Showing posts with label COPPA. Show all posts
Showing posts with label COPPA. Show all posts

Friday, February 1, 2013

Path Pays $800,000 to FTC for Alleged Privacy Violations


On the same day that the FTC released its new report on mobile privacy, the Commission also announced its latest online mobile privacy enforcement action, an $800,000 settlement with the operator of the Path social networking app. According to the FTC's news release:
Path operates a social networking service that allows users to keep journals about “moments” in their life and to share that journal with a network of up to 150 friends.  Through the Path app, users can upload, store, and share photos, written “thoughts,” the user’s location, and the names of songs to which the user is listening.

In its complaint, the FTC charged that the user interface in Path's iOS app was misleading and provided consumers no meaningful choice regarding the collection of their personal information.  In version 2.0 of its app for iOS, Path offered an “Add Friends” feature to help users add new connections to their networks.  The feature provided users with three options: “Find friends from your contacts;” “Find friends from Facebook;” or “Invite friends to join Path by email or SMS.”  However, Path automatically collected and stored personal information from the user’s mobile device address book even if the user had not selected the “Find friends from your contacts” option.  For each contact in the user’s mobile device address book, Path automatically collected and stored any available first and last names, addresses, phone numbers, email addresses, Facebook and Twitter usernames, and dates of birth.
The FTC also alleged that Path’s privacy policy deceived consumers by claiming that it automatically collected only certain user information such as IP address, operating system, browser type, address of referring site, and site activity information.  In fact, version 2.0 of the Path app for iOS automatically collected and stored personal information from the user’s mobile device address book when the user first launched version 2.0 of the app and each time the user signed back into the account.

The agency also charged that Path, which collects birth date information during user registration, violated the Children’s Online Privacy Protection Act (COPPA) Rule by collecting personal information from approximately 3,000 children under the age of 13 without first getting parents’ consent.  Through its apps for both iOS and Android, as well as its website, Path enabled children to create personal journals and upload, store and share photos, written “thoughts,” their precise location, and the names of songs to which the child was listening.  Path version 2.0 also collected personal information from a child’s address book, including full names, addresses, phone numbers, email addresses, dates of birth and other information, where available....
The case documents may be found here.

The FTC has been actively enforcing violations of children's privacy for more than ten years, and is explicitly increasing its enforcement activities in mobile privacy and data security. (The FTC recently announced changes to its COPPA rule, but those have not yet gone into affect; the Path enforcement arises out of the current rule.) This latest action is consistent with the Commission's ongoing efforts to both encourage proper practices with regard to consumers' personal information, and punish those firms that fail to appropriately respect privacy and data security.

Wednesday, December 19, 2012

FTC Announces Significant Update of COPPA Rule



After a number of rounds of public comment and workshops, the FTC has released its revised regulations under the Children’s Online Privacy Protection Act of 1998 (“COPPA”). The new regulations, to take effect on July 1, 2013, take into account changes in both technology and business since the original statute and regulations were enacted. According to the FTC’s release, the revised COPPA regulations:
  • modify the list of “personal information” that cannot be collected without parental notice and consent, clarifying that this category includes geolocation information, photographs, and videos;
  • offer companies a streamlined, voluntary and transparent approval process for new ways of getting parental consent;
  • close a loophole that allowed kid-directed apps and websites to permit third parties to collect personal information from children through plug-ins without parental notice and consent;
  • extend coverage in some of those cases so that the third parties doing the additional collection also have to comply with COPPA;
  • extend the COPPA Rule to cover persistent identifiers that can recognize users over time and across different websites or online services, such as IP addresses and mobile device IDs;
  • strengthen data security protections by requiring that covered website operators and online service providers take reasonable steps to release children’s personal information only to companies that are capable of keeping it secure and confidential;
  • require that covered website operators adopt reasonable procedures for data retention and deletion; and
  • strengthen the FTC’s oversight of self-regulatory safe harbor programs.

In his public statement describing the new Rule, FTC Chairman Jon Leibowitz described the FTC’s intentions with its revisions:

Just like you, we want a Rule that will protect innovation, and we think we have crafted one. Just like you, we want a Rule that will foster safe and vibrant spaces for children that are beneficial for learning and growth without creating a sanitized version of the Internet for older kids and adults, and we think we have struck that balance. Just like you, we want a Rule that will support diverse and free services online, and we think we are offering one today.

And, let’s be clear about one thing: under this Rule, advertisers and even ad networks can continue to advertise, even on sites directed to children. Business models that depend on advertising will continue to thrive. The only limit we place is on behavioral advertising, and in this regard our Rule is simple, effective, and straightforward: until and unless you get parental consent, you may not track children to build massive profiles for behavioral advertising purposes. Period.

The FTC has prepared a list of “Five Need-to-Know Changes” to the COPPA Rule for businesses, available here. The full text of the new Rule, to be published in the Federal Register, may be downloaded from this link. Finally, for some historical perspective, the following (courtesy of C-SPAN) is the original floor speech by Senator Richard Bryan of Nevada introducing COPPA on July 17, 1998:
 

Monday, December 17, 2012

Children's Privacy: CDD files FTC Complaint Against Nickelodeon Spongebob App



In the latest legal development in the increasingly active world of children's privacy law, the Center for Digital Democracy announced that it had filed a complaint with the Federal Trade Commission against the cable network Nickelodeon and software developer PlayFirst over the SpongeBob Diner Dash game for iOS. According to the CDD's release, the description for the game in Apple's iTunes store inaccurately states that the app complies with the Children's Online Privacy Protection Act ("COPPA"):

As the complaint documents, Nickelodeon and PlayFirst engage in deceptive acts by representing in the privacy disclosure on the Apple App Store that the app’s “data collection is in accordance with applicable law, such as COPPA,” when in fact it is not. The SpongeBob Diner Dash game asks children to provide a wide range of personal information, including full name, email address, and other online contact information, without providing notice to parents or obtaining prior parental consent, as required by the Children’s Online Privacy Protection Act. Nor does the app provide an adequate description of the personal information it collects or how it is used.  
The FTC has not yet responded to CDD's request to investigate Nickelodeon and PlayFirst. CDD's complaint may be read here.

In a related matter, the FTC will reportedly release its update to the COPPA rules this week. These rules, which have been the subject of significant public discussion and comment, are the key regulatory requirements for those companies which collect personal information from children under the age of 13.

Sunday, October 7, 2012

Artist Arena pays $1 Million to Settle FTC COPPA Charges That It Illegally Collected Children’s Information

On October 4th, 2012, the Federal Trade Commission (FTC) and Artist Arena, a company that runs celebrity Web sites for music stars Justin Bieber, Rihanna, Demi Lovato, and Selena Gomez have agreed to settle for $1 million. The FTC charges that Artist Arena violated the Children’s Online Privacy Protection Act (COPPA) by collecting personal information from children under the age of 13, including names, addresses, email addresses, birthdates, and gender without notifying parents and obtaining their consent.

The FTC’s COPPA Rule requires that Web site operators notify parents and obtain their consent before they collect, use or disclose personal information from children under the age of 13. The settlement will impose a $1 million civil penalty on Artist Arena, bar future violations of the rule, and require that Artist Arena delete information collected in violation of the rule. In addition, for the next five years Artist Arena must prominently display a link to the federal Web site, http://www.onguardonline.gov/, in places where they collect personal data. Artist Arena also agreed to strict record keeping and compliance monitoring requirements over the next ten years.

The FTC alleges that Artist Arena, which is owned by Warner Music Group, knowingly registered over 25,000 children under the age of 13 and maintained personal information from almost 75,000 additional children who began, but did not complete, the registration process. The company falsely claimed it would not activate a registration nor collect children’s personal information without prior parental consent. Artist Arena has neither admitted nor denied the allegations but no longer allows children under the age of 13 to register as members of their fan sites.

The FTC Chairman, Jon Leibowitz, said:

“Marketers need to know that even a bad case of Bieber Fever doesn’t excuse their legal obligation to get parental consent before collecting personal information from children. The FTC is in the process of updating the COPPA Rule to ensure that it continues to protect kids growing up in the digital age.”

Businesspeople who want to learn about COPPA and how they can comply can visit You, Your Privacy Policy and COPPA - How to Comply with the Children's Online Privacy Protection Act for more information.

The complaint in its entirety can be viewed here. The consent decree, order for civil penalties, injunction, and other relief can be viewed here.

(Written by Jeff Wells, Fall 2012 IBLT Entrepreneurship Assistance Fellow)