Showing posts with label FTC. Show all posts
Showing posts with label FTC. Show all posts

Wednesday, October 30, 2013

Ezor on Secure Times: Recent FTC Actions and Statements Show Continuing Focus on Privacy

IBLT Director Jonathan I. Ezor is blogging this week at the American Bar Association Privacy & Security Law Committee's Secure Times blog. His first contribution is below:

Recent FTC Actions and Statements Show Continuing Focus on Privacy

The Federal Trade Commission has long taken a lead role in issues of privacy and data protection, under its general consumer protection jurisdiction under Section 5 of the FTC Act (15 U.S.C. §45) as well as specific legislation such as the Children's Online Privacy Protection Act of 1998 ("COPPA") (which itself arose out of FTC reports). The FTC continues to bring legal actions against companies it believes have improperly collected, used or shared consumer personal information, including the recent settlement of a complaint filed against Aaron's, Inc., a national rent-to-own retail chain based in Atlanta, GA. In its October 22, 2013 press release announcing the settlement, the FTC described Aaron's alleged violations of Section 5:
Aaron’s, Inc., a national, Atlanta-based rent-to-own retailer, has agreed to settle FTC charges that it knowingly played a direct and vital role in its franchisees’ installation and use of software on rental computers that secretly monitored consumers including by taking webcam pictures of them in their homes. According to the FTC’s complaint, Aaron’s franchisees used the software, which surreptitiously tracked consumers’ locations, captured images through the computers’ webcams – including those of adults engaged in intimate activities – and activated keyloggers that captured users’ login credentials for email accounts and financial and social media sites.... The complaint alleges that Aaron’s knew about the privacy-invasive features of the software, but nonetheless allowed its franchisees to access and use the software, known as PC Rental Agent. In addition, Aaron’s stored data collected by the software for its franchisees and also transmitted messages from the software to its franchisees. In addition, Aaron’s provided franchisees with instructions on how to install and use the software. The software was the subject of related FTC actions earlier this year against the software manufacturer and several rent-to-own stores, including Aaron’s franchisees, that used it. It included a feature called Detective Mode, which, in addition to monitoring keystrokes, capturing screenshots, and activating the computer’s webcam, also presented deceptive “software registration” screens designed to get computer users to provide personal information.
The FTC's Consent Order Agreement with Aaron's includes a prohibition on the company using keystroke- or screenshot-monitoring software or activating the consumer's microphone or Web cam and a requirement to obtain express consent before installing location-tracking technology and provide notice when it's activated. Aaron's may not use any data it received through improper activities in collections actions, must destroy illegally obtained information, and must encrypt any transmitted location or tracking data it properly collects. The FTC is also continuing its efforts to educate and promote best practices about privacy for both consumers and businesses. On October 28, 2013, FTC Commissioner Julie Brill published an opinion piece in Advertising Age magazine entitled Data Industry Must Step Up to Protect Consumer Privacy. In the piece, Commissioner Brill criticizes data collection and marketing firms for failing to uphold basic privacy principles, and calls on them to join an initiative called "Reclaim Your Name" which Commissioner Brill announced earlier this year. Brill writes in AdAge:
The concept is simple. Through creation of consumer-friendly online services, Reclaim Your Name would empower the consumer to find out how brokers are collecting and using data; give her access to information that data brokers have amassed about her; allow her to opt-out if a data broker is selling her information for marketing purposes; and provide her the opportunity to correct errors in information used for substantive decisions. Improving the handling of sensitive data is another part of Reclaim Your Name. Data brokers that participate in Reclaim Your Name would agree to tailor their data handling and notice and choice tools to the sensitivity of the information at issue. As the data they handle or create becomes more sensitive -- relating to health conditions, sexual orientation and financial condition, for example -- the data brokers would provide greater transparency and more robust notice and choice to consumers.
For more information on the FTC's privacy guidance and enforcement, see the privacy and security section of the FTC Web site.

Monday, February 4, 2013

New Article: Privacy, Transparency and Google's Blurred Glass


I have just posted a new short article, Privacy, Transparency and Google's Blurred Glass, which looks at Google's privacy disclosures and how they may fall short of being as transparent as Google (and many others) would wish. The piece can be downloaded (as a PDF) from this link. Comments and questions are always welcome.

Friday, February 1, 2013

Path Pays $800,000 to FTC for Alleged Privacy Violations


On the same day that the FTC released its new report on mobile privacy, the Commission also announced its latest online mobile privacy enforcement action, an $800,000 settlement with the operator of the Path social networking app. According to the FTC's news release:
Path operates a social networking service that allows users to keep journals about “moments” in their life and to share that journal with a network of up to 150 friends.  Through the Path app, users can upload, store, and share photos, written “thoughts,” the user’s location, and the names of songs to which the user is listening.

In its complaint, the FTC charged that the user interface in Path's iOS app was misleading and provided consumers no meaningful choice regarding the collection of their personal information.  In version 2.0 of its app for iOS, Path offered an “Add Friends” feature to help users add new connections to their networks.  The feature provided users with three options: “Find friends from your contacts;” “Find friends from Facebook;” or “Invite friends to join Path by email or SMS.”  However, Path automatically collected and stored personal information from the user’s mobile device address book even if the user had not selected the “Find friends from your contacts” option.  For each contact in the user’s mobile device address book, Path automatically collected and stored any available first and last names, addresses, phone numbers, email addresses, Facebook and Twitter usernames, and dates of birth.
The FTC also alleged that Path’s privacy policy deceived consumers by claiming that it automatically collected only certain user information such as IP address, operating system, browser type, address of referring site, and site activity information.  In fact, version 2.0 of the Path app for iOS automatically collected and stored personal information from the user’s mobile device address book when the user first launched version 2.0 of the app and each time the user signed back into the account.

The agency also charged that Path, which collects birth date information during user registration, violated the Children’s Online Privacy Protection Act (COPPA) Rule by collecting personal information from approximately 3,000 children under the age of 13 without first getting parents’ consent.  Through its apps for both iOS and Android, as well as its website, Path enabled children to create personal journals and upload, store and share photos, written “thoughts,” their precise location, and the names of songs to which the child was listening.  Path version 2.0 also collected personal information from a child’s address book, including full names, addresses, phone numbers, email addresses, dates of birth and other information, where available....
The case documents may be found here.

The FTC has been actively enforcing violations of children's privacy for more than ten years, and is explicitly increasing its enforcement activities in mobile privacy and data security. (The FTC recently announced changes to its COPPA rule, but those have not yet gone into affect; the Path enforcement arises out of the current rule.) This latest action is consistent with the Commission's ongoing efforts to both encourage proper practices with regard to consumers' personal information, and punish those firms that fail to appropriately respect privacy and data security.

Thursday, January 3, 2013

FTC/Google Settlement: Covers Patents, Advertising; No Actionable Search Bias


The FTC has reached a proposed settlement with Google regarding multiple antitrust-related claims. The FTC's investigations covered issues including Google's control over key patents after its Motorola Mobility acquisition, Google's policies regarding cross-platform advertising campaign management, and allegations of so-called "search bias" through which Google was supposedly favoring its own content in its search results over competitors' pages.

With regard to search bias, the FTC found:
...that the evidence presented at this time does not support the allegation that Google’s display of its own vertical content at or near the top of its search results page was a product design change undertaken without a legitimate business justification. Rather, we conclude that Google’s display of its own content could plausibly be viewed as an improvement in the overall quality of Google’s search product. Similarly, we have not found sufficient evidence that Google manipulates its search algorithms to unfairly disadvantage vertical websites that compete with Google-owned vertical properties....
The FTC did, however, find some evidence that Google may have unfairly "scraped" competing Web sites' content for its own use and threatened to delist those that protested, and may further have placed "unreasonable restrictions" on advertisers' abilities to advertise on Google and competing search engines at the same time. Google agreed to refrain from both types of practices in the future.

Google additionally agreed to make certain changes in its patent and advertising practices. The FTC found that Google had blocked willing licensees of its patents from making deals on so-called fair, reasonable and non-discriminatory ("FRAND") terms, including through use of injunctions; in the settlement, Google agreed not to pursue such injunctions against those with whom Google had previously agreed to FRAND terms:


Google also agreed to alter elements of the contract terms covering the use of its AdWords API (application programming interface), which impeded advertisers' efforts to better manage and control their ad campaigns both within and beyond Google and its properties.

The FTC's proposed consent agreement with Google is subject to public comment through February 4th, 2013, in hard copy or online. The release (with links to the relevant documents, including dissents) may be found on the FTC's Web site.

Wednesday, December 19, 2012

FTC Announces Significant Update of COPPA Rule



After a number of rounds of public comment and workshops, the FTC has released its revised regulations under the Children’s Online Privacy Protection Act of 1998 (“COPPA”). The new regulations, to take effect on July 1, 2013, take into account changes in both technology and business since the original statute and regulations were enacted. According to the FTC’s release, the revised COPPA regulations:
  • modify the list of “personal information” that cannot be collected without parental notice and consent, clarifying that this category includes geolocation information, photographs, and videos;
  • offer companies a streamlined, voluntary and transparent approval process for new ways of getting parental consent;
  • close a loophole that allowed kid-directed apps and websites to permit third parties to collect personal information from children through plug-ins without parental notice and consent;
  • extend coverage in some of those cases so that the third parties doing the additional collection also have to comply with COPPA;
  • extend the COPPA Rule to cover persistent identifiers that can recognize users over time and across different websites or online services, such as IP addresses and mobile device IDs;
  • strengthen data security protections by requiring that covered website operators and online service providers take reasonable steps to release children’s personal information only to companies that are capable of keeping it secure and confidential;
  • require that covered website operators adopt reasonable procedures for data retention and deletion; and
  • strengthen the FTC’s oversight of self-regulatory safe harbor programs.

In his public statement describing the new Rule, FTC Chairman Jon Leibowitz described the FTC’s intentions with its revisions:

Just like you, we want a Rule that will protect innovation, and we think we have crafted one. Just like you, we want a Rule that will foster safe and vibrant spaces for children that are beneficial for learning and growth without creating a sanitized version of the Internet for older kids and adults, and we think we have struck that balance. Just like you, we want a Rule that will support diverse and free services online, and we think we are offering one today.

And, let’s be clear about one thing: under this Rule, advertisers and even ad networks can continue to advertise, even on sites directed to children. Business models that depend on advertising will continue to thrive. The only limit we place is on behavioral advertising, and in this regard our Rule is simple, effective, and straightforward: until and unless you get parental consent, you may not track children to build massive profiles for behavioral advertising purposes. Period.

The FTC has prepared a list of “Five Need-to-Know Changes” to the COPPA Rule for businesses, available here. The full text of the new Rule, to be published in the Federal Register, may be downloaded from this link. Finally, for some historical perspective, the following (courtesy of C-SPAN) is the original floor speech by Senator Richard Bryan of Nevada introducing COPPA on July 17, 1998:
 

Tuesday, December 18, 2012

FTC Orders 9 Data Brokers to Provide Info on Privacy Practices

The FTC announced today that it had issued orders to nine data brokers to disclosure how they collect and use consumer data. This is consistent with earlier guidance from the FTC, which recommended legislation targeting the data broker industry in its March 2012 Report on Protecting Consumer Privacy:



[T]he Commission recommends that Congress consider enacting targeted legislation to provide greater transparency for, and control over, the practices of information brokers. The proposed framework recommended that companies provide consumers with reasonable access to the data the companies maintain about them, proportionate to the sensitivity of the data and the nature of its use. Several commenters discussed in particular the importance of consumers’ ability to access information that information brokers have about them. These commenters noted the lack of transparency about the practices of information brokers, who often buy, compile, and sell a wealth of highly personal information about consumers but never interact directly with them. Consumers are often unaware of the existence of these entities, as well as the purposes for which they collect and use data.
The Commission agrees that consumers should have more control over the practices of information brokers and believes that appropriate legislation could help address this goal. Any such legislation could be modeled on a bill that the House passed on a bipartisan basis during the 111th Congress, which included a procedure for consumers to access and dispute personal data held by information brokers.
According to today's release, the FTC will use the information provided by the nine data brokers "to prepare a study and to make recommendations on whether, and how, the data broker industry could improve its privacy practices." The FTC's orders (in PDF format) may be downloaded here.

Monday, December 17, 2012

Children's Privacy: CDD files FTC Complaint Against Nickelodeon Spongebob App



In the latest legal development in the increasingly active world of children's privacy law, the Center for Digital Democracy announced that it had filed a complaint with the Federal Trade Commission against the cable network Nickelodeon and software developer PlayFirst over the SpongeBob Diner Dash game for iOS. According to the CDD's release, the description for the game in Apple's iTunes store inaccurately states that the app complies with the Children's Online Privacy Protection Act ("COPPA"):

As the complaint documents, Nickelodeon and PlayFirst engage in deceptive acts by representing in the privacy disclosure on the Apple App Store that the app’s “data collection is in accordance with applicable law, such as COPPA,” when in fact it is not. The SpongeBob Diner Dash game asks children to provide a wide range of personal information, including full name, email address, and other online contact information, without providing notice to parents or obtaining prior parental consent, as required by the Children’s Online Privacy Protection Act. Nor does the app provide an adequate description of the personal information it collects or how it is used.  
The FTC has not yet responded to CDD's request to investigate Nickelodeon and PlayFirst. CDD's complaint may be read here.

In a related matter, the FTC will reportedly release its update to the COPPA rules this week. These rules, which have been the subject of significant public discussion and comment, are the key regulatory requirements for those companies which collect personal information from children under the age of 13.

Wednesday, December 5, 2012

FTC Settles With Online Marketer Over "History Sniffing"



The Federal Trade Commission ("FTC"), the chief federal agency for consumer protection, has announced a proposed settlement with online marketer Epic Marketplace, Inc., over what the Commission called a "deceptive" use of a technology called "history sniffing." According to the FTC's release:

Epic Marketplace is a large advertising network that has a presence on 45,000 websites.  Consumers who visited any of the network’s sites received a cookie, which stored information about their online practices including sites they visited and the ads they viewed.  The cookies allowed Epic to serve consumers ads targeted to their interests, a practice known as online behavioral advertising.   
In its privacy policy, Epic claimed that it would collect information only about consumers’ visits to sites in its network.  However, according to the FTC, Epic was employing history-sniffing technology that allowed it to collect data about sites outside its network that consumers had visited, including sites relating to personal health conditions and finances. 
According to the FTC complaint, the history sniffing was deceptive and allowed Epic to determine whether a consumer had visited any of more than 54,000 domains, including pages relating to fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy.
The technique used by Epic apparently combined two methods enabled by its cookie-placing network: seeing whether a user's browser program colored particular links to indicate they had been previously clicked, and accessing the cache (temporarily stored files) of the browser.

The proposed settlement order bars Epic from futher history sniffing, mandates full and accurate disclosure of Epic's information collection practices, and places restrictions and retention requirements on Epic's data collection and sharing. It does not, however, contain any financial penalties for Epic's conduct.

Tuesday, November 27, 2012

Facebook “Hoax” Shows Privacy A Serious Matter for Users


In recent days, numerous Facebook users have posted a legal-sounding statement as an update to their pages containing some version of the following:

“In response to the new Facebook guidelines I hereby declare that my copyright is attached to all of my personal details, illustrations, comics, paintings, professional photos and videos, etc. (as a result of the Berner Convention). For any commercial use of the above my written consent is needed at all times! Anyone reading this can copy this text and paste it on their Facebook Wall. This will place you under protection of copyright laws. By the present communiqué, I notify Facebook that it is strictly forbidden to disclose, copy, distribute, disseminate, or take any other action against me on the basis of this profile and/or its contents.

The aforementioned prohibited actions also apply to employees, students, agents and/or any staff of Facebook or under their direction or control. The content of this profile is private and confidential information. A violation of my privacy is punishable by law (UCC 1 1-308-308 1-103 and the Rome Statute).

Facebook is now an open capital entity. All members are recommended to publish a notice like this, or if you prefer, you may copy and paste this version. If you do not publish a statement at least once, you will be tacitly allowing the use of elements such as your photos as well as the information contained in your profile status updates.”

This is not the first time Facebook users have felt the need to add a legal disclaimer to their statuses in an effort to protect their rights. A similar statement made the rounds a few months ago, with a greater focus on privacy:

Facebook is now a publicly traded entity. Unless you state otherwise, anyone can infringe on your right to privacy once you post to this site. It is recommended that you and other members post a similar notice as this, or you may copy and paste this version. If you do not post such a statement once, then you are indirectly allowing public use of items such as your photos and the information contained in your status updates.

PRIVACY NOTICE: Warning - any person and/or institution and/or Agent and/or Agency of any governmental structure including but not limited to the United States Federal Government also using or monitoring/using this website or any of its associated websites, you do NOT have my permission to utilize any of my profile information nor any of the content contained herein including, but not limited to my photos, and/or the comments made about my photos or any other "picture" art posted on my profile.

You are hereby notified that you are strictly prohibited from disclosing, copying, distributing, disseminating, or taking any other action against me with regard to this profile and the contents herein. The foregoing prohibitions also apply to your employee , agent , student or any personnel under your direction or control.

The contents of this profile are private and legally privileged and confidential information, and the violation of my personal privacy is punishable by law. UCC 1-103 1-308 ALL RIGHTS RESERVED WITHOUT PREJUDICE

These two statements have a few elements in common. First, there was no new policy (or change to a policy) at Facebook to trigger these notices. Next, even had there been such a policy, the notices themselves were ineffectual and inaccurate from a legal perspective (e.g. profile notices do not modify contracts; there is a Berne Convention regarding copyright but no “Berner Convention”; the U.C.C., or Uniform Commercial Code, is a state law regarding the sale of goods, having nothing to do with Facebook profiles or privacy). Additionally, both notices went viral very quickly, spreading to literally tens of thousands or more Facebook users, even as others posted rebuttals and links to sites such as Snopes.com and news sites covered and furthered debunk the warnings about “new Facebook guidelines.”

The main factor that these viral postings share, though, is the lesson that they can provide to Facebook and numerous other organizations: namely, that users care deeply about, and do whatever they think they can to ensure, their privacy. This is not a new idea, nor is this the first time a rumored (though inaccurate) threat to privacy generated vast consumer and even legislative response. In late 1996, e-mails spread warning about the supposed revelation by Lexis/Nexis of Social Security numbers and mothers’ maiden names (two important pieces of data that could be misused by identity thieves to steal account access) in its new P-Trak consumer information database. In reality, P-Trak had originally included Social Security numbers but had been quickly revised to allow only searching by such numbers if the searcher already knew them, and the database had never contained mothers’ maiden names. Nonetheless, consumers jammed Lexis/Nexis’ customer service lines demanding to be removed, and the incident sparked a letter from three senators to the FTC and a resulting FTC public workshop and report to Congress on privacy of social security numbers and other information.

The overall idea of consumers and other users being able to know and manage the information being collected about them has long been a significant part of privacy best practices. The FTC and numerous other bodies in the U.S. and throughout the world have promulgated some version of Fair Information Practice Principles (“FIPP”), which generally include sections on notice, choice and participation. More recently, in February 2012, the Obama Administration published a report entitled Consumer Data Privacy In A Networked World: A Framework For Protecting Privacy And Promoting Innovation In The Global Digital Economy, which included a Consumer Privacy Bill of Rights incorporating individual control, transparency, and access and accuracy among its elements. The whole concept of a Web site’s “privacy policy” is that it serves as a disclosure document, informing and empowering consumers with regard to the personal information collection and use by the site’s owner, and even absent general federal mandates for privacy policies in the United States, the vast majority of sites offer them, largely because consumers might otherwise suspect a site without a privacy policy of misusing their personal data.

Unfortunately, the theory of privacy policies and fair information practices does not always translate into reality. The double wave of Facebook viral postings, which were frequently made by those who weren’t either privacy advocates or lawyers, shows both that accurate information about Facebook’s practices was not being effectively communicated to its millions of users, and that users did not know how to find and use Facebook’s actual privacy controls. As confusing as Facebook’s controls may be, those of search/software/service giant Google are substantially more challenging, given how many different products Google offers, the numerous platforms on which they run, and the sheer volume of information being collected and used by Google.

If Facebook is paying attention to its users, it can do a huge service to them and the overall Internet community by taking this latest viral reaction to heart. Facebook should use this incident as a spark to substantially improve user access to and understanding of, its information collection practices. Other sites, including those many news sites that covered the story, should likewise reexamine and improve their own user privacy experiences. Otherwise, they may face not only unhappy and confused users, but regulatory and legislative actions that have a much more severe and longlasting impact on their businesses and their ability to properly (and transparently) use what they learn about their customers.

Sunday, October 7, 2012

Artist Arena pays $1 Million to Settle FTC COPPA Charges That It Illegally Collected Children’s Information

On October 4th, 2012, the Federal Trade Commission (FTC) and Artist Arena, a company that runs celebrity Web sites for music stars Justin Bieber, Rihanna, Demi Lovato, and Selena Gomez have agreed to settle for $1 million. The FTC charges that Artist Arena violated the Children’s Online Privacy Protection Act (COPPA) by collecting personal information from children under the age of 13, including names, addresses, email addresses, birthdates, and gender without notifying parents and obtaining their consent.

The FTC’s COPPA Rule requires that Web site operators notify parents and obtain their consent before they collect, use or disclose personal information from children under the age of 13. The settlement will impose a $1 million civil penalty on Artist Arena, bar future violations of the rule, and require that Artist Arena delete information collected in violation of the rule. In addition, for the next five years Artist Arena must prominently display a link to the federal Web site, http://www.onguardonline.gov/, in places where they collect personal data. Artist Arena also agreed to strict record keeping and compliance monitoring requirements over the next ten years.

The FTC alleges that Artist Arena, which is owned by Warner Music Group, knowingly registered over 25,000 children under the age of 13 and maintained personal information from almost 75,000 additional children who began, but did not complete, the registration process. The company falsely claimed it would not activate a registration nor collect children’s personal information without prior parental consent. Artist Arena has neither admitted nor denied the allegations but no longer allows children under the age of 13 to register as members of their fan sites.

The FTC Chairman, Jon Leibowitz, said:

“Marketers need to know that even a bad case of Bieber Fever doesn’t excuse their legal obligation to get parental consent before collecting personal information from children. The FTC is in the process of updating the COPPA Rule to ensure that it continues to protect kids growing up in the digital age.”

Businesspeople who want to learn about COPPA and how they can comply can visit You, Your Privacy Policy and COPPA - How to Comply with the Children's Online Privacy Protection Act for more information.

The complaint in its entirety can be viewed here. The consent decree, order for civil penalties, injunction, and other relief can be viewed here.

(Written by Jeff Wells, Fall 2012 IBLT Entrepreneurship Assistance Fellow)

Wednesday, September 19, 2012

FTC Finalizes Privacy Settlement with MySpace


On 9/11/12, the Federal Trade Commission, in an effort to protect consumers and prevent fraudulent, deceptive, and unfair business practices, approved a final settlement agreement with the social networking site MySpace over charges that MySpace misrepresented its protection of user’s personal information, an alleged violation of Section 5 of the FTC Act. MySpace is a social networking site with 25 million users worldwide who create custom online profiles of themselves for other users to view. When a profile is created on MySpace a unique identifier is assigned to that user which MySpace calls a “Friend ID.” The Friend ID can be used to access a user’s age, gender, profile picture, display name, and even the user's full name. A user’s profile may also contain additional information such as pictures, video’s, music, hobbies, interests, and lists of users' friends.


MySpace promised under the privacy policy posted on its Web site that it would not share a user’s personally identifiable information or otherwise exploit such information in a way that was inconsistent with the purpose for which it was submitted without first giving notice to and receiving permission from the user. A user’s personally identifiable information is defined by MySpace’s privacy policy as the user's full name, email address, mailing address, telephone number, or credit card number. Furthermore, the privacy policy also promised that the means through which it customized ads would not allow advertisers to access personally identifiable information or individually identify users.


MySpace earns revenue by allowing third-party or affiliate advertising networks to place advertisements directly on its site. According to the FTC, MySpace misled users about what information third-party advertisers received about them. The FTC charged that MySpace provided advertisers with the Friend ID of users who were viewing particular pages on the site. The advertisers were then able to use the Friend ID to easily access a user's MySpace profile to obtain personal information publicly available on the profile to link broader web-browsing activity to a specific individual. Additionally, the FTC alleges that MySpace made false statements about its compliance with U.S.-EU Safe Harbor Framework which is in place to protect the transfer of personal information from the European Union to the United States.


The settlement proposed by the FTC prohibits MySpace from misrepresenting the degree to which it protects the privacy of users’ personal information or to which it complies with other programs such as the U.S.-E.U. Safe Harbor Framework. The settlement also requires MySpace to take immediate action to develop a comprehensive privacy program to protect consumers’ information, including mandatory biennial audits of that program for 20 years by an independent third party.


The FTC notes that the administrative complaint issued against MySpace that led to the settlement agreement is not a finding or ruling that MySpace actually violated a law nor is the settlement agreement an admission by MySpace that it violated the law. However, now that the FTC has voted to accept the settlement agreement it carries the force of law with respect to future actions and each violation of such an order may result in a civil penalty of up to $16,000.


What does this mean for businesses and their privacy policies? Companies that collect a consumer’s personal information have a legal responsibility to stand by what is promised in their privacy policies and may share personal information or otherwise use the information only after first giving notice and, if required by the policy or applicable law, receiving permission from the consumers. It is important for companies to make an effort to craft their privacy policies in a more transparent manner for consumers. The FTC is making sure that companies are living up to their privacy policies and will take legal action against a company that has violated consumers’ privacy rights. If a company violates a consumer’s privacy rights it could lead to an assessment of monetary damages and it may possibly have a damaging effect on a companies goodwill. Therefore, it is important for a company to regularly review their privacy policies and make sure it provides for the utmost protection of a consumer’s personal information and to be certain that the company is in full compliance with its policy.

(written by Jeff Wells, Fall 2012 IBLT Entrepreneurship Assistance Fellow)