Children’s online privacy

In response to concerns over children’s online privacy, the Federal Trade Commission has initiated measures to protect privacy, including proposed regulations to limit collection of personal information from children. The FTC has actively promoted online privacy by lobbying Congress and initiating legal challenges. In its 1998 Report to Congress, the FTC determined that only 2 percent of 1,400 websites surveyed had adopted comprehensive privacy policies. Significantly, most kids’ websites collected personal information, with less than 10 percent of those sites requiring parental consent.

FTC legal enforcement included a complaint against GeoCities, which was settled last year, and a recent action against Liberty Financial Companies, Inc., the operator of the Young Investor website. In both cases, the companies reportedly collected personal information from children without parental consent. The Young Investor website, directed to children and teen investors, allegedly misrepresented that information obtained in a survey would remain anonymous, when it was actually maintained in an identifiable manner. A consent agreement by the FTC on May 6 requires Young Investors to adopt a privacy policy that includes verifiable parental consent before collecting children’s information.

Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting

Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…

Learn More

The FTC’s recent action against Young Investors is consistent with the Children’s Online Privacy Protection Act of 1998 (COPPA). COPPA, passed by Congress last October, is intended to promote parental involvement and consent to collection of information about children and to protect children’s online safety. COPPA requires that operators of websites “directed to children” or who knowingly deal with children must obtain parental consent before collecting information. Parents must be given complete disclosure of collection practices and uses. They must also have access to, and the opportunity to prevent further use of, personal information.

As called for by COPPA, the FTC issued proposed regulations addressing children’s privacy issues on April 27, 1999. The proposed Children’s Online Privacy Protection Rule requires that online services “directed to children” not condition children’s participating in an online service or activity on the submission of more personal information than is necessary to participate in the activity.

- Advertisement -

Importantly, this will prevent the use of popular games and activities to obtain children’s information. Children’s websites must prominently display a link to a privacy notice which explains how information will be collected and used. The proposed Rule also allows industry groups to seek Commission approval for self-regulatory guidelines.

The FTC’s proposed Rule is designed to allow children to safely take advantage of online learning, recreation and communication activities. Although these objectives are admirable, web industry compliance will require more careful review of current practices and program applications. For example, the Rule defines “collection” to include requests for information and materials available on chat rooms and message boards. Thus, information obtained from these sources must comply with the proposed Rule. In addition, passive tracking devices such as “cookies” may ultimately be prohibited from use on kids’ websites.

Regulatory compliance obligations are placed on those owning and controlling a website and anyone collecting personal information on another’s website. In determining whether a website is “directed to children,” the FTC will consider a broad range of factors including a website’s subject matter, content, intended and actual audience composition and advertising. Practically, this standard would require periodic review of a website as content is updated to determine whether it is oriented towards children.

A concern which is immediately apparent in the proposed Rule is the FTC’s range of options under consideration for its “verifiable consent” standard. A general standard under consideration includes compliance by use of reasonably available technology. More specific standards under consideration requires the use of consent forms returned by e-mail or postal mail or the use of digital signature technology.

These standards present a host of problems for web-based businesses because the general standard is vague and largely depends on a firm’s access to funds for technology enhancements, while the more specific standards don’t account for technological enhancements and innovation on the web. Compliance with the more specific standards, such as the use of consent forms returned by postal mail, would add paperwork burdens and delays in providing service which frustrates a key advantage of web-based commerce.

Parents of children who are active on the web may not be entirely pleased with the prospect of filling out consent forms each time their child hits a new website. Finally, digital signature technology, while offering a superior technological solution, is not yet widely available, thereby limiting its application.

In view of the FTC’s proposed children’s privacy standards, website operators should review the proposed Rule to identify problem areas and compliance issues. Comments concerning the proposed Rule, which is available on the FTC’s website at www.ftc.gov, may be submitted to the FTC by June 11, 1999.

Kevin McNeely is a lawyer at the Providence law firm of Partridge, Snow & Hahn, LLP, and can be reached for comment by e-mail at kjm@psh.com.

No posts to display