an article by Vasileios Chatzistefanou and Konstantinos Limniotis (Open University of Cyprus, Nicosia) published in International Journal of Electronic Governance Volume 11 Number 3/4 (2019)
Abstract
The anonymity provided by the so-called anonymous social networks is studied in this paper. More precisely, emphasis is given on investigating whether the underlying personal data processing in such networks may suffice to result in tracking or identification of the users.
To this end, five popular anonymous smart applications are being analysed through monitoring the outgoing traffic of Android devices in real-time when using these applications, to examine which personal data – including device data – are being processed by either the anonymous networks or third parties such as library providers.
The corresponding privacy policies of these applications are also examined, towards evaluating whether the information provided to the users is sufficient.
Our analysis concludes that there is personal data processing in place even in such (so-called anonymous) applications which in turn implies that users anonymity cannot be ensured, whilst the corresponding privacy policies may leave room for further improvement.
Showing posts with label personal_data. Show all posts
Showing posts with label personal_data. Show all posts
Monday, 2 December 2019
Friday, 15 February 2019
‘Personal data literacies’: A critical literacies approach to enhancing understandings of personal digital data
an article by Luci Pangrazio (Deakin University, Australia) and Neil Selwyn (Monash University, Australia) New Media & Society Volume 21 Issue 2 (February 2019)
Abstract
The capacity to understand and control one’s personal data is now a crucial part of living in contemporary society. In this sense, traditional concerns over supporting the development of ‘digital literacy’ are now being usurped by concerns over citizens’ ‘data literacies’. In contrast to recent data safety and data science approaches, this article argues for a more critical form of ‘personal data literacies’ where digital data are understood as socially situated and context dependent.
Drawing on the critical literacies tradition, the article outlines a range of salient socio-technical understandings of personal data generation and processing.
Specifically, the article proposes a framework of ‘Personal Data Literacies’ that distinguishes five significant domains:
The article concludes by outlining the implications of this framework for future education and research around the area of individuals’ understandings of personal data.
Abstract
The capacity to understand and control one’s personal data is now a crucial part of living in contemporary society. In this sense, traditional concerns over supporting the development of ‘digital literacy’ are now being usurped by concerns over citizens’ ‘data literacies’. In contrast to recent data safety and data science approaches, this article argues for a more critical form of ‘personal data literacies’ where digital data are understood as socially situated and context dependent.
Drawing on the critical literacies tradition, the article outlines a range of salient socio-technical understandings of personal data generation and processing.
Specifically, the article proposes a framework of ‘Personal Data Literacies’ that distinguishes five significant domains:
- Data Identification,
- Data Understandings,
- Data Reflexivity,
- Data Uses, and
- Data Tactics.
The article concludes by outlining the implications of this framework for future education and research around the area of individuals’ understandings of personal data.
Friday, 8 December 2017
Data is the New Love
via Doc Searles Weblog

Personal data, that is.
Because it’s good to give away – but only if you mean it.
And it’s bad to take it, even it seems to be there for the taking.
I bring this up because a quarter million pages (so far) on the Web say “data is the new oil.”
That’s because a massive personal data extraction industry has grown up around the simple fact that our data is there for the taking. Or so it seems. To them. And their apologists.
As a result, we’re at a stage of wanton data extraction that looks kind of like the oil industry did in 1920 or so:

Continue reading
Personal data, that is.
Because it’s good to give away – but only if you mean it.
And it’s bad to take it, even it seems to be there for the taking.
I bring this up because a quarter million pages (so far) on the Web say “data is the new oil.”
That’s because a massive personal data extraction industry has grown up around the simple fact that our data is there for the taking. Or so it seems. To them. And their apologists.
As a result, we’re at a stage of wanton data extraction that looks kind of like the oil industry did in 1920 or so:
Continue reading
Labels:
advertising,
data,
ideas,
Internet,
marketing,
personal_data
Saturday, 26 August 2017
What small businesses need to know about the General Data Protection Regulation
via Bytestart by Stuart Crook a data protection expert and Associate at the national law firm, Stephensons.

Despite Brexit, the UK government has confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect on 28 May 2018.
The aim of General Data Protection Regulation is to encourage companies across the European Union to think seriously about data protection. In practice, the new GDPR lays down some fairly stringent legislation, for both large and small businesses, governing the standards by which personal data is collected and stored.
To help UK businesses understand the new laws, and avoid the heavy punishments failure to abide by them bring, here’s a guide to the GDPR legislation.
Continue reading
Despite Brexit, the UK government has confirmed it will abide by the new General Data Protection Regulation (GDPR), which is due to come into effect on 28 May 2018.
The aim of General Data Protection Regulation is to encourage companies across the European Union to think seriously about data protection. In practice, the new GDPR lays down some fairly stringent legislation, for both large and small businesses, governing the standards by which personal data is collected and stored.
To help UK businesses understand the new laws, and avoid the heavy punishments failure to abide by them bring, here’s a guide to the GDPR legislation.
Continue reading
Thursday, 13 July 2017
Cyber Security Breaches Survey 2017
I’ve just been reading Privacy & Data Protection (Volume 17 Issue 5 (April/May 2017). An analysis of the above report published by the DCMS forms the subject of Expert Comment by Bridget Treacy, a partner at global law firm Hunton & Williams.
Ms Treacy tells us that it unsurprising that 61% of businesses view cyber security as an important issue.
What is surprising, both to Ms Treacy and to me, is that viewing security seriously and doing something about risk are two very different things. Specifically, the report notes that:
Ms Treacy, writing in a personal capacity, ends her article by commenting that “These are worrying conclusions for all of us who regularly entrust our personal data to UK companies for processing.”
Ms Treacy tells us that it unsurprising that 61% of businesses view cyber security as an important issue.
What is surprising, both to Ms Treacy and to me, is that viewing security seriously and doing something about risk are two very different things. Specifically, the report notes that:
- only 37% have segregated wireless networks, or any rules around the encryption of personal data;
- 33% have a formal policy that covers cyber security risks, and only 32% document these risks in business continuity plans, internal audits or risk registers;
- 29% have made specific board members responsible for cyber security;
- a mere 20% have required staff to attend cyber security training in the last twelve months, with non-specialist staff being particularly unlikely to have attended;
- although 19% of businesses are worried about their suppliers’ cyber security, only 13% require suppliers to adhere to specific cuber security standards or good practice; and
- only 11% have a cyber security incident management plan in place.
Ms Treacy, writing in a personal capacity, ends her article by commenting that “These are worrying conclusions for all of us who regularly entrust our personal data to UK companies for processing.”
Wednesday, 2 November 2016
CJEU Says Dynamic IP Addresses Can Constitute Personal Data
an article by Cynthia O'Donoghue and Curtis McCluskey (Reed Smith (Worldwide)) via Mondaq blog
The Court of Justice of the European Union ("CJEU") has ruled that dynamic IP addresses can constitute personal data.
Dynamic IP addresses, registered by a website provider when an individual accesses its website, shall constitute personal data where the operator has the legal means to combine the data with additional data (held by the internet service provider) to identify the data subject.
Continue reading
The Court of Justice of the European Union ("CJEU") has ruled that dynamic IP addresses can constitute personal data.
Dynamic IP addresses, registered by a website provider when an individual accesses its website, shall constitute personal data where the operator has the legal means to combine the data with additional data (held by the internet service provider) to identify the data subject.
Continue reading
Friday, 7 August 2015
Google decision leaves data controllers “exposed and vulnerable”
An article in Privacy & Data Protection Volume 15 Issue 5 (April/May 2015) briefly covers the decision in the UK Court of Appeal.
pdp journals does not make its articles available for free and there are no abstracts.
I have, however, found an article in Practical Law which will, I believe, set out the issues covered.
and also access a copy of the decision here
pdp journals does not make its articles available for free and there are no abstracts.
I have, however, found an article in Practical Law which will, I believe, set out the issues covered.
The Court of Appeal has held that individual users who claimed that their data were collected by Google without their consent for the purposes of more effectively targeting advertising are entitled to seek damages, despite not suffering any pecuniary loss. The decision effectively opens up a potential flood of litigation from individuals whose data are collected or processed unlawfully.Continue reading
Christopher Knight, 11KBW
and also access a copy of the decision here
Tuesday, 13 August 2013
Ruling shows that deleting personal data can remove burdens brought by data subject access requests, says expert
via Out-Law.com
A ruling by the High Court on the issue of dealing with data subject access requests highlights the positives that can be derived by businesses that decide to dispose of personal data records they no longer need, an expert has said.
Continue reading
A ruling by the High Court on the issue of dealing with data subject access requests highlights the positives that can be derived by businesses that decide to dispose of personal data records they no longer need, an expert has said.
Continue reading
Thursday, 4 July 2013
Google not always a 'data controller' of data processed by search engines, says legal advisor
via Out-Law.com
Internet search engine providers do not have to delete personal data from their index where that information has been published on third party websites, a legal advisor has said.
Continue reading
Internet search engine providers do not have to delete personal data from their index where that information has been published on third party websites, a legal advisor has said.
Continue reading
Wednesday, 19 December 2012
Redacting for anonymisation: Article 8 v Article 10 in child protection context
via Panopticon Blog by Robin Hopkins
Panopticon has reported recently on the ICO’s new Code of Practice on Anonymisation: see Rachel Kamm’s post here.
That Code offers guidance for ensuring data protection-compliant disclosure in difficult cases such as those involving apparently anonymous statistics, and situations where someone with inside knowledge (or a “motivated intruder”) could identify someone referred to anonymously in a disclosed document.
The Upper Tribunal in Information Commissioner v Magherafelt District Council [2012] UKUT 263 AAC grappled with those issues earlier this year in the context of disclosing a summarised schedule of disciplinary action.
Continue reading
Panopticon has reported recently on the ICO’s new Code of Practice on Anonymisation: see Rachel Kamm’s post here.
That Code offers guidance for ensuring data protection-compliant disclosure in difficult cases such as those involving apparently anonymous statistics, and situations where someone with inside knowledge (or a “motivated intruder”) could identify someone referred to anonymously in a disclosed document.
The Upper Tribunal in Information Commissioner v Magherafelt District Council [2012] UKUT 263 AAC grappled with those issues earlier this year in the context of disclosing a summarised schedule of disciplinary action.
Continue reading
Tuesday, 24 July 2012
What happens to my data? A novel approach to informing users of data processing practices
an article by Bibi van den Berg and Simone van der Hof (Centre for Law in the Information Society at Leiden University) published in First Monday Voume 17 Number 7 (July 2012)
Abstract
Citizens increasingly use the Internet to buy products or engage in interactions with others, both individuals and businesses. In doing so they invariably share (personal) data. While extensive data protection legislation exists in many countries around the world, citizens are not always aware (enough) of their rights and obligations with respect to sharing (personal) data. To remedy this gap, users ought to become better informed of companies’ data processing practices.
In the past, various research groups have attempted to create tools to this end, for example through the use of icons or labels similar to those used in nutrition. However, none of these tools has gained extensive adoption, mostly because it turns out that capturing privacy legislation in simple, accessible graphics is a complicated task. Moreover, we believe that the tools that were developed so far do not align closely enough with the preferences and understanding of ordinary users, precisely because they are too “legalistic”.
In this paper we discuss a user study conducted to gain a better understanding of the kinds of information users would wish to receive with respect to companies’ data processing practices, and the form this information ought to take. On the basis of this user study we found a new approach to communicating this information, in which we return to the OECD’s Fair Information Principles, which formed the basis for (almost all) data protection legislation.
We end the paper with a rudimentary proposal for an end user tool to be used on companies’ websites.
Full text (HTML)
Abstract
Citizens increasingly use the Internet to buy products or engage in interactions with others, both individuals and businesses. In doing so they invariably share (personal) data. While extensive data protection legislation exists in many countries around the world, citizens are not always aware (enough) of their rights and obligations with respect to sharing (personal) data. To remedy this gap, users ought to become better informed of companies’ data processing practices.
In the past, various research groups have attempted to create tools to this end, for example through the use of icons or labels similar to those used in nutrition. However, none of these tools has gained extensive adoption, mostly because it turns out that capturing privacy legislation in simple, accessible graphics is a complicated task. Moreover, we believe that the tools that were developed so far do not align closely enough with the preferences and understanding of ordinary users, precisely because they are too “legalistic”.
In this paper we discuss a user study conducted to gain a better understanding of the kinds of information users would wish to receive with respect to companies’ data processing practices, and the form this information ought to take. On the basis of this user study we found a new approach to communicating this information, in which we return to the OECD’s Fair Information Principles, which formed the basis for (almost all) data protection legislation.
We end the paper with a rudimentary proposal for an end user tool to be used on companies’ websites.
Full text (HTML)
Friday, 25 May 2012
A market for unbiased private data: Paying individuals according to their privacy attitudes
an article by Christina Aperjis and Bernardo A. Huberman (Hewlett–Packard Laboratories, Palo Alto, California) published in First Monday Volume 17 Number 5 (May 2012)
Abstract
Since there is, in principle, no reason why third parties should not pay individuals for the use of their data, we introduce a realistic market that would allow these payments to be made while taking into account the privacy attitude of the participants.
And, since it is usually important to use unbiased samples to obtain credible statistical results, we examine the properties that such a market should have and suggest a mechanism that compensates those individuals that participate according to their risk attitudes.
Equally important, we show that this mechanism also benefits buyers, as they pay less for the data than they would if they compensated all individuals with the same maximum fee that the most concerned ones expect.
Full article (HTML)
Abstract
Since there is, in principle, no reason why third parties should not pay individuals for the use of their data, we introduce a realistic market that would allow these payments to be made while taking into account the privacy attitude of the participants.
And, since it is usually important to use unbiased samples to obtain credible statistical results, we examine the properties that such a market should have and suggest a mechanism that compensates those individuals that participate according to their risk attitudes.
Equally important, we show that this mechanism also benefits buyers, as they pay less for the data than they would if they compensated all individuals with the same maximum fee that the most concerned ones expect.
Full article (HTML)
Subscribe to:
Posts (Atom)