Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

Monday, April 1, 2024

The Federal Trade Commission 2023 Privacy and Data Security Update

"The past three years have been a tremendously busy period for the Commission, and I am particularly proud of our accomplishments in the areas of privacy and data security. We have worked vigorously to ensure that the law has equal force across the digital ecosystem, rising to the challenges presented by new technologies and seeking meaningful remedies that establish critical standards for protecting consumers’ information, rather than placing the burden on consumers to protect themselves. This is an area that demands an all-hands-on-deck response, and as the examples in the report show, the Commission is using every tool it has to safeguard consumers’ rights. To highlight a few of the agency’s achievements:

• Artificial Intelligence: The Commission has been leading efforts to ensure that AI and similar technologies are not deployed in harmful ways. In addition to obtaining orders against Rite Aid, Ring, and Amazon to ensure that companies are disincentivized from using data that was wrongfully collected or trained to develop AI, we have initiated a market study of social media and video streaming platforms on the use of AI, announced a public contest to develop new approaches to protect consumers from AI-enabled voice cloning harms, proposed rules to crack down on AI-fueled impersonator and fake review fraud, and issued numerous business guidance alerts.

• Children and Teens: The Commission proposed strengthening the Children’s Online Privacy Protection Act to make digital services safer and more secure for children, and to put the onus on providers rather than parents to keep kids’ data secure. The Commission has also been active in the enforcement arena, obtaining a record-breaking civil penalty settlement with Epic Games, and implementing substantive protections for teens as well, by mandating that settings default to protect their privacy. Our work in the educational technology space—including our case against Edmodo and policy statement on education technology—sent a strong message that businesses cannot outsource compliance when it comes to children’s privacy. 1 This Update covers the time period from January 2021 to December 2023. 2023 Privacy and Data Security Update FEDERAL TRADE COMMISSION FTC.GOV 2

• Sensitive Data: As the privacy threats from data collection continue to grow, protecting the privacy and security of consumers' sensitive data has continued to be a top Commission priority. The Commission’s groundbreaking actions to safeguard health, biometric, and geolocation data—including BetterHelp, GoodRx Holdings, Premom, Flo Heath, RiteAid, and Kochava, along with the InMarket, X-Mode, and Avast cases that were filed after the time period covered by this update—demonstrate that our agency will not tolerate failures to protect consumers’ sensitive information at any stage in the data lifecycle

. • Market-wide Protections: The Commission initiated rulemaking initiatives to establish sensible and reasonable baselines that protect consumers and put honest businesses on a level playing field. These included amendments to require financial institutions to notify the FTC of large data breaches, notices of proposed rulemaking to clarify the application of the Health Breach Notification Rule to health apps and strengthen the Children’s Online Privacy Protection Act Rule, and an advanced notice of proposed rulemaking to explore rules that would crack down on harmful commercial surveillance and lax data security.

While the work of the FTC’s attorneys, economists, investigators, technologists, and other specialists has made enormous strides in protecting the privacy and security of consumers’ information, there is much more that needs to be done. The explosive growth in data collection and the rapid pace of technological developments that allow information to be exploited in new ways demands action. The Commission has consistently called on Congress to restore its ability under Section 13(b) of the FTC Act to return money to consumers in federal court, and to pass comprehensive privacy legislation. As the data abuses described in this report makes clear, that ask is more urgent than ever.."
FTC Privacy and Data Security 

Wednesday, December 7, 2022

Computer Matching and Privacy Protection Act: Data Integration and Individual Rights

"Computers and information technologies have increased the amount of data that can be collected, stored, and processed. Computers make it easier to exchange, share, and match data on individuals across programmatic and agency boundaries, enabling the use of that data for various executive branch operations.

The Computer Matching and Privacy Protection Act of 1988 (CMPPA) provides the requirements and processes by which agencies may, for certain purposes, conduct a matching program using individuals’ data. Congress passed the CMPPA to increase the administrative controls and oversight of matching programs. The CMPPA amended provisions enacted by the Privacy Act of 1974 and operates within the Privacy Act’s statutory framework.

The CMPPA covers how agencies may conduct a computerized comparison of automated records to administer federal benefit programs or to use federal personnel and payroll records. A matching program may involve two or more federal agencies or a federal agency and a state or local government agency.

Matching programs are used throughout the executive branch at agencies such as the Department of Health and Human Services, the Department of Homeland Security, the Federal Communications Commission, the Small Business Administration, the Social Security Administration, and the Department of the Treasury. A matching program may exchange and compare any number of records, and some match millions of records. 

The CMPPA establishes a number of requirements for agencies conducting matching programs. These requirements include the execution of written matching agreements that contain a number of specifics on the conduct of matching programs, costbenefit analyses of matching programs and documentation of specific savings, and the establishment of a Data Integrity Board (DIB) within each federal agency that conducts or participates in a matching program to approve matching agreements and oversee matching programs. Matching agreements are to be available to the public and may be published on an agency’s website. An agency’s DIB is required to submit to the agency head and the Office of Management and Budget (OMB) an annual report that describes the agency’s matching activities.."
Computer Matching and Privacy 

Monday, October 17, 2022

Data Protection and Privacy Law: An Introduction

"Recent controversy surrounding how third parties protect the privacy of individuals in the digital age has raised national concerns over legal protections of Americans’ electronic data. The current legislative paradigms governing cybersecurity and data privacy are complex and technical and lack uniformity at the federal level. This In Focus provides an introduction to data protection laws and an overview of considerations for Congress. (For a more detailed analysis, see CRS Report R45631, Data Protection Law: An Overview, by Stephen P. Mulligan, Wilson C. Freeman, and Chris D. Linebaugh.)

Defining Data Protection

As a legislative concept, data protection melds the fields of data privacy (i.e., how to control the collection, use, and dissemination of personal information) and data security (i.e., how to protect personal information from unauthorized access or use and respond to such unauthorized access or use). Historically, many laws addressed these issues separately, but more recent data protection initiatives indicate a trend toward combining data privacy and security into unified legislative schemes.

Federal Data Protection Laws

While the Supreme Court has interpreted the Constitution to provide individuals with a right to privacy, this right generally guards only against government intrusions. Given the limitations in constitutional law, Congress has enacted a number of federal laws designed to provide statutory protections of individuals’ personal information. However, these statutory protections are not comprehensive in nature and primarily regulate certain industries and subcategories of data. ."
Data protection and privacy 

Thursday, January 18, 2018

Privacy & Data Security Update (2017): An Overview of the Commission’s Enforcement, Policy Initiatives, and Consumer Outreach and Business Guidance in the Areas of Privacy and Data Security: January 2017 – December 2017

"Federal Trade Commission 2017 Privacy and Data Security Update.

The Federal Trade Commission (FTC or Commission) is an independent U.S. law enforcement agency charged with protecting consumers and enhancing competition across broad sectors of the economy. The FTC’s primary legal authority comes from Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive practices in the marketplace. The FTC also has authority to enforce a variety of sector specific laws, including the Truth in Lending Act, the CAN-SPAM Act, the Children’s Online Privacy Protection Act, the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the Fair Debt Collection Practices Act, and the Telemarketing and Consumer Fraud and Abuse Prevention Act. This broad authority allows the Commission to address a wide array of practices affecting consumers, including those that emerge with the development of new technologies and business models.
How Does the FTC Protect Consumer Privacy and Promote Data Security?

 The FTC uses a variety of tools to protect consumers’ privacy and personal information. The FTC’s principal tool is to bring enforcement actions to stop law violations and require companies to take affirmative steps to remediate the unlawful behavior. This includes, when appropriate, implementation of comprehensive privacy and security programs, biennial assessments by independent experts, monetary redress to consumers, disgorgement of ill-gotten gains, deletion of illegally obtained consumer information, and providing robust transparency and choice mechanisms to consumers. If a company violates an FTC order, the FTC can seek civil monetary penalties for the violations. The FTC can also obtain civil monetary penalties for violations of certain privacy statutes and rules, including the Children’s Online Privacy Protection Act, the Fair Credit Reporting Act, and the Telemarketing Sales Rule. To date, the Commission has brought hundreds of privacy and data security cases protecting billions of consumers..."
FTC privacy and data security report

Tuesday, May 26, 2015

Department of Justice Policy Guidance1 Domestic Use of Unmanned Aircraft Systems (UAS)

"The law enforcement agencies of the Department of Justice ("the Department") work diligently to protect the American people from national security threats, enforce our nation's laws, and ensure public safety. In doing so, these agencies use a wide variety of investigative methods. Some of these methods have been in use for decades; others are relatively new and rely on technological innovation. In all cases, investigations and other activities must be conducted consistent with the Constitution and the laws of the United States-and with our commitment to protecting privacy and civil liberties..."
Drone policy

Thursday, July 17, 2014

Privacy Protection for Customer Financial Information

"One of the functions transferred to the Consumer Financial Protection Bureau (CFPB) under P.L.
111-203, the Dodd-Frank Wall Street Reform and Consumer Protection Act (Dodd-Frank), is authority to issue regulations and take enforcement actions under the two major federal statutes that specify conditions under which customer financial information may be shared by financial institutions: Title V of the Gramm-Leach-Bliley Act of 1999 (GLBA, P.L. 106-102) and the Fair Credit Reporting Act (FCRA). Possible topics for congressional oversight in the 113
th Congress include (1) the transition of power from the fina ncial institution prudential regulators and the Federal Trade Commission to the CFPB; (2) CFPB’s interaction with other federal regulators and coordination with state enforcement efforts; and (3) the CFPB’s success at issuing rules that adequately protect consumers without unreasonably increasing the regulatory burden on financial institutions.."
Privacy and Financial Information

Wednesday, July 3, 2013

Revised Children's Online Privacy Protection Rule Goes Into Effect Today

"The Federal Trade Commission’s revised Children’s Online Privacy Protection Act Rule took effect today, giving parents greater control over the online collection of their children’s personal information. The revised COPPA rule culminates more than two years of review by the agency to modernize the rule..."
Revised Children Online Privacy Protection Rules

Tuesday, March 26, 2013

Cloud Computing: Constitutional and Statutory Privacy Protections

"In light of this rapidly changing technology, there have been several legislative proposals to
augment the Fourth Amendment’s protections for digital communications and update existing
statutory protections like the SCA for information shared and stored in the cloud.."
https://www.fas.org/sgp/crs/misc/R43015.pdf

Tuesday, November 20, 2012

Privacy: An Overview of Federal Statutes Governing Wiretapping and Electronic Eavesdropping

"This report provides an overview of the Electronic Communications Privacy Act (ECPA) and the
Foreign Intelligence Surveillance Act (FISA). ECPA consists of three parts. The first, often
referred to as Title III, outlaws wiretapping and electronic eavesdropping, except as otherwise
provided. The second, the Stored Communications Act, governs the privacy of, and government
access to, the content of electronic communications and to related records. The third outlaws the
use and installation of pen registers and of trap and trace devices, unless judicially approved for
law enforcement or intelligence gathering purposes..."
http://www.fas.org/sgp/crs/intel/98-326.pdf

Thursday, May 3, 2012

United States v Jones: GPS Monitoring, Property, and Privacy

"In United States v Jones, 132 S. Ct. 945 (20120, all nine Supreme Court Justices agreed that Jones was searched when the police attached a Global Positioning System (GPS) device to the undercarriage of this car and tracked his movements for four weeks. The Court, however, splintered on what constituted the search: the attachment of the device or the long-term monitoring. The majority held that the attachment of the GPS  device and an attempt to obtain information was the violation; Justice Alito, concurring, argued that the monitoring was a violation of  Jones's reasonable expectation of privacy; and Justice Sotomayer, also concurring, agreed with them both, but would provide further Fourth Amendment protections. This report will examine these three decisions in an effort to find their place in the body of existing Fourth Amendment laws pertaining to privacy, property, and technology..."

Tuesday, March 27, 2012

FTC Issues Final Commission Report on Protecting Consumer Privacy

"The Federal Trade Commission, the nation's chief privacy policy and enforcement agency, issued a final report setting forth best practices for businesses to protect the privacy of American consumers and give them greater control over the collection and use of their personal data. In the report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations For Businesses and Policymakers," the FTC also recommends that Congress consider enacting general privacy legislation, data security and breach notification legislation, and data broker legislation..."

Saturday, February 25, 2012

Consumer Privacy Bill of Rights

"The Obama Administration today unveiled a “Consumer Privacy Bill of Rights” as part of a comprehensive blueprint to improve consumers’ privacy protections and ensure that the Internet remains an engine for innovation and economic growth. The blueprint will guide efforts to give users more control over how their personal information is used on the Internet and to help businesses maintain consumer trust and grow in the rapidly changing digital environment. At the request of the White House, the Commerce Department will begin convening companies, privacy advocates and other stakeholders to develop and implement enforceable privacy policies based on the Consumer Privacy Bill of Rights..."

Tuesday, December 27, 2011

Governmental Tracking of Cell Phones and Vehicles: The Confluence of Privacy, Technology, and Law

"This report will briefly survey Fourth Amendment law as it pertains to the government’s tracking programs. It will then summarize federal electronic surveillance statutes and the case law surrounding cell phone location tracking. Next, the report will describe the GPS-vehicle tracking cases and review the pending Supreme Court GPS tracking case, United States v. Jones. Finally, the report will summarize the geolocation and electronic surveillance legislation introduced in the
112th Congress..."

Monday, October 10, 2011

FTC Testifies on Protecting Children Online

"The Federal Trade Commission today told a House Subcommittee that it is committed to protecting children online, and that the agency recently proposed changes to the Children’s Online Privacy Protection Rule (COPPA Rule) to make sure the Rule keeps pace with fast-changing technology.

Delivering testimony on behalf of the FTC, the agency’s Associate Director for Advertising Practices, Mary K. Engle, told the House Committee on Energy and Commerce, Subcommittee on Commerce, Manufacturing and Trade, that the FTC has actively promoted adherence to the COPPA Rule through enforcement actions and by educating businesses and consumers. The modifications to the Rule proposed by the FTC last month are designed to make sure that the Rule continues to be effective even as evolving technology is changing the way children access and use the Internet, the testimony states..."

Wednesday, May 25, 2011

Privacy Protection and for Personal Information Online
"There is no comprehensive federal privacy statute that protects personal information. Instead, a patchwork of federal laws and regulations govern the collection and disclosure of personal information and has been addressed by Congress on a sector-by-sector basis. Federal laws and regulations extend protection to consumer credit reports, electronic communications, federal agency records, education records, bank records, cable subscriber information, video rental
records, motor vehicle records, health information, telecommunications subscriber information, children’s online information, and customer financial information. Some contend that this patchwork of laws and regulations is insufficient to meet the demands of today’s technology. Congress, the Obama Administration, businesses, public interest groups, and citizens are all involved in the discussion of privacy solutions. This report examines some of those efforts with respect to the protection of personal information. This report provides a brief overview of selected recent developments in the area of federal privacy law. This report does not cover
workplace privacy laws or state privacy laws..."

Thursday, April 21, 2011

Privacy Protections for Personal Information Online
"There is no comprehensive federal privacy statute that protects personal information. Instead, a patchwork of federal laws and regulations govern the collection and disclosure of personal information and has been addressed by Congress on a sector-by-sector basis. Federal laws and regulations extend protection to consumer credit reports, electronic communications, federal agency records, education records, bank records, cable subscriber information, video rental records, motor vehicle records, health information, telecommunications subscriber information,
children’s online information, and customer financial information. Some contend that this patchwork of laws and regulations is insufficient to meet the demands of today’s technology. Congress, the Obama Administration, businesses, public interest groups, and citizens are all involved in the discussion of privacy solutions. This report examines some of those efforts with respect to the protection of personal information. This report provides a brief overview of selected recent developments in the area of federal privacy law. This report does not cover workplace privacy laws or state privacy laws..."

Wednesday, January 19, 2011

Statistical Methods for Protecting Personally Identifiable Information in Aggregate Reporting
"This Statewide Longitudinal Data Systems (SLDS) Technical Brief examines what protecting student privacy means in a reporting context. To protect a student’s privacy, the student’s personally identifiable information must be protected from public release. When schools, districts, or states publish reports on students’ educational progress, they typically release aggregated data—data for groups of students—to prevent disclosure of information about an individual. However, even with aggregation, unintended disclosures of personally identifiable information may occur. Current reporting practices are described and each is accompanied by an example table that is used to consider whether the intended protections are successful..."

Saturday, December 4, 2010

FTC Staff Issues Privacy Report Offers Framework for Consumers, Businesses, and Policymakers
"Endorses “Do Not Track” to Facilitate Consumer Choice About Online Tracking
The Federal Trade Commission, the nation’s chief privacy policy and enforcement agency for 40 years, issued a preliminary staff report today that proposes a framework to balance the privacy interests of consumers with innovation that relies on consumer information to develop beneficial new products and services. The proposed report also suggests implementation of a “Do Not Track” mechanism – likely a persistent setting on consumers’ browsers – so consumers can choose whether to allow the collection of data regarding their online searching and browsing activities.

“Technological and business ingenuity have spawned a whole new online culture and vocabulary – email, IMs, apps and blogs – that consumers have come to expect and enjoy. The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation and consumer choice. We believe that’s what most Americans want as well,” said FTC Chairman Jon Leibowitz.

The report states that industry efforts to address privacy through self-regulation “have been too slow, and up to now have failed to provide adequate and meaningful protection.” The framework outlined in the report is designed to reduce the burdens on consumers and businesses..."

Friday, December 4, 2009

FTC Website Educates Kids about Privacy and Fraud
"Today, the Federal Trade Commission opened new areas of a “virtual mall” with content that will help kids learn to protect their privacy, spot frauds and scams, and avoid identity theft. The FTC Web site, www.ftc.gov/YouAreHere, introduces key consumer and business concepts and helps youngsters understand their role in the marketplace. The FTC is the nation’s consumer protection agency.

YouAreHere presents practical lessons about money and business in a fun and familiar setting,” said David Vladeck, Director of the FTC’s Bureau of Consumer Protection. “The new content takes kids behind the scenes to raise their awareness of advertising and marketing, pricing and competition, fraud and identity theft.

At the FTC’s online mall, visitors play games, watch short animated films, and interact with customers and store owners. They can design and print advertisements for a shoe store, investigate suspicious claims in ads and sales pitches, learn to identify the catches behind bogus modeling schemes and vacation offers, and guess the retail prices of various candies based on their supply, demand, and production costs..."

Tuesday, January 20, 2009

Guide to Protecting the Confidentiality of Personally Identifiable Information (PII) (Draft), Recommendations of the National Institute of Standards and Technology, January 13, 2009.
"Breaches of personally identifiable information (PII) have increased dramatically over the past few years and have resulted in the loss of millions of records.1 Breaches of PII are hazardous to both individuals and organizations. Individual harms may include identity theft, embarrassment, or blackmail. Organizational harms may include a loss of public trust, legal liability, or high costs to handle the breach. To appropriately protect the confidentiality of PII, organizations should use a risk-based approach; as McGeorge Bundy2 once stated, “If we guard our toothbrushes and diamonds with equal zeal, we will lose fewer toothbrushes and more diamonds.” This document provides guidelines for a risk-based approach to protecting the confidentiality3 of PII..."