Showing posts with label Safe Harbor. Show all posts
Showing posts with label Safe Harbor. Show all posts

Wednesday, November 27, 2013

EU Calls for US to Restore Privacy Trust But Maintains Safe Harbor



On November 27th, 2013, the European Commission announced that it would not suspend the safe harbor agreement between the EU and the United States that has allowed cross-border personal data transfers between the two jurisdictions since 2000. The announcement followed the Edward Snowden revelations of U.S. surveillance activities, which prompted a number of public calls for suspension of the safe harbor by EU member states and statements by EU officials condemning the U.S.' reported practices.

In preserving (for now) the Safe Harbor, the EC nonetheless called for changes to U.S. governmental practices in order to "restore trust in EU-U.S. data flows." It released a Communication (strategy paper) on data flows between the regions, an analysis of how the Safe Harbor has functioned (and where it has failed), and other documents supporting its position. In the accompanying press release, the EC called for action in six key areas:

  • A swift adoption of the EU's data protection reform: the strong legislative framework, as proposed by the European Commission in January 2012 (IP/12/46), with clear rules that are enforceable also in situations when data is transferred and processed abroad is, more than ever, a necessity. The EU institutions should therefore continue working towards the adoption of the EU data protection reform by spring 2014, to make sure that personal data is effectively and comprehensively protected (see MEMO/13/923). 
  • Making Safe Harbour safer: the Commission today made 13 recommendations to improve the functioning of the Safe Harbour scheme, after an analysis also published today finds the functioning of the scheme deficient in several respects. Remedies should be identified by summer 2014. The Commission will then review the functioning of the scheme based on the implementation of these 13 recommendations. 
  • Strengthening data protection safeguards in the law enforcement area: the current negotiations on an “umbrella agreement” (IP/10/1661) for transfers and processing of data in the context of police and judicial cooperation should be concluded swiftly. An agreement must guarantee a high level of protection for citizens who should benefit from the same rights on both sides of the Atlantic. Notably, EU citizens not resident in the U.S. should benefit from judicial redress mechanisms. 
  • Using the existing Mutual Legal Assistance and Sectoral agreements to obtain data: The U.S. administration should commit to, as a general principle, making use of a legal framework like the mutual legal assistance and sectoral EU-U.S. Agreements such as the Passenger Name Records Agreement and Terrorist Financing Tracking Programme whenever transfers of data are required for law enforcement purposes. Asking the companies directly should only be possible under clearly defined, exceptional and judicially reviewable situations. 
  • Addressing European concerns in the on-going U.S. reform process: U.S. President Obama has announced a review of U.S. national security authorities’ activities. This process should also benefit EU citizens. The most important changes should be extending the safeguards available to US citizens to EU citizens not resident in the US, increased transparency and better oversight. 
  • Promoting privacy standards internationally: The U.S. should accede to the Council of Europe’s Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (“Convention 108”), as it acceded to the 2001 Convention on Cybercrime. 
The complete collection of the EC's materials accompanying the announcement may be found here.

Wednesday, December 19, 2012

FTC Announces Significant Update of COPPA Rule



After a number of rounds of public comment and workshops, the FTC has released its revised regulations under the Children’s Online Privacy Protection Act of 1998 (“COPPA”). The new regulations, to take effect on July 1, 2013, take into account changes in both technology and business since the original statute and regulations were enacted. According to the FTC’s release, the revised COPPA regulations:
  • modify the list of “personal information” that cannot be collected without parental notice and consent, clarifying that this category includes geolocation information, photographs, and videos;
  • offer companies a streamlined, voluntary and transparent approval process for new ways of getting parental consent;
  • close a loophole that allowed kid-directed apps and websites to permit third parties to collect personal information from children through plug-ins without parental notice and consent;
  • extend coverage in some of those cases so that the third parties doing the additional collection also have to comply with COPPA;
  • extend the COPPA Rule to cover persistent identifiers that can recognize users over time and across different websites or online services, such as IP addresses and mobile device IDs;
  • strengthen data security protections by requiring that covered website operators and online service providers take reasonable steps to release children’s personal information only to companies that are capable of keeping it secure and confidential;
  • require that covered website operators adopt reasonable procedures for data retention and deletion; and
  • strengthen the FTC’s oversight of self-regulatory safe harbor programs.

In his public statement describing the new Rule, FTC Chairman Jon Leibowitz described the FTC’s intentions with its revisions:

Just like you, we want a Rule that will protect innovation, and we think we have crafted one. Just like you, we want a Rule that will foster safe and vibrant spaces for children that are beneficial for learning and growth without creating a sanitized version of the Internet for older kids and adults, and we think we have struck that balance. Just like you, we want a Rule that will support diverse and free services online, and we think we are offering one today.

And, let’s be clear about one thing: under this Rule, advertisers and even ad networks can continue to advertise, even on sites directed to children. Business models that depend on advertising will continue to thrive. The only limit we place is on behavioral advertising, and in this regard our Rule is simple, effective, and straightforward: until and unless you get parental consent, you may not track children to build massive profiles for behavioral advertising purposes. Period.

The FTC has prepared a list of “Five Need-to-Know Changes” to the COPPA Rule for businesses, available here. The full text of the new Rule, to be published in the Federal Register, may be downloaded from this link. Finally, for some historical perspective, the following (courtesy of C-SPAN) is the original floor speech by Senator Richard Bryan of Nevada introducing COPPA on July 17, 1998:
 

Wednesday, September 19, 2012

FTC Finalizes Privacy Settlement with MySpace


On 9/11/12, the Federal Trade Commission, in an effort to protect consumers and prevent fraudulent, deceptive, and unfair business practices, approved a final settlement agreement with the social networking site MySpace over charges that MySpace misrepresented its protection of user’s personal information, an alleged violation of Section 5 of the FTC Act. MySpace is a social networking site with 25 million users worldwide who create custom online profiles of themselves for other users to view. When a profile is created on MySpace a unique identifier is assigned to that user which MySpace calls a “Friend ID.” The Friend ID can be used to access a user’s age, gender, profile picture, display name, and even the user's full name. A user’s profile may also contain additional information such as pictures, video’s, music, hobbies, interests, and lists of users' friends.


MySpace promised under the privacy policy posted on its Web site that it would not share a user’s personally identifiable information or otherwise exploit such information in a way that was inconsistent with the purpose for which it was submitted without first giving notice to and receiving permission from the user. A user’s personally identifiable information is defined by MySpace’s privacy policy as the user's full name, email address, mailing address, telephone number, or credit card number. Furthermore, the privacy policy also promised that the means through which it customized ads would not allow advertisers to access personally identifiable information or individually identify users.


MySpace earns revenue by allowing third-party or affiliate advertising networks to place advertisements directly on its site. According to the FTC, MySpace misled users about what information third-party advertisers received about them. The FTC charged that MySpace provided advertisers with the Friend ID of users who were viewing particular pages on the site. The advertisers were then able to use the Friend ID to easily access a user's MySpace profile to obtain personal information publicly available on the profile to link broader web-browsing activity to a specific individual. Additionally, the FTC alleges that MySpace made false statements about its compliance with U.S.-EU Safe Harbor Framework which is in place to protect the transfer of personal information from the European Union to the United States.


The settlement proposed by the FTC prohibits MySpace from misrepresenting the degree to which it protects the privacy of users’ personal information or to which it complies with other programs such as the U.S.-E.U. Safe Harbor Framework. The settlement also requires MySpace to take immediate action to develop a comprehensive privacy program to protect consumers’ information, including mandatory biennial audits of that program for 20 years by an independent third party.


The FTC notes that the administrative complaint issued against MySpace that led to the settlement agreement is not a finding or ruling that MySpace actually violated a law nor is the settlement agreement an admission by MySpace that it violated the law. However, now that the FTC has voted to accept the settlement agreement it carries the force of law with respect to future actions and each violation of such an order may result in a civil penalty of up to $16,000.


What does this mean for businesses and their privacy policies? Companies that collect a consumer’s personal information have a legal responsibility to stand by what is promised in their privacy policies and may share personal information or otherwise use the information only after first giving notice and, if required by the policy or applicable law, receiving permission from the consumers. It is important for companies to make an effort to craft their privacy policies in a more transparent manner for consumers. The FTC is making sure that companies are living up to their privacy policies and will take legal action against a company that has violated consumers’ privacy rights. If a company violates a consumer’s privacy rights it could lead to an assessment of monetary damages and it may possibly have a damaging effect on a companies goodwill. Therefore, it is important for a company to regularly review their privacy policies and make sure it provides for the utmost protection of a consumer’s personal information and to be certain that the company is in full compliance with its policy.

(written by Jeff Wells, Fall 2012 IBLT Entrepreneurship Assistance Fellow)