<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Microsoft Privacy &amp; Safety : Privacy Community</title><link>http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Community/default.aspx</link><description>Tags: Privacy Community</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Peter Cullen on Privacy Accountability</title><link>http://blogs.technet.com/privacyimperative/archive/2009/11/04/peter-cullen-on-privacy-accountability.aspx</link><pubDate>Wed, 04 Nov 2009 22:23:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3291550</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3291550.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3291550</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3291550</wfw:comment><description>Peter Cullen here. The concept of “accountability” has certainly become a recent catch-cry in the wake of the global economic crisis but it has long been an established principle of privacy and data protection. In fact, the concept was first established...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/11/04/peter-cullen-on-privacy-accountability.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3291550" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Community/default.aspx">Privacy Community</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Standards/default.aspx">Privacy Standards</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Peter+Cullen/default.aspx">Peter Cullen</category></item><item><title>Data Privacy Day – Focus Group Findings</title><link>http://blogs.technet.com/privacyimperative/archive/2009/01/28/data-privacy-day-focus-group-findings.aspx</link><pubDate>Wed, 28 Jan 2009 18:39:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3193676</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>1</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/3193676.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=3193676</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=3193676</wfw:comment><description>Today the United States, the European Union and Canada are celebrating Data Privacy Day, which is dedicated to educating people about online privacy protections. To commemorate the day, Microsoft commissioned focus group research examining consumer perceptions...(&lt;a href="http://blogs.technet.com/privacyimperative/archive/2009/01/28/data-privacy-day-focus-group-findings.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3193676" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Community/default.aspx">Privacy Community</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Peter+Cullen/default.aspx">Peter Cullen</category></item><item><title>Recent Research Commissioned by Microsoft on Data Governance and Role Collaboration</title><link>http://blogs.technet.com/privacyimperative/archive/2007/11/26/recent-research-commissioned-by-microsoft-on-data-governance-and-role-collaboration.aspx</link><pubDate>Tue, 27 Nov 2007 01:38:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:2566885</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/2566885.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=2566885</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=2566885</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;IMG title="Brendon Lynch" style="WIDTH: 61px; HEIGHT: 85px" height=85 alt="Brendon Lynch" hspace=1 src="http://blogs.technet.com/photos/microsoft_privacy_team/images/2584188/original.aspx" width=61 align=left vspace=1 border=1 mce_src="http://blogs.technet.com/photos/microsoft_privacy_team/images/2584188/original.aspx"&gt;Hi, I am Brendon Lynch, Director of Privacy Strategy in Microsoft’s Trustworthy Computing group.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Among other things, my team’s work includes engagement with external privacy stakeholders and advising Microsoft product groups on data governance strategies.&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I wanted to highlight some interesting research we recently conducted which explores how different roles within organizations are collaborating to protect personal information.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;As you are probably aware, there is a lot of concern about personal information today.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Research, including the latest edition of Microsoft’s &lt;/FONT&gt;&lt;A href="http://download.microsoft.com/download/4/8/9/4890888b-dc6f-4742-88d4-0e333217789c/Microsoft%20Security%20Intelligence%20Report%20V3%20Key%20Findings%20Summary.pdf" mce_href="http://download.microsoft.com/download/4/8/9/4890888b-dc6f-4742-88d4-0e333217789c/Microsoft%20Security%20Intelligence%20Report%20V3%20Key%20Findings%20Summary.pdf"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;Security Intelligence Report&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;, shows that criminals are increasingly targeting personal information for financial gain.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Other research shows that consumers are expressing concerns about shopping and banking online.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We are also observing a seemingly endless string of reports of data breaches.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In response to these concerns, many organizations in both the public and private sectors are investing in people, process and technology to better govern the data they collect and manage.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Looking at the people dimension of data governance, three important roles within organizations that standout are information security professionals, the data collectors and users (e.g., marketers) and privacy professionals (the newest role to emerge).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We thought it would be interesting to explore how these roles are working with each other (or not!) to address data governance.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Our survey of over 3600 professionals across these three roles, and across three countries (USA, UK and Germany), was conducted by the Ponemon Institute and provided some very interesting results, including:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpFirst style="MARGIN: 0in 0in 0pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Marketers consult security and privacy professionals a lot less often than security and privacy professionals think they do&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoListParagraphCxSpLast style="MARGIN: 0in 0in 10pt 0.5in; TEXT-INDENT: -0.25in; mso-list: l0 level1 lfo1"&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Organizations that had better collaboration between the roles reported that they had significantly less data breaches than organizations with poor collaboration&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;I encourage you to take a deeper look at the &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/mscorp/twc/iappandrsa/research.mspx" mce_href="http://www.microsoft.com/mscorp/twc/iappandrsa/research.mspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;research results&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; and &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.microsoft.com/mscorp/twc/iappandrsa.mspx" mce_href="http://www.microsoft.com/mscorp/twc/iappandrsa.mspx"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;view two related keynote presentations&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; from Microsoft executives last month: Scott Charney, presenting to the International Association of Privacy Professionals (IAPP) annual Privacy Academy in San Francisco; and Ben Fathi presenting to the RSA Security Conference in London.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT face=Calibri size=3&gt;Trevor Hughes, executive director of IAPP and Peter Cullen, chief privacy strategist for Microsoft, also recorded a &lt;/FONT&gt;&lt;/SPAN&gt;&lt;A href="http://www.microsoft.com/mscorp/twc/media/iappexec.wvx" mce_href="http://www.microsoft.com/mscorp/twc/media/iappexec.wvx"&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT face=Calibri color=#0000ff size=3&gt;video&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT face=Calibri size=3&gt; discussing the data protection research and other challenges facing privacy professionals today.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;!-- AddThis Bookmark Button BEGIN --&gt;&lt;A title="Bookmark using any bookmark manager!" onclick="window.open('http://www.addthis.com/bookmark.php?wt=nw&amp;amp;pub=erikbratt&amp;amp;url='+encodeURIComponent(location.href)+'&amp;amp;title='+encodeURIComponent(document.title), 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no,screenX=200,screenY=100,left=200,top=100'); return false;" href="http://www.addthis.com/bookmark.php" target=_blank&gt;&lt;IMG height=16 alt="AddThis Social Bookmark Button" src="http://s9.addthis.com/button1-bm.gif" width=125 border=0&gt;&lt;/A&gt; &lt;!-- AddThis Bookmark Button END --&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=2566885" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy/default.aspx">Privacy</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Community/default.aspx">Privacy Community</category></item><item><title>A Privacy Call to Action </title><link>http://blogs.technet.com/privacyimperative/archive/2007/07/23/a-privacy-call-to-action.aspx</link><pubDate>Mon, 23 Jul 2007 14:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1589113</guid><dc:creator>Microsoft Privacy Team</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/privacyimperative/comments/1589113.aspx</comments><wfw:commentRss>http://blogs.technet.com/privacyimperative/commentrss.aspx?PostID=1589113</wfw:commentRss><wfw:comment>http://blogs.technet.com/privacyimperative/rsscomments.aspx?PostID=1589113</wfw:comment><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 10pt"&gt;&lt;FONT face=Calibri size=3&gt;Peter Cullen, Microsoft's Chief Privacy Strategist, here ...&lt;/P&gt;
&lt;P&gt;&lt;IMG title="Peter Cullen" style="WIDTH: 67px; HEIGHT: 85px" height=85 alt="Peter Cullen" hspace=1 src="http://blogs.technet.com/photos/microsoft_privacy_team/images/1599475/original.aspx" width=67 align=left vspace=1 border=1 mce_src="http://blogs.technet.com/photos/microsoft_privacy_team/images/1599475/original.aspx"&gt;Today, &lt;A class="" href="http://www.microsoft.com/presspass/press/2007/jul07/07-22MSAskPrivacyPR.mspx" target=_blank mce_href="http://www.microsoft.com/presspass/press/2007/jul07/07-22MSAskPrivacyPR.mspx"&gt;joined by industry colleague Ask.com&lt;/A&gt;, we are encouraging other technology leaders, consumer advocacy organizations and academics to come together in an effort to develop global privacy principles for data collection, use and protection related to search and online advertising. &lt;/P&gt;
&lt;P&gt;Additionally, expanding on our ongoing work to protect customer privacy, &lt;A class="" href="http://www.microsoft.com/presspass/press/2007/jul07/07-22EnhancedPrivacyPrinciplesPR.mspx" target=_blank mce_href="http://www.microsoft.com/presspass/press/2007/jul07/07-22EnhancedPrivacyPrinciplesPR.mspx"&gt;Microsoft also announced&lt;/A&gt; a set of &lt;A class="" href="http://download.microsoft.com/download/3/7/f/37f14671-ddee-499b-a794-077b3673f186/Microsoft’s%20Privacy%20Principles%20for%20Live%20Search%20and%20Online%20Ad%20Targeting.doc" target=_blank mce_href="http://download.microsoft.com/download/3/7/f/37f14671-ddee-499b-a794-077b3673f186/Microsoft’s Privacy Principles for Live Search and Online Ad Targeting.doc"&gt;privacy principles&lt;/A&gt; to protect the privacy of Microsoft’s Windows Live users, including making search query data anonymous after 18 months by permanently removing cookie IDs, the entire IP address and other identifiers from search terms. &lt;/P&gt;
&lt;P&gt;I wanted to take a moment to focus on two important aspects of these announcements: why we believe industry needs to establish a set of global privacy principles, and why we believe it is important to strike the right balance between privacy and security for our users when storing search queries linkable to IP addresses.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Industry dialogue will benefit consumers&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;The details of data collection and use practices in the search and online advertising space are difficult enough to understand even if you are a technologist or privacy professional.&amp;nbsp; So it’s probably an understatement to say that it is very difficult for most Internet users to know how, or if, their privacy is being protected.&amp;nbsp; Given these services are becoming ubiquitous across the Web, it is hard for a consumer to know which companies may be logging information relating to their interactions with Web sites.&amp;nbsp; Therefore, we believe it’s time for a comprehensive discussion between industry and the privacy community.&amp;nbsp; Some of the topics for discussion might include ways to provide the appropriate amount of user notice so consumers can make informed choices; appropriate approaches to providing user choice relating to the use of their data, appropriate ways to secure data to protect data from unauthorized access; and an agreed upon timeframe for anonymizing search records and the method of that anonymization.&lt;/P&gt;
&lt;P&gt;We hope others in the industry will join us in developing and supporting principles that address these important issues. People should be able to search and surf online without having to navigate a complicated patchwork of privacy policies.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Security relies on enough data to detect seasonal changes&lt;BR&gt;&lt;/STRONG&gt;&lt;BR&gt;In determining the appropriate time period before anonymiszing search queries data, we carefully examined the uses of the data that are necessary to operate our Windows Live Search service, and have concluded that 18 months of data strikes the right balance and allows us to ensure that we are providing users with relevant search results, to protect the financial integrity of our business model including being able to detect and defend against click fraud, and to help protect the security and integrity of the Windows Live Search service.&amp;nbsp; For example, in order to detect and protect against security threats such as botnet attacks, click fraud, worms, and other future threats, it is necessary to create a baseline of normal traffic patterns against which to conduct the analysis.&amp;nbsp; Because search patterns vary seasonally, it is necessary to look back to the same time the prior year, and several months before and after, in order to create that baseline.&amp;nbsp; An even longer period would help to provide a more reliable baseline, but we believe that 18 months strikes an appropriate balance.&lt;BR&gt;&amp;nbsp;&lt;BR&gt;We look forward to engaging in a dialogue between industry and the privacy community on these matters with the goal of enabling consumers to continue to realize the benefits of technology at the same time as being confident that their privacy and security are appropriately protected.&amp;nbsp; We plan to provide an update on progress in September.&lt;BR&gt;&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=1589113" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Community/default.aspx">Privacy Community</category><category domain="http://blogs.technet.com/privacyimperative/archive/tags/Privacy+Standards/default.aspx">Privacy Standards</category></item></channel></rss>