We normally focus on technology and its impact on business. That is our background and those are areas we feel comfortable writing about. In the next two newsletters we are stepping out of our comfort zone to write about something that gets us darn nervous – the interaction of the US government with our right to privacy and what this means for IT organizations.
We normally focus on technology and its impact on business. That is our background and those are areas we feel comfortable writing about. In the next two newsletters we are stepping out of our comfort zone to write about something that gets us darn nervous – the interaction of the U.S. government with our right to privacy and what this means for IT organizations.
U.S. gov’t panel calls for new privacy rules
One of the reasons this topic is on our minds is the research we are currently performing into the use that IT organizations are making of public cloud computing services such as Salesforce.com or Amazon’s Elastic Compute Cloud (EC2). What we have heard loud and clear from hundreds of IT professionals is that their biggest concern about using public cloud computing services is the security and privacy of their data. Initially we were tempted to recommend to our clients that if they intend to use a cloud computing service provider, that they need to include in their agreement with that provider a provision that their data not leave the United States. After further research, we are not sure we will make that specific recommendation.
So why are we concerned about the U.S. government and data privacy? One reason is that in 2006 the U.S. Justice Department subpoenaed four major Internet companies for data on what people search for on the Web. At least three of the four companies complied with the subpoena. The Justice Department’s stated goal was to crack down on child pornography – a goal we both strongly endorse. However, that particular subpoena raises some significant concerns about the U.S. government’s ability to track what ordinary people view on the Internet.
Another reason we are concerned is what is referred to as the third party doctrine. In an interesting article in the UCLA Journal of Law and Technology, Matthew Lawless explains that the third party doctrine provides that information “knowingly exposed” to a third party is not subject to Fourth Amendment protection because one “assumes the risk” that the third party will disclose that information to the government.
The Lawless article describes numerous ways that the third party doctrine has been applied to date. In our next newsletter we will describe a couple of them and talk about what we think this means to IT organizations – particularly IT organizations that are using public cloud computing services. In the mean time, we would like to hear from you. What are you biggest data privacy concerns?




