Perimeter
6/25/2009
01:57 PM
Sara Peters
Sara Peters
Commentary
Connect Directly
Twitter
RSS
E-Mail
50%
50%

EU Group: Social Networks, Thirty-Party App Developers Subject To EU Privacy Laws

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.

I just took a close look at the Article 29 Data Protection Working Party's opinion report on online social networking. While some of its recommendations are what you'd expect, others came as a surprise.The report (PDF) "principally is intended to provide guidance to SNS [social network service] providers on the measures that need to be in place to ensure compliance with EU law." Social network providers, both inside and outside of the EU, ought to pay heed to this report -- but they're not the only ones. The app developers who use the social networks' APIs to build apps for those platforms should also give it a close read. So should users, whether you use the service for personal reasons or use it for professional reasons -- particularly if your organization is using social networks for marketing purposes.

The Working Party is an independent European advisory board on data protection and privacy. Some of the Party's recommendations are not out of the blue: making users very aware of how their data is being used; more secure default settings; deleting all a user's account data immediately after they cancel their account, etc.

Others, however, are less expected.

For example, the Party recommends that SNS should allow users to adopt a pseudonym. Although rarely enforced, one of Facebook's terms of service is that user's must use their real name. (I'll give Facebook this: Last year I found users named "Fake Name," "Faketh Nameth," and "Betsy Faken Namer," to name a few. I did not, however, find any such people in my Facebook people search today.)

The Party's rationale for the "allow pseudonyms" recommendation is "Article 6 para 1 letter c) of the [EU] Data Protection Directive requires the data to be 'adequate, relevant and not excessive in relation to the purposes for which they are collected and/or further processed.' In this context, it can be observed that SNS may need to register some identifying data about members but does not need to publish the real name of members on the Internet."

The strong privacy rules also apply to those miscreants whose dirty deeds get them banned from these SNS. The recommendations say "Some SNS also retain identification data of users who were banned from the service, to ensure that they cannot register again. In that case, these users must be informed that such processing is taking place. In addition, the only information that may be retained is identification information, and not the reasons why these persons were banned. This information should not be retained for more than one year." It is not clear to me whether by "this information" they mean only the "reasons why these persons were banned" or the identification information as well. I've contacted the Working Party to get some clarification.

The Party also says that third-party application developers may in some cases be considered "data controllers" which means they may also be subject to these privacy mandates. For example, the app developers are advised not to perform any operations on imported user contacts' data other than personal usage.

Further, they advise the social network services and marketers that any "behavioral marketing"--which selects which ads to serve up to users based on observation and analysis of those users' activity over time--is rather naughty as well.

Note well, these are recommendations, not official mandates. They're not made to get in trouble; rather they're made to keep you out of trouble.

Now ain't that neighborly? Sara Peters is contributing editor to Dark Reading and editor-in-chief of Enterprise Efficiency. Prior that she was senior editor for the Computer Security Institute, writing and speaking about virtualization, identity management, cybersecurity law, and a myriad of other ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-6651
Published: 2014-07-31
Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

CVE-2014-2970
Published: 2014-07-31
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of CVE-2014-5139, and has also been used to refer to an unrelated topic that is currently outside the scope of CVE. This unrelated topic is a LibreSSL code change adding functionality ...

CVE-2014-3488
Published: 2014-07-31
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

CVE-2014-3554
Published: 2014-07-31
Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

CVE-2014-5171
Published: 2014-07-31
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

Best of the Web
Dark Reading Radio