We have debate and over the course of time are, i think, whats critical. You have already taken steps by moving away from sequestration. That will be helpful to us as well. But again i think that recognizing that we have to manage risk and that we cant prevent every incident, and as long as we are adapting. General . Yes, sir. The federal protective services to the be very brief, very brief. We have to work and weve our way through both state, local, federal, and civilian contractors environments. And we do that with a very small force. Your help in helping us to your support in helping us move through and navigate through some of those areas is critical, quite frankly. Because we are trying to look out and predict, if you will, what is coming down the road to keep our people safe. And we really need the support of folks like yourself and this committee to help us see through that and help us to work through some of these challenges. Brief response, please. We believe that continuing to evaluate those employees who have access to classified information and to our facilities is critical, and we need to have resources to be able to conduct those evaluations. We need to have access to records that are sometimes publicly available, sometimes not available in order to do those evaluations. General support for that approach to doing business i think is essential. All right. Thanks. Senator ayotte, before you arrived i was think senator heitkamp was here, we were blessed to have four former state attorney generals on this committee that really adds a great deal of expertise in this particular area, so welcome. And one. I want to thank the witnesses for being here. I wanted to follow up with you, mr. Lewis, and ask you about how other dod policies might affect the security clearances at facilities. And then those who can gain access to them. In particular, just the thought of whether any duty regulations that need to be reviewed or revised. For example, the current discharge regulation and how to implement it. As i understand it, in the case of mr. Alexis, had he been dishonorably discharge that wouldve raised a flag, and that would have gone right directly to his fitness to hold his security clearance. Could you help me understand in light of this case, is this something that we need to think about . One of the things, im wondering about is, well, is the whole breakdown with the reach out, obviously that was beyond is there anything that we need to do on the Mental Health and here looking back on this . And i understand that 2020 its always 2020 when you look back in something and you can see things that you didnt see at a time. But what im trying to understand is there anything we need look at the interment on those two issues from the dod perspective or anything we can do i also served on the joint Armed Service committee, on the committees we should be doing . I do not believe that there are issues with how the discharges occur. And not to get into specifics, but generally based on what was known at the time of his discharge, it was not considered to be an unusual determination as to an Honorable Discharge in that particular case. But the larger issue is how do we collect, how do we identify and collect relevant information that allows us to constantly adjust our perspective about certain individuals, and individuals were entrusted positions . Thats really the challenge. I hate to keep blowing the same horn, but that continuous evaluation process, not just collecting information but having the staff available to evaluate the information and take action on that information, to me that is the real issue. Well, i appreciate it. And then, of course, senator collins, senator mccaskill, senator heitkamp and i also have one whether do random checks that would be important is welcome at the receiver security clearance. Instead of a pretty lengthy but right now upon which theres the review unless theres a reason something is flagged. I wanted to ask also, mr. Lewis, general lewis, what steps have we taken im sorry, general patterson. I apologize. General patterson, what do you see as we look at this whole situation now with whats happening at the navy yard that youre already implement and to make sure that we dont find ourselves in the same situation . We can legislate but i know youre reviewing the whole situation and understanding what steps are already taking and a positive action that you can talk about . Yes, maam. Within the federal Protection Service we are working very closely with our federal partners to look at again processes and procedures for folks coming and going into Federal Buildings. We are also looking at our communications processes as well as to one of the challenges during the navy yard was the fact that so many of the responding agencies, the level of communication and how do you do that. So we are looking aggressively at how we do that, not just in the washington, d. C. Area, but across the United States. Because in a crisis situation, communication becomes critical, and as such, good time adjudication is essential hopefully to a positive result. So we are looking at a variety of areas and taking lessons as they come about from the navy yard as to how we improve processes across the spectrum within the federal protective services. Thank you very much. I also wanted to ask you, mr. Patterson, is it accurate to say that general patterson is it accurate to say that fps doesnt use a Risk Assessment tool consistent with the interagency Security Committees standards . Trying to understand where we are with this. I know that there was also a report from gao that fpss interim Assessment Tool wasnt consistent with this assessment standards because it excludes consequence from assessments. And i want to understand if there is a difference, why isnt there. Is it something we should be more uniform are putting in place, or is there a reason for its . There is a reason, and we have just built what we call a modified Infrastructure Survey tool, and that particular to was developed from ip, Infrastructure Protection folks within the department who didnt were developed that to a repeat of about six or seven years. We thought that this was a tool that we could modify, and because it brought what we believe all of the areas of the isc requirements to bear. Now, so what we look at with our tool is specifically bone ability. Thats what the tool is for, to look at the bone ability of a facility. Separate from the vulnerability peace we also do a threat assessment. We connect with the joint Terrorism Task force, with local Law Enforcement, with any number of agencies out there to get what we believe a very in depth comprehensive perspective on the threat that we also provide to our federal partners. The peace that is not part of the process is the consequence peace. We havent figured out how to do that yet within a federal facility. What was what does that mean . Thats one of the things were working on with the isc for a better design. What is a winner asking for consequence within the federal sector, what is it youre looking for . We know that when we help a federal partners begin to pull together and understand their emergency occupancy plans, that we help them to understand and we go to the consequence peace. When they look at that, after studying the federal security level, were also looking at the consequence peace. We havent figured out yet how to incorporate that in an algorithm method that will allow us to provide a reasonable and rational meaning if you will take consequent, to lets say the least facility. We are fairly certain that folks like irs, Social Security and others have stepped through the consequences of losing a facility or if it was an event something happened to the facility. We havent figured out yet how to incorporate that into a tool. Thats something were working on to figure out. I appreciate your answer and want to thank all of you. Look forward to working with you on this important issue. Thank you. Thank you, sir and a yacht. At this point im going to excuse this panel of witnesses, and thank you again. Thanks for the work i would you say as you head back for work from here, just keep in mind, all those people, hundreds of families who lost loved ones in Oklahoma City in that bombing, keep in mind those at fort hood who lost their loved ones. Keep in mind if you will the families of the 12 men and women who died at the Washington Navy yard. And just think of them as we celebrate christmas or some other way, the holidays, the families sitting around the christmas tree, their dining room table and theres somebody missing. Theres somebody missing. We need to do our dead level best every day to ensure that those number of indie chairs, people who are not around because of a tragic like the ones i just mentioned, keep their families in mind and that touches energized our efforts going forward. This is not just about process. This is not just about gao recommendations and comply with recommendations. This is about saving peoples lives and make sure they have a good life and share that life for a long time with their families. Take it with you, and thank you. [inaudible conversations] [inaudible conversations] to our second and final panel, welcome. We are glad you could join us. Just very briefly introduces and then welcome the statement and have a chance to ask some questions. Our first witness is mark goldstein, director for United StatesGovernment Accountability office, gao as was mentioned earlier, investigative audit arm of the United States congress. Were grateful for the work that you and your colleagues do. Mr. Goldstein is responsible for government property, Critical Infrastructure and in telecommunications. At the request of this committee, and i think of the congressional committees, gao has conducted 12 reviews of federal Facility Security federal protective service became part of the Homeland Security and 23 caching 2003. Planning and budgeting for security and challenges hampering protection of federal agencies. The second witness is Stephen Amitay is the emphasis on the first syllable . Good. Executive director and general counsel for the National Association of Security Companies. Mr. Amitay has worked with congress, federal agencies and government accountable office, focus on Facility Security since 2006. Final witness, david wright, mr. Wright is present of the National Protection and American Federation of government employees. Mr. Wright has served in his present passably since 2006. And mr. Wright is a 27 year veteran of the federal protective services, last served as inspector. Mr. Wright rings a wealth of expensive with me and work with the agency and congress to find solutions to many of the challenges facing federal protective service. We thank you for all of that. We welcome you. You will each are invited to summarize your prepared statement in about five minutes and your entire state will be made a part of the record. Thank you for joining us today. Let me ask a question. Were you all here for the first panel . Raised her hand. Great. Thanks for staying for yours. You are recognize, mr. Goldste mr. Goldstein. Thank you, mr. Chairman, members of the committee. Thank you for the opportune to testify on issues related to federal Protection Service and protection of Federal Buildings. As part of the department of Homeland Security the federal protective service is responsible for protecting federal employees and visitors an approximate 9600 federal facilities, under the control and custody of the administration. Recent incidents of federal facilities demonstrate the continued bone ability to attack or other acts of violence. Talpa published its mission sts connects the two security assessments and thats approximate 13,500 Contract Security guards deployed to federal facilities. My testimony discusses challenges we face in first ensuring contract guard are deployed to federal facility and properly trained. And conducting Risk Assessment at federal facility. It is based on jails were issued from 20082013 Risk Assessment and programs and preliminary results of geos ongoing work to determine the extent to which fps and select federal agencies facility Risk Assessment methodologies align with federal Risk Assessment standards. Our findings are as follows. First fps faces challenges in turn that contract have improperly trained and certified before being deployed to federal facilities around the country. In our september 2013 report we found a providing active should respond in screener training is the challenge for fps are for example, according to Guard Companies, the contract guard have not received training on how to respond during incidents involving an active she did it without injuring all guard received training on how to respond to incidents at federal facilities, involving an active should come fps is limited assurance that the guards were prepared for this thread. Similarly an official from one fps contract guard, one fps contract recovery stated that 133, about 38 , of its 350 guards had never received screener training. As result the guards deployed at federal this is maybe using xray, magnetometer equipment but theyre not qualified to use which raises questions about the ability to screen access at the gao facility. One of their primary responsibilities. Gao is unable to determine the extent to which the guards have received active should respond in screener training in part because fps lacks the competence and reliable system for guard oversight. Fbs agreed with gaos 2013 recommendations they take steps to identify guards that are not required training and provided to them. G. Also found fps can just like effective Management Controls to ensure its guards have met training requirements. Although fps agreed with our 2012 recommendation that they develop a comprehensive and reliable system for managing information on parts training, certification and politician, it does not yet have such a system. Fps continue to face challenges assessing risk at federal facilities. Gao reported in 2012 fps does not assess the risk at federal facilities in a manner consistent with federal standards. Gao spent in a result from a tank we work on Risk Assessment at federal this was indicated it still is a challenge. Federal standards such as national Infrastructure Protection plan to Risk Management framework and provision state that a Risk Assessment should include threats, phone number and cost assessment. Risk assessment help Decision Makers to identify and evaluate Security Risks and implement protective measures to mitigate that risk. Instead of conducting Risk Assessment, theyre using an interim vulnerability Assessment Tool referred to as a modified infrastructure server tool, mist, to assist federal facilities. However, mist did not assess the consequence, resulting from an undesirable event. Risk assessment experts jia spoke with jim agreed that a tool does not estimate consequence does not allow an agency to fully assess its risk. They have limited knowledge of risks based at about 9600 set of facilities around the country. Fps official stated they did not include consequence information in mist because is not part of the original design. Gao will continue to monitor this and plans to issue report on this issue early next year. In response to recent report, we have agreed with recommendations in our 2012 and 2013 reports to improve fps contract guard and the Risk Assessment processes. Mr. Chairman, this concludes my opening statement. I would happy to answer questions. Mr. Amitay. Chairman carper, serna ayotte, my name is Stephen Amitay and an executive director for nasper, National Association of Security Companies. Its nations largest contract degree trade association with Member Companies employed more than 300,000 Security Officers across the nation servicing governmental clients including numerous federal agencies. Nasc works with officials at every level of government to put in place Higher Standards and requirements for Security Companies and private Security Officers. Of most relevant todays hearing since 2007, nasco has worked with congress, fps and gao on issues and legislation related to the federal protective Services Protected security officer, pso program. Nasco also recruited federal Security Committee on its 2013 best practices for armed Security Officers in federal facilities. Not including the military services that are boxing 35,000 contracts at the officers across the federal government and the use of Contract Security is a proven, effective and cost efficient countermeasure to reduce risk and mitigate threats at federal facilities. To further ensure security at federal securities, fps and its security contractors need to Work Together to address issues and challenges with the pso program that gao has identified over the past several years. At the same time improvements need to be made to other elements in the Risk Assessment and threat mitigation process for federal facilities. These elements are governed by isc standards. However, as gsa has found out and as we learned earlier today, often the requirements of the isc standards are not met i federal facilities. One critical element in this process is the decision to implement specific security countermeasures for its facility. Ngsa owned or leased buildings, fps is is possible for conducting the facility to security assessment and recommending countermeasures. But trendy as you noted in your opening remarks, the decision template those recommendations or put another way, the decision to mitigate risk or accept risk is solely up to the Facility Security committee, or the fsc, which is made up of representatives from facilities. However, again, as gao has found, quote tenant agent representatives to the fsc generally do not have any security knowledge or experience but are expected to make security decisions for their respective agencies. A lack of experienced decisionmakers on fscs is something that security contractors have witnessed her stand and it calls into question whether fscs are making informed riskbased decisions regarding the mitigation or acceptance of risk. Of course, tight budgets have put pressure on agency to accept more risk. In the end, countermeasures deemed necessary for sigir should not be rejected because of a lack of understanding or and and willingness to provide funding. Tracked in support strength for fsc members as most teachers being able to challenge and fsc over noncompliance with standards or decision not to implement countermeasures. Old provisions were and legislation that was passed last congress by this committee. As to addressing the issues with fps, pso program that gao has identified, as most other issues of the program, while fps pace may not be as fast as dsl and to get a contractors would like, none the less fps commitment to improve the pso program is not questioned under been substantial progress made. Since the appointment of the director patterson, the degree of dialogue and breath of cooperation between fps and to get a contractors has been unparalleled and currently fps and security contractors are working on a host of initiatives to improve the pso program. To address the lack of fps resources to provide critical pso extra and magnetometer training, fps is about to launch a Pilot Program developed with nasco that will train and certify contract instructors so that they can provide this important trend. Fps is also moving to increase active Shooter Training for psos, and wisely theyre looking at what other federal agencies are doing in this area as well as seeking input from security contractors. Fps is working with nasco to revise and standardize the pso training lesson plans and his plan to require that security contractor instructors be certified for all areas of pso training. Fps is come out with a muchneeded revision of the Security Guard information manual, and it cover to instruct pso somehow to act and not following it is considered a contract violation to the format of this new version will also allow for making revisions as needed. One area that needs further review of the instructions related to a psos ability and authority to act and potential liability for acting in extreme situations such as active shooter as is provided to Contract Security officers of some federal Agency Congress but want to consider providing dhs the Statutory Authority to authorize psos to make arrests on federal property. Fps is also working to improve pso post orders and improve its management of pso training and certification data. For this latter effort nasco strongly recommends fps export commercially available technology. In conclusion much still needs to be done to address the pso program issues raised by gao. However, fps has come a long way in the past decade with its Contract Security force. Nasco looks forward to continue to work with fps and congress to improve the security at federal facilities. Thank you. Thank you so much. [inaudible] make sure your microphone is on. We want to hear every word. Chairman carper, send ayotte, thank you for the opportunity to testify at this important hearing. Im david wright, president of the American Federation of government employees, local 918 which represents federal protective Service Officers nationwide. Im also an inspector with the fps. We are committed to the critical Homeland Security mission of securing our nations Federal Buildings, but are important issues that required resolution. Federal employees and facilities are extremely vulnerable to attack from both criminal and terrorist threats. I want to assure you that my fps Law Enforcement officers are trained, equipped and competent in responding to active shooter attacks. And i am appalled that bureaucracy and inefficiency restricted our fps Law Enforcement officers whose office is less than one mile away from navy yard from assisting with the pursuit of the active shooter. Basically, its because the navy does not pay security piece to the fps. Congressional review of fiscal security at federal properties must be viewed in the context with the leadership required to accomplish the fps mission. Which to say the least, remains unfocused if not broken. At all levels. Fiscal sector to place a significant role in protection of all occupants of Federal Buildings, but the frustrating, efficient and outright wasteful bureaucratic system of implement and physical security to countermeasures through a flawed Facility Security assessment process, and implementation by facilities Security Committee who have to divert their Mission Funding is i can be and not to security. Security in the Dirksen SenateOffice Building is not based on individual Senate Offices ability to pay. Why should other major federal facilities be different . The fps expected workforce is constantly beleaguered by new and or modified security assessment programs, and individual conflicting management demands throughout the assessment process. Ive lost confidence in the ability of the National ProtectionProgram Director at to resolve this wasteful process. I understand the Department Science and Technology Directorate has offered to make the integrated rapid officials screening tool compliant with the isc. It was tested by both General Services administration and officials at the federal protective service. I think that would be a good start to ring again our assessment problems. The use of private Contract Security guards at major federal facility is a risk. They are basically limited to the arrest powers of a citizen. The proactive Law Enforcement patrol and weapons screening at this building is accomplished by federal Police Officers who have the lawful afford to respond to active shooters, and how can we demand less to Federal Buildings with thousands of occupants . When he arranged to buy a system from his neighbor on behalf of the government. The punishment of a three day suspension is the opposite of accountability. Ive been told there are other instances of misconduct by equal and even higher ranking officials. After accountability is established, performance across the board can improve with focused professional and ethical management that builds on best practices in the regions. Give our inspectors and Police Officers adequate. Com and tools that work in direction on priorities and will make sure the job instead. In conclusion, federal employees and the public they serve deserve the best and most effective protection we can provide. Theyre not getting that now, an expeditious and fair action by dhs and congress is required. Once again, i thank you for this opportunity and im available for questions. Mr. Wright, thank you for coming and for your service. Senator ayotte for the first question that this panel. Senator ayotte. Thank you, mr. Chairman. I appreciate that. I want to ask rest mr. Goldstein is particularly on the gao report and what you have found. It really troubles me when we think that there is no comprehensive, i believe you described a strategy or oversight model. And then, the fact we are not sure how many people are receiving. Theres certain that category receiving act of duty Shooter Training and or screener training. How can we from the gao perspective what is your recommendation in terms of the policy is how we can do this as quickly as possible to address this problem . Thank you, senator. We been concerned with respect to active Shooter Training and training on magnetometers that fps has not done a good enough job at ensuring that his contract guard work force is able to get that training. One of the problems of the active Shooter Training, which i think people dont understand, though, is it is a small part of one part of the training they receive anyhow. They get kind of a special training or two hours, which covers special events of various kinds that might occur in a building. Out of 120 hours to receive overall, only two hours go to a special event is only a fraction of that actually covers active Shooter Training. Its important to recognize contract guards are not really getting active Shooter Training for the most part. We are concerned they dont have enough training in the area. Sanest roofer of magnetometers. When gao did Penetration Testing and penetrated all 10 buildings we try to get into in a variety of different cities with bomb making materials, we found out timecards did not have the requisite training to be a post and we find now, several years later, but many guards still do not have that. Manage the contract guards. Yes, maam. Let me ask mr. Wright, with respect to the agencies that can pay the fee, how does your training differ . How does the training of the individual i understand would work, maybe i have this wrong, but what worked in the federal protective service union. You know, when i look at this training issue, do you know how the training differs . The as federal law in person officers, we complete our training that the federal law enforced the training center. Said he would go through the same veteran training of any Law Enforcement officer . The yes. There is a slight difference. We are talking contract guards. They are stationary at their pose, whereas our federal protective service inspectors and Police Officers are mobile. And if he were to the point of your testimony, if you were to provide the services, for example, at the navy yard at the federal protective service, just so i understand, would you do more of a roaming capacity . The capitol Police Officers actually seen that the magnetometer when we walk through. Im trying to understand physically what this would look like. That is the model i would look for is a model that works at the capital and capital buildings that you would have federal officers began their career at the magnetometer, at the xrays before they promote up and gain seniority and go out into the field. And i want to understand, is there other agencies with regard to this training issue on the fps contracting issue, is this something we are facing beyond the navy yard . Is in the contracting issue in terms of the training issue goes well beyond the navy yard facility. Is that true, mr. Goldstein . The work weve done here focuses on sbs. We have not looks at contract guards situations. It would be focused here on the navy yard. Ray. We have found that the training overall that fps is given, by nasa, the pentagon force protection, kennedy center. They remind generally with the kinds of training you would give to a contract guard at the federal facility. The problem is implementing it. Thats where we seem to see the falloff is ensuring the guards are actually getting. Theres basically no accountability. We can check out the training box, but no one is saying this person has done it. We are tracking them. Basically no one person is setting, you have to do a certain amount of streaming you have to complete every year and that is part of being in that position. That isnt happening with this . Excuse me, i senator coburn noted, those are contract requirements to have your protective Security Officers have to require training and certifications. That would be a contract violation. So we are entering contracts or recount of every choir to train a preening . With the xray and magnetometer training, of the 132 hours of required training for fps Security Officers, contract guards, 16 hours are provided by fps, eight of which is xray bag screening. Fpss inability for their personnel to provide that training is an issue that the gao has noted. That is not a matter of the security contractors not providing the training they require to provide. Were not providing training for security contractors come in but we should be reviewing contracts to make sure to properly prioritize the type of agreement were brokering for background and training, shouldnt we . Theres a couple issues. One is, as mr. Amitay says correct me, it is not providing in many cases the training theyre obligated to provide. On the other hand, fps is also not gaining the assurance that he is a contract Guard Companies themselves are providing the training that they are obligated to provide. Theyre not doing enough for the checks and certifications. Who is watching all of this . You are watching that, but who within the chain of command, and meaning to management of this is making sure it gets done . Each region is supposed to go through a process to assure themselves into checks and audits. Some regions have not done it. Some have not done at any random fashion adult with a but they could gain assurance. Some have done it. But weve gone in and looked at what theyve done, not only did we find our own breaches in any case is a guards standing post about proper certifications and qualifications, we also found significant disparities between our review in the review fps had done as well. I think also some of those disparities are in the documentation per se. I think there are instances where the guards have received required training. They do have required certifications, but there are issues with the documentation. With certain medical requirements. Some require a licensed physician and others could be a nice bright visionary. Gao might come in and looking at what the current requirements are for licensed physician and see this ps ill was kind of banners practitioner and is in violation. I know my time as i peered what we talk about here is the documentation on this training for the most important focus here, the screaming and active Shooter Training. It was a wide variety of issues. Weve got not just the magnetometer, but we found 23 of files we reviewed contained no documentation for the required training and certification. This could be firearms training, drug testing. No indication fps we reviewed is across the spectrum of the certifications cards need. My time is up. Thank you. Thank you for those questions. Well ask two questions. The second one i am going to ask, i like to ask in a couple situations like this, different panels, different points of views, a broad range of perspectives to testify and answer questions. I want you to beach pic may be one we will say to you. Go back to what you hurt one another saying in response to the testimony, response to questions. In fact, the first panel, some of the things they said in the testimony and just thinking about takeaways for us. You would just like to put the exclamation point behind it. Keep these couple of points in mind. These are really good takeaways. Thats my second question. Seal be thinking about that. The first question i have is for mr. Goldstein. Re attack two days and some extent. I would say to be visited very, very briefly. In the past decade or so, youve overseen 12 independent reports of federal facility in the armed card programs. You collaborate with state and local Law Enforcement and Human Capital planning. Gao has also conduct it covert testing. You talked about some of the stuff thats gone on at federal facilities. In other words, they tried to penetrate how secure they are. Its a little like what we do in the Nuclear Power plant world. How we can, for the record, how would you assess federal security facility today . Over 30,000 feet, how would you assess federal Facility Security today . Realizing way on a time continuum. We focus more and more going back to especially 1995. How are we doing today . Getting better, getting worse . Is an uneven . Is very uneven, mr. Chairman. Yes, there have been improvements since Oklahoma City and since the twin towers of course we have more focus on this area, more intelligence as well. Some of the basic issues still remain unresolved. The kinds of issues he got up in some of your issues brought up this morning. They still do not equate information in the forefront in terms of getting into a Federal Building and making sure not only to people who stand on the frontlines of Federal Buildings are qualified to be there and can do the service they are being paid to do, that taxpayers are paying them for. More broadly, we are wisely using Government Resources in this area because we havent defectively adapted a Risk Management process to the federal portfolio, virtually every building at a level three or level for Security Risk is treated in the same fashion. We dont prioritize across that portfolio in an effective way to make sure we are effectively spending Government Resources. I think we still have a long way to go. If a question is maybe you had to pick the next thing that the federal protective services are to be doing in order to further improve federal facilities, securities expeditiously as possible. I dont know if thats a fair question, but take a shot at it. Weve talked a lot this morning about the two fundamental issues on Risk Assessment and contractors. While they are moving slowly, i think theyre trying to move in the right direction in both of those areas. The area that is still the Security Community here and has come up a couple of times is the three leg will between gsa, federal Security Committees and fps in trying to get security at Federal Buildings. Should there be a significant role for individual agents used within a specific building for people who dont have a lot of security back around. Should they be making decisions about the governments buildings . By the isc has developed anders to try and improve the level and effectiveness of the federal Security Committees, thats an area they still need to spend more time in trying to figure out, is that the best way we can protect Federal Buildings . Been that good, thank you very much. I am going to ask you to respond to my first question again. A pointer to really like to say of anything else you heard in this hearing, dont forget this. Theres a few things we have to keep in mind. Just one or two if you would. Go ahead. If you will indulge the focus of this hearing was navy yard tragedy. Just very clearly, right off the bat in regards to active shooter, look at our jurisdiction and authority. Our guys responded to the navy yard. We were lasting two minutes away and we had people at the d. O. T. , the department of transportation facility right across the street, ready to act his age and use their training and equipment. We were held back. That is just a real low level status. I need you to demand accountability. This committee, as referred to by mr. Goldstein in 2009, after they penetrated 10 of our buildings, our sbs director sat here and committed to this committee that he would fix the national weapon detection training program. To this day, that program is not complete. Are we making any progress . Uneven. It is scattered across the nation. I think one of the big problems with fps is you finally have a vision or at least someone is a vision at headquarters. I guarantee you, once that vision these headquarters, it goes down to 11 different regions. I think three, four, five different Senior ExecutiveService Officials and the message gets lost. Thereby once again reducing any semblance of accountability. We have 11 different regions and 11 different ways of doing business regardless of what our headquarters says. Okay, thank you. Mr. Amitay. Thank you. Going off of what david just said, it is true that there is a vision now at headquarters. Part of that is to standardize the training, to increase the training and the lines of communication with the regents do need to be improved. Of those than a problem with fps, the fact intent to do with 11 different regions. They think youll see as fps cant even mention the national weapon detection training program, which is basically the xray and magnetometer training for pss. That is a new program that requires six hours of initial training and eight hours of eight or pressure training to the current requirement of eight hours of initial training and essentially eight hours combined with 40 hours of Refresher Training every three years. Thats a positive development. Delivery of the training has been a problem and has been slow getting it out. I think fps realizes the inspectors really should not be doing training. That should be their mission and theyre starting to turn this over. They want to turn it over to certified Contract Security and struck hers and we think thats a great idea that will allow for more cost efficient and faster training. Also, an active Shooter Training. Definitely, fps needs to be doing more with that. Other regencies are ahead in terms of training Contract Security officers to respond to active shooter is immense. Ive talked with several contract is in a basically say what those instructions opposed orders, there is some confusion for pss as to what they can do an active shooter situation. Obviously, as the instructions do say, when youre faced with an active shooter and loss of life coming you can engage them. Are they able to be more aggressive in terms of maybe detect being an active shooter. The person comes and has been really suspicious. Can they get into the guys face and see what hes doing . Ive been in told that at d. O. E. , the active shooter policy for their Contract Security officers is basically dont let the threat contained in. I think fps is working to improve the training, to bring it up to a higher quality. They are working to monitor better their certification and training records. Stay on them with it. There is technology out there. I sometimes cringe when they say we are working with science and technology to basically try to come up with a Data Management system, some theme as was pointed out, the contractors have greater integration in terms of a comprehensive Data Management system. So the fps contractors can no gao can know who does have the required training certifications. Already. Thank you. Mr. Goldstein, last word. Thank you, mr. Chairman. One quick clarification. Gaos recommendation, thereve been 26 between 2010 and 2013. Buyer records, only four are in process and have been a process for three or four weeks. We will provide your staff at the exact information. Is very interesting. Thank you. Three points brought up this morning, which is very relevant. I think it is important there be better clarity and to contract liabilities. Weve interviewed dozens and dozens of contractors over the last decade, all of whom have felt they dont have clarity on what their roles and responsibilities our and when they can is for someone they when they cant use force. Most have told us over the years that their companies have all been said, did you ever pull out your gun. Dont you ever do anything with it. There is a lack of clarity in this area. The second is the role of the inspector at the federal protective service. It would be great if they were able to come as mr. Wright has said, be able to roam around more, to be able to assure the security and buildings they responsibly for. They are doing other work. Theyre involved in getting contracts at the door. Theyre often still contract officers. The level of things that they are responsible for really precludes them in many instances from actually being out and about and be in the and ears and taking care of the police function they really have. That would be the second. The third finally as i dont believe there is much ordination at all based on the work weve done in the past with local and state Police Jurisdictions so that when tragedy does strike at the federal protective service has worked out in any kind of detail with local Police Jurisdictions exactly what kind of focus, what kind of approach, what kind of countermeasures they can take in the event of tragedy. More work needs to be done in that area as well. Thank you all for being here. Thank you for what you do with your lives. Thank you for your preparation for this hearing and for your response to her question. Mr. Goldstein, a special thanks to everyone at gao for the continued good work that you do. Our caucus lunch has begun and im late. So im going to wrap it up here. If i had more time, one of the things i would get into this the issue of turnover among these contract officers. I dont think we spent much time on that. I would just say as a closing thought, when i was governor of delaware, we had a real problem in the area of information technology, training folks who work in that area as state employees, to provide skills and get hired away by someone paid a lot more money. The governor has succeeded me was further to realize that we ought to pay and changeup the way we incentivize folks to work for the state of delaware in that arena. We have a similar problem at the federal government. If you look at the skill set and compensation packages and the way we attract and retain skilled folks in the cyberworld, and the department of Homeland Security and National Security agency, theres a difference. Our staff and colleagues are working on the way to reduce the disparity said dhs will hire people to work in cybersecurity and train and hire away by others. Were going to work on that. It would be interesting to know. Training is so important. Not just original training, but the quality of that training. My guess is theres a fair amount of turnover in these jobs. A lot of training dad, in order to the benefit of federal taxpayers, but those who ultimately contract officers go to work for. Divide my time, i ask each of you to respond to that. Just raise your hands, is that a problem . Is that a concern we should have . Okay, thank you very much. I would say in closing, the hearing record will remain open percent 17 months. All right, 17 days. Until january 3rd at 5 00 p. M. For the submission of statements and questions for the record. Im sure youll get some. We would appreciate you responding to those. Again, thank you for being here with us today. Best wishes to you and your families during this holiday season. Thanks very much. [inaudible conversations] [inaudible conversations] [inaudible conversations] we now have set their norms instead of theological norms that govern our acceptance or rejection of the ways in which a god or god or goddess can be to people. So for instance, david caresses saying that he has the additional insight into the bible and that deep inside help the other members of the community understand the bible, particularly the book of revelation vendor and understanding of living in a way most americans dont accept. That by itself doesnt have to be a problem. But when that leads to other elements, then that trigger both on for a snack as the popular press is concerned. And suddenly, this idea of somebody listening to god and having his followers to things that seem to be out of the national norms, but dangerous and that needs to be policed and controlled. Federal trade commissioner, julie brill spoke about efforts in the u. S. To secure personal information on the internet. Shes introduced by a valid account on foreign relations. If youre ready, we can get started. Although, we are delighted to welcome you to this roundtable with ftc, federal trade commission, commissioner julie brill. This is part of our policy series made possible by a generous grant from the verbena foundation. I am instructed to ask you to please or not their cell phones. If you havent figured out the nice gentleman in the corner, this is on the record. In fact, we arrived he spent. I am sent to you, a senior fellow here at the count over digital policy. Juliet burdock a has organized this roundtable series and were grateful her. This meeting is happening that incredibly timely moment that leading Tech Companies are meeting with the president at the white house today. Theres a hearing in the senate tomorrow on data brokers in the trade negotiations with europe. The u. S. Is expected to table something on ecommerce, cyberframework throughout has been recently released and you published on november 27, some recommendations on the safe harbor. We are thrilled to be having this meeting today and we know it will be a fantastic conversation. Im going to kick it off with brief comments. I recently served as ambassador to the oecd in paris. We convened a group of business leaders, government, technology and ngos. And came up with the first set of Global Internet policy principles. These principles and privacy guidelines affirm to ideas that are sometimes missing in the debate and are very important for us to remember are not in conflict and are both essential. The free flow of information. The free flow of information at this agile to an open internet. Of course im an open internet has become an essential platform for innovation, expression and commerce. On the other hand, there is a need for individual countries to make rules protecting their, whether its on privacy, cyber, fraud. These two things, sometimes the debate forget they are both essential. Were so lucky to have julie brill here to talk specifically an area privacy where shes become a leading voice. Julie, just to give you background on her, i will take you her story. Julie was sworn in as commission in 2010. Shes been focusing their on issues affecting todays consumers come including privacy, advertising substantiation, fraud and competition and High Technology and health care. Before she came to the ftc, commissioner brill as attorney general chief of Consumer Protection in a trust for the North Carolina department of justice. Before that, she was an assistant attorney general for the state of vermont for over 20 years. For 1998 to 2009. Commissioner brill has chaired the antitrust section of the american bar association. Im just halfway through. Prior to her cruel month for a snack, commissioner brill clerked for vermont, Federal District court judge franklin junior. She graduated magna laude from princeton and nyu where she had a root scholarship for commitment to Public Service and nyu last goal. Commissioner brill has been at the lot. She perceived awards and has testified for congress, published numerous articles, thereve been many expert panel, Consumer Protection issues such as pharmaceuticals, privacy, Credit Reporting. When im most grateful to commissioner brill for is the cutting issues. Shes figuring out what the right policies are that balance all the equities and then shes finding a way to speak about it in a way that satisfies the academics, advocates an average consumers. I have to believe part of that comes from the fact she doesnt spend all of her time in washington. Shes based in vermont, where her family is and it actually seen her there so i can testify. She does her Grocery Shopping there. She thought of getting out around the country in the world and that gives her a really fabulous perspective and we are so lucky to have her at the commission. Thanks, karen. I am pleased to be here. I wish i had your resume to read because yours is impressive, to. Even though were both really young. The way well run this as im going to ask julie a few questions. Then well open it up because all of your experts. This is really roundtable discussion. He just returned from 10 days in europe speaking mostly about privacy issues. Can you tell us about the mood they are and of course we are also aware of the fact that the nsa surveillance revelation, the line between commercial privacy and government privacy has been completely blurred and theres been a real change. Its been interesting. A number of people who are here who would bear with me were also in europe, will comment on this that make it to the question and answer period. We should start out by saying the u. S. And the e. U. In europe have a long history of cooperation. I mean, you know better than anyone that the oecd. We need to remember that and keep in mind as we are thinking about entering to work through some of the latest areas of a troubled some of the latest areas causing tension in a relationship that is basically very, very sad. The nsa revelation has created tension. I mean, there is no question about that. As much press as it is god here in the United States, i think its probably gotten much more in europe. I find that an overarching, especially seeing the change from september through now is that there is an increased willingness to try to cooperate and figure out a way to resolve the problems that exist. In other words, in the last six months ive been to europe or four times, both prior to this note and nsa revelation and if it timbre when they were still very, very fresh and i just got back from a long trip. I think between september and now, there has any recognition that we need to try to work through the problems. You know, there have been extensive government groups as well as private groups focus deeply on trying to address these issues here in the United States. You know, how should we be balancing a National Security and individual citizens privacy rights. There have been a number of working groups underway. Some of the results are starting to get discussed. There will be much more of that in the coming months. There have been working groups between the e. U. And the united state said that some folks in the working group that are european policymakers and whatnot have been able to interface with our policy leaders to try to talk through these issues as well. I think all of that has led to, while perhaps not a complete agreement on the way in which we doing things, at least an understanding to a certain extent of why certain things have been done and maybe the areas we need to address going forward. So you know, one of the things you asked about and maybe we should talk through is this issue of, should commercial privacy and government surveillance be treated together, or should they be treated separately . As one of the things i spent quite a bit of time talking about in europe. Should we focus on not . Sure, go right ahead. I have told my european counterparts and audiences in france are the same thing in the United States that the government surveillance issues are incredibly important. Its a conversation long overdue. Im very glad its happening here in the United States and europe in the trade atlantic discussion. The discussion around commercial use of data, i think, is a very important conversation. Nec have been here in the United States, but it is a separate conversation. It should be happening separately from the National Security issues. I say this for a number of reasons. I think if you look at the 1995 e. U. Data protection directive, it has National Security exceptions. If you look at the ways in which data flows between the United States and the e. U. , whether it is through binding corporate rules for safe harbor, any other mechanism, there are National Security exceptions. So we need to address the National Security issues clearly. But lets talk about commercial privacy and all that needs to be done in the commercial privacy scare separately. So lets talk about commercial privacy. Tell us your thoughts about the e. U. Privacy regulation outline and also this concept of adequate d. Sure. The e. U. Regulation actually i think mirrors a number of the things weve been talking about. But at the ftc, federal trade commission, which is the nations leading privacy regulator in the u. S. Or whether it is looking at some of the things happening in the state with respect to privacy. So when you look at the overarching, kind of policy is being pushed forward in the e. U. Regulation, you see things like a desire to get parental consent for information about children. You see references and provisions dealing with data breach notification. Ec privacy by design, which is a con fact that we have tried to urge on industry here in the United States. You see a focus on enhancing consumers control over their data, increasing transparency, improving data accuracy, strengthening Data Security and encouraging accountability. These are all concepts, whether embedded in law in the United States or are being discussed the federal trade commission and elsewhere in terms of developing best practices for industry here in the United States. These are all concepts. Frankly, we embrace. Certainly i embrace as they federal trade commission or and i know many of our counterpart also in race. So we have a lot in the United States dealing with childrens privacy, or collection and use of information about kids under 13. We have data breach notification law for the state level, not the federal level. It would be nice to have Data Security law. But we do have some provision dealing with this on the state level. And our privacy report, the federal trade commission issued a big privacy report last year. They talked about a lot of concepts. Privacy by Design Company to build privacy into products and services and not to push everything onto the consumers, overwhelming them with choices they need to make about privacy when frankly consumers are going online for using smartphones are engaging with connected devices in order to think about privacy. They want to do some pain with all this technological tools. So you need to build more privacy into products and services is deeply important. Having said that, i think there are areas where we definitely need improvement in the United States. I think we have a ways to go, especially around transparency issues. So i spent a lot of my time talking about need for entities that are engaged in big data analytics, profiling of consumers, especially when it is focused on consumers at the individual level, rather than trying to do with identifying information. When we talk about profiles created about consumers being used whether for marketing purposes or eligibility decisions, we need a lot more transparency in that area. When it comes to the internet of things that is connected devices, connected cars, medical devices, anything else that is to devise that connects to the internet. Again, we need more transparency and me to think about the tools that we can make available to consumers so they can stand what is going to happen with the information. Who will be collecting it and what they will do with it. I think online tracking through developing some tools were consumers is very important so that can dimmers can control the percent to which they are tracked online. Do not track is an issue that some folks that began with deeply and have developed some tools. Some of the browsers have developed tools. Some trade groups have developed tools. In some standards organizations are working on developing tools around tracking online. Id like to see much more progress made there. Finally, when it comes to legislation here in the United States, all ive been talking about the fire hasnt and the legislative sphere. Its been much more in terms of developing best practices and providing better tools to the ever so they understand that data is collect detainees and for what purposes come at better. We could use a more lost in the United States based on privacy ledges nation withheld. It helped level the playing field. It would clarify business is what ought to do and dont need to worry about and would make clear to the dimmers with their rights are and what can happen to their data. Particularized law around data brokers and data profiling would also be helpful. Ive also mentioned Data Security. So again, taking a step back and look at the transatlantic picture, i do think there are clear similarities between what europe is pushing. I think that here in the United States, we share many of those ideas and values and have been pushing it forward. Here in the United States, there is room for improvement. Ive certainly spent a lot of time talking about that. Let me ask you two quick things. One of the things is telling europeans when i was over at the oecd is while they think that europeans care much more about privacy than we do, what we would pay as you will have more rules on the books, but we have a lot more force. I want to ask you about that because youre at the enforcement agent v. Also, just where you see the safe harbor going. I read you think youre weak about it, but this report does come out with recommendations. A touchier talk about that. It is true. We have really good enforcement in the 90s its not as respected the laws we do have in the books. I have spent a lot of time trying to educate not only folks here in the United States and for instance the act community, the day need to make sure they and the laws that apply. For instance, if they are engaged in activity that might cut on Credit Reporting great time at last or a list a tool for h. R. Departments to use to screen prospective employees. Our Credit Report is not applied. I spent a lot of time trying to educate entities in the United States about the breath of privacy laws. Similarly, i spent time talking to european counterparts about the breadth of our privacy laws. We dont have a signed privacy legislation. In sensitive areas, but their Health Information, although we can talk a little bit about that because there are some gaps they are. Whether its Health Information, Financial Information from a childrens information or Credit Reporting information, we do have good laws. The ftc is death by the cop on the beat. We do great and force them. Ive heard many european counterparts say that they wish they could combine their regulation but the ftc enforcement of prowess. I know for some businesses that might be more freight team. I think it was a chuckle. They do privacy enforcement because one of the tools in the last i talked about is the federal trade commission. Their acts and practices. It doesnt focused on financial fraud or add substantiation. And fact, it was written at the height of the depression and the joining up with the law that created us in 1914 at the height of the progressive area and is designed to be very broad and remedial. We use it in just that way. In the privacy contacts, weve used are unfair and deceptive privacy act of not only to focus on some of the biggest consumer facing companies, some of whom are represented in this room. Google, facebook, myspace and twitter are under 20 year order as a result of i believe they have violated the federal trade Commission Act and engaged in unfair deceptive acts and practices. Weve also focused on smaller players that arent household names, but are playing key roles throughout the echo system, whether its for mobile or internet or a case. Hardware developers, active developers, analytics firms, ad networks. You name it, we have looked at the crack this is when they been brought to our attention or when weve learned about them. If we felt they were violating either the deception principle or in fairness principle, we go after them. How do we two of the safe harbor we understand how rules work in this. How can we safeguard the safe harbor and the flow of data . Thats one of the areas ive seen change just in the last three. As the result of the nsa and snowden revelation, there started to be a growing conversation in europe the safe harbor was the problem. The reason why european citizen data was being looked at, was being examined by government for National Security purposes was because of this tool. The safe harbor is one of several mac in the end that is in existence that allows for the transfer of data on a Company Based says between europe and the United States. Without getting too detailed into involvement in all of the rigmarole of the lot, i can say from an Economic Perspective and from a business is, it is clearly an incredibly important tool and allows for a huge amount of trade and important relationships that consumers benefit from and businesses benefit from. Yet it became kind of a target in this conversation. I started to say in september and i said last week, it was an easy target, but it wasnt the right target. If we want to focus on government surveillance issues, we should focus on government surveillance issues. Whether its happening through companies that have signed up for safe harbor or corporate rules or inadequacy determination, or any other mechanisms for crossborder transfers. You know, that is where the conversation should have been around the perp or is owed the government surveillance. So what ive noticed, frankly the e. U. Commission just issued a report. A first step in its report on safe harbor. I think this conversation had been engaged in, as well as others. I dont want to say im the only one i any means. It seems to have gained residents resonance. If you read the latest report on building trust, as they call it, between the u. S. And e. U. , they talk about the importance of safe harbor and the importance of maintaining it because of the important ties and level of business thats transact it between the e. U. And the u. S. Having said all of that, safe harbor has been in existence for 15 years had a lot has changed. You know, i could ramble off all of the facts. Just think about the number of smartphones people have come to the collection of geolocation information. All of these things does not exist or existed and perhaps nobody else is. I think what we need to do is look at safe harbor and say, are there ways we can improve it . The e. U. Commission has made her Team Proposed recommendations for improving it. Some of which i and we ought to, on this side take a serious look at. I talked about that last week in europe. I said there are ways without doing too much work. These are really a heavy lift, but it would help get rid of some of the irritant in terms of how safe harbor operates. For instance, creating better links between companys privacy Policies Department of Commerce Website so its clear whos in safe harbor and whos out about alternative dispute resolution that is each of the Company Since you seem. An alternative dispute recognition is required for every company that signs up for safe harbor of some kind or another. The vast bulk of Companies Use an alternative resolution mechanism like trustee, which is free. Its free to european citizens. If they have a complaint about a company, they can go either to the European Data protection authority, kind of like the country specific regulator or they can go to one of these companies and have their complaint heard for free. 20 of the company signed up for safe harbor are using a mechanism that will charge the consumer money. A lot can consumer advocate, i just had to say i dont think that the right direction here. I think we should work hard to try to get those alternative dispute resolution mechanism fees down as close as we can to europe. We need to increase transparency on the website and i think again, those are things that can be done fairly easily so people can understand what companies are in safe harbor, what companies are out, what their privacy policies arent things like that. Finally, we have to be lucky not the other crossborder data flow frameworks that we have been talking about globally. Aipac, and the asiapacific crossborder framework thats been developed and pushed forward has a really interesting concept builtin around accountability mechanisms. Before a company ever reaches someone like me, a regulator who said he violated the law, they have put in place mechanisms for selfassessment for checks so that there is an entity, a private entity that can help ensure they are in compliance. I think it is a really good at that can be helpful to companies. I think we have to be thinking about whether or not there is room within the safe harbor framework for appropriate, you know, accountability mechanisms that are basically selfregulatory mechanism before you ever get to the cop on the beat. Those are the ways in which i think safe harbor can be improved. The e. U. Has all the things ive talked about. They have in some fashion or another mention. They talk about a number of other proposed changes, some of which i think would be tough. Some of which i think need to be focused need to be a discussion within the national Security Community. Some of them again i think relatively easy lives for the United States and we ought to be taking a serious look at them. Its a great tour of whats going on between us and europe. Chew wants some of that provocative. I think well have a great discussion. I want to open it up to questions. Please identify yourself when youre called on it that would be terrific. If you want, you can turn your name tag on it side. I work on near as this gentleman has done in the back in an exemplary way. Thank you. I enjoyed your remarks in europe last week. Can you say where youre from . Alan roth. [inaudible] a question i would have for you is do you think the u. S. Should be making a case in the lousy describing the enforcement you referred to for adequacy and the safe harbor for the United States, its almost in congress to guess, it works good and plays very long time. Its ursula useful purposes. Some of the countries deemed adequate armor my guess is there is not so much enforcement there. Maybe they have rules, but much less of orders made. Interesting and provocative question. That would be my divine. Im going to call on people. Weve got some twitching of it there. [laughter] weve done a lot of work, looking at the Economic Impact and how its affecting u. S. Companies. One of the big changes are seen, specially nationally as the growth of data nationalist emoticons that other countries are really looking that restrict teen data, even within their borders. This obviously has a huge impact on the internet, how it works, does this models and u. S. Tech companies. Be seen that in the past. The problem that we really see here is for inadvertent disclosures that additional privacy and security threats, theres a Lot Companies can do. They can make their systems more secure. We cannot gymnastic laws. But what we cant do is have from the air, and a response if we give our data to a Foreign Company that the government will mandate. Theres not in the third can do. Thats why its such a problem right now, especially since this is the private sector. The question is aside from recommending the Geneva Convention not data, how do we address this . It seems like thats the sticking point, but not in the private sector can address. Its a very important issue. I think as i said in the opening dialogue that we had covered the issues around government access to information, whether its information that private Companies Hold or elsewhere within government or the state level or local level, all it is is theres a huge come in my view, robust discussion underway in the United States about the appropriate level of surveillance and how its taking place. I think its great that conversation is going not. Their personal views about it. Im sure everybody has personal views about it. My job as a federal trade commissioner is to focus on of information. They are, and not fear of commercial use of information, again, i think i would disagree with you that theres nothing companies can do to better protect information. I understand where youre coming from, which is when someone taps into their data coming in now, whether it is a Government Entity or whatnot, they cant really stop it in the current framework and theyre very involved in that conversation here the first conversation i talked about is how is government doing that. Having said that, i know you want to jump in, but having said that, i think there is a Lot Companies can do to improve privacy protection. Again, focusing on privacy by design. Deidentifying data as much as possible. We have tons of recommendations about what businesses can do to enhance privacy. What is so special about this moment, in light of the revelation, while again i think commercial use of data and government use of data is separate and separate conversations, it is a moment in time for our society, as well as the Global Community is really focused on what is happening with data. Now is a really good time for companies to step up to the plate and say look, we get it and were going to do as much as we can to try to enhance privacy and Data Security. Uic not from Tech Companies, in particular the United States, or a dialoguing today the president and have written a great deal as their desire to disclose more about what is happening in the governments surveillance side. Noticed macina and very much appreciate that. Looking at how that plays out, if you could talk about how we keep that tone going because what really helped us is bridging the view of the 13 points and that was going to take what must be done and the safe harbor as you put things we should look at very carefully some of them very powerful and that is simply much more difficult. A great question. And i think that we in the United States need to take that list of 13 items very seriously. I think that we are taking it very seriously. I am sure if there will be a group focused on developing a formal response. I have had conversations with my counterparts and folks at the Commission Last fall about my personal thoughts about them including those which i thought were relatively appropriate. Not necessarily easy with i didnt focus on it in that way, but these things should be done. And then those that i thought would present a more difficult would have a more difficult road for good reason and i tried to describe what some of those reasons are, but i do think its important that we move, meaning our government moved relatively quickly because i do think i am pleased to hear that you recognize the same shift. And all i would like to keep the momentum going in the current direction. The conversation going in the direction it is heading. I think that is important and one of the ways we can do that is to make it clear to the european counterparts that we are recognizing the issues that they have raised and we think there are serious issues and we want to work with them and im hopeful we will have a position and sit down with them and talk through each of the points. They mentioned to me various time frames in the report but will be sometime in march or april that we will be looking at january which is just a couple of weeks away to begin this conversation in a robust way because there will be evens that will take place in europe that identified for me that will raise the political focus on this issue even more. In order to build the trust that the europeans are asking us to build i think we need to do our part in that bridge building. I want to learn more from you about the american enforcement of privacy. Let me first say i completely agree from the limited experience its not much there. Every time i go and give a lecture i ask people in the audience if anybody had ever asked for permission to use their information for a secondary use and i havent seen one hand and going up but i need to know more about the american side. If it is that by the private company in arkansas and this company was 35 contracts i dont see anybody stopping them and the difference between having the data base is very charismatic and it is one click away for microsoft is building in new york city into one base it is hard to imagine the privacy. Teach me some more about how you protect our privacy. I think a lot more needs to be done with respect to the profiles and with respect to the data brokers. You were referencing one particular company in arkansas and you referenced another large company. With respect to the entities that are engaged in profiling consumers that is the commercial entities they are creating profiles and the consumers used from the marketing purposes for eligibility decisions that are not currently covered by the law. And some of the profiles have very Sensitive Information including Health Conditions like very detailed information about Health Conditions, sexual orientation, ethnicity and other what i think most of us in this room and society would believe is highly Sensitive Information. I would very much like to see with respect to the day the brokers that are creating individual profiles about consumers. They would call reclaim your name and i would like to see American Consumers be able to reclaim their name by the use of some of these Greater Transparency control tools. So for instance you referenced the Arkansas Company that we might as well call it axiom since we know who we are talking about the taken a step down the road providing the transparency tools to consumers they have a portal and the data that provides some information about some of the data they have on the consumers that is used for marketing. There are other large data brokers that could easily provide similar transparency tools and its not just important to let consumers know what data you have about them but to the extent that its used for marketing purposes i think that it should be the consumer should have the ability to say i dont want to be marketed based on the fact that i have diabetes. I dont want to be marketed based on the fact that i am of what ever ethnicity or whatever. And consumers should also be able to correct information if they want to. And then finally, to the extent this information is used for important decisions like are you who you say you are and can we do business with you, eligibility decisions that are not governed by current law. I think consumers need to have the right to see that information and correct it if its wrong of course decisions are going to be made about them that are based on inaccurate information. So, we do a good job of protecting privacy. And i try to outline all that or some of that and my opening remarks. Its hard again to talk about it so quickly that i think that there is room for improvement particularly in the area that you have identified. Some the news about safe harbor in a slightly different direction you made the point that the way things have changed in the last 15 years with respect to a safe harbor the that is also true with the internet itself. So that was 15 years ago. It was 11. It wasnt transactional. There was a lot of structured data. Today the internet is one timoney and there is unstructured data. The way we think about the internet and privacy and the guidelines and those were obviously in a different era. In your thoughts how do we get that those guidelines in the 21st century and the Transformative Technology and you talked a little bit about the transparency sort of in the context of the beta brokers who but what would you like to see in terms of transparency and accountability as we begin to think about how we get out of those guidelines. That is a good question and deep because there are a lot of different ways in which we can adapt some of the principles for the modern technology. I think a great starting point for that conversation is the report that the federal trade commission did in 2012, where i think thats fair information practices are still good because they are general and the trick isnt so much do they apply to new technologies but how we are going to apply them to the new technologies and so we talked about implementing three or four techniques if he will or getting the business to focus on the ways in which they cant help shape the new technology so that consumers do have notice and choice and theres accountability and transparency and accuracy and all those other principals so we talked about the need for the proxy by design. That is one issue and i touched on that briefly before and that is the concept where we dont place so much of a burden to make a million choices about privacy because it is just too hard and overwhelming for the consumers. Instead, companies folk focus on building and they do so at the beginning, not when the problem arises but they are sensitized to doing that at the beginning. So the second would be to engage in a much simpler notice and a choice for consumers. That is its fine to have a fullblown Privacy Policy thats, you know, ten pages in small type but no one ever reads except for academics and technologists and we read them but no consumer actually reads them and to have that at the end of the day is helpful but its much more important especially on smart phones when you think about the limited realestate that is available to have quick messages to consumers. We are about to collect the location and download the contact list. The icons, pictures, simplified notice and choice is a very important issue. Transparency is the feared initio and i touched on that and i think there is a lot more that we can do to inform consumers about whats happening with the data and what control they might have. The fourth principle is important and thats the issue of the identification and how as much as possible we can focus on using the information in a form that is identified as robust as possible. And we have a three part recommendation on how to identify. Three part recommendation on how to identify the information. It is identified to the extent reasonably possible from a technological perspective and a company that is engaged in using the identified information promises to not read identify the information because now theres been so many studies showing how easy it is to take the identified information and identify it with individuals and in particular consumers. So theres a promise to not identify and if the data is transferred to anyone else, the company that holds the data makes the company that is giving the data to promise to also not agree identify. Those are some principles that i think helped to deal with the current incredible change that weve seen in technology and focus on how we can implement to these important principles in this new technological age. But its complex. I recognize that. It is complicated, but you are making it come alive. I apologize and we will come to you next. Im going to pull together your comments with those that we heard earlier where i heard it but i will also add another setting this morning where we can identify and i am interested in the negotiations between the United States and europe and recognize the word is because of the snowden regulations making it an even more difficult job. Negotiating between the u. S. And europe which is commonly called ttip trade investment negotiation partnership. You suggest that there is room for agreement at least in your positive reactions to recent european regulatory annunciations. I am very conscious that there is a whole u. S. Interagency process in the ftc and the agency and yet i dont know the how much you have to coordinate with the trade representatives but many people feel the trade representatives going on between europe is really more about regulatory harmonization than anything else. So what extent do you have to really or do relate in this atmosphere in which these negotiations have now had three meetings and the president has put some emphasis on this . The issues i was talking about in terms of the safe harbor and the e. U. Report in terms of how to improve to maintain net am the separate ttip discussions and trade negotiations. We are an independent agency has pointed out we are not officially the federal trade commission is not officially involved and the ttip discussions. However, the u. S. The art and other folks who are deeply involved in it, the u. S. Trade representative and others do consult with our staff about technical issues particularly when it comes to issues around privacy enforcement because again trying to explain it is in the sentence, it is a. So, we are not tall at the table in those discussions and my job is to focus on protecting consumers and protecting competition and with respect to the privacy data flow it is to make sure that we have appropriately Law Enforcement and we are engaged inappropriate Law Enforcement as well as development around those issues. Ive been a cop on the beat at the state level or the federal level for a long time and by a big believer in enforcement. That is our job that is separate and different than the trade negotiations. Part of what is coming up is a lack of of the revelations created a real sense that the lack of trust or created for some type of negotiations as a part of the ttip and they talked about putting the chapter of the information into the negotiations and those of you that are not aware, the resolution put aside a fabulous task force with a Global Security internet to see whether in fact this is happening. There are other people on the side of the ftc. Do they want to comment in any way on anything . Okay. Thank you, commissioner, for your always thoughtful remarks. On the Application Developers ive come to the conclusion that the corporations are poor and making decisions for consumers, but they are only slightly better than the government particularly the foreign government. This is my personal opinion. When the consumers can benefit on a great scale from the mass customization and personalization. I worry that a rules set in place that might do things like limit the Data Collection done for the consumers benefit that limit the opportunities for the consumers to make choices themselves about what goods and services they can obtain at the low cost or no cost and im wondering if you can share your thoughts about what we can do to ensure that the mass customization and the personalization and individualized goods and services becomes an opportunity and they do not foreclose those by setting rules and the limitations. Some of what i have talked about i do think what focus on collections of issues. There are thoughtful questions as always. Whether or not there are permissible purposes for which information can be collected as well as used and my view is that in terms of attracting consumers online given the incredible depth of information that is now available, the explosion of data about each and everyone of us as we walk around with our smart phones and we use our applications and our engagement and Online Activity and the activity is all getting linked together to create a very rich profiles it strikes me that you are presenting a framework that arguably says if there is no collection we dont have any benefits for the consumers and the way that information is either collected or created. As a good example, we have some very strong walls about how the Health Information will be used, collected and used for the providers that work with them. The other entities that are really in the Health Care System consumers are going online and investigating what does it mean if my skin is itchy does this mean i have a condition or my kid has been up for five nights and i dont know if that is a fl