Thursday, 28 January 2010
Happy Data Privacy Day!
I am taking this opportunity to greet a very Happy Data Privacy Day. 28 January every year, is the designated date for such a must-to-celebrate Data Privacy day not only in the United States, but also in some parts of the world - Canada, Australia and some European Union countries too. Stakeholders representing the corporate organisations, universities, Information Commissioners' Office, Privacy Commissioners and all have joint this celebration with its collective mission in data protection and privacy. Detailed history of its birth, the reports of 2008 and 2009 are respectively readable here. In a related development, I have just discovered a Privacy Project website that focuses their discussions, research and consultations in the area of data protection privacy as well. It will be quite fascinating to gauge the progress of these efforts, not only at the United States' level, but also, at the global level.
Security, At What Cost - A study by RAND
Thanks to Dr. Ian Brown for posting this quantitative research / study by RAND on the above. I will map it based on the lense of RFID in my research.
RFID SEC 2010 Asia
Singapore Management University will be hosting the RFID SEC 2010 on February 2010. Do peek the details.
Monday, 25 January 2010
Technology Predictions for 2010 - GPS and RFID
These predictions are interesting. We will see and await the next eleven (11) months of translation - whether it hit, or otherwise.
Cloud-based RFID; A privacy crawler?
It is always about the cost factor for companies. But, it maybe partly due to technology trend as well. In Australia, the proposition to design a cloud-based RFID was mooted. I am unsure whether the idea has been translated into a proof of concept. If it has, it maybe a privacy crawler, especially, at this point of time - where people around the world has been advocating on cloud computing's chief issues: security, data protection and privacy.
Thursday, 14 January 2010
RFID interoperability within healthcare
This American healthcare solutions' commentator views that RFID will be linking its deployment to other predicted technology growth. It's very interesting to look into the top ten (10) predictions of the healthcare IT trends:-
Electronic Medical Records (EMRs) will gain momentum
Personal Health Records (PHRs) earn legitimacy
Cost containment is a paramount
Alternative care delivery models emerge
War waged on Medicare fraud
Increased focus on outbreak preparedness
Patient safety initiatives intensify
Healthcare professionals in short supply
Storage and business continuity concerns abound
Physician groups join healthcare systems
As cliche' as it sounds, predictions may hit and it may not hit. If one is to bring RFID within one of these predictions, stakeholders should also consider the privacy impact assessment and its respective informational privacy responses.
As cliche' as it sounds, predictions may hit and it may not hit. If one is to bring RFID within one of these predictions, stakeholders should also consider the privacy impact assessment and its respective informational privacy responses.
RFID Cluster in Songdo Korea
In an ambitious move and plan, Songdo, a city in Korea will be an enabled-RFID-city. The Korea IT Times reports. In the absence of such primary English literature on RFID, I am unsure whether Korea has a strong data protection / privacy laws (if any). Or, whether the country has a guideline, code or any piecemeal legislation that is related to informational privacy. It would be very much interesting to gauge certain discovery on this matter. Having said that, I anticipate and predict that Korea needs to address informational privacy issues vis-a'-vis RFID from various spectrum and viewpoints. Wondering whether the Songdo RFID development is taking a gradual and progressive phase.
Friday, 8 January 2010
RFID & NFC pairs for Digital Monies' evolution?
What sparks the move on having digital monies in place? I have reached into varying contexts and views after reading this. One of the contributing factors, amongst others, is also due to the evolution of Near Field Communications (known as NFC). In my RFID research and reading, I have come across how NFC has been developed as a standard for technology applications.
Thus, whilst pre-empting and anticipating the NFC hype, many technology companies lobbied to get engaged with its development globally. In South Korea and Japan, NFC applications within mobile phones have taken place as early as 2002 (trial stage). Today, some locations are deployed with readers that are read-enabled with NFC, and of course, with the integration of RFID chip. Concurrently, my research and reading have ideally outlined that the pairing of such technology - NFC and RFID will transform consumers and users' convenient almost to perfection. My thought hit and affirmed it. As the commentator suggested, by 2020, one shall gradually witness the usage of cash to reach the stage of extinction. It's interesting to see how possible the prediction of a cashless consumer shall be. Today, we have been using Debit cards and Credit cards. PanPal, on the other hand, seems to lead the cashless environment intermediary convincingly acceptable by its customers and users via online (secured, fast and cashless).
Now,what the future lies on digital monies or digital cash is a significant question that policy makers should anticipate from various viewpoints - technology, legal, regulations, business and social. I may predict that there should be a public consultation or white paper on technology coupling (alike of NFC and RFID) that links towards various aforementioned viewpoints. The call for such a viewpoint should be brainstormed skeletally without further ado.
Thus, whilst pre-empting and anticipating the NFC hype, many technology companies lobbied to get engaged with its development globally. In South Korea and Japan, NFC applications within mobile phones have taken place as early as 2002 (trial stage). Today, some locations are deployed with readers that are read-enabled with NFC, and of course, with the integration of RFID chip. Concurrently, my research and reading have ideally outlined that the pairing of such technology - NFC and RFID will transform consumers and users' convenient almost to perfection. My thought hit and affirmed it. As the commentator suggested, by 2020, one shall gradually witness the usage of cash to reach the stage of extinction. It's interesting to see how possible the prediction of a cashless consumer shall be. Today, we have been using Debit cards and Credit cards. PanPal, on the other hand, seems to lead the cashless environment intermediary convincingly acceptable by its customers and users via online (secured, fast and cashless).
Now,what the future lies on digital monies or digital cash is a significant question that policy makers should anticipate from various viewpoints - technology, legal, regulations, business and social. I may predict that there should be a public consultation or white paper on technology coupling (alike of NFC and RFID) that links towards various aforementioned viewpoints. The call for such a viewpoint should be brainstormed skeletally without further ado.
Thursday, 7 January 2010
Germany leads the world's first RFID ID card (by 2010)
I am so interested with the potential acceptance by stakeholders once the RFID ID card would have been issued. "The Local" Germany News In English reports.
My three (3) chief predictions:-
i) Invidious acceptance: It maybe partly harmful and maybe partly okayed by certain segments. However, awareness and notification on how RFID works should be diffused. It's the primary role of the Data Protection Commissioner to do so;
ii) Controlled surveillance: potential cases on terrorism will be inhibited and minimised in that sense. Border control shall be beefed up and percentage of illegal immigrant cases maybe plummeted;
iii) Periodic updates: Maybe, it's best for the Data Protection Commissioner through their higher level representation to be able to voluntarily update the status of post implementation to the Article 29 Working Party and the RFID consultative group. This may provide useful guidance and case study on the effectiveness of implementation and how well Germany manages their stakeholders' perception.
My three (3) chief predictions:-
i) Invidious acceptance: It maybe partly harmful and maybe partly okayed by certain segments. However, awareness and notification on how RFID works should be diffused. It's the primary role of the Data Protection Commissioner to do so;
ii) Controlled surveillance: potential cases on terrorism will be inhibited and minimised in that sense. Border control shall be beefed up and percentage of illegal immigrant cases maybe plummeted;
iii) Periodic updates: Maybe, it's best for the Data Protection Commissioner through their higher level representation to be able to voluntarily update the status of post implementation to the Article 29 Working Party and the RFID consultative group. This may provide useful guidance and case study on the effectiveness of implementation and how well Germany manages their stakeholders' perception.
Wednesday, 6 January 2010
The EU Data Protection Review - What's Next?
I have read, religiously, and between the lines on "The Review of EU Data Protection Law" - both the technical report and the summary report.
There are flows of anticipating questions emerged, as I was reading it. Nevertheless, I think, it's best to put the crux of the concerns at a later stage in my proposed written paper (or hopefully, a publication, by end of 2010). My impression after reading these reports are partly mixed. The positive and ambitious part was the timeframe taken by the commissioned Consultants in addressing the interviewees' responses, which I think, may lead to certain ideas - on who's who to approach in my research. The uncertain part is the effectiveness of post-report or review pursuant to the recommendations that have been put forward. Most, or largely, are all practicable and insightful constructive. I duly hope the national EU Member States have adopted, at least, some of it or at least, the minimum implementation.
Congratulations to the Consultants for the thorough works, in depth analysis, research, study and recommendations.
Note: In a related development, the work on The Future Of Privacy was released on December 2009. Special thanks to Hunton & Williams for the dissemination via their blog.
There are flows of anticipating questions emerged, as I was reading it. Nevertheless, I think, it's best to put the crux of the concerns at a later stage in my proposed written paper (or hopefully, a publication, by end of 2010). My impression after reading these reports are partly mixed. The positive and ambitious part was the timeframe taken by the commissioned Consultants in addressing the interviewees' responses, which I think, may lead to certain ideas - on who's who to approach in my research. The uncertain part is the effectiveness of post-report or review pursuant to the recommendations that have been put forward. Most, or largely, are all practicable and insightful constructive. I duly hope the national EU Member States have adopted, at least, some of it or at least, the minimum implementation.
Congratulations to the Consultants for the thorough works, in depth analysis, research, study and recommendations.
Note: In a related development, the work on The Future Of Privacy was released on December 2009. Special thanks to Hunton & Williams for the dissemination via their blog.
Tuesday, 5 January 2010
RFID for London Olympics 2012?
Suddenly, Olympics came into mind. Beijing 2008 was a huge success, in many ways. It also includes the deployed RFID infrastructure during the Olympics. Main reasons were largely on security and surveillance. I personally think London 2012 may emulate the Beijing's success if painstaking caution is put in place. Despite the mixed views on its potential deployment and privacy concerns, I anticipate, there shall be some reactions by the Information Commissioner's Office to respond.
My predictions for London Olympics 2012 surrounding RFID, data protection and privacy are:-
i) Tapping the RFID investment: The ruling Government shall invest considerably large on security and surveillance. RFID and other biometrics technology will take place gradually;
ii) Road show on RFID: The Information Commissioner's Office shall play active roles for public notification and awareness. If possible, guidance on related RFID devices that will be deployed for London Olympics should be well-informed.
iii) Post Olympics 2012 report on RFID deployment: By having this report, it will instill stakeholders' confidence that this technology has advantages for the British public and the world.
My predictions for London Olympics 2012 surrounding RFID, data protection and privacy are:-
i) Tapping the RFID investment: The ruling Government shall invest considerably large on security and surveillance. RFID and other biometrics technology will take place gradually;
ii) Road show on RFID: The Information Commissioner's Office shall play active roles for public notification and awareness. If possible, guidance on related RFID devices that will be deployed for London Olympics should be well-informed.
iii) Post Olympics 2012 report on RFID deployment: By having this report, it will instill stakeholders' confidence that this technology has advantages for the British public and the world.
Monday, 4 January 2010
Accepted Abstracts in Quarter 1 of 2010
Happy New Year and welcome to the new decade of 2010!
For the past one month, I have been busy with writing, reading and researching. The results of which, are tremendously engaging. New facts. New discoveries. And new arguments. For the first (1st) quarter of 2010, I will be presenting two (2) papers:-
Conference 1: Malaysia Glasgow Doctoral Colloquium
Paper 1:-
Paper:-
For the past one month, I have been busy with writing, reading and researching. The results of which, are tremendously engaging. New facts. New discoveries. And new arguments. For the first (1st) quarter of 2010, I will be presenting two (2) papers:-
Conference 1: Malaysia Glasgow Doctoral Colloquium
Paper 1:-
Malaysia’s Data Protection Bill; Some Useful Headway From The United Kingdom (UK) And European Union (EU)
Noriswadi Ismail
MPhil/PhD Candidate
The Institute of Computer and Communications Law
The Centre for Commercial Law Studies
School of Law, Queen Mary, University of London
Abstract
In the nearest future, the Data Protection Act will take place in Malaysia’s legal regime. It is anticipated that there shall be potential compliance costs to be accommodated by the stakeholders. This paper anticipates substantive concerns that Malaysia should learn from the UK and EU. Selected case studies shall be appraised.
Summary
On 8 October 2009, there are series of online and hardcopy of highlights that surrounded data protection concerns, issues and the need for enforcements in Malaysia. Some authors, experts and critiques have rightfully opined that it is about time for Malaysia to be vigorous on this subject matter. Whilst the feedbacks are very much a triangulation, this paper shall anticipate further what and how Malaysia should endlessly learn from the UK and EU on these similar concerns. From the country’s perspective, Malaysia is not far behind from her other Association of South East Asian Nation (ASEAN)’s counterparts in giving the birth of a data protection legislation. Whilst some ASEAN’s member states legal regime are sector-specific based, self-regulatory via other existing legislations and prevalent soft-law approaches, Malaysia has to anticipate series of fundamental issues once the Data Protection Bill is in force.
Appropriately, data protection and privacy involves its actors and stakeholders. Their participation in daily activities, commerce, trade and communications are engaging – be it virtual, physical and in our real lives. Extensive virtual navigation via Web 2.0 sphere has triggered concerns to our lives today and leads to such chilling effects to all countries. Malaysia is not an exception to this effect. Potential strategies must be pre-empted for Malaysia once the Bill will be a gazetted legislation. This paper shall cursorily analyse selected cases and progressive experiences from the UK and EU within different periods of era (from 1990s to 2000 and to date), being the decade of data protection’s maturity in the UK and EU. These cases and experiences are indispensable for Malaysia’s roadmap. The author has personally opted for not paraphrasing the draft Bill or any of the UK and EU Directives. Instead, pragmatic analysis, rationales and reasons will be enlightened to support such assertions and views to support as to why Malaysia should learn from these jurisdictions and regimes.
Arguably, there are three main terms of reference that are substantiated towards this paper. First, as Malaysia is very new to this peace of legislation, a thorough overview should be inferred to disseminating potential data protection issues to the stakeholders. This is to gauge a clear apprehension on its inter-relationship with various actors and stakeholders. In this paper, the actors and stakeholders are referred to any individuals and the roles may interchangeably apply. Second, as Malaysia’s government has its own preferred approaches to focusing and retaining it’s governmental data via other existing legislation, the author shall appraise the broad analysis of the UK Freedom of Information Act 2000, that, in a way, relates and cross refers to certain intersection of data protection concerns. Third, as Malaysia has targeted 6% of annual Gross Domestic Product (GDP) by 2020, it is undeniably paramount that the growth contribution factors are derived from domestic and international trades and investments. Due to the latter, the exchanges of data, data retention, security and trans border data flows will be aggressive or maybe uncontrollable. – if due care and diligent of data protection is not adopted seriously Thus, it needs special painstaking attention by the actors and stakeholders in dealing with different data protection approaches, principles and enforcements with and amongst Malaysia’s trading partner. All of these references shall be discussed via the UK and EU’s actors and stakeholders’ experiences.
Conclusion
This paper shall be concluded via proposing a data protection strategy roadmap to Malaysian actors and stakeholders. It is hoped that the future Data Protection Commissioner or the equivalent Privacy Commissioner will be able to consider the rationales of such an adoption for Malaysia in a localised context and setting. In the second part of the conclusion, the author shall suggest proposed regional and international collaboration, networks and diffusion that relates to data protection at the regional and international foray.
Keywords: Data Protection. Privacy. Malaysia. United Kingdom. European Union.
References
Books
Chris Reed (ed), Reed and Angel: Computer Law (5th rev OUP, Oxford 2003) 417-453.
Ian J. Lloyd, Information Technology Law (OUP, Oxford 2008) 3-180.
Ian Walden, Computer Crimes and Digital Investigations (OUP, Oxford 2007).
Rosemary Jay and Angus Hamilton, Data Protection Law and Practice, (Sweet & Maxwell, 1999).
Ruth Boardman and Richard Morgan, Data Protection Strategy, (Sweet & Maxwell, 1st Edition, 2003).
Websites
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data accessed 9 November 2009.
Review of EU Data Protection Directive: Summary < http://www.ico.gov.uk/upload/documents/library/data_protection/detailed_specialist_guides/review_of_eu_dp_directive_summary.pdf> accessed 9 November 2009.
Paper:-
Mobile Radio Frequency Identification Technology (Mobile-RFID);
where is privacy?
___________________________________________________________________
By Noriswadi Ismail
MPhil/PhD Candidate
The Institute of Computer and Communications Law
The Centre for Commercial Law Studies
School of Law, Queen Mary, University of London
Abstract
i2010 is aimed towards the European Information Society for growth and employment. There shall also be priorities for new strategy for European information society (2010-2015). These ambitious aims are part and parcel of the digitalizing Europe vision for the next 5 years. One of the significant growths in this sphere is Mobile Commerce (M-Commerce) and Radio Frequency Identification Technology (RFID). Mobile Commerce or technically termed as M-Commerce has been deployed widely by mobile operators in their present business models. In the United Kingdom (UK) and Europe, stakeholders and consumers have had a mixed bag of responses on its effectiveness, quality of service, functionalities and liabilities. As M-Commerce evolves, Radio Frequency Identification Technology (RFID) has been put into trials within the M-Commerce environment. The main motivation is purely on convenience to the stakeholders and consumers – as the top priority list. Nevertheless, there are two main concerns surrounding this trials and deployment. First, it may spark the issue of data surveillance in a greater context. And second, it may question the issue of privacy in a broader context. This paper shall narrate potential challenges that shall be faced by mobile operators based on these concerns. Careful substantiated reasons are also outlined. At a generic level, this paper shall also touch documented trials on Mobile-RFID in selected East Asian Countries as cross border and comparative analysis. At a specific level, it shall appraise the Mobile-RFID trials and developments and proposing potential considerations within the ambit of data protection and privacy concerns in Mobile-RFID that are prevalent to the existing consultative member states of the European Union.
Wednesday, 9 December 2009
RFID & Standardisation
In my research, one of the boundaries that I am looking into is on standardisation of RFID in its frequencies and tags across these jurisdictions: South Korea, Japan, Europe and Asia Pacific. Special cross reference will be made to the United States' contours. Prior to zooming into these countries/continents, Australia has had made a commendable progress last January 2009 on its RFID standardisation. The question that I am pondering (at this juncture), is how and why, to what extent, these standards co-exist with data protection and privacy? It would be particularly engaging if I could look and deal with case-by-case scenarios of RFID applications that are being deployed in various industries as against the background of standards. Maybe IBM or MOTOROLA RFID-based solutions shall provide some general technical guidance.
Tuesday, 24 November 2009
The awaiting birth?
After 10 years, Malaysians are awaiting the birth of the Malaysia Personal Data Protection Bill, being an Act, soon. Now, it's in the second and third reading at Parliament. I predict it will be gazetted by end of this year, or perhaps, by the first quarter of 2010. Back in 2002, Professor Dr. Ida Madieha wrote a very interesting article on the Bill, by paraphrasing some of the relevant sections vis-a'-vis issues on e-commerce and privacy.
I fervently hope that the analysis and comments have been taken into consideration by the legislator and consultant. Once the Bill is ready to kick-off, there will be potential compliance costs. It is anticipated that organisations and companies are required to get ready with the potential transformation: internal compliance road shows, compliance costs, strategies and awareness for and to all Malaysian stakeholders on data protection. Particularly, the ICT and banking sectors. It's just the beginning for Malaysians.
Cursorily, a brief overview of other Asia Pacific countries on data protection and privacy is readable here (published by DLA Piper, as at March 2009).
Wondering how the Bill responds to RFID? (in Malaysia).
Tag Broker Model to protect privacy?
This paper is quite technical to comprehend. Nevertheless, it sounds interesting as to how such a model has been proposed to protect privacy within an RFID enabled setting. Briefly, this article discusses on such a tag broker model approach for an enabled Mobile RFID which is compatible with Near Field Communication (NFC). I am wondering whether is there any literature that touches on data protection and privacy issues in relation to NFC? Reason being: NFC, is an industry standard that results to the technical compatibility and operability, deriving from RFID. Or, maybe, it's a subset of RFID as well? Pondering.
Thursday, 12 November 2009
RFID in youtube
This video is by the Metro group. Easy to be understood by a layman like me. This second video, is also interesting, with additional perspectives by privacy advocates in the US. I personally like this third video - practical and eye opening. This, on another hand, explains about microchip implantation. Medical technology has made this verichip useful as practised by this Harvard Doctor. Essentially, this looks like RFID has started to rule the world. Interestingly, this guy has guided viewer how to remove RFID chip from an Oyster card. That is cool. In the UK, this video looks informative. Themed as Big Brother Is Watching (it has 3 sequels). In a broader context, this video canvasses Britain's surveillance state, in general. Worth to watch.
Monday, 9 November 2009
RFID deployment was put on halt; the Philippine's case study
RFID, has been said as illegal and expensive. This is what the views that could be adduced from the people. Wondering whether the republic has considered data protection and privacy terms prior to implementation or anticipating the same in the future.
Mobile-RFID; a new hype?
This is an interesting move by RFID solutions architect; Mobile-RFID is now a hype.
Subscribe to:
Posts (Atom)
