Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Wednesday, June 12, 2013

The Summer of Privacy: With the Government Under Fire, Retailers May Overlook New Rules and Risks


This may one day be known as the Summer of Privacy. From claims that the NSA surreptitiously obtains cellphone (and GPS) information from at least 100,000,000 Americans to the Supreme Court blessing routine collection of DNA evidence from arrestees, it is impossible to avoid almost daily stories on governmental privacy issues. But, don't be fooled by the focus on governmental activity. From advances on the "do not track" front to a vastly expanded federal children's privacy rule going into effect on July 1, 2013, the privacy temperature is rising not just for the government, but for online and multichannel retailers as well.

For someone who has worked in the field of privacy for many years, this summer has involved a much welcome return of focus to the substantial harm that can result from a governmental violations of privacy rights, as opposed to the alleged harms caused by retailers. Unlike the recent privacy case against Michaels Stores in Massachusetts, where the alleged “harm” was the mere receipt of unwanted catalogs, government collection and misuse of private information can lead to dire consequences, ranging from Internal Revenue Service audits to profiling and criminal charges.  Moreover, the privacy issue as it relates to the government is one of constitutional dimensions.  As Justice Brandeis famously (and presciently) said in his dissenting opinion in Olmstead v. U.S., 277 U.S. 438, 478 (1928), the very first wiretapping case heard by the Court, each citizen has “the right to be let alone — the most comprehensive of rights and the right most valued by civilized men. To protect that right, every unjustifiable intrusion by the government upon the privacy of the individual, whatever the means employed, must be deemed a violation of the Fourth Amendment.” Olmstead was ultimately overturned, and Justice Brandeis' famous standard adopted, in Katz v. U.S., 389 U.S. 347 (1967), where the Court found a constitutional “right to be let alone” where a "reasonable expectation of privacy" existed.

Don't Be Fooled.  Even though the media is dominated by stories involving governmental intrusions into our private lives, the government itself remains fixated on pushing “do not track” requirements, with even a Republican FTC Commissioner giving industry what may amount to one last chance to come up with meaningful self-regulation rather than face the “static legislative solution” championed by Democratic FTC Chairwoman Edith Ramirez.  Ramirez recently vowed "to more aggressively regulate Internet companies like Facebook and Google and has called on Congress to pass privacy legislation.” Ironically, the most publicized "do not track" bills of the last few years impacted mostly on smaller online companies, and included gaping loopholes for the likes of Google, Facebook, and Apple.  As a result, every online seller needs to look closely at proposed "do not track" schemes — whether legislative or under voluntary industry standards — and decide whether proactive measures are appropriate, including involvement in industry groups and lobbying.  In all of their various iterations, "do no track" rules could have a considerable negative impact on online and multichannel retailers.

New Children's Privacy Rules.  There are also the new children’s privacy rules that go into effect on July 1, 2013, and which are creating significant compliance issues for many companies. Among other things, the new rule expands the definition of “personal information” to include “persistent identifiers” which can include online user names, cookies, and IP addresses, and the number of web sites that could fall under its requirements may be far larger than under prior law.

Privacy Litigation In Full Bloom.  Finally, litigation over privacy issues continues apace, not only including the now infamous zip code collection class actions, but also actions brought by privacy rights groups against companies like Snapchat.  Snapchat is accused of misleading users by claiming that its messages self-destruct after a fixed period of time.  However, according the Electronic Privacy Information Center, they do not.  This kind of litigation underscores the risks that can result if a company does not accurately describe its privacy-related practices, and reinforces the need to keep a close watch on your business activities to make sure that your privacy policy and other statements to consumers remain accurate.

We will continue to follow developments in privacy as it relates to both merchants and consumers and continue to update our readers in this space.

UPDATE:  The National Journal published a thoughtful and detailed article on June 13, 2013 about what Americans think about privacy, and which institutions they trust most. As the author, Ronald Brownstein explains: "Asked what would do the most to protect people’s personal information on the Internet, just 8 percent picked more government oversight. The biggest group (48 percent) said the key was 'more commitment by companies to not share users’ information with other businesses or government.'"

Wednesday, March 17, 2010

Facebook: Not Just For Friends?

The Obama Administration is considering sending federal officers undercover on Facebook and other popular social networking sites. This effort raises a number of interesting questions, some legal, some not. For example, would the feds work with Facebook, or simply register, and silently patrol the social network looking for leads? If they went with the cooperative approach, just how much help could Facebook provide given its privacy policy and terms of use? Would it unlock the kingdom based upon an informal request, or would it require a subpoena or search warrant to comply? And, if the government decided to slip into the system without alerting Facebook, would it be required to follow Facebook's terms of use -- such as providing real names and contact information? What are the consequences if a person "tricks" someone into being their friend?

A confidential Department of Justice presentation obtained by the Electronic Frontier Foundation sheds some light on these issues, and also provides useful guidance in the crafting of privacy policies and terms of use by eCommerce companies, including those who provide social networks or online communities.

The presentation first shows that Facebook is "[o]ften cooperative with emergency requests." It is probably in the interest of most eCommerce companies to be cooperative in those situations, but it is likewise vital to ensure that your privacy policy makes clear the nature of such cooperation, and that you have some degree of internal controls in place to ensure that the emergency exception does not swallow the privacy rule. Vetting such requests with counsel can be an important protective measure to an appropriate balance of company interests.

In defending itself, Facebook explained: "We scrutinize every single law enforcement request; require a detailed description of why the request is being made; and if it is deemed appropriate, share only the minimum amount of information. We strive to respect the balance between law enforcement's need for information and the privacy rights of our users, and as a responsible company we adhere to the letter of the law." The presentation notes, in contrast, that Twitter only produces data "in response to legal process." Both approaches are sound.

The presentation also discusses the fact that supplying fake credentials (in violation of the terms of service) can result in civil and potentially criminal liability. CNET reports that at least one case has found no criminal liability from a breach of such terms of service, but the law, as CNET notes, remains unsettled. In the Drew case, the defendant allegedly created a deliberately false identity and pretended to be a sixteen-year old for the purpose of communicating with a minor, all "conscious violations" of the MySpace terms of service. In dismissing the criminal charges, the trial court concluded that the Computer Fraud and Abuse Act was unconstitutionally vague in connection with the argument that it criminalized intentional breaches of a website's terms of service. While it is helpful to know that the DOJ is mindful of the potential criminal implications of using false pretenses in connection with a social media account, the presentation also shows a degree of interest in such techniques that might be considered to be very disturbing by some.

Apart from whether fraudulent access to a community web site is a crime, the Drew case underscores the general importance of terms of service, and the additional degree of protection they can provide to users both in terms of criminal infiltration and unwarranted government intrusion. Clear terms that require accurate personal information in connection with all accounts help safeguard users from online predators and fraud, while also helping to ensure that law enforcement goes through appropriate channels (and not secretly) to obtain content from those sites. This is just another reminder to take those terms seriously and to treat them as more than simply boilerplate. As with privacy policies, periodic reviews are wise.