Showing posts with label online privacy. Show all posts
Showing posts with label online privacy. Show all posts

Friday, July 08, 2011





Confidence in Internet Depends on Privacy Protections: FTC

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Consumers must be confident that their privacy will be protected if they are to take advantage of all the benefits offered by the Internet marketplace, the FTC told the Senate Committee on Commerce, Science and Transportation on June 29.

Commissioner Julie Brill delivered testimony on behalf of the FTC at a hearing examining how entities collect, maintain, secure, and use personal information in today’s economy and whether consumers are adequately protected under current law.

“Privacy has been an important component of the Commission’s consumer protection mission for 40 years,” Brill said. “During this time, the Commission’s goal in the privacy arena has remained constant: to protect consumers’ personal information and ensure that they have the confidence to take advantage of the many benefits offered by the dynamic and ever-changing marketplace.”

FTC Approach

According to the testimony, the FTC has taken a three-pronged approach to preserving consumers’ privacy: law enforcement actions, consumer and business education efforts, and policy initiatives.

In the last 15 years, the FTC has brought more than 300 privacy-related actions, including 34 data security cases; 84 Fair Credit Reporting Act cases; 97 spam cases; 15 spyware cases; and 16 cases enforcing the Children’s Online Privacy Protection Act.

The FTC noted that, while the Commission has not taken positions advocating any particular legislative proposals, it favors data security legislation “that would (1) impose data security standards on companies, and (2) require companies, in appropriate circumstances, to provide notification to consumers when there is a security breach.”

Based on roundtable discussions that involved privacy experts, business representatives, and academics, the FTC staff issued a preliminary report on December 1, 2010, proposing a privacy framework with three main concepts, the testimony stated. First, companies should adopt a “privacy by design” approach by building privacy protections into their everyday business practices, FTC staff recommended.

Second, companies should provide an easy way for consumers to control the collection and use of their personal information—for example, by offering a mechanism to opt out of online behavioral tracking, often referred to as “Do Not Track.” A Do Not Track system should have five key attributes, the FTC said:

(1) It should be universal;

(2) It should be easy to find, understand, and use;

(3) Choices offered should be persistent;

(4) It should be comprehensive, effective, and enforceable; and

(5) It would not only opt consumers out of receiving targeted ads, but it also would opt them out of collection of behavioral data for all purposes other than certain commonly accepted practices.
Third, the staff report called on companies to improve their privacy notices so that consumers, advocacy groups, regulators, and others can compare data practices and choices across companies, thus promoting competition.

The Commission vote to issue the testimony was 5-0, with Commissioner J. Thomas Rosch dissenting in part and issuing a separate statement recommending that the Commission and Congress learn more about Do Not Track before proceeding.

Commissioner Rosch’s Statement

“The root problem with the concept of ‘Do Not Track’ is that we, and with respect, the Congress, do not know enough about most tracking to determine how to achieve the five attributes identified in today’s Commission testimony, or even whether those attributes can be achieved,” Rosch said.

“This is not to say that a Do Not Track mechanism is not feasible. It is to say that we must gather competent and reliable evidence about what kind of tracking is occurring before we embrace any particular mechanism. We must also gather reliable evidence about the practices most consumers are concerned about.”

Tuesday, February 15, 2011





"Do Not Track" Bill Would Restrict Collection, Use of Online Activity Data

This posting was written by Jeffrey May, Editor of CCH Trade Regulation Reporter.

The proposed "Do Not Track Me Online Act of 2011" (H.R. 654) would give consumers the ability to prevent the collection and use of data on their online activities, according to the bill's sponsor, Rep. Jackie Speier (D, Calif.).

The measure would direct the FTC to prescribe, within 18 months after enactment, regulations concerning the collection and use of information obtained by tracking the Internet activity of an individual.

The proposal would not cover entities that store information on fewer than 15,000 individuals; collect information on fewer than 10,000 individuals during any 12-month period; or do not use information to study, monitor, or analyze the behavior of individuals as their primary business.

The do-not-track legislation was introduced on February 11, along with the proposed "Financial Information Privacy Act of 2011” (H.R. 653), which would amend the Gramm-Leach-Bliley Act to strengthen protections for nonpublic personal information provided by consumers to financial institutions.

BEST PRACTICES Act

A day earlier, Rep. Bobby Rush (D, Ill.) introduced the proposed "Building Effective Strategies To Promote Responsibility Accountability Choice Transparency Innovation Consumer Expectations and Safeguards Act" or the "BEST PRACTICES Act" (H.R. 611).

Similar to legislation introduced in the 111th Congress, the measure would require covered entities to provide notice to consumers of information collection practices. The FTC would have enforcement authority, under the proposal.

The bill also provides companies with a Safe Harbor program. In order to qualify, companies would have to set up a "Do-Not-Track" mechanism to allow consumers to opt-out of having the personal information that they provide made available to third parties, according to Rep. Rush.

Thursday, July 08, 2010





User Consent Needed for Online Ad Tracking: EU Working Party

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Online behavioral advertising providers are required to obtain the informed consent of users before installing tracking devices, such as cookies, on their computers, under the terms of the European Union’s online privacy rules, according to the Article 29 Data Protection Working Party.

Use of an “opt out” mechanism would not be sufficient to comply with the requirements of the recently revised ePrivacy Directive, the Working Party said in an opinion released June 24.

Behavioral Advertising

Behavioral advertising is defined as the continuous tracking of individuals across multiple websites. Commonly, tracking cookies are used to collect information about individual surfing behavior and to send users targeted advertisements. In most cases, according to the Working Party, individuals are unaware that this is happening.

Although online behavioral advertising may bring advantages to online businesses and users, the Working Party said, its implications for personal data protection and privacy are significant. Monitoring Internet surfing can give third parties a very detailed picture of a person’s online life. Thus, online advertising networks and browser vendors must employ simple and effective mechanisms for users to affirmatively give their consent for online behavioral advertising.

Equally simple and effective mechanisms should be established for users to withdraw consent, the Working Party added.

Consent

Currently, three of the four most widely used browsers are set by default to accept all cookies, the Working Party noted. Not changing a default setting cannot be considered meaningful consent, in most cases. Advertising networks and publishers should provide information about the purposes of tracking in a clear and understandable manner to enable users to make informed choices about whether they want their browsing behavior to be monitored.

Advertising network providers should work with browser manufacturers and developers to implement privacy by design in browsers, the Working Party recommended.

Ad network providers should enable individuals to exercise their rights to access their personal data stored by the networks and to make corrections and request erasure of such information. Ad networks also should implement retention policies that ensure information is automatically deleted after a reasonable period of time. These policies should apply to alternative tracking technologies, such as “Java cookies.”

Application to Children

In addition, in the Working Party’s view, online advertising networks should not serve behavioral advertising to children at all, because of inherent difficulties in obtaining informed consent and because of the vulnerability of children.

The Working Party is an independent advisory body on data protection and privacy, set up under Article 29 of the EU Data Protection Directive. It is composed of representatives from the national data protection authorities of the EU Member States, the European Data Protection Supervisor, and the European Commission.

Text of the Working Party’s Opinion 2/2010 on online behavioural advertising appears at CCH Privacy Law in Marketing ¶60,494.

Thursday, March 25, 2010





FTC Seeks Comments on Revising COPPA Rule

This posting was written by Cheryl Beise, Editor of CCH Guide to Computer Law.

The FTC announced on March 24 that it is seeking public comments on the costs and benefits of the agency’s Children’s Online Privacy Protection Act (COPPA) Rule.

The COPPA Rule has not changed since its adoption ten years ago. Changes to the online environment over the past five years, including children’s increasing use of mobile technology to access the Internet, warrant reexamining the Rule, the agency said.

COPPA imposes requirements on operators of websites or online services that are aimed at children under 13 years of age, or that knowingly collect personal information from children under 13.

The COPPA Rule requires that online operators notify parents and get their permission before collecting, using, or disclosing children’s personal information. It also imposes security requirements and restrictions on use of information collected about children.

Issues the FTC would like to see addressed are:

• What implications for COPPA enforcement are raised by mobile communications, interactive television, interactive gaming, or other similar interactive media?

• How are automated systems—those that filter out any personally identifiable information prior to posting—being used to review children’s Internet submissions?

• Do operators have the ability to contact specific individuals using information collected from children online, such as persistent IP addresses, mobile geolocation data, or information collected in connection with behavioral advertising? Should the Rule’s definition of “personal information" be expanded accordingly?

• Are there additional technological methods for obtaining verifiable parental consent that should be added to the COPPA Rule? Should any of the current methods be removed?

• Are parents exercising their right under the Rule to review or delete personal information collected from their children? What challenges do operators face in authenticating parents?

• Does the Rule’s process for the FTC’s approval of self-regulatory guidelines (safe harbor programs) enhance compliance? Should the criteria for FTC approval and oversight of the guidelines be modified?

The 90-day comment period will end on June 30, 2010.

The Request for Public Comment on the Federal Trade Commission’s Implementation of the Children’s Online Privacy Protection Rule is posted here on the FTC’s website. The FTC’s March 24 Press Release is available here.

Wednesday, January 06, 2010





Website Commenter Did Not Waive First Amendment Right to Anonymity

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

An anonymous poster of a comment on a newspaper website did not waive his or her First Amendment right to remain anonymous by registering for an account with the website, the federal district court in Kansas City has ruled.

A plaintiff bringing a lawsuit against a Springfield, Missouri police officer, who allegedly injured him, was not entitled to an order compelling disclosure of the poster’s identity.

The poster—who was not a party to the lawsuit—had written a comment to a story on The Springfield News-Leader website about prosecutors’ decision to drop charges against the officer in connection with the facts underlying the suit. In the comment, the poster suggested that the City of Springfield had knowledge of the officer’s alleged violent tendencies.

The News-Leader required website users to register for an account in order to post comments. When registering for this account, users were not required to provide their first or last names or any other personal information.

Privacy Policy

The website’s privacy policy disclosed what information the News-Leader would gather from its online users and how that information would be used, generally in a commercial manner. The privacy policy stated that, in some cases, the News-Leader may use and share personally-identifiable information.

Nothing on the face of the privacy policy hinted that users might be waiving their constitutional right to anonymous free speech by posting comments or materials on the website, according to the court.

Given the presumption against waiver and the boilerplate language of the privacy policy, it could not be said that the poser was aware that he or she could be waiving the right to speak anonymously, let alone the significance of such waiver.

The decision in Sedersten v. Taylor appears at CCH Privacy Law in Marketing ¶60,414.

Friday, December 11, 2009





FTC Hears Views on Regulation of Online Privacy

This posting appeared in the December 15, 2009 issue of Telecommunications Reports.

One member of the Federal Trade Commission has called for "comprehensive privacy legislation," while the agency's chairman has offered a more measured aspiration for a regulatory approach to online privacy, intended to serve both consumers and companies that track them better than the status quo.

Speaking at the FTC's Dec. 7 privacy roundtable in Washington, FTC Commissioner Pamela Jones Harbour—who noted that her time at the agency is "coming to a close" (her term expired in September)—said that her call for comprehensive legislation was not a disparagement of efforts by Rep. Rick Boucher (D., Va.) for online privacy protections, but that "the privacy debate goes far beyond" online concerns.

"Real change cannot just be aspirational," she observed.

Commissioner Jones Harbour said that for every company taking a good faith approach to a privacy policy, there is another trying to "parse and evade commission guidance." She suggested that the current "turbulent economic times are forcing companies to seek out new sources of income" through the collection and sale of consumer data.

Looking forward, she said, "I know the Commission will continue to be the thought leader on privacy," and pledged to continue to do her part to "push" the FTC on this issue.

“Watershed Moment in Privacy”

Recalling the history of privacy jurisprudence, FTC Chairman Jon Leibowitz said, "We're at another watershed moment in privacy," adding that it is time for the FTC to act. He suggested that among the factors increasing threats to online privacy is the ever-decreasing cost of storing and analyzing data.

Chairman Leibowitz said that, as the agency pursues its privacy proceeding over the next six months, he hopes to "find a way [that is] better for consumers and fairer for companies as well." He noted that "we all know consumers don't read privacy disclosures very well" and suggested that it might be possible "to meet consumer expectations" of privacy in other ways that will work for companies.

He suggested that consideration should be given to how to treat "vulnerable categories of consumers such as children."

The text of the Chairman Leibowitz’s introductory remarks appears here on the FTC website.

Views of Business, Consumer Groups

Richard Smith, a consultant with Boston Software Forensics who made two presentations during the roundtable, echoed Chairman Leibowitz's point about the low cost of data storage, saying, "It actually costs more to delete the information off of drives" than to store it.

Susan Grant, director-consumer protection at the Consumer Federation of America, warned that "if people were to realize that their rights are being violated," their trust and willingness to use online tools such as search engines would be eroded.

Michael Hintze, associate general counsel at Microsoft Corp., called for "a multifaceted approach [to privacy] from the beginning," adding that "anonymization [of data] is important but not a silver bullet." Asked to defend the benefits of wireless location-based services, Mr. Hintze acknowledged that it is "cool." However, he added, "it is one thing to know where your customer is right now; it's another to keep a record of every place they've been for last three years."

David Hoffman, director-security policy and global privacy officer at Intel Corp., said privacy assurances should include limitations on the use and collection of data, as well as limitations on how long the data can be retained. He also advised looking carefully "at any regulations that require companies to maintain data longer than they otherwise would for business purposes," such as for homeland security purposes, because simply retaining the data longer increases the potential for data breaches.

Alessandro Acquisti, an economics professor at Carnegie Mellon University, observed, "There are problems that education and transparency can't address," in part because "privacy costs are often long-term" and it has "been proven over and over that we are very bad at making decisions when benefits are short-term but risk is long-term."

Jules Polenetsky, co-chairman and director of the Future of Privacy Forum, said, "We need a little bit of experimentation and leeway to create a [privacy preferences] feature that will succeed in the marketplace" and that "you need a little bit of room for people to delight users" with new ways of using information.

Peder McGee, a senior attorney in the FTC's Division of Privacy and Identity Protection who co-moderated one of the panels, said that some panelists' proposals for allowing consumers to decide whether to seek out information about a company's privacy policy and use of data "seem[] to put a lot of burden on consumer to find out about things that aren't very transparent."

Telecommunications Reports is published by Telecommunications Reports International, a Division of Aspen Publishers, a Wolters Kluwer Company. Further information about Telecommunications Reports is available here at www.tr.com.