Perimeter
6/25/2009
01:57 PM
Sara Peters
Sara Peters
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

EU Group: Social Networks, Thirty-Party App Developers Subject To EU Privacy Laws

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.The report (PDF) "principally is intended to provide guidance to SNS [social network service] providers on the measures that need to be in place to ensure compliance with EU law." Social network providers, both inside and outside of the EU, ought to pay heed to this report -- but they're not the only ones. The app developers who use the social networks' APIs to build apps for those platforms should also give it a close read. So should users, whether you use the service for personal reasons or use it for professional reasons -- particularly if your organization is using social networks for marketing purposes.

The Working Party is an independent European advisory board on data protection and privacy. Some of the Party's recommendations are not out of the blue: making users very aware of how their data is being used; more secure default settings; deleting all a user's account data immediately after they cancel their account, etc.

Others, however, are less expected.

For example, the Party recommends that SNS should allow users to adopt a pseudonym. Although rarely enforced, one of Facebook's terms of service is that user's must use their real name. (I'll give Facebook this: Last year I found users named "Fake Name," "Faketh Nameth," and "Betsy Faken Namer," to name a few. I did not, however, find any such people in my Facebook people search today.)

The Party's rationale for the "allow pseudonyms" recommendation is "Article 6 para 1 letter c) of the [EU] Data Protection Directive requires the data to be 'adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed.' In this context, it can be observed that SNS may need to register some identifying data about members but does not need to publish the real name of members on the Internet."

The strong privacy rules also apply to those miscreants whose dirty deeds get them banned from these SNS. The recommendations say "Some SNS also retain identification data of users who were banned from the service, to ensure that they cannot register again. In that case, these users must be informed that such processing is taking place. In addition, the only information that may be retained is identification information, and not the reasons why these persons were banned. This information should not be retained for more than one year." It is not clear to me whether by "this information" they mean only the "reasons why these persons were banned" or the identification information as well. I've contacted the Working Party to get some clarification.

The Party also says that third-party application developers may in some cases be considered "data controllers" which means they may also be subject to these privacy mandates. For example, the app developers are advised not to perform any operations on imported user contacts' data other than personal usage.

Further, they advise the social network services and marketers that any "behavioral marketing"--which selects which ads to serve up to users based on observation and analysis of those users' activity over time--is rather naughty as well.

Note well, these are recommendations, not official mandates. They're not made to get in trouble; rather they're made to keep you out of trouble.

Now ain't that neighborly? Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3352
Published: 2014-08-30
Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) 2008.3_SP9 and earlier does not properly consider whether a session is a problematic NULL session, which allows remote attackers to obtain sensitive information via crafted packets, related to an "iFrame vulnerability," aka Bug ID CSCuh...

CVE-2014-3908
Published: 2014-08-30
The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2010-5110
Published: 2014-08-29
DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVE-2012-1503
Published: 2014-08-29
Cross-site scripting (XSS) vulnerability in Six Apart (formerly Six Apart KK) Movable Type (MT) Pro 5.13 allows remote attackers to inject arbitrary web script or HTML via the comment section.

CVE-2013-5467
Published: 2014-08-29
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM)...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.