Any company that collects personal information about individuals, such as credit card numbers and social security numbers, must be very careful about the way in which it stores and secures that information. Even a blood bank that stores umbilical cord blood needs to keep these privacy rules in clear view. That is one of the messages of a recent Federal Trade Commission action.
California-based Cbr Systems is one of the leaders in the growing field of umbilical cord storage. Umbilical cords are rich in stem cells, and new parents are paying to have the cord or cord blood stored away for the child’s possible medical use later in life. Cbr acquires and stores the cords for an annual fee.
Cbr also stores a vast amount of information related to these tissues, including names, dates and times of birth, Social Security numbers, credit card numbers, checking account numbers, addresses, and driver’s license numbers. In December 2010, a Cbr employee removed four backup tapes containing this sensitive information in order to transport them to a different office. Soon after, a thief stole the tapes and other company devices from the employee’s car. In all, personal information of nearly 300,000 Cbr customers was compromised. The tapes and other devices were not encrypted.
Under the terms of the settlement, Cbr must establish an information security system, submit to security audits every other year for the next 20 years, and ensure that it does not misrepresent its privacy and security practices. A violation of the final order could result in Cbr paying up to $16,000 per violation.
In addition to the FTC action, Cbr clients filed a class action against the company alleging that the company failed to adequately protect the information, and belatedly notified customers of the privacy breach. On February 5, 2013, a federal judge in Johansson-Dohrmann v. CBR Systems Inc., in the U.S. District Court for the Southern District of California, No. 12-1115, granted preliminary approval of a proposed settlement in which CBR must provide credit monitoring and identity theft insurance to each affected class member, as well as make cash reimbursements for any losses resulting from identity theft. The settlement also provides up to $600,000 in payments to the plaintiffs’ lawyers.
Data privacy breaches are a serious concern for any company. They can result in serious reputational harm, as well as financial loss through costly legal actions initiated by the FTC, states, or class actions. The cost of developing and implementing an effective data privacy protocol is a worthwhile investment to guard against these losses. Companies should refer to the FTC’s guides and manuals for protecting consumers’ personal information. Implementing these procedures will serve to protect both consumers and the company itself.
Maryland Attorney General Douglas Gansler (D) has announced that his office is launching a new Internet Privacy Unit designed to address issues related to online privacy and to ensure that companies are in compliance with state and federal consumer protection laws. The unit will also handle issues related to cyberbullying and cybersecurity.
Gansler, who also serves as the president of the National Association of Attorneys General (NAAG), has previously stated that online privacy was a priority. Gansler said in a statement that Internet privacy is “one of the most essential consumer protection issues of the 21st century.”
The Internet Privacy Unit will also work with major industry stakeholders and privacy advocates to provide outreach and education to businesses and consumers. The unit may also pursue enforcement actions “where appropriate” to ensure that consumers’ privacy is protected.
One area of online privacy that the unit will examine is whether companies are complying with the Children’s Online Privacy Protection Act (COPPA), a federal law that restricts site operators from knowingly collecting personal data from children younger than 13. The Federal Trade Commission (FTC) announced in December that it adopted new rules governing COPPA that will go into effect in July 2013, which were the first significant revisions since the original rules went into effect in 2000. The new rules significantly increase the number of types of companies that are required to obtain parental permission before knowingly collecting personal details from children, as well as the types of information that will require parental consent to collect.
The unit will also “examine weaknesses” in online privacy policies. Not only will companies be required to have privacy policies in place, but these policies need to be thorough and comprehensive to ensure compliance with all relevant privacy laws. And, of course, companies need to be following in practice what they “preach” in their privacy policies.
The FTC and state attorney general offices will doubtless continue to be aggressive in their enforcement of privacy laws. Companies with an online presence should review their privacy policies and practices, particularly as affected by recent rule changes such as the COPPA revisions. Also, Maryland is signaling that it will be an active player in monitoring and enforcement of personal privacy and cybersecurity. While federal legislation continues to stall, the states are most definitely moving ahead.
When the Baltimore Ravens and San Francisco 49ers won their NFL conference championship games, a Super Bowl matchup emerged with a great storyline — the opposing head coaches are brothers. An interesting legal question has also developed regarding the right to trademarks associated with the match-up between brothers.
Last February, Roy Fox, a football fan in Indiana, said he spent more than $1,000 to file for the trademarks “Harbowl” and “Harbaugh Bowl” in anticipation that Jim Harbaugh’s San Francisco 49ers and John Harbaugh’s Baltimore Ravens might meet in the Super Bowl. Fox said he remembered how former Los Angeles Lakers Coach Pat Riley made money by trademarking the term “Three-Peat” and thought that if the brothers were to meet in the Super Bowl he could make some money selling some T-shirts.
Fox applied for a trademark in February. In July, the United States Patent and Trademark Office (USPTO) published the trademark request, which is the standard procedure used by the office to see if anyone is opposed to a request.
In August, the NFL got the USPTO to extend the period of time allowed for filing an objection. At the same time, the NFL sent Fox a note saying that it was concerned that his recent trademarks could be easily confused with the NFL’s trademark of the Super Bowl or that “it may cause the public to mistakenly believe that your goods and/or services are authorized or sponsored by or are somehow affiliated with the NFL or its Member Clubs.”
The NFL continued to push Fox to drop his trademark application and began using more aggressive language in its correspondence.
“If you are still interested in resolving this matter amicably and abandoning your trademark application, please contact me as soon as possible,” NFL Assistant Counsel Delores DiBella wrote to Mr. Fox in October. She warned that otherwise, the NFL “will be forced to file an opposition proceeding and to seek the recoupment of our costs from you.”
Fox said he made a few requests of the league including a reimbursement of money he spent on the trademark applications, Indianapolis Colts tickets, and an autographed picture of NFL Commissioner Roger Goodell. Fox said that all of his requests were denied. Fox said he then dropped the trademark applications in October when additional correspondence from the league became more threatening and because he did not want to go to court to fight the NFL.
Trademark law protects a trademark owner’s exclusive right to use a trademark when use of the mark by another would be likely to cause consumer confusion as to the source or origin of the goods.
In order for the NFL to prevail on a challenge to Fox’s trademark, the league would have to show that the use of the “Harbowl” or “Harbaugh Bowl” mark would “cause a likelihood of confusion” as to the affiliation, connection or association of the mark with the marks owned by the NFL, or as to the origin, sponsorship, or approval of defendant’s goods services or commercial activities. Generally speaking, a “likelihood of confusion” exists when consumers viewing the allegedly infringing mark would probably assume the product or service it represents is associated with the source of a different product or service identified with a similar mark.
The NFL’s strong-arm tactics were successful in getting Fox to abandon his trademark application. The threat of a lengthy and costly legal battle is often enough to deter people from pursuing trademarks that another trademark owner – in this case the NFL – considers to be possibly infringing, even if the USPTO or a court may not ultimately agree.
It is unclear who would have prevailed had this case been contested, but it seems unlikely that the NFL ultimately would have prevailed. While it is clear in some sense, with the benefit of knowing now that the Ravens and 49ers are in the championship game, that “Harbowl” or “Harbaugh Bowl” is referring to the “Super Bowl” (which is a trademark owned by the NFL), it likely would not have risen to the “likelihood of confusion” level that would be needed for the NFL to prevail before the USPTO or in court.
Angered by the recent tragic suicide of Internet activist Aaron Swartz, a group of hackers claiming to be from the group Anonymous, made threats over the weekend to release sensitive information about the United States Department of Justice. The group claimed to have a file on multiple servers that is ready to be released immediately.
Swartz’s suicide has served to mobilize the group Anonymous, a loosely defined collective of Internet “hacktivists” that oppose attempts to limit Internet freedoms. Anonymous is a staunch advocate of open access to information, as was Swartz. Anonymous said that Swartz “was killed” because he “faced an impossible choice.”
Swartz was facing federal computer fraud charges that carried a maximum sentence of 35 years in prison, although in reality he probably would not have been given a sentence anywhere near approaching the statutory maximum. Prosecutors told Swartz’s legal team they would recommend to the judge a sentence of six months in a low-security setting.
The charges arose from allegations that he made freely available an enormous archive of research articles and similar documents offered by JSTOR, an online academic database, through the computers at the Massachusetts Institute of Technology.
Swartz was a leading activist involved in the movement to make information more freely available on the Internet and is credited with helping to lead the protests that ultimately defeated the Stop Online Piracy Act (SOPA), a statute that would have significantly broadened law enforcement powers in policing Internet content that may violate U.S. copyright laws.
Earlier this month, Rep. Zoe Lofgren (D-Calif.) indicated that she is drafting a bill that she terms “Aaron’s Law,” which would limit the scope of the Computer Fraud and Abuse Act, a 1986 law that prosecutors used to help bring these charges against Swartz.
The hackers reportedly hijacked the website of the United States Sentencing Commission, the federal agency responsible for the federal sentencing guidelines for criminal offenses. They said that the Sentencing Commission’s website was chosen because of its influence in creating sentences that they deemed unfair. The hackers posted a message that demanded reform of the criminal justice system or threatening that sensitive information would be leaked. Anonymous also posted an editable version of the website, which invited users to edit it as they pleased.
Today is Data Privacy Day. These recent incidents serve to show that no organization – not even the U.S. Department of Justice – is immune from security breaches. Data breaches and data losses will occur and it is crucial for an organization to be prepared and have policies in place to allow a quick response when something does happen.
The legal ramifications and bad publicity that follow such an incident can be very damaging to an organization. However, by making sure that you are prepared, you can minimize your damages. Preparedness involves consultation across a range of specialties, including information technology, legal advice, and public relations. The impact that a data breach or loss can have on the bottom line of any organization is enormous and preparation is the best method to combat it.
A data breach or data loss can also have far-reaching legal consequences under international, federal and various state laws. For example, companies may not realize that if they have even a few employees or customers in a state, it may trigger a number of different requirements under state privacy laws. In order to avoid problems with federal agencies or state attorney general offices, it is best for companies to have a plan in place in advance and make sure they are already compliant with all relevant laws.
As we cautioned in a September post, the FTC is stepping up enforcement actions against mobile app developers for failure to comply with consumer protection principles. This month, the FTC took another major step in that direction with a groundbreaking settlement applying the Fair Credit Reporting Act (FCRA) to app developers Filquarian Publishing, LLC, Choice Level, LLC, and Joshua Linsk.
The FCRA is a consumer protection statute designed to regulate the collection, dissemination, and use by companies of consumer information. Filquarian markets mobile apps that run background checks using criminal records obtained from Choice Level, and Linsk is the owner and sole officer of both companies.
Although this was the first time that the FTC has applied the FCRA to a mobile app developer, the prospect has been on the horizon for quite some time. Last February, the Commission issued a press release announcing that it had issued official warning letters to marketers of six mobile apps for background screening. The warnings were explicit: “If you have reason to believe that your background reports are being used for employment or other FCRA purposes,” both you and those customers must comply with the FCRA. Additionally, the FTC posted a “Word of Warning” on its Business Center Blog, informing the public about the warning letters and cautioning app marketers that “disclaimers or not, the FCRA would still apply.”
According to the FTC, Linsk and his companies failed to heed these conspicuous warnings. As detailed in the FTC complaint, since at least 2010, Filquarian had been specifically targeting employers with ads like this one: “Are you hiring somebody and wanting to quickly find out if they have a record? Then Texas Criminal Record Search is the perfect application for you.” Instead of attempting to comply with the FCRA, the FTC’s complaint said, Filquarian and Choice Level posted a disclaimer stating that the companies were not complaint with the FCRA, that their reports were not to be considered screening products for the various FCRA-proscribed purposes, and that the users of their reports assume sole responsibility for FCRA compliance.
The complaint against them cited numerous FCRA violations: (i) regularly furnishing reports to individuals who did not have a permissible purpose to use them, (ii) failing to maintain any procedures for assuring maximum possible accuracy of information provided in the reports, and (iii) failing to provide required notices to users of the consumer reports. The agency concluded that the disclaimers were not enough to absolve the company of FCRA liability, especially when the disclaimer directly contradicts express representations in the company’s advertisements.
Again, we urge all mobile app developers to be aware of the following principles to reduce the likelihood of an FTC enforcement action: (i) an app is no different from an Internet website, which is no different from a print ad, (ii) you’d be smart to pay attention to the FTC’s warnings to other companies and their enforcement actions, and (iii) disclaimers are important but often they simply aren’t enough to avoid liability. Also, the FTC has definitely shown that it will use its broad statutory authority and apply existing laws and regulations – including the 1970s -era FCRA — to mobile apps and other online offerings.
The rise of social media has led to the application of old law to new forms of communication. For instance, an effort by the National Labor Relations Board to educate workers on their right to engage in protected concerted activity has left some employers feeling that the NLRB went too far in supporting employees’ rights – particularly their right to post disparaging work-related comments on social media forums without reprisal.
Section 7 of the National Labor Relations Act (NLRA) protects all private-sector employees’ absolute right to engage in protected concerted activity, including the right to discuss among themselves their wages, hours, benefits and other terms and conditions of their employment. Generally, this requires two or more employees acting together to improve wages or working conditions, but the action of a single employee may be considered concerted if he or she involves co-workers before acting, or acts on behalf of others. It also requires that the improvement sought benefit more than just the employee taking action, so as to distinguish protected concerted activity from mere individual complaints.
Last year, the NLRB launched a website seeking to educate workers on their right to engage in protected concerted activity. The site provides several examples of cases in which employers violated an employee’s right to engage in protected concerted activity over the Internet. For example, in one case the NLRB issued a complaint against an employer that terminated an employee who criticized her supervisor on Facebook. The Board also found that the employer’s Internet policy, which prohibited employees from making negative statements about the company or supervisors, interfered with the right to engage in concerted activity.
The NLRB has in fact ruled in workers’ favor in a number of social media cases. For example, in Hispanics United of Buffalo, the NLRB considered a case in which an employer discharged five employees because of their Facebook posts. In that case, an employee went on Facebook to solicit her coworkers’ thoughts on work-related criticism she received from a fellow employee. In response, four coworkers weighed in about working conditions, work load and staffing issues at the company. All of the employees’ posts were made off-duty on the employees’ personal computers. The employer terminated all five employees, claiming that their comments constituted harassment of the employee mentioned in the initial post.
An NLRB administrative law judge reviewed the case and found that the employees had been unlawfully discharged. The ALJ found that the NLRA protects employees in “circumstances where individual employees seek to initiate or to induce or to prepare for group action, as well as individual employees bringing truly group complaints to the attention of management,” even if that action takes place online. Since the employees were discussing the terms and conditions of their employment, the discussion was protected concerted activity within the meaning of Section 7 of the NLRA.
While cases like Hispanics United of Buffalo have served as a rallying cry for employers on the NLRB’s perceived overreaching in support of workers, a recent report on NLRB social and general media cases reveals that the NLRB actually sided with employers in slightly more than half the time by finding that employees’ statements on Facebook or Twitter did not constitute “protected concerted activity” under the NLRA. For example, in Karl Knauz Motors, Inc., the NLRB found that an employee was lawfully terminated for his Facebook postings about an accident that took place at a car dealership owned by his employer. The NLRB found that these comments were not protected because they were not related to the terms and conditions of his employment.
Similarly, in another case brought before the Board, an employee who had just been reprimanded by her supervisor posted a Facebook status that consisted of an expletive and the name of the company that employed her. One of her coworkers “liked” that status. Half an hour later the same employee posted a comment expressing her belief that the company did not value its employees. None of the employee’s coworkers responded to that posting. The company terminated the employee for her postings.
On review, the NLRB upheld the employee’s termination, finding that the posts were merely the expression of a personal gripe. The NLRB’s Associate General Counsel summarized the Board’s reasoning by stating, “The Charging Party had no particular audience in mind when she made that post, the post contained no language suggesting that she sought to initiate or induce coworkers to engage in group action, and the post did not grow out of a prior discussion about terms and conditions of employment with her coworkers. Moreover, there is no evidence that she was seeking to induce or prepare for group action or to solicit group support for her individual complaint. Although one of her coworkers offered her sympathy and indicated some general dissatisfaction with her job, she did not engage in any extended discussion with the Charging Party over working conditions or indicate any interest in taking action with the charging party.”
Despite the uproar over the NLRB’s application of “protected concerted activities” to social media, this does not represent a shift from the NLRB’s previous decisions. It merely applies existing policy to a new set of facts brought about by technological changes in how workers communicate. As before, employers may set limits on employee’s social media activities as long as they do not impinge on the employees’ protected concerted activities.
As part of its aggressive program to protect consumers in financial matters, the Consumer Protection Financial Bureau (CFPB) has announced that it is prepared to adopt a controversial “disparate impact” theory of liability against lenders. A case that the U.S. Supreme Court may accept would have a major impact on whether the CFPB is actually going to be able to do that.
The “disparate impact” theory was first articulated by the Supreme Court and further addressed by the Civil Rights Act of 1991 in the employment discrimination context. In a 1971 decision, Griggs v. Duke Power Co., the Court held that Title VII “proscribes not only overt discrimination but also practices that are fair in form, but discriminatory in operation.”
In the employment context, under Griggs, even though an employer may not intend to discriminate against a protected group, it may still be found liable under anti-discrimination laws for practices that disproportionately disadvantage such a group.
The theory was administratively adopted for federal fair lending laws in the 1990s, as laid out in a 1994 Interagency Policy Statement on Fair Lending. This statement from the Department of Justice and other federal agencies says that lenders may be liable for fair lending law violations if their policies or practices are shown to have a disparate impact on protected groups – even if there was no intent to discriminate. The statement, however, does not have the force of law.
In addition, the federal government, in practice, had not aggressively pursued fair lending cases in the absence of intentional discrimination against a protected group — until the Obama Administration’s CFPB announced its intention to use the “disparate impact” theory.
That is where the pending Supreme Court case, Mount Holly v. Mount Holly Gardens Citizens in Action, Inc. comes in. In that case, the Township of Mount Holly, N.J., made plans to redevelop a blighted residential area that was primarily inhabited by low- and moderate-income minority residents. Under the plan, the neighborhood would be demolished, and significantly more-expensive housing would be built. Many of the residents objected to the redevelopment, saying that their neighborhood would be destroyed and that they would not be able to afford to live in the new neighborhood. They sued under the Fair Housing Act, alleging that although the plan was not specifically targeted against minorities, it would have a disparate impact on them. The U.S. Court of Appeals for the Third Circuit allowed the case to proceed, and the Supreme Court is now considering it.
The issue is whether “disparate impact” is cognizable under the Fair Housing Act, as it is in the employment context. If the Court holds that impact as well as intent leads to a cause of action under the Fair Housing Act, the CFPB will go ahead and act under the theory. It will bring cases, for example, against banks that make loans only in areas that happen to be inhabited by high-income people and decline to make loans in areas where low-income people (many of whom are minorities) live. It will use geography as a proxy for racial or ethnic discrimination: Where were loans made, and where were they denied?
The Supreme Court has not yet decided whether it will hear the Mount Holly case. The most recent activity was the Court’s request, at the end of October, that the U.S. solicitor general formally express the views of the U.S. government on the issue. The solicitor general has not yet filed, and it will probably be a few weeks until he does file and the justices consider the SG’s arguments and decide whether to grant certiorari.
Consumer advocacy groups have actively pushed the disparate impact theory. The National Fair Housing Alliance has filed administrative complaints against Bank of America, Wells Fargo, and U.S. Bancorp, alleging that bank practices in maintaining foreclosed properties discriminate against people in predominantly black and Hispanic neighborhoods. Bank of America, Wells Fargo and SunTrust have recently paid some $500 million to settle claims: Since the banks opted to settle these cases, there was no formal legal ruling on the theory of liability.
Thus, “disparate impact” has been slowly taking hold in the lending context – without any real statutory basis or judicial clarification. The theory is still being used only by extension or analogy to the employment context. A high court ruling would clarify this very important area of law. Lenders, developers, and borrowers are waiting for clarification.
The Federal Trade Commission announced on December 19, 2012, that it has adopted final amendments to the Children’s Online Privacy Protection Act (COPPA) that strengthen privacy protections online and give parents greater control over their children’s personal information. FTC officials said that they updated the rules to keep pace with the increasing use of mobile phones and tablets by children.
The original rules have not seen significant changes since they went into effect in 2000. The FTC has been examining possible changes to the COPPA rules since March 2010 and has received hundreds of comments from interested parties through multiple comment periods.
“Congress enacted COPPA in the desktop era and we live in an era of smartphones and mobile marketing,” FTC Chairman Jon Leibowitz said. “This is a landmark update of a seminal piece of legislation.”
The new rules go into effect on July 1, 2013. The vote was approved by a 3-1 vote, with one commissioner abstaining. Commissioner Maureen Ohlhaussen voted no on the ground that she believes a core provision of the new rules, extending the statutory definition of “operator” to impose obligations on certain websites or online services that do not collect personal information from children or have access to or control of such information collected by a third party, exceeds the scope of the authority granted by Congress in COPPA.
The new rules significantly increase the types of companies that are required to obtain parental permission before knowingly collecting personal details from children, as well as the types of information that will require parental consent to collect.
Under the new amendments, the FTC said companies must seek permission from parents to collect a child’s photographs, videos, audio files, and geo-location information.
The new rules also expand the definition of personal information to include persistent IDs, such as a unique serial number on a mobile phone or the IP address of a browser, if they are used to show a child behavior-based ads. It requires third parties such as advertising networks and social media networks that know they are operating on children’s sites to notify and obtain consent from parents before collecting personal information. Additionally, the rule makes children’s sites responsible for notifying parents about data collection by third parties that are integrated into their services.
The FTC said that the new amendments will now require apps and websites that are targeted at children with third-party plug-ins to websites such as Twitter and Facebook, to require parental consent to collect personal information. Those third parties must obtain parental consent when they have “actual knowledge” that they are collecting information from a website or service targeted at children.
In a departure from the rule changes that were proposed by the government in August, the FTC explicitly exempted app stores, such as those run by Google and Apple, from responsibility for privacy violations by games and software sold in their stores. The government also reversed a prior proposal by agreeing to continue to allow parental consent to be obtained by email as long as apps and websites only collect the data for internal usage.
Now that these new guidelines have been issued, all operators need to review their policies to ensure compliance. These revisions have significantly expanded the type of information that is considered private and the number of companies that will need to comply. The FTC has previously brought enforcement actions against companies that were in violation of COPPA in the past, and these new rules will allow for more actions to be brought in the future.
On December 18, 2012, the Federal Trade Commission issued orders requiring nine data brokerage companies to provide the agency with information on how they collect data from consumers and use it. The nine companies asked to provide this data to the FTC include Acxiom, Datalogix, Intellius and Peekyou.
Data brokers are companies that collect personal information about consumers from a variety of sources, both public and non-public, and then package the information and sell it to companies. As the FTC noted in its announcement, in many ways this data can benefit consumers and the economy by enabling companies to prevent fraud or allowing customers to see ads that interest them.
However, the FTC seems concerned that much of the data brokerage industry operates unregulated. No current laws require data brokers to maintain the privacy of an individual’s data unless it is used for employment, credit, insurance, housing, or another similar purpose. Some estimates indicate that these data brokers have several thousand details on the majority of adults in the United States.
The FTC is specifically seeking details about:
1. The nature and sources of the consumer information that data brokers collect.
2. How data brokers use, maintain, and disseminate the information they collect.
3. The extent to which the data brokers allow consumers to access and correct their information or to opt out of having their personal information sold.
The FTC said that it will use the responses to prepare a study and to make recommendations on whether and how the industry could improve its privacy practices.
The FTC has already called on Congress to address data brokers’ practices through legislation. In March, the FTC advocated for legislation to “address the invisibility of, and consumers’ lack of control over, data brokers’ collection and use of consumer information.” The FTC has also urged Congress to pass a law that would require data brokers to let individuals examine the data contained in files on them, similar to the way that federal laws allow for consumers to get free credit reports every year.
In July, Rep. Edward Markey (D-MA) and Rep. Joe Barton (R-TX), co-chairs of the Bipartisan Congressional Privacy Caucus, opened an investigation into the practices of the industry. The Privacy Caucus has expressed concerns that many Americans do not know how the industry operates and that controls may be lacking for individuals over their own information.
In October, Sen. John D. Rockefeller IV (D-WV) opened his own investigation into the data broker industry. Rockefeller said he was struck by the amount of personal, medical, and financial information that could be collected and sold.
This week’s announcement provides further notice that the FTC has intensified its scrutiny of the data brokerage industry. Companies in the data compilation business should continue to monitor their practices to ensure that they are complying with all regulations and should stay abreast of any forthcoming changes in regulations and laws.
The Federal Trade Commission released a report on December 10, 2012, that concluded that mobile apps targeted at children were collecting large amounts of data from children and sharing their information with advertisers without disclosing their practices.
The FTC report examined 400 leading apps designed for kids that were sold in the mobile stores run by Apple and Google. The agency said it is launching an investigation to determine if certain mobile apps developers have violated the Children’s Online Privacy Protection Act (COPPA) or engaged in unfair or deceptive trade practices.
The FTC’s authority over children’s mobile apps comes from laws that prohibit unfair and deceptive acts of commerce, as well as from COPPA, which requires operators of online services for children under 13 to get consent from parents before collecting and sharing personal information, among other requirements.
The report itself does not call for regulatory changes. However, the FTC is reviewing COPPA to determine if it needs to be updated, and is expected to announce updates soon COPPA was enacted in 1998, and FTC officials say the law needs to be changed to reflect the growing prominence of mobile apps and social networking sites used by children. The regulations under COPPA have not been substantially revised since its introduction. COPPA sets forth specific requirements for websites aimed at children, but its guidance on mobile technology is far less clear.
The FTC proposed updating COPPA, but it has been met with pushback thus far from technology companies. The proposed changes could significantly increase the need for children’s sites and apps to obtain parental permission to collect certain types of data, including device IDs, photos, and voice recordings. FTC officials have also emphasized that they consider the exact location of a mobile device to be personal information that would require parental permission to collect.
The FTC report noted that it was particularly concerned with the collection of a user’s device ID, which is a string of letters or numbers that identifies each mobile device. Nearly 60 percent of the mobile apps that the FTC reviewed transmitted the device ID. Some of those apps then shared that ID with an advertising network or other third party, including some apps that disclosed the phone number and location of the device. Additionally, more than half the apps also contained interactive features such as advertising or in-app purchases that were largely undisclosed to parents.
Only 20 percent of the apps reviewed in the report disclosed any information about the app’s privacy practices. FTC Chairman Jon Leibowitz said, “Our study shows that kids’ apps siphon an alarming amount of information from mobile devices without disclosing this fact to parents.”
This week’s report serves as further notice to all mobile app developers that the FTC is monitoring the mobile app market. App developers, particularly developers that are targeting children, need to review their compliance with FTC guidelines, as well as their overall truth-in-advertising and data privacy policies, to make sure their apps are complying. The FTC has made clear that it will take enforcement actions against industry participants and will continue to aggressively pursue action in the future.