Study on the Economic Benefits of Privacy-Enhancing Technologies
Total Page:16
File Type:pdf, Size:1020Kb
Study on the economic benefits of privacy‐enhancing technologies (PETs) Final Report to The European Commission DG Justice, Freedom and Security Prepared by July 2010 About London Economics London Economics is one of Europe's leading specialist economics and policy consultancies and has its head office in London. We also have offices in Brussels, Dublin, Cardiff and Budapest, and associated offices in Paris and Valletta. We advise clients in both the public and private sectors on economic and financial analysis, policy development and evaluation, business strategy, and regulatory and competition policy. Our consultants are highly‐qualified economists with experience in applying a wide variety of analytical techniques to assist our work, including cost‐benefit analysis, multi‐criteria analysis, policy simulation, scenario building, statistical analysis and mathematical modelling. We are also experienced in using a wide range of data collection techniques including literature reviews, survey questionnaires, interviews and focus groups. Head Office: 11‐15 Betterton Street, London, WC2H 9BP, United Kingdom. w: www.londecon.co.uk e: [email protected] t: +44 (0)20 7866 8185 f: +44 (0)20 7866 8186 Acknowledgements We would like to thank the participants of the Workshop on the Economic Benefits of PETs, hosted by DG Justice, Freedom and Security on 12 November 2009 (http://tinyurl.com/2b23ll), for comments on an earlier version of this report. In particular, we acknowledge valuable contributions by Mr Caspar Bowden (Microsoft) and Mr John Borking (Borking Consultancy). We also owe a debt of gratitude to Professor Alessandro Acquisti (Carnegie Mellon University) and Ms Marit Hansen (Independent Centre for Privacy Protection Schleswig‐Holstein) for enlightening discussions on the subject of PETs. Finally, we are grateful to the many individuals who provided us with information on the case studies that were conducted as part of the report. Copyright © 2010 London Economics. Except for the quotation of short passages for the purposes of criticism or review, no part of this document may be reproduced without permission. Contents Page Glossary vi Executive summary vii 1 Introduction 1 1.1 Terms of reference 1 1.2 Approach 2 2 PETs: definition and technical overview 7 2.1 Definition 7 2.2 Classification 8 2.3 Technical overview 14 2.4 Summary 28 3 PETs deployment: context and issues 29 3.1 Outline of the economic approach 29 3.2 Individuals’ demand for PETs 32 3.3 Data controllers’ deployment decision 45 3.4 PETs and competition 52 3.5 Patterns of technology adoption 56 3.6 Summary 59 4 Stakeholders’ views 64 4.1 Risks to privacy and the state of data protection 65 4.2 The role of PETs 69 4.3 Promoting PETs deployment 76 4.4 Summary 77 5 Case Studies 79 5.1 Assessing the economic benefits of PETs 79 5.2 Case study I: GENOMatch 83 5.3 Case study II: PriPAYD 96 5.4 Case study III: Pseudonymisation services 103 5.5 Case study IV: location‐based mobile services 107 5.6 Case study V: CCTV privacy zones 112 5.7 Case study VI: Nightclub fingerprint identification 117 5.8 Summary 120 6 Business survey 125 6.1 Response sample and respondent profile 125 6.2 Use of personal information 128 6.3 PETs and the benefits of holding personal data 133 6.4 Summary 143 7 Options for public‐private cooperation 146 7.1 Theoretical arguments 146 7.2 Case study evidence 149 London Economics Study on the economic benefits of privacy‐enhancing technologies (PETs) i 7.3 Views of businesses and stakeholder organisations 151 7.4 Summary 151 8 Conclusions 153 9 References 156 Stakeholder consultation documents 163 rNPV of pharmaceuticals – model parameters 169 Exploratory case Studies 171 Business survey 230 London Economics ii Study on the economic benefits of privacy‐enhancing technologies (PETs) Tables & Figures Page Table 1: Consultation with national data protection authorities, business associations and consumer associations 4 Table 2: FIDIS (2007) PETs classification 10 Table 3: META GROUP (2005) PETs classification 11 Table 4: Clarke’s (2007) PETs classification 13 Table 5: PETs classification after Hacohen (2009) 13 Table 6: Summary of PETs reviewed 27 Table 7: Prices for personal data sold via underground economy servers (2008) 36 Table 8: Overview of data tracks of the average Austrian citizen 38 Table 9: Determinants of e‐commerce participation in the EU: regression results 43 Table 10: Summary of event studies 54 Table 11: Return on investment from a Privacy Management System (PMS) 82 Table 12: Success rates during the development process 91 Table 13: Direct cost of GENOMatch to data controllers 91 Table 14: Example of clinical trial costs 92 Table 15: Effect of PET 94 Table 16: Please use sentence case 101 Table 17: Indicative cost of pseudonymisation services 105 Table 18: Conventional LBS deployment distribution of information 109 Table 19: LBS partitioned information 109 Table 20: Costs of privacy zones in CCTV systems 114 Table 21: Benefits of privacy zones 116 Table 22: Case studies summary 123 Table 23: Distribution of firms by activity 127 Table 24: Relationship between volume and detail of customer data held by survey respondents 130 Table 25: Net economic impact for businesses deploying PETs 140 Table 26: rNPV of pharmaceuticals – model parameters 169 Table 27 Exploratory case studies: overview 174 Table 28: Exploratory case studies: selected summaries 178 Table 29: Please use sentence case 211 Figure 1: Potential costs and benefits of PETs deployment xi Figure 2: Methodological approach for considering the economic benefits of PETs deployment 3 Figure 3: The 'PET‐Staircase' 12 Figure 4: The consequences of misjudging the risk of misuse 34 Figure 5: Rate of identity loss events (2000‐2008) 35 Figure 6: Consumer risk aversion 39 Figure 7: Perceived security of transactions over the Internet 40 Figure 8: E‐commerce transactions and consumer concern in the EU (2008) 42 Figure 9: E‐commerce transactions and broadband penetration in the EU (2008) 43 London Economics Study on the economic benefits of privacy‐enhancing technologies (PETs) iii Tables & figures Page Figure 10: Awareness of tools or technologies improving data security 44 Figure 11: The ‘S‐curve’ 57 Figure 12: Distribution of firm privacy valuations (xi) 58 Figure 13: Potential costs and benefits of PETs deployment 62 Figure 14: Are the risks to privacy and the protection of personal data associated with online activity increasing? 67 Figure 15: Is the deployment of PETs an effective means of minimising the risks associated with online activity? 69 Figure 16: Is the deployment of PETs currently widespread? 70 Figure 17: Has the deployment of PETs changed significantly over the past 5 years? 71 Figure 18: To what extent could the deployment of PETs yield economic benefits to data controllers? 72 Figure 19: To what extent could the deployment of PETs yield non‐economic benefits to data controllers? 74 Figure 20: Factors limiting PETs deployment 75 Figure 21: Classification scheme for business case techniques 81 Figure 22: The stages of drug development 84 Figure 23: GENOMatch system architecture 86 Figure 24: Risk‐adjusted NPV of drug X 93 Figure 25: Current PAYD model 98 Figure 26: Black box, high‐level specification 99 Figure 27: Privacy‐friendly PAYD model 99 Figure 28: LBS with location intermediary 109 Figure 29: Privacy zones in CCTV 113 Figure 30: No. of responses to business survey per Member State 126 Figure 31: Size distribution of no. of employees of respondents 128 Figure 32: Type of personal data held 129 Figure 33: Number of records, by data type 130 Figure 34: Type of personal data (customers, suppliers 3rd parties), by business size 131 Figure 35: Number of records, by company size 132 Figure 36: Type of personal data, by sector 133 Figure 37: Overall benefit of personal data, by size of data controller 134 Figure 38: Benefit of personal data on customers, by size of data controller 134 Figure 39: Privacy risk to businesses 136 Figure 40: Net economic impact of PETs 137 Figure 41: Awareness of PETs 138 Figure 42: Awareness and perceived benefits 139 Figure 43: Effectiveness of PETs 140 Figure 44: Awareness and perceived effectiveness 141 Figure 45: Factors preventing deployment of PETs 142 Figure 46: Consumer concern and business awareness of PETs 143 London Economics iv Study on the economic benefits of privacy‐enhancing technologies (PETs) Tables & Figures Page Figure 47: Users of FinanzOnline (as of March 2009) 181 Figure 48: Proportion of sales tax return filings via FinanzOnline (as of April 2009) 181 Figure 49: Proportion of income tax return filings via FinanzOnline (as of April 2009) 182 Figure 50: Electronic file exchange via EDIAKT 184 Figure 51: Two examples of EDIAKT II objects 185 Figure 52: EDIAKT metadata 186 Figure 53: Average usage of SRF filled in through electronic system 195 Figure 54: Screenshot personal information held by TNS Infratest 203 Figure 55: Architecture of genome projects database system 207 Figure 56: The technological architecture of e‐school system 210 Figure 57: Schools in Estonia (and Sweden) using the eSchool system (September 2009) 211 Figure 58: The CdB certificate 225 Figure 59: The one‐stop‐shop concept 226 Figure 60: Distribution of sectors across Member States 232 Figure 61: Type of personal data held on CUSTOMERS, by business size 233 Figure 62: Type of personal data held on STAFF, by business size 233 Figure 63: Type of personal data held on SUPPLIERS, by business size 234 Figure 64: Type of personal data held on 3rd parties,