nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
February 2016
- 32 participants
- 150 messages
Coming to Terms with Secret Law
by Alberto Cammozzo
COMING TO TERMS WITH SECRET LAW
Dakota S. Rudesill
Ohio State University (OSU) - Michael E. Moritz College of Law
January 6, 2015
7 Harvard National Security Journal, 2015, Forthcoming
Ohio State Public Law Working Paper No. 321
The allegation that the U.S. government is producing secret law has
become increasingly common. This article evaluates this claim, examining
the available evidence in all three federal branches. In particular,
Congress’s governance of national security programs via classified
addenda to legislative reports is here given the first focused scholarly
treatment, including empirical analysis that
shows references in Public Law to these classified documents spiking in
recent years. Having determined that the secret law allegation is well
founded in all three branches, the article argues that secret law is
importantly different from secrecy generally: the constitutional norm
against secret law is stronger than the constitutional norm against
secret fact. Three normative options are constructed and compared: live
with secret law as it exists, abolish it, or reform it. The article
concludes by proposing principles for governing secret law, starting
with the cardinal rule of public law’s supremacy over secret law.
<http://papers.ssrn.com/sol3/papers.cfm?abstract_id=2687223>
Feb. 5, 2016
Re: [nexa] EU-US nuovo accordo Safe Harbour . Considerazioni ART29WP
by Alessandro Mantelero
questo è infatti l'incipit che ho usato in un primo
commento a caldo
Da Safe Harbour a Privacy Shield, cosa è cambiato?
[...]
La risposta corretta è “non si sa”.
https://medium.com/@mantelero/da-safe-harbour-a-privacy-shield-cosa-%C3%A8-…
AM
On Thu, 4 Feb 2016 18:39:06 +0100
Alberto Cammozzo <ac+nexa(a)zeromx.net> wrote:
> Una delle criticità che viene sottolineata è proprio
>che, contrariamente alla prassi, nessuno ha ancora visto
>il testo dell'accordo.
> Diversi commentatori leggono il fatto come un modo per
>"rispettare la scadenza" e frenare le DPA.
>
> Julie Brill, negoziatrice US (FTC) dell'accordo, ha
>rilasciato un'intervista:
> <https://www.youtube.com/watch?v=hzB3GrYcpjk>
> Parla di "stronger FTC/DPA coordination" e di
>"addressing consumer complaints" (con in più ADR gratuite
>e referral delle DPA nazionali verso FTC) ma sempre
>ribadendo il bilanciamento con la sicurezza nazionale.
> Surveillance side: il privacy system US è complesso...
>Gli europei fanno fatica a capirlo. L'intelligence
>community ha fatto grandi sforzi per far capire come
>funziona. I partner di UE DG Justice hanno capito, mentre
>le DPA no.
> Una persona in US accoglierà le lamentele dei cittadini
>US in merito a Sigint...
> In merito ai dettagli dell'accordo, devono ancora essere
>scritti da parte di UE(!).
> A marzo a Berlino Art29DP valuterà se l'accordo
>rispecchia le loro valutazioni.
>
> Altri commenti:
> <https://theintercept.com/2016/02/03/new-safe-harbor-data-deal-may-be-more-p…>
> “The deadline has passed, and they have not delivered.
>This is not really improving the legal situation of
>European citizens — there’s not any change in the legal
>text foreseen.” He said the U.S. was only required to
>“make a promise that everything’s fine” and appoint “an
>ombudsman, who is just the messenger for answers that are
>the same” about U.S. policy.
>
> <https://edri.org/privacyshield-unspinning-the-spin/>
> However, fundamental problems remain with the key mass
>surveillance measures, in particular Section 702 of the
>Foreign Intelligence Surveillance Act (FISA) and
>Executive Order 12.333. A simple question needs to be
>asked: if the judicial body tasked with oversight of
>implementation of FISA can be “systematically misled“, if
>the author of the PATRIOT Act can complain of that
>legislation being “abused“, if a group of congressmen can
>credibly accuse the Director of National Intelligence of
>“lying to Congress under oath” then what trust can non-US
>citizens have in letters signed by an outgoing US
>President?
>
> <https://www.irishtimes.com/business/technology/privacy-shield-a-safe-harbou…>
> Privacy Shield is more Privacy Figleaf, hastily bestowed
>to cover up the failure to produce an actual, written
>agreement in time to meet a January 31st deadline imposed
>three months ago, post-Schrems decision, by the Article
>29 working group of European data protection authorities.
>
> What is the point in Europeans having judicial redress
>when they will not know if their data has been spied on?
>It is likely that the new deal will be tested in the
>European Court of Justice.
> But if the European Commission tells the court that
>American privacy protection is now adequate, it will be a
>lot harder for judges to rule otherwise.
> <http://www.economist.com/blogs/economist-explains/2016/02/economist-explain…>
>
> Mi pare chiaro che sono stati (e forse efficacemente)
>affrontati problemi di armonizzazione della DP ma non il
>nodo della questione sorveglianza.
>
> Ma, come dici, aspettiamo il testo e che diranno le
>DPA...
>
> Alberto
>
>
>
>
> On 04/02/2016 07:58, Alessandro Mantelero wrote:
>> E' ipotizzabile che vi siano criticità nell'accordo,
>>come è ipotizzabile che esso sia una sorta di "ponte"
>>verso un regime migliore. Negli US ci sono infatti
>>diversi provvedimenti in discussione, in primis il
>>Consumer Privacy Bill of Rights Act, così come una
>>crescente pressione politico-economico-sociale per una
>>maggior tutela dei dati.
>> Alla vigilia delle elezioni presidenziali, non mi pare
>>però realistico un significativo mutamento delle leggi
>>sulla sorveglianza. L'accordo sblocca la situazione e
>>permette ai vari attori (DPAs, Commissione, società
>>civile, corti) di contribuire al miglioramento del quadro
>>e, stante la posizione dell'ART29WP, rappresenta anche
>>un'occasione per allargare la riflessione agli altri
>>strumenti di legittimazione dei flussi dati (SCCs, BCRs).
>> Detto questo, posto che nemmeno l'ART29WP ha ricevuto il
>>testo dell'accordo, mi pare poco meditato esprimere
>>giudizi su qualcosa di ancora ignoto, a meno che tutti
>>questi soggetti non abbiano il testo approvato e allora
>>sarebbe bene lo rendessero pubblico.
>>
>> AM
>>
>>
>>
>>
>>
>>
>>
>> On Wed, 3 Feb 2016 23:56:38 +0100
>> Alberto Cammozzo <ac+nexa(a)zeromx.net> wrote:
>>> Anche Intercept è critico, citando fonti di parlamento
>>>UE e diritti civili...
>>>
>>> <https://theintercept.com/2016/02/03/new-safe-harbor-data-deal-may-be-more-p…>
>>>
>>> Jan Philipp Albrecht, a member of the European
>>>Parliament serving on the Committee on Civil Liberties,
>>>Justice, and Home Affairs,quickly
>>><http://www.greens-efa.eu/eu-us-data-protectionsafe-harbour-15127.html>lashed
>>>out at the deal, calling it “an affront to the European
>>>Court of Justice” that “foresees no legally binding
>>>improvements” to American or European spying laws.
>>>
>>> “There has only been a political agreement on the
>>>general framework” of the data-sharing arrangement,
>>>Albrecht told me in a telephone interview. “The deadline
>>>has passed, and they have not delivered. This is not
>>>really improving the legal situation of European citizens
>>>— there’s not any change in the legal text foreseen.” He
>>>said the U.S. was only required to “make a promise that
>>>everything’s fine” and appoint “an ombudsman, who is just
>>>the messenger for answers that are the same” about U.S.
>>>policy.
>>>
>>> Estelle Masse, a policy analyst for the Brussels-based
>>>rights group Access Now, also thought the deal was built
>>>more on politics than a genuine intention to reform.
>>>
>>> “For months the negotiators were having political
>>>discussion about a legal question,” she wrote in an email
>>>to/The Intercept/. “The discussions were about whether
>>>the ruling was ‘anti-American’ or if the EU was rejecting
>>>the U.S. as a democracy. This is neither the case nor the
>>>point. As a result, what we have today is an attempt at a
>>>political fix.”
>>>
>>> European Digital Rights plainly described Tuesday’s
>>>announcement as Europe’s “plans to back down from
>>>defending the European Court’s ruling and accept a new
>>>badly flawed arrangement.” Joe McNamee, the rights
>>>group’s executive director, predicted that the deal would
>>>be a short term stop gap: “Today’s announcement means
>>>that European citizens and businesses on both sides of
>>>the Atlantic face an extended period of uncertainty while
>>>waiting for this new stop-gap solution to fail.”
>>>
>>> Businesses and trade groups, while feverishly releasing
>>>congratulatory press releases as the deal was announced,
>>>worried privately that they may soon be right back in the
>>>same uncertain position.
>>>
>>> “Any risk of legal challenge is unsettling for
>>>business,” said Mike Uehlein, a spokesperson for the
>>>Direct Marketing Association, during a phone call
>>>with/The Intercept./While he emphasized that the trade
>>>group is “excited [negotiators have] continued to make
>>>this a priority,” he told me that a second European Court
>>>of Justice challenge would put “everyone back in the
>>>sticky situation, wondering what’s going to happen. It
>>>has not been fun.”
>>>
>>> Daniel Castro, a vice president at the Information,
>>>Technology, and Innovation Foundation, agreed that
>>>“uncertainty is always bad for business” but expressed
>>>optimism that good faith efforts to arrive at an
>>>agreement would likely continue. “The agreement shows
>>>that U.S. and EU policymakers are deeply committed to
>>>finding an interoperable solution.”
>>>
>>> [...]
>>>
>>> “The Redress Act doesn’t deal with any of the
>>>surveillance concerns in the Schrems case,” said Amie
>>>Stepanovich, U.S. policy manager for Access Now, over the
>>>phone on Tuesday. “We do think it is really important
>>>that substantive surveillance reform be put into place
>>>before [the agreement] can survive challenge. And EU
>>>member states need to take a look at their own
>>>surveillance practices.”
>>>
>>>
>>>
>>> Alberto
>>>
>>>
>>>
>>>
>>> On 03/02/2016 16:16, Alessandro Mantelero wrote:
>>>> STATEMENT OF THE ARTICLE 29 WORKING PARTY
>>>> ON THE CONSEQUENCES OF THE SCHREMS JUDGMENT
>>>>
>>>> http://ec.europa.eu/justice/data-protection/article-29/press-material/press…
>>>>
>>>> On Wed, 03 Feb 2016 16:09:11 +0100
>>>> "Alessandro Mantelero" <alessandro.mantelero(a)polito.it>
>>>>wrote:
>>>>> ecco l'attesa risposta dell'ART29WP sull'EU-US Privacy
>>>>>Shield
>>>>>
>>>>> https://scic.ec.europa.eu/streaming/article-29-subgroup-implementation-of-t…
>>>>>
>>>>>
>>>>> --
>>>>> Prof. Avv. Alessandro Mantelero
>>>>> Politecnico di Torino
>>>>>
>>>>> Nexa Center for Internet and Society | Director of
>>>>>Privacy
>>>>> Politecnico di Torino–Tongji University| Coordinator,
>>>>>Double Degree program in Management and IP Law
>>>>> Nanjing University of Information Science and Technology
>>>>>| Part-time Expert, School of Public Administration
>>>>> European Data Protection Law Review | Associate Editor
>>>>>
>>>>> http://staff.polito.it/alessandro.mantelero
>>>>>
>>>>> EMAIL POLICY: twice a day (Mon-Fri)
>>>>> _______________________________________________
>>>>> nexa mailing list
>>>>> nexa(a)server-nexa.polito.it
>>>>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>>>
>>>> --
>>>> Prof. Avv. Alessandro Mantelero
>>>> Politecnico di Torino
>>>>
>>>> Nexa Center for Internet and Society | Director of
>>>>Privacy
>>>> Politecnico di Torino–Tongji University| Coordinator,
>>>>Double Degree program in Management and IP Law
>>>> Nanjing University of Information Science and Technology
>>>>| Part-time Expert, School of Public Administration
>>>> European Data Protection Law Review | Associate Editor
>>>>
>>>> http://staff.polito.it/alessandro.mantelero
>>>>
>>>> EMAIL POLICY: twice a day (Mon-Fri)
>>>> _______________________________________________
>>>> nexa mailing list
>>>> nexa(a)server-nexa.polito.it
>>>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>>
>>> _______________________________________________
>>> nexa mailing list
>>> nexa(a)server-nexa.polito.it
>>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>
>> --
>> Prof. Avv. Alessandro Mantelero
>> Politecnico di Torino
>>
>> Nexa Center for Internet and Society | Director of
>>Privacy
>> Politecnico di Torino–Tongji University| Coordinator,
>>Double Degree program in Management and IP Law
>> Nanjing University of Information Science and Technology
>>| Part-time Expert, School of Public Administration
>> European Data Protection Law Review | Associate Editor
>>
>> http://staff.polito.it/alessandro.mantelero
>>
>> EMAIL POLICY: twice a day (Mon-Fri)
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
--
Prof. Avv. Alessandro Mantelero
Politecnico di Torino
Nexa Center for Internet and Society | Director of Privacy
Politecnico di Torino–Tongji University| Coordinator,
Double Degree program in Management and IP Law
Nanjing University of Information Science and Technology |
Part-time Expert, School of Public Administration
European Data Protection Law Review | Associate Editor
http://staff.polito.it/alessandro.mantelero
EMAIL POLICY: twice a day (Mon-Fri)
Feb. 4, 2016
Dutch Saunas Warned Against Use of Security Cameras
by Alberto Cammozzo
A violazioni non scherzano neanche i danesi...
Saunas can't make use of security cameras in rooms where guests are
walking in their birthday suits, warns the Dutch Data Protection
Authority (AP). The AP sent a letter to several saunas following
complaints. According to the AP, filming nude individuals is a "huge
infringement on privacy" and only appropriate in exceptional
circumstances. Prevention of sexual acts or theft doesn't suffice.
Camera images that are watched right then without retention are not
allowed either. People must be free of spying in these rooms, the AP states.
<http://www.liberties.eu/en/short-news/9248>
Alberto
Feb. 4, 2016
Re: [nexa] Problemi di privacy con il nuovo sistema di identificazione?
by Stefano Quintarelli
Due cose:
Non mi piace la terminologia identity provider. L'identità è cosa più
complessa della autenticazione e qui si parla di autenticazione. I giuristi
lo giudicarono inopportuno ed adesso abbiamo quelle parole. Ma in un tuo
documento di identità c'è molto di più che nel sistema di autenticazione spid.
Meglio una organizzazione a rete o una centralizzata ?
Cosa offre le maggiori prospettive di efficacia di implementazione,
ammodernamento, arricchimento di servizi, fault tolerance, mitigazione del
rischio, ec..: un solo idp pubblico (per competenza ministero interni) o
molti idp privati, sorvegliati da più soggetti pubblici ?
Io non ho dubbi..
Secondo:è indubbio che un idp compia un trattamento (deve darti
credenziali, autenticarti, revocarle, ecc). Ti sentiresti più a tuo agio se
il regolamento non stabilisse quanto sotto ? (Incluso la previsione di
proporzionalità)
Ciao!,s.
Il 4 febbraio 2016 17:49:51 Federico Morando <federico.morando(a)gmail.com>
ha scritto:
> On 04/02/2016 14:59, Stefano Quintarelli wrote:
>> non mi pare che considerai che un utente puo' avere tutti gli identity
>> provider che vuole ed usarli in modo intercambiabile.
> Vero, sicuramente. Diciamo che a me fa piacere che ce ne sia uno con
> regole e supervisione pubblica, ma certamente si potrebbe fare di più
> per garantire che questo sistema sia un equivalente digitale
> dell'anagrafe, anziché yet another identity provider sostanzialmente
> privato. Non sono abbastanza ferrato per scendere nei dettagli.
> Da cittadino, mi pare solo che una versione (debole) di autenticazione
> nazionale con user e password (che poi posso rafforzare con smart card
> ed altro) sia oltremodo necessaria.
> L'idea di aprirne l'uso anche ai privati, di per sé, mi pare buona. Che
> i provider siano privati, forse, è una parte non necessariamente
> altrettanto saggia, salvo essere molto rigorosi nelle regole (e, v.
> sotto, forse non lo siamo abbastanza, per ora).
> Poi, resto volentieri in ascolto di approfondimenti da chi ne sa più di
> me, e sicuramente tu sei tra quelli, come altri in lista il cui aiuto
> nel farmi un'opinione sullo SPID apprezzerei molto :-)
>> e non ho colto il passaggio in cui dice che gli identity provider non
>> possono fare attivita' di raccolta dati e profilazione degli utenti...
>> (lo dice ?)
>>
>> ;-)
> No, non mi pare che lo dica... il Regolamento SPID per l'accreditamento
> dei gestori sembra implicare l'opposto, a pensar male, quando richiede
> una "relazione che descrive i trattamenti di dati personali effettuati
> riportandone le informazioni essenziali e le misure messe in atto per
> conformare tali trattamenti alla normativa sulla protezione dei dati
> personali, con particolare riferimento ai principi di necessità,
> pertinenza e non eccedenza dei dati,
> nonché di correttezza nel trattamento e all’obbligo di rendere previa e
> idonea informativa agli utenti del servizio di identificazione elettronica".
>
> O, meglio, se davvero i principi fossero implementati a dovere, quanto
> sopra potrebbe anche bastare: per garantire la tua identità non sono
> certo tenuto a profilarti, per cui farlo non sarebbe un trattamento
> necessario, pertinente o coerente con la minimizzazione dei dati... però
> temo proprio che il tutto non sia interpretato in modo così stringente.
>
> Federico
>
Feb. 4, 2016
Re: [nexa] EU-US nuovo accordo Safe Harbour . Considerazioni ART29WP
by Alberto Cammozzo
Una delle criticità che viene sottolineata è proprio che, contrariamente
alla prassi, nessuno ha ancora visto il testo dell'accordo.
Diversi commentatori leggono il fatto come un modo per "rispettare la
scadenza" e frenare le DPA.
Julie Brill, negoziatrice US (FTC) dell'accordo, ha rilasciato
un'intervista:
<https://www.youtube.com/watch?v=hzB3GrYcpjk>
Parla di "stronger FTC/DPA coordination" e di "addressing consumer
complaints" (con in più ADR gratuite e referral delle DPA nazionali
verso FTC) ma sempre ribadendo il bilanciamento con la sicurezza nazionale.
Surveillance side: il privacy system US è complesso... Gli europei fanno
fatica a capirlo. L'intelligence community ha fatto grandi sforzi per
far capire come funziona. I partner di UE DG Justice hanno capito,
mentre le DPA no.
Una persona in US accoglierà le lamentele dei cittadini US in merito a
Sigint...
In merito ai dettagli dell'accordo, devono ancora essere scritti da
parte di UE(!).
A marzo a Berlino Art29DP valuterà se l'accordo rispecchia le loro
valutazioni.
Altri commenti:
<https://theintercept.com/2016/02/03/new-safe-harbor-data-deal-may-be-more-p…>
“The deadline has passed, and they have not delivered. This is not
really improving the legal situation of European citizens — there’s not
any change in the legal text foreseen.” He said the U.S. was only
required to “make a promise that everything’s fine” and appoint “an
ombudsman, who is just the messenger for answers that are the same”
about U.S. policy.
<https://edri.org/privacyshield-unspinning-the-spin/>
However, fundamental problems remain with the key mass surveillance
measures, in particular Section 702 of the Foreign Intelligence
Surveillance Act (FISA) and Executive Order 12.333. A simple question
needs to be asked: if the judicial body tasked with oversight of
implementation of FISA can be “systematically misled“, if the author of
the PATRIOT Act can complain of that legislation being “abused“, if a
group of congressmen can credibly accuse the Director of National
Intelligence of “lying to Congress under oath” then what trust can
non-US citizens have in letters signed by an outgoing US President?
<https://www.irishtimes.com/business/technology/privacy-shield-a-safe-harbou…>
Privacy Shield is more Privacy Figleaf, hastily bestowed to cover up the
failure to produce an actual, written agreement in time to meet a
January 31st deadline imposed three months ago, post-Schrems decision,
by the Article 29 working group of European data protection authorities.
What is the point in Europeans having judicial redress when they will
not know if their data has been spied on? It is likely that the new deal
will be tested in the European Court of Justice.
But if the European Commission tells the court that American privacy
protection is now adequate, it will be a lot harder for judges to rule
otherwise.
<http://www.economist.com/blogs/economist-explains/2016/02/economist-explain…>
Mi pare chiaro che sono stati (e forse efficacemente) affrontati
problemi di armonizzazione della DP ma non il nodo della questione
sorveglianza.
Ma, come dici, aspettiamo il testo e che diranno le DPA...
Alberto
On 04/02/2016 07:58, Alessandro Mantelero wrote:
> E' ipotizzabile che vi siano criticità nell'accordo, come è
> ipotizzabile che esso sia una sorta di "ponte" verso un regime
> migliore. Negli US ci sono infatti diversi provvedimenti in
> discussione, in primis il Consumer Privacy Bill of Rights Act, così
> come una crescente pressione politico-economico-sociale per una
> maggior tutela dei dati.
> Alla vigilia delle elezioni presidenziali, non mi pare però realistico
> un significativo mutamento delle leggi sulla sorveglianza. L'accordo
> sblocca la situazione e permette ai vari attori (DPAs, Commissione,
> società civile, corti) di contribuire al miglioramento del quadro e,
> stante la posizione dell'ART29WP, rappresenta anche un'occasione per
> allargare la riflessione agli altri strumenti di legittimazione dei
> flussi dati (SCCs, BCRs).
> Detto questo, posto che nemmeno l'ART29WP ha ricevuto il testo
> dell'accordo, mi pare poco meditato esprimere giudizi su qualcosa di
> ancora ignoto, a meno che tutti questi soggetti non abbiano il testo
> approvato e allora sarebbe bene lo rendessero pubblico.
>
> AM
>
>
>
>
>
>
>
> On Wed, 3 Feb 2016 23:56:38 +0100
> Alberto Cammozzo <ac+nexa(a)zeromx.net> wrote:
>> Anche Intercept è critico, citando fonti di parlamento UE e diritti
>> civili...
>>
>> <https://theintercept.com/2016/02/03/new-safe-harbor-data-deal-may-be-more-p…>
>>
>>
>> Jan Philipp Albrecht, a member of the European Parliament serving on
>> the Committee on Civil Liberties, Justice, and Home Affairs,quickly
>> <http://www.greens-efa.eu/eu-us-data-protectionsafe-harbour-15127.html>lashed
>> out at the deal, calling it “an affront to the European Court of
>> Justice” that “foresees no legally binding improvements” to American
>> or European spying laws.
>>
>> “There has only been a political agreement on the general framework”
>> of the data-sharing arrangement, Albrecht told me in a telephone
>> interview. “The deadline has passed, and they have not delivered.
>> This is not really improving the legal situation of European citizens
>> — there’s not any change in the legal text foreseen.” He said the
>> U.S. was only required to “make a promise that everything’s fine” and
>> appoint “an ombudsman, who is just the messenger for answers that are
>> the same” about U.S. policy.
>>
>> Estelle Masse, a policy analyst for the Brussels-based rights group
>> Access Now, also thought the deal was built more on politics than a
>> genuine intention to reform.
>>
>> “For months the negotiators were having political discussion about a
>> legal question,” she wrote in an email to/The Intercept/. “The
>> discussions were about whether the ruling was ‘anti-American’ or if
>> the EU was rejecting the U.S. as a democracy. This is neither the
>> case nor the point. As a result, what we have today is an attempt at
>> a political fix.”
>>
>> European Digital Rights plainly described Tuesday’s announcement as
>> Europe’s “plans to back down from defending the European Court’s
>> ruling and accept a new badly flawed arrangement.” Joe McNamee, the
>> rights group’s executive director, predicted that the deal would be a
>> short term stop gap: “Today’s announcement means that European
>> citizens and businesses on both sides of the Atlantic face an
>> extended period of uncertainty while waiting for this new stop-gap
>> solution to fail.”
>>
>> Businesses and trade groups, while feverishly releasing
>> congratulatory press releases as the deal was announced, worried
>> privately that they may soon be right back in the same uncertain
>> position.
>>
>> “Any risk of legal challenge is unsettling for business,” said Mike
>> Uehlein, a spokesperson for the Direct Marketing Association, during
>> a phone call with/The Intercept./While he emphasized that the trade
>> group is “excited [negotiators have] continued to make this a
>> priority,” he told me that a second European Court of Justice
>> challenge would put “everyone back in the sticky situation, wondering
>> what’s going to happen. It has not been fun.”
>>
>> Daniel Castro, a vice president at the Information, Technology, and
>> Innovation Foundation, agreed that “uncertainty is always bad for
>> business” but expressed optimism that good faith efforts to arrive at
>> an agreement would likely continue. “The agreement shows that U.S.
>> and EU policymakers are deeply committed to finding an interoperable
>> solution.”
>>
>> [...]
>>
>> “The Redress Act doesn’t deal with any of the surveillance concerns
>> in the Schrems case,” said Amie Stepanovich, U.S. policy manager for
>> Access Now, over the phone on Tuesday. “We do think it is really
>> important that substantive surveillance reform be put into place
>> before [the agreement] can survive challenge. And EU member states
>> need to take a look at their own surveillance practices.”
>>
>>
>>
>> Alberto
>>
>>
>>
>>
>> On 03/02/2016 16:16, Alessandro Mantelero wrote:
>>> STATEMENT OF THE ARTICLE 29 WORKING PARTY
>>> ON THE CONSEQUENCES OF THE SCHREMS JUDGMENT
>>>
>>> http://ec.europa.eu/justice/data-protection/article-29/press-material/press…
>>>
>>>
>>> On Wed, 03 Feb 2016 16:09:11 +0100
>>> "Alessandro Mantelero" <alessandro.mantelero(a)polito.it> wrote:
>>>> ecco l'attesa risposta dell'ART29WP sull'EU-US Privacy Shield
>>>>
>>>> https://scic.ec.europa.eu/streaming/article-29-subgroup-implementation-of-t…
>>>>
>>>>
>>>>
>>>> --
>>>> Prof. Avv. Alessandro Mantelero
>>>> Politecnico di Torino
>>>>
>>>> Nexa Center for Internet and Society | Director of Privacy
>>>> Politecnico di Torino–Tongji University| Coordinator, Double Degree
>>>> program in Management and IP Law
>>>> Nanjing University of Information Science and Technology |
>>>> Part-time Expert, School of Public Administration
>>>> European Data Protection Law Review | Associate Editor
>>>>
>>>> http://staff.polito.it/alessandro.mantelero
>>>>
>>>> EMAIL POLICY: twice a day (Mon-Fri)
>>>> _______________________________________________
>>>> nexa mailing list
>>>> nexa(a)server-nexa.polito.it
>>>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>>
>>> --
>>> Prof. Avv. Alessandro Mantelero
>>> Politecnico di Torino
>>>
>>> Nexa Center for Internet and Society | Director of Privacy
>>> Politecnico di Torino–Tongji University| Coordinator, Double Degree
>>> program in Management and IP Law
>>> Nanjing University of Information Science and Technology | Part-time
>>> Expert, School of Public Administration
>>> European Data Protection Law Review | Associate Editor
>>>
>>> http://staff.polito.it/alessandro.mantelero
>>>
>>> EMAIL POLICY: twice a day (Mon-Fri)
>>> _______________________________________________
>>> nexa mailing list
>>> nexa(a)server-nexa.polito.it
>>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>>
>> _______________________________________________
>> nexa mailing list
>> nexa(a)server-nexa.polito.it
>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
> --
> Prof. Avv. Alessandro Mantelero
> Politecnico di Torino
>
> Nexa Center for Internet and Society | Director of Privacy
> Politecnico di Torino–Tongji University| Coordinator, Double Degree
> program in Management and IP Law
> Nanjing University of Information Science and Technology | Part-time
> Expert, School of Public Administration
> European Data Protection Law Review | Associate Editor
>
> http://staff.polito.it/alessandro.mantelero
>
> EMAIL POLICY: twice a day (Mon-Fri)
Feb. 4, 2016
Re: [nexa] Problemi di privacy con il nuovo sistema di identificazione?
by Federico Morando
On 04/02/2016 14:59, Stefano Quintarelli wrote:
> non mi pare che considerai che un utente puo' avere tutti gli identity
> provider che vuole ed usarli in modo intercambiabile.
Vero, sicuramente. Diciamo che a me fa piacere che ce ne sia uno con
regole e supervisione pubblica, ma certamente si potrebbe fare di più
per garantire che questo sistema sia un equivalente digitale
dell'anagrafe, anziché yet another identity provider sostanzialmente
privato. Non sono abbastanza ferrato per scendere nei dettagli.
Da cittadino, mi pare solo che una versione (debole) di autenticazione
nazionale con user e password (che poi posso rafforzare con smart card
ed altro) sia oltremodo necessaria.
L'idea di aprirne l'uso anche ai privati, di per sé, mi pare buona. Che
i provider siano privati, forse, è una parte non necessariamente
altrettanto saggia, salvo essere molto rigorosi nelle regole (e, v.
sotto, forse non lo siamo abbastanza, per ora).
Poi, resto volentieri in ascolto di approfondimenti da chi ne sa più di
me, e sicuramente tu sei tra quelli, come altri in lista il cui aiuto
nel farmi un'opinione sullo SPID apprezzerei molto :-)
> e non ho colto il passaggio in cui dice che gli identity provider non
> possono fare attivita' di raccolta dati e profilazione degli utenti...
> (lo dice ?)
>
> ;-)
No, non mi pare che lo dica... il Regolamento SPID per l'accreditamento
dei gestori sembra implicare l'opposto, a pensar male, quando richiede
una "relazione che descrive i trattamenti di dati personali effettuati
riportandone le informazioni essenziali e le misure messe in atto per
conformare tali trattamenti alla normativa sulla protezione dei dati
personali, con particolare riferimento ai principi di necessità,
pertinenza e non eccedenza dei dati,
nonché di correttezza nel trattamento e all’obbligo di rendere previa e
idonea informativa agli utenti del servizio di identificazione elettronica".
O, meglio, se davvero i principi fossero implementati a dovere, quanto
sopra potrebbe anche bastare: per garantire la tua identità non sono
certo tenuto a profilarti, per cui farlo non sarebbe un trattamento
necessario, pertinente o coerente con la minimizzazione dei dati... però
temo proprio che il tutto non sia interpretato in modo così stringente.
Federico
Feb. 4, 2016
testo del framework in materia di cybersecurity 2015 presentato alla Sapienza a Roma il 4 febbraio
by Mauro Alovisio
Gent.me/mi
segnalo il testo definitivo del framework in materia di cybersecurity che è
stato presentato questo pomeriggio presso l'Università La Sapienza di
Roma, il testo era stato sottoposto a consultazione pubblica on line
alla quale hanno partecipato associazioni e studiosi
http://www.cybersecurityframework.it/sites/default/files/CSR2015_web.pdf
Cordiali saluti
Mauro Alovisio
Cyber Security Report 2015, realizzato dal CIS-Sapienza e dal Laboratorio
Nazionale di Cyber Security, in collaborazione con diverse organizzazioni
pubbliche e private, presenterà un Framework Nazionale per la Cyber
Security. Lo scopo del documento è quello di offrire alle organizzazioni un
approccio omogeneo per affrontare la cyber security, al fine di ridurre il
rischio legato alla minaccia cyber. L'approccio del framework è intimamente
legato a una analisi del rischio e non a standard tecnologici.
Il framework si fonda sul noto "Framework for Improving Critical
Infrastructure Cybersecurity" emanato dal NIST per poi essere ampliato ed
attualizzato al contesto italiano. Offrirà una guida per incrementare il
livello di cyber security per la Piccola Media Impresa italiana e
raccomandazioni per il top management di grandi aziende e infrastrutture
critiche su come organizzare processi di cyber security risk management.
Feb. 4, 2016
Re: [nexa] Problemi di privacy con il nuovo sistema di identificazione?
by Stefano Quintarelli
non mi pare che considerai che un utente puo' avere tutti gli identity
provider che vuole ed usarli in modo intercambiabile.
e non ho colto il passaggio in cui dice che gli identity provider non
possono fare attivita' di raccolta dati e profilazione degli utenti...
(lo dice ?)
;-)
On 04/02/2016 14:30, Federico Morando wrote:
> On 04/02/2016 13:43, Diego Giorio wrote:
>> http://www.forumpa.it/pa-digitale/spid-solo-una-soluzione-per-gli-utenti-o-…
>>
>> L'uso massiccio del nuovo sistema unico di identificazione per la PA,
>> oltre a semplificare gli accessi, potrà portare a nuove, e più
>> invasive, possibilità di profilazione
> Questo potrebbe essere vero, ma in confronto ad un sistema frammentato.
> Consideriamo, però, che il confronto è con un sistema in cui c'è già
> l'aggregazione, ma quasi sempre tramite account Google o Facebook...
> qui, forse, ci guadagnamo, nel senso che si potrebbe passare da una
> stewardship privata ad una pubblica. (Ovviamente, ci sono poi gli
> aspetti di sicurezza informatica e simili... e lì, io temo ancora di
> fidarmi più di Google che della PA italiana, ma spero di sbagliare...)
>
> My two cents,
>
> Federico
>
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
>
>
> Nessun virus nel messaggio.
> Controllato da AVG - www.avg.com <http://www.avg.com>
> Versione: 2016.0.7357 / Database dei virus: 4522/11552 - Data di
> rilascio: 04/02/2016
>
Feb. 4, 2016
Re: [nexa] Problemi di privacy con il nuovo sistema di identificazione?
by Federico Morando
On 04/02/2016 13:43, Diego Giorio wrote:
> http://www.forumpa.it/pa-digitale/spid-solo-una-soluzione-per-gli-utenti-o-…
>
> L'uso massiccio del nuovo sistema unico di identificazione per la PA,
> oltre a semplificare gli accessi, potrà portare a nuove, e più
> invasive, possibilità di profilazione
Questo potrebbe essere vero, ma in confronto ad un sistema frammentato.
Consideriamo, però, che il confronto è con un sistema in cui c'è già
l'aggregazione, ma quasi sempre tramite account Google o Facebook...
qui, forse, ci guadagnamo, nel senso che si potrebbe passare da una
stewardship privata ad una pubblica. (Ovviamente, ci sono poi gli
aspetti di sicurezza informatica e simili... e lì, io temo ancora di
fidarmi più di Google che della PA italiana, ma spero di sbagliare...)
My two cents,
Federico
Feb. 4, 2016
Problemi di privacy con il nuovo sistema di identificazione?
by Diego Giorio
http://www.forumpa.it/pa-digitale/spid-solo-una-soluzione-per-gli-utenti-o-…
L'uso massiccio del nuovo sistema unico di identificazione per la PA, oltre a semplificare gli accessi, potrà portare a nuove, e più invasive, possibilità di profilazione
Saluti a tutti
Diego
Feb. 4, 2016