Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Friday, October 25, 2013

California Ups the Ante On Privacy Policy Disclosures

For the past decade, California law has set the template for commercial website privacy policies.  With the passage of a new law, set to take effect January 1, 2014, the state has updated the disclosures required of any commercial website operator who collects personally identifiable information from California residents.

California’s Online Privacy Protection Act.   In 2003, California became the only state to require all websites that collect personal information (“PII”) from visitors – in this case, California residents – to post a privacy policy.   Until then, there was no generally applicable privacy policy requirement under either state or federal law, and, to this day, neither the other states nor the federal government have imposed such a requirement.  Federal privacy policy requirements have been limited to specific kinds of information (such as under Children’s Privacy Protection Act) or industries (under the Health Insurance Portability and Accountability Act).  Under the 2003 law, Internet sites need to identify the “categories” of personally identifiable information collected about “individual consumers”; describe the “categories” of third parties with whom the information may be shared; disclose (if there is one) any process for individuals to review or request changes to their personal information; explain how notice is given to consumers of changes in the privacy policy; and post the policy’s effective date. The definition of PII is more expansive than encountered in data breach statutes, and includes email addresses, partial addresses (including street names and towns), and first and last names.  The privacy policy also must be “conspicuously” posted, as defined by the statute.

Now, however, the law has been significantly expanded.

The New Requirements. Under recently enacted Assembly Bill 370, the privacy policy requirements of California’s Online Privacy Protection Act have been expanded to include (1) disclosure of how the web site “responds to Web browser ‘do not track’ signals or other mechanisms that provide consumers the ability to exercise choice regarding the collection of personally identifiable information about an individual consumer’s online activities over time and across third-party Web sites or online services, if the operator engages in that collection”; and (2) disclosure of “whether other parties may collect personally identifiable information about an individual consumer’s online activities over time and across different Web sites when a consumer uses the operator’s Web site or service.” The statute was approved by the Governor and chaptered by the Secretary of State on September 27, 2013. It will take effect on January 1, 2014. Fortunately for Internet sellers, the law provides that “[a]n operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.” As a result, potential liability will only attach after a notice of noncompliance. Nonetheless, it is prudent to review and amend privacy policies to conform with the new law to avoid having to implement last minute changes should your company receive notice of non-compliance (which is not defined, and presumably could include a telephone call or email from a consumer).

The Light Still Shines.   Companies should also remain mindful of California’s so-called “Shine the Light” Law, which can be found at California Civil Code § 1798.83, and as to which we’ve previously blogged. Violations of this law, which, among other things, requires privacy policy disclosures, have led to class actions being filed against Internet sellers.  Customers can be awarded up to $3,000 per each violation, plus attorneys’ fees and costs.  Some of these cases have been dismissed, but the costs of defending even an unsuccessful class action lawsuit can be substantial.

The Shape Of Things To Come.  California isn’t stopping there. Beginning on January 1, 2015, all web sites that direct services to minors, or have actual knowledge that minors are using their sites, must provide a “delete” button to permit minors to remove all of their online content (together with clear instructions for doing so). The law will also prohibit Internet marketing of a wide variety of products and services to minors, including aerosol paint (apparently to inhibit graffiti), etching creams, BB guns, and tanning services. Unlike the COPPA, which is directed to persons under the age of 13, the California law applies to all persons under the age of 18.

Wednesday, June 12, 2013

The Summer of Privacy: With the Government Under Fire, Retailers May Overlook New Rules and Risks


This may one day be known as the Summer of Privacy. From claims that the NSA surreptitiously obtains cellphone (and GPS) information from at least 100,000,000 Americans to the Supreme Court blessing routine collection of DNA evidence from arrestees, it is impossible to avoid almost daily stories on governmental privacy issues. But, don't be fooled by the focus on governmental activity. From advances on the "do not track" front to a vastly expanded federal children's privacy rule going into effect on July 1, 2013, the privacy temperature is rising not just for the government, but for online and multichannel retailers as well.

For someone who has worked in the field of privacy for many years, this summer has involved a much welcome return of focus to the substantial harm that can result from a governmental violations of privacy rights, as opposed to the alleged harms caused by retailers. Unlike the recent privacy case against Michaels Stores in Massachusetts, where the alleged “harm” was the mere receipt of unwanted catalogs, government collection and misuse of private information can lead to dire consequences, ranging from Internal Revenue Service audits to profiling and criminal charges.  Moreover, the privacy issue as it relates to the government is one of constitutional dimensions.  As Justice Brandeis famously (and presciently) said in his dissenting opinion in Olmstead v. U.S., 277 U.S. 438, 478 (1928), the very first wiretapping case heard by the Court, each citizen has “the right to be let alone — the most comprehensive of rights and the right most valued by civilized men. To protect that right, every unjustifiable intrusion by the government upon the privacy of the individual, whatever the means employed, must be deemed a violation of the Fourth Amendment.” Olmstead was ultimately overturned, and Justice Brandeis' famous standard adopted, in Katz v. U.S., 389 U.S. 347 (1967), where the Court found a constitutional “right to be let alone” where a "reasonable expectation of privacy" existed.

Don't Be Fooled.  Even though the media is dominated by stories involving governmental intrusions into our private lives, the government itself remains fixated on pushing “do not track” requirements, with even a Republican FTC Commissioner giving industry what may amount to one last chance to come up with meaningful self-regulation rather than face the “static legislative solution” championed by Democratic FTC Chairwoman Edith Ramirez.  Ramirez recently vowed "to more aggressively regulate Internet companies like Facebook and Google and has called on Congress to pass privacy legislation.” Ironically, the most publicized "do not track" bills of the last few years impacted mostly on smaller online companies, and included gaping loopholes for the likes of Google, Facebook, and Apple.  As a result, every online seller needs to look closely at proposed "do not track" schemes — whether legislative or under voluntary industry standards — and decide whether proactive measures are appropriate, including involvement in industry groups and lobbying.  In all of their various iterations, "do no track" rules could have a considerable negative impact on online and multichannel retailers.

New Children's Privacy Rules.  There are also the new children’s privacy rules that go into effect on July 1, 2013, and which are creating significant compliance issues for many companies. Among other things, the new rule expands the definition of “personal information” to include “persistent identifiers” which can include online user names, cookies, and IP addresses, and the number of web sites that could fall under its requirements may be far larger than under prior law.

Privacy Litigation In Full Bloom.  Finally, litigation over privacy issues continues apace, not only including the now infamous zip code collection class actions, but also actions brought by privacy rights groups against companies like Snapchat.  Snapchat is accused of misleading users by claiming that its messages self-destruct after a fixed period of time.  However, according the Electronic Privacy Information Center, they do not.  This kind of litigation underscores the risks that can result if a company does not accurately describe its privacy-related practices, and reinforces the need to keep a close watch on your business activities to make sure that your privacy policy and other statements to consumers remain accurate.

We will continue to follow developments in privacy as it relates to both merchants and consumers and continue to update our readers in this space.

UPDATE:  The National Journal published a thoughtful and detailed article on June 13, 2013 about what Americans think about privacy, and which institutions they trust most. As the author, Ronald Brownstein explains: "Asked what would do the most to protect people’s personal information on the Internet, just 8 percent picked more government oversight. The biggest group (48 percent) said the key was 'more commitment by companies to not share users’ information with other businesses or government.'"

Tuesday, December 4, 2012

Data Breaches: Some Lessons

Some of our readers may have read about recent high profile data breaches, such as the one involving credit card information taken from many Barnes & Noble retail stores. Or they may have heard of the huge class action law suits against Sony which resulted from its handling of a 2011 incident involving hackers into the Sony Playstation network. In that case, the hackers accessed personal information including names, addresses, user names, passwords, and other personal information from about 77 million user accounts. And they may have read about the breach involving TD Bank, in which TD Bank misplaced in March 2012 computer back-up tapes containing personal information for 267,000 customers, but did not inform the affected customers and pertinent state authorities until seven months later, in October. Each of these instances brings to light some apparent misconceptions regarding the handling of data breaches.  

Myth 1: There is no law that requires action in the event of a data breach.

Fact 1: There is no federal law (aside from laws regarding specialized industries such as banking and health care) that requires a response. However, 46 states, the District of Columbia, Puerto Rico, and the U.S. Virgin Islands require certain actions be taken in the event of a data breach regarding personal information, and each of these laws is different.

Myth 2: My company only needs to comply with the data breach laws of the states in which my company has an office or other physical presence.

Fact 2: A company is subject to the data breach laws of not only the states in which it has a physical presence but also the states in which it has customers.

Myth 3: I need only look at one state’s laws if there has been a data breach.

Fact 3:In the unfortunate event of a data breach, you need to follow the laws of each state where the affected persons reside, and not just the law of the state where their information is maintained or the breach has occurred.

Myth 4: My company can have a uniform response to a data breach.

Fact 4: State laws require notifications to affected consumers and state agencies in the event of a breach. Some also require notifications to credit reporting agencies. The laws are not uniform with regard to what constitutes a data breach, the government agencies to be notified, the credit reporting agencies, if any, that need to be contacted, and the contents of the notice to individuals whose information was compromised.

Myth 5: My company is not required to have a data breach response plan in the event of a data breach.

Fact 5: If the company makes sales to residents of Massachusetts, then the company must have a written plan to disclose how it intends to respond to data breaches. This is part of a so-called WISP, as required by a 2010 Massachusetts law. Moreover, a data breach response plan can provide a critical defense to class action lawsuits claiming that your company failed in its duty to protect customers against harm resulting from data breaches.

Myth 6: My company can play it by ear when there is a data breach, so it is of little value to plan.

Fact 6: A company must and should tailor its response to a data breach to the facts and circumstances of the breach—and so there is a need “to call audibles at the line of scrimmage.” However, data breaches are dynamic events that require immediate, consistent action to: investigate what happened, determine the appropriate responses to stop the security breach, shape the correspondence with individuals whose information is compromised, and decide on notification to the appropriate federal and state authorities. Most of the actions require approval at the highest levels of a business. There needs to be a signal caller for the plays based on a play book developed before the game and the play takes place.

Myth 7: There is no requirement that my company respond quickly to a data breach, and we certainly do not want our actions to take away from our company’s efforts to operate the business.

Fact 7: No state law requires a fixed period of time to respond to a data breach. Many of the laws require prompt responses, however. And every day of delay for serious data breaches increases the potential exposure to real damage done to persons whose information has been compromised. Sony has oftentimes been criticized, and it has been hit with a number of class action law suits, because of the one week delay in notifying appropriate federal and state officials and the users whose information was compromised. A data breach response plan permits companies to continue to operate their businesses at times of a data breach, yet take the necessary action in as short a time possible under the circumstances. Finally, many state laws require notice to consumers before a data breach has been confirmed where there a reasonable likelihood of such a breach. As a result, waiting until a full investigation has been completed can violate applicable laws.

Myth 8: The data breach does not affect credit card numbers. Therefore, there is no required response.

Fact 8: Each of the data breach laws require notification of consumers and state agencies if the information compromised involves personal information, which is generally defined as a combination of a name and a data element, which may be a credit card number, but may also be a social security number, driver’s license number, bank account number. or other state-issued identification number. In addition, data breach notification requirements can be triggered even if the data involved is encrypted, since the laws of some states provide no exceptions for encrypted information.

Myth 9: The information was compromised when possessed by a third party, so my company need not make any notification to our customers.

Fact 9: The state data breach notification laws generally apply to any company that stores or maintains personal information or owns or licenses personal information of an individual. Thus, if a retailer submits personal information to a third party for processing—e.g., to a company to do a merge/purge or to send emails—it has a duty to notify the consumer whose information was compromised. All retailers should make sure that their contracts with outside contractors have suitable provisions addressing the confidentiality of personal information of their customers and employees as well as required notifications to the retailers in the event of a breach.

Myth 10: Data breaches occur only for large companies and my company is too small to be subject to either a data breach or the required response to a data breach.

Fact 10: In a recent survey, PricewaterhouseCoopers found that 70 percent of companies responding to the survey had experienced a data breach in the prior year. Other studies have found that data breaches are episodic and can occur to companies regardless of size. None of the data breach laws maintain a small business exception.

Conclusion

Inappropriate responses to data breaches can expose a company to significant liability and unfavorable publicity. Developing and implementing a sound data breach plan can reduce these adverse consequences and help avoid penalties from government “referees."

Friday, May 18, 2012

FTC Report outlines Consumer Privacy Framework, urges self-regulation

Following on the heels of the White House’s “Consumer Privacy Bill of Rights,” (recently discussed in this space), the Federal Trade Commission released its own final report on Consumer Privacy last month: “Protecting Consumer Privacy in an Era of Rapid Change, Recommendations for Businesses and Policymakers.” The issue of consumer privacy online continues to receive sustained attention from privacy advocates, policymakers and journalists (see, for example, the Wall Street Journal’s “What they Know” series), and this latest policy paper highlights a number of important areas for retailers.

The Commission’s Report, like the White House Report before it, is at heart a set of recommendations.  Its publication does not change the state of the law, or impose any new obligations on companies with respect to privacy.  While the Commission does urge Congress to pass targeted legislation requiring greater transparency in the data broker industry, its approach is primarily focused on encouraging industry self-regulation.  The advantages of this approach for industry sectors are obvious: by acting affirmatively in an area of public concern, industries can have a hand in shaping the rules so that they appropriately reflect the realities of a particular sector.  An adequate system of self-regulation could eliminate the perceived need for further regulatory or legislative action.  Companies should keep in mind, however, that once they adopt a voluntary code of conduct, they must abide by it, or they may open themselves up to an FTC enforcement action.  The practical lesson is simple: companies should only make promises they intend to keep.

The Commission outlines a privacy framework that it believes should be the basis for the voluntary codes of conduct it hopes companies will develop and adopt.  The four key areas of focus are:

Scope: The Commission applies its privacy framework to all companies that handle personal data, with a limited exception for companies that handle personal data for fewer than 5,000 individuals a year, and who do not share that data with any third parties.  The framework applies to data that is “Reasonably linkable to a specific consumer, computer, or device.”  This definition is an expansion of the traditional definition of “Personally Identifiable Information,” and reflects, in part, the Commission’s concern that data which has been removed of personally-identifiable characteristics, or “de-identified,” can often be re-identified.   

Privacy By Design: The Commission urges companies to adopt privacy practices consistent with the “Privacy by Design” model.  This means implementing practices that reflect the substantive principles of Data Security, Reasonable Collection Limits, Sound Retention Practices, and Data Accuracy.  These principles recognize that there is often both a business need and a consumer benefit associated with the collection and use of personal data, but requires that the scope of data collection and retention be reasonably related to the purpose for which it is collected.

Simplified Consumer Choice:  The Commission believes that consumers should be given meaningful and understandable choices about the way their personal data is collected and used by companies.  One of the important features of the Framework is its emphasis on context in determining the appropriate level of choice required for a particular data practice.  Thus, companies who collect personal data directly from consumers may use that data without offering a consumer any choice, when they engage in certain “commonly accepted” practices, including 1) product and service fulfillment; 2) internal operations; 3) fraud prevention; 4) legal compliance and public purpose; and 5) most first-party marketing.  For other types of data uses, including tracking across websites for behavior-based advertising, the Commission calls for companies to offer consumers clear choices, provided at a relevant time.  This includes respecting consumers’ use of a “do not track” option on web browsers.  

Increased Transparency: Consistent with its focus on the context in which personal data is collected and used, the Commission calls for increased transparency regarding consumer privacy practices.  It is particularly concerned with practices that take place without consumer awareness, including the practice of “data enhancement,” in which companies take personal data they have collected in the context of a relationship with a consumer, and combine it with data obtained by third party data brokers to create detailed consumer profiles.  Because data brokers – who collect and sell personal information about consumers directly to other businesses for marketing or other purposes – are largely invisible to consumers, it is difficult for consumers to exercise choices about the way their personal data is collected and used by these brokers.  The Commission supports targeted legislation to increase the transparency of the data broker industry, and suggests the creation of a centralized data broker portal, that consumers could visit to learn more about what information data brokers have collected about them, to verify the accuracy of that data, and to exercise appropriate choice.

The Commission’s emphasis on context reflects a new way of thinking about privacy in the internet era.  In a world of social media, consumers are accustomed to sharing some personal data and to making trade-offs relating to privacy, but they are concerned when a company’s collection or use of personal data is surprising or inappropriate to the service being provided.  Google and Facebook, for example, provide free services to consumers in exchange for using consumer-provided personal data to target those consumers for advertising.  Both companies ran afoul of the FTC, however, when they unilaterally made public certain information that consumers had previously assumed to be private.  The Commission deemed these actions to be unfair and deceptive trade practices and brought enforcement actions.  As a result of settlements with the Commission, both Google and Facebook have agreed to obtain affirmative, express consent from consumers before materially altering their privacy policies, and to submitting to 20 years of privacy audits.

For retailers, the Commission’s Report, and its record of enforcement in the Consumer Privacy area, illustrates an important truth about privacy: the practices that will receive the greatest scrutiny, and provoke the strongest reaction – be it public outcry, regulatory enforcement or legislative action – are those practices which are generally unknown to consumers, and which, when they come to light, strike consumers as surprising and inappropriate.  One way to guard against this kind of outcry is to take steps to better explain the ways that personal data is collected and used.  On the other hand, a sure way to provoke outcry and invite regulatory attention is to take a public position on privacy and then unilaterally fail to abide by it.

Regulators generally recognize that the collection and use of personal information is essential to the growth of the internet economy.  With their focus on encouraging self-regulation, the White House and the Commission hope to strike a balance that allows for continued innovation, while giving consumers greater comfort and more control regarding the ways their information is collected and used.  By cooperating with the Commission in developing sector-specific codes of conduct, retailers and other companies who collect and use personal data in the course of business have an opportunity to shape the rules pertaining to acceptable data practices.  The Commission does view these proposed self-regulatory codes of conduct as enforceable, however, and it will investigate companies found to be violating their own commitments.  Companies should thus be cautious in developing their privacy policies, and should only make commitments they are confident they can honor.

Co-authored by Nat Bessey