Tuesday, August 6, 2019

Development of Electronic Data Flows

Development of Electronic Data Flows 1. Introduction The current development on the flow of electronic data, especially those relating to personal data across nations is increasing daily. Most of the flows are related to business activities whereas services are provided to fulfill the needs of people. It also leads to the transformation of commerce, which becomes worldwide and increasingly international. The transfer of huge quantities of data, relating to customers and employees, are required and often occurred among entities that located in different countries. An example would be the system of outsourcing, a practice in which companies and governments hire an external service provider in another country to deliver a program or provide a service, such as managing database of human resources or customers. This can often result in improved efficiencies and levels of services. Further, the advancement of global networks, such as the internet, provides the possibilities to collect, process, and distribute personal data on an unprecedente d scale. However, the trans-border flow of personal data is not only performed by companies or governments but also conducted by individuals in everyday life as well. When the data is used by companies or government, this can represent a high volume of data, such as in the form of the transfer of databases. There will be a quite different volume of data when it is provided by individuals when they disclose their personal data while participating in particular activities, such as browsing the internet or registering on various websites to obtain certain services. Additionally, there is a strong possibility for individuals, who are engaging in data transfer activities to lack of full awareness concerning what could be done to their personal data. In some instances, they do not realize that they have disclosed their personal data and it is subject to transmission and processing within countries not offering the same level of protection as their own country. For example, a student physically located in the Netherlands may complete an online game registration form, containing several spaces soliciting his/her identities, not knowing that the actual service provider is registered in India. Another example, a social worker residing within the United Kingdom might disclose his/her personal data on a web application for an internet banking service provided by a bank based in the United States. From the short description above, the trans-border flow of personal data exists in everyday life on a daily basis and it becomes a vital need of every stakeholder, whether governments or private sectors, including individuals. Nevertheless, while the flow has led to greater efficiencies and economic benefits, on the other hand this kind of flow has also raised concerns that some information could end up in the hands of people for whom it was not intended. Worse even is the situation when no one has realized the flow has taken place, spawning a great opportunity for infringement upon ones privacy rights. Some rules concerning privacy and data protection have been set up at national, regional, and international levels to guarantee privacy as one of the human rights is not harmed by any activity, including data processing as the final purpose of trans-border flow. Consequently, the trans-border flow of personal data has to be conducted in a lawful manner. In this respect, a legal framework on trans-border flow of personal data has been enacted in Europe by the European Commission (EC) under two directives. The first one is Directive 95/46/EC concerning the Protection of Individuals with Regard to the Processing of Personal Data and on the Free Movement of Such Data. This Directive has been further equipped by the second directive, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications). In relation to the research objective of this thesis, Directive 95/46/EC is the most relevant and therefore, Directive 2002/58/EC will be referred to when necessary. It should be noted that whenever a term the Directive is being used in this thesis, the term shall refer to Directive 95/46/EC. Under the Directive, a main rule concerning the trans-border flow of personal data has been set up. These include the obligation of data controller to use personal data for specified, explicit, and legitimate purposes, to collect only relevant and necessary data, to guarantee the security of the data against accidental or unauthorized access or manipulation, and in specific cases to notify the competent independent supervisory body before carrying out all or certain types of data processing operations. On the other hand, there is a series of rights for individuals as data subject, such as the right to receive certain information whenever data is collected, to access and correct the data, and to object to certain types of data processing. Nevertheless, all of the practice of these rights and obligations present a significant problem when the trans-border flow of personal data takes place from the European Union/European Economic Area (the EU/EEA) Member States to countries outside the EU/EEA, for the reason that the Directive requires an adequate level of protection in the destination countries. The transfer of personal data to a third country is prohibited when the third country does not have an adequate level of protection to ensure that the processing of personal data will not cause any violation to the rights of data subjects. The binding power of the Directive to the EU/EEA Member States requires each of the Member States to embed the provisions in the Directive into their national legal system. Thus, there is a free zone where trans-border flow of personal data can take place freely among the Member States because they provide the adequate level of protection. Any approval, adequate safeguard, or additional requirement is not necessary to any further extent. As far as public international law is concerned, by applying the extra-territoriality principle, the requirement of the adequacy is automatically fulfilled at the official representatives of the EU/EEA Member States in the third country, such as the Embassy or Consulate General because of the extended jurisdiction of the Member States. However, this principle is not extended to private sectors, since subsidiary offices of multinational companies, still have to abide to the national law in the third country although the base of operations of the company is located in the EU/EEA Member States. In this case, the adequate level of protection is still required even though the transfer is conducted internally among the subsidiaries of the company located in third countries. Currently, the EC has conducted some adequacy findings and has compiled a white list of countries providing an adequate level of protection. This approval means the trans-border flow of personal data can take place as in the free zone between the EU/EEA Member States. However, to date, the white list covers a limited list of countries, seven to be exact. This list might not prove too sufficient from the point of view of multinational companies in accommodating their interest, as it does not include many countries of growing commercial interest. From this point of view, there is a need to harmonize various privacy and data protection regulations in many countries through the establishment of an internationally congruent legal framework for privacy and data protection. Unfortunately, it will take some effort and time for the establishment, while a fast solution is needed. By considering the Directive thus far the strictest legal framework compared with other existing legal framework on privacy and data protection, obviously, there is a need for countries outside the EU/EEA Member States to improve their legal framework to become compliance with adequate level of protection requirement under the Directive. Since Indonesia is neither a Member State of the EU/EEA nor included in the white list of adequacy finding, the requirement of adequate level of protection is applied to Indonesia as a third country. The trans-border flow of personal data only can take place after the data controller is certain that the protection level of personal data in Indonesia is adequate under the Directive. Apparently, Indonesia is needed to criticize, whether or not its legal framework providing an adequate level of protection. Moreover, Indonesia as a Member State of the Asia-Pacific Economic Cooperation (APEC) has received a pressure to provide a sufficient level of protection on trans-border flow of personal data, in relation to the existence of the APEC Privacy Framework. This pressure has become heavier because of Indonesia position as the Association of South East Asian Nations/ASEAN Member States. Therefore, the main objective of this thesis is to examinehow Indonesia can improve its legal framework to comply with the adequate level of protection in view of Directive 95/46/EC. Conducting this examination is important in determining ways Indonesia might be developed into an attractive destination country for international commerce activities. In order to answer the objective of this thesis, three research questions have to be answered: firstly,currently, why Directive 95/46/EC is being acknowledged as the strictest legal instrument concerning privacy and data protection on conducting trans-border flow of personal data compared with other existing legal instruments. Secondly, how the European Commission determines the adequate level of protection in the third country in question under Directive 95/46/EC. Then, thirdly, to what extent legal framework of data protection in Indonesia measures up to the adequate level of protection in Indonesia under Directive 95/46/EC. In line with the effort to answer the first research question, this thesis will try to identify any possibility for improvement towards the current adequacy finding system. Hence, a balance accommodation might be obtained and maintained between the one who requires the adequate level of protection and the one who has to fulfill it. This thesis will be structured as follows. The first chapter is the introduction in which the objective of this thesis is explained. In the second chapter, there will be a brief comparison between the Directive with other legal instruments concerning privacy and data protection. Afterwards, some explanations on the requirement of the adequate level of protection in the light of the Directive will be provided, including the measurement to be used in conducting the adequacy finding and will explore any possible solution if there is no adequate level of protection in the third country in question. Further, this chapter will cover the current problems within the Directive as well as possible suggestions to overcome them. Thus, answering the first and second research question. In the third chapter, relevant issues surrounding Indonesian legal framework will be discussed, including a brief explanation on how Indonesia regulates privacy and data protection as well as a number of the difficulties experienced in doing so. The findings in the second and third chapters shall be employed to carry out the examination in the fourth chapter, which objective is to answer the third research question. The chapter serves to analyze the adequate level of protection of Indonesian legal framework by applying the measurements in the light of the Directive. The analysis will include various potential problems faced by Indonesia on its effort to improve protection of personal data along with several suggestions on how to overcome them. At the final stage, there will be a conclusion, to what extent Indonesia can be deemed as providing an adequate level of protection. As a result, a solution on how Indonesia might improve its legal framework under the Directive to both avoid a lack of protection and offer an adequate level of protection will be achieved. 2. The EU Legal Framework regarding trans-border flow of Personal Data The trans-border flow of personal data is stipulated by regulations concerning data protection. Since the early eighties, several regulations, drawn up by different organizations, have been published in this respect. The first initiative was performed by Organization for Economic Co-operation and Development (OECD) by establishing the Guidelines on the Protection of Privacy and Trans-border Flows of Personal Data (the OECD Guidelines) in 1980. The intention of the Guidelines is to prevent any conflicts between national laws, which can hamper the free flow of personal data between the OECD Member States. This establishment brought an awareness of the importance protection of the trans-border flow of personal data. A similar purpose with the OECD Guidelines has brought the Member States of the Council of Europe (the CoE) to publish a convention on their interest in the following year. They agreed that it is needed to reconcile the fundamental values of the respect for privacy and the free flow of information between them. The agreement is stated in the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (CETS No. 108), with purpose to take into account the right of privacy and the increasing flow across frontiers of personal data in regards of automatic processing, as a way to extend the safeguards for everyones rights and fundamental freedoms. In 1990, by considering the UN has more Member States compared with the OECD and the CoE, Guidelines concerning Computerized Personal Data Files (the UN Guidelines) was established as a way to bring the principles on privacy and data protection being implemented wider among countries. The UN General Assembly through Resolution No. A/RES/45/95 on 14 December 1990, requests the Governments of every Member States to take into account this Guidelines in their legislation. Further, the governmental, intergovernmental, and non-governmental organizations are also requested to respect the Guidelines in carrying out the activities within their field of competence. Nonetheless, the OECD Guidelines, the CETS No. 108, and the UN Guidelines still have some weaknesses. There are some principles of data protection, which are required to be embedded in national laws of each of the Member States but there is no means for ensuring their effective application. For examples, there are no supervisory authority provision in the CETS No. 108 and a lack of procedural clauses in the OECD Guidelines. In another case, concerning the binding power of the instrument, the OECD Guidelines is voluntarily binding to its Member States as well as the UN Guidelines, even though the UN Guidelines has the supervision and sanction provisions. Therefore, Directive 95/46/EC on the Protection of Individuals with regard to the Processing of Personal Data and on the Free Movement of Such Data has been established by the European Union (the EU) to overcome the limited effect of the two Guidelines and the Convention as mentioned above. Good level of compliance, support and help to individual data subject, and appropriate redress to the injured parties are the means used by the Directive for ensuring the effective application of the content of the rules. Apart from the compliance issue, the obligations and rights set down in the Directive are built upon the OECD Guidelines, the CETS No. 108, and the UN Guidelines. These three legal instruments contain similar principles, except for lawfulness, fairness, and non-discrimination principles are from the UN Guidelines; and special categories of data and additional safeguards for the data subject principles are from the ECTS No. 108. While the rest of the adopted principles are collection limitation, data quality, purpose specification, use limitation, security safeguard, openness, individual participation, and accountability. Further, the aims of the Directive can be seen from two perspectives. The first one is the economical perspective, in relation to the establishment and functioning of an internal market, in which to ensure the free movement of goods, persons, services, and capital, including the free movement of personal data. The second is from the fundamental rights perspective, in which to set the rules for high-level data protection to ensure the protection of the fundamental rights of the individuals. The newest legal instrument concerning privacy and data protection is the APEC Privacy Framework 2004 (the Framework), established by Asia-Pacific Economic Cooperation (APEC). The purpose of the Framework is to ensure there are no barriers for information flows among the APEC Member Economies by promoting a consistent approach to data protection. There are nine principles in the Framework that are built based on the OECD Guidelines. In brief, the adopted principles are preventing harm, notice, collection limitation, uses of personal information, choice, integrity of personal information, security safeguard, access and correction, and accountability. However, this Framework has the same weakness as the previous legal instruments on privacy and data protection before the Directive, which is the absent of means for ensuring the effective application of the principles. Additionally, it should be noted that APEC is a forum that established based on a voluntary basis, without any constitut ion or legally binding obligations for the Member Economies. Hence, the Framework is not binding to the Member Economies. From the brief analysis above, currently, the Directive posses the highest level of protection compared with other existing legal instruments on privacy and data protection. In this respect, to achieve the objective of this thesis as stated in the first chapter, the research questions will be answered by focusing on the Directive. Therefore, in the next section, there will be an explanation on the legal bases of trans-border flow of personal data to third countries under the Directive, followed by a rationalization on how the European Commission (EC) determines whether or not an adequate level of protection exists in the third country in question. Subsequently, the means for ensuring the effective application of the content of rules will be elaborated upon a description on a series of possibilities if the third country in question is not deemed to provide an adequate level of protection. Although currently, the Directive provides high-level of protection, some problems and suggestions will be provided, as an effort to address input for improvement. The findings in this chapter will be used to carry out the adequacy finding of Indonesia as a third country (in the fourth chapter) by doing a comparison with the findings on Indonesian legal framework in chapter three. 2. The Legal Bases of Trans-border Flows of Personal Data to Third Countries The trans-border flow of personal data to a third country to be acknowledged as lawful, it has to be conducted in accordance with the national data protection law of the EU/EEA Member States. It is applicable to the data controllers established in the EU, both at the time when data is being collected and processed. In general, the law consists of a combination between the obligations of data controllers and the rights of data subject. Before the establishment of the Directive, these rights and obligations were regulated under some national data protection laws with different level of protection. In the light of the functioning of internal market in the EU/EEA, all these obligations and rights, including certain procedures to be applied in case of trans-border flow of personal data to a third country, are regulated in the Directive. Whereas the Directive is legally binding to the EU/EEA Member States, an adequate level of protection is fulfilled and consequently trans-border flow of personal data is able to take place among them. Further, when the personal data is used for electronic communication purposes, then the rights and obligations as lay down in Directive 2002/58/EC shall take place. There are three possible types of transfer under the Directive. The first and second types are a communication of personal data by a data controller based in the EU/EEA Member States to another data controller or to a processor based in a third country. Another possibility type is a communication of personal data by a data subject based in the EU/EEA Member States to a data controller based in a third country. Nevertheless, it should noted that the Directive does not cover transfers of personal data in the course of judicial and police cooperation activities falling within Titles V and VI of the Treaty on European Union. The main regulation in the Directive concerning trans-border flow of personal data to a third country is Article 25. The first paragraph of the Article sets out the principle that the EU/EEA Member States shall allow the transfer of personal data only if the third country in question ensures an adequate level of protection. From this provision, it is necessary to explain further on the subject of the transfer of personal data and an adequate level of protection. First, what the Directive means by the transfer of personal data. Undoubtedly, it is often associated with the act of sending or transmitting personal data from one country to another, for instance by sending paper or electronic documents containing personal data by post or e-mail. By seeing from a different perspective, the situation where one conducts a certain activity with the purpose to make data available for others, besides the owner of the data (the data subject), and located in another country, is included as a trans-border flow of personal data. However, by making data accessible for everyone who connects to internet by uploading any personal data on internet web pages, even though that person is located in another country, is not included in the meaning of transfer of personal data to another country. The reason for the previous statement is this kind of activity is properly acknowledged as publishing activity, not transferring activity. This exception is stated clearly by the Court of Justice in the Bodil Lindqvist Case as there is no transfer of personal data to a third country where an individual in a Member State loads personal data onto an internet page making those data accessible to anyone who connects to the internet, including people in a third country. Subsequently, since the Directive is binding to 27 EU Member States, including three countries (Norway, Liechtenstein, and Iceland), which are bound by the Directive by virtue of the European Economic Area agreement (EEA), personal data can flow freely among them. In other words, there is a free zone among the EU/EEA member states. Therefore, transfer in the light of the Directive has to be seen as transfer of personal data from EU/EEA member states to other countries outside EU/EEA, which are recognized as third countries, and the adequate level of protection in those third countries has to be assessed. There is a so-called white list of countries, which have been assessed by the EC and affirmed to provide an adequate level of protection according to the Directive. Currently, the list consists of seven countries as follows: Argentina, Canada (limited to private sector data), Switzerland, United States (Safe Harbor and specific type of transfer: Passenger Name Record/PNR), the Bailiwick of Guernsey, the Isle of Man, and the Bailiwick of Jersey. The approval of adequacy shall be analyzed more carefully because once a country is listed in the white list, does not automatically mean that personal data can flow to the country freely. One should pay attention whether the affirmation is given for the entire legal framework or only for certain part of it in a specific field, sector (public or private), or regarding a specific type of transfer. Insofar, even though the result of adequacy finding shows that the data protection level in certain countries is not adequate, the EC will not create a black list for that negative finding because of political consequences. Instead of the black list, the EC tends to enter into negotiation with the certain country in order to find a solution. It can be concluded from the foregoing, that the adequacy finding is temporary and subject to be reviewed. Procedure of the Adequacy Finding In acknowledging the adequacy finding, the EC has to follow certain procedure, which has been determined in Article 25 Paragraph (6) of the Directive and is known as comitology. At first, there will be a proposal from the EC, followed by an opinion from Article 29 Working Party and an opinion from Article 31 Management Committee, which needs to be delivered by a qualified majority of member states. Afterwards, the EC submits the proposed finding to the European Parliament (EP), who will examine whether the EC has used its executing powers correctly and comes up with recommendation if necessary. As a final point, the EC then can formally issue the result of the adequacy finding. In the next section, the measurements used by the EC in conducting the finding will be explained in detail. 3. Assessing the Adequate Level of Protection The Article 29 Working Party has given an obvious statement thatany meaningful analysis of adequate protection must comprise the two basic elements: the content of the rules applicable and the means for ensuring their effective application.According to WP 12 of the European Commission (EC), a set of content principles that should be embodied in the existing regulations are the following: Purpose limitation principle: data should be processed for a specific purpose and subsequently used or further communicated only if it is compatible with the purpose of the transfer. Data quality and proportionality principle: data should be accurate and, where necessary, kept up to date. Transparency principle: individuals should be provided with information as to the purpose of the processing, the identity of the data controller in the third country and other necessary information to ensure fairness. Security principle: technical and organizational measures should be taken by the data controller that are appropriate to the risks presented by the processing. Rights of access, rectification and opposition: the data subject have the right to obtain a copy of all data relating to him/her that are processed, to rectification of those data that are shown to be inaccurate, and be able to object to the processing of the data. Restrictions on onwards transfers to non-parties to the contract: further transfers of the personal data by the recipient of the original data transfer only permitted if the second recipient provides an adequate level of protection. In addition to these content principles, another set of the means for ensuring the effective application of the principles, whether judicial or non-judicial, are required in order to fulfill the following objectives: Good level of compliance with the rules: the level of awareness of controllers and data subjects and the existence of effective and dissuasive sanctions are the measurements to examine the compliance level, including direct verification by authorities, auditors, or independent data protection officials. Support and help to individual data subjects: an individual should be able to enforce his/her rights rapidly and effectively without prohibitive cost. Institutional mechanism is needed to conduct independent investigation of complaints. Appropriate redress to the injured parties: where rules are not complied, redress to the injured party with independent adjudication or arbitration is provided, including compensation and sanction impose. Beyond the content principles, some additional principles are still needed to consider when it comes to certain types of processing. Additional safeguards when sensitive categories of data are involved and a right to opt-out when data are processed for direct marketing purposes should be in place. Another principle is the right for the data subject not to be a subject to an automated individual decision that intended to evaluate certain aspects, which can give any legal effects and have a significant effect to the data subject. These content principles, including additional principles, and the means for ensuring their effectiveness should be viewed as a minimum requirement in assessing the adequate level of protection in all cases. However, according to Article 25 Paragraph 2 of the Directive, in some cases, there will be two possibilities. There is a need to add the list with more requirements or to reduce it. To determine whether some requirements need to be added or reduced, the degree of risk that the transfer poses to the data subject becomes an important factor. The Article 29 Working Party has provided a list of categories of transfer, which poses particular risks to privacy, as mentioned below: Transfers involving certain sensitive categories of data as defined by Article 8 of the Directive Transfers which carry the risk of financial loss (e.g., credit card payments over the internet) Transfers carrying a risk to personal safety Transfers made for the purpose of making a decision which significantly affects the individual (e.g., recruitment or promotion decisions, the granting of credit, etc) Transfers which carry a risk of serious embarrassment or tarnishing of an individuals reputation Transfers which may result in specific actions which constitute a significant intrusion into an individuals private life (e.g., unsolicited telephone calls) Repetitive transfers involving massive volumes of data (e.g., transactional data processed over telecommunications networks, the Internet, etc.) Transfers involving the collection of data in a particularly covert or clandestine manner (e.g., internet cookies) To sum up, the circumstances should be taken into account when assessing adequacy in a specific case, being: the nature of the data the purpose and duration of the proposed processing operations the country of origin and the country of final destination the rules of law, both general and sectoral, in force in the country in question the professional rules and the security measures which are complied with in that country. Self -regulation From the circumstances as referred to Article 25 Paragraph 2 of the Directive, it can be seen that the assessments of the adequate level of protection is conducted according to the rules of law as well as the professional rules and the security measures. In other words, it has to be examined from a self-regulation perspective as well. The Article 29 Working Party presents a broad meaning of self-regulation asany set of data protection rules applying to a plurality of the data controllers from the same profession or industry sector, the content of which has been determined primarily by members of the industry or profession concerned.This wide definition offers the possibility to on the one hand a voluntary data protection code developed by a small industry association with only a few members and on the other hand a set of codes of professional ethics with quasi judicial force for a certain profession, such as doctors or bankers. Still, one should bear in mind, to be considered as an appropriate legal instrument to be analyzed, it has to have binding power to its members and has to provide adequate safeguards if the personal data are transferred again to non-member entities. Ob Development of Electronic Data Flows Development of Electronic Data Flows 1. Introduction The current development on the flow of electronic data, especially those relating to personal data across nations is increasing daily. Most of the flows are related to business activities whereas services are provided to fulfill the needs of people. It also leads to the transformation of commerce, which becomes worldwide and increasingly international. The transfer of huge quantities of data, relating to customers and employees, are required and often occurred among entities that located in different countries. An example would be the system of outsourcing, a practice in which companies and governments hire an external service provider in another country to deliver a program or provide a service, such as managing database of human resources or customers. This can often result in improved efficiencies and levels of services. Further, the advancement of global networks, such as the internet, provides the possibilities to collect, process, and distribute personal data on an unprecedente d scale. However, the trans-border flow of personal data is not only performed by companies or governments but also conducted by individuals in everyday life as well. When the data is used by companies or government, this can represent a high volume of data, such as in the form of the transfer of databases. There will be a quite different volume of data when it is provided by individuals when they disclose their personal data while participating in particular activities, such as browsing the internet or registering on various websites to obtain certain services. Additionally, there is a strong possibility for individuals, who are engaging in data transfer activities to lack of full awareness concerning what could be done to their personal data. In some instances, they do not realize that they have disclosed their personal data and it is subject to transmission and processing within countries not offering the same level of protection as their own country. For example, a student physically located in the Netherlands may complete an online game registration form, containing several spaces soliciting his/her identities, not knowing that the actual service provider is registered in India. Another example, a social worker residing within the United Kingdom might disclose his/her personal data on a web application for an internet banking service provided by a bank based in the United States. From the short description above, the trans-border flow of personal data exists in everyday life on a daily basis and it becomes a vital need of every stakeholder, whether governments or private sectors, including individuals. Nevertheless, while the flow has led to greater efficiencies and economic benefits, on the other hand this kind of flow has also raised concerns that some information could end up in the hands of people for whom it was not intended. Worse even is the situation when no one has realized the flow has taken place, spawning a great opportunity for infringement upon ones privacy rights. Some rules concerning privacy and data protection have been set up at national, regional, and international levels to guarantee privacy as one of the human rights is not harmed by any activity, including data processing as the final purpose of trans-border flow. Consequently, the trans-border flow of personal data has to be conducted in a lawful manner. In this respect, a legal framework on trans-border flow of personal data has been enacted in Europe by the European Commission (EC) under two directives. The first one is Directive 95/46/EC concerning the Protection of Individuals with Regard to the Processing of Personal Data and on the Free Movement of Such Data. This Directive has been further equipped by the second directive, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications). In relation to the research objective of this thesis, Directive 95/46/EC is the most relevant and therefore, Directive 2002/58/EC will be referred to when necessary. It should be noted that whenever a term the Directive is being used in this thesis, the term shall refer to Directive 95/46/EC. Under the Directive, a main rule concerning the trans-border flow of personal data has been set up. These include the obligation of data controller to use personal data for specified, explicit, and legitimate purposes, to collect only relevant and necessary data, to guarantee the security of the data against accidental or unauthorized access or manipulation, and in specific cases to notify the competent independent supervisory body before carrying out all or certain types of data processing operations. On the other hand, there is a series of rights for individuals as data subject, such as the right to receive certain information whenever data is collected, to access and correct the data, and to object to certain types of data processing. Nevertheless, all of the practice of these rights and obligations present a significant problem when the trans-border flow of personal data takes place from the European Union/European Economic Area (the EU/EEA) Member States to countries outside the EU/EEA, for the reason that the Directive requires an adequate level of protection in the destination countries. The transfer of personal data to a third country is prohibited when the third country does not have an adequate level of protection to ensure that the processing of personal data will not cause any violation to the rights of data subjects. The binding power of the Directive to the EU/EEA Member States requires each of the Member States to embed the provisions in the Directive into their national legal system. Thus, there is a free zone where trans-border flow of personal data can take place freely among the Member States because they provide the adequate level of protection. Any approval, adequate safeguard, or additional requirement is not necessary to any further extent. As far as public international law is concerned, by applying the extra-territoriality principle, the requirement of the adequacy is automatically fulfilled at the official representatives of the EU/EEA Member States in the third country, such as the Embassy or Consulate General because of the extended jurisdiction of the Member States. However, this principle is not extended to private sectors, since subsidiary offices of multinational companies, still have to abide to the national law in the third country although the base of operations of the company is located in the EU/EEA Member States. In this case, the adequate level of protection is still required even though the transfer is conducted internally among the subsidiaries of the company located in third countries. Currently, the EC has conducted some adequacy findings and has compiled a white list of countries providing an adequate level of protection. This approval means the trans-border flow of personal data can take place as in the free zone between the EU/EEA Member States. However, to date, the white list covers a limited list of countries, seven to be exact. This list might not prove too sufficient from the point of view of multinational companies in accommodating their interest, as it does not include many countries of growing commercial interest. From this point of view, there is a need to harmonize various privacy and data protection regulations in many countries through the establishment of an internationally congruent legal framework for privacy and data protection. Unfortunately, it will take some effort and time for the establishment, while a fast solution is needed. By considering the Directive thus far the strictest legal framework compared with other existing legal framework on privacy and data protection, obviously, there is a need for countries outside the EU/EEA Member States to improve their legal framework to become compliance with adequate level of protection requirement under the Directive. Since Indonesia is neither a Member State of the EU/EEA nor included in the white list of adequacy finding, the requirement of adequate level of protection is applied to Indonesia as a third country. The trans-border flow of personal data only can take place after the data controller is certain that the protection level of personal data in Indonesia is adequate under the Directive. Apparently, Indonesia is needed to criticize, whether or not its legal framework providing an adequate level of protection. Moreover, Indonesia as a Member State of the Asia-Pacific Economic Cooperation (APEC) has received a pressure to provide a sufficient level of protection on trans-border flow of personal data, in relation to the existence of the APEC Privacy Framework. This pressure has become heavier because of Indonesia position as the Association of South East Asian Nations/ASEAN Member States. Therefore, the main objective of this thesis is to examinehow Indonesia can improve its legal framework to comply with the adequate level of protection in view of Directive 95/46/EC. Conducting this examination is important in determining ways Indonesia might be developed into an attractive destination country for international commerce activities. In order to answer the objective of this thesis, three research questions have to be answered: firstly,currently, why Directive 95/46/EC is being acknowledged as the strictest legal instrument concerning privacy and data protection on conducting trans-border flow of personal data compared with other existing legal instruments. Secondly, how the European Commission determines the adequate level of protection in the third country in question under Directive 95/46/EC. Then, thirdly, to what extent legal framework of data protection in Indonesia measures up to the adequate level of protection in Indonesia under Directive 95/46/EC. In line with the effort to answer the first research question, this thesis will try to identify any possibility for improvement towards the current adequacy finding system. Hence, a balance accommodation might be obtained and maintained between the one who requires the adequate level of protection and the one who has to fulfill it. This thesis will be structured as follows. The first chapter is the introduction in which the objective of this thesis is explained. In the second chapter, there will be a brief comparison between the Directive with other legal instruments concerning privacy and data protection. Afterwards, some explanations on the requirement of the adequate level of protection in the light of the Directive will be provided, including the measurement to be used in conducting the adequacy finding and will explore any possible solution if there is no adequate level of protection in the third country in question. Further, this chapter will cover the current problems within the Directive as well as possible suggestions to overcome them. Thus, answering the first and second research question. In the third chapter, relevant issues surrounding Indonesian legal framework will be discussed, including a brief explanation on how Indonesia regulates privacy and data protection as well as a number of the difficulties experienced in doing so. The findings in the second and third chapters shall be employed to carry out the examination in the fourth chapter, which objective is to answer the third research question. The chapter serves to analyze the adequate level of protection of Indonesian legal framework by applying the measurements in the light of the Directive. The analysis will include various potential problems faced by Indonesia on its effort to improve protection of personal data along with several suggestions on how to overcome them. At the final stage, there will be a conclusion, to what extent Indonesia can be deemed as providing an adequate level of protection. As a result, a solution on how Indonesia might improve its legal framework under the Directive to both avoid a lack of protection and offer an adequate level of protection will be achieved. 2. The EU Legal Framework regarding trans-border flow of Personal Data The trans-border flow of personal data is stipulated by regulations concerning data protection. Since the early eighties, several regulations, drawn up by different organizations, have been published in this respect. The first initiative was performed by Organization for Economic Co-operation and Development (OECD) by establishing the Guidelines on the Protection of Privacy and Trans-border Flows of Personal Data (the OECD Guidelines) in 1980. The intention of the Guidelines is to prevent any conflicts between national laws, which can hamper the free flow of personal data between the OECD Member States. This establishment brought an awareness of the importance protection of the trans-border flow of personal data. A similar purpose with the OECD Guidelines has brought the Member States of the Council of Europe (the CoE) to publish a convention on their interest in the following year. They agreed that it is needed to reconcile the fundamental values of the respect for privacy and the free flow of information between them. The agreement is stated in the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (CETS No. 108), with purpose to take into account the right of privacy and the increasing flow across frontiers of personal data in regards of automatic processing, as a way to extend the safeguards for everyones rights and fundamental freedoms. In 1990, by considering the UN has more Member States compared with the OECD and the CoE, Guidelines concerning Computerized Personal Data Files (the UN Guidelines) was established as a way to bring the principles on privacy and data protection being implemented wider among countries. The UN General Assembly through Resolution No. A/RES/45/95 on 14 December 1990, requests the Governments of every Member States to take into account this Guidelines in their legislation. Further, the governmental, intergovernmental, and non-governmental organizations are also requested to respect the Guidelines in carrying out the activities within their field of competence. Nonetheless, the OECD Guidelines, the CETS No. 108, and the UN Guidelines still have some weaknesses. There are some principles of data protection, which are required to be embedded in national laws of each of the Member States but there is no means for ensuring their effective application. For examples, there are no supervisory authority provision in the CETS No. 108 and a lack of procedural clauses in the OECD Guidelines. In another case, concerning the binding power of the instrument, the OECD Guidelines is voluntarily binding to its Member States as well as the UN Guidelines, even though the UN Guidelines has the supervision and sanction provisions. Therefore, Directive 95/46/EC on the Protection of Individuals with regard to the Processing of Personal Data and on the Free Movement of Such Data has been established by the European Union (the EU) to overcome the limited effect of the two Guidelines and the Convention as mentioned above. Good level of compliance, support and help to individual data subject, and appropriate redress to the injured parties are the means used by the Directive for ensuring the effective application of the content of the rules. Apart from the compliance issue, the obligations and rights set down in the Directive are built upon the OECD Guidelines, the CETS No. 108, and the UN Guidelines. These three legal instruments contain similar principles, except for lawfulness, fairness, and non-discrimination principles are from the UN Guidelines; and special categories of data and additional safeguards for the data subject principles are from the ECTS No. 108. While the rest of the adopted principles are collection limitation, data quality, purpose specification, use limitation, security safeguard, openness, individual participation, and accountability. Further, the aims of the Directive can be seen from two perspectives. The first one is the economical perspective, in relation to the establishment and functioning of an internal market, in which to ensure the free movement of goods, persons, services, and capital, including the free movement of personal data. The second is from the fundamental rights perspective, in which to set the rules for high-level data protection to ensure the protection of the fundamental rights of the individuals. The newest legal instrument concerning privacy and data protection is the APEC Privacy Framework 2004 (the Framework), established by Asia-Pacific Economic Cooperation (APEC). The purpose of the Framework is to ensure there are no barriers for information flows among the APEC Member Economies by promoting a consistent approach to data protection. There are nine principles in the Framework that are built based on the OECD Guidelines. In brief, the adopted principles are preventing harm, notice, collection limitation, uses of personal information, choice, integrity of personal information, security safeguard, access and correction, and accountability. However, this Framework has the same weakness as the previous legal instruments on privacy and data protection before the Directive, which is the absent of means for ensuring the effective application of the principles. Additionally, it should be noted that APEC is a forum that established based on a voluntary basis, without any constitut ion or legally binding obligations for the Member Economies. Hence, the Framework is not binding to the Member Economies. From the brief analysis above, currently, the Directive posses the highest level of protection compared with other existing legal instruments on privacy and data protection. In this respect, to achieve the objective of this thesis as stated in the first chapter, the research questions will be answered by focusing on the Directive. Therefore, in the next section, there will be an explanation on the legal bases of trans-border flow of personal data to third countries under the Directive, followed by a rationalization on how the European Commission (EC) determines whether or not an adequate level of protection exists in the third country in question. Subsequently, the means for ensuring the effective application of the content of rules will be elaborated upon a description on a series of possibilities if the third country in question is not deemed to provide an adequate level of protection. Although currently, the Directive provides high-level of protection, some problems and suggestions will be provided, as an effort to address input for improvement. The findings in this chapter will be used to carry out the adequacy finding of Indonesia as a third country (in the fourth chapter) by doing a comparison with the findings on Indonesian legal framework in chapter three. 2. The Legal Bases of Trans-border Flows of Personal Data to Third Countries The trans-border flow of personal data to a third country to be acknowledged as lawful, it has to be conducted in accordance with the national data protection law of the EU/EEA Member States. It is applicable to the data controllers established in the EU, both at the time when data is being collected and processed. In general, the law consists of a combination between the obligations of data controllers and the rights of data subject. Before the establishment of the Directive, these rights and obligations were regulated under some national data protection laws with different level of protection. In the light of the functioning of internal market in the EU/EEA, all these obligations and rights, including certain procedures to be applied in case of trans-border flow of personal data to a third country, are regulated in the Directive. Whereas the Directive is legally binding to the EU/EEA Member States, an adequate level of protection is fulfilled and consequently trans-border flow of personal data is able to take place among them. Further, when the personal data is used for electronic communication purposes, then the rights and obligations as lay down in Directive 2002/58/EC shall take place. There are three possible types of transfer under the Directive. The first and second types are a communication of personal data by a data controller based in the EU/EEA Member States to another data controller or to a processor based in a third country. Another possibility type is a communication of personal data by a data subject based in the EU/EEA Member States to a data controller based in a third country. Nevertheless, it should noted that the Directive does not cover transfers of personal data in the course of judicial and police cooperation activities falling within Titles V and VI of the Treaty on European Union. The main regulation in the Directive concerning trans-border flow of personal data to a third country is Article 25. The first paragraph of the Article sets out the principle that the EU/EEA Member States shall allow the transfer of personal data only if the third country in question ensures an adequate level of protection. From this provision, it is necessary to explain further on the subject of the transfer of personal data and an adequate level of protection. First, what the Directive means by the transfer of personal data. Undoubtedly, it is often associated with the act of sending or transmitting personal data from one country to another, for instance by sending paper or electronic documents containing personal data by post or e-mail. By seeing from a different perspective, the situation where one conducts a certain activity with the purpose to make data available for others, besides the owner of the data (the data subject), and located in another country, is included as a trans-border flow of personal data. However, by making data accessible for everyone who connects to internet by uploading any personal data on internet web pages, even though that person is located in another country, is not included in the meaning of transfer of personal data to another country. The reason for the previous statement is this kind of activity is properly acknowledged as publishing activity, not transferring activity. This exception is stated clearly by the Court of Justice in the Bodil Lindqvist Case as there is no transfer of personal data to a third country where an individual in a Member State loads personal data onto an internet page making those data accessible to anyone who connects to the internet, including people in a third country. Subsequently, since the Directive is binding to 27 EU Member States, including three countries (Norway, Liechtenstein, and Iceland), which are bound by the Directive by virtue of the European Economic Area agreement (EEA), personal data can flow freely among them. In other words, there is a free zone among the EU/EEA member states. Therefore, transfer in the light of the Directive has to be seen as transfer of personal data from EU/EEA member states to other countries outside EU/EEA, which are recognized as third countries, and the adequate level of protection in those third countries has to be assessed. There is a so-called white list of countries, which have been assessed by the EC and affirmed to provide an adequate level of protection according to the Directive. Currently, the list consists of seven countries as follows: Argentina, Canada (limited to private sector data), Switzerland, United States (Safe Harbor and specific type of transfer: Passenger Name Record/PNR), the Bailiwick of Guernsey, the Isle of Man, and the Bailiwick of Jersey. The approval of adequacy shall be analyzed more carefully because once a country is listed in the white list, does not automatically mean that personal data can flow to the country freely. One should pay attention whether the affirmation is given for the entire legal framework or only for certain part of it in a specific field, sector (public or private), or regarding a specific type of transfer. Insofar, even though the result of adequacy finding shows that the data protection level in certain countries is not adequate, the EC will not create a black list for that negative finding because of political consequences. Instead of the black list, the EC tends to enter into negotiation with the certain country in order to find a solution. It can be concluded from the foregoing, that the adequacy finding is temporary and subject to be reviewed. Procedure of the Adequacy Finding In acknowledging the adequacy finding, the EC has to follow certain procedure, which has been determined in Article 25 Paragraph (6) of the Directive and is known as comitology. At first, there will be a proposal from the EC, followed by an opinion from Article 29 Working Party and an opinion from Article 31 Management Committee, which needs to be delivered by a qualified majority of member states. Afterwards, the EC submits the proposed finding to the European Parliament (EP), who will examine whether the EC has used its executing powers correctly and comes up with recommendation if necessary. As a final point, the EC then can formally issue the result of the adequacy finding. In the next section, the measurements used by the EC in conducting the finding will be explained in detail. 3. Assessing the Adequate Level of Protection The Article 29 Working Party has given an obvious statement thatany meaningful analysis of adequate protection must comprise the two basic elements: the content of the rules applicable and the means for ensuring their effective application.According to WP 12 of the European Commission (EC), a set of content principles that should be embodied in the existing regulations are the following: Purpose limitation principle: data should be processed for a specific purpose and subsequently used or further communicated only if it is compatible with the purpose of the transfer. Data quality and proportionality principle: data should be accurate and, where necessary, kept up to date. Transparency principle: individuals should be provided with information as to the purpose of the processing, the identity of the data controller in the third country and other necessary information to ensure fairness. Security principle: technical and organizational measures should be taken by the data controller that are appropriate to the risks presented by the processing. Rights of access, rectification and opposition: the data subject have the right to obtain a copy of all data relating to him/her that are processed, to rectification of those data that are shown to be inaccurate, and be able to object to the processing of the data. Restrictions on onwards transfers to non-parties to the contract: further transfers of the personal data by the recipient of the original data transfer only permitted if the second recipient provides an adequate level of protection. In addition to these content principles, another set of the means for ensuring the effective application of the principles, whether judicial or non-judicial, are required in order to fulfill the following objectives: Good level of compliance with the rules: the level of awareness of controllers and data subjects and the existence of effective and dissuasive sanctions are the measurements to examine the compliance level, including direct verification by authorities, auditors, or independent data protection officials. Support and help to individual data subjects: an individual should be able to enforce his/her rights rapidly and effectively without prohibitive cost. Institutional mechanism is needed to conduct independent investigation of complaints. Appropriate redress to the injured parties: where rules are not complied, redress to the injured party with independent adjudication or arbitration is provided, including compensation and sanction impose. Beyond the content principles, some additional principles are still needed to consider when it comes to certain types of processing. Additional safeguards when sensitive categories of data are involved and a right to opt-out when data are processed for direct marketing purposes should be in place. Another principle is the right for the data subject not to be a subject to an automated individual decision that intended to evaluate certain aspects, which can give any legal effects and have a significant effect to the data subject. These content principles, including additional principles, and the means for ensuring their effectiveness should be viewed as a minimum requirement in assessing the adequate level of protection in all cases. However, according to Article 25 Paragraph 2 of the Directive, in some cases, there will be two possibilities. There is a need to add the list with more requirements or to reduce it. To determine whether some requirements need to be added or reduced, the degree of risk that the transfer poses to the data subject becomes an important factor. The Article 29 Working Party has provided a list of categories of transfer, which poses particular risks to privacy, as mentioned below: Transfers involving certain sensitive categories of data as defined by Article 8 of the Directive Transfers which carry the risk of financial loss (e.g., credit card payments over the internet) Transfers carrying a risk to personal safety Transfers made for the purpose of making a decision which significantly affects the individual (e.g., recruitment or promotion decisions, the granting of credit, etc) Transfers which carry a risk of serious embarrassment or tarnishing of an individuals reputation Transfers which may result in specific actions which constitute a significant intrusion into an individuals private life (e.g., unsolicited telephone calls) Repetitive transfers involving massive volumes of data (e.g., transactional data processed over telecommunications networks, the Internet, etc.) Transfers involving the collection of data in a particularly covert or clandestine manner (e.g., internet cookies) To sum up, the circumstances should be taken into account when assessing adequacy in a specific case, being: the nature of the data the purpose and duration of the proposed processing operations the country of origin and the country of final destination the rules of law, both general and sectoral, in force in the country in question the professional rules and the security measures which are complied with in that country. Self -regulation From the circumstances as referred to Article 25 Paragraph 2 of the Directive, it can be seen that the assessments of the adequate level of protection is conducted according to the rules of law as well as the professional rules and the security measures. In other words, it has to be examined from a self-regulation perspective as well. The Article 29 Working Party presents a broad meaning of self-regulation asany set of data protection rules applying to a plurality of the data controllers from the same profession or industry sector, the content of which has been determined primarily by members of the industry or profession concerned.This wide definition offers the possibility to on the one hand a voluntary data protection code developed by a small industry association with only a few members and on the other hand a set of codes of professional ethics with quasi judicial force for a certain profession, such as doctors or bankers. Still, one should bear in mind, to be considered as an appropriate legal instrument to be analyzed, it has to have binding power to its members and has to provide adequate safeguards if the personal data are transferred again to non-member entities. Ob

Monday, August 5, 2019

Dynamics of Two Dimensional Projectile Motion

Dynamics of Two Dimensional Projectile Motion Experiment: Study of Projectile Motion SUMMARY Moving an object in a bilaterally symmetrical, parabolic path is called Projectile motion. The path followed by the object is called its trajectory (Boundless, 2014). Some of examples are as follows:- Firstly, projectile is dropping object from rest position; secondly, an object thrown vertically upward is also called projectile in the end, an object which is thrown at an angle upward to the horizontal is also a projectile (providing effect of air resistance is negligible). Furthermore, in projectile object that once projected or dropped remains in motion by its own inertia and is inclined only by the downward force of gravity (Anonymous, 1996). KEY POINTS OF PROJECTILE MOTION: Time of Flight, T: The time of flight depends upon two things that are angle of projection and initial velocity of an object. Moreover, the vertical displacement of an object will be zero when the point of projection and return will be on the same horizontal surface (Boundless, 2014). Symmetry: If the point of projection and return occur along the same horizontal surface means current motion is symmetrical in the vertical plane (Boundless, 2014). Maximum Height, H: When the vertical component of velocity, vy, will be equals to zero shows the maximum height of an object. Projectile goes against gravity as it moves up, so the velocity decelerates likewise velocity accelerates downward under gravity (Boundless, 2014). Range of the Projectile, R: Displacement in the horizontal direction is called range. Acceleration is absent in this direction and the line of range shown when gravity only acts vertically (Boundless, 2014). As shown in this image, range of projectile is independent of the forces of gravity (Boundless, 2014). OBJECTIVES The purpose of this experiment was to analyze the dynamics of two dimensional projectile motion. Moreover, this was done by providing a ball with a horizontal velocity and measuring the time of flight and range. Furthermore, check the systematic errors in the data by comparing the values of vertical and horizontal acceleration. PRIMARY OBJECTIVE: To follow the two dimensional motion of an object and to determine that the motion can be analyzed by considering the motion in each dimension separately. SECONDARY OBJECTIVE: To check the existing possible systematic errors by comparing the horizontal acceleration with expected value of zero and vertical acceleration with the accepted value for g. THEORY Figure above is showing the experimental setup displaying measured values of initial height, range and time of flight The ball According to the Newton’s first law of motion, there will be no acceleration in horizontal direction, unless a horizontally directed force acts on the ball. Ignoring the air friction, only force acting on the ball during flights is the force of gravity. The range is the horizontal distance, x, between the hooter of the launcher and the place where the ball lands. The range is given by x = (v0 cos à ¸) t, Where v0 is the initial speed of the ball as it leaves the hooter, à ¸ is the angle of inclination above the horizontal, and t is the time of flight. If the ball is shot horizontally (à ¸ = 0), then the cos à ¸ = 1 and the range is given by x = v0 t. The time of flight will be t = x / v0 [Equation 1] The vertical distance, y, that the ball falls in time t is given by y = v0y t + 1/2 g t2 where v0y = 0 thus giving y = 1/2 g t2. Substituting for time, t with equation [1] will yield EXPERIMENTAL METHOD Equipment required: 1: Science Workshop Interface 2: A photo gate motion sensor 3: Time-of-flight timing sensor pad 4: Projectile Launcher 5: A plastic ball 6: Measuring tape Experimental procedure: Firstly, set up the angle that you have to launch by using the protractor; angles are 0, 30 or 60. Secondly, with the help of ramrod set the ball into the launcher. Moreover, the most important point is setting the right range that you wanted to calculate that is short, medium or long range. After that adjust the time of flight sensor pad, open the software â€Å"Projectile Motion† on computer and activate the application. By pulling the trigger launch the ball; note the reading for the time of flight from computer and then by using ruler measure the range. Take measurements three times for each range (short, medium, long range). Furthermore repeat the same process and take measurements three times for each angle (short range at 30 and 60). QUESTION/ANSWERS How do the values for the time of flight for short, medium and long range distances compare when the ball was launched horizontally? Also compare the values with the theoretical value of time of flight at 0. How do the values for the time of flight in horizontal, 30 and 60 launch compare when the ball was launched (in short range)? DISCUSSION Object moving in both motions that is falling free under gravity and moving both in horizontal direction is called as projectile motion; both the vertical and horizontal motions occur simultaneously but they don’t depend on each other. Moreover, after inputting the diameter of the ball into Data Studio we began our first shot at angle 0 and then according to that adjusted the landing pad to start collecting data. Furthermore, during this process we were making sure that the launcher speed remains same in every shot and also its angle; there were no problems in recording the data. CONCLUSION Projectile motion is two dimensional motion under constant acceleration due to gravity. Moreover, it is not necessary that an object should be thrown with some initial velocity in the horizontal direction; it is clear that there is a relationship between the angle of takeoff and the distance from which ball is thrown. Furthermore, the motion of a projectile can be studied easily by resolving it into horizontal and vertical components which are independent of each other. STUDENT’S SUGGESTION We have learned many things from this experiment like to calculate total time of the flight of an object and the prediction of landing point of a projectile. Moreover, Projectile motion helps in hitting the target. In addition, some of the real life examples are as follows: A golfer needs to know at what angle above the ground the golf ball should travel to reach closer to the golf pot, there are many applications of a projectile. Real life applications of projectile include bullets on a straight spinning flight, rockets, and missiles. Furthermore, football kicked off by a player, a ball thrown by a cricketer and a missile fired from launching pad, all projected at some angles with the horizontal, are called projectiles. References Anonymous. (1996). the Physics Classroom. Retrieved 03 28, 2015, from physicsclassroom.com: http://www.physicsclassroom.com/class/vectors/Lesson-2/What-is-a-Projectile Boundless. (2014, 12 12). Key Points: Range, Symmetry, Maximum Height. Retrieved 03 24, 2015, from boundless.com: https://www.boundless.com/physics/textbooks/boundless-physics-textbook/two-dimensional-kinematics-3/projectile-motion-42/key-points-range-symmetry-maximum-height-230-11284/ http://amrita.vlab.co.in/?sub=1brch=74sim=191cnt=1 http://www.phy.olemiss.edu/~thomas/weblab/221_exp_procedures_spr2006/221_proced_Proj_mo_spr2006.pdf https://www.pa.msu.edu/courses/2002summer/PHY251/Projectile.pdf https://www.google.ae/url?sa=trct=jq=esrc=ssource=webcd=9cad=rjauact=8ved=0CE0QFjAIurl=http://engineering.nyu.edu/gk12/Information/RAISE_Workshop_PowerPointFiles/Projectile%20Motion.pptei=T0UUVfDSO9PLaNWogdgCusg=AFQjCNHOrhZXFDclOBiI89btpHAQIHCLWgsig2=CqlyKDLGcXo1QS-W7SHNow http://www.pa.msu.edu/courses/1997fall/phy251/proj_mo.pdf https://www.google.ae/url?sa=trct=jq=esrc=ssource=webcd=7cad=rjauact=8sqi=2ved=0CDoQFjAGurl=http://www.mssch.edu.hk/phy/lab/example/Projectile%20Motion%20Lab%20Report.docei=0WwVVfOHOpLdaNq0gMANusg=AFQjCNG8yUN-hLdBJj8YHOi1BSZHcXRJ8Qsig2=cw7jFYS9MqXH5KnSJXsnYQ https://www.google.ae/url?sa=trct=jq=esrc=ssource=webcd=39cad=rjauact=8ved=0CE0QFjAIOB4url=http://www.rlasd.k12.pa.us/teachers/bsmith/Mr._Smiths_Physics_Classroom/Honors_Unit_4_files/Proj%20Motion%20Lab%20book.docei=yHUVVY39KoPzaN2pgbgCusg=AFQjCNEyanaLfh_BArpQ0408H7C5ZbDGFQsig2=snGyLOYUigF9iBf8o4I1dA http://www.pa.msu.edu/courses/1997fall/phy251/proj_mo.pdf https://docs.google.com/document/d/1UiGi0B9NPZeliXzZeptQoKA8G-Zg9z87ejszD9nSeHw/edit https://prettygoodphysics.wikispaces.com/file/view/Projectile+Motion+Lab.pdf https://186734.wikispaces.com/file/view/IWB++Camera.pdf

Sunday, August 4, 2019

Telemachus in The Odyssey Essay -- Papers Odyssey Essays Papers

Telemachus in The Odyssey The first four books of the Odyssey are sometimes known as 'Telemachy'. It is a self-contained section that could in fact be easily removed, allowing the story to begin with Odysseus without damaging the plot. They deal with Telemachus' struggle and coming of age through his travels and quest. Telemachus is sent on his travels because although he has grown to adulthood, when Athene first visits him in book one, he is somewhat pathetic, lonely and very much a young boy and is not strong enough to remove the suitors from his father's palace: "Sitting disconsolate among the Suitors, imagining how his noble father might come back out of the blue, drive the Suitors headlong from the house, and so regain his royal honours, and reign over his own once more" Telemachus had no one strong to support him and there were 108 suitors for his mother. Telemachus at this point would not impress the great Odysseus (his father). As Telemachus was only an infant when his father left for Troy, he was desperate for some news about him. Telemachus says that he knows that he is Odysseus' son only by what he has been told and he is also very negative about ever finding his father, and his conviction that he is dead is obvious: "My father's unhappy end" Also, his grandfather Laertes was not at the palace and so he has no male role model to lead him on the right path to becoming a man. His travels also give Telemachus a chance to develop his own identity and Kleos and become a man. He develops somewhat in books one to four. Kleos in Homeric context meant what people said of you and defined how you'd be r... ...s, which tie him to his childlike life with his overly emotional mother. He needs to learn about being a hero and polite etiquette in the company of gods or heroic men. He must prepare himself for the imminent arrival of his father, which is delayed by Homer whilst Telemachus becomes a son resembling his father in ways other than physically. He gains a role model in characters such as Menelaus and a positive attitude that comes from reassuring words from him and confidence from Athene. Telemachus discovers the last known whereabouts of his father, is given hope that he could still be alive and learns that his father was indeed a hero with many important friends. We feel sorry for Telemachus' difficult childhood, and yet think that he needs to become a stronger, more confident character, that his father can be proud of.

Saturday, August 3, 2019

Chaucers Canterbury Tales - The Miller’s Tale and the Life of Christ E

The Miller’s Tale and the Life of Christ      Ã‚  Ã‚  Ã‚   When Chaucer wrote The Canterbury Tales, he created a great majority of the individual tales by "borrowing" and reworking material from various sources. Most of these stories would have been very familiar to his medieval audience, and the changes he made in the standard version of these tales for his work would have been a form of tacit communication that would have added an extra dimension to each of them. Howard says that "... the tales possess a relatedness of their own within a world of other texts. They can be understood only with reference to shared formulas of language or generic traits..." (448). In the Miller's tale Chaucer parodies the Knight's Tale, which itself was "adapted from a longer tale ... from Italy ... from Boccaccio" (Howard 448), by combining and satirizing highly irreverent references to the life of Jesus Christ with the story of Oedipus to make the tale as bawdy and comical as possible. The Miller's tale introduces a carpenter, John, his wife, Alison, and a student lodger, Nicholas. The identification of John as a carpenter immediately causes the audience to relate these characters to another famous carpenter and his wife, namely, Joseph and Mary from the Bible. (quote) The character of John is similar to Joseph not only because of their shared profession, but also because of the shared situations with their wives before marriage. Chaucer mentions how it was a rather rash move for John to marry Alison, a woman much younger than he. He says "He might have known, were Cato on his shelf,/A man should marry someone like himself" (89). Just as Joseph was wary of marrying Mary because she was already pregnant such that he "did not want to expose her to p... ...t flood, cuts loose the ropes holding his tub to the ceiling and falls to the ground, breaking his arm in the process. The ridicule that John receives from the neighbors who have been told by Alison and Nicholas that he is insane, serves to create enough of a triumph as to symbolize Christ's resurrection. The triumph would not have been nearly as dramatic if it had merely consisted of Nicholas's recovery or Absalon's defeat because it would not have fulfilled Nicholas's main goal of "killing" his father and "marrying" his mother. Works Cited Chaucer, Geoffrey. The Canterbury Tales. England: Penguin Books, 1977. Howard, Donald R. Chaucer: His Life, His Works, His World. New York: E. P. Dutton, 1987. New International Version. Holy Bible. Michigan: Zondervan Bible Publishers, 1988. Wilson, A. N. Jesus: A Life. New York: W. W. Norton & Company, 1992.      

Friday, August 2, 2019

The Mind of Someone Who Uses Drugs :: essays papers

The Mind of Someone Who Uses Drugs In the mind of someone who does drugs there is always a reason to take that hit of acid, that pill of ecstasy, that line of coke or that bump of crystal. Justification is a powerful tool of persuasion, it’s a manipulation tool that others can use on you but more commonly you use on yourself. You don’t have to go to work for ten hours and the acid trip will only last about seven hours so as long as you don’t go to sleep you’ll be fine. You’ll not sleep for twenty-four hours and you’ll be cracked out as all hell at work but hell, it’s worth it. Most people that do drugs will say that they have great will power and only do a drug when they know they have the time and energy. I have heard and said that phrase so many times. The more drugs you do the less will you have to say no and the easier it is for people to persuade you to take that pill with them. Friends don’t persuade you because they want you to be â€Å"bad† like they are or any of that other crap you see on anti-drug commercials on television. Your friends want you to be there so that they can have fun with you while on the drugs together.. It is generally true that I have had most of my drug experiences with friends and it is also true that I have made some true bonds with people while on drugs. The question I use to always ask myself is â€Å"who are my real friends and who were friends that I made simply because we were on a substance†. It is so easy to bond with someone while on drugs, especially ecstasy. On the drug ecstasy it’s possible to bond with someone while that you have never gotten along with and probably never will again. My girlfriend who I dated for about three months, while knowing that I was gay, I met through drugs. Since she and I were generally high on something at all times our relationship was completely ( what does this meanthrough) and because of drugs. I have not spoken to her for over five months and if we did speak we would probably have little interest in each other.

Thursday, August 1, 2019

Computer Security Incident Response Team Essay

In the last decade, more and more companies have started to look into e-commerce to connect them to the infinite world of global suppliers, partners, consumers and much more. This boom in technology has placed multiple assets are risk from a security stand point allowing hackers/crakers and anyone on the internet to gain access to these network and gain information or try to jeopardize business to a point where it stand stills. Increase in Denial of service attacks, child pornography, virus/worms and other tools used by individuals to destroy data has lead to law enforcement and media to look into why and how these security breaches are conducted and what new statutory laws are needed to stop this from happening. According to CSI computer crime and security Survey 2007, the average annual loss reported by security breach has shot up to $350,424 from 168,000 the previous year. To add to this, more and more organizations are reporting computer intrusions to law enforcement which inclined to 29 percent compared to 25 percent the year before. 1] To be successful in respond to an incident, there are a few things that need to be followed: 1. Minimize the number of severity of security incidents. 2. Assemble the core computer security Incident Response Team (CSIRT). 3. Define an incident response plan. 4. Contain the damage and minimize risk. [3] How to minimize the number of severity and security incidents: It is impossible to prevent all security related incidents, but there are things that can be done to minimize the impact of such incidents: †¢Establishing and enforcing security policies and procedures. Gaining support from Management in both enforcing security policies and handling incidents. Accessing vulnerabilities on the environment on regular basis including regular audits. †¢Checking all devices on certain time frames to make sure that all the updates were performed. †¢Establishing security policies for both end users and security personal and asking for security clearance each and every time an access is granted. †¢Posting banners and reminders for responsibilities and restriction of use of applications, and other systems on the network. †¢Implementing secure password polices thought the network. Checking log files on regular basics and monitoring traffic. †¢Verifying backups are done on regular basics and maintained in an appropriate manner. This would also include the new email backup policy laws. †¢Create Computer Security Response Team (CSIRT) [3] Security threat is the same for both large, small, and government organizations and therefore it is important that regardless of what the company has for its security measures, it also ha s a written document that establishes guidelines for incident response. Incident respond planning is a set of guidelines that document on security incident handling and communication efforts. This plan is activated when an incident that could impact the company’s ability to function is established. Computer Security Incident Response Plan (CSIRP) should contain the following: 1. Mission: Things the response team will be responsible for, including how to handle incidents as they happen and what steps are necessary to minimize the impact of such incidents. 2. Scope: this would define, who is responsible for which area of security, it can include things like application, network(s), employees, communication both internally and to the public and much more. . Information flow: How information will be handled in case of an emergency and how it will be reported to the appropriate authority, pubic, media and internal employees. 4. Services provided: This document should contain all the services that are either provided to the users or services that are used or bought from other vendors including testing, education, service provider issues to name a few. [2] The CSIRT team must contain several members including a Team leader which will monitor changes in individual’s actives and responsibility of reviewing actions. An Incident Lead, that will be dedicated as the owner of set of incidents and will be responsible for speaking to anyone outside the team while and corresponding changes and updates. A group of individual’s part of the CISRT team called members will be responsible to handle responsibility of the incident and will monitor different areas of the company. Other members of this team should include Legal help, public relations officers, contractors and other member of management both from business and IT that can help during security breaches. If an Incident has occurred, it is important to classify this as an incident severity. Most companies use between Severity 1-5. 1 being the highest and 5 being the research phase where no system or user’s are affected. For most system anything under Severity 3 is not a major impact of the system but if there is a system wide issue that requires immediate attention, a severity 1 or 2 would fall under the category of Incident response procedure and set up a high alert. The cost of an incident can be very high, depending on the loss of data, therefore identifying the risk and all the real threat fall under this category. Once the incident has been identified it should go into the assessment phase, where it should be determined if the system can be bought back up again and how much damage is done. If the business is impacted assessment should be done. The assessment includes forensic investigation usually involving a team of expert that look into the how many computer were affected, what kind of information was stolen or changed, entry level of attacks, potential damage done by incident, recovery process and the best way to assess this from happening again. The next phase of this is containment, which is the assessment of damage and isolation of other systems that can also be compromised including network. Backup of the system in the current state should be done at this time for further forensic investigation. Analyzing of log files and uncovering systems that were used like firewalls, routers should be identified. Any modification of files including dos, exe should also be carried out in this phase. Once all this is done, the next step is Recovery. Recovery is restoring clean data back the system so it can perform is function as required. After installing last good backup, it is important to test the system before putting this in production again. Further surveillance of network and application should be set in place as intruders might try this again. Every company today, weather small or big needs an incident response unity to defend itself against predators on the web. The government agencies has set some rules and regulations on such standards and are required that company follow these standards to avoid further disruption of the service. This becomes even more critical for companies that play important place in the economy like credit card, health, insurance and much more. Several regional companies today can help plan CSIRP plan that provide help creating a team of individuals that can act fast in such situations. The implementation of such plan cost less in the long run, when compared to companies that don’t have such response plan and loose data that is critical to their survival.

Online Shopping in India

Online Shopping in India is evolving fast and has the potential to grow exponentially, with the internet penetration growing far and wide. Now a days Indian e-commerce is getting mature. Indians are increasingly seen using the internet to get more information and to shortlist preferences. When it comes to online shopping, Indians are proving that they can surely beat the world. Average middle class Indians are getting more tech-friendly in terms of consumer electronics, changing the way India shops. The customers can easily compare the prices of any product among different vendors . Online shopping stores put the convenience of shopping at our finger tips. The traditional Indian mindset about shopping is conservative. Consumers want to touch and feel the product before buying it, and also make sure that they get the best bargain, the best deal. But with modernization and the ultra fast pace of life today, the scene has changed. The constraint of time is one of the big reasons of the increasing dependencies on Online Shopping . There are many benefits of buying the products on-line. Wide variety of products are available in portals. People don't need to go to markets or malls in search of better deals. One can find everything here and also individuals can shop at anytime of the day. These portals are open 24 hours and 365 days. A person can save lot of their precious time. Buyers can also get lots of variety and best deals here. They can also compare the product prices and find themselves with a better option. Online Shopping has been revolutionized by the presence of a large number of Online Shopping Store / Portals in India that offer wide variety of products. And it doesn’t stop with variety, today there are online shopping portals that offer discounted rates, free shipping all over India .