Feeds

Canucks crack whip on Facebook privacy

Death becomes your profile

High performance access to file storage

Facebook has vowed to overhaul how personal information is shared with third-party applications after Canada's privacy Czar scolded the social website for its promiscuous policies.

The site has also agreed to retrofit its privacy terms to better explain why Facebook collects personal data, make the distinction between deactivating versus deleting an account more clear, and provide consent to have profiles "memorialized" after death.

The changes - which are to be rolled out over the next year - were spurred by an investigation from the office of Canada's Privacy Commissioner found that Facebook's data handling was in violation of Canadian law.</p

"This is extremely important. People will be able to enjoy the benefits of social networking without giving up control of their personal information. We're very pleased Facebook has been responsive to our recommendations," Privacy Commissioner Jennifer Stoddart said in an statement.

Stoddart said last July that she gave Facebook a 30-days ultimatum to respond to the Office's privacy concerns, and she's now satisfied with Facebook's proposed fixes.

Scrabble is watching you

The Canadian privacy squad's biggest beef with Facebook was privacy risks involved with the site's inadequate safeguards to restrict third-party Facebook app developers from accessing users' personal information.

"Application developers have virtually unrestricted access to Facebook users' personal information. The changes Facebook plans to introduce will allow users to control the types of personal information that applications can access," Stoddart said.

Under a new permissions model, a user can control which categories of personal information an application can access. Devs must also provide a link detailing how the information will be used.

Facebook said the new model requires "significant technological changes" and will need an entire year to get the new process running.

The company warned app developers that the changes will likely require modifications to their code base and promised to give ample warning ahead of time.

"A significant part of our roll out plan will involve educating users about why they should allow applications access to their information and their friends'" Facebook Platform chief Ethan Beard said in the developer blog. "We plan on providing users with examples of ways applications utilize their data to create great social experiences. This should result in better informed users who are more eager to engage with applications on Facebook."

Deactivation rectification

Canada's second demand was to make it clear to users they have a choice between deleting and deactivating their account. The distinction will be explained on the redone privacy policy and users will receive a notice about the delete option during the deactivation process.

"We determined the company's approach — providing clarity about the options, offering a clear choice, and alleviating the confusion — is acceptable because it will allow users to make informed decisions about how their personal information was handled," the Commissioner's office stated

Facebook said data for deactivated accounts is retained indefinitely, but data on deleted accounts is removed within two weeks.

Difference between mostly dead and all dead

Another point was to begin informing users what happens to their account in the event of their death. ("Look upon my 'Which Family Guy character are you' quiz results, ye Mighty, and despair.")

"People should have a better way to provide meaningful consent to have their account 'memorialized' after their death. As such, Facebook should be clear in its privacy policy that it will keep a user's profile online after death so that friends can post comments and pay tribute," the office said.

Facebook also agreed to add information in its terms of use on how data of non-users are handled. The website confirmed to the office that it does not use email addresses to track the success of its invitation feature, nor does it maintain a separate address list for that purpose.

"With the conclusion of the Facebook investigation, our Office has made clear our expectations for how social networking sites need to protect personal information," stated Assistant Commissioner Elizabeth Denham. "Other sites should take note — and take steps to ensure they're complying with Canadian law." ®

High performance access to file storage

More from The Register

next story
Audio fans, prepare yourself for the Second Coming ... of Blu-ray
High Fidelity Pure Audio – is this what your ears have been waiting for?
Dropbox defends fantastically badly timed Condoleezza Rice appointment
'Nothing is going to change with Dr. Rice's appointment,' file sharer promises
MtGox chief Karpelès refuses to come to US for g-men's grilling
Bitcoin baron says he needs another lawyer for FinCEN chat
Did a date calculation bug just cost hard-up Co-op Bank £110m?
And just when Brit banking org needs £400m to stay afloat
Zucker punched: Google gobbles Facebook-wooed Titan Aerospace
Up, up and away in my beautiful balloon flying broadband-bot
Apple DOMINATES the Valley, rakes in more profit than Google, HP, Intel, Cisco COMBINED
Cook & Co. also pay more taxes than those four worthies PLUS eBay and Oracle
It may be ILLEGAL to run Heartbleed health checks – IT lawyer
Do the right thing, earn up to 10 years in clink
France bans managers from contacting workers outside business hours
«Email? Mais non ... il est plus tard que six heures du soir!»
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.