Showing posts with label online social networking services. Show all posts
Showing posts with label online social networking services. Show all posts

Thursday, March 31, 2011





Google Settles FTC Privacy Charges Over Social Networking Service

This posting was written by Cheryl Beise, Editor of CCH Guide to Computer Law.

Google, Inc. has agreed to settle Federal Trade Commission charges that it violated Gmail users’ privacy and acted deceptively when it introduced its social networking service Google Buzz last year. Google Buzz allows Gmail users to share status updates, comments, photos, and videos.

This is the first time the FTC has required a company to implement a comprehensive privacy program, the agency said in a March 30 news release.

Privacy advocates expressed concern about Buzz from the day it was launched. The FTC initiated its investigation in response to a complaint by the Electronic Privacy Information Center (EPIC) one week after Buzz made its debut. Google tweaked Buzz in response to criticism, but its practices failed to alleviate the agency’s concerns.

In its complaint against Google, the FTC delineated several deceptive or misleading practices it considered to be violations of Section 5(a) of the FTC Act.

The FTC alleged that Google’s Gmail Privacy Policy falsely represented that (1) Google would use Gmail users’ messages, contacts, and other account data only for providing Gmail services, and (2) Google would ask for users’ consent before using their personal information for a purpose other than for which is was collected.

In fact, Google used Gmail users’ information to populate Buzz without seeking users’ prior consent, according to the complaint.

The agency also contended that Google acted deceptively when it launched Buzz by (1) failing to disclose to Gmail users that Buzz’s default settings would publicly share certain previously private information, such as frequent email contacts and (2) misrepresenting Gmail users’ ability to opt-out of Buzz services.

User controls for limiting the sharing of personal information were “confusing and difficult to find,” the FTC said.

According to the FTC, Google’s Privacy Policy also falsely represented that Google complied with the US-EU Safe Harbor Framework. Google’s sharing of user information without obtaining consent allegedly violated the U.S. Safe Harbor Privacy Principles of Notice and Choice.

Under the proposed agreement and consent order, Google would be required, among other things, to:

• Comply with its stated information sharing practices;

• Not misrepresent the privacy and confidentiality of “covered information.” Covered information is defined to include first and last name, street address, physical address, location, telephone number, email address or other online contact information, such as user ids or screen names, lists of contacts, and persistent identifiers, such as static IP addresses;

• Establish and maintain a comprehensive privacy program designed to protect the privacy and confidentiality of covered information;

• Assess privacy risks associated with existing and when developing new products and services;

• Establish privacy controls and procedures; and

• Permit an independent privacy audit every other year for 20 years.


In a March 30 blog post (“An Update on Buzz”), Google apologized “for the mistakes we made with Buzz.”

Acknowledging that the launch of Google Buzz “fell short of our usual standards for transparency and user control—letting our users and Google down,” Google reassured users that “we are 100 percent focused on ensuring that our new privacy procedures effectively protect the interests of all our users going forward.”

Further information about In the matter of Google, Inc. File No. 102 3136, is available here on the FTC’s website.

A description of the agreement and consent order will be published soon in the Federal Register. Interested parties may submit written comments electronically or in paper form through May 2, 2011. Comments in electronic form should be submitted here.

Thursday, January 28, 2010





Direct Marketing Association Releases New Guidelines for Endorsements, Testimonials

This posting was written by William Zale, Editor of CCH Advertising Law Guide.

The Direct Marketing Association (DMA) announced on January 25 that its Board of Directors has approved recommended changes to DMA’s Guidelines for Ethical Business Practice for testimonials and endorsements in all channels.

DMA developed and recommended these amendments to keep the guidelines consistent with the Federal Trade Commission’s Guides for Testimonials and Endorsements, as revised in October 2009. (For further information on the FTC guides, see Trade Regulation Talk, October 5, 2009.)

Typical Results/Performance

Under DMA’s new Guidelines, marketers must clearly and conspicuously disclose the generally expected or typical results/performance of the advertised products or services, if the claims made are not typical of what a user could expect under normal circumstances.

This requirement contrasts with the previous version of DMA’s Guidelines and the 1980 version of the FTC Guides, both of which allowed marketers to describe unusual results in a testimonial as long as they included a disclaimer such as “results not typical.” DMA’s revised Guidelines and the FTC Guides no longer allow for this safe harbor.

Endorser Disclosures

DMA’s revised Guidelines also reinforce the need for marketers to disclose any material connections between marketers and their endorsers that the consumer would not expect.

A material connection refers to a connection between the endorser and marketer that materially affects the weight or credibility of the endorsement, such as payments or free products or an employer/employee relationship. This includes endorsements that are conveyed by bloggers or other “word-of-mouth” marketers.

Celebrity Endorsements

DMA’s Guidelines also address celebrity endorsements. Marketers should ensure that their celebrity endorsers disclose their relationships with marketers when making endorsements outside the context of traditional advertisements, such as on talk shows or in social media, and they should not knowingly make statements that are false or unsubstantiated.

Blogs, Social Networking, Word-of-Mouth Marketing

The Guidelines apply to both traditional and new interactive media, including but not limited to social networking sites, online message boards, blogging, and “word-of-mouth” marketing. The Guidelines are enforced by the DMA’s Committee on Ethical Business Practices through its casework process.

Further details on the revised DMA guidelines will appear in Do’s and Don’ts in Advertising and CCH Advertising Law Guide.

Wednesday, July 15, 2009





EU Privacy Law Applies to Social Networks Headquartered Outside of Europe

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

European data protection law applies to online social networking services (SNS), such as Facebook and MySpace, even if their headquarters are located outside Europe, according to the Article 29 Data Protection Working Party.

In an opinion adopted on June 12, 2009, the Working Party stated that SNS operators and, in many cases, third-party application providers are "data controllers," for purposes of European law.

As data controllers, SNS operators should disclose the ways they intend to process users' personal data, as well as the risks inherent from uploading data onto the SNS. Marketing activities by SNS operators must comply with the EU's Data Protection and ePrivacy Directives, the Working Party said.

Adoption of Security and Privacy Practices

The Working Party urged SNS operators to adopt robust security practices and privacy-friendly default settings, with particular care taken regarding the processing of the personal data of children and minors. A tool for lodging complaints regarding privacy and protection of personal data should be made available to members and non-members on the services' homepages.

The Working Party is an independent advisory body on data protection and privacy, composed of representatives from the national data protection authorities of the EU Member States, the European Data Protection Supervisor, and the European Commission.

Text of the Working Party's opinion on online social networking appears at CCH Privacy Law in Marketing ¶60,346.