Showing posts with label Internet law. Show all posts
Showing posts with label Internet law. Show all posts

Wednesday, December 19, 2012

FTC Announces Significant Update of COPPA Rule



After a number of rounds of public comment and workshops, the FTC has released its revised regulations under the Children’s Online Privacy Protection Act of 1998 (“COPPA”). The new regulations, to take effect on July 1, 2013, take into account changes in both technology and business since the original statute and regulations were enacted. According to the FTC’s release, the revised COPPA regulations:
  • modify the list of “personal information” that cannot be collected without parental notice and consent, clarifying that this category includes geolocation information, photographs, and videos;
  • offer companies a streamlined, voluntary and transparent approval process for new ways of getting parental consent;
  • close a loophole that allowed kid-directed apps and websites to permit third parties to collect personal information from children through plug-ins without parental notice and consent;
  • extend coverage in some of those cases so that the third parties doing the additional collection also have to comply with COPPA;
  • extend the COPPA Rule to cover persistent identifiers that can recognize users over time and across different websites or online services, such as IP addresses and mobile device IDs;
  • strengthen data security protections by requiring that covered website operators and online service providers take reasonable steps to release children’s personal information only to companies that are capable of keeping it secure and confidential;
  • require that covered website operators adopt reasonable procedures for data retention and deletion; and
  • strengthen the FTC’s oversight of self-regulatory safe harbor programs.

In his public statement describing the new Rule, FTC Chairman Jon Leibowitz described the FTC’s intentions with its revisions:

Just like you, we want a Rule that will protect innovation, and we think we have crafted one. Just like you, we want a Rule that will foster safe and vibrant spaces for children that are beneficial for learning and growth without creating a sanitized version of the Internet for older kids and adults, and we think we have struck that balance. Just like you, we want a Rule that will support diverse and free services online, and we think we are offering one today.

And, let’s be clear about one thing: under this Rule, advertisers and even ad networks can continue to advertise, even on sites directed to children. Business models that depend on advertising will continue to thrive. The only limit we place is on behavioral advertising, and in this regard our Rule is simple, effective, and straightforward: until and unless you get parental consent, you may not track children to build massive profiles for behavioral advertising purposes. Period.

The FTC has prepared a list of “Five Need-to-Know Changes” to the COPPA Rule for businesses, available here. The full text of the new Rule, to be published in the Federal Register, may be downloaded from this link. Finally, for some historical perspective, the following (courtesy of C-SPAN) is the original floor speech by Senator Richard Bryan of Nevada introducing COPPA on July 17, 1998:
 

Tuesday, December 4, 2012

Blogger Settles Case with Former Employer Over Twitter Follower Ownership

Noah Kravitz' Twttter Statistics


The social media and technology blog Mashable reports that blogger Noah Kravitz has settled the lawsuit filed by his former employer, mobile tech blog PhoneDog, over the Twitter followers Kravitz kept when he left PhoneDog in October 2010 and changed his Twitter account from @phonedog_noah to a more personal @noahkravitz. The original complaint filed in the Northern District of California in July 2011 alleged that Kravitz' keeping the Twitter followers constituted misappropriation of trade secrets, intentional interference with prospective economic advantage, and other business torts. According to Mashable, the case has been settled through mediation.

The issue of ownership of a company's online resources, particularly those created and built by former employees on their own initiatives, is not new; in the mid-nineties, the New York Post had a dispute over the NYPost.com domain name with Farhan Memon, a former freelancer who had registered it during his work for the Post, and MTV had a similar conflict with its former VJ Adam Curry over the MTV.com domain Curry had registered. The Kravitz case, though, serves as a reminder that whenever an organization is being represented through an online presence, it needs to create and enforce clear guidelines in advance over who controls that presence, which should include ensuring that a single employee's departure (willing or otherwise) does not impede the organization's online efforts.

Sunday, December 2, 2012

Australian Federal Police Shut Down Romanian Cybercrime Ring

Australian Federal Police flag


The Australian Federal Police announced on November 29th that it had charged seven people in Romania for "the largest credit card data theft in Australia's history." According to the release, the investigation began in June 2011 based upon a referral from an Australian financial institution, and ultimately involved "numerous international law enforcement partners" including Romanian authorities.

The scope of the data theft is substantial: more than 500,000 credit cards were potentially accessible, with approximately 30,000 being used for "fraudulent transactions amounting to more than $30 million" Australian dollars. The cost of the fraud was apparently not borne by Australian consumers; instead, as in the United States, the issuing banks reimbursed the cardholders for the fraudulent transactions, which were performed throughout the world, including in Europe and the United States.

The case highlights the borderless nature of the Internet and the resulting challenges for law enforcement officials, as well as the significant financial exposure by companies and consumers for international (and local) data breaches and theft.

(Via @mukimu on ZDNet)

Wednesday, November 28, 2012

Mobile App Privacy: A Slowly Expanding Area

The area of consumer privacy is a broad area that has been discussed, analyzed and given guidance by both the Federal Trade Commission and the White House. Mobile application privacy, an important subset of consumer privacy, is an area of privacy that has been receiving significant attention over the past year as the importance of the mobile platform increases.

The push for protection in mobile app privacy most clearly began with a Joint Statement of Principles laid out by the California Attorney General, created in February 2012. The California Joint Principles represent an agreement by several top companies in the mobile industry. The agreement, which includes Apple, Google, Research In Motion, HP, and Microsoft (in addition to Facebook, which signed on in June), states what these companies promise to do in their mobile app store. The agreement reached by the major mobile companies provides that the California Online Privacy Protection Act is applicable to any application that collects personal data from a consumer. Such an app requires a “conspicuously posted” privacy policy. The agreement provides that when an app is submitted to a mobile app store by the developer there should be a hyperlink to the privacy policy or the actual privacy policy for that particular app. The privacy policy, whether a hyperlink or the full text, should be available in the mobile app store prior to download of the app. The major mobile companies must also provide a method for users to report apps that do not have such a policy or whose policy does not comply with applicable law.

In addition to the Joint Principles, the FTC has released a new Report on marketing mobile applications, in September of 2012, that contains suggestions on how to limit privacy concerns in a mobile app.  The FTC suggests that mobile app creators:

Build privacy considerations in from the start.  The FTC calls this “privacy by design.”… Incorporating privacy protections into your practices, limiting the information you collect, securely storing what you hold on to, and safely disposing of what you no longer need.  Apply these principles in selecting the default settings for your app and make the default settings consistent with what people would expect based on the kind of app you’re selling.  For any collection or sharing of information that’s not apparent, get users’ express agreement.  That way your customers aren’t unwittingly disclosing information they didn’t mean to share.
Be transparent about your data practices….Offer choices that are easy to find and easy to use…Honor your privacy promises…The FTC has taken action against dozens of companies that claimed to safeguard the privacy or security of users’ information, but didn’t live up to their promises in the day-to-day operation of their business.  The FTC also has taken action against businesses that made broad statements about their privacy practices, but then failed to disclose the extent to which they collected or shared information with others – like advertisers or other app developers…Protect kids’ privacy…
Collect sensitive information only with consent.  Even when you’re not dealing with kids’ information, it’s important to get users’ affirmative OK before you collect any sensitive data from them, like medical, financial, or precise geolocation information.  It’s a mistake to assume they won’t mind.
Keep user data secure...The wisest policy is to:
  •  collect only the data you need;
  • secure the data you keep by taking reasonable precautions against well-known security risks;
  • limit access to a need-to-know basis; and
  • safely dispose of data you no longer need.
As mobile app privacy is a new and growing area, the actual implications on businesses are not yet clear. The California Joint Statements only require that those mobile app store providers will provide a location for the individual app’s privacy policy. This only implicitly requires that mobile app creators should have a privacy policy. The FTC guidelines are less stringent. As stated in its report on consumer privacy, the FTC does not believe that they have the powers, at this time, to broadly regulate the area of privacy. However, the FTC suggestions show what the the Commission might enforce if given the power to do so by Congress.

(Written by Brett Alazraki, Fall 2012 IBLT Entrepreneurship Assistance Fellow)

Friday, November 23, 2012

ABA Adopts New Cybersecurity Policy

The Board of Governors of the American Bar Association ("ABA"), the U.S.' largest legal professional organization, has recently adopted a cybersecurity policy recommended by the association's Cybersecurity Legal Task Force. The ABA hopes that its new effort will guide "the executive and legislative branches" of the government in "making policy determinations for improving cybersecurity for the U.S. public and private sectors."

The ABA's policy consists of five principles:
  • Principle 1: Public–private frameworks are essential to successfully protect U.S. assets, infrastructure, and economic interests from cybersecurity attacks.
  • Principle 2: Robust information sharing and collaboration between government agencies and private industry are necessary to manage global cyber risks.
  • Principle 3: Legal and policy environments must be modernized to stay ahead of or, at a minimum, keep pace with technological advancements.
  • Principle 4: Privacy and civil liberties must remain a priority when developing cybersecurity law and policy.
  • Principle 5: Training, education, and workforce development of government and corporate senior leadership, technical operators, and lawyers require adequate investment and resourcing in cybersecurity to be successful.
Beyond their stated goal of governmental guidance, the ABA's principles also form a useful roadmap for every organization, public and private, considering and implementing cybersecurity efforts. Further, even if an organization is not itself managing network security (for example, if it outsources its IT functions), the new guidelines will assist it in understanding and specifying the level of service it receives from the entity that is responsible for cybersecurity.

The new policy is one of many recent initiatives by the ABA seeking to raise both the awareness and diligence of attorneys and lawmakers about technology's impact on law and legal ethics. While the ABA has no formal enforcement authority, its recommendations can be very influential on state and federal governments as well as courts.

Thursday, October 4, 2012

Recent Trend: States Protect Individuals from Employers' and Universities' Logging into Their Social Media Accounts

California recently passed a law that protects individuals from having to give potential employers their login credentials for various social media accounts. The law also prohibits universities from demanding the information from prospective students. The California law is a recent example of numerous states’ laws designed to protect employees/potential employees and students/prospective students.

The text of the employer law itself gives an incredibly broad definition of social media:
As used in this chapter, ‘social media’ means an electronic service or account, or electronic content, including, but not limited to, videos, still photographs, blogs, video blogs, podcasts, instant and text messages, email, online services or accounts, or Internet Web site profiles or locations.

The student protection bill has a slightly different definition of social media:

As used in this chapter, ‘social media’ means an electronic medium where users may create, share, and view user-generated content, including uploading or downloading videos or still photographs, blogs, video blogs, podcasts, instant messages, or Internet Web site profiles or locations.

 While the two definitions are different, they seemingly cover the same types of social media and should be broad enough to cover all forms of social media existing or possibly created in the future.

Maryland was the first state to enact a law of this type, in May of 2012, and the provisions have gone into effect as of October 1, 2012. The law goes about protecting employees by not defining social media, but by protecting employees’ personal accounts.

Several other states have created laws protecting similar employees’ social media accounts, such as Illinois and Delaware. Several other states, including Massachusetts and New York have bills currently in the legislatures or in a committee, waiting to be passed.

The impacts of these new laws on businesses are clear. Businesses can no longer demand that employees hand over username and passwords to personal social media accounts. Therefore, in order to try to find individuals profiles and posts, employers will have to spend significantly more time and resources. The laws also show that states believe that individuals’ social media accounts are something that should be protected from employers and that this is part of a privacy right of citizens.

In addition, to state actions, the National Labor Relations Board has shown that the board is willing to step in and protect employers’ ability to use social media. A September decision by the board struck down a Costco rule that broadly limiting Costco employee use of social media. The board’s decision shows a continued effort by the federal government to protect the right of social media users.

(Written by Brett Alazraki, Fall 2012 IBLT Entrepreneurship Assistance Fellow) 

Wednesday, September 19, 2012

FTC Finalizes Privacy Settlement with MySpace


On 9/11/12, the Federal Trade Commission, in an effort to protect consumers and prevent fraudulent, deceptive, and unfair business practices, approved a final settlement agreement with the social networking site MySpace over charges that MySpace misrepresented its protection of user’s personal information, an alleged violation of Section 5 of the FTC Act. MySpace is a social networking site with 25 million users worldwide who create custom online profiles of themselves for other users to view. When a profile is created on MySpace a unique identifier is assigned to that user which MySpace calls a “Friend ID.” The Friend ID can be used to access a user’s age, gender, profile picture, display name, and even the user's full name. A user’s profile may also contain additional information such as pictures, video’s, music, hobbies, interests, and lists of users' friends.


MySpace promised under the privacy policy posted on its Web site that it would not share a user’s personally identifiable information or otherwise exploit such information in a way that was inconsistent with the purpose for which it was submitted without first giving notice to and receiving permission from the user. A user’s personally identifiable information is defined by MySpace’s privacy policy as the user's full name, email address, mailing address, telephone number, or credit card number. Furthermore, the privacy policy also promised that the means through which it customized ads would not allow advertisers to access personally identifiable information or individually identify users.


MySpace earns revenue by allowing third-party or affiliate advertising networks to place advertisements directly on its site. According to the FTC, MySpace misled users about what information third-party advertisers received about them. The FTC charged that MySpace provided advertisers with the Friend ID of users who were viewing particular pages on the site. The advertisers were then able to use the Friend ID to easily access a user's MySpace profile to obtain personal information publicly available on the profile to link broader web-browsing activity to a specific individual. Additionally, the FTC alleges that MySpace made false statements about its compliance with U.S.-EU Safe Harbor Framework which is in place to protect the transfer of personal information from the European Union to the United States.


The settlement proposed by the FTC prohibits MySpace from misrepresenting the degree to which it protects the privacy of users’ personal information or to which it complies with other programs such as the U.S.-E.U. Safe Harbor Framework. The settlement also requires MySpace to take immediate action to develop a comprehensive privacy program to protect consumers’ information, including mandatory biennial audits of that program for 20 years by an independent third party.


The FTC notes that the administrative complaint issued against MySpace that led to the settlement agreement is not a finding or ruling that MySpace actually violated a law nor is the settlement agreement an admission by MySpace that it violated the law. However, now that the FTC has voted to accept the settlement agreement it carries the force of law with respect to future actions and each violation of such an order may result in a civil penalty of up to $16,000.


What does this mean for businesses and their privacy policies? Companies that collect a consumer’s personal information have a legal responsibility to stand by what is promised in their privacy policies and may share personal information or otherwise use the information only after first giving notice and, if required by the policy or applicable law, receiving permission from the consumers. It is important for companies to make an effort to craft their privacy policies in a more transparent manner for consumers. The FTC is making sure that companies are living up to their privacy policies and will take legal action against a company that has violated consumers’ privacy rights. If a company violates a consumer’s privacy rights it could lead to an assessment of monetary damages and it may possibly have a damaging effect on a companies goodwill. Therefore, it is important for a company to regularly review their privacy policies and make sure it provides for the utmost protection of a consumer’s personal information and to be certain that the company is in full compliance with its policy.

(written by Jeff Wells, Fall 2012 IBLT Entrepreneurship Assistance Fellow)

Wednesday, September 12, 2012

Thoughts on Education and Compliance re: Cookie Consent Law from UK's Information Commissioner's Office

Dave Evans, the Group Manager, Business and Industry for the UK's Information Commissioner's Office ("ICO") has posted a new blog entry discussing the ICO's efforts in both education and enforcement regarding the use of cookies by companies. The UK's law on cookies, passed in compliance with Article 5.3 of the EU's Data Protection Directive as it was revised in 2009, places specific requirements for organizations to obtain consent for placing and using cookie files on users' computers, and the ICO has previously published guidance on how to understand and follow the law.

In his September 10, 2012 blog entry, Evans discusses the two-prong approach the ICO has taken in connection with implementing the cookies law and regulations:

Broadly speaking, there’s two ways we go about this: an education programme to inform the industry, and enforcement work to ensure compliance.

So we’ve issued guidance and press releases, spoken at conferences, held meetings and workshops and even written to 75 of the most visited websites, asking what steps they had taken to achieve compliance and offering our help. We are working through the intelligence we have gathered to see if websites are taking action to increase the visibility of information about cookies, and already a fair number have.

But we’re balancing that with enforcement: for example, some sites have failed to engage with us at all, and they’re now being set a deadline to take steps towards compliance, with formal enforcement action likely if they fail to meet this deadline. Failure to act on an enforcement notice is a criminal offence.
This mirrors the approach taken by the U.S.' Federal Trade Commission ("FTC") in its privacy and data security activities, as with the moving deadlines and business education program around the Red Flags Rule. Both agencies understand that laws and regulations cannot fulfill their purposes if those who must comply with them are unaware of the requirements. In the privacy and data security area, this challenge is especially great for the numerous small and mid-sized businesses which may not have the personnel or other resources to keep abreast of either legal mandates or best practices. To reach those audiences, governmental agencies do well to partner with regional and local trade groups and educational institutions (such as Touro Law's Institute for Business, Law and Technology) to help spread the word.

Tuesday, September 11, 2012

Welcome to the new privacy and technology law blog published by the Institute for Business, Law and Technology (“IBLT”) at Touro College Jacob D. Fuchsberg Law Center in Central Islip, NY. This blog will highlight legal developments and discuss best practices in business privacy, data protection, and the intersection of business, law and technology. Our posts, which will be written by faculty and students at Touro Law Center, including the IBLT’s director, Prof. Jonathan I. Ezor, and the IBLT’s student Entrepreneurship Initiative Fellows. We welcome your thoughts and comments at iblt@tourolaw.edu, and you can also follow the IBLT on Twitter and Facebook.