"The past three years have been a tremendously busy period for the Commission, and I
am particularly proud of our accomplishments in the areas of privacy and data security.
We have worked vigorously to ensure that the law has equal force across the digital
ecosystem, rising to the challenges presented by new technologies and seeking
meaningful remedies that establish critical standards for protecting consumers’
information, rather than placing the burden on consumers to protect themselves. This is
an area that demands an all-hands-on-deck response, and as the examples in the
report show, the Commission is using every tool it has to safeguard consumers’ rights.
To highlight a few of the agency’s achievements:
• Artificial Intelligence: The Commission has been leading efforts to ensure that
AI and similar technologies are not deployed in harmful ways. In addition to
obtaining orders against Rite Aid, Ring, and Amazon to ensure that companies
are disincentivized from using data that was wrongfully collected or trained to
develop AI, we have initiated a market study of social media and video streaming
platforms on the use of AI, announced a public contest to develop new
approaches to protect consumers from AI-enabled voice cloning harms,
proposed rules to crack down on AI-fueled impersonator and fake review fraud,
and issued numerous business guidance alerts.
• Children and Teens: The Commission proposed strengthening the Children’s
Online Privacy Protection Act to make digital services safer and more secure for
children, and to put the onus on providers rather than parents to keep kids’ data
secure. The Commission has also been active in the enforcement arena,
obtaining a record-breaking civil penalty settlement with Epic Games, and
implementing substantive protections for teens as well, by mandating that
settings default to protect their privacy. Our work in the educational technology
space—including our case against Edmodo and policy statement on education
technology—sent a strong message that businesses cannot outsource
compliance when it comes to children’s privacy.
1 This Update covers the time period from January 2021 to December 2023.
2023 Privacy and Data Security Update
FEDERAL TRADE COMMISSION FTC.GOV 2
• Sensitive Data: As the privacy threats from data collection continue to grow,
protecting the privacy and security of consumers' sensitive data has continued to
be a top Commission priority. The Commission’s groundbreaking actions to
safeguard health, biometric, and geolocation data—including BetterHelp,
GoodRx Holdings, Premom, Flo Heath, RiteAid, and Kochava, along with the
InMarket, X-Mode, and Avast cases that were filed after the time period covered
by this update—demonstrate that our agency will not tolerate failures to protect
consumers’ sensitive information at any stage in the data lifecycle
.
• Market-wide Protections: The Commission initiated rulemaking initiatives to
establish sensible and reasonable baselines that protect consumers and put
honest businesses on a level playing field. These included amendments to
require financial institutions to notify the FTC of large data breaches, notices of
proposed rulemaking to clarify the application of the Health Breach Notification
Rule to health apps and strengthen the Children’s Online Privacy Protection Act
Rule, and an advanced notice of proposed rulemaking to explore rules that would
crack down on harmful commercial surveillance and lax data security.
While the work of the FTC’s attorneys, economists, investigators, technologists, and
other specialists has made enormous strides in protecting the privacy and security of
consumers’ information, there is much more that needs to be done. The explosive
growth in data collection and the rapid pace of technological developments that allow
information to be exploited in new ways demands action. The Commission has
consistently called on Congress to restore its ability under Section 13(b) of the FTC Act
to return money to consumers in federal court, and to pass comprehensive privacy
legislation. As the data abuses described in this report makes clear, that ask is more
urgent than ever.."
FTC Privacy and Data Security
Monday, April 1, 2024
The Federal Trade Commission 2023 Privacy and Data Security Update
Wednesday, December 7, 2022
Computer Matching and Privacy Protection Act: Data Integration and Individual Rights
"Computers and information technologies have increased the amount of data that can be collected,
stored, and processed. Computers make it easier to exchange, share, and match data on
individuals across programmatic and agency boundaries, enabling the use of that data for various
executive branch operations.
The Computer Matching and Privacy Protection Act of 1988 (CMPPA) provides the
requirements and processes by which agencies may, for certain purposes, conduct a matching
program using individuals’ data. Congress passed the CMPPA to increase the administrative controls and oversight of
matching programs. The CMPPA amended provisions enacted by the Privacy Act of 1974 and operates within the Privacy
Act’s statutory framework.
The CMPPA covers how agencies may conduct a computerized comparison of automated records to administer federal
benefit programs or to use federal personnel and payroll records. A matching program may involve two or more federal
agencies or a federal agency and a state or local government agency.
Matching programs are used throughout the executive branch at agencies such as the Department of Health and Human
Services, the Department of Homeland Security, the Federal Communications Commission, the Small Business
Administration, the Social Security Administration, and the Department of the Treasury. A matching program may exchange
and compare any number of records, and some match millions of records.
The CMPPA establishes a number of requirements for agencies conducting matching programs. These requirements include
the execution of written matching agreements that contain a number of specifics on the conduct of matching programs, costbenefit analyses of matching programs and documentation of specific savings, and the establishment of a Data Integrity
Board (DIB) within each federal agency that conducts or participates in a matching program to approve matching agreements
and oversee matching programs. Matching agreements are to be available to the public and may be published on an agency’s
website. An agency’s DIB is required to submit to the agency head and the Office of Management and Budget (OMB) an
annual report that describes the agency’s matching activities.."
Computer Matching and Privacy
Monday, October 17, 2022
Data Protection and Privacy Law: An Introduction
"Recent controversy surrounding how third parties protect
the privacy of individuals in the digital age has raised
national concerns over legal protections of Americans’
electronic data. The current legislative paradigms governing
cybersecurity and data privacy are complex and technical
and lack uniformity at the federal level. This In Focus
provides an introduction to data protection laws and an
overview of considerations for Congress. (For a more
detailed analysis, see CRS Report R45631, Data Protection
Law: An Overview, by Stephen P. Mulligan, Wilson C.
Freeman, and Chris D. Linebaugh.)
Defining Data Protection
As a legislative concept, data protection melds the fields of
data privacy (i.e., how to control the collection, use, and
dissemination of personal information) and data security
(i.e., how to protect personal information from unauthorized
access or use and respond to such unauthorized access or
use). Historically, many laws addressed these issues
separately, but more recent data protection initiatives
indicate a trend toward combining data privacy and security
into unified legislative schemes.
Federal Data Protection Laws
While the Supreme Court has interpreted the Constitution to
provide individuals with a right to privacy, this right
generally guards only against government intrusions. Given
the limitations in constitutional law, Congress has enacted a
number of federal laws designed to provide statutory
protections of individuals’ personal information. However,
these statutory protections are not comprehensive in nature
and primarily regulate certain industries and subcategories
of data. ."
Data protection and privacy
Thursday, January 18, 2018
Privacy & Data Security Update (2017): An Overview of the Commission’s Enforcement, Policy Initiatives, and Consumer Outreach and Business Guidance in the Areas of Privacy and Data Security: January 2017 – December 2017
The Federal Trade Commission (FTC or Commission) is an independent U.S. law enforcement agency charged with protecting consumers and enhancing competition across broad sectors of the economy. The FTC’s primary legal authority comes from Section 5 of the Federal Trade Commission Act, which prohibits unfair or deceptive practices in the marketplace. The FTC also has authority to enforce a variety of sector specific laws, including the Truth in Lending Act, the CAN-SPAM Act, the Children’s Online Privacy Protection Act, the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the Fair Debt Collection Practices Act, and the Telemarketing and Consumer Fraud and Abuse Prevention Act. This broad authority allows the Commission to address a wide array of practices affecting consumers, including those that emerge with the development of new technologies and business models.
How Does the FTC Protect Consumer Privacy and Promote Data Security?
The FTC uses a variety of tools to protect consumers’ privacy and personal information. The FTC’s principal tool is to bring enforcement actions to stop law violations and require companies to take affirmative steps to remediate the unlawful behavior. This includes, when appropriate, implementation of comprehensive privacy and security programs, biennial assessments by independent experts, monetary redress to consumers, disgorgement of ill-gotten gains, deletion of illegally obtained consumer information, and providing robust transparency and choice mechanisms to consumers. If a company violates an FTC order, the FTC can seek civil monetary penalties for the violations. The FTC can also obtain civil monetary penalties for violations of certain privacy statutes and rules, including the Children’s Online Privacy Protection Act, the Fair Credit Reporting Act, and the Telemarketing Sales Rule. To date, the Commission has brought hundreds of privacy and data security cases protecting billions of consumers..."
FTC privacy and data security report
Tuesday, May 26, 2015
Department of Justice Policy Guidance1 Domestic Use of Unmanned Aircraft Systems (UAS)
Drone policy
Thursday, July 17, 2014
Privacy Protection for Customer Financial Information
Wednesday, July 3, 2013
Revised Children's Online Privacy Protection Rule Goes Into Effect Today
Revised Children Online Privacy Protection Rules
Tuesday, March 26, 2013
Cloud Computing: Constitutional and Statutory Privacy Protections
augment the Fourth Amendment’s protections for digital communications and update existing
statutory protections like the SCA for information shared and stored in the cloud.."
https://www.fas.org/sgp/crs/misc/R43015.pdf
Tuesday, November 20, 2012
Privacy: An Overview of Federal Statutes Governing Wiretapping and Electronic Eavesdropping
Foreign Intelligence Surveillance Act (FISA). ECPA consists of three parts. The first, often
referred to as Title III, outlaws wiretapping and electronic eavesdropping, except as otherwise
provided. The second, the Stored Communications Act, governs the privacy of, and government
access to, the content of electronic communications and to related records. The third outlaws the
use and installation of pen registers and of trap and trace devices, unless judicially approved for
law enforcement or intelligence gathering purposes..."
http://www.fas.org/sgp/crs/intel/98-326.pdf
Thursday, May 3, 2012
United States v Jones: GPS Monitoring, Property, and Privacy
Tuesday, March 27, 2012
FTC Issues Final Commission Report on Protecting Consumer Privacy
Saturday, February 25, 2012
Consumer Privacy Bill of Rights
Tuesday, December 27, 2011
Governmental Tracking of Cell Phones and Vehicles: The Confluence of Privacy, Technology, and Law
112th Congress..."
Monday, October 10, 2011
FTC Testifies on Protecting Children Online
Delivering testimony on behalf of the FTC, the agency’s Associate Director for Advertising Practices, Mary K. Engle, told the House Committee on Energy and Commerce, Subcommittee on Commerce, Manufacturing and Trade, that the FTC has actively promoted adherence to the COPPA Rule through enforcement actions and by educating businesses and consumers. The modifications to the Rule proposed by the FTC last month are designed to make sure that the Rule continues to be effective even as evolving technology is changing the way children access and use the Internet, the testimony states..."
Wednesday, May 25, 2011
"There is no comprehensive federal privacy statute that protects personal information. Instead, a patchwork of federal laws and regulations govern the collection and disclosure of personal information and has been addressed by Congress on a sector-by-sector basis. Federal laws and regulations extend protection to consumer credit reports, electronic communications, federal agency records, education records, bank records, cable subscriber information, video rental
records, motor vehicle records, health information, telecommunications subscriber information, children’s online information, and customer financial information. Some contend that this patchwork of laws and regulations is insufficient to meet the demands of today’s technology. Congress, the Obama Administration, businesses, public interest groups, and citizens are all involved in the discussion of privacy solutions. This report examines some of those efforts with respect to the protection of personal information. This report provides a brief overview of selected recent developments in the area of federal privacy law. This report does not cover
workplace privacy laws or state privacy laws..."
Thursday, April 21, 2011
"There is no comprehensive federal privacy statute that protects personal information. Instead, a patchwork of federal laws and regulations govern the collection and disclosure of personal information and has been addressed by Congress on a sector-by-sector basis. Federal laws and regulations extend protection to consumer credit reports, electronic communications, federal agency records, education records, bank records, cable subscriber information, video rental records, motor vehicle records, health information, telecommunications subscriber information,
children’s online information, and customer financial information. Some contend that this patchwork of laws and regulations is insufficient to meet the demands of today’s technology. Congress, the Obama Administration, businesses, public interest groups, and citizens are all involved in the discussion of privacy solutions. This report examines some of those efforts with respect to the protection of personal information. This report provides a brief overview of selected recent developments in the area of federal privacy law. This report does not cover workplace privacy laws or state privacy laws..."
Wednesday, January 19, 2011
"This Statewide Longitudinal Data Systems (SLDS) Technical Brief examines what protecting student privacy means in a reporting context. To protect a student’s privacy, the student’s personally identifiable information must be protected from public release. When schools, districts, or states publish reports on students’ educational progress, they typically release aggregated data—data for groups of students—to prevent disclosure of information about an individual. However, even with aggregation, unintended disclosures of personally identifiable information may occur. Current reporting practices are described and each is accompanied by an example table that is used to consider whether the intended protections are successful..."
Saturday, December 4, 2010
"Endorses “Do Not Track” to Facilitate Consumer Choice About Online Tracking
The Federal Trade Commission, the nation’s chief privacy policy and enforcement agency for 40 years, issued a preliminary staff report today that proposes a framework to balance the privacy interests of consumers with innovation that relies on consumer information to develop beneficial new products and services. The proposed report also suggests implementation of a “Do Not Track” mechanism – likely a persistent setting on consumers’ browsers – so consumers can choose whether to allow the collection of data regarding their online searching and browsing activities.
“Technological and business ingenuity have spawned a whole new online culture and vocabulary – email, IMs, apps and blogs – that consumers have come to expect and enjoy. The FTC wants to help ensure that the growing, changing, thriving information marketplace is built on a framework that promotes privacy, transparency, business innovation and consumer choice. We believe that’s what most Americans want as well,” said FTC Chairman Jon Leibowitz.
The report states that industry efforts to address privacy through self-regulation “have been too slow, and up to now have failed to provide adequate and meaningful protection.” The framework outlined in the report is designed to reduce the burdens on consumers and businesses..."
Friday, December 4, 2009
"Today, the Federal Trade Commission opened new areas of a “virtual mall” with content that will help kids learn to protect their privacy, spot frauds and scams, and avoid identity theft. The FTC Web site, www.ftc.gov/YouAreHere, introduces key consumer and business concepts and helps youngsters understand their role in the marketplace. The FTC is the nation’s consumer protection agency.
“YouAreHere presents practical lessons about money and business in a fun and familiar setting,” said David Vladeck, Director of the FTC’s Bureau of Consumer Protection. “The new content takes kids behind the scenes to raise their awareness of advertising and marketing, pricing and competition, fraud and identity theft.
At the FTC’s online mall, visitors play games, watch short animated films, and interact with customers and store owners. They can design and print advertisements for a shoe store, investigate suspicious claims in ads and sales pitches, learn to identify the catches behind bogus modeling schemes and vacation offers, and guess the retail prices of various candies based on their supply, demand, and production costs..."
Tuesday, January 20, 2009
"Breaches of personally identifiable information (PII) have increased dramatically over the past few years and have resulted in the loss of millions of records.1 Breaches of PII are hazardous to both individuals and organizations. Individual harms may include identity theft, embarrassment, or blackmail. Organizational harms may include a loss of public trust, legal liability, or high costs to handle the breach. To appropriately protect the confidentiality of PII, organizations should use a risk-based approach; as McGeorge Bundy2 once stated, “If we guard our toothbrushes and diamonds with equal zeal, we will lose fewer toothbrushes and more diamonds.” This document provides guidelines for a risk-based approach to protecting the confidentiality3 of PII..."