Now Available:

line

Featured Resources:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Rebecca.

« Cloudy Privacy Computing | Main | Data Privacy Day Activities That Deserve Recognition »

New Online Behavioral Advertising Principles: Self Regulation Does Not Mean Less Scrutiny By The FTC!

On February 12 the U.S. Federal Trade Commission (FTC), the most actively aggressive oversight agency in the U.S. with regard to enforcing privacy protections, released new behavioral advertising principles...

"FTC Staff Report: February 2009 Self-Regulatory Principles For Online Behavioral Advertising"

This is a good and interesting read; check it out. See how it aligns with your organization's marketing activities and plans.

This report fundamentally supports the FTC's many activities related to protecting consumer privacy, and holding organizations responsible for not only providing appropriate safeguards, but also to following their own (legally binding) posted privacy policies.

Giving clear "notice," a fundamental privacy principle, is indeed an important activity, but one that too many organizations overlook or simply do not invest the time in doing. Thus the criticism from a wide variety of privacy oversight groups with regard to self-regulation. Obtaining consent, providing choice, and de-identification of personal information are also important activities.

As stated in the FTC's press release about the new principles:

"The report notes, however, that regardless of the scope of the principles, companies must still comply with all applicable privacy laws, some of which may impose requirements that are similar to those established by the principles.

The report also provides additional guidance regarding each of the four principles and sets forth revised principles reflecting this guidance. The first principle - transparency and consumer control - remains unchanged from the proposed principles. Accordingly, Web sites are expected to provide clear and prominent notice regarding behavioral advertising, as well as an easily accessible way for consumers to choose whether to have their information collected for such purpose. Noting that privacy policies posted on companies' Web sites often are long and difficult to understand, the report encourages firms to design creative and effective disclosure mechanisms that are separate from their privacy policies. The report also states that companies that collect information outside the traditional Web site context - for example, through a mobile device or by an Internet Service Provider - should develop disclosure mechanisms that are meaningful and effective for these contexts.

In addition, the report continues to urge companies to provide reasonable security for any data they collect for behavioral advertising and to retain data only as long as it is needed to fulfill a legitimate business or law enforcement need.

As to the material change principle, the report clarifies that its focus is on retroactive changes - for example, material changes to a privacy policy that affect information a company collected prior to the changes. Accordingly, the principle has been revised to reflect that clarification. The report recognizes that prospective changes require a more flexible approach, and that depending on the circumstances, some form of prominent notice and opt-out choice may be sufficient.

Finally, due to the heightened privacy concerns raised by the collection and use of consumers' sensitive data, the report continues to urge companies to obtain affirmative express consent before collecting such data for behavioral advertising. The report states that FTC staff has traditionally considered financial information, information about children, health information, and Social Security numbers to be sensitive, but encourages stakeholders to develop more specific standards to address this issue.

Today's report is the next step in an ongoing process to examine online behavioral advertising that involves the FTC, industry, consumer and privacy organizations, and individual consumers. The report notes that significant work in this area remains, and that FTC staff will continue the public dialogue regarding the privacy issues raised by behavioral advertising. In the coming year, staff also will evaluate self-regulatory programs and will conduct investigations, where appropriate, to determine whether practices in this industry violate Section 5 of the FTC Act. The Commission vote to approve the report was 4-0, with separate concurring statements from Commissioners Jon Leibowitz and Pamela Jones Harbour:

"This staff report, while commendable, focuses too narrowly," Harbour said. "Threats to consumer privacy abound, both online and offline, and behavioral advertising represents just one aspect of a multifaceted privacy conundrum surrounding data collection and use. I would prefer that the Commission take a more comprehensive approach to privacy, and evaluate behavioral advertising within that broader context."

"Industry needs to do a better job of meaningful, rigorous self-regulation, or it will certainly invite legislation by Congress and a more regulatory approach by our Commission," Leibowitz said. "Put simply, this could be the last clear chance to show that self-regulation can - and will - effectively protect consumers' privacy in a dynamic online marketplace.""


So, U.S. businesses had better start proactively protecting personally identifiable information (PII) and performing all the recommended privacy principles, such as giving notice, obtaining clear consent, and so on, which are already required by many laws worldwide. Otherwise, you will likely get not only fines and penalties from the FTC, but the government may very well inact tougher and more restrictive privacy legal requirements.

It makes sense that if self-regulation does not work, that laws will be put in place to make sure businesses do the right thing with regard to PII privacy protection.

TrackBack

TrackBack URL for this entry:
http://www.realtime-itcompliance.com/type/mt-tb.cgi/933

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Rebecca Herold's Bio:

Rebecca Herold, CISSP, CIPP, CISM, CISA, FLMI, has been providing information security, privacy and regulatory assistance and services to organizations from a wide range of industries for the past two decades. Rebecca was instrumental in building the information security and privacy program while at Principal Financial Group, which was awarded the CSI Information Security Program of the Year Award in 1998. IT Security ranked Rebecca as one of the top 59 IT security influencers, and Computerworld put Rebecca their list of the world's best privacy experts and on their list of the best privacy consulting firms in both 2007 and 2008. Rebecca has been CPO for two consulting organizations, and has had her own information privacy, security and compliance business since 2004. Rebecca has written chapters for several books, dozens of articles, and has been writing a monthly privacy column for the CSI Alert newsletter since the beginning of 2001, and is working on her 13th book. Some of her other books include The Privacy Papers, Managing an Information Security and Privacy Awareness and Training Program, The Definitive Guide to Security Inside the Perimeter (Realtime Publishers), The Shortcut Guide to Improving IT Service Support through ITIL (Realtime Publishers), and The Practical Guide to HIPAA Privacy and Security Compliance. In addition, Rebecca is the leader of The Realtime IT Compliance Community where she posts to her IT Compliance weblog. You can contact Rebecca at: rebecca_herold@realtimepublishers.net.