Perimeter
6/25/2009
01:57 PM
Sara Peters
Sara Peters
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

EU Group: Social Networks, Thirty-Party App Developers Subject To EU Privacy Laws

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.The report (PDF) "principally is intended to provide guidance to SNS [social network service] providers on the measures that need to be in place to ensure compliance with EU law." Social network providers, both inside and outside of the EU, ought to pay heed to this report -- but they're not the only ones. The app developers who use the social networks' APIs to build apps for those platforms should also give it a close read. So should users, whether you use the service for personal reasons or use it for professional reasons -- particularly if your organization is using social networks for marketing purposes.

The Working Party is an independent European advisory board on data protection and privacy. Some of the Party's recommendations are not out of the blue: making users very aware of how their data is being used; more secure default settings; deleting all a user's account data immediately after they cancel their account, etc.

Others, however, are less expected.

For example, the Party recommends that SNS should allow users to adopt a pseudonym. Although rarely enforced, one of Facebook's terms of service is that user's must use their real name. (I'll give Facebook this: Last year I found users named "Fake Name," "Faketh Nameth," and "Betsy Faken Namer," to name a few. I did not, however, find any such people in my Facebook people search today.)

The Party's rationale for the "allow pseudonyms" recommendation is "Article 6 para 1 letter c) of the [EU] Data Protection Directive requires the data to be 'adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed.' In this context, it can be observed that SNS may need to register some identifying data about members but does not need to publish the real name of members on the Internet."

The strong privacy rules also apply to those miscreants whose dirty deeds get them banned from these SNS. The recommendations say "Some SNS also retain identification data of users who were banned from the service, to ensure that they cannot register again. In that case, these users must be informed that such processing is taking place. In addition, the only information that may be retained is identification information, and not the reasons why these persons were banned. This information should not be retained for more than one year." It is not clear to me whether by "this information" they mean only the "reasons why these persons were banned" or the identification information as well. I've contacted the Working Party to get some clarification.

The Party also says that third-party application developers may in some cases be considered "data controllers" which means they may also be subject to these privacy mandates. For example, the app developers are advised not to perform any operations on imported user contacts' data other than personal usage.

Further, they advise the social network services and marketers that any "behavioral marketing"--which selects which ads to serve up to users based on observation and analysis of those users' activity over time--is rather naughty as well.

Note well, these are recommendations, not official mandates. They're not made to get in trouble; rather they're made to keep you out of trouble.

Now ain't that neighborly? Sara Peters is Senior Editor at Dark Reading and formerly the editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9710
Published: 2015-05-27
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time windo...

CVE-2014-9715
Published: 2015-05-27
include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that trig...

CVE-2015-1157
Published: 2015-05-27
CoreText in Apple iOS 8.x through 8.3 allows remote attackers to cause a denial of service (reboot and messaging disruption) via crafted Unicode text that is not properly handled during display truncation in the Notifications feature, as demonstrated by Arabic characters in (1) an SMS message or (2)...

CVE-2015-2666
Published: 2015-05-27
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to t...

CVE-2015-2830
Published: 2015-05-27
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrate...

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?