If your’re taking data on consumers, you’d better learn FTC guidelines

Privacy is one of the hottest issues on the Internet. Until recently, there had been no express federal regulations requiring specific privacy protections; only general prohibitions against unfair and deceptive practices were enforced by both federal and state regulators. The landscape changed dramatically this spring. In April, the FTC published privacy regulations to implement the Children’s Online Privacy Protection Act (“COPPA”); in May it published proposed regulations under the Financial Services Modernization Act of 1999. Although these two sets of regulations apply only to companies engaged in certain specified activities, both reflect four basic standards that the FTC has described as “widely accepted fair information practices:” notice, choice, access and security. Consequently, any company that collects personal information about consumers – essentially every company that does business on-line – should take notice of the regulations, since they provide useful guidelines for the kind of practices that are acceptable.

I. Privacy regulation under COPPA
An operator of an online service is subject to COPPA if it meets two requirements. First, the Act applies only to operators of online services that are directed at or knowingly servicing children under 13 years of age.

Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting

Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…

Learn More

Second, the Act applies only to sites that collect personal information online. Personal information is individually identifiable information that would allow a child to be identified and contacted, such as full name, address, e-mail, telephone number.

The operator of a site that meets these two requirements must: (1) provide notice as to how personal information is collected, used, and disclosed; (2) notify parents and obtain their consent prior to collecting, using or disclosing information about a child; (3) refrain from conditioning participation in activities on the provision of personal information unnecessary for the activity; (4) allow parents to review and amend their child’s information as well as prohibit further collection; and (5) establish procedures to protect the security of personal information collected from children.

- Advertisement -

1. Privacy Notice: Placement and Content
The FTC’s Final Rule and guidelines specify that an operator must post on its homepage a clear and prominent link to a notice of its privacy and information practices. The link should be distinguishable from other links. Preferably, it should be in a larger font and a different color from other text

The content of the notice must be clear, without any extraneous or confusing material, and it must convey: (a) the name and contact information of the entity collecting and maintaining the personal information; (b) the types of personal information collected; (c) the planned use(s) of the information; (d) whether the information will be disclosed to third parties (and if so, the types of businesses engaged in by these third parties); and (e) a statement that the operator does not condition participation in an online activity on the disclosure of more personal information than “is reasonably necessary.”

2. Parental Notice, Consent, and Access
Before any personally identifiable information is collected from a child, an operator must provide written notice to the parent, by mail or e-mail, containing the same information as required on the Web site. The operator must also obtain the parent’s “verifiable consent.” The sufficiency of “verifiable consent” has been the subject of considerable debate; the FTC has announced that it will decide the issue by means of a sliding scale that weighs the use of the information against the reliability of the consent.

Finally, the operator has a duty to provide the parent, upon request, with a list of the general type of information the operator collects as well as the specific information that has been collected about the child. The parent has the right to delete information and prohibit further collection.

The statute authorizes the FTC and state attorneys general to bring enforcement actions.

II. Privacy Regulation under the Financial Services Modernization Act.
On May 15th the FTC, by a unanimous vote, issued a final rule implementing the provisions of the Financial Services Modernization Act of 1999. The Rule becomes effective November 13, 2000; however, an extension for full compliance has been provided until July 1, 2001. The main focus of the Financial Services Modernization Act was to repeal Depression-era rules that placed barriers between the offering of banking, insurance and securities services and products. One provision of the bill, however, regulates the collection of personal information from customers.

The FTC rule rests upon the same principles of notice, choice, access, and security as the regulations published under COPPA. Companies covered by the rule are required to give clear and conspicuous notice to consumers as to what personal, nonpublic information is being collected about them.

III. The Future of Regulation
Implementation of the COPPA Rule and publication of the Final Rule for the Financial Services Modernization Act of 1999 have not been the only Internet privacy initiatives taken by the FTC recently. Indeed, regulations implementing these two statutes are just the beginning of the FTC’s efforts to implement a more expansive regulatory scheme. On May 22, 2000, following a 3-2 vote split along the party lines of the commission members, the FTC changed its longstanding policy of encouraging privacy to be patrolled by industry-self regulation by asking Congress to enact legislation granting the FTC broad authority to police all on-line privacy.

Whatever the outcome of legislative and regulatory efforts, online firms must also be concerned about private lawsuits. Late last year as many as 15 suits were filed in federal and state courts against on-line advertiser DoubleClick, and the prominent plaintiff’s firm of Milberg Weiss Bershad Hynes & Lerach is now pursuing litigation against such firms as DoubleClick, Amazon.com, RealNetworks and Buy.com. All these suits claim that the businesses are collecting and disseminating personal information about consumers without their permission.

As a result, any company that collects data from consumers on-line should be familiar with the FTC’s four principal rules of privacy protection, even if the regulations issued under COPPA or the Financial Services Modernization Act do not expressly apply. A proactive, well reasoned policy may spare a firm from scrutiny by the federal government, state officials, and private litigants.

Ted Long practices in the corporate department of the Providence Office of Holland & Knight. He formerly served as Legal Counsel to U.S. Senator Jack Reed of Rhode Island. Ted’s email is tlong@hklaw.com. Edward J. Naughton practices in the litigation department of the Boston Office of Holland & Knight, concentrating his practice in business litigation and intellectual property matters. He can be reached at enaughto@hklaw.com.

No posts to display