Showing posts with label Twitter. Show all posts
Showing posts with label Twitter. Show all posts

Saturday, March 15, 2014

How Financial Institutions Can Manage Social Media Risks

image by Matt Cordell using Creative Commons content BY-SA 3.0
Bankers, does your bank use social media? Do employees use social media on behalf of the bank? Do you know what examiners will be looking for in a social media risk assessment and a social media risk management program?

The Federal Financial Institutions Examination Council (FFIEC) has published guidance recently that will be used by the Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the Currency (OCC), the Board of Governors of the Federal Reserve System (Board), the National Credit Union Administration (NCUA), and the Consumer Financial Protection Bureau (CFPB) to evaluate financial institutions' compliance with various privacy and other laws and regulations.

What kinds of social media are covered?

The guidance defines "social media" as any form of interactive online communication in which users can generate and share content through text, images, audio, and/or video. Examples include micro-blogging sites (e.g., Facebook, Google Plus, MySpace, and Twitter), forums, blogs (e.g., BizLawNC.com or PrivacyLawNC.com), customer review web sites and bulletin boards (e.g., Yelp), photo and video sites (e.g., Flickr and YouTube), sites that enable professional networking (e.g., LinkedIn), virtual worlds (e.g., Second Life), and social games (e.g., Farmville). These platforms have a wide spectrum of uses, and their user profiles vary.

Financial institutions most often use social media for marketing directly to customers, but it can also be used to provide incentives, collect feedback from the public, recruit employees, and to otherwise engage with prospects and customers. Each of these efforts carries with it particular goals and varying types and degrees of risk.

The FFIEC Guidance states that every financial institution must conduct a risk assessment that addresses the risks raised by its use of social media and maintain a risk management program that is tailored to the risk profile. Every institution using social media should identify, measure, monitor,and control the risks related to social media.

How detailed should the policy statement be? How comprehensive should the procedures be?

The size and complexity of the program should be commensurate with the degree of the institution's involvement in social media, both in terms of depth and breadth. For example, a financial institution that relies heavily on one medium (e.g. Facebook) should have a more focused program. An institution using several media (e.g., Facebook, LinkedIn, Twitter, Yelp, Google +, and YouTube) should have procedures that are more comprehensive.

Who should be involved?

The FFIEC advises that a social media risk management program should be designed with participation from specialists in compliance, technology, information security, legal, human resources, and marketing. A better suggestion, in my opinion, is the inclusion of individuals whose expertise spans more than one of these categories. (Can you think of anyone who might know about more than one of these areas?)

What are the elements of a social media risk management program?

  • A governance structure with clear roles and responsibilities;
  • Policies and procedures (either stand-alone or incorporated into other policies and procedures) regarding the use and monitoring of social media and compliance with all applicable consumer protection laws and regulations;
  • A process for selecting and managing third-party relationships;
  • An employee training program;
  • An oversight process;
  • Audits to ensure ongoing compliance; and
  • Reporting to the board of directors or senior management to enable periodic evaluation of the program.

What are the key areas of risk?


What if we don't use social media at our bank?

Even financial institutions that do not use social media should perform a risk assessment, say the regulators: "a financial institution that has chosen not to use social media should still consider the potential for negative comments or complaints that may arise within the many social media platforms described above, and,when appropriate, evaluate what, if any, action it will take to monitor for such comments and/or respond to them." I have already written about online reputation management at length, and rather than repeat my advice here, I will refer you my earlier post on the subject.

Furthermore, just because an institution does not have an official social media account does not mean individual employees (especially those with business development responsibilities) are not posting on LinkedIn, Facebook, Twitter, and other platforms about, and apparently on behalf of, the the institution. It is unusual these days to find anyone in a sales role who is not active on social media.

Conclusion

The FFIEC Guidance is intended to help financial institutions understand and successfully manage (not eliminate) the risks associated with use of social media. The regulators expect institutions to manage potential risks to themselves and and their customers by identifying areas of risk proactively and adopting and implementing programs to mitigate those risks effectively...and more importantly, so do an increasing number of customers.




Wednesday, February 12, 2014

Does Your Website Privacy Policy Pass the Test?


In the past couple of years, Facebook, Twitter, and Google each settled disputes with the Federal Trade Commission ("FTC") relating to website privacy, and Google has reportedly paid $8.5 million to settle a class action suit based on similar privacy-based claims.  Even though actions against these Internet giants capture the headlines, all organizations, regardless of size, with websites can learn valuable lessons from the FTC's recent enforcement actions (as Upromise, Inc. learned in 2012 when the FTC took action against it on similar grounds).  The following discussion presents a high-level description of various aspects of website privacy law that organizations should not overlook:

Capturing Information

If your organization has a website that collects information in any way, including through an embedded "contact" form, or even cookies, you should strongly consider establishing a website privacy policy statement to protect your organization from liability.  Privacy policies are not just for large corporations and "web-based" companies.  A myriad of laws control what must be disclosed in a website privacy policy statement and how it is presented, as well as the underlying privacy practices.

Making Promises

Organization sometimes make promises in their website privacy statements that they fail to fulfill in practice.  Allegations of broken promises can be found in most of the FTC's recent enforcement actions in this area.  This is particularly unfortunate because, in many instances, the organization created an otherwise avoidable risk by establishing privacy standards that were stricter than the law required.  This type of risk is increased if an organization (or its third-party website designer) simply copies another organization's privacy policy statement without first understanding all of the legal and practical considerations that went into the original privacy statement, including what different or additional policies an organization may need to have because of the different ways in which it does business.  To be effective in protecting your organizationfrom liability, your website privacy policy statement must be tailored to your organization's own practices. 

Conducting Business On-Line  
If your organization does business through its website, it may well have additional financial privacy protection obligations and disclosure requirements under various federal and state financial privacy laws, particularly if credit is extended for online transactions.  Any organization engaging in credit transactions through its website needs to be aware of the many additional legal obligations created by the patchwork of financial privacy laws.

Protecting Children

Websites directed at children are subject to additional restrictions and requirements under the Children's Online Privacy Protection Act ("COPPA").  If your
organization's website, or a section of the website, is designed for children, COPPA disclosures and policies are necessary.

Opt-Out Requirements for Advertising

A federal law, the Controlling the Assault of Non-Solicited Pornography and Marketing Act, commonly known as the "CAN-SPAM Act," limits electronic advertising.  Although it is not a privacy law per se, it does require Internet and email advertisers to provide an opt-out mechanism for electronic marketing, among other things.  If your company advertises through its website or by email, you must have CAN-SPAM policies and an opt-out procedure.  It is customary and advisable to address the CAN-SPAM Act and opt-out rights in a website privacy policy.

Don't Forget State Laws

A few states have their own website privacy laws with which your organization must comply if you are directing your website to residents of any of those states.  For example, if your organization's website is directed at California residents, or at U.S. audiences generally, your website will need to comply with California's rules, which are reputed to be the most rigorous and which include specific requirements that go beyond the requirements of the federal rules.

Conclusion

Internet privacy is gaining increasing attention from governmental entities, consumer groups, and plaintiffs' class action attorneys, and is expected to be an emerging source of risk for many companies.  Fortunately, much of that risk is avoidable if care is taken to observe the patchwork of applicable legal requirements.