{"id":2884,"date":"2011-04-13T20:28:17","date_gmt":"2011-04-13T20:28:17","guid":{"rendered":"http:\/\/www.thesocialcmo.com\/blog\/?p=2884"},"modified":"2011-04-13T20:37:11","modified_gmt":"2011-04-13T20:37:11","slug":"what-you-should-know-about-the-eus-new-internet-of-things-privacy-framework","status":"publish","type":"post","link":"https:\/\/www.thesocialcmo.com\/blog\/2011\/04\/what-you-should-know-about-the-eus-new-internet-of-things-privacy-framework\/","title":{"rendered":"What You Should Know About the EU&#8217;s New &#8220;Internet of Things&#8221; Privacy Framework"},"content":{"rendered":"<p>To many, <a href=\"http:\/\/en.wikipedia.org\/wiki\/Internet_of_Things\"><strong>&#8220;The Internet of Things,&#8221;<\/strong><\/a> a predicted, transformative moment in time when nearly all \u201cthings\u201d in the physical world will be interconnected,  wirelessly, with communication capabilities linking the physical and  virtual worlds for a variety of cooperative applications, is a distant  point in the future.\u00a0 To others, the internet of things is now.<\/p>\n<p><object style=\"height: 351px; width: 432px\"><param name=\"movie\" value=\"http:\/\/www.youtube.com\/v\/eob532iEpqk?version=3\"><param name=\"allowFullScreen\" value=\"true\"><param name=\"allowScriptAccess\" value=\"always\"><embed src=\"http:\/\/www.youtube.com\/v\/eob532iEpqk?version=3\" type=\"application\/x-shockwave-flash\" allowfullscreen=\"true\" allowScriptAccess=\"always\" width=\"432\" height=\"351\"><\/object><\/p>\n<p><strong><em> <\/em><\/strong><\/p>\n<h2><span style=\"color: #ff0000;\"><strong>RFID &#8220;Smart Tags&#8221; Connecting <\/strong><\/span><\/h2>\n<h2><span style=\"color: #ff0000;\"><strong>Physical Things to Virtual Things<\/strong><\/span><\/h2>\n<p><span style=\"color: #ff0000;\"><strong><br \/>\n<\/strong><\/span><\/p>\n<p><a href=\"http:\/\/en.wikipedia.org\/wiki\/Radio-frequency_identification\"><strong>Radio-frequency identification technology (RFID)<\/strong><\/a>,  a technology that uses &#8220;smart tags&#8221;, tags with\u00a0microchips,\u00a0to provide  information to a virtual network, is considered to be a primary  technology in advancing &#8220;the internet of things.&#8221;\u00a0 In 2011, RFID revenue  is expected to exceed<strong> <\/strong><a href=\"http:\/\/rfid-alert.com\/rfid-revenue-to-exceed-6-billion\/\"><strong>$6 billion, <\/strong><\/a> with\u00a0<a href=\"http:\/\/www.ubergizmo.com\/2011\/02\/item-level-rfid-tags-get-support-from-major-retailer\/\"><strong>more than 750 million so-called &#8220;item-level&#8221; RFID tags<\/strong> <\/a> used in global apparel markets alone.\u00a0 In Europe, about <a href=\"http:\/\/europa.eu\/rapid\/pressReleasesAction.do?reference=IP\/11\/418&amp;format=HTML&amp;aged=0&amp;language=en&amp;guiLanguage=en\"><strong>one billion &#8220;smart tags&#8221;<\/strong><\/a> are expected to be used in 2011, linking many &#8220;things&#8221; to the virtual world.<!--more--><\/p>\n<p><object style=\"height: 351px; width: 432px;\" classid=\"clsid:d27cdb6e-ae6d-11cf-96b8-444553540000\" width=\"100\" height=\"100\" codebase=\"http:\/\/download.macromedia.com\/pub\/shockwave\/cabs\/flash\/swflash.cab#version=6,0,40,0\"><param name=\"allowFullScreen\" value=\"true\" \/><param name=\"allowScriptAccess\" value=\"always\" \/><param name=\"src\" value=\"http:\/\/www.youtube.com\/v\/sfEbMV295Kk?version=3\" \/><param name=\"allowfullscreen\" value=\"true\" \/><embed style=\"height: 351px; width: 432px;\" type=\"application\/x-shockwave-flash\" width=\"100\" height=\"100\" src=\"http:\/\/www.youtube.com\/v\/sfEbMV295Kk?version=3\" allowscriptaccess=\"always\" allowfullscreen=\"true\"><\/embed><\/object><\/p>\n<p>The <a href=\"http:\/\/europa.eu\/index_en.htm\"><strong>European Union (EU)<\/strong><\/a>,  representing twenty-seven member states, has expressed grave concerns  about the privacy implications of an unregulated internet and unchecked  technology.<\/p>\n<p><object style=\"height: 351px; width: 432px\"><param name=\"movie\" value=\"http:\/\/www.youtube.com\/v\/S0PeNFi7Bpw?version=3\"><param name=\"allowFullScreen\" value=\"true\"><param name=\"allowScriptAccess\" value=\"always\"><embed src=\"http:\/\/www.youtube.com\/v\/S0PeNFi7Bpw?version=3\" type=\"application\/x-shockwave-flash\" allowfullscreen=\"true\" allowScriptAccess=\"always\" width=\"432\" height=\"351\"><\/object><\/p>\n<p>Responding to the privacy concerns  it perceived as being presented by the &#8220;the Internet of Things&#8221;, the  EU, in 2009,\u00a0adopted a fourteen-point strategic plan of action:<\/p>\n<h2><span style=\"color: #ff0000;\"><strong>EU&#8217;s 2009 Internet of Things: <\/strong><\/span><\/h2>\n<h2><span style=\"color: #ff0000;\"><strong>14-point Strategic Action Plan<\/strong><\/span><\/h2>\n<p><strong>1.\u00a0 Governance.<\/strong> The Commission will work on the definition of a set of principles  underlying the governance of the Internet of Things and the design of  an architecture endowed with a sufficient level of decentralised  management.<\/p>\n<p><strong>2.\u00a0 Privacy and data protection.<\/strong> The Commission will observe carefully the application of data protection legislation to the Internet of Things.<\/p>\n<p><strong>3.\u00a0 The right to the &#8220;silence of the chips&#8221;.<\/strong> The  Commission will launch a debate about whether individuals should be able  to disconnect from their networked environment at any moment. Citizens  should be able to read basic RFID (Radio Frequency Identification  Devices) tags \u2013 and destroy them too \u2013 to preserve their privacy. Such  rights are likely to become more important as RFID and other wireless  technologies become small enough to be invisible.<\/p>\n<p><strong>4.\u00a0 Emerging risks.<\/strong> The Commission will take effective action to enable the Internet of  Things to meet challenges related to trust, acceptance and security.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>5.\u00a0 Vital resource.<\/strong> In connection with its activities on the protection of critical  information infrastructures, the Commission will closely follow the  development of the Internet of Things into a vital resource for Europe.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>6.\u00a0 Standardisation. <\/strong>The Commission will, if necessary, launch additional standardisation mandates related to the Internet of Things.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>7.\u00a0 Research.<\/strong> The Commission will continue to finance collaborative research projects  in the area of the Internet of Things through the 7 th Framework  Programme.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>8.\u00a0 Public Private Partnership.<\/strong> The Commission will integrate, as adequate, the Internet of Things in  the four research and development public-private partnerships that are  being prepared.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>9.\u00a0 Innovation.<\/strong> The Commission will launch pilot projects to promote the readiness of  EU organisations to effectively deploy marketable, interoperable, secure  and privacy-aware Internet of Things applications.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>10.\u00a0 Institutional awareness.<\/strong> The Commission will regularly inform the European Parliament and the Council about Internet of Things developments.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>11.\u00a0 International dialogue.<\/strong> The Commission will intensify the dialogue on the Internet of Things  with its international partners to share information and good practices  and agree on relevant joint actions.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>12.\u00a0 Environment.<\/strong> The Commission will assess the difficulties of recycling RFID tags as  well as the benefits that the presence of these tags can have on the  recycling of objects.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>13.\u00a0 Statistics.<\/strong> Eurostat will start publishing statistics on the use of RFID technologies in December 2009<br \/>\n<strong> <\/strong><\/p>\n<p><strong>14.\u00a0 Evolution.<\/strong> The Commission will gather a representative set of European stakeholders to monitor the evolution of the Internet of Things.<br \/>\n<strong> <\/strong><\/p>\n<h2><span style=\"color: #ff0000;\"><strong>The &#8220;Internet of Things&#8221; Privacy Framework\ufeff<\/strong><\/span><\/h2>\n<p>Completing the promise of their earlier action plan, the EU and private stakeholders, with a simple, two-page\u00a0<a href=\"http:\/\/ec.europa.eu\/information_society\/policy\/rfid\/documents\/rfidpiapressrelease.pdf\"><strong>press release<\/strong><\/a> and signing ceremony in Brussels, on April 6, 2011, announced that they had\u00a0established of a voluntary <a href=\"http:\/\/ec.europa.eu\/information_society\/policy\/rfid\/documents\/infso-2011-00068.pdf\"><strong>Privacy and Data Protection Impact Assessment Framework for RFID Applications<\/strong><\/a>&#8220;, dubbed the<strong> <\/strong><a href=\"http:\/\/www.nytimes.com\/external\/readwriteweb\/2011\/04\/07\/07readwriteweb-european-union-signs-internet-of-things-priva-509.html?partner=rss&amp;emc=rss&amp;pagewanted=print\"><strong> &#8220;Internet of Things Privacy Framework&#8221;<\/strong><\/a> by the New York Times.\u00a0 Specifically, the framework establishes  \u201cguidelines for all companies in Europe to address the data protection  implications of smart tags (Radio Frequency Identification Devices \u2013  RFID) prior to placing them on the market.\u201d<br \/>\n<strong> <\/strong><\/p>\n<p><strong>At the signing ceremony,<\/strong> one industry representative observed, \u201cData protection authorities  sometimes seem to be one-track minded and force compliance with data  protection rules\u2026.Today, we have overcome this very unfruitful  deadlock\u2026.\u201d Despite the fanfare of many signatures, the framework is  voluntary, with no express auditing mechanisms, though record-keeping  procedures are outlined, and no defined penalties for non-compliance.<br \/>\n<strong> <\/strong><\/p>\n<p><strong>Coincidentally, the announcement of the EU\u2019s voluntary framework<\/strong> came within one week of the release of a\u00a0<a href=\"http:\/\/repository.cmu.edu\/cgi\/viewcontent.cgi?article=1081&amp;context=cylab&amp;sei-redir=1#search=%22carnegies+mellon+behavioral+advertising+2011%22\"><strong>report<\/strong><\/a> by Carnegie Mellon University showing \u201clagging compliance\u201d with U.S.  industry self-regulation in online behavioral advertising.<br \/>\n<strong> <\/strong><\/p>\n<h2><span style=\"color: #ff0000;\"><strong>Four-step Privacy Impact Assessment (PIA) <\/strong><\/span><strong> <\/strong><\/h2>\n<p>Under the  Commission\u2019s framework, RFID operators would be required to complete a  four-step Privacy Impact Assessment (PIA) process prior to introducing a  new RFID application into the market:<br \/>\n1. Describe the RFID Application;<\/p>\n<p>2. Identify and  list how the RFID Application under review could threaten privacy and  estimate the magnitude and likelihood of those risks;<br \/>\n3. Document current and proposed technical and organisational controls to mitigate\u00a0identified risks; and<br \/>\n4. Document the resolution (results of the analysis) regarding the Application.<\/p>\n<h2><span style=\"color: #ff0000;\"><strong>Let the Internet of Things Begin!<\/strong><\/span><\/h2>\n<p><strong><img loading=\"lazy\" decoding=\"async\" class=\"alignleft\" title=\"chip\" src=\"http:\/\/3.bp.blogspot.com\/-aH_K9JWMLdM\/TaNKivHuXYI\/AAAAAAAAAYI\/PXG1CUVtA80\/s1600\/computerchipgreen.jpg\" alt=\"\" width=\"100\" height=\"67\" \/>So what is the most significant impact of the framework? Privacy? Perhaps not.<\/strong> Instead, the real significance of the framework may have been captured  in an observation made in the official press release from the signing,  namely, that the framework will give the business sector the \u201clegal  certainty that the use of their tags is compatible with European privacy  legislation.\u201d In other words, the framework gives private stakeholders  the green light to continue full-steam ahead with their already massive  investment in RFID technologies and the \u201cinternet of things\u201d it heralds.<\/p>\n<p><strong>Why might industry leaders have been concerned about limitations on RFID technologies?<\/strong> The EU has also just reaffirmed its commitment to<strong> <\/strong><a href=\"http:\/\/www.euractiv.com\/en\/infosociety\/reding-defines-new-eu-data-privacy-rules-news-503172\"><strong>&#8220;Privacy by Default&#8221;<\/strong><\/a> as  the core of its data protection laws.\u00a0 So Europeans are now given &#8220;the  right to be forgotten&#8221; online and the right to be remembered in real  life&#8230;<br \/>\n<strong> <\/strong><\/p>\n<h2><span style=\"color: #ff0000;\"><strong>The Internet of Things?<\/strong><\/span><\/h2>\n<p>The EU Commission website provides an example to illuminate the \u201cinternet of things\u201d:<br \/>\n<em> <\/em><\/p>\n<p><em><img loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"suitcase\" src=\"http:\/\/1.bp.blogspot.com\/-yMwoa-Ed3ls\/TaNIvUS5XzI\/AAAAAAAAAYA\/Z-CSvauiwsM\/s200\/luggage.jpg\" alt=\"\" width=\"200\" height=\"152\" \/>Take  one example: a suitcase itself can indicate which plane it should be  sent to. This is possible thanks to Radio Frequency Identification  (RFID). With RFID, more and more objects communicate with each other,  slowly creating a network of information, a so-called \u2018internet of  things\u201d.<\/em><br \/>\n<em> <\/em><\/p>\n<p><em>This  network could potentially make our lives much easier\u2026No need to worry  about your suitcase being sent to the wrong plane anymore! But we must  also be careful how we use it, and avoid certain pitfalls. <\/em><\/p>\n<h2><span style=\"color: #ff0000;\"><strong>Thanks! Your pants just told us where you are.<\/strong><\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft\" title=\"tower\" src=\"http:\/\/2.bp.blogspot.com\/-fqdhGUqn_PY\/TaNJz58z43I\/AAAAAAAAAYE\/UROsBgpgV3E\/s200\/antennae.jpg\" alt=\"\" width=\"150\" height=\"200\" \/>Worried that your smart phone is broadcasting your whereabouts?<br \/>\nYour pants may be doing the same.<br \/>\nWhat sort of privacy concerns are raised by RFID tags?<\/p>\n<p>According to the  commission, one concern the new Framework seeks to address is \u201cthe  possibility of a third party accessing your personal data (e.g.,  concerning your location) without your permission.\u201d How could that  happen? Well, the pants you just bought might come with a small, RFID  tag that has an \u201celectronic memory that is readable and perhaps  writable, and antennae.\u201d<br \/>\n<strong> <\/strong><\/p>\n<h2><span style=\"color: #ff0000;\"><strong>The U.S. Approach<\/strong><\/span><\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft\" title=\"usa\" src=\"http:\/\/1.bp.blogspot.com\/-A83r1TDmpzs\/TaNHZspX0zI\/AAAAAAAAAX8\/7m3soeMqqTQ\/s1600\/ftc.bmp\" alt=\"\" width=\"225\" height=\"225\" \/>Ever lagging behind the EU\u2019s privacy initiatives, the U.S., in a<strong> <\/strong><a href=\"http:\/\/www.ftc.gov\/oia\/commentsrfid.pdf\"><strong>staff report<\/strong> <\/a>from the <a href=\"http:\/\/ftc.gov\/ftc\/about.shtm\"><strong>Federal Trade Commission (FTC) <\/strong><\/a>concluded:<br \/>\n<em><strong> <\/strong><\/em><\/p>\n<p><em><strong>The FTC staff also agrees with the EC that there is a need to raise consumer awareness about RFID technology<\/strong>,  in order to enhance consumer trust and to give consumers the tools to  protect themselves from the risk of misuse of their information. Given  the current stage of deployment of consumer-facing RFID applications, <strong>however,  the FTC believes that mandating or encouraging specific technological  tools for protecting consumer privacy is premature.<\/strong><\/em><br \/>\n<strong>How Will the Internet of Things Be Social?<\/strong><\/p>\n<p>The  New York Marathon provides a great example of how the &#8220;internet of  things&#8221; will interact with the virtual world and integrate with social\ufeff:<\/p>\n<p><object style=\"height: 351px; width: 432px;\" classid=\"clsid:d27cdb6e-ae6d-11cf-96b8-444553540000\" width=\"100\" height=\"100\" codebase=\"http:\/\/download.macromedia.com\/pub\/shockwave\/cabs\/flash\/swflash.cab#version=6,0,40,0\"><param name=\"allowFullScreen\" value=\"true\" \/><param name=\"allowScriptAccess\" value=\"always\" \/><param name=\"src\" value=\"http:\/\/www.youtube.com\/v\/SnrzClsOlyU?version=3\" \/><param name=\"allowfullscreen\" value=\"true\" \/><embed style=\"height: 351px; width: 432px;\" type=\"application\/x-shockwave-flash\" width=\"100\" height=\"100\" src=\"http:\/\/www.youtube.com\/v\/SnrzClsOlyU?version=3\" allowscriptaccess=\"always\" allowfullscreen=\"true\"><\/embed><\/object><\/p>\n<p><strong>What are your thoughts?<\/strong> Please let me know!<\/p>\n<p>Glen Gilmore<\/p>\n<p>Please join me on Twitter:\u00a0 <a href=\"http:\/\/twitter.com\/GlenGilmore\"><strong>@GlenGilmore<\/strong><\/a> and <a href=\"http:\/\/twitter.com\/SocialMediaLaw1\"><strong>@SocialMediaLaw1<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>To many, &#8220;The Internet of Things,&#8221; a predicted, transformative moment in time when nearly all \u201cthings\u201d in the physical world will be interconnected, wirelessly, with communication capabilities linking the physical and virtual worlds for a variety of cooperative applications, is a distant point in the future.\u00a0 To others, the internet of things is now. RFID &#8230; <a class=\"read-more\" href=\"https:\/\/www.thesocialcmo.com\/blog\/2011\/04\/what-you-should-know-about-the-eus-new-internet-of-things-privacy-framework\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[137,85],"tags":[293,1197,1200,1199,1196,1198],"class_list":["post-2884","post","type-post","status-publish","format-standard","hentry","category-all-posts","category-glengilmore","tag-connectivity","tag-internet-of-things","tag-kill-chips","tag-privacy","tag-rfid","tag-sensors"],"_links":{"self":[{"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/posts\/2884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/comments?post=2884"}],"version-history":[{"count":11,"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/posts\/2884\/revisions"}],"predecessor-version":[{"id":2895,"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/posts\/2884\/revisions\/2895"}],"wp:attachment":[{"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/media?parent=2884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/categories?post=2884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesocialcmo.com\/blog\/wp-json\/wp\/v2\/tags?post=2884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}