Showing posts with label right to privacy. Show all posts
Showing posts with label right to privacy. Show all posts

Friday, 10 September 2021

THE EFCC CHAIRMAN AND CRYPTO


Abdulrasheed Bawa, chairman of the Economic and Financial Crimes Commission (EFCC),
said that cryptocurrencies have become a preference for persons engaged in illegal financial transactions.

Meanwhile, El Salvador has become the first country to adopt Bitcoin as official currency. Also, Ukraine has legalized #bitcoin and #cryptocurrencies. Does it mean that Ecuador and Ukraine are accepting or encouraging illegal transactions by adopting and legalizing crypto currency?

The battle between privacy and security is an age-old battle. Law enforcement and intelligence agencies around the world are always looking for opportunities to do away with privacy or technologies that enhance privacy. See the FBI–Apple encryption dispute. They argue that privacy enhancing technologies, such as encryption, impede or make their work of securing lives and property difficult or impossible. So does it mean that the death of privacy will make us more secure?

In the US, the FBI has severally claimed that they are "going dark", that is to say that crime busting and investigation is being hampered by the increasing use or adoption of encryption by tech consumers. In other words, the FBI and other law enforcement and intelligence agencies have been claiming for years that the increased use of encryption by consumers is making surveillance and lawful interception much more difficult and impeding investigations.

However, recent events have shown that the claim of going dark is over exaggerated. On May 22, 2018, the Washington Post reported that the FBI repeatedly cited inflated statistics about the number of cellphones whose data it could not access because of encryption.

Also in June, 2021, it was reported that for three years, the Federal Bureau of Investigation and the Australian Federal Police owned and operated a commercial encrypted phone app, called AN0M, that was used by organized crime around the world. In other words, instead of the FBI trying to break encryption or hack into devices, they created an encrypted phone app and put it out there and some criminals felt the phone app was secure and their communications were end to end encrypted, whereas, law enforcement agents had access to all their communications which were supposed to be encrypted and unreadable or inaccessible to third parties. With this, can you say the law enforcement and intelligence agencies are really going dark? See: The FBI's Anom Stunt Rattles the Encryption Debate.

In view of the above, the Chairman's claim might just be another ploy by a law enforcement agency to try chirp away at privacy and anonymity as law enforcements are wont to do, while hiding under the guise of fighting crime.

Further reading:

(1) Going Dark, Going Forward: A Primer On The Encryption Debate 

(2) US: FBI’s Encryption Statistics Inflated

(3) Rethinking Encryption

(4) Harvard Study Questions ‘Going Dark’ Cryptoproblem-

Tuesday, 28 June 2016

WILL THE DEATH OF PRIVACY GUARANTEE BETTER SECURITY OF LIVES AND PROPERTY FOR ALL OF US?


With every terrorist attack in the West legislators and law enforcement authorities call for laws (or amendment of extant laws) for increased surveillance of citizens. This they argue will enhance the capabilities of law enforcement authorities to prevent and where they occur, investigate terrorist attacks.

It has been reported here that: 
The federal government is taking another step it says would make the US homeland safer from terrorism. US border authorities are proposing that millions of tourists entering the country each year reveal their social media identities.
The proposal from US Customs and Border Protection, announced last week in the Federal Register, would add a line to the online or paper form that US-bound visitors must fill out if they don't have a visa and plan on staying for up to 90 days for vacation, business, or other affairs. The agency says travelers coming to the US under the Visa Waiver Program won't be forced to disclose their social media handles, but leaving it blank obviously could raise red flags.
Here's what will be asked: "Please enter information associated with your online presence—Provider/Platform—Social media identifier." 
It has also been reported that "Federal agents (in the US) are planting microphones to secretly record conversations."

Arstechnica also reported that:
Russia's lower house of parliament, the State Duma, has approved a series of new online surveillance measures as part of a wide-ranging anti-terrorism lawAs well as being able to demand access to encrypted services, the authorities will require Russia's telecom companies to store not just metadata, but the actual content of messages too, for a period of six months. Metadata alone must then be held for a total of three years, according to a summary of the new law on the Meduza site. Authorities will be able to access the stored content and metadata information on demand…the legislation still needs to be approved by Russia's upper house, the Federation Council, and signed by President Putin.”
Slowly and gradually our right to privacy is being be eroded. Nigerians may think this is only happening in the US but it is happening at home here in Nigeria too, for e.g. compelling mobile phone users to register their GSM lines and submit biometric data etc. before activation of the lines for use.


See also the Facebook post by one James S. Gbudu claiming to monitor the internet with the hope of riding it of fake social media accounts being used to abuse Nigerians!

It may not be out of place to conclude that the future for privacy looks bleak! I therefore foresee a situation whereby little by little the right to privacy(online and possibly offline) will be gradually eroded until there is no more right to privacy most especially in the name of fighting terrorism and other crimes. This erosion of privacy will be further aided by the coming Internet of Things (IoT).

The question then is; will the DEATH of privacy guarantee better security of lives and property for all of us?


Monday, 29 February 2016

RICKY TARFA (SAN): THE RIGHT TO REMAIN SILENT AND PASSWORD-PROTECTED MOBILE PHONES



 On the 24th of February, 2016 a Senior Advocate of Nigeria, Mr. Rickey Tarfa withdrew an N5billion fundamental rights violation suit he filed against the Economic and Financial Crimes Commission (EFCC) and four other respondents. The senior lawyer had filed the suit, alleging violation of his right to privacy by the respondents

Mr. Tarfa in the suit sought a court declaration that his right to privacy was violated when the call records/log on his phone with mobile number 08034600000 was allegedly accessed without his authority and made available to Sahara Reporters and other online news media without any reasonable cause or a lawful court order.

He also urged the court to hold that it was unlawful for his iPhone 6 with mobile number 08034600000 to have been used in calling one Alhaji Ado in Kaduna on mobile number 08061272929 on February 9, 2016 while the said phone was with Magu and the EFCC without any reasonable cause or any court order.

Furthermore, Mr. Tarfa also urged the court to hold that it was unlawful for the EFCC to access his bank details, clients’ information, private and confidential information contained in his iPhone 6 with number 08034600000 and Samsung 6 phone with number 08077341616 without any reasonable cause or any court order.

The writer cannot tell if Mr. Tarfa’s mobile phones were password-protected but assuming he had pass-worded/locked his mobile phones (just like Syed Rizwan Farook, one of the two killers (who were later killed in a shootout with the police) in the December 2, 2015 San Bernardino, California mass shootings, who left behind a pass-worded/locked iPhone 5c whose data the FBI has not been able to get access to) and the EFCC were unable to access the mobile phones either through hacking or guessing his passwords, would it have been lawful for the EFCC to demand from Mr. Tarfa or compel him to provide the passwords to his mobile phones?

The Position of the Law in Nigeria
According to Section 35(2) 1999 Constitution as amended:
“Any  person  who  is  arrested  or  detained  shall  have  right  to  remain silent  or  avoid  answering  any  question  until  after  consultation  with  a legal practitioner or any other person of his own choice”

Section 36(11) further provides that “No person who is tried for a criminal offence shall be compelled to give evidence”. However, section 35(2) is more germane to the issue at hand so this discourse will be limited to the said section.

The import of the section 35(2) is that whenever a suspect is in police custody, his constitutional right to remain silent begins, and this right is to the effect that he cannot be forced or coerced to say a word unless he volunteers to do so as it is the duty of the prosecution to prove its case beyond reasonable doubt. The above position of the law has been upheld by the Supreme Court of Nigeria in the case of Sugh v. State (1988) NWLR (Pt. 77)475. See also Ajudua v. FRN (2014) LPELR-24126(CA) where it was held that an  accused  has the  right  to  remain  silent  as  he  cannot  be forced to make a statement during investigation.

The Position of the Law in the United States
In the United States the general position of the law regarding the right to remain silent or right against compelled self-incrimination is provided for in the Fifth Amendment to the United States Constitution which provides that “No person shall…be compelled in any criminal case to be a witness against himself.”

In the case of Securities and Exchange Commission (SEC) v. Bonan Huang et al (Case 2:15-cv-00269-MAK), the SEC were investigating the defendants who allegedly used insider information associated with their jobs to trade stocks. The SEC suspected the mobile devices were holding evidence of insider trading and demanded (via a motion filed in court) that the defendants turn over their passcodes. The defendants declined supplying their passcodes contending that the Fifth Amendment protected them.  The issue was therefore, whether the defendants could be forced to give up passcodes to devices that were provided by their employer, but secured by passcodes chosen by the employees themselves. The Federal District Court (the Supreme Court has never ruled on the constitutionality of the issue) in Eastern Pennsylvania ruled that the defendants cannot be compelled to give up the passcode to their cell phones as doing so would be equal to giving self-incriminating  testimony.

The Position of the Law in the United Kingdom
The privilege against compelled self-incrimination or the right to remain silent is deeply rooted in the common law. Goddard LJ in Blunt v Park Lane Hotel [1942] 2 KB 53 at 257 stated thus;
"No one is bound to answer any question if the answer thereto would, in the opinion of the judge, have a tendency to expose (him) to any criminal charge, penalty or forfeiture which the judge regards as reasonably likely to be preferred …" 

In Saunders v UK [1996] 23 EHRR 313 it was held that Article 6 of the European Convention of Human Rights guarantees the protection against self-incrimination.
"The right to silence and the right not to incriminate oneself, are generally recognised international standards which lie at the heart of the notion of a fair procedure under article 6….the right not to incriminate oneself, in particular, presupposes that the prosecution in the criminal case seek to prove their case against the accused without resort to evidence obtained through methods of coercion or oppression in defiance of the will of the accused. In this sense the right is closely linked to the presumption of innocence contained in article 6(2)".

However, the right is subject to numerous statutory exceptions which limit, amend, or abrogate the privilege in specified circumstances. Therefore, despite the privilege, individuals may sometimes be required to answer questions or provide information or documents which may incriminate them. For instance the Regulation of Investigatory Powers Act 2000 (RIPA), Part III, activated by ministerial order in October 2007, requires persons to supply decrypted information and/or keys/passwords to government representatives or law enforcement agents with a court order. Failure to disclose carries a maximum penalty of two years in jail. Thus, under the provisions of the RIPA Syed Hussain was convicted of failing to provide police with the password to the USB memory stick seized in a counter-terrorism operation. When Hussain was arrested in April 2012, police seized a USB memory stick from his home - but they discovered the information on the device was protected by sophisticated encryption technology. Hussain told detectives that he could not remember the password because he was suffering from stress – which meant they could not access its contents. Police called in experts from GCHQ, the government's secret eavesdropping and communications agency, but even they were unable to crack the device.

Oliver Drage, a 19-year old was arrested as part of an investigation into child sexual abuse images. His computer was seized by police who were unable to access some material on it thanks to a 50-character encryption password. Police formally requested the password from Drage, he refused to co-operate, an offence under the RIPA. He was accordingly sentenced to 16 weeks in a young offenders’ institution for refusing to give police the password to an encrypted file on his computer. See-

Conclusion
Considering the position or state of the law in Nigeria it may be safe to conclude that if Mr. Tarfa’s mobile phones were locked or pass-worded, the EFCC would have acted outside the law or illegally if they compelled Mr. Tarfa to disclose the passwords to his mobile phones which they seized. This is so as to the best of the writer’s knowledge there is no exception to the right to remain silent under Nigerian law; unlike the position in the UK, during interrogation in the custody of law enforcement agents.

However, as one writer observed:
“Realistically, the right to silence has a low value and not really exercised by most suspects. Only a suspect who knows the law and the right well would exercise the right as most people would not be able to withstand the mental pressures during the interrogation. False evidences, lies, isolation and many other psychological tactics are practiced to make the suspect confess the crime. As a result of this, many false confessions happen due to unbearable psychological pressures.”

It may therefore, not be out of place to suggest that it would take an extraordinarily strong-willed suspect undergoing interrogation during detention by any of the law enforcement agencies in Nigeria, especially the Nigerian Police who are notorious for torturing suspects in detention, to exercise his right to remain silent as guaranteed by section 35(2) of the 1999 Constitution as amended!

Tuesday, 2 September 2014

EFCC AND ATTEMPTED HACKING

On the 30th of August, 2014 Sahara Reporters posted a news story on their website; captioned: “EFCC Arrests Three Suspected Fraudsters for Attempted Hacking.” The gist of the story is that some persons conspired to break into or compromise the computer systems/computer networks of a bank using an electronic device, for the purpose of stealing funds. However; their plan failed as an insider reported them to the Economic and Financial Crimes Commission (EFCC) and they were arrested.

The caption of the story got me wondering whether there is a law in Nigeria which directly criminalizes attempted hacking or hacking or breaking into someone’s computer networks or computer systems. To the best of my knowledge there is no such law in Nigeria that directly criminalizes hacking or breaking into or compromising someone’s computer networks or computer systems? Therefore, the caption: “EFCC Arrests Three Suspected Fraudsters for Attempted Hacking.” by Sahara Reporters is inappropriate or misleading.

In the US the Computer Fraud and Abuse Act, has prohibited certain computer crimes. The Act prohibits accessing or attempting to a computer without authorization and subsequently transmitting classified government information, theft of financial information, computer fraud, transmitting code that causes damage to a computer system, trafficking in computer passwords for the purpose of affecting interstate commerce or a government computer, etc. Also in South Africa, under the Electronic Communications and Transactions (ECT) Act 25 of 2002; unauthorised access to, interception of or interference with data on a computer or computer networks is  criminalized.

However, with regard to Nigeria, there is no law like that of the US and South Africa mentioned above. It is therefore, high time that a law regulating computer/internet crime in Nigeria is enacted. The need for a law criminalizing computer crime/cybercrime in Nigeria becomes more urgent considering the drive by the Government (Central Bank of Nigeria) to encourage cashless transactions which compels people to use electronic(computer) means of transactions. Criminals may exploit weaknesses in these electronic means of transactions to defraud customers but a computer crime/cybercrime law would be able to curb such criminal acts by punishing criminals who contravene the law.

In addition to the above, many Nigerians are now taking to online transactions/ecommerce. This can be inferred from the growth and popularity of the two leading online shops in Nigeria: Konga and Jumia. It is has therefore become necessary to pass computer crime/cybercrime laws to protect users of these ecommerce channels/shops. Apart from such computer crime /cybercrime laws there is also need for a data protection law to guard against the misuse/abuse of the personal data which operators of these ecommerce sites gather and hold concerning their customers/users. For instance in China, P.R.C. Criminal Law  stipulates criminal penalties for improper sales, provision and collection of personal data. In the same China, three men were arrested for illegal sales of millions of items of personal information.

Monday, 6 January 2014

Nigeria and Data Protection

“We live in an age of “big data.” Data has become the raw material of production, a new source of immense economic and social value. Advances in data mining  and  analytics  and  the  massive  increase  in  computing  power  and  data storage capacity have expanded, by orders of magnitude, the scope of information available to businesses, government, and individuals. In addition, the increasing  number  of  people,  devices,  and  sensors  that  are  now  connected  by digital networks has revolutionized the ability to generate, communicate, share, and access data. Data create enormous value for the global economy, driving innovation, productivity, efficiency, and growth.  At the same time, the “data deluge” presents privacy concerns that could stir a regulatory backlash, dampening the data economy and stifling innovation."

It is therefore clear from the above that data, especially personal data(any data or information in connection with a specific individual, which can be used, separately or in combination with other data, to identify an individual) has acquired an immense value in the age we are living(the digital age) and serious steps ought to be taken to protect the personal data of citizens but Nigeria seems to be lagging behind as the best we have at the moment is the guidelines on personal data issued by National Information Technology Development Agency(NITDA) which is good gut not enough(what we need is a law) and there is also a draft bill on Personal Information and Data Protection which is pending before the federal lawmakers.

This does not augur well for the citizens whose personal data is scattered all over the place (banks, the Federal Road Safety Commission (FRSC), the National Identity Management Commission (NIMC), the Nigeria Communications Commission (NCC), GSM service providers and online retailers like Jumia and Konga who are currently making waves in the Nigeria internet sphere as online shopping is becoming increasingly popular among Nigerians).

In China they have taken serious steps to guard and protect the personal data of their citizens with the passage of such laws as the Peoples’ Republic of China Law on the Protection of Consumer Rights and Interests and persons who flout the law are been arrested and prosecuted. For instance the Police in China, apprehended a 10-member gang in Beijing and Shanghai for illegally obtaining and selling nearly one million...You can find the rest of the story here

Wednesday, 17 July 2013

RIGHT TO PRIVACY IN THE INFORMATION AGE: MYTH OR REALITY

Introduction
We live in a world today where vast Information and Communications Technology (ICT) infrastructures and extensive flows of information have become natural and unquestioned features of modern life. For instance in when I sat for the Senior School Certificate Examination (SSCE), I registered for the examination via a non-electronic method. Nowadays, candidates for that examination register for it online, in much the same way as candidates for the Universities Matriculation Examinations (UME) and several other examinations. The tremendous growth of online services—everything from social media to ecommerce—has come to define our day-to-day lives in ways we could never have imagined a decade ago. This increasingly pervasive, unpredictable, and rapidly changing interaction between ICT and society poses a great threat to the right to privacy; especially informational privacy. The revelations that the US National Security Agency (NSA), Britain’s Government Communications Headquarters (GCHQ) and other government agencies are spying on or in the case of Nigeria; trying to acquire surveillance equipment to spy on their citizens’ internet communications and the rapid digitization of our routine activities, has brought to the front burner the question whether the right to privacy in the information age is a myth or reality. This article will examine the right to privacy in the information age. It will briefly examine certain laws or instruments providing for the right to privacy and how the right is been threatened or eroded in the information age and it would conclude on whether this right still exists.
Definition of terms:
<!--[if !supportLists]-->1.           <!--[endif]-->Information age: According to the online Free Dictionary, the information age is:
The period beginning around 1970 and noted for the abundant publication, consumption, and manipulation of information, especially by computers and computer networks.
<!--[if !supportLists]-->2.           <!--[endif]-->Privacy: Privacy  is  the  ability  of  an  individual or    group  to  seclude  themselves or information   about   themselves   and thereby reveal themselves selectively. According to a privacy think tank; Privacy International:
Privacy is the right to control who knows what about you, and under what conditions. The right to share different things with your family, your friends and your colleagues. The right to know that your personal emails, medical records and bank details are safe and secure. Privacy is essential to human dignity and autonomy in all societies.

Frank La Rue (Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression) in his report to the 23rd session of the Human Rights Council also defined privacy as:
…the presumption that individuals should have an area of autonomous  development,  interaction  and  liberty,  a  “private  sphere”  with  or  without interaction  with  others,  free  from  State  intervention  and  from  excessive  unsolicited intervention  by  other  uninvited  individuals. The  right  to  privacy  is  also  the  ability  of individuals  to  determine  who  holds  information  about  them  and  how  is  that  information used.
The law recognizes two types of privacy, namely; informational and physical privacy. Informational privacy basically relates to an individual’s right to control his or her personal information held by others while physical privacy according to the online encyclopedia; Wikipedia: can be referred to as the right to prevent intrusions into ones physical space or solitude. I am more concerned with informational privacy in this article.

Legal framework
The human right to privacy is recognized at the international level by instruments such as the United Nations Universal Declaration of Human Rights. Article 12 of the Declaration states that:
No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, or to attacks upon his honour and reputation.  Everyone has the right to the protection of the law against such interference or attacks.
In Europe Article 8 of the European Convention on Human Rights (ECHR) protects the right to privacy in Article 8.
In the US, privacy is protected by their constitution and through a plethora of privacy legislation dealing with specific types of personal information.  For example the Family Educational Rights and Privacy Act of 1974, 20 U.S.C. §§ 1221 note, 1232g — protects the privacy of school records. Right to Financial Privacy Act of 1978, 12 U.S.C. §§ 3401–3422 — requires a  subpoena  or  search  warrant  for  law  enforcement  ocials  to  obtain nancial records. Health Insurance Portability and Accountability Act of 1996 — gives the Department of Health and Human Services (HHS) the authority to promulgate regulations governing the privacy of medical records. There are also several ways the US constitution protects privacy; for example the First Amendment right to speak anonymously, the First Amendment freedom of association, which protects privacy of one’s associations, the Fourth Amendment’s protection against unreasonable searches and seizures and the Fifth Amendment’s privilege against self-incrimination.
Section 37 of the 1999 Constitution of the Federal Republic as amended provides that the privacy of citizens, their homes, correspondence, telephone conversations and telegraphic communications is guaranteed and protected.
The   right   to   privacy   was affirmed   in   the   case   of   Medical and Dental Practitioners Disciplinary Tribunal Vs.   Dr.   John Emewulu Nicholas Okonkwo (2001) 7 NWLR Pt.  711 p. 206 @ 244 Para E.
There are other statutory examples which seem to safeguard the right to privacy.  For  example  section  182  of  the  Evidence  Act, 2011 protects the confidentiality of communication during marriage by providing that no husband or wife shall be compelled to disclose any communication made to him  or  her  during  marriage  by  any  person  to  whom  he  or  she  is  or  has  been married; nor shall he or she be permitted to disclose any such communication, unless the person who made it, or that person's representative consents, except in suits  between  married  persons,  or  proceedings  in  which  one  married  person  is prosecuted for certain specified offenses.
There  are  limits  imposed  by  law on  a  person’s  rights  to  privacy. Examples  are  laws  dealing  with taxation  which  provide  for  certain specific     disclosures     by     the  individual. See also section 45 of the Nigerian constitution.
The right to privacy may also be trammeled where the trammeling activity, including communications surveillance, is justified by a prescribed law, necessary to achieve a legitimate aim, and is proportionate to the aim pursued.

Erosion of the Right to Privacy
Technological innovation and the proliferation of cellphones, tablets, and other basic tools of modern life, has given governments and companies the ability to extract, analyze, and indefinitely archive every single oral communication, text, key stroke, search term, website visit, and any other digital transaction that we make. Despite the widespread recognition of the obligation to protect privacy, governments especially of the western world have been carrying on surveillance activities which severely undermine the right to privacy. The leaks by Edward Snowden, a former contractor for the CIA, which exposed US spy programmes clearly shows that the right to privacy of internet users is seriously been threatened by the US which has prided herself as the defender of civil liberties. President Obama, a lawyer specializing in US constitutional law, was also critical about the restrictions on civil rights and liberties (e.g. The Patriot Act) enacted in connection with President George W. Bush's "War on Terror." However, since becoming the president, he has not reversed those restrictions he complained of during the Bush administration. President Obama in his forward to the White House privacy report stated that:
Americans have always cherished our privacy. From the birth of our republic, we assured ourselves protection against unlawful intrusion into our homes and our personal papers. At the same time, we set up a postal system to enable citizens all over the new nation to engage in commerce and political discourse. Soon after, Congress made it a crime to invade the privacy of the mails. Citizens who feel protected from misuse of their personal information feel free to engage in commerce, to participate in the political process, or to seek needed health care. This is why the Supreme Court has protected anonymous political speech, the same right exercised by the pamphleteers of the early Republic and today‘s bloggers.
In spite of this forward by President Obama which seemed as if he had interest in protecting the privacy of Americans his administration still went ahead to eavesdrop on or spy on internet communications of millions of Americans and foreigners alike through spying programs like Prism which allows the NSA to tap directly into the servers of nine internet firms including Facebook, Google, Microsoft and Yahoo to track online communication. The leaks also show that Britain's electronic eavesdropping agency GCHQ has also been gathering information on the online activities of internet users via Prism.  
In defending the NSA surveillance Obama said that the government is only looking at phone numbers and durations of calls, however, by knowing who an individual speaks to, when, and for how long, intelligence agencies can build up a detailed picture of that person, their social network, and more. Combine  that information with other data sets being collected, like credit card bills, and you could even deduce when a woman is pregnant before her own family knows, thereby violating her privacy (i.e. the right to control who knows about her pregnancy and under what conditions.)
The right to privacy is also been eroded or undermined by for-profit companies like Google and Facebook which collect our personal data and use them to make profit through targeted adverts. (Targeted advertisements are advertisements that take the data you provide to offer adverts specific to you.) For instance if on your Facebook profile you state that you like jazz music Facebook uses that data or information to provide you with jazz related adverts or if you log onto Facebook and your IP address (a unique series of numbers assigned to every computer or device connected to the internet) shows you are from Nigeria you will be targeted with adverts from Nigerian companies/websites or Nigerian products/services.
As the number of people who use smartphones/tablets increases so does our right to privacy diminishes or dies away. Smartphones have applications that make it easy for privacy to be breached. For example functions like geotagging, which when turned on can show the geographical location at which pictures have been taken thereby revealing your location which you would probably have preferred not to disclose.
Certain smartphone apps (applications) that we install on our phones are known to secretly upload phone contacts (address book) to servers/computers without users’ permission and this resulted in a class-action lawsuit against Facebook, Apple, Twitter and 15 other companies in 2012 for invasion of privacy.
Daniel J. Solove, a leading privacy law expert in his book; “The Digital Person: Technology and Privacy in The Information Age” on pages 23 to 25 details how browsing the web impacts on your privacy. Permit me to quote extensively from his book. He explains thus:
Currently, there are two basic ways that websites collect personal information.  First, many websites directly solicit data from their users.  Numerous websites  require  users  to  register  and  log  in,  and registration  often  involves  answering  a  questionnaire.  Online merchants amass data from their business transactions with consumers.
For  example,  I  shop  on  Amazon.com(since this article is targeted mainly to a Nigerian audience I prefer replacing Amazon.com with konga.com or jumia.com.ng which are two of the leading Nigerian online shops used by many Nigerians; in order to make this explanation more clearer),  which  keeps  track  of  my  purchases in books, videos, music, and other items. I can view its records of every item I’ve ever ordered... When I click on this option, I get an alphabetized list of everything I bought  and  the  date  I  bought  it.  Amazon.com uses its extensive records to recommend new books and videos. With a click, I can see dozens  of  books  that  Amazon.com  thinks  I’ll  be  interested  in.  It is eerily good, and it can pick out books for me better than my relatives can. It has me pegged.
Websites can also secretly track a customer’s websurng. When a person explores a website, the website can record data about her ISP(internet service provider), computer  hardware  and  software,  the  website  she  linked  from,  and exactly what parts of the website she explored and for how long. This information is referred to as “clickstream data” because it is a trail of how a user navigates throughout the web by clicking on various links. It enables the website to calculate how many times it has been visited and what parts are most popular. With a way to connect this information to particular web users, marketers can open a window into people’s minds. This is a unique vision, for while marketers can measure the size of audiences for other media such as television, radio, books, and magazines, they have little ability to measure attention span. Due to the interactive nature of the Internet, marketers can learn how we respond to what we hear and see.  A website collects information about the way a user interacts with the site and stores the information in its database.  This information will enable the website to learn about the interests of a user so it can better target advertisements to the user. For example, Amazon.com can keep track of every book or item that a customer browses but does not purchase.
To connect this information with particular users, a company can either require a user to log in or it can secretly tag a user to recognize her when she returns.  This latter form of identification occurs through what is called a “cookie.” A cookie is a small text le of codes that is deployed into the user’s computer when she downloads a web page. Websites place a unique identification code into the cookie, and the cookie is saved on the user’s hard drive. When the user visits the site again, the site looks for its cookie, recognizes the user, and locates the information it collected about the user’s previous surng activity in its database. Basically, a cookie works as a form of high-tech cattle-branding.
Cookies have certain limits. First, they often are not tagged to particular individuals—just too particular computers.  However, if the website requires a user to log in or asks for a name, then the cookies will often contain data identifying the individual.  Second,  typically, websites  can  only  decipher  the  cookies  that  they  placed  on  a  user’s computer; they cannot use cookies stored by a dierent website.
To get around these limitations, companies have devised strategies of information sharing with other websites. One of the most popular information sharing techniques is performed by a firm called DoubleClick. When a person visits a website, it often takes a quick detour to DoubleClick. DoubleClick accesses its cookie on the person’s computer and looks up its prole about the person. Based on the prole, DoubleClick  determines  what  advertisements  that  person  will  be most responsive to, and these ads are then downloaded with the website  the  person  is  accessing.  All this occurs in milliseconds, without the user’s knowledge. Numerous websites subscribe to DoubleClick. This means that if I click on the same website as you at the very same time,  we will  receive  dierent  advertisements  calculated  by  DoubleClick  to  match  our  interests.  People may not know it, but DoubleClick cookies probably reside on their computer. As of the end of 1999, DoubleClick had amassed millions of customer proles.
Another information collection device, known as a “web bug,” is embedded into a web page or even an email message. The web bug is a hidden snippet of code that can gather data about a person. For example, a company can send a spam email with a web bug that will report back when the message is opened. The bug can also record when the message is forwarded to others. Web bugs also can collect information about people as they explore a website. Some of the nastier versions of web bugs can even access a person’s computer les.
Companies also use what has become known as “spyware,” which is software that is often deceptively and secretly installed into people’s computers. Spyware can gather information about every move one makes when surng the Internet. This data is then used by spyware    companies    to    target    pop-up    ads    and    other    forms    of advertising.
Flowing from the above it can be deduced that we have lost our right to privately make purchases or to make certain purchases unnoticed, our right to read a book privately as some books are published only in e-book format and some newspapers only exist online thereby forcing one to read them online where one’s clicks and page views are tracked and companies are doing everything in their power to associate those clicks and page views with one’s names, addresses, demographic information, and other personal information.

Conclusion
Considering the extent to which the right to privacy (and please do remember I am more concerned in this article with the right to informational privacy) is been eroded as has been earlier explained above, it may not be out of place to conclude that the right to privacy in the information age is a myth. However, the extent to which this is correct depends on where you live in the world. People living in countries with less internet penetration rates (penetration is the rate of a country's population which are internet users) may not have lost their right to privacy as much as people in countries with high internet penetration rates.
The conclusion that the right to privacy in the information age is a myth is somewhat buttressed by Glenn Greenwald, a former constitutional lawyer and now columnist on civil liberties and US national security issues for the Guardian and also author of the book: “With Liberty And Justice For Some: How The Law Is Used To Destroy Equality And Protect The Powerful.” Greenwald while commenting on the NSA’s mass and indiscriminate bulk collection of the internet communications of millions of citizens of Brazil said thus:
That the US government - in complete secrecy - is constructing a ubiquitous spying apparatus aimed not only at its own citizens, but all of the world's citizens, has profound consequences. It erodes, if not eliminates, the ability to use the internet with any remnant of privacy or personal security.
The conclusion is further buttressed by the documentary: “‘Terms and Conditions May Apply” which exposes what corporations and governments learn about people through internet and cell phone usage, and what can be done about it, if anything. In reviewing the documentary Lloyd Grove of dailybeast.com, hit the nail on the head thus: 
With the Facebooks and the AT&Ts of the world hungry to know you better for the bottom line's sake, and with the government empowered to ask them to pass along what they know without the bother of a Fourth Amendment search- and- seizure test, the goose of privacy has been cooked, sauced and served.
Privacy is a very important right which enables us to exercise and enjoy other rights like freedom of expression which is guaranteed under section 39 of the 1999 constitution of Nigeria as amended. It empowers us to feel that we can speak freely, associate freely, and access information freely.
It is therefore sad that this right appears to be dead as even the tools which exist to ensure privacy online are not user-friendly or common place compared to the ones which do not protect our privacy as explained by Timothy B. Lee in the article: NSA Proof Encryption Exists. Why Nobody Doesn’t Anyone Use It? Tor Browser is good for protecting privacy but can only be used effectively by those who are highly skilled computer users.
You may be wondering why it is sad but the right to privacy also includes  the  ability  of individuals  to  determine  who  holds  information  about  them  and  how  is  that  information used. However, once your personal information is collected by the numerous websites you visit on the internet, you may lose control over how and what they can do with that information.  You therefore lose your right to privacy. Remember also that privacy is  the  ability  of  an  individual or    group  to  seclude  themselves or information   about   themselves   and thereby reveal themselves selectively. On the internet it is very difficult to seclude information about yourself and reveal it selectively.
There are certain programmes like Adblock Plus, Ghostery (which blocks the invisible tracking cookies and plug-ins on many web sites, showing it all to you, and then giving you the choice whether you want to block them one-by-one, or all together so you'll never worry about them again. The best part about Ghostery is that it's not just limited to social networks, but will also catch and show you ad-networks and web publishers as well) and Do Not Track. These will only protect your personal information from been tracked, collected and analyzed for advertisement purposes but not against secret, overly broad and unlawful surveillance or monitoring by NSA or GCHQ.