Showing posts with label Shine the Light. Show all posts
Showing posts with label Shine the Light. Show all posts

Friday, October 25, 2013

California Ups the Ante On Privacy Policy Disclosures

For the past decade, California law has set the template for commercial website privacy policies.  With the passage of a new law, set to take effect January 1, 2014, the state has updated the disclosures required of any commercial website operator who collects personally identifiable information from California residents.

California’s Online Privacy Protection Act.   In 2003, California became the only state to require all websites that collect personal information (“PII”) from visitors – in this case, California residents – to post a privacy policy.   Until then, there was no generally applicable privacy policy requirement under either state or federal law, and, to this day, neither the other states nor the federal government have imposed such a requirement.  Federal privacy policy requirements have been limited to specific kinds of information (such as under Children’s Privacy Protection Act) or industries (under the Health Insurance Portability and Accountability Act).  Under the 2003 law, Internet sites need to identify the “categories” of personally identifiable information collected about “individual consumers”; describe the “categories” of third parties with whom the information may be shared; disclose (if there is one) any process for individuals to review or request changes to their personal information; explain how notice is given to consumers of changes in the privacy policy; and post the policy’s effective date. The definition of PII is more expansive than encountered in data breach statutes, and includes email addresses, partial addresses (including street names and towns), and first and last names.  The privacy policy also must be “conspicuously” posted, as defined by the statute.

Now, however, the law has been significantly expanded.

The New Requirements. Under recently enacted Assembly Bill 370, the privacy policy requirements of California’s Online Privacy Protection Act have been expanded to include (1) disclosure of how the web site “responds to Web browser ‘do not track’ signals or other mechanisms that provide consumers the ability to exercise choice regarding the collection of personally identifiable information about an individual consumer’s online activities over time and across third-party Web sites or online services, if the operator engages in that collection”; and (2) disclosure of “whether other parties may collect personally identifiable information about an individual consumer’s online activities over time and across different Web sites when a consumer uses the operator’s Web site or service.” The statute was approved by the Governor and chaptered by the Secretary of State on September 27, 2013. It will take effect on January 1, 2014. Fortunately for Internet sellers, the law provides that “[a]n operator shall be in violation of this subdivision only if the operator fails to post its policy within 30 days after being notified of noncompliance.” As a result, potential liability will only attach after a notice of noncompliance. Nonetheless, it is prudent to review and amend privacy policies to conform with the new law to avoid having to implement last minute changes should your company receive notice of non-compliance (which is not defined, and presumably could include a telephone call or email from a consumer).

The Light Still Shines.   Companies should also remain mindful of California’s so-called “Shine the Light” Law, which can be found at California Civil Code § 1798.83, and as to which we’ve previously blogged. Violations of this law, which, among other things, requires privacy policy disclosures, have led to class actions being filed against Internet sellers.  Customers can be awarded up to $3,000 per each violation, plus attorneys’ fees and costs.  Some of these cases have been dismissed, but the costs of defending even an unsuccessful class action lawsuit can be substantial.

The Shape Of Things To Come.  California isn’t stopping there. Beginning on January 1, 2015, all web sites that direct services to minors, or have actual knowledge that minors are using their sites, must provide a “delete” button to permit minors to remove all of their online content (together with clear instructions for doing so). The law will also prohibit Internet marketing of a wide variety of products and services to minors, including aerosol paint (apparently to inhibit graffiti), etching creams, BB guns, and tanning services. Unlike the COPPA, which is directed to persons under the age of 13, the California law applies to all persons under the age of 18.

Tuesday, April 16, 2013

California "Right to Know" Act Would Require Companies to Disclose Personal Information to Consumers

A California legislator recently re-introduced a bill that, if passed, would further solidify California’s place at the forefront of privacy regulation among U.S. States. AB 1291, the “Right to Know Act of 2013,” would require businesses to provide to consumers, upon request, a copy of all personal information the company has collected and retained about that consumer, as well as information about any parties with whom that information is shared.

Under California’s existing “Shine the Light” law, California consumers already have a right to request, no more than once a year, a list of third parties with whom a company has shared personal information for direct marketing purposes, and a description of the information shared. Companies may currently comply with the law by allowing consumers to opt-out of having their information shared with third parties for direct-marketing purposes.

The proposed law would broaden a consumer’s right of access considerably, giving consumers a right to obtain a copy of any personal information a company retains about that customer, regardless of whether the information is shared with third party marketers. Significantly, this includes both information a company may collect from a customer in connection with a transaction (e.g. name, email address, mailing address, order history), as well as any information purchased from third-party data brokers and incorporated into the consumer profile maintained by the company (e.g. demographic information provided by data brokers).

It is too early to predict whether the bill will be passed by the California legislature, but it is sure to be controversial. Some privacy advocates have applauded the bill, arguing that consumers need greater transparency regarding data collection practices, and noting that Europeans already enjoy similar rights of access. (An Austrian law student made headlines several years ago when he requested his information from Facebook and received more than 1,200 pages of data). Industry groups, on the other hand, are justifiably concerned about the potential cost of complying with the bill’s mandate, and about potentially increased exposure to lawsuits. As currently written, the bill would allow private consumer lawsuits, which could make litigation attractive to class-action lawyers.

We will continue to monitor developments in this area. Whether or not this particular bill becomes law, it is not the first and will not be the last time we see a push for greater transparency around data collection, particularly with respect to the practice of “data enhancement” or using information about consumers provided by data brokers rather than the consumers, themselves. (See related blog posts, here and here).