Privacy by Design

As we reported last week, MEP Jan Philipp Albrecht, the rapporteur for the lead European Parliament Committee (LIBE) for the proposed EU Data Protection Regulation, has released a controversial report on the Commission’s proposal. 

There have been several news articles and commentaries in recent days about numerous aspects of the report — including the threat to the U.S.-EU Safe Harbor, the dilution of the “one-stop shop” concept regarding regulators, the re-emphasis on consent and limiting the “legitimate interests” ground for processing data, further restrictions on profiling, etc. — but one troubling aspect of the report has generally not received the attention that it arguably deserves amidst this hubbub: namely, that the report proposes to expand general compliance obligations and “privacy-by-design”/“privacy-by-default” requirements, in particular, to software and hardware manufacturers — regardless of whether they process personal data.Continue Reading EU Data Privacy Rules to Extend to All Software and Hardware Manufacturers — Regardless of Whether They Process Personal Data?

On Thursday, the Federal Trade Commission (“FTC”) hosted a workshop to explore the practices and privacy implications of comprehensive data collection. The event gathered consumer protection groups, academics, privacy professionals, and business and industry representatives to examine the current state of comprehensive data collection, its risks and potential benefits, and what the future holds for consumers and their choices.

In her opening remarks, FTC Commissioner Julie Brill indicated the agency was open to revising its consumer privacy framework if comprehensive data collection warranted heightened restrictions or enhanced consent to protect and inform users: “We know that comprehensive data collection allows for greater personalization and other benefits, but there may be other contexts in which it does not lead to desirable results.”

The workshop was one of five main action items adopted by the FTC as part of its March 2012 report, Protecting Consumer Privacy In an Era of Rapid Change.  In the report, the commission told companies that consent was not required for the collection and use of information that was consistent with a particular transaction or the company’s relationship with the consumer. But the agency said it needed more information to determine how this principle applied to technologies that could capture large amounts of consumer information, such as deep packet inspection (DPI).Continue Reading FTC Hosts Workshop to Examine Comprehensive Data Collection

This week, the FTC released a staff report urging companies to adopt best practices for commercial uses of facial recognition technology.  The report, entitled Facing Facts: Best Practices for Common Uses of Facial Recognition Technologies, follows a workshop held last December and more than 80 public comments addressing issues raised at the workshop.  Facing Facts largely discusses how the core privacy principles from the Commission’s March 2012 privacy report — privacy by design, simplified choice, and transparency — should inform the use of facial recognition technologies, such as digital signs that can assess the age and gender of consumers standing before them as well as online photo tagging tools. 

In this post, we provide an overview of the staff report’s guidance on how each of the principles should be applied by companies that employ facial recognition in their products and services.Continue Reading FTC Issues Guidance on Best Practices for Facial Recognition Technology

The Federal Trade Commission has released a guide, Marketing Your Mobile App: Get It Right from the Start, to help mobile application developers comply with truth-in-advertising standards and privacy principles.  Although the guide is informal and not binding guidance, it does represent helpful FTC commentary.  The guide notes that a one-size fits…

Continue Reading FTC Releases Privacy Guide for Mobile Application Developers

As states are initiating docket proceedings related to smart meter privacy and passing privacy protection legislation to regulate utility providers utilizing smart meters, it is interesting to note how one utility provider has taken steps towards protecting consumer privacy. 

San Diego Gas & Electric (SDG&E) is a utility provider based in southern California.  California has been one of the most active states in the country in proactively regulating the protection of smart grid consumer data.  So SDG&E has sought to address the regulatory and consumer concerns by adopting Privacy by Design with respect to its smart meter programs.

This blog has previously covered the FTC’s adoption of Privacy by Design as a central component of its recent privacy report.  The premise underlying Privacy by Design is that companies will better protect consumer data privacy if they fully incorporate safeguards and a culture of respecting privacy into the early stages of operations, rather than simply responding to legislation and regulations.Continue Reading Privacy by Design for smart meters

Following more than a year of deliberation, the Federal Trade Commission today released its seminal report on consumer privacy, entitled Protecting Consumer Privacy in an Era of Rapid Change.  The report contains “best practices” for businesses as well as recommendations to Congress for legislation.  The final report issued today…
Continue Reading Federal Trade Commission Releases Privacy Report

Companies often view privacy and data security as legal or compliance issues, but a number of recent surveys show that there is also a business case for building privacy and data security into products and services.  For example: 

  • According to TRUSTe, 88% of U.S. adults report that they avoid

…
Continue Reading Making the Business Case for Privacy and Data Security

Yesterday, the FTC announced that it has settled charges against Upromise, Inc., a company that enables consumers to receive rebates when shopping at partner merchants.  (The rebates are placed in college savings accounts—hence Upromise’s name.)  According to the Commission’s complaint, Upromise offered online users a toolbar feature, which, when…

Continue Reading Upromise Settles FTC Privacy Charges

Your company has just launched an innovative new social media service, and you’ve received fanfare from the press, increased website traffic, and a spike in advertising revenues.  In short, the service is a complete success — until you’re served with a class action complaint seeking millions of dollars in damages and a civil investigative demand from the FTC.  What did you do wrong, and what can you do to get out of this mess?

That’s the question that I recently explored as a part of a panel at the summer meeting of the Virginia Bar Association on the benefits and risks of social media.  On the panel, we discussed the many ways that social media has influenced law and policy over the past few months and highlighted what businesses and their lawyers need to understand about privacy issues online in order to avoid litigation and regulatory enforcement.

One of the main reasons that companies face litigation and investigations in the social media area is that they haven’t fully evaluated the information that they are collecting through social media and how that information is (or could be) used.  That is why the discussion on privacy today is coalescing around the concept of “privacy by design,” which Kashmir Hill at Forbes recently described as companies “bak[ing] privacy into their products” rather than considering privacy only reactively.  (You can read more about privacy by design here.)Continue Reading Social Media: Legal Risks and Rewards

Over the past few weeks, online publishers have seen regulators’ focus on privacy in the social media context reach the boiling point.  Just this week, Politico reported that FTC Chairman Jon Leibowitz confirmed in a letter to Sen. Mark Pryor that “FTC staff are carefully monitoring the privacy and security issues associated with social networking sites.”  Sen. Pryor, who chairs the Consumer Protection Subcommittee of the Senate’s Committee on Commerce, Science, and Transportation, had expressed concern about privacy and security issues in the context of social media apps, and so we expect that social media privacy issues will play a key role in forthcoming online privacy legislation.  (We’ve posted Sen. Pryor’s letter to Leibowitz here.)

The announcement of the FTC’s focus on social networking comes on the heels of the FTC’s highly publicized settlement with Google over its Buzz product, which Erin Egan reported on earlier this year and was just approved by the court last week.  According to FTC blogger Lesley Fair, the agency alleged that consumers “weren’t adequately informed that certain information that had been private — including the people they chatted with or emailed most often — would be shared publicly by default.”

For other online publishers, the headline from the Google Buzz settlement is the requirement that Google implement a comprehensive “privacy by design” program across all of its products.  In a recent speech, FTC Consumer Protection Bureau Chief David Vladick pointed to this aspect of the Google settlement as a key shift in the agency’s expectations for social media providers generally.  In fact, the FTC has announced that it wants the privacy by design provisions of the Google settlement to “serve as a guide to industry.”  Privacy by design programs, it said, are a “good idea for all companies” and should be “flexible and scalable.”Continue Reading Regulators Take Aim at Social Networking Privacy