Privacy Commissioner of Canada Recommends Updates to PIPEDA

On May 23, 2013, the Office of the Privacy Commissioner of Canada (“OPC”) issued a position paper (the “Paper”) proposing revisions to the Personal Information Protection and Electronic Documents Act (“PIPEDA”) to better align PIPEDA with the risks facing a modern information economy. Privacy Commissioner of Canada Jennifer Stoddart addressed the release of the Paper in her remarks at the IAPP Canada Privacy Symposium, stating that “[i]t is increasingly clear that the law is not up to the task of meeting the challenges of today – and certainly not those of tomorrow.” According to the Paper, the surge in the collection, availability and use of personal data has upset the balance between the privacy rights of individuals and the legitimate needs of businesses originally struck by PIPEDA. In response, the Paper proposes four general revisions to PIPEDA: Continue reading…

Tags: Canada, Enforcement, International, Jennifer Stoddart, Security Breach

HHS Announces Settlement with Idaho State University

On May 21, 2013, the Department of Health and Human Services (“HHS”) announced a resolution agreement and $400,000 settlement with Idaho State University (“ISU”) for a breach that affected 17,500 individuals.

The ISU settlement relates to servers that had their firewall protections disabled, which left the electronic protected health information (“ePHI”) of patients at ISU’s Pocatello Family Medicine Clinic unsecured for at least ten months. Following the submission of a breach report to the HHS Office for Civil Rights (“OCR”), an investigation determined that ISU allegedly had not complied with HIPAA Security Rule requirements, including by conducting an incomplete and inadequate risk analysis and by failing to “adequately implement procedures to regularly review records of information system activity to determine if any ePHI was used or disclosed in an inappropriate manner.”

Continue reading…

Tags: Department of Health and Human Services, Enforcement, Health Privacy, HIPAA, HITECH Act, Protected Health Information, Security Rule

FCC Clarifies Sellers’ Liability for Third Parties’ Telemarketing Violations

On May 9, 2013, the Federal Communications Commission (“FCC”) released a declaratory ruling clarifying the liability of a seller for violations of the Telemarketing Consumer Protection Act (“TCPA”) made by third-party telemarketers and others who place calls to market the seller’s products or services.

Continue reading…

Tags: Consumer Protection, Do Not Call, Enforcement, Marketing, Telephone Consumer Protection Act, U.S. Federal Law

FTC Reminds Companies of Impending COPPA Deadline

On May 15, 2013, the Federal Trade Commission announced that it sent educational letters to over 90 businesses that appear to collect personal information from children under the age of 13, reminding them of the impending July 1 deadline for compliance with the updated Children’s Online Privacy Protection Rule (the “Rule”). The letters were sent to domestic and foreign companies that may be collecting information from children that is now considered “personal information” under the Children’s Online Privacy Protection Act (“COPPA”) but was not previously considered “personal information.” The definition of “personal information” under COPPA was expanded to include (1) photos, videos and audio recordings of children; and (2) persistent identifiers that may recognize users over time and across various websites and online services (e.g., cookies and IP addresses).

Continue reading…

Tags: Consumer Protection, Cookies, COPPA, Enforcement, Federal Trade Commission, Online Privacy, U.S. Federal Law

California AG’s Mobile App Case Against Delta Dismissed

A state court has dismissed the California Attorney General’s claims that Delta Air Lines Inc. (“Delta”) violated the California Online Privacy Protection Act by failing to have an appropriately posted privacy policy for its mobile application, Bloomberg reports. The California AG sued Delta in December as part of an enforcement campaign that began with the issuance of warning letters to approximately 100 operators of mobile apps, including Delta. According to the Bloomberg report, a basis for the dismissal was the federal Airline Deregulation Act, under which a state “may not enact or enforce a law, regulation, or other provision having the force and effect of law related to a price, route, or service of an air carrier that may provide air transportation under this subpart.” 49 U.S.C. § 41713.

Tags: California, Enforcement, Mobile App, Online Privacy, Personally Identifiable Information, Privacy Policy, State Attorneys General, U.S. Federal Law, U.S. State Law

German Court Rules Apple’s Privacy Policy Violates German Law

On April 30, 2013, the regional court of Berlin enjoined Apple Sales International, which is based in Ireland, (“Apple”) from relying on eight of its existing standard data protection clauses in contracts with customers based in Germany. The court also prohibited Apple’s future use of such clauses.

Continue reading…

Tags: Advertisement, Anonymization, Apple Inc., Behavioral Advertising, Cross-Border Data Flow, Data Protection Act, Enforcement, European Union, Geolocation, Germany, International, Marketing, Opt-In Consent, Privacy Policy, Service Provider

German Parliament Passes New Telecom User Data Access Bill

On May 3, 2013, the German Federal Council (Bundesrat) passed a new bill regarding access to telecom user data, such as names, addresses, passwords and credit card PIN codes. This comes after the German Federal Diet (Bundestag) passed the German government’s bill on March 21, 2013, which amends, among other laws, Germany’s Federal Telecommunications Act.

Continue reading…

Tags: Enforcement, European Union, Germany, International, Telecommunications

FTC Won’t Delay COPPA Rule Implementation Deadline

On May 6, 2013, the Federal Trade Commission announced that it had voted unanimously to reject a request from industry groups to delay the July 1, 2013 deadline for implementation of the updated Children’s Online Privacy Protection Rule (the “Rule”). The groups had argued that the delay was necessary because they needed more time to comply with the changes to the Rule, which the FTC promulgated on December 19, 2012. In its response to the groups, the FTC asserted that the groups have been on notice of the changes since the beginning of the rulemaking process over three years ago, and a number of the updates constitute only minor changes from existing standards and obligations. The FTC’s letter also indicated that, in appropriate cases, in the months immediately following the implementation deadline, the FTC might exercise prosecutorial discretion with respect to small entities that have made a good-faith effort to comply with the updated Rule.

View the text of the updated COPPA Rule.

Tags: Advertisement, Consumer Protection, COPPA, Enforcement, Federal Trade Commission, Online Privacy

Chinese Ministry of Industry and Information Technology Enacts Draft Rules on Personal Information

On April 10, 2013, the Ministry of Industry and Information Technology of the People’s Republic of China (the “MIIT”) enacted two draft rules (“Provisions on the Protection of Personal Information of Telecommunications and Internet Users” and “Provisions on the Registration of Real Identity Information of Telephone Users”) to solicit public comments. The comment period is open until May 15, 2013. Both Drafts include proposals for substantial provisions on the protection of personal information and were enacted according to the Resolution of the Standing Committee of the National People’s Congress Relating to Strengthening the Protection of Information on the Internet (issued by the Standing Committee in December 2012) and some other telecommunications rules.

Continue reading…

Tags: China, Criminal Law, Enforcement, Information Security, International, Marketing, Online Privacy, Penalty, Personally Identifiable Information, Security Breach, Telecommunications

FTC Sends FCRA Warning Letters to Tenant Rental History Websites

On April 3, 2013, the Federal Trade Commission issued a press release announcing that it had sent warning letters to operators of six websites that provide rental history reports to landlords for tenant screening purposes. The letters informed the website operators that they may be considered consumer reporting agencies (“CRAs”) subject to the requirements of the Fair Credit Reporting Act (“FCRA”).

Continue reading…

Tags: Consumer Protection, Credit Report, Enforcement, FCRA, Federal Trade Commission, Information Security, Online Privacy