Showing posts with label digital advertising. Show all posts
Showing posts with label digital advertising. Show all posts

Thursday, May 26, 2022

A Cautionary Tale About Secondary Use

Twitter has agreed to pay a $150,000,000 fine (13% of revenue) to settle FTC allegations that it enticed consumers into sharing personal information under false pretenses.

Twitter began asking people to provide emails and phone numbers in 2013, explaining that the information would help them reset accounts or enable two-factor authentication. However, over the years, the company used those email addresses and phone numbers as identifiers, sharing them with media agencies and ad networks to create audiences for online advertising.  The Federal Trade Commission viewed this as a "bait-and-switch" tactic in violation of Section 5 of the FTC Act.

When companies tell consumers they need data for certain reasons, and later use it for other reasons, it's called "secondary use," and it's frowned upon by regulators around the globe. Regulators insist on "purpose limitation," meaning that companies should only use personal data for the purposes that were described to the consumer at or before the time the data was collected or used. 
A new purpose that is very closely related to the original purpose might be acceptable, but it's a gray area that requires careful legal judgment. 

This is a good reminder that companies' consumer privacy disclosures should describe *every* likely use of personal data, *before* the data is collected or used.

If additional uses are later identified but are not closely related to the original purposes disclosed to consumers, companies must notify consumers of the new use (or ask for permission, depending upon the type of data and the jurisdiction) before using the data for the additional purpose.

 

image of the Federal Trade Commission Building

 

Saturday, June 23, 2018

California Lawmakers Make Last-Ditch Effort to Preempt Privacy Ballot Proposal

I recently wrote about a ballot initiative in California that, if approved by voters in November, will dramatically change privacy law in California (and very likely the rest of the United States).  Two days ago, a bill was introduced in the California legislature in an attempt to pre-empt the ballot initiative.  (Remember how I keep telling you how quickly things move in privacy law?!?!)




image of laptop with eyeball and written text California [If you have not already, read my summary and analysis of the ballot initiative first.]

California's deadline for collecting signatures for initiatives to be included on the ballot in the fall is June 28 (next week).  The Consumer Right to Privacy Act of 2018 (v.2, No. 17-0039) already has far more signatures than is necessary, and is almost certain to be eligible for inclusion on the ballot when the deadline arrives next week.  Many industries, and specifically the digital advertising industry, are scrambling to address it before it causes massive disruption (and opportunity?) in the digital marketing world.

Two days ago, on June 21, California lawmakers (from each house) introduced AB 375 in the Assembly, titled "The California Consumer Privacy Act of 2018" (which, if you are paying attention, you will notice has the same title as the ballot proposal...probably not by accident).  If this bill is adopted by the legislature and signed by the Governor before the ballot initiative's qualification deadline next week (6/28), the proponent of the ballot initiative has agreed to revoke the ballot proposal from consideration.

As you might imagine, the legislative bill intentionally includes several elements that are present in the ballot initiative, but is more friendly to business (especially digital marketing/advertising) in some ways than the ballot proposal.  Importantly, the bill would be enforced primarily by the California Attorney General, whereas the ballot initiative would  likely leave enforcement primarily to plaintiff's class action lawyers.  Penalties under the bill are limited to $100-750 per violation, and only for failing to protect data from a breach.  The bill also has important exclusions, such as data collected for one-time transactions, de-identified data, etc.  Based on my initial reading, the right of a consumer to opt out in the bill appears to apply only to data sales, not just data sharing for business purposes.  The proposal's prohibition on discriminating against consumers who opt out seems somewhat softened in the bill.


On the other hand, the bill seems to be a bit more rigorous in some ways (surprisingly!).  For example, the bill would require organizations to tell a consumer the "specific pieces" of personal information that have been collected about an individual Californian (not just the "categories" of information).  In addition, the bill includes a data deletion right similar to the EU concept of the "right to be forgotten" (but with several exceptions, some broad).