Showing posts with label enforcement. Show all posts
Showing posts with label enforcement. Show all posts

Wednesday, October 7, 2009

When the "Safe Harbor" is Not So Safe

If your company transfers personal data cross-border and you participate in the Safe Harbor program, it’s time to check the status of your certification. For the second time in a month, the Federal Trade Commission has announced enforcement actions against companies under Safe Harbor, the international privacy framework that provides a means for U.S. companies to transfer data from the European Union to the United States in keeping with EU and U.S. law.

In September, the first ever Safe Harbor enforcement action was announced against a California company, Balls of Kryptonite, which had falsely represented that it had self-certified to the Safe Harbor program, when apparently it never had. Yesterday, the FTC continued the trend by announcing six separate enforcement actions in one fell swoop.

According to the six separate complaints, the companies deceptively claimed they held current certifications under the Safe Harbor framework, when in fact the companies had allowed those certifications to expire. Under the proposed settlement agreements, which are subject to public comment, the companies are prohibited from misrepresenting the extent to which they participate in any privacy, security, or other compliance program sponsored by a government or any third party. To participate in Safe Harbor, a company must self-certify annually to the Department of Commerce that it complies with a defined set of privacy principles. The proposed settlements do not include any monetary penalties nor any admission of guilt, but would require compliance monitoring for 20 years.

If you have put Safe Harbor (either compliance or certification) on the “back burner” because it appeared that the FTC was not enforcing the program, the time for change has come. You should check what representations are being made on public-facing websites and privacy policies regarding Safe Harbor certification and ensure that these representations are accurate and up-to-date. In the cases announced yesterday, the defendant companies had been certified, but had let those certifications lapse. The exhibits to the FTC’s complaints included pages from their websites (see links below), and their own words were used against them.

For more information:
To file a public comment in the FTC proceeding - http://www.ftc.gov/os/2009/10/sixcasespubliccomment.pdf and follow the instructions at that site.

FTC Complaints:
In the Matter of World Innovators, Inc.
In the Matter of ExpatEdge Partners, LLC
In the Matter of Onyx Graphics, Inc.
In the Matter of Directors Desk LLC
In the Matter of Progressive Gaitways LLC
In the Matter of Collectify LLC

Safe Harbor List
To check the status of your company’s Safe Harbor certification - Safe Harbor List

Wednesday, July 29, 2009

BREAKING NEWS -- FTC Delays Enforcement of "Red Flag" Rules ---Again

BREAKING NEWS: 

 
The Federal Trade Commission has again extended the enforcement deadline for the Red Flags Rule, according to an agency press release. Creditors and financial institutions now have until November 1, 2009 to come into compliance with the rule, which was mandated by the Fair and Accurate Credit Transactions Act of 2003. Meanwhile, the commission will redouble efforts to educate businesses affected by the rule on what they must do to comply. The Red Flags Rule requires entities to implement programs for identifying, detecting and responding to harbingers of identity theft, or "red flags."   Hospitals and retailers had been especially vocal about lack of knowledge as to whether they should be required to comply.  In addition, the American Bar Association had been threatening to take legal action if the FTC did not clarify that the rule should not apply to lawyers before August 1. 


More coming. 

Thursday, July 9, 2009

Major Consumer Protection Actions at FTC

There is increased activity at the Federal Trade Commission on the consumer protection front. David Vladeck, the FTC's new director of the Bureau of Consumer Protection is wasting no time in getting down to business. With less than a month on the job, Vladeck announced two major enforcement actions: one involving a nationwide crackdown against scammers, and the other resulting in a $3.7 million penalty for CAN-SPAM violations.

Mintz Levin colleague Farrah Short writes that "Director Vladeck was named to the position in April and began his new role in June, after a handful of consumer watchdog groups called for the FTC Chairman to appoint someone with “a track record as a genuine champion of consumer rights.” If these early announcements are any indication, Director Vladeck may be on his way to fulfilling that wish."

For more:

CAN-SPAM action
FTC scammer action