The Federal Trade Commission on Feb. 24 announced it had approved a new safe-harbor program for online services that are subject to the Children’s Online Privacy Protection Act (COPPA), a federal law that regulates the online collection of personal information from children under 13. Under COPPA and the FTC’s implementing rule, online services that comply
February 2012
Court Won’t Undo Dismissal of in re Facebook Privacy Litigation
Last week, Judge Ware of the Northern District of California denied a motion to amend his November 2011 dismissal, with prejudice, in In re Facebook Privacy Litigation, a case in which plaintiffs had argued that Facebook improperly transmitted users’ personal information, including User ID numbers or usernames, to third party advertisers. In his most…
No Federal Court Jurisdiction to Review FTC Enforcement of Google Buzz Consent Decree, Judge Rules
An action brought by the Electronic Privacy Information Center (“EPIC”) asking that the FTC be compelled to enforce its Google Buzz consent order (previously described, here) was dismissed by Judge Amy Berman Jackson of the United States District Court for the District of Columbia, who held that “enforcement decisions are committed to agency discretion…
Q&A Regarding Proposed Reforms to European Data Protection Framework
As we have previously posted, on January 25, 2012, the European Commission proposed comprehensive measures to reform the European data protection framework. Among other things, the proposal would impose restrictions on the processing of personal data relating to children; create a breach notification requirement in the EU; require organizations employing 250 or more persons…
White House Releases “Consumer Privacy Bill of Rights”
The White House released a report today containing its “Consumer Privacy Bill of Rights,” referring to the new privacy framework as a “comprehensive blueprint to protect individual privacy rights and give users more control over how their information is handled.” The report is entitled “Consumer Data Privacy in a Networked World: A Framework for Protecting…
Mobile Platforms Agree to Require Apps to Display Privacy Policies
Yesterday California Attorney General Kamala D. Harris announced an agreement she forged among Amazon, Apple, Google, Hewlett-Packard, Microsoft, and Research in Motion to ensure that mobile device apps that collect personal information contain privacy policies. The agreement is designed to ensure that mobile apps comply with the California Online Privacy Protection Act, which requires operators of…
Minnesota AG Files First HIPAA Enforcement Action Against Business Associate
Last month, the Minnesota Attorney General filed a lawsuit in federal court against Accretive Health, Inc. alleging that the company violated various provisions of HIPAA as well as Minnesota consumer privacy and protection law. Although HIPAA-covered entities have been the subject of enforcement actions by state AGs and the Department of Health and Human Services,…
Report Finds Advertising Companies Comply With Self-Regulatory Standards
The Network Advertising Initiative (“NAI”), a coalition of more than 80 online advertising companies committed to self-regulation, released a report this week finding that there is a high degree of compliance with the NAI’s Self-Regulatory Code of Conduct, which governs the use of consumer data for purposes of online behavioral advertising. In particular, the report concludes…
FTC Report Calls For More Notice Involving Mobile Apps Directed To Kids, Warns Enforcement Could Come Over Next Six Months
The FTC staff released a report today calling for participants in the mobile app ecosystem — including app developers, app stores, and third parties who collect data through mobile apps — to provide better privacy notices to parents about mobile apps directed to children, and warning that over the next six months, staff will be conducting additional reviews…
New PCI Council Chairman Establishes Mobile Payments as Top Priority for 2012
Newly-appointed chairman of the PCI Security Standards Council, Michael Mitchell, recently reiterated the importance of data security for mobile payments technology and the Council’s priority in studying and advising the industry on such technology. Chairman Mitchell pointed out the sharp increase in mobile payments but also a lag in security technology protecting such payments. “The adoption of…