Showing posts with label Google. Show all posts
Showing posts with label Google. Show all posts

Thursday, May 14, 2015

Open letter to Google on RTBF processes

I'm one of 80 signatories to an open letter to Google requesting more transparency from the company over how it processes so-called ‘right to be forgotten’ requests. The letter was drafted and coordinated by Julia Powles at Cambridge University and Ellen P. Goodman at Rutgers University School of Law.

Copy below.
"What We Seek
Aggregate data about how Google is responding to the >250,000 requests to delist links thought to contravene data protection from name search results. We should know if the anecdotal evidence of Google’s process is representative: What sort of information typically gets delisted (e.g., personal health) and what sort typically does not (e.g., about a public figure), in what proportions and in what countries?
Why It’s Important
Google and other search engines have been enlisted to make decisions about the proper balance between personal privacy and access to information. The vast majority of these decisions face no public scrutiny, though they shape public discourse. What’s more, the values at work in this process will/should inform information policy around the world. A fact-free debate about the RTBF is in no one’s interest.
Why Google
Google is not the only search engine, but no other private entity or Data Protection Authority has processed anywhere near the same number of requests (most have dealt with several hundred at most). Google has by far the best data on the kinds of requests being made, the most developed guidelines for handling them, and the most say in balancing informational privacy with access in search. We address this letter to Google, but the request goes out to all search engines subject to the ruling.

One year ago, the European Court of Justice, in Google Spain v AEPD and Mario Costeja González, determined that Google and other search engines must respond to users’ requests under EU data protection law concerning search results on queries of their names. This has become known as the Right to Be Forgotten (RTBF) ruling. The undersigned have a range of views about the merits of the ruling. Some think it rightfully vindicates individual data protection/privacy interests. Others think it unduly burdens freedom of expression and information retrieval. Many think it depends on the facts.
We all believe that implementation of the ruling should be much more transparent for at least two reasons: (1) the public should be able to find out how digital platforms exercise their tremendous power over readily accessible information; and (2) implementation of the ruling will affect the future of the RTBF in Europe and elsewhere, and will more generally inform global efforts to accommodate privacy rights with other interests in data flows.
Google reports that it has received over 250,000 individual requests concerning one million URLs in the past year. It also reports that it has delisted from name search results just over 40% of the URLs that it has reviewed. In various venues, Google has shared some 40 examples of delisting requests granted and denied (including 22 examples on its website), and it has revealed the top sources of material requested to be delisted (amounting to less than 8% of total candidate URLs). Most of the examples surfaced more than six months ago, with minimal transparency since then. While Google’s decisions will seem reasonable enough to most, in the absence of real information about how representative these are, the arguments about the validity and application of the RTBF are impossible to evaluate with rigour.
Beyond anecdote, we know very little about what kind and quantity of information is being delisted from search results, what sources are being delisted and on what scale, what kinds of requests fail and in what proportion, and what are Google’s guidelines in striking the balance between individual privacy and freedom of expression interests.
The RTBF ruling addresses the delisting of links to personal information that is “inaccurate, inadequate, irrelevant, or excessive for the purposes of data processing,” and which holds no public interest. Both opponents and supporters of the RTBF are concerned about overreach. Because there is no formal involvement of original sources or public representatives in the decision-making process, there can be only incidental challenges to information that is delisted, and few safeguards for the public interest in information access. Data protection authorities seem content to rely on search engines’ application of the ruling’s balancing test, citing low appeal rates as evidence that the balance is being appropriately struck. Of course, this statistic reveals no such thing. So the sides do battle in a data vacuum, with little understanding of the facts — facts that could assist in developing reasonable solutions.
Peter Fleischer, Google Global Privacy Counsel, reportedly told the 5th European Data Protection Days on May 4 that, “Over time, we are building a rich program of jurisprudence on the [RTBF] decision.” (Bhatti, Bloomberg, May 6). It is a jurisprudence built in the dark. For example, Mr. Fleischer is quoted as saying that the RTBF is “about true and legal content online, not defamation.” This is an interpretation of the scope and meaning of the ruling that deserves much greater elaboration, substantiation, and discussion.
We are not the only ones who want more transparency. Google’s own Advisory Council on the RTBF in February 2015 recommended more transparency, as did the Article 29 Working Party in November 2014. Both recommended that data controllers should be as transparent as possible by providing anonymised and aggregated statistics as well as the process and criteria used in delisting decisions. The benefits of such transparency extend to those who request that links be delisted, those who might make such requests, those who produce content that is or might be delisted, and the wider public who might or do access such material. Beyond this, transparency eases the burden on search engines by helping to shape implementation guidelines and revealing aspects of the governing legal framework that require clarification.
Naturally, there is some tension between transparency and the very privacy protection that the RTBF is meant to advance. The revelations that Google has made so far show that there is a way to steer clear of disclosure dangers. Indeed, the aggregate information that we seek threatens privacy far less than the scrubbed anecdotes that Google has already released, or the notifications that it is giving to webmasters registered with Google webmaster tools. The requested data is divorced from individual circumstances and requests. Here is what we think, at a minimum, should be disclosed:
  1. Categories of RTBF requests/requesters that are excluded or presumptively excluded (e.g., alleged defamation, public figures) and how those categories are defined and assessed.
  2. Categories of RTBF requests/requesters that are accepted or presumptively accepted (e.g., health information, address or telephone number, intimate information, information older than a certain time) and how those categories are defined and assessed.
  3. Proportion of requests and successful delistings (in each case by % of requests and URLs) that concern categories including (taken from Google anecdotes): (a) victims of crime or tragedy; (b) health information; (c) address or telephone number; (d) intimate information or photos; (e) people incidentally mentioned in a news story; (f) information about subjects who are minors; (g) accusations for which the claimant was subsequently exonerated, acquitted, or not charged; and (h) political opinions no longer held.
  4. Breakdown of overall requests (by % of requests and URLs, each according to nation of origin) according to the WP29 Guidelines categories. To the extent that Google uses different categories, such as past crimes or sex life, a breakdown by those categories. Where requests fall into multiple categories, that complexity too can be reflected in the data.
  5. Reasons for denial of delisting (by % of requests and URLs, each according to nation of origin). Where a decision rests on multiple grounds, that complexity too can be reflected in the data.
  6. Reasons for grant of delisting (by % of requests and URLs, each according to nation of origin). As above, multi-factored decisions can be reflected in the data.
  7. Categories of public figures denied delisting (e.g., public official, entertainer), including whether a Wikipedia presence is being used as a general proxy for status as a public figure.
  8. Source (e.g., professional media, social media, official public records) of material for delisted URLs by % and nation of origin (with top 5–10 sources of URLs in each category).
  9. Proportion of overall requests and successful delistings (each by % of requests and URLs, and with respect to both, according to nation of origin) concerning information first made available by the requestor (and, if so, (a) whether the information was posted directly by the requestor or by a third party, and (b) whether it is still within the requestor’s control, such as on his/her own Facebook page).
  10. Proportion of requests (by % of requests and URLs) where the information is targeted to the requester’s own geographic location (e.g., a Spanish newspaper reporting on a Spanish person about a Spanish auction).
  11. Proportion of searches for delisted pages that actually involve the requester’s name (perhaps in the form of % of delisted URLs that garnered certain threshold percentages of traffic from name searches).
  12. Proportion of delistings (by % of requests and URLs, each according to nation of origin) for which the original publisher or the relevant data protection authority participated in the decision.
  13. Specification of (a) types of webmasters that are not notified by default (e.g., malicious porn sites); (b) proportion of delistings (by % of requests and URLs) where the webmaster additionally removes information or applies robots.txt at source; and (c) proportion of delistings (by % of requests and URLs) where the webmaster lodges an objection.
As of now, only about 1% of requesters denied delisting are appealing those decisions to national Data Protection Authorities. Webmasters are notified in more than a quarter of delisting cases (Bloomberg, May 6). They can appeal the decision to Google, and there is evidence that Google may revise its decision. In the remainder of cases, the entire process is silent and opaque, with very little public process or understanding of delisting.
The ruling effectively enlisted Google into partnership with European states in striking a balance between individual privacy and public discourse interests. The public deserves to know how the governing jurisprudence is developing. We hope that Google, and all search engines subject to the ruling, will open up."
Full list of signatories, who have the additional honour of riding high in the TechnoLlama approval ratings, available at the Guardian and medium.com.

Thursday, September 04, 2014

Jennifer Lawrence and the right to be forgotten

Privacy is back in the news because some celebrities, such as the talented Jennifer Lawrence, have had compromising photographs leaked and the police have been accessing a journalist's phone records.

Can the latest scandals throw any light on the mislabeled and erroneously reported Court of Justice of the European Union (CJEU) Google "right to be forgotten" decision?

Well perhaps, at least in the case of the leaked photos. Some of our US cousins, for example, find it hard to understand the ruling and consider it fundamentally incompatible with US First Amendment guarantees for freedom of expression.What the hell do those regressive Europeans think they are doing?

These same horror-stricken people, however, do see that a movie star, who has embarrassing photographs copied or stolen and leaked around the world, should have some means of redress, recovering those photos and/or suppressing their distribution. Likewise the victims of revenge porn or blackmail as in AMP v persons unknown.

It's not the same, but did Mario Costeja González have the right to redress in relation to Google's prominent display in search results of a link to a news article about historical financial difficulties?

Lilian Edwards did a terrific job explaining that EU law requires that yes he should, in the process nailing some of the key myths circulating about the decision.

Having been completely neglectful in not yet analysing the case here, I've been prompted to some brief thoughts by the latest round of stories. Disclaimer: This doesn't constitute a proper analysis (for which, sadly, I have little time at the moment). In any case...

Firstly, everybody makes mistakes and suffers embarrassment.

Fear of same actually constrains some people so much they neglect to do or say anything that in any way might rebound on them or be used as a metaphoric stick to beat them with by the communities within which they exist. This can be incredibly debilitating.

Historically, however, society has enabled "recovery" from mistakes or embarrassment through collective fading and displacement of memories of those events.

We have now, though, spent the best part of the last 30 years enabling, actively and/or passively, the building and operation of a communications mass surveillance infrastructure and 'permanent' digital memory store, unparalleled in the history of the human race. We've been happy to revel in the benefits of these technologies as have governments and large economic actors like Google. But as John Naughton so eloquently puts it, our " indolence is a shocking case study of what complacent ignorance can do to a democracy, and we are now living with the consequences of it."

We are, nevertheless, where we are and it presents us with a complex mess to sort out.  So on the Google case specifically, it's worth at least asking a few questions.

Supposing Google or other economic agents or governments prominently and permanently tags/connects a past mistake or embarrassment to a person's name, so that we cannot "recover" through fading or displacement of collective memory. Supposing also that these agents prominently flag these mistakes through headline search results that, in our world of short attention spans, means we can never escape them. Let's face it we are a society quick to condemn on the basis of flimsy, minimal or non-existent evidence and occasionally don't even bother to click on the link, merely judge by the headline...

Is this a problem?
  1. for the individual?
  2. for the individual's family, friends, community?
  3. for society generally?
  4. for Google and other economic agents as collectors, processors and controllers of the personal data at issue?
  5. for government and the courts?
I'd answer 'yes' to each of these to a variety of degrees for a variety of reasons. If you answer yes to any of them we have a significant mess that requires sorting out. The part of that mess the CJEU attempted to target in the very narrowly tailored Google Spain v González decision was, on balance,  a tiny step in the right direction.

Even Google have got over their original hissy fit over the decision and are getting on with it. They've stopped 'loudly' indicating results were being censored and anyone wanting to see them could click on a convenient link, provided on the search results page to the US version of Google.

The decision itself requires only the link from the name of the person formally requesting a takedown to the page that name appears in be removed. The webpage with the information about the individual's past remains in place. Someone with semi coherent search skills can still easily find it. Lazy name searches, for those subjects who successfully request it, just don't now lead directly to the equivalent of a digital loudhailer proclaiming the individual, like everyone, has some mistakes in their past that society should accept are spent.

The ruling does not constitute a general 'right to be forgotten' which might itself present all kinds of challenges. The one major problem with it is that it delegates a public interest and fundamental rights decision to a private economic actor, Google in this instance, that should probably sit within the remit of a court, tribunal or at least some other quasi-judicial public authority.

And finally, for the 1st Amendment absolutists, how free to speak is the sensitive man/woman/child terrified that any misspoken comment, mistake or embarrassing situation will be blown up and held against them for the rest of their natural lives? This, given our out of control mass surveillance society, is a 1st amendment issue too, just not necessarily in the way you suppose.

Update: John Naughton's exposé of the ugly side of human nature "celebgate" reveals is essential reading.

Friday, July 04, 2014

House of Lords evidence session on CJEU Google ruling

The House of Lords EU Sub-Committee on Home Affairs, Health and Education had a hearing earlier in the week about the European Court of Justice decision in the Google v González case, popularly known as the right to be forgotten ruling.
Witnesses at the first session were Neil Cameron, consultant; Chris Scott, Partner, Schillings; Jennie Sumpster, Senior Associate, Schillings; and Jim Killock, Executive Director, Open Rights Group.

Tuesday, April 29, 2014

Free is a lie - Aral Balkan at TNW

Take 32 mins and listen to Indie phone's Aral Balkan's talk at the recent TNW conference.



Balkan opens with a simple thought experiment. He's setting up a hypothetical business, Schnail Mail, which will solve the problem of mail delivery by delivering letters and parcels of all shapes and sizes anywhere in the world for free. He asks his audience how many of them would sign up for it. Sounds like an attractive enterprise so many would. In the interests of full disclosure he then explains that by the way Schnail mail will open and forensically examine all letters and parcels to learn about their customers, obviously in the interests only of offering them a better service. How many would now sign up? Not very many though there were still a hard core half a dozen or so. In any case the Schnail Mail business model is the Google, Facebook, [big tech co of choice] "free" service business model.

The business model of "free" is the business model of mass surveillance. We effectively hand over quarries of personal data for these corporations to mine for their own ends. He quotes Eric Schmidt noting Google knows who you are, where you are and what you are thinking; and Facebook knowing people are on the path to a relationship before those people possibly even know it themselves.

He also quotes the Google executive chairman saying:
"If you have something you don't want everyone to know maybe you shouldn't be doing it in the first place."
That's not the kind of world Balkan wants. Privacy is not about whether you have something to hide. It's about having control of what you want to share and what to keep to yourself. But in the world of "free" mass surveillance you don't have that control. The corporations do and they have acquired that control by deceit because consumers largely have no idea of the information they have surrendered/bartered in exchange for "free" services.  If we make the panopticon the default that leads to a society where anything we want to keep private has an association of guilt attached. Privacy becomes only about hiding bad things. Balkan rejects that notion.

Ordinary consumers currently have no choice - all roads lead to digital feudalism regardless of which corporate walled garden is chosen. Techies say use free and open source alternatives. But ordinary mortals have not got the time, skills or resources to architect or build our own FOSS, experience-led digital privacy assured shells to shield our rich personal data quarries / digital personas, thereby enabling us to participate in the information society without compromising our privacy. So techies, entrepreneurs, the market have to start to provide custom built user friendly privacy enhanced technologies. One such effort is Balkan's indie phone.

The true cost of "free" he says is our privacy, our civil liberties, our human rights.

Good luck to Mr Balkan with his indie phone venture. His success will likely depend on the degree to which he can manage the pathological calculus that is -

Privacy vs Convenience/attraction/gratification/access/community/conformity/convenience
- in addition to the small matter of taking on the power of the mass surveillance addicted market incumbents.