<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>OlenderFeldman LLP &#187; Federal Trade Commission (FTC)</title>
	<atom:link href="http://olenderfeldman.com/tag/federal-trade-commission-ftc/feed" rel="self" type="application/rss+xml" />
	<link>http://olenderfeldman.com</link>
	<description>Privacy Lawyers : eCommerce Lawyers : FTC Compliance Lawyers</description>
	<lastBuildDate>Fri, 10 May 2013 19:16:40 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
		<item>
		<title>FTC Proposes Revisions for COPPA</title>
		<link>http://olenderfeldman.com/privacy/ftc-proposes-revisions-for-coppa</link>
		<comments>http://olenderfeldman.com/privacy/ftc-proposes-revisions-for-coppa#comments</comments>
		<pubDate>Thu, 02 Aug 2012 15:22:20 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Behavioral Advertising]]></category>
		<category><![CDATA[Behavioral Targeting]]></category>
		<category><![CDATA[Children's Online Privacy Protection Act (COPPA)]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[FTC Compliance]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=1365</guid>
		<description><![CDATA[The Federal Trade Commission has proposed revisions that will bring the Children&#8217;s Online Privacy Protection Act in line with 21st century technology, largely targeting social networks and online advertisers. By Alice Cheng Based on comments solicited last year, the Federal Trade Commission (FTC) has posted proposed revisions to the Children’s Online Privacy Protection Act (COPPA). [...]]]></description>
			<content:encoded><![CDATA[<h2>The Federal Trade Commission has proposed revisions that will bring the Children&#8217;s Online Privacy Protection Act in line with 21st century technology, largely targeting social networks and online advertisers.</h2>
<h5>By Alice Cheng</h5>
<p style="text-align: justify;">Based on comments solicited last year, the Federal Trade Commission (FTC) has posted <a rel="nofollow" target="_blank" href="http://www.ftc.gov/os/2012/08/120801copparule.pdf" rel="nofollow">proposed revisions</a> to the Children’s Online Privacy Protection Act (COPPA). The Act, which has not been updated since its inception in 1998, may be extended to include social networks and online advertisers.</p>
<p style="text-align: justify;">According to the current regulations, COPPA applies only to website operators who know or have reason to know that users are under the age of 13, requiring the sites to obtain parental consent before any collection of data. In the past decade, an increased ability to harvest consumer information has necessitated revisions. In a <a href="http://olenderfeldman.com/tag/childrens-online-privacy-protection-act-coppa">FTC staff report conducted earlier this year</a>, the Commission addressed a growing need for app stores and app developers to provide more information regarding their data collection practices to parents. With the proposed changes posted today, the FTC plans to update COPPA to respond to modern concerns surrounding social networking sites, advertising networks, and applications. Under the proposed changes, such third parties may be held responsible for unlawful data collection practices when they know or have reason to know that they are connecting to children’s websites. Mixed audience websites may have to screen all visitors in order for COPPA regulations to apply to users under 13 years of age. Additionally, restrictions on advertising based on children’s online activity may be tightened.</p>
<p style="text-align: justify;"> The FTC will be accepting public comment to the proposed rules via <a rel="nofollow" target="_blank" href="https://ftcpublic.commentworks.com/ftc/2012copparulereview/" rel="nofollow">the FTC website</a>. Comments will be accepted until September 10, 2012.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/ftc-proposes-revisions-for-coppa/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lawmakers Seek Data Broker Information Practices</title>
		<link>http://olenderfeldman.com/privacy/lawmakers-seek-data-broker-information-practices</link>
		<comments>http://olenderfeldman.com/privacy/lawmakers-seek-data-broker-information-practices#comments</comments>
		<pubDate>Tue, 31 Jul 2012 15:31:02 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Acxiom]]></category>
		<category><![CDATA[Bi-Partisan Privacy Caucus]]></category>
		<category><![CDATA[Data brokers]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[FTC Compliance]]></category>
		<category><![CDATA[Senator Ed Markey]]></category>
		<category><![CDATA[Senator Joe Barton]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=1371</guid>
		<description><![CDATA[Several House lawmakers have sent letters to nine major data broker firms, seeking transparency on data practices. By Alice Cheng Last week, eight House members, including Congressional Bi-Partisan Privacy Caucus chairmen Ed Markey (D-Mass.) and Joe Barton (R-Tex.), sent letters to nine major data broker firms, asking for information on how they collect, assemble, maintain, [...]]]></description>
			<content:encoded><![CDATA[<h2>Several House lawmakers have sent letters to nine major data broker firms, seeking transparency on data practices.</h2>
<h5>By Alice Cheng</h5>
<p style="text-align: justify;">Last week, eight House members, including Congressional Bi-Partisan Privacy Caucus chairmen Ed Markey (D-Mass.) and Joe Barton (R-Tex.), sent <a rel="nofollow" target="_blank" href="http://markey.house.gov/sites/markey.house.gov/files/documents/Axciom%20letter.pdf" rel="nofollow">letters</a> to nine major data broker firms, asking for information on how they collect, assemble, maintain, and sell consumer information to third parties.</p>
<p style="text-align: justify;">The letter references a recent New York Times <a rel="nofollow" target="_blank" href="http://www.nytimes.com/2012/06/17/technology/acxiom-the-quiet-giant-of-consumer-database-marketing.html?pagewanted=all" rel="nofollow">article</a> profiling data broker Acxiom, which may have spurred the lawmakers’ decision to target the firms. Data brokers are large firms that aggregate information about hundreds of millions of consumers, selling them to third parties for marketing, advertising, and other purposes.  Oftentimes, profiles of consumers are created to reflect spending habits, political affiliation, and other behavioral information. As the article explains, the issue with these activities is that they are largely unregulated, largely unknown to the general public, and are often be difficult to opt out of.</p>
<p style="text-align: justify;">Privacy advocates, lawmakers, and often the <a rel="nofollow" target="_blank" href="http://olenderfeldman.com/privacy/spokeo-settles-charges-of-fair-credit-reporting-act-fcra-violations">Federal Trade Commission</a> have made continued moves towards increased <a href="http://olenderfeldman.com/privacy/national-telecommunications-and-information-administration-ntia-holds-public-meeting-on-mobile-privacy">transparency</a> of the activities of data brokers. A <a href="http://markey.house.gov/press-release/bipartisan-group-lawmakers-query-data-brokers-about-practices-involving-consumers%E2%80%99" rel="nofollow">statement</a> explains that, in sending the letter to the nine firms, the lawmakers in the Bi-Partisan Privacy Caucus seek to obtain information on the brokers relating to  “privacy, transparency and consumer notification, including as they relate to children and teens.”</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/lawmakers-seek-data-broker-information-practices/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Survey on App Privacy Policies Finds Increased Implementation, Overall</title>
		<link>http://olenderfeldman.com/privacy/survey-on-app-privacy-policies-finds-increased-implementation-overall</link>
		<comments>http://olenderfeldman.com/privacy/survey-on-app-privacy-policies-finds-increased-implementation-overall#comments</comments>
		<pubDate>Mon, 23 Jul 2012 15:22:58 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[FTC Compliance]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Lawyer]]></category>
		<category><![CDATA[Privacy Policies]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=1368</guid>
		<description><![CDATA[Survey finds that only 61.3% of apps have privacy policies, reflecting perceived need for increased app privacy regulations. By Alice Cheng A recent survey conducted by the Future of Privacy Forum (FPF) examined whether popular free and paid mobile apps provided users with access to a privacy policy. The survey found that 61.3% of the [...]]]></description>
			<content:encoded><![CDATA[<h2>Survey finds that only 61.3% of apps have privacy policies, reflecting perceived need for increased app privacy regulations.</h2>
<h5>By Alice Cheng</h5>
<p><span style="text-align: justify;">A </span><a rel="nofollow" target="_blank" style="text-align: justify;" href="http://www.futureofprivacy.org/2012/07/11/fpf-study-results-show-app-developers-heed-call-for-privacy-policies/">recent survey</a><span style="text-align: justify;"> conducted by the </span><a rel="nofollow" target="_blank" style="text-align: justify;" href="http://www.futureofprivacy.org/" rel="nofollow">Future of Privacy Forum</a><span style="text-align: justify;"> (FPF) examined whether popular free and paid mobile apps provided users with access to a privacy policy. The survey found that 61.3% of the 150 apps examined had a privacy policy, while more free apps than paid apps had privacy policies. While the numbers of apps with privacy policies are still low, these findings mark an overall increase from the previous year.</span></p>
<p style="text-align: justify;">The FPF credits the consumer privacy efforts of various groups, including the Federal Trade Commission and the California Attorney General. The FTC has made continuous efforts to develop companies develop <a rel="nofollow" target="_blank" href="http://olenderfeldman.com/privacy/ftc-releases-final-consumer-privacy-report">best consumer privacy practices</a>, and has been involved in <a href="http://olenderfeldman.com/privacy/spokeo-settles-charges-of-fair-credit-reporting-act-fcra-violations">battling privacy violations</a>. In February, California Attorney General Kamala Harris persuaded six major companies with mobile platforms (including Apple, Microsoft, and Google) to ensure that app developers include privacy policies that comply with the California Online Privacy Protection Act. More recently, Harris also <a href="http://www.informationweek.com/news/government/policy/240004137" rel="nofollow">announced the formation of the Privacy Enforcement and Protection Unit</a> to oversee privacy issues and to ensure that companies are in compliance with the state’s privacy laws.</p>
<p style="text-align: justify;">Together with the FPF survey results, these recent strides reflect a growing nationwide concern for information privacy. However, mere access to privacy policies does not ensure that consumers are aware of what happens to information collected about them. Many policies are long and onerous, and can be confusing for consumers. As many privacy laws focus on protecting the consumer’s privacy interests, providing a <a href="http://olenderfeldman.com/privacy/what-do-i-need-to-look-for-in-a-privacy-policy">clear privacy policy</a> is oftentimes a best practice for all companies.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/survey-on-app-privacy-policies-finds-increased-implementation-overall/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spokeo Settles Charges of Fair Credit Reporting Act (FCRA) Violations</title>
		<link>http://olenderfeldman.com/privacy/spokeo-settles-charges-of-fair-credit-reporting-act-fcra-violations</link>
		<comments>http://olenderfeldman.com/privacy/spokeo-settles-charges-of-fair-credit-reporting-act-fcra-violations#comments</comments>
		<pubDate>Thu, 21 Jun 2012 17:41:23 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Fair Credit Reporting Act (FCRA)]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[Spokeo]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=1181</guid>
		<description><![CDATA[The Federal Trade Commission fined an online data broker who allegedly sold consumer reports containing internet and social media data in the context of employment screenings without adhering to the Fair Credit Reporting Act’s consumer protections. By Alice Cheng Data broker Spokeo recently agreed to pay $800,000 to settle Federal Trade Commission (FTC) charges in what [...]]]></description>
			<content:encoded><![CDATA[<h2><a href="http://olenderfeldman.com/practice-areas/labor-and-employment"><img class="alignleft size-full wp-image-1183" title="Employment Background Checks Lead to Fair Credit Reporting Act Violations " src="http://olenderfeldman.com/wp-content/uploads/skull-return.jpg" alt="Use of internet and social media data for background checks violated the Fair Credit Reporting Act (FCRA)" width="214" height="95" /></a></h2>
<h2 style="text-align: justify;">The Federal Trade Commission fined an online data broker who allegedly sold consumer reports containing internet and social media data in the context of employment screenings without adhering to the Fair Credit Reporting Act’s consumer protections.</h2>
<h4>By Alice Cheng</h4>
<p style="text-align: justify;">Data broker <a rel="nofollow" target="_blank" rel="nofollow" href="http://www.spokeo.com/">Spokeo</a> recently agreed to pay $800,000 to settle Federal Trade Commission (FTC) charges in what is the FTC’s first Fair Credit Reporting Act (FCRA) case involving the “sale of internet and social media data in the employment screening context.”</p>
<p style="text-align: justify;">Spokeo, a social network aggregator website, has long been notorious for the comprehensive profiles (including name, address, email address, phone number, hobbies, ethnicity, religion, etc.) it compiles and sells to third parties. Personal information of individuals is collected both online and offline, and profiles have been used for employment screening purposes—a practice that the FTC has alleged is in violation of <a rel="nofollow" target="_blank" href="http://www.ftc.gov/os/statutes/031224fcra.pdf">the FCRA</a>.</p>
<p style="text-align: justify;">The FTC recently took legal action against the company after receiving an initial complaint about its practices from the <a rel="nofollow" target="_blank" rel="nofollow" href="https://www.cdt.org/comments/complaint-ftc-matter-spokeo">Center of Democracy &amp; Technology</a> in 2010. The FCRA violations include failing to make sure that the information was sold for legally permissible uses only, failing to ensure that the information was accurate, and failing to notify users of the consumer reports about their obligations under FCRA.</p>
<p style="text-align: justify;">The FCRA is a federal law regulating the collection, dissemination, and use of consumer information (including consumer credit information) to promote the accuracy, fairness, and privacy of such information. In order to avoid violating FCRA regulations, Spokeo says it will no longer build “consumer reports” and will no longer sell its information for employment screening purposes.</p>
<p style="text-align: justify;">Aside from potential FCRA violations, such widespread collection of data by data aggregators like Spokeo continues to be an ongoing privacy issue. The collection of personally identifiable information, such as social security numbers or driver’s license numbers, carry obvious concerns, but <a href="http://olenderfeldman.com/privacy/why-protecting-%E2%80%9Cnon-sensitive%E2%80%9D-information-is-a-sensitive-subject">even the collection of “non-sensitive” information can be problematic</a>. Aggregation of this data is commonly <a href="http://olenderfeldman.com/privacy/behavioral-advertising-and-%E2%80%9Cdo-not-track%E2%80%9D-navigating-the-privacy-minefield">used by advertisers to target prospective customers</a>, or as in Spokeo’s case, sold to any willing buyers. While it may not always be easy to pinpoint any concrete harm to consumers, many are nevertheless uneasy about such compilations.</p>
<p style="text-align: justify;">While the FTC has been increasingly vigilant regarding big data concerns, little progress is being made in developing data protection regulations. Continual changes in technology, such as <a href="http://olenderfeldman.com/privacy/who-owns-your-data-and-what-can-they-do-with-it-understanding-data-privacy-and-information-security-in-the-cloud">the move to cloud computing services</a>, may also invite further complications to developing appropriate regulations.  Consumers need to be aware of what information is being collected and how it is used.  Businesses need to be aware of what laws, rules and regulations govern their collection and use of information so they can assure successful compliance.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/spokeo-settles-charges-of-fair-credit-reporting-act-fcra-violations/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Who Owns Your Data and What Can They Do With It? Understanding Data Privacy and Information Security in the Cloud</title>
		<link>http://olenderfeldman.com/privacy/who-owns-your-data-and-what-can-they-do-with-it-understanding-data-privacy-and-information-security-in-the-cloud</link>
		<comments>http://olenderfeldman.com/privacy/who-owns-your-data-and-what-can-they-do-with-it-understanding-data-privacy-and-information-security-in-the-cloud#comments</comments>
		<pubDate>Tue, 29 May 2012 07:00:19 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Litigation]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Security Regulations]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[FTC Compliance]]></category>
		<category><![CDATA[Information Privacy]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[Personally Identifiable Information (PHI)]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Policies]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=1096</guid>
		<description><![CDATA[“Cloud” Technology Offers Flexibility, Reduced Costs, Ease of Access to Information, But Presents Security, Privacy and Regulatory Concerns With the recent introduction of Google Drive, cloud computing services are garnering increased attention from entities looking to more efficiently store data. Specifically, using the “cloud” is attractive due to its reduced cost, ease of use, mobility and [...]]]></description>
			<content:encoded><![CDATA[<h2 style="text-align: justify;"><a href="http://olenderfeldman.com/attorneys/aaron-i-messing"><img class="alignleft size-full wp-image-1111" title="Cloud Computing Has Privacy, Data Security and Regulatory Concerns" src="http://olenderfeldman.com/wp-content/uploads/cloud-disk.jpg" alt="Check Cloud Contracts for Provisions Related to Privacy, Data Security and Regulatory Concerns" width="162" height="180" /></a>“Cloud” Technology Offers Flexibility, Reduced Costs, Ease of Access to Information, But Presents Security, Privacy and Regulatory Concerns</h2>
<p style="text-align: justify;">With the <a rel="nofollow" target="_blank" title="Cloud Computing Legal Issues" href="http://features.techworld.com/virtualisation/3355901/pondering-google-drive-who-owns-your-data-in-cloud/" rel="nofollow">recent introduction of Google Drive</a>, cloud computing services are garnering increased attention from entities looking to more efficiently store data. Specifically, using the “cloud” is attractive due to its reduced cost, ease of use, mobility and flexibility, each of which can offer tremendous competitive benefits to businesses. Cloud computing refers to the practice of storing data on remote servers, as opposed to on local computers, and is used for everything from personal webmail to hosted solutions where all of a company’s files and other resources are stored remotely. As convenient as cloud computing is, it is important to remember that these benefits may come with significant legal risk, given the <a title="Privacy Lawyers Recommend Embedding Privacy For FTC Compliance" href="http://olenderfeldman.com/privacy/putting-privacy-first">privacy and data protection issues</a> inherent in the use of cloud computing. Accordingly, it is important to check your cloud computing contracts carefully to ensure that your legal exposure is minimized in the event of a data breach or other security incident.</p>
<p style="text-align: justify;">Cloud computing allows companies convenient, remote access to their networks, servers and other technology resources, regardless of location, thereby creating “virtual offices” which allow employees remote access to their files and data which is identical in scope the access which they have in the office. The cloud offers companies flexibility and scalability, enabling them to pool and allocate information technology resources as needed, by using the minimum amount of physical IT resources necessary to service demand. These hosted solutions enable users to easily add or remove additional storage or processing capacity as needed to accommodate fluctuating business needs. By utilizing only the resources necessary at any given point, cloud computing can provide significant cost savings, which makes the model especially attractive to small and medium-sized businesses. However, the rush to use cloud computing services due to its various efficiencies often comes at the expense of data privacy and security concerns.</p>
<p style="text-align: justify;">The laws that govern cloud computing are (perhaps somewhat counterintuitively) geographically based on the physical location of the cloud provider’s servers, rather than the location of the company whose information is being stored. American state and federal laws concerning data privacy and security tend to vary while servers in Europe are subject to more comprehensive (and often more stringent) privacy laws. However, this may change, as the<a rel="nofollow" target="_blank" href="http://www.chron.com/?controllerName=search&amp;action=search&amp;channel=business%2Fpress-releases&amp;search=1&amp;inlineLink=1&amp;query=%22Federal+Trade+Commission%22">Federal Trade Commission</a> (FTC) has been investigating the privacy and <a rel="nofollow" target="_blank" title="FTC Investigates Privacy and Security of Cloud Computing" href="http://www.readwriteweb.com/enterprise/2010/01/ftc-to-investigate-cloud-compu.php" rel="nofollow">security implications of cloud computing</a> as well.</p>
<p style="text-align: justify;">In addition to location-based considerations, companies expose themselves to potentially significant liability depending on the types of information stored in the cloud. Federal, state and international laws all govern the storage, use and protection of certain types of personally identifiable information and protected health information. For example, the <a rel="nofollow" target="_blank" title="Massachusetts Data Security Regulations Safeguard Personally Identifiable Information" href="http://olenderfeldman.com/privacy/massachusetts-data-security-regulations">Massachusetts Data Security Regulations</a> require all entities that own or license personal information of Massachusetts residents to ensure appropriate physical, administrative and technical safeguards for their personal information (regardless of where the companies are physically located), with fines of up to $5,000 per incident of non-compliance. That means that the companies are directly responsible for the actions of their cloud computing service provider. <a href="http://www.chron.com/?controllerName=search&amp;action=search&amp;channel=business%2Fpress-releases&amp;search=1&amp;inlineLink=1&amp;query=%22Aaron+Messing%22">Aaron Messing</a>, an information privacy and technology attorney at OlenderFeldman LLP, notes that some information is inappropriate for storage in the cloud without proper precautions. &#8220;We strongly recommend against storing any type of personally identifiable information, such as birth dates or social security numbers in the cloud. Similarly, sensitive information such as financial records, medical records and confidential legal files should not be stored in the cloud where possible,&#8221; he says, “unless it is encrypted or otherwise protected.” In fact, even a <a title="Data Breach of Non-Sensitive Information Can Have Serious Legal Implications" href="http://olenderfeldman.com/privacy/why-protecting-%E2%80%9Cnon-sensitive%E2%80%9D-information-is-a-sensitive-subject">data breach related to non-sensitive information</a> can have serious adverse effects on a company’s bottom line and, perhaps more distressing, its public perception.</p>
<p style="text-align: justify;">Additionally, the information your company stores in the cloud will also be affected by <a title="Privacy Policies Can Form A Legally Binding Contract" href="http://olenderfeldman.com/privacy/what-do-i-need-to-look-for-in-a-privacy-policy">the rules set forth in the privacy policies</a> and terms of service of your cloud provider. Although these terms may seem like legal boilerplate, they may very well form a binding contract which you are presumed to have read and consented to. Accordingly, it is extremely important to have a grasp of what is permitted and required by your cloud provider’s privacy policies and terms of service. For example, the privacy policies and terms of service will dictate whether your cloud service provider is a data processing agent, which will only process data on your behalf or a data controller, which has the right to use the data for its own purposes as well. Notwithstanding the terms of your agreement, if the service is being provided for free, you can safely presume that the cloud provider is a data controller who will analyze and process the data for its own benefit, such as to serve you ads.</p>
<p style="text-align: justify;">Regardless, when sharing data with cloud service providers (or any other third party service providers)), it is important to obligate third parties to process data in accordance with applicable law, as well as your company’s specific instructions &#8212; especially when the information is personally identifiable or sensitive in nature. This is particularly important because in addition to the loss of goodwill, most data privacy and security laws hold companies, rather than service providers, responsible for compliance with those laws. That means that your company needs to ensure the data’s security, regardless of whether it’s in a third party’s (the cloud providers) control. It is important for a company to agree with the cloud provider as to the appropriate level of security for the data being hosted. <a rel="nofollow" target="_blank" href="http://www.chron.com/?controllerName=search&amp;action=search&amp;channel=business%2Fpress-releases&amp;search=1&amp;inlineLink=1&amp;query=%22Christian+Jensen%22">Christian Jensen</a>, a litigation attorney at OlenderFeldman LLP, recommends contractually binding third parties to comply with applicable data protection laws, especially where the law places the ultimate liability on you. “Determine what security measures your vendor employs to protect data,” suggests Jensen. “Ensure that access to data is properly restricted to the appropriate users.” Jensen notes that since data protection laws generally do not specify the levels of commercial liability, it is important to ensure that your contract with your service providers allocates risk via indemnification clauses, limitation of liabilities and warranties. Businesses should reserve the right to audit the cloud service provider’s data security and information privacy compliance measures as well in order to verify that the third party providers are adhering to its stated privacy policies and terms of service. Such audits can be carried out by an independent third party auditor, where necessary.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/who-owns-your-data-and-what-can-they-do-with-it-understanding-data-privacy-and-information-security-in-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC Releases Final Consumer Privacy Report</title>
		<link>http://olenderfeldman.com/privacy/ftc-releases-final-consumer-privacy-report</link>
		<comments>http://olenderfeldman.com/privacy/ftc-releases-final-consumer-privacy-report#comments</comments>
		<pubDate>Mon, 26 Mar 2012 17:54:45 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Corporate]]></category>
		<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Behavioral Advertising]]></category>
		<category><![CDATA[Behavioral Targeting]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[FTC Compliance]]></category>
		<category><![CDATA[Information Privacy]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Lawyer]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=853</guid>
		<description><![CDATA[The Federal Trade Commission (FTC) issued a final report setting forth best practices for businesses to protect the privacy of American consumers and give them greater control over the collection and use of their personal data, entitled "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers." ]]></description>
			<content:encoded><![CDATA[<h3>By <a rel="nofollow" target="_blank" title="Email Aaron" href="mailto:amessing@olenderfeldman.com">Aaron Messing</a></h3>
<p style="text-align: justify;">Today, the Federal Trade Commission (FTC) issued a final report setting forth best practices for businesses to protect the privacy of American consumers and give them greater control over the collection and use of their personal data, entitled <a rel="nofollow" target="_blank" href="http://ftc.gov/os/2012/03/120326privacyreport.pdf" target="_blank">&#8220;Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers.&#8221;</a> The FTC also issued a brief new <a rel="nofollow" target="_blank" href="http://onguardonline.gov/blog/ftc-releases-final-privacy-report" target="_blank">video</a> explaining the FTC&#8217;s positions.  Here are the key take-aways from the final report:</p>
<ul style="text-align: justify;">
<li><strong>Privacy by Design.</strong> Companies should incorporate privacy protections in developing their      products, and in their everyday business practices. These include      reasonable security for consumer data, limited collection and retention of      such data, and reasonable procedures to ensure that such data is accurate;</li>
<li><strong>Simplified Choice.</strong> Companies should give consumers the option to decide what information is      shared about them, and with whom. Companies should also give consumers that      choice at a time and in a context that matters to people, although choice      need not be provided for certain “commonly accepted practices” that the      consumer would expect.</li>
<li><strong>Do Not Track.</strong> Companies should include a Do-Not-Track mechanism that would provide a      simple, easy way for consumers to control the tracking of their online      activities.</li>
<li><strong>Increased Transparency.</strong> Companies should disclose details about their      collection and use of consumers&#8217; information, and provide consumers access      to the data collected about them.</li>
<li><strong>Small Businesses Exempt.</strong> The above restrictions do not apply to companies      who collect only non-sensitive data from fewer than 5,000 consumers a      year, provided they don’t share the data with third parties.</li>
</ul>
<p style="text-align: justify;">
<p>Interestingly, the FTC&#8217;s focus on consumer unfairness, rather than consumer deception, was something that FTC Commissioner Julie Brill hinted to me when we discussed overreaching <a href="http://olenderfeldman.com/privacy/big-data-big-issues-symposium-a-quick-chat-with-ftc-commissioner-julie-brill" target="_blank">privacy policies and terms of service</a> at Fordham University&#8217;s Big Data, Big Issues symposium earlier this month.</p>
<p style="text-align: justify;">If businesses want to minimize the chances of finding themselves the subject of an FTC investigation, they should be prepared to follow these best practices. If you have any questions about what the FTC’s guidelines mean for your business, please feel free to contact us.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/ftc-releases-final-consumer-privacy-report/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Privacy Lawyer Aaron Messing Presents Legal Considerations for Search and Social at SES New York 2012 Conference</title>
		<link>http://olenderfeldman.com/privacy/privacy-lawyer-presents-legal-considerations-for-search-and-social-at-ses-new-york-2012-conference</link>
		<comments>http://olenderfeldman.com/privacy/privacy-lawyer-presents-legal-considerations-for-search-and-social-at-ses-new-york-2012-conference#comments</comments>
		<pubDate>Sat, 24 Mar 2012 03:45:40 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Corporate]]></category>
		<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Behavioral Advertising]]></category>
		<category><![CDATA[Behavioral Targeting]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[e-Commerce]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[FTC Compliance]]></category>
		<category><![CDATA[Information Privacy]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Lawyer]]></category>
		<category><![CDATA[Regulated Industries]]></category>
		<category><![CDATA[Social Media]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=845</guid>
		<description><![CDATA[Companies are increasingly using a combination of search and social media to attract consumers. Here's some pitfalls to watch out for, and some best practices to keep your company FTC compliant, while respecting privacy.]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;"><a rel="nofollow" target="_blank" title="Privacy lawyer" href="http://olenderfeldman.com/attorneys/aaron-i-messing">Privacy lawyer</a> Aaron Messing gave a presentation on Wednesday at the SES New York 2012 conference about emerging legal issues in search engine optimization (SEO) and <a title="online behavioral advertising" href="http://olenderfeldman.com/privacy/behavioral-advertising-and-%E2%80%9Cdo-not-track%E2%80%9D-navigating-the-privacy-minefield">online behavioral advertising</a>. The topic of his presentation, <a href="http://sesconference.com/newyork/agenda-day2.php" rel="nofollow">Legal Considerations for Search &amp; Social in Regulated Industries</a>, focused on search and social media strategies in regulated industries. Regulated industries, which include healthcare, banking, finance, pharmaceuticals and publicly traded companies, among others, are subject to various government regulations, he said, but often lack sufficient guidance regarding acceptable practices in social media, search and targeted advertising.</p>
<p style="text-align: justify;">Messing began with a discussion of common methods that search engine optimization companies use to raise their client’s sites in the rankings. The top search spots are extremely competitive, and the difference between being on the first or second page can make a huge difference in a company’s bottom line. One of the ways that search engines determine the relevancy of a web page is through link analysis. Search engines examine which websites link to that page, and what the text of those links &#8212; the anchor text – says about the page, as well as the surrounding content, to determine relevance. In essence, these links and contents can be considered a form of online citations.</p>
<p style="text-align: justify;">A typical method used by SEO companies to raise website rankings is to generate content, using paid affiliates, freelance bloggers, or other webpages under the SEO company’s control, in order to increase the website’s ranking on search engines. However, since this content is mostly for the search engine spiders, and not for human consumption, the content is rarely screened, which can lead to issues with government agencies, especially in the regulated industries. This content also rarely contains disclosures that the author was paid to create the content, which could be unfair and deceiving to consumers. SEO companies dislike disclosing paid links and content because search engines penalize paid links. Messing said, “SEO companies are caught between the search engines, who severely penalize disclosure [of paid links], and the FTC, which severely penalizes nondisclosure.”</p>
<p style="text-align: justify;">The main enforcement agency is the Federal Trade Commission, which has the power to investigate and prevent <a rel="nofollow" target="_blank" href="http://ftc.gov/bcp/index.shtml">unfair and deceptive trade practices</a> across most industries, though other regulated industries have additional enforcement bodies. The FTC rules require full disclosure when there is a “material connection” between a merchant and someone promoting its product, such as a cash payment, or a gift item. Suspicious “reviews” or unsubstantiated content can raise attention, especially in regulated industries. “If a FTC lawyer sees one of these red flags, you could attract some very unwanted attention from the government,” Messing noted.</p>
<p style="text-align: justify;">Recently, the FTC has increased its focus on paid links, content and reviews. While the FTC requires mandatory disclosures, it doesn’t specify how those disclosures should be made. This can lead to confusion as to what the FTC considers adequate disclosure, and Messing said he expects the FTC to issue guidance on disclosures in the SEO, social media and mobile devices areas. “There are certain <a href="http://olenderfeldman.com/practice-areas/ecommerce-internet">ecommerce laws</a> that desperately need clarification,” said Messing.</p>
<p style="text-align: justify;">Messing stated that clients need to ask what their SEO company is doing and SEOs companies need to tell them, because ultimately, both can be held liable for unfair or deceptive content. He recommends ensuring that all claims made in SEO content be easily substantiated, and recommended building SEO through goodwill. “In the context of regulated industries,” he said, “consumers often visit healthcare or financial websites when they have a specific problem. If you provide them with valuable, reliable and understandable information, they will reward you with their loyalty.”</p>
<p style="text-align: justify;">Messing cautioned companies to be careful of what information they collect for behavioral advertising, and to consider the privacy ramifications. “Data is currency, but the more data a company holds, the more potential liability it is exposed to.” Messing expects further developments in privacy law, possibly in the form of legislation. In the meantime, he recommends using data responsibly, and in accordance with the <a href="http://olenderfeldman.com/privacy/why-protecting-%e2%80%9cnon-sensitive%e2%80%9d-information-is-a-sensitive-subject" target="_blank">data&#8217;s sensitivity</a>. “Developing policies for data collection, retention and deletion is crucial. Make sure your<a href="http://olenderfeldman.com/privacy/have-you-really-thought-about-the-practices-you-preach"> policies accurately reflect your practices</a>.” Finally, Messing noted that companies lacking a robust compliance program governing collection, protection and use of personal information may face significant risk of a data breach or legal violation, resulting litigation, and a hit to their bottom lines. He recommends speaking to a law firm that is experienced in privacy and <a href="http://olenderfeldman.com/practice-areas/business">legal compliance</a> for businesses to ensure that your practices do not attract regulatory attention.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/privacy-lawyer-presents-legal-considerations-for-search-and-social-at-ses-new-york-2012-conference/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aaron Messing to Speak at SES NY 2012 about Privacy and FTC Compliance</title>
		<link>http://olenderfeldman.com/privacy/aaron-messing-to-speak-at-ses-ny-2012-about-privacy-and-ftc-compliance</link>
		<comments>http://olenderfeldman.com/privacy/aaron-messing-to-speak-at-ses-ny-2012-about-privacy-and-ftc-compliance#comments</comments>
		<pubDate>Mon, 12 Mar 2012 13:24:59 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Behavioral Advertising]]></category>
		<category><![CDATA[Behavioral Targeting]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Business Risk]]></category>
		<category><![CDATA[Data Breach]]></category>
		<category><![CDATA[Data Security Regulations]]></category>
		<category><![CDATA[Do Not Track (DNT)]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[Information Privacy]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[Personally Identifiable Information (PHI)]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Lawyer]]></category>
		<category><![CDATA[Securities and Exchange Commission (SEC)]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=834</guid>
		<description><![CDATA[By Aaron Messing I will be speaking at SES New York 2012 conference about emerging legal issues in search engine optimization and online behavioral advertising. The panel will discuss  Legal Considerations for Search &#38; Social in Regulated Industries: Search in Regulated Industries Legal Considerations for Search &#38; Social in Regulated Industries Programmed by: Chris Boggs Since [...]]]></description>
			<content:encoded><![CDATA[<h2>By Aaron Messing</h2>
<p style="text-align: justify;">I will be speaking at SES New York 2012 conference about emerging legal issues in search engine optimization and <a rel="nofollow" target="_blank" href="http://olenderfeldman.com/privacy/behavioral-advertising-and-%E2%80%9Cdo-not-track%E2%80%9D-navigating-the-privacy-minefield">online behavioral advertising</a>. The panel will discuss  <a rel="nofollow" href="http://sesconference.com/newyork/agenda-day2.php">Legal Considerations for Search &amp; Social in Regulated Industries</a>:</p>
<blockquote style="text-align: justify;"><p>Search in Regulated Industries<br />
<strong>Legal Considerations for Search &amp; Social in Regulated Industries</strong><br />
<a rel="nofollow" target="_blank" rel="chris-boggs" href="http://sesconference.com/newyork/speaker-profiles.php#chris-boggs" rel="nofollow"><img src="http://www.searchenginestrategies.com/img/headshots/boggs-chris.jpg" rel="nofollow" alt="" /></a>Programmed by: <a rel="nofollow" target="_blank" rel="chris-boggs" href="http://sesconference.com/newyork/speaker-profiles.php#chris-boggs" rel="nofollow">Chris Boggs</a><br />
Since FDA letters to pharmaceutical companies began arriving in 2009, and with constantly increasing scrutiny towards online marketing, many regulated industries have been forced to look for ways to modify their legal terms for marketing and partnering with agencies and other 3rd party vendors. This session will address the following:</p>
<ul>
<li>Legal rules for regulated industries such as Healthcare/Pharmaceutical, Financial Services, and B2B, B2G</li>
<li>Interpretations and discussion around how Internet Marketing laws are incorporated into campaign planning and execution</li>
<li>Can a pharmaceutical company comfortably solicit inbound links in support of SEO?</li>
<li>Should Financial Services companies be limited from using terms such as &#8220;best rates?</li>
</ul>
<ul>
<li><em>Moderator:</em><br />
<a rel="nofollow" target="_blank" rel="chris-boggs" href="http://sesconference.com/newyork/speaker-profiles.php#chris-boggs" rel="nofollow">Chris Boggs</a>, SES Advisory Board; Director, SEO, Rosetta</li>
<li><em>Speakers:</em><br />
<a rel="nofollow" target="_blank" rel="thomas-catan" href="http://sesconference.com/newyork/speaker-profiles.php#thomas-catan" rel="nofollow">Thomas C. Catan</a>, Staff Reporter, Wall Street Journal<br />
<a rel="nofollow" target="_blank" rel="aaron-messing" href="http://sesconference.com/newyork/speaker-profiles.php#aaron-messing" rel="nofollow">Aaron Messing, Esq., CIPP</a>, Attorney, OlenderFeldman LLP<br />
<a rel="nofollow" target="_blank" rel="jamie-peck" href="http://sesconference.com/newyork/speaker-profiles.php#jamie-peck" rel="nofollow">Jamie Peck</a>, Managing Partner, Rosetta Healthcare<br />
<a rel="nofollow" target="_blank" rel="jud-soderborg" href="http://sesconference.com/newyork/speaker-profiles.php#jud-soderborg">Jud Soderborg</a>, SEO Manager, Reprise Media</li>
</ul>
</blockquote>
<p style="text-align: justify;">Looks like it will be a great panel. I will post my slideshow after the presentation.</p>
<p style="text-align: justify;"><strong>(Updated on 3.22.12 to add presentation below)</strong></p>
<div id="__ss_12116609" style="width: 425px; text-align: justify;"><strong><a rel="nofollow" target="_blank" title="Search and Social In Regulated Industries" href="http://www.slideshare.net/aaronmessing/search-and-social-in-regulated-industries">Search and Social In Regulated Industries</a></strong><object id="__sse12116609" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="wmode" value="transparent" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=presentationversion-regulatedindustries-120322094716-phpapp02&amp;stripped_title=search-and-social-in-regulated-industries&amp;userName=aaronmessing" /><param name="name" value="__sse12116609" /><param name="allowfullscreen" value="true" /><embed id="__sse12116609" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=presentationversion-regulatedindustries-120322094716-phpapp02&amp;stripped_title=search-and-social-in-regulated-industries&amp;userName=aaronmessing" name="__sse12116609" wmode="transparent" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="padding-top: 5px; padding-right: 0px; padding-bottom: 12px; padding-left: 0px; text-align: justify;">View more <a rel="nofollow" target="_blank" href="http://www.slideshare.net/">presentations</a> from <a rel="nofollow" target="_blank" href="http://www.slideshare.net/aaronmessing">aaronmessing</a>.</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/aaron-messing-to-speak-at-ses-ny-2012-about-privacy-and-ftc-compliance/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Big Data, Big Issues Symposium &#8211; A Quick Chat with FTC Commissioner Julie Brill</title>
		<link>http://olenderfeldman.com/privacy/big-data-big-issues-symposium-a-quick-chat-with-ftc-commissioner-julie-brill</link>
		<comments>http://olenderfeldman.com/privacy/big-data-big-issues-symposium-a-quick-chat-with-ftc-commissioner-julie-brill#comments</comments>
		<pubDate>Sat, 03 Mar 2012 00:40:25 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Corporate]]></category>
		<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=843</guid>
		<description><![CDATA[By Aaron Messing I had the pleasure of attending Fordham Law School&#8217;s Center on Law &#38; Information Policy (CLIP)&#8217;s Big Data, Big Issues Symposium today, which had a fascinating lineup of many of best thinkers in privacy. The Federal Trade Commission (FTC)&#8217;s  Julie Brill, delivered a very interesting keynote address about the benefits and dangers of big [...]]]></description>
			<content:encoded><![CDATA[<h3 style="text-align: justify;">By <a rel="nofollow" target="_blank" title="Email Aaron" href="mailto:amessing@olenderfeldman.com">Aaron Messing</a></h3>
<p style="text-align: justify;">I had the pleasure of attending Fordham Law School&#8217;s Center on Law &amp; Information Policy (CLIP)&#8217;s Big Data, Big Issues Symposium today, which had a fascinating lineup of many of best thinkers in privacy. The Federal Trade Commission (FTC)&#8217;s  Julie Brill, delivered a <a rel="nofollow" target="_blank" title="FTC Commissioner's Keynote Text" rel="nofollow" href="http://t.co/RVrcIGZs" target="_blank">very interesting keynote address</a> about the benefits and dangers of big data, as well as the evolving privacy concerns. The address is well worth a read.</p>
<p style="text-align: justify;">I had a chance to chat with Commissioner Brill after her speech, and asked her thoughts about privacy policies and terms of service that allow for unrestricted and unlimited use of data, such as the <a rel="nofollow" target="_blank" href="http://www.forbes.com/sites/andygreenberg/2012/01/25/the-worlds-worst-privacy-policy/" rel="nofollow" target="_blank">infamous Skipity policies</a>. Commissioner Brill stated that, given that most users don&#8217;t read privacy policies and terms of service, the FTC is very concerned by these types of one-sided policies. She mentioned that  the aggregation and use of data outside of the context of collection is something that the FTC hopes to issue guidance on in the future, and may well be unfair and deceptive regardless of a consumer&#8217;s consent.</p>
<p style="text-align: justify;">My takeaway from the chat is that consumer consent will not insulate a website from FTC scrutiny, and that the reasonable expectations of a consumer may dictate the FTC&#8217;s considerations of whether a policy is unfair or deceptive, especially given that so little attention is paid to these policies by consumers. However, at the same time, it is important that policies reflect the company&#8217;s <a href="http://olenderfeldman.com/privacy/have-you-really-thought-about-the-practices-you-preach">actual practices</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/big-data-big-issues-symposium-a-quick-chat-with-ftc-commissioner-julie-brill/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Behavioral Advertising and “Do Not Track”: Navigating the Privacy Minefield</title>
		<link>http://olenderfeldman.com/privacy/behavioral-advertising-and-%e2%80%9cdo-not-track%e2%80%9d-navigating-the-privacy-minefield</link>
		<comments>http://olenderfeldman.com/privacy/behavioral-advertising-and-%e2%80%9cdo-not-track%e2%80%9d-navigating-the-privacy-minefield#comments</comments>
		<pubDate>Tue, 28 Feb 2012 20:04:29 +0000</pubDate>
		<dc:creator>Aaron Messing</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Corporate]]></category>
		<category><![CDATA[Data Privacy & Information Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Behavioral Advertising]]></category>
		<category><![CDATA[Behavioral Targeting]]></category>
		<category><![CDATA[Do Not Track (DNT)]]></category>
		<category><![CDATA[e-Commerce]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Federal Trade Commission (FTC)]]></category>
		<category><![CDATA[Information Privacy]]></category>
		<category><![CDATA[Information Sharing]]></category>
		<category><![CDATA[Personally Identifiable Information (PHI)]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Privacy Lawyer]]></category>
		<category><![CDATA[Privacy Lawyers]]></category>

		<guid isPermaLink="false">http://olenderfeldman.com/?p=822</guid>
		<description><![CDATA[Do Not Track threatens to upend the existing business models of online publishers and advertisers, and overly intrusive tracking can alienate customers. OlenderFeldman LLP provides a status report on privacy law, FTC compliance and online behavioral advertising.]]></description>
			<content:encoded><![CDATA[<h3 style="text-align: justify;"><a rel="nofollow" target="_blank" href="www.olenderfeldman.com/blog"><img class="alignleft size-full wp-image-1073" title="Privacy Minefield Online Behavioral Tracking" src="http://olenderfeldman.com/wp-content/uploads/1159613_binary_code_1.jpg" alt="Navigating the Privacy Minefield - Online Behavioral Tracking" width="212" height="300" /></a>By <a rel="nofollow" target="_blank" title="Email Aaron" href="mailto:amessing@olenderfeldman.com">Aaron Messing</a></h3>
<p style="text-align: justify;">The Internet is fraught with privacy-related dangers for companies. For example, Facebook’s IPO filing contains multiple references to the various <a rel="nofollow" target="_blank" href="http://olenderfeldman.com/privacy/limits-of-privacy-on-facebook">privacy risks</a> that may threaten its business model, and it seems like every day a new class action suit is filed against Facebook alleging surreptitious tracking or other breaches of privacy laws. Google has recently faced a resounding public backlash related to its new uniform privacy policy, to the extent that <a rel="nofollow" href="http://techdailydose.nationaljournal.com/2012/02/scrutiny-over-google-privacy-c.php?mrefid=site_search">36 state attorney generals</a> are considering filing suit. New privacy legislation and regulatory activities have been proposed, with the Federal Trade Commission (FTC) taking an active role in enforcing compliance with the various privacy laws. The real game changer, however, might be the renewed popularity of “Do Not Track”, which threatens to upend the existing business models of online publishers and advertisers. “Do Not Track” is a proposal which would enable users to opt out of tracking by websites they do not visit, including analytics services, advertising networks, and social platforms.</p>
<p style="text-align: justify;">To understand the genesis of “Do Not Track” it is important to understand what online tracking is and how it works. If you visit any website supported by advertising (as well as many that are not), a number of tracking objects may be placed on your device. These online tracking technologies take many forms, including HTTP cookies, web beacons (clear GIFs), local shared objects or flash cookies, HTML5 cookies, browser history sniffers and browser fingerprinting. What they all have in common is that they use tracking technology to observe web users’ interests, including content consumed, ads clicked, and other search keywords and conversions  to track online movements, and build an online behavior profiles that are used to determine which ads are selected when a particular webpage is accessed. Collectively, these are known as behavioral targeting or advertising. Tracking technologies are also used for other purposes in addition to behavioral targeting, including site analytics, advertising metrics and reporting, and capping the frequency with which individual ads are displayed to users.</p>
<p style="text-align: justify;">The focus on behavioral advertising by advertisers and ecommerce merchants stems from its effectiveness. Studies have found that behavioral advertising <a rel="nofollow" target="_blank" rel="nofollow" href="http://research.microsoft.com/apps/pubs/default.aspx?id=80378">increases the click through rate by as much as 670%</a> when compared with non-targeted advertising. Accordingly, <a rel="nofollow" target="_blank" rel="nofollow" href="http://www.networkadvertising.org/pdfs/NAI_Beales_Release.pdf">behavioral advertising can bring in an average of 2.68 more</a> revenue than of non-targeted advertising.</p>
<p style="text-align: justify;">If behavioral advertising provides benefits such as increased relevance and usefulness to both advertisers and consumers, how has it become so controversial? Traditionally, advertisers have avoided collecting personally identifiable information (PII), preferring anonymous tracking data. However, new analytic tools and algorithms make it possible to combine “anonymous” information to create detailed profiles that can be associated with a particular computer or person. Formerly anonymous information can be re-identified, and companies are taking advantage in order to deliver increasingly targeted ads. Some of those practices have led to renewed privacy concerns. For example, recently <a rel="nofollow" target="_blank" rel="nofollow" href="http://www.nytimes.com/2012/02/19/magazine/shopping-habits.html?pagewanted=9&amp;_r=1&amp;hp">Target was able to identify that a teenager was pregnant</a> – before her father had any idea. It seems that Target has identified certain patterns in expecting mothers, and assigns shoppers a “pregnancy prediction score.” Apparently, the father was livid when his high-school age daughter was repeatedly targeted with various maternity items, only to later find out that, well, Target knew more about his daughter than he did (at least in that regard). Needless to say, some PII is more sensitive than others, but it is almost always alarming when you don’t know what others know about you.</p>
<p style="text-align: justify;">Ultimately, most users find it a little creepy when they find out that Facebook tracks your web browsing activity through their “Like” button, or that detailed profiles of their browsing history exist that could be associated with them. According to a recent <a rel="nofollow" target="_blank" rel="nofollow" href="http://www.gallup.com/poll/145337/Internet-Users-Ready-Limit-Online-Tracking-Ads.aspx">Gallup poll</a>, 61% of individuals polled felt the privacy intrusion presented by tracking was not worth the free access to content. 67% said that advertisers should not be able to match ads to specific interests based upon websites visited.</p>
<p style="text-align: justify;">The wild west of internet tracking may soon be coming to a close. The FTC has <a rel="nofollow" target="_blank" rel="nofollow" href="http://www.ftc.gov/opa/2010/12/privacyreport.shtm">issued its recommendations for Do Not Track</a>, which they recommend be instituted as a browser based mechanism through which consumers could make persistent choices to signal whether or not they want to be tracked or receive targeted advertising. However, you shouldn’t wait for an FTC compliance notice to <a href="http://olenderfeldman.com/privacy/putting-privacy-first">start rethinking your privacy practices</a>.</p>
<p style="text-align: justify;">It goes without saying that companies are required to follow the existing privacy laws. However, it is important to not only <a rel="nofollow" target="_blank" href="www.olenderfeldman.com" target="_blank">speak with a privacy lawyer</a> to ensure compliance with existing privacy laws and regulations (the FTC compliance division also monitors whether companies comply with posted privacy policies and terms of service) but also to ensure that your tracking and analytics are done in an non-creepy, non-intrusive manner that is clearly communicated to your customers and enables them to opt-in, and gives them an opportunity to opt out at their discretion. Your respect for your consumers’ privacy concerns will reap long-term benefits beyond anything that surreptitious tracking could ever accomplish.</p>
]]></content:encoded>
			<wfw:commentRss>http://olenderfeldman.com/privacy/behavioral-advertising-and-%e2%80%9cdo-not-track%e2%80%9d-navigating-the-privacy-minefield/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
