Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Wednesday, November 27, 2013

EU Calls for US to Restore Privacy Trust But Maintains Safe Harbor



On November 27th, 2013, the European Commission announced that it would not suspend the safe harbor agreement between the EU and the United States that has allowed cross-border personal data transfers between the two jurisdictions since 2000. The announcement followed the Edward Snowden revelations of U.S. surveillance activities, which prompted a number of public calls for suspension of the safe harbor by EU member states and statements by EU officials condemning the U.S.' reported practices.

In preserving (for now) the Safe Harbor, the EC nonetheless called for changes to U.S. governmental practices in order to "restore trust in EU-U.S. data flows." It released a Communication (strategy paper) on data flows between the regions, an analysis of how the Safe Harbor has functioned (and where it has failed), and other documents supporting its position. In the accompanying press release, the EC called for action in six key areas:

  • A swift adoption of the EU's data protection reform: the strong legislative framework, as proposed by the European Commission in January 2012 (IP/12/46), with clear rules that are enforceable also in situations when data is transferred and processed abroad is, more than ever, a necessity. The EU institutions should therefore continue working towards the adoption of the EU data protection reform by spring 2014, to make sure that personal data is effectively and comprehensively protected (see MEMO/13/923). 
  • Making Safe Harbour safer: the Commission today made 13 recommendations to improve the functioning of the Safe Harbour scheme, after an analysis also published today finds the functioning of the scheme deficient in several respects. Remedies should be identified by summer 2014. The Commission will then review the functioning of the scheme based on the implementation of these 13 recommendations. 
  • Strengthening data protection safeguards in the law enforcement area: the current negotiations on an “umbrella agreement” (IP/10/1661) for transfers and processing of data in the context of police and judicial cooperation should be concluded swiftly. An agreement must guarantee a high level of protection for citizens who should benefit from the same rights on both sides of the Atlantic. Notably, EU citizens not resident in the U.S. should benefit from judicial redress mechanisms. 
  • Using the existing Mutual Legal Assistance and Sectoral agreements to obtain data: The U.S. administration should commit to, as a general principle, making use of a legal framework like the mutual legal assistance and sectoral EU-U.S. Agreements such as the Passenger Name Records Agreement and Terrorist Financing Tracking Programme whenever transfers of data are required for law enforcement purposes. Asking the companies directly should only be possible under clearly defined, exceptional and judicially reviewable situations. 
  • Addressing European concerns in the on-going U.S. reform process: U.S. President Obama has announced a review of U.S. national security authorities’ activities. This process should also benefit EU citizens. The most important changes should be extending the safeguards available to US citizens to EU citizens not resident in the US, increased transparency and better oversight. 
  • Promoting privacy standards internationally: The U.S. should accede to the Council of Europe’s Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (“Convention 108”), as it acceded to the 2001 Convention on Cybercrime. 
The complete collection of the EC's materials accompanying the announcement may be found here.

Wednesday, November 20, 2013

Proposed USA FREEDOM Act Seeks to Limit NSA’s Reach


Photo courtesy of Electronic Frontier Foundation 
(https://supporters.eff.org/shop/illegal-spying-eagle-sticker)


 On October 29, 2013, Senator Patrick Leady (D-VT) and Representative Jim Sensenbrenner (R-WI) introduced a new NSA reform bill into both the House of Representatives and the Senate.  As of this writing, the act has 16 co-sponsors in the Senate and over 70 in the House.  The bill is called the Uniting and Strengthening America by Fulfilling Rights and Ending Eavesdropping, Dragnet-collection and Online Monitoring Act, or the USA FREEDOM ACT for short.  The goal of the act is to drastically limit the ability of the National Security Agency to collect information of United States citizens.  As stated in the bill’s official summary:

The bipartisan, bicameral USA FREEDOM Act will rein in the dragnet collection of data by the National Security Agency (NSA), increase the transparency of Foreign Intelligence Surveillance Court (FISA Court) decision-making, provide businesses the ability to release information regarding FISA requests, create an independent advocate to argue cases before the FISA Court, and impose new and shorter sunsets on controversial surveillance authorities.

Introduction of the bill comes amidst increasing concern of the NSA’s surveillance practices conducted on both American soil and abroad.   Prior to the leak committed by former intelligence analyst Edward Snowden last spring, the true scope of the NSA’s operations was unknown.  Now, it has been revealed that many of the NSA’s operations are being conducted with little judicial oversight and may even breach constitutional boundaries.  So far, Snowden’s leak has revealed that the NSA collects the metadata of millions of American citizens.  Metadata is information about the time and location of a phone call or email.  Though the contents of the call or email are not surveyed, it has been argued that collecting metadata infringes on Americans expectations of privacy and can reveal facts many citizens would not wish to disclose.  Also, pursuant to the 2008 FISA Amendments Act, these collections can be conducted without a warrant as long as one end of the communications is a non-US citizen, or if surveillance is sought over a US citizen located outside the country.  For matters concerning U.S. citizens at home, the NSA must request a warrant from a FISA (Foreign Intelligence Surveillance Act) court.  The FISA court sits ex parte- meaning that only the judge and the government are present at the hearings.  There is no attorney present to advocate against the granting of a surveillance warrant.  Since the court was established in 1978, the court has rejected only .03% of all government surveillance requests.

It has furthermore been revealed that through a program known as PRISM, the agency can collect data from major Internet companies such as Google, Facebook, Apple, Yahoo, and Skype.  Through PRISM, the NSA can collect content such as e-mail, videos, photos, file transfers, social network details, and even voice samples.  Many of these Internet companies claim that they are compelled by law to release this data in cooperation with the NSA, and have lobbied Congress for the right to disclose to the public exactly how many of its members are affected by the NSA’s data collection requests.  The goal of this transparency is to help the Internet companies regain the trust of its users and dispel any notions that the government has direct access to these companies’ servers.

Ironically, much of the NSA’s current powers were granted under the Patriot Act of 2001, which was written in part by Representative Jim Sensenbrenner, co-writer of the USA FREEDOM Act.  The USA FREEDOM Act seeks to limit the scope of the NSA’s powers by amending certain sections of the Patriot Act as well as the Foreign Intelligence Surveillance Act (FISA).  The act seeks to end the bulk collection of American metadata, place a “Special Advocate” to be present at FISA court hearings to dispute government surveillance requests, and allow companies to disclose an estimate of the number of FISA orders and National Security Letters they have received, the number they complied with, and the number of users and accounts impacted.  

The USA FREEDOM ACT’s complete text can be found here.

(Blog entry written by Alex Diamond, IBLT/Carter DeLuca Entrepreneurship Support Fellow for the Fall 2013 semester)

Wednesday, October 30, 2013

Facebook Loosens Privacy Policy for Teens


On October 16, 2013, Facebook gave teenagers (age 13-17) the option of sharing their videos, pictures, and status updates with the general public. Previously, people aged 13-17 only had the option of sharing with people designated as “Friends” of their social network and “Friends of Friends.” In a statement on Facebook’s website, the company touted the new freedoms it was affording its teenage users:

Teens are among the savviest people using social media, and whether it comes to civic engagement, activism, or their thoughts on a new movie, they want to be heard. So, starting today, people aged 13 through 17 will also have the choice to post publicly on Facebook.

Teenagers will also be able to turn on the “Follow” feature for their profile, allowing any Facebook member (Friends or otherwise) to see the teen’s public posts in the main news feed. To balance these less strict settings, Facebook has implemented two new privacy protection measures for teenagers as well. Now, when a teenager signs up for a Facebook account, by default their posts will only be shown to their “Friends.” Previously, posts where shown to “Friends” and “Friends of Friends” by default. Also, when a teen chooses to share their posts with the general public, they will be presented with a pair of warnings. One warning reads:

Did you know that public posts can be seen by anyone, not just people you know?


You and any friends you tag could end up getting friend requests and messages from people you don’t know personally.

Following acceptance of the above warning, the user will be presented with another warning, which states:

Tip: Sharing with Public means anyone (not just people you know) may see your post.

It is likely that Facebook has opted to ease the privacy restrictions on teenagers to compete with other social networks such as Twitter and Tumblr, which allow teenagers to share with the public. In Facebook’s 10-K Report filed with the Securities Exchange Commission last February, the company expressed concerns that “younger users, are aware of an actively engaging with other products and services similar to, or as a substitute for, Facebook.”


Critics fear that Facebook’s new policy affords teenagers too much freedom and puts them at risk. Indeed, users who choose to share with the general public run the risk of being contacted and/or solicited by complete strangers. Also, teenagers that choose to share their images, statuses, and videos with the general public are burdened with the fact that any ill-advised posts may come back to haunt them, either professionally or otherwise.

(Blog entry written by Alex Diamond, IBLT/Carter DeLuca Entrepreneurship Support Fellow for the Fall 2013 semester)

Ezor on Secure Times: Recent FTC Actions and Statements Show Continuing Focus on Privacy

IBLT Director Jonathan I. Ezor is blogging this week at the American Bar Association Privacy & Security Law Committee's Secure Times blog. His first contribution is below:

Recent FTC Actions and Statements Show Continuing Focus on Privacy

The Federal Trade Commission has long taken a lead role in issues of privacy and data protection, under its general consumer protection jurisdiction under Section 5 of the FTC Act (15 U.S.C. §45) as well as specific legislation such as the Children's Online Privacy Protection Act of 1998 ("COPPA") (which itself arose out of FTC reports). The FTC continues to bring legal actions against companies it believes have improperly collected, used or shared consumer personal information, including the recent settlement of a complaint filed against Aaron's, Inc., a national rent-to-own retail chain based in Atlanta, GA. In its October 22, 2013 press release announcing the settlement, the FTC described Aaron's alleged violations of Section 5:
Aaron’s, Inc., a national, Atlanta-based rent-to-own retailer, has agreed to settle FTC charges that it knowingly played a direct and vital role in its franchisees’ installation and use of software on rental computers that secretly monitored consumers including by taking webcam pictures of them in their homes. According to the FTC’s complaint, Aaron’s franchisees used the software, which surreptitiously tracked consumers’ locations, captured images through the computers’ webcams – including those of adults engaged in intimate activities – and activated keyloggers that captured users’ login credentials for email accounts and financial and social media sites.... The complaint alleges that Aaron’s knew about the privacy-invasive features of the software, but nonetheless allowed its franchisees to access and use the software, known as PC Rental Agent. In addition, Aaron’s stored data collected by the software for its franchisees and also transmitted messages from the software to its franchisees. In addition, Aaron’s provided franchisees with instructions on how to install and use the software. The software was the subject of related FTC actions earlier this year against the software manufacturer and several rent-to-own stores, including Aaron’s franchisees, that used it. It included a feature called Detective Mode, which, in addition to monitoring keystrokes, capturing screenshots, and activating the computer’s webcam, also presented deceptive “software registration” screens designed to get computer users to provide personal information.
The FTC's Consent Order Agreement with Aaron's includes a prohibition on the company using keystroke- or screenshot-monitoring software or activating the consumer's microphone or Web cam and a requirement to obtain express consent before installing location-tracking technology and provide notice when it's activated. Aaron's may not use any data it received through improper activities in collections actions, must destroy illegally obtained information, and must encrypt any transmitted location or tracking data it properly collects. The FTC is also continuing its efforts to educate and promote best practices about privacy for both consumers and businesses. On October 28, 2013, FTC Commissioner Julie Brill published an opinion piece in Advertising Age magazine entitled Data Industry Must Step Up to Protect Consumer Privacy. In the piece, Commissioner Brill criticizes data collection and marketing firms for failing to uphold basic privacy principles, and calls on them to join an initiative called "Reclaim Your Name" which Commissioner Brill announced earlier this year. Brill writes in AdAge:
The concept is simple. Through creation of consumer-friendly online services, Reclaim Your Name would empower the consumer to find out how brokers are collecting and using data; give her access to information that data brokers have amassed about her; allow her to opt-out if a data broker is selling her information for marketing purposes; and provide her the opportunity to correct errors in information used for substantive decisions. Improving the handling of sensitive data is another part of Reclaim Your Name. Data brokers that participate in Reclaim Your Name would agree to tailor their data handling and notice and choice tools to the sensitivity of the information at issue. As the data they handle or create becomes more sensitive -- relating to health conditions, sexual orientation and financial condition, for example -- the data brokers would provide greater transparency and more robust notice and choice to consumers.
For more information on the FTC's privacy guidance and enforcement, see the privacy and security section of the FTC Web site.

Thursday, October 10, 2013

Got an Internet Business Law Question? Ask the IBLT!


The Touro Law Center for Innovation in Business, Law and Technology ("IBLT") proudly announces "Ask the IBLT," a new initiative to help entrepreneurs and others better understand the business-critical issues of Internet-related law and risk management. Anyone can e-mail a question to asktheiblt@tourolaw.edu. The IBLT will provide answers (prepared by Touro Law students and IBLT faculty affiliates) through its blog, YouTube channel, Google+ page, Facebook page, Twitter account and other channels.

Among the topics for questions for the IBLT are:

  • Privacy and data breaches
  • Social media use (and misuse)
  • Intellectual property (copyright, trademark, patent, trade secrets)
  • Online advertising and marketing
  • Affiliate programs
  • Sweepstakes, contests and other prize promotions
  • Cybercrime
  • Crowdsourcing
  • Crowdfunding
  • International law


"Ask the IBLT is just one part of our overall mission to educate our students and the business and legal communities about these new and evolving areas of law and risk," says Prof. Jonathan I. Ezor, director of the IBLT. "We can't answer every question, and we won't be giving specific legal advice. Instead, we're answering those questions that apply to the most organizations, and offering information and links to resources they can use to succeed and grow while avoiding the biggest pitfalls of doing business online."

Wednesday, February 6, 2013

Mobile Application Privacy: NTIA Publishes Latest Multistakeholder Transparency Draft for Comment


The National Telecommunications and Information Administration ("NTIA"), part of the U.S. Department of Commerce, has been convening multistakeholder meetings to work on improvements to data collection/use transparency--an effort called for in the Obama Administration's Consumer Privacy Bill of Rights. On February 4th, 2013, the NTIA released the latest discussion draft of its Code of Conduct for Mobile Application Transparency. The goals of this initiative, as stated in the latest draft, are to "balance the objectives of transparency, brevity and functionality," or more specifically:


  • Transparency: Consumers expect clear, succinct explanations of an app’s data collection and third party data sharing policies.
  • Brevity: Short form notices must enhance app transparency and understanding in context.
  • Functionality: App developers need transparency standards that they can easily implement in the context of an app without diminishing the user experience.
  • Consumers hold a spectrum of attitudes towards sharing their data with apps. Consumers’ willingness to share data will vary with context and time, and apps should facilitate those choices.
  • Regulators, legislators, and privacy and consumer advocates all seek a fair balance among all of the interests involved, recognizing some consumers’ choice to share data with apps in exchange for a wide variety of tools, content, entertainment.
  • Apps will evolve over time to offer fixes, enhancements, and changes to the original functionality. Apps may need to offer new functionality and/or they may need to adapt their business models. When apps’ data policies evolve in material ways, the apps must promptly and prominently update their disclosures to consumers.
  • Continued work will need to be done to help integrate the full range of fair information practices with effective methods of transparency for innovative data uses. App developers understand that the implementation of these principles is just one aspect of satisfying consumer expectations and they commit to leading their industry to develop common practices and tools that adhere to fair information practices (these principles include access to personal information, control over storing information and sharing it with third parties).
  • App Developers who adhere to this code of conduct and provide short form notice as described in Section II, are engaging in a best practice that significantly enhances transparency of data practices. This code reflects the state of industry best practices for transparency. Although compliance with the code and provision of a short form notice does not guarantee that any individual developer is providing an accurate notice for their specific practices, the authors of this code believe that compliance with the standardization provided by this notice should be a compelling factor serving to limit claims that a notice is deficient.
According to John Verdi, Director of Privacy Initiatives for the NTIA,comments and proposed changes on the latest discussion draft should be sent either to Tim Sparapani or Verdi himself by February 18, 2013. Verdi further states that "[c]omments from prospective adopters are particularly encouraged!"

The informational page for the multistakeholder process on moible application transparency, including meeting schedules and other relevant links, may be found here.

Monday, February 4, 2013

New Article: Privacy, Transparency and Google's Blurred Glass


I have just posted a new short article, Privacy, Transparency and Google's Blurred Glass, which looks at Google's privacy disclosures and how they may fall short of being as transparent as Google (and many others) would wish. The piece can be downloaded (as a PDF) from this link. Comments and questions are always welcome.

Friday, February 1, 2013

Path Pays $800,000 to FTC for Alleged Privacy Violations


On the same day that the FTC released its new report on mobile privacy, the Commission also announced its latest online mobile privacy enforcement action, an $800,000 settlement with the operator of the Path social networking app. According to the FTC's news release:
Path operates a social networking service that allows users to keep journals about “moments” in their life and to share that journal with a network of up to 150 friends.  Through the Path app, users can upload, store, and share photos, written “thoughts,” the user’s location, and the names of songs to which the user is listening.

In its complaint, the FTC charged that the user interface in Path's iOS app was misleading and provided consumers no meaningful choice regarding the collection of their personal information.  In version 2.0 of its app for iOS, Path offered an “Add Friends” feature to help users add new connections to their networks.  The feature provided users with three options: “Find friends from your contacts;” “Find friends from Facebook;” or “Invite friends to join Path by email or SMS.”  However, Path automatically collected and stored personal information from the user’s mobile device address book even if the user had not selected the “Find friends from your contacts” option.  For each contact in the user’s mobile device address book, Path automatically collected and stored any available first and last names, addresses, phone numbers, email addresses, Facebook and Twitter usernames, and dates of birth.
The FTC also alleged that Path’s privacy policy deceived consumers by claiming that it automatically collected only certain user information such as IP address, operating system, browser type, address of referring site, and site activity information.  In fact, version 2.0 of the Path app for iOS automatically collected and stored personal information from the user’s mobile device address book when the user first launched version 2.0 of the app and each time the user signed back into the account.

The agency also charged that Path, which collects birth date information during user registration, violated the Children’s Online Privacy Protection Act (COPPA) Rule by collecting personal information from approximately 3,000 children under the age of 13 without first getting parents’ consent.  Through its apps for both iOS and Android, as well as its website, Path enabled children to create personal journals and upload, store and share photos, written “thoughts,” their precise location, and the names of songs to which the child was listening.  Path version 2.0 also collected personal information from a child’s address book, including full names, addresses, phone numbers, email addresses, dates of birth and other information, where available....
The case documents may be found here.

The FTC has been actively enforcing violations of children's privacy for more than ten years, and is explicitly increasing its enforcement activities in mobile privacy and data security. (The FTC recently announced changes to its COPPA rule, but those have not yet gone into affect; the Path enforcement arises out of the current rule.) This latest action is consistent with the Commission's ongoing efforts to both encourage proper practices with regard to consumers' personal information, and punish those firms that fail to appropriately respect privacy and data security.

Thursday, January 31, 2013

Bird Watching: Twitter's Transparency Report


Following in the example of Google, Twitter is also releasing a semi-annual Transparency Report disclosing the number and type of user information requests it receives from various governments, and the percentage of the requests to which Twitter responded positively. In its most recent report, covering July through December 2011, Twitter stated that it had received 1,009 information requests, 42 content removal requests, and 3,268 takedown and related notices regarding alleged copyright infringement on the service. The former two numbers were up substantially from the preceding six month period; the copyright notices declined slightly (from 3,378 to 3,268) in that time.

Twitter additionally broke down the data by country, and specifically focused on its home country, the United States. According to Twitter, requests from governmental bodies within the United States from July through December 2012 included the following:

User Information RequestsPercentage where some or all information producedUser / Accounts SpecifiedSubpoenasCourt OrdersSearch WarrantsOthers
81569%114560%11%19%10%

As with that of Google, Twitter's transparency report is a useful reminder both of the attractiveness of social media services to governmental information gathering, as well as the overall privacy issues arising out of social media use. Law enforcement and other government officials understand how much information people share on social media services; it's crucial for users to understand this as well.

Thursday, January 24, 2013

The Other Google Search: 8438 Data Requests by U.S. Gov't


Google has released the latest version of its Transparency Report, covering the period from July 1 through December 31, 2012. In the report, Google states that the U.S. government made 8,438 requests of user data from Google during the period, covering a reported 14,791 users/accounts, and that Google responded fully or partially to an aggregate of 88% of those requests, broken down as follows:

July to December 2012

Records Requested

Users/Accounts

Percentage Fully/Partially Complied With

Search Warrant

1,896

3,152

88%

Subpoena

5,784

10,390

88%

Other 

758

1,249

90%

The number of of these requests, particularly from the U.S. government, has been steadily increasing over the past few years; the U.S. government made only 3,580 total requests in the same period in 2009. Google states in the introduction to its report, "We review each request to make sure that it complies with both the spirit and the letter of the law, and we may refuse to produce information or try to narrow the request in some cases." It also attributes some of the increase to its own growth: "Usage of our services have increased every year, and so have the user data request numbers."

While Google is to be commended for its efforts to disclose (some of) the requests for information it receives, the report and the increases it shows serve as a reminder of the size, scope and value of Google's collection of data about its users. Given how many products Google owns, many of which may not bear obvious Google branding (such as the Zagat Restaurant Guide) but may still be feeding user data into Google's central servers (Zagat's privacy policy is the Google shared one, as is that of its fellow non-obvious Google acquisition, the Frommer's Travel Guides site), one may legitimately question whether all users are able to provide truly informed consent to Google's data collection, which is increasingly a governmental resource as well.

Thursday, January 3, 2013

$50,000 HIPAA Security Violation Settlement Announced by HHS OCR


On January 2, 2013, the Office of Civil Rights of the U.S. Department of Health and Human Services ("OCR") announced its first-ever settlement of a health privacy violation case involving information from fewer than 500 individuals. According to OCR, the Hospice of North Idaho will pay $50,000 to settle the case brought under the Security Rule of the Health Insurance Portability and Accountability Act of 1996 ("HIPAA").

According to the OCR's press release,
The HHS Office for Civil Rights (OCR) began its investigation after HONI reported to HHS that an unencrypted laptop computer containing the electronic protected health information (ePHI) of 441 patients had been stolen in June 2010. Laptops containing ePHI are regularly used by the organization as part of their field work. Over the course of the investigation, OCR discovered that HONI had not conducted a risk analysis to safeguard ePHI. Further, HONI did not have in place policies or procedures to address mobile device security as required by the HIPAA Security Rule. Since the June 2010 theft, HONI has taken extensive additional steps to improve their HIPAA Privacy and Security compliance program.

“This action sends a strong message to the health care industry that, regardless of size, covered entities must take action and will be held accountable for safeguarding their patients’ health information.” said OCR Director Leon Rodriguez. “Encryption is an easy method for making lost information unusable, unreadable and undecipherable.”

The Health Information Technology for Economic and Clinical Health (HITECH) Breach Notification Rule requires covered entities to report an impermissible use or disclosure of protected health information, or a “breach,” of 500 individuals or more to the Secretary of HHS and the media within 60 days after the discovery of the breach. Smaller breaches affecting less than 500 individuals must be reported to the Secretary on an annual basis. 
The release also discussed a new joint educational effort by OCR and the HHS Office of the National Coordinator for Health Information Technology entitled Mobile Devices: Know the RISKS. Take the STEPS. PROTECT and SECURE Health Information.

The resolution agreement for the Hospice of North Idaho case can be read here. For more information on both the HIPAA Privacy Rule and HIPAA Security Rule, visit HHS' main HIPAA page. OCR also offers an e-mail distribution list for its privacy-related activities, OCR-PRIVACY-List, available via this link.

Tuesday, December 18, 2012

FTC Orders 9 Data Brokers to Provide Info on Privacy Practices

The FTC announced today that it had issued orders to nine data brokers to disclosure how they collect and use consumer data. This is consistent with earlier guidance from the FTC, which recommended legislation targeting the data broker industry in its March 2012 Report on Protecting Consumer Privacy:



[T]he Commission recommends that Congress consider enacting targeted legislation to provide greater transparency for, and control over, the practices of information brokers. The proposed framework recommended that companies provide consumers with reasonable access to the data the companies maintain about them, proportionate to the sensitivity of the data and the nature of its use. Several commenters discussed in particular the importance of consumers’ ability to access information that information brokers have about them. These commenters noted the lack of transparency about the practices of information brokers, who often buy, compile, and sell a wealth of highly personal information about consumers but never interact directly with them. Consumers are often unaware of the existence of these entities, as well as the purposes for which they collect and use data.
The Commission agrees that consumers should have more control over the practices of information brokers and believes that appropriate legislation could help address this goal. Any such legislation could be modeled on a bill that the House passed on a bipartisan basis during the 111th Congress, which included a procedure for consumers to access and dispute personal data held by information brokers.
According to today's release, the FTC will use the information provided by the nine data brokers "to prepare a study and to make recommendations on whether, and how, the data broker industry could improve its privacy practices." The FTC's orders (in PDF format) may be downloaded here.

Wednesday, December 12, 2012

Peter Fleischer, Other Google Execs Still May Face Jail in Italy Privacy Case

AP Image of trial court via KLEWTV.com
 In the latest installment in a case that highlights both the legal risks and absurdity of the cross-border nature of the Internet, the Milanese prosecutor in the case against Peter Fleischer and two other Google executives has asked an appeals court to uphold the six-month jail sentences they received in a criminal privacy case. The case arose out of a 2006 posting to Google Video by Italian teenagers of a short video of a learning-disabled classmate. Although none of the executives had any involvement with the posting or its prompt removal by Google Video after notification, they were still charged (along with another colleague, later acquitted) of violations of Italian privacy law. Fleischer, who was then Google's chief privacy counsel in Europe, was arrested when he traveled from his Paris office to Italy to give a lecture in January 2009. After the case came to trial, Fleischer and two of his colleagues (including Google's chief legal officer, David Drummond) were convicted in February 2010 and given six month sentences, automatically suspended under Italian law. The case was then appealed, leading to the latest development.

Fleischer, in a recent blog entry about the appeal, describes both the facts and the illogical nature of the case against him, given that he and his colleagues had nothing to do with the incident:

Under European law, hosting platforms that do not create content, such as Google Video, YouTube, Bebo, Facebook, and even university bulletin boards, are not legally responsible for the content that others upload onto these sites. But in this instance, a public prosecutor in Milan decided to charge us with criminal defamation and a failure to comply with the Italian privacy code.  None of us, however, had anything to do with this video. We did not appear in it, film it, upload it or review it. None of us knew the people involved or were even aware of the video's existence until after it was removed.
 This case, similar in many ways to the action in Germany against Compuserve's Felix Somm in 1996, serves as a stark reminder that those associated with companies doing business online may find themselves facing personal liability or even prosecution based on the laws of other countries, even when the individuals had no connection with the activity in question, and even when the activity was fully legal under the laws of the jurisdiction in which the company is based. While it is impossible to research and be certain of compliance with every relevant law in every possible country with access to the Internet, those who work for high-profile businesses, especially companies whose activities may potentially violate particular nations' cultural norms, should at the least be aware of these risks when considering business or personal travel to other regions. Companies, for their part, must include these risks in their overall assessments when choosing to do business online.

Wednesday, December 5, 2012

FTC Settles With Online Marketer Over "History Sniffing"



The Federal Trade Commission ("FTC"), the chief federal agency for consumer protection, has announced a proposed settlement with online marketer Epic Marketplace, Inc., over what the Commission called a "deceptive" use of a technology called "history sniffing." According to the FTC's release:

Epic Marketplace is a large advertising network that has a presence on 45,000 websites.  Consumers who visited any of the network’s sites received a cookie, which stored information about their online practices including sites they visited and the ads they viewed.  The cookies allowed Epic to serve consumers ads targeted to their interests, a practice known as online behavioral advertising.   
In its privacy policy, Epic claimed that it would collect information only about consumers’ visits to sites in its network.  However, according to the FTC, Epic was employing history-sniffing technology that allowed it to collect data about sites outside its network that consumers had visited, including sites relating to personal health conditions and finances. 
According to the FTC complaint, the history sniffing was deceptive and allowed Epic to determine whether a consumer had visited any of more than 54,000 domains, including pages relating to fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy.
The technique used by Epic apparently combined two methods enabled by its cookie-placing network: seeing whether a user's browser program colored particular links to indicate they had been previously clicked, and accessing the cache (temporarily stored files) of the browser.

The proposed settlement order bars Epic from futher history sniffing, mandates full and accurate disclosure of Epic's information collection practices, and places restrictions and retention requirements on Epic's data collection and sharing. It does not, however, contain any financial penalties for Epic's conduct.

Wednesday, November 28, 2012

Mobile App Privacy: A Slowly Expanding Area

The area of consumer privacy is a broad area that has been discussed, analyzed and given guidance by both the Federal Trade Commission and the White House. Mobile application privacy, an important subset of consumer privacy, is an area of privacy that has been receiving significant attention over the past year as the importance of the mobile platform increases.

The push for protection in mobile app privacy most clearly began with a Joint Statement of Principles laid out by the California Attorney General, created in February 2012. The California Joint Principles represent an agreement by several top companies in the mobile industry. The agreement, which includes Apple, Google, Research In Motion, HP, and Microsoft (in addition to Facebook, which signed on in June), states what these companies promise to do in their mobile app store. The agreement reached by the major mobile companies provides that the California Online Privacy Protection Act is applicable to any application that collects personal data from a consumer. Such an app requires a “conspicuously posted” privacy policy. The agreement provides that when an app is submitted to a mobile app store by the developer there should be a hyperlink to the privacy policy or the actual privacy policy for that particular app. The privacy policy, whether a hyperlink or the full text, should be available in the mobile app store prior to download of the app. The major mobile companies must also provide a method for users to report apps that do not have such a policy or whose policy does not comply with applicable law.

In addition to the Joint Principles, the FTC has released a new Report on marketing mobile applications, in September of 2012, that contains suggestions on how to limit privacy concerns in a mobile app.  The FTC suggests that mobile app creators:

Build privacy considerations in from the start.  The FTC calls this “privacy by design.”… Incorporating privacy protections into your practices, limiting the information you collect, securely storing what you hold on to, and safely disposing of what you no longer need.  Apply these principles in selecting the default settings for your app and make the default settings consistent with what people would expect based on the kind of app you’re selling.  For any collection or sharing of information that’s not apparent, get users’ express agreement.  That way your customers aren’t unwittingly disclosing information they didn’t mean to share.
Be transparent about your data practices….Offer choices that are easy to find and easy to use…Honor your privacy promises…The FTC has taken action against dozens of companies that claimed to safeguard the privacy or security of users’ information, but didn’t live up to their promises in the day-to-day operation of their business.  The FTC also has taken action against businesses that made broad statements about their privacy practices, but then failed to disclose the extent to which they collected or shared information with others – like advertisers or other app developers…Protect kids’ privacy…
Collect sensitive information only with consent.  Even when you’re not dealing with kids’ information, it’s important to get users’ affirmative OK before you collect any sensitive data from them, like medical, financial, or precise geolocation information.  It’s a mistake to assume they won’t mind.
Keep user data secure...The wisest policy is to:
  •  collect only the data you need;
  • secure the data you keep by taking reasonable precautions against well-known security risks;
  • limit access to a need-to-know basis; and
  • safely dispose of data you no longer need.
As mobile app privacy is a new and growing area, the actual implications on businesses are not yet clear. The California Joint Statements only require that those mobile app store providers will provide a location for the individual app’s privacy policy. This only implicitly requires that mobile app creators should have a privacy policy. The FTC guidelines are less stringent. As stated in its report on consumer privacy, the FTC does not believe that they have the powers, at this time, to broadly regulate the area of privacy. However, the FTC suggestions show what the the Commission might enforce if given the power to do so by Congress.

(Written by Brett Alazraki, Fall 2012 IBLT Entrepreneurship Assistance Fellow)