.
While users have the ability to choose whether or not they wish to add an application, they canโt control what applications their friends are adding, he pointed out. โThe problem is, no one knows what these application developers are getting,โ he said.
There are currently more than 950,000 Facebook developers in roughly 180 countries around the world.
The recommendations are more about giving more knowledge and control to users than taking anything way, according to Israel. โItโs the users that are concerned about privacy that are benefiting. The ones that arenโt, arenโt really losing anything,โ he said.
Hickernell considers many aspects in the original complaint as โnot Facebookโs problem.โ
โThey are what I would call dumb users โ users that, despite the risks and despite having things thrown right in their face telling them whatโs going to happen if they click โAccept,โ still do it โฆ Most of the concerns Iโve read from the original report is the Commissioner trying to protect citizens from themselves,โ he said.
Hickernell does suggest Facebook expose privacy options in real time when the opportunity arises. โEvery time you do something or make a change or extend your network, if there is a privacy setting that can apply at that point, I think it would make sense for them to start exposing those settings at that time, in addition to having the master privacy settings console,โ he said.
Chris Kelly, chief privacy officer at Facebook, announced upcoming changes to Facebookโs privacy features in early July. A new Publisher Privacy Control tool will allow users to control who sees what on a per-post basis, with options that range from limiting the post to a single friend up to an โeveryoneโ option that reveals the post to audiences on the Web.
Other changes include removing regional networks and simplifying privacy settings by consolidating them all on a single page, standardizing options for each setting โso the choices are always the sameโ and removing overlapping settings.