Showing posts with label internet privacy. Show all posts
Showing posts with label internet privacy. Show all posts

Thursday, May 26, 2022

A Cautionary Tale About Secondary Use

Twitter has agreed to pay a $150,000,000 fine (13% of revenue) to settle FTC allegations that it enticed consumers into sharing personal information under false pretenses.

Twitter began asking people to provide emails and phone numbers in 2013, explaining that the information would help them reset accounts or enable two-factor authentication. However, over the years, the company used those email addresses and phone numbers as identifiers, sharing them with media agencies and ad networks to create audiences for online advertising.  The Federal Trade Commission viewed this as a "bait-and-switch" tactic in violation of Section 5 of the FTC Act.

When companies tell consumers they need data for certain reasons, and later use it for other reasons, it's called "secondary use," and it's frowned upon by regulators around the globe. Regulators insist on "purpose limitation," meaning that companies should only use personal data for the purposes that were described to the consumer at or before the time the data was collected or used. 
A new purpose that is very closely related to the original purpose might be acceptable, but it's a gray area that requires careful legal judgment. 

This is a good reminder that companies' consumer privacy disclosures should describe *every* likely use of personal data, *before* the data is collected or used.

If additional uses are later identified but are not closely related to the original purposes disclosed to consumers, companies must notify consumers of the new use (or ask for permission, depending upon the type of data and the jurisdiction) before using the data for the additional purpose.

 

image of the Federal Trade Commission Building

 

Thursday, October 8, 2020

A New Technology for Web Browser Opt-Outs Could Trigger New Legal Requirements

If your organization has a website directed at California consumers (or US consumers generally), you should start thinking about this soon: A group has developed the technology to honor web browsers’ privacy signals, which could have implications under the California Consumer Privacy Act.

The California Online Privacy Protection Act of 2003 (CalOPPA) was the first broadly-applicable consumer privacy statue in the US. It merely required companies to have website privacy policy statements and to state clearly whether or not they would honor “Do Not Track” signals from a user’s web browser; it did not require companies to honor those signals.

The lawmakers assumed that technology would be created to honor those opt-out signals, and that companies would be pressured by market forces to honor them, but that never really happened.  It has been almost impossible to honor those signals until now, and as a result, almost all US-facing websites have a privacy policy statement that says “we do not recognize browsers’ Do Not Track signals.”

California's Attorney General, which enforces CalOPPA, was not satisfied with industry's failure to develop the technology and honor Do Not Track signals.  When the AG released regulations under the California Consumer Privacy Act, which became enforceable in mid-August, he included a provision that says that companies must honor browsers’ privacy signals as a valid Do Not Sell instruction…even though the technology doesn’t yet exist. T
he AG explained that the requirement "is forward-looking and intended to encourage innovation and the development of technological solutions to facilitate and govern the submission of requests to opt-out." Section 999.315 of the regulations says "[i]f a business collects personal information from consumers online, the business shall treat user-enabled global privacy controls, such as a browser plug-in or privacy setting, device setting, or other mechanism, that communicate or signal the consumer’s choice to opt-out of the sale of their personal information as a valid request submitted pursuant to Civil Code section 1798.120 for that browser or device, or, if known, for the consumer." [emphasis added]

Now, it appears a group of companies and nonprofits, including the Electronic Frontier Foundation and DuckDuckGo have developed the technology, calling it the Global Privacy Control framework.  THe express intent, according to the creators is "to communicate a Do Not Sell request from a global privacy control, as per CCPA-REGULATIONS §999.315." It is already available in beta in certain browser updates or as add-on browser scripts, and consumers will begin sending those signals all over the Internet.  Companies will  be under tremendous pressure to adopt the technology framework and begin honoring the signals quickly.

 It is not yet perfectly clear if and when the GPC would be treated as a legally binding Do-Not-Sell instruction.  Here's why:

  • It is not clear whether the AG had the authority to include this requirement in section 315 of the regulations.  The global privacy control concept is not expressly stated in the CCPA, although the DOJ and Office of Administrative Laws obviously felt the authority was there.  The delegation of authority to the AG in Section 1798.185(a)(7) is broad.
  • Competing frameworks could develop. It is not clear who will decide whether a framework is "official" or "enforceable."  Perhaps a formal endorsement of the California Attorney General is required.  California's Attorney General has informally endorsed the GPC framework via Twitter.
  • Right now the GPC framework is not a finalized standard, according to the website.  It's still being tested.  It is not certain when it would be finalized.

Because the CCPA's definition of "sale" is so broad, and could be interpreted to cover technologies that are ubiquitous across the web (such as third-party advertising cookies), the GPC could affect large numbers of website operators.

Key Point: Companies covered by CCPA should begin thinking now about whether and how to implement this new technical framework. 

Monday, March 11, 2019

Will the "Washington Privacy Act" be the aftershock to the CCPA's seismic shift?


Washington State Outline




California has been getting most of the attention lately for the California Consumer Privacy Act, but Washington may be following closely behind with its own bold new privacy statute.  Senate Bill 5376 has been approved by the state's Senate and is currently before the House (in the Environment, Energy & Technology Committee as of the date of this post).  The current version can be viewed here

"Washingtonians cherish privacy as an element of their individual freedom..." the bill begins (somewhat awkwardly), and takes off from there.  Briefly, here are some highlights:
  • Jurisdiction resembles the CCPA. It applies to entities that conduct business in Washington or intentionally target residents if they (a) processes personal data of 100,000 consumers; or(b) derives over fifty percent of gross revenue from the sale of personal data and process personal data of 25,000 consumers.
  • The controller/processor paradigm is clearly set out, reflecting the influence of HIPAA and international laws.  Controllers and processors share liability under a "comparative fault" framework.
  • Access, correction, and deletion rights are all specifically conferred (not unlike CCPA and GDPR).  These are each subject to "verification" of the request.  
  • Consumers have a right to information regarding a controller's sharing of their data (by category) with processors, and processors must cooperate with controllers to fulfill opt-out, correction, and deletion requests from consumers. 
  • Consumers are given the specific right to opt out of "targeted advertising" by controllers, and third-party processors must honor the request.
  • Consumer requests should be fulfilled within 30 days, but the timeline can be extended by 60 days if necessary. 
  • Risk assessments (similar to privacy impact assessments) are mandated for all new processing of personal information or material changes.  This is not limited to processing of sensitive data.  If the risks are substantial, consumer consent is required.  The AG may inspect risk assessments, but otherwise they are confidential.
  • There are healthcare carve-outs; it doesn't appear to be intended to overlap with HIPAA.
  • The use of facial recognition (a) for decision-making with "significant effects" or (b) by the government is specifically restricted.
  • There is no private right of action created by the statute.
  • The AG will enforce the statute, but there is a 30 day cure period. 
  • An "office of privacy and data protection" is created, and (all of) the civil penalties extracted from violators by the AG will be used to fund it.
The statute would become effective July 1, 2021.  Stay tuned!






Thursday, June 28, 2018

California Enacts Sweeping Privacy Law to Avoid Vote on Ballot Proposal in November

Well, they did it.  

California is re-shaping U.S. privacy law again.  At the last possible minute, California lawmakers enacted a statute and persuaded the proponent of a strict privacy ballot initiative to withdraw the proposal.  

Today, the California legislature passed, and the California Governor signed, Assembly Bill 375 (the "Consumer Right to Privacy Act of 2018").  I wrote last week about the proposed bill, which resembles the ballot initiative of the same name, but is more business-friendly in most (but not all) ways than the ballot proposal (which I described here). The proponents of the ballot imitative have revoked their proposal on the final day prior to official qualification for the November ballot. 

image of laptop computer with eye on screen and text "California" Matt Cordell is a great privacy lawyerThe world now has until January 1, 2020 to decide how to play by the new rules in California. 

Rumors are already swirling on social media that the statute could be amended (i.e., weakened) before it becomes effective. (Statutes enacted by the California legislature can be more easily amended than laws approved by voters at the ballot box.) 

You can read my initial thoughts on the bill in my earlier post.  I intend to provide a more detailed analysis soon. 

Friday, May 11, 2018

California May Be Poised To Dramatically Alter Consumer Privacy (Again)

I have previously written (for example, hereherehere, and here) that California law usually dictates U.S. privacy practices because it tends to be the most protective of consumer privacy (or aggressive, depending upon your perspective).  California may once again be poised to dramatically re-shape consumer privacy in the United States.
 
An aggressive consumer privacy proposal has gained enough signatures to be placed on the California ballot for a referendum in November. If enacted, it would effectively create a new set of standards for consumer privacy throughout the U.S., because most companies would likely adopt the California standards nationwide rather than treating California residents differently from other Americans.  
 
Background
 

The Consumer Right to Privacy Act of 2018 (specifically v.2, No. 17-0039, which I'll call the "Proposal") was filed October 12, 2017, and has gained almost twice the number of signatures necessary to be included in the November ballot (which is usually an indication that professional petition firms have been engaged).  The qualification deadline is June 28, and it appears that nothing stands in the way of this Proposal making its way onto the ballot.  The named sponsor of the Proposal is the lobbying/law firm of Remcho, Johnasen & Purcell, LLP out of Oakland California. However, it is said that Alastair A. Mactaggart,  a wealthy San Francisco-based real estate investor and executive, is funding this project. He seems to be a first-time political activist who has not been so heavily involved in ballot initiatives in the past.  
 
In a Nutshell
 

The over-simplified-but-concise explanation is that the Proposal:

  • Would give a consumer the right to demand an accounting of all disclosures made by a business of information about the consumer.
  • Would make it illegal to “sell” or "disclose" for a business purpose information about a consumer once a consumer opts out.
  • Would prohibit a business from conditioning any offering or service on a consumer's opt-out decision.
  • Would require very specific disclosures on all business websites.
  • Would be enforced primarily by class action litigation rather than a state entity.  
  • Would not require that any consumer actually suffer any harm (strict liability). 
  • Would result in penalties of $1,000 per person per occurrence, and up to $3,000 if the government concludes the violation was knowing.
  • Would deem a data security breach to be a violation of law by the breached company if the company's security procedures were not reasonable (judged, of course, with the benefit of hindsight).


In More Detail


The Proposal confers on a consumer the right to know what categories of personal information are being collected by a business. 
 
The Proposal gives a consumer the right, at any time, to direct a business that sells personal information about the consumer not to sell the consumer's personal information (the so-called “Opt-Out”). A business must give consumers a notice of this Opt-Out right and must honor Opt Outs after receiving them (presumably immediately). A consumer can authorize another person to Opt Out on his or her behalf, but the Proposal does not specify what form that authorization should take (e.g., a power of attorney).
 
A business cannot “discriminate against” a consumer because the consumer requested information or opted out, including by: (a) denying goods or services to the consumer; (b) charging different prices or rates for goods or services, including through the use of discounts or other benefits or imposing penalties; ( c) providing a different level or quality of goods or services to the consumer; or ( d) suggesting that the consumer will receive a different price or rate for goods or services, or a different level or quality of goods or services, if the consumer exercises the consumer's rights.  (It is worth noting that this provision goes further than even the GDPR)
 
A business must designate at least two methods for consumers to submit requests for information, including a toll-free telephone number, and if the business maintains a website, a website address.
 
Requests for information must be honored within 45 days, with no delay allowed for verifying the request. The look-back period is 12 months, and the consumer controls how the report is delivered. Only one demand may be made each 12 months.
 
Opt-out requests must be honored for at least 12 months, and then it appears that the Proposal would require an affirmative consent from the consumer in order for a business to begin sharing information again. [This provision is somewhat unclear.]
 
Website (and probably application) privacy policy statements must be revised to include a statement of rights that Californians have under the Proposal and a link to the opt-out mechanism titled.  The link must be “clear and conspicuous” and titled "Do Not Sell My Personal Information." 
 
There is a training provision in the Proposal that requires “all individuals responsible for handling consumer inquiries about the business's privacy practices or the business's compliance with [the Proposal]” to be aware of how to handle those inquiries.
 
A business that suffers a security breach involving consumers' personal information may be held liable if the business has failed to implement and maintain "reasonable security procedures and practices."


The Proposal includes a private right of action, and the consumer need not show that he or she suffered a loss of money or property as a result of the violation in order to bring an action. Statutory damages are set at one thousand dollars ($1,000) or actual damages, whichever is greater, for each violation, but a knowing and willful violation can result in damages of three thousand dollars ($3,000), or actual damages, whichever is greater, for each violation. An intentional violation can result in a civil penalty.  Civil penalties of up to $7,500 for each violation are authorized for intentional violations. A civil enforcement action can be brought by the California Attorney General, by any district attorney, any city attorney of a city having a population in excess of 750,000, by any city attorney, or any full-time city prosecutor, in any court of competent jurisdiction.
 
Definitions


The devil is in the details, and at least some of the Proposal's terms are defined in ways that could be easily misunderstood:


The categories of personal information covered by the Proposal are:
 
(1) Identifiers such as a real name, alias, postal address, unique identifier, internet protocol address, electronic mail address, account name, social security number, driver's license number, passport number, or other similar identifiers;
 
(2) All categories of personal information enumerated in Civil Code 1798.80 et. seq, with specific reference to the category of information that has been collected (any information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, his or her name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. “Personal information” does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.)
 
(3) All categories of personal information relating to characteristics of protected classifications under California or federal law, with specific reference to the category of information that has been collected, such as race, ethnicity, or gender;
 
(4) Commercial information, including records of property, products or services provided, obtained, or considered, or other purchasing or consuming histories or tendencies;
 
(5) Biometric data;
 
(6) Internet or other electronic network activity information, including browsing history, search history, and information regarding a consumer's interaction with a website, application, or advertisement;
 
(7) Geolocation data;
 
(8) Audio, electronic, visual, thermal, olfactory, or similar information;
 
(9) Psychometric information;
 
(10) Professional or employment-related information;
 
(11) Inferences drawn from. any of the information identified above; and
 
(12) Any information pertaining to minor children of a consumer.
 
"Personal information" does not include information that is publicly available or that is de-identified.
 
The terms "sell," "selling," "sale," or "sold," includes sharing orally, in writing, or by electronic or other means, a consumer's personal information with a third party, whether for valuable consideration or for no consideration, for the third party's commercial purposes.
 
"Third party" means any person who is not (i) the “business” that collects personal information from consumers or (ii) to whom the business discloses a consumer's personal information for a business purpose pursuant to a written contract, provided that the contract tightly restricts further resale, use or retention beyond the scope of the business purpose and includes a “certification” that the recipient understands the restrictions. 
 
The term "business" means any organization that is for-profit, has annual revenue of at least $50MM, or 100,000 or more consumers annually, or derives at least half of its revenue from selling consumer information. A business includes entities controlled by another (including by 50% or more voting equity), or businesses that share a common brand or trademark.


   
Opposition


Opponents are already pointing out some downsides to the Proposal:  For example, there’s no safety exception. Some businesses might not be able to send recall notices to consumers who have opted out. A car dealer might not be able to share consumer information with a car manufacturer for purposes of compiling recall notice lists.
 
There is also a fear that without a requirement to demonstrate any actual harm, frivolous litigation will run amok and drive up insurance costs and other costs of doing business.
 
There is also the argument that California should not be attempting to regulate the “world wide web.”  Some fear that businesses will begin to exclude California customers or will cease services in order to avoid the burdens of the Proposal.   
 
More Information


You can read the proposal in its entirety here and judge for yourself.


I intend to follow this Proposal closely, and will likely post more about developments here and on LinkedIn and Twitter



Tuesday, June 14, 2016

Don't Be Tardy. Get Schooled on North Carolina's New Education Technology Law Now!

Photo of Education Tech Privacy North Carolina Data Security Lawyer Matt Cordell Best Lawyer Raleigh North Carolina Privacy Attorney RTP North Carolina

New NC Law Enhances Student Privacy Rights and Restricts Providers of Online Educational Resources

Education technology (or "EdTech") organizations will want to pay close attention to a new North Carolina statute that was signed into law a couple of days ago.  On Thursday, June 9, 2016, a new law titled "An Act to Protect Student Online Privacy" was enacted to further protect the privacy of K-12 students in North Carolina.  It becomes effective October 1st, so education technology companies have very little time to prepare before the upcoming school year begins.  They should review their data collection, storage, use and sharing policies and procedures in light of the new law, and adjust their practices if necessary.  In some cases, this may require changing or disabling the features and functions of websites or applications.


Who Is Affected?


The law is primarily aimed at the fast-growing Ed Tech sector.  Organizations may be affected whether or not they have a contract with a school, school board, or the State of North Carolina.  The statute applies to the operators of websites, online services, online applications, or mobile applications who know that the site, service, or application is used primarily for K-12 school purposes.  School boards are also affected, because they should ensure that their contracts with providers of online services require those providers to comply with the new law.
Like the existing student privacy statute, the law applies to public schools only.  Private schools, and their service providers, will remain unaffected.  (If private schools wish to protect the privacy of their students, they must do so by including contractual protections with their service providers.  I would strongly suggest that they do so.)


New Prohibitions


Online operators are prohibited from selling or renting a student's information without parental consent.  They are also generally prohibited from disclosing a student's covered information (defined below) except for six specific purposes.  The permissible disclosures include disclosures to a subcontractor who is contractually prohibited from further disclosure of the information and who agrees to implement reasonable security procedures.


Online operators may not engage in so-called "targeted advertising" (better known as "behavioral advertising") based on information received for "school purposes."  "Targeted advertising" means presenting an advertisement to a student where the advertisement is selected based on information obtained (or inferred over time) from that student's online behavior, usage of applications, or covered information.  Furthermore, they are prohibited from "amassing a profile" of a student except for school purposes.


New Requirements


In addition to proscribing new limitations, the statute imposes two new obligations on online operators.  All operators must "implement and maintain reasonable security procedures" and "protect covered information from unauthorized access, destruction, use, modification, or disclosure."  Operators are also required to delete a student's information at the request of the school board, or when the operator stops providing service to the school board, unless the student's parent consents to the record retention.


Broader Scope of Covered Information


Although the student privacy statute already contained a definition of the term "personally identifiable information," the new statutes creates a significantly more broad definition of the same term that is applicable only for purpose of online privacy protections.  It includes twenty nine (29) categories of information.


Interaction with Existing Law


You may recall that I wrote in mid-2014 about a then-new student privacy law in North Carolina.  You can read that summary here.  Titled "An Act to Ensure the Privacy and Security of Student Educational Records," the law prohibited schools from collecting certain categories of information, restricted the disclosure of personally identifiable student data, required school boards to give parents an annual summary of parental rights and opt-out opportunities, and directed the State Board of Education to make rules regarding privacy standards, audits, breach notification and data retention and destruction policies.  The 2016 law described in this article amends and enhances the 2014 statute.


It should be noted that the federal Children's Online Privacy Protection Act (better known as COPPA) already protects children's online privacy in the educational context as well as in all other contexts.  Any organization affected by North Carolina's new statute should already be in compliance with COPPA, but if it is not, there is no better time than now to become compliant.


Don't Get Sent to the Principal's Office!


Education technology companies and school boards have very little time to revise their policies and practices in order to comply with the new statute.  They should consult with their privacy counsel quickly so that they will not be "sent to the principal's office" when the summer break ends!








You can find more posts like this by Ward and Smith, P.A. attorney and Certified Information Privacy Professional (CIPP/US) Matt Cordell at the North Carolina Privacy and Information Security Law Blog: www.PrivacyLawNC.com.  Matt Cordell practices in the areas of privacy law, information security law, data use law and related consumer protection laws, and has offices in Raleigh, New Bern, Greenville, Wilmington and Asheville.  This article is not intended to give, and should not be relied upon for, legal advice in any particular circumstance or fact situation. No action should be taken in reliance upon the information contained in this article without obtaining the advice of an attorney.

Saturday, May 24, 2014

New Guidance on the New Website Privacy Requirements

Those of you who read this blog regularly know that I've previously written about how a few states have their own website privacy rules, and expressed the widely-held view that California's are the most rigorous. I have also explained that websites directed at U.S. audiences generally need to comply with California's strict rules.
Image source material  Truthout / Foter.com
A few weeks ago, I wrote about a new website privacy law that amends California's existing Online Privacy Protection Act, which became effective at the first of the year.
 
Last week, California's Attorney General published some guidance to aid organizations in complying with the recent changes in California privacy law.   The portion of the guidance that relates to the newest requirements offers the following general recommendations:
  • Make it easy for a consumer to find the section in which you describe your policy regarding online tracking by labeling it, for example: "How We Respond to Do Not Track Signals," "Online Tracking" or "Do Not Track Disclosures." 
  • Describe how you respond to a browser’s Do Not Track signal or to other such mechanisms. This is more transparent than linking to a "choice program."
  • State whether other parties are or may be collecting personally identifiable information of consumers while they are on your site or service.
  • Explain your uses of personally identifiable information beyond what is necessary for fulfilling a customer transaction or for the basic functionality of an online service.
  • Whenever possible, provide a link to the privacy policies of third parties with whom you share personally identifiable information.
More specific recommendations are included in the guidance relating to these and other aspects of California privacy law.

Organizations that have a nationwide audience should update their website privacy policy statements in light of the new rules and guidance, if they have not already.

Wednesday, February 12, 2014

Does Your Website Privacy Policy Pass the Test?


In the past couple of years, Facebook, Twitter, and Google each settled disputes with the Federal Trade Commission ("FTC") relating to website privacy, and Google has reportedly paid $8.5 million to settle a class action suit based on similar privacy-based claims.  Even though actions against these Internet giants capture the headlines, all organizations, regardless of size, with websites can learn valuable lessons from the FTC's recent enforcement actions (as Upromise, Inc. learned in 2012 when the FTC took action against it on similar grounds).  The following discussion presents a high-level description of various aspects of website privacy law that organizations should not overlook:

Capturing Information

If your organization has a website that collects information in any way, including through an embedded "contact" form, or even cookies, you should strongly consider establishing a website privacy policy statement to protect your organization from liability.  Privacy policies are not just for large corporations and "web-based" companies.  A myriad of laws control what must be disclosed in a website privacy policy statement and how it is presented, as well as the underlying privacy practices.

Making Promises

Organization sometimes make promises in their website privacy statements that they fail to fulfill in practice.  Allegations of broken promises can be found in most of the FTC's recent enforcement actions in this area.  This is particularly unfortunate because, in many instances, the organization created an otherwise avoidable risk by establishing privacy standards that were stricter than the law required.  This type of risk is increased if an organization (or its third-party website designer) simply copies another organization's privacy policy statement without first understanding all of the legal and practical considerations that went into the original privacy statement, including what different or additional policies an organization may need to have because of the different ways in which it does business.  To be effective in protecting your organizationfrom liability, your website privacy policy statement must be tailored to your organization's own practices. 

Conducting Business On-Line  
If your organization does business through its website, it may well have additional financial privacy protection obligations and disclosure requirements under various federal and state financial privacy laws, particularly if credit is extended for online transactions.  Any organization engaging in credit transactions through its website needs to be aware of the many additional legal obligations created by the patchwork of financial privacy laws.

Protecting Children

Websites directed at children are subject to additional restrictions and requirements under the Children's Online Privacy Protection Act ("COPPA").  If your
organization's website, or a section of the website, is designed for children, COPPA disclosures and policies are necessary.

Opt-Out Requirements for Advertising

A federal law, the Controlling the Assault of Non-Solicited Pornography and Marketing Act, commonly known as the "CAN-SPAM Act," limits electronic advertising.  Although it is not a privacy law per se, it does require Internet and email advertisers to provide an opt-out mechanism for electronic marketing, among other things.  If your company advertises through its website or by email, you must have CAN-SPAM policies and an opt-out procedure.  It is customary and advisable to address the CAN-SPAM Act and opt-out rights in a website privacy policy.

Don't Forget State Laws

A few states have their own website privacy laws with which your organization must comply if you are directing your website to residents of any of those states.  For example, if your organization's website is directed at California residents, or at U.S. audiences generally, your website will need to comply with California's rules, which are reputed to be the most rigorous and which include specific requirements that go beyond the requirements of the federal rules.

Conclusion

Internet privacy is gaining increasing attention from governmental entities, consumer groups, and plaintiffs' class action attorneys, and is expected to be an emerging source of risk for many companies.  Fortunately, much of that risk is avoidable if care is taken to observe the patchwork of applicable legal requirements.