Showing posts with label COPPA. Show all posts
Showing posts with label COPPA. Show all posts

Thursday, August 02, 2012

FTC Seeks Comments on Proposed Changes to Children’s Online Privacy Protection Act Rule

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

The Federal Trade Commission announced on August 1, 2012 that it is publishing a Federal Register Notice seeking public comments on proposed changes to the Children’s Online Privacy Protection (COPPA) Rule (16 CFR Part 312).

Proposed modifications to the definitions of “operator” and “website or online service directed to children” would allocate and clarify the responsibilities under COPPA when third parties—such as advertising networks and providers of downloadable software “plug-ins”—collect personal information from users through child-directed websites or services.

The Commission proposes to state within the definition of “operator” that personal information is “collected or maintained on behalf of” an operator when it is collected in the interest of, as a representative of, or for the benefit of, the operator. This change would make clear that an operator of a child-directed site or service that integrates the services of others that collect personal information should itself be considered a covered “operator” under the Rule.

The Commission also proposes to modify the definition of “website or online service directed to children” to:

(1) Clarify that a plug-in provider or ad network is covered by the Rule when it knows or has reason to know that it is collecting personal information through a child-directed website or online service;

(2) Allow websites with mixed audiences of children and adults to age-screen visitors in order to provide COPPA’s protections only to users under age 13; and

(3) Clarify that child-directed sites or services that knowingly target children under 13 as their primary audience or whose overall content is likely to attract children under age 13 as their primary audience must still treat all users as children.
“Personal Information”

Finally, the Commission proposes to modify the Rule’s definition of “personal information” to make it clear that a persistent identifier will be considered personal information when it can be used to recognize a user over time, or across different sites or services, and when it is used for purposes other than support for internal operations.

Use of such identifiers in the course of such activities as site maintenance, network communications, authentication of users, serving contextual advertisements, and protecting against fraud and theft would not be considered collection of personal information, as long as the information collected is not used to contact a specific individual, including through the use of behaviorally-targeted advertising.

Public comments will be accepted through September 10, 2012. Details are available here on the FTC website.

Further information regarding CCH Privacy Law in Marketing appears here.

Thursday, September 15, 2011





FTC Proposes Amendments to Children’s Online Privacy Protection Rule

This posting was written by John W. Arden.

The Federal Trade Commission has proposed amendments to the Children’s Online Privacy Protection Rule in order to ensure that the rule continues to protect children’s privacy, as online technologies evolve. The agency is seeking public comment on the proposal through November 28, 2011.

According to a September 15 press release, the proposed amendments would give parents control over what personal information websites may collect from children under 13 years of age.

The Children’s Online Privacy Protection Act (COPPA) (CCH Trade Regulation Reporter ¶27,590) requires operators of websites or online services directed to children under 13—or those having actual knowledge that they are collecting personal information from children under 13—to obtain verifiable consent from parents before collecting, using, or disclosing such information.

The FTC rule implementing COPPA—the Children’s Online Privacy Protection Rule (CCH Trade Regulation Reporter ¶38,059)—became effective in 2000.

In April 2010, the Commission sought public comment on the COPPA Rule, posing numerous questions for public consideration, holding a public roundtable, and reviewing 70 comments from industry representatives, advocacy groups, academics, technologists, and members of the public.

Proposed changes to the rule, released today, include:

Definitions. The FTC proposes updating the definition of “personal information” that may not be collected from children under 13 without parental consent to include geolocation information and certain “persistent identifiers” such as tracking cookies used for behavioral advertising. The agency further proposed a change to the definition of “collection” to allow children to participate in interactive communities, without parental consent, as long as the operators take reasonable measures to delete children’s personal information before it is made public.

Parental notice. The Commission seeks to streamline and clarify the direct notice that operators must give parents prior to collecting children’s personal information in a succinct “just-in-time” notice rather than just in a privacy policy.

Parental consent mechanisms. New proposed methods of obtaining verifiable parental consent would include electronic scans of signed parental consent forms, video-conferencing, and use of government-issued identification checked against a database. These new methods would supplement the existing methods of obtaining parental consent, which include signed parental consent forms, parents’ use of a credit card in connection with a transaction, and parents' calls to a toll-free telephone number. The FTC proposes eliminating parental consent through “e-mail plus,” an e-mail to a parent coupled with another step such as sending an e-mail confirmation.

Confidentiality and security. Proposed rules would strengthen confidentiality and security by requiring that operators ensure that any third party to whom they disclose personal information has reasonable procedures to protect that information, retain the information for only as long as reasonably necessary, and properly delete that information.

Safe harbor. The FTC proposes to strengthen its oversight of self regulatory “safe harbor programs” by requiring groups to audit their members at least annually and to report the results of audits to the Commission.

The 122-page notice of proposed rule and request for comments appears here on the FTC website.

Submission of Comments

Interested persons may submit comments online here or may send a hard copy of comments to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex E), 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580.

Write “COPPA Rule Review, 16 CFR Part 312, Project No. P-104503” on the submissions.

Thursday, March 25, 2010





FTC Seeks Comments on Revising COPPA Rule

This posting was written by Cheryl Beise, Editor of CCH Guide to Computer Law.

The FTC announced on March 24 that it is seeking public comments on the costs and benefits of the agency’s Children’s Online Privacy Protection Act (COPPA) Rule.

The COPPA Rule has not changed since its adoption ten years ago. Changes to the online environment over the past five years, including children’s increasing use of mobile technology to access the Internet, warrant reexamining the Rule, the agency said.

COPPA imposes requirements on operators of websites or online services that are aimed at children under 13 years of age, or that knowingly collect personal information from children under 13.

The COPPA Rule requires that online operators notify parents and get their permission before collecting, using, or disclosing children’s personal information. It also imposes security requirements and restrictions on use of information collected about children.

Issues the FTC would like to see addressed are:

• What implications for COPPA enforcement are raised by mobile communications, interactive television, interactive gaming, or other similar interactive media?

• How are automated systems—those that filter out any personally identifiable information prior to posting—being used to review children’s Internet submissions?

• Do operators have the ability to contact specific individuals using information collected from children online, such as persistent IP addresses, mobile geolocation data, or information collected in connection with behavioral advertising? Should the Rule’s definition of “personal information" be expanded accordingly?

• Are there additional technological methods for obtaining verifiable parental consent that should be added to the COPPA Rule? Should any of the current methods be removed?

• Are parents exercising their right under the Rule to review or delete personal information collected from their children? What challenges do operators face in authenticating parents?

• Does the Rule’s process for the FTC’s approval of self-regulatory guidelines (safe harbor programs) enhance compliance? Should the criteria for FTC approval and oversight of the guidelines be modified?

The 90-day comment period will end on June 30, 2010.

The Request for Public Comment on the Federal Trade Commission’s Implementation of the Children’s Online Privacy Protection Rule is posted here on the FTC’s website. The FTC’s March 24 Press Release is available here.