<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/css" href="/css/rss.css" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
         xmlns="http://purl.org/rss/1.0/"
         xmlns:dc="http://purl.org/dc/elements/1.1/"
         xmlns:georss="http://www.georss.org/georss"><docs>This is a RSS file. Copy the URL into your aggregator of choice. If you don't know what this means and want to learn more, please see: <span>http://platial.typepad.com/news/2006/04/really_simple_t.html</span> for more info.</docs>
<channel rdf:about="http://platial.comhttp://platial.com/map/Privacy-of-Personal-Information/3970">
<link>http://platial.comhttp://platial.com/map/Privacy-of-Personal-Information/3970</link>
<title>Privacy Of Personal Information</title>
<description>I work as an academic researcher on privacy in on-line environments. Facing legislation on privacy and data protection all day, some oddities I run into just have to be documented.

This is what this map / blog is about.

Privacy oddities.</description>
<items>
<rdf:Seq>
<rdf:li resource="http://platial.com/post/61525"/>
<rdf:li resource="http://platial.com/post/61527"/>
<rdf:li resource="http://platial.com/post/68681"/>
<rdf:li resource="http://platial.com/post/61530"/>
<rdf:li resource="http://platial.com/post/2569708"/>
<rdf:li resource="http://platial.com/post/2939916"/>
<rdf:li resource="http://platial.com/post/2556132"/>
<rdf:li resource="http://platial.com/post/2567901"/>
<rdf:li resource="http://platial.com/post/2935213"/>
<rdf:li resource="http://platial.com/post/2556320"/>
<rdf:li resource="http://platial.com/post/2556322"/>
<rdf:li resource="http://platial.com/post/2935697"/>
</rdf:Seq>
</items>
</channel>
<item rdf:about="http://platial.com/post/61525">
<link>http://platial.com/post/61525</link>
<title>ESAG City-Center Toilet Surveillance Camera</title>
<description>
        <![CDATA[
        This modern building right next to Dresden's central railway station is a combination of office space, shoping mall and conference center. 
Surprisingly, the facility security concept includes video surveillance of the men's toilets.
Asked about how long the videos are being stored, how they are handeled and who has access to them, the securtiy staff refused to answer. The phone number for the chief security officer I received never worked. 
Anyway, enjoy the photos, guys!

Spotted: October 2005<br /><br /><a href="http://platial.com/post/61525">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2006-04-13 00:42:30.837874+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/61527">
<link>http://platial.com/post/61527</link>
<title>Private Banking in Austria - Where Money doesn't talk</title>
<description>
        <![CDATA[
        Austria has constitutional support for banking secrecy. Additionally, Austria has local laws about not charging taxes for interest earned on accounts belinging to foreign persons.
The result can be found in a ´valley called "Kleinwalsertal", in particular in the village of Riezlern: Most of Austria's banks offer privacy-enhanced  financial products to tourists from Germany. The fun part is their advertising. Enjoy!

Spotted on various occasions in 2005.<br /><br /><a href="http://platial.com/post/61527">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2006-04-13 00:58:05.241358+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/68681">
<link>http://platial.com/post/68681</link>
<title>Computerized telephone direct marketing: Burda Direct</title>
<description>
        <![CDATA[
        Germany's Budra Verlag is a big corporation. Parts of it deal with direct marketing. Other parts provide technology for Burda. Two of them cooperate in the exploitation of modern technology for privacy-invasive direct marketing: Budra Direct (a marketing services company) and Burda Ciscom (the technology provider).
Together, they offer a platform for computerized direct marketing calls. They rent out computer time and call capacity on the platform to other companies that wish to call people. Phone numbers and call consent is to be managed by the renting customers of Burda direct. This way, Burda Direct avoids being sued for supporting illegal cold calls, which are banned in Germany.
However, which phone numbers are being provided by the customers renting the service is none of Burda's business. This resulted to a series of calls and messages to my private line, stuffing my answering machine with calls of the "Hit 1 to have instant lottery wins with our system" kind.  I hit "1" and asked for the origin of my phone number. They hung up on me. Uh oh.

I started to investigate.

Going through the order call center, I found Burda Ciscom as the service provider. Inquiries remained unanswered. Calling in, a person on the phone explained to me that the lottery sales company moved away. The town hall secretary told me the company should still be there.

So I went for a visit. I found Burda Direct, and on their board of doorbells, there was a buzzer for the lottery team. Okay.

Next, I sent a formal letter to the privacy officer, asking for the documented consent, and ordering my blacklisting on their core machine. I got it, including a 3-page-letter explaining why direct marketing has positive effects on society in general.

Also, I posted Burda Ciscom's president's tennis club, golf club, public speech at the Baden-Baden marketing club and personal profile to a newsgroup about tele-marketing lottery fraud, where many users were wondering how to cancel the lottery subscriptions their grandparents had made on the phone with Burda Direct's customers. See http://www.aerger-forum.de/dcforum/DCForumID1/482.html#36

The latest news is that there will be another branch of Burda Direct in Russia to develop SMS based mobile marketing.

<br /><br /><a href="http://platial.com/post/68681">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2006-04-25 07:25:17.63054+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/61530">
<link>http://platial.com/post/61530</link>
<title>Sophie Calle: Cash Machine Mug Shots from CCTV</title>
<description>
        <![CDATA[
        In Berlin's Gropiusbau, I went to see an exhibition by performance artist Sophie Calle. It was quite interesting to find a large room full of facial photos of people who are using a cash / ATM machine while being unaware of the ATM security cameras taking their photo. Obviously, the artist got access to the CCTV system... so was it really "closed"?
Anyway, this is what the great exhibit is about:
Sophie Calle developed the Cash
Machine series in 1991 from
photographs stored in a
Minneapolis police station -from
shots taken every 20 seconds by a
security camera above a cash
point connected to the station.
Sophie Calle has extracted a
collection of eloquent sequences
that sensitively relate human
emotions and behaviour, from
hope to fear, disappointment, loss,
violence and joy.

Spotted Nov. 2004<br /><br /><a href="http://platial.com/post/61530">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2006-04-13 01:19:34.317728+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2569708">
<link>http://platial.com/post/2569708</link>
<title>Web Browser Betrayal!</title>
<description>
        <![CDATA[
        Leader.ru provides a web page that analyzes your Web Browsing, and tells you what it can find out about you, and your network setup. The results can be surprising - as well as shocking.  All this information about your OS, preferred language, versions... available to all web servers, secret services, detectives.... and the police?

Better start using anonymizing tools... see Oslo/Norway  on this map for details!<br /><br /><a href="http://platial.com/post/2569708">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-01-15 07:25:39.904249+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2939916">
<link>http://platial.com/post/2939916</link>
<title>Cheap salary, cheap privacy - LIDL cheap on employees</title>
<description>
        <![CDATA[
        A bit off the information privacy agenda, but interesting nontheless. LIDL, the Germany-based discounter chain, uses illegal employee profiling practices. According to Spiegel Online (http://www.spiegel.de/wirtschaft/0,1518,543431,00.html, 26-Mar-2008), LIDL staff uses in-store surveillance cameras to spy on employees. Dossiers that got into the hand of the press contained minutes of breakroom converations, notes about private planes of employees for their evenings, and many details about their work day, even taking down the frequency and duration of bathroom visits. 
The article is headed "STASI-METHODEN BEIM DISCOUNTER:
Lidl ließ Mitarbeiter systematisch bespitzeln".

Germany's data protection officer,  Peter Schaar, commented that such practice clearly is illegal and should be investigated. <br /><br /><a href="http://platial.com/post/2939916">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-03-26 02:51:52.987929+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2556132">
<link>http://platial.com/post/2556132</link>
<title>Credit Card  on the Air - Taxi Radio -  Cambridge, UK</title>
<description>
        <![CDATA[
        Did you imagine that a taxi service would radio your credit card number live on the taxi radio for clearing? 
Including your name and expiration date? No? Well... this taxi driver even radioed the CVC code used for internet verification.
The radio has a range of at least 10 miles... when no relais is involved. Cambridge is full of technology students... what a radio programming to listen to! 
Ready-to-shop credit card data! 

Naturally I was rater displeased by the incident. So was Eurocard when I reported it. 

Here we go.



To: Panther Taxis / www.panthertaxis.co.uk / (01223)715714

Cc: Eurocard Norge Customer Service

Concerning: Mishandling of Eurocard credit card of Mr. ******** **********, ending number **********


Dear Sir or Madam,

I have been a customer of your company on 16-Dec-2007. I ordered a taxi for a transfer from Cabridge to Stansted, which took place on that day from approx. 14:45 to 15:30.

I have two unsatisfactory points to express about the handling of my credit card. First of all, a 5% add-on fee for credit card use was charged, but not put on the receipt written by the driver of the taxi with licence plate KNO3XMA. Thus I have paied approx. £44, but received a
receipt of £41.00. I like to express that I will go ahead and ask Eurocard to cancel the transaction if my card should show more than the £41.00 amount which I have received a receipt for.

Secondly, for credit card clearing, your driver used the taxi radio to broadcast my credit card number AND my personal CVC (card verification code) to the dispatcher. The CVC is a personal security code, not a public
asset. I requested not to broadcast the CVC - and my wife was a witness in the cab that the driver not only neglected to inform me that he was going to compromise my credit card CVC on a broadcast radio, but also that he ignored my urgent request not to broadcast the CVC to the public in
Cambridge.

I have talked to Eurocard. They have never heard of such a dilletantic practice, and offered to block and re-issue my credit card for security reasons.

To ensure the secure handling of my credit card and CVC, I hereby request a statement of the data acquisition, storage, processing, and deletion
procedure concerning my above mentioned personal data according to the British implementation of  the EU data protection directive (2002/58/EC). In detail, I request complete information on:

- the audience that can listen to the taxi radio system (is it digital? Is it encrypted? How strong is the encryption? Is this property certified?
What broadcast range has the radio system in the taxi  ith licence plate KNO3XMA?)

- how the call center receiving the broadcast is handling the card number? Where is it stored, how many people have access to the data record, and how is the access control security of the CVC record handled? How many
computer systems between dispatching call center and card clearer are involved? What is the exact way the CVC went through these systems?

- How long is the card number & CVC kept on your IT system, and how is secure deletion ensured?

Please have your data protection officer reply to these questions in satisfactory detail within two weeks (Dec. 31, 2007), otherwise I will contact the British Information Commissioner requesting an audit of your firm in this matter.

This e-mail is copied to Eurocard Norway.


---

Dear Sir,

Thank you for your email dated 17th December.  I am sorry to hear of the  problem you encountered whilst paying by Credit Card.

In respect of the questions raised regarding our handling of card transactions I am pleased that you brought to my attention the drivers use of his radio to transmit your card details. Drivers are instructed to telephone the office using their mobile telephones, or request a call back 
from the office, in order to obtain authorisation for payment by credit card. This clearly did not happen on this occasion and the driver in question has been reminded of his duties and responsibilities when dealing with card payments, as has the radio controller who should have also advised the driver to telephone the office or indeed called him back.

The handling fee of 5% is added to all credit card transactions; I have listened to the recording of the booking made for you, during which a quote was given of £41.00 GBP, it was not mentioned during the booking that payment was being made by credit card. If it had been mentioned then we would have advised of the charge and taken payment then and there over the 
telephone.

When the driver has arrived and been told that payment was to be made by credit card, he has advised you of the charge and given you the opportunity to pay by cash, offering to take you to a cash point if required.  The 
driver told you of the 5% charge which ultimately you agreed to pay,  although the driver should have included the fee on the receipt.

We are happy to forward the PDQ machine receipt to you as proof of the charge, as we do for other customers who make a request for it, but require a postal address to do so.

In respect of your request for information; The taxi radio is not encrypted, the broadcast range is approximately a 10 miles radius from the drivers vehicle.  Please note that transmission and reception are carried out on different radio channels.

The card details are entered directly into a PDQ machine supplied by our card handling merchant; the card details are not entered into a computer at any point of the transaction within our office.  There is no written record 
of the CVC held by us; once the transaction has taken place a customer and merchant receipt is printed, neither receipt has the CVC number upon it. 
These receipts are subsequently kept in a secure area where only two appointed members of senior staff have access.

I trust this email has answered your questions,and I am truly sorry that this breach has taken place.  We do take the security of confidential information very seriously and have been registered under the Data Protection Act 1988 for many years.

Unfortunately even with the tightest controls mistakes can happen which they clearly did on this occasion. As a gesture of goodwill I am happy to refund the administration charge made to your card and I will await your instructions.

Warm regards and Christmas greetings.

John Raynham
Director

Panther Taxis Ltd,
Convent Drive,
Waterbeach,
Cambridge.
CB5 9QT.

Tel (01223) 715715
Fax (01223) 715716



Unencrypted radio? A recorded phone call? I can't recall any hint at recording either... oh boy. 


End of the story: Eurocard issued a new card.
<br /><br /><a href="http://platial.com/post/2556132">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-01-09 00:43:37.130916+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2567901">
<link>http://platial.com/post/2567901</link>
<title>Pre-paid mobile phone card exchange: SIM registration privacy</title>
<description>
        <![CDATA[
        Does it bug you that you have to register your identity when you buy a pre-paid mobile phone card?

Germany's anti-data-retention initiative provides you with a pre-paid SIM card for mobile phones that is registered on another person - if you provide your own pre-paid SIM to them. Here is a web page describing the rules for the pre-paid exchange:

http://www.vorratsdatenspeicherung.de/content/view/187/77/

Note that this is all in German language yet. 

Happy SIM card trading!
<br /><br /><a href="http://platial.com/post/2567901">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-01-14 06:21:10.468403+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2935213">
<link>http://platial.com/post/2935213</link>
<title>Smile when you ride the railway</title>
<description>
        <![CDATA[
        Norwegian's railway NSB (http://www.nsb.no) will install 3200 new security cameras into their coaches - filming anyone who is using a train in Norway. This is - according to Stein Nilsen, director of NSB's person transport - mainly a "preventive measure" against violence in trains (see Aftenposten, 25.Mar.2008, http://www.aftenposten.no/nyheter/iriks/article2325143.ece). 

I couldn't find any hint to the technical security of the cameras and their videos, but it is good to know that NSB promises that "no one but the police and the train accident commission" can access the videos (NSB, http://www.nsb.no/om_nsb/aktuelt/article28308-2707.html, 27.2.2008). This is according to requirements from the Norwegian data protection office(http://www.personvernnemnda.no/vedtak/2005_13.htm, which do not present any technical security requirements, however).

So until further notice, don't put your finger up your nose on Norwegian trains if you think someone might like to have you doing that on Newspaper.

Post Scriptum: Take a look at the Flexus RFID train ticket project in Oslo. It implements the Nordic E-Ticket specification (http://www.nsb.no/flexus/). Now - as a paparazzi - you could actually  put up receivers at train stations that tell you who's boarding which train (with a RFID ticket), and then go  steal the harddisks with the videos from these trains if you need celebrity photos. Cool!<br /><br /><a href="http://platial.com/post/2935213">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-03-25 02:05:46.917278+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2556320">
<link>http://platial.com/post/2556320</link>
<title>PETweb Privacy Technology Report, Oslo</title>
<description>
        <![CDATA[
        The Norwegian Computing Center researched tools for on-line privacy protection in the PETweb project.

There, you can find a report on "State of the Art of Privacy-Enhancing Technology" for download to learn how to protect your privacy on the Net. <br /><br /><a href="http://platial.com/post/2556320">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-01-09 02:13:21.252163+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2556322">
<link>http://platial.com/post/2556322</link>
<title>Movies: Teenage Web2.0 Privacy Campaign</title>
<description>
        <![CDATA[
        Some hilarious movies and a brochure targetet at teenagers are available from http://www.dubestemmer.no/ .
They are part of a campaign targetet at school kids. Teachers and parents can talk about privacy and web2.0 behaviour. A movie competition and teacher info packs are available from the web page.

The movies are worth watching, even though the language is Norwegian. Go to the movie page!<br /><br /><a href="http://platial.com/post/2556322">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-01-09 02:20:46.613748+00:00</dc:date>
</item>
<item rdf:about="http://platial.com/post/2935697">
<link>http://platial.com/post/2935697</link>
<title>Swipe your credit card - Flytoget will keep it for 10 years!</title>
<description>
        <![CDATA[
        Oslo's hi-speed airport train shuttle is the most important train in Norway. For passenger's convenienve, you can just pull your credit card through a reader at the entrace & exit doors instead of getting a ticket from the machines (see http://www.flytoget.no/nor/Reiseinfo/Billettl%C3%B8se-reiser). If you need a bill for your files, you can log on, add your personal data to the credit card number, and access your recent travels.

So I asked for the - nonexistant - privacy policy and the data handling procedures for my movement and credit card profile that is accumulated at Flytoget's data base.

They store all transactions for 10 years, is the bottom line. Not that their advertising flyer mentions data storage at all. Oh well.

Here's the e-mail I got from Flytoget:

Dear mr. XXX,

Thank you very much for your enquiry regarding Flytogets data processing and privacy procedures.

Flytoget operates in accordance with internal policies and statutory regulations, to ensure the integrity and confidentiality of all data. 
We are currently working on a policy statement that will be published on our websites.

To answer your questions:

Flytoget does not share customer data with 3rd parties.

Time of travel is retained for up to 10 years for accounting purposes. 
This includes information about the credit card used for payment. Only receipts for travels made during the last 12 months are available on flytogetkvittering.no.
The connection between credit card number and e-mail address is retained for as long as you keep an agreement with Flytoget. When you delete your account at flytogetkvittering.no, or remove a credit card from the account, the link between card number and e-mail is deleted and the receipts on flytogetkvittering.no are deleted from your profile.

You may at any time request your travel information by logging in at flytogetkvittering.no or by contacting our Customer Support.

Regards,
Flytoget AS
<br /><br /><a href="http://platial.com/post/2935697">Map this on Platial</a><br /> 
        ]]>
        </description>
<georss:point> </georss:point>
<dc:creator></dc:creator>
<dc:date>2008-03-25 02:44:39.872321+00:00</dc:date>
</item>
</rdf:RDF>