ECommerce Computer Science Tripos Part II International Perspectives on Internet Legislation Easter Term 2010 Richard Clayton.

Slides:



Advertisements
Similar presentations
BY FRANK. MARKETING AND ADVERTISING IN E-COMMERCE Online Marketing and Advertising Considerations Posting on Web Site Content Storage of Web Site Content.
Advertisements

Tips and tools to keep you and your information safe on-line. We will go over a lot of information today, so it is important to pay attention and follow.
HIPAA Privacy Training. 2 HIPAA Background Health Insurance Portability and Accountability Act of 1996 Copyright 2010 MHM Resources LLC.
Health Insurance Portability and Accountability Act HIPAA Education for Volunteers and Students.
The Health Insurance Portability and Accountability Act of 1996– charged the Department of Health and Human Services (DHHS) with creating health information.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
Economics & Law Computer Science Tripos Part 1B UK Law and the Internet Easter 2011 Richard Clayton Jack Lang.
Health Insurance Portability & Accountability Act (HIPAA)
1.3.1.G1 © Family Economics & Financial Education – Revised October 2004 – Consumer Protection Unit – Identity Theft Funded by a grant from Take Charge.
PRIVACY COMPLIANCE An Introduction to Privacy Privacy Training.
ECommerce Computer Science Tripos Part II International Perspectives on Internet Legislation Lent Term 2011 Richard Clayton.
Introduction to the APPs and the OAIC’s regulatory approach Presented by: Este Darin-Cooper Director, Regulation and Strategy May 2015.
Legislation Who governs e-commerce?. E-commerce is regulated by laws and guidelines. These aim to ensure that sites operate effectively and that online.
Legalities of ICT Chapter 7.
ECommerce Computer Science Tripos Part II An International Perspective on Internet Legislation 17 th May 2007 Richard Clayton.
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Electronic Signatures This work is the intellectual property of the author. Permission is granted for this material.
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
Data Protection Act. Lesson Objectives To understand the data protection act.
Marketing - Best Practice from a Legal Point of View Yvonne Cunnane - Information Technology Law Group 30 November 2006.
Practical Information Management
E-commerce Law Electronic signatures and security.
E-commerce Law Consumer Protection. This lecture will examine legislation protecting consumers. We will look specifically at: –Consumer Protection (Distance.
Legislation For e-commerce to operate correctly, it needs to adhere to the relevant legislation. These laws protect both the business and the consumer.
Eric J. Pritchard One Liberty Place, 46 th Floor 1650 Market Street Philadelphia, Pennsylvania (215)
Infrastructure II commercial relationships Chris Reed Professor of Electronic Commerce Law Centre for Commercial Law Studies 1.
HIPAA PRIVACY AND SECURITY AWARENESS.
CLOUD AND SECURITY: A LEGISLATOR'S PERSPECTIVE 6/7/2013.
Law Additional Exercise ANSWERS. Question #1 (a) Any one of: gain unauthorised access (1st) to computer material (1) gain (unauthorised) access to computer.
Elma Graham. To understand what data protection is To reflect on how data protection affects you To consider how you would safeguard the data of others.
Component 4: Introduction to Information and Computer Science Unit 2: Internet and the World Wide Web 1 Component 4/Unit 2Health IT Workforce Curriculum.
Computerized Networking of HIV Providers Workshop Data Security, Privacy and HIPAA: Focus on Privacy Joy L. Pritts, J.D. Assistant Research Professor Health.
Computing Essentials 2014 Privacy, Security and Ethics © 2014 by McGraw-Hill Education. This proprietary material solely for authorized instructor use.
Part 6 – Special Legal Rights and Relationships Chapter 35 – Privacy Law Prepared by Michael Bozzo, Mohawk College © 2015 McGraw-Hill Ryerson Limited 34-1.
OCR Nationals Level 3 Unit 3.  To understand how the Data Protection Act 1998 relates to the data you will be collecting, storing and processing  To.
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
INTERLEGES AGM KIEV THE “ESSENTIALS” OF LAW FIRM WEBSITES.
Data Protection Act AS Module Heathcote Ch. 12.
The law on Intermediary Liability in India
Prepared by Douglas Peterson, University of Alberta 15-1 Part 3 – The Law of Contract Chapter 15 Electronic Business Law and Data Protection.
COPYRIGHT © 2011 South-Western/Cengage Learning. 1 Click your mouse anywhere on the screen to advance the text in each slide. After the starburst appears,
Why the Data Protection Act was brought in  The 1998 Data Protection Act was passed by Parliament to control the way information is handled and to give.
Regulation of Personal Information Sally Brierley & Emma Harvey.
C HAPTER 34 Code Blue Health Sciences Edition 4. Confidentiality of sensitive information is an important issue in healthcare. Breaches of confidentiality.
IM NETWORK MEETING 20 TH JULY, 2010 CONSULTATION WITH 3 RD PARTIES.
Alert against Online Shopping Frauds. Online Shopping A form of electronic commerce whereby consumers directly buy goods or services from a seller over.
Information Systems Unit 3.
Information Management in Retail: A Legal Perspective Chris Hill Barlow Lyde & Gilbert LLP 17 September 2009.
© 2010 Pearson Education, Inc., publishing as Prentice-Hall 1 INTERNET LAW AND E-COMMERCE © 2010 Pearson Education, Inc., publishing as Prentice-Hall CHAPTER.
Intellectual Property. Confidential Information Duty not to disclose confidential information about a business that would cause harm to the business or.
Protecting Yourself from Fraud including Identity Theft Personal Finance.
ICT and the Law Mr Conti. Did you see anything wrong with that? Most people wouldn’t want that sort of information posted in a public place. Why? Because.
Protecting Yourself from Fraud including Identity Theft Advanced Level.
ICT Legislation  Copyright, Designs and Patents Act (1988);  Computer Misuse Act (1990);  Health and Safety at Work Act (1974);  EU Health and Safety.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
DATA PROTECTION ACT DATA PROTECTION ACT  Gives rights to data subjects (i.e. people who have data stored about them on a computer)  Information.
Introduction to the Australian Privacy Principles & the OAIC’s regulatory approach Privacy Awareness Week 2016.
Data protection—training materials [Name and details of speaker]
HIPAA Training. What information is considered PHI (Protected Health Information)  Dates- Birthdays, Dates of Admission and Discharge, Date of Death.
Yes, it’s the holidays... A time of joy, a time of good cheer, a time of celebration... From the Office of the Chief Human Capital Officer (CHCO ) Privacy.
1 HIPAA’s Impact on Depository Financial Institutions 2 nd National Medical Banking Institute Rick Morrison, CEO Remettra, Inc.
Surveillance around the world
Infrastructure II commercial relationships
GDPR Overview Gydeline – October 2017
Data Protection Legislation
GDPR Overview Gydeline – October 2017
Introduction to GDPR 09/11/2018.
G.D.P.R General Data Protection Regulations
The new data protection rules
Protecting Yourself from Fraud including Identity Theft
Protecting Yourself from Fraud including Identity Theft
Presentation transcript:

ECommerce Computer Science Tripos Part II International Perspectives on Internet Legislation Easter Term 2010 Richard Clayton

May 2010International Perspectives on Internet Legislation Outline Data Protection Act 1998 –US Privacy Laws Government access to data –Regulation of Investigatory Powers Act 2000 –US PATRIOT Act 2001 –Privacy & Electronic Communications Regulations –Data Retention E-Commerce Regulations –Copyright Infringement –Deep Linking, Brands and other web-page issues –Phishing, Politics and International Policing

May 2010International Perspectives on Internet Legislation Further Reading Most of the relevant statutes available online –many court judgments now also appearing online –reading acts of parliament is relatively straightforward (judgments vary in clarity!) –however, law is somewhat flexible in practice, and careful textual analysis may disappoint Wealth of explanatory websites –often solicitors (and expert witnesses) seeking to show their expertise IANAL! (although I am sometimes an expert)

May 2010International Perspectives on Internet Legislation Data Protection Act 1998 Overriding aim is protect the interests of (and avoid risks to) the Data Subject –differs from US “privacy protection” landscape Data processing must comply with the eight principles (as interpreted by the regulator) All data controllers must “notify” (£35) the Information Commissioner (unless exempt) –exemptions for “private use”, “basic business purposes” (but not CCTV) : see website for details Data Subjects have a right to see their data

May 2010International Perspectives on Internet Legislation US Privacy US approach is sector specific (and often driven by specific cases) For example: –privacy of mail (1782, 1825, 1877) –privacy of telegrams (state laws in the 1880s) –privacy of Census (1919) –Bank Secrecy Act 1970 (requires records kept!) –Privacy Act 1974 (regulates the Government) –Cable Communications Policy Act 1984 (viewing data) –Video Privacy Protection Act 1988 (purchase/rentals) –Telephone Consumer Protection Act 1991 (DNC in 2003) –Driver’s Privacy Protection Act 1994 (license data)

May 2010International Perspectives on Internet Legislation HIPAA US Federal Law (Health Insurance Portability and Accountability Act 1996) Sets standards for privacy and security –Personal Health Information (medical & financial) must be disclosed to individual upon request, and when required by law or for treatment, payments etc (but info must be minimized where appropriate) –all disclosures must be recorded –must record, eg, that patients to be called at work –security implies admin, physical & technical safeguards Requires use of a universal (10digit) identifier

May 2010International Perspectives on Internet Legislation Sarbanes-Oxley US Federal Law (Public Company Accounting Reform and Investor Protection Act of 2002) –introduced after Enron/WorldCom/etc scandals Public companies have to evaluate and disclose the effectiveness of their internal controls as they relate to financial reporting Auditors required to understand & evaluate the company controls Companies now have to pay much more attention to data retention and data retrieval

May 2010International Perspectives on Internet Legislation Security Breach Disclosure California State Law SB1386 (2002) updated by AB1950 (2004) –must protect personal data –if disclosed then must tell individuals involved Now taken up by 45 (of 50) states & talk of a Federal Law (for harmonisation) –early on had a dramatic impact, now (100 million disclosures later) becoming part of the landscape –no central reporting (so hard to track numbers) –some disclosures look like junk mail! EU will soon have a provision for telcos/ISPs

May 2010International Perspectives on Internet Legislation RIP Act 2000 Part I, Chapter Iinterception –replaced IOCA; Exceptions for “Lawful Business Practice” Part I, Chapter IIcommunications data –replaced informal scheme under DPA 1984, 1998 Part IIsurveillance & informers –necessary for HRA 1998 compliance Part IIIencryption –end of a long road, starting with “key escrow” Part IVoversight etc –sets up tribunal & Interception Commissioner

May 2010International Perspectives on Internet Legislation Electronic Communications Act 2000 Part II – electronic signatures –electronic signatures “shall be admissible in evidence” –creates power to modify legislation for the purposes of authorising or facilitating the use of electronic communications or electronic storage –not as relevant, in practice, as people in the “dot com bubble” thought it would be. Most systems continue to use contract law to bind people to commitments. Remaining parts of EU Electronic Signature Directive were implemented as SI 318(2002)

May 2010International Perspectives on Internet Legislation RIP Act 2000 – Encryption Basic requirement is to “put this material into an intelligible form” –can be applied to messages or to stored data –you can supply the key instead –if you claim to have lost or forgotten the key or password, prosecution must prove otherwise Keys can be demanded –notice must be signed by Chief Constable –notice can only be served at top level of company –reasoning must be reported to commissioner Specific “tipping off” provisions may apply

May 2010International Perspectives on Internet Legislation PATRIOT Act Federal Law passed after 9/11 (strictly, the Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism Act of 2001) –huge range of provisions, such as roving wiretaps, access to business records without court order, removal of restrictions on domestic activity, removes many checks & balances generally, permits more information sharing, permits access to “content” in hacking cases… Re-authorised in PATRIOT II (2006)

May 2010International Perspectives on Internet Legislation Privacy & Electronic Communications Implementing EU Directive 2002/58/EC Replaces existing Directive (& UK Regulations) Rules on phone directories, location info etc Bans unsolicited marketing to natural persons – but not to legal persons –but see your ISP’s “acceptable use policy” Controls on the use of “cookies” –transparency: so should avoid, or provide a choice –or if essential, then tell people what you’re doing

May 2010International Perspectives on Internet Legislation Data Retention European Directive passed in 2005 (in record time, following attacks in Madrid & London) Done under 1 st pillar (internal market) rather than 3 rd pillar (police/judicial co-operation) Wording of Directive makes little technical sense – and is therefore being implemented haphazardly and inconsistently. UK transposed this in April 2009 –only applies to you if Home Office sends you a notice –notices supposed to be sent to all (public) CSPs

May 2010International Perspectives on Internet Legislation Copyright Material US has the DMCA, “safe harbor” until notified then must remove; but may be “put back” EU has eCommerce Directive and a “hosting” immunity – which UGC might qualify for Under the UK’s Digital Economy Act 2010 there is to be “graduated response” to notification of file sharing infringements –it is envisaged that only a court will grant access to customer details (or of course a police officer can serve RIP paperwork) –similar initiatives elsewhere, but not yet? in US

May 2010International Perspectives on Internet Legislation E-Commerce Law Distance Selling Regulations (2000) –remote seller must identify themselves –details of contract must be delivered ( is OK) –right to cancel (unless service already delivered) –contract VOID if conditions not met E-Commerce Directive (2002) –restates much of the above –online selling and advertising is subject to UK law if you are established in the UK – whoever you sell to –significant complexities if selling to foreign consumers if you specifically marketed to them

May 2010International Perspectives on Internet Legislation Politics & Terrorism Mainstream politics is now following the extremists onto the web –especially Obama (but Howard Dean did it first) Many issues arise on content –defamation, incitement, anti-terror laws Raising money raises lots of issues for parties: –need to know identity if amount over £200 –need to report if over £5000 (or even £1000) –need to identify “permissible donors” –raising money for terrorism forbidden (!)

May 2010International Perspectives on Internet Legislation Deep Linking Pointing at specific pages on another website rather than the top level. Courts ruling against this when “passing off” –1996 Shetland Times v Shetland News (UK) settled –1997 TicketMaster v Microsoft (US) settled –2000 TicketMaster v tickets.com (US) allowed [since clear] –2006 naukri.com v bixee.com (India) injunction –2006 HOME v OFiR (Denmark) allowed [not a database] –2006 SFX motor sports v supercrosslive (Texas) injunction –2007 Copiepresse Press v Google (Belgium) forbidden

May 2010International Perspectives on Internet Legislation Framing, Inlining & Linking Framing is being permitted for search engines –Kelly v Ariba (US) : thumbnails of Kelly’s photos in Ariba’s search engine were “fair use”, and full-size “inlined” or “framed” copies were also OK –but don’t do your own design of a Dilbert page! Linking is much less of a problem –even from disparaging site (US) Ford Motor Co case –but linking to bad things generally bad In general, framing causes problems –Hard Rock Café v Morton (US) “single visual presentation” –Washington Post v Total News (US) settled

May 2010International Perspectives on Internet Legislation Brand Names Significant protection for brands in domain names –mikerowsoft.com settled, microsuck.com survived… Using other people’s brand names in meta-tags doesn’t usually survive legal challenge Many US rulings on “adwords” now occurring; if you just buy keyword then OK, but problems if use trademarks in ad copy, or on landing page Germany, UK, Austria following US line, France is not. ECJ have followed the US approach.

May 2010International Perspectives on Internet Legislation Phishing Sites clearly illegal (branded to look identical to real banks) Fraud Act 2006 ensures they can be illegal even if not yet operating Should you be concerned about what you are being asked to do, Fraud Act (& Serious Crime Bill) worth checking for a range of shiny new offences involving the creation of tools for fraud and offences of helping criminals…

May 2010International Perspectives on Internet Legislation International Policing Foreign police priorities differ (as do laws) –specialist advice is essential Police do not usually operate across borders –Interpol mainly a fax distribution centre –although we now have European Arrest Warrant Problem for searches of remote/cloud systems –once police become aware must use MLAT –MLAT allows the diplomats to consider the issues –but it often makes glaciers look quick Gambling, non-banks &c => no US holidays!

May 2010International Perspectives on Internet Legislation Review Important to understand difference between European Data Protection & US privacy –however, much common ground and ideas like security breach notification gaining traction Governments now grok computers and the Internet and are getting into data retention, traffic analysis &c in a major way Much still to be finally settled on the web Being a backroom boffin in serious crime is not as safe as it once was

May 2010International Perspectives on Internet Legislation Ignorance of the law excuses no man; not that all men know the law; but because ‘tis an excuse every man will plead, and no man can tell how to confute him. John Selden ( )