Some of our readers may have read about recent high profile data breaches, such as the one involving credit card information taken from many Barnes & Noble retail stores. Or they may have heard of the huge class action law suits against Sony which resulted from its handling of a 2011 incident involving hackers into the Sony Playstation network. In that case, the hackers accessed personal information including names, addresses, user names, passwords, and other personal information from about 77 million user accounts. And they may have read about the breach involving TD Bank, in which TD Bank misplaced in March 2012 computer back-up tapes containing personal information for 267,000 customers, but did not inform the affected customers and pertinent state authorities until seven months later, in October. Each of these instances brings to light some apparent misconceptions regarding the handling of data breaches.
Myth 1: There is no law that requires action in the event of a data breach.
Fact 1: There is no federal law (aside from laws regarding specialized industries such as banking and health care) that requires a response. However, 46 states, the District of Columbia, Puerto Rico, and the U.S. Virgin Islands require certain actions be taken in the event of a data breach regarding personal information, and each of these laws is different.
Myth 2: My company only needs to comply with the data breach laws of the states in which my company has an office or other physical presence.
Fact 2: A company is subject to the data breach laws of not only the states in which it has a physical presence but also the states in which it has customers.
Myth 3: I need only look at one state’s laws if there has been a data breach.
Fact 3:In the unfortunate event of a data breach, you need to follow the laws of each state where the affected persons reside, and not just the law of the state where their information is maintained or the breach has occurred.
Myth 4: My company can have a uniform response to a data breach.
Fact 4: State laws require notifications to affected consumers and state agencies in the event of a breach. Some also require notifications to credit reporting agencies. The laws are not uniform with regard to what constitutes a data breach, the government agencies to be notified, the credit reporting agencies, if any, that need to be contacted, and the contents of the notice to individuals whose information was compromised.
Myth 5: My company is not required to have a data breach response plan in the event of a data breach.
Fact 5: If the company makes sales to residents of Massachusetts, then the company must have a written plan to disclose how it intends to respond to data breaches. This is part of a so-called WISP, as required by a 2010 Massachusetts law. Moreover, a data breach response plan can provide a critical defense to class action lawsuits claiming that your company failed in its duty to protect customers against harm resulting from data breaches.
Myth 6: My company can play it by ear when there is a data breach, so it is of little value to plan.
Fact 6: A company must and should tailor its response to a data breach to the facts and circumstances of the breach—and so there is a need “to call audibles at the line of scrimmage.” However, data breaches are dynamic events that require immediate, consistent action to: investigate what happened, determine the appropriate responses to stop the security breach, shape the correspondence with individuals whose information is compromised, and decide on notification to the appropriate federal and state authorities. Most of the actions require approval at the highest levels of a business. There needs to be a signal caller for the plays based on a play book developed before the game and the play takes place.
Myth 7: There is no requirement that my company respond quickly to a data breach, and we certainly do not want our actions to take away from our company’s efforts to operate the business.
Fact 7: No state law requires a fixed period of time to respond to a data breach. Many of the laws require prompt responses, however. And every day of delay for serious data breaches increases the potential exposure to real damage done to persons whose information has been compromised. Sony has oftentimes been criticized, and it has been hit with a number of class action law suits, because of the one week delay in notifying appropriate federal and state officials and the users whose information was compromised. A data breach response plan permits companies to continue to operate their businesses at times of a data breach, yet take the necessary action in as short a time possible under the circumstances. Finally, many state laws require notice to consumers before a data breach has been confirmed where there a reasonable likelihood of such a breach. As a result, waiting until a full investigation has been completed can violate applicable laws.
Myth 8: The data breach does not affect credit card numbers. Therefore, there is no required response.
Fact 8: Each of the data breach laws require notification of consumers and state agencies if the information compromised involves personal information, which is generally defined as a combination of a name and a data element, which may be a credit card number, but may also be a social security number, driver’s license number, bank account number. or other state-issued identification number. In addition, data breach notification requirements can be triggered even if the data involved is encrypted, since the laws of some states provide no exceptions for encrypted information.
Myth 9: The information was compromised when possessed by a third party, so my company need not make any notification to our customers.
Fact 9: The state data breach notification laws generally apply to any company that stores or maintains personal information or owns or licenses personal information of an individual. Thus, if a retailer submits personal information to a third party for processing—e.g., to a company to do a merge/purge or to send emails—it has a duty to notify the consumer whose information was compromised. All retailers should make sure that their contracts with outside contractors have suitable provisions addressing the confidentiality of personal information of their customers and employees as well as required notifications to the retailers in the event of a breach.
Myth 10: Data breaches occur only for large companies and my company is too small to be subject to either a data breach or the required response to a data breach.
Fact 10: In a recent survey, PricewaterhouseCoopers found that 70 percent of companies responding to the survey had experienced a data breach in the prior year. Other studies have found that data breaches are episodic and can occur to companies regardless of size. None of the data breach laws maintain a small business exception.
Conclusion
Inappropriate responses to data breaches can expose a company to significant liability and unfavorable publicity. Developing and implementing a sound data breach plan can reduce these adverse consequences and help avoid penalties from government “referees."
Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts
Tuesday, December 4, 2012
Tuesday, April 26, 2011
Commercial Privacy Bill of Rights Introduced in Congress
The introduction of the so-called Commercial Privacy Bill of Rights by Senators Kerry and McCain on April 12, 2011 suggests that we may be about to enter an era of robust regulation of information gathering regarding the online browsing and shopping habits of consumers. This type of data has come to be an important tool for online marketers to improve the efficiency of online advertising buys, and to improve other marketing techniques. At a minimum, this development presents a risk that online merchants will need to build out substantial new technical infrastructure to accommodate a welter of new rules under this bill. Beyond that, it may make it difficult even for highly respected and responsible merchants to engage in marketing activities that are an important part of their tool kit in the information age.
Among other things, the bill contains the following requirements:
Further, the bill stretches the definition of personal information beyond any commonly understood meaning of that term. It includes email addresses and postal addresses, and if "used, transferred or stored" in connection with any of the foregoing, birth date, and most significantly, "unique identifier information." Unique identifier information is defined as "a unique persistent identifier associated with an individual or a networked device, including a customer number held in a cookie, a user ID, a processor serial number, or a device serial number." This definition essentially means that virtually any data collected about a browsing session will be protected by this statute, with strict limits on the ability to use or transfer that data without approval.
The existence of an "established business relationship" exception to some of the requirements of the bill provides cold comfort. It applies not to the commonly understood relationship of customer and merchant, but only to the "establishment of an account." While this may be typical of some merchants' relationships with their customers, many retailers do not require the establishment of an account in order to make a purchase. It is interesting to note, however, that the 800 pound gorillas in the online space, notably Google and Facebook, would be the most likely to benefit from this exception.
The bill seeks to accomplish these objectives by requiring the FTC to promulgate regulations effectuating the statute's requirements for the most part within 60 to 180 days after enactment of the bill, depending upon the provision at issue. Accordingly, it will likely be a long time before these requirements take effect (if ever), given the Congressional legislative calendar, and the frequently protracted rule-making process that would attend any promulgation of regulations. During both the legislative process and the regulatory process, the direct marketing industry will have an opportunity to point out the technical challenges presented by this statute, as well as the potential unintended consequences, including damage to the economy, that the statute could create.
Among other things, the bill contains the following requirements:
- Collectors of information must implement security measures to protect the information they collect and maintain.
- Collectors of information must provide clear notice to individuals of the collection practices and the purposes of such collection. Additionally, collectors must provide the ability for an individual to opt out of any information collection that is unauthorized by the Act and to provide affirmative consent (opt-in) for the collection of sensitive personally identifiable information. Respecting companies’ existing relationships with customers and the ability to develop a relationship with a potential customers, the bill would require "robust and clear" notice to an individual of his or her ability to opt-out of the collection of information for the purpose of transferring it to third parties for behavioral advertising. It would also require collectors to provide individuals either the ability to access and correct their information, or to request cessation of its use and distribution.
- Collectors must bind third parties by contract to ensure that any individual information transferred to the third party by the collector will only be used or maintained in accordance with the bill’s requirements. The bill requires the collector to attempt to establish and maintain reasonable procedures to ensure that information is accurate.
Further, the bill stretches the definition of personal information beyond any commonly understood meaning of that term. It includes email addresses and postal addresses, and if "used, transferred or stored" in connection with any of the foregoing, birth date, and most significantly, "unique identifier information." Unique identifier information is defined as "a unique persistent identifier associated with an individual or a networked device, including a customer number held in a cookie, a user ID, a processor serial number, or a device serial number." This definition essentially means that virtually any data collected about a browsing session will be protected by this statute, with strict limits on the ability to use or transfer that data without approval.
The existence of an "established business relationship" exception to some of the requirements of the bill provides cold comfort. It applies not to the commonly understood relationship of customer and merchant, but only to the "establishment of an account." While this may be typical of some merchants' relationships with their customers, many retailers do not require the establishment of an account in order to make a purchase. It is interesting to note, however, that the 800 pound gorillas in the online space, notably Google and Facebook, would be the most likely to benefit from this exception.
The bill seeks to accomplish these objectives by requiring the FTC to promulgate regulations effectuating the statute's requirements for the most part within 60 to 180 days after enactment of the bill, depending upon the provision at issue. Accordingly, it will likely be a long time before these requirements take effect (if ever), given the Congressional legislative calendar, and the frequently protracted rule-making process that would attend any promulgation of regulations. During both the legislative process and the regulatory process, the direct marketing industry will have an opportunity to point out the technical challenges presented by this statute, as well as the potential unintended consequences, including damage to the economy, that the statute could create.
Friday, December 24, 2010
Is a Privacy Battle Brewing? The Department of Commerce Pushes Back On Commercial Privacy Regulation
In an unusual move, the Department of Commerce has chimed in on the question of Internet data privacy, issuing a 78-page report from its Internet Policy Task Force. While the Chairman of the FTC has welcomed the new report, the business-oriented tone of the Commerce report suggests that a battle is brewing. Indeed, the report offers strong support for a “voluntary, multi-stakeholder process” that includes businesses as important, cooperative partners, while the FTC treats voluntary efforts by industry -- and industry itself -- almost contemptuously. While Commerce defers to the FTC as the primary enforcement authority, it also stages what appears to be a power grab to take a leadership role in defining how industry will or will not be regulated in the areas of privacy and information security.
So, what exactly is the Commerce report, and where is it likely to lead? The Commerce report refers to itself as a “green paper,” which one might think is a nod to wholesome environmental practices. Actually, in government-speak, a green paper is merely a tentative proposal or call for comments that might lead, eventually, to a white paper, which is a more formal statement of governmental policy. As a result, both the Commerce report and the FTC initiative reflect tentative steps in the direction of statutory, regulatory, and policy changes. How far they proceed is a matter of guesswork, particularly with a new and more conservative Congress waiting in the wings.
The Commerce Report Sounds the Defense of the Status Quo In Privacy Regulation, Founded In Large Part On Self-Regulation By Industry. The Commerce report praises almost unconditionally the handling of the Internet under US law, focusing mainly on at the success of industry as voluntary self-regulators. The report also posits the Department of Commerce itself as the leadership entity within the US Government on privacy matters, and claims a power to “ensure the Internet fulfills its social and economic potential.” The FTC’s mandate of protecting consumers from commercial abuses is far narrower. Direct marketers may have found, in the Department of Commerce, a voice to stand up to the newly regulation-happy and business-unfriendly FTC, and one that is ready to take power from the FTC. This could not be clearer than in Commerce’s own recommendation that an overarching Privacy Policy Office be created under its regulatory umbrella.
FIPPs. Commerce’s approach centers on the “broad adoption” of Fair Information Privacy Practices (“FIPPs”) that are sweeping and general enough to provide “ample flexibility” and “encourage innovation,” and envisions these being reflected in “voluntary, enforceable codes of conduct.” If they are voluntary, of course, they likely would not be promulgated in the form of statutes and regulations. If they are nonetheless enforceable, it would seem as if Commerce -- at least in part -- envisions trade groups and associations to require adherence by members and to provide for their own policing. Whatever the implications, they are different from the FTC’s report requesting that Congress invest it with greater legal authority over privacy matters. The FIPPs, as envisioned by Commerce, would include “simple notices, clearly articulated purposes for data collection, commitments to limit data uses to fulfill those purposes, and the expanded use of robust audit systems to bolster accountability.”
The PPO. Commerce’s proposed Privacy Policy Office is intended to be both “the convener of diverse stakeholders” on privacy matters, but also the “center of Administration commercial data privacy expertise.” It would work with the FTC in “leading efforts to develop voluntary but enforceable codes of conduct.” In a sentence that likely made career FTC employees cringe, Commerce states that compliance with such voluntary codes would serve as a “safe harbor for companies facing certain complaints about their privacy practices.” In other words, compliance with these voluntary codes could potentially insulate a company from privacy and security related claims asserted by the FTC, the individual states, and potentially even money-hungry class action lawyers. Of course, the scope of the “safe harbor” protection is not made especially clear in the Commerce report, and past experience—as in the telemarketing area—suggests that Congress could seriously fumble on the issue preemption of state laws and limitations on bankrupting class action lawsuits.
Uniform Security Breach Notification Rules? The Commerce report takes on an issue that has plagued direct marketers in recent years, and on which Congress has been unable to anything meaningful. Specifically, it proposes replacing the patchwork of dozens of inconsistent state security breach laws with a single national law. While this would put an array of consultants out of business, it would—if done correctly—remove significant regulatory expense (and uncertainty) from the shoulders of direct marketers of all sizes.
Overall, the Commerce report, if it is taken at face value as a genuine reflection of the Department of Commerce's position on commercial privacy matters, is a breath of fresh air. Unlike the FTC's report, which treats things like personalized advertisements as horrible invasions of privacy, the Commerce report reflects an understanding that the collection and use of customer information by businesses has an important place in not only bolstering the growing internet economy, but also serving legitimate consumer and business interests. And, unlike the FTC, places the greatest governmental focus on far more important privacy issues like data security and identity theft.
We are now at the beginning stages of a great debate about Internet privacy that could result in considerable change to the regulatory landscape. In subsequent blog posts, we will be addressing in greater detail individual issues raised by both the Commerce and FTC reports, and provide insights how the debate is evolving.
We wish all of our readers a wonderful holiday season!
So, what exactly is the Commerce report, and where is it likely to lead? The Commerce report refers to itself as a “green paper,” which one might think is a nod to wholesome environmental practices. Actually, in government-speak, a green paper is merely a tentative proposal or call for comments that might lead, eventually, to a white paper, which is a more formal statement of governmental policy. As a result, both the Commerce report and the FTC initiative reflect tentative steps in the direction of statutory, regulatory, and policy changes. How far they proceed is a matter of guesswork, particularly with a new and more conservative Congress waiting in the wings.
The Commerce Report Sounds the Defense of the Status Quo In Privacy Regulation, Founded In Large Part On Self-Regulation By Industry. The Commerce report praises almost unconditionally the handling of the Internet under US law, focusing mainly on at the success of industry as voluntary self-regulators. The report also posits the Department of Commerce itself as the leadership entity within the US Government on privacy matters, and claims a power to “ensure the Internet fulfills its social and economic potential.” The FTC’s mandate of protecting consumers from commercial abuses is far narrower. Direct marketers may have found, in the Department of Commerce, a voice to stand up to the newly regulation-happy and business-unfriendly FTC, and one that is ready to take power from the FTC. This could not be clearer than in Commerce’s own recommendation that an overarching Privacy Policy Office be created under its regulatory umbrella.
FIPPs. Commerce’s approach centers on the “broad adoption” of Fair Information Privacy Practices (“FIPPs”) that are sweeping and general enough to provide “ample flexibility” and “encourage innovation,” and envisions these being reflected in “voluntary, enforceable codes of conduct.” If they are voluntary, of course, they likely would not be promulgated in the form of statutes and regulations. If they are nonetheless enforceable, it would seem as if Commerce -- at least in part -- envisions trade groups and associations to require adherence by members and to provide for their own policing. Whatever the implications, they are different from the FTC’s report requesting that Congress invest it with greater legal authority over privacy matters. The FIPPs, as envisioned by Commerce, would include “simple notices, clearly articulated purposes for data collection, commitments to limit data uses to fulfill those purposes, and the expanded use of robust audit systems to bolster accountability.”
The PPO. Commerce’s proposed Privacy Policy Office is intended to be both “the convener of diverse stakeholders” on privacy matters, but also the “center of Administration commercial data privacy expertise.” It would work with the FTC in “leading efforts to develop voluntary but enforceable codes of conduct.” In a sentence that likely made career FTC employees cringe, Commerce states that compliance with such voluntary codes would serve as a “safe harbor for companies facing certain complaints about their privacy practices.” In other words, compliance with these voluntary codes could potentially insulate a company from privacy and security related claims asserted by the FTC, the individual states, and potentially even money-hungry class action lawyers. Of course, the scope of the “safe harbor” protection is not made especially clear in the Commerce report, and past experience—as in the telemarketing area—suggests that Congress could seriously fumble on the issue preemption of state laws and limitations on bankrupting class action lawsuits.
Uniform Security Breach Notification Rules? The Commerce report takes on an issue that has plagued direct marketers in recent years, and on which Congress has been unable to anything meaningful. Specifically, it proposes replacing the patchwork of dozens of inconsistent state security breach laws with a single national law. While this would put an array of consultants out of business, it would—if done correctly—remove significant regulatory expense (and uncertainty) from the shoulders of direct marketers of all sizes.
Overall, the Commerce report, if it is taken at face value as a genuine reflection of the Department of Commerce's position on commercial privacy matters, is a breath of fresh air. Unlike the FTC's report, which treats things like personalized advertisements as horrible invasions of privacy, the Commerce report reflects an understanding that the collection and use of customer information by businesses has an important place in not only bolstering the growing internet economy, but also serving legitimate consumer and business interests. And, unlike the FTC, places the greatest governmental focus on far more important privacy issues like data security and identity theft.
We are now at the beginning stages of a great debate about Internet privacy that could result in considerable change to the regulatory landscape. In subsequent blog posts, we will be addressing in greater detail individual issues raised by both the Commerce and FTC reports, and provide insights how the debate is evolving.
We wish all of our readers a wonderful holiday season!
Tuesday, December 14, 2010
Do As I Say, Not As I Do: The FTC "Do Not Track" Initiative Could Cripple E-Commerce
Just as governments – including our own – are pursuing aggressive new initiatives to gather information about our individual browsing habits and electronic communications for law enforcement purposes, the FTC has decided to advise Congress on sweeping initiatives to prevent direct marketers from engaging in far less invasive practices that present none of the grave risks attendant to enhanced government surveillance. Indeed, many of the commercial practices targeted by the FTC actually benefit consumers by assisting Internet sellers to configure their web sites, adjust their product offerings, and tailor advertising to the specific needs and interests of consumers. While the FTC shrilly intones that consumer information about Internet browsing has been used by an unidentified "some" in "an irresponsible or even reckless manner," it fails to acknowledge forthrightly that the vast majority of direct marketers use such information solely to better serve their customers, and that new laws and FTC initiatives are unlikely to faze the tiny group of Internet pirates who misuse consumer data.
Although most headlines have focused on the FTC's proposal for a "do not track" list, the FTC report is about much more than that. It foretells a highly aggressive new regulatory strategy that may change the landscape of Internet privacy without any concern for the cost impact on industry or a realistic assessment of the privacy interests of consumers. It sweeps so broadly against business as to suggest that–if the FTC has its way–even entirely benign and non-intrusive information collection practices that do not track individual consumers will be sharply curtailed. At the same time, new and intrusive requirements will be injected multiple times into virtually every consumer experience on the Web. If you do business on the Internet, you need to know what the FTC is hoping to unleash on eCommerce.
If the FTC has its way, you will need to redesign your web sites and emails to provide real-time notice and choice to every consumer, whether or not they make any purchases. The overarching theme of the report is highly paternalistic, suggesting that consumers are incapable of making informed choices about their buying decisions and Internet browsing activities. Thus, privacy policies and full disclosure of information collection practices are viewed dimly by the FTC. Instead, it commands that “consumers should [repeatedly] be presented with choice about collection and sharing of their data at the time and in the context in which they are making decisions.” Not only would implementation of such a scheme add substantially to the programming costs of commercial web sites, it could interfere significantly with the consumer purchasing experience. It is hard to imagine Web sales not suffering.
The FTC's "Do Not Track" Initiative Creates a Presumption Against Collecting Information About Web Site Usage, Even If that Information Is Not Individually Identifiable. The item in the report receiving the largest amount of press is the “do not track” recommendation. It would obligate direct marketers to implement technology – through something “similar to a cookie,” according to the FTC – that would prevent the collection of web browsing activities by individuals or individual browser installations. This would be mandated even if retailers do not actually collect individually-identifiable personal information. Indeed, the FTC report supports doing away with the line drawn in existing law between information that is personally identifiable and that which is not, claiming that “traditional distinctions between the two categories of data are eroding.” Because "some" companies allegedly find surreptitious ways to connect non-personal information to specific individuals, the FTC is ready to recommend that all companies be prevented from collecting even aggregate usage data, which could be a significant blow to retailers who use this data to obtain helpful information for their businesses. Data collection serves important functions that parallel the physical retail environment, including the measuring of foot traffic in certain areas of a store. Denying this data to retailers in its non-personally identifiable form suggests a significant lack of government understanding of – or at least a gross lack of sensitivity to – legitimate industry needs.
At present, the FTC, itself, believes that it does not have authority to implement a tracking system without further action by Congress. But, the pressure is on for Congress to enact a potentially sweeping new set of powers for the agency. In the interim, the makers of at least one popular browser, Firefox, are exploring ways to implement a “do not track” feature that leaves it to consumers to choose whether they will be tracked. Microsoft has already implemented a similar feature in its most recent release of Internet Explorer. This approach is far less onerous for retailers, but may rob them of the very data they need to present consumers with meaningful purchasing choices through targeted advertising. The least effective and most intrusive recommendation – that the FTC appears to favor – involves a “do not track” list that may leave it to Internet companies to figure out whether a person who is visiting their web site has chosen to place themselves on a list. Because the specifics have yet to be determined, it is unclear what this list would even look like. The FTC claims that a list of machine specific identifiers (as might be embedded in an operating system or hardware) or IP addresses is not a likely option.
Prepare to Open Your Files. Some of what the FTC report recommends is positive for the industry, including “standardized” privacy-related notices (which might reduce uncertainty surrounding potential challenges by privacy rights groups, among other things), but the context – including whether federally mandated notices would preempt individual states from enacting different or more complicated disclosure requirements and whether class action lawsuits would be permitted against violators – remains a mystery, and the potential perils for eCommerce are significant. Other FTC recommendations are chilling, including the requirement that companies provide customers “reasonable access” to all the data maintained about them and that the Children’s Online Privacy Protection Act’s onerous obligations be extended to cover children between the ages of 13 and 17.
What's Next? The FTC has asked for industry comments as it pushes forward with its new privacy initiative. This is a critical moment for direct marketers to be heard in petitioning the government to create and implement a more sensible, uniform approach to privacy protection that balances a realistic assessment of the potential harm to consumers against potentially dramatic and commerce-suppressing costs.
Although most headlines have focused on the FTC's proposal for a "do not track" list, the FTC report is about much more than that. It foretells a highly aggressive new regulatory strategy that may change the landscape of Internet privacy without any concern for the cost impact on industry or a realistic assessment of the privacy interests of consumers. It sweeps so broadly against business as to suggest that–if the FTC has its way–even entirely benign and non-intrusive information collection practices that do not track individual consumers will be sharply curtailed. At the same time, new and intrusive requirements will be injected multiple times into virtually every consumer experience on the Web. If you do business on the Internet, you need to know what the FTC is hoping to unleash on eCommerce.
If the FTC has its way, you will need to redesign your web sites and emails to provide real-time notice and choice to every consumer, whether or not they make any purchases. The overarching theme of the report is highly paternalistic, suggesting that consumers are incapable of making informed choices about their buying decisions and Internet browsing activities. Thus, privacy policies and full disclosure of information collection practices are viewed dimly by the FTC. Instead, it commands that “consumers should [repeatedly] be presented with choice about collection and sharing of their data at the time and in the context in which they are making decisions.” Not only would implementation of such a scheme add substantially to the programming costs of commercial web sites, it could interfere significantly with the consumer purchasing experience. It is hard to imagine Web sales not suffering.
The FTC's "Do Not Track" Initiative Creates a Presumption Against Collecting Information About Web Site Usage, Even If that Information Is Not Individually Identifiable. The item in the report receiving the largest amount of press is the “do not track” recommendation. It would obligate direct marketers to implement technology – through something “similar to a cookie,” according to the FTC – that would prevent the collection of web browsing activities by individuals or individual browser installations. This would be mandated even if retailers do not actually collect individually-identifiable personal information. Indeed, the FTC report supports doing away with the line drawn in existing law between information that is personally identifiable and that which is not, claiming that “traditional distinctions between the two categories of data are eroding.” Because "some" companies allegedly find surreptitious ways to connect non-personal information to specific individuals, the FTC is ready to recommend that all companies be prevented from collecting even aggregate usage data, which could be a significant blow to retailers who use this data to obtain helpful information for their businesses. Data collection serves important functions that parallel the physical retail environment, including the measuring of foot traffic in certain areas of a store. Denying this data to retailers in its non-personally identifiable form suggests a significant lack of government understanding of – or at least a gross lack of sensitivity to – legitimate industry needs.
At present, the FTC, itself, believes that it does not have authority to implement a tracking system without further action by Congress. But, the pressure is on for Congress to enact a potentially sweeping new set of powers for the agency. In the interim, the makers of at least one popular browser, Firefox, are exploring ways to implement a “do not track” feature that leaves it to consumers to choose whether they will be tracked. Microsoft has already implemented a similar feature in its most recent release of Internet Explorer. This approach is far less onerous for retailers, but may rob them of the very data they need to present consumers with meaningful purchasing choices through targeted advertising. The least effective and most intrusive recommendation – that the FTC appears to favor – involves a “do not track” list that may leave it to Internet companies to figure out whether a person who is visiting their web site has chosen to place themselves on a list. Because the specifics have yet to be determined, it is unclear what this list would even look like. The FTC claims that a list of machine specific identifiers (as might be embedded in an operating system or hardware) or IP addresses is not a likely option.
Prepare to Open Your Files. Some of what the FTC report recommends is positive for the industry, including “standardized” privacy-related notices (which might reduce uncertainty surrounding potential challenges by privacy rights groups, among other things), but the context – including whether federally mandated notices would preempt individual states from enacting different or more complicated disclosure requirements and whether class action lawsuits would be permitted against violators – remains a mystery, and the potential perils for eCommerce are significant. Other FTC recommendations are chilling, including the requirement that companies provide customers “reasonable access” to all the data maintained about them and that the Children’s Online Privacy Protection Act’s onerous obligations be extended to cover children between the ages of 13 and 17.
What's Next? The FTC has asked for industry comments as it pushes forward with its new privacy initiative. This is a critical moment for direct marketers to be heard in petitioning the government to create and implement a more sensible, uniform approach to privacy protection that balances a realistic assessment of the potential harm to consumers against potentially dramatic and commerce-suppressing costs.
Tuesday, March 16, 2010
Think You’re Safe Storing or Releasing “Anonymized” Data? Think Again.
Anonymity is increasingly difficult to safeguard, and direct marketers that collect, maintain, share, and use customer information should take note of a recent class action settlement by Netflix than stemmed from the company's disclosure of an "anonymized" customer database.
Most federal and state privacy and data security statutes focus on the protection of "personally identifiable information," such as names, addresses, telephone numbers, financial account numbers, social security numbers, and email addresses. In response to such laws, many companies strip personally identifiable information from databases containing sensitive information. Once stripped of identifiers, the theory goes, the risks of identity theft or violations of consumer privacy rights resulting from disclosure of the data (whether purposeful or not) are eliminated. Some companies may even conclude that the data may be shared for marketing or "data mining" purposes without violating their privacy policies or applicable laws.
According to the Electronic Privacy Information Center, however, "computer scientists have revealed that this 'anonymized' data can easily be re-identified, such that the sensitive information may be linked back to an individual."
Ten years ago, the risk of such "re-identification" was "largely theoretical":
"In a corner of the U.S. Census Bureau, a small group of statisticians has been sweating out the agency's nightmare scenario: 're-identification.' That's the term for a technique that the bureau fears could allow marketers and other "intruders" to match anonymous census information with the names of the people who provided it. Such a concern is largely theoretical, so far. But if perfected, the technique could have great appeal to marketers of everything from french fries to financial services."
-Glenn R. Simpson, "The 2000 Count: Bureau Blurs Data To Keep Names Confidential," The Wall Street Journal, February 14, 2001.
The risk is theoretical no more, and online sellers and direct marketers that fail to pay attention to the issue do so at their own peril.
The Netflix Case. Netflix just announced that it is canceling its Netflix Prize after being sued in federal court on a class action basis for invasion of privacy and violation of the Video Privacy Protection Act ("VPPA") based upon the alleged re-identification of individuals whose movie rating information was made public in a database that had been scrubbed of personal information.
Netflix sponsored a contest to see if entrants could provide "collaborative filtering algorithms" that could better predict viewers' movie ratings than Netflix's existing Cinematch recommendation engine. In connection with the contest, entrants were given an "anonymized" training data set that contained 100 million subscriber movie ratings covering 480,000 subscribers and 18,000 movies. Each of the rating entries included a unique numeric identifier representing the subscriber, but contained no personally identifiable information.
It didn't take long, however, for two researchers at the University of Texas to identify two of the anonymous subscribers in the training data set. They did so by using public reviews available on the Internet Movie Database and re-identification algorithms. The researchers found that one of the people they identified "had strong-ostensibly private-opinions about liberal and gay-themed films and had ratings for some religious films." (The complete study is available here.) The researchers were apparently able to identify individual subscribers despite the "perturbation techniques" employed by Netflix to protect individual identities. (Perturbation adds "noise" to a database to protect individual record confidentiality. The UT researchers had developed a technique that was "robust to perturbation in the data.")
In at least one respect, the Netflix case presented a good opportunity for class action plaintiffs because the federal VPPA specifically makes video rental information private. (As is often the case with privacy laws, the VPPA was passed in reaction to a highly publicized event - in this case, the release of Judge Robert Bork's video rental records during Senate hearings on his nomination to the United States Supreme Court.) But, the Netflix suit went far beyond alleged VPPA violations, and included sweeping counts under California statutes (including for alleged unfair trade practices and false advertising), as well as common law privacy claims. Not only was Netflix sued, the Federal Trade Commission jumped on the bandwagon. Eventually, after "productive discussions" with the FTC, the suit was settled and the Netflix Prize was no more.
Takeaway. The Netflix case raises very serious questions for online sellers and direct marketers with regard to supposedly anonymous aggregated databases that reflect customer information, including purchasing histories and demographic information. In the future, we may well see privacy and security laws evolve to cover databases that are susceptible to re-identification. Each company should actively examine the intersection between its business objectives and the privacy concerns of its customers with regard to the collection, storage, and use of customer data. Clear and accurate privacy policy disclosures are essential to ensure that consumers understand a company's information collection and disclosure practices. The claims against Netflix included assertions that standard privacy policy provisions were materially misleading given the availability of re-identification.
Most federal and state privacy and data security statutes focus on the protection of "personally identifiable information," such as names, addresses, telephone numbers, financial account numbers, social security numbers, and email addresses. In response to such laws, many companies strip personally identifiable information from databases containing sensitive information. Once stripped of identifiers, the theory goes, the risks of identity theft or violations of consumer privacy rights resulting from disclosure of the data (whether purposeful or not) are eliminated. Some companies may even conclude that the data may be shared for marketing or "data mining" purposes without violating their privacy policies or applicable laws.
According to the Electronic Privacy Information Center, however, "computer scientists have revealed that this 'anonymized' data can easily be re-identified, such that the sensitive information may be linked back to an individual."
Ten years ago, the risk of such "re-identification" was "largely theoretical":
"In a corner of the U.S. Census Bureau, a small group of statisticians has been sweating out the agency's nightmare scenario: 're-identification.' That's the term for a technique that the bureau fears could allow marketers and other "intruders" to match anonymous census information with the names of the people who provided it. Such a concern is largely theoretical, so far. But if perfected, the technique could have great appeal to marketers of everything from french fries to financial services."
-Glenn R. Simpson, "The 2000 Count: Bureau Blurs Data To Keep Names Confidential," The Wall Street Journal, February 14, 2001.
The risk is theoretical no more, and online sellers and direct marketers that fail to pay attention to the issue do so at their own peril.
The Netflix Case. Netflix just announced that it is canceling its Netflix Prize after being sued in federal court on a class action basis for invasion of privacy and violation of the Video Privacy Protection Act ("VPPA") based upon the alleged re-identification of individuals whose movie rating information was made public in a database that had been scrubbed of personal information.
Netflix sponsored a contest to see if entrants could provide "collaborative filtering algorithms" that could better predict viewers' movie ratings than Netflix's existing Cinematch recommendation engine. In connection with the contest, entrants were given an "anonymized" training data set that contained 100 million subscriber movie ratings covering 480,000 subscribers and 18,000 movies. Each of the rating entries included a unique numeric identifier representing the subscriber, but contained no personally identifiable information.
It didn't take long, however, for two researchers at the University of Texas to identify two of the anonymous subscribers in the training data set. They did so by using public reviews available on the Internet Movie Database and re-identification algorithms. The researchers found that one of the people they identified "had strong-ostensibly private-opinions about liberal and gay-themed films and had ratings for some religious films." (The complete study is available here.) The researchers were apparently able to identify individual subscribers despite the "perturbation techniques" employed by Netflix to protect individual identities. (Perturbation adds "noise" to a database to protect individual record confidentiality. The UT researchers had developed a technique that was "robust to perturbation in the data.")
In at least one respect, the Netflix case presented a good opportunity for class action plaintiffs because the federal VPPA specifically makes video rental information private. (As is often the case with privacy laws, the VPPA was passed in reaction to a highly publicized event - in this case, the release of Judge Robert Bork's video rental records during Senate hearings on his nomination to the United States Supreme Court.) But, the Netflix suit went far beyond alleged VPPA violations, and included sweeping counts under California statutes (including for alleged unfair trade practices and false advertising), as well as common law privacy claims. Not only was Netflix sued, the Federal Trade Commission jumped on the bandwagon. Eventually, after "productive discussions" with the FTC, the suit was settled and the Netflix Prize was no more.
Takeaway. The Netflix case raises very serious questions for online sellers and direct marketers with regard to supposedly anonymous aggregated databases that reflect customer information, including purchasing histories and demographic information. In the future, we may well see privacy and security laws evolve to cover databases that are susceptible to re-identification. Each company should actively examine the intersection between its business objectives and the privacy concerns of its customers with regard to the collection, storage, and use of customer data. Clear and accurate privacy policy disclosures are essential to ensure that consumers understand a company's information collection and disclosure practices. The claims against Netflix included assertions that standard privacy policy provisions were materially misleading given the availability of re-identification.
Thursday, March 11, 2010
Colorado's HB 1193 Risks Constitutional Violations and Threatens Consumer Privacy
The assault on eCommerce by short-sighted state legislators and tax officials continues. By now, many of you have heard or read about the new Colorado law (HB 1193) enacted in February, that imposes certain sales tax notice and reporting obligations upon each “retailer that does not collect Colorado sales tax.” Under the law, most non-collecting retailers are required:
(a) beginning effective March 1, 2010, to inform their Colorado purchasers of the purchaser’s duty to remit use tax on certain purchases under Colorado law;
(b) beginning in January 2011, to provide Colorado purchasers an annual statement of all of their Colorado purchases from the retailer; and
(c) beginning in January 2011, to file annually with the Colorado Department of Revenue a list of all purchasers and the amount of their Colorado purchases.
These new obligations are backed by substantial penalties for retailers that do not comply. Amazon.com reacted to the passage of the bill by terminating all of its Colorado online affiliate relationships, angering Colorado lawmakers who had worked with Amazon and its local affiliates in removing “New York style” affiliate nexus provisions from earlier drafts of the bill.
But the tiff between Amazon and Colorado is really a side-show that masks the genuine problems with the law, including both potential constitutional violations and invasions of consumer privacy. Colorado lawmakers and revenue officials made no secret during debate on the bill that the new law was expressly intended to force out-of-state online and direct marketers to begin collecting Colorado use tax on their sales to Colorado residents, despite constitutional prohibitions against the imposition of such tax obligations under the Commerce Clause, as reaffirmed by the Supreme Court in Quill Corp. v. North Dakota.
The burdens imposed by the new law are real and discriminatory; no Colorado retailer is required to comply with them, but out-of-state online and direct marketers’ compliance is mandatory. Also, given the propensity for “copy cat” nexus legislation among the states in recent years, such laws are likely to proliferate in other state legislation soon, unless online and direct marketers (and voting consumers) trumpet the problems with such laws. Already, the South Dakota Department of Revenue & Regulation is following Colorado’s lead by informally demanding that out-of-state companies provide it a list of in-state purchasers who may owe use tax.
Consumers should take note because the new Colorado law suggests that some state lawmakers feel that the answer to encouraging increased use tax compliance by online shoppers is the systematic invasion of their privacy, on a massive scale. Under the Colorado law, every online and mail-order purchaser in Colorado will have the source and amount of his or her purchases from out-of-state sellers fully documented in Colorado Department of Revenue databases, down to the last penny. Such files are presumptively public records, and thus potentially subject to disclosure under Colorado’s Open Records Law. Furthermore, even if the Department resists the formal requests for access to such records that will inevitably come, public agencies such as the Department are typically not subject to data security laws (for example, Colorado’s data breach statute applies only to individuals and commercial entities), and thus unlike private businesses are not compelled to have meaningful data security measures in place. Little wonder the great majority of all data breaches have occurred through public agencies, including other Colorado agencies.
Voters in other states beware.
(a) beginning effective March 1, 2010, to inform their Colorado purchasers of the purchaser’s duty to remit use tax on certain purchases under Colorado law;
(b) beginning in January 2011, to provide Colorado purchasers an annual statement of all of their Colorado purchases from the retailer; and
(c) beginning in January 2011, to file annually with the Colorado Department of Revenue a list of all purchasers and the amount of their Colorado purchases.
These new obligations are backed by substantial penalties for retailers that do not comply. Amazon.com reacted to the passage of the bill by terminating all of its Colorado online affiliate relationships, angering Colorado lawmakers who had worked with Amazon and its local affiliates in removing “New York style” affiliate nexus provisions from earlier drafts of the bill.
But the tiff between Amazon and Colorado is really a side-show that masks the genuine problems with the law, including both potential constitutional violations and invasions of consumer privacy. Colorado lawmakers and revenue officials made no secret during debate on the bill that the new law was expressly intended to force out-of-state online and direct marketers to begin collecting Colorado use tax on their sales to Colorado residents, despite constitutional prohibitions against the imposition of such tax obligations under the Commerce Clause, as reaffirmed by the Supreme Court in Quill Corp. v. North Dakota.
The burdens imposed by the new law are real and discriminatory; no Colorado retailer is required to comply with them, but out-of-state online and direct marketers’ compliance is mandatory. Also, given the propensity for “copy cat” nexus legislation among the states in recent years, such laws are likely to proliferate in other state legislation soon, unless online and direct marketers (and voting consumers) trumpet the problems with such laws. Already, the South Dakota Department of Revenue & Regulation is following Colorado’s lead by informally demanding that out-of-state companies provide it a list of in-state purchasers who may owe use tax.
Consumers should take note because the new Colorado law suggests that some state lawmakers feel that the answer to encouraging increased use tax compliance by online shoppers is the systematic invasion of their privacy, on a massive scale. Under the Colorado law, every online and mail-order purchaser in Colorado will have the source and amount of his or her purchases from out-of-state sellers fully documented in Colorado Department of Revenue databases, down to the last penny. Such files are presumptively public records, and thus potentially subject to disclosure under Colorado’s Open Records Law. Furthermore, even if the Department resists the formal requests for access to such records that will inevitably come, public agencies such as the Department are typically not subject to data security laws (for example, Colorado’s data breach statute applies only to individuals and commercial entities), and thus unlike private businesses are not compelled to have meaningful data security measures in place. Little wonder the great majority of all data breaches have occurred through public agencies, including other Colorado agencies.
Voters in other states beware.
LifeLock: $12 Million to Settle Data Security False Advertising Claims
The company whose advertising campaign included displaying their CEO's social security number on the side of a truck has reached a settlement to pay $12 million to the FTC and 35 states who charged LifeLock, Inc. with false representations about the effectiveness of its services. In an official press release, FTC Chairman Jon Leibowitz said that “[w]hile LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it.”
But the case against LifeLock didn't end there. The FTC and the states also charged LifeLock with making false claims about its own data security practices. According to the FTC, LifeLock failed to live up to the following representations:
• “Only authorized employees of LifeLock will have access to the data that you provide to us, and that access is granted only on a ‘need to know’ basis.”
• “All stored personal data is electronically encrypted.”
• “LifeLock uses highly secure physical, electronic, and managerial procedures to safeguard the confidentiality and security of the data you provide to us.”
The FTC charged that "LifeLock’s data was not encrypted, and sensitive consumer information was not shared only on a 'need to know' basis." The agency also charged that the company’s data system was vulnerable and could have been exploited by those seeking access to customer information." Read more here.
Takeaway: Many companies make promises about data security, particularly in connection with online transactions. If your company is going to publish those kinds of assurances, make sure you live up to them. While this is not the first time the FTC has penalized a company for allegedly false claims about data security, the fine is one of the largest.
But the case against LifeLock didn't end there. The FTC and the states also charged LifeLock with making false claims about its own data security practices. According to the FTC, LifeLock failed to live up to the following representations:
• “Only authorized employees of LifeLock will have access to the data that you provide to us, and that access is granted only on a ‘need to know’ basis.”
• “All stored personal data is electronically encrypted.”
• “LifeLock uses highly secure physical, electronic, and managerial procedures to safeguard the confidentiality and security of the data you provide to us.”
The FTC charged that "LifeLock’s data was not encrypted, and sensitive consumer information was not shared only on a 'need to know' basis." The agency also charged that the company’s data system was vulnerable and could have been exploited by those seeking access to customer information." Read more here.
Takeaway: Many companies make promises about data security, particularly in connection with online transactions. If your company is going to publish those kinds of assurances, make sure you live up to them. While this is not the first time the FTC has penalized a company for allegedly false claims about data security, the fine is one of the largest.
The WISP Has (Finally) Landed: MA's Data Protection Law Now In Effect
After a seemingly unending series of delays and modifications, Massachusetts's data protection regulation finally went into effect on March 1, 2010. A copy of the regulation can be obtained here. Unlike the data protection laws of most states, the Massachusetts regulation requires holders of data to put in place a comprehensive set of written measures to protect confidential information (also known as a "WISP," or “written information security policy”), and to update their WISPs on an annual basis. The required contents of the WISP are outlined in the regulation, and cover topics ranging from encryption to vendor agreements.
Thumbnail: The new regulation applies to all persons and companies who either own or license personal information about residents of Massachusetts, and applies both to electronic and paper records. While the opening clause of the regulation appears to limit its coverage to "customer information" and "consumers," the balance of the regulation does not distinguish between information about customers, consumers, employees, or other categories of persons. If past experience with the administrative process in Massachusetts is any guide, it will be a long and winding road before we get any formal guidance as to the regulation’s scope.
Takeaway: Irrespective of Massachusetts's new regulation, it is in the interest of every company that possesses confidential personal information to have a written security policy to protect confidential information from inadvertent disclosure and from disclosure by intentional interception or theft. The Massachusetts regulation provides a useful set of guidelines as to what should be in that policy.
Here are some reasons to pay attention:
First, companies can face substantial liability for data disclosures, including by consumer class actions and enforcement actions by regulators. A written WISP that is implemented and followed can be important as a defense against such claims, including claims under theories of negligence.
Second, many companies make information security promises on their web pages, and failure to back up those promises with written protocols and standards can lead to FTC complaints and penalties, among other unpleasant consequences.
Third, a written policy is probably the only practical way to effectively control the use and dissemination of confidential information within an organization of any size and to avoid, to the fullest extent possible, the legal and public relations nightmare of a data breach.
Finally, the measures set out in the WISP ought to provide a company with early warnings so that it can promptly notify regulatory agencies, law enforcement, and consumers whose information may have been compromised.
At least for now, Massachusetts has indicated that it will only audit a company for compliance with the regulation if the company notifies the state of a security breach (as it is required to do), or if a security breach as to which the State was not notified hits the press. While a potential data security breach presents inherent public relations and legal risks for a company, having a solid WISP and a good faith effort to implement it is the first and best line of defense.
Thumbnail: The new regulation applies to all persons and companies who either own or license personal information about residents of Massachusetts, and applies both to electronic and paper records. While the opening clause of the regulation appears to limit its coverage to "customer information" and "consumers," the balance of the regulation does not distinguish between information about customers, consumers, employees, or other categories of persons. If past experience with the administrative process in Massachusetts is any guide, it will be a long and winding road before we get any formal guidance as to the regulation’s scope.
Takeaway: Irrespective of Massachusetts's new regulation, it is in the interest of every company that possesses confidential personal information to have a written security policy to protect confidential information from inadvertent disclosure and from disclosure by intentional interception or theft. The Massachusetts regulation provides a useful set of guidelines as to what should be in that policy.
Here are some reasons to pay attention:
First, companies can face substantial liability for data disclosures, including by consumer class actions and enforcement actions by regulators. A written WISP that is implemented and followed can be important as a defense against such claims, including claims under theories of negligence.
Second, many companies make information security promises on their web pages, and failure to back up those promises with written protocols and standards can lead to FTC complaints and penalties, among other unpleasant consequences.
Third, a written policy is probably the only practical way to effectively control the use and dissemination of confidential information within an organization of any size and to avoid, to the fullest extent possible, the legal and public relations nightmare of a data breach.
Finally, the measures set out in the WISP ought to provide a company with early warnings so that it can promptly notify regulatory agencies, law enforcement, and consumers whose information may have been compromised.
At least for now, Massachusetts has indicated that it will only audit a company for compliance with the regulation if the company notifies the state of a security breach (as it is required to do), or if a security breach as to which the State was not notified hits the press. While a potential data security breach presents inherent public relations and legal risks for a company, having a solid WISP and a good faith effort to implement it is the first and best line of defense.
Subscribe to:
Posts (Atom)