Insights on personal information,Google

Act, Amazon, Apple, California, communications, Communications Act, FCC, FTC, Google, Hewlett-Packard, Microsoft, Mobile, privacy, RIM

FCC Seeks Public Comment on Mobile Carrier Privacy Policies Following Data Collection Controversy

By InfoLawGroup LLP on June 29, 2012

In re-launching the inquiry into carriers' data privacy and security practices, the FCC argues that not informing customers about the software or its data practices may have violated the carriers' responsibility pursuant to Section 222 of the Communications Act of 1934 to protect customer data "that is made available to a carrier solely by virtue of the carrier-customer relationship." The law allows such data to be used only in "limited circumstances," a term which is not defined in Section 222. It appears that one of the goals of the renewed inquiry is for the FCC to define the scope of the "limited circumstances."

California, class action, credit cards, loyalty program, personal identification information, personal information, rewards program, Song-Beverly

Class Certification Ruling Suggests that a Plaintiff's Membership in a Retailer's Pre-Existing Rewards Program May Not Excuse a Retailer's Request for Personal Information at the Register

By InfoLawGroup LLP on May 17, 2012

The U.S. District Court for the Southern District of California recently granted class certification in a Song-Beverly Credit Card Act case, refusing to exclude from the class individuals who joined the retailer's rewards program months after the alleged Song-Beverly violation. See Yeoman v. IKEA U.S. West, Inc., No. 11CV701, 2012 WL 1598051 (S.D. Cal. May 4, 2012). The Court's discussion suggests that a retailer may also face Song-Beverly liability even if it requests personal information at the register that it already holds by virtue of the customer's membership in its rewards program.

behavioral analytics, behavioral marketing, behavorial advertising, cookies, EU, European Union, Google, international, Privacy Policy

European Criticism for Google's New Privacy Policy

By W. Scott Blackmer on February 28, 2012

Google's new privacy policy (and its plans to create user profiles across multiple online services) has drawn fire from European data protection authorities. Online and mobile retailers and service providers should take account of a renewed emphasis on transparency and proportionality in collecting data about users.

Amazon, Apple, Apps, California, CalOPPA, Google, Harris, HP, Microsoft, Mobile, mobile privacy, privacy bill of rights, Privacy Policy, RIM, Shine the Light, White House

Privacy in Principle (As California Goes, So Goes the Nation? Part Four)

By InfoLawGroup LLP on February 27, 2012

What happened in the privacy world last week? On Thursday, just before the release of the White House Paper, California Attorney General Kamala Harris announced an agreement with the leading operators of mobile application platforms to privacy principles designed to bring the mobile app industry in line with a California law requiring mobile apps that collect personal information to have a privacy policy. It might be argued that the White House is now enunciating principles and best practices, and encouraging legislation of principles, that have long been embodied not only as best practice but as actual legislation under California law.

Buzz, consent, EPIC, FTC, FTC Act, Google, InfoLawGroup, information law group, privacy, privacy enforcement, Privacy Policy, Section 5, Segalis

EPIC Alleges Epic FTC Fail In Google Saga; We Review the Complaint

By InfoLawGroup LLP on February 13, 2012

On February 8, 2012, the Electronic Privacy Information Center (EPIC) asked the Federal District Court for the District of Columbia to compel the Federal Trade Commission (FTC) to enforce the terms of the agency's Google Buzz privacy settlement with Google. EPIC seeks to compel the FTC to stop Google's planned consolidation of user data from across the company's services into a single profile for each user under a single privacy policy. EPIC has alleged that the proposed changes and the way Google seeks to implement the changes violate the Google Buzz consent order. The District Court will hear the case before March 1, 2012.In this post, we discuss the highlights of EPIC's complaint, Google's response and lessons learned.

data brokers, data protection, David Vladeck, Fair Credit Reporting Act, FCRA, Federal Trade Commission, FTC, FTC consent, InfoLawGroup, information law group, personal information, privacy enforcement, Segalis, Teletrack

FCRA Violations Result in $1.8 Million FTC Penalty

By InfoLawGroup LLP on June 26, 2011

The Federal Trade Commission announced today that Teletrack, Inc. has agreed to pay $1.8 million to settle charges that the company sold credit reports for marketing purposes, in violation of the Fair Credit Reporting Act (FCRA). According to the FTC's complaint, Teletrack sells credit reports and other services to businesses that mainly serve financially distressed consumers. Teletrack's business customers include pay day lenders, rental purchase stores and non-prime rate auto lenders. These businesses use Teletrack's credit reports to decide whether and on what terms to extend credit to their customers.

Apple, Boris Segalis, data protection, Directive, DPA, EU Data Protection Directive, Google, InfoLawGroup, information law group, mobile privacy, privacy, privacy enforcement, WP29

Mobile Location Privacy Opinion Adopted by Europe's WP29

By InfoLawGroup LLP on May 19, 2011

On May 16, 2011, EU's Article 29 Working Party (WP29) adopted an opinion setting out privacy compliance guidance for mobile geolocation services.WP29 is comprised of representatives from the EU member states' data protection authorities (DPAs), the European Data Protection Supervisor and the European Commission. WP29's mandate includes (i) giving expert advice to the EU member states regarding the implementation of European data protection directives, and (ii) promoting uniform implementation of the directives in all EU state members as well as in Norway, Liechtenstein and Iceland. WP29's opinions, therefore, carry significant weight in the interpretation and enforcement of data protection laws by European DPAs. Not surprisingly, WP29 has concluded that geolocation data is "personal data" subject to the protections of the European data protection framework, including the EU Data Protection Directive 95/46/EC. The Working Party also determined that the collection, use and other processing of geolocation data through mobile devices generally requires explicit, informed consent of the individual. Below are the highlights of the opinion.

Boris Segalis, data protection, data security, FIPPs, InfoLawGroup, information law group, Korea, personal information, Personal Information Protection Act, PIPA, privacy, privacy legislation

Personal Data Protections Expand in Korea

By InfoLawGroup LLP on May 18, 2011

Mr. Kwang Hyun Ryoo, a partner at the Korean law firm of Bae, Kim & Lee LLC, is reporting in the firm's newsletter that on March 29, 2011, Korea enacted a comprehensive personal data protection law, entitled Personal Information Protection Act (PIPA). Most of the act's provisions will come into force on September 30, 2011.

Apple, Apple Apps Commission DOJ Privacy mobile privacy FTC Franken Whitehouse Cobur..., Apps, Coburn, Commission, data protection, DOJ, Fox, Franken, FTC, Google, Hearing, InfoLawGroup, information law group, InformationLawGroup, Leahy, location, Mobile, mobile privacy, privacy, privacy by design, Privacy, Technology and the Law, Segalis, Senate, Senate Hearing, Senate Subcommittee, smartphone, Technology and the Law, tracking, Whitehouse

InfoLawGroup Speaks with Fox Live about Mobile Privacy

By InfoLawGroup LLP on May 12, 2011

On May 10, 2011, the Senate Subcommittee on Privacy, Technology and the Law held a hearing on mobile privacy. We covered the hearing in detail on our blog. Yesterday, InfoLawGroup partner Boris Segalis spoke with Fox Live's Tracy Byrnes about the balance between business and consumer interests that mobile privacy implicates.The clip from the interview is available on Fox at http://video.foxnews.com/v/4689248/the-congressional-mobile-privacy-hearing/?playlist_id=86861

Apple, Apps, Commission, data, Data Privacy Law or Regulation, Department, Department of Justice, Devices, DOJ, Federal, Federal Trade Commission, Franken, FTC, Google, group, Hearing, InfoLawGroup, information, information law group, InformationLawGroup, Justice, Law, Leahy, Legislation, location, location data, location tracking, Mobile, Mobile Devices, of, or, privacy, privacy legislation, Regulation, Senate, smartphones, tracking, Trade, wifi

Senate Subcommittee Holds Hearing on Mobile Privacy

By InfoLawGroup LLP on May 09, 2011

Ceridian, deceptive practices, enforcement, Federal Trade Commission, FTC, FTC Act, FTC consent, InfoLawGroup, information law group, information security, information security program, InformationLawGroup, Lookout, personal data, personal information, privacy enforcement, Section 5, Segalis

FTC Privacy Enforcement Update: Two Companies Allegedly Failed to Protect Sensitive Employee Data

By InfoLawGroup LLP on May 06, 2011

On May 3, 2011, the Federal Trade Commission announced that Ceridian Corporation and Lookout Services, Inc. agreed to settle the FTC's allegations that the companies failed to safeguard their business customers' employee personal information. Ceridian's services include payroll processing, payroll-related tax filing, benefits administration and other human resource services for business customers. Lookout provides a web-based computer product that is designed to help employers comply with their obligations under federal law to complete and maintain a U.S. Citizenship and Immigration Services Form I-9 about each employee in order to verify that the employee is eligible to work in the United States.

Breach, damages, litigation, personal information, privacy, security breach litigation

California Federal Court Holds that Damages Properly Alleged in RockYou Data Breach Case

By InfoLawGroup LLP on April 19, 2011

In what may be a sign of an evolving judicial atmosphere and approach concerning data breach lawsuits, a Federal judge in the Northern District of California District Court recently refused to dismiss various causes of action related to a data breach involving RockYou. In particular, the Court explored the issue of whether the plaintiff sufficiently alleged "harm" arising out of the data breach. This blog post takes a look the highlights of the Court's decision.