Showing posts with label Class Actions. Show all posts
Showing posts with label Class Actions. Show all posts

Friday, October 25, 2013

California Ups the Ante On Privacy Policy Disclosures

For the past decade, California law has set the template for commercial website privacy policies.  With the passage of a new law, set to take effect January 1, 2014, the state has updated the disclosures required of any commercial website operator who collects personally identifiable information from California residents.

California’s Online Privacy Protection Act.   In 2003, California became the only state to require all websites that collect personal information (“PII”) from visitors – in this case, California residents – to post a privacy policy.   Until then, there was no generally applicable privacy policy requirement under either state or federal law, and, to this day, neither the other states nor the federal government have imposed such a requirement.  Federal privacy policy requirements have been limited to specific kinds of information (such as under Children’s Privacy Protection Act) or industries (under the Health Insurance Portability and Accountability Act).  Under the 2003 law, Internet sites need to identify the “categories” of personally identifiable information collected about “individual consumers”; describe the “categories” of third parties with whom the information may be shared; disclose (if there is one) any process for individuals to review or request changes to their personal information; explain how notice is given to consumers of changes in the privacy policy; and post the policy’s effective date. The definition of PII is more expansive than encountered in data breach statutes, and includes email addresses, partial addresses (including street names and towns), and first and last names.  The privacy policy also must be “conspicuously” posted, as defined by the statute.

Now, however, the law has been significantly expanded.

The New Requirements. Under recently enacted Assembly Bill 370, the privacy policy requirements of California’s Online Privacy Protection Act have been expanded to include (1) disclosure of how the web site “responds to Web browser ‘do not track’ signals or other mechanisms that provide consumers the ability to exercise choice regarding the collection of personally identifiable information about an individual consumer’s online activities over time and across third-party Web sites or online services, if the operator engages in that collection”; and (2) disclosure of “whether other parties may collect personally identifiable information about an individual consumer’s online activities over time and across different Web sites when a consumer uses the operator’s Web site or service.” The statute was approved by the Governor and chaptered by the Secretary of State on September 27, 2013. It will take effect on January 1, 2014. Fortunately for Internet sellers, the law provides that “[a]n operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.” As a result, potential liability will only attach after a notice of noncompliance. Nonetheless, it is prudent to review and amend privacy policies to conform with the new law to avoid having to implement last minute changes should your company receive notice of non-compliance (which is not defined, and presumably could include a telephone call or email from a consumer).

The Light Still Shines.   Companies should also remain mindful of California’s so-called “Shine the Light” Law, which can be found at California Civil Code § 1798.83, and as to which we’ve previously blogged. Violations of this law, which, among other things, requires privacy policy disclosures, have led to class actions being filed against Internet sellers.  Customers can be awarded up to $3,000 per each violation, plus attorneys’ fees and costs.  Some of these cases have been dismissed, but the costs of defending even an unsuccessful class action lawsuit can be substantial.

The Shape Of Things To Come.  California isn’t stopping there. Beginning on January 1, 2015, all web sites that direct services to minors, or have actual knowledge that minors are using their sites, must provide a “delete” button to permit minors to remove all of their online content (together with clear instructions for doing so). The law will also prohibit Internet marketing of a wide variety of products and services to minors, including aerosol paint (apparently to inhibit graffiti), etching creams, BB guns, and tanning services. Unlike the COPPA, which is directed to persons under the age of 13, the California law applies to all persons under the age of 18.

Wednesday, May 29, 2013

Meditations On the Consumer Class Action: Statutory Penalties

To know the consumer class action is to fear it. Any online marketer or other retailer that has gone through a class action lawsuit – even if it prevails in the end – no doubt has scars and legal bills to show for it. Because the stakes are so high, even winning a class action case at trial may leave retailers limping and still in great peril. Numerous class actions have settled after the appeal from a defendant’s successful summary judgment motion because, even if the odds of winning on appeal were good, the downside risk of losing was large enough to make the gamble unthinkable.  And the range of potential consumer class action lawsuits often seems overwhelmingly diverse. Is your “sale price” really a “sale price”? Is there enough fruit in your fruit roll-ups? Did you collect customer zip codes in credit card transactions?

While it is impossible for online and direct marketers to insulate themselves fully from an increasingly litigious world, there are rational steps you can take to help prevent your company from becoming "low hanging fruit" for class action lawyers. This is the first in a series of articles on just that subject, and it focuses on state consumer protection, marketing, and privacy laws that have per violation penalties.  The recent Michaels Stores case in Massachusetts involved just such a law.

Honey for Class Action Lawyers.  Among the main weapons for class action plaintiffs’ lawyers are statutes that impose monetary penalties on a per violation basis. A real vulnerability to maintenance of a class action is that, absent a penalty, a determination of damages may require an individual analysis of each plaintiff’s claim – which, as a general matter, is anathema to maintenance of a class action. A statutorily prescribed penalty makes the assessment of damages straightforward once a violation is shown. And so, if you are accused of illegally collecting zip codes on credit card transactions, you take the number of times zip codes were collected and multiply it by the per violation penalty.

Astronomical Numbers.  As an example, if you collected 1,000,000 zip codes from customers over a six year-period (which is often the length of the statute of limitations) you simply multiply 1,000,000 by the maximum potential per violation penalty to determine your worst-case risk. In California, the penalty can be as high as $1,000 per violation, and so the potential exposure is $1,000,000,000. That’s right. One billion dollars. And if you want to gauge accurately your maximum potential liability, add to the $1 billion a third of that number again for plaintiffs’ attorneys fees. And, resign yourself to the fact that absent extraordinary circumstances which almost never occur, there is no hope for a defendant, even an outrageously successful one, to recover its own attorneys’ fees.

Of course, the “maximum” potential exposure may not be realistic. Penalties are often imposed on a sliding scale – for example, in California, they can range from $250 to $1,000 in certain cases. Many, if not most, of these cases also settle, so we do not have compelling public data on how much money actually changes hands. And most settlements are engineered around providing coupons and checks to class members that may or may not be redeemed by the ultimate consumer, ensuring that the only payout certainty will be for the plaintiffs’ attorneys' fees.  Those fees, more likely than not, will be far higher than what you pay hourly-rate outside counsel to defend you.

Focused Compliance.  And, so, an essential element of a strategy to reduce your risk of becoming a class action defendant is to focus like a laser beam on complying with consumer protection/privacy laws with per violation penalty provisions.

How does this help?  While some states, like California, impose penalties in almost every consumer class action case, elsewhere, and at the federal level, the number of laws to be familiar with is more limited and manageable.  One area to be wary about, for example, is telemarketing, with federal laws imposing penalties that can easily exceed $1,000 per violation.  In this area, retailers should retain legal counsel to provide them with clear operating principles under which to engage in telemarketing.  These principles should address both state and federal telemarketing laws, and they should be adopted in internal policies and employee training.  The direct marketer should also make sure that risk is assigned to vendors that provide telemarketing services, with insurance policies to back them up. After all, indemnification from a vendor that goes belly up is obviously worthless. Since vendors often find themselves in hot water for a number of clients simultaneously, even a financially well-heeled vendor could be brought to its knees.

Careful focus and preparation to avoid violation of penalty-laden laws is a good first step in a process of prudently managing consumer class action risk.   But, there are other steps to take, as well, which will be addressed in future posts.

Thursday, April 25, 2013

Beyond California and Massachusetts: Will Collecting Zip Codes Invite Class Actions Across the United States?

Although California and Massachusetts have stolen the spotlight with high profile cases banning zip code collection in connection with credit card purchases, thirteen other states and the District of Columbia have similar laws. With voracious class action attorneys circling, it is critical for retailers to know their legal obligations in these jurisdictions and, if necessary, adjust their privacy practices and policies.

Yet, because these statutes are to varying degrees vague, untested, and archaic, compliance can be difficult. At the same time, the risks could scarcely be higher. Hundreds of companies have already been ensnared in consumer class action lawsuits in California and Massachusetts, and the litigation floodgates may now open in other states as well.  And the math is simple. With penalties as high as $1,000 every single time a zip code, address, or telephone number is collected illegally--for periods going back as far as six years--even a relatively small company could face a liability in the millions or tens of millions of dollars.  You're also likely to be required to pay the plaintiffs' legal fees if you lose, which are often as much as one-third of the penalty calculation.

The State Law Landscape.  A general baseline for state statutes governing the collection of personal information during credit card transactions is a prohibition against retailers requiring customers to provide certain information in connection with a credit card transaction.  California and a few other states, including Wisconsin, go further, barring even the requesting of such information.  Other states, like Massachusetts, prohibit the "writing" of such information, usually on "a credit card transaction form" -- although, as the industry learned in Massachusetts, writing doesn't necessarily mean writing (it can mean inputting information electronically) and a "transaction form" might be interpreted to include a marketing database (the Massachusetts court dodged this issue for now).

Not Just Zip Codes.  Seven states appear to limit their prohibitions to customers' addresses and telephone numbers, and not the sweeping concept of "personal identification information" included in the California and Massachusetts statutes.  (In California, for example, "personal identification information" is defined as information not appearing on the face of a credit card, and so it could include not only zip codes, but also a state of residence, a birthday, an email address, or a person's gender.)

But, even in the states that expressly limit their bans to addresses and telephone numbers, the decisions in Massachusetts and California reveal a path by which these statutes might be interpreted to reach the collection of zip codes only.  For example, the Supreme Court of Massachusetts felt free to deem zip codes to be "personal identification information" because "a consumer's zip code, when combined with the consumer's name, provides the merchant with enough information to identify through publicly available databases the consumer's address or telephone number, the very information § 105 (a) expressly identifies as personal identification information."  As a result, the court found that not extending the prohibition to zip codes "would render hollow the statute's explicit prohibition on the collection of customer addresses and telephone numbers, and undermine the statutory purpose of consumer protection." In other words, even if you are not collecting addresses and telephone numbers in these states, you could still be at risk.

Exceptions.  Most of these statutes have exceptions that benefit direct marketers. California, for example, allows retailers to collect zip codes and other "personal identification information" if it "is required for a special purpose incidental but related to the individual credit card transaction, including, but not limited to, information relating to shipping, delivery, servicing, or installation of the purchased merchandise, or for special orders."  In other states, like Massachusetts, the exception is more narrowly drawn, and, in some states, there are no exceptions at all.  And even for those laws which allow address information to be collected for shipping, the exception does not extend to address collection in gift transactions where the billing address and the shipping address are different.

Enforcement.   Of course, one of the biggest issues for direct marketers is the risk of being the subject of a government investigation or a class action lawsuit.  The risk of government enforcement (by a state attorney general, for example) is likely low in all states except in the event of a data breach--which underscores the need for companies to have in place information privacy and security policies that reduce the risks of such a breach.  As importantly, states are unlikely to seek astronomical penalties from retailers, something that is the bread and butter of class action cases.

The risk of a federal or state class action lawsuit--on behalf thousands upon thousands of consumers--is much higher.  These privacy statutes are very attractive to class action lawyers because they often have a "per violation" penalty that can drive potential recoveries into the stratosphere. This, in addition to provisions that allow plaintiffs (but not defendants) to recover attorneys' fees, makes them a very attractive basis for filing a barrage of lawsuits in the hopes that some of them will succeed or, even in failing, provoke lucrative settlements.

In the past, privacy-related class actions have often foundered because the plaintiffs could not demonstrate any "injury."  Many state consumer protection laws, including the one in Massachusetts, require such an injury to allow a suit to go forward.  (Some, like California, Wisconsin, and the District of Columbia, do not require a showing of injury.)  But, we learned from the Michaels case in Massachusetts that courts can stretch the concept of "injury" beyond recognition.  The Supreme Court of Massachusetts found that the "invasion of privacy" caused by the receipt of a just one unwanted catalog was sufficient "injury" to maintain a class action lawsuit.  In Michaels, it was alleged that the retailer used the zip code to obtain customers' mailing addresses, and then sent unsolicited catalogs to those addresses.  That was the extent of the "harm."

Tuesday, March 19, 2013

The Perils of Zip Code Collection Reach Massachusetts

On March 11, 2013, the Supreme Court of Massachusetts joined California in prohibiting the collection and retention of customer zip codes by retailers in connection with credit card transactions. In Tyler v. Michaels Stores, Inc., the Court based its decision on Massachusetts General Law ch. 93, § 105(a), which provides that retailers cannot “write, cause to be written, or require that a credit card holder write personal identification information not required by the credit card issuer, on the credit card transaction form.”  Like California, the Massachusetts court interpreted "personal identification information" so broadly as to include mere zip codes.

Background.  In 2011, the Supreme Court of California sent shock waves through the retail industry when it ruled in Pineda v. Williams Sonoma Stores, Inc. that zip codes constituted “personal identification information” under California Civil Code § 1747.08 that could not be collected and retained in connection with credit card transactions except in very limited instances. The prohibition against collection of personal identification information applied even if zip codes were requested, but not required, to complete a purchase. As a result of the decision, retailers selling to California consumers have faced costly class action lawsuits (with claims for as much as $1,000 per violation) even if no actual damages or injury could be shown. And while the Supreme Court of California recently held in Apple, Inc. v. Superior Court, that this prohibition did not apply to online transactions involving digitally downloaded products, the Court was careful to state that it was reserving judgment as to whether it applied to “any other transactions that do not involve in-person, face-to-face interaction between the customer and retailer”—explaining that “we express no view on whether the statute governs mail order or telephone order transactions...”

It should be noted that the California prohibition does not apply where address information (including zip codes) is required for “a special purpose incidental but related to the individual credit card transaction, including, but not limited to, information relating to shipping, delivery, servicing, or installation of the purchased merchandise, or for special orders.” Cal. Civ. § 1747.08(c)(4). Thus, in most instances, direct marketers may be outside the scope of California’s prohibition when the address information is required, for example, for shipping. This exclusion, however, may not apply in gift transactions where a product is shipped to a third-party, or where the customer makes arrangements to pick up a product at an in-state location other than his or her home address.   Like California’s law, the statute in Massachusetts defines “personal identification information” broadly, and includes a narrower exception where the information is “necessary for shipping, delivery or installation of purchased merchandise or services or for a warranty when such information is provided voluntarily by a credit card holder.”

The Massachusetts Case.  In reaching its holding, the Supreme Court of Massachusetts concluded that zip codes were “personal identification information” because, when combined with a consumer’s name, they provide “the merchant with enough information to identify through publicly available databases the consumer’s address or telephone number…” And while the Court found that a consumer had to show injury in order to sue based upon a violation of § 105(a), such an injury was not limited to a “loss of money or property.” The court ruled that “actual receipt by a consumer of unwanted marketing materials” constituted an actionable injury, as did “the merchant’s sale of a customer’s personal identification information to a third party.” While the court was not presented with the question of whether the law applied to online or mail order transactions, its expansive interpretation could well reach direct marketers who fall outside § 105(a)’s limited safe harbor.  One question the Massachusetts court did not address: whether the law prohibits the entry of a zip code (or other personal information) into a company database, as opposed to its entry on an electronic credit card transaction form. That nuance may provide a ray of hope for retailers caught up in the class action frenzy this decision is likely to trigger.

Nationwide Risks.  Retailers face risks in other jurisdictions that have statutes similar to those in California and Massachusetts, including Delaware, the District of Columbia, Maryland, Minnesota, Nevada, New Jersey, New York, Ohio, Oregon, Pennsylvania, Rhode Island, and Wisconsin. It would be wise to carefully review your information collection rules in these and other states as a first line of defense against class action lawsuits and state enforcement actions.  In combination, the California and Massachusetts decisions are so wide-sweeping as to provide tremendous encouragement to class action lawyers eager to test the reach of laws in other states.

Wednesday, February 16, 2011

Arbitration Clauses, Class Actions and State Tax

What a funny combination of terms. You might be asking what state tax has to do with arbitration and class action suits. Two recent court decisions illustrate the connection.

In particular, a “bad day” for a corporate executive is receiving the complaint and summons for a class action lawsuit. While there have been fewer class action lawsuits in connection with state taxes than there have been in other areas of the law, the plaintiff’s bar has looked at state tax as a development opportunity and has commenced suits for inappropriate collection of state taxes. The basis commonly used for such a suit is that the state’s unfair and deceptive trade practices statute is violated by the collection of sales tax if such tax is not due. For example, a company might be collecting tax on food in a state in which food is not taxable. A better example would be collecting tax on Internet access, which is prohibited under a federal statute, the Internet Tax Freedom Act, 47 U.S.C. § 151n (1998) (“ITFA”), as amended, unless a state is grandfathered.

AT&T found out the hard way about class action lawsuits in the state tax area. It was collecting tax on Internet access services. Under the ITFA, it was prohibited from collecting such tax in all but a few states. Thus, as I wrote in my blog post of September 17, 2010, AT&T was slammed with a class action lawsuit, and settled for payment of millions of dollars of attorneys’ fees and other costs.

AT&T also recently discovered that there is a way to preclude such class action suits, at least in Texas. In particular, AT&T provided in its agreements with customers that the exclusive basis for resolving all disputes relating to its service was arbitration. When a class action lawsuit was brought against AT&T by Texas consumers for collecting tax on Internet access charges less than $25.00 (Texas, a grandfathered state, imposes tax only on Internet access charges in excess of $25.00 per month), AT&T filed a motion to dismiss the suit based on the arbitration clause in its agreement. Construing the clause broadly, the U.S. District Court for the Southern District of Texas ruled in the case of Stephen T. Johnson v. AT&T Mobility, LLC (12/21/2010), that the clause should be read to include disputes regarding the collection of sales and use tax. Thus, the court dismissed the class action lawsuit and stated that each customer would be required to bring its own dispute in arbitration. If such decision is sustained on appeal, it will significantly limit AT&T’s exposure.

Whether an arbitration clause will in all instances require potential plaintiffs to present their claims in private arbitration rather than public litigation will depend upon a number of factors, but any company doing business with consumers should consider the use of arbitration clauses as a means to resolve disputes. This, of course, is particularly appropriate in the case of a telecom company, but it can be used for Internet retailers and other direct marketers, as well.

Friday, September 17, 2010

The Conservative Approach of Over-Collection of Sales Tax Is Perilous

Many companies (and their advisors) believe there is no harm in “over-collecting” sales tax and, therefore, erring on the side of collection of tax in gray areas.  But that is a very risky course of action, as AT&T recently found out.

It seems that AT&T was collecting sales and use tax on Internet service it provided to customers.  It did so, despite the federal Internet Tax Freedom Act, 47 U.S.C. § 151 n. (1998), as extended and amended by the Internet Tax Nondiscrimination Act, P.L. 108-435 (2004) and the Internet Tax Freedom Act Amendments Act of 2007, P.L. 110-108 (2007), which prohibits states from imposing taxes on Internet access, with the exception of certain grandfathered states.  Even a company of the size of AT&T apparently got it wrong, since it continued to collect tax on Internet access in all states.  Its customers reacted, and commenced a class action law suit against AT&T.

AT&T recently settled the lawsuit with the class action plaintiffs at significant expense to AT&T.  See In re AT&T Mobility Wireless Data Services Sales Litigation, MDL No. 2147, Case No. 10 C 2278 (N.D. Ill. Aug.11, 2010).  While AT&T is not obligated to refund to the plaintiffs any amounts not refunded to AT&T by a state, it is required to seek such refunds.  If it obtains a refund, AT&T, of course, must distribute the amounts it receives to its customers, but it doesn’t have to dip into its own pocket to do so.

So, you say, what is the harm to AT&T?  As part of the settlement, AT&T is required to pay the cost of notice to each member of the class.  Given the size of the class, this likely will be a substantial cost.  In addition, AT&T must pay a contingency fee to the lawyers for the class action plaintiffs, which is generally based on the value of the settlement, and can be millions of dollars.  Thus, far from being an income neutral proposition for AT&T, AT&T’s decision to collect tax created a large expense to it.

The conclusion to be drawn is that retailers need to be very careful to make sure they get it right.  To simply err on the side of over-collection may prove to create substantial exposure.  Rather, the true amount due must be collected.  If a retailer gets in a bind by over-collecting, the state will not compensate the retailer for its additional expenses.

Tuesday, March 16, 2010

Think You’re Safe Storing or Releasing “Anonymized” Data? Think Again.

Anonymity is increasingly difficult to safeguard, and direct marketers that collect, maintain, share, and use customer information should take note of a recent class action settlement by Netflix than stemmed from the company's disclosure of an "anonymized" customer database.

Most federal and state privacy and data security statutes focus on the protection of "personally identifiable information," such as names, addresses, telephone numbers, financial account numbers, social security numbers, and email addresses. In response to such laws, many companies strip personally identifiable information from databases containing sensitive information. Once stripped of identifiers, the theory goes, the risks of identity theft or violations of consumer privacy rights resulting from disclosure of the data (whether purposeful or not) are eliminated. Some companies may even conclude that the data may be shared for marketing or "data mining" purposes without violating their privacy policies or applicable laws.

According to the Electronic Privacy Information Center, however, "computer scientists have revealed that this 'anonymized' data can easily be re-identified, such that the sensitive information may be linked back to an individual."

Ten years ago, the risk of such "re-identification" was "largely theoretical":

"In a corner of the U.S. Census Bureau, a small group of statisticians has been sweating out the agency's nightmare scenario: 're-identification.' That's the term for a technique that the bureau fears could allow marketers and other "intruders" to match anonymous census information with the names of the people who provided it. Such a concern is largely theoretical, so far. But if perfected, the technique could have great appeal to marketers of everything from french fries to financial services."

-Glenn R. Simpson, "The 2000 Count: Bureau Blurs Data To Keep Names Confidential," The Wall Street Journal, February 14, 2001.

The risk is theoretical no more, and online sellers and direct marketers that fail to pay attention to the issue do so at their own peril.

The Netflix Case. Netflix just announced that it is canceling its Netflix Prize after being sued in federal court on a class action basis for invasion of privacy and violation of the Video Privacy Protection Act ("VPPA") based upon the alleged re-identification of individuals whose movie rating information was made public in a database that had been scrubbed of personal information.

Netflix sponsored a contest to see if entrants could provide "collaborative filtering algorithms" that could better predict viewers' movie ratings than Netflix's existing Cinematch recommendation engine. In connection with the contest, entrants were given an "anonymized" training data set that contained 100 million subscriber movie ratings covering 480,000 subscribers and 18,000 movies. Each of the rating entries included a unique numeric identifier representing the subscriber, but contained no personally identifiable information.
It didn't take long, however, for two researchers at the University of Texas to identify two of the anonymous subscribers in the training data set. They did so by using public reviews available on the Internet Movie Database and re-identification algorithms. The researchers found that one of the people they identified "had strong-ostensibly private-opinions about liberal and gay-themed films and had ratings for some religious films." (The complete study is available here.) The researchers were apparently able to identify individual subscribers despite the "perturbation techniques" employed by Netflix to protect individual identities. (Perturbation adds "noise" to a database to protect individual record confidentiality. The UT researchers had developed a technique that was "robust to perturbation in the data.")

In at least one respect, the Netflix case presented a good opportunity for class action plaintiffs because the federal VPPA specifically makes video rental information private. (As is often the case with privacy laws, the VPPA was passed in reaction to a highly publicized event - in this case, the release of Judge Robert Bork's video rental records during Senate hearings on his nomination to the United States Supreme Court.) But, the Netflix suit went far beyond alleged VPPA violations, and included sweeping counts under California statutes (including for alleged unfair trade practices and false advertising), as well as common law privacy claims. Not only was Netflix sued, the Federal Trade Commission jumped on the bandwagon. Eventually, after "productive discussions" with the FTC, the suit was settled and the Netflix Prize was no more.

Takeaway. The Netflix case raises very serious questions for online sellers and direct marketers with regard to supposedly anonymous aggregated databases that reflect customer information, including purchasing histories and demographic information. In the future, we may well see privacy and security laws evolve to cover databases that are susceptible to re-identification. Each company should actively examine the intersection between its business objectives and the privacy concerns of its customers with regard to the collection, storage, and use of customer data. Clear and accurate privacy policy disclosures are essential to ensure that consumers understand a company's information collection and disclosure practices. The claims against Netflix included assertions that standard privacy policy provisions were materially misleading given the availability of re-identification.