Massive Online Data Collection Class Action Lawsuit Moves Forward

On June 11, 2013, the United States Court of Appeals for the Seventh Circuit denied software maker comScore, Inc.’s petition to appeal class certification in a litigation related to comScore software that allegedly collected extensive data from consumers’ computers without authorization. The plaintiffs alleged that comScore (an online analytics company) gathered data from consumers’ computers through software that it bundled with third-party software, such as free screensavers, games, music-copying programs and greeting card templates. According to the plaintiffs, this software collected data including “the monitored consumer’s usernames and passwords; queries on search engines…; the website(s) the monitored consumer is currently viewing; credit card numbers and any financial or otherwise sensitive information inputted into any website the monitored consumer views; the goods purchased online by the monitored consumer, the price paid by the monitored consumer for the goods, and amount of time the monitored consumer views the goods before purchase; and specific advertisements clicked by the monitored consumer,” as well as data about all files on the consumer’s computer.

Continue reading…

Tags: Consumer Protection, Credit Monitoring, Litigation, U.S. Federal Law

FCC Clarifies Sellers’ Liability for Third Parties’ Telemarketing Violations

On May 9, 2013, the Federal Communications Commission (“FCC”) released a declaratory ruling clarifying the liability of a seller for violations of the Telemarketing Consumer Protection Act (“TCPA”) made by third-party telemarketers and others who place calls to market the seller’s products or services.

Continue reading…

Tags: Consumer Protection, Do Not Call, Enforcement, Marketing, Telephone Consumer Protection Act, U.S. Federal Law

FTC Reminds Companies of Impending COPPA Deadline

On May 15, 2013, the Federal Trade Commission announced that it sent educational letters to over 90 businesses that appear to collect personal information from children under the age of 13, reminding them of the impending July 1 deadline for compliance with the updated Children’s Online Privacy Protection Rule (the “Rule”). The letters were sent to domestic and foreign companies that may be collecting information from children that is now considered “personal information” under the Children’s Online Privacy Protection Act (“COPPA”) but was not previously considered “personal information.” The definition of “personal information” under COPPA was expanded to include (1) photos, videos and audio recordings of children; and (2) persistent identifiers that may recognize users over time and across various websites and online services (e.g., cookies and IP addresses).

Continue reading…

Tags: Consumer Protection, Cookies, COPPA, Enforcement, Federal Trade Commission, Online Privacy, U.S. Federal Law

California AG’s Mobile App Case Against Delta Dismissed

A state court has dismissed the California Attorney General’s claims that Delta Air Lines Inc. (“Delta”) violated the California Online Privacy Protection Act by failing to have an appropriately posted privacy policy for its mobile application, Bloomberg reports. The California AG sued Delta in December as part of an enforcement campaign that began with the issuance of warning letters to approximately 100 operators of mobile apps, including Delta. According to the Bloomberg report, a basis for the dismissal was the federal Airline Deregulation Act, under which a state “may not enact or enforce a law, regulation, or other provision having the force and effect of law related to a price, route, or service of an air carrier that may provide air transportation under this subpart.” 49 U.S.C. § 41713.

Tags: California, Enforcement, Mobile App, Online Privacy, Personally Identifiable Information, Privacy Policy, State Attorneys General, U.S. Federal Law, U.S. State Law

Obama Administration Threatens to Veto CISPA

On April 16, 2013, the Office of the President issued a Statement of Administration Policy that includes a threat to veto the U.S. House of Representatives’ Cyber Intelligence Sharing and Protection Act (“CISPA” or H.R. 624) if further changes are not made to the bill’s privacy protections. Specifically, the Obama Administration recommends that the bill require private entities to remove personal information when sharing cybersecurity information with the government or other private entities.

Continue reading…

Tags: CISPA, Congress, Cybersecurity, Information Security, Legislation, Obama, U.S. Federal Law

Appeals Court Holds “Reasonable Suspicion” Required for Forensic Search of Laptop at the Border

On March 8, 2013, a U.S. federal appeals court issued a decision in the case United States v. Cotterman, holding that the federal government must have “reasonable suspicion” of criminal activity to conduct a forensic search of laptops and similar devices in the possession of individuals attempting to cross the border. The case arose after Howard Cotterman attempted to enter the United States by car at a checkpoint on the Mexican border. When border agents determined that he had a criminal record related to sexual misconduct, they seized his laptop and attempted to search it. They initially discovered some password-protected files but no proof of illegal activity and allowed him to enter the country but did not return his laptop. The agents then subjected the computer to a forensic analysis and discovered it contained child pornography in portions of the hard drive that had been deleted or protected with passwords. The federal district court ordered suppression of this evidence in the criminal case against Cotterman on the ground that the agents’ forensic analysis of his computer violated the Fourth Amendment’s prohibition on warrantless searches.

Continue reading…

Tags: Criminal Law, Encryption, Mexico, Ninth Circuit, U.S. Federal Law

U.S. Court Finds National Security Letter Nondisclosure Provisions Unconstitutional

On March 14, 2013, the United States District Court for the Northern District of California granted a motion to prohibit the government from issuing National Security Letters (“NSLs”) to electronic communication service providers (“ECSPs”) requesting “subscriber information” and enforcing nondisclosure clauses contained in such letters. The nondisclosure clauses are intended to prevent ECSPs from disclosing that they received an NSL. The court also held that the sections of two federal statutes relating to the nondisclosure provisions of NSLs, 18 U.S.C. §2709(c) and 18 U.S.C. §3511(b), (collectively, the “NSL Nondisclosure Statutes”) were unconstitutional because they violated the First Amendment as well as separation of powers principles. In light of the significant constitutional and national security implications, the court stayed enforcement of its judgment pending appeal to the Ninth Circuit, or for 90 days if no appeal is filed.

Continue reading…

Tags: California, Consumer Protection, FCRA, Financial Privacy, Service Provider, U.S. Federal Law

Supreme Court Limits Plaintiffs Ability to Cap Damages Prior to Class Certification

As reported in the Hunton Employment & Labor Perspectives Blog:

On March 19, 2013, in Standard Fire Insurance Co .v. Knowles, the United States Supreme Court ruled that stipulations by a named plaintiff on behalf of a proposed class prior to class certification cannot serve as the basis for avoiding federal jurisdiction under the Class Action Fairness Act of 2005 (“CAFA”).

Continue reading…

Tags: Class Action, Cookies, Litigation, Supreme Court, U.S. Federal Law, U.S. State Law, Workplace Privacy

Disclosure of Cybersecurity Risks in SEC Filings on the Rise

As reported in The Washington Post, large financial institutions are increasingly disclosing cyber attacks, and potential vulnerability to cyber threats, in their annual reports filed with the Securities and Exchange Commission. Numerous banks disclosed such attacks in their 2012 reports, even in cases where the ongoing threat of the attacks did not result in any material harm to the institution. For example: Continue reading…

Tags: Cybersecurity, Financial Privacy, Information Security, Obama, Securities and Exchange Commission, Security Breach, U.S. Federal Law

Kmart Settles FCRA Class Action for $3 Million

On January 25, 2013, Kmart Corporation (“Kmart”) agreed to a $3 million settlement stemming from allegations that it violated the Fair Credit Reporting Act (“FCRA”) when using background checks to make employment decisions. The FCRA addresses adverse actions taken against consumers based on information in consumer reports and includes numerous requirements relating to the use of such reports in the employment context.

Continue reading…

Tags: Class Action, Consent Order, Consumer Protection, FCRA, Litigation, U.S. Federal Law, Workplace Privacy