I learned about the rallying cry from the health world, and passed it on to my colleagues, and it applies equally to other domains, and to the places where our data crosses domains.

The Venn is about the "practice of privacy" in organizations. Some of privacy practice is simply about good security practice. Some of it is about good policy and governance rules. (And these all overlap; the intersections aren't empty, as is shown.) Where there hasn't been much in the way of solutions, driven by little business motivation, is on supporting the positive goals that individuals have that come under various "privacy definitions". My testimony to the API Task Force made a case about some factors that are arising now that seem to be changing the equation somewhat.

Privacy by Design and Privacy Engineering are actually two very different disciplines, though of course the goals aren't so very different. Privacy Engineering is a very technical discipline, as I discovered firsthand when I presented to the IEEE workshop -- deeply concerned with encryption techniques, for example. I found it to be firmly ensconced in the upper left bubble.

ForgeRock's solution includes both an AS component and an RS enablement component. A variety of organizations could be interested, including health/consumer/IoT platforms, governments, retail players/platforms, and others. The sizes of the ecosystems range, so far, from "narrow" to "medium". As you know, the "#wideeco" use case is one that has particular challenges (and not just for UMA but for OAuth and other tech), and it's on our roadmap to discuss in 2016.


Eve Maler
Cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl


On Wed, Feb 3, 2016 at 6:51 PM, Adrian Gropper <agropper@healthurl.com> wrote:
The video is lovely. "nothing about me without me" has been a rallying cry of the Society for Participatory Medicine for years now.

The Venn is somewhat confusing. What is policy? Who's policy is it ?

What ForgeRock is selling is baffling. Who is buying AS from ForgeRock? How many UMA Authorization Servers will one person have? Who will own my AS in the sense of being able to take it off-line if they choose to?

PS: Privacy by Design has never sat well with me. I prefer Privacy Engineering, but that's maybe a personal problem for me.

Adrian

On Wed, Feb 3, 2016 at 9:30 PM, Eve Maler <eve@xmlgrrl.com> wrote:
FWIW, I debuted a new, very lightweight Venn diagram in a blog post last week (where ForgeRock was announcing its new platform version with UMA support!) describing elements of privacy. It's not to be taken too literally, but it echoes themes I talked about in this paper and talk from last year.


Eve Maler
Cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl


On Wed, Feb 3, 2016 at 6:01 PM, Ken Dagg <kendaggtbs@gmail.com> wrote:
Hi UmanitRians,

I'm an UMA lurker. That being said, the discussion around privacy is something of great interest to me and I couldn't resist chiming in.

Dictionary definitions, such as the dictionary.com definition below, (not that I'm totally in agreement with these definitions) all seem to revolve around privacy being a state (this part I do agree with) and legislation from various jurisdictions provide requirements to achieve this state (without providing a definition of privacy).

For example, Canada's two pieces of privacy legislation (Privacy Act and Personal Information Protection and Electronic Documents Act (PIPEDA)) basically specify what must be achieved regarding the collection, storage, use and disposal of Personally Identifiable Information (as well as defining what PII is) including what and where consent is required.

I would suggest that defining privacy without defining the requirements (including consent) for achieving it would be negligent and doing a disservice to UMA. 

My two cents,
Ken 

1. the state of being apart from other people orconcealed from their view; solitude; seclusion: (Please leave the room and give me some privacy.)
2. the state of being free from unwanted or undue intrusion or disturbance in one's private life or affairs; freedom to be let alone: (Tourists must respect the tribe’s privacy. Those who wish to smoke can do so in the privacy of their own homes.) See also invasion of privacy. 
3. freedom from damaging publicity, public scrutiny,secret surveillance, or unauthorized disclosure ofone’s personal data or information, as by agovernment, corporation, or individual: (Ordinary citizens have a qualified right to privacy. There is so much information about us online that personal privacy may be a thing of the past.)
4. the state of being concealed; secrecy: (Before he told us of his plans, he insisted on total privacy.)




On Wednesday, 3 February 2016, Eve Maler <eve@xmlgrrl.com> wrote:
I don't think there is any UMA publication that defines privacy, but there is one (older) publication that discusses UMA with respect to Privacy by Design, here:


I was thinking recently that it might be a good time to revise this paper, and/or write a new and more expanded one, in light of the many regulatory moves being made and discussions about the role of "consent" (as UMA enables) within those regulations. (I happen to have been doing a lot of writing and presenting along those lines in various forms myself lately, and others of us such as Jon Neiditz have as well.)


Eve Maler
Cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl


On Tue, Feb 2, 2016 at 9:07 AM, arr@worldknowledgebank.com <arr@worldknowledgebank.com> wrote:

Is there an uma definition of privacy?

 

Regards,

 

Ann Racuya-Robbins

 

 

 

 

 

“When you share what you know in a just way

you sustain life and transform the way the world works.”

 

Ann Racuya-Robbins

Founder

Virtual Democratic Countries

https://www.worldknowledgebank.com

 

4440 Willard Ave #729

Chevy Chase, MD 20815

and

2 Placita Road, La Puebla, Espanola, New Mexico 87532

 

202.304.7103, 505.216.5343, 301.951.1809

 

This message (including any attachments) is intended only for the use of the individual or entity to which it is addressed and may contain information that is non-public, proprietary, privileged, confidential, and exempt from disclosure under applicable law or may constitute as attorney work product. If you are not the intended recipient, you are hereby notified that any use, dissemination, distribution, or copying of this communication is strictly prohibited. If you have received this communication in error, notify us immediately by telephone and (i) destroy this message if a facsimile or (ii) delete this message immediately if this is an electronic communication.

 




--
Kenneth Dagg
Independent Consultant
Identification and Authentication
613-825-2091
kendaggtbs@gmail.com


_______________________________________________
WG-UMA mailing list
WG-UMA@kantarainitiative.org
http://kantarainitiative.org/mailman/listinfo/wg-uma




--

Adrian Gropper MD

PROTECT YOUR FUTURE - RESTORE Health Privacy!
HELP us fight for the right to control personal health data.

DONATE: http://patientprivacyrights.org/donate-2/