nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- 1 participants
- 30631 messages
Re: [nexa] New Trans-Atlantic Data Privacy Framework largely a copy of "Privacy Shield". noyb will challenge the decision.
by Stefano Quintarelli
mi pare non sia preciso, ma chiedo ai giusristi...
On 13/07/23 11:33, Damiano Verzulli wrote:
> Riprendo questo thread, perché temo la cosa sia "sottovalutata".
>
> Di fatto --se capisco bene-- il nuovo "framework" approvato tre giorni fa:
>
> https://ec.europa.eu/commission/presscorner/detail/en/IP_23_3721
>
> rende _PERFETTAMENTE_ utilizzabili _TUTTI_ i servizi "cloud" erogati dai GAFAM, senza
> problema alcuno.
il fatto che la commissione faccia un accordo non vuole dire che sia legale.
(lo ha fatto in passato e due volte la corte europea di giustizia ha detto "quello che hai
fatto e' illegale".)
adesso lo fa una terza volta, ma non vuol dire che sia legale
un accordo illegale non rende legale il comportamento di chi si basa su di esso
quindi, da quanto capisco io, no, non sono "perfettamente utilizzabili".
estremizzo: se la commissione facesse un accordo che dicesse "si puo' fare benzina senza
pagarla", non vuol dire che puoi andare al distributore, farti il piano e andartene...
e' illecito, checche' ne dica la commissione
almeno questo e' quello che credo di capire,
ma i giuristi saranno piu' precisi...
ciao!, s.
>
> Quindi --ripeto; se capisco bene-- ora le PP.AA. possono "tornare a" / "continuare a"
> utilizzare i vari Google Analytics, Google Classroom, Microsoft Teams e/o tutti gli altri
> N-mila servizi cloud offerti dai GAFAM... senza alcun problema "giuridico".
>
> In molti evidenziano che tale decisione avra' vita breve, e dara' adito ad una Shrems III
> (ossia ad una "bocciatura" da parte della Corte di Giustizia Europea) ma... nel frattempo,
> la "legalita'" mi pare sia tornata a prevalere (con un adeguamento della norma, piuttosto
> che con un cambiamento negli utilizzi).
>
> Mi chiedo quali conseguenze produrra', tale "decisione", negli approcci dei vari manager
> pubblici (dai Dirigenti degli Istituti Comprensivi o delle Scuole Superiori... o anche
> degli Atenei) che, negli ultimi mesi/anno hanno dovuto "gestire" le richieste degli amici
> di Monitora-PA...
>
> Cosa fare, ora? Lo chiedo ai Nexiani di questa lista...
>
> Saluti,
> DV
>
>
> Il 11/07/23 11:03, Alberto Cammozzo via nexa ha scritto:
>> Conformità ottenuta tramite ingegneria semantica del termine 'proportionate'.
>>
>>
>>
>> <https://noyb.eu/en/european-commission-gives-eu-us-data-transfers-third-rou…>
>>
>> Third attempt of the European Commission to get a stable agreement on EU-US data
>> transfers will be likely back at the Court of Justice (CJEU) in a matter of months. The
>> allegedly "new" Trans-Atlantic Data Privacy Framework is largely a copy of the failed
>> "Privacy Shield". Despite the European Commission's public relations efforts, there is
>> little change in US law or the approach taken by the EU. The fundamental problem with
>> FISA 702 was not addressed by the US, as the US still takes the view that only US
>> persons are worthy of constitutional rights.
>>
>> Comparison of the change in US law since 2014:
>>
>> *
>> o "Old" PPD-28 (2014)
>> <https://obamawhitehouse.archives.gov/the-press-office/2014/01/17/presidenti…>
>> o "New" EO 14086, replacing PPD-28 (2022)
>> <https://www.govinfo.gov/content/pkg/FR-2022-10-14/pdf/2022-22531.pdf>
>> * Comparison with previous public relation efforts:
>> o "Rebuilding Trust in EU-US Data Flows" and the "Umbrella" from 2013
>> <https://eur-lex.europa.eu/resource.html?uri=cellar:4d874331-784a-11e3-b889-…>
>> o Press Statement on the "Privacy Shield" from 2016
>> <https://ec.europa.eu/commission/presscorner/detail/en/IP_16_2461>
>> o Media FAQs on the "Privacy Shield" from 2016
>> <https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>
>> o Single Page "Agreement in Principle" between Biden and von der Leyen from 2022
>> <https://ec.europa.eu/commission/presscorner/api/files/attachment/872132/Tra…>
>> * European Commission Draft Adequacy Decision (December 2022)
>> <https://noyb.eu/en/European Commission Draft Adequacy Decision (December 2022)>
>>
>> *Background.* In 2013 Edward Snowden disclosed that the US government used "big tech"
>> companies and programs like "PRISM <https://en.wikipedia.org/wiki/PRISM>" or "Upstream
>> <https://en.wikipedia.org/wiki/Upstream_collection>" under FISA 702
>> <https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act_of_1978…> and EO 12.333 <https://en.wikipedia.org/wiki/Executive_Order_12333> to spy on the rest of the world without the need for probable cause or judicial approval. This was not limited to crime or terrorism, but also included espionage on "partners" of the US. Since a 1995 EU law, personal data may generally not be sent outside of the EU unless there is a "essentially equivalent" protection in the destination country. The US industry heavily relied on a European Commission Decision called "Safe Harbor" that declared the US "essentially equivalent" in 2000. The CJEU has annulled the Commission Decision in C-362/14 ("Schrems I") <https://curia.europa.eu/juris/liste.jsf?nat=or&mat=or&pcs=Oor&jur=C%2CT%2CF…> in 2015, given the vase US surveillance laws. In 2016 the European Commission has passed largely the same Decision on EU-US Data Transfers again, under the new name "Privacy Shield", which was invalidated by the CJEU in C-311/18 ("Schrems II") <https://curia.europa.eu/juris/liste.jsf?nat=or&mat=or&pcs=Oor&jur=C%2CT%2CF…> in 2020 largely on the same grounds.
>>
>> *Ursula's and Joe's "Magic" Tricks. *After the annulment of the "Privacy Shield" the
>> negotiations between the EU and the US saw little progress. The US insisted that EU data
>> would stay subject to US mass surveillance and "non-US" persons will /not /have the same
>> protections as US persons. After little movement for more than 1.5 years, the US has
>> reportedly used the war in Ukraine to put pressure on the EU on sharing personal data
>> <https://www.politico.eu/article/us-eyes-breakthrough-on-data-dispute-with-e…>. Soon thereafter, Joe Biden and Ursula von der Leyen met on 25 March 2022. The same day, the two have suddenly "solved" what the lawyers were unable to solve and presented an "agreement in principle <https://ec.europa.eu/commission/presscorner/api/files/attachment/872132/Tra…>", a one pager which in essence contained two "tricks" that should calm the public:
>>
>> * /First/, the CJEU found that*FISA 702 bulk surveillance being not "proportionate"*
>> within the meaning of Article 52 of the EU's Charter of Fundamental Rights (CFR).
>> The "new" US Executive Order 14086
>> <https://www.govinfo.gov/content/pkg/FR-2022-10-14/pdf/2022-22531.pdf> (which is
>> largely equivalent to PPD-28 from 2014
>> <https://obamawhitehouse.archives.gov/the-press-office/2014/01/17/presidenti…>) would now include the word "proportionate". The "trick" here: *the US will attribute another meaning to the word "proportionate" than the CJEU*. EO 14086 declares FISA 702 bulk surveillance to be "proportionate" under an undisclosed "US understanding" of the word and contrary to the two findings by the CJEU. This way the EU and the US were able to claim that they agreed on the same word ("proportionate") - even when there is no agreement on the meaning of the word.
>> * /Secondly/, the CJEU found that *redress via the Privacy Shield "Ombudsperson"* was
>> not even remotely complying with Article 47 CFR**- even when the Ombudsperson was
>> hailed by the Commission public relations in 2016 as an "/independent/" form of
>> "/redress in the area of national security/"
>> <https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>. The "trick" on
>> redress: the Ombudsperson mechanism was*renamed and split to a Civil Liberties
>> Protection Officer (CLPO) and a so-called "Court"* (which is not a court, but a
>> partly independent executive body). While there are some minor improvements over the
>> Ombudsperson, the individual will not have any direct interaction with the new
>> bodies (they will have to send a complaint to an EU data protection authority and
>> not be heard by the US) and they will give the exact same response as the previous
>> "Ombudsperson". Under EO 14086 the CLPO and the Court must in any case respond by
>> saying: "/Without confirming or denying that the complainant was subject to United
>> States signals intelligence activities, the review either did not identify any
>> covered violations or the Data Protection Review Court issued a determination
>> requiring appropriate remediation/" (see here
>> <https://www.federalregister.gov/d/2022-22531/p-107>). The "judgment" of this
>> "Court" is therefore known even before a case is brought. There are many additional
>> problem with the mechanism, that will largely ensure that complaints will not even
>> be admitted. It seems unthinkable that the Court of Justice would accept this as
>> "judicial redress" under Article 47 CFR.
>> * /Finally/, the*US has refused to reform FISA 702* to give non-US persons reasonable
>> privacy protections. There is agreement on both sides of the Atlantic that FISA 702
>> and EO 12.333 violate fundamental rights under the 4th Amendment in the US and
>> Articles 7, 8 and 47 CFR in the EU - but the US continues to insist that non-US
>> persons do not have constitutional rights in the US - hence a violation of their
>> right to privacy is not covered by the 4th Amendment.
>> * *FISA 702 will have to be prolonged by the end of 2023*, given that there is a
>> "sunset clause" in US law. This would have been the perfect opportunity to improve
>> US law, but given the new deal with the EU, there will be little reason for the US
>> to reform FISA 702.
>>
>> Overall the new "Trans-Atlantic Data Privacy Framework" is a copy of Privacy Shield
>> (from 2016), which in turn was a copy of "Safe Harbor" (from 2000). Given that this
>> approach has failed twice before, there was no legal basis for the change of course -
>> only logic of having a deal was political.
>>
>> Max Schrems, chair of /noyb/: "/They say the definition of insanity is doing the same
>> thing over and over again and expecting a different result. Just like 'Privacy Shield'
>> the latest deal is not based on material changes, but by political interests. Once again
>> the current Commission seems to think that the mess will be the next Commission's
>> problem. FISA 702 needs to be prolonged by the US this year, but with the announcement
>> of the new deal the EU has lost any power to get a reform of FISA 702."/
>>
>> *Fool me Thrice? *Already in the wake of the Snowden disclosures in 2013, the European
>> Commission announced that it will "rebuild" trust
>> <https://eur-lex.europa.eu/resource.html?uri=cellar:4d874331-784a-11e3-b889-…> and "/make Safe Harbor safer/" and come up with an "/umbrella agreement/".**In 2016 journalists were told that <https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462> the "Privacy Shield" would mean that /"for the first time, the US has given the EU written assurance",/ that there would be /"clear limitations, safeguards and oversight mechanisms" /and even/"no indiscriminate mass surveillance". /None of these claims and systems has prove stable when put before the CJEU. In the current version of the Commission's public relations efforts, the same (ever-repeating) claims are entertained.
>>
>> Max Schrems: "/We now had 'Harbors', 'Umbrellas', 'Shields' and 'Frameworks' - but no
>> substantial change in US surveillance law. The press statements of today are almost a
>> literal copy of the once from the past 23 years. Just announcing that something is
>> 'new', 'robust' or 'effective' does not cut it before the Court of Justice. We would
>> need changes in US surveillance law to make this work - and we simply don't have it./"
>>
>> *CJEU challenge ready to be filed. *Anyone who's personal data will be transferred under
>> the new deal can bring a challenge with Data Protection Authorities or Courts. /noyb
>> /has prepared various procedural options to bring the new deal back before the CJEU. We
>> expect the new system to be implemented by the first companies within the next months,
>> which will open the path towards a challenge by a person who's data is transferred under
>> the new instrument. It is not unlikely that a challenge would reach the CJEU by the end
>> of 2023 or beginning of 2024. The CJEU would then even have the option to suspend the
>> "Framework" for the time of the procedure. A final decision by the CJEU would be likely
>> by 2024 or 2025. No matter if such a challenge will be successful, this will bring
>> clarity to the "Trans-Atlantic Data Privacy Framework" within about two years.
>>
>> Max Schrems:/"We have various options for a challenge already in the drawer, although we
>> are sick and tired of this legal ping-pong. We currently expect this to be back at the
>> Court of Justice by the beginning of next year. The Court of Justice could then even
>> suspend the new deal while it is reviewing the substance of it. For the sake of legal
>> certainty and the rule of law we will then get an answer if the Commission's tiny
>> improvements were enough or not./ /For the past 23 years all EU-US deals were declared
>> invalid retroactively, making all past data transfers by business illegal - we seem to
>> just add another two years of this ping-pong now./"
>>
>> *EU Commission shows little care for rule of law and citizens' privacy. *This third
>> attempt to pass largely the same unlawful decision also raises questions as to the
>> larger role of the European Commission being the guardian of the EU treaties. Instead of
>> upholding the 'rule of law' the Commission simply passes an invalid decision over and
>> over again, despite clear rulings by the CJEU. Despite large outrage after the Snowden
>> disclosures in the EU and repeated calls by the European Parliament to take action, the
>> Commission seems to give the diplomatic relations with the US and business pressure on
>> both side of the Atlantic the priority over the rights of Europeans and the requirements
>> of EU law.
>>
>> Max Schrems: "/The Commission is meant to be the 'guardian of the treaties' and the
>> defender or the 'rule of law'. It loves that role when it comes to Member States
>> violating EU law. Now the Commission itself simply ignores the Court of Justice for the
>> third time./"
>>
>>
>> _______________________________________________
>> nexa mailing list
>> nexa(a)server-nexa.polito.it
>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
> --
> Damiano Verzulli
> e-mail:damiano@verzulli.it
> ---
> possible?ok:while(!possible){open_mindedness++}
> ---
> "...I realized that free software would not generate the kind of
> income that was needed. Maybe in USA or Europe, you may be able
> to get a well paying job as a free software developer, but not
> here [in Africa]..." -- Guido Sohne - 1973-2008
> http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
July 13, 2023
China finalizes first-of-its-kind rules governing generative A.I. services like ChatGPT
by Zulu
Di solito leggo i digest quotidiani, ma per la prima volta contribuisco
anche io. Giusto scrivendo una parte su due casi di copyright infringement
in Cina, notizie su generative AI!
https://www.cnbc.com/2023/07/13/china-introduces-rules-governing-generative…
Buona giornata!
Francesco M.
--
*Francesco Mittica*
Future Graduate, Global Law and Transnational Legal Studies
MSOI Member
AI Aficionado
July 13, 2023
Re: [nexa] New Trans-Atlantic Data Privacy Framework largely a copy of "Privacy Shield". noyb will challenge the decision.
by Damiano Verzulli
Riprendo questo thread, perché temo la cosa sia "sottovalutata".
Di fatto --se capisco bene-- il nuovo "framework" approvato tre giorni fa:
https://ec.europa.eu/commission/presscorner/detail/en/IP_23_3721
rende _PERFETTAMENTE_ utilizzabili _TUTTI_ i servizi "cloud" erogati dai
GAFAM, senza problema alcuno.
Quindi --ripeto; se capisco bene-- ora le PP.AA. possono "tornare a" /
"continuare a" utilizzare i vari Google Analytics, Google Classroom,
Microsoft Teams e/o tutti gli altri N-mila servizi cloud offerti dai
GAFAM... senza alcun problema "giuridico".
In molti evidenziano che tale decisione avra' vita breve, e dara' adito
ad una Shrems III (ossia ad una "bocciatura" da parte della Corte di
Giustizia Europea) ma... nel frattempo, la "legalita'" mi pare sia
tornata a prevalere (con un adeguamento della norma, piuttosto che con
un cambiamento negli utilizzi).
Mi chiedo quali conseguenze produrra', tale "decisione", negli approcci
dei vari manager pubblici (dai Dirigenti degli Istituti Comprensivi o
delle Scuole Superiori... o anche degli Atenei) che, negli ultimi
mesi/anno hanno dovuto "gestire" le richieste degli amici di Monitora-PA...
Cosa fare, ora? Lo chiedo ai Nexiani di questa lista...
Saluti,
DV
Il 11/07/23 11:03, Alberto Cammozzo via nexa ha scritto:
> Conformità ottenuta tramite ingegneria semantica del termine
> 'proportionate'.
>
>
>
> <https://noyb.eu/en/european-commission-gives-eu-us-data-transfers-third-rou…>
>
> Third attempt of the European Commission to get a stable agreement on
> EU-US data transfers will be likely back at the Court of Justice
> (CJEU) in a matter of months. The allegedly "new" Trans-Atlantic Data
> Privacy Framework is largely a copy of the failed "Privacy Shield".
> Despite the European Commission's public relations efforts, there is
> little change in US law or the approach taken by the EU. The
> fundamental problem with FISA 702 was not addressed by the US, as the
> US still takes the view that only US persons are worthy of
> constitutional rights.
>
> Comparison of the change in US law since 2014:
>
> *
> o "Old" PPD-28 (2014)
> <https://obamawhitehouse.archives.gov/the-press-office/2014/01/17/presidenti…>
> o "New" EO 14086, replacing PPD-28 (2022)
> <https://www.govinfo.gov/content/pkg/FR-2022-10-14/pdf/2022-22531.pdf>
> * Comparison with previous public relation efforts:
> o "Rebuilding Trust in EU-US Data Flows" and the "Umbrella" from
> 2013
> <https://eur-lex.europa.eu/resource.html?uri=cellar:4d874331-784a-11e3-b889-…>
> o Press Statement on the "Privacy Shield" from 2016
> <https://ec.europa.eu/commission/presscorner/detail/en/IP_16_2461>
> o Media FAQs on the "Privacy Shield" from 2016
> <https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>
> o Single Page "Agreement in Principle" between Biden and von der
> Leyen from 2022
> <https://ec.europa.eu/commission/presscorner/api/files/attachment/872132/Tra…>
> * European Commission Draft Adequacy Decision (December 2022)
> <https://noyb.eu/en/European Commission Draft Adequacy Decision
> (December 2022)>
>
> *Background.* In 2013 Edward Snowden disclosed that the US government
> used "big tech" companies and programs like "PRISM
> <https://en.wikipedia.org/wiki/PRISM>" or "Upstream
> <https://en.wikipedia.org/wiki/Upstream_collection>" under FISA 702
> <https://en.wikipedia.org/wiki/Foreign_Intelligence_Surveillance_Act_of_1978…>
> and EO 12.333 <https://en.wikipedia.org/wiki/Executive_Order_12333> to
> spy on the rest of the world without the need for probable cause or
> judicial approval. This was not limited to crime or terrorism, but
> also included espionage on "partners" of the US. Since a 1995 EU law,
> personal data may generally not be sent outside of the EU unless there
> is a "essentially equivalent" protection in the destination country.
> The US industry heavily relied on a European Commission Decision
> called "Safe Harbor" that declared the US "essentially equivalent" in
> 2000. The CJEU has annulled the Commission Decision in C-362/14
> ("Schrems I")
> <https://curia.europa.eu/juris/liste.jsf?nat=or&mat=or&pcs=Oor&jur=C%2CT%2CF…>
> in 2015, given the vase US surveillance laws. In 2016 the European
> Commission has passed largely the same Decision on EU-US Data
> Transfers again, under the new name "Privacy Shield", which was
> invalidated by the CJEU in C-311/18 ("Schrems II")
> <https://curia.europa.eu/juris/liste.jsf?nat=or&mat=or&pcs=Oor&jur=C%2CT%2CF…>
> in 2020 largely on the same grounds.
>
> *Ursula's and Joe's "Magic" Tricks. *After the annulment of the
> "Privacy Shield" the negotiations between the EU and the US saw little
> progress. The US insisted that EU data would stay subject to US mass
> surveillance and "non-US" persons will /not /have the same protections
> as US persons. After little movement for more than 1.5 years, the US
> has reportedly used the war in Ukraine to put pressure on the EU on
> sharing personal data
> <https://www.politico.eu/article/us-eyes-breakthrough-on-data-dispute-with-e…>.
> Soon thereafter, Joe Biden and Ursula von der Leyen met on 25 March
> 2022. The same day, the two have suddenly "solved" what the lawyers
> were unable to solve and presented an "agreement in principle
> <https://ec.europa.eu/commission/presscorner/api/files/attachment/872132/Tra…>",
> a one pager which in essence contained two "tricks" that should calm
> the public:
>
> * /First/, the CJEU found that*FISA 702 bulk surveillance being not
> "proportionate"* within the meaning of Article 52 of the EU's
> Charter of Fundamental Rights (CFR). The "new" US Executive Order
> 14086
> <https://www.govinfo.gov/content/pkg/FR-2022-10-14/pdf/2022-22531.pdf>
> (which is largely equivalent to PPD-28 from 2014
> <https://obamawhitehouse.archives.gov/the-press-office/2014/01/17/presidenti…>)
> would now include the word "proportionate". The "trick" here: *the
> US will attribute another meaning to the word "proportionate" than
> the CJEU*. EO 14086 declares FISA 702 bulk surveillance to be
> "proportionate" under an undisclosed "US understanding" of the
> word and contrary to the two findings by the CJEU. This way the EU
> and the US were able to claim that they agreed on the same word
> ("proportionate") - even when there is no agreement on the meaning
> of the word.
> * /Secondly/, the CJEU found that *redress via the Privacy Shield
> "Ombudsperson"* was not even remotely complying with Article 47
> CFR**- even when the Ombudsperson was hailed by the Commission
> public relations in 2016 as an "/independent/" form of "/redress
> in the area of national security/"
> <https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>.
> The "trick" on redress: the Ombudsperson mechanism was*renamed and
> split to a Civil Liberties Protection Officer (CLPO) and a
> so-called "Court"* (which is not a court, but a partly independent
> executive body). While there are some minor improvements over the
> Ombudsperson, the individual will not have any direct interaction
> with the new bodies (they will have to send a complaint to an EU
> data protection authority and not be heard by the US) and they
> will give the exact same response as the previous "Ombudsperson".
> Under EO 14086 the CLPO and the Court must in any case respond by
> saying: "/Without confirming or denying that the complainant was
> subject to United States signals intelligence activities, the
> review either did not identify any covered violations or the Data
> Protection Review Court issued a determination requiring
> appropriate remediation/" (see here
> <https://www.federalregister.gov/d/2022-22531/p-107>). The
> "judgment" of this "Court" is therefore known even before a case
> is brought. There are many additional problem with the mechanism,
> that will largely ensure that complaints will not even be
> admitted. It seems unthinkable that the Court of Justice would
> accept this as "judicial redress" under Article 47 CFR.
> * /Finally/, the*US has refused to reform FISA 702* to give non-US
> persons reasonable privacy protections. There is agreement on both
> sides of the Atlantic that FISA 702 and EO 12.333 violate
> fundamental rights under the 4th Amendment in the US and Articles
> 7, 8 and 47 CFR in the EU - but the US continues to insist that
> non-US persons do not have constitutional rights in the US - hence
> a violation of their right to privacy is not covered by the 4th
> Amendment.
> * *FISA 702 will have to be prolonged by the end of 2023*, given
> that there is a "sunset clause" in US law. This would have been
> the perfect opportunity to improve US law, but given the new deal
> with the EU, there will be little reason for the US to reform FISA
> 702.
>
> Overall the new "Trans-Atlantic Data Privacy Framework" is a copy of
> Privacy Shield (from 2016), which in turn was a copy of "Safe Harbor"
> (from 2000). Given that this approach has failed twice before, there
> was no legal basis for the change of course - only logic of having a
> deal was political.
>
> Max Schrems, chair of /noyb/: "/They say the definition of insanity is
> doing the same thing over and over again and expecting a different
> result. Just like 'Privacy Shield' the latest deal is not based on
> material changes, but by political interests. Once again the current
> Commission seems to think that the mess will be the next Commission's
> problem. FISA 702 needs to be prolonged by the US this year, but with
> the announcement of the new deal the EU has lost any power to get a
> reform of FISA 702."/
>
> *Fool me Thrice? *Already in the wake of the Snowden disclosures in
> 2013, the European Commission announced that it will "rebuild" trust
> <https://eur-lex.europa.eu/resource.html?uri=cellar:4d874331-784a-11e3-b889-…>
> and "/make Safe Harbor safer/" and come up with an "/umbrella
> agreement/".**In 2016 journalists were told that
> <https://ec.europa.eu/commission/presscorner/detail/en/MEMO_16_2462>
> the "Privacy Shield" would mean that /"for the first time, the US has
> given the EU written assurance",/ that there would be /"clear
> limitations, safeguards and oversight mechanisms" /and even/"no
> indiscriminate mass surveillance". /None of these claims and systems
> has prove stable when put before the CJEU. In the current version of
> the Commission's public relations efforts, the same (ever-repeating)
> claims are entertained.
>
> Max Schrems: "/We now had 'Harbors', 'Umbrellas', 'Shields' and
> 'Frameworks' - but no substantial change in US surveillance law. The
> press statements of today are almost a literal copy of the once from
> the past 23 years. Just announcing that something is 'new', 'robust'
> or 'effective' does not cut it before the Court of Justice. We would
> need changes in US surveillance law to make this work - and we simply
> don't have it./"
>
> *CJEU challenge ready to be filed. *Anyone who's personal data will be
> transferred under the new deal can bring a challenge with Data
> Protection Authorities or Courts. /noyb /has prepared various
> procedural options to bring the new deal back before the CJEU. We
> expect the new system to be implemented by the first companies within
> the next months, which will open the path towards a challenge by a
> person who's data is transferred under the new instrument. It is not
> unlikely that a challenge would reach the CJEU by the end of 2023 or
> beginning of 2024. The CJEU would then even have the option to suspend
> the "Framework" for the time of the procedure. A final decision by the
> CJEU would be likely by 2024 or 2025. No matter if such a challenge
> will be successful, this will bring clarity to the "Trans-Atlantic
> Data Privacy Framework" within about two years.
>
> Max Schrems:/"We have various options for a challenge already in the
> drawer, although we are sick and tired of this legal ping-pong. We
> currently expect this to be back at the Court of Justice by the
> beginning of next year. The Court of Justice could then even suspend
> the new deal while it is reviewing the substance of it. For the sake
> of legal certainty and the rule of law we will then get an answer if
> the Commission's tiny improvements were enough or not./ /For the past
> 23 years all EU-US deals were declared invalid retroactively, making
> all past data transfers by business illegal - we seem to just add
> another two years of this ping-pong now./"
>
> *EU Commission shows little care for rule of law and citizens'
> privacy. *This third attempt to pass largely the same unlawful
> decision also raises questions as to the larger role of the European
> Commission being the guardian of the EU treaties. Instead of upholding
> the 'rule of law' the Commission simply passes an invalid decision
> over and over again, despite clear rulings by the CJEU. Despite large
> outrage after the Snowden disclosures in the EU and repeated calls by
> the European Parliament to take action, the Commission seems to give
> the diplomatic relations with the US and business pressure on both
> side of the Atlantic the priority over the rights of Europeans and the
> requirements of EU law.
>
> Max Schrems: "/The Commission is meant to be the 'guardian of the
> treaties' and the defender or the 'rule of law'. It loves that role
> when it comes to Member States violating EU law. Now the Commission
> itself simply ignores the Court of Justice for the third time./"
>
>
> _______________________________________________
> nexa mailing list
> nexa(a)server-nexa.polito.it
> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
--
Damiano Verzulli
e-mail:damiano@verzulli.it
---
possible?ok:while(!possible){open_mindedness++}
---
"...I realized that free software would not generate the kind of
income that was needed. Maybe in USA or Europe, you may be able
to get a well paying job as a free software developer, but not
here [in Africa]..." -- Guido Sohne - 1973-2008
http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
July 13, 2023
A proposito dell'IA/ML c/o UniPI (...e del realtivo budget IT) [Era: relatività della rete in azione...]
by Damiano Verzulli
Il 10/07/23 17:14, Antonio ha scritto:
>> Non mi è chiara la "fonte" dell'informazione sui € 330.000 + IVA.
>> Qual'e'? E' "ufficiale"?
> https://www.unipi.it/index.php/gare/item/24390-procedura-negoziata-ai-sensi…
Riprendo questo thread, che scaturiva dai documenti ufficiali del
bilancio UniPI 2022, dai quali si desumevano alcuni aspetti legati alla
gestione dell'IT (nel 2022).
Fra l'altro, è stato evidenziato che nel 2022 sono stati spesi € 402.600
(ossia: 330.00 + IVA 22%) per l'acquisto di un "box" [1] che fa HPC/AI.
Dopo una (mia) attenta analisi di tale documentazione, ho capito che lo
stesso "box", **IDENTICO** sia nella sostanza (modello specifico), che
nel costo (altri € 402.600), che, soprattutto, del fornitore, è stato
**RI**comprato una seconda volta ad inizio 2023.
Quindi... CE NE SONO DUE!
1 -
https://www.gazzettaufficiale.it/atto/contratti/caricaDettaglioAtto/origina…
2 -
https://www.gazzettaufficiale.it/atto/contratti/caricaDettaglioAtto/origina…
Mi chiedo se il fatto che uno dei due sia in quota PNRR sia una
feature... o un bug... (non ho la risposta).
In ogni caso, mi associo all'aspettativa di Antonio, che in [2]
ricordava di un messaggio di Attardi dello scorso febbraio 2022 [3]
(quindi PRIMA che tali acquisti venissero concretizzati) che segnalava
che "Tuttavia queste tecnologie rimangono appannaggio di pochi e rendono
più difficile ad altri ricercatori di restare al passo."
Ecco: UniPI... ci ha messo sopra 805.000 euro... OTTOCENTOCINQUEMILA euro.
Vorrei scrivere un sacco di cose, tutte relative al fatto che 800k €
*PUBBLICI* sono una MALEDETTAMENTE GRANDE quantita' di denaro.... e che
con quello stesso denaro, si potevano pagare una decine di stipendi per
un paio d'anni... ma non lo faccio.
Ci terrei, pero', a sentire l'opinione dei Pisani, qui in lista.
Saluti,
DV
P.S.: A latere: al prossimo che mi dice che in UNIV servono piu'
risorse.... lo vengo a trovare e gli rigo la macchina...
[1] I piu' curiosi possono "vederlo" dalla pagina del produttore:
https://www.nvidia.com/en-us/data-center/dgx-h100/
[2] https://server-nexa.polito.it/pipermail/nexa/2023-July/051259.html
[3] https://server-nexa.polito.it/pipermail/nexa/2022-February/048692.html
--
Damiano Verzulli
e-mail: damiano(a)verzulli.it
---
possible?ok:while(!possible){open_mindedness++}
---
"...I realized that free software would not generate the kind of
income that was needed. Maybe in USA or Europe, you may be able
to get a well paying job as a free software developer, but not
here [in Africa]..." -- Guido Sohne - 1973-2008
http://ole.kenic.or.ke/pipermail/skunkworks/2008-April/005989.html
July 12, 2023
Undone Computer Science conference
by Norberto Patrignani
Segnalo ... la call scade 10 Ottobre 2023
https://undonecs.sciencesconf.org/
buona estate
Norberto
July 12, 2023
Re: [nexa] AI revolution puts skilled jobs at highest risk, OECD says
by Federico Guerrini
Sul sito del magazine in-house del Parlamento britannico, Politics
Home,
c'era di recente un articolo interessante che diceva, in sostanza:
Se oggi grazie ai software di AI è possibile automatizzare molti
compiti intellettuali prima tipicamente umani,mentre si incontrano
molte difficoltà a replicare certi lavori manuali (raccoglitore di
frutta e simili)che richiedono un eccezionale coordinamento
corpo-cervello, quali sono le vere "skill" da valorizzaree premiare
(l'autore, un MP, fa riferimento al concetto di immigrazione
"qualificata", chi sono a questo punto i "qualificati")?
Si tratta certamente di un punto di vista riduttivo, se non altro
perché si stanno facendo moltissimi progressi anchenell'automatizzare
i compiti di manovalanza, ma lo segnalo perché mi era sembrato un
interessante ribaltamento di prospettiva:
https://www.politicshome.com/thehouse/article/artificial-intelligence-deman…
All fin fine, non potrebbe essere che i lavori puramente
intellettuali e puramente manuali siano in bilico, mentre quelli dove
sono richieste"entrambe" le abilità siano i più resistenti al
cambiamento?
Ciao,
buona giornata,
F.
On 12/7/2023 at 10:34 AM, "Luigi Scorca"
wrote:https://www.theguardian.com/technology/2023/jul/11/ai-revolution-puts…
Luigi
http://www.forbes.com/sites/federicoguerrini/
https://reutersinstitute.politics.ox.ac.uk/our-research/newsroom-curators-a…
My latest book: Content Curation (Italian):
http://www.amazon.it/Content-Curation-Federico-Guerrini/dp/8820366126
July 12, 2023
Re: [nexa] AI revolution puts skilled jobs at highest risk, OECD says
by Fabio Alemagna
Il giorno mer 12 lug 2023 alle ore 10:34 Luigi Scorca
<luigi.scorca(a)gmail.com> ha scritto:
>
> https://www.theguardian.com/technology/2023/jul/11/ai-revolution-puts-skill…
Mi permetto di dire che mi pare una cosa buona: posta l'inevitabilità
dell'avvento di questa e sempre intelligenti tecnologie, credo - ma
magari mi sbaglio - che il fatto che i lavori più a rischio siano
quelli dei colletti bianchi possa finalmente creare quella pressione
necessaria sulla politica affinché si arrivi a un Reddito di Base
Universale.
Fabio
July 12, 2023
AI revolution puts skilled jobs at highest risk, OECD says
by Luigi Scorca
https://www.theguardian.com/technology/2023/jul/11/ai-revolution-puts-skill…
Luigi
July 12, 2023
Pricing Algorithms Aren’t Colluding, Yet
by Luigi Scorca
"Axel Gautier, Ashwin Ittoo, and Pieter van Cleynenbreugel write that the
practice of pricing algorithms tacitly colluding remains theoretical for
now, and technological obstacles render it very unlikely in the short term.
However, regulators must still prepare for a future in which artificial
intelligence achieves the necessary sophistication to collude."
https://www.promarket.org/2023/07/11/pricing-algorithms-arent-colluding-yet/
July 11, 2023
proposte di collaborazione
by Angelo Raffaele Meo
carissimi,
colgo l'opportunità dell'incontro di domani, 12 luglio, per rinnovare una proposta di collaborazione a tutti gli amici di Nexa. Sicuramente domani non avremo il tempo necessario per discutere questa mia proposta, ma potremo approndire la questione durante le vacanzze estive via mail o videoconferenze remote.
I capitoli più importanti della proposta hanno per oggetto: a) il nostro portale FARE; b) l'archivio nazionale delle O.E.R. (o "Open Education Resources", secondo la definizione di UNESCO).
a). Il nostro prodotto "FARE". come "Free Architecture for Remote Education", sviluppato negli ultimi dieci anni da una gruppo di ricercatori e insegnanti operanti prevalentemente presso il Politecnico di Torino, , attualmente contiene:
a) un archivio di oltre 2000 OER, che spero diventi il punto di partenza di un progetto nazionale che ho appena proposto all'Accademia delle Scienze e ad altri enti di ricerca;
b) gli strumenti per creare o comporre nuove OER;
c) gli strumenti per produrre nuovi MOOC ("Massive Open Online Courseware") che hanno vinto il secondo premio al concorso nazionale "TalentItaly" del MIUR;
d) altri strumenti per l'attuazione dei nuovi modelli didattici come la "Flipped Classroom";
e) una linea di strumenti per la didattica a distanza che a noi pare superiore ai noti prodotti del mercato come Google o Microsoft.
Queste funzionalità possono essere facillmente verificate con un collegamento a "testfare.polito.it". Se vi interessasse potrei inviarvi un documento tecnico analitico e il filmato di un mio intervento che ho avuto l'onore di fare a conclusione del progetto nazionale "Programmailfuturo", rivolto a tutte le scuole italiane da CINI e MIUR.
In questo momento stiamo concludendo una fase della progettazione che consente ad una scuola una facile installazione di FARE sul proprio server in modo che la scuola possa fornire i servizi della "didattica a distanza" non soltanto ai propri allievi e insegnanti ma anche ad allievi e insegnanti di altre scuole. Inoltre stiamo avviando la ricerca per l'attuazione dell'integrazione di FARE nel nuovo innovativo modello della PDND,, ossia "Piattaforma Digitale Nazionale dei Dati", fortemente raccomandato dal Dipartimento della Funzione Pubblica. Inoltre, ovviamente, i nuovi strumenti per la didattica basati su intelligenza artificiale e robotica potranno essere integrati nel nostro portale.
Per una felice circostanza, il modello del "Connected Learning Environment" descritto nel documento del PNRR "Scuola 4.0" ha esattamente le funzionalità di FARE. Di conseguenza, una scuola che adotti FARE può con piccole integrazioni candidarsi alla collaborazione con il PNRR.
b) Alcuni autorevoli responsabili dell'Accademia delle Scienze di Torino e del Politecnico di Torino hanno manifestato grande interesse per la proposta di attuare in grande archicio nazionale dellle Open Education Resources. Ha manifestato grande interesse anche il noto giurista Marco Ciurcina che si è candidato alla guida del progetto con particolare attenzione agli aspetti della proprietà intellettuale e della "privacy".
Il server dove sarà allocato l'archivio non avrà particolare esigenze dal punto di vista della banda trasmissiva e quindi potrà essere una macchina di basso costo. Il software necessario per la gestione del progetto è già disponibile, poichè è esattamente quello che attualmente gestisce l'archivio di FARE. Il lavoro più difficile è l'identificazione di almeno una ventina di "responsabili di area scientifica". Quando un operatore della scuola o, al limite, un autore, vorrà aggiungere all'archivio un nuovo "learning object", lo dovrà inviare al responsabile di quella area scientifica. Questo ultimo, dopo un'analisi del valore di quell'oggetto, lo installerà direttamente sull'archivio.
A differenza del precedente punto a), agli amici di Nexa chiediamo ora non una collaborazione alla ricerca, ma all'insegnamento.
Chiudo questa mail con una domanda finale (chiara manifestazione di "interesse privato in atti di ufficio"). Qualche amico ha letto o fatto leggere ad altri amici la mia dimostrazione sul "problema del millennio"?
Con moltissimo affetto
Raf
July 11, 2023