DECEMBER 2010

FTC Seeks Input on Sweeping Changes to Consumer Privacy Protections: Recommendations Include Do-Not-Track and Much More

In a preliminary report to Congress, released by the FTC last week, the agency proposed sweeping changes to how it believes companies should approach consumer privacy. This report marks a major change in the way the FTC approachs privacy, essentially creating an EU-like approach for all entities that collect and maintain personal information. The FTC has sought industry input by January 31, 2011.  Although the FTC’s comments about online behavioral advertising and a “do not track” functionality (under which a consumer could set his or her browser to stop any online behavioral advertising) have received a great deal of publicity, the report includes many other proposals that would have significant impact. 

In particular, the FTC contemplates a three-pronged approach to privacy.  First, it recommends that companies incorporate privacy protections at every stage of their business, treating privacy as a “basic consideration – similar to keeping track of costs and revenues.”  Under this prong companies would need reasonable security to protect personally identifiable information, reasonable limits on collection, sound retention practices, safe disposal of data that is no longer needed, and efforts around data accuracy.  These types of procedural recommendations about business operations have arisen not only abroad, but also in state laws and laws specific to certain types of information (health, financial).  This is the first time, however, that the FTC has issues such sweeping recommendations about procedural steps companies should put in place for general personally identifiable information. 

The second prong is to provide consumers with streamlined choice about how their information is used, whether in the offline context, or online for traditional computer or mobile devices.  The FTC is considering — and is seeking comment from the industry – about choice that would involve “durable” affirmative consent from consumers for all except “commonly accepted” practices.  Commonly accepted practices are currently viewed by the FTC as including advertising a company’s own products and services, and internal operations like customer satisfaction surveys.  Falling outside of common practices would be, inter alia, online behavioral advertising, use of data for purposes outside of the scope of the initial collection, and sharing data with a third party for that third party’s advertising purposes.  The FTC has sought input from the industry on how affirmative consent should best be obtained, when a “take it or leave it” approach to consent would be appropriate (“either accept our practices or don’t use our website”), and the scope of “common practices” in different online situations (such as when a data broker is involved).  The FTC has also called on the industry to ensure that choice is meaningful on a mobile device (pointing out that in some circumstances, consumers are forced to click-through 100 screens to read a privacy policy).

Finally, the third prong would require companies to give better transparency about their data practices.  These include improving privacy policies to make them easier to understand and compare, giving consumers reasonable access to information maintained by the company about them, obtaining consent prior to  changing practices, and increasing consumer education.  Many of the specific steps in these three prongs have already been enforced by the FTC under its authority through the FTC Act, although some are new, or some have not been fully fleshed-out under current FTC case law. 

TIP: Companies should consider getting involved in the comment process.  The suggestions from the FTC could have far-reaching implications on how companies operate their businesses, and portions could be enforced – without new legislation – under existing authority from the FTC Act.  For other areas, at least three legislators appear to be looking into proposing new broad privacy laws in 2011.  Companies that maintain personal information should begin to think about what parts of the proposed approach they already follow, and what parts might require changes to their internal procedures, and how such changes could be effectuated.


If you have any questions concerning this Privacy Bulletin Special Alert, please contact one of the following attorneys:
Chicago Los Angeles

Liisa M. Thomas
(Advertising)

(312) 558-8121

Steven D. Atlee
(Litigation)
(213) 615-1827
Julie Bauer
(Litigation)
(312) 558-5973 Anna S. Masters
(Labor and Employment)
(213) 615-1711
Monique Bhargava
(Advertising)
(312) 558-3732    

Stephen P. Durchslag
(Advertising)

(312) 558-5288

New York

 

Christine A. Edwards
(Financial Services)

(312) 558-5571

Virginia R. Richard
(Intellectual Property)
(212) 294-4639

Brian D. Fergemann
(Advertising)

(312) 558-8024

   

Delilah B. Flaum
(Health Care, Litigation)

(312) 558-8922

Paris  

Jason W. Gordon
(Advertising)

(312) 558-6145

Sébastian Ducamp
(Employment, Litigation)
33 0(1) 53 64 82 08

Brian L. Heidelberger
(Advertising)

(312) 558-5897

Blaise Deltombe
(Employment, Litigation)
33 0(1) 53 64 82 31

Mary Hutchings Reed
(Advertising)

(312) 558-5721

Nathalie Hadjadj-Cazier
(Intellectual Property)
33 (0)1 53 64 81 50
Michael Melbinger
(Employee Benefits)
(312) 558-7588 Gwendaline Sarrat
(Intellectual Property)

33 (0) 1 53 64 82 47

Robert H. Newman
(Advertising)

(312) 558-8125

   
Michael Philipp
(Financial Services)
(312) 558-5905 San Francisco  
Tim Rivelli
(Litigation)
(312) 558-5817 David S. Bloch
(Intellectual Property, Litigation)
(415) 591-1452

Cardelle B. Spangler
(Labor & Employment, Litigation)

(312) 558-7541

Andrew P. Bridges
(Intellectual Property)
(415) 591-1482

Marc H. Trachtenberg
(Advertising)

(312) 558-7964

Kimberly E. Eckhart
(Intellectual Property)
(415) 591-6805

Amanda C. Wiley
(Associate)

(312) 558-8795

Jennifer A. Golinveaux
(Intellectual Property, Litigation)
(415) 591-1056
London Becky L. Troutman
(Intellectual Property)
(415) 591-1401
Zoë Ashcroft
(Corporate, Financial)
44 (0)20 7105 0025    
Danvers Baillieu
(Litigation, Financial)

44 (0)20 7105 0017

Washington, D.C.  
Barry Vitou
(Corporate, Financial)

44 (0)20 7105 0018

Marion K. Goldberg
(Health Care)
(202) 282-5788

Attorney Advertising Materials

These materials have been prepared by Winston & Strawn for informational purposes only. These materials do not constitute legal advice and cannot be relied upon by any taxpayer for the purpose of avoiding penalties imposed under the Internal Revenue Code. Receipt of this information does not create an attorney-client relationship. No reproduction or redistribution without written permission of Winston & Strawn LLP.

Along with this briefing, a library of all the Winston & Strawn LLP briefings published to date can be accessed by visiting the Publications Library section of Winston & Strawn LLP's Web site (www.winston.com).

© 2010 Winston & Strawn LLP