Issues Online

Online

Almost every time we go online, using our computers or mobile devices, each of us produces data in some form. This data may contain only oblique information about who we are and what we are doing, but when enough of it is aggregated, facts about us which we believed were private has the potential to become known to and used by others.

Many people are surprised to learn that data about their online habits, including the web sites and services they visit, are being collected and shared by marketers in order to target advertising. While such targeted advertising may provide more relevant information to consumers on which they can base their purchasing decisions, and while online advertising supports free online content for consumers, the lack of transparency about these practices has led to consumer apprehension and government concern.

As policy makers, regulators and consumer advocates press for significant reforms , there is an urgent need for companies using online technologies to demonstrate that they respect consumers’ right to privacy and their right to control the collection of information about them. Consumers need to feel confident that what is happening online is being done for them and not to them.

 

  • There is no across-the-board privacy law in the United States.

Instead, the U.S. has a “sectoral” approach comprised of multiple statutes that aim to protect privacy in specific industries. Accordingly, persons or entities that collect, use, share and or/retain personal information are subject to various privacy laws at both federal and state levels, including those that apply based on the nature of the data involved, such as financial, health or children’s data.

Section 5 of the Federal Trade Commission (FTC) Act, 15 U.S.C. § 45(a), prohibits and makes unlawful “unfair methods of competition in or affecting commerce, and unfair or deceptive acts or practices in or affecting commerce.” The FTC enforces against companies that make privacy promises in privacy policies, but fail to keep those promises. That is, the companies collect, use, share or retain personal information in a way that is inconsistent with the representations they made in their privacy policies. The FTC has also enforced against companies whose privacy policies do not adequately inform consumers about the company’s actual practices.

  • There is a range of various federal laws governing the privacy of specific kinds of personal information.

The federal Health Insurance Portability and Accountability Act (HIPAA) governing health data collected by covered entities, the Gramm-Leach-Bliley Act (GLBA) covering financial data, and the Children’s Online Privacy Protection Act (COPPA) covering data collected by children under 13 are examples of laws applicable to specific kinds of data.

  • In addition to law enacted at the federal level, states also have privacy and data security laws.

Most states have so-called “mini-FTC Acts” under which they have authority similar to that of the FTC to take enforcement actions in response to unfair or deceptive trade practices. This could include tracking consumers without proper notice or when a promise has been made not to track consumer behavior. A number of state attorneys general have been vigilant in enforcing against entities collecting personal information from consumers.

Forty-six states also have data security breach notification laws that require entities holding personal data to provide notices in the event of breaches of the security of that data, and those laws apply regardless of how the data may have been collected, meaning that data that is collected is subject to a security breach will trigger notification obligations. Certain states have specific data security obligations, as well.

*This material is not intended as legal advice and may not be relied on as such. It is presented here to outline the privacy laws aimed to protect consumers in the U.S.

 

Privacy Calendar

May
19
Sun
all-day IEEE Symposium on Security and Privacy @ The Westin St. Francis
IEEE Symposium on Security and P… @ The Westin St. Francis
May 19 – May 22 all-day
The IEE Symposium on Security and Privacy will mark its 34th annual meeting as they present recent developments in computer security and electronic privacy. The [...]
May
22
Wed
all-day Georgetown’s 1st Annual Cybersecurity Law Institute Washington, DC @ Georgetown University Law Center
Georgetown’s 1st Annual Cybersec… @ Georgetown University Law Center
May 22 – May 23 all-day
“Georgetown Law CLE has created the inaugural Cybersecurity Law Institute, designed by a national advisory board of professionals who have been in the trenches dealing with [...]
all-day IAPP Canada Privacy Symposium 2013
IAPP Canada Privacy Symposium 2013
May 22 – May 24 all-day
Join the IAPP for their Canada Symposium 2013, where you will have the chance to learn and debate on the issues that matter most to [...]
May
23
Thu
all-day IAB Interact Sponsored by TRUSTe @ Hotel W Barcelona
IAB Interact Sponsored by TRUSTe @ Hotel W Barcelona
May 23 – May 24 all-day
“ Join leading European advertisers, agencies and media owners, regulators and policy makers for a two-day debate in Barcelona on the theme ‘The Battle of the [...]
May
24
Fri
11:45 am “Enabling Do Not Track Privacy: Is It Dead or Alive?” Washington, DC @ Rayburn House Office Building - Room B-339
“Enabling Do Not Track Privacy: … @ Rayburn House Office Building - Room B-339
May 24 @ 11:45 am – 1:30 pm
Join Congressional Internet Caucus Advisory Committee (ICAC) for a boxed lunch series on the Do Not Track (DNT) issue. Panel will include: Ashkan Soltani, Independent Researcher [...]
May
30
Thu
all-day Ramp Up Summit @ Computer History Museum
Ramp Up Summit @ Computer History Museum
May 30 all-day
Over 1,000 marketers, advertisers, and industry insiders come together to discuss the convergence of offline and online data in digital advertising. For more information or to register [...]
Jun
3
Mon
6:30 pm EPIC’s Champion of Freedom Awards Dinner 2013 Washington, DC @ The Fairfax at Embassy Row
EPIC’s Champion of Freedom Award… @ The Fairfax at Embassy Row
Jun 3 @ 6:30 pm – 9:00 pm
Join Electronic Privacy Information Center (EPIC) for the annual Champion of Freedom Awards Dinner 2013 Honorees: Sen. Paul Rand (R-KY), Sen. Ron Wyden (D-OR), Martha [...]
Jun
6
Thu
all-day The 6th Annual Privacy Law Scholars Conference @ Claremont Hotel Club & Spa
The 6th Annual Privacy Law Schol… @ Claremont Hotel Club & Spa
Jun 6 – Jun 7 all-day
BCLT and The George Washington University Law School will host the sixth annual Privacy Law Scholars Conference (PLSC). The PLSC assembles a wide array of [...]

View Calendar