Home » Posts tagged 'privacy' (Page 16)

Tag Archives: privacy

Our mission

Free Government Information (FGI) is a place for initiating dialogue and building consensus among the various players (libraries, government agencies, non-profit organizations, researchers, journalists, etc.) who have a stake in the preservation of and perpetual free access to government information. FGI promotes free government information through collaboration, education, advocacy and research.

Census Bureau Accidently Places Data Online

From the news release:

The Census Bureau today reported that a file containing limited respondent information on 302 households, commingled with fictitious test records, was improperly posted on one of the agency’s externally accessible servers in violation of strict agency policies regarding the protection of respondent information. The file was immediately removed. No Social Security numbers were contained in the files and the Census Bureau has no evidence that any respondent data were misused. “As soon as we learned of the improper posting, we moved quickly to fix the problem. We immediately shut down the site and began an investigation,” said Census Director Charles Louis Kincannon.
Continue reading

Continue Reading →

TIA becomes ADVISE

Congress killed the Total Information Awareness (TIA) program in 2003 and several new programs have been reported to take its place. (See Total Information Awareness just changed its name FGI, 2006-02-26.) A forthcoming GAO report looks at the use of the Analysis, Dissemination, Visualization, Insight and Semantic Enhancement (ADVISE) system.

The Department of Homeland Security is testing a data-mining program that would attempt to spot terrorists by combing vast amounts of information about average Americans, such as flight and hotel reservations. Similar to a Pentagon program killed by Congress in 2003 over concerns about civil liberties, the new program could take effect as soon as next year. But researchers testing the system are likely to already have violated privacy laws by reviewing real information...
Continue reading

Continue Reading →

Why we care about privacy

Every now and then, someone asks one of us at FGI why we still care about privacy. The often unspoken assumption is that we don't have privacy anymore and we should just accept the fact and live with it. But we still believe that it is an important right for citizens to be able to examine information collected, compiled, and created by our government without worrying that the government is monitoring who is reading what and what our interests are. Here is a good item that goes into the current state of government spying on citizens and why it is bad. I recommend it. As he says, "If a Government is permitted to collect and maintain vast dossiers on its citizens, that information is going to be abused" and "our democracy can only function if citizens know what its Government is doing."

As we've noted repeatedly here, GPO's privacy policies will be moot and irrelevant if we accept government surveillance. One way to circumvent such spying on citizens is to insist that GPO and government agencies deposit copies of government information with FDLP libraries, ensuring that citizens have access to government information from libraries that respect privacy and honor the "right to read" which depends or our right to privacy. Continue reading

Continue Reading →

Privacy and the “Terrorist Surveillance Act”

President Bush says that he wants the lame duck Congress to pass the Terrorist Surveillance Act (President Bush Meets with Cabinet Rose Garden, November 9, 2006).

What does this have to do with government information? If we continue with the current trend of government information being available only on the web from government-controlled web servers, we enhance and simplify the ability of the government to monitor and examine the government information we read. The "Terrorist Surveillance Act" will make this worse because it will effectively change the minimalist privacy policies the government has (see Will GPO guarantee user privacy? Can it?) into surveillance policies.

The "Terrorist Surveillance Act" is misnamed. It doesn't authorize the government to spy on terrorists, it authorizes the government to spy on everyone hoping that it can find terrorists.

Why is that bad? Surely, it shouldn't be bad "if I have nothing to hide" right? As Guy Kewney explains, mining data for patterns yields matches for people who are not terrorists. It enables the government to find innocent people and worse it enables the government to find...

...[n]ot terrorists, just enemies. Hostile journalists, campaigning lobbyists, critical journalists, businessmen who are likely to sponsor rival parties, people who oppose the party leader's favourite idea of the year.
Kewney's comment uses examples from the UK, but it is relevant to citizens of any government that is trying to use data mining of legitimate information seeking behavior to try to identify terrorists. Such surveillance has more of a chilling effect on regular citizens than it does on actual terrorists.

The "Terrorist Surveillance Act" is a misleading name for a bad idea. I believe it is just the sort of misguided, bad policy that voters rejected in our recent election.

Now we can do two things: We can tell our representatives that we don't want this legislation now, or in January, or ever. And, we can insist that GPO and government agencies deposit copies of government information with FDLP libraries, ensuring that citizens have access to government information from libraries that respect privacy and honor the "right to read" which depends or our right to privacy.

Continue reading

Continue Reading →

PRIVACY: Key Challenges Facing Federal Agencies

With the federal government's growing interest in acquiring ever larger amounts of personal information on Americans, I thought FGI readers might be interested in this May 2006 report issued by the nonpartisan Government Accountability Office of the US Congress: PRIVACY: Key Challenges Facing Federal Agencies Report GAO-06-777T, May 17, 2006 Full Report at http://www.gao.gov/new.items/d06777t.pdf As a public federal document, the full summary can be posted here:

What GAO found: Agencies and their privacy officers face growing demands in addressing privacy challenges. For example, as GAO reported in 2003, agency compliance with Privacy Act requirements was uneven, owing to ambiguities in guidance, lack of awareness, and lack of priority. While agencies generally did well with certain aspects of the Privacy Act's requirements - such as issuing notices concerning certain systems containing collections of personal information - they did less well at others, such as ensuring that information is complete, accurate, relevant, and timely before it is disclosed to a nonfederal organization. In addition, the E-Gov Act requires that agencies perform privacy impact assessments (PIA) on such information collections. Such assessments are important to ensure, among other things, that information is handled in a way that conforms to privacy requirements. However, in work on commercial data resellers, GAO determined in 2006 that many agencies did not perform PIAs on systems that used reseller information, believing that these were not required. In addition, in public notices on these systems, agencies did not always reveal that information resellers were among the sources to be used. To address such challenges, chief privacy officers can work with officials from OMB and other agencies to identify ambiguities and provide clarifications about the applicability of privacy provisions, such as in situations involving the use of reseller information. In addition, as senior officials, they can increase agency awareness and raise the priority of privacy issues. Agencies and privacy officers will also face the challenge of ensuring that privacy protections are not compromised by advances in technology. For example, federal agency use of data mining - the analysis of large amounts of data to uncover hidden patterns and relationships - was initially aimed at detecting financial fraud and abuse. Increasingly, however, the use of this tool has expanded to include purposes such as detecting terrorist threats. GAO found in 2005 that agencies employing data mining took many steps needed to protect privacy (such as issuing public notices), but none followed all key procedures (such as including in these notices the intended uses of personal information). Another new technology development presenting privacy challenges is radio frequency identification (RFID), which uses wireless communication to transmit data and thus electronically identify, track, and store information on tags attached to or embedded in objects. GAO reported in 2005 that federal agencies use or propose to use the technology for physical access controls and tracking assets, documents, or materials. For example, the Department of Defense was using RFID to track shipments. Although such applications are not likely to generate privacy concerns, others could, such as the use of RFIDs by the federal government to track the movement of individuals traveling within the United States. Agency privacy offices can serve as a key mechanism for ensuring that privacy is fully addressed in agency approaches to new technologies such as data mining and RFID.
There are some more specific remarks on RFID technology starting on page 17 of the PDF file. I found GAO's remarks on privacy concerns and "mission creep" to be especially interesting:
A number of specific privacy issues can arise from RFID use. For example, individuals may not be aware that the technology is being used and that it could be embedded in items they are carrying and thus used to track them. Three agencies indicated to us that employing the technology would allow for the tracking of employees' movements. Tracking is real-time or near-real-time surveillance in which a person’s movements are followed through RFID scanning. Media reports have described concerns about ways in which anonymity is likely to be undermined by surveillance. Further, public surveys have identified a distinct unease with the potential ability of the federal government to monitor individuals' movements and transactions. Like tracking, profiling - the reconstruction of a person's movements or transactions over a specific period of time, usually to ascertain something about the individual's habits, tastes, or predilections - could also be undertaken through the use of RFID technology. Because tags can contain unique identifiers, once a tagged item is associated with a particular individual, personally identifiable information can be obtained and then aggregated to develop a profile of the individual. Both tracking and profiling can compromise an individual's privacy and anonymity. Concerns also have been raised that organizations could develop secondary uses for the information gleaned through RFID technology; this has been referred to as "mission-" or "function-creep." The history of the Social Security number, for example, gives ample evidence of how an identifier developed for one specific use has become a mainstay of identification for many other purposes, governmental and nongovernmental. Secondary uses of the Social Security number have been a matter not of technical controls but rather of changing policy and administrative priorities. As agencies take advantage of the benefits of RFID technology and implement it more widely, it will be critical for privacy officers to help ensure that a full consideration is made of potential privacy issues, both short-term and long-term, as the technology is implemented.
I think in light of the "the innocent have nothing to hide" mentality of the last few administration, full consideration of privacy issues will not be made by the federal government. On the other hand, libraries have a rich history of protecting patron privacy. Continue reading

Continue Reading →

Latest Posts

Latest Comments

Blogroll

Archives

Meta

Archives

Powered by WordPress / Academica WordPress Theme by WPZOOM