Cambridge Analytica, Facebook & GDPR

Since Donald Trump’s surprise victory in the 2016 US presidential election, claims and counter-claims have been swirling around about what might have tipped the poll in his favour. Two factors have been the focus of repeated discussion, fake news and targeting of ads.

A Department of Culture, Media and Sport select committee has recently been taking evidence about the first of these. But reports in The Guardian and C4 televison news have brought the second activity into its fresh focus.

According to a former employee of Cambridge Analytica, Christopher Wylie, the company did collect data on Facebook users and use it to target political ads, despite the denials made by its founder, Alexander Nix, including during evidence given to the DCMS committee in February.

Facebook has responded by suspending the accounts of Strategic Communication Laboratories, the parent company of Cambridge Analytica, and Wylie.

It has denied that the incident constitutes a data breach, states that data subjects gave their consent and that it was an academic researcher, Aleksandr Kogan, who violated the terms of a license under which he was given permission to run an app on Facebook by sharing the data collected.

The DCMS has announced that it will call back Nix and Facebook to explain their earlier statements that no personal information was involved in this activity.

What has happened to the Facebook Data?

Kogan applied for and was granted a license to operate an app, thisisyourdigitallife, on Facebook. Users were asked to take a personality test whose purpose was to capture likes as part of a psychographic modelling exercise to identify how predictive these are of other behaviours, such as political affiliation and voting intention.

This type of exercise is a relatively common practice, it underpins The University of Cambridge Psychometric Centre’s Magic Sauce profiling system, for example, because of the scale of Facebook’s user base and the visibility it provides into preferences.

Some 270,000 Facebook users downloaded the app. As part of the data collection it involved, their friends who had privacy settings that allowed for data sharing were also included in a data set said to involve up to 50 million individuals. Wylie alleges that the raw data from this app was passed by Kogan to Cambridge Analytica, in breach of the license he was granted.

Facebook was aware of this in 2015 and demanded that all copies be destroyed. In the wake of the DCMS hearing, the incident has gained fresh momentum and new questions are being asked about who knew about the data sharing, when it happened and whether the personal information involved was actually used and subsequently deleted.

What does the Data Protection Act say about this?

Cambridge Analytica is a UK-based company which has brought the Information Commissioner’s Office into the picture. Crucially, much will depend on whether any UK citizen’s data is involved.

Given the global footprint of Facebook, even if the app was aimed at US voters, it is possible that some of the data covers British subjects, potentially as friends of those direct downloaders.

If this is the case, then any data collected is covered by the existing Data Protection Act. Two key principles are involved:

Use for a limited, specifically-stated purpose: The ICO will want to be satisfied that any UK citizens who downloaded the app were made aware of the purpose for which it would be used. If the data collection notice only mentioned academic research and not political profiling or data sharing, this would be a breach of the DPA. Facebook states that data sharing was not part of the terms and conditions of the license it granted.

Protection of sensitive information, such as political opinions: Any information that is potentially sensitive, such as a user’s political opinions, has to meet high standards for the basis on which it will be processed. An academic researcher could claim legitimate interest provided they meet strict conditions - any additional usage would require consent. Facebook says users of the thisisyourdigitallife app provided this.

What would happen under the General Data Protection Regulation?

As the app was launched in 2015, it is covered by the DPA. But if it were to be in use after 25th May of this year, then GDPR would apply.

Transparency, definition of purpose and granularity of consent are all much tougher under the GDPR Regulation.

The distinction between data controllers and data processors is also less, which would play an important part in any investigation into who directly accessed and controlled app data, including whether Facebook was a first-party controller.

Penalties for breaches of GDPR are substantial, sharing personal information and using it beyond the stated purpose would be likely to incur a €20 million or 4% of global turnover fine.

Why does this matter?

There are three critical dimensions to the Cambridge Analytica data issue. The first is for UK data subjects who may have had their sensitive personal information shared without their consent. The ICO will focus on establishing this in order to decide whether it has jurisdiction.

The second is for the fake news investigation being carried out by DCMS (which the ICO has also been asked to engage with). It is recalling Nix and Facebook to challenge evidence they provided in February about personal information sharing by Kogan with Cambridge Analytica.

With Facebook now stating it knew this had happened back in 2015, it is likely to come under significant pressure about subsequent statements.

But there is a third group that needs to take a close look at its data collection practices, including consent notices and data sharing. Competitions, quizzes and games are common techniques deployed by affiliates as data capture mechanisms.

In 2015, the ICO wrote to 1,000 companies in this sector asking about the basis for their data processing. In the wake of this weekend’s Cambridge Analytica revelations, it may just decide to take another look.

DataIQ

You Might Also Read: 

Data Protection Officer's Guide To The GDPR Galaxy:

Facebook’s Influence On UK Politics:

 

« Criminal Web-Injects Can Steal Cryptocurrency
How to Access the Dark Web Anonymously »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

GrammaTech

GrammaTech

GrammaTech is a leading developer of software-assurance tools and advanced cyber-security solutions.

Centripetal Networks

Centripetal Networks

Centripetal Networks was founded with one vision - to protect networks from advanced threats by simplifying intelligence-driven security.

CLUSIF

CLUSIF

Clusif is the reference association for digital security in France. Its mission is to promote the exchange of ideas and feedback through working groups, conferences and publications.

CyberDefcon

CyberDefcon

CyberDefcon is an independent organization dedicated to the pursuit of making the internet a safer place.

Celestya

Celestya

Celestya is dedicated to providing the most advanced and cost effective systems for human behavior education on cybersecurity awareness training.

Cybonet

Cybonet

Cybonet is committed to empowering organizations of all sizes with the tools and capabilities to detect and engage cyber security threats.

NSA Career Development Programs

NSA Career Development Programs

NSA offers entry-level programs to help employees enhance their skills, improve their understanding of a specific discipline and even cross-train into a new career field.

Right-Hand Cybersecurity

Right-Hand Cybersecurity

Right-Hand Cybersecurity empowers businesses to monitor, measure and mitigate employee induced cyber risks in real-time.

VikingCloud

VikingCloud

VikingCloud (formerly Sysnet Global Solutions) offers organizations an integrated cybersecurity and compliance solution to make informed, predictive, and cost-effective risk mitigation and prevention

Kalima Systems

Kalima Systems

Kalima’s mission is to securely collect, transport, store and share Industrial IoT (IIoT) trusted data in real time with devices, services and mobile workers.

Nonprofit Cyber

Nonprofit Cyber

Nonprofit Cyber is a first-of-its-kind coalition of global nonprofit organizations to enhance joint action to improve cybersecurity.

Forta

Forta

Forta is a real-time detection network for security & operational monitoring of blockchain activity.

Approov

Approov

Approov provides a comprehensive runtime security solution for mobile apps and their APIs, unified across iOS and Android.

Triangle

Triangle

Triangle enable innovative business transformation by ensuring critical hybrid infrastructures are optimised, interoperable and secure.

Sterling Information Technologies

Sterling Information Technologies

Sterling is an information security, operational risk consulting and advisory group. Our Advisory services help to safeguard information assets while supporting business operations.

StrongBox IT

StrongBox IT

Strongbox IT provides solutions to secure web applications and infrastructure.