Showing posts with label Tracking Cookies. Show all posts
Showing posts with label Tracking Cookies. Show all posts

Tuesday, August 28, 2012

Consumer Privacy and Cookies: What the FTC's $22.5 Million Settlement With Google Means For Your Company



Author: Paul C. Van Slyke




Recently the Federal Trade Commission reached a record $22.5 million settlement with Google for consumer privacy violations of an earlier order involving what is called “online behavioral advertising” or OBA.  The Google case is a roadmap for avoiding serious legal missteps for tracking of consumer interests in violation of a company’s own policies and claims that are commonly made and often overlooked.  In the Google settlement, the FTC sent a loud and clear message that it will not tolerate promises and claims made in fine print to protect the privacy of consumers and breaking those promises by use of cookies and user tracking tools in day-to-day operations long after the promises in fine print are forgotten. 

Overlooked Privacy Claims in the Google Case

Most companies have gotten the message that what they say in their privacy policies has to line up with their day-to-day operations. The problem is that many companies are conveying claims not just in a formal privacy policy in the fine print on the website, blog or social media brand page, but also where the company states choice mechanisms, opt-outs, and other ways consumers can customize their experience.  The FTC’s complaint against Google highlights alleged misrepresentations on the company’s Advertising Cookie Opt-Out Plug-in page that were overlooked for compliance.  Cookies are the unique file codes placed on a consumer’s computer when a website is opened and consumer choices are made on the website.

Google claimed in its fine print that for users of the Safari browser that it would not place tracking cookies on the users’ computers or serve them targeted advertisements.  The  FTC alleged that Google used codes to disguise its cookies to work around Safari’s opt-out default setting. 

Overlooked Claims of  Self-Regulatory Compliance

Many companies promote on their website their affiliation with self-regulatory programs.  For example, to join the Network Advertising Initiative (NAI), a voluntary self-regulatory group for the online advertising industry, company members agree to disclose to users their data collection and use practices.  Although Google touted its NAI membership on its website, the FTC says the company did not truthfully disclose what it was doing with Safari users’ data. 

Key Points


  • The CEO and top executives of your company must often repeat that they are committed to compliance with consumer privacy and advertising laws and they will hold the IT director and Chief Marketing Officer accountable.
  • Your information technology staff needs to take the lead in compliance before your marketing managers and legal advisors get involved.
  • It helps for a company to adopt an internal consumer privacy policy that places primary responsibility on the IT Department and secondary responsibility on the marketing staff for compliance with laws and regulations on the use of cookies and user tracking tools.
  •  The internal policy should require that IT department make and update a list of all the places on your company websites, social media promotions and sponsored blogs where  privacy representations and claims are made,  maintain an inventory of the cookies they use, and not launch new ones without both marketing and legal review.
  • The internal policy should also require that the marketing staff make and update a separate list of all the user tracking tools being used on your company websites, social media promotions and sponsored blogs and maintain an inventory of the categories of data being collected from users, and not launch new tracking tools or categories of data being collected without both IT and legal review.
  •  Sidestepping users’ preferences can lead to costly legal missteps.

Tuesday, November 29, 2011

Congressmen Ask FTC to Investigate Secret Use of Supercookies For Behavioral Advertising

Two Congressmen recently wrote the Federal Trade Commission (FTC) asking the FTC to investigate the privacy implications of the installation of files called Flash cookies or Supercookies on consumers’ computers.  These Supercookies allow companies such as Hulu.com to gain personal information from consumers without their knowledge for behavioral advertising targeting. The two Congressmen, Joe Barton (R-TX) and Ed Markey (D-MA), are Co-Chairman of the Congressional Bi-Partisan Privacy Caucus.
Supercookies are Hidden
The Congressmen’s letter is based on an August Wall Street Journal article discussing the use of Supercookies.  Supercookies differ from regular “cookies” because Supercookies are hidden from view and cannot be deleted.  Consumers are unaware these files are placed on their computer.  They remain on a computer even when the consumer clears the browsing history and cache.  And they record information even when the consumer is browsing in “private browsing” mode.
Supercookies Common on Many Top Websites
A recent study found 100 Supercookies placed on users’ computers by 37 of the top 100 websites.  Some Supercookies can even “respawn” traditional cookies after a consumer deletes them. Amazingly, the study also suggests that owners of the top website surveyed have little or even no knowledge that their websites are being used by third party tracking companies to place Supercookies on consumers’ computers.
Class Action Suits Filed on Secret Use of Supercookies
Earlier this year, a California class action lawsuit against Web measurement company Quantcast and widget maker Clearspring based on surreptitious placement of Supercookies settled for $2.5 Million. Another class action lawsuit in California against Kissmetrics and Hulu.com alleging that surreptitious placement of cookies and similar tracking files violates the Computer Fraud and Abuse, Electronic Communications, and Video Privacy Protection Acts, as well as several similar state laws, is still pending.  Most recently, on Nov. 23, 2011 web video company Metacafe settled a similar suit by the agreeing to stop use of Supercookies to recreate users’ regular cookies. 

FTC Action/Settlement

The FTC itself on Nov. 8, 2011 both filed a complaint and announced a settlement agreement containing a consent injunction against ad network ScanScout (which was acquired last year by Tremor Media).  The agreement requires ScanScout and Tremor to give prominent notice on its website that it is collecting information to send the consumer targeted ads, unless the consumer opts out by clicking on a hyperlink declining to receive targeted ads. The agreement also requires that the hyperlink take consumers to a mechanism that allows them to block the company from collecting information that can identify them or their computer, from redirecting their browser to third parties that collect date with their approval; and from associating any previously collected personal data with them.  The consumer’s choice must last for at least five years, unless the consumer changes it. The agreement will be subject to public comment for 30 days, continuing through December 8, 2011, after which the Commission will decide whether to make it final.

Implications of Secret Use of Supercookies
The FTC investigation requested by Congressmen Barton and Markey, the pending class action lawsuits, and actions by the FTC are likely to lead to additional regulations and limits on behavioral advertising through the use of Supercookies.  The FTC is likely to rule that obtaining personal data using Supercookies without notice and an opportunity for consumers to opt out violates current laws and FTC privacy guides.  It is unclear whether companies will be liable for engaging in behavioral advertising by acquiring and using personal data obtained by third parties with the use of Supercookies, but we expect further limits on such use.


Authors: Paul Van Slyke



Gregory Casamento
Patrick Hatfield