Aborto vietato negli Usa, privacy a rischio per tutte le donne in età riproduttiva

Dopo la sentenza che abolisce il diritto all’aborto negli Usa, i dati online di tutte le donne in età riproduttiva potrebbero essere utilizzati contro le persone che fanno ricerche sull’aborto. Una conseguenza diretta sulla nostra privacy, quindi, ora che la sentenza Roe vs. Wade è stata ribaltata rendendo di fatto illegale l’aborto in gran parte degli Stati Uniti.

Grido d’allarme per la privacy

E’ questo il grido d’allarme che si è alzato negli Usa, dopo la sentenza della Corte Suprema americana che ha abolito il diritto di interrompere la gravidanza. Secondo gli esperti, oltre a privare le donne dei diritti di abortire, la sentenza della Corte Suprema Usa modifica alla radice il rapporto delle donne con la Rete e con il mondo digitale tout court. Lo scrive il sito specializzato The Conversation, in un’interessante articolo di commento.

Chiunque si rivolga a internet per cercare informazioni sull’aborto, oppure prodotti e servizi legati all’aborto, nei paesi dove questa pratica è diventata all’improvviso illegale è a rischio di sorveglianza online.

Tutte le donne in età da figli, a prescindere da quanto si possano sentire sicure o privilegiate, si troveranno d’ora in poi marginalizzate e a rischio privacy, come parte della popolazione più vulnerabile e a rischio.

Tutti sanno da tempo come Google, i social media e i dati di Internet in genere possono essere utilizzati per la sorveglianza da parte delle forze dell’ordine per lanciare reti a strascico digitali. Le donne sono a rischio non solo per ciò che rivelano sul loro stato riproduttivo sui social media, ma anche per i dati delle loro applicazioni sanitarie, che potrebbero incriminarle se venissero citate in giudizio.

Chi è sotto controllo e come

Le persone più vulnerabili all’invasione della privacy online e all’uso o abuso dei loro dati sono tradizionalmente quelle che la società considera meno degne di protezione: persone senza mezzi, potere o posizione sociale. La sorveglianza rivolta alle persone emarginate riflette non solo una mancanza di interesse a proteggerle, ma anche una presunzione che, in virtù della loro identità sociale, abbiano maggiori probabilità di commettere crimini o trasgredire in modi che potrebbero giustificare attività di polizia preventiva.

Molte persone emarginate sono donne, comprese le madri a basso reddito, per le quali il semplice atto di richiedere l’assistenza pubblica può sottoporle a presunzioni di intento criminale. Queste presunzioni sono spesso utilizzate per giustificare le invasioni della loro privacy. Ora, con la legislazione anti-aborto che sta investendo gli stati controllati dai repubblicani e pronta ad entrare in vigore con la fine di Roe v. Wade, è probabile che tutte le donne in età riproduttiva in quegli stati siano soggette a quelle stesse presunzioni.

Prima, le donne dovevano preoccuparsi solo che Target o Amazon potessero venire a conoscenza delle loro gravidanze. Sulla base di ciò che è già noto sulle incursioni della privacy da parte delle forze dell’ordine contro le persone emarginate, è probabile che nel mondo post-Roe le donne saranno più nel mirino della scientifica digitale. Ad esempio, le forze dell’ordine utilizzano regolarmente strumenti forensi per perquisire i cellulari delle persone quando indagano su un’ampia gamma di crimini, a volte senza un mandato di perquisizione.

App del ciclo mestruale

Immagina uno scenario in cui un collega o un vicino denuncia qualcuno alle autorità, il che fornisce alle forze dell’ordine motivi per perseguire le prove digitali. Tali prove potrebbero includere, ad esempio, ricerche su Internet su fornitori di aborti e dati di app per il ciclo che mostrano periodi mancati.

Il rischio è particolarmente acuto nei luoghi che favoriscono la caccia di taglie. In uno stato come il Texas, dove c’è la possibilità che i cittadini abbiano la possibilità di citare in giudizio le persone che aiutano gli altri ad accedere ai servizi di aborto, tutto ciò che dici o fai in qualsiasi contesto diventa rilevante perché non c’è una causa probabile che ostacoli l’accesso ai tuoi dati.

Al di fuori di questo caso, è difficile rendere pienamente giustizia a tutti i rischi perché il contesto è importante e diverse combinazioni di circostanze possono cospirare per aumentare i danni. Ecco i rischi da tenere a mente:

Condividere sui social media informazioni sulla tua gravidanza

Comportamento di ricerca su Internet correlato direttamente o indirettamente alla gravidanza o alla salute riproduttiva, indipendentemente dal motore di ricerca utilizzato.

Tracciamento della posizione tramite il telefono, ad esempio mostrando che hai visitato un luogo che potrebbe essere collegato alla tua salute riproduttiva.

Utilizzo di app che rivelano dati sensibili rilevanti, come il ciclo mestruale.

Essere troppo sicuri nell’usare la crittografia o strumenti anonimi.

https://www.key4biz.it/aborto-vietato-negli-usa-privacy-a-rischio-per-tutte-le-donne-in-eta-riproduttiva/408389/




Spurred by Roe overturn, senators seek FTC probe of iOS and Android tracking

A Illustration of a smartphone at the center of a target.

Four Democratic US senators today asked the Federal Trade Commission to “investigate Apple and Google for engaging in unfair and deceptive practices by enabling the collection and sale of hundreds of millions of mobile phone users’ personal data.”

“The FTC should investigate Apple and Google’s role in transforming online advertising into an intense system of surveillance that incentivizes and facilitates the unrestrained collection and constant sale of Americans’ personal data,” they wrote. “These companies have failed to inform consumers of the privacy and security dangers involved in using those products. It is beyond time to bring an end to the privacy harms forced on consumers by these companies.”

The letter cited the Supreme Court decision overturning Roe v. Wade, saying that women “seeking abortions and other reproductive healthcare will become particularly vulnerable to privacy harms, including through the collection and sharing of their location data.” It continued:

Data brokers are already selling, licensing, and sharing the location information of people that visit abortion providers to anyone with a credit card. Prosecutors in states where abortion becomes illegal will soon be able to obtain warrants for location information about anyone who has visited an abortion provider. Private actors will also be incentivized by state bounty laws to hunt down women who have obtained or are seeking an abortion by accessing location information through shady data brokers.

iOS, Android “fueled unregulated data broker market”

The letter was sent to FTC Chair Lina Khan by Sens. Ron Wyden (D-Ore.), Elizabeth Warren (D-Mass.), Cory Booker (D-N.J.), and Sara Jacobs (D-Calif.). Apple and Google “knowingly facilitated these harmful practices by building advertising-specific tracking IDs into their mobile operating systems,” the senators wrote.

“Apple and Google both designed their mobile operating systems, iOS and Android, to include unique tracking identifiers which they have specifically marketed for advertising purposes,” the letter said. “These identifiers have fueled the unregulated data broker market by creating a single piece of information linked to a device that data brokers and their customers can use to link to other data about consumers. This data is bought or acquired from app developers and online advertisers, and can include consumers’ movements and web browsing activity.”

While Apple has stopped enabling the tracking identifiers by default, the senators wrote that both companies harmed consumers:

Both Apple and Google now allow consumers to opt out of this tracking. Until recently, however, Apple enabled this tracking ID by default and required consumers to dig through confusing phone settings to turn it off. Google still enables this tracking identifier by default, and until recently did not even provide consumers with an opt-out. By failing to warn consumers about the predictable harms that would result by using their phones with the default settings that these companies chose, Apple and Google enabled governments and private actors to exploit advertising tracking systems for their own surveillance and exposed hundreds of millions of Americans to serious privacy harms.

Last week, Warren proposed legislation that would prohibit data brokers from selling Americans’ location and health data.

“Anonymous” identifiers can be linked to people

The advertising identifiers are “purportedly anonymous” but in reality “are easily linkable back to individual users,” the letter said. “This is because some data brokers sell databases that explicitly link these advertising identifiers to consumers’ names, email addresses, and telephone numbers. But even without buying this additional data, it is often possible to easily identify a particular consumer in a dataset of ‘anonymous’ location records by looking to see where they sleep at night.”

We asked Apple and Google for comment on the letter and will update this story if we get any response.

Update at 2:55 pm ET: Google responded to Ars, touting its efforts to block apps that violate Google Play policies and the bans it has imposed on companies that apparently sold user data. “Google never sells user data, and Google Play strictly prohibits the sale of user data by developers,” the company said in a statement. “The advertising ID was created to give users more control and provide developers with a more private way to effectively monetize their apps. Additionally, Google Play has policies in place that prohibit using this data for purposes other than advertising and user analytics. Any claims that advertising ID was created to facilitate data sale are simply false.”

Google also said its Android Privacy Sandbox will “enable new, more private advertising solutions that limit sharing of user data with third parties and operate without cross-party identifiers, including advertising IDs.” Ars reporter Ron Amadeo’s coverage of that initiative called it “toothless.”

EFF calls for action by Congress and tech companies

The senators’ letter was prepared before the official release of the Supreme Court’s abortion decision, which came out today after a draft was leaked in early May. Reacting to the court ruling today, the Electronic Frontier Foundation said it “underscores the importance of fair and meaningful protections for data privacy.”

“Everyone deserves to have strong controls over the collection and use of information they necessarily leave behind as they go about their normal activities, like using apps, search engine queries, posting on social media, texting friends, and so on,” the EFF said. “But those seeking, offering, or facilitating abortion access must now assume that any data they provide online or offline could be sought by law enforcement.”

The EFF urged state and federal lawmakers to “pass meaningful privacy legislation” and said companies should protect privacy “by allowing anonymous access, stopping behavioral tracking, strengthening data deletion policies, encrypting data in transit, enabling end-to-end message encryption by default, preventing location tracking, and ensuring that users get notice when their data is being sought.”

Last month, more than 40 Democratic members of Congress called on Google to stop collecting and retaining customer location data that prosecutors could use to identify women who obtain abortions. Lawmakers have also been working on comprehensive data privacy legislation, but no proposal is close to being passed.

https://arstechnica.com/?p=1862757




Facebook is receiving sensitive medical information from hospital websites

Facebook is receiving sensitive medical information from hospital websites
Aurich Lawson | Getty Images

A tracking tool installed on many hospitals’ websites has been collecting patients’ sensitive health information—including details about their medical conditions, prescriptions, and doctor’s appointments—and sending it to Facebook.

The Markup tested the websites of Newsweek’s top 100 hospitals in America. On 33 of them we found the tracker, called the Meta Pixel, sending Facebook a packet of data whenever a person clicked a button to schedule a doctor’s appointment. The data is connected to an IP address—an identifier that’s like a computer’s mailing address and can generally be linked to a specific individual or household—creating an intimate receipt of the appointment request for Facebook.

On the website of University Hospitals Cleveland Medical Center, for example, clicking the “Schedule Online” button on a doctor’s page prompted the Meta Pixel to send Facebook the text of the button, the doctor’s name, and the search term we used to find her: “pregnancy termination.”

Clicking the “Schedule Online Now” button for a doctor on the website of Froedtert Hospital, in Wisconsin, prompted the Meta Pixel to send Facebook the text of the button, the doctor’s name, and the condition we selected from a dropdown menu: “Alzheimer’s.”

The Markup also found the Meta Pixel installed inside the password-protected patient portals of seven health systems. On five of those systems’ pages, we documented the pixel sending Facebook data about real patients who volunteered to participate in the Pixel Hunt project, a collaboration between The Markup and Mozilla Rally. The project is a crowd-sourced undertaking in which anyone can install Mozilla’s Rally browser add-on in order to send The Markup data on the Meta Pixel as it appears on sites that they visit. The data sent to hospitals included the names of patients’ medications, descriptions of their allergic reactions, and details about their upcoming doctor’s appointments.

Former regulators, health data security experts, and privacy advocates who reviewed The Markup’s findings said the hospitals in question may have violated the federal Health Insurance Portability and Accountability Act (HIPAA). The law prohibits covered entities like hospitals from sharing personally identifiable health information with third parties like Facebook, except when an individual has expressly consented in advance or under certain contracts.

Neither the hospitals nor Meta said they had such contracts in place, and The Markup found no evidence that the hospitals or Meta were otherwise obtaining patients’ express consent.

“I am deeply troubled by what [the hospitals] are doing with the capture of their data and the sharing of it,” said David Holtzman, a health privacy consultant who previously served as a senior privacy adviser in the U.S. Department of Health and Human Services’ Office for Civil Rights, which enforces HIPAA. “I cannot say [sharing this data] is for certain a HIPAA violation. It is quite likely a HIPAA violation.”

University Hospitals Cleveland Medical Center spokesperson George Stamatis did not respond to The Markup’s questions but said in a brief statement that the hospital “comport[s] with all applicable federal and state laws and regulatory requirements.”

After reviewing The Markup’s findings, Froedtert Hospital removed the Meta Pixel from its website “out of an abundance of caution,” Steve Schooff, a spokesperson for the hospital, wrote in a statement.

As of June 15, six other hospitals had also removed pixels from their appointment booking pages and at least five of the seven health systems that had Meta Pixels installed in their patient portals had removed those pixels.

The 33 hospitals The Markup found sending patient appointment details to Facebook collectively reported more than 26 million patient admissions and outpatient visits in 2020, according to the most recent data available from the American Hospital Association. Our investigation was limited to just over 100 hospitals; the data sharing likely affects many more patients and institutions than we identified.

Facebook itself is not subject to HIPAA, but the experts interviewed for this story expressed concerns about how the advertising giant might use the personal health data it’s collecting for its own profit.

“This is an extreme example of exactly how far the tentacles of Big Tech reach into what we think of as a protected data space,” said Nicholson Price, a University of Michigan law professor who studies big data and health care. “I think this is creepy, problematic, and potentially illegal” from the hospitals’ point of view.

The Markup was unable to determine whether Facebook used the data to target advertisements, train its recommendation algorithms, or profit in other ways.

https://arstechnica.com/?p=1861234




Codice della Privacy

A cura di Emilio Tosi
Pubblicato: maggio 2022
Editore: La Tribuna
Pagine: 1.728
ISBN: 9788829110254
Prezzo: 35,00 euro
XII edizione

Dalla data dell’entrata in vigore della prima normativa quadro in materia di trattamento dei dati personali – 8 maggio 1997 – ad oggi” – così scrive il curatore dell’opera Emilio Tosi, Professore Associato di Diritto Privato nell’Università di Milano Bicocca, Direttore Diritto Nuove Tecnologie® e Managing Partner di Tosi & Partners High Tech Legal nell’aggiornatissimo Codice recentemente pubblicato per i tipi La Tribuna – “si è progressivamente rafforzata e sviluppata una diffusa cultura della tutela e sicurezza dei dati personali in Italia e nella UE. Il rapido susseguirsi di interventi normativi generali e settoriali in materia ha, però, creato non poche difficoltà operative di interpretazione e coordinamento tanto ai giuristi che agli operatori economici e ai cittadini ormai destinati – tutti – a confrontarsi quotidianamente con tali nuove e delicate problematiche.

Si pensi alle pervasive problematiche poste dal trattamento dei dati personali raccolti mediante piattaforme digitali, motori di ricerca, social network, Internet of Things (IoT), wearables, droni, rilevatori biometrici e last but not least ai big data e al trattamento dei dati genetici.

Tenuto conto della complessità e attualità della materia e della già considerevole elaborazione normativa ad oggi formatasi, si è ritenuto utile – a supporto dell’opera interpretativa del giurista, dell’applicazione aziendale della normativa e della tutela dei diritti della persona fisica – raccogliere in un Codice della Privacy la normativa comunitaria, interna e internazionale inerente la tutela e la sicurezza dei dati personali, unitamente ai più significativi provvedimenti del Garante per la protezione dei dati personali”.

Il Codice si compone di una prima parte generale dedicata alla normativa comune seguita da una corposa parte speciale ordinata in voci alfabetiche di cui si segnalano le voci principali e precisamente: Amministratori di sistema; Autorità garante per la protezione dei dati personali; Autorizzazioni generali per il trattamento dei dati particolari; Autorizzazioni generali al trasferimento dei dati all’estero; Beni culturali e del paesaggio; Carte magnetiche; Casellario giudiziale; Codici deontologici; Contratti telematici, firme elettroniche e firma digitale; Dati anagrafici e stato civile; Dati assicurativi; Dati bancari; Dati biometrici; Dati sulla circolazione stradale; Dati customer care; Dati etichette RFID; Dati finanziari; Dati fiscali; Dati genetici; Dati giudiziari; Dati PMI; Dati sanitari; Dati traffico telefonico e telematico; Fidelity card; Furti di identità; Indagini difensive; Media conciliazione; Misure minime di sicurezza; Pubblica sicurezza; Regolarizzazione dei ricorsi; Semplificazione dei riti civili; Servizi di comunicazione; Servizi di informazione; Telecomunicazioni; Tutela dei lavoratori; Videosorveglianza; Vigilanza privata.

Come noto la disciplina della tutela della riservatezza e protezione dei dati personali è assicurata oggi da un doppio livello normativo:

  • europeo: in forza del Regolamento (UE) 2016/679 del Parlamento europeo e del Consiglio, del 27 aprile 2016, relativo alla protezione delle persone fisiche con riguardo al trattamento dei dati personali, nonché alla libera circolazione di tali dati, c.d. General Data Protection Regulation (di seguito per brevità, “GDPR”);
  • interno: in forza del D. Lgs. 30 giugno 2003, n. 196, c.d. Codice della Privacy (di seguito per brevità, Codice”) come armonizzato dal D.Lgs. 10 agosto 2018, n. 101 recante disposizioni per l’adeguamento dell’ordinamento nazionale al GDPR.

Tale doppio livello di regolazione della protezione e circolazione dei dati personali è articolato in rapporto gerarchico tra fonti europee sovraordinate e fonti interne sottoordinate.

Riservatezza e protezione dei dati personali sono diritti fondamentali della persona tutelati dall’art. 7 e 8 della Carta dei diritti fondamentali della UE.

Si tenga presente quale criterio ermeneutico generale che l’interprete – in caso di contrasti tra norme o dubbi interpretativi – deve ritenere prevalente la fonte europea sovraordinata – il GDPR – rispetto a quella sottordinata del Codice.

Il Codice è stato, infatti, conservato solo dopo essere stato ampiamente emendato e armonizzato al GDPR in forza del citato D.Lgs. 101/2018 e da ultimo ulteriromente aggiornato dalla L.  205/2021.

Non a caso gli artt. 1 e 2 del Codice armonizzato recitano quanto segue:

– Art. 1 Oggetto: Il trattamento dei dati personali avviene secondo le norme del Regolamento (UE) 2016/679 del Parlamento europeo e del Consiglio, del 27 aprile 2016, di seguito «Regolamento», e del presente Codice, nel rispetto della dignita’ umana, dei diritti e delle liberta’ fondamentali della persona;

Art. 2. Finalità: Il presente codice reca disposizioni per l’adeguamento dell’ordinamento nazionale alle disposizioni del regolamento.

Il Codice armonizzato ha, fra l’altro, abrogato a far data dal 19/9/2018, ampie parti della normativa italiana previgente che ha assunto, quindi, carattere residuale e recessivo rispetto a quella prevalente europea.

Il GDPR come noto è divenuto pienamente applicativo a far data dal 25 maggio 2018 ed è divenuto rapidamente un legal benchmark globale per la protezione dei dati personali.

Unica criticità da stigmatizzare: la tanto attesa riforma della privacy nelle comunicazioni elettroniche – c.d. e-privacy – che completerà il quadro normativo europeo in materia di protezione dei dati personali – riformando la Direttiva CE 2002/58 aggiornata dalla Direttiva CE 209/136 – è tutt’ora in corso.

L’aumento esponenziale del trattamento massivo e pervasivo dei dati personali nella società della sorveglianza digitale richiede da tempo anche tale ultimo tassello normativo”.

Il presente Codice – di sicuro interesse per Data Protection Officer, Giuristi di Impresa, Avvocati, Magistrati, Notai, Docenti Universitari, studenti di materie giuridiche ed appassionati della materia – è aggiornato alla G.U. n. 110 del 12/5/2022.

Emilio Tosi, è Professore Associato Diritto Privato e Diritto delle Nuove Tecnologie, Università degli Studi di Milano Bicocca.

https://www.key4biz.it/codice-della-privacy-3/406790/




Meta rumored to develop ‘Basic Ads’ in response to recent privacy changes

Meta Platforms’ Facebook is reportedly in the early stages of planning a Basic Ads product. Basic Ads would be aimed at advertisers who are looking to build awareness around their brands. 

What are Basic Ads? A Basic Ads product would offer and report only the simplest metrics such as engagement and video views.

With the release of iOS14 in 2020, and the option for users to opt-out to having their data collected, Facebook advertisers are having a more difficult time reporting on performance.

The initial response. Since Meta hasn’t officially announced the new product, little has been said about it in the advertising community. But Facebook veteran Curt Maly of Black Box Social Media, who is aware of Meta’s plans, said it’s interesting to think how a basic product with no targeting and no objectives would be beneficial. 

“More than 90% of all the online marketers I know are focused on direct response where efforts can be directly tracked… with this basic ads platform, it appears that tracking will be rather difficult,” Maly said. “Branding and awareness are used by larger companies with deeper pockets, most small businesses can’t compete with a brand who spends money ‘branding,’ small business owners need/want to drive results now.”

He added that brand new online advertisers and ad vets flock to Facebook to see fast results from targeting, conversion objectives and tracking results.

“If these three major goal lines are moved, I think we will be seeing a lot more people flock to Google/YouTube ads, TikTok ads and Apple’s new ad platform,” Maly said. “I mean Apple didn’t update iOS to ‘help protect users.’ Apple collects all the info they block on Facebook, Apple is about to get into the ad platform game once again and this is yet another reason for people to flock to a better ad platform.”

Privacy changes impact on Meta revenue. Meta estimates a $12.8 billion hit to their revenue in 2022 due to the Apple changes. Meta CEO Mark Zuckerberg also reports “unprecedented levels of competition” from new platforms such as TikTok.

In April, Meta laid out a three-tier plan to save its ad business in the wake of Apple’s privacy crackdown. At the time, Meta COO Sheryl Sandberg described the strategy as “doing more with less data.”

Meta’s response. Facebook declined to comment on the new product. There has not been a release date for a rollout, though Business Insider reports testing to start in the EU ahead of the U.S.

Why we care. The Facebook ads platform was previously known for its wide range of targeted audiences and demographic options. As of late, it seems like a lot of advertisers and businesses are moving away from the platform, reporting a decline in performance. Basic Ads could be a good alternative if they’re able to follow GDPR regulations while still providing useful targeting options.

Basic Ads may work well for household names such as Nike or Netflix whose goals are engagement and awareness. But smaller businesses that rely on more granular targeting and lead generation, such as courses for business owners, or youth soccer camp registrations, may have a more difficult time and may abandon Facebook for good. 


New on Search Engine Land

About The Author

Nicole Farley is an editor for Search Engine Land covering all things PPC. In addition to being a Marine Corps veteran, she has an extensive background in digital marketing, an MBA and a penchant for true crime, podcasts, travel, and snacks.

https://searchengineland.com/meta-basic-ads-385618




Privacy: il lavoro di Lepida come DPO della Regione Emilia-Romagna

Nel corso del 2021 Lepida ha svolto diverse attività in qualità di Data Protection Officer o DPO della Giunta e dell’Assemblea legislativa della Regione Emilia-Romagna e di altre 5 Agenzie regionali.

In particolare si è consolidata l’azione di sorveglianza attraverso gli incontri svolti ogni 3 mesi con gli Enti per un totale complessivo di 22 e sono state svolte 46 diverse attività tra pareri, analisi istruttorie, redazione di documenti e azioni di supporto.

Particolarmente intensa è stata l’attività in ambito nazionale con la partecipazione a 22 Incontri del Tavolo Nazionale Privacy della Conferenza Stato – Regioni aventi a oggetto la risposta comune alle istanze presentate in tema di negazione del consenso al Fascicolo Sanitario Elettronico (FSE), alle misure previste per il contenimento della pandemia da COVID-19 con particolare riferimento all’art. 4 del Decreto Legge 44, agli aspetti vaccinali e all’introduzione del Certificato verde.

Sempre a livello nazionale hanno avuto luogo, insieme ad altre Regioni, diversi incontri per rispondere all’istruttoria del Garante sul trattamento dei dati personali effettuato su richiesta del Ministero della Salute nonché diversi confronti con gli uffici del Garante sul percorso di adozione del regolamento della Legge 14/2015 sui soggetti fragili.

Infine sono state ricevute 2.475 istanze – prima manifestazione massiva di esercizio dei diritti in tema di protezione dei dati personali – da parte di interessati via mail, PEC e raccomandata riguardanti il FSE aventi ad oggetto la negazione del consenso alla consultazione del FSE.

A ciascuna istanza è stata data risposta individuale, oggetto di redazione e condivisione con la Direzione generale Cura della persona, salute e welfare della Regione Emilia-Romagna e con le altre Regioni.

https://www.key4biz.it/privacy-il-lavoro-di-lepida-come-dpo-della-regione-emilia-romagna/405975/




Tim Hortons coffee app broke law by constantly recording users’ movements

Outside view of a Tim Hortons restaurant in Toronto shows the Tim Hortons logo and a maple leaf.
Enlarge / A Tim Hortons in Toronto in May 2022.
Getty Images | Roberto Machado Noa

Canadian investigators determined that users of the Tim Hortons coffee chain’s mobile app “had their movements tracked and recorded every few minutes of every day,” even when the app wasn’t open, in violation of the country’s privacy laws.

“The Tim Hortons app asked for permission to access the mobile device’s geolocation functions but misled many users to believe information would only be accessed when the app was in use. In reality, the app tracked users as long as the device was on, continually collecting their location data,” according to an announcement Wednesday by Canada’s Office of the Privacy Commissioner. The federal office collaborated with provincial authorities in Quebec, British Columbia, and Alberta in the investigation of Tim Hortons.

“The app also used location data to infer where users lived, where they worked, and whether they were traveling,” the Office of the Privacy Commissioner said. “It generated an ‘event’ every time users entered or left a Tim Hortons competitor, a major sports venue, or their home or workplace.”

Tim Hortons scrapped plans to use the app for targeted advertising but “continued to collect vast amounts of location data” for another year “even though it had no legitimate need to do so,” the Office of the Privacy Commissioner said. Tim Hortons said it used aggregated location data “to analyze user trends—for example, whether users switched to other coffee chains, and how users’ movements changed as the pandemic took hold,” the federal office said.

“Inappropriate form of surveillance”

Canada Privacy Commissioner Daniel Therrien said, “Tim Hortons clearly crossed the line by amassing a huge amount of highly sensitive information about its customers. Following people’s movements every few minutes of every day was clearly an inappropriate form of surveillance.”

Tim Hortons has more than 5,100 stores in 13 countries. Most are in Canada, but there are more than 600 in the US, mostly in New York, Michigan, and Ohio.

Tim Hortons halted the continual tracking of users’ locations in 2020 after the government began investigating. But that “did not eliminate the risk of surveillance” because “Tim Hortons’ contract with an American third-party location services supplier contained language so vague and permissive that it would have allowed the company to sell ‘de-identified’ location data for its own purposes,” the Office of the Privacy Commissioner said. As the office noted, there “is a real risk that de-identified geolocation data could be re-identified.”

Tim Hortons agreed to implement the agencies’ recommendations but apparently will not face any punishment. The investigative report said that Tim Hortons’ commitments “will bring the company into compliance” with Canadian law and that “we therefore find this matter to be well-founded and conditionally resolved.” That’s the language used when an organization violates Canadian privacy laws but has “committed to implementing satisfactory corrective actions.”

The announcement said Tim Hortons agreed to “delete any remaining location data and direct third-party service providers to do the same,” implement a privacy program that “includes privacy impact assessments for the app and any other apps it launches,” implement “a process to ensure information collection is necessary and proportional to the privacy impacts identified,” and ensure “that privacy communications are consistent with, and adequately explain, app-related practices.” Tim Hortons also agreed to report back to the government with details on its compliance.

Reporter uncovered privacy violation

The investigation began after a June 2020 Financial Post report titled “Double-double tracking: How Tim Hortons knows where you sleep, work, and vacation.” Reporter James McLeod found that “Tim Hortons had recorded my longitude and latitude coordinates more than 2,700 times in less than five months, and not just when I was using the app,” even though the app “told customers that it tracks location ‘only when you have the app open.'”

Tim Hortons’ statement said, “In June 2020, we took immediate steps to improve how we communicate with guests about the data they share with us and began reviewing our privacy practices with external experts. Shortly thereafter, we proactively removed the geolocation technology outlined in the report from the Tims app. Data from this geolocation technology was never used for personalized marketing for individual guests. The very limited use of this data was on an aggregated, de-identified basis to study trends in our business—and the results did not contain personal information from any guests.”

Alberta Information and Privacy Commissioner Jill Clayton said the investigation provides “yet another example where an organization has not effectively notified customers about its practices. Tim Hortons’ customers did not have adequate information to consent to the location tracking that was actually occurring.”

https://arstechnica.com/?p=1857804




4 anni di GDPR. Il report di E-Lex sullo stato della data protection

Il GDPR ha compiuto 4 anni. Il 25 maggio 2018, infatti, entrava in vigore il Regolamento europeo che ha profondamente innovato il sistema della data protection, modificando radicalmente l’approccio alla protezione dei dati in Europa.

Per celebrare questo giorno, lo Studio Legale E-Lex, fondato dall’attuale componente del Collegio del Garante Guido Scorza e specializzato in diritto delle nuove tecnologie, ha pubblicato il Report che ripercorre le novità più interessanti degli ultimi dodici mesi: oltre 200 pagine di commento, che passano in rassegna le principali modifiche legislative e i provvedimenti di Garante Privacy e dell’European Data Protection Board (EDPB). Per il download del Rapporto vai al link “Un anno di Data Protection. Il report di E-Lex”.

Nel presentare il Report, Giovanni Maria Riccio, socio dello studio E-Lex, ha affermato: “Spesso, anche per noi esperti del settore può essere complesso riuscire a seguire tutto quello che succede. Per questo motivo, abbiamo pensato che potesse essere utile uno strumento agile, ma sistematico, che mettesse ordine e classificasse per macroaree alcuni dei temi di maggiore attualità”.

Il Report è suddiviso in 9 sezioni, che spaziano dai dati giudiziari e sensibili, alle attività delle pubbliche amministrazioni e all’utilizzo dei dati, spesso sanzionato dal Garante, per attività di marketing e telemarketing.

Particolare attenzione, nel Report, è riservata anche alle nuove tecnologie. Sono così esaminate le sanzioni che le diverse autorità garanti (in Italia, Svezia e Germania) hanno comminato a Clear View AI, l’app statunitense che ha raccolto decine di milioni di dati biometrici, resi pubblicamente accessibili su siti internet e social network, attraverso la tecnica del cosiddetto “web scraping”.

Le tecniche di acquisizione di dati biometrici sono una grandissima risorsa, ma al tempo stesso possono evocare scenari distopici”, ha dichiarato Adriana Peduto, socia di E-Lex. “Lo sviluppo costante di nuove tecnologie impone un’attenzione quotidiana, che deve condurre alla ricerca di un equilibrio tra diritti di impresa e ragioni dell’innovazione, da un lato, e diritti e libertà fondamentali dei cittadini, soprattutto dei più vulnerabili, dall’altro”.

La protezione dei dati, in un’economica globalizzata, non è però una questione esclusivamente nazionale. Non a caso una sezione del report prende in esame alcuni provvedimenti di altre autorità nazionali, tra cui quella del CNIL sui requisiti del DPO, e alcune modifiche legislative extracomunitarie, come la nuova legge cinese, che, pur riprendendo alcune soluzioni tipiche del GDPR (come la ripartizione tra titolare e responsabile e le basi giuridiche che legittimano il trattamento dei dati), continua ad assegnare allo Stato poteri molto invasivi di controllo sui dati dei cittadini. L’ottica transfrontaliera interessa anche la sezione sul trasferimento dei dati extra UE, tema attualissimo dopo la sentenza Schrems II della Corte di Giustizia, che ha invalidato gli accordi di trasferimento tra Europa e Stati Uniti, e la vicenda di Google Analytics che sta interessando in questi giorni le pubbliche amministrazioni italiane.

Per Ernesto Belisario, socio di E-Lex, “Si tratta di una vicenda sintomatica della scarsa attenzione che spesso le amministrazioni dedicano alla scelta dei propri fornitori, così come dimostrato dai tanti provvedimenti del Garante Privacy dell’ultimo anno che hanno avuto ad oggetto proprio l’attività dei responsabili del trattamento di enti pubblici”.

https://www.key4biz.it/4-anni-di-gdpr-il-report-di-e-lex-sullo-stato-della-data-protection/405183/




Trattamento dei dati: il Garante Privacy sanziona Uber per 4,2 milioni di euro

Due sanzioni di 2 milioni e 120mila euro ciascuna sono state comminate dal Garante privacy a Uber B.V. (UBV), con sede legale ad Amsterdam, e a Uber Technologies Inc (UTI), con sede legale a San Francisco, ritenute entrambe responsabili delle violazioni commesse nei confronti di oltre 1 milione e mezzo di utenti italiani, tra autisti e passeggeri.

Informativa inidonea, dati trattati senza consenso, mancata notificazione all’Autorità sono le violazioni riscontrate dal Garante nel corso di accertamenti ispettivi effettuati presso Uber Italy srl a seguito di un data breach reso pubblico dalla capofila statunitense nel 2017.

L’incidente di sicurezza, avvenuto prima della piena applicazione del Regolamento europeo (Gdpr), aveva coinvolto i dati di circa 57 milioni di utenti di tutto il mondo, ed era stato sanzionato dall’Autorità privacy olandese e da quella inglese sulla base delle rispettive normative nazionali.

Le informazioni personali trattate da Uber riguardavano i dati anagrafici e di contatto (nome, cognome, numero di telefono e e-mail), le credenziali di accesso all’app, dati di localizzazione (quelli che risultavano al momento della registrazione), le relazioni con altri utenti (condivisione di viaggi, presentazione di amici, informazioni di profilazione).

Con il provvedimento odierno l’Autorità sanziona dunque la società di diritto olandese Uber BV e la statunitense Uber Technologies, come contitolari del trattamento, ciascuna responsabile delle violazioni del Codice privacy commesse nei confronti degli utenti italiani.

Le sanzioni riguardano in particolare l’inidonea informativa resa agli utenti (in quanto priva dell’indicazione relativa alla contitolarità del trattamento) e “formulata in maniera generica e approssimativa” con “informazioni poco chiare e incomplete” e “di non facile comprensione”.

Nell’informativa, infatti, non erano ben specificate le finalità del trattamento, i riferimenti ai diritti degli interessati risultavano vaghi e lacunosi, e non era neppure chiaro se gli utenti fossero obbligati o meno a fornire i propri dati, né quali fossero le conseguenze di un eventuale diniego.

Uber, inoltre, senza aver acquisito un valido consenso, trattava i dati di circa 1.379.00 passeggeri profilandoli sulla base del cosiddetto “rischio frode”, assegnando loro un giudizio qualitativo (ad es., low) e un parametro numerico (da 1 a 100).

La multinazionale, infine, non aveva rispettato l’obbligo di notificare all’Autorità il trattamento di dati per finalità di geolocalizzazione, come previsto dalla normativa in vigore prima del nuovo Regolamento Ue.

Nel definire l’ammontare delle sanzioni, applicabile nella stessa misura di 2 milioni e 120mila euro sia a UBV che a UTI, l’Autorità, oltre alla gravità delle violazioni accertate, ha tenuto conto anche del rilevante numero di persone coinvolte e delle condizioni economiche della società.

https://www.key4biz.it/trattamento-dei-dati-il-garante-privacy-sanziona-uber-per-42-milioni-di-euro/404327/




Congresso Asso Dpo, “un must per esperti privacy”: 12 maggio a Milano e online

È online il programma dell’ottava edizione del congresso annuale internazionale Asso Dpo, “diventato un must per chi si occupa di data protection in Italia”, raccontano gli organizzatori: l’Associazione Data Protection Officer, guidata da Matteo Colombo.

Il focus: nuove norme privacy in Italia e all’estero e cybersecurity

I principali DPO di multinazionali e pubbliche amministrazioni in Italia e in Europa, il Garante Privacy italiano ed europeo, le Autorità Garanti del resto del mondo, Associazioni privacy europee, professori universitari, esperti in cybersecurity e tutti gli stakeholder europei sulla protezione dei dati. Saranno questi i relatori dell’edizione, che si terrà il 12 maggio prossimo. 

I temi di questa edizione? Presentare, in modo approfondito, ai partecipanti sia le nuove norme europee in fase di discussione sulla data protection, che affiancheranno il GDPR, come il Data Act, sia far conoscere agli esperti privacy italiani le norme internazionali sulla protezione dei dati. Ampio spazio anche ai temi di attualità, come l’utilizzo dell’intelligenza artificiale in ambito privacy. E poi i DPO racconteranno la propria vita da Data Protection Officer, per scoprire come stanno organizzando l’agenda lavorativa.

Il programma e come registrarsi per seguirlo onsite o online

Il Congresso si svolgerà nella modalità ibrida: in presenza, a Milano al Palazzo delle Stelline, e da remoto. Di seguito il programma del Congresso e qui le informazioni su come registrarsi a pagamento per seguirlo onsite o online.

WELCOME COFFEE

REGISTRAZIONE PARTECIPANTI

10:00 / 10:15

SALUTI ISTITUZIONALI E PRESENTAZIONE

Matteo Colombo, Presidente di ASSO DPO 

10:15 / 10:35

KEYNOTE SPEAKER

Claudio Filippi, Vicesegretario generale, Garante per la protezione dei dati, Italia

Intervista: Raffaele Barberio, Presidente Privacy Italia

10:35 / 10:45

SESSIONE I: ASSO DPO ON AIR 2022

Massimo Giuriati, Vice Presidente ASSO DPO

10:45 / 11:05

COOKIE & E-PRIVACY: LA GESTIONE DEL BANNER TRA DEFINIZIONI TECNICHE E IL RUOLO DELLE TERZE PARTI COINVOLTE

Sponsored by: PRIVACY LAB

Andrea Chiozzi, CEO PrivacyLab

11:05 / 11:25

SESSIONE II: CYBERSECURITY

Intervista: Marco Armoni, Esperto in cyber security e Coordinatore Gruppo Cyber Security, Comitato Scientifico ASSO DPO 

11:25 / 11:40

SESSIONE SPONSOR

Sponsored by: ONE TRUST

Andrea Rossi, Senior Solution Engineer, One Trust | “Prova valida del consenso: come coltivare la fiducia e dimostrare la conformità”

11:40 / 12:00

SESSIONE III: NEW EUROPEAN LEGISLATION ON DATA 

Cecilia Àlvarez, EMEA Privacy Policy Director, Facebook

Intervista: Paul Jordan, Professional Advisory, Representation, Government, Regulatory & Industry Affair, all things data strategy & governance

12:00 / 13:00

SESSIONE IV: ATTIVITÀ ISPETTIVE IN UNIONE EUROPEA

Sponsored by: DELOITTE

Marco Menegazzo, Comandante del Gruppo Privacy del “Nucleo Speciale Tutela Privacy e Frodi Tecnologiche”

Alexandra Jaspar, Director Risk Advisory, Data Protection & Privacy, Deloitte

Dieter Kugelmann, State Commissioner at Rhineland, Palatinate. DHPol

Intervista: Anna Pouliou, Partner Deloitte, Coordinatore Gruppo Internazionale, Comitato Scientifico ASSO DPO

13:00 / 14:00

LUNCH TIME

14:00 / 14:20

KEYNOTE SPEAKER

Bojana Bellamy, Presidente di Hunton Andrews Kurth LLP’s CIPL

Intervista: Paul Jordan, Professional Advisory, Representation, Government, Regulatory & Industry Affair, all things data strategy & governance

14:20 / 15:00

SESSIONE V: EUROPEAN DIGITAL SOVEREIGNTY AND INNOVATION: IMPACTS ON DATA PROTECTION AND PRIVACY

EDPS, European Data Protection Supervisor

European Commission

Intervista: Nicola Fabiano, Avvocato, Già Garante Repubblica di San Marino, Cybersecurity, IoT, Blockchain Lawyer

15:00 / 16:00

SESSIONE VI: TEMATICHE PRIVACY IN SANITÀ

Helga Porisdottir, Data Protection Commissioner, Islanda

Baroum Mrad Georgis, DPO Responsabile Servizio protezione dati e privacy, Ente Ospedaliero Cantonale Ticino, Svizzera

Silvia Melchionna, Funzionario GPDP Area direttiva Settore Sanità

Intervista: Nadia Arnaboldi, Comitato Direttivo ASSO DPO

16:00 / 16:15

COFFEE BREAK

16:15 / 16:30

SESSIONE SPONSOR

16:30 / 17:30

SESSIONE VII: NUOVE SFIDE PER IL DPO: L’INTELLIGENZA ARTIFICIALE E LA TUTELA DELLA PERSONA ALLA LUCE DEI REGOLAMENTI

Carmelo Fontana, Senior Regional Counsel, Google

Giovanni Ziccardi, Professore Associato Informatica Giuridica, Università Milano

Massimiliano Pappalardo, Partner Studio Legale Ughi e Nunziante, CIPP/E

Intervista: Rodolfo Mecarelli, Comitato Scientifico ASSO DPO

17:30 / 19:30

Aperitivo Conclusivo – Network Event

https://www.key4biz.it/congresso-asso-dpo-un-must-per-esperti-privacy-12-maggio-a-milano-e-online/400039/