Electronic Fare Payment System Privacy Considerations

Similar documents
CONNECT TRANSIT CARD Pilot Program - Privacy Policy Effective Date: April 18, 2014

Public-Private Partnerships in Transit

System Expansion Implementation Plan. Board Meeting, April 2017

METRO SHORT RANGE TRANSIT PLAN FY Executive Summary May 2009 DIVERSIFIED TRANSPORTATION SOLUTIONS

Privacy: Pre- and Post-Breach

Data Compromise Notice Procedure Summary and Guide

SECTION 106 ACTIVITIES ANNUAL REPORT

A RESOLUTION. WHEREAS, Title 6, Subtitle C, Local Government Code (Local Government Records Act),

Maximizing Asset ROI for Self & Clients in a Public Sector Setting. July 16 th San Diego

Northern Virginia Transportation Authority

Managed Lane owner decision needed San Mateo County s options Understanding revenues & costs Pros & cons of County s options Proposed next steps

Looking Ahead. A Context for the Next Twenty Year Needs Assessment. July 2013

MVTA-Prior Lake-Shakopee Merger. SCALE Presentation, October 10, 2014

SECTION 106 ACTIVITIES ANNUAL REPORT

SUBJECT: PRESTO operating agreement renewal update. Committee of the Whole. Transit Department. Recommendation: Purpose: Page 1 of Report TR-01-17

Cybersecurity: Federalism as Defense-in-Depth

Security Breach Notification Reflections on the U.S. Experience

Click to edit Master title style Click to edit Master title style

Joint Committee Report

GENERAL ASSEMBLY OF NORTH CAROLINA SESSION 2007 H 1 HOUSE BILL 1699

Figure 1: Summary Status of Actions Recommended in June 2016 Committee Report. Status of Actions Recommended # of Actions Recommended

A full list of SaltWire Network Inc. publications is available by visiting saltwire.com.

Community Update. June 21, 2011

Honorable Mayor and Members of the City Council. Memorandum of Understanding: Interstate 80 Integrated Corridor Mobility (I-80 ICM) Project

SOUTHEASTERN PENNSYLVANIA TRANSPORTATION AUTHORITY. Justifying Investments in Security Technology

Professional Engineers Ontario. canada s anti-spam. Guidelines for Chapters

Community Update. May 31, 2011

Transportation & Mobility

Veirs Mill Road Metrobus Improvements Request to Conduct Public Hearing

THE CCPA AND PREPARING FOR STATE PRIVACY LEGISLATION. Nathan Taylor Morrison & Foerster LLP

I-495 & I-270 Managed Lanes Study. Edit presentation title MM/DD/YYYY 1

CITY OF VANCOUVER ADMINISTRATIVE REPORT

Statement of Organization, Functions, and Delegations of Authority: Office of the

The Blue Line Extension

Organizational Structure of the Toronto Environment Office

Los Angeles County Metropolitan Transportation Authority (Metro) Arterial Performance Measures Framework

GDOT PowerPoint Title Page MMPT. Technical Committee April 6, 2010

Region of Waterloo Corporate Services Facilities & Fleet Management

SANMINA CORPORATION PRIVACY POLICY. Effective date: May 25, 2018

[Planning Code - Transportation Demand Management Program Requirement]

Bay Area Regional Bicycle Share Pilot Project. Karen Schkolnick, BAAQMD SPUR Evening Forum: Bike Sharing Around the Bay June 25, 2013

NEW SERVICES IN KAUFMAN COUNTY

Regional Multi-Modal Public Transit Automated Fare Collection Study Tasks 2 & 3 Findings

Implementation Plan FY

brand guidelines partner Version

Project Tracker. User s Guide. Texas Department of Transportation TPP

I-95 Corridor Coalition. Multi-State VMT-Based Road-User Fee Initiative. Mark F. Muriello

North Carolina Utilities Commission Public Staff. Christopher J. Ayers Executive Director

SACOG Board of Directors

November 28, 2012 ALTERNATIVES ANALYSIS PUBLIC MEETING

Privacy Policy. What information do we collect automatically?

Investigating Insider Threats

EDENRED COMMUTER BENEFITS SOLUTIONS, LLC PRIVACY POLICY. Updated: April 2017

Meeting attendees are now required to go through security screenings upon entering the building. Please allow for extra time.

NERC Staff Organization Chart Budget 2019

CITY OF VANCOUVER ADMINISTRATIVE REPORT

This privacy policy has been compiled to better serve those who are concerned with

Community Update. June 8, 2011

BOARD OF SUPERVISORS 2015 TRANSIT SUMMIT INFORMATION ITEM. New Electronic Payments Program Update

Red Flag Policy and Identity Theft Prevention Program

Shaw Privacy Policy. 1- Our commitment to you

MAJOR PROJECTS STRATEGY

How to Build Privacy into Intelligent Transportation Systems PROFESSOR DOROTHY J. GLANCY SANTA CLARA UNIVERSITY SCHOOL OF LAW

Department of Transportation Maryland Transit Administration

Integrated Resource Planning April 20, 2010

Developing Issues in Breach Notification and Privacy Regulations: Risk Managers Are you having the right conversation with the C Suite?

NERC Staff Organization Chart Budget 2019

Keeping It Under Wraps: Personally Identifiable Information (PII)

David Young Law Compliance Bulletin April 2014

Planning, Design, CM and Construction Opportunities. UTCA Briefing. August 2016

SAN FRANCISCO MUNICIPAL TRANSPORTATION AGENCY BOARD OF DIRECTORS. RESOLUTION No

Greater Toronto Area

UNITED STATES OFFICE OF PERSONNEL MANAGEMENT

UCOP ITS Systemwide CISO Office Systemwide IT Policy

Bill Jackson Asst. Statewide Utility Engineer, Office of Construction MDOT SHA

National Counterterrorism Center

C Line Rapid Bus 90% Design

Privacy Policy

Review of the Feasibility Plan for Coordinating Operations of the North Carolina Research and Education Network and the State Network Infrastructure

ISSUE BRIEF SC DMV ELECTRONIC TICKET TRANSMISSION MANDATE (November, 2017)

Data Protection System of Georgia. Nina Sarishvili Head of International Relations Department

FIBER OPTIC RESOURCE SHARING IN VIRGINIA

NERC Staff Organization Chart Budget 2018

Dulles Area Transportation Association

ACEC State Markets Conference April 2018

milestoned LLP Privacy Policy p. 1 Privacy Policy

COUNTY OF PERTH. Corporate Services Department. Archives Division (Stratford-Perth Archives) Business Plan.

VII. GUIDE TO AGENCY PROGRAMS

Credit Card Data Compromise: Incident Response Plan

Community Update. June 30, Presented at: York Civic Centre

Creating Dallas-Fort Worth s Transportation System: Celebrating Partnerships and Milestones

Red Flags Program. Purpose

2. What is Personal Information and Non-Personally Identifiable Information?

Network, Policy & Privacy Considerations for Connected Autonomous Vehicle Initiatives

Consolidated Privacy Notice

COMMENTARY. Information JONES DAY

Re: Special Publication Revision 4, Security Controls of Federal Information Systems and Organizations: Appendix J, Privacy Control Catalog

Webinar on Shared Transportation Services - Leveraging GTFS with Regional Partners. June 20, 2018

Dot-Tech LLC DBA Fallout-Hosting Privacy Policy

Denver Union Station Area Redevelopment Project

Transcription:

Electronic Fare Payment System Privacy Considerations APTA Legal Affairs Seminar Palm Springs, California, February 25, 2014 Brooke Abola Senior Counsel, Office of General Counsel Metropolitan Transportation Commission, Oakland, CA

Clipper Program Overview Operating on 8 systems that together account for 95% of regional transit rides 45% market share 1.3 million active cards Processing $30M+/month Phased implementation from 2006-2012 Ongoing and planned expansions 2

Why Clipper? MTC has legislative mandate to coordinate transit services 9-county region 7.1 million residents 1.5 million daily transit trips 28 transit systems Bus, ferry, light rail, commuter rail, heavy rail No system carries >50% of riders Diverse fare programs 3

Program Timeline

MTC s Clipper Privacy Policy MTC is committed to ensuring customer privacy and security. Policy established 2006 Major updates in 2010, 2011, 2012 and 2013 Driven by California law Stats. 2003, Chapter 829; effective 7/1/04 Codified at Business and Professions Code Sections 22575-22579 Personally Identifiable Information (PII) under the law generally includes information that identifies or describes a specific individual 5

Elements of Privacy Policy Definition of PII: Clipper -specific definition How PII Collected/Used Third Parties with Access to PII Retention of PII: California law limits to 4.5 years Security of PII: Technological and procedural Updates to Policy: How communicated 6

Recent California Legislative Changes Increasing consumer protections AB 370 Effective 1/1/14 Do Not Track law Modified Bus. & Prof. Code Section 22575 AB 1149/SB 46 Effective 1/1/14 Existing law (Civ. Code Section 1798.29) requires CA residents to receive notice of security breach Modified to apply to local agencies SB 568 Effective 1/1/15 Limits types of advertising on websites directed to minors Requires websites and apps to allow minors to remove content they have posted 7

Recent California Legislative Changes AB 179: Specific to electronic transit fare payment Modifies existing law that applied to electronic toll collection systems Streets & Highways Code Sections 31490 et seq. Limits storage and sharing of PII Clipper Program Response Privacy policy distribution Customer opt-in initiative Practical Applications Customer communications Clipper card theft Missing person 8

Pending Privacy Legislation in California AB 1442: Would extend the Information Practices Act of 1977 to local government SB 828: Affects local agency cooperation with federal agencies seeking electronic data; urgency bill SB 383: Credit card-related PII and downloadable products AB 1291: Would require companies to reveal customer data shared with third parties if requested by customer Possible further enhancements to Do Not Track statute Various bills proposing amendments to BPC 22575 (most recent is SB 849) 9

A Peek at the Future: C2 Implementation 2013 2014 2015 2016 2017 2018 2019 Phase 3 Launch: Napa/ Solano Operators PLANNING PHASE Phase 3 Launch: East Bay Operators Phase 3 Launch: North Bay/ 101 Corridor Operators Planning Process Detail PROCUREMENT PHASE Award Contract(s) 2013 2014 Q3 Q4 Q1 Q2 Q3 Q4 Mission/Vision/Goals State of the Clipper System/Industry Analysis & Peer Review Peer Agency Concept of Operations Site Visits Fare Policy Coordination Technology/Operations Transition Plan Governance Options Analysis Procurement Strategy IMPLEMENTATION PHASE Technical Specification(s) 2015 Q1 Begin C2 Operations Parallel Ops Nov. 2019 End of Current Contract

MTC Clipper and Privacy Contacts Carol Kuester Director, Electronic Payment Systems 510.817.5853; ckuester@mtc.ca.gov Cynthia Segal Deputy General Counsel 510.817.5713; csegal@mtc.ca.gov Lynn Valdivia Principal, Clipper 510.817.5766; lvaldivia@mtc.ca.gov Brooke Abola Senior Counsel 510.817.5956; babola@mtc.ca.gov Stephen Abbanat Senior Program Coordinator, Technical Operations and Financials 510.817.5822; sabbanat@mtc.ca.gov Key project documents available at: clipper.mtc.ca.gov Derek Toups Senior Program Coordinator, Strategic Planning and Program Expansion & Enhancements 510.817.5726; dtoups@mtc.ca.gov David Weir Senior Program Coordinator, Cardholder and Operator Support 510.817.5979; dweir@mtc.ca.gov 11