Showing posts with label cookies. Show all posts
Showing posts with label cookies. Show all posts

Thursday, January 24, 2013

The Other Google Search: 8438 Data Requests by U.S. Gov't


Google has released the latest version of its Transparency Report, covering the period from July 1 through December 31, 2012. In the report, Google states that the U.S. government made 8,438 requests of user data from Google during the period, covering a reported 14,791 users/accounts, and that Google responded fully or partially to an aggregate of 88% of those requests, broken down as follows:

July to December 2012

Records Requested

Users/Accounts

Percentage Fully/Partially Complied With

Search Warrant

1,896

3,152

88%

Subpoena

5,784

10,390

88%

Other 

758

1,249

90%

The number of of these requests, particularly from the U.S. government, has been steadily increasing over the past few years; the U.S. government made only 3,580 total requests in the same period in 2009. Google states in the introduction to its report, "We review each request to make sure that it complies with both the spirit and the letter of the law, and we may refuse to produce information or try to narrow the request in some cases." It also attributes some of the increase to its own growth: "Usage of our services have increased every year, and so have the user data request numbers."

While Google is to be commended for its efforts to disclose (some of) the requests for information it receives, the report and the increases it shows serve as a reminder of the size, scope and value of Google's collection of data about its users. Given how many products Google owns, many of which may not bear obvious Google branding (such as the Zagat Restaurant Guide) but may still be feeding user data into Google's central servers (Zagat's privacy policy is the Google shared one, as is that of its fellow non-obvious Google acquisition, the Frommer's Travel Guides site), one may legitimately question whether all users are able to provide truly informed consent to Google's data collection, which is increasingly a governmental resource as well.

Wednesday, December 5, 2012

FTC Settles With Online Marketer Over "History Sniffing"



The Federal Trade Commission ("FTC"), the chief federal agency for consumer protection, has announced a proposed settlement with online marketer Epic Marketplace, Inc., over what the Commission called a "deceptive" use of a technology called "history sniffing." According to the FTC's release:

Epic Marketplace is a large advertising network that has a presence on 45,000 websites.  Consumers who visited any of the network’s sites received a cookie, which stored information about their online practices including sites they visited and the ads they viewed.  The cookies allowed Epic to serve consumers ads targeted to their interests, a practice known as online behavioral advertising.   
In its privacy policy, Epic claimed that it would collect information only about consumers’ visits to sites in its network.  However, according to the FTC, Epic was employing history-sniffing technology that allowed it to collect data about sites outside its network that consumers had visited, including sites relating to personal health conditions and finances. 
According to the FTC complaint, the history sniffing was deceptive and allowed Epic to determine whether a consumer had visited any of more than 54,000 domains, including pages relating to fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy.
The technique used by Epic apparently combined two methods enabled by its cookie-placing network: seeing whether a user's browser program colored particular links to indicate they had been previously clicked, and accessing the cache (temporarily stored files) of the browser.

The proposed settlement order bars Epic from futher history sniffing, mandates full and accurate disclosure of Epic's information collection practices, and places restrictions and retention requirements on Epic's data collection and sharing. It does not, however, contain any financial penalties for Epic's conduct.

Wednesday, September 12, 2012

Thoughts on Education and Compliance re: Cookie Consent Law from UK's Information Commissioner's Office

Dave Evans, the Group Manager, Business and Industry for the UK's Information Commissioner's Office ("ICO") has posted a new blog entry discussing the ICO's efforts in both education and enforcement regarding the use of cookies by companies. The UK's law on cookies, passed in compliance with Article 5.3 of the EU's Data Protection Directive as it was revised in 2009, places specific requirements for organizations to obtain consent for placing and using cookie files on users' computers, and the ICO has previously published guidance on how to understand and follow the law.

In his September 10, 2012 blog entry, Evans discusses the two-prong approach the ICO has taken in connection with implementing the cookies law and regulations:

Broadly speaking, there’s two ways we go about this: an education programme to inform the industry, and enforcement work to ensure compliance.

So we’ve issued guidance and press releases, spoken at conferences, held meetings and workshops and even written to 75 of the most visited websites, asking what steps they had taken to achieve compliance and offering our help. We are working through the intelligence we have gathered to see if websites are taking action to increase the visibility of information about cookies, and already a fair number have.

But we’re balancing that with enforcement: for example, some sites have failed to engage with us at all, and they’re now being set a deadline to take steps towards compliance, with formal enforcement action likely if they fail to meet this deadline. Failure to act on an enforcement notice is a criminal offence.
This mirrors the approach taken by the U.S.' Federal Trade Commission ("FTC") in its privacy and data security activities, as with the moving deadlines and business education program around the Red Flags Rule. Both agencies understand that laws and regulations cannot fulfill their purposes if those who must comply with them are unaware of the requirements. In the privacy and data security area, this challenge is especially great for the numerous small and mid-sized businesses which may not have the personnel or other resources to keep abreast of either legal mandates or best practices. To reach those audiences, governmental agencies do well to partner with regional and local trade groups and educational institutions (such as Touro Law's Institute for Business, Law and Technology) to help spread the word.