Amazon: What does it know about us?

Szczecin, Poland-November 2018: Amazon Logistics Center in Szczecin, Poland in the light of the rising sun,panorama

By Susan Wolf

If you are like me, and currently self-isolating, then it is entirely possible that you are spending more time than usual browsing the internet, doing online shopping, buying books on your Kindle or watching movies on Amazon Prime. However, if you are looking for something educational (and food for thought) then I would recommend you take the time to watch the Panorama documentary “Amazon: What They Know About Us” screened on BBC 1 on 17th February 2020. You can draw your own conclusions, but for me the documentary made scary viewing and raised so many data protection issues that it made my head ache.

The programme charts the almost exponential growth of Amazon from 1994, when it was an online book seller, to the current position as ‘corporate superpower’.
According to Wikipedia Amazon is now the second company in history to reach a market cap of $1 trillion and Jeff Bezos, Amazon’s Chief Executive and founder, is described as the richest person on the planet. Whilst a great deal of this is already well known, the programme sheds light on Amazon’s more recent entry into other markets, and it is these current and prospective ventures that are particularly concerning from a data protection and privacy perspective.

It’s all about the data

Right from the start, Amazon fully understood the value of  personal data. Its mission to be the ‘earth’s most customer centric’ company sounds very positive. However such ‘altruistic’ ambitions disguise the company’s mission of turning our personal data into big bucks. As one commentator, a Harvard Business School Professor notes, users of Amazon are not in fact just customers, they are ‘sources of raw material’ and that raw material is the personal data that Amazon collects every time we interact with it.

So how does Amazon collect so much data?

As early as 1995 Amazon recognised that it could use the data supplied by its online  purchasers, through their browsing history and online purchases, to predict what books, music or videos they might be interested in purchasing. Later they appointed computer scientists to use algorithms to record and track all the personal data to create ‘digital DNA profiles’ of customers. By selecting one individual customer they had the capacity to predict ‘everything about that person’ based on what that customer clicked and didn’t click (their click streams histories).

As Amazon expanded into Amazon Market Place it invited other sellers onto the platform, in order to become the “everything store”. Amazon used a standard agreement with third party sellers that enabled them to sell their products on the Amazon platform, but effectively gave Amazon the rights over the sellers’ customer data.
These agreements allowed Amazon to operate as both a retailer and a marketplace and to use customer data from third party sellers to secure a competitive advantage against them. In July 2019, the EU Competition Commission opened up an investigation into the possible anti-competitive behaviour of Amazon, which could result in a possible fine of up to 10% of its annual global turnover under EU competition rules.

Of course, anybody using the Amazon website is entitled to review the company’s Privacy Notice to see what personal data is collected and why it is processed.
However, even to my relatively trained eye this doesn’t really convey the full extent of how much personal data Amazon collects from people whenever they use an Amazon service. One privacy campaigner made a request to Amazon for details of her click stream history (as anyone can do under the right of access using Article 15 of the GDPR). She was shocked to discover that 100 purchases had generated 15,000 pieces of information about her, based on her click stream. Amazon were able to tell which days she had taken holidays, or was sick, or when she couldn’t sleep at night.

The sheer volume of personal data that Amazon collects, and processes is demonstrated by the fact that Amazon operated a data warehouse called ‘Helix’ to analyse customers’ personal data ‘over the entirety of their lifetime’. It processes the data of hundreds of millions of people worldwide.

What about Alexa?

The BBC documentary also touches on one question that I have frequently heard people ask: ‘Can Alexa (Amazon’s voice assistant) listen to my conversations?’. The answer is yes. Amazon acknowledges that their workers can listen to anything that you say when the Amazon Echo’s blue light is on, and some of these private conversations are transcribed. If that’s disturbing, then Amazon’s ambitions for Alexa are even more worrying.

Amazon aspires for most things in the home to be Alexa enabled. This could result in the entire activity in the home being recorded. The more people interact with Alexa the more information that Amazon will be able to collect, or as one person said, it wants everything that people do in their homes to be ‘mic’d’ and recorded.

Coupled with this the company has obtained a patent that will enable Alexa to embed certain ‘sniffer’ algorithms to identify ‘trigger words’ that will enable Amazon to send direct marketing messages to Alexa users. Amazon says it has no current plans to do this, but equally is doesn’t refute the possibility. Commentators say that this increased data collection, particularly collecting data about people in their homes, will enable Amazon to start influencing and shaping people’s behaviour, and this constitutes a real threat to democracy and privacy.

Doorbells and Drones

In 2019 Amazon made nearly $12 billion profit and used some of that profit to buy into other lucrative markets that enable it to collect yet more data about people.
The BBC documentary charts the purchase of ‘’Ring’ a manufacturer of smart video doorbells. These doorbells allow users to record anyone who comes to their door, and are marketed as a means of ensuring the security of people’s homes (See Ring UK). However, in practice they are most likely to capture images of friends and neighbours and people delivering goods. (Forgive me for being sceptical but I wonder how many burglars or intruders are polite enough to ring first). However, Amazon is known to have given 1000 ‘Amazon Ring’ doorbells to three police forces in the UK and these are being embraced by Suffolk Police for their crime fighting potential. (Amazon may have provided free doorbells to other police forces but, in response to a BBC freedom of information request, only three police forces have confirmed that they have received the free doorbells.)

At this point you may be thinking that extra home security is a good thing. However, in America Amazon has created a ‘Ring Neighbours app’ that  enables ‘ring’ users to share footage with others to create a digital neighbourhood scheme. This data is being shared with 913 US police forces who can obtain the data with the resident’s consent and without a warrant. There are concerns that the app may become available here in the UK.

According to Amazon the ring doorbells are not marketed as a surveillance device. However Tony Porter, the Surveillance Camera Commissioner considers that if the app were to be introduced into the UK it would change the dynamic of the surveillance from being a community form of reassurance to a state form of surveillance.
This clearly needs to be addressed by the Information Commissioner and through the General Data Protection Regulation. Tony Porter states that “we could end up living in a surveillance state.”

Then there is the Prime Air Drone; a delivery aerial drone equipped with cameras and sensors. Two weeks after its launch in 2019, Amazon was granted patent rights to allow it to use delivery drones for aerial home security. Amazon calls this ‘surveillance as a service’ and that the drone would be an ‘opt in’ service. However, even a fully consented opt in by subscribers of this service would not address the privacy issues of others who would inevitably be filmed by such drones. According to the Surveillance Commissioner, this could take us into a whole new area of unregulated territory and a shift into a surveillance state.

Save for some statements by the Surveillance Camera Commissioner, the documentary doesn’t address the data protection issues in particular whether the activities of Amazon comply with the General Data Protection Regulation(GDPR). However, it quite clearly raises numerous issues about lawful and transparent processing and several other GDPR compliance issues.

Jeff Bezos’ take on this is that the Amazon’s use of our data should be for us to decide. The implication being that if users aren’t happy then they don’t need to use Amazon services. However, as one former Amazon Executives says, “don’t necessarily see it as Big Brother if it is done carefully”, which probably reflects the fact that most people don’t really know the full extent of what is going on.

Susan Wolf is an associate with Act Now Training.

More on this and other developments in our GDPR update webinar.  Looking for a GDPR qualification from the comfort of your home office? Our GDPR practitioner certificate is now available as an online option.

gdprcert-online

Act Now Supporting Innovative Digital DPIA Project

EQaZlPcXsAEyAX4

Act Now Training is pleased to announce that it is supporting a new public sector collaboration to co-design and develop a digital approach to Data Protection Impact Assessments (DPIAs).

This innovative six month project will help Data Controllers conducting DPIAs to ensure that a ’Data Protection by Design and Default’ approach is embedded into the process. The project is also supported by the Information Commissioner’s Office, NHSX and the Information and Records Management Society.

Greater Manchester Combined Authority, the London Office of Technology and Innovation, Norfolk County Council and the University of Nottingham are leading the project which follows on from a successful alpha phase undertaken last year. A full project overview can be read here: https://cc2i.org.uk/digital-dpia/

Ibrahim Hasan, Director of Act Now Training, said:

“We are really pleased to be supporting this innovative new project alongside the Information Commissioner’s Office, NHSX and the IRMS. A digital DPIA solution will be a valuable tool to help DPOs ensure that privacy and data protection are at the heart of every new data driven project.”

Are you a public authority wishing to a share in this exciting new project and shape the future of the Digital DPIA? Using a proven co-funding approach (similar to crowdfunding, but on a corporate level), the collective is actively looking for partners to join them in this cost-neutral project.

A webinar on the project and approach is being hosted on Wednesday 12th at 2pm. Led by Stephen Girling, Information Governance Project Manager at GMCA and Lianne Hawkins, Head of Service Design at Looking Local, this webinar will cover:

  • The background and outcomes of the original Digital DPIA alpha project undertaken by GMCA – including the headline business case
  • The benefits of a uniform approach to DPIAs across public sector
  • The work packages planned to deliver a digital DPIA solution
  • Partner benefits and their motivation to be part of this collaborative approach
  • Project partners timelines & what’s involved

We would encourage all our blog subscribers to register for the webinar here: http://bit.ly/2ScGdi2 A recording of the webinar will also be available. Please email  irene.zdziebko@cc2i.org.uk 

PrivSec London Conference: Act Now Announces Winners of Free Tickets

DPWF Draw image

Act Now is pleased to announce the winners of the 7 free delegate tickets for the  PrivSec London Conference taking place on 4th and 5th February 2020. We are exhibiting at this two day event which will deliver  top-level strategic content, insights, networking, and discussion around data protection, privacy and security. In addition to leading content, tickets will include refreshments, lunch and access to exclusive post-event content.

And the winners are…

1.    Alison Hope of Greenwood Academies Trust
2.    Tony Sheppard of GDPR In Schools
3.    Rhiannon Platt of Royal Devon & Exeter NHS Foundation Trust
4.    Jamie Pickering of The Valuation Office
5.    Claire Owen of Cumbria County Council
6.    Amanda Godridge of Hampshire County Council
7.    Sam Smith of Herefordshire Council

Congratulations to all the winners who will receive an email informing them of how to claim their free ticket. Thank you to all of those who expressed an interest.

Act Now is in full conference mode now. Like last year, we hope to be exhibiting at the ICO Data Protection Practitioner’s Conference in Manchester.

In April, Ibrahim Hasan will travel to Las Vegas to address the 21st Annual NAPCP Commercial Card and Payment Conference. Ibrahim will be talking about the California Consumer Privacy Act (CCPA) which comes into force on 1st January 2020. It is sometimes known as the US equivalent of GDPR and provides broader rights to consumers and stricter compliance requirements for businesses than any other state or federal privacy law.

In May we will be exhibiting at the IRMS Conference in Birmingham. If you are attending any of these conferences, come and say hello on our stand and talk to us about our range of  GDPR Update Workshops,  E learning and Certificate Courses (Oh and collect some freebies!)

The New Year Honours Data Breach

man in santa claus costume

The New Year Honours list is supposed to “recognise the achievements and service of extraordinary people across the United Kingdom.” However more media attention this year has been on the fact that, together with the names of recipients, the Cabinet Office accidentally published their addresses; a clear breach of the General Data Protection Regulation (GDPR) particularly the sixth data protection principle and Article 32 (security).

The Honours List file contained the details of 1097 people, including the singer Sir Elton John, cricketer Ben Stokes, the politician Iain Duncan Smith and the TV cook Nadiya Hussain. More than a dozen MoD employees and senior counter-terrorism officers as well as holocaust survivors were also on the list which was published online at 10.30pm on Friday 26thDecember. The Cabinet Office said the list was downloadable from its website for around an hour and was taken down in the early hours of Saturday. The vast majority of people on the list had their house numbers, street names and postcodes published with their name.

Such a breach can result in the Information Commissioner’s Office (ICO) issuing a fine of up to 4% of a company’s annual global turnover or £17m, whichever is greater. It comes hot on the heels of the first GDPR fine issued to a London based pharmacy. Doorstep Dispensaree Ltd was fined £275,000 for careless storage of the medical data of half a million people. We are also waiting for a final decision on whether, and how much, British Airways and Marriot International will be fined after both were issued with Notices of Intent for millions of pounds.

The Cabinet Office, which (ironically) manages the UK’s cybersecurity, has apologised for the breach and said it is investigating the cause. The ICO is also “making inquiries.” Can the Cabinet Office expect a large fine? Article 83(2) of GDPR requires the ICO, when deciding whether to impose a fine and the amount, to have due regard to various factors including (amongst others):

  • The nature, gravity and duration of the infringement
  • The number of data subjects affected and the level of damage suffered by them
  • The intentional or negligent character of the infringement
  • Any action taken by the responsible party to mitigate the damage suffered by data subjects
  • The degree of cooperation with the ICO, in order to remedy the infringement and mitigate the possible adverse effects of the infringement
  • The categories of personal data affected by the infringement
  • The manner in which the infringement became known to the ICO, in particular whether, and if so to what extent, it was notified of the infringement
  • Any other aggravating or mitigating factor applicable to the circumstances of the case

Whilst this data breach involved over 1000 people, the effect on each will be different. The leak could endanger the lives of some of them e.g police and government officials. “A number of those receiving honours are employed in extremely sensitive positions in the police and intelligence agencies,” Richard Walton, the former head of counterterrorism at Scotland Yard, told the Sunday Times.

“The release of the private addresses of these individuals into the public domain will mean that a threat and risk assessment will need to be undertaken resulting in some having new private security measures introduced into their homes,” he added.

The fact that the Cabinet Office took almost immediate action to remedy the situation and reported the data breach to the ICO will count in its favour. It has also said that it is contacting the individuals affected and providing them with guidance if they have security concerns.  As long as the Cabinet Office can satisfy the ICO that it had appropriate security measures in place and staff were aware of their data protection obligations, my personal view is that the ICO will exercise one of its less serious corrective powers, under Article 58(2) of GDPR, most probably a warning. Depending on what it discovers during its investigation, it may also issue an Enforcement Notice under Section 149 of the Data Protection Act 2018.

Training and awareness of staff involved in the data breach will also be one of the areas the ICO will wish to focus on during its investigation. Most of the audits and advisory visits completed recently feature recommendations on this topic. (See for example the report into North Bristol NHS Trust and Essex Police.) Our new e-learning course, GDPR Essentials is ideal for training frontline staff.

Even if the ICO decides not to impose a fine the Cabinet Office (at least in theory) faces the threat of legal action by those affected by the data breach.  Article 79 and 82 of GDPR give them a free-standing right to sue the Cabinet Office in the civil courts for compensation for the material and non-material damage suffered. A recent Court of Appeal decision as well as S.168 of the DPA make it clear that this includes distress. Much depends on the attitude of the affected individuals. Many may just be grateful for the accolade and will not want to sour relations with the Government. Others may put it down to human error and move on.

The Guardian reports that it was alerted to the list by a member of the public. So what of those who managed to download the full list, with the addresses, in the hour or so that it was available?  Section 170 of the DPA 2018 makes it a criminal offence to “… after obtaining personal data, to retain it without the consent of the person who was the controller in relation to the personal data when it was obtained.”

There will be much to learn from conclusion of the ICO’s investigation into this high profile data breach. Whatever the outcome, it has certainly highlighted the importance of getting data protection right.  Furthermore, GDPR is now being mentioned in the same sentence as Sir Elton John, Ainsley Harriott and Olivia Newton-John. Proof, if it were needed, that data protection is cool!

These and other GDPR developments will be discussed in detail in our GDPR update workshop. Our new new e-learning course, GDPR Essentials will help you train your staff in 30 minutes. Watch the demo here

Photo by bruce mars on Pexels.com