Home » Posts tagged 'privacy' (Page 17)
Tag Archives: privacy
Nevada Library Assn presentation: Privacy
FGI volunteers Daniel Cornwall, James R. Jacobs and Shinjoung Yeo were invited to give a panel at the Nevada Library Association's 2005 annual conference in Reno, NV, on October 21, 2005. Below is the text of James' part of the presentation about privacy and government information in the digital age. We'd love to hear your comments, corrections, suggestions or ideas.
NLA presentation, Friday October 21, 2005, 10:30 - 12:00 Government Documents Interest Group (GODIG) Who's Government Information? Our Government Information! Presenters: Cornwall, Yeo, Jacobs --Introduction: Welcome and thanks for coming. My name is James R. Jacobs. I'm a government information librarian at University of California San Diego. These are my colleagues Daniel Cornwall, from the AK State Library, and Shinjoung Yeo, also at UC San Diego. The three of us -- along with Jim Jacobs (yes there are actually 2 of us, both in the same department at UC San Diego!! and James Staub from the Tennessee State Library -- started the advocacy organization Free Government Information almost a year ago as a way to reach a broader audience and create dialogue among the various players (libraries, government agencies, non-profit organizations, researchers, journalists, citizens etc.) who have a stake in the preservation of and perpetual free access to government information. Today, we'd like to give some background of the debate as we see it currently working its way through the docs community, the libraries in the Federal Depository Library Program, the members of the Depository Library Council, and the Government Printing Office (GPO). We'll discuss the move, since about 1985, toward digital-only government information and how this move to digital is affecting and will continue to affect, how libraries do their jobs. If you've visited the website at http://freegovinfo.info, you know that we are concerned that the move to digital, although exciting and full of possibilities for increased library services, contains some major obstacles to overcome in order to provide free, fully-functional digital information while protecting users' privacy. We have discussed in various forums the need to continue the FDLP tradition of document deposit and will hopefully make a strong case here for digital deposit of government information as the primary means of preserving government information, giving widespread access to that information and protecting users' privacy in what they read and access online. --Background and history of government information: I'd like to start with some background and history of government information. First off, what exactly IS government information? I found this poignant quote from Anne Morris Boyd in 1949 that sums up what I mean when I talk about government information.
"Government publications, commonly called public documents, are among the oldest records, and if measured by their influence on civilization, are probably the most important of all written records. They are the sources of political, economic, and social history of peoples of all times; they contain the authentic accounts of the world's great explorations, discoveries, and inventions in every field of human endeavor; they reveal and explain the phenomenal scientific and technological developments of modern times; they open up great treasuries wherein man has attempted to give expression to his artistic impulses. They contain the history of civilization itself in all its aspects."Perhaps a bit hyperbolic but you get her drift! Government information is the information collected, compiled and created by governments in their official capacity, funded by our tax dollars, and used by us for our common understanding and our common good. Government information belongs to citizens who have a right to know their government's activities in order to participate fully in the democratic process. Since 1860, there has been a system in place to insure public access to government information through a partnership between the Government Printing Office (GPO) and the hundreds of libraries in the Federal Depository Library Program (FDLP). Similar systems have been set up in nearly every state for state-produced information. The California State Library has been collecting documents from CA state legislative, executive, and judicial branches, commissions, etc. since 1850, before even the FDLP was around. CA has always been on the cutting edge! You may have seen Daniel's previous presentation which shows that now Alaska is on the cutting edge in terms of digital govt information!! He'll talk more about that later. In essence, the FDLP has provided for centralized processing for a deliberate, distributed collection able to have been well-preserved over time. For almost 150 years, this system has been largely successful in providing for one of the core tenets of a democracy, an informed citizenry, not to mention being a veritable goldmine for researchers across the academic disciplines. So now I've set the stage for Shinjoung who will talk about the current conditions we find ourselves in and ACCESS issues regarding the move to digital government information. I will then be back to talk about PRIVACY and then Daniel will wrap up with a discussion about PRESERVATION. PRIVACY: --Philosophy of privacy: Libraries have traditionally protected patron privacy as one of the core tenets of librarianship. Patron privacy is an integral part of the practice of intellectual freedom inherent in the First Amendment of the Bill of Rights to the US Constitution. Like the Hippocratic oath, ALA's Code of Ethics includes principles that guide our work as librarians. Among them are:
--We uphold the principles of intellectual freedom and resist all efforts to censor library resources. --We protect each library user's right to privacy and confidentiality with respect to information sought or received and resources consulted, borrowed, acquired or transmitted. ALA Code of EthicsThis professional code, along with individual libraries' strong privacy protecting policies, has led ALA and librarians to work tirelessly to protect patron privacy. In fact the American Bar Association, in an article in their ABA Journal in August of this year, recognized the growing lobbying clout of ALA, calling them, "one of the most active players in legal fights over technology, copyright, national security, censorship and privacy law." Librarians have been at the forefront in the battle against such legislation as the Children's Internet Protection Act (CIPA) and against certain provisions of the USA PATRIOT (Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism) Act (or USAPA in government documents parlance!) -- primarily section 215, the "library" section. Section 215 allows the FBI to access business records (including library circulation records showing what patrons are reading) with no probable cause and places a non-disclosure gag order on those librarians or libraries that are being asked for library records. USAPA precludes state statutes protecting private information. The strong stance against USAPA has led many libraries, in an effort to circumvent USAPA, to proactively delete circulation records and Web server logs and has led many to evaluate what personal information they keep and for how long. This strong historical pillar of privacy protection is perhaps most important where govt information is concerned. What you read about your government (or about anything else for that matter) needs to be protected and kept strictly confidential. In the analog world, this was easier to assure since govt information was distributed to libraries that then gave access and had the power and organizational policies to protect privacy. Privacy in the digital world is on much more tenuous footing. In the digital world the servers of the information decide how much privacy they'll let you have, and this decision is not necessarily based on Codes of ethics, or explicit policies protecting user privacy, but on business plans and economic realities. Downloading a digital document from a Federal Agency web site, or from a server at the Government Printing Office will allow those organizations to collect the following information:
- The IP address of your computer and Internet provider.
- The date and time you accessed their site.
- Information about the document or piece of data downloaded.
- The Internet address of the web site that referred you to their site.
- Tracking information via cookies.
“Policy neutral” does not mean “neutral policies”
Below is a copy of a comment I posted today to the Future Digital System (FDsys) Blog in response to a discussion thread there on the "policy neutral" nature of the FDsys.I invite your responses here or there. "Policy neutral" does not mean "neutral policies." "Policy neutral" means that there are no inviolable policies. The new system will, according to Magan Fleetwood, "adapt" to "guidelines created or adopted by GPO." So, while GPO may be committed today to no-fee permanent public access, the future digital system is designed to accommodate a change to that policy. While the FDsys requirements "do not prevent or limit free public access to authenticated content" neither do the requirements guarantee it. On the contrary, the system is designed to accommodate any policy, including the opposite of the current commitment. The FDSys is designed to be flexible enough to accommodate treating different information products differently -- some without fees and some with fees, for instance. It is easy to imagine how well-intentioned policies today could be superseded by financial or other constraints tomorrow. (See What the Copyright Office / Internet Explorer rule tells us about government information for real-life examples of such constraints.) The original "Transition Plan" was explicit about recognizing limitations when it said, "Electronic information under the custody of the SOD will be maintained for access" not permanently, but only, "as long as usage warrants." [emphasis added]. We can take no comfort from the fact that this wording (from 1996-1998 Transition Plan) has been dropped from subsequent plans because the new system is being designed not to prevent such policies, but to accommodate them. It is easy to imagine FDSys adapting to new policies and dropping information such as old reports that are not being used frequently, or statistics that are "out of date," or content judged "sensitive" by politicians, or large databases that are too expensive to keep online. It is easy to imagine content that is expensive to keep online and that is not used frequently being relegated to a fee-based system, or "permanent" access being provided by private-sector "partners." It is easy to imagine policies changing to accommodate financial constraints so that some information is available to the public without fees, but other information (or more functional versions of that information) are available only for a fee. When government information was deposited in depository libraries, such policy changes were difficult or impossible to implement. The new system is being designed to make it easy to implement them. In fairness, GPO cannot guarantee anything else. Magan is right to include qualifications to GPO's commitment to providing no-fee permanent public access; ("Based on enabling legislation" and "in-scope content" and "GPO intends to... permit..." [emphasis added]). GPO cannot go beyond what it is legislatively authorized and funded to do. How could it guarantee to provide access in the future to content that became defined by others as out of scope? How could it provide permanent, public, no-fee access to everything if its funding became inadequate to do so? How can GPO guarantee no-fee access if its own mission is to distribute electronic documents "on a cost recovery basis." GPO cannot guarantee these things so its "commitment," while noble, is not enough. There are, however, two things that GPO can guarantee. I ask GPO to respond here if it will do so. 1. Will GPO guarantee that it will provide information products for free to the public and that those products will be fully-functional and not encumbered, disabled, controlled or otherwise non-optimal or locked-down versions? 2. Will GPO guarantee that it will make available for deposit, without fee, into FDLP libraries that wish to receive them, all fully functional digital government information products within its purview? These are guarantees that GPO can make and that will accomplish two things that promises of future commitment cannot. First, they will ensure that government information will be, at its release, freely available to all without encumbrance and individuals will be able to use and re-use the information without having to pay for the information or its use and re-use. Second, while GPO cannot control the future, it can ensure that every new document is deposited, at its release, in as many libraries as possible, creating a safety net and alternative to the FDSys in case policies change. Continue reading
Will GPO guarantee user privacy? Can it?
September 1, 2005 / Leave a comment
Will GPO guarantee the privacy of users? Will any guarantees it does make be implemented carefully and accurately? It is important to ask these questions if libraries do not have copies of digital government information and all users must retrieve copies from government managed web servers. If libraries had copies of digital government information, users could retrieve that information from libraries (which have a long tradition and policies of protecting privacy of users) rather than from the government.
I was thinking about these issues and GPO's commitment to data mining in its "Future Digital System" when I read a story this morning that sheds some light on current implementation of data mining in federal government agencies:
The story quotes a new GAO report and says that "implementing privacy and security measures is haphazard.... Of five data mining programs at five different agencies, 'none followed all key procedures' for privacy and security measures." The GAO report:
GPO's commitment to data mining is spelled out in its Future Digital System requirements document in section 3.2.14.7, pages 92-95. This section specifies that the FDsys will log transactions and be able to extract, analyze and present data from Business Process Information, perform cross tabulations and "clusterization" and categorization, and perform association and link analyses. It will be able to "expose" sequential and temporal relationships and patterns and filter data at different levels of granularity and will have ability to create customizable reports for analysis of search terms. It will be able to send alerts or notifications to GPO users based on defined criteria.
Each of those functions could be used in ways that improved system performance and did not violate privacy. Indeed the system specifies that it must "provide the capability conform to GPO's privacy policy and Federal privacy laws and regulations."
Unfortunately, there are two problems with this. First, since the new system is "policy neutral" (see Policy, by Magan Fleetwood, August 29, 2005, Future Digital System (FDsys) Blog, and comments to that blog including: "Policy neutral" does not mean "neutral policies" by James A. Jacobs, 8/21/2005 or FGI copy of that comment), GPO provides no guarantee of user privacy. Instead, it only guarantees that it will conform to whatever policy is in place at any given point in time. And, it is developing a system flexible enough to conform to changing policies. Its system guarantees that it can implement a no-privacy policy. So, even though the system will, for example, be designed so that it has "the capability of maintaining Access privacy (e.g., Search, Request)," there is nothing that says it must implement that capability.
Second there is nothing in the system specification to prevent the kinds of problems found by the GAO. Having procedures and policies in place doesn't help if the agency doesn't follow them.
What is to be done? FDLP librarians and others should be demanding that GPO has a strong privacy policy, of course. But even more importantly, we should be insisting that GPO guarantee the availability of fully-functional digital content to the public and to libraries. To restate questions I've asked before:
- Will GPO guarantee that it will provide information products for free to the public and that those products will be fully-functional and not encumbered, disabled, controlled or otherwise non-optimal or locked-down versions?
- Will GPO guarantee that it will make available for deposit, without fee, into FDLP libraries that wish to receive them, all fully functional digital government information products within its purview?
Continue reading →Continue Reading →