{"id":4183,"date":"2023-01-20T18:03:14","date_gmt":"2023-01-20T18:03:14","guid":{"rendered":"https:\/\/2024.thenexus.today\/index.php\/2023\/01\/20\/privacy-news-january-20\/"},"modified":"2023-01-20T18:03:14","modified_gmt":"2023-01-20T18:03:14","slug":"privacy-news-january-20","status":"publish","type":"post","link":"https:\/\/2024.thenexus.today\/index.php\/2023\/01\/20\/privacy-news-january-20\/","title":{"rendered":"Privacy News: January 20"},"content":{"rendered":"<p>Websites selling abortion pills sharing data with Google, the My Health My Data Act, the &#8220;no fly&#8221; list accidentally exposed, a state privacy legislation bonanza &#8230; and more!<\/p>\n<h2 id=\"privacy-after-roe\">Privacy After Roe<\/h2>\n<h3 id=\"websites-selling-abortion-pills-are-sharing-sensitive-data-with-google\"><a href=\"https:\/\/propublica.org\/article\/websites-selling-abortion-pills-share-sensitive-data-with-google\">Websites Selling Abortion Pills Are Sharing Sensitive Data With Google<\/a><\/h3>\n<p>Jennifer Gollan on ProPublica (propublica.org)<\/p>\n<p>That&#8217;s bad. \u00a0Using <a href=\"https:\/\/themarkup.org\/blacklight\">the Markup&#8217;s Blacklight tool<\/a>, a nonprofit tech-journalism newsroom, ProPublica ran checks on 11 online pharmacies that sell abortion medication to reveal the web tracking technology they use. \u00a0At least 9 of them had web trackers.<\/p>\n<blockquote><p>These third-party trackers, including a Google Analytics tool and advertising technologies, collect a host of details about users and feed them to tech behemoth Google, its parent company, Alphabet, and other third parties, such as the online chat provider LiveChat. Those details include the web addresses the users visited, what they clicked on, the search terms they used to find a website, the previous site they visited, their general location and information about the devices they used, such as whether they were on a computer or phone&#8230;. <\/p>\n<p>While many people may assume their health information is legally protected, U.S. privacy law does little to constrain the kind or amount of data that companies such as Google and Facebook can collect from individuals. Tech companies are generally not bound by the Health Insurance Portability and Accountability Act, known as HIPAA, which limits when certain health care providers and health plans can share a patient\u2019s medical information. Nor does federal law set many limits on how companies can use this data.<\/p><\/blockquote>\n<h3 id=\"proposed-washington-law-puts-period-tracking-apps-on-notice\"><a href=\"https:\/\/www.theregister.com\/2023\/01\/18\/washington_period_tracking_apps\/\">Proposed Washington law puts period-tracking apps on notice<\/a><\/h3>\n<p>Jessica Lyons Hardcastle on The Register (theregister.com)<\/p>\n<p>My Health My Data, a bill currently in Washington&#8217;s state legislature, would protect health data that collected by apps and websites &#8212; including reproductive health care data. \u00a0For some reason, the articles about it so far have focused on period-tracking apps, but that&#8217;s only the tip of the iceberg.<\/p>\n<blockquote><p>&#8220;Think about period-tracking apps that can sell information about a woman&#8217;s missed or late period,&#8221; [sponsor Rep. Vandana] Slatter said. &#8220;Or a pregnancy crisis center that someone visits and then learns they can&#8217;t receive an abortion, but their information can be sold to anti-abortion groups. Or digital advertising firms that set up geofencing around healthcare facilities. This bill is about closing the gap on health data privacy protections from the technological side of it.&#8221;<\/p><\/blockquote>\n<p>I talked more about My Health My Data and its prospects here last week in <a href=\"__GHOST_URL__\/wa-privacy-more-favorable-environment\/\">A much more favorable environment: Washington state privacy legislation 2023<\/a>, and with a hearing on Tuesday I&#8217;ll have more to say about it soon!<\/p>\n<p><strong>ALSO:<\/strong><\/p>\n<ul>\n<li><a href=\"https:\/\/cnn.com\/2023\/01\/18\/politics\/washington-state-period-tracking-apps\">Washington state bill would make period-tracking apps follow privacy laws in reflection of post-Roe fears <\/a>, Shawna Mizelle on CNN (cnn.com)<\/li>\n<\/ul>\n<p>A pair of articles about My Health My Data, a bill introduced by Democrats in Washington\u2019s state legislature would prevent private health data that is collected by apps &#8212; particularly those that track menstrual cycles &#8212; from being shared without consumers\u2019 consent.<\/p>\n<h4><\/h4>\n<h2 id=\"surveillance\">Surveillance<\/h2>\n<h3 id=\"us-airline-accidentally-exposes-%E2%80%98no-fly-list%E2%80%99-on-unsecured-server\"><a href=\"https:\/\/dailydot.com\/debug\/no-fly-list-us-tsa-unprotected-server-commuteair\">U.S. airline accidentally exposes \u2018No Fly List\u2019 on unsecured server<\/a><\/h3>\n<p>Mikael Thalen on The Daily Dot (dailydot.com)<\/p>\n<p>CommuteAir, a United Airlines subsidiary, left a copy of the U.S. No Fly List on an unsecured server as a file named &#8220;NoFly.csv&#8221; that could be viewed by anyone. \u00a0<\/p>\n<blockquote><p>The list, according to crimew, appeared to have more than 1.5 million entries in total. The data included names as well as birth dates. It also included multiple aliases, placing the number of unique individuals at far less than 1.5 million.<\/p><\/blockquote>\n<h3 id=\"little-known-surveillance-program-captures-money-transfers-between-us-and-more-than-20-countries\"><a href=\"https:\/\/wsj.com\/articles\/little-known-surveillance-program-captures-money-transfers-between-u-s-and-more-than-20-countries-11674019904\">Little-Known Surveillance Program Captures Money Transfers Between U.S. and More Than 20 Countries<\/a><\/h3>\n<p>Dustin Volz and Byron Tau on The Wall Street Journal (wsj.com)<\/p>\n<p>Law-enforcement agencies across the U.S. have direct access to over 150 million transactions housed at an Arizona-based nonprofit.<\/p>\n<h2 id=\"state-privacy-legislation\">State privacy legislation<\/h2>\n<h3 id=\"states-are-readying-a-flurry-of-privacy-bills-as-washington-stalls\"><a href=\"https:\/\/www.washingtonpost.com\/politics\/2023\/01\/20\/states-are-readying-flurry-privacy-bills-washington-stalls\/\">States are readying a flurry of privacy bills as Washington stalls<\/a><\/h3>\n<p>Cristiano Lima on the Washington Post (washingtonpost.com)<\/p>\n<p>A roundup of some of the various laws being proposed, including<\/p>\n<ul>\n<li>Comprehensive privacy bills in Massachusetts, Iowa, Mississippi, Indiana, Oklahoma, Oregon, Tennessee, New York and Kentucky<\/li>\n<li>Protections for children\u2019s data in Connecticut, Oregon, West Virginia, Virginia and New Jersey.<\/li>\n<li>Biometrics, health data, and data broker laws in New York, Mississippi, Maryland, Oregon, New Jersey, Virginia and Washington.<\/li>\n<\/ul>\n<p>That&#8217;s a lot!<\/p>\n<h3 id=\"state-legislators-aren%E2%80%99t-waiting-for-congress-to-regulate-children%E2%80%99s-online-privacy\"><a href=\"https:\/\/cyberscoop.com\/california-age-appropriate-design-code-oregon-privacy\">State legislators aren\u2019t waiting for Congress to regulate children\u2019s online privacy<\/a><\/h3>\n<p>Tonya Riley on CyberScoop (cyberscoop.com)<\/p>\n<p>More states are following California\u2019s lead in regulating children\u2019s privacy. But experts say the laws raise many tough questions.<\/p>\n<h3 id=\"data-privacy-%E2%80%98panoply%E2%80%99-looms-as-states-move-to-fill-federal-hole\"><a href=\"https:\/\/news.bloomberglaw.com\/privacy-and-data-security\/data-privacy-panoply-looms-as-states-move-to-fill-federal-hole\">Data Privacy \u2018Panoply\u2019 Looms as States Move to Fill Federal Hole<\/a><\/h3>\n<p>Brenna Goth and Skye Witley on Bloomberg Law (news.bloomberglaw.com)<\/p>\n<p>Consumers across the US could gain more control over how companies collect and use their personal information through state legislative efforts to create new data privacy requirements.<\/p>\n<h2 id=\"and\">And &#8230;<\/h2>\n<h3 id=\"the-future-of-manipulative-design-regulation\"><a href=\"https:\/\/fpf.org\/blog\/the-future-of-manipulative-design-regulation\/\">The Future of Manipulative Design Regulation<\/a><\/h3>\n<p>Felicity Slater, Future of Privacy Forum (fpf.org)<\/p>\n<p>A look at rules and enforcement actions, in the US and around the world, targeting manipulative design practices online. <\/p>\n<blockquote><p>These efforts are complex and address a range of consumer protection issues, including privacy and data protection risks. They raise thorny questions about how to distinguish between lawful designs that encourage individuals to consent to data practices, and unlawful designs that manipulate users through unfair and deceptive techniques. As policymakers enforce existing laws and propose new rules, it is crucial to identify when the design and default settings of online services constitute unlawful manipulative design that impairs user\u2019s intentional decision-making.<\/p><\/blockquote>\n<h4 id=\"how-the-netherlands-is-taming-big-tech\"><a href=\"https:\/\/nytimes.com\/2023\/01\/18\/technology\/dutch-school-privacy-google-microsoft-zoom.html\">How the Netherlands Is Taming Big Tech<\/a><\/h4>\n<p>Natasha Singer on NYTimes (nytimes.com)<\/p>\n<p>Dutch privacy negotiators have spurred major changes at Google, Microsoft and Zoom, using a landmark European data protection law as a lever.<\/p>\n<h4 id=\"thinking-and-reading-at-the-intersection-of-labor-race-and-tech\"><a href=\"https:\/\/points.datasociety.net\/thinking-and-reading-at-the-intersection-of-labor-race-and-tech-c86e687fa0cf\">Thinking and Reading at the Intersection of Labor, Race, and Tech<\/a><\/h4>\n<p>Data &amp; Society on Data &amp; Society: Points (points.datasociety.net)<\/p>\n<p>The rise of data-centric technologies is an opportunity for the labor and racial justice movements to build new bridges.<\/p>\n<h4 id=\"meta-dodged-a-%E2%82%AC4bn-privacy-fine-over-unlawful-ads-argues-gdpr-complainant\"><a href=\"https:\/\/techcrunch.com\/2023\/01\/19\/meta-ads-noyb-epdb-gdpr-complaint\">Meta dodged a \u20ac4BN privacy fine over unlawful ads, argues GDPR complainant<\/a><\/h4>\n<p>Natasha Lomas on TechCrunch (techcrunch.com)<\/p>\n<p>A \u20ac390M privacy fine against Meta\u2019s behavioural ads issued earlier this month in the EU was several billion dollars smaller than it should have been, argues the original complainant.<\/p>\n<h4 id=\"the-year-in-uk-gdpr-regulatory-enforcement-action\"><a href=\"https:\/\/privacylaws.com\/uk125enforce\">The year in UK GDPR regulatory enforcement action<\/a><\/h4>\n<p>on Privacy Laws &amp; Business (privacylaws.com)<\/p>\n<h4 id=\"the-battle-over-women%E2%80%99s-data\"><a href=\"https:\/\/wired.com\/story\/privacy-health-data-women\">The Battle Over Women\u2019s Data<\/a><\/h4>\n<p>Chi Onwurah on WIRED (wired.com)<\/p>\n<p>In a post-Roe world, bodily autonomy must include control over personal data.<\/p>\n<h4 id=\"all-the-data-apple-collects-about-you%E2%80%94and-how-to-limit-it\"><a href=\"https:\/\/wired.com\/story\/apple-privacy-data-collection\">All the Data Apple Collects About You\u2014and How to Limit It<\/a><\/h4>\n<p>Matt Burgess on WIRED (wired.com)<\/p>\n<p>Cupertino puts privacy first in a lot of its products. But the company still gathers a bunch of your information.<\/p>\n<h4 id=\"the-big-risk-in-the-most-popular-and-aging-big-tech-default-email-programs\"><a href=\"https:\/\/cnbc.com\/2023\/01\/15\/the-most-popular-big-tech-email-programs-are-old-and-vulnerable.html\">The big risk in the most-popular, and aging, big tech default email programs<\/a><\/h4>\n<p>Elizabeth MacBride on CNBC (cnbc.com)<\/p>\n<p>Many individuals and businesses rely on Google and Microsoft email programs created long ago, and big tech email \u2018age\u2019 is a big cybersecurity risk.<\/p>\n<h4 id=\"irish-data-protection-authority-gives-%E2%82%AC-397-billion-present-to-meta-authority-allegedly-unable-to-assess-financial-benefit-from-meta%E2%80%99s-gdpr-violations\"><a href=\"https:\/\/noyb.eu\/en\/irish-data-protection-authority-gives-eu-397-billion-present-meta-authority-allegedly-unable-assess\">Irish Data Protection Authority gives \u20ac 3.97 billion present to Meta. Authority allegedly unable to assess financial benefit from Meta\u2019s GDPR violations.<\/a><\/h4>\n<p>on noyb.eu (noyb.eu)<\/p>\n<p>The DPC has turned a blind eye on the revenue generated by Meta from violating the GDPR since 2018. Ignoring the EDPB demand to include the unlawful revenue of Meta, reduced the fine by 3,97 Mrd EUR.<\/p>\n<h4 id=\"privacy-fines-gdpr-sanctions-last-year-surged-to-3-billion\"><a href=\"https:\/\/bankinfosecurity.com\/privacy-fines-gdpr-sanctions-last-year-surged-to-3-billion-a-20950\">Privacy Fines: GDPR Sanctions Last Year Surged to $3 Billion<\/a><\/h4>\n<p>Mathew J. Schwartz on bankinfosecurity.com<\/p>\n<p>European data protection regulators last year imposed known privacy and data breach fines under GDPR collectively worth at least 2.9 billion euros, or $3.1 billion,<\/p>\n<h4 id=\"uk-data-agency-plays-down-privacy-risks-of-connected-tech-as-demand-for-amazon-alexa-and-google-nest-show-consumer-trust\"><a href=\"https:\/\/cityam.com\/uk-data-agency-plays-down-privacy-risks-of-connected-tech-as-demand-for-amazon-alexa-and-google-nest-show-consumer-trust\">UK data agency plays down privacy risks of connected tech, as demand for Amazon Alexa and Google Nest show consumer trust<\/a><\/h4>\n<p>Jess Jones on CityAM (cityam.com)<\/p>\n<p>The UK\u2019s data watchdog has played down potential privacy concerns linked to connected technology, arguing that strong demand for devices like the Amazon<\/p>\n<h4 id=\"privacy-shield-20-what%E2%80%99s-next-for-international-data-transfers\"><a href=\"https:\/\/swlaw.com\/publications\/view\/privacy-shield-20-whats-next-for-international-data-transfers\">Privacy Shield 2.0 What\u2019s Next for International Data Transfers?<\/a><\/h4>\n<p>Myriad Interactive on Snell &amp; Wilmer (swlaw.com)<\/p>\n<p>Snell &amp; Wilmer is one of the largest law firms in the western Unites States.<\/p>\n<h4 id=\"podcast-why-privacy-matters\"><a href=\"https:\/\/techpolicy.com\/PrivacyExpertsRichards-Citron-WhyPrivacyMatters.aspx\">Podcast: Why Privacy Matters<\/a><\/h4>\n<p>Neil Richards and Danielle Citron on Tech Policy (techpolicy.com)<\/p>\n<p>In a UVA Common Law podcast, privacy law expert Neil Richards, law professor at Washington University in St. Louis, joins University of Virginia law professor Danielle Citron to discuss how privacy regulation could ensure that information cannot be used to gain control and influence others.<\/p>\n<h4 id=\"cdt-and-technologists-file-scotus-brief-urging-court-to-hold-that-section-230-applies-to-recommendations-of-content\"><a href=\"https:\/\/cdt.org\/insights\/cdt-and-technologists-file-scotus-brief-urging-court-to-hold-that-section-230-applies-to-recommendations-of-content\">CDT and Technologists File SCOTUS Brief Urging Court To Hold that Section 230 Applies to Recommendations of Content<\/a><\/h4>\n<p>Caitlin Vogus, Emma Llans\u00f3, Samir Jain on Center for Democracy and Technology (cdt.org)<\/p>\n<p>The Center for Democracy &amp; Technology and six technologists with expertise in online recommendation systems filed an amicus brief today in Gonzalez v. Google. The brief urges the U.S. Supreme Court to hold that Section 230\u2019s liability shield applies to claims against interactive computer service pro\u2026<\/p>\n<h4 id=\"podcast-how-a-spy-in-your-pocket-threatens-the-end-of-privacy-dignity-and-democracy\"><a href=\"https:\/\/lawfareblog.com\/lawfare-podcast-how-spy-your-pocket-threatens-end-privacy-dignity-and-democracy\">Podcast: How a Spy in Your Pocket Threatens the End of Privacy, Dignity, and Democracy<\/a><\/h4>\n<p>Jen Patja Howell on Lawfare (lawfareblog.com)<\/p>\n<p>Lawfare fellow in technology policy and law Eugenia Lostri sat down with Laurent Richard and Sandrine Rigaud to talk about their new book, \u201cPegasus: How a Spy in Your Pocket Threatens the End of Privacy, Dignity, and Democracy.\u201d<\/p>\n<h4 id=\"apple-privacy-under-question-as-apps-get-independent-checks\"><a href=\"https:\/\/techhq.com\/2023\/01\/apple-privacy-tracking-anonymity-fact-checkers-whether-they-like-it-or-not\">Apple privacy under question as apps get independent checks<\/a><\/h4>\n<p>Molly Loe on TechHQ (techhq.com)<\/p>\n<p>Question\u2019s around Apple privacy policies as it\u2019s found that Apple\u2019s own applications identify users personally and phone data home.<\/p>\n<h4 id=\"meta-centralizes-more-user-and-privacy-settings-across-its-apps-announces-changes-to-ads-controls\"><a href=\"https:\/\/techcrunch.com\/2023\/01\/19\/meta-centralizes-more-user-and-privacy-settings-across-its-apps-announces-changes-to-ads-controls\">Meta centralizes more user and privacy settings across its apps, announces changes to ads controls<\/a><\/h4>\n<p>Sarah Perez on TechCrunch (techcrunch.com)<\/p>\n<p>Facebook parent Meta announced today it\u2019s further centralizing various user settings across its suite of apps \u2014 Facebook, Instagram, and Messenger. As a result, several existing settings will be relocated to Meta\u2019s \u201cAccounts Center\u201d feature, first launched in 2020. Specifically, the changes will see\u2026<\/p>\n<h4 id=\"publishers-are-preparing-for-2023%E2%80%99s-new-consumer-privacy-laws\"><a href=\"https:\/\/digiday.com\/sponsored\/publishers-are-preparing-for-2023s-new-consumer-privacy-laws\">Publishers are preparing for 2023\u2019s new consumer privacy laws<\/a><\/h4>\n<p>Melissa Cooper, Sovrn on Digiday (digiday.com)<\/p>\n<p>A new set of<a href=\"https:\/\/www.huschblackwell.com\/2023-state-privacy-law-tracker\"> state-specific privacy regulations<\/a> is scheduled to take effect in 2023.<\/p>\n<h4 id=\"how-can-breaching-citizens%E2%80%99-privacy-be-lawful\"><a href=\"https:\/\/asianews.network\/how-can-breaching-citizens-privacy-be-lawful\">How can breaching citizens\u2019 privacy be lawful?<\/a><\/h4>\n<p>Kamal Ahmed on Asia News Network (asianews.network)<\/p>\n<p>Without legal safeguards, putting in place such surveillance systems aimed at suspected anti-state activities carries serious risks of innocent victims being harassed.<\/p>\n<h4 id=\"obtaining-consent-for-privacy-practices\"><a href=\"https:\/\/jdsupra.com\/legalnews\/obtaining-consent-for-privacy-practices-2797343\">Obtaining Consent for Privacy Practices<\/a><\/h4>\n<p>Mallory Acheson on JD Supra (jdsupra.com)<\/p>\n<p>By now, most businesses are aware of the growing requirements to provide notice to consumers regarding how a business uses and discloses personal information.<\/p>\n<hr>\n<p>Image credit: Originally by <a href=\"http:\/\/www.nyphotographic.com\/\">Nick Youngson<\/a>, licensed from <a href=\"http:\/\/alphastockimages.com\/\">Alpha Stock Images<\/a> under <a href=\"https:\/\/creativecommons.org\/licenses\/by-sa\/3.0\/\" rel=\"license\">CC BY-SA 3.0<\/a> via <a href=\"https:\/\/www.picpedia.org\/chalkboard\/p\/privacy.html\">Picpedia<\/a><\/p>\n<h4><\/h4>\n","protected":false},"excerpt":{"rendered":"<p>Websites selling abortion pills sharing data with Google, the My Health My Data Act, the &#8220;no fly&#8221; list accidentally exposed, a state privacy legislation bonanza &#8230; and more! Privacy After Roe Websites Selling Abortion Pills Are Sharing Sensitive Data With Google Jennifer Gollan on ProPublica (propublica.org) That&#8217;s bad. \u00a0Using the Markup&#8217;s Blacklight tool, a nonprofit [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[460],"class_list":["post-4183","post","type-post","status-publish","format-standard","hentry","category-uncategorized","tag-privacy-news"],"_links":{"self":[{"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/posts\/4183","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/comments?post=4183"}],"version-history":[{"count":0,"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/posts\/4183\/revisions"}],"wp:attachment":[{"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/media?parent=4183"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/categories?post=4183"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/2024.thenexus.today\/index.php\/wp-json\/wp\/v2\/tags?post=4183"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}