Regulation Context Implications Strategy
Implications of Context for Regulation
Jesse Sowell
Engineering Systems Division, MIT Advanced Network Architecture Group, CSAIL
Jesse Sowell MIT Implications of Context for Regulation
Implications of Context for Regulation Jesse Sowell Engineering - - PowerPoint PPT Presentation
Regulation Context Implications Strategy Implications of Context for Regulation Jesse Sowell Engineering Systems Division, MIT Advanced Network Architecture Group, CSAIL Jesse Sowell MIT Implications of Context for Regulation Regulation
Regulation Context Implications Strategy
Engineering Systems Division, MIT Advanced Network Architecture Group, CSAIL
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Two distinct privacy regulatory paradigms:
◮ EU: socially protective ◮ US: normatively liberal
◮ Problem: Tools available to these two privacy paradigms may
◮ Illustrative Instance: Surfacing the privacy implications of
◮ Cyber environments ◮ Cyber+terrestrial via mobile platforms ◮ Smart power grid
◮ Question: How do we create sufficiently responsive standards
◮ What are the roles of regulatory bodies? ◮ What might a hybrid regime look like? ◮ What are the politically and strategically feasible incentive
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Two distinct privacy regulatory paradigms:
◮ EU: socially protective ◮ US: normatively liberal
◮ Problem: Tools available to these two privacy paradigms may
◮ Illustrative Instance: Surfacing the privacy implications of
◮ Cyber environments ◮ Cyber+terrestrial via mobile platforms ◮ Smart power grid
◮ Question: How do we create sufficiently responsive standards
◮ What are the roles of regulatory bodies? ◮ What might a hybrid regime look like? ◮ What are the politically and strategically feasible incentive
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Modern regulation rooted in the FIPs
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Modern regulation rooted in the FIPs ◮ Evolved in the privacy climate of the 60’s and 70’s
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Modern regulation rooted in the FIPs ◮ Evolved in the privacy climate of the 60’s and 70’s ◮ Response to government use of mainframes
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Modern regulation rooted in the FIPs ◮ Evolved in the privacy climate of the 60’s and 70’s ◮ Response to government use of mainframes ◮ Concurrently developed in US and EU
◮ Younger Committee (UK, early 1970’s) ◮ Westin and Baker’s recommendations to National Academies
◮ Nascent articulations in 1970 Fair Credit Reporting Act ◮ 1974 Privacy Act ◮ COE Convention for the Protection of Individuals with Regard to
◮ OECD Guidelines Governing the Protection of Privacy and
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Modern regulation rooted in the FIPs ◮ Evolved in the privacy climate of the 60’s and 70’s ◮ Response to government use of mainframes ◮ Concurrently developed in US and EU
◮ Younger Committee (UK, early 1970’s) ◮ Westin and Baker’s recommendations to National Academies
◮ Nascent articulations in 1970 Fair Credit Reporting Act ◮ 1974 Privacy Act ◮ COE Convention for the Protection of Individuals with Regard
◮ OECD Guidelines Governing the Protection of Privacy and
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Openness: repository known data
◮ Access and Correction: ability to
◮ Collection Limitation: collected
◮ Use Limitation: limited to original
◮ Disclosure Limitation: data may
◮ Security Principle: sufficient
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Openness: repository known data
◮ Access and Correction: ability to
◮ Collection Limitation: collected
◮ Use Limitation: limited to original
◮ Disclosure Limitation: data may
◮ Security Principle: sufficient
◮ Notice mechanisms ◮ Opt-in/opt-out Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Openness: repository known data
◮ Access and Correction: ability to
◮ Collection Limitation: collected
◮ Use Limitation: limited to original
◮ Disclosure Limitation: data may
◮ Security Principle: sufficient
◮ Notice mechanisms ◮ Opt-in/opt-out
◮ Policy convergence and
◮ Need operationalization to become
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Openness: repository known data
◮ Access and Correction: ability to
◮ Collection Limitation: collected
◮ Use Limitation: limited to original
◮ Disclosure Limitation: data may
◮ Security Principle: sufficient
◮ Notice mechanisms ◮ Opt-in/opt-out
◮ Policy convergence and
◮ Need operationalization to become
◮ Conventional PII captured ◮ Aggregate image of attributes . . . ? Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ EU
◮ Socially protective → privacy is an inalienable human right ◮ Comprehensive regulation covers public and private sector ◮ DPAs implement monitoring, audit, and enforcement ◮ Top down comprehensive ◮ Failure mode: ◮ DPA capacity issues ◮ DPA-company communication
◮ US
◮ Normatively liberal → privacy is an alienable commodity that may
◮ Ad hoc, sectoral, chaotic self-regulatory structure ◮ Self-help: harms are identified as they emerge ◮ Bottom up self-regulatory ◮ Failure mode: ◮ Information asymmetries ◮ Collective action problems
◮ Implications of Context?
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Environment is the “place”
◮ Can be anywhere ◮ Online: environment is architected
◮ Context is a social construction that
◮ Rules of appropriateness ◮ Rules of distribution
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Environment is the “place”
◮ Can be anywhere ◮ Online: environment is architected
◮ Context is a social construction that
◮ Rules of appropriateness ◮ Rules of distribution
◮ Public place, still a notion of privacy
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Environment is the “place”
◮ Can be anywhere ◮ Online: environment is architected
◮ Context is a social construction that
◮ Rules of appropriateness ◮ Rules of distribution
◮ Public place, still a notion of privacy ◮ Context changes when new actors
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Environment is the “place”
◮ Can be anywhere ◮ Online: environment is architected
◮ Context is a social construction that
◮ Rules of appropriateness ◮ Rules of distribution
◮ Public place, still a notion of privacy ◮ Context changes when new actors
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Architectural dynamics defies
◮ Context different on each visit ◮ Different actors “at the table”
◮ Lack of policy transitivity
◮ OSP policy rooted in limiting
◮ Contractual info absent
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Architectural dynamics defies
◮ Context different on each visit ◮ Different actors “at the table”
◮ Lack of policy transitivity
◮ OSP policy rooted in limiting
◮ Contractual info absent
Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Architectural dynamics defies
◮ Context different on each visit ◮ Different actors “at the table”
◮ Lack of policy transitivity
◮ OSP policy rooted in limiting
◮ Contractual info absent
Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Architectural dynamics defies
◮ Context different on each visit ◮ Different actors “at the table”
◮ Lack of policy transitivity
◮ OSP policy rooted in limiting
◮ Contractual info absent
Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Architectural dynamics defies
◮ Context different on each visit ◮ Different actors “at the table”
◮ Lack of policy transitivity
◮ OSP policy rooted in limiting
◮ Contractual info absent
Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
◮ {age range, coarse locale, gender
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
◮ {age range, coarse locale, gender
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
◮ {age range, coarse locale, gender
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
◮ {age range, coarse locale, gender
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
◮ {age range, coarse locale, gender
◮ Next search for food may include
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Segments considered non-PII
◮ age range, interest in wine, region,
◮ Individually “innocuous” ◮ Together → aggregate image
◮ {age range, coarse locale, gender
◮ Next search for food may include
◮ Privacy violation or appropriate
◮ Depends on privacy preferences Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info user info trust money trust service
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info user info trust money trust service info exposure
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info user info trust money trust service info exposure
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info
user info trust money trust service info exposure
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Ad networks’ blue “i” a start ◮ Rating mechanism for ads
◮ Data sharing amongst relevant
◮ Natural experiments to collect
◮ Advertiser reputation market
◮ OSP rating transitivity ◮ OSP-advertiser relationship Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Ad networks’ blue “i” a start ◮ Rating mechanism for ads
◮ Data sharing amongst relevant
◮ Natural experiments to collect
◮ Advertiser reputation market
◮ OSP rating transitivity ◮ OSP-advertiser relationship Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Ad networks’ blue “i” a start ◮ Rating mechanism for ads
◮ Data sharing amongst relevant
◮ Natural experiments to collect
◮ Advertiser reputation market
◮ OSP rating transitivity ◮ OSP-advertiser relationship Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk
7.5 1.4 5.2 9.7 0.5 2.5
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Ad networks’ blue “i” a start ◮ Rating mechanism for ads
◮ Data sharing amongst relevant
◮ Natural experiments to collect
◮ Advertiser reputation market
◮ OSP rating transitivity ◮ OSP-advertiser relationship Banner Ad Banner Ad Favorite OSP OSP content Ad1 Ad2 Ad3
Beacon1 Beacon2 Beaconk
7.5 1.4 5.2 9.7 0.5 2.5 3.6
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info user info trust money trust service info exposure
OSP rep advertiser rep context rep
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info
user info pressure money trust service info exposure
OSP rep advertiser rep context rep
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
user info
user info pressure money trust service info exposure
OSP rep advertiser rep context rep
Jesse Sowell MIT Implications of Context for Regulation
Regulation Context Implications Strategy
◮ Back to initial questions . . .
◮ What is the role of regulatory bodies? ◮ What is missing from this hybrid regime? ◮ Self-reinforcing mechanisms . . . ◮ What are the politically and strategically feasible incentive
◮ A few more . . .
◮ “Ideal” CSO solution is one particular end point ◮ Are there there politically and strategically feasible options? How
◮ What characterizes the collection of entry points to a critical path to
◮ How can we use this to compare options? Jesse Sowell MIT Implications of Context for Regulation