Showing posts with label safe harbor. Show all posts
Showing posts with label safe harbor. Show all posts

Wednesday, April 13, 2011





Senators Introduce Proposed “Commercial Privacy Bill of Rights Act”

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

A new comprehensive regulatory framework to protect consumers’ personal information would be established by a Senate Bill unveiled by Senators John Kerry (D-Mass.) and John McCain (R-Ariz.) on April 12. If enacted, the proposed “Commercial Privacy Bill of Rights Act of 2011” (S. 799) would regulate the collection, use, and dissemination of covered information.

“John and I start with a bedrock belief that protecting Americans’ personal, private information is vital to making the Information Age everything it should be,” said Senator Kerry. “Americans have a right to decide how their information is collected, used, and distributed and businesses deserve the certainty that comes with clear guidelines.”

Senator McCain said, “Consumers want to shop, browse and share information in an environment that is respectful of their personal information. Our legislation sets forth a framework for companies to create such an environment and allows businesses to continue to market and advertise to all consumers, including potential customers.”

Covered Information

The measure would cover personally identifiable information (PII)—including name, postal address, e-mail address, phone number, Social Security, credit card number, and biometric data—as well as any information that is used, collected, or stored in connection with PII in a manner that may reasonably be used to identify a specific individual—such as a birth date or an IP address.

Coverage would exclude PII obtained from public records; PII obtained from a forum where the individual voluntarily shared the information, that is widely and publicly available, and that contains no restrictions on who can access and view such information; PII reported in public media; and PII dedicated to contacting an individual at the individual’s place of work

Covered Entities

The law would apply to any person who collects, uses, or transfers covered information concerning more than 5,000 individuals during a 12-month period, and over whom the Federal Trade Commission has authority pursuant to Sec. 5(a) (2) of the FTC Act. The law also would apply to common carriers under the Communications Act of 1934 and to nonprofit organizations.

Right to Security and Accountability

The bill would call on the FTC to create rules requiring covered entities to carry out security measures to protect covered information.

Taking a “privacy by design” approach to data protection, the bill would require covered entities to implement a comprehensive information privacy program by incorporating development processes and practices throughout the product life cycle that are designed to safeguard PII based on the subject individuals’ reasonable expectations and any relevant threats.

Covered entities also would be required to maintain appropriate management processes and practices throughout the data life cycle.

Right to Notice and Individual Participation

Collectors of information would be required to provide clear notice to individuals on their collection practices and the purpose for such collection. Additionally, individuals would have to have the ability to opt out of any information collection that would otherwise be unauthorized by the law, as well as the ability to opt out of having their information used by third parties for behavioral marketing or advertising.

Affirmative consent (opt-in) would be required for the collection of sensitive personally identifiable information, including information related to a medical condition or religious affiliation.

Individuals would be given the right to access and correct their information, or to request cessation of its use and distribution.

Data Minimization, Constraints on Distribution, Data Integrity

Collectors of information would be permitted to collect only as much information as necessary to process or enforce a transaction, to deliver a service, to prevent or detect fraud, to investigate a possible crime, to engage in advertising or marketing, for research and development, or for certain internal operations.

Information could be retained only as long as it takes to provide or deliver goods or services to the subject individual or as long as the information is necessary for research and development purposes.

Collectors would have to contractually bind third parties to which they transfer information, to ensure that the third parties comply with the law’s requirements. The bill would require the collector to attempt to establish and maintain reasonable procedures to ensure that PII collected and maintained is accurate, if that PII could be used to deny consumers benefits or could cause significant harm.

Enforcement

A knowing or repetitive violation of the law would be treated as an unfair or deceptive act or practice in violation of the FTC Act. The FTC would be charged with enforcing the measure. State attorneys general also would have enforcement powers, unless the FTC takes action first. Violations would be subject to civil penalties.

The bill provides that it may not be construed to provide any private right of action.

The measure would supersede state laws relating to the collection, use, or disclosure of covered information. It would not preempt state laws (1) addressing health or financial information, (2) addressing notification requirements in the event of a data breach, or (3) relating to acts of fraud.

Safe Harbor

The bill would direct the FTC to create requirements for the establishment and administration of voluntary safe harbor programs to be overseen by nongovernmental organizations. Safe harbor programs would have to achieve protections at least as rigorous as those enumerated in the bill.

As incentive for enrolling in a safe harbor program, participants would be permitted to design or customize procedures for compliance and would be exempt from some requirements of the bill.

Further Information

Further information, including the text of the bill, is available here on Senator Kerry’s website.

Tuesday, February 15, 2011





"Do Not Track" Bill Would Restrict Collection, Use of Online Activity Data

This posting was written by Jeffrey May, Editor of CCH Trade Regulation Reporter.

The proposed "Do Not Track Me Online Act of 2011" (H.R. 654) would give consumers the ability to prevent the collection and use of data on their online activities, according to the bill's sponsor, Rep. Jackie Speier (D, Calif.).

The measure would direct the FTC to prescribe, within 18 months after enactment, regulations concerning the collection and use of information obtained by tracking the Internet activity of an individual.

The proposal would not cover entities that store information on fewer than 15,000 individuals; collect information on fewer than 10,000 individuals during any 12-month period; or do not use information to study, monitor, or analyze the behavior of individuals as their primary business.

The do-not-track legislation was introduced on February 11, along with the proposed "Financial Information Privacy Act of 2011” (H.R. 653), which would amend the Gramm-Leach-Bliley Act to strengthen protections for nonpublic personal information provided by consumers to financial institutions.

BEST PRACTICES Act

A day earlier, Rep. Bobby Rush (D, Ill.) introduced the proposed "Building Effective Strategies To Promote Responsibility Accountability Choice Transparency Innovation Consumer Expectations and Safeguards Act" or the "BEST PRACTICES Act" (H.R. 611).

Similar to legislation introduced in the 111th Congress, the measure would require covered entities to provide notice to consumers of information collection practices. The FTC would have enforcement authority, under the proposal.

The bill also provides companies with a Safe Harbor program. In order to qualify, companies would have to set up a "Do-Not-Track" mechanism to allow consumers to opt-out of having the personal information that they provide made available to third parties, according to Rep. Rush.

Wednesday, December 01, 2010





FTC Privacy Report Proposes “Do Not Track” Mechanism for Web Users

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

The Federal Trade Commission has proposed, as part of a framework to balance the privacy interests of consumers with innovation that relies on consumer information, the implementation of a “Do Not Track” mechanism for Internet users.

Described in a preliminary staff report, the mechanism would likely be a persistent setting on consumers’ web browsers, the FTC said, and would enable consumers to choose whether to allow the collection of data regarding their online searching and browsing activities.

“Technological and business ingenuity have spawned a whole new online culture and vocabulary—email, IMs, apps and blogs—that consumers have come to expect and enjoy,” said FTC Chairman Jon Leibowitz. “The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation, and consumer choice.”

Failure of Self Regulation

The report—titled “Protecting Consumer Privacy in an Era of Rapid Change”—states that industry efforts to address privacy through self-regulation “have been too slow, and up to now have failed to provide adequate and meaningful protection.” The framework outlined in the report is designed to reduce the burdens on consumers and businesses.

The proposed framework also is intended to inform policymakers, including Congress, as they develop solutions, policies, and potential laws governing privacy, and to guide and motivate industry as it develops more robust and effective best practices and self-regulatory guidelines.

Leibowitz added that the FTC, in addition to making policy recommendations, “will take action against companies that cross the line with consumer data and violate consumers’ privacy—especially when children and teens are involved.”

“Privacy by Design”

To reduce the burden on consumers and to ensure basic privacy protections, the report recommends that companies adopt a “privacy by design” approach by building privacy protections into their everyday business practices. Such protections would include security measures for consumer data, limited collection and retention of such data, and reasonable procedures to promote data accuracy.

Companies also should implement and enforce procedurally sound privacy practices throughout their organizations, including assigning personnel to oversee privacy issues, training employees, and conducting privacy reviews for new products and services.

Consumer Choice

Consumers should have the opportunity to make choices about the collection and sharing of their data at the time and in the context in which they are making decisions—not after having to read long, complicated privacy policies that they often cannot find.

The report adds that, to simplify choice for both consumers and businesses, companies should not have to seek consent for certain commonly accepted practices, such as product fulfillment, fraud prevention, and legal compliance.

A “Do Not Track” mechanism would constitute a simplified means of consumer choice, the report said, allowing consumers to opt out of the collection of information about their Internet behavior for targeted ads.

Transparency

The report also recommended other measures to improve the transparency of information practices, including consideration of standardized notices that allow the public to compare information practices of competing companies. Consumers should have “reasonable access” to the data that companies maintain about them, particularly for non-consumer facing entities such as data brokers. In addition, the report proposed that stakeholders undertake a broad effort to educate consumers about commercial data practices and the choices available to them.

Text of the report is available here on the FTC website.

“Safe Harbor” Proposed

In response to the report, Senator John Kerry (D-Mass.) stated, “The Federal Trade Commission’s report should be a wakeup call for every Internet user in this country. The report confirms that many companies—both online and offline—don’t do enough to protect consumer privacy.”

Kerry continued, “The report also makes clear that properly protected information and respect for consumer trust can be good for both business and consumers.”

The senator called for the creation of FTC-approved safe harbor programs through which organizations can establish procedures to ensure compliance with standards on data protection, disclosures on information collected and the uses of such information, and the right of consumers to opt out.

“Those actors participating in safe harbor programs would be subject to FTC oversight and penalties,” Kerry said, “but because of their voluntary participation and commitment to high standards, they would be free from a private right of action and the complaint and adjudication process.”

Saturday, November 28, 2009





AstraZeneca Not Liable For Marketing of Nexium

This posting was written by Jody Coultas, Editor of CCH State Unfair Trade Practices Law.

A group of consumers alleging false advertising in the sale of heartburn medication failed to state an Arkansas Deceptive Trade Practices Act (DTPA) claim against AstraZeneca Pharmaceuticals, Inc. (AZ) because the claim fell within the safe harbor provision of the statute, according to the Arkansas Supreme Court.

In 2001, AZ's medication Nexium was approved by the Food and Drug Administration (FDA) for marketing as a heartburn medication. Nexium was meant to take the place of AZ's other heartburn medication Prilosec when the patent for Prilosec expired.

The consumers argued that AZ falsely advertised its heartburn medication, causing consumers to purchase a more expensive medication that was not "more powerful" and did not actually work "better" than a similar medication, as advertised. At the time of the complaint, one pill of Nexium cost $4.46, while the over-the-counter Prilosec cost $0.59 per pill.

Safe Harbor

The safe harbor provision of the DTPA, which barred the claim, provided that the statute does not apply to advertising that is subject to and complies with laws administered by a federal agency.

In this case, federal law specifically authorized pharmaceutical companies to promote drugs to consumers and physicians in a manner supported by the labeling approved by the FDA. Because the FDA-approved labeling indicated that the approved dose of the medication was superior to the similar drug, the advertising complied with the labeling.

The decision is DePriest v. AstraZeneca Pharmaceuticals, L.P., CCH State Unfair Trade Practices Law ¶31,932.