<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Search Results for &#8220;ABC&#8221; &#8211; Australian Privacy Foundation</title>
	<atom:link href="https://privacy.org.au/search/ABC/feed/rss2/" rel="self" type="application/rss+xml" />
	<link>https://privacy.org.au</link>
	<description>Defending your right to be free from intrusion</description>
	<lastBuildDate>Sat, 04 May 2024 06:15:29 +0000</lastBuildDate>
	<language>en-AU</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://privacy.org.au/wp-content/uploads/2021/04/cropped-logo_horizontal2-32x32.png</url>
	<title>Search Results for &#8220;ABC&#8221; &#8211; Australian Privacy Foundation</title>
	<link>https://privacy.org.au</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>APF Newsletter – 4 May 2024</title>
		<link>https://privacy.org.au/2024/05/04/apf-newsletter-4-may-2024/</link>
		
		<dc:creator><![CDATA[Roger Clarke]]></dc:creator>
		<pubDate>Sat, 04 May 2024 06:15:29 +0000</pubDate>
				<category><![CDATA[Newsletter]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5358</guid>

					<description><![CDATA[The Australian Privacy Foundation Newsletter of 4 May 2024 APF Board members continue their efforts to influence policy in privacy-sensitive ways. The load continues to be high, and we need more contributors. That way we can deepen, but also to diversify, the insights that we bring to environmental scanning, evidence-gathering, analysis and the presentation of&#8230; <span class="excerpt-more"><a href="https://privacy.org.au/2024/05/04/apf-newsletter-4-may-2024/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "DTD/xhtml1-transitional.dtd">
<html>
<head>
<!--  .................. ASK PHP TO INSERT STYLES FILE ............... -->
<?php include("/customer/http/business/privacy.org.au/Library/stylescall.php"); ?>
<title>The Australian Privacy Foundation</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />

<!-- comment this in and out during DW editing to show format ...
<link href="/customer/http/business/privacy.org.au/Library/Styles/default.css" rel="stylesheet" type="text/css" /> -->

</head>

<body>

<!-- ............... ASK PHP TO INSERT HEADER ................. -->

<?php $headertext = 'Newsletter - 4 May 2024'; ?>

<?php include("/customer/http/business/privacy.org.au/Library/header.txt"); ?>

<!-- ............... ASK PHP TO INSERT NAVIGATION BAR ................ -->
<?php include("/customer/http/business/privacy.org.au/Library/navbar.txt"); ?>


<!-- ........................  BODY  .............................. -->

<h3 align="center">Newsletter of 4 May 2024</h3>
<hr />

<p>APF Board members continue their efforts to influence policy in privacy-sensitive ways.

<p>The load continues to be high, and we need more contributors.  That way we can deepen, but also to diversify, the insights that we bring to environmental scanning, evidence-gathering, analysis and the presentation of arguments.

<p>This Newsletter features an invitation to participate in a privacy-relevant focus group, and APF media media activity in the health area and in relation to cars and privacy.

<hr>

<p>The Board is currently considering a draft Policy Statement by a contributor on '<b>Privacy and Promiscuous Motor Vehicles</b>'.

<p>Two recent articles quote APF Board Chair David and another active member, Katharine:
<ul>
<li><a href="https://www.abc.net.au/news/2024-02-09/toyota-car-brands-collecting-driver-data-privacy-concerns-laws/103443500" rel="noopener" target="_blank">Toyota and Driver Data Privacy Concerns</a>
<li><a href="https://theconversation.com/cars-are-a-privacy-nightmare-on-wheels-heres-how-they-get-away-with-collecting-and-sharing-your-data-214386" rel="noopener" target="_blank">Cars Are A Privacy Nightmare on Wheels</a>
</ul>
<p>Another Board member and past Chair of APF's Health Committee, Bernard, was quoted at length on <a href="https://www.rollingstone.com/culture/culture-features/ai-health-care-patient-safety-privacy-1235006118/" rel="noopener" target="_blank">"The AI Healthcare Boom"</a>.

<p>And the current Chair, Juanita, has very recently finalised a <a href="https://privacy.org.au/wp-content/uploads/2024/05/OAIC-NationalHlthPrivRules-240501.pdf" rel="noopener" target="_blank">Submission on the National Health (Privacy) Rules</a> to the (still anti-privacy) OAIC.
<hr>
<p>APF has been approached by researchers well-known to APF Board-members, requesting that we draw to APF members' attention a project that the researchers are conducting.
<p><b>The project aims to understand how 'communication' is understood by diverse consumers, with the view to better inform the regulation of digital communications technologies</b>.
<p>The project is funded by ACCAN and conducted by researchers from Deakin University and the Victorian University of Wellington.
<p>Participation will involve an approximately 90-minute focus group and seeks a wide range of consumer perspectives to discuss the concept of communication. Auslan interpreters are available for the focus groups where needed.
<p>Please note participation is voluntary and there is no obligation to participate.
<p>If you decide not to participate there will be no impact on you or your relationship with the researchers or Deakin University, Victorian University of Wellington or ACCAN. Participants will receive a $50 gift card to compensate their time and must be Australian, 18 years or older and speak English.
<p>Details are available as follows:
<ul>
<li><a href="https://privacy.org.au/wp-content/uploads/2024/05/A4Flyer-DefComm-240504.pdf" rel="noopener" target="_blank">A4 recruitment flyer</a></li>
<li><a href="https://privacy.org.au/wp-content/uploads/2024/05/A6Flyer-DefComm-240504.pdf" rel="noopener" target="_blank">A6 recruitment flyer</a></li>
<li><a href="https://privacy.org.au/wp-content/uploads/2024/05/StmtAndForm-DefComm-240504.docx" rel="noopener" target="_blank">Focus Group Plain Language Statement and Consent Form</a></li>
</ul>

<p>If you are interested, please scan the QR code on one of the flyers to fill out a Qualtrics survey to participate, or return the signed consent form via email to: definingcomm@deakin.edu.au
<p>[This study has received Deakin university ethics approval (2023-293)]
<p>Roger Clarke, as APF Secretary
<hr />

<?php
$footertext = 'http://www.privacy.org.au/Directory/Page.html';
$created = '4 May 2024';
// $verify_date is set at folder level in verification_date.txt
?>

<?php //LAST AMENDED BY SECTION - COMMENT OUT OLD PERSON AND DATE AND ADD IN YOURS BELOW
//$lastperson='Last person'; $lastamended = '24 January 2010';
$lastperson='Roger Clarke'; $lastamended = '4 May 2024';
?>

<!-- ............... ASK PHP TO INSERT FOOTER FILE ................... -->
<?php include("/customer/http/business/privacy.org.au/Library/footer.txt"); ?>

</body></html>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>APF Newsletter – 4 May 2024</title>
		<link>https://privacy.org.au/apf-newsletter-4-may-2024/</link>
		
		<dc:creator><![CDATA[Roger Clarke]]></dc:creator>
		<pubDate>Sat, 04 May 2024 06:09:32 +0000</pubDate>
				<guid isPermaLink="false">https://privacy.org.au/?page_id=5350</guid>

					<description><![CDATA[The Australian Privacy Foundation Newsletter of 4 May 2024 APF Board members continue their efforts to influence policy in privacy-sensitive ways. The load continues to be high, and we need more contributors. That way we can deepen, but also to diversify, the insights that we bring to environmental scanning, evidence-gathering, analysis and the presentation of&#8230; <span class="excerpt-more"><a href="https://privacy.org.au/apf-newsletter-4-may-2024/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "DTD/xhtml1-transitional.dtd">
<html>
<head>
<!--  .................. ASK PHP TO INSERT STYLES FILE ............... -->
<?php include("/customer/http/business/privacy.org.au/Library/stylescall.php"); ?>
<title>The Australian Privacy Foundation</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" />

<!-- comment this in and out during DW editing to show format ...
<link href="/customer/http/business/privacy.org.au/Library/Styles/default.css" rel="stylesheet" type="text/css" /> -->

</head>

<body>

<!-- ............... ASK PHP TO INSERT HEADER ................. -->

<?php $headertext = 'Newsletter - 4 May 2024'; ?>

<?php include("/customer/http/business/privacy.org.au/Library/header.txt"); ?>

<!-- ............... ASK PHP TO INSERT NAVIGATION BAR ................ -->
<?php include("/customer/http/business/privacy.org.au/Library/navbar.txt"); ?>


<!-- ........................  BODY  .............................. -->

<h3 align="center">Newsletter of 4 May 2024</h3>
<hr />

<p>APF Board members continue their efforts to influence policy in privacy-sensitive ways.

<p>The load continues to be high, and we need more contributors.  That way we can deepen, but also to diversify, the insights that we bring to environmental scanning, evidence-gathering, analysis and the presentation of arguments.

<p>This Newsletter features an invitation to participate in a privacy-relevant focus group, and APF media media activity in the health area and in relation to cars and privacy.

<hr>

<p>The Board is currently considering a draft Policy Statement by a contributor on '<b>Privacy and Promiscuous Motor Vehicles</b>'.

<p>Two recent articles quote APF Board Chair David and another active member, Katharine:
<ul>
<li><a href="https://www.abc.net.au/news/2024-02-09/toyota-car-brands-collecting-driver-data-privacy-concerns-laws/103443500" rel="noopener" target="_blank">Toyota and Driver Data Privacy Concerns</a>
<li><a href="https://theconversation.com/cars-are-a-privacy-nightmare-on-wheels-heres-how-they-get-away-with-collecting-and-sharing-your-data-214386" rel="noopener" target="_blank">Cars Are A Privacy Nightmare on Wheels</a>
</ul>
<p>Another Board member and past Chair of APF's Health Committee, Bernard, was quoted at length on <a href="https://www.rollingstone.com/culture/culture-features/ai-health-care-patient-safety-privacy-1235006118/" rel="noopener" target="_blank">"The AI Healthcare Boom"</a>.

<p>And the current Chair, Juanita, has very recently finalised a <a href="https://privacy.org.au/wp-content/uploads/2024/05/OAIC-NationalHlthPrivRules-240501.pdf" rel="noopener" target="_blank">Submission on the National Health (Privacy) Rules</a> to the (still anti-privacy) OAIC.
<hr>
<p>APF has been approached by researchers well-known to APF Board-members, requesting that we draw to APF members' attention a project that the researchers are conducting.
<p><b>The project aims to understand how 'communication' is understood by diverse consumers, with the view to better inform the regulation of digital communications technologies</b>.
<p>The project is funded by ACCAN and conducted by researchers from Deakin University and the Victorian University of Wellington.
<p>Participation will involve an approximately 90-minute focus group and seeks a wide range of consumer perspectives to discuss the concept of communication. Auslan interpreters are available for the focus groups where needed.
<p>Please note participation is voluntary and there is no obligation to participate.
<p>If you decide not to participate there will be no impact on you or your relationship with the researchers or Deakin University, Victorian University of Wellington or ACCAN. Participants will receive a $50 gift card to compensate their time and must be Australian, 18 years or older and speak English.
<p>Details are available as follows:
<ul>
<li><a href="https://privacy.org.au/wp-content/uploads/2024/05/A4Flyer-DefComm-240504.pdf" rel="noopener" target="_blank">A4 recruitment flyer</a></li>
<li><a href="https://privacy.org.au/wp-content/uploads/2024/05/A6Flyer-DefComm-240504.pdf" rel="noopener" target="_blank">A6 recruitment flyer</a></li>
<li><a href="https://privacy.org.au/wp-content/uploads/2024/05/StmtAndForm-DefComm-240504.docx" rel="noopener" target="_blank">Focus Group Plain Language Statement and Consent Form</a></li>
</ul>

<p>If you are interested, please scan the QR code on one of the flyers to fill out a Qualtrics survey to participate, or return the signed consent form via email to: definingcomm@deakin.edu.au
<p>[This study has received Deakin university ethics approval (2023-293)]
<p>Roger Clarke, as APF Secretary
<hr />

<?php
$footertext = 'http://www.privacy.org.au/Directory/Page.html';
$created = '4 May 2024';
// $verify_date is set at folder level in verification_date.txt
?>

<?php //LAST AMENDED BY SECTION - COMMENT OUT OLD PERSON AND DATE AND ADD IN YOURS BELOW
//$lastperson='Last person'; $lastamended = '24 January 2010';
$lastperson='Roger Clarke'; $lastamended = '4 May 2024';
?>

<!-- ............... ASK PHP TO INSERT FOOTER FILE ................... -->
<?php include("/customer/http/business/privacy.org.au/Library/footer.txt"); ?>

</body></html>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Digital ‘death knocks’: is it fair game for journalists to mine social media profiles of victims and their families?</title>
		<link>https://privacy.org.au/2024/04/17/digital-death-knocks-is-it-fair-game-for-journalists-to-mine-social-media-profiles-of-victims-and-their-families/</link>
		
		<dc:creator><![CDATA[Alysson Watson]]></dc:creator>
		<pubDate>Wed, 17 Apr 2024 03:07:17 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5346</guid>

					<description><![CDATA[Alysson Watson, Associate lecturer in journalism, University of Newcastle The family of Ash Good, one of the Bondi stabbing victims and the mother of the nine-month-baby who was also stabbed, issued a plea overnight for media to stop reproducing photos of Ash, her partner and their baby without consent. Good, 38, was an osteopath who&#8230; <span class="excerpt-more"><a href="https://privacy.org.au/2024/04/17/digital-death-knocks-is-it-fair-game-for-journalists-to-mine-social-media-profiles-of-victims-and-their-families/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<div class="theconversation-article-body"><p><span><a href="https://theconversation.com/profiles/alysson-watson-1514581">Alysson Watson</a>, Associate lecturer in journalism, <em><a href="https://theconversation.com/institutions/university-of-newcastle-1060">University of Newcastle</a></em></span></p>

<p>The family of Ash Good, one of the Bondi stabbing victims and the mother of the nine-month-baby who was also stabbed, issued a plea overnight for media to stop reproducing photos of Ash, her partner and their baby without consent.</p>

<p>Good, 38, was an osteopath who liked to exercise, post photographs of her young family and share thoughts on new motherhood: the endless nights and blurry days, the joy, the anxiety, <a href="https://www.smh.com.au/national/nsw/indescribable-love-new-mother-ash-good-among-the-bondi-junction-victims-20240414-p5fjmk.html">the “indescribable love”</a>.</p>

<p>Journalists discovered this from “mining” her (and her friends’ and family’s) social media accounts.</p>

<p>As well as Good’s family, federal politician Allegra Spender, whose electorate of Wentworth covers Westfield Bondi Junction, posted on social media a plea for “the media and everyone” to respect the wishes of those affected by the “tragedy at Bondi Junction”.</p>

<p>She wrote: “I have been contacted by Ash’s family. They have asked the media not to publish personal images from social media. I ask the media and everyone to respect their wishes.”</p>

<p>But will the victims’ privacy be respected? <a href="https://intellectdiscover.com/content/journals/10.1386/ajr_00106_7">My research </a>indicates that is unlikely.</p>



<h2>What can, and can’t, journalists do?</h2>

<p>The practice of journalists taking photos from social media, both with and without consent, is now commonplace, and is sanctioned in Australia by law and by professional codes, with some caveats.</p>

<p>Journalists <a href="https://www.oaic.gov.au/engage-with-us/submissions/privacy-act-review-issues-paper-submission/part-4-exemptions">are exempted</a> from the Privacy Act “in the course of journalism”, and while advice from professional bodies such as the <a href="https://presscouncil.org.au/standards/statement-of-principles">Australian Press Council</a> and the Australian Communications and Media Authority (<a href="https://www.acma.gov.au/sites/default/files/2019-12/Privacy%20guidelines%20for%20broadcasters.pdf">ACMA</a>) is to tread with caution when reproducing images from social media, they do permit publication “in the public interest”. So do the guidelines of media companies, including <a href="https://about.abc.net.au/wp-content/uploads/2012/06/EditorialPOL2011.pdf">the ABC</a>.</p>

<p>The ethical code that binds member journalists in Australia, <a href="https://www.meaa.org/meaa-media/code-of-ethics/">the MEAA Code of Ethics</a>, also advises journalists to respect privacy and grief. It gives them the right not to intrude, but tempers this advice with a “guidance clause” about their capacity to override standards if publication is in the public interest.</p>

<p>The “<a href="https://theconversation.com/whose-interests-why-defining-the-public-interest-is-such-a-challenge-84278">public interest</a>” is a nebulous concept that increasingly <a href="https://the-media-leader.com/in-the-public-interest/">extends</a> to “what the public is interested in”.</p>

<h2>The modern-day ‘death knock’</h2>

<p>As citizens and news consumers, we want information about everyone who is impacted, and it is the job of news reporters to feed the hungry beast that is digital news. How can they resist the intensely personal content that is shared on “public” social media accounts which gives such a human face to tragedy? Is it reasonable to expect them to?</p>

<p>These are questions I am exploring though <a href="https://intellectdiscover.com/content/journals/10.1386/ajms_00134_1">my PhD research</a> into the practice journalists informally (and perhaps unpalatably) call <a href="https://www.editorandpublisher.com/stories/death-knocks,204472">the “death knock”. </a></p>

<p>On hearing of a newsworthy death (or crime or major incident), journalists will do whatever they can to get information about the people impacted – the perpetrators, victims, and witnesses.</p>

<p>The job of gathering news is to find the most credible sources, and, in addition to expert voices (such as police, ambulance, health authorities and politicians), those who know something about the event or the people impacted.</p>

<h2>Should journalists ask for permission?</h2>

<p>Increasingly, in the digital age, newsgathering starts (and sometimes ends) with journalists mining social media.</p>

<p>Journalists use social media as a tool to find people they want to interview, but also as a source of information, images and tributes.</p>

<p>If people’s accounts are set to “public”, there is nothing to stop journalists using the photos and comments they find there in their stories.</p>

<p>Some journalists will pause and ask for permission, but not all will, and most do not feel compelled to.</p>

<p>However, my research indicates that journalists, by and large, are not thoughtless when it comes to what some view as stealing images from social media. They face enormous pressure to do so, from colleagues, editors and competitors.</p>

<p>Many argue that if images are in the public domain, they are fair game. And if everyone else is doing it, why wouldn’t they? They may ask themselves “how can I tell my boss I’m not going to do it when our competitors have already done it? If I pause to ask for permission, will I be scooped? What if I don’t hear back? What if permission is refused?”</p>

<p>In the UK, where <a href="https://www.ipso.co.uk/">protections</a> from media harassment are arguably stronger, people impacted by tragedy are <a href="https://www.gov.uk/government/publications/handling-media-attention/handling-media-attention-after-a-major-incident">advised</a> to check their social media privacy settings or delete material altogether.</p>

<p>This though assumes users are social media-literate, <a href="https://www.routledge.com/Journalism-Ethics-at-the-Crossroads-Democracy-Fake-News-and-the-News-Crisis/Patching-Hirst/p/book/9780367197285">but journalists</a> are “very adept at finding ways around privacy settings, and won’t hesitate to do so in pursuit of a story or photo”.</p>



<h2>A better path forward?</h2>

<p>Reporting on tragedy is routine work for many journalists, but it can <a href="https://www.journoresources.org.uk/mental-toll-reporting-tragedy-journalist/">take its toll</a>, sometimes in the form of <a href="https://americanpressinstitute.org/how-moral-injury-is-impacting-the-news-industry-and-what-you-can-do-about-it/#:%7E:text=For%20journalists%2C%20moral%20injury%20can,contravene%20an%20employee's%20moral%20code.">moral injury</a>, when they feel compelled to break their own moral code.</p>

<p>My research indicates journalists want better preparation, guidance, and support from their employers in reporting tragedy, and they want to be listened to about the impacts of this work on them.</p>

<p>However, in the realm of the “<a href="https://intellectdiscover.com/content/journals/10.1386/ajr_00106_7">digital death knock</a>” – the use of social media to report on tragedy – some argue that an ethical approach alone cannot stem what some believe is egregious behaviour, and that legislative (citizen privacy protections) and normative (stronger advice from professional bodies) approaches may be needed to protect journalists from themselves – and better protect people who fall victim to tragedy.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img decoding="async" src="https://counter.theconversation.com/content/227784/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" width="1" height="1" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" referrerpolicy="no-referrer-when-downgrade" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p>

<p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/digital-death-knocks-is-it-fair-game-for-journalists-to-mine-social-media-profiles-of-victims-and-their-families-227784">original article</a>.</p></div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Your face for sale: anyone can legally gather and market your facial data without explicit consent</title>
		<link>https://privacy.org.au/2024/03/06/your-face-for-sale-anyone-can-legally-gather-and-market-your-facial-data-without-explicit-consent/</link>
		
		<dc:creator><![CDATA[Margarita Vladimirova]]></dc:creator>
		<pubDate>Wed, 06 Mar 2024 08:46:00 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5341</guid>

					<description><![CDATA[Margarita Vladimirova, PhD in Privacy Law and Facial Recognition Technology, Deakin University The morning started with a message from a friend: “I used your photos to train my local version of Midjourney. I hope you don’t mind”, followed up with generated pictures of me wearing a flirty steampunk costume. I did in fact mind. I&#8230; <span class="excerpt-more"><a href="https://privacy.org.au/2024/03/06/your-face-for-sale-anyone-can-legally-gather-and-market-your-facial-data-without-explicit-consent/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<figure>
    <figure style="width: 744px" class="wp-caption aligncenter"><a href="https://www.shutterstock.com/image-photo/futuristic-technological-scanning-face-beautiful-woman-1554013514"><img fetchpriority="high" decoding="async" src="https://images.theconversation.com/files/579102/original/file-20240301-28-tzp738.jpg?ixlib=rb-1.1.0&#038;rect=956%2C85%2C6119%2C4218&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" width="754" height="520" alt="" /></a><figcaption class="wp-caption-text">Kitreel/Shutterstock</figcaption></figure>
</figure>

<p><span><a href="https://theconversation.com/profiles/margarita-vladimirova-1514577">Margarita Vladimirova</a>, PhD in Privacy Law and Facial Recognition Technology, <em><a href="https://theconversation.com/institutions/deakin-university-757">Deakin University</a></em></span></p>

<p>The morning started with a message from a friend: “I used your photos to train my local version of Midjourney. I hope you don’t mind”, followed up with generated pictures of me wearing a flirty steampunk costume.</p>

<p>I did in fact mind. I felt violated. Wouldn’t you? I bet Taylor Swift did when <a href="https://theconversation.com/taylor-swift-deepfakes-new-technologies-have-long-been-weaponised-against-women-the-solution-involves-us-all-222268">deepfakes of her hit the internet</a>. But is the legal status of my face different from the face of a celebrity?</p>

<p>Your facial information is a unique form of personal sensitive information. It can identify you. Intense profiling and mass government surveillance <a href="https://www.forbes.com/sites/kalevleetaru/2019/05/06/as-orwells-1984-turns-70-it-predicted-much-of-todays-surveillance-society/?sh=38a97b4e11de">receives much attention</a>. But businesses and individuals are also using tools that <a href="https://www.sbs.com.au/news/article/creepy-and-invasive-kmart-bunnings-and-the-good-guys-accused-of-using-facial-recognition-technology/h08q8evb1">collect</a>, <a href="https://www.afr.com/technology/how-clearview-ai-unleashed-a-global-dystopia-20230929-p5e8lc">store</a> and modify facial information, and we’re facing an unexpected wave of <a href="https://deepai.org/machine-learning-model/text2img">photos</a> and <a href="https://theconversation.com/what-is-sora-a-new-generative-ai-tool-could-transform-video-production-and-amplify-disinformation-risks-223850">videos</a> generated with artificial intelligence (AI) tools.</p>

<p>The development of legal regulation for these uses is lagging. At what levels and in what ways should our facial information be protected?</p>

<h2>Is implied consent enough?</h2>

<p>The Australian <a href="https://www.legislation.gov.au/C2004A03712/latest/text">Privacy Act</a> considers biometric information (which would include your face) to be a part of our personal sensitive information. However, the act doesn’t <em>define</em> biometric information.</p>

<p>Despite its drawbacks, the act is currently the main legislation in Australia aimed at facial information protection. It states biometric information cannot be collected without a person’s consent.</p>

<p>But the law doesn’t specify whether it should be <a href="https://www.ipc.nsw.gov.au/fact-sheet-consent">express or implied consent</a>. Express consent is given explicitly, either orally or in writing. Implied consent means consent may reasonably be inferred from the individual’s actions in a given context. For example, if you walk into a store that has a sign “facial recognition camera on the premises”, your consent is implied.</p>

<figure class="align-right zoomable">
            <figure style="width: 590px" class="wp-caption alignright"><a href="https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=1000&#038;fit=clip"><img decoding="async" alt="A poster at a supermarket that says camera technology trial in progress, partially obscured by a couple of bins." src="https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=237&#038;fit=clip" srcset="https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=600&#038;h=1067&#038;fit=crop&#038;dpr=1 600w, https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=600&#038;h=1067&#038;fit=crop&#038;dpr=2 1200w, https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=600&#038;h=1067&#038;fit=crop&#038;dpr=3 1800w, https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;h=1340&#038;fit=crop&#038;dpr=1 754w, https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=754&#038;h=1340&#038;fit=crop&#038;dpr=2 1508w, https://images.theconversation.com/files/578587/original/file-20240228-28-ns24xh.jpg?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=754&#038;h=1340&#038;fit=crop&#038;dpr=3 2262w" sizes="(min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px" width="600" height="1067" /></a><figcaption class="wp-caption-text">An inconspicuous sign that flags camera technology trial is in progress counts as implied consent. &#8211; Margarita Vladimirova</figcaption></figure>
            <figcaption>
             
            </figcaption>
        </figure>

<p>But using implied consent opens our facial data up to potential exploitation. <a href="https://www.choice.com.au/consumers-and-data/data-collection-and-use/how-your-data-is-used/articles/kmart-bunnings-and-the-good-guys-using-facial-recognition-technology-in-store">Bunnings, Kmart</a> and <a href="https://www.theguardian.com/business/2023/feb/19/woolworths-expands-self-checkout-ai-that-critics-say-treats-every-customer-as-a-suspect">Woolworths</a> have all used easy-to-miss signage that facial recognition or camera technology is used in their stores.</p>

<h2>Valuable and unprotected</h2>

<p>Our facial information has become so valuable, <a href="https://www.theguardian.com/australia-news/2023/oct/24/australian-federal-police-afp-pimeyes-facial-recognition-facecheck-id-search-engine-platform">data companies such as Clearview AI and PimEye</a> are mercilessly hunting it down on the internet <a href="https://onezero.medium.com/i-got-my-file-from-clearview-ai-and-it-freaked-me-out-33ca28b5d6d4">without our consent</a>.</p>

<p>These companies put together databases for sale, used not only by the police in various countries, <a href="https://www.theguardian.com/australia-news/2023/oct/24/australian-federal-police-afp-pimeyes-facial-recognition-facecheck-id-search-engine-platform">including Australia</a>, but also by <a href="https://www.clearview.ai/developer-api">private companies</a>.</p>

<p>Even if you deleted all your facial data from the internet, you could easily be captured in public and appear in some database anyway. Being in someone’s TikTok video <a href="https://www.abc.net.au/news/2022-07-14/tiktok-video-maree-melbourne-flowers/101228418">without your consent</a> is a prime example – in Australia this is legal.</p>



<p>Furthermore, we’re also now contending with generative AI programs such as Midjourney, DALL-E 3, Stable Diffusion and others. Not only the collection, but the modification of our facial information can be easily performed by anyone.</p>

<p>Our faces are unique to us, they’re part of what we perceive as ourselves. But they don’t have special legal status or special legal protection.</p>

<p>The only action you can take to protect your facial information from aggressive collection by a store or private entity <a href="https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us">is to complain</a> to the office of the Australian Information Commissioner, which may or may not result in an investigation.</p>

<p>The same applies to deepfakes. The Australian Competition and Consumer Commission will consider only activity that applies to trade and commerce, for example if a <a href="https://www.theguardian.com/technology/2022/mar/18/accc-takes-meta-to-court-over-facebook-scam-ads-depicting-australian-identities">deepfake is used for false advertising</a>.</p>

<p>And the Privacy Act doesn’t protect us from other people’s actions. I didn’t consent to have someone train an AI with my facial information and produce made-up images. But there is no oversight on such use of generative AI tools, either.</p>

<p>There are currently no laws that <em>prevent</em> other people from collecting or modifying your facial information.</p>



<h2>Catching up the law</h2>

<p>We need a range of regulations on the collection and modification of facial information. We also need a stricter status of facial information itself. Thankfully, some developments in this area are looking promising.</p>

<p>Experts at the University of Technology Sydney have proposed a comprehensive legal framework for <a href="https://www.uts.edu.au/human-technology-institute/projects/facial-recognition-technology-towards-model-law">regulating the use of facial recognition technology</a> under Australian law.</p>

<p>It contains proposals for regulating the first stage of non-consensual activity: the collection of personal information. That may help in the development of new laws.</p>

<p>Regarding photo modification using AI, we’ll have to wait for announcements from the newly established government <a href="https://www.minister.industry.gov.au/ministers/husic/media-releases/new-artificial-intelligence-expert-group">AI expert group</a> working to develop “safe and responsible AI practices”.</p>

<p>There are no specific discussions about a higher level of protection for our facial information in general. However, the government’s recent <a href="https://www.ag.gov.au/rights-and-protections/publications/government-response-privacy-act-review-report">response to the Attorney-General’s Privacy Act review</a> has some promising provisions.</p>

<p>The government has agreed further consideration should be given to enhanced risk assessment requirements in the context of facial recognition technology and other uses of biometric information. This work should be coordinated with the government’s ongoing work on Digital ID and the National Strategy for Identity Resilience.</p>

<p>As for consent, the government has agreed in principle that the definition of consent required for biometric information collection should be amended to specify it must be voluntary, informed, current, specific and unambiguous.</p>

<p>As facial information is increasingly exploited, we’re all waiting to see whether these discussions do become law – hopefully sooner rather than later.</p>

<hr />

<p><em>Correction: we have amended a sentence to clarify Woolworths use camera technology but not necessarily facial recognition technology.</em><!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading="lazy" decoding="async" src="https://counter.theconversation.com/content/224643/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" width="1" height="1" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" referrerpolicy="no-referrer-when-downgrade" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p>

<p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/your-face-for-sale-anyone-can-legally-gather-and-market-your-facial-data-without-explicit-consent-224643">original article</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Popular fertility apps are engaging in widespread misuse of data, including on sex, periods and pregnancy</title>
		<link>https://privacy.org.au/2023/03/22/popular-fertility-apps-are-engaging-in-widespread-misuse-of-data-including-on-sex-periods-and-pregnancy/</link>
		
		<dc:creator><![CDATA[Katharine Kemp]]></dc:creator>
		<pubDate>Wed, 22 Mar 2023 11:24:05 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5285</guid>

					<description><![CDATA[Fertility apps collect deeply sensitive data about consumers’ sex lives, health, emotional states and menstrual cycles. And many of them are intended for use by children as young as 13. An analysis by UNSW's Katharine Kemp has uncovered a number of concerning practices by these apps including: confusing and misleading privacy messages, a lack of choice in how data are used, inadequate de-identification measures when data are shared with other organisations, and retention of data for years even after a consumer stops using the app, exposing them to unnecessary risk from potential data breaches. <span class="excerpt-more"><a href="https://privacy.org.au/2023/03/22/popular-fertility-apps-are-engaging-in-widespread-misuse-of-data-including-on-sex-periods-and-pregnancy/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<figure>
    <img decoding="async" src="https://images.theconversation.com/files/516601/original/file-20230321-690-se9b8m.jpeg?ixlib=rb-1.1.0&#038;rect=24%2C58%2C3210%2C2095&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" class="aligncenter" />
</figure>

<p><span><a href="https://theconversation.com/profiles/katharine-kemp-402096">Katharine Kemp</a>, Senior Lecturer, Faculty of Law &amp; Justice, <em><a href="https://theconversation.com/institutions/unsw-sydney-1414">UNSW Sydney</a></em></span></p>

<p>New research reveals serious privacy flaws in fertility apps used by Australian consumers – emphasising the need for urgent reform of the Privacy Act.</p>

<p>Fertility apps provide a number of features. For instance, they may help users track their periods, identify a “fertile window” if they’re trying to conceive, track different stages and symptoms of pregnancy, and prepare for parenthood up until the baby’s birth.</p>

<p>These apps collect deeply sensitive data about consumers’ sex lives, health, emotional states and menstrual cycles. And many of them are intended for use by children as young as 13.</p>

<p>My report <a href="https://allenshub.unsw.edu.au/sites/default/files/2023-03/KKemp%20Your%20Body%20Our%20Data%2022.03.23.pdf">published today</a> analysed the privacy policies, messages and settings of 12 of the most popular fertility apps used by Australian consumers (excluding apps that require a connection with a wearable device).</p>

<p>This analysis uncovered a number of concerning practices by these apps including:</p>

<ul>
<li>confusing and misleading privacy messages</li>
<li>a lack of choice in how data are used</li>
<li>inadequate de-identification measures when data are shared with other organisations</li>
<li>retention of data for years even after a consumer stops using the app, exposing them to unnecessary risk from potential data breaches.</li>
</ul>



<h2>The data collected</h2>

<p>The apps in this study collect intimate data from consumers, such as:</p>

<ul>
<li>their pregnancy test results</li>
<li>when they have sex and whether they had an orgasm</li>
<li>whether they used a condom or “withdrawal” method</li>
<li>when they have their period</li>
<li>how their moods change (including anxiety, panic and depression)</li>
<li>and if they have health conditions such as polycystic ovary syndrome, endometriosis or uterine fibroids.</li>
</ul>

<p>Some ask for unnecessary details, such as when a user smokes and drinks alcohol, their education level, whether they struggle to pay their bills, if they feel safe at home, and whether they have stable housing.</p>

<p>They also track which support groups you join, what you add to your “to-do list” or “questions for doctor”, and which articles you read. All of this creates a more detailed picture of your health, family situation and intentions.</p>

<h2>Confusing or misleading privacy messages</h2>

<p>Consumers should expect the clearest information about how such data are collected, used and disclosed. Yet we found some of the messaging is highly confusing or misleading.</p>

<p>Some apps say “we will never sell your data”. But the fine print of the privacy policy contains a term that allows them to sell all your data as part of the sale of the app or database to another company.</p>

<p>This possibility is not just theoretical. Of the 12 apps included in the study, one was previously taken over by a drug development company, and another two by a digital media company.</p>

<p>Other apps explain privacy settings using language that makes it almost impossible for a consumer to understand what they are choosing, or obscure the privacy settings by placing them numerous clicks and scrolls away from the home screen.</p>

<h2>Keeping sensitive data for too long</h2>

<p>The <a href="https://www.abc.net.au/news/2022-10-21/medibank-optus-data-hack/101558932">major data breaches</a> of the past six months highlight the risks of companies holding onto personal data longer than necessary.</p>

<p>Breaches of highly sensitive information about health and sexual activities could lead to <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4387341">discrimination, exploitation, humiliation or blackmail</a>.</p>

<p>Most of the apps we analysed keep user data for at least three years after the user quits the app – or seven years in the case of one brand. Some apps give no indication of when user data will be deleted.</p>

<h2>Can’t count on ‘de-identification’</h2>

<p>Some apps also give consumers no choice regarding whether their “de-identified” health data will be sold or transferred to other companies for research or business. Or, they have consumers opted-in to these extra uses by default, putting the onus on users to opt out.</p>

<p>Moreover, some of these data are not truly de-identified. For example, removing your name and email address and replacing it with a unique number is not de-identification for legal purposes. Someone would only need to work out the link between your name and that number in order to link your whole record with you.</p>

<p>When supposedly de-identified Medicare records were published in 2016, <a href="https://www.unimelb.edu.au/newsroom/news/2017/december/research-reveals-de-identified-patient-data-can-be-re-identified">University of Melbourne researchers</a> showed how just a few data points can connect a de-identified record to a unique individual.</p>



<h2>Need for reform</h2>

<p>This research highlights the unfair and unsafe data practices consumers are subjected to when they use fertility apps. And these findings reinforce the need for Australia’s privacy laws to be updated.</p>

<p>We need improvements in what data are covered by the Privacy Act, what choices consumers can make about their data, what data uses are prohibited, and what security systems companies must have in place.</p>

<p>The government is seeking <a href="https://www.ag.gov.au/rights-and-protections/publications/privacy-act-review-report">submissions</a> on potential privacy law reforms until March 31.</p>

<p>In the meantime, if you’re using a fertility app, there are some steps you can take to help reduce some of the privacy risks: <!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading="lazy" decoding="async" src="https://counter.theconversation.com/content/202127/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" referrerpolicy="no-referrer-when-downgrade" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p>

<ol>
<li>when launching the app for the first time, don’t agree to tracking of your data, or you can limit ad tracking via iPhone device settings</li>
<li>don’t log in via a social media account</li>
<li>don’t answer questions or add data you don’t need to for your own purposes</li>
<li>don’t share your Apple Health or FitBit data</li>
<li>if the app provides privacy choices, opt out of tracking and having your data sold or used for research, and delete your data when you stop using the app</li>
<li>bear in mind that every article you read, and how long you spend on it, and every group you join and comment you make there may be added to a profile about you.</li>
</ol>

<p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/popular-fertility-apps-are-engaging-in-widespread-misuse-of-data-including-on-sex-periods-and-pregnancy-202127">original article</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Proposed privacy reforms could help Australia play catch-up with other nations. But they fail to tackle targeted ads</title>
		<link>https://privacy.org.au/2023/02/21/proposed-privacy-reforms-could-help-australia-play-catch-up-with-other-nations-but-they-fail-to-tackle-targeted-ads/</link>
		
		<dc:creator><![CDATA[Katharine Kemp]]></dc:creator>
		<pubDate>Tue, 21 Feb 2023 03:36:25 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5276</guid>

					<description><![CDATA[In the recently released Privacy Act Review Report, the Attorney-General’s Department makes numerous important proposals that could see the legislation, enacted in 1988, begin to catch up to leading privacy laws globally. However, the report’s proposals on targeted advertising don’t properly address the power imbalance between companies and consumers. Instead, they largely accept a status quo that sacrifices consumer privacy to the demands of online targeted ad businesses. <span class="excerpt-more"><a href="https://privacy.org.au/2023/02/21/proposed-privacy-reforms-could-help-australia-play-catch-up-with-other-nations-but-they-fail-to-tackle-targeted-ads/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<figure><figure style="width: 744px" class="wp-caption alignright"><img loading="lazy" decoding="async" src="https://images.theconversation.com/files/511077/original/file-20230220-19-p8vr96.jpeg?ixlib=rb-1.1.0&#038;rect=123%2C6%2C4461%2C3052&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" alt="" width="754" height="516" /><figcaption class="wp-caption-text">Image from Shutterstock</figcaption></figure><figcaption></figcaption><p>In the recently released <a href="https://www.ag.gov.au/sites/default/files/2023-02/privacy-act-review-report.pdf">Privacy Act Review Report</a>, the Attorney-General’s Department makes numerous important proposals that could see the legislation, enacted in 1988, begin to catch up to leading privacy laws globally.</p></figure><p>Among the positive proposed changes are: more realistic definitions of personal information and consent, tighter limits on data retention, a right to erasure, and a requirement for data practices to be fair and reasonable.</p><p>However, the report’s proposals on targeted advertising don’t properly address the power imbalance between companies and consumers. Instead, they largely accept a status quo that sacrifices consumer privacy to the demands of online targeted ad businesses.</p><h2>Capturing personal information used to track and profile</h2><p>Obligations under the existing Privacy Act only apply to “personal information”, but there has been legal uncertainty about what exactly constitutes “personal information”.</p><p>Currently, companies can track an individual’s online behaviour across different websites and connect it with their offline movements by matching their data with data collected from third parties, such as retailers or <a href="https://www.oracle.com/au/cx/advertising/data-enrichment-measurement/#data-enrichment">data brokers</a>.</p><p>Some of these companies claim they’re not dealing in “personal information” since they don’t use the individual’s name or email address. Instead, the matching is done based on a unique identifier allocated to that person – such as a <a href="https://help.abc.net.au/hc/en-us/articles/4402890310671">hashed email</a>, for example.</p><p>The report proposes an expanded definition of “personal information” that clearly includes the various technical and online identifiers being used to track and profile consumers. Under this definition, companies could no longer claim such data collection and sharing are outside the scope of the Privacy Act.</p><h2>Improved consent (when required)</h2><p>The report also proposes higher standards for how consent is sought, in cases where the act requires it. This would require voluntary, informed, current, specific and unambiguous consent.</p><p>This would work against organisations claiming consumers have consented to unexpected data uses just because they used a website or an app with a link to a broadly worded privacy policy with take-it-or-leave-it terms.</p><p>For example, companies would need to demonstrate the higher standard of consent to collect sensitive information about someone’s mental health or sexual orientation. The report also proposes that some further data practices, such as precise geolocation tracking, should require consent.</p><p>However, it specifically states consent should not be required for some targeted ad practices. Yet <a href="https://www.accc.gov.au/system/files/Digital%20platforms%20inquiry%20-%20final%20report.pdf">surveys</a> show most consumers regard these as misuses of their personal information.</p><h2>‘Fair and reasonable’ data practices</h2><p>The report proposes a “fair and reasonable” test for dealings with personal information in general.</p><p>This recognises that consumers are saddled with too much of the responsibility for managing how their personal information is collected and used, while they lack the information, resources, expertise and control to do this effectively.</p><p>Instead, organisations covered by the Privacy Act should ensure their data handling practices are “fair and reasonable”, regardless of whether they have consumer consent. This would include considering whether a reasonable person would expect the data to be collected, used or disclosed in that way, and whether any dealing with children’s information is in the best interests of the child.</p><h2>Prohibiting targeted ads based on sensitive information</h2><p>The report proposes the prohibition of targeting based on sensitive information and traits. However, it’s not always easy to draw the line between “sensitive” information or traits, and other personal information.</p><p>For instance, is having an interest in “cosmetic procedures” or “rapid weight loss” a sensitive trait, or a general reading interest? Companies may exploit such grey areas. So while prohibiting targeting based on sensitive information is appropriate, it’s not enough in itself.</p><p>Another loophole arises in the report’s proposal that consumer consent should be necessary before an organisation trades in their personal information. The report leaves open an exception to this consent requirement where the “trading” is reasonably necessary for an organisation’s functions or activities.</p><p>This may be a substantial exception: data brokers, for example, might argue their trade in personal information (without consumers’ knowledge or consent) is necessary.</p><h2>Opt out only, not opt in</h2><p>Both the <a href="https://www.accc.gov.au/system/files/Digital%20platforms%20inquiry%20-%20final%20report.pdf">ACCC</a> and the <a href="https://assets.publishing.service.gov.uk/media/5fa557668fa8f5788db46efc/Final_report_Digital_ALT_TEXT.pdf">UK Competition &amp; Markets Authority</a> have recommended consumers should opt <em>in</em> to the use of their personal information for targeted advertising if they wish to see this content.</p><p>But the report proposes individuals should only be allowed to opt <em>out</em> of “seeing” targeted ads. This still wouldn’t stop companies from collecting, using and disclosing a user’s personal information for broader targeting purposes.</p><p>Even if a consumer opts out of seeing targeted ads, a business may continue to collect their personal information to create “lookalike audiences” and target other people with similar attributes.</p><p>Although having the option to opt out of seeing targeted ads gives consumers some limited control, companies still control the “<a href="https://www.accc.gov.au/system/files/DPB%20-%20DPSI%20-%20September%202021%20-%20Full%20Report%20-%2030%20September%202021%20%283%29_1.pdf">choice architecture</a>” of such settings. They can use their control to make opting out <a href="https://cprc.org.au/dupedbydesign/">confusing and difficult</a> for users, by forcing them to navigate through multiple pages or websites with obscurely labelled settings.</p><h2>Are targeted ads necessary to support online services?</h2><p>This limitation of consumers’ choices was partly explained by the view of the Attorney-General’s Department that targeted ads are necessary to fund “free” services. This refers to services where consumers “pay” with their attention and data (which companies use to make revenue from targeted advertising).</p><p>However, many companies using customers’ personal information for targeted ad businesses aren’t providing free services. Consider online marketplaces such as Amazon or eBay, or subscription-based products of media companies such as NewsCorp and Nine.</p><p>Meta (Facebook) and the Interactive Advertising Bureau Australia argued that if consumers opt out of targeted ads, a company should be able to stop offering them the service in question. This proposal was rejected on the basis that a platform can still show non-targeted ads to such consumers.</p><p>Inconsistently, the report failed to question broader claims that targeted advertising – as opposed to less intrusive forms of advertising – must be protected for online services to be viable.</p><h2>Real change is needed</h2><p>The reform of our privacy laws is long overdue. The government should avoid watering down potential improvements by attempting to preserve the status quo dictated by large businesses.</p><p>The government is seeking <a href="https://ministers.ag.gov.au/media-centre/landmark-privacy-act-review-report-released-16-02-2023">feedback on the report</a> until March 31. It will then decide on the final form of the reforms it proposes, before these are debated in Parliament. <!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading="lazy" decoding="async" src="https://counter.theconversation.com/content/200166/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" referrerpolicy="no-referrer-when-downgrade" width="1" height="1" /><code style="display: none;"></code><span><em><a href="https://theconversation.com/institutions/unsw-sydney-1414"></a></em></span></p><p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/proposed-privacy-reforms-could-help-australia-play-catch-up-with-other-nations-but-they-fail-to-tackle-targeted-ads-200166">original article</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Not Big Brother, but close: a surveillance expert explains some of the ways we’re all being watched, all the time</title>
		<link>https://privacy.org.au/2022/12/19/not-big-brother-but-close-a-surveillance-expert-explains-some-of-the-ways-were-all-being-watched-all-the-time/</link>
		
		<dc:creator><![CDATA[Ausma Bernot]]></dc:creator>
		<pubDate>Mon, 19 Dec 2022 01:23:03 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5255</guid>

					<description><![CDATA[Ausma Bernot, PhD Candidate, School of Criminology and Criminal Justice, Griffith University A group of researchers studied 15 months of human mobility movement data taken from 1.5 million people and concluded that just four points in space and time were sufficient to identify 95% of them, even when the data weren’t of excellent quality. That&#8230; <span class="excerpt-more"><a href="https://privacy.org.au/2022/12/19/not-big-brother-but-close-a-surveillance-expert-explains-some-of-the-ways-were-all-being-watched-all-the-time/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<h1 class="legacy"></h1>

<figure>
    <figure style="width: 744px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" src="https://images.theconversation.com/files/499955/original/file-20221209-20279-c0jq3z.jpeg?ixlib=rb-1.1.0&#038;rect=95%2C107%2C7893%2C4383&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" alt="" width="754" height="419" /><figcaption class="wp-caption-text">Image from Shutterstock</figcaption></figure>
</figure>
<p><span><a href="https://theconversation.com/profiles/ausma-bernot-963292">Ausma Bernot</a>, PhD Candidate, School of Criminology and Criminal Justice, <em><a href="https://theconversation.com/institutions/griffith-university-828">Griffith University</a></em></span></p>

<p>A group of <a href="https://www.nature.com/articles/srep01376;">researchers studied</a> 15 months of human mobility movement data taken from 1.5 million people and concluded that just four points in space and time were sufficient to identify 95% of them, even when the data weren’t of excellent quality.</p>

<p>That was back in 2013.</p>

<p>Nearly ten years on, surveillance technologies permeate all aspects of our lives. They collect swathes of data from us in various forms, and often without us knowing.</p>

<p>I’m a surveillance researcher with a focus on technology governance. Here’s my round-up of widespread surveillance systems I think everyone should know about.</p>

<h2>CCTV and open-access cameras</h2>

<p>Although China has more than 50% of <a href="https://www.comparitech.com/vpn-privacy/the-worlds-most-surveilled-cities/">all surveillance cameras installed</a> in the world (about 34 cameras per 1,000 people), Australian cities are <a href="https://www.comparitech.com/vpn-privacy/the-worlds-most-surveilled-cities/">catching up</a>. In 2021, Sydney had 4.67 cameras per 1,000 people and Melbourne had 2.13.</p>

<p>While CCTV cameras can be used for legitimate purposes, such as promoting safety in cities and assisting police with criminal investigations, their use also poses serious concerns.</p>

<p>In 2021, New South Wales police <a href="https://www.innovationaus.com/facial-recognition-and-the-nsw-protest-crowds/">were suspected of</a> having used CCTV footage paired with facial recognition to find people attending anti-lockdown protests. When questioned, they didn’t confirm or deny if they had (or if they would in the future).</p>

<p>In August 2022, the United Nations confirmed CCTV is <a href="https://www.ohchr.org/en/documents/country-reports/ohchr-assessment-human-rights-concerns-xinjiang-uyghur-autonomous-region">being used to</a> carry out “serious human rights violations” against Uyghur and other predominantly Muslim ethnic minorities in the Xinjiang region of Northwest China.</p>

<p>The CCTV cameras in China don’t just record real-time footage. Many are equipped with facial recognition to <a href="https://www.nytimes.com/2019/04/14/technology/china-surveillance-artificial-intelligence-racial-profiling.html">keep tabs on</a> the movements of minorities. And some have reportedly been trialled to <a href="https://www.bbc.com/news/technology-57101248">detect emotions</a>.</p>

<p>The US also has a long history of using CCTV cameras to support racist policing practices. In 2021, Amnesty International <a href="https://www.amnesty.org/en/latest/news/2021/06/scale-new-york-police-facial-recognition-revealed/">reported</a> areas with a higher proportion of non-white residents had more CCTV cameras.</p>

<p>Another issue with CCTV is security. Many of these cameras are open-access, which means they don’t have password protection and can often be easily accessed online. So I could spend all day watching a livestream of someone’s porch, as long as there was an open camera nearby.</p>

<p>Surveillance artist Dries Depoorter’s recent project <a href="https://driesdepoorter.be/thefollower/">The Follower</a> aptly showcases the vulnerabilities of open cameras. By coupling open camera footage with AI and Instagram photos, Depoorter was able to match people’s photos with the footage of where and when they were taken.</p>

<p>There was pushback, with one of the <a href="https://www.inverse.com/input/culture/dries-depoorters-ai-surveillance-art-the-follower-instagram-influencers-photos">identified people saying</a>:</p>

<blockquote>
<p>It’s a crime to use the image of a person without permission.</p>
</blockquote>

<p>Whether or not it is illegal will depend on the specific circumstances and where you live. Either way, the issue here is that Depoorter was able to do this in the first place.</p>

<h2>IoT devices</h2>

<p>An IoT (“Internet of Things”) device is any device that connects to a wireless network to function – so think smart home devices such as Amazon Echo or Google Dot, a baby monitor, or even smart traffic lights.</p>

<p>It’s estimated global spending on IoT devices will <a href="https://acola.org/hs5-internet-of-things-australia/">have reached</a> US$1.2 trillion by some point this year. Around 18 billion connected devices form the IoT network. Like unsecured CCTV cameras, IoT devices are easy to hack into if they use default passwords or passwords that have <a href="https://haveibeenpwned.com/">been leaked</a>.</p>

<p>In some examples, hackers have hijacked baby monitor cameras to <a href="https://www.npr.org/sections/thetwo-way/2018/06/05/617196788/s-c-mom-says-baby-monitor-was-hacked-experts-say-many-devices-are-vulnerable/">stalk</a> breastfeeding mums, <a href="https://www.npr.org/sections/thetwo-way/2018/06/05/617196788/s-c-mom-says-baby-monitor-was-hacked-experts-say-many-devices-are-vulnerable/">threaten</a> parents that their baby was being kidnapped, and say creepy things like “<a href="https://www.nbcnews.com/news/us-news/stranger-hacks-baby-monitor-tells-child-i-love-you-n1090046">I love you</a>” to children.</p>

<figure>
            <iframe loading="lazy" width="440" height="260" src="https://www.youtube.com/embed/xbk3OdYBLHA?wmode=transparent&#038;start=0" frameborder="0" allowfullscreen="allowfullscreen"></iframe>
</figure>

<p>Beyond hacking, businesses can also use data collected through IoT devices to further target customers with products and services.</p>

<p>Privacy experts raised the alarm in September over Amazon’s merger agreement with robot vacuum company iRobot. <a href="https://www.fightforthefuture.org/news/2022-09-09-letter-to-the-ftc-challenge-amazon-irobot-deal">A letter</a> to the US Federal Trade Commission signed by 26 civil rights and privacy advocacy groups said:</p>

<blockquote>
<p>Linking iRobot devices to the already intrusive Amazon home system incentivizes more data collection from more connected home devices, potentially including private details about our habits and our health that would endanger human rights and safety.</p>
</blockquote>

<p>IoT-collected data can also change hands with third parties through data partnerships (which are very common), and this too without customers’ explicit consent.</p>

<figure class="align-center zoomable">
            <figure style="width: 744px" class="wp-caption alignnone"><a href="https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=1000&#038;fit=clip"><img loading="lazy" decoding="async" alt="" src="https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" srcset="https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=600&#038;h=338&#038;fit=crop&#038;dpr=1 600w, https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=600&#038;h=338&#038;fit=crop&#038;dpr=2 1200w, https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=600&#038;h=338&#038;fit=crop&#038;dpr=3 1800w, https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;h=424&#038;fit=crop&#038;dpr=1 754w, https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=754&#038;h=424&#038;fit=crop&#038;dpr=2 1508w, https://images.theconversation.com/files/499953/original/file-20221209-25000-9tmah6.jpeg?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=754&#038;h=424&#038;fit=crop&#038;dpr=3 2262w" sizes="auto, (min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px" width="754" height="424" /></a><figcaption class="wp-caption-text">Smart speakers with digital assistants consistently raise data privacy concerns among experts.</figcaption></figure>
</figure>

<h2>Big tech and big data</h2>

<p>In 2017, the <a href="https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data">value of big data exceeded</a> that of oil. Private companies have driven the majority of that growth.</p>

<p>For tech platforms, the expansive collection of users’ personal information is business as usual, literally, because more data mean more precise analytics, more effective targeted ads <a href="https://www.facebook.com/business/help/716180208457684?id=1792465934137726">and more revenue</a>.</p>

<p>This logic of profit-making through targeted advertising has been <a href="https://journals.sagepub.com/doi/full/10.1177/1095796018819461">dubbed</a> “surveillance capitalism”. As <a href="https://quoteinvestigator.com/2017/07/16/product/">the old saying</a> goes, if you’re not paying for it, then you’re the product.</p>

<p>Meta (which owns both Facebook and Instagram) <a href="https://www.forbes.com/sites/bradadgate/2022/11/03/revenue-of-alphabet-and-meta-the-digital-duopoly-have-been-slipping/?sh=2ebf3dad2fed">generated</a> almost US$23 billion in advertising revenue in the third quarter of this year.</p>

<p>The vast machinery behind this is illustrated well in the 2021 documentary The Social Dilemma, even if in a dramatised way. It <a href="https://theconversation.com/netflixs-the-social-dilemma-highlights-the-problem-with-social-media-but-whats-the-solution-147351">showed us how</a> social media platforms rely on our psychological weaknesses to keep us online for as long as possible, measuring our actions down to the seconds we spend hovering over an ad.</p>

<figure class="align-center ">
            <figure style="width: 744px" class="wp-caption alignnone"><img loading="lazy" decoding="async" alt="" src="https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" srcset="https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=600&#038;h=247&#038;fit=crop&#038;dpr=1 600w, https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=600&#038;h=247&#038;fit=crop&#038;dpr=2 1200w, https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=600&#038;h=247&#038;fit=crop&#038;dpr=3 1800w, https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;h=310&#038;fit=crop&#038;dpr=1 754w, https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=754&#038;h=310&#038;fit=crop&#038;dpr=2 1508w, https://images.theconversation.com/files/497297/original/file-20221124-24-idgeki.gif?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=754&#038;h=310&#038;fit=crop&#038;dpr=3 2262w" sizes="auto, (min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px" width="754" height="310" /><figcaption class="wp-caption-text">A graphic excerpt from Social Dilemma.</figcaption></figure>
</figure>

<h2>Loyalty programs</h2>

<p>Although many people don’t realise it, loyalty programs are one of the biggest personal data collection gimmicks out there.</p>

<p>In a particularly intrusive example, in 2012 one <a href="https://www.forbes.com/sites/kashmirhill/2012/02/16/how-target-figured-out-a-teen-girl-was-pregnant-before-her-father-did/?sh=706b0cd96668">US retailer</a> sent a teenage girl a catalogue dotted with pictures of smiling infants and nursery furniture. The girl’s angered father went to confront managers at the local store, and learned that predictive analytics knew more about his daughter than he did.</p>

<p>It’s estimated 88% of Australian consumers <a href="https://www.oaic.gov.au/privacy/privacy-assessments/loyalty-program-assessment-woolworths-rewards-woolworths-limited">over age 16 are members</a> of a loyalty program. These schemes build your consumer profile to sell you more stuff. Some might even charge you <a href="https://www.abc.net.au/everyday/making-loyalty-cards-worth-your-time-and-money/10998806">sneaky fees</a> and lure you in with future perks to sell you at steep prices.</p>

<p>As technology journalist <a href="https://www.choice.com.au/consumers-and-data/data-collection-and-use/who-has-your-data/articles/loyalty-program-data-collection">Ros Page notes</a>:</p>

<blockquote>
<p>[T]he data you hand over at the checkout can be shared and sold to businesses you’ve never dealt with.</p>
</blockquote>

<p>As a cheeky sidestep, you could find a buddy to swap your loyalty cards with. Predictive analytics is only strong when it can recognise behavioural patterns. When the patterns are disrupted, the data turn into noise. <!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading="lazy" decoding="async" src="https://counter.theconversation.com/content/194917/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" referrerpolicy="no-referrer-when-downgrade" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p>

<p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/not-big-brother-but-close-a-surveillance-expert-explains-some-of-the-ways-were-all-being-watched-all-the-time-194917">original article</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Optus says it needed to keep identity data for six years. But did it really?</title>
		<link>https://privacy.org.au/2022/10/01/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really/</link>
					<comments>https://privacy.org.au/2022/10/01/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really/#comments</comments>
		
		<dc:creator><![CDATA[Brendan Walker-Munro]]></dc:creator>
		<pubDate>Sat, 01 Oct 2022 06:58:13 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5143</guid>

					<description><![CDATA[Among the many questions raised by the Optus data leak is why the company was storing so much personal information for so long. Optus has said it is legally required to do so. But your name, address and account reference number should be all it needs for this, not your passport, driver’s licence or Medicare details. The only clear legal requirement for it to keep “information for identification purposes” comes from the Telecommunications (Interception and Access) Act 1979, which requires that identification information and metadata be kept for two years (to assist law enforcement and intelligence agencies). <span class="excerpt-more"><a href="https://privacy.org.au/2022/10/01/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<p><span><a href="https://theconversation.com/profiles/brendan-walker-munro-1326958">Brendan Walker-Munro</a>, Senior Research Fellow, <em><a href="https://theconversation.com/institutions/the-university-of-queensland-805">The University of Queensland</a></em></span></p><p>Among the many questions raised by the Optus data leak – cybersecurity experts are confident it wasn’t a hack, but that may have to be decided by a court – is why the company was storing so much personal information for so long.</p><p>Optus had a <a href="https://www.sbs.com.au/news/article/optus-faces-a-customer-exodus-calls-for-compensation-amid-anger-over-leaked-data/mw79n7avs">legitimate need</a> to collect that data – to verify customers were real people and potentially to recover any debts later. This is known as a “<a href="https://www.austrac.gov.au/business/how-comply-and-report-guidance-and-resources/customer-identification-and-verification/customer-identification-know-your-customer-kyc">know your customer</a>” (or “KYC”) requirement.</p><p>But the reason about <a href="https://www.news.com.au/finance/business/technology/big-problem-with-optus-email-sparks-fury-among-aussies/news-story/5f255af9157686fb7bb505c1c6043abc">4 million former customers</a> along with 5.8 million current customers are now worrying about their driver’s licences, passport numbers and Medicare numbers ending up in <a href="https://www.sbs.com.au/news/article/federal-police-are-monitoring-reports-leaked-optus-customer-data-is-being-sold-on-the-dark-web/6sish60wb">the hands of criminals</a> is due to Optus hanging on to it for six years.</p><p>Optus <a href="https://www.theguardian.com/australia-news/2022/sep/24/optus-cyber-attack-how-do-you-know-if-your-identity-has-been-stolen-and-what-will-happen-to-your-data">has said</a> it is legally required to do so.</p><p>It is required by the <a href="https://www.commsalliance.com.au/__data/assets/pdf_file/0011/64784/TCP-C628_2019-incorporating-variation-no.1-2022.pdf">Telecommunications Consumer Protections Code</a>, the industry code of practice overseen by the Australian Communications and Media Authority, to provide customers (or former customers) billing information for “up to six years prior to the date the information is requested”.</p><p>But your name, address and account reference number should be all it needs for this, not your passport, driver’s licence or Medicare details. If it needs to confirm your identity it could simply ask for documents again.</p><p>The only clear legal requirement for it to keep “information for identification purposes” comes from the <a href="https://www.oaic.gov.au/privacy/guidance-and-advice/telecommunications-service-providers-obligations-arising-under-the-privacy-act-1988-as-a-result-of-part-5-1a-of-the-telecommunications-interception-and-access-act-1979">Telecommunications (Interception and Access) Act 1979</a>, which requires that identification information and metadata be kept for two years (to assist law enforcement and intelligence agencies).</p><h2>Is there any limit?</h2><p>The big problem with Australia’s data retention laws is that there’s really no limit on how long a company can keep personal data.</p><p>The federal <a href="https://www.oaic.gov.au/privacy/guidance-and-advice/guide-to-securing-personal-information">Privacy Act</a> says only that information must be destroyed “where the entity no longer needs the information for any purpose for which the information may be used or disclosed by the entity”.</p><p>That’s a loose requirement. A company could theoretically argue it “needs” to keep customer information for anything – such as defending against a civil claim in court, as part of its corporate records, or for marketing. This is especially the case when we have consented to those uses when we sign up for the services, another practice the Privacy Act allows.</p><p>This is a serious weakness with our privacy laws. Consumer data is big business. Companies are collecting – and keeping – much more personal information than they need without a truly legitimate commercial or legal purpose.</p><p>I call this trend “hyper-collection”. It’s turning companies into goldfields for hackers. Once personal information is stolen there is often <a href="https://www.afr.com/companies/telecommunications/minister-rebukes-optus-for-breach-we-should-not-expect-to-see-20220926-p5bkzr">little authorities can do</a>.</p><h2>It’s time to get serious about data privacy</h2><p>Australia needs to get more serious about unnecessary data collection and retention. As technology gets more interwoven into our daily lives, protecting personal data presents massive challenges.</p><p>The need for vigilance should have been made clear to the federal government in 2020, when its own <a href="https://www.afr.com/politics/federal/hacked-thousands-of-mygov-accounts-for-sale-on-dark-web-20200701-p55833">myGov website was hacked</a>.</p><p>The usernames and passwords of thousands of accounts were made available for sale on the dark web. Anyone buying those details would have had access to Medicare, Centrelink, National Disability Insurance Scheme and tax office records.</p><figure class="align-center "><figure style="width: 744px" class="wp-caption alignnone"><img loading="lazy" decoding="async" alt="The Australian government's MyGov website was hacked in 2020." src="https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" srcset="https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=600&#038;h=400&#038;fit=crop&#038;dpr=1 600w, https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=600&#038;h=400&#038;fit=crop&#038;dpr=2 1200w, https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=600&#038;h=400&#038;fit=crop&#038;dpr=3 1800w, https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;h=503&#038;fit=crop&#038;dpr=1 754w, https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=754&#038;h=503&#038;fit=crop&#038;dpr=2 1508w, https://images.theconversation.com/files/487029/original/file-20220928-16-4rlsq7.jpg?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=754&#038;h=503&#038;fit=crop&#038;dpr=3 2262w" sizes="auto, (min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px" width="754" height="503" /><figcaption class="wp-caption-text">The Australian government’s MyGov website was hacked in 2020. &#8211; Image from Shutterstock</figcaption></figure></figure><p>Privacy laws are too weak both in obligations and penalties. The fines for “serious interference with privacy” are $444,000 for individuals and $2.2 million for companies – hardly enough for a corporation the size of Optus to sit up and take notice. Nor do they offer comfort to those affected.</p><p>Legislative action is needed to clarify what information companies can collect, how they can collect it, and what they can do with it.</p><h2>Opportunities for action</h2><p>There are two obvious opportunities for the federal government to act.</p><p>The first is in its response to recommendations arising from the Attorney-General’s Department’s long-running review of the <a href="https://www.ag.gov.au/integrity/consultations/review-privacy-act-1988">Privacy Act</a> (which has yet to deliver its final report). Ironically Optus made a submission to the review that actually <a href="https://www.ag.gov.au/sites/default/files/2021-01/optus.PDF">suggested weakening privacy protections</a>.</p><p>The second is what it does with the <a href="https://www.homeaffairs.gov.au/reports-and-publications/submissions-and-discussion-papers/data-security">National Data Security Action Plan</a> being developed by the Department of Home Affairs.</p><p>The intention of this plan appears to be to treat data as a national asset. If so, it should strengthen policy and legislation around security, ensure Australians know their rights and responsibilities, and ensure consistent responses to cybercrime.</p><p>We need to scrutinise every company – not just Optus, and not just after the fact – and ask questions about their data collection. Why do they need to know things? What information are they keeping, how long for and why?</p><p>Without action, the next breach at this kind is a matter of when, not if.</p><hr /><p>We asked Optus to clarify the reasons it needs to keep identification data for six years but received no response.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading="lazy" decoding="async" src="https://counter.theconversation.com/content/191498/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" referrerpolicy="no-referrer-when-downgrade" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p><p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really-191498">original article</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://privacy.org.au/2022/10/01/optus-says-it-needed-to-keep-identity-data-for-six-years-but-did-it-really/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>This law makes it illegal for companies to collect third-party data to profile you. But they do anyway</title>
		<link>https://privacy.org.au/2022/09/21/this-law-makes-it-illegal-for-companies-to-collect-third-party-data-to-profile-you-but-they-do-anyway/</link>
		
		<dc:creator><![CDATA[Katharine Kemp]]></dc:creator>
		<pubDate>Wed, 21 Sep 2022 00:48:00 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5124</guid>

					<description><![CDATA[A little-known provision of the Privacy Act makes it illegal for many companies in Australia to buy or exchange consumers’ personal data for profiling or targeting purposes. It’s almost never enforced. The burning question is: why is there not a single published case of this law being enforced against companies “enriching” customer data for profiling and targeting purposes? <span class="excerpt-more"><a href="https://privacy.org.au/2022/09/21/this-law-makes-it-illegal-for-companies-to-collect-third-party-data-to-profile-you-but-they-do-anyway/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<p><span><a href="https://theconversation.com/profiles/katharine-kemp-402096">Katharine Kemp</a>, Senior Lecturer, Faculty of Law &amp; Justice, UNSW, <em><a href="https://theconversation.com/institutions/unsw-sydney-1414">UNSW Sydney</a></em></span></p><p>A little-known provision of the Privacy Act makes it illegal for many companies in Australia to buy or exchange consumers’ personal data for profiling or targeting purposes. It’s almost never enforced. In a <a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4224653">research paper</a> published today, I argue that needs to change.</p><p>“Data enrichment” is the intrusive practice of companies going behind our backs to “fill in the gaps” of the information we provide.</p><p>When you purchase a product or service from a company, fill out an online form, or sign up for a newsletter, you might provide only the necessary data such as your name, email, delivery address and/or payment information.</p><p>That company may then turn to other retailers or <a href="https://www.oracle.com/au/cx/advertising/data-enrichment-measurement/#data-enrichment">data brokers</a> to purchase or exchange extra data about you. This could include your age, family, health, habits and more.</p><p>This allows them to build a more detailed individual profile on you, which helps them predict your behaviour and more precisely target you with ads.</p><p>For almost ten years, there has been a law in Australia that makes this kind of data enrichment illegal if a company can “reasonably and practicably” request that information directly from the consumer. And at least <a href="https://consultations.ag.gov.au/rights-and-protections/privacy-act-review-discussion-paper/consultation/view_respondent?_b_index=60&#038;uuId=926016195">one major data broker</a> has asked the government to “remove” this law.</p><p>The burning question is: why is there not a single published case of this law being enforced against companies “enriching” customer data for profiling and targeting purposes?</p><h2>Data collection ‘only from the individual’</h2><p>The relevant law is Australian Privacy Principle 3.6 and is part of the federal <a href="https://www.legislation.gov.au/Details/C2022C00199">Privacy Act</a>. It applies to most organisations that operate businesses with annual revenues higher than A$3 million, and smaller data businesses.</p><p>The law says such organisations:</p><blockquote><p>must collect personal information about an individual only from the individual […] unless it is unreasonable or impracticable to do so.</p></blockquote><p>This “direct collection rule” protects individuals’ privacy by allowing them some control over information collected about them, and avoiding a combination of data sources that could reveal sensitive information about their vulnerabilities.</p><p>But this rule has received almost no attention. There’s only one published determination of the federal privacy regulator on it, and that was against the <a href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/AICmr/2020/69.html">Australian Defence Force</a> in a different context.</p><p>According to Australian Privacy Principle 3.6, it’s only legal for an organisation to collect personal information from a third party if it would be “unreasonable or impracticable” to collect that information from the individual alone.</p><p>This exception was intended to apply to <a href="https://www.oaic.gov.au/privacy/australian-privacy-principles-guidelines/chapter-3-app-3-collection-of-solicited-personal-information#collecting-directly-from-the-individual">limited situations</a>, such as when:</p><ul><li>the individual is being investigated for some wrongdoing</li><li>the individual’s address needs to be updated for delivery of legal or official documents.</li></ul><p>The exception shouldn’t apply simply because a company wants to collect extra information for profiling and targeting, but realises the customer would probably refuse to provide it.</p><h2>Who’s bypassing customers for third-party data?</h2><p>Aside from data brokers, companies also exchange information with each other about their respective customers to get extra information on customers’ lives. This is often referred to as “data matching” or “data partnerships”.</p><p>Companies tend to be very vague about who they share information with, and who they get information from. So we don’t know for certain who’s buying data-enrichment services from data brokers, or “matching” customer data.</p><p>Major companies such as <a href="https://www.amazon.com.au/gp/help/customer/display.html?nodeId=202075050&#038;ref_=footer_iba">Amazon Australia</a>, <a href="https://www.ebay.com.au/help/policies/member-behaviour-policies/user-privacy-notice-privacy-policy?id=4260&#038;mkevt=1&#038;mkcid=1&#038;mkrid=705-53470-19255-0&#038;campid=5337590774&#038;customid=&#038;toolid=10001#section4">eBay Australia</a>, <a href="https://www.facebook.com/privacy/policy/?subpage=1.subpage.4-InformationFromPartnersVendors">Meta</a> (Facebook), <a href="https://www.viacomcbsprivacy.com/en/policy">10Play Viacom</a> and <a href="https://twitter.com/en/privacy#twitter-privacy-1">Twitter</a> include terms in the fine print of their privacy policies that state they collect personal information from third parties, including demographic details and/or interests.</p><p><a href="https://policies.google.com/privacy?hl=en-US#infocollect">Google</a>, <a href="https://preferences.news.com.au/privacy">News Corp</a>, <a href="https://www.sevenwestmedia.com.au/privacy-policies/privacy">Seven</a>, <a href="https://login.nine.com.au/privacy?client_id=smh">Nine</a> and others also say they collect personal information from third parties, but are more vague about the nature of that information.</p><p>These privacy policies don’t explain why it would be unreasonable or impracticable to collect that information directly from customers.</p><h2>Consumer ‘consent’ is not an exception</h2><p>Some companies may try to justify going behind customers’ backs to collect data because there’s an obscure term in their privacy policy that mentions they collect personal information from third parties. Or because the company <em>disclosing</em> the data has a privacy policy term about sharing data with “trusted data partners”.</p><p>But even if this amounts to consumer “consent” under the relatively weak standards for consent in our current privacy law, this is not an exception to the direct collection rule.</p><p>The law allows a “consent” exception for government agencies under a separate part of the direct collection rule, but <em>not</em> for private organisations.</p><h2>Data enrichment involves personal information</h2><p>Many companies with third-party data collection terms in their privacy policies acknowledge this is personal information. But some may argue the collected data isn’t “personal information” under the Privacy Act, so the direct collection rule doesn’t apply.</p><p>Companies often exchange information about an individual without using the individual’s legal name or email. Instead they may use a unique advertising identifier for that individual, or <a href="https://help.abc.net.au/hc/en-us/articles/4402890310671">“hash” the email address</a> to turn it into a unique string of numbers and letters.</p><p>They essentially allocate a “code name” to the consumer. So the companies can exchange information that can be linked to the individual, yet say this information wasn’t connected to their actual name or email.</p><p>However, this information should still be treated as personal information because it can be linked back to the individual when combined with other <a href="https://www.austlii.edu.au/cgi-bin/viewdoc/au/cases/cth/FCAFC/2017/4.html">information about them</a>.</p><h2>At least one major data broker is against it</h2><p>Data broker <a href="https://www.experian.com.au/business/solutions/audience-targeting/digital-solutions-sell-side/digital-audiences-ss">Experian Australia</a> has asked the government to “remove” Australian Privacy Principle 3.6 “altogether”. In its <a href="https://consultations.ag.gov.au/rights-and-protections/privacy-act-review-discussion-paper/consultation/view_respondent?_b_index=60&#038;uuId=926016195">submission</a> to the Privacy Act Review in January, Experian argued:</p><blockquote><p>It is outdated and does not fit well with modern data uses.</p></blockquote><p>Others who profit from data enrichment or data matching would probably agree, but prefer to let sleeping dogs lie.</p><figure class="align-center zoomable"><figure style="width: 744px" class="wp-caption aligncenter"><a href="https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=1000&#038;fit=clip"><img loading="lazy" decoding="async" alt="A screenshot shows six different categories of consumer data offered by Experian." src="https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;fit=clip" srcset="https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=600&#038;h=369&#038;fit=crop&#038;dpr=1 600w, https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=600&#038;h=369&#038;fit=crop&#038;dpr=2 1200w, https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=600&#038;h=369&#038;fit=crop&#038;dpr=3 1800w, https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=45&#038;auto=format&#038;w=754&#038;h=463&#038;fit=crop&#038;dpr=1 754w, https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=30&#038;auto=format&#038;w=754&#038;h=463&#038;fit=crop&#038;dpr=2 1508w, https://images.theconversation.com/files/485485/original/file-20220920-14-p8l88p.png?ixlib=rb-1.1.0&#038;q=15&#038;auto=format&#038;w=754&#038;h=463&#038;fit=crop&#038;dpr=3 2262w" sizes="auto, (min-width: 1466px) 754px, (max-width: 599px) 100vw, (min-width: 600px) 600px, 237px" width="754" height="463" /></a><figcaption class="wp-caption-text">On its website, Experian claims to offer a ‘combination of demographic, geographic, financial and market research data &#8211; both online and offline’. &#8211; Screenshot/Experian</figcaption></figure></figure><p>Experian argued the law favours large companies with direct access to lots of customers and opportunities to pool data collected from across their own corporate group. It said companies with access to fewer consumers and less data would be disadvantaged if they can’t purchase data from brokers.</p><p>But the fact that some digital platforms impose extensive personal data collection on customers supports the case for stronger privacy laws. It doesn’t mean there should be a data free-for-all.</p><h2>Our privacy regulator should take action</h2><p>It has been three years since the consumer watchdog recommended <a href="https://www.accc.gov.au/system/files/Digital%20platforms%20inquiry%20-%20final%20report.pdf">major reforms</a> to our privacy laws to reduce the disadvantages consumers suffer from invasive data practices. These reforms are probably still years away, if they eventuate at all.</p><p>The direct collection rule is a very rare thing. It is an existing Australian privacy law that favours consumers. The privacy regulator should prioritise the enforcement of this law for the benefit of consumers.<!-- Below is The Conversation's page counter tag. Please DO NOT REMOVE. --><img loading="lazy" decoding="async" src="https://counter.theconversation.com/content/190758/count.gif?distributor=republish-lightbox-basic" alt="The Conversation" style="border: none !important; box-shadow: none !important; margin: 0 !important; max-height: 1px !important; max-width: 1px !important; min-height: 1px !important; min-width: 1px !important; opacity: 0 !important; outline: none !important; padding: 0 !important;" width="1" height="1" /><!-- End of code. If you don't see any code above, please get new code from the Advanced tab after you click the republish button. The page counter does not collect any personal data. More info: https://theconversation.com/republishing-guidelines --></p><p>This article is republished from <a href="https://theconversation.com">The Conversation</a> under a Creative Commons license. Read the <a href="https://theconversation.com/this-law-makes-it-illegal-for-companies-to-collect-third-party-data-to-profile-you-but-they-do-anyway-190758">original article</a>.</p>]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Newsletter 23 August 2022</title>
		<link>https://privacy.org.au/2022/08/23/newsletter-23-august-2022/</link>
		
		<dc:creator><![CDATA[Roger Clarke]]></dc:creator>
		<pubDate>Mon, 22 Aug 2022 22:45:21 +0000</pubDate>
				<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://privacy.org.au/?p=5089</guid>

					<description><![CDATA[Australian Privacy Foundation &#8211; Occasional Newsletter 23 August 2022 We&#8217;re combining this newsletter with the Annual Renewal Notice How to renew Check how much to pay ($275 Life, $40, or $10 concession), here Note: If you joined within the last 6 months, it won&#8217;t be necessary for you to renew until next year&#8217;s notice Pay&#8230; <span class="excerpt-more"><a href="https://privacy.org.au/2022/08/23/newsletter-23-august-2022/">Read More</a></span>]]></description>
										<content:encoded><![CDATA[<h4 align="center">Australian Privacy Foundation  &#8211;  Occasional Newsletter</h4>
<p align="center">23 August 2022

<p align="center"><b>We&#8217;re combining this newsletter with the Annual Renewal Notice</b>

<p align="center"><b>How to renew</b>

<ol>
<li>Check how much to pay ($275 Life, $40, or $10 concession), <a href="https://privacy.org.au/about/members/application-form/#RTFToC4">here</a>
<br>Note:  If you joined within the last 6 months, it won&#8217;t be necessary for you to renew until next year&#8217;s notice
<li>Pay the relevant amount into this account:
<br>Bendigo Bank, BSB 633000 A/c No. 126879162
<br><b>Include your name</b>, so that we can reconcile the account
<li><a href="mailto:treasurer@privacy.org.au">Email to us</a>, saying you&#8217;ve paid
</ol>

<p align="center"><b>Call for Nominations</b>
<p>As you can see from the brief outline of activities below, the APF Board is buried in work to defend privacy interests.  With a couple of recent retirements from the fray by major contributors, we&#8217;re short-handed.
<br>Please consider assisting the Board, whether casually on a matter of concern to you, via one of the Committees, or on the Board.  Details are <a href="https://privacy.org.au/about/contacts/">here</a>.
<br>If you&#8217;re aware of talent who we should be approaching, please put us in contact with them, or vice versa!

<p align="center"><b>Key Aspects of APF Activities during 2021-22</b>

<ol>
<li>Continued busyness, fighting against privacy-invasive behaviours, for privacy-sensitive practices, and for privacy protections. See at the bottom for a quick summary of recent major contributions
<li>A shortage of volunteer policy analysts and other active support
<li>We&#8217;re announcing <b>waiver of the annual fee for volunteers</b> who commit to
material assistance in relation to any of the following:
<ul>
<li>research into new technologies, business practices and government initiatives that are likely to have privacy implications
<li>drafting and review of proactive Policy Positions
<li>drafting and review of submissions in response to policy-influencing opportunities in parliaments, governments and industry sectors
<li>frequent social media postings on APF&#8217;s behalf, in the appropriate communication-style for one or more particular social media channels
<li>drafting of old-fashioned, but still-needed, media releases
<li>identification of media reports of suitable quality and relevance, and extraction and posting to <a href="http://lists.efa.org.au/mailman/listinfo/privacy_lists.efa.org.au">the privacy policy e-list</a> of the text and the source, with optional commentary on the topic
<li>monthly maintenance of <a href="https://privacy.org.au/publications/by-date/">the APF publications index-pages</a> (by date, by topic, and by jurisdiction)
</ul>
</ol>

<p align="center"><b>Some Major Areas of Recent APF Activities</b>

<p align="center"><b>The Federal Election</b>
<ul>
<li><a href="https://privacy.org.au/2022/04/11/media-release-federal-election-platform-principles-2022/">Media Release of 11 April 2022</a>
<li><a href="https://privacy.org.au/election2022/">The resulting 2022 Federal Election Scorecard, version of 19 May 22</a>
<li><b>The election-result was highly privacy-positive</b>.  The new AG has previously supported a privacy right of action, and the large cross-bench comprises Greens and Andrew Wilkie, whose platforms are strongly pro-privacy, plus &#8216;Teal Liberals&#8217; who are moderately so.
</ul>

<p align="center"><b>Your(?) ABC Joins the Digital Surveillance Economy
<br>Imposition of Mandatory Registration to use ABC iView</b>
<ul>
<li><a href="https://privacy.org.au/wp-content/uploads/2022/03/APF-Open-letter_-Mandatory-registration-for-use-of-ABC-iView-online-services-02032022.pdf">Open Letter &#8211; 2 Mar 22</a>
<li><a href="https://privacy.org.au/wp-content/uploads/2022/03/Reply_Australian-Privacy-Foundation_08.03.22.pdf">ABC Chair Ita Buttrose&#8217;s reply of 8 Mar 2022</a>
<li><a href="https://privacy.org.au/wp-content/uploads/2022/05/APF-ABC_iView_rply0428_220511.pdf">Letter to the ABC Chair on 11 May 2022</a>
<li><a href="https://privacy.org.au/2022/05/15/media-release-our-abc-iview-mandatory-login-requirement-unnecessary-and-linked-to-export-to-data-aggregators/">Media Release on 15 May 2022</a>
<li>See also this <a href="https://www.salingerprivacy.com.au/2022/01/06/the-abcs-of-privacy/">blog-entry by a past chair of APF</a>
</ul>

<p align="center"><b>Health Privacy</b>
<ul>
<li>Health Legislation Amendment (Information Sharing) Bill 2021 (Vic)
<li>National Disability Insurance Scheme (NDIS) &#8211; a serious data breach
<li>The unjustifiably demanding ACT COVID &#8216;Case Investigation&#8217; Form
</li>Health Insurance Companies&#8217; Marketing of Wearables to Consumers
</ul>

<p align="center"><b>Australia’s Electronic Surveillance Framework</b>
<ul>
<li>Submission to Dept of Home Affairs, of 8 Feb 2022, in conjunction with QCCL and Liberty Victoria
<li>Australian Border Force&#8217;s Warrant-less Access to Smartphone Comms
</ul>]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
