cardsystems

Showing posts with label cardsystems. Show all posts
Showing posts with label cardsystems. Show all posts

Grocery Store Loyalty Card Use is Strong Despite Privacy Concerns

A recent survey has confirmed what I've thought for some time: consumers will trade away their privacy at the drop of a hat. The study from Boston University suveyed a range of US consumers on their use and attitude to loyalty cards. Consumers will consistently trade their anonymity (and thus privacy) in exchange for discounts and other perceived benefits. This is even the case for those who are concerned about privacy (16% of those surveyed think about the personal information they are giving away each time they use their cards).

I'll try to find more information on the study, particularly the questions asked as part of the survey. I'm particularly curious if consumers selectively use their cards out of concern for the information that would be included in their profiles (for example, privacy-conscious consumers may not use their cards when they purchase items that may disclose too much personal information) and whether they really think about all the uses to which the information may be put.

The press release is reproduced in full below:

PRESS RELEASE: Grocery Store Loyalty Card Use is Strong Despite Privacy Concerns:

"New research from Boston University finds that 86% of adults carry a grocery store loyalty card and use it, even though cards give stores the right to track consumer purchases.

Boston, MA (PRWEB) December 28, 2004 -- Grocery story loyalty cards are more widespread than the Internet or the home computer: 86% of adults have at least one, most have more than one. Yet nearly half of the people who carry them didn’t know about the sophisticated web of tracking and marketing they were getting stuck in when they signed up. Is this a privacy bomb waiting to go off? No, according to results of a Fall 2004 study by a student research team at Boston University’s College of Communication. In an online survey of 515 adult supermarket shoppers the students found that even though privacy concerns are high, most cardholders agree that the benefits of using a loyalty card outweigh any infringement on personal privacy.

Grocery store loyalty cards are the credit card or keychain-sized cards with a barcode or magnetic stripe offered by most large supermarket chains. Chances are good you have at least one in your wallet or purse. When scanned at the cash register, the card unlocks special discounts offered to “loyal” members. In return for the savings, cardholders agree to allow the grocery store to track their purchases each time they shop. Grocery stores use this information to decide which products to carry, what prices to charge, and in some cases, to target consumers with specific coupons and promotions on behalf of grocery manufacturers.

Actual grocery store uses vary by store – some find the data analysis so time consuming they have chosen to abandon the cards altogether as PW Supermarkets, a small chain in Northern California, recently did. Still others have sophisticated systems for matching publicly available information about consumer households with the data collected at the cash register, a practice that infuriates privacy advocacy groups.

Does this tracking influence the consumer’s choice to use a discount card? A clear majority – 76% – of cardholders report that they use their grocery store loyalty card nearly every time they shop despite the fact that 52% also are concerned about how much of their personal information is collected by companies generally. Why do it, then? Sixty-nine percent of consumers report that the card benefits them in the form of lower prices and access to special promotions. And while seven in ten shoppers now know that grocery stores keep track of what they spend, only 16% think about this fact each time they use it.

“The fact that consumers – even those generally concerned about privacy – are willing to use these cards is testament to the fact that personal information is a commodity people are willing to trade with the right company for the right price,” explains Professor James McQuivey, who supervised the research project. No doubt this will only embolden supermarkets as they try to squeeze ever more dollars from a thin-margin retailing environment. What’s next? McQuivey offers, “Expect radio frequency identification embedded in the loyalty card of the future, an electronic tag that will identify you when you walk through the door, when you’re standing in front of the Pampers, and when you arrive at checkout. All with your permission, of course, and in exchange for a benefit grocery stores have yet to identify.”

About the survey

An online survey of 515 people 18 years of age and older was conducted during the last week of October 2004. As such it can only represent the two-thirds of households with Internet access. Sample was randomly drawn from a representative subgroup of participants in Survey Sampling International’s US online panel. The margin of error for a randomly drawn sample this size is +/-5%.


About the College of Communication at Boston University

The College of Communication at Boston University is home to the Communication Research Center where professors train undergraduate and graduate students in the science of consumer research and analysis. This project was designed by students under the supervision of Professor James McQuivey.

Contact Information:

James McQuivey

Assistant Professor

College of Communication

Boston University

640 Commonwealth Ave

Boston, MA 02215

617.803.6209 p

617.507.7892 f"


Data Privacy Issues to Persist Next Year

On the data privacy front, the new year will bring more of the same, according to eWeek:

Data Privacy Issues to Persist Next Year:

"People may remember 2005 as the year that corporate America woke up to the problem of data breaches and the importance of data privacy. Data leaks at Bank of America Corp., LexisNexis' Seisint division, ChoicePoint Inc. and CardSystems Inc. fed headlines for months, spawned countless lawsuits on behalf of aggrieved consumers and provided the impetus for federal legislation--still pending--to protect consumer data. But what will 2006 bring?

More of the same, say leading security experts.

More than ever before, enterprise IT managers will have to fight a battle on two fronts next year. On one side, more sophisticated and targeted attacks from organized, online criminal groups will test networks in new ways that are hard to detect...."

Incident: Security breach at Sam's Club exposes credit card data

From Computerworld:

Security breach at Sam's Club exposes credit card data - Computerworld

DECEMBER 12, 2005 (COMPUTERWORLD) - Sam's Club, a division of Wal-Mart Stores Inc., is investigating a security breach that has exposed credit card data belonging to an unspecified number of customers who purchased gas at the wholesaler's stations between Sept 21 and Oct. 2.
In a brief statement released Dec. 2, the Bentonville, Ark.-based company said it was alerted to the problem by credit card issuers who reported that customers were complaining of fraudulent charges on their statements.

It's still not clear how the data was obtained, according to the statement. But "electronic systems and databases used inside its stores and for Samsclub.com are not involved," the company said.

Sam's Club is currently working with both Visa International Inc. and MasterCard International Inc. to investigate the breach. The company also has notified the U.S. Attorney's Office for the Western District of Arkansas and the U.S. Secret Service .

Sam's Club officials didn't respond to calls for comment.

In a statement, Visa said it has alerted all of the affected financial institutions, asked them to provide independent fraud-monitoring services to affected customers and requested that they issue new cards as needed.

Cardsystems acquisition closes

The acquisition of Cardsystems by Pay by Touch announced in October (The Canadian Privacy Law Blog: Another suitor for CardSystems) has been concluded, according to a release issued on Friday: Pay By Touch Completes Acquisition of CardSystems Solutions: Financial News - Yahoo! Finance.

For those who may have forgotten, Cardsystems was involved in a high-profile data breach earlier this year: The Canadian Privacy Law Blog: Incident: Security Breach at CardSystems Solutions Inc. Could Expose 40M to Fraud.

More Ontario government damage control

The Ontario government has released an apology and an account for what happened in the most recent breach of privacy that involved 27,000 government benefits recipients:

Update On Disclosure Of Personal Information :

Government Apologizes And Takes Immediate Steps To Correct Computer Error

  TORONTO, Dec. 6 /CNW/ - On behalf of the Ontario government, Gerry
Phillips, Chair of Management Board of Cabinet, today repeated his apology to
recipients of cheques from the Ontario Child Care Supplement for Working
Families Program whose privacy was breached last week. The breach, which
affects approximately 27,000 people, resulted from an error that caused the
stub portion of the cheques to include the name, address and an identifier
that includes the SIN number of another client.

  Phillips has stressed that the Ontario government will take every action
possible to help prevent the recurrence of such incidents in the future.

  This disclosure of personal information about another recipient was
caused by a cheque-printing error that occurred during the implementation of a
computer software upgrade. These cheques were dated November 30, 2004, and
were part of a run of approximately 27,000. The approximately 86,000 people
who receive payments by direct bank deposit were not affected.

  While there were many people affected, the personal information of any
single recipient is only included on one other cheque stub.

Measures Taken

--------------

  Once ministry staff learned of the nature and scope of the problem on the
evening of December 2, government cheque production and distribution were
stopped.

  On December 3, the government informed the Information and Privacy
Commissioner and all MPPs of the breach. Government officials worked with the
Information and Privacy Commissioner and others to determine the most
appropriate way to assist the affected individuals.

  On the weekend, letters of apology were prepared for all Ontario Child
Care Supplement clients affected by this breach. At 7 a.m. today, the letters
were given to Canada Post for delivery.

  Based on advice from the Information and Privacy Commissioner, the
government has asked people affected by this to destroy any personal
information they received which does not belong to them. As a precautionary
measure, the government has recommended that cheque recipients monitor and
verify all bank accounts, credit card and other financial transaction
statements for any suspicious activity.

  Government officials have identified the problem, fixed and tested its
computer cheque systems, and been assured that these systems will operate
properly.

  Officials have also taken steps to ensure that no problems have arisen in
other computer cheque systems. These systems are operating correctly, cheque
processing has resumed, and no backlog is expected.

  The government has implemented additional quality assurance measures and
will continue to update appropriate technical and procedural measures to
ensure the highest standards for safeguarding personal information.

  The government welcomes and will cooperate fully with the Information and
Privacy Commissioner during any investigation into this matter.

  In addition to seeking the Commissioner's advice, the government is
conducting an internal audit into this breach to determine precisely what
happened and why.

  The government sincerely regrets the breach of privacy."



Cornell University outlines security and privacy incident response plans

In response to a new New York law that requires notification of security and privacy breaches, Cornell University has issued the following media release outlining their plans for compliance:

Cornell complies with new state law on notification about stolen data:

By Bill Steele

If someone hacks into a Cornell University computer and pulls out personal and private information about members of the Cornell community, the people whose data has been compromised will be notified promptly, according to Cornell Information Technologies and the University Counsel's office.

Although the exact procedures have not been worked out, notification would be by ordinary mail, according to Norma Schwab, associate university counsel. E-mail notification, she said, is not legally adequate and might be unreliable, especially in an age when users are bombarded with "phishing" messages with subject lines like "your account has been compromised."

The notification plan is being developed by an ad hoc group called the Data Incident Response Team, which includes members from the Office of Information Technologies, the Office of University Counsel, Cornell Police and the University Audit Office. The group meets periodically to consider data security policy and comes together whenever there is a concern that sensitive data may have been accessed.

The action is in response to a New York state law, the Information Security Breach and Notification Act, passed in August and going into effect Dec. 8. The law requires any business -- including nonprofits -- that maintains personal and private data to provide notification when its systems are invaded and there is a reasonable belief that personal information might have been revealed. The kinds of data involved include Social Security and driver's license numbers and credit card information, and the notification requirement is intended to help consumers fend off possible identity theft.

"It made sense that we should let people know that we are complying with the new law," said Steve Schuster, director of information security. Schuster said he plans to take advantage of the opportunity to make Cornell staff more aware of their responsibilities to protect sensitive data.

"We're still in a state where our data resides in a lot of different areas," he explained. "We all have to take responsibility for it." In other words, sensitive information is not all on one university mainframe, but may also be on ordinary desktop computers in various departments. Schuster plans to require that all new staff members receive a policy and practices briefing -- a short version of the Travelers of the Electronic Highway course required for new students -- before they are issued net IDs. He hopes eventually to set up some sort of annual review of security procedures for all staff. For nontechnical staff, security measures include using strong passwords, protecting those passwords from disclosure and physically securing the computer.

University policies on security are being updated. The venerable Responsible Use of Electronic Communications policy is being expanded as Responsible Use of Information Technology Resources, and it will incorporate policies on data management and security. Data will be broken into three categories: regulated information for which state and federal laws require security, such as Social Security numbers and grades; "Cornell confidential" information, such as salaries and performance reviews; and public data. Security should be tailored to the level of confidentiality of the data. "It will be necessary for departments to inventory where these data reside in their systems," Schuster said.

Despite having very talented people around, higher education institutions are not immune to security breaks, Schuster pointed out. "In the first six months of 2005 there were 72 media-worthy computer compromises in the United States," he reported, "and slightly over half of them were in higher ed. We deal with break-ins here all the time, but we have a really good process in place."

The New York law, patterned on one passed about two years ago in California, was inspired by several incidents in which large corporate databases were compromised. In the most widely publicized case, ChoicePoint, a credential-verifying firm, allowed criminals to obtain personal data on some 140,000 people. At least 15 states have passed similar laws, and legislation is pending at the federal level.


US Government developing standard for positive identification

According to Privacy Digest, the National Institute for Science and Technology is developing a national standard for positive indentification of government employees and contractors. The following is a general introduction to the project, from a working paper released on the NIST site:

The “Personal Identity Verification for Federal Employees and Contractors” briefing was developed in response to the Homeland Security Presidential Directive (HSPD-12). The directive sets a policy for a common identification standard for Federal employees and contractors. It also establishes the high level requirements to be satisfied in the Personal Identity Verification standard.

The following information is intended to convey current thinking regarding the NIST response to the HSPD. The concept and design decisions contained herein are tentative and subject to change in the course of consultations with affected Federal government departments and agencies.

A general threat facing government agencies is the unauthorized access to physical facilities or logical assets under the protection umbrella of the PIV system and in which a PIV card is employed in access control processes. Specific examples of threats to government resources include the following:

  • Cardholder makes improper use of a valid card
  • Counterfeit cards are used to intercept or gain access to stored information
  • Stolen or borrowed cards are used to gain unauthorized access
  • PIN information is captured / intercepted through passive surveillance
  • Lower sensitivity rated cards are used to gain access to more sensitive and critical assets.


HSPD-12 mandates a government-wide standard for secure and reliable forms of identification. The policy further defines the following criteria for a secure and reliable form of identification. The identification standard (PIV FIPS 201) will be:

  • Based on sound criteria to verify an individual employee’s identity
  • Strongly resistant to fraud, tampering, counterfeiting, and terrorist exploitation
  • Rapidly verifiable electronically
  • Issued by providers whose reliability has been established by an official accreditation process
  • Applicable to all government organizations and contractors
  • Used to grant access to Federally controlled facilities and information systems
  • Flexible enough for agencies to select the appropriate security level for each application by providing graduated criteria from least secure to most secure
  • Not applicable to identification associated with national security systems
  • Implemented in a manner that protects citizens’ privacy


The program working paper is available at http://csrc.nist.gov/piv-project/Papers/Narration-PIV-Briefing10-1.doc and a slideshow from the project briefing is available at http://csrc.nist.gov/piv-project/Papers/PIV-BriefingSept16-2004.pdf.

Thanks to Privacy Digest for the pointer.


This is a complete aside, but I found it very interesting that the word document above is loaded with metadata, showing the last minute revisions that were made to it before the briefing. The tone of the narrative was shifted slightly. To see the changes, open the document, right-click on the toolbar above the document, select "Reviewing" and, on the toolbar that appears, select "Final, showing changes" in the drop-down box. Voila, you can see the revisions made.

Lucily for NIST, the document it is not full of "notes to draft" or anything significantly embarrasing. It is a bit surprising in any event that the organization responsible for IT security standards is posting metadata-laden documents on its website!

Round two of labour-sponsored privacy campaign against BC government to begin

Labour groups are once again attacking the government of British Columbia for outsourcing public services that involve personal information. This second campaign comes after its high-profile attempt to derail the outsourcing of the province's medicare administration (See BCGEU's privacy campaign). While that campaign did not dissuade the Campbell government from its plans (BC announces medical privatization plan), it did lead to a significant inquiry by the province's Information and Privacy Commissioner. Now under attack is the province's plan to outsource bill collection:

B.C. opens private bank and credit data to U.S. scrutiny: "B.C. opens private bank and credit data to U.S. scrutiny

New privatization deal means U.S. authorities will have access to bank account and credit card numbers, property records, income and driver's licence information on B.C. residents

Vancouver - The B.C. Government and Services Employees' Union (BCGEU/NUPGE) plans to launch a new campaign this week warning residents that the Liberal government of B.C. Premier Gordon Campbell is making highly personal data vulnerable to American scrutiny through outsourcing and privatization.

The latest information to be placed in the hands of private American companies involves a wide range of information on most B.C. residents, including bank account and credit card numbers, property records, income and driver's licence information.

The province announced a $572-million ($483-million US) deal Friday with Electronic Data Systems (EDS) of Plano, Texas, to take over much of its bill collection activity. The 10-year deal comes with barely six months remaining in the Liberals' current mandate.

The province argues that privacy provisions contained in the contract will safeguard personal information but the union says the government is misleading citizens because it is already known that the contract will not withstand the overriding and intrusive powers available to American authorities under the U.S. Patriot Act.

The Patriot Act was passed by Congress and signed into law by President George Bush following the Sept. 11, 2001 terrorist attacks on New York and Washington.

The deal is even worse than a recent 10-year, $324-million contract signed with U.S.-based Maximus Inc. to privatize the processing of the medical claims of B.C. residents.

Privacy commissioner ignored

Once again, the province has ignored concerns raised by its own information and privacy commissioner, putting private sector ideological interests ahead of those of its own people, the BCGEU says.

Essentially, the latest contract means that intensely personal information on most British Columbians will be exposed to potential scrutiny by the FBI and other U.S. government agencies, the union warns.

"It’s another example of the Liberals bullying ahead without heeding the warnings of privacy commissioner David Loukidelis issues raised by the privatizing of records management, says BCGEU president George Heyman.

Loukidelis said the U.S. Patriot Act creates a real risk that personal information, once placed in the hands of private companies with U.S. links, will be open to scrutiny by the FBI and other American agencies. He recommended a series of measures to protect the privacy of British Columbians.

Heyman says Premier Campbell has failed to take the necessary range of measures recommended by the commissioner.

Patriot Act applies

"The fact is that the Patriot Act applies. EDS is an American company, and all the records in its possession are exposed," Heyman says.

"The Campbell government is clearly misleading the public and betraying the promise they made to British Columbians that real protections would be in place before any contracts were signed."

A long list of personal data at risk, Heyman warns..

"It includes everything from credit card and bank account numbers, personal property and asset details, individual and family income, and drivers license, vehicle and insurance information. It’s pretty serious stuff that British Columbians wouldn’t want to share with the Bush government," he says.

Meanwhile, the BCGEU leader said full details on his union's latest campaign to warn residents will be announced this week. The union is also continuing efforts to mount a legal challenge to the government.

The union says privacy guarantees written into the contract by EDS and the province will be overridden by the all-intrusive federal powers of the U.S. Privacy Act.

NUPGE


Leading privacy groups release annual global report

Privacy International and the Electronic Privacy Information Center have recently released their seventh annual Privacy and Human Rights Survey, which details global threats to privacy and related civil rights. It particularly highlights the increasing surveillance of citizens and intrusive uses of technology in the battle against terrorism.

From the joint EPIC/PI press release:


Privacy International & EPIC Release Annual Global Privacy Study

17/11/2004

GLOBAL HUMAN RIGHTS STUDY WARNS OF ENDEMIC PRIVACY THREATS

Major report sets out government surveillance strategies

17th November 2004

A major international privacy report published today has concluded that governments across the world have substantially increased surveillance in the past year. The report warns that threats to personal privacy have reached a level that is dangerous to fundamental human rights.

The 7th annual Privacy and Human Rights survey, published by Privacy International & the US based Electronic Privacy Information Center (EPIC) reviews the state of privacy in sixty countries and warns that invasions of privacy across the world has increased significantly in the past twelve months. The 800 page report is available free of charge at http://www.privacyinternational.org/survey/phr2004

The report paints a bleak picture of the erosion of the right to privacy, particularly since the September 11th attacks in the United States. It observed: that crime and public order laws passed in recent years have placed substantial limitations on numerous rights, including freedom of assembly, privacy, freedom of movement, the right of silence, and freedom of speech. Governments have continued to use terrorism as the pretext for an increase of surveillance, even when surveillance is unwarranted.

The report identifies a trend across the world toward mass surveillance of the general population, and cited a catalogue of illegal spying and surveillance activities by government agencies.

In response to calls for increased security many countries have pursued policy and legislative efforts that aim at implementing identification schemes, expanding the surveillance of communications for law enforcement and national security agencies, weakening data protection regimes, and intensifying data sharing and collection practices - all made possible by a growing cooperation between government entities and the private sector.

The report singles out a number of trends:


  • New identification measures and new traveller pre-screening and profiling systems
  • New anti-terrorism laws and governmental measures provide for increased search capabilities and sharing of information among law enforcement authorities
  • Increased video surveillance
  • DNA and health information databases
  • Censorship measures
  • Radio frequency identification technologies
  • New electronic voting technologies
  • Mismanagement of personal data and major data leaks


Privacy International's Director, Simon Davies, said the report highlighted a 'disturbing' trend toward greater state power. 'Governments are systematically removing the right to privacy. Surveillance of every type is being instituted throughout society without any thought about the need for safeguards.'

'The spectre of terrorism has at last become the device that any government can deploy to entrench the powers they always sought. The situation has become a dangerous farce,' he added.

'Governments are joining together their data systems. They are sharing information to a greater extent each year with the private sector. And they are cooperating unquestioningly with other governments to exchange vast reserves of personal information. This situation cannot continue without imperilling the right to privacy', said Mr Davies.

On a more upbeat note, the report did identify positive counter-trends:

'Invasions of privacy were met in various countries with forceful reactions from human rights groups. In Germany, outcry against a retail chain's use of RFID tags unbeknownst to its customers led to the halt to the company's projects. In Greece, the data protection authority struck down the use of biometric identity verification in airports because the collection of personal information through RFID tags exceeded its purpose. In Malaysia, the Bar Council criticized the security and privacy risks of Mykad, the multi-purpose smart card, which forced the government to work on a legislation to answer such concerns. In Poland, the Constitutional Tribunal held unconstitutional a law that allowed police officers to observe and record events in public places. Public interest groups had opposed the law alleging that it violated the right to privacy enshrined in the Polish Constitution. In Sweden, the privacy commissioner forbade a school's fingerprint recognition program. In Ukraine, a new law that restricts access to information was strongly opposed by several NGOs and international organizations because of its violation of the Constitution and global freedom of information standards. In reaction, amendments were introduced that improve the final version of the law.'

Incident: Shoe chain says customer data stolen

A shoe store chain in the US is reporting that their systems were compromised, resulting in the theft of customer credit card information, according to MSNBC:

MSNBC - Shoe chain says customer data stolen:

"COLUMBUS, Ohio - Credit card information from customers of more than 100 DSW Shoe Warehouse stores was stolen from a company computer's database over the last three months, a lawyer for the national chain said Tuesday.

The company discovered the theft of credit card and personal shopping information on Friday and reported it to federal authorities, said Julie Davis, general counsel for the chain's parent, Retail Ventures Inc. The Secret Service is investigating, she said...."

Wisconsin reissues cards after CardSystems breach

The largest bank based in Wisconsin has replaced a number of customers' debit and credit cards after the high-profile CardSystems breach: JS Online: M&I reissues credit, debit cards.

Summaries of incidents cataloged on PIPEDA and Canadian Privacy Law

Since I started this blog in January 2004, I have noted a few incidents related to inappropriate release of personal information. After an e-mail exchange with Rob Hyndman, I thought it would be interesting to figure out how many incidents I've blogged about. So here is a brief catalog of what I've picked up over the last year and a bit.

Hacking and inappropriate disposal rank highly as the reasons for ending up on this list. But, if there is one thing to learn from all of this: inadequate security of personal information is the one practice that is the most likely to put your company on the front pages of the paper and to destroy any customer trust you've managed to develop.


Last updated - 20050405

Momentum Building Against Database Aggregation of Personal Data?

In his blog today, Canadian technology lawyer Rob Hyndman asks: "Momentum Building Against Database Aggregation of Personal Data?"

I'm very interested to see how the latest round of incidents are going to play out in the United States. Apparently the Bank of America incident specifically involves the personal information of US legislators who carry a special Visa card for government employees. This may hit a little close to home for those with their hands on the levers of power.

There's an interesting dynamic in the United States at the moment. Consumers are increasingly worried about identity theft. The growth of this sort of crime is spurred by the inadequate security of personal information and security breaches (such as Choice Point and BoA). Agglomerating all this sensitive financial information by data aggregators dramatically increases the risk of significant consequences if security is breached.

But, at the same time, there is pressure to have higher quality personal information available to so-called legitimate businesses, such as credit grantors.

This data is also used to prevent credit fraud (see PIPEDA and Canadian Privacy Law: Identity-verifying questions are getting personal). Biometrics and big databases can also be used to positively verify the identity of those applying for credit. If, for example, there were a reliable database of biometric identifiers available to financial institutions, a credit card company can make sure that someone applying for credit in the name of Bob Smith is the Bob Smith and not someone who happened to snatch a pre-approved credit card mailout from Bob's mailbox.

(As an aside, I think that ID theft would drop dramatically if it were illegal to open a credit facility for anybody whose identity is not positively identified.)

There's also a sense that these databases are useful to prevent terrorism and lesser crimes. They are routinely used to run background checks and, according to Choice Point, law enforcement are significant customers of these systems. There will be continued pressure to make these databses available for such use.

We will never see the end of these databases, but I am waiting to see how the contrary pressures will eventually play out.

So what's the solution? I think the ten principles from the Canadian Standards Association Model Code for the Protection of Personal Information are a good start (see the Code as Schedule I to PIPEDA), coupled with a positive obligation to report any breach of security related to one's personal information.

  • Individuals should have a right to know what their personal information will be used for.
  • Organizations should not be able to collect information (from any source) unless the individual consents. For example, a credit grantor should not run a credit check without the consent of the individual and a data aggregator should not relese the credit report unless it has confirmation that the individual has consented.
  • Public records should not be "mined" for collateral uses unrelated to the purpose of the original record unless the individuals concerned have consented.
  • Individuals should have access to all their records, including information about to whom they have been disclosed. This should be provided free of charge by data aggregators as a cost of doing business.

The exceptions to the ten principles of the CSA Model Code that are in PIPEDA are generally sensible, recognizing that there are circumstances where consent should not be required or where access can be denied.

But will the US implement anything like this on a national basis? Probably not, but if they want my opinion they are welcome to it.

CardSystems class action update

The pre-trial process in the Cardsystems class action lawsuit continues, while the parties are squabbling over what and how much information Visa and MasterCard should be providing to the plaintiffs about their relationships with Cardsystems: Squabble continues over credit card breach | Tech News on ZDNet.

Your ID and credit are worth ten bucks

Your ID is apparently worth about ten bucks. Today's New York Times has a feature on identity theft, its history, who are the criminals and what is being done to address the problem:

The New York Times > Business > Your Money > Identities Stolen in Seconds:

"....A spokesman for the Consumer Data Industry Association, the trade group representing credit reporting agencies, said consumers could put fraud alerts on their credit histories if they wanted to keep prying eyes at bay. Representatives of Visa and MasterCard, the two largest credit card associations in the country, say that they are guarding customer account numbers more carefully, for example, by deleting the numbers in mail and other documents delivered to customers' homes.

Sergio Pinon, the head of security and risk services at MasterCard, said that MasterCard was deploying computer systems that analyze the spending patterns of individual card users and pluck out anomalies in case a fraud is under way. Like Ms. Feddis, Mr. Pinon said that he was the victim of an identity thief, but that he stopped the fraud because his bank had quickly spotted an intrusion into his credit card account.

Both MasterCard and Visa also monitor Web sites that broker stolen credit card numbers and other personal information. 'One of the things we've discovered is that your identity is worth about $10' on the Internet, said Linda Locke, a MasterCard spokeswoman.

With identities so cheap, experts say that criminals who want to mask themselves inside the envelope of someone else's financial world will continue to have ample opportunities to express themselves.

'The only limitation to identity theft is the creativity of the thief, and that's scary because there's really no limit on creativity, is there?' Ms. Foley said. 'The tour guides on this crazy ride are the thieves, not us and not law enforcement, and as long as that continues it's going to be a problem.' ..."

Another suitor for CardSystems

First, CardSystems was circling the bowl: CardSystems threatened with extinction due to Visa and AMEX termination.

Then, CardSystems was being bought by CyberSource: Cardsystems assets being sold to CyberSource.

Then, CyberSource leaves CardSystems at the altar: CyberSource Terminates Negotiations with CardSystems.

Now, CardSystems is being wooed by Pay by Touch: Card Center Hit by Thieves Agrees to Sale (registration req'd).

CyberSource Terminates Negotiations with CardSystems

A press release put out today says that Cybersource has withdrawn its offer to purchase embattled CardSystems: CyberSource Terminates Negotiations with CardSystems: Financial News - Yahoo! Finance.

See, also, The Canadian Privacy Law Blog: Cardsystems assets being sold to CyberSource, et seq.

Article: Who's trustworthy? Canadians, Americans disagree

Articles about consumer privacy are appearing in the traditional Canadian media, spurred it seems by recent debate over the potential impact of the USA Patriot Act on Canadian privacy. The Toronto Star has an article in today's edition that discusses two consumer privacy issues: (a) what companies do Canadians and Americans trust with their personal information and (b) what impact could the USA Patriot Act have on our privacy.

The article is a good survey of consumer privacy concerns and also brings to light some instances of reams of Canadian data being processed by American companies.

TheStar.com - Who's trustworthy? Canadians, Americans disagree:

"Prospect of U.S. Patriot Act-snooping bothers Canadians

TYLER HAMILTON

...That means some Canadian consumer information — everything from bank and insurance records to medical data — could be under surveillance by U.S. authorities without our knowledge.

"I think it's a real issue," says Ponemon. "If a company that's in the U.S. has your e-mail and you happen to be a Canadian citizen, by default the e-mail may be viewed and selected for deeper analysis and investigation by U.S. law enforcement."

Think it's a stretch?

Consider that Rogers Cable has a close partnership with U.S. Internet giant Yahoo Inc., which now manages all e-mail for Rogers' high-speed Internet customers. Consider that Bell Canada has a similar relationship with Microsoft's MSN portal.

...Outsourcing is the culprit. Both the CIBC and Royal Bank of Canada have their credit card operations managed by Total Systems Services Inc., which is based out of Georgia and is under the jurisdiction of the Patriot Act.

Consider that Royal Bank was ranked third in Ponemon's survey [of most trusted companies].

If the issue of outsourcing brews into an even larger privacy concern for Canadians, it's conceivable that Royal could fall off the list while those banks that don't outsource to the United States rise to the top.

The implications of data outsourcing aren't something to ignore. All companies need to consider them if they wish to remain trustworthy in the eyes of Canadian consumers."

Visa delays plan to cut ties with CardSystems

Hot on the heels of the announcement that CyberSource was planning to acquire CardSystems, VISA USA now says it will delay by three months its planned termination of its relationship with CardSystems. This may ultimately lead to the survival of the embattled transactions processor: Visa delays plan to cut ties with CardSystems - Computerworld.

Students crack RFID security

The New York Times is reporting that a group of researchers have managed to crack the most prevalent impelementation of RFID as a security device. They can read your chip/card while standing next to you in the elevator, crack the keys and, less than an hour later, replicate your chip or card.

While the threat remains theoretical, this has significant repurcussions for owners of vehicles that use RFID immobilizers, pay-at-the-pump systems and facilities that use RFID access cards. See: The New York Times > Science > Students Find Hole in Car Security Systems. See also a discussion at Slashdot: Slashdot Mobil SpeedPass, Various Car RFID Car Keys Cracked

Update: The full articled on how it was done is available here:

RFIDAnalysis.org:

"The Texas Instruments DST tag is a cryptographically enabled RFID transponder used in several wide-scale systems including vehicle imobilizers and the ExxonMobil SpeedPass system. This page serves as an overview of our successful attacks on DST enabled systems. A preliminary version of the full academic paper describing our attacks in detail is also available below. "