Access Denied! Contrasting Data Access in the United States and Ireland

Open access

Abstract

The ability of an Internet user to access data collected about himself as a result of his online activity is a key privacy safeguard. Online, data access has been overshadowed by other protections such as notice and choice. This paper describes attitudes about data access. 873 US and Irish Internet users participated in a survey designed to examine views on data access to information held by online companies and data brokers. We observed low levels of awareness of access mechanisms along with a high desire for access in both participant groups. We tested three proposed access systems in keeping with industry programs and regulatory proposals. User response was positive. We conclude that access remains an important privacy protection that is inadequately manifested in practice. Our study provides insight for lawmakers and policymakers, as well as computer scientists who implement these systems.

If the inline PDF is not rendering correctly, you can download the PDF file here.

  • [1] 104th Congress Public Law 104-191. Health Insurance Portability and Accountability Act of 1996 1996.

  • [2] 105th Congress Public Law 105-277. Children’s Online Privacy Protection Act of 1998 1998.

  • [3] 108th Congress Public Law 108-159. Fair and Accurate Credit Transactions Act of 2003 2003.

  • [4] 114th Congress S.668. Data Broker Accountability and Transparency Act of 2015 2015.

  • [5] A. Acquisti and R. Gross. Privacy Enhancing Technologies chapter Imagined Communities: Awareness Information Sharing and Privacy on the Facebook page 11. Springer Berlin Heidelberg 2006. G. Danezis and P. Golle eds.

  • [6] Act no. 6 of 2003. Data Protection (Amendment) Act 2003 2003.

  • [7] Acxiom. Viewing and editing data about you. http://documentation.acxiom-online.com/aspect/#b6811t5921n/s-1/s15/s15b1851/s15b1859 [Accessed: 07- Jun- 2015].

  • [8] American Civil Liberties Union. Right to Know Act (ab 1291). https://www.aclunc.org/our-work/legislation/rightknow-act-ab-1291 [Accessed: 02- Jun- 2015].

  • [9] J. Angwin. Dragnet Nation: A quest for privacy security and freedom in a world of relentless surveillance. Times Books 2014.

  • [10] K. Bachman. Senate commerce report says data brokers ‘operate behind a veil of secrecy’ 2013. http://www.adweek.com/news/technology/senate-commerce-report-says-databrokers-operate-behind-veil-secrecy-154579 [Accessed: 17- Jun- 2015].

  • [11] Better Regulation. EU Data Protection Regulation 2014. http://www.betterregulation.com/ie/data-protectionproposals [Accessed: 17- Jun- 2015].

  • [12] M. Brantley. Acxiom begins consumer access to some data 2013. http://www.arktimes.com/ArkansasBlog/archives/2013/09/04/acxiom-begins-consumer-access-to-some-data [Accessed: 17- Jun- 2015].

  • [13] J. Brill. “Reclaim Your Name” keynote address at the 23rd computers freedom and privacy conference 2013. https://www.ftc.gov/sites/default/files/documents/public_statements/reclaim-your-name/130626computersfreedom.pdf [Accessed: 17- Jun- 2015].

  • [14] Business World. Irish data protection is not “soft” 2015. https://www.businessworld.ie/european-news/Irish-dataprotection-is-not-soft--1667.html [Accessed: 20- Jul- 2015].

  • [15] California Business and Professions Code section 22575-22579 online privacy protection act 2003. http://www.leginfo.ca.gov/cgi-bin/displaycode?section=bpc&group=22001-23000&file=22575-22579 [Accessed: 14-Feb-2016].

  • [16] California AB-1291. Right to Know Act of 2013: disclosure of a customer’s personal information 2013.

  • [17] California Civil Code section 1798.83. California Shine the Light law 2005.

  • [18] Cint. Cint - about us 2015. http://www.cint.com/about [Accessed: 06- Apr- 2015].

  • [19] M. Cogley. Of course Facebook would go to a country with the lowest levels of data protection 2015. http://www.newstalk.com/Of-course-Facebook-would-go-to-a-countrywith- the-lowest-levels-of-data-protection- [Accessed: 20- Jul- 2015].

  • [20] Administration discussion draft: Consumer Privacy Bill of Rights Act of 2015 2015. https://www.whitehouse.gov/sites/default/files/omb/legislative/letters/cpbr-act-of-2015-discussion-draft.pdf [Accessed: 15- Jun- 2015].

  • [21] Council of the European Union. Proposal for a regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (general data protection regulation) 9565/15 2015.

  • [22] Council of the European Union. Proposal for a regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (general data protection regulation) [first reading]-analysis of the final compromise text with a view to agreement 15039/15 2015.

  • [23] L. Cranor J. Reagle and M. Ackerman. The Internet Upheaval: Raising Questions Seeking Answers in Communications Policy chapter Beyond concern: Understanding net users’ attitudes about online privacy pages 47-70. MIT Press 2000. I. Vogelsang and B. Compaine eds.

  • [24] S. Curtis. Facebook ordered to stop tracking non-users in Belgium or face fines 2015. http://www.telegraph.co.uk/technology/facebook/11985694/Facebook-ordered-to-stoptracking-non-users-in-Belgium-or-face-fines.html [Accessed 22-Feb-2016].

  • [25] P. Dixon. Testimony of Pam Dixon executive director World Privacy Forum before the Senate Committee on Commerce Science and Transportation “what information do data brokers have on consumers and how do they use it?” 2013. http://www.worldprivacyforum.org/wp-content/uploads/2013/12/WPF_PamDixon_CongressionalTestimony_DataBrokers_2013_fs.pdf [Accessed: 15- Jul- 2015].

  • [26] Equifax. Equifax 2014 annual report 2014. http://www.equifax.com/pdfs/corp/Equifax_2014_Annual_Report.pdf [Accessed: 03- Aug- 2015].

  • [27] Europe Versus Facebook. Get your data! make an access request at Facebook! http://www.europe-v-facebook.org/EN/Get_your_Data_/get_your_data_.html [Accessed: 25- Oct- 2015].

  • [28] European Commission. Why do we need an EU data protection reform? 2012. http://ec.europa.eu/justice/dataprotection/document/review2012/factsheets/1_en.pdf [Accessed 28-Nov-2015].

  • [29] Experian. Experian annual report 2015 2015. http://annualreport.experianplc.com/2015/_resources/pdf/ ExperianAnnualReport2015.pdf [Accessed: 03- Aug- 2015].

  • [30] Federal Trade Commission. Privacy online: A report to Congress. Technical report FTC 1998.

  • [31] Federal Trade Commission. A summary of your rights under the Fair Credit Reporting Act. Technical report FTC 2009. https://www.consumer.ftc.gov/articles/pdf-0096-fair-creditreporting-act.pdf [Accessed: 20-Jul-2015].

  • [32] Federal Trade Commission. Cookies: Leaving a trail on the web. Consumer Report 2011. https://www.consumer.ftc.gov/articles/0042-cookies-leaving-trail-web [Accessed: 14-Feb-2016].

  • [33] Federal Trade Commission. FTC to study data broker industry’s collection and use of consumer data 2012.

  • [34] Federal Trade Commission. Protecting consumer privacy in an era of rapid change. Technical report FTC 2012.

  • [35] Federal Trade Commission. Data brokers: A call for transparency and accountability May 2014. https://www.ftc.gov/system/files/documents/reports/databrokers-call-transparency-accountability-report-federaltrade-commission-may-2014/140527databrokerreport.pdf [Accessed: 29-Nov-2015].

  • [36] S. Fennell. Information re data brokers in Ireland. Personal email Sept. 9 2014. e-mail: infodataprotection.ie Message: ‘In relation to your email you may wish to direct any queries you have to the Irish Brokers Association. The following link will take you to their website: http://www.iba.ie/’.

  • [37] J. Fromholz. The European Union Data Privacy Directive. Berkeley Technology Law Journal 15(1):471-472 2000.

  • [38] FundingUniverse. Acxiom corporation history 2011. http://www.fundinguniverse.com/company-histories/acxiomcorporation-history/ [Accessed: 06- Jun- 2015].

  • [39] S. Gibbs. Belgium takes Facebook to court over privacy breaches and user tracking 2015. http://www.theguardian.com/technology/2015/jun/15/belgium-facebook-courtprivacy-breaches-ads [Accessed: 20- Jul- 2015].

  • [40] Google. Control your Google ads. https://www.google.com/settings/ads/ [Accessed: 15- Jul- 2015].

  • [41] Google. Privacy and terms. https://www.google.com/policies/privacy/key-terms/#toc-terms-personal-info [Accessed: 14-Feb-2016].

  • [42] D. Gross. Forget godzilla: Facebook rolls out its own dinosaur 2014. http://edition.cnn.com/2014/05/23/tech/social-media/facebook-dinosaur-mascot/ [Accessed: 15- Jul-2015].

  • [43] G. Gross. FTC: Congress should rein in data brokers 2014. http://www.pcworld.com/article/2168060/ftc-congressshould-rein-in-data-brokers.html [Accessed: 15- Jun- 2015].

  • [44] H. Teufel III. The Fair Information Practice Principles: Framework for privacy policy at the Department of Homeland Security. Technical report The Privacy Office U.S. Department of Homeland Security 2008.

  • [45] Irish Brokers Association. About the IBA. http://iba.ie/about-us/about-the-iba/ [Accessed: 09- Sep- 2014].

  • [46] Irish Brokers Association. Irish brokers association. http://iba.ie [Accessed: 09- Sep- 2014].

  • [47] J. Jerome and B. Dambrine. Comparing the Data Broker Bill to the Consumer Privacy Bill of Rights 2015. http:// www.futureofprivacy.org/2015/03/16/comparing-the-databroker-bill-to-the-consumer-privacy-bill-of-rights/ [Accessed: 15- Jun- 2015].

  • [48] K. Harris Attorney General of California. Privacy on the go recommendations for the mobile ecosystem 2013. http://oag.ca.gov/sites/all/files/agweb/pdfs/privacy/privacy_ on_the_go.pdf [Accessed: 14-Feb-2016].

  • [49] A. Kittur E. Chi and B. Suh. Crowdsourcing user studies with mechanical turk. 26th Special Interest Group on Computer-Human Interaction (SIGCHI) Conference 2008.

  • [50] M. Liedtke. Google demystifies privacy controls with new redesign 2015. http://www.inc.com/associated-press/googletries-to-demystify-privacy-controls-with-new-approach.html [Accessed: 15- Jul- 2015].

  • [51] K. Lillington. Strong data protection laws better for EU than sniping 2015. http://www.irishtimes.com/business/ technology/strong-data-protection-laws-better-for-eu-thansniping-1.2185370 [Accessed: 20- Jul- 2015].

  • [52] M. Madden and L. Rainie. Americans’ attitudes about privacy security and surveillance 2015. http://www.pewinternet.org/2015/05/20/americans-attitudes-aboutprivacy- security-and-surveillance/ [Accessed: 29-Nov-2015].

  • [53] Microsoft. Safety & security center. https://www.microsoft.com/security/online-privacy/overview.aspx [Accessed: 15- Jul- 2015].

  • [54] Microsoft. Your privacy and Microsoft personalized ads. http://choice.microsoft.com/en-US [Accessed: 15- Jul-2015].

  • [55] P. Newenham. Facebook responds to Belgian tracking claims 2015. http://www.irishtimes.com/business/technology/facebook-responds-to-belgian-tracking-claims-1.2219799 [Accessed: 20- Jul- 2015].

  • [56] L. Newman. Here’s how Facebook chooses which ads to show you 2014. http://www.slate.com/blogs/future_tense/2014/08/14/facebook_s_why_am_i_seeing_this_shows_what_the_company_knows_about_you.html [Accessed: 10- Jun- 2015].

  • [57] J. O’Connor and A. Bohan. Getting the Deal Through - Data Protection & Privacy chapter Ireland pages 73-81. Gideon Roberton 2014. Rosemary P Jay ed. http://www.matheson.com/images/uploads/documents/Ireland_GTDT_Data_Protection__Privacy_2014.pdf [Accessed: 17- Jun-2015].

  • [58] Official Journal of the European Union L 281. Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free

  • [59] Organization for Economic Co-operation and Development. Guidelines on the protection of privacy and transborder flows of personal data. Technical report OECD 1980.

  • [60] Pew Research Center. Internet user demographics 2014. http://www.pewinternet.org/data-trend/internet-use/lateststats/ [Accessed 30-Nov-2015].

  • [61] M. Scott. Facebook to appeal a Belgian court’s ruling on data privacy 2015. http://www.nytimes.com/2015/11/ 11/business/international/facebook-belgium-privacy.html [Accessed 22-Feb-2016].

  • [62] SimilarWeb. Aboutthedata.com traffic overview 2015. http://www.similarweb.com/website/aboutthedata.com [Accessed: 15- Jul- 2015].

  • [63] N. Singer. Mapping and sharing the consumer genome 2012. http://www.nytimes.com/2012/06/17/technology/acxiom-the-quiet-giant-of-consumer-database-marketing.html [Accessed: 17- Jun- 2015].

  • [64] O. Solon. How much data did Facebook have on one man? 1200 pages of data in 57 categories 2012. http://www.wired.co.uk/magazine/archive/2012/12/start/privacyversus-facebook [Accessed: 25- Oct- 2015].

  • [65] D. Solove. Introduction: Privacy self-management and the consent dilemma. Harvard Law Review 126(1880) 2013.

  • [66] L. Sotto and A. Simpson. Getting the Deal Through - Data Protection & Privacy chapter United States pages 191-204. Gideon Roberton 2014. Rosemary P Jay ed. https://www.hunton.com/files/Publication/1f767bed-fe08-42bf-94e0-0bd03bf8b74b/Presentation/PublicationAttachment/b167028d-1065-4899-87a9-125700da0133/United_StatesGTDT_Data_Protection_and_Privacy_2014.pdf [Accessed: 17- Jun- 2015].

  • [67] M. Taddicken. The ‘privacy paradox’ in the social web: The impact of privacy concerns individual characteristics and the perceived social relevance on different forms of selfdisclosure. Journal of Computer Mediated Communication 19(2):248 2013.

  • [68] TNS Opinion & Social. Attitudes on data protection and electronic identity in the European Union 2011. http://ec.europa.eu/public_opinion/archives/ebs/ebs_359_en.pdf [Accessed: 29-Nov-2015].

  • [69] TNS Opinion & Social. Data protection 2015. http://ec.europa.eu/public_opinion/archives/ebs/ebs_431_sum_en.pdf [Accessed: 29-Nov-2015].

  • [70] A. Toth. Testimony of Anne Toth vice president of policy and head of privacy Yahoo! inc. before the Joint Hearing of the Subcommittee on Communications Technology and the Internet and the Subcommittee on Commerce Trade and Consumer Protection of the Energy and Commerce Committee of the United States House of Representatives on behavioral advertising: Industry practice and consumers’ expectations 2009. http://democrats.energycommerce. house.gov/sites/default/files/documents/Testimony-Toth- CTCP-CTI-Behavioral-Advertising-Practices-2009-6-18.pdf [Accessed: 15- Jul- 2015].

  • [71] B. Ur P. Leon L. Cranor R. Shay and Y. Wang. Smart useful scary creepy: perceptions of online behavioral advertising. Proceedings of the Eighth Symposium on Usable Privacy and Security - SOUPS 2012.

  • [72] US Senate Committee on Commerce Science and Transportation. A review of the data broker industry: Collection use and sale of consumer data for marketing purposes. Technical report United States Senate 2013.

  • [73] T. Walker. Max Schrems: The Austrian law graduate who became a champion of Facebook users 2015. http://www.independent.co.uk/life-style/gadgets-andtech/news/max-schrems-the-austrian-law-graduate-whobecame-a-champion-of-facebook-users-a6683711.html [Accessed: 11- Oct- 2015].

  • [74] W. Ware. Records computers and the rights of citizens. Technical report Rand Corporation Santa Monica 1973.

  • [75] Yahoo! Ad interest manager. http://info.yahoo.com/privacy/us/yahoo/opt_out/targeting/details.html [Accessed: 15- Jul- 2015].

  • [76] Yahoo! Yahoo privacy center (ie). https://policies.yahoo.com/ie/en/yahoo/privacy/index.htm [Accessed: 11- Jun-2015].

  • [77] Yahoo! Yahoo privacy center (us). https://policies.yahoo.com/us/en/yahoo/privacy/index.htm [Accessed: 11- Jun-2015].

Search
Journal information
Cited By
Metrics
All Time Past Year Past 30 Days
Abstract Views 0 0 0
Full Text Views 437 188 2
PDF Downloads 202 81 1