Debunking Myths of European and U.S. Privacy:

Similar documents
Good Regulatory Practices: Conducting Public Consultations on Proposed Regulations in the Internet Era

Open Progress Forum, 19 June 2015

COU CIL OF THE EUROPEA U IO. Brussels, 6 ovember 2008 (11.11) (OR. fr) 15251/08 MIGR 108 SOC 668

Inside the Global Workfare Project: Where Welfare State Politics Meets Street-Level Practice

Abuja Action Statement. Reaffirmation of the Commitments of the Abuja Action Statement and their Implementation January, 2019 Abuja, Nigeria

INPS - 30 ottobre 2014 Intervento Villani- China Project

INTRODUCTION EB434 ENTERPRISE + GOVERNANCE

MOZAMBIQUE EU & PARTNERS' COUNTRY ROADMAP FOR ENGAGEMENT WITH CIVIL SOCIETY

President's introduction

Proposals for CETA-amendments No. 4 out of

WTO TRADE FACILITATION NEGOTIATIONS SUPPORT GUIDE

SOUTH CAUCASUS MEDIA CONFERENCE. Public service broadcasting in the digital age

Police and crime panels. Guidance on confirmation hearings

Albanian National Strategy Countering Violent Extremism

RESPONSE TO. Questionnaire. On the patent system in Europe INTRODUCTION

REFORMING WATER SERVICES: THE KEY ROLE OF MESO-INSTITUTIONS

APPROACHES TO RISK FRAMEWORKS FOR EMERGING TECHNOLOGIES) PALO ALTO, CA, MARCH 13, 2014

Why the Federal Government Should Have a Privacy Policy Office

Establishing trust in the multilateral trade system through transparency and international standards implementation monitoring

Scope of the Work of the Article 15 Committee

It is a special honor for me and pleasure to respond to your invitation and to address you today, as GFMD Co-Chair on behalf of Germany.

Feed the Future. Civil Society Action Plan

Corporate Governance

ESF Workshop, September 1-2, 2014

Discussion paper: Multi-stakeholders in Refugee Response: a Whole-of- Society Approach?

Major Group Position Paper

SUPPORTING PRINCIPLED LOCAL ACTION IN HUMANITARIAN RESPONSE

Initiatives within the UN system to increase environmental security in relation to armed conflicts

Differences and Convergences in Social Solidarity Economy Concepts, Definitions and Frameworks

Flood Awareness and Prevention Policy in border areas INBO 7 th General Assembly, 7 June Bart Swanenvleugel

STRATEGY FOR HUNGARY

Building and Securing Organizational Legitimacy

A submission to the Consultation by the Government of Ireland on a National Action Plan for Business and Human Rights

Terms of Reference Moving from policy to best practice Focus on the provision of assistance and protection to migrants and raising public awareness

[ARTICLES OF COLLABORATION]

Public Private Dialogue. The role of the private sector in monitoring & evaluation

Modes of Governance and Their Evaluation. Prof. Dr. Christoph Knill University of Konstanz Germany

GARDEN COURT CHAMBERS CIVIL TEAM. Response to Consultation Paper CP25/2012: Judicial Review: proposals for reform

Dr Katalin Pallai & Dr Peter Klotz 11/3/2016 1

Access to remedy for business-related human rights abuses

Mobilizing Aid for Trade: Focus Latin America and the Caribbean

Determining the applicable law in a world of globalization

AFGHANISTAN S PRIVATE SECTOR. Status and ways forward REPORT EXECUTIVE SUMMARY RICHARD GHIASY, JIAYI ZHOU AND HENRIK HALLGREN

Cross-Border Internal Investigations: Data Protection and Employee Issues. June 11, 2014

A Modern European Data Protection Framework. Bruno Gencarelli DG JUSTICE and CONSUMERS

From aid effectiveness to development effectiveness: strategy and policy coherence in fragile states

Capacity Building Seminar POBAL, Dublin, Ireland April 2007

Evaluation of the Good Governance for Medicines programme ( ) Brief summary of findings

New Directions for Social Policy towards socially sustainable development Key Messages By the Helsinki Global Social Policy Forum

COUNCIL DECISION (CFSP)

Consultation on the General Data Protection Regulation: CAP s evaluation of responses

First Additional Protocol to the General Regulations of the Universal Postal Union

Framework Agreement on Facilitation of Cross-border Paperless Trade in Asia and the Pacific - an introduction -

Rethinking Future Elements of National and International Power Seminar Series 21 May 2008 Dr. Elizabeth Sherwood-Randall

World Vision International-OGP Strategic Collaboration

Heather Connolly, Miguel Martínez Lucio & Stefania Marino (Universities of Manchester and Warwick)

Global Governance - EU and India s contribution to a contested concept in theory and practice

Forum Report. #AfricaEvidence. Written by Kamau Nyokabi. 1

CHANGING PRIVACY LANDSCAPE MARTIN ABRAMS

The Land Conflict Prevention Handbook

Strategy for the period for the United Nations Office on Drugs and Crime

ACEVO s policy strategy: an overview

Researching the politics of gender: A new conceptual and methodological approach

Partnership Accountability

ECUADOR S SUBMISSION ON LOCAL COMMUNITIES AND INDIGENOUS PEOPLES PLATFORM, REFERRED TO IN PARAGRAPH 135 OF DECISION 1/CP.21

(Hard) BREXIT and labour mobility

DÓCHAS STRATEGY

Socializing and Democratizing the European Semester. Jonathan Zeitlin University of Amsterdam November 2014

REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL. On Progress in Bulgaria under the Co-operation and Verification Mechanism

WHY THE FEDERAL GOVERNMENT SHOULD HAVE A PRIVACY POLICY OFFICE

CORPORATE GOVERNANCE

Internet Governance An Internet Society Public Policy Briefing

COMMENT. On the Decree on Access to the Administrative Documents of Public Authorities of Tunisia

CONSTITUTION of the FACULTY and FACULTY SENATE SAINT LOUIS UNIVERSITY MADRID CAMPUS. **VERSION FOR RATIFICATION (November 18, 2014) **

Results of regional projects under the Council of Europe/European Union Partnership for Good Governance 1

Evaluation of the European Commission-European Youth Forum Operating Grant Agreements /12

Public Procurement. Stéphane Saussier Sorbonne Business School IAE de Paris Class 2

Information Note Civil Society and Indigenous Peoples Organizations Role in REDD+

EU Data Protection Law - Current State and Future Perspectives

Review of the Functions of Toronto's Accountability Offices

About UN Human Rights

CVE ENHANCED COMMUNITY POLICING & ACCELERATING CVE STEVAN WEINE M.D. PROFESSOR OF PSYCHIATRY UNIVERSITY OF ILLINOIS AT CHICAGO

BYLAWS OF THE GLOBAL FUND TO FIGHT AIDS, TUBERCULOSIS & MALARIA 1

T he European Union s Article 29 Data Protection

Strategy for the period for the United Nations Office on Drugs and Crime

Decentralisation and WHO. reform: a broader perspective

Input to the Secretary General s report on the Global Compact Migration

Social License to Operate: Revisiting the Concept

Peacebuilding Commission, Annual Session 2015 Predictable financing for peacebuilding: Breaking the silos 23 June 2015.

INTERNATIONAL CONFERENCE ON REMITTANCES G8 GLOBAL REMITTANCES WORKING GROUP PLENARY MEETING

MASTER PROGRAM IN PUBLIC GOVERNANCE AND INTERNATIONAL RELATIONS

ASA ECONOMIC SOCIOLOGY SECTION NEWSLETTER ACCOUNTS. Volume 9 Issue 2 Summer 2010

Biotechnology, Food, and Agriculture Disputes or Food Safety and International Trade

Limited Assistance for Limited Impact: The case of international media assistance in Albania

ADP: Compiled text on pre-2020 action to be tabled

Revue Française des Affaires Sociales. The Euro crisis - what can Social Europe learn from this?

Report on the 2016 UN Forum on Business and Human Rights

Gender-Based Violence in Emergencies

Import-dependent firms and their role in EU- Asia Trade Agreements

Analytical assessment tool for national preventive mechanisms

Transcription:

Debunking Myths of European and U.S. Privacy: New Data on Corporate Privacy Management Prof. Kenneth A. Bamberger University of California, Berkeley, School of Law Berkeley Center for Law and Technology

Conventional Scholarly and Policy Focus on the books formal law; sometimes institutions 2

3

Last Research 1995 US Legal Ambiguity creates: systemic inattention & lack of resources non-existent policies or not followed in practice administered by low-level managers not involved in business decisions Push towards Europe: omnibus, unambiguous mandates; dedicated privacy regulators; rights; full FIPPs No comparable work demonstrating success of the European model. 4

Sea Change in US Privacy Professionals Associations Services Higher ed Evidence of Bureaucratization in Europe Divergence Between European Jurisdictions 5

Elements Targeted interviews with leading corporate privacy officers (CPOs), as well as regulators Document internal firm practices Broader surveys of firms 6

Key Findings: The Rise of Best Practices For Privacy Management Among Industry Leaders A Convergence Between Practices US, German, and UK(?) Leaders Key Questions: Why do we see this pattern emerging? What can we learn for policy reform 7

1)` Boundary-Spanning CPOs Internal Influence External Orientations Translation function 2) The Managerialization of Privacy Expertise within the Firm Distributed Expertise Tools and Technology Leveraging Firm-wide Risk-Management Systems Distributed Accountability 3) Privacy as Strategy and Operations (vs. notice and consent or notification) 8

Organizational Behavior/Decisionmaking Research Distribution vs. Siloed Function Empowering Internal Actors within Organization Tools and Technologies in Decisionmaking Privacy Research Rules based on notice and consent vs. contextual assessment & understanding of risk and harms Privacy by Design 9

U.S. Leaders Definitions Limited role of compliance New goal: Manage Risk New touchstone: Protecting Expectations; avoiding creepy German Leaders Definitions Compliance but nested in broader ethical frames Data Protection linked to privacy; social interests and ethical obligations; workers rights UK Leaders Definitions Privacy as Controls/Risk Management Privacy as Pragmatic 10

Definition Privacy as political, unpredictable and volatile Compliance not realistic Operationalization Legal task: rule bound, isolated, internal focus But Hi-tech socializing privacy High profile more external engagement 11

Definition What? -- Compliance/detailed rules-based Operationalization Limited; Siloed; Compliance-Focused Lower-level privacy function Absence of firm-wide leads in 1/3 of firms 12

A New U.S. Story: A Network of Norms, New Governance at the FTC Other Legal Inputs State Laws/DBN EU Directive Professionalism Social License 13

Privacy Norms in Germany: Nested Norms and the Negotiation of Privacy s Meaning Legal protections for DPOs; expansion of the role Internal attention Nested Norms Others laws; Shoah; Nuremberg Protocol Ex ante dialogues with multiple regulators Stakeholder negotiations works councils ; DPOs Professional Network Growth 14

France: Rules-orientation Role of CNIL -- In the end it s the CNIL that decides. Limits of the CIL designation Lack of Third Party Involvement Ongoing Transformation Regulatory transparency and leadership CIL/DPO as an entrée for professional networks Spain Specification of Unachievable Formalities Penalties Politics 15

Need to Shift the Lens From law and legal institutions to the privacy field From top down to bottom up 16

Substance Formal/procedural? Notice and comment Cross-Border transfers Substance/principle? Form Regulatory Specificity vs. Flexibility/Ambiguity Transparency and Publicity Institutional practices Create fora? Create institutional actors? 17

Specified regulatory obligation? or negotiated social constraint (with enforcement threat)? Associated with other value frameworks, harnessing market and workplace forces? Empowering the CPO Where is the Privacy Expertise? and how is it used? 18

Questions of Diffusion Dominant stories The Central Role of Privacy Professionals 19

PRIVACY ON THE GROUND: LESSONS FROM REGULATORY CHOICES AND CORPORATE DECISIONS IN THE US AND EUROPE (MIT Press: forthcoming 2014) Privacy in Europe: Initial Data on Governance Choices and Corporate Practices, George Washington University Law Review (forthcoming July, 2013) New Governance, Chief Privacy Officers, and the Corporate Management of Information Privacy in the United States, Law and Policy (2011) Privacy on the Books and on the Ground, Stanford Law Review (2011) 20