Search FCW


Subscribe Now!
Table of Contents
Sprint
Business
BPM
CXOs
Columns
Columnists
Defense
E-Government
Elections 2008
Enterprise Architecture
Funding
Homeland Security
Health IT
IPv6
LOB
Management
Procurement
Privacy
Policy
Program Management
State and Local
Security
Technology
Telework
Training and Certification
Workforce

More Topics
resourcecenter
Home
Letters to the Editor
Current Issue/Download
Print/Online Archives
Editorial Calendar
researchstore
resourcecenter
Communications for Continuity Operations

Oracle Resource Center
NEW! Transforming Data Center
Managed Services
Service Oriented Architecture
Training & Simulation
Networking Communications
Security Directives and Compliance
Data Center Virtualization
Air Force ELSG Contract Guide

More >>



Latest News
ADVERTISEMENT





 

Mind your own business

The best way to safeguard personal information? Don't collect it.

By Dibya Sarkar
Published on January 9, 2005

Comment

Click here to comment on this article


Related story links

Intro: Life outside the box

Enough with convention already

Don't talk to strangers

Pack rats, beware

It's time for feds to share their ideas

Throw away that MBA

Develop, license, repeat

Steal a page from the GM playbook

Put that home page in the circular file

You flunked the test

Thoughts on the box and life outside it


Newsletters

You might also be interested in these FCW newsletters:

Daily

To learn more, click here.


The concept of "data minimization" might be easier to understand if you think about it in terms of dieting: You still eat the food you need, but you avoid consuming extra calories you'll have to burn off later. Government, like many organizations, is a profligate eater of personal information, said John Sabo, a former fed who is now manager of security, privacy and trust initiatives at Computer Associates International. The Web's ubiquity has "created a culture where we collect everything and then park it and attempt to make use of it later," Sabo said. That would be fine if government agencies had airtight privacy policies, but that's not the case, he said. Protocols and mandates, such as the Government Paperwork Elimination Act of 1998, help agencies when they collect data from individuals. But they have no comparable guidelines for collecting personal data that has been amassed by private organizations or businesses. Worse yet, agency officials often cannot determine the accuracy of secondhand information, Sabo said. The solution? Agencies should err on the side of privacy and not collect information for which they have no pressing need, he said. Ari Schwartz, associate director of the Center for Democracy and Technology, agreed. The good news is that data minimization is an element of the privacy impact assessments that agency officials were required to begin conducting in 2002 for all new data collections. "If agencies are doing the privacy impact assessments as they're supposed to, they should be addressing those issues at least upfront," he said. "The question is: How is that being put into place later on? The law reads they have to do that every time the system's upgraded."

upcoming event

Green Computing Summit, Ronald Reagan Building, Washington, DC
December 2 - December 3, 2008

Trusted Internet Connection and the Comprehensive National Cyber Security Initiative, The Willard Intercontinental Hotel, Washington, DC
December 4, 2008


 

head
fcw
issue
First Name State
Last Name Zip
Title Email