Showing posts with label FTC. Show all posts
Showing posts with label FTC. Show all posts

Tuesday, November 26, 2013

Mail Order Merchandise Rule: Are Your Business Processes up to Snuff?

This is the first in a series of blog posts highlighting the major legal and regulatory issues that are specific to the multichannel merchant. The Mail Order Merchandise Rule, promulgated by the Federal Trade Commission, is intended to ensure that mail order customers actually receive the items that they order from catalog or online merchants. The Rule requires that when a seller advertises merchandise, it must have a reasonable basis for stating or implying that it can ship the merchandise within a certain time. If the business makes no shipment statement, it must have a reasonable basis for believing that it can ship within 30 days. That is why direct marketers sometimes call this the "30-day Rule." Surprisingly, though, many well-established mail order companies have only a loose grip on the operational steps necessary to comply with this rule.

It is usually the case in the highly competitive, technologically advanced environment of mail order and internet sales, that merchants are easily able to comply with the Rule by providing a stated shipment representation. If a website says the product will be shipped in two days, it almost always is, and often it is shipped even sooner. But when products are not timely shipped, things sometimes go a little sideways. The most common reason for failure to ship within the stated time frame is the lack of a product–the back order issue.

The rule provides that, if after taking the customer’s order, a seller learn that it cannot ship within the time stated, it must seek the customer’s consent to the delayed shipment. If it is the first such delay, and if the seller can provide a revised shipment date, it must notify the customer of his or her right to cancel the order; sellers are permitted to treat the client’s silence in response as an expression of assent.  But, if there is a second delay, or if the seller cannot provide a revised shipment date, then the seller MUST get the client to consent affirmatively to the continued delay. If a seller cannot obtain the customer’s consent to the delay – or if the customer refuses to consent -- the seller must, without being asked, promptly refund all the money the customer paid for the unshipped merchandise.

There are at least two safe harbors from which many catalog companies may benefit. First, the clock does not begin ticking on any shipment representations until there is a “properly completed order.” An order is properly completed when the seller receives the correct full or partial payment, accompanied by all the information needed to fill the order. In many instances, merchants do not collect payment on backordered items as a matter of routine-though they are permitted to do so. This prevents the shipping representation clock for beginning.

Second, a shipment representation made at the time of order trumps shipment representations contained on a product page or in a catalog. So if customer service representatives explain to a customer that an item is backordered for 6 weeks, then that becomes the new shipment representation.

Like many legal issues, the Mail Order Merchandise Rule need not present a business risk, provided that you are aware of its requirements and plan accordingly. It is important for catalog and web merchants to have business processes in place to track shipment representations, and to ensure that the proper notifications are sent to customers.

In my next blog post, we will touch on some unusual and unexpected California-specific regulations that can impact multichannel merchants.

Thursday, June 27, 2013

Indemnification Clauses Critical to Fighting Patent Trolls

Much has been written about the rise of lawsuits, and threatened lawsuits by so-called patent trolls, also known as “patent assertion entities” or “PAEs.” If your business has not yet been the target of a patent troll, you can count yourself among the fortunate few. The proliferation of these types of claims is so widespread that the Federal Trade Commission has actually instituted an investigation into the business practices of patent assertion entities. According to a White House Report issued on June 4, 2013, PAE lawsuits have jumped 250% since 2011, now accounting for 62% of all infringement cases. As many as 100,000 companies have been threatened by patent trolls just in the last 12 months. Often these cases are based on highly questionable interpretations of highly questionable patents, applying them to technology not imagined at the time that the patent was granted. Rather than bear the cost and risk associated with litigation, businesses faced with these claims often agree to pay license fees to the PAE, further feeding the cycle.

As with many threats to business, the most effective technique for dealing with these claims is to anticipate them during your procurement process. In many instances, a well-negotiated agreement with a vendor can provide you with protection against patent trolls in the form of an indemnification clause requiring the supplier of the product or service that gives rise to the patent claim to defend you. A well-drafted indemnification provision properly allocates risk to the party in the best position to understand and assess the risk of a claim. In addition, the supplier of the product or technology actually has an economic incentive to do battle with a patent troll that its individual customer may lack. Intellectual property indemnification provisions accordingly are a critical component of any agreement.

In our commercial transactional practice, we have long been routinely advising clients on this issue and, by and large, vendors understand the need to stand behind the technology or product that they sell. In the last several months, however, a new development has arisen. A recent agreement reviewed for a client contained a carve-out from the indemnification provision in instances “where Client authorized the implementation of generally applicable and non-site specific technology, know-how, materials or information representing functionality already readily available on the internet to the public or used throughout the industry without a license.” This carve out seems to target the non-practicing entity issue and shift risk associated with patent troll claims back to the client. To the extent that this becomes a trend, you and your advisors will need to continue to be vigilant and to insist on adequate IP indemnifications in your commercial agreements.

Wednesday, June 12, 2013

The Summer of Privacy: With the Government Under Fire, Retailers May Overlook New Rules and Risks


This may one day be known as the Summer of Privacy. From claims that the NSA surreptitiously obtains cellphone (and GPS) information from at least 100,000,000 Americans to the Supreme Court blessing routine collection of DNA evidence from arrestees, it is impossible to avoid almost daily stories on governmental privacy issues. But, don't be fooled by the focus on governmental activity. From advances on the "do not track" front to a vastly expanded federal children's privacy rule going into effect on July 1, 2013, the privacy temperature is rising not just for the government, but for online and multichannel retailers as well.

For someone who has worked in the field of privacy for many years, this summer has involved a much welcome return of focus to the substantial harm that can result from a governmental violations of privacy rights, as opposed to the alleged harms caused by retailers. Unlike the recent privacy case against Michaels Stores in Massachusetts, where the alleged “harm” was the mere receipt of unwanted catalogs, government collection and misuse of private information can lead to dire consequences, ranging from Internal Revenue Service audits to profiling and criminal charges.  Moreover, the privacy issue as it relates to the government is one of constitutional dimensions.  As Justice Brandeis famously (and presciently) said in his dissenting opinion in Olmstead v. U.S., 277 U.S. 438, 478 (1928), the very first wiretapping case heard by the Court, each citizen has “the right to be let alone — the most comprehensive of rights and the right most valued by civilized men. To protect that right, every unjustifiable intrusion by the government upon the privacy of the individual, whatever the means employed, must be deemed a violation of the Fourth Amendment.” Olmstead was ultimately overturned, and Justice Brandeis' famous standard adopted, in Katz v. U.S., 389 U.S. 347 (1967), where the Court found a constitutional “right to be let alone” where a "reasonable expectation of privacy" existed.

Don't Be Fooled.  Even though the media is dominated by stories involving governmental intrusions into our private lives, the government itself remains fixated on pushing “do not track” requirements, with even a Republican FTC Commissioner giving industry what may amount to one last chance to come up with meaningful self-regulation rather than face the “static legislative solution” championed by Democratic FTC Chairwoman Edith Ramirez.  Ramirez recently vowed "to more aggressively regulate Internet companies like Facebook and Google and has called on Congress to pass privacy legislation.” Ironically, the most publicized "do not track" bills of the last few years impacted mostly on smaller online companies, and included gaping loopholes for the likes of Google, Facebook, and Apple.  As a result, every online seller needs to look closely at proposed "do not track" schemes — whether legislative or under voluntary industry standards — and decide whether proactive measures are appropriate, including involvement in industry groups and lobbying.  In all of their various iterations, "do no track" rules could have a considerable negative impact on online and multichannel retailers.

New Children's Privacy Rules.  There are also the new children’s privacy rules that go into effect on July 1, 2013, and which are creating significant compliance issues for many companies. Among other things, the new rule expands the definition of “personal information” to include “persistent identifiers” which can include online user names, cookies, and IP addresses, and the number of web sites that could fall under its requirements may be far larger than under prior law.

Privacy Litigation In Full Bloom.  Finally, litigation over privacy issues continues apace, not only including the now infamous zip code collection class actions, but also actions brought by privacy rights groups against companies like Snapchat.  Snapchat is accused of misleading users by claiming that its messages self-destruct after a fixed period of time.  However, according the Electronic Privacy Information Center, they do not.  This kind of litigation underscores the risks that can result if a company does not accurately describe its privacy-related practices, and reinforces the need to keep a close watch on your business activities to make sure that your privacy policy and other statements to consumers remain accurate.

We will continue to follow developments in privacy as it relates to both merchants and consumers and continue to update our readers in this space.

UPDATE:  The National Journal published a thoughtful and detailed article on June 13, 2013 about what Americans think about privacy, and which institutions they trust most. As the author, Ronald Brownstein explains: "Asked what would do the most to protect people’s personal information on the Internet, just 8 percent picked more government oversight. The biggest group (48 percent) said the key was 'more commitment by companies to not share users’ information with other businesses or government.'"

Friday, May 18, 2012

FTC Report outlines Consumer Privacy Framework, urges self-regulation

Following on the heels of the White House’s “Consumer Privacy Bill of Rights,” (recently discussed in this space), the Federal Trade Commission released its own final report on Consumer Privacy last month: “Protecting Consumer Privacy in an Era of Rapid Change, Recommendations for Businesses and Policymakers.” The issue of consumer privacy online continues to receive sustained attention from privacy advocates, policymakers and journalists (see, for example, the Wall Street Journal’s “What they Know” series), and this latest policy paper highlights a number of important areas for retailers.

The Commission’s Report, like the White House Report before it, is at heart a set of recommendations.  Its publication does not change the state of the law, or impose any new obligations on companies with respect to privacy.  While the Commission does urge Congress to pass targeted legislation requiring greater transparency in the data broker industry, its approach is primarily focused on encouraging industry self-regulation.  The advantages of this approach for industry sectors are obvious: by acting affirmatively in an area of public concern, industries can have a hand in shaping the rules so that they appropriately reflect the realities of a particular sector.  An adequate system of self-regulation could eliminate the perceived need for further regulatory or legislative action.  Companies should keep in mind, however, that once they adopt a voluntary code of conduct, they must abide by it, or they may open themselves up to an FTC enforcement action.  The practical lesson is simple: companies should only make promises they intend to keep.

The Commission outlines a privacy framework that it believes should be the basis for the voluntary codes of conduct it hopes companies will develop and adopt.  The four key areas of focus are:

Scope: The Commission applies its privacy framework to all companies that handle personal data, with a limited exception for companies that handle personal data for fewer than 5,000 individuals a year, and who do not share that data with any third parties.  The framework applies to data that is “Reasonably linkable to a specific consumer, computer, or device.”  This definition is an expansion of the traditional definition of “Personally Identifiable Information,” and reflects, in part, the Commission’s concern that data which has been removed of personally-identifiable characteristics, or “de-identified,” can often be re-identified.   

Privacy By Design: The Commission urges companies to adopt privacy practices consistent with the “Privacy by Design” model.  This means implementing practices that reflect the substantive principles of Data Security, Reasonable Collection Limits, Sound Retention Practices, and Data Accuracy.  These principles recognize that there is often both a business need and a consumer benefit associated with the collection and use of personal data, but requires that the scope of data collection and retention be reasonably related to the purpose for which it is collected.

Simplified Consumer Choice:  The Commission believes that consumers should be given meaningful and understandable choices about the way their personal data is collected and used by companies.  One of the important features of the Framework is its emphasis on context in determining the appropriate level of choice required for a particular data practice.  Thus, companies who collect personal data directly from consumers may use that data without offering a consumer any choice, when they engage in certain “commonly accepted” practices, including 1) product and service fulfillment; 2) internal operations; 3) fraud prevention; 4) legal compliance and public purpose; and 5) most first-party marketing.  For other types of data uses, including tracking across websites for behavior-based advertising, the Commission calls for companies to offer consumers clear choices, provided at a relevant time.  This includes respecting consumers’ use of a “do not track” option on web browsers.  

Increased Transparency: Consistent with its focus on the context in which personal data is collected and used, the Commission calls for increased transparency regarding consumer privacy practices.  It is particularly concerned with practices that take place without consumer awareness, including the practice of “data enhancement,” in which companies take personal data they have collected in the context of a relationship with a consumer, and combine it with data obtained by third party data brokers to create detailed consumer profiles.  Because data brokers – who collect and sell personal information about consumers directly to other businesses for marketing or other purposes – are largely invisible to consumers, it is difficult for consumers to exercise choices about the way their personal data is collected and used by these brokers.  The Commission supports targeted legislation to increase the transparency of the data broker industry, and suggests the creation of a centralized data broker portal, that consumers could visit to learn more about what information data brokers have collected about them, to verify the accuracy of that data, and to exercise appropriate choice.

The Commission’s emphasis on context reflects a new way of thinking about privacy in the internet era.  In a world of social media, consumers are accustomed to sharing some personal data and to making trade-offs relating to privacy, but they are concerned when a company’s collection or use of personal data is surprising or inappropriate to the service being provided.  Google and Facebook, for example, provide free services to consumers in exchange for using consumer-provided personal data to target those consumers for advertising.  Both companies ran afoul of the FTC, however, when they unilaterally made public certain information that consumers had previously assumed to be private.  The Commission deemed these actions to be unfair and deceptive trade practices and brought enforcement actions.  As a result of settlements with the Commission, both Google and Facebook have agreed to obtain affirmative, express consent from consumers before materially altering their privacy policies, and to submitting to 20 years of privacy audits.

For retailers, the Commission’s Report, and its record of enforcement in the Consumer Privacy area, illustrates an important truth about privacy: the practices that will receive the greatest scrutiny, and provoke the strongest reaction – be it public outcry, regulatory enforcement or legislative action – are those practices which are generally unknown to consumers, and which, when they come to light, strike consumers as surprising and inappropriate.  One way to guard against this kind of outcry is to take steps to better explain the ways that personal data is collected and used.  On the other hand, a sure way to provoke outcry and invite regulatory attention is to take a public position on privacy and then unilaterally fail to abide by it.

Regulators generally recognize that the collection and use of personal information is essential to the growth of the internet economy.  With their focus on encouraging self-regulation, the White House and the Commission hope to strike a balance that allows for continued innovation, while giving consumers greater comfort and more control regarding the ways their information is collected and used.  By cooperating with the Commission in developing sector-specific codes of conduct, retailers and other companies who collect and use personal data in the course of business have an opportunity to shape the rules pertaining to acceptable data practices.  The Commission does view these proposed self-regulatory codes of conduct as enforceable, however, and it will investigate companies found to be violating their own commitments.  Companies should thus be cautious in developing their privacy policies, and should only make commitments they are confident they can honor.

Co-authored by Nat Bessey

Wednesday, March 14, 2012

Obama Administration Releases Consumer Privacy Bill of Rights

In April 2011, Senators Kerry and McCain introduced a bill entitled the “Commercial Privacy Bill of Rights." As discussed in this space, the bill would have required online collectors of information to permit individuals to opt out of the collection of information about browsing and shopping activities and required affirmative consent (opt-in) for the collection of sensitive personally identifiable information, including email addresses. The bill’s introduction was met with significant hand-wringing by the online business community about the impact that it might have on the business practices of even the most reputable electronic merchants. The bill was referred to committee, and little has been heard about it since.

But the issue has not gone away. Apple, Google, Facebook, Path, UPromise, and others have all suffered embarrassing public relations setbacks as a result of the exposure of certain of their practices relating to the collection and use of user information.

In the meantime, the Obama Administration has shifted its focus to a (mostly) non-legislative solution to the perceived need for more robust protection of consumers’ online privacy. On February 23, 2012, the Obama administration published A Consumer Privacy Bill of Rights The Consumer Privacy Bill of Rights provides for industry self-regulation coupled with the prospect of government enforcement in the event that industry fails to do the things that it claims it will do. It would apply to “personal data,” broadly defined as any data that can be linked back to an individual.

The seven principles enshrined in the Consumer Privacy Bill of Rights are as follows:
  1. “Consumers have a right to exercise control over what personal data companies collect from them and how they use it.” This principle would require that consumers be given an appropriate measure of control over the personal data that companies collect and use. The control mechanisms should be simple and be commensurate with the scope and sensitivity of the data being collected.
  2. “Consumers have a right to easily understandable and accessible information about privacy and security practices.” This principle would require clear and meaningful disclosures of the types of date collected, why the data is needed, how it will be used, and whether and for what purpose it might be shared with third parties.
  3. “Consumers have a right to expect that companies will collect, use, and disclose personal data in ways that are consistent with the context in which consumers provided the data.” Pursuant to this principle, companies should limit their use and disclosure of data to purposes that are consistent with the relationship that the company has with the consumer, and the context in which the data was disclosed.
  4. “Consumers have a right to secure and responsible handling of personal data.” This principle imposes an obligation on companies to handle personal data in a responsible manner and to maintain reasonable safeguards against loss, unauthorized access, or disclosure.
  5. “Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data is inaccurate.” This concept would require that, at least with respect to certain kinds of sensitive data, companies should permit consumers to view information that has been archived about them and allow consumers to make corrections to that data.
  6. “Consumers have a right to reasonable limits on the personal data that companies collect and retain.” Under this theory, companies should only collect as much data as they need to accomplish the disclosed purpose of their data collection and should delete the data when it is no longer necessary.
  7. “Consumers have a right to have personal data handled by companies with appropriate measures in place to assure they adhere to the Consumer Privacy Bill of Rights.” This provision would require training of employees and accountability to enforcement authorities in the event of noncompliance with the principles embedded in the Consumer Privacy Bill of Rights.
The basic provisions of the Consumer Privacy Bill of Rights are so general as to be virtually meaningless without significant additional work. The administration’s plan is to work with stakeholder groups from various industries though what it refers to as a “multistakeholder process” to develop the practices and technologies necessary to implement these general principles. The stated objective is to draft a set of guidelines specific enough to be enforceable But, at least initially, the process does not contemplate enforceable legislation or regulation. Rather, the working groups would establish best practices which companies would then have the opportunity to adopt. In the event that a company fails to comply with the voluntarily undertaken rules, it would be subject to potential enforcement action by the FTC. Ultimately, however, the administration acknowledges that it would be in favor of legislation providing the FTC and the various state attorneys general to enforce the industry-written guidelines.

Although the substantive provisions of the Consumer Privacy Bill of Rights are very general, the document contains some clues as to the administration’s priorities among the specific provisions of the final codes of conduct.   Nevertheless, the text of the report foreshadows some of the specific rules that appear to be important to the administration:
  1. It appears likely that changes to browser technology (something akin to Firefox’s “private browsing” tool) may play an important role. Major online players such as Google and the Digital Advertising Alliance were involved in the drafting of the document and the publishers of the major browsers have apparently agreed to honor consumers’ “do not track” selections.
  2. On0e of the seven basic principles focuses on accessibility to information and the ability of consumers to correct mistakes.Many collectors of online data currently do not provide either of those capabilities, so it will be interesting to see in what direction the discussion moves on that topic.
  3. The “individual control” discussion, a discussion of the complexities presented by third party aggregators of data, must be addressed. These third party aggregators may have no direct relationship with consumers, and include those who search publicly available sources of data for the purpose of building profiles of individuals. These entities currently are not within the reach of privacy regulations, but the focus on that model suggests that they may be within the reach of the new standards.
It remains to be seen whether the process envisioned by the Obama Administration will actually result in any enforceable or meaningful development in the privacy area. And there is no guaranty, of course, that Congress will refrain from acting in the meantime, or that various states may act on their own. It is certain, however, that the conversation will continue, and that the outcome has the potential to be very important to members of the direct and online marketing communities.

Tuesday, April 26, 2011

Commercial Privacy Bill of Rights Introduced in Congress

The introduction of the so-called Commercial Privacy Bill of Rights by Senators Kerry and McCain on April 12, 2011 suggests that we may be about to enter an era of robust regulation of information gathering regarding the online browsing and shopping habits of consumers. This type of data has come to be an important tool for online marketers to improve the efficiency of online advertising buys, and to improve other marketing techniques. At a minimum, this development presents a risk that online merchants will need to build out substantial new technical infrastructure to accommodate a welter of new rules under this bill. Beyond that, it may make it difficult even for highly respected and responsible merchants to engage in marketing activities that are an important part of their tool kit in the information age.

Among other things, the bill contains the following requirements:
  • Collectors of information must implement security measures to protect the information they collect and maintain.
  • Collectors of information must provide clear notice to individuals of the collection practices and the purposes of such collection. Additionally, collectors must provide the ability for an individual to opt out of any information collection that is unauthorized by the Act and to provide affirmative consent (opt-in) for the collection of sensitive personally identifiable information. Respecting companies’ existing relationships with customers and the ability to develop a relationship with a potential customers, the bill would require "robust and clear" notice to an individual of his or her ability to opt-out of the collection of information for the purpose of transferring it to third parties for behavioral advertising. It would also require collectors to provide individuals either the ability to access and correct their information, or to request cessation of its use and distribution.
  • Collectors must bind third parties by contract to ensure that any individual information transferred to the third party by the collector will only be used or maintained in accordance with the bill’s requirements. The bill requires the collector to attempt to establish and maintain reasonable procedures to ensure that information is accurate.
These requirements can be expected to have significant operational impacts on direct marketers. The requirement for notice and opt-out rights for a series of practices that are quite technical in nature promises to be easier said than done. Existing privacy laws require only notice of the collection of personal information (much more narrowly defined than in this bill) and only very limited opt-out rights–essentially limited to CAN-SPAM compliance. This new bill would potentially require merchants to allow consumers to opt out of the collection of pixel tags, the placing of cookies, and the sharing of data harvested from those tools with third parties. Simply building the tools necessary to collect and implement those requirements would pose significant burdens and costs for online marketers, and may very well be beyond the abilities of many merchants.

Further, the bill stretches the definition of personal information beyond any commonly understood meaning of that term. It includes email addresses and postal addresses, and if "used, transferred or stored" in connection with any of the foregoing, birth date, and most significantly, "unique identifier information." Unique identifier information is defined as "a unique persistent identifier associated with an individual or a networked device, including a customer number held in a cookie, a user ID, a processor serial number, or a device serial number." This definition essentially means that virtually any data collected about a browsing session will be protected by this statute, with strict limits on the ability to use or transfer that data without approval.

The existence of an "established business relationship" exception to some of the requirements of the bill provides cold comfort. It applies not to the commonly understood relationship of customer and merchant, but only to the "establishment of an account." While this may be typical of some merchants' relationships with their customers, many retailers do not require the establishment of an account in order to make a purchase. It is interesting to note, however, that the 800 pound gorillas in the online space, notably Google and Facebook, would be the most likely to benefit from this exception.

The bill seeks to accomplish these objectives by requiring the FTC to promulgate regulations effectuating the statute's requirements for the most part within 60 to 180 days after enactment of the bill, depending upon the provision at issue. Accordingly, it will likely be a long time before these requirements take effect (if ever), given the Congressional legislative calendar, and the frequently protracted rule-making process that would attend any promulgation of regulations. During both the legislative process and the regulatory process, the direct marketing industry will have an opportunity to point out the technical challenges presented by this statute, as well as the potential unintended consequences, including damage to the economy, that the statute could create.

Friday, December 24, 2010

Is a Privacy Battle Brewing? The Department of Commerce Pushes Back On Commercial Privacy Regulation

In an unusual move, the Department of Commerce has chimed in on the question of Internet data privacy, issuing a 78-page report from its Internet Policy Task Force.  While the Chairman of the FTC has welcomed the new report, the business-oriented tone of the Commerce report suggests that a battle is brewing.  Indeed, the report offers strong support for a “voluntary, multi-stakeholder process” that includes businesses as important, cooperative partners, while the FTC treats voluntary efforts by industry -- and industry itself -- almost contemptuously.  While Commerce defers to the FTC as the primary enforcement authority, it also stages what appears to be a power grab to take a leadership role in defining how industry will or will not be regulated in the areas of privacy and information security.

So, what exactly is the Commerce report, and where is it  likely to lead?  The Commerce report refers to itself as a “green paper,” which one might think is a nod to wholesome environmental practices. Actually, in government-speak, a green paper is merely a tentative proposal or call for comments that might lead, eventually, to a white paper, which is a more formal statement of governmental policy.  As a result, both the Commerce report and the FTC initiative reflect tentative steps in the direction of statutory, regulatory, and policy changes.  How far they proceed is a matter of guesswork, particularly with a new and more conservative Congress waiting in the wings.

The Commerce Report Sounds the Defense of the Status Quo In Privacy Regulation, Founded In Large Part On Self-Regulation By Industry.   The Commerce report praises almost unconditionally the handling of the Internet under US law, focusing mainly on at the success of industry as voluntary self-regulators.  The report also posits the Department of Commerce itself as the leadership entity within the US Government on privacy matters, and claims a power to “ensure the Internet fulfills its social and economic potential.”  The FTC’s mandate of protecting consumers from commercial abuses is far narrower.  Direct marketers may have found, in the Department of Commerce, a voice to stand up to the newly regulation-happy and business-unfriendly FTC, and one that is ready to take power from the FTC.  This could not be clearer than in Commerce’s own recommendation that an overarching Privacy Policy Office be created under its regulatory umbrella.

FIPPs.  Commerce’s approach centers on the “broad adoption” of Fair Information Privacy Practices (“FIPPs”) that are sweeping and general enough to provide “ample flexibility” and “encourage innovation,” and envisions these being reflected in “voluntary, enforceable codes of conduct.”  If they are voluntary, of course, they likely would not be promulgated in the form of statutes and regulations. If they are nonetheless enforceable, it would seem as if Commerce -- at least in part -- envisions trade groups and associations to require adherence by members and to provide for their own policing. Whatever the implications, they are different from the FTC’s report requesting that Congress invest it with greater legal authority over privacy matters.  The FIPPs, as envisioned by Commerce, would include “simple notices, clearly articulated purposes for data collection, commitments to limit data uses to fulfill those purposes, and the expanded use of robust audit systems to bolster accountability.”

The PPO.  Commerce’s proposed Privacy Policy Office is intended to be both “the convener of diverse stakeholders” on privacy matters, but also the “center of Administration commercial data privacy expertise.”  It would work with the FTC in “leading efforts to develop voluntary but enforceable codes of conduct.”  In a sentence that likely made career FTC employees cringe, Commerce states that compliance with such voluntary codes would serve as a “safe harbor for companies facing certain complaints about their privacy practices.”  In other words, compliance with these voluntary codes could potentially insulate a company from privacy and security related claims asserted by the FTC, the individual states, and potentially even money-hungry class action lawyers.   Of course, the scope of the “safe harbor” protection is not made especially clear in the Commerce report, and past experience—as in the telemarketing area—suggests that Congress could seriously fumble on the issue preemption of state laws and limitations on bankrupting class action lawsuits.

Uniform Security Breach Notification Rules?  The Commerce report takes on an issue that has plagued direct marketers in recent years, and on which Congress has been unable to anything meaningful.  Specifically, it proposes replacing the patchwork of dozens of inconsistent state security breach laws with a single national law.  While this would put an array of consultants out of business, it would—if done correctly—remove significant regulatory expense (and uncertainty) from the shoulders of direct marketers of all sizes.

Overall, the Commerce report, if it is taken at face value as a genuine reflection of the Department of Commerce's position on commercial privacy matters, is a breath of fresh air.  Unlike the FTC's report, which treats things like personalized advertisements as horrible invasions of privacy, the Commerce report reflects an understanding that the collection and use of customer information by businesses has an important place in not only bolstering the growing internet economy, but also serving legitimate consumer and business interests.  And, unlike the FTC, places the greatest governmental focus on far more important privacy issues like data security and identity theft.

We are now at the beginning stages of a great debate about Internet privacy that could result in considerable change to the regulatory landscape.  In subsequent blog posts, we will be addressing in greater detail individual issues raised by both the Commerce and FTC reports, and provide insights how the debate is evolving.

We wish all of our readers a wonderful holiday season!

Tuesday, December 14, 2010

Do As I Say, Not As I Do: The FTC "Do Not Track" Initiative Could Cripple E-Commerce

Just as governments – including our own – are pursuing aggressive new initiatives to gather information about our individual browsing habits and electronic communications for law enforcement purposes, the FTC has decided to advise Congress on sweeping initiatives to prevent direct marketers from engaging in far less invasive practices that present none of the grave risks attendant to enhanced government surveillance.  Indeed, many of the commercial practices targeted by the FTC actually benefit consumers by assisting Internet sellers to configure their web sites, adjust their product offerings, and tailor advertising to the specific needs and interests of consumers.  While the FTC shrilly intones that consumer information about Internet browsing has been used by an unidentified "some" in "an irresponsible or even reckless manner," it fails to acknowledge forthrightly that the vast majority of direct marketers use such information solely to better serve their customers, and that new laws and FTC initiatives are unlikely to faze the tiny group of Internet pirates who misuse consumer data.

Although most headlines have focused on the FTC's proposal for a "do not track" list, the FTC report is about much more than that.  It foretells a highly aggressive new regulatory strategy that may change the landscape of Internet privacy without any concern for the cost impact on industry or a realistic assessment of the privacy interests of consumers.  It sweeps so broadly against business as to suggest that–if the FTC has its way–even entirely benign and non-intrusive information collection practices that do not track individual consumers will be sharply curtailed.  At the same time, new and intrusive requirements will be injected multiple times into virtually every consumer experience on the Web.  If you do business on the Internet, you need to know what the FTC is hoping to unleash on eCommerce.

If the FTC has its way, you will need to redesign your web sites and emails to provide real-time notice and choice to every consumer, whether or not they make any purchases.   The overarching theme of the report is highly paternalistic, suggesting that consumers are incapable of making informed choices about their buying decisions and Internet browsing activities.  Thus, privacy policies and full disclosure of information collection practices are viewed dimly by the FTC.  Instead, it commands that “consumers should [repeatedly] be presented with choice about collection and sharing of their data at the time and in the context in which they are making decisions.”  Not only would implementation of such a scheme add substantially to the programming costs of commercial web sites, it could interfere significantly with the consumer purchasing experience.  It is hard to imagine Web sales not suffering. 

The FTC's "Do Not Track" Initiative Creates a Presumption Against Collecting Information About Web Site Usage, Even If that Information Is Not Individually Identifiable.  The item in the report receiving the largest amount of press is the “do not track” recommendation.  It would obligate direct marketers to implement technology – through something “similar to a cookie,” according to the FTC – that would prevent the collection of web browsing activities by individuals or individual browser installations.  This would be mandated even if retailers do not actually collect individually-identifiable personal information.  Indeed, the FTC report supports doing away with the line drawn in existing law between information that is personally identifiable and that which is not, claiming that “traditional distinctions between the two categories of data are eroding.” Because "some" companies allegedly find surreptitious ways to connect non-personal information to specific individuals, the FTC is ready to recommend that all companies be prevented from collecting even aggregate usage data, which could be a significant blow to retailers who use this data to obtain helpful information for their businesses.  Data collection serves important functions that parallel the physical retail environment, including the measuring of foot traffic in certain areas of a store.  Denying this data to retailers in its non-personally identifiable form suggests a significant lack of government understanding of – or at least a gross lack of sensitivity to – legitimate industry needs.

At present, the FTC, itself, believes that it does not have authority to implement a tracking system without further action by Congress.  But, the pressure is on for Congress to enact a potentially sweeping new set of powers for the agency.  In the interim, the makers of at least one popular browser, Firefox, are exploring ways to implement a “do not track” feature that leaves it to consumers to choose whether they will be tracked.  Microsoft has already implemented a similar feature in its most recent release of Internet Explorer.  This approach is far less onerous for retailers, but may rob them of the very data they need to present consumers with meaningful purchasing choices through targeted advertising.  The least effective and most intrusive recommendation – that the FTC appears to favor – involves a “do not track” list that may leave it to Internet companies to figure out whether a person who is visiting their web site has chosen to place themselves on a list.   Because the specifics have yet to be determined, it is unclear what this list would even look like.  The FTC claims that a list of machine specific identifiers (as might be embedded in an operating system or hardware) or IP addresses is not a likely option.

Prepare to Open Your Files.  Some of what the FTC report recommends is positive for the industry, including “standardized” privacy-related notices (which might reduce uncertainty surrounding potential challenges by privacy rights groups, among other things), but the context – including whether federally mandated notices would preempt individual states from enacting different or more complicated disclosure requirements and whether class action lawsuits would be permitted against violators – remains a mystery, and the potential perils for eCommerce are significant.  Other FTC recommendations are chilling, including the requirement that companies provide customers “reasonable access” to all the data maintained about them and that the Children’s Online Privacy Protection Act’s onerous obligations be extended to cover children between the ages of 13 and 17.

What's Next?  The FTC has asked for industry comments as it pushes forward with its new privacy initiative.  This is a critical moment for direct marketers to be heard in petitioning the government to create and implement a more sensible, uniform approach to privacy protection that balances a realistic assessment of the potential harm to consumers against potentially dramatic and commerce-suppressing costs.

Friday, May 7, 2010

The "Draft" Federal Privacy Bill: Uniformity, But at What Cost?

On May 3, 2010, Representatives Rick Boucher, Democrat of Virginia, and Cliff Stearns, Republican of Florida introduced a “discussion draft” of a bill “[t]o require notice to and consent of an individual prior to the collection and disclosure of certain personal information relating to that individual.”  The bill seeks to provide uniform, national regulation of information collection and disclosure practices for a wide range of companies--governing not only the Internet, but all other channels of interaction between businesses and consumers--and it has already generated controversy.  Not only does it include a definition of private information that goes far beyond all existing laws, it contains strict notice and consent provisions that may be difficult and costly to implement.  It is unclear what triggered the drafting of the bill, nor what compelling public interest would warrant such a degree of intrusion into private business practices.

It is important to keep the draft bill in perspective.  Numerous privacy and security bills have been proposed over the years and Congress has, to date, been unable to pass anything coming close to comprehensive national legislation.  For example, repeated attempts to pass federal security breach legislation have failed, resulting in a plethora of state laws which are both confusing and inconsistent.  If Congress can't bring itself to pass uniform rules dealing with the very real issue of security breaches involving the theft or loss of sensitive personal information, the likelihood of it passing a comprehensive law governing the collection and use of personal information -- a far less serious matter -- seems limited, at best.

Nevertheless, it remains useful to examine the bill and how it addresses key issues that affect eCommerce companies.  Even if the bill fails to gather support in Congress, individual states may feel inspired to adopt some of its provisions.

Background.  To date, the laws governing online information collection and usage have been a patchwork.  While some states, like California, have enacted more general Internet-related privacy laws, the federal government has never seen fit to act globally in this arena, leaving businesses generally to self-regulate through the voluntary adoption of privacy policies.  Although it may come as a surprise to some, there is no federal law mandating privacy policies as a general matter.  Instead, Congress has limited such requirements to discrete categories of businesses (such as online businesses catering to children, banks and financial institutions, and health care providers, among others).

Key protections for business.  Most notably—and importantly—for direct marketers, the draft bill has a clear preemption provision.  In other words, it supersedes “any provision of a statute, regulation, or rule of a State that includes requirements for the collection, use, or disclosure of covered information.”  This would dramatically simplify the initial task of understanding the scope of a company's legal obligations in this arena, and would prohibit overlapping regulation by the states.  Just as importantly, the bill provides no private right of action in federal or state court, not even the much abused class action lawsuit.  Enforcement would rest in the hands of regulators rather than plaintiffs’ lawyers—removing a profit motive for enforcement which often prevents reasonable settlements.  Unlike plaintiffs' attorneys, regulators will take into account the unique facts and circumstances of each case and exercise something akin to "prosecutorial discretion" in determining which cases to bring and the appropriateness of any resulting penalty.

Who is subject to the requirements of the bill?  The only companies that escape its reach are those that (1) collect “covered information” from less than 5,000 individuals in any 12-month period and (2) do not collect “sensitive information.”  Unless you meet both of these criteria, you are subject to all of the bill's requirements.

What information does the bill cover?   In terms of what is deemed to be private information, the bill's reach is unprecedented and ought to be very worrisome to the industry.  A person's name, alone, is suddenly protected, as any individual's postal address, telephone number, or email address.  To date, no state or federal law reaches this far, and, as drafted, it leads to absurd results.  For example, it could mean that telephone companies have broken the law by publishing their local "white pages," since names and/or telephone numbers are deemed private.  Private information also includes fax numbers, unique biometric data, any government-issued identification number, financial account numbers (including credit and debit card numbers) along with any password necessary to permit access, any “unique persistent identifier,” including an IP address, and even preference profiles.  (Under the bill, a "preference profile" means “a list of information, categories of information, or preferences associated with a specific individual or a computer or device owned or used by a particular user that is maintained by or relied upon by a covered entity.”)  “Sensitive information” is defined to include all medical information; race or ethnicity; religious beliefs; sexual orientation; financial information associated with a financial account; and “precise geolocation information.”

The following is a sampling of some of the substantive provisions of the bill:
  • The bill requires a “privacy notice” to be made available to every individual from whom “covered information” is obtained.   Where information is collected via the Internet, the notice must be clearly and conspicuously posted and accessible from the home page.  Given FTC guidance in this area, the clear and conspicuous requirement would mean the link should be visible without scrolling down.  Where information is collected by means other than the Internet, the notice must be provided in writing before the information is collected.  It appears that this requirement could be met by with a counter display or printed handout.  However, such a sign or handout would be far more than a simple "heads up" notice.
  • There are fifteen separate content requirements for a “privacy notice." It would need to include  the nature of the “covered information” collected; how such information is collected; the specific purposes to which such information is put; how (and how long) such information is stored; how such information may be combined with other information obtained about the individual from other sources; how the information is disposed of; the purposes for which such information is disclosed to third parties and the “categories” of such third parties; the choices available to consumer to limit or prohibit collection or disclosure; the means by and extent to which the individual may obtain access to such information; the process by which notice is given of changes to the policy; and the effective date of the policy.  While some of these disclosures are familiar to online sellers, they—in whole—exceed customary industry practices.
  • Businesses must obtain the prior consent of the individual to collect and use “covered information.”  Such consent must be either an “affirmative grant” or a failure “to decline consent,” either of which must follow the provision of the privacy statement to the individual.  Strikingly, however, the law allows the consumer to withdraw consent to the use information at any time, even if it was previously collected after consent was obtained.  
  • With some exceptions, express affirmative consent must be obtained in the event of any material change to the privacy notice or any new use of information which an individual would reasonably “not expect based on the covered entity’s prior privacy notice.”
As might be expected, consumer groups are already arguing that the bill fails to go far enough.

Tuesday, May 4, 2010

Should You Be FACTA Compliant? -- June 1, 2010 Deadline for Compliance with the FTC’s Red Flags Rule Approaches

Under the Fair and Accurate Credit Transactions Act (“FACTA”), Congress in 2003 mandated that businesses which extend credit to consumers for personal, family or household purposes must adopt policies and procedures designed to identify instances of possible “identity theft” in connection with transactions/requesting such credit.  The regulations promulgated by the Federal Trade Commission (“FTC”) implementing FACTA’s provisions are referred to as the “Red Flags Rule,” because the procedures adopted by businesses are supposed to identify “red flags” that signal a risk of identity theft in connection with a consumer credit transaction.  After deferring the effective date of the Red Flags Rule four times, the deadline for affected businesses to comply is now June 1, 2010.

On its face, FACTA would not appear to apply to many direct marketers or Internet sellers, who most often do not extend credit, themselves, but instead rely on credit cards.  The requirements of FACTA, however, extend to those retailers that sell products or services on installment plans or otherwise extend credit to consumers.  In addition, retailers that offer private label or co-brand credit cards (i.e. the retailer’s name appears on the credit card) may also be affected, even if they do not act as the issuer of the card.  This is because the FTC’s Red Flags Rule also applies to service providers and others who assist creditors (the card issuer) in receiving or processing requests for credit.  Furthermore, FTC staff has indicated their intent to apply the Red Flags Rule very broadly, so that the rule may be applied even to transactions involving the extension of credit to sole proprietorships, on the theory that such transactions involve a risk of identity theft for the individual operating such a business.

If your company is required to comply with the Red Flags Rule, you will need to adopt procedures satisfying certain prescribed elements, tailored to your particular business.  In addition, you should be aware that Congress (perhaps to demonstrate the seriousness it ascribes to the growing crime of identity theft) expressly mandated in FACTA that affected businesses and institutions must ratify their Red Flags procedures through action of the company’s board of directors or a committee of the board of directors.

Determining your obligations under FACTA, if any, and adopting appropriate procedures requires careful consideration of your various business activities with the assistance of experienced counsel.  The downside of failure to adopt Red Flags procedures is not limited to enforcement action by the FTC –– worse, by far, would be the consumer and public relations problems following a data breach of sensitive customer information without having a required FACTA plan in place to identify potential risks of identity theft.  The good news is that the analysis of whether a plan is required, and the subsequent crafting and adoption of a plan, need not be burdensome.

Thursday, March 25, 2010

What’s Next For Sales Tax (a/k/a Use Tax) On Direct Mail?

Direct marketers know that successful eCommerce strategies often depend upon reaching customers offline as well as online. Direct mail, including the distribution of catalogs, remains one of the most effective ways of driving traffic to a website. Indeed, given the reluctance of some consumers to give out their e-mail addresses, and the protections afforded consumers from unwanted solicitation under anti-SPAM, Do-Not-Call and other consumer privacy laws, traditional “snail mail” marketing techniques remain an important way for Internet sellers to communicate directly with customers.

Although several larger states (including California, New York, and Pennsylvania) provide exemptions from tax for certain types of direct mail, the vast majority of jurisdictions treat direct mail as taxable. And in all states, including those that provide exemptions, there are myriad other complex legal issues affecting taxability, including sourcing rules, taxability of postage, “direct mail” certificates, and nexus considerations, each of which make determining the proper sales tax treatment of direct mail transactions challenging. Add the fact that mailings go to recipients in many, if not all 50 states (and countless localities), each of which has its own tax law, and the difficulty of properly applying tax to any particular direct mail transaction multiplies exponentially.

Perhaps due to this complexity, states historically did not aggressively pursue audits or assessments on direct mail.  But, those days are gone. In recent years, states and localities have begun focusing more and more on sales and use tax application to direct mail, in part due to attention given the issue by the Streamlined Sales and Use Tax Agreement (“SSUTA”). Although it takes no position on whether direct mail should be subject to tax, the SSUTA project raised the issue’s profile by adopting provisions addressing the sourcing of direct mail transactions. Those provisions were amended in late 2009 to separate the treatment of “advertising and promotional direct mail” from other types of direct mail, such as invoices, notices, etc. But, the provisions do nothing to minimize (and, coupled with other provisions in the SSUTA, arguably aggravate) the complexity of taxation of direct mail.

In the last two years, many of the more aggressive states, particularly non-SSUTA states, began to put pressure on large printers and letter shops to collect the use tax on their sales of direct mail pieces, even on sales to clients that lacked any presence in the state. Internet and direct marketers began to receive unwelcome notices from their printers that they would have to pay tax on large print contracts, adding 7-10% to the already high cost of doing business for direct marketers

Given budgetary problems in states throughout the nation, revenue departments will likely continue to look for ways to boost tax collections from direct mail transactions. Direct marketers need to be aware of this issue prior to entering into any negotiation over print and other direct mail contracts; direct mail firms should understand their potential tax obligations and recognize that they may be able to take steps to minimize their tax exposure and thereby offer more competitive fees to their clients.

Tuesday, March 16, 2010

Think You’re Safe Storing or Releasing “Anonymized” Data? Think Again.

Anonymity is increasingly difficult to safeguard, and direct marketers that collect, maintain, share, and use customer information should take note of a recent class action settlement by Netflix than stemmed from the company's disclosure of an "anonymized" customer database.

Most federal and state privacy and data security statutes focus on the protection of "personally identifiable information," such as names, addresses, telephone numbers, financial account numbers, social security numbers, and email addresses. In response to such laws, many companies strip personally identifiable information from databases containing sensitive information. Once stripped of identifiers, the theory goes, the risks of identity theft or violations of consumer privacy rights resulting from disclosure of the data (whether purposeful or not) are eliminated. Some companies may even conclude that the data may be shared for marketing or "data mining" purposes without violating their privacy policies or applicable laws.

According to the Electronic Privacy Information Center, however, "computer scientists have revealed that this 'anonymized' data can easily be re-identified, such that the sensitive information may be linked back to an individual."

Ten years ago, the risk of such "re-identification" was "largely theoretical":

"In a corner of the U.S. Census Bureau, a small group of statisticians has been sweating out the agency's nightmare scenario: 're-identification.' That's the term for a technique that the bureau fears could allow marketers and other "intruders" to match anonymous census information with the names of the people who provided it. Such a concern is largely theoretical, so far. But if perfected, the technique could have great appeal to marketers of everything from french fries to financial services."

-Glenn R. Simpson, "The 2000 Count: Bureau Blurs Data To Keep Names Confidential," The Wall Street Journal, February 14, 2001.

The risk is theoretical no more, and online sellers and direct marketers that fail to pay attention to the issue do so at their own peril.

The Netflix Case. Netflix just announced that it is canceling its Netflix Prize after being sued in federal court on a class action basis for invasion of privacy and violation of the Video Privacy Protection Act ("VPPA") based upon the alleged re-identification of individuals whose movie rating information was made public in a database that had been scrubbed of personal information.

Netflix sponsored a contest to see if entrants could provide "collaborative filtering algorithms" that could better predict viewers' movie ratings than Netflix's existing Cinematch recommendation engine. In connection with the contest, entrants were given an "anonymized" training data set that contained 100 million subscriber movie ratings covering 480,000 subscribers and 18,000 movies. Each of the rating entries included a unique numeric identifier representing the subscriber, but contained no personally identifiable information.
It didn't take long, however, for two researchers at the University of Texas to identify two of the anonymous subscribers in the training data set. They did so by using public reviews available on the Internet Movie Database and re-identification algorithms. The researchers found that one of the people they identified "had strong-ostensibly private-opinions about liberal and gay-themed films and had ratings for some religious films." (The complete study is available here.) The researchers were apparently able to identify individual subscribers despite the "perturbation techniques" employed by Netflix to protect individual identities. (Perturbation adds "noise" to a database to protect individual record confidentiality. The UT researchers had developed a technique that was "robust to perturbation in the data.")

In at least one respect, the Netflix case presented a good opportunity for class action plaintiffs because the federal VPPA specifically makes video rental information private. (As is often the case with privacy laws, the VPPA was passed in reaction to a highly publicized event - in this case, the release of Judge Robert Bork's video rental records during Senate hearings on his nomination to the United States Supreme Court.) But, the Netflix suit went far beyond alleged VPPA violations, and included sweeping counts under California statutes (including for alleged unfair trade practices and false advertising), as well as common law privacy claims. Not only was Netflix sued, the Federal Trade Commission jumped on the bandwagon. Eventually, after "productive discussions" with the FTC, the suit was settled and the Netflix Prize was no more.

Takeaway. The Netflix case raises very serious questions for online sellers and direct marketers with regard to supposedly anonymous aggregated databases that reflect customer information, including purchasing histories and demographic information. In the future, we may well see privacy and security laws evolve to cover databases that are susceptible to re-identification. Each company should actively examine the intersection between its business objectives and the privacy concerns of its customers with regard to the collection, storage, and use of customer data. Clear and accurate privacy policy disclosures are essential to ensure that consumers understand a company's information collection and disclosure practices. The claims against Netflix included assertions that standard privacy policy provisions were materially misleading given the availability of re-identification.

Friday, March 12, 2010

Thoughts from the NEMOA Spring Conference: Perils for Vendors from Affiliate Endorsements

Today was Day 3 of the New England Mail Order Association Spring Conference in Boston. It was a great conference with lots of opportunities for benchmarking and networking. A number of industry gurus were present, including George Michie from The Rimm-Kaufman Group, who gave a great talk on paid search issues that this lawyer found compelling.

Marty Eisenstein and I moderated a round table discussion on emerging online affiliate issues. There was quite a bit of interest in new FTC guidelines regarding testimonials and endorsements. These new guidelines have the potential to impact seriously a number of business practices that are quite common among reputable online merchants.

Imagine if you will the following scenario: Acme Direct Marketing is an online seller of skin cream. Acme enters into an agreement with a third party to create a revenue-sharing affiliate network for the purpose of generating traffic to Acme's website. Affiliates enroll through the third party--perhaps Google. Many affiliates, if not all, are anonymous as far as Acme is concerned. They are paid each month based upon the traffic that they drive to Acme's website. Traffic is measured by the third party, who bills Acme for traffic generated each month. I am guessing that this scenario sounds quite familiar to many online merchants--in fact almost all online merchants engage in some variation of this business practice.

Now assume that one such affiliate (or maybe several) includes content on its website for the purpose of attracting attention and referring traffic to the merchants for whom it is an affiliate. The material that it posts on its website is often not entirely accurate--after all, these folks know nothing about the cosmetics business, and even less about truth-in-advertising. Perhaps the affiliate takes some liberties with the supposed benefits of Acme's product.

Under new FTC guidelines, Acme is responsible for false or misleading statements made by its affiliates. Moreover, the affiliate is obligated to disclose that it receives remuneration in exchange for sending traffic to Acme's website.

In many instances, the system for managing far flung affiliate networks is simply not designed to permit monitoring of these affiliate sites. In addition, early indications in the marketplace show that third party affiliate programs are not eager to assume any of the legal risks associated with these new guidelines.

Under the circumstances, responsible merchants need to be thinking about techniques for monitoring affiliate networks, and for securing contractual assurances that the affiliates will comply with the new rules.

Thursday, March 11, 2010

LifeLock: $12 Million to Settle Data Security False Advertising Claims

The company whose advertising campaign included displaying their CEO's social security number on the side of a truck has reached a settlement to pay $12 million to the FTC and 35 states who charged LifeLock, Inc. with false representations about the effectiveness of its services. In an official press release, FTC Chairman Jon Leibowitz said that “[w]hile LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it.”

But the case against LifeLock didn't end there. The FTC and the states also charged LifeLock with making false claims about its own data security practices. According to the FTC, LifeLock failed to live up to the following representations:

• “Only authorized employees of LifeLock will have access to the data that you provide to us, and that access is granted only on a ‘need to know’ basis.”

• “All stored personal data is electronically encrypted.”

• “LifeLock uses highly secure physical, electronic, and managerial procedures to safeguard the confidentiality and security of the data you provide to us.”

The FTC charged that "LifeLock’s data was not encrypted, and sensitive consumer information was not shared only on a 'need to know' basis." The agency also charged that the company’s data system was vulnerable and could have been exploited by those seeking access to customer information." Read more here.

Takeaway
: Many companies make promises about data security, particularly in connection with online transactions. If your company is going to publish those kinds of assurances, make sure you live up to them. While this is not the first time the FTC has penalized a company for allegedly false claims about data security, the fine is one of the largest.