<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Francis Davey</title>
	<atom:link href="http://francisdavey.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://francisdavey.wordpress.com</link>
	<description>Law, computers and the internet</description>
	<lastBuildDate>Thu, 25 Jun 2009 21:52:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='francisdavey.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/f479dd59d534a6fc5c04f8ade709c880?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Francis Davey</title>
		<link>http://francisdavey.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://francisdavey.wordpress.com/osd.xml" title="Francis Davey" />
	<atom:link rel='hub' href='http://francisdavey.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Pirate Bay loses appeal</title>
		<link>http://francisdavey.wordpress.com/2009/06/25/pirate-bay-loses-appeal/</link>
		<comments>http://francisdavey.wordpress.com/2009/06/25/pirate-bay-loses-appeal/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 16:43:42 +0000</pubDate>
		<dc:creator>fjmd1</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://francisdavey.wordpress.com/?p=11</guid>
		<description><![CDATA[According to the Swedish Court Service website, the four defendants in the Pirate Bay case have lost their appeal. The Svea Court of Appeal decided that, despite some criticism of the way in which the judges in the trial had proceeded, the trial was fair. I have yet to read a reasoned decision so I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=francisdavey.wordpress.com&amp;blog=8323030&amp;post=11&amp;subd=francisdavey&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://209.85.227.132/translate_c?hl=en&amp;sl=sv&amp;tl=en&amp;u=http://www.domstol.se/templates/DV_Press____11044.aspx&amp;prev=hp&amp;rurl=translate.google.com&amp;usg=ALkJrhjj-1gWcgyDr9vOrdSTpcfIXg6RAg">According</a> to the Swedish Court Service website, the four defendants in the Pirate Bay case have lost their appeal. The Svea Court of Appeal decided that, despite some criticism of the way in which the judges in the trial had proceeded, the trial was fair.</p>
<p>I have yet to read a reasoned decision so I am relying on the press release. One line of reasoning seems to have gone as follows: the presiding judge was a member of two organisations operating in the field of intellectual property. Let us say, for the sake of argumen, that the judge&#8217;s membership of these organisations showed that he was in favour of the enforcement of intellectual property and would thus be supportive of rights holders. That does not, thought the court, prevent a fair trial because intellectual property rights are legal rights in Sweden as the law stands. Being in favour of them merely means being in favour of the law.</p>
<p>An analogous argument might be used in a case in which a judge who was in favour of private property rights and their enforcement should still be allowed to sit on a case of theft, or for eviction of trespassers.</p>
<p>Having said that the court appears to have thought that information like this (membership of relevant associations)  ought to have been available at the earliest stage, so that it can be properly dealt with then rather than on appeal.</p>
<p>I remain sceptical as to whether the judge (Tomas Norström) really was biased in any way. The Swedish Association for the Protection of Industrial Property and the Swedish Copyright Association do not look (to me) like industry organisations that pursue infringers of intellectual property, but rather more like the sorts of organisations that lawyers routinely get involved in for the better exchange of ideas and study of a subject.</p>
<p>Members are likely to have a lot of different affiliations, work against each other in practice on many occasions and the mere fact that A and B are both members of such an assocaition doesn&#8217;t mean they will even like each other. I certainly can&#8217;t stand the sight of some people in the same professional bodies as myself.</p>
<p>The trouble is I haven&#8217;t seen a good analysis of the two Swedish bodies to be sure. I look forward to reading the full decision of the Court of Appeal (if it becomes available) to make up my own mind.</p>
<p>Where does this leave the Pirate Bay four? If the press release is to be believed, there is no appeal but proceedings in the European Court of Human Rights are sure to follow.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/francisdavey.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/francisdavey.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/francisdavey.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/francisdavey.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/francisdavey.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/francisdavey.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/francisdavey.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/francisdavey.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=francisdavey.wordpress.com&amp;blog=8323030&amp;post=11&amp;subd=francisdavey&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://francisdavey.wordpress.com/2009/06/25/pirate-bay-loses-appeal/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e361831338d5d1b5df96974fe7a172f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">fjmd1</media:title>
		</media:content>
	</item>
		<item>
		<title>Social networking sites and data protection</title>
		<link>http://francisdavey.wordpress.com/2009/06/25/social-networking-sites-and-data-protection/</link>
		<comments>http://francisdavey.wordpress.com/2009/06/25/social-networking-sites-and-data-protection/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 14:16:10 +0000</pubDate>
		<dc:creator>fjmd1</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[article 29 working party]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://francisdavey.wordpress.com/2009/06/25/social-networking-sites-and-data-protection/</guid>
		<description><![CDATA[The Article 29 Data Protection Working Group has published its opinion on the relationship between the Data Protection Directive and Social Networking Sites (SNS). A key point to take away is that operators of SNS are data controllers rather than merely data processors, so that they are more likely to be subject to European data [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=francisdavey.wordpress.com&amp;blog=8323030&amp;post=3&amp;subd=francisdavey&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://ec.europa.eu/justice_home/fsj/privacy/workinggroup/index_en.htm">Article 29 Data Protection Working Group</a> has published <a href="http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2009/wp163_en.pdf">its opinion</a> on the relationship between the <a href="http://eur-lex.europa.eu/smartapi/cgi/sga_doc?smartapi!celexapi!prod!CELEXnumdoc&amp;lg=EN&amp;numdoc=31995L0046&amp;model=guichett">Data Protection Directive</a> and Social Networking Sites (SNS).</p>
<p>A key point to take away is that operators of SNS are data controllers rather than merely data processors, so that they are more likely to be subject to European data protection law than if they were merely &#8220;data processors&#8221;.</p>
<h3>Who is the working party?</h3>
<p>The working party was set up by by the data protection directive as an advisory body. Its opinions are not legally binding, but they are likely to be persuasive and the Commission must respond them.</p>
<h3>Key points</h3>
<p>The response to the opinion (so far) has concentrated on the view that SNS operators are probably data controllers. I&#8217;ll have more to say about that at the end of this post.</p>
<p>For me the most interesting points are:</p>
<ul>
<li>SNS operators are usually data controllers</li>
<li>&#8230; and so are many third party application providers</li>
<li> &#8230; as indeed will be many users</li>
<li>privacy should be the default setting</li>
<li>release of profile information beyond a user&#8217;s selected friends should never be implicit</li>
<li>third party applications should not by default be given access to all an individual&#8217;s profile information, but only what is necessary for that application to work</li>
</ul>
<p>It seems to me that this signals a tougher line to SNS like facebook which will not be able to get away with, for example, a <a href="http://www.lightbluetouchpaper.org/2009/06/09/how-privacy-fails-the-facebook-applications-debacle/">completely cavalier attitude to third party applications</a>.</p>
<p>There are a couple of specific points of interest.</p>
<h3>Users</h3>
<p>Almost anything about someone is &#8220;personal data&#8221; but most individuals using an SNS won&#8217;t be subject to the Directive because it excludes processing &#8220;by a natural person in the course of a purely personal or household activity&#8221;.</p>
<p>The working group notes an increased use of SNS for other purposes such as for businesses or campaigning. Those would fall outside the household exception and such users would need to comply with the Act.</p>
<p>The Working Group makes three recommendations on this point:</p>
<blockquote><p>- SNS providers provide adequate warnings to users about the privacy risks to themselves and to others when they upload information on the SNS<br />
- SNS users should also be reminded that uploading information about other individuals may impinge upon their privacy and data protection rights;<br />
- SNS users should be advised by SNS that if they wish to upload pictures or information about other individuals, this should be done with the individual’s consent.</p></blockquote>
<p>Which seems entirely positive. Strictly speaking you don&#8217;t always need an individual&#8217;s permission to process their data, so the last point is not quite right, though it is good practice. What the Directive does require is that individual&#8217;s are notified of the processing, which could be done by a tagging system.</p>
<p>Having said that, the Directive was not (I think) written with uses of SNS in mind. I suspect that more difficulties will follow.</p>
<h3>Controller vs Processor</h3>
<p>The Directive makes a distinction between &#8220;controllers&#8221; on the one hand &#8220;processors&#8221; on the other. A controller is an entity which &#8220;alone or jointly with others determines the purposes and means of the processing of personal data.&#8221;</p>
<p>In the context of an SNS you might argue that it is the users of the site who decide the purpose and means of processing the data, the operator of the site provides nothing more than an environment for the users to do what they wish (post pictures, disclose information about themselves and so on). In other words, they are just a processor.</p>
<p>The Working Party thinks not. Amongst other things sites like facebook decide what use is to be made of data contributed to the site for the purposes of advertising and marketing.</p>
<p>This matters for two reasons: first because it is on the controller (not the processor) that most of the obligations of the directive are imposed; but second because the location of the controller affects whether or not the directive applies at all.</p>
<h3>How far does the Directive reach?</h3>
<p>The answer to that question applies in article 4 of the directive which states:</p>
<blockquote><p>(a) the processing is carried out in the context of the activities of an establishment of the controller on the territory of the Member State; when the same controller is established on the territory of several Member States, he must take the necessary measures to ensure that each of these establishments complies with the obligations laid down by the national law applicable;<br />
(b) the controller is not established on the Member State&#8217;s territory, but in a place where its national law applies by virtue of international public law;<br />
(c) the controller is not established on Community territory and, for purposes of processing personal data makes use of equipment, automated or otherwise, situated on the territory of the said Member State, unless such equipment is used only for purposes of transit through the territory of the Community.</p></blockquote>
<p>The first two provisions give little difficult: if your processing is being carried out in/with or by an establishment of yours in a member state (or somewhere else that state&#8217;s law applies) then unsurprisingly you have to comply with the Directive.</p>
<p>The odd one is (c). The Working Group have previously in their <a href="http://ec.europa.eu/justice_home/fsj/privacy/docs/wpdocs/2008/wp148_en.pdf">opinion on search engines</a> said that storing a cookie in a user&#8217;s browser amounts to &#8220;making use of&#8221; equipment (the user&#8217;s browser) so that wherever on the plant a data controller might be, if their processing of the data involves cookies they will be subject to the directive.</p>
<p>I am not entirely convinced by that argument. It would require any such site to have a designated representative in every member state from which anyone were to browse them (under article 4(2)). It also seems to me that what the directive means is that if you process the data in question in a member state then the directive applies to the processing of that data in that member state. A cookie will necessarily contain much personal data of itself.</p>
<h3>Conclusion</h3>
<p>The opinion seems to me to be useful. It is relatively short and an easy read. Let us hope that it contributes to the pressure on sites like facebook to put their house in order.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/francisdavey.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/francisdavey.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/francisdavey.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/francisdavey.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/francisdavey.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/francisdavey.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/francisdavey.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/francisdavey.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=francisdavey.wordpress.com&amp;blog=8323030&amp;post=3&amp;subd=francisdavey&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://francisdavey.wordpress.com/2009/06/25/social-networking-sites-and-data-protection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7e361831338d5d1b5df96974fe7a172f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">fjmd1</media:title>
		</media:content>
	</item>
	</channel>
</rss>
