Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Jan 2, 2011

Doing Gov 2.0 Backwards in High Heels

2 comments
Ginger Rogers dancing with Fred Astaire backwards and in high heelsI was reading the awesomely comprehensive 2010 roundup of Gov 2.0 by Alex Howard and stumbled into a little Twitter dust-up between Alex and one of his readers, Microsoft's public sector evangelist, Mark Drapeau.

The twit-for-tat was around Mark's criticism that Gov 2.0 activities were focused on "govies, policies, and techies, and little citizens, services, engagement." He's right. There continues to be a lot of foundation-level work going on--like writing policies, creating governance, training, upgrading systems, cleaning up and making available data, etc. It makes it hard to see how this is having an impact on citizens and the public.

Then, Alex referenced Gov 2.0 impact on citizens
As the new year beckons, there are more ways for the citizens of the United States to provide feedback to their federal government than perhaps there ever have been in its history. In 2011, the open question is whether "We the people" will use these new participatory platforms to help government work better. The evolution of these kinds of platforms aren't U.S.-centric, either. Ushahidi, for example, started in Africa and has been deployed worldwide. The crowd matters more now in every sense: crowdfunding, crowdsourcing, crowdmapping, collective intelligence, group translation, and human sensor networks--O'Reilly Radar
Alex is finding some Gov 2.0 activity that is actually touching people. A good start, but how does this play for my sister in Indiana?

But, as Mark went on,
twitter image from Drapeau, Well @digiphile, government exists to serve all its citizens. Thusfar Government 2.0 mainly exists to serve wonks and geeks.
he and I part ways.

The heady newness of the Open Government Directive and the first forays into social media are over. We look back wistfully, like on the faded blush of a new romance. That was fun! But now we are left to work in the trenches to realize the promise. Much less sexy, but critical to success.

This year has included some very important new guidance--for example on surveys (Paperwork Reduction Act), privacy (including cookies and participating in 3rd party networks), plain language and prize authority to name a few--that agencies are trying to apply. And there is increasing scrutiny, oversight, and evaluation from both within and outside of agencies.

It seems that nothing breeds slowdowns like success. The layer of people who like things "the way they are" are not excited about new ways of interaction. And some are pulling the many levers at their disposal to doubly ensure that all T's are crossed and I's dotted.

Then, there are many early evangelists who are practicing what they were preaching. Being change agents in their agencies mean that they are less available to take to the pulpits of conferences and blog posts to proselytize across agencies.

I am neither a wonk nor a geek. I am a citizen, though. I am a citizen who works in government. And I am a citizen who works in a government built on--and sustained by--a massive command and control bureaucracy from a pre-Internet and social networking era. I am a citizen who works in this slow-moving behemoth and trying to make change for my fellow citizens, not to serve wonks and geeks.

Folks working in the trenches welcome the thoughtful criticism of outsiders. We don't have all the answers and have plenty of blind spots. Keep our feet to the fire, help us make change, and keep caring! But, I gotta tell you, from an insider's perspective, this is harder than it looks.

Jan 24, 2010

Three Privacy Tales

3 comments
Black t-shirt that reads, privacy is not a crimeA very smart, millennial new media colleague was talking online privacy over a beer. He said that he didn't really have an expectation of privacy and that he trusted Google to do right.

Last month, Google CEO Eric Schmidt ruffled more than a few privacy feathers.
In a recent interview [CEO Schmidt] suggested that people pushing for privacy are the one's at fault: "If you have something that you don't want anyone to know, maybe you shouldn't be doing it in the first place."

This sounds suspiciously like a reheated version of "if you've done nothing wrong, you've got nothing to worry about," that's trotted out by law enforcement types when pushing for stronger laws to violate individuals' privacy. It's an odd statement for someone like Schmidt to make, especially given the incredible level of scrutiny given to Google for the view it has into people's lives. To folks who are worried about such things, it sounds positively dismissive, which isn't the position that Google should be cultivating with those who are concerned right now." --
More on TechDirt
This month, another tech giant, Facebook founder Mark Zuckerberg, resurrected the controversy when he said that people don't expect privacy anymore.
Facebook founder Mark Zuckerberg told a live audience this weekend that the world has changed, that it's become more public and less private, and that the controversial new default and permanent settings reflect how the site would work if he were to create it today. Not everyone agrees with his move and its justification.

Has society become less private or is it Facebook that's pushing people in that direction? Is privacy online just an illusion anyway?--Read more on ReadWriteWeb
Facebook, with it's 350 million members has modified it's views on privacy as well as its policies. From a closed network in which only people that you have approved can see your profile, photos and other information to a fairly open network in which the default is "open to all" including search engine results.

My third privacy tale is from another direction--and continent. Europe has had pretty strong online privacy protections. In November, the European Union passed a law requiring Internet users' consent before cookies can be placed on their machines.
The amended directive will now state that national governments must "ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his/her consent, having been provided with clear and comprehensive information."

Cookies without user consent would only be allowed when they are "strictly necessary" to provide a service "explicitly requested" by the user such as storing shopping cart information on e-commerce sites, for example.--Read more at ClickZ
So, as big U.S. tech/new media moguls posit that privacy is becoming less important, to the Europeans, at least, it's critical to protect.

In the U.S., dot-gov has stronger privacy requirements than the private sector. There are some who think, though, that the EU controls will force a change in the commercial sector--especially to put more control in the hands of the consumer to be included in tracking and data gathering.

In the meantime, federal agencies will continue to face barriers in using commercial tools that use cookies to track users as these privacy tales play out.

Nov 1, 2009

Yellow Brick Roadmap: Five Examples of Getting Gov 2.0 Done

2 comments
The Ruby Slippers and Dorothy from Wizard of OzSince my post talking about the frustration in talking about making government more transparent, participatory, and collaborative, I had an epiphany. We are all Dorothy Gale.

Dorothy, from the Wizard of Oz, wore magical ruby slippers that empowered her to do what she most wanted--return home to Kansas. BUT she couldn't unleash their power until she believed that she could. Crazy, no?

How did our heroine get to believing? Via real life experiences. So, for Halloween I will be a Good Witch and provide guidance in the form of examples of real agencies solving the problems in becoming the government that we want to be. Call it the Yellow Brick Roadmap.

So, what are the barriers and what are solutions that agencies have found?

Privacy: The Department of Justice (DOJ) unveiled a new website and a set of social media tools at the end of September. They addressed privacy issues in 3rd party web tools--like Facebook, YouTube and Twitter--head on with a comprehensive Privacy Impact Assessment. DOJ writes that
[T]hese third-party websites are not a part of the Department’s internal information systems nor will they be operated by a contractor of the Department, the Department does not and will not collect information from individuals when individuals interact with the Department’s social web accounts. While it may appear that information posted by third parties on the Department’s accounts is the Department’s information, such third-party postings are technically and factually under the dominion of the third-party social websites.
DOJ's construct may be a good model for other agencies. Read the PDF of Justice's Privacy Impact Assessment.

Employee Use of Social Media: The Government Services Administration (GSA) is a Federal agency that provides services and support to other government agencies. They published a social media employee use policy in July. This policy addresses agency expectations,
As the technology evolves, this order and its accompanying handbook will evolve, but in general terms, this order defines guiding principles for use of these technologies by GSA employees. The use of social media technology follows the same standards of professional practice and conduct associated with everything else we do. Common sense and sound judgment help avoid the most vexing issues.
Read the PDF of the GSA Policy for Employee Use of Social Media.

Legal barriers in standard 3rd-party terms of service agreements: This was the original show-stopper for many agencies trying to use social networks. The federal government could not agree to some clauses in standard agreements with social media service providers.

Since this problem was identified a year ago, government-wide agreements have been negotiated with You Tube, Flickr, Facebook, MySpace, and more with additional agreements in the works. This has been a collaborative effort with many agencies contributing time and lawyers including EPA, Commerce, GSA, Library of Congress and the White House.

While each agency will decide when and how to implement social media and social networking tools based on their priorities and strategies, a basic legal hurdle for all government has been cleared. See more on the process for using standard terms of service agreements on Webcontent.gov.

Strategy and process: Frankly, another barrier has been, how do you get started? A terrific model for people to learn from is provided by The Smithsonian, the world's largest museum complex and research organization.
This Smithsonian Web and New Media Strategy was created through a fast and transparent process that directly involved, and continues to involve, hundreds of stakeholders inside and outside the Institution. This strategy will feed into the Smithsonian’s comprehensive strategic plan, currently under development.
I'll quick stipulate that the Smithsonian is not a typical government agency, yet their approach can be modified to fit the culture and needs of any agency. First, tie new media to the agency strategy. Second, appoint a leader with decision-making authority. Third, create a tactical road map. Fourth, create a funded unit that will implement the strategy.

Before people [you!] start to moan about how hard this is, nobody said it would be easy. The Smithsonian, however, is showing a way. See all the details at the Smithsonian Web and New Media Strategy Wiki.

Transparency & Open Government. While the long-awaited Open Government Directive is not yet published, the President's January 21st call for a more transparent, participatory and collaborative government has already made an impact.

The Department of Health and Human Services and Department of Homeland Security have undertaken dialogues with stakeholders to strengthen not only services but also strategy. The Open Government Directive development process itself has included public brainstorming and a wiki to help develop the policy. Each of these projects and tools are part of the learning process to make open government robust and meaningful. It's already happening.

This Yellow Brick Roadmap to real accomplishments is meant to help people [you!] believe that we are making progress opening up government. And, to show concrete examples that can be leveraged by people [you!] trying to make progress in your own agencies.

The path to success is recognizing that we [you!] are already on the path, that you have the tools/ruby slippers and it's up to you to make it happen. Got it?

Have more examples with enough resources for folks to replicate? Add to the comments below. Then, pick up your basket and your little dog, too, and follow the Yellow Brick Road!

Aug 18, 2009

Research on Privacy Perceptions

0 comments
The White House is reviewing the federal government's cookie policy. Abridged version, it's been a 9-year rejection of the use of what many see as a benign tool and others see as government invading citizen privacy.

Part of this discussion has included what privacy means to people using online tools in 2009. Some think that people don't care about privacy, some that folks have no (or should have no) expectations of privacy, and others think that people care very much about their online privacy.

Fortunately, to help us learn more about just what privacy means, Patricia Abril and Avner Levin published a paper in the Vanderbilt Journal of Entertainment & Technology Law on privacy perceptions in online social networks. The team surveyed 2,500 young adults between the ages of 18 and 24 about the personal information they post online, what they do to protect their information, and any concerns regarding their personal information.

They reported that sharing information on social networks, and allowing other to share information about you, creates vulnerabilities, and that people know that they are potentially vulnerable.
  • 72% have adjusted privacy settings to restrict some groups of people from accessing their profiles.
  • More than 60% believe that they have taken sufficient steps to protect themselves.
  • 42% said they have read social networking sites' privacy policies.
  • Only 22% were not concerned that information about them (photos, videos, comments by others about them) could be created and posted by others.
  • 67% said that they were were most concerned about potential harm to their image or reputation.
  • 54.3% agreed with the statement, “Work life is completely separate from personal life, and what you do in one should not affect the other.”
  • 82% said that it would be inappropriate for employers to require them to "friend" a manager.
This young cohort appears to be both careful and realistic about their privacy. They are most worried about privacy lapses that could affect their reputations. And they want to keep some sort of firewall between their social selves and their work selves.

Based on their research, Abril and Levin created a concept of "network privacy."
We call this notion network privacy. According to network privacy, information is considered by online socializers to be private as long as it is not disclosed outside of the network to which they initially disclosed it, if it originates with them, or as long as it does not affect their established online personae, if it originates with others. [online social network]s, as businesses profiting from socializing online, are best positioned to offer online socializers, often the young and vulnerable, effective protection in accordance with their notion of network privacy above and beyond regular measures of personal information control, and they should be required to do so.--Read "Two Notions of Privacy Online."
Moving forward toward a meaningful, twenty-first century privacy policy, we will need to recognize the conflict between the desire and need to share information within networks and the difficulty in regulating networks with loose barriers.

Translating this to the cookies' debate, it seems that people may be less concerned with the mechanics of being "tracked" except when any "tracking" would reflect poorly on them.

Jul 17, 2009

What Is the Most Important Thing?

4 comments
My desk phone rang at 7:00 p.m. "Go Home!" said the caller.

Of course, he was glad to have caught me, and we had a quick confab about social media. And the arrows all pointed at the disruptive communications technologies that are social media.

The early days of ignorance and bliss are gone. The days when government staffers innocently clicked the button that said, "I agree," and opened up the Pandora's box of Facebook, YouTube, AddThis, Feedburner, MySpace, and Twitter.

Those few days when the Internet was free and open--a new, more transparent, collaborative and participatory way--for government to communicate and interact with her citizens. The days before the inevitable crush of rules and regulations, of some CFR thingie and the threat of potential hearings, made us grow up and take notice of what we had unleashed.

So today's discussion with my friend was about one of the regulatory tigers [link to pdf]. It doesn't matter which one because they are all important. Could be security. Could be privacy. Could be protecting the record of how a decision is made. Could be ethics. Could be cramming the Internet pipes of an agency with who knows what. Could be the sovereignty of the United States of America, for goodness' sake!

They are all important. And so is embracing the uncertainty and risk of this new more transparent, collaborative and participatory way for government to communicate and interact with her citizens.

Amazing photo of traffic circle by Nikolas R. Schiller, Los Angeles, Calif April 2008
We are now standing in the middle of an incredibly busy intersection of dozens of important interests. Working through the interests, it sometimes seems that these important interests don't know or recognize that they are all part of the same ecosystem. An ecosystem that is not yet in any balance. And, as each of the interests advocate vociferously for their needs, the shape of the discussion distorts.

My friend @bashley said, "We'll know #gov20 has come of age once it's cross-examined as if a defendant before a magistrate, awaiting sentence."

We are trying to build the perfect traffic circle. A circle in which all the interests enter into the traffic flow--the flow of this new more transparent, collaborative and participatory way for government to communicate and interact with her citizens--without colliding, without impeding the stream and without giving too much favor to any one interest.

Jun 14, 2009

The Revolution, et.al., Will Be Twittered

0 comments
Crisis Camp retweet Tweet globally, act locallyAndrew Sullivan blogging on Iranians using Twitter and social media as telephones and television communications were being shut down:
Mock not. As the regime shut down other forms of communication, Twitter survived. With some remarkable results. Those rooftop chants that were becoming deafening in Tehran? A few hours ago, this concept of resistance was spread by a twitter message.

That a new information technology could be improvised for this purpose so swiftly is a sign of the times. It reveals in Iran what the Obama campaign revealed in the United States. You cannot stop people any longer. You cannot control them any longer. They can bypass your established media; they can broadcast to one another; they can organize as never before.--Read the entire post at The Atlantic. 
While it's too early to say what will happen, it's clear that people are using whatever conduits they find to communicate, especially during a crisis.

At the same time the situation in Iran was unfolding, Crisis Camp was happening in Washington, D.C.

Directory of sessions for Crisis Camp, Flood, Earthquake, Pandemic, Twister, Dirty Bomb, Last Supper-ArmageddonCrisisCamp DC started with one idea, "How can technology help people around the world during times and places of crisis?" Over the weekend about a hundred people got together to talk about how technology is or can be used for humanitarian relief. Industry, NGOs, responders, academics, public health, geek, non-geek and a few government joined to usher in a movement. 

Where else can you find sessions like Flood, Earthquake, Pandemic, Twister, Dirty Bomb, Last Supper-Armageddon, or the use of zombies as an example to help people think in new ways?

Government limits were also in the mix. Government can be slow, not willing to trust citizens as adults, hobbled by privacy and potential corruption, and too top-down when crisis is definitely felt and fought from the ground up (see Camp tweets for fuller flavor). A big theme was emphasis on listening rather then telling, adapting rather than knowing, and sharing. 

There has been discussion about authoritative sources for crisis information, and government is at the beginnings of understanding our role. We know what we know, but unofficial sources--real people--know what they are experiencing. Bringing these views and experiences together, with the help of smart smart people and technology, will define success and failure in future crisis. And, as everyone at Crisis Camp was well aware, on the ground this is real--survival and pace of recovery.

See notes from some sessions here, and as your interest is piqued,  join like-minded innovators at the Ning network for Crisis Camp. The hope is for the movement to go viral, with camps around the world working and sharing to best use technology in times of crisis.

May 23, 2009

5 Social Media Memes Changing Government

4 comments
Red Boy Scout patch with number 5Federal Computer Week, reporting on a government leadership summit [sorry, too lazy to find out more about another one of these meetings prolly sponsored by some publisher or something] talks about five social media elements that will change the way the government works.  

My [very] loose roundup of the new memes are

1.  Where, once, government was leading on technology requirements, it is now one among many (competing) consumer interests. 
What I think this means: I've been at plenty of meetings where folks say "we're the government, we are huge, they want our business, they will change to meet our needs." But if a company's entire business model is advertisement, and government doesn't drive enough traffic, where is their incentive to destroy their income stream? If government wants to use the tools, we need to figure out how we can adapt.

2. Public engagement reveals the law of unintended consequences. 
What this means: Forays into social tools need to be flexible, and program managers need to keep an eye on results. None of us knows what will happen when we try something out--servers may crash, agencies may be overwhelmed with comments, the only response will be the chirps of crickets, or you might be stuck naming your international space station after a satirical opinionator. Good news for NASA on this last one--they saw an opportunity rather than a disaster.

3. Stop the analysis paralysis and make data available. 
What this means: Here is a big cultural change, from the government churning data into tables and reports that is delivered tied up in a bow to a dynamic process of developers unleashing the data to tell all kinds of stories. See #2. Also, expect a clamoring to open up more data sources.

4. It's the content, stupid!
What this means: Government can embarrass itself jumping into social streams without having anything to say. It's a conversation. It's a message. It's not just having a Facebook page or Twtitter account. It's not the technology, but the way that it's used.  So, if you say, "What's a hashtag?" you have no business putting your government agency on Twitter. Leading to #5.

5. This is the new way of the world. 
What this means: Despite old-fashioned concerns about employees goofing around (what's the difference between that sudoku book and YouTube, as far as productivity goes?) and real, to-be-addressed concerns about privacy and security, people are working, learning, collaborating and living differently. It's happening. And, even as some of the tools fall to the wayside and new ones developed, expectations of citizens and employees are out of the bottle. They can't be put back in.

Welcome to the changing government.

Read the FCW article I jumped off from, here. 

Apr 4, 2009

Shorts: Tools not Gov20 Ready, Catch-22 and URL Shorteners

0 comments
Khaki women's walking shorts.Twitter, Facebook not ready for Government 2.0? Bill Schrier, CIO for the City of Seattle and a creative adopter of technology, writes, "Amazingly enough, social networking tools may not be of much use to local government, unless there are significant improvements or new applications. How do social media companies and local governments need to change to really bring social networking "to the people"? " Schrier calls out issues with identity and relationships to government, challenges with volume and true one-one communications with officials, and the digital divide as issues that need to be thought through and addressed. Read his post.

Government 2.0 Meets Catch 22. NY Times blogger Saul Hansell writes, “Do I need to P.I.A. Facebook?” said the perplexed bureaucrat squished into a narrow basement hotel conference room in Washington DC. P.I.A. stands for Privacy Impact Assessment, a procedure that federal agencies must go through every time they create a new computer system. It was one of many questions about how the government can use the tools of Web 2.0 raised in a session of a privacy conference last week. Organizations of all sorts have been trying to figure out how they can adapt social networks, blogs, wiki’s and other Web tools to their traditional operating methods in order to connect to customers and partners." Really, who woulda thunk that a PIA would be mentioned in a NYT blog? Also, for the record the Dept of Homeland Security doesn't have a Facebook page per some misinformed "official" quoted in the blog. Read the entire post.

Analysis: Which URL Shortening Service Should You Use? Search Engine Land has a great primer and comparison for URL shorteners. "URL shortening services are experiencing a renaissance in the age of Twitter. When every character counts, these services reduce long URLs to tiny forms. But which is the best to use, when so many are offered and new ones seem to appear each day? Below, issues to consider and a breakdown of popular services, including recommendations and services to avoid (the new DiggBar being one of these)." Very practical read.

Mar 22, 2009

Open Data: Compare and Contrast

0 comments
Lock labeled Privacy. (Image Rpongsaj/Flickr)Soon after I posted on the very open and collaborative project at the U.S. Geological Survey, Wired had a post on the other side of the coin, Officials Hoard Valuable Databases Funded by Taxpayers
Government agencies across the country are sitting on gigabytes of valuable digital data that could be mashed, mixed and re-organized in crafty ways by Web 2.0 entrepreneurs and public interest groups engaged in everything from government oversight, to providing practical information to Americans.

Yet, despite federal and state public records laws designed to make the data accessible, many agencies are fighting more ferociously than ever to keep data created with public funds out of public hands. In their battles to withhold information, bureaucrats are citing everything from copyright and trade secret privileges to privacy and national security concerns. -Read more on Wired.
It's the clash of the titans. In one example from Wired, a nonprofit requested anonymous information about patient diagnoses, along with the physicians' identifying number, the procedures performed and amounts billed to Medicare to help match patients to experienced doctors for specific procedures and to determine if practitioners were over-billing Medicare or receiving government funds for high-risk procedures they didn't have the experience to perform. The nonprofit wanted to make this information available to consumers via their website. But the U.S. Department of Health and Human Services--parent of Medicare--denied the request on grounds that it violated doctor privacy by disclosing physician incomes.

And therein lies the rub for more than a few datasets: individual privacy and personally identifiable information (PII). Information that had been gathered painstakingly using paper and data cards and maps stored in City Hall are now much easier to put together and much easier to access. And data gathered for one purpose might be very useful for another, unrelated purpose. One that the data owner did not necessarily agree to. 

Government under the Privacy Act has an obligation to protect citizens' privacy. The Privacy Act states in part:
No agency shall disclose any record which is contained in a system of records by any means of communication to any person, or to another agency, except pursuant to a written request by, or with the prior written consent of, the individual to whom the record pertains... (See the Department of Justice for the Privacy Act of 1974).
We are experiencing a huge shift in data accessibility. 

Example of Big Shift #1: When we were buying our house in the early 1990's, I had to go downtown during "business hours" to research the amount of money that the current owners paid. [They were claiming that they were going to lose money on the transaction, and the data showed otherwise!] Now, anyone can go to WashingtonPost.com and see the price we paid. 

Example of Big Change #2: A few years ago, we used to call people to get directions to their houses. (Make a right at the second light there's a 7-11, then you'll drive by the house with the gnomes...) Now you give me a number and street, I can easily get specific directions--and even a picture--of your nearby Starbucks or your house. From my GPS enabled cellphone.

So what?, you say. Well, the Supreme Court, privacy advocates, and just plain people who don't want everyone to know how much money they make are concerned about making private information--or information that they consider private--easily available and combinable online. The barriers of time, location, and, even, expertise have fallen away. It changes the entire game.

In many, many cases, the PII can be scrubbed from the data set. But in some subset of cases, when data sets are combined, PII is exposed.  

This is the true clash of the titans--transparency versus privacy. The public versus the personal. Increasingly, it is government between these two giants, trying to balance and move forward (okay, and to be honest, sometimes playing one against the other to meet other, less pure objectives).

We live in interesting times. There are real problems to solve. We got some work cut out for us.