CREATORS OF THE COMPLIANCE TUNE-UP®

AARMR | ABA | ACAMS | ALTA | ARMCP | IAPP | IIA | MBA | MERS® | MISMO | NAMB

Showing posts with label Protecting Consumer Privacy. Show all posts
Showing posts with label Protecting Consumer Privacy. Show all posts

Friday, April 6, 2012

FTC Issues New Consumer Privacy Guidelines

Recently, we notified you that on March 12, 2012, the Consumer Financial Protection Bureau (CFPB) announced proposed amendments to the confidential treatment of information obtained from persons in connection with its exercise of authorities under federal consumer financial law. *
The proposed amendments would add a new section to the rules which provide that the submission by any person of any information to the Bureau in the course of the Bureau's supervisory or regulatory processes will not waive or otherwise affect any privilege such person may claim with respect to such information under federal or state law as to any other person or entity. Additionally, the CFPB is proposing to adopt a provision which provides that privileged information given by the CFPB to another federal or state agency does not waive any applicable privilege, whether the privilege belongs to the CFPB or any other person.
Today, we will take a brief look at consumer privacy protection updates at the Federal Trade Commission (FTC), the watchdog enforcement agency charged with protecting consumer privacy, issued a sweeping revisions to its privacy rules.
In this article, we will take a look at the FTC's call for companies to adopt best privacy practices. These best practices include making privacy the "default setting" for commercial data practices and giving consumers greater control over the collection and use of their personal data through simplified choices and increased transparency.
_______________________________________
IN THIS ARTICLE
Overview
Privacy by Design
Simplified Choice for Businesses and Consumers
Greater Transparency
What Has Changed?
Future Issues
_______________________________________
OVERVIEW
On March 26, 2012, the FTC issued a final report of 112 pages, setting forth best practices for businesses to protect the privacy of American consumers and give them greater control over the collection and use of their personal data.
In the report, Protecting Consumer Privacy in an Era of Rapid Change: Recommendations For Businesses and Policymakers, the FTC also recommends that Congress consider enacting general privacy legislation, data security and breach notification legislation, and data broker legislation.
The Report follows a preliminary staff report that the FTC issued in December 2010. The preliminary report proposed a framework for protecting consumer privacy with respect to the new communication technologies of this century.
Like this Report, the framework urged companies to adopt the following practices, consistent with the Fair Information Practice Principles first articulated almost 40 years ago:
  • Privacy by Design: Build in privacy at every stage of product development.

  • Simplified Choice for Businesses and Consumers: Give consumers the ability to make decisions about their data at a relevant time and context, including through a Do Not Track mechanism, while reducing the burden on businesses of providing unnecessary choices.

  • Greater Transparency: Make information collection and use practices transparent.
PRIVACY BY DESIGN
Companies should build in consumers' privacy protections at every stage in developing their products. These include reasonable security for consumer data, limited collection and retention of such data, and reasonable procedures to promote data accuracy.
SIMPLIED CHOICES FOR BUSINESSES AND CONSUMERS
Companies should give consumers the option to decide what information is shared about them, and with whom. This should include a Do-Not-Track mechanism that would provide a simple, easy way for consumers to control the tracking of their online activities.
GREATER TRANSPARENCY
Companies should disclose details about their collection and use of consumers' information, and provide consumers access to the data collected about them.
WHAT HAS CHANGED?
The Report changes the guidance's scope; that is, the preliminary report of December 2010 recommended that the proposed framework apply to all commercial entities that collect or use consumer data that can be linked to a specific consumer, computer, or other device, but now this final Report concludes that the framework should not apply to companies that collect and do not transfer only non-sensitive data from fewer than 5,000 consumers a year.
The Report also responds to comments filed by organizations and individuals that, with technological advances, more and more data could be "reasonably linked" to consumers, computers, or devices. Thus, the Report concludes that data is not "reasonably linked" if a company takes reasonable measures to re-identify the data, commits not to re-identify it, and prohibits downstream recipients from re-identifying it.