Book Review: Jonathan Clough, Principles Of Cybercrime, 2nd Ed (Cambridge: Cambridge University Press, 2015),
2016
Schulich School of Law, Dalhousie University
Book Review: Jonathan Clough, Principles Of Cybercrime, 2nd Ed (Cambridge: Cambridge University Press, 2015), Christopher D. Ram
Canadian Journal of Law and Technology
The past decade has seen an enormous explosion of scholarship on the subject of cybercrime, as technologies and offenders pose new challenges and law enforcement, government and academic experts struggle to keep up. The new, second edition of Professor Jonathan Clough’s book occupies a fairly substantial, but specific niche in this increasingly diverse and complex landscape. Principles of Cybercrime contains only a cursory review of the history and criminology of cybercrime, it does not deal at all with IT security, investigative or enforcement matters, and discussion of cybercrime as a global issue is limited to brief discussions of the 2001 …
Minding The Gap: Why Or How Nova Scotia Should Enact A New Cyber-Safety Act - Case Comment On Crouch V. Snell,
2016
Stewart McKelvey
Minding The Gap: Why Or How Nova Scotia Should Enact A New Cyber-Safety Act - Case Comment On Crouch V. Snell, Jennifer Taylor
Canadian Journal of Law and Technology
Nova Scotia’s Cyber-safety Act was meant to fill a gap in the law. Where criminal charges and civil claims like defamation were unavailable or undesirable, the Act, it was hoped, would contain a substantive definition of cyberbullying, set out when it was actionable, and provide procedures for victims to obtain remedies. But the statute that was ultimately passed was too blunt a tool to address the problem, from both a substantive and a procedural perspective.
That helps explain why Justice McDougall of the Supreme Court of Nova Scotia struck down the entire statute as unconstitutional, in the recent case of …
Protecting The Privacy Of Canadians' Health Information In The Cloud,
2016
Schulich School of Law, Dalhousie University
Protecting The Privacy Of Canadians' Health Information In The Cloud, Adrian Thorogood, Howard Simkevitz, Mark Phillips, Edward S. Dove, Yann Joly
Canadian Journal of Law and Technology
This article presents results from a year-long research project reviewing health privacy issues in the cloud, funded by the Contributions Program of the Office of the Privacy Commissioner of Canada (OPC). Section I provides a brief primer on cloud computing and its applications in data-centric health research and health care. Section II reviews Canadian privacy and health privacy laws and how they apply to CSPs. Section III identifies privacy risks arising from the technological, organizational, and jurisdictional complexity of cloud computing. Section IV argues that Canadian health privacy laws fail to address difficulties custodians face in balancing responsibilities with CSPs, …
Data-Driven Elections And Political Parties In Canada: Privacy Implications, Privacy Policies And Privacy Obligations,
2016
University of Victoria, Department of Political Science
Data-Driven Elections And Political Parties In Canada: Privacy Implications, Privacy Policies And Privacy Obligations, Colin J. Bennett
Canadian Journal of Law and Technology
In light of the revelations concerning Cambridge Analytica, we are now in an era of heightened publicity and concern about the role of voter analytics in elections. Parties in Canada need to enhance their privacy management practices and commit to complying with national privacy principles in all their operations. As shown in this article’s comparative analysis of the privacy policies of federal and provincial political parties in Canada, policies are often difficult to find, unclear, and, with a couple of exceptions, do not address all the privacy principles. Accountability and complaints mechanisms are often not clearly publicized, and many are …
Fighting Spam. How Stringent Is The Canadian Legal Arsenal. An Analysis In The Light Of The U.S. Can-Spam Act,
2016
Faculty of Business Administration, Université Laval
Fighting Spam. How Stringent Is The Canadian Legal Arsenal. An Analysis In The Light Of The U.S. Can-Spam Act, Serge Kablan
Canadian Journal of Law and Technology
Following several countries, Canada recently passed Canada’s Anti-Spam Legislation (CASL), in an attempt to tackle spam. The law aims to ‘‘protect Canadians while ensuring that businesses can continue to compete in the global marketplace”. For this purpose, CASL prohibits not only the sending of commercial electronic messages without consent, but also any alteration of transmission data in the course of a commercial activity. Moreover, the Act disallows the installation of a computer program on another person’s computer system and the sending of commercial electronic messages following the installation. These three activities are prohibited unless the author or initiator has obtained …
Cyber Force: The International Legal Implications Of The Communication Security Establishment's Expanded Mandate Under Bill C-59,
2016
SJD Candidate, University of Toronto
Cyber Force: The International Legal Implications Of The Communication Security Establishment's Expanded Mandate Under Bill C-59, Leah West
Canadian Journal of Law and Technology
Canada is about to join the ranks of Russia, China, Iran, and North Korea; countries with a declared policy and authorized program of state-sponsored cyber attacks. In the summer of 2017, the Liberal Government introduced Bill C-59 An Act 2 Respecting National Security Matters. The bill, if passed, represents the most significant overhaul to Canadian national security institutions since the establishment of the Canadian Security Intelligence Service (CSIS) as a separate organization from the Royal Canadian Mounted Police (RCMP) in 1984. One component of this sweeping reform is the introduction of The Communications Security Establishment Act (CSE Act or the …
Modern-Day Monitorships,
2016
Notre Dame Law School
Modern-Day Monitorships, Veronica Root
Journal Articles
When a sexual abuse scandal rocked Penn State, when Apple engaged in anticompetitive behavior, and when servicers like Bank of America improperly foreclosed upon hundreds of thousands of homeowners, each organization entered into a Modern-Day Monitorship. Modern-Day Monitorships are utilized in an array of contexts to assist in widely varying remediation efforts. They provide outsiders a unique source of information about the efficacy of the tarnished organization’s efforts to remediate misconduct. Yet despite their use in high-profile and serious matters of organizational wrongdoing, they are not an outgrowth of careful study and deliberate planning. Instead, Modern-Day Monitorships have been employed …
Big Data And The Future For Privacy,
2016
Washington University in St. Louis School of Law
Big Data And The Future For Privacy, Neil M. Richards, Jonathan H. King
Scholarship@WashULaw
In our inevitable big data future, critics and skeptics argue that privacy will have no place. We disagree. When properly understood, privacy rules will be an essential and valuable part of our digital future, especially if we wish to retain the human values on which our political, social, and economic institutions have been built. In this paper, we make three simple points. First, we need to think differently about "privacy." Privacy is not merely about keeping secrets, but about the rules we use to regulate information, which is and always has been in intermediate states between totally secret and known …
The Atlantic Divide On Privacy And Speech,
2016
Washington University in St. Louis School of Law
The Atlantic Divide On Privacy And Speech, Neil M. Richards, Kirsty Hughes
Scholarship@WashULaw
When does a right to privacy become a right of censorship? Conversely when does freedom of speech become a carte blanche to violate the dignity and autonomy of others? Discussions of privacy throughout the world frequently boil down to these questions. Despite the parallel relationships between privacy and speech in the United Kingdom and America, and despite their shared legal heritage, the two legal systems have struck the balance in radically different ways. In the United States, decisions balancing privacy and the First Amendment have invariably favoured the free speech interest, at least where a press defendant published lawfully-obtained “newsworthy” …
Taking Trust Seriously In Privacy Law,
2016
Washington University in St. Louis School of Law
Taking Trust Seriously In Privacy Law, Neil M. Richards, Woodrow Hartzog
Scholarship@WashULaw
Trust is beautiful. The willingness to accept vulnerability to the actions of others is the essential ingredient for friendship, commerce, transportation, and virtually every other activity that involves other people. It allows us to build things, and it allows us to grow. Trust is everywhere, but particularly at the core of the information relationships that have come to characterize our modern, digital lives. Relationships between people and their ISPs, social networks, and hired professionals are typically understood in terms of privacy. But the way we have talked about privacy has a pessimism problem – privacy is conceptualized in negative terms, …
People Analytics And The Regulation Of Information Under The Fair Credit Reporting Act,
2016
Washington University in St. Louis School of Law
People Analytics And The Regulation Of Information Under The Fair Credit Reporting Act, Pauline Kim, Erika Hanson
Scholarship@WashULaw
People analytics — the use of big data and computer algorithms to make personnel decisions — has been drawing increasing public and scholarly scrutiny. Concerns have been raised that the data collection intrudes on individual privacy, and that algorithms can produce unfair or discriminatory results. This symposium contribution considers whether the Fair Credit Reporting Act’s regulation of consumer information used for employment purposes can respond these concerns. The FCRA establishes certain procedural requirements, and these can sometimes help individual workers challenge inaccurate information about them. However, the statute does little to curb intrusive data collection practices or to address the …
The New Retail Experience And Its Unaddressed Privacy Concerns: How Rfid And Mobile Location Analytics Are Collecting Customer Information,
2016
Case Western Reserve University School of Law
The New Retail Experience And Its Unaddressed Privacy Concerns: How Rfid And Mobile Location Analytics Are Collecting Customer Information, Ava Farshidi
Journal of Law, Technology, & the Internet
"Part I of this paper will look at the newest development of the retail experience and suggest a method to understand the privacy concerns as well as suggest a regulatory scheme to protect customers without inhibiting their shopping experience. Part II will provide a background of the three stages of shopping experiences and the evolution of privacy concerns associated with them. Part III will address the current American stance on data collection and privacy law with a particular look at privacy concerns that the eStore is facing. Finally, Part IV will provide guidance on how to deal with these data …
The Need For An International Convention On Data Privacy: Taking A Cue From The Cisg,
2016
Brooklyn Law School
The Need For An International Convention On Data Privacy: Taking A Cue From The Cisg, Morgan Corley
Brooklyn Journal of International Law
In light of the invalidation of the U.S.-EU Safe Harbor, along with the increase in sales of personal data as a commodity, data privacy has become a major concern amongst different nations. The lack of harmonization of data-privacy laws around the world continues to pose obstacles to the free flow of data across national borders. The free flow of data is, nonetheless, essential the international economy. As a result, nations continue to work together to try to create mechanisms by which data can be transferred across borders in a secure manner. This Note examines the current state of data-privacy law …
The Sixth Pillar Of Anti-Money Laundering Compliance: Balancing Effective Enforcement With Financial Privacy,
2016
Brooklyn Law School
The Sixth Pillar Of Anti-Money Laundering Compliance: Balancing Effective Enforcement With Financial Privacy, Maria A. De Dios
Brooklyn Journal of Corporate, Financial & Commercial Law
The U.S. government has responded to the increase of financial crimes, including money laundering and terrorist financing, by requiring that financial institutions implement anti-money laundering compliance programs within their institutions. Most recently, the Financial Crimes Enforcement Network exercised its regulatory powers, as authorized by the Treasury Department, by proposing regulations that now explicitly add customer due diligence to the preexisting anti-money laundering regime. The policy behind the government’s legislative and regulatory measures is clear—financial institutions must ensure that they are protected from and not aiding in the illegal efforts of criminals. The complexity and insidiousness of these financial crimes makes …
Standing Up For Their Data: Recognizing The True Nature Of Injuries In Data Breach Claims To Afford Plaintiffs Article Iii Standing,
2016
Brooklyn Law School
Standing Up For Their Data: Recognizing The True Nature Of Injuries In Data Breach Claims To Afford Plaintiffs Article Iii Standing, Andrew Braunstein
Journal of Law and Policy
Over the last several years, data breaches have become increasingly more common, due in no small part to the failures of organizations charged with storing and protecting personal data. Consumers whose data has fallen victim to these breaches are more often turning to federal courts in attempts to be made whole from the loss of their information, whether simple credit card information or, as breaches become more sophisticated, social security information, medical and financial records, and more. These consumers are often being turned away from the courthouse, however, due to a failure of many federal courts to find that the …
After Snowden: Regulating Technology-Aided Surveillance In The Digital Age,
2016
Georgetown University Law Center
After Snowden: Regulating Technology-Aided Surveillance In The Digital Age, David Cole
Georgetown Law Faculty Publications and Other Works
Imagine a state that compels its citizens to inform it at all times of where they are, who they are with, what they are doing, who they are talking to, how they spend their time and money, and even what they are interested in. None of us would want to live there. Human rights groups would condemn the state for denying the most basic elements of human dignity and freedom. Student groups would call for boycotts to show solidarity. We would pity the offending state's citizens for their inability to enjoy the rights and privileges we know to be essential …
When The Default Is No Penalty: Negotiating Privacy At The Ntia,
2016
University of Colorado Law School
When The Default Is No Penalty: Negotiating Privacy At The Ntia, Margot E. Kaminski
Publications
Consumer privacy protection is largely within the purview of the Federal Trade Commission. In recent years, however, the National Telecommunications and Information Administration (NTIA) at the Department of Commerce has hosted multistakeholder negotiations on consumer privacy issues. The NTIA process has addressed mobile apps, facial recognition, and most recently, drones. It is meant to serve as a venue for industry self-regulation. Drawing on the literature on co-regulation and on penalty defaults, I suggest that the NTIA process struggles to successfully extract industry expertise and participation against a dearth of federal data privacy law and enforcement. This problem is most exacerbated …
Classification Standards For Health Information: Ethical And Practical Approaches,
2016
University of Colorado Law School
Classification Standards For Health Information: Ethical And Practical Approaches, Craig Konnoth
Publications
Secondary health information research requires vast quantities of data in order to make clinical and health delivery breakthroughs. Restrictive policies that limit the use of such information threaten to stymie this research. While the Notice of Proposed Rulemaking (NPRM) for the new Common Rule permits patients to provide broad consent for the use of their information for research, that policy offers insufficient flexibility. This Article suggests a flexible consenting system that allows patients to consent to a range of privacy risks. The details of the system will be fleshed out in future work.
The Shaky Ground Of The Right To Be Delisted,
2016
Vanderbilt University Law School
The Shaky Ground Of The Right To Be Delisted, Miquel Peguera
Vanderbilt Journal of Entertainment & Technology Law
It has long been discussed whether individuals should have a "right to be forgotten" online to suppress old information that could seriously interfere with their privacy and data protection rights. In the landmark case of Google Spain v. Agencia Espafiola de Proteccion de Datos, the Court of Justice of the European Union (CJEU) addressed the particular question of whether, under EU Data Protection Law, individuals have a right to have links delisted from the list of search results in searches made on the basis of their name. It found that they do have this right--which can be best described as …
The Right To Be Forgotten: Comparing U.S. And European Approaches,
2016
Ketterman, Rowland & Westlund, P.C.
The Right To Be Forgotten: Comparing U.S. And European Approaches, Samuel W. Royston
St. Mary's Law Journal
This Article compares the European and United States stances regarding the right to be forgotten. Within that context, this Article explores the implications of technological advances on constitutional rights, specifically the intersection of the right to free speech and the right to privacy, commonly referred to as the "right to be forgotten" paradox. In the United States, the trend is to favor free speech, while Europe places an emphasis on human rights. Each approach is analyzed based on supporting case law. The consequences of each approach on society, both long- and short-term, are also discussed. This Article argues that a …
