Showing posts with label Australian Privacy Foundation. Show all posts
Showing posts with label Australian Privacy Foundation. Show all posts

Thursday, April 12, 2007

Lawmakers seek RFID privacy protections

LEGISLATORS in California are expected to vote within two weeks on bills that seek to regulate the way RFID (radio frequency IDs) can be used in government documents.

Like Australia, the debate in California has been about how privacy protections can be built into RFID-enabled identity systems.

In Australia that debate has focused on the Federal Government’s proposed Access Card, while lawmakers in California are seeking to put protections in place to cover a range of IDs, from student ID at schools to state driver’s licences.

It has been a testy debate in the Sacramento legislature. Legislation that was approved by lawmakers last year – and similar to what is now being proposed – was torpedoed by a Governor Arnold Schwarzenegger veto last October.

This time around, the provisions seeking to regulate RFID-enabled documents have been split into five separate bills, giving more moderate measures a better chance of making it into law.

Two of the bills seek to put a three-year moratorium on the use of RFID chips in either driver’s licences or school ID cards. Others create stop-gap privacy protections for RFID-based cards already used by Government, and make it a crime for unauthorised skimming of personal data from the card.

The last bill makes it illegal for companies to try to take the extreme measure of having employees implanted with an RFID chip.

It is not yet clear what attitude Governor Schwarzenegger will take to the bills, or whether he intends vetoing any or all of them – although it is thought he wants to keep open State options for using RFID chips in government IDs.

In Australia, Federal legislators have not sought to pass laws governing all possible government RFID-enabled documents.

The enabling legislation for the $1 billion Access Card project did not adequately provide protections for citizens and has been withdrawn for a re-write by Government.

The Australian Privacy Foundation has already rejected as inadequate the industry code of practice self-regulation proposals put forward by the product ID organisation GS1.

For more RFID news, click here.

Friday, March 16, 2007

Privacy concerns over RFID plans

PRIVACY advocates have rejected a draft RFID Code of Practice for retailers issued by the barcode and product numbering association GS1, highlighting consumer concerns about the technology.

The Australian Privacy Foundation said the Code was “fundamentally flawed” because it did not protect consumers from RFID (radio frequency ID) technologies being used to track products after they pass the retail point of sale.

In a submission to GS1, the APF also expressed disappointment that GS1 had not taken the “next logical step” in registering the Code with the Office of the Federal Privacy Commissioner, which would make it binding on signatories.

The APF submission welcomed the “timely and well-structured” GS1 initiative in seeking to create a Code of Practice. The foundation said it was particularly pleased that Code had defined the term ‘deactivation’ to mean that RFID tags could not be re-activated “in whole or in part.”

But it is highly critical of the Code putting the responsibility for ensuring deactivation on the consumer rather than the retailer.

“The draft Code of Practice is fundamentally flawed in its opt-out approach to de-activation at point of sale,” the Privacy Foundation submission said. “The default option should be that RFID tags are de-activated at the point of sale, unless the consumer expressly requests that the tag remains active.”

“We are also disappointed that the industry has not taken the next logical step of seeking registration of the Code by the Privacy Commissioner so that it becomes binding on signatories.

The AFP is also critical that the Code does not include the relationship between the retailer and the manufacturer in the way RFID can be used.

“While it is comforting for a consumer to know that the retailer from which a particular item was bought will not abuse the information that can be gathered, such a feeling may be one of false security should the tag be left active, and in the event that the manufacturer of the item or other third parties will be monitoring the tag,” the submission says.

For more RFID news click here.

Monday, February 26, 2007

Legislation heats Access Card debate

CIVIL libertarians and privacy advocates have stepped up their campaign against the proposed Federal government smartcard just weeks after enabling legislation for the so-called Access Card was introduced to Federal parliament.

The Victorian Council for Civil Liberties – which opposes the proposal, calling it is a national ID card – will host a public forum on the Access Card in Melbourne on Thursday.

Chaired by high-profile silk and Liberty Victoria president Julian Burnside, the meeting will include speeches from Labor Human Services spokeswoman Tanya Plibersek and Public Interest Advocacy Centre chief executive Robin Banks.

The meeting, which includes an address by Tim Warner, convener of the Access Card No Way campaign, is expected to be the first of a series of meetings around the country seeking to galvanise opponents of the card.

The billion dollar Access Card proposal seeks to replace 17 health and welfare cards – including the ubiquitous Medicare card – with single government smartcard.

The introduction of Access Card legislation to Parliament two weeks ago detailing how the card will function has set the scene for a long anticipated brawl between supporters of the card – who say it will make Government services more efficient – and those who oppose the initiative.

Advocacy groups like the Australian Privacy Foundation and Electronic Frontiers Australia say the Access Card is effectively a national identity card, and compared the proposal to the defeated 1987 Australia Card proposal.

Human Services Minister Ian Campbell dismisses the charge, saying the legislation introduced to Parliament provides for a penalty of five years jail for anyone demanding that the Access Card be produced for strictly identification purposes.

The proposal is understood to have already caused ructions within the Coalition party room among backbenchers concerned about privacy provisions in the legislation.

Labor has said it supports in principle the introduction of card that improves government services, but is concerned that the proposal has been rushed through without adequate privacy protections.

For more e-Government news click here .