Task force: IT systems' design should incorporate privacy safeguards

Connect with state & local government leaders
 

Connecting state and local government leaders

A group of academics recommends that new IT tools for homeland security be deployed 'if and only if' privacy protections have been taken into account during their development.

New IT tools such as data mining ought to be used for homeland security only if their intrusiveness on privacy and infringement of due process rights can be adequately addressed in advance, according to a new report from a task force sponsored by the New America Foundation, a Washington-based think tank.

The task force of academics examined technologies including data mining, link analysis, data integration and biometrics, and recommended that they be deployed in efforts to counteract terrorism 'if and only if' privacy protections are in place. It also suggested principles to follow to ensure the protections.

'Even more important than its specific recommendations, this paper is an exhortation to technology developers: Consider privacy at the start of any system development,' wrote task force member Paul Rosenzweig, senior legal research fellow at the Heritage Foundation. 'Privacy protection methods and code (such as immutable audits, or selective revelation techniques) need to be built into new systems from the beginning, both as a matter of good policy and as a matter of good politics.'

One of the principles suggested by Rosenzweig and the Task Force on Protecting the Homeland and Preserving Freedom is that new technologies in cyberspace should comply with existing legal and policy limitations in physical space. For example, if an individual normally has an opportunity to object to a transfer of personal data to a third party, that opportunity should be written into software design for new systems.

To minimize intrusiveness, IT systems for homeland security would be best applied if they are voluntary and used for limited purposes, such as verifying identity or initiating a lead for a law enforcement investigation. Data mining on its own should not be the source of information used to identify an individual for specific consequences, such as an arrest or preventing a passenger from boarding a plane, Rosenzweig wrote.

'Knowledge discovery technology is best understood as enhancing the efficiency of the information-gathering process. But it should not be seen as an end in itself; just as in the physical world, the enhanced scrutiny must produce tangible results before adverse consequences beyond the fact of scrutiny should be allowed to be imposed,' the task force report states.

To reduce the possibility of abuse, the task force recommends distributed architectures rather than a centralized system for collecting data. 'The impulse to centralization should be resisted where possible,' the report states.

The task force also advises use of technologies that foster anonymity while allowing individuals to be uniquely identified without rendering their specific identities. One way to enhance privacy is 'one-way hashing' that allows lists of individuals to be compared without disclosing the identities of the people on the list.

'[The] Disney [Co.] can compare its list of visitors [to its theme parks] with the Terrorist Screening Center's watch list and neither need disclose the contents of the lists. If, and only if, a match occurs, would Disney be obliged to disclose the identity,' the report reads.

New IT technologies should have strong oversight mechanisms built in, being either tamperproof or tamper evident, with automatic audit functions logging all activity for later review, the task force suggested. Also, new technologies should require authorization and review by a public official before deployment to ensure accountability.

Redress mechanisms for false positive identifications must be robust, the task force added. 'People's gravest fear is being misidentified by an automated system. The prospect of not being allowed to fly or of being subject to covert surveillance based on electronic records scares them,' Rosenzweig wrote. The task force said a formal redress process was needed ' one with administrative and judicial mechanisms ' to resolve such concerns.

The task force is one of nine anti-terrorism working groups convened by the New America Foundation, which are meeting in Washington this week at a conference titled 'Terrorism, Security and America's Purpose.' Supporters for the event include the New America Foundation, the Rockefeller Brothers Fund, the Hauser Foundation and the New York Community Trust.

Alice Lipowicz is a staff writer for Government Computer News' sister publication, Washington Technology.

X
This website uses cookies to enhance user experience and to analyze performance and traffic on our website. We also share information about your use of our site with our social media, advertising and analytics partners. Learn More / Do Not Sell My Personal Information
Accept Cookies
X
Cookie Preferences Cookie List

Do Not Sell My Personal Information

When you visit our website, we store cookies on your browser to collect information. The information collected might relate to you, your preferences or your device, and is mostly used to make the site work as you expect it to and to provide a more personalized web experience. However, you can choose not to allow certain types of cookies, which may impact your experience of the site and the services we are able to offer. Click on the different category headings to find out more and change our default settings according to your preference. You cannot opt-out of our First Party Strictly Necessary Cookies as they are deployed in order to ensure the proper functioning of our website (such as prompting the cookie banner and remembering your settings, to log into your account, to redirect you when you log out, etc.). For more information about the First and Third Party Cookies used please follow this link.

Allow All Cookies

Manage Consent Preferences

Strictly Necessary Cookies - Always Active

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data, Targeting & Social Media Cookies

Under the California Consumer Privacy Act, you have the right to opt-out of the sale of your personal information to third parties. These cookies collect information for analytics and to personalize your experience with targeted ads. You may exercise your right to opt out of the sale of personal information by using this toggle switch. If you opt out we will not be able to offer you personalised ads and will not hand over your personal information to any third parties. Additionally, you may contact our legal department for further clarification about your rights as a California consumer by using this Exercise My Rights link

If you have enabled privacy controls on your browser (such as a plugin), we have to take that as a valid request to opt-out. Therefore we would not be able to track your activity through the web. This may affect our ability to personalize ads according to your preferences.

Targeting cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.

Social media cookies are set by a range of social media services that we have added to the site to enable you to share our content with your friends and networks. They are capable of tracking your browser across other sites and building up a profile of your interests. This may impact the content and messages you see on other websites you visit. If you do not allow these cookies you may not be able to use or see these sharing tools.

If you want to opt out of all of our lead reports and lists, please submit a privacy request at our Do Not Sell page.

Save Settings
Cookie Preferences Cookie List

Cookie List

A cookie is a small piece of data (text file) that a website – when visited by a user – asks your browser to store on your device in order to remember information about you, such as your language preference or login information. Those cookies are set by us and called first-party cookies. We also use third-party cookies – which are cookies from a domain different than the domain of the website you are visiting – for our advertising and marketing efforts. More specifically, we use cookies and other tracking technologies for the following purposes:

Strictly Necessary Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Functional Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Performance Cookies

We do not allow you to opt-out of our certain cookies, as they are necessary to ensure the proper functioning of our website (such as prompting our cookie banner and remembering your privacy choices) and/or to monitor site performance. These cookies are not used in a way that constitutes a “sale” of your data under the CCPA. You can set your browser to block or alert you about these cookies, but some parts of the site will not work as intended if you do so. You can usually find these settings in the Options or Preferences menu of your browser. Visit www.allaboutcookies.org to learn more.

Sale of Personal Data

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Social Media Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.

Targeting Cookies

We also use cookies to personalize your experience on our websites, including by determining the most relevant content and advertisements to show you, and to monitor site traffic and performance, so that we may improve our websites and your experience. You may opt out of our use of such cookies (and the associated “sale” of your Personal Information) by using this toggle switch. You will still see some advertising, regardless of your selection. Because we do not track you across different devices, browsers and GEMG properties, your selection will take effect only on this browser, this device and this website.