Facebook to Tighten Privacy After Canadian Investigation

Facebook will enhance its social-networking site's privacy features over the next 12 months as a result of a set of recommendations from the Canadian government.

By Juan Carlos Perez
Thu, August 27, 2009

IDG News Service — Facebook will enhance its social-networking site's privacy features over the next 12 months as a result of a set of recommendations from the Canadian government.

Facebook will increase the information it provides to its users about its privacy features, as well as make technical changes to tighten privacy controls, the company said Thursday.

The changes come as a direct result of a review of Facebook's privacy policies and controls conducted by the Office of the Privacy Commissioner of Canada. Facebook cooperated with the Canadian agency's study, which lasted more than a year.

Specifically, Facebook will update its privacy policy so that it more clearly explains its privacy practices. Facebook will also reach out to users, prompting them to review their privacy settings.

For the tens of thousands of third-party applications built for the Facebook platform, Facebook will begin to require that they comply with a new set of permissions, specifying the types of information they want to access. "Express consent" from end users will also be required before their data and their friends' data is made available to external applications.

In a separate statement issued by her office, Privacy Commissioner of Canada Jennifer Stoddart said the changes to privacy policies and practices that Facebook has agreed to make will bring it into compliance with Canadian law.

"We're very pleased Facebook has been responsive to our recommendations," she said in the statement.

The Canadian agency's biggest concern has been what it called application developers' "virtually unrestricted access to Facebook users' personal information."

The new privacy requirements for third-party applications will take about a year to implement because they involve changes to the Facebook platform's API (application programming interface) and to the applications themselves. It will be interesting to see how Facebook developers react to the news that they will have to re-tool their applications to comply with these stricter privacy controls.

In a blog posting for its developer community, Facebook official Ethan Beard didn't sugar-coat the implications of the changes to the API.

"We have committed to making these enhancements over the next twelve months, and anticipate a lengthy beta period including opportunities for you to provide input, multiple blog posts, and updated documentation delivered well ahead of time. Understanding that this will likely require modifications to your code base, we want to give you the earliest heads up that these enhancements are on our road map," Beard wrote.

Ultimately, the goal is to make Facebook members better informed about how applications use their data, and to give them more control. "This should result in better informed users who are more eager to engage with applications on Facebook," he wrote.

In July, Facebook announced plans to simplify its privacy features, saying that they have become too numerous and complicated for end users to understand and apply.

Under pressure from Twitter, Facebook is also in the process of adding less restrictive privacy settings for end users who want to make their profiles, or at least portions of it, more public and thus more widely available to others on and off Facebook.

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center