Thanks to my colleague, Sonny Zulhuda of Multimedia University, Malaysia for a comprehensive update on this awaiting news.
The next array of anticipating issues shall be: Implementation & Enforcement. Oh. It's also compliance cost and awareness. Much to be done. But, well done Malaysia! After twelth years of waiting.
So much so, the above map's colour on Malaysia should change it's colour to blue instead of red!
Friday, 9 April 2010
Tuesday, 16 March 2010
Tuesday, 9 March 2010
RFID Privacy Law in the US
The Washington HB1011 is, arguably, and perhaps, a precedent for some. The RFID Journal reports.
In the United States, Nevada, New York, New Hampshire and Virginia are adopting the Washington effort towards a similar motivation. Comparatively, UK and EU RFID Technical guidance via the Information Commissioner's Office and the Article 29 Working Party should relook into some of the provisions in those States. Maybe, UK and EU could learn something from the US. Or, alternatively, inferring to the Canadian approach, may also lead to something insightful.
By and large, personally, I would anticipate that in few years time, a review will take place in the UK and EU on this matter. The latter may also correspond the latest ICO report on "Privacy Dividend". Alas, it's not that too late for recognising RFID as a dividend of the Internet of Things!
Image source: Google Images
Monday, 8 March 2010
New release by ICO: The Privacy Dividend Report
I am pleased to share the recent release of Information Commissioner's Office literature on: The Privacy Dividend Report. It will be interesting to note the findings. Hopefully, potential headways could be linked towards commercial interests and technologists' motivation. Three (3) observations came in mind. First, how can RFID fits in the setting of a balanced or return of dividend (if any)? Second, whether proactive privacy protection is an indirect translation of a privacy code for technology? Third, will the business case being sustainable should more sophisticated Privacy Enhancing Technologies (PETs) come into being? I will only be able to answer once analysed and substantiated it.
Image Source: ICO Website (Cover Report of The Privacy Dividend Report)
Wednesday, 24 February 2010
RFID is not bad? But, the intention matters?
I read this article between the lines.
There were several observations that popped out. First, the writer's position in RFID deployment is linked towards the political landscape of his home country. Second, maybe, the writer should be able to understand the brief taxonomy of RFID applications in-depthly. Third, the writer maybe, could also extract whether the nationals of his home country regard RFID as a threat or a bad innovation? I think, on this point, intention matters. Oh, by looking into his profile religiously, I sense that he is running for an important post in his home country. If elected, maybe brainy technology, legal abd public policy advisers should educate him on RFID and other related issues against the country's backdrop.
Image source: Google (illustration: an RFID Car Key)
Thursday, 18 February 2010
Identity Theft Test - a gateway to profiling
I am so impressed with the designed online Identity Theft Self-Assessment Test that was devised by the Norwegian Data Inspectorate. Do attempt the test HERE. Identity theft could happen everywhere, whether online and offline. It's a gateway to profiling the authencity of a person/user/pseudonym and any parties who are deemed to be an under cover person. Zooming into the lens of an RFID environment, I am unsure whether the test would provide the necessary controls in view of the Privacy Enhancing Technologies (PeTs). Maybe it is a different element altogether. Nevertheless, it is best to recommend this test to consumers and customers of all industries (via their websites), especially service-based and consumer-based businesses. Then, it would provide added value, useful diffusion and dissemination so that the message will reach them ideally well.
Thursday, 11 February 2010
RFID in McDonald's (Japan)
This YouTube video features how a customer could utilise his/her Mobile-RFID in a McDonald's restaurant. What constitutes the capability? They are:-
i) Mobile-RFID (some Japanese models have embedded RFID chip inside their mobile phones)
ii) Subscription with the Internet Service Provider (via the line subscriber) - Wifi/3G/4G/5G enabled - only in Japan; and
iii) Reader (normally, attached in front of the cashier).
And the customer will get his/her order without queuing during the peak hours!
Pondering: What are the data protection and privacy issues that could be anticipated here?
Image source: Google Images.
i) Mobile-RFID (some Japanese models have embedded RFID chip inside their mobile phones)
ii) Subscription with the Internet Service Provider (via the line subscriber) - Wifi/3G/4G/5G enabled - only in Japan; and
iii) Reader (normally, attached in front of the cashier).
And the customer will get his/her order without queuing during the peak hours!
Pondering: What are the data protection and privacy issues that could be anticipated here?
Image source: Google Images.
Wednesday, 10 February 2010
South Korea & RFID
I have been keeping in touch with the South Korea RFID progress for the past five (5) months of my research. Today, by accident, I have stumbled upon the translated version of their Articles / Provisions in relation to RFID Privacy Protection Guideline (Republic of Korea). It is interesting to note that the guideline's coverage is quite concise. If one is to dissect the Articles, I wonder whether it achieves the adequacy protection terms under the Directive 95/46/EC. In the interim, it may not reach the adequacy level of protection, arguendo, taking into account the detailed analysis of compliance checklist by the Directive.
(Image Source: Google Images) - A marketing campaign (integrating RFID capability) via credit card at a Petrol Station somewhere in Korea.
(Image Source: Google Images) - A marketing campaign (integrating RFID capability) via credit card at a Petrol Station somewhere in Korea.
Friday, 5 February 2010
Mobile-RFID Cloud Computing in East Asia
This blog aptly mentioned the Mobile Cloud Computing environment that will be tested and trialled in South Korea by 2014. In my research, I have also looked into Mobile-RFID and Near Field Communications (NFC) that is known as pairing technology. Mobile-RFID environment is quite new in certain countries. But, Japan and South Korea are already on track. Now, South Korea, or maybe, Japan too, are looking into the possibility to extend it to cloud computing. I anticipate that should such plan takes place, security and data privacy issues will be more sophisticated. On one hand, these countries are too advanced (comparably to others). On the other hand, in my humble opinion, the EU and US need to collectively agree on a certain reformation within their states' or federal's legislation and how to respond to the South Korea and Japan's progress. A trilateral data protection initiative between US-Europe-Asia maybe a good start? So much so, public policy lobbying is much needed.
In the meantime, I am sharing an image (imported from Google images) - copyright by Gartner on what's holding cloud computing back. Maybe another point that should be stressed upon in that image is on - data privacy, security and retention - or in a trendy way - Information Governance on the cloud!
In the meantime, I am sharing an image (imported from Google images) - copyright by Gartner on what's holding cloud computing back. Maybe another point that should be stressed upon in that image is on - data privacy, security and retention - or in a trendy way - Information Governance on the cloud!
Thursday, 4 February 2010
Cloud Computing and RFID - Data privacy at stake?
In the midst of refining my research, I have stumbled upon this interesting write up that generally narrates about cloud computing. Most of the issues discussed were on data privacy, security and less on liability. The regime was largely focusing on the United States. There are also several interesting discussions that have taken place. One of them, lately, is Microsoft's proposal towards potential legislative reform on cloud computing. The proposal seems to be intuitive, yet, needs added substance. Especially, how, the third (3rd) countries and other continents / regimes response towards the reform. It would be very much interesting to witness what shall be the legal impact of a service provider based in the US, which is outsourced by a company in a country (within South East Asia contour) where both countries have had not reached the adequate data protection under the EU data protection standards (EC 95/46 Directive). In corresponding to that, the company manages RFID deployment for its client / customer (which is a governmental agency). Question: How cloud computing liabilities respond? And how the data protection laws apply? And when to draw the technical compliance, information security and risks between these? It needs some brainstorming and rethink.
Maybe, as a start. Johnathan Zittrain of Harvard Law School's article on: "Lost In The Cloud" is a recommended casual reading.
Image source: Google. Copyright belongs to the owner. The illustration is for informational purpose only.
Maybe, as a start. Johnathan Zittrain of Harvard Law School's article on: "Lost In The Cloud" is a recommended casual reading.
Image source: Google. Copyright belongs to the owner. The illustration is for informational purpose only.
Thursday, 28 January 2010
MGDC 2010 - A Brief Retrospective
Last week, (20-21 January 2010), I had the privilege to present a paper on: "Malaysian Data Protection Bill; Some Useful Headways from the United Kingdom (UK) and the European Union (EU)" at the Malaysia-Glasgow Doctoral Colloquium. My 20 minutes presentation was scheduled at the Social Science Stream parallel session 4.
My presentation slides are viewable HERE.
It was the inaugural colloquium, jointly hosted by the Glasgow-based Universities; University of Strathclyde, University of Glasgow and Glasgow Caledonian University. The colloquium was sponsored by the Ministry of Higher Education, some benefactors and sponsors of the Universities. Overall, it was a well-managed one, albeit, the first time, such a Malaysian postgraduate research colloquium took place in Scotland. Congratulations to the resources and all who were involved with this colloquium directly and indirectly.
During the presentation, I have shared:-
1. The current Data Protection Bill's position in Malaysia - that will be potentially to undergo a third (3rd) reading in the Parliament.
2. The Executive Summary of my research and the link with my PhD research in RFID, data protection and privacy in the UK and EU.
3. Literature Review and Research Methodology (content analysis, data analysis and observations)
4. Research Limitation.
5. Substantial issues under the Malaysian Bill: Governance, Corporate Binding Rules, Enforcement, Application of the Bill only to commercial and private sectors - not the State and the Government, Dissemination, Diffusion and Standard of adequacy protection.
6. Cross references to issues and challenges posed by the UK and EU by responding to the potential issues under item number 5 above.
7. A way forward for Malaysia.
8. What's next in my research.
The above are related substantial pointers that I have had presented. In the interest of time, I managed to complete the presentation and called for more questions and discussions. It was exceedingly an eye opener to have had witnessed interactive members of the audience that were very much interested to share their insights and opinions on data protection and privacy. The reviewer (panel) had provided useful comments too. I was asked four (4) questions. But, I have selected two (2) leading questions (not in verbatim, but have been proof edited by myself) that captured my next stage of research, as follows:-
Question 1: Whether should there be an extension of data protection and privacy from the perspective of pyschology and the professionals in this area ? (as the questioner is an expert from one of the local universities in Malaysia).
Answer: Yes. However, the notion of data protection and privacy was not yet embedded as a culture, generally, in Malaysia. However, some professions have been abiding with the confidentiality clauses in relation to the client's confidentiality alike of lawyers and doctors. However, at times, there is a tendency for one to share the information and prying a client's privacy to someone that they trust in a relationship (like to their spouses, families or siblings). The intrusion and prying indirectly happened without knowing the condition that the more one speaks and talks about their works, the higher, his or her client's privacy is intruded. However, for the time being, it is also best to propose a code of conduct or code of ethics that may self-regulate any professions whilst awaiting the Bill's translation to be transformed into a Law, restrospectively. If there are such codes, not only to the aforementioned professionals, but to all, a harmonised application should be adopted by looking into the spirit and motivation of data protection bill.
Question 2: What do you think about the current MyKad ID, wondering whether are there any data protection and privacy issues that may potentially arise?
Answer: MyKad ID has been developed through and by different service providers and platforms. Thus, there are several and selected deployed technologies embedded. However, the issues that may arise is whether; what would be the security risks of the respective parties when it comes to issues of data protection and privacy breach. Taking an example of four (4) different companies, having deployed four (4) different platforms, in a MyKad deployment. The important notion is whether all companies are able to share the collective risks in the event there shall be security and data breach. In the absence of data protection legislation, I may argue that the technology and controls prevail (like encryption and other security technology methods and standards). However, should the Data Protection Bill be a reality, the respective parties should make a compliance checklist in accommodating the data protection and privacy priorities. So much so, in this context, the technical liabilities of data protection and privacy apply.
Besides the two (2) questions above, the Reviewer has commented on my research methodology and proposed a feasible alternative as to ensure the research should be mapped for a PhD research as opposed to a Post Doctoral research. The similar sentiment was also mooted out by a PhD colleague (also a Presenter) from Warwick Institute of Education. His insightful comments, observations and views motivated me to revisit and relook my research coherently pragmatic. A mouthful thanks for the inspiration.
There are also three (3) questions that were posed by some of the presenters in relation to the retrospective effect of the Malaysian Data Protection Bill towards the banking industries. A presenter of Durham asked me the latter. I aptly responded that banking industries should be able to anticipate the compliance costs as to make themselves compliant and relevant. Road shows, awareness and diffusion are the key towards that. Issues of governance, resource, implementation and enforcement should also be prioritised.
A different presenter of Durham asked me about Radio Frequency Identification Technology (RFID) by inferring to the United States' recent surveillance limbo. I briefly responded that when it comes to surveillance issues, there are mixed responses, especially when it comes to RFID. It used to be a military technology. Now, it is a commercialised technology. Yet, the world (one day) will witness the ambient intelligence (Ai) communications that are surrounded by objects and things communicable via RFID chips. It maybe harmful and prying one's privacy if there are no controls. It may also be useful for our daily lives' activities. It may depend on how one looks at a particular RFID technology. It goes back to purpose. He, then, passed the remark: "...we are living in an Orwellian world" - during the introductory part of his presentation, by relating to my presentation topic earlier. I might partly agree.
A presenter of Glasgow Caledonian asked: how RFID technology works, the interrelationship within an RFID environment. Within my knowledge, reading and exposure, I shared with her the generic illustration on the RFID tag categories - active and passive. It is depending upon the frequency usage of the tags, database management and notification to the stakeholders/consumers (I have cited the examples of some leading retailers in the UK that have deployed RFID). I hope my brief technological explanation to her was succintly clear.
After one (1) week of analysing my paper. I have made some improvements to my current works (research and writing). This paper, shall be submitted to the Malaysian Government and stakeholders by June 2010. For a long term strategy and plan, I will cite this paper in one of the PhD chapters (under the Data Protection and Privacy Chapter).
Thank you very much indeed for the experience, networking, discussions and opportunities. I look forward to attending my next paper presentation in BILETA 2010, to be held at the University of Vienna.
Respectfully reported.
Noriswadi Ismail
MPhil/PhD Candidate
Institute of Computer and Communications Law
Centre for Commercial Law Studies
School of Law, Queen Mary, University of London
My presentation slides are viewable HERE.
It was the inaugural colloquium, jointly hosted by the Glasgow-based Universities; University of Strathclyde, University of Glasgow and Glasgow Caledonian University. The colloquium was sponsored by the Ministry of Higher Education, some benefactors and sponsors of the Universities. Overall, it was a well-managed one, albeit, the first time, such a Malaysian postgraduate research colloquium took place in Scotland. Congratulations to the resources and all who were involved with this colloquium directly and indirectly.
During the presentation, I have shared:-
1. The current Data Protection Bill's position in Malaysia - that will be potentially to undergo a third (3rd) reading in the Parliament.
2. The Executive Summary of my research and the link with my PhD research in RFID, data protection and privacy in the UK and EU.
3. Literature Review and Research Methodology (content analysis, data analysis and observations)
4. Research Limitation.
5. Substantial issues under the Malaysian Bill: Governance, Corporate Binding Rules, Enforcement, Application of the Bill only to commercial and private sectors - not the State and the Government, Dissemination, Diffusion and Standard of adequacy protection.
6. Cross references to issues and challenges posed by the UK and EU by responding to the potential issues under item number 5 above.
7. A way forward for Malaysia.
8. What's next in my research.
The above are related substantial pointers that I have had presented. In the interest of time, I managed to complete the presentation and called for more questions and discussions. It was exceedingly an eye opener to have had witnessed interactive members of the audience that were very much interested to share their insights and opinions on data protection and privacy. The reviewer (panel) had provided useful comments too. I was asked four (4) questions. But, I have selected two (2) leading questions (not in verbatim, but have been proof edited by myself) that captured my next stage of research, as follows:-
Question 1: Whether should there be an extension of data protection and privacy from the perspective of pyschology and the professionals in this area ? (as the questioner is an expert from one of the local universities in Malaysia).
Answer: Yes. However, the notion of data protection and privacy was not yet embedded as a culture, generally, in Malaysia. However, some professions have been abiding with the confidentiality clauses in relation to the client's confidentiality alike of lawyers and doctors. However, at times, there is a tendency for one to share the information and prying a client's privacy to someone that they trust in a relationship (like to their spouses, families or siblings). The intrusion and prying indirectly happened without knowing the condition that the more one speaks and talks about their works, the higher, his or her client's privacy is intruded. However, for the time being, it is also best to propose a code of conduct or code of ethics that may self-regulate any professions whilst awaiting the Bill's translation to be transformed into a Law, restrospectively. If there are such codes, not only to the aforementioned professionals, but to all, a harmonised application should be adopted by looking into the spirit and motivation of data protection bill.
Question 2: What do you think about the current MyKad ID, wondering whether are there any data protection and privacy issues that may potentially arise?
Answer: MyKad ID has been developed through and by different service providers and platforms. Thus, there are several and selected deployed technologies embedded. However, the issues that may arise is whether; what would be the security risks of the respective parties when it comes to issues of data protection and privacy breach. Taking an example of four (4) different companies, having deployed four (4) different platforms, in a MyKad deployment. The important notion is whether all companies are able to share the collective risks in the event there shall be security and data breach. In the absence of data protection legislation, I may argue that the technology and controls prevail (like encryption and other security technology methods and standards). However, should the Data Protection Bill be a reality, the respective parties should make a compliance checklist in accommodating the data protection and privacy priorities. So much so, in this context, the technical liabilities of data protection and privacy apply.
Besides the two (2) questions above, the Reviewer has commented on my research methodology and proposed a feasible alternative as to ensure the research should be mapped for a PhD research as opposed to a Post Doctoral research. The similar sentiment was also mooted out by a PhD colleague (also a Presenter) from Warwick Institute of Education. His insightful comments, observations and views motivated me to revisit and relook my research coherently pragmatic. A mouthful thanks for the inspiration.
There are also three (3) questions that were posed by some of the presenters in relation to the retrospective effect of the Malaysian Data Protection Bill towards the banking industries. A presenter of Durham asked me the latter. I aptly responded that banking industries should be able to anticipate the compliance costs as to make themselves compliant and relevant. Road shows, awareness and diffusion are the key towards that. Issues of governance, resource, implementation and enforcement should also be prioritised.
A different presenter of Durham asked me about Radio Frequency Identification Technology (RFID) by inferring to the United States' recent surveillance limbo. I briefly responded that when it comes to surveillance issues, there are mixed responses, especially when it comes to RFID. It used to be a military technology. Now, it is a commercialised technology. Yet, the world (one day) will witness the ambient intelligence (Ai) communications that are surrounded by objects and things communicable via RFID chips. It maybe harmful and prying one's privacy if there are no controls. It may also be useful for our daily lives' activities. It may depend on how one looks at a particular RFID technology. It goes back to purpose. He, then, passed the remark: "...we are living in an Orwellian world" - during the introductory part of his presentation, by relating to my presentation topic earlier. I might partly agree.
A presenter of Glasgow Caledonian asked: how RFID technology works, the interrelationship within an RFID environment. Within my knowledge, reading and exposure, I shared with her the generic illustration on the RFID tag categories - active and passive. It is depending upon the frequency usage of the tags, database management and notification to the stakeholders/consumers (I have cited the examples of some leading retailers in the UK that have deployed RFID). I hope my brief technological explanation to her was succintly clear.
After one (1) week of analysing my paper. I have made some improvements to my current works (research and writing). This paper, shall be submitted to the Malaysian Government and stakeholders by June 2010. For a long term strategy and plan, I will cite this paper in one of the PhD chapters (under the Data Protection and Privacy Chapter).
Thank you very much indeed for the experience, networking, discussions and opportunities. I look forward to attending my next paper presentation in BILETA 2010, to be held at the University of Vienna.
Respectfully reported.
Noriswadi Ismail
MPhil/PhD Candidate
Institute of Computer and Communications Law
Centre for Commercial Law Studies
School of Law, Queen Mary, University of London
Happy Data Privacy Day!
I am taking this opportunity to greet a very Happy Data Privacy Day. 28 January every year, is the designated date for such a must-to-celebrate Data Privacy day not only in the United States, but also in some parts of the world - Canada, Australia and some European Union countries too. Stakeholders representing the corporate organisations, universities, Information Commissioners' Office, Privacy Commissioners and all have joint this celebration with its collective mission in data protection and privacy. Detailed history of its birth, the reports of 2008 and 2009 are respectively readable here. In a related development, I have just discovered a Privacy Project website that focuses their discussions, research and consultations in the area of data protection privacy as well. It will be quite fascinating to gauge the progress of these efforts, not only at the United States' level, but also, at the global level.
Security, At What Cost - A study by RAND
Thanks to Dr. Ian Brown for posting this quantitative research / study by RAND on the above. I will map it based on the lense of RFID in my research.
RFID SEC 2010 Asia
Singapore Management University will be hosting the RFID SEC 2010 on February 2010. Do peek the details.
Monday, 25 January 2010
Technology Predictions for 2010 - GPS and RFID
These predictions are interesting. We will see and await the next eleven (11) months of translation - whether it hit, or otherwise.
Cloud-based RFID; A privacy crawler?
It is always about the cost factor for companies. But, it maybe partly due to technology trend as well. In Australia, the proposition to design a cloud-based RFID was mooted. I am unsure whether the idea has been translated into a proof of concept. If it has, it maybe a privacy crawler, especially, at this point of time - where people around the world has been advocating on cloud computing's chief issues: security, data protection and privacy.
Thursday, 14 January 2010
RFID interoperability within healthcare
This American healthcare solutions' commentator views that RFID will be linking its deployment to other predicted technology growth. It's very interesting to look into the top ten (10) predictions of the healthcare IT trends:-
Electronic Medical Records (EMRs) will gain momentum
Personal Health Records (PHRs) earn legitimacy
Cost containment is a paramount
Alternative care delivery models emerge
War waged on Medicare fraud
Increased focus on outbreak preparedness
Patient safety initiatives intensify
Healthcare professionals in short supply
Storage and business continuity concerns abound
Physician groups join healthcare systems
As cliche' as it sounds, predictions may hit and it may not hit. If one is to bring RFID within one of these predictions, stakeholders should also consider the privacy impact assessment and its respective informational privacy responses.
As cliche' as it sounds, predictions may hit and it may not hit. If one is to bring RFID within one of these predictions, stakeholders should also consider the privacy impact assessment and its respective informational privacy responses.
RFID Cluster in Songdo Korea
In an ambitious move and plan, Songdo, a city in Korea will be an enabled-RFID-city. The Korea IT Times reports. In the absence of such primary English literature on RFID, I am unsure whether Korea has a strong data protection / privacy laws (if any). Or, whether the country has a guideline, code or any piecemeal legislation that is related to informational privacy. It would be very much interesting to gauge certain discovery on this matter. Having said that, I anticipate and predict that Korea needs to address informational privacy issues vis-a'-vis RFID from various spectrum and viewpoints. Wondering whether the Songdo RFID development is taking a gradual and progressive phase.
Subscribe to:
Posts (Atom)











