SUBSCRIBE

Canada takes leading role in Facebook privacy issues


Discussions between Facebook Inc. and the Office of the Privacy Commissioner of Canada (OPC) over the social networking siteโ€™s compliance with Canadian federal privacy law are moving along smoothly, according to spokespersons from both sides.

The OPC released the findings of an extensive investigation into Facebookโ€™s privacy policy and practices last month, which began as a response to a complaint filed by the Ottawa-based Canadian Internet Policy and Public Internet Clinic (CIPPIC) in May 2008.

Privacy Commissioner Jennifer Stoddart found Facebook in violation of the Personal Information Protection and Electronic Documents Act (PIPEDA). Canada is now recognized as the first country in the world to issue legally binding recommendations to the social networking site.

Facebookโ€™s 30-day period to review the OPCโ€™s recommendations and submit a formal response outlining its plans for action ended on Aug. 17. Stoddart has 15 days to review the response and determine whether to refer the matter to Canadaโ€™s federal court.

โ€œWe received from [Facebook] their undertakings and we are in the midst of reviewing those undertakings to determine whether or not they are sufficient,โ€ said Anne-Marie Hayden, spokesperson for the OPC.

Hayden indicated the discussions are going well. โ€œWe continue to have positive discussions with Facebook,โ€ she said.

The OPC will make the outcomes of its discussions with Facebook public, but needs time to review and assess the undertakings first, she explained. โ€œWe need to do a thorough review and look at it carefully and once weโ€™ve done so, we will determine the next steps,โ€ said Hayden.

Talks began when the original complaint was filed and have carried on for 14 months now, said Facebook spokesperson Alexandra Brown. โ€œThey will continue for the next 15 days,โ€ she said.

Further details on the discussions have not been provided, but an issued statement from Facebook to the press suggests minimal conflict lies ahead:

โ€œFrom our many discussions with the OPC, it is clear that we share the same goals of ensuring people have control over their information and that they are able to make informed choices about privacy. Many of the recommendations in their Report provide an excellent opportunity to clarify and enhance our privacy practices in a way that is consistent with our companyโ€™s values and our usersโ€™ expectations.โ€

Tamir Israel, a staff lawyer at CIPPIC, doubts the matter will escalate to the federal court level. โ€œGenerally speaking, recommendations are fairly authoritative interpretations of the law. Itโ€™s very rare that these things get challenged,โ€ he said.

CIPPIC supports the OPCโ€™s decisions. โ€œWe are happy with it and we are hoping that Facebook does comply. We are pretty confident that the solutions they come up with will be reasonable and address the concerns of the Privacy Commissioner,โ€ said Israel.

David Young, lawyer and co-chair of Lang Michener LLPโ€™s privacy group in Toronto, expects both parties are interested in finding a โ€œproductive, constructiveโ€ result. โ€œThey seem to be in active negotiations and everythingโ€™s pointing to the fact that they probably will resolve them this week or next,โ€ he said.

Tim Hickernell, lead analyst at Info-Tech Research Group Ltd., imagines Facebook would find a way to settle the issue, given the large number of Facebook users in Canada and the amount of associated advertising dollars.

While Canadians represent only 12 million of Facebookโ€™s 250 million users around the world, with a national population of 33 million, we continue to rank among the top in terms of per capita use.

Hickernell suspects Facebook has a number of adjustments already in the works. โ€œIt wouldnโ€™t surprise me if half the things they put in their response were citing things that they were already working on and planning to release,โ€ he said.

But this is no run-of-the-mill privacy issue, Hickernell pointed out, and other larger countries may follow suit. โ€œI think the most successful will be the European Union, for the simple reason that they have a large, well-organized, within-the-EU-level privacy organization,โ€ he said.

โ€œThereโ€™s a fine line here as to how much privacy officials are going to be able to push back globally. The larger countries with the larger advertising bases are obviously going to be the countries Facebook is more likely to deal with,โ€ said Hickernell.

First-generation privacy regulations written before social networks became popular are trying to play catch-up, but they are โ€œa bit behind the times in not really understanding that the entire value in social networking is the ability to intentionally see the demographics of a network at any given time,โ€ he said.

โ€œBeing able to not just know about the person, but to know something about the personโ€™s friends through their network โ€“ thatโ€™s where all the value is being derived from and why the advertising value as well as those who are building applications is different than they would get if they were doing say just a traditional Yahoo or MSN portal,โ€ he said.

This is why it is necessary for applications to access peopleโ€™s basic information, according to Hickernell. โ€œTo cut all that off at some point really diminishes the value of the social network,โ€ he said.

โ€œI would caution government not to try to treat these emerging technologies as they would traditional online portals circa 1996. They need to update the privacy laws as well as the technology,โ€ said Hickernell.

Establishing a privacy policy that satisfies privacy laws in multiple countries is โ€œquite doable,โ€ according to Young. โ€œThere are cases where Iโ€™ve certainly advised on privacy policies that are international and sometimes there is something very specific to one country, but typically, the policies tend to cover applications in all countries,โ€ he said.

As the Canadian federal governmentโ€™s privacy regulations have the potential to effect an internal organization operating in a number of countries, Stoddart is in a unique position of power.

โ€œYou could argue to some extent that the Privacy Commissioner is having an impact on Facebook disproportionate to Canadaโ€™s place in the Facebook community, even though it is supposedly quite large,โ€ said Young.

โ€œThe reason (is) that Facebook doesnโ€™t want to be seen in its general international community as not according to standards that are set by a government regulatory in Canada, where there is a national privacy law,โ€ he said.

The U.S., by contrast, doesnโ€™t have a single federal privacy regulator, he said. โ€œI think the Commissioner is having extra leverage in achieving a good result here,โ€ said Young.

This isnโ€™t the first time Canada has had an influence on Facebook privacy issues. The Office of the Privacy Commissioner of Ontario played a key role when the social networking site was just starting to circulate among the college student crowd.

Anne Cavoukianโ€™s relationship with Facebook began five years ago when Chris Kelly and Mozelle Thompson called upon her for consultation in regards to Facebookโ€™s privacy settings. โ€œI was intrigued by the concept,โ€ she said.

Cavoukian gathered a focus group of 20 students from universities across Canada to determine whether Facebook was an area of interest and growing concern. During the meeting, Cavoukian found several students had used other social networking sites and didnโ€™t like them. All the students had used Facebook, she said.

โ€œI was floored โ€ฆ they all loved Facebook,โ€ said Cavoukian.

At the end of the discussion, Cavoukian asked the students if they were using the privacy settings available on Facebook at the time. โ€œZero, not one hand goes up,โ€ she said. She also asked how many knew about the privacy settings. โ€œZero, not one hand goes up.โ€

Cavoukianโ€™s suggestion to Kelly was to educate the public, especially kids, on what they should be concerned about and why they should care about their privacy online.

The Ontario Privacy Commissionerโ€™s work with Facebook included reviewing the existing privacy settings, trying to strengthen them in certain areas and putting out publications. Two brochures, a DVD and tip sheet with a step-by-step guide on how to protect your privacy on Facebook were developed.

โ€œThe most important thing about working with Facebook has been their openness to be willing to educate their users about the privacy settings, and then of course it has to be the userโ€™s decision to exercise control and set their privacy settings at what they think should be the right setting,โ€ said Cavoukian.

โ€œYouโ€™ve got privacy controls on Facebook, use them. I think thatโ€™s the most important message. Education is so important in this area and thatโ€™s where we play a role,โ€ she said.

Social networking developed at a very rapid pace and wasnโ€™t really on the horizon five years ago, Israel pointed out. โ€œBecause it is such a new medium, there are a lot of issues to be worked out, especially in the privacy realm,โ€ he said.

Education is a component, said Israel. โ€œUsers just donโ€™t have the right perception of whatโ€™s happening when they put information on Facebook,โ€ he said.

The basis of CIPPICโ€™s complaint was to apply existing legislation norms to this new medium with the ultimate goal of โ€œmaking sure Canadians have more control and knowledge of how their information is being used on the site,โ€ said Israel.

Facebook is the first social networking site CIPPIC has filed a complaint against, partly because of its large exposure in Canada and partly because privacy is something Facebook seems to care about, said Israel.

โ€œWe thought they would be more responsible to these types of things and would actually make good efforts to address any concerns that were raised, but the ultimate goal was to start creating a set of standards that Facebook as well as other social networking sites could apply to the way that they run their applications,โ€ he said.

The OPCโ€™s 113-page report is one of the longest decisions by any privacy data body in the world, according to Israel. โ€œI think the decision does set the framework, for a while at least,โ€ he said.

Twelve issues were raised in CIPPICโ€™s original complaint. The OPC dismissed four as โ€œnot well founded,โ€ considered another four resolved โ€œafter Facebook agreed to make specific changes to its policies or practicesโ€ and issued recommendations to address the remaining four โ€œwell foundedโ€ aspects.

Facebookโ€™s current practice of keeping a database of e-mail addresses on individuals who donโ€™t have a Facebook account and requiring non-users to sign up for an account in order to untag their name from a photo are in question.

Confusion over how to delete a Facebook account and how long Facebook retains user information are other areas of concern.

Facebookโ€™s two-tier process includes the option of either deactivating or deleting an account, but doesnโ€™t provide clear instructions on how to perform the second action. Facebook also retains user information on its servers for an indefinite period of time after an account is cancelled and reserves the right to keep a userโ€™s profile active after their death.

But the main issue concerns third-party applications, according to Israel. These applications not only have access to a wide range of information from your Facebook account, but they also get access to all of your friendsโ€™ information, he said.

While users have the ability to choose whether or not they wish to add an application, they canโ€™t control what applications their friends are adding, he pointed out. โ€œThe problem is, no one knows what these application developers are getting,โ€ he said.

There are currently more than 950,000 Facebook developers in roughly 180 countries around the world.

The recommendations are more about giving more knowledge and control to users than taking anything way, according to Israel. โ€œItโ€™s the users that are concerned about privacy that are benefiting. The ones that arenโ€™t, arenโ€™t really losing anything,โ€ he said.

Hickernell considers many aspects in the original complaint as โ€œnot Facebookโ€™s problem.โ€

โ€œThey are what I would call dumb users โ€“ users that, despite the risks and despite having things thrown right in their face telling them whatโ€™s going to happen if they click โ€˜Accept,โ€™ still do it โ€ฆ Most of the concerns Iโ€™ve read from the original report is the Commissioner trying to protect citizens from themselves,โ€ he said.

Hickernell does suggest Facebook expose privacy options in real time when the opportunity arises. โ€œEvery time you do something or make a change or extend your network, if there is a privacy setting that can apply at that point, I think it would make sense for them to start exposing those settings at that time, in addition to having the master privacy settings console,โ€ he said.

Chris Kelly, chief privacy officer at Facebook, announced upcoming changes to Facebookโ€™s privacy features in early July. A new Publisher Privacy Control tool will allow users to control who sees what on a per-post basis, with options that range from limiting the post to a single friend up to an โ€œeveryoneโ€ option that reveals the post to audiences on the Web.

Other changes include removing regional networks and simplifying privacy settings by consolidating them all on a single page, standardizing options for each setting โ€œso the choices are always the sameโ€ and removing overlapping settings.

Tech Jobs

Categories