BUSINESSES AND POLICYMAKERS

Agency decision

Ask Donna

What actually matters in this document.

Text

RECOMMENDATIONS FOR

BUSINESSES AND POLICYMAKERS

FTC REPORT

FEDERAL TRADE COMMISSION | MARCH 2012

RECOMMENDATIONS FOR

BUSINESSES AND POLICYMAKERS

FTC REPORT

MARCH 2012

CONTENTS

Executive Summary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . i

Final FTC Privacy Framework and Implementation Recommendations. . . . . . . . . . . . . . . . . . . . . . . . vii

I. Introduction. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1

II. Background . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2

A. FTC Roundtables and Preliminary Staff Report. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2

B. Department of Commerce Privacy Initiatives. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3

C. Legislative Proposals and Efforts by Stakeholders. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4

1. Do Not Track. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4

2. Other Privacy Initiatives. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5

III. Main Themes From Commenters. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7

A. Articulation of Privacy Harms . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 7

B. Global Interoperability. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9

C. Legislation to Augment Self-Regulatory Efforts . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 11

IV. Privacy Framework. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15

A. Scope. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15

1. Companies Should Comply with the Framework Unless They Handle Only Limited

Amounts of Non-Sensitive Data that is Not Shared with Third Parties. . . . . . . . . . . . . . . . . . . 15

2. The Framework Sets Forth Best Practices and Can Work in Tandem with Existing

Privacy and Security Statutes.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16

3. The Framework Applies to Offline As Well As Online Data. . . . . . . . . . . . . . . . . . . . . . . . . . . 17

4. The Framework Applies to Data That is Reasonably Linkable to a Specific Consumer,

Computer, or Device. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 18

B. Privacy by Design. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22

1. The Substantive Principles: Data Security, Reasonable Collection Limits, Sound

Retention Practices, and Data Accuracy.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 23

2. Companies Should Adopt Procedural Protections to Implement the Substantive Principles.. . . 30

C. Simplified Consumer Choice. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 35

1. Practices That Do Not Require Choice.. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36

2. For Practices Inconsistent with the Context of their Interaction with Consumers,

Companies Should Give Consumers Choices. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 48

D. Transparency . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 60

1. Privacy Notices. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 61

2. Access. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 64

3. Consumer Education. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 71

V. Conclusion . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 72

FTC Privacy Milestones

Personal Data Ecosystem

Dissenting Statement of Commissioner J. Thomas Rosch

EXECUTIVE SUMMARY

In today’s world of smart phones, smart grids, and smart cars, companies are collecting, storing, and

sharing more information about consumers than ever before. Although companies use this information

to innovate and deliver better products and services to consumers, they should not do so at the expense of

consumer privacy.

With this Report, the Commission calls on companies to act now to implement best practices to protect

consumers’ private information. These best practices include making privacy the “default setting” for

commercial data practices and giving consumers greater control over the collection and use of their personal

data through simplified choices and increased transparency. Implementing these best practices will enhance

trust and stimulate commerce.

This Report follows a preliminary staff report that the Federal Trade Commission (“FTC” or

“Commission”) issued in December 2010. The preliminary report proposed a framework for protecting

consumer privacy in the 21st Century. Like this Report, the framework urged companies to adopt the

following practices, consistent with the Fair Information Practice Principles first articulated almost 40 years

ago:

xx Privacy by Design: Build in privacy at every stage of product development;

xx Simplified Choice for Businesses and Consumers: Give consumers the ability to make decisions

about their data at a relevant time and context, including through a Do Not Track mechanism, while

reducing the burden on businesses of providing unnecessary choices; and

xx Greater Transparency: Make information collection and use practices transparent.

The Commission received more than 450 public comments in response to the preliminary report from

various stakeholders, including businesses, privacy advocates, technologists and individual consumers. A

wide range of stakeholders, including industry, supported the principles underlying the framework, and

many companies said they were already following them. At the same time, many commenters criticized the

slow pace of self-regulation, and argued that it is time for Congress to enact baseline privacy legislation. In

this Report, the Commission addresses the comments and sets forth a revised, final privacy framework that

adheres to, but also clarifies and fine-tunes, the basic principles laid out in the preliminary report.

Since the Commission issued the preliminary staff report, Congress has introduced both general privacy

bills and more focused bills, including ones addressing Do Not Track and the privacy of teens. Industry has

made some progress in certain areas, most notably, in responding to the preliminary report’s call for Do Not

Track. In other areas, however, industry progress has been far slower. Thus, overall, consumers do not yet

enjoy the privacy protections proposed in the preliminary staff report.

The Administration and certain Members of Congress have called for enactment of baseline privacy

legislation. The Commission now also calls on Congress to consider enacting baseline privacy legislation and

reiterates its call for data security legislation. The Commission is prepared to work with Congress and other

stakeholders to craft such legislation. At the same time, the Commission urges industry to accelerate the

pace of self-regulation.

i

The remainder of this Executive Summary describes key developments since the issuance of the

preliminary report, discusses the most significant revisions to the proposed framework, and lays out several

next steps.

DEVELOPMENTS SINCE ISSUANCE OF THE PRELIMINARY REPORT

In the last 40 years, the Commission has taken numerous actions to shape the consumer privacy

landscape. For example, the Commission has sued dozens of companies that broke their privacy and

security promises, scores of telemarketers that called consumers on the Do Not Call registry, and more

than a hundred scammers peddling unwanted spam and spyware. Since it issued the initial staff report,

the Commission has redoubled its efforts to protect consumer privacy, including through law enforcement,

policy advocacy, and consumer and business education. It has also vigorously promoted self-regulatory

efforts.

On the law enforcement front, since December 2010, the Commission:

xx Brought enforcement actions against Google and Facebook. The orders obtained in these cases

require the companies to obtain consumers’ affirmative express consent before materially changing

certain of their data practices and to adopt strong, company-wide privacy programs that outside

auditors will assess for 20 years. These orders will protect the more than one billion Google and

Facebook users worldwide.

xx Brought enforcement actions against online advertising networks that failed to honor opt outs. The

orders in these cases are designed to ensure that when consumers choose to opt out of tracking by

advertisers, their choice is effective.

xx Brought enforcement actions against mobile applications that violated the Children’s Online Privacy

Protection Act as well as applications that set default privacy settings in a way that caused consumers

to unwittingly share their personal data.

xx Brought enforcement actions against entities that sold consumer lists to marketers in violation of the

Fair Credit Reporting Act.

xx Brought actions against companies for failure to maintain reasonable data security.

On the policy front, since December 2010, the FTC and staff:

xx Hosted two privacy-related workshops, one on child identity theft and one on the privacy

implications of facial recognition technology.

xx Testified before Congress ten times on privacy and data security issues.

xx Consulted with other federal agencies, including the Federal Communications Commission, the

Department of Health and Human Services, and the Department of Commerce, on their privacy

initiatives. The Commission has supported the Department of Commerce’s initiative to convene

stakeholders to develop privacy-related codes of conduct for different industry sectors.

xx Released a survey of data collection disclosures by mobile applications directed to children.

xx Proposed amendments to the Children’s Online Privacy Protection Act Rule.

ii

On the education front, since December 2010, the Commission:

xx Continued outreach efforts through the FTC’s consumer online safety portal, OnGuardOnline.gov,

which provides information in a variety of formats – articles, games, quizzes, and videos – to help

consumers secure their computers and protect their personal information. It attracts approximately

100,000 unique visitors per month.

xx Published new consumer education materials on identity theft, Wi-Fi hot spots, cookies, and mobile

devices.

xx Sent warning letters to marketers of mobile apps that do background checks on individuals,

educating them about the requirements of the Fair Credit Reporting Act.

To promote self-regulation, since December 2010, the Commission:

xx Continued its call for improved privacy disclosures and choices, particularly in the area of online

behavioral tracking. In response to this call, as well as to Congressional interest:

xx A number of Internet browser vendors developed browser-based tools for consumers to request

that websites not track their online activities.

xx The World Wide Web Consortium, an Internet standard setting organization, is developing a

universal web protocol for Do Not Track.

xx The Digital Advertising Alliance (“DAA”), a coalition of media and marketing organizations,

has developed a mechanism, accessed through an icon that consumers can click, to obtain

information about and opt out of online behavioral advertising. Additionally, the DAA has

committed to preventing the use of consumers’ data for secondary purposes like credit and

employment and honoring the choices about tracking that consumers make through the settings

on their browsers.

xx Participated in the development of enforceable cross-border privacy rules for businesses to harmonize

and enhance privacy protection of consumer data that moves between member countries of the

forum on Asia Pacific Economic Cooperation.

THE FINAL REPORT

Based upon its analysis of the comments filed on the proposed privacy framework, as well as commercial

and technological developments, the Commission is issuing this final Report. The final framework is

intended to articulate best practices for companies that collect and use consumer data. These best practices

can be useful to companies as they develop and maintain processes and systems to operationalize privacy

and data security practices within their businesses. The final privacy framework contained in this Report

is also intended to assist Congress as it considers privacy legislation. To the extent the framework goes

beyond existing legal requirements, the framework is not intended to serve as a template for law enforcement

actions or regulations under laws currently enforced by the FTC. While retaining the proposed framework’s

fundamental best practices of privacy by design, simplified choice, and greater transparency, the Commission

makes revised recommendations in three key areas in response to the comments.

iii

First, the Commission makes changes to the framework’s scope. The preliminary report proposed

that the privacy framework apply to all commercial entities that collect or use consumer data that can be

reasonably linked to a specific consumer, computer, or other device. To address concerns about undue

burdens on small businesses, the final framework does not apply to companies that collect only non-sensitive

data from fewer than 5,000 consumers a year, provided they do not share the data with third parties.

Commenters also expressed concern that, with improvements in technology and the ubiquity of public

information, more and more data could be “reasonably linked” to a consumer, computer or device, and that

the proposed framework provided less incentive for a business to try to de-identify the data it maintains.

To address this issue, the Report clarifies that data is not “reasonably linkable” to the extent that a company:

(1) takes reasonable measures to ensure that the data is de-identified; (2) publicly commits not to try to reidentify the data; and (3) contractually prohibits downstream recipients from trying to re-identify the data.

Second, the Commission revises its approach to how companies should provide consumers with privacy

choices. To simplify choice for both consumers and businesses, the proposed framework set forth a list

of five categories of “commonly accepted” information collection and use practices for which companies

need not provide consumers with choice (product fulfillment, internal operations, fraud prevention, legal

compliance and public purpose, and first-party marketing). Several business commenters expressed concern

that setting these “commonly accepted practices” in stone would stifle innovation. Other commenters

expressed the concern that the “commonly accepted practices” delineated in the proposed framework were

too broad and would allow a variety of practices to take place without consumer consent.

In response to these concerns, the Commission sets forth a modified approach that focuses on the

context of the consumer’s interaction with the business. Under this approach, companies do not need

to provide choice before collecting and using consumers’ data for practices that are consistent with the

context of the transaction, consistent with the company’s relationship with the consumer, or as required

or specifically authorized by law. Although many of the five “commonly accepted practices” identified in

the preliminary report would generally meet this standard, there may be exceptions. The Report provides

examples of how this new “context of the interaction” standard would apply in various circumstances.

Third, the Commission recommends that Congress consider enacting targeted legislation to provide

greater transparency for, and control over, the practices of information brokers. The proposed framework

recommended that companies provide consumers with reasonable access to the data the companies maintain

about them, proportionate to the sensitivity of the data and the nature of its use. Several commenters

discussed in particular the importance of consumers’ ability to access information that information brokers

have about them. These commenters noted the lack of transparency about the practices of information

brokers, who often buy, compile, and sell a wealth of highly personal information about consumers but

never interact directly with them. Consumers are often unaware of the existence of these entities, as well as

the purposes for which they collect and use data.

The Commission agrees that consumers should have more control over the practices of information

brokers and believes that appropriate legislation could help address this goal. Any such legislation could be

iv

modeled on a bill that the House passed on a bipartisan basis during the 111th Congress, which included a

procedure for consumers to access and dispute personal data held by information brokers.

IMPLEMENTATION OF THE PRIVACY FRAMEWORK

While Congress considers privacy legislation, the Commission urges industry to accelerate the pace

of its self-regulatory measures to implement the Commission’s final privacy framework. Although some

companies have excellent privacy and data security practices, industry as a whole must do better. Over the

course of the next year, Commission staff will promote the framework’s implementation by focusing its

policymaking efforts on five main action items, which are highlighted here and discussed further throughout

the report.

xx Do Not Track: As discussed above, industry has made significant progress in implementing Do Not

Track. The browser vendors have developed tools that consumers can use to signal that they do not

want to be tracked; the Digital Advertising Alliance (“DAA”) has developed its own icon-based tool

and has committed to honor the browser tools; and the World Wide Web Consortium (“W3C”)

has made substantial progress in creating an international standard for Do Not Track. However, the

work is not done. The Commission will work with these groups to complete implementation of an

easy-to use, persistent, and effective Do Not Track system.

xx Mobile: The Commission calls on companies providing mobile services to work toward improved

privacy protections, including the development of short, meaningful disclosures. To this end, FTC

staff has initiated a project to update its business guidance about online advertising disclosures. As

part of this project, staff will host a workshop on May 30, 2012 and will address, among other

issues, mobile privacy disclosures and how these disclosures can be short, effective, and accessible to

consumers on small screens. The Commission hopes that the workshop will spur further industry

self-regulation in this area.

xx Data Brokers: To address the invisibility of, and consumers’ lack of control over, data brokers’

collection and use of consumer information, the Commission supports targeted legislation – similar

to that contained in several of the data security bills introduced in the 112th Congress – that would

provide consumers with access to information about them held by a data broker. To further increase

transparency, the Commission calls on data brokers that compile data for marketing purposes to

explore creating a centralized website where data brokers could (1) identify themselves to consumers

and describe how they collect and use consumer data and (2) detail the access rights and other

choices they provide with respect to the consumer data they maintain.

xx Large Platform Providers: To the extent that large platforms, such as Internet Service Providers,

operating systems, browsers, and social media seek, to comprehensively track consumers’ online

activities, it raises heightened privacy concerns. To further explore privacy and other issues related to

this type of comprehensive tracking, FTC staff intends to host a public workshop in the second half

of 2012.

v

xx Promoting Enforceable Self-Regulatory Codes: The Department of Commerce, with the support

of key industry stakeholders, is undertaking a project to facilitate the development of sector-specific

codes of conduct. FTC staff will participate in that project. To the extent that strong privacy codes

are developed, the Commission will view adherence to such codes favorably in connection with its

law enforcement work. The Commission will also continue to enforce the FTC Act to take action

against companies that engage in unfair or deceptive practices, including the failure to abide by selfregulatory programs they join.

vi

FINAL FTC PRIVACY FRAMEWORK AND

IMPLEMENTATION RECOMMENDATIONS

The final privacy framework is intended to articulate best practices for companies that collect and use consumer

data. These best practices can be useful to companies as they develop and maintain processes and systems

to operationalize privacy and data security practices within their businesses. The final privacy framework

contained in this report is also intended to assist Congress as it considers privacy legislation. To the extent the

framework goes beyond existing legal requirements, the framework is not intended to serve as a template for

law enforcement actions or regulations under laws currently enforced by the FTC.

SCOPE

Final Scope: The framework applies to all commercial entities that collect or use consumer data that can be

reasonably linked to a specific consumer, computer, or other device, unless the entity collects only nonsensitive data from fewer than 5,000 consumers per year and does not share the data with third parties.

PRIVACY BY DESIGN

Baseline Principle: Companies should promote consumer privacy throughout their organizations and at every

stage of the development of their products and services.

A. The Substantive Principles

Final Principle: Companies should incorporate substantive privacy protections into their practices, such as

data security, reasonable collection limits, sound retention and disposal practices, and data accuracy.

B. Procedural Protections to Implement the Substantive Principles

Final Principle: Companies should maintain comprehensive data management procedures throughout the life

cycle of their products and services.

SIMPLIFIED CONSUMER CHOICE

Baseline Principle: Companies should simplify consumer choice.

A. Practices That Do Not Require Choice

Final Principle: Companies do not need to provide choice before collecting and using consumer data for

practices that are consistent with the context of the transaction or the company’s relationship with the

consumer, or are required or specifically authorized by law.

To balance the desire for flexibility with the need to limit the types of practices for which choice is not

required, the Commission has refined the final framework so that companies engaged in practices consistent

with the context of their interaction with consumers need not provide choices for those practices.

vii

B. Companies Should Provide Consumer Choice for Other Practices

Final Principle: For practices requiring choice, companies should offer the choice at a time and in a context

in which the consumer is making a decision about his or her data. Companies should obtain affirmative

express consent before (1) using consumer data in a materially different manner than claimed when the

data was collected; or (2) collecting sensitive data for certain purposes.

The Commission commends industry’s efforts to improve consumer control over online behavioral tracking

by developing a Do Not Track mechanism, and encourages continued improvements and full implementation

of those mechanisms.

TRANSPARENCY

Baseline Principle: Companies should increase the transparency of their data practices.

A. Privacy notices

Final Principle: Privacy notices should be clearer, shorter, and more standardized to enable better

comprehension and comparison of privacy practices.

B. Access

Final Principle: Companies should provide reasonable access to the consumer data they maintain; the extent

of access should be proportionate to the sensitivity of the data and the nature of its use.

The Commission has amplified its support for this principle by including specific recommendations governing

the practices of information brokers.

C. Consumer Education

Final Principle: All stakeholders should expand their efforts to educate consumers about commercial data

privacy practices.

LEGISLATIVE RECOMMENDATIONS

The Commission now also calls on Congress to consider enacting baseline privacy legislation and reiterates

its call for data security and data broker legislation. The Commission is prepared to work with Congress and

other stakeholders to craft such legislation. At the same time, the Commission urges industry to accelerate

the pace of self-regulation.

FTC WILL ASSIST WITH IMPLEMENTATION IN FIVE KEY AREAS

As discussed throughout the Commission’s final Report, there are a number of specific areas where policy

makers have a role in assisting with the implementation of the self-regulatory principles that make up the

final privacy framework. Areas where the FTC will be active over the course of the next year include the

following:

1. Do Not Track

Industry has made significant progress in implementing Do Not Track. The browser vendors have developed

tools that consumers can use to signal that they do not want to be tracked; the DAA has developed its own

icon-based tool and has committed to honor the browser tools; and the W3C has made substantial progress

in creating an international standard for Do Not Track. However, the work is not done. The Commission will

work with these groups to complete implementation of an easy-to use, persistent, and effective Do Not Track

system.

viii

2. Mobile

The Commission calls on companies providing mobile services to work toward improved privacy protections,

including the development of short, meaningful disclosures. To this end, FTC staff has initiated a project to

update its business guidance about online advertising disclosures. As part of this project, staff will host a

workshop on May 30, 2012 and will address, among other issues, mobile privacy disclosures and how these

disclosures can be short, effective, and accessible to consumers on small screens. The Commission hopes

that the workshop will spur further industry self-regulation in this area.

3. Data Brokers

To address the invisibility of, and consumers’ lack of control over, data brokers’ collection and use of

consumer information, the Commission supports targeted legislation – similar to that contained in several

of the data security bills introduced in the 112th Congress – that would provide consumers with access to

information about them held by a data broker. To further increase transparency, the Commission calls on

data brokers that compile data for marketing purposes to explore creating a centralized website where data

brokers could (1) identify themselves to consumers and describe how they collect and use consumer data

and (2) detail the access rights and other choices they provide with respect to the consumer data they

maintain.

4. Large Platform Providers

To the extent that large platforms, such as Internet Service Providers, operating systems, browsers, and

social media, seek to comprehensively track consumers’ online activities, it raises heightened privacy

concerns. To further explore privacy and other issues related to this type of comprehensive tracking, FTC

staff intends to host a public workshop in the second half of 2012.

5. Promoting Enforceable Self-Regulatory Codes

The Department of Commerce, with the support of key industry stakeholders, is undertaking a project to

facilitate the development of sector-specific codes of conduct. FTC staff will participate in that project. To

the extent that strong privacy codes are developed, the Commission will view adherence to such codes

favorably in connection with its law enforcement work. The Commission will also continue to enforce the

FTC Act to take action against companies that engage in unfair or deceptive practices, including the failure to

abide by self-regulatory programs they join.

In all other areas, the Commission calls on individual companies, trade associations, and self-regulatory

bodies to adopt the principles contained in the final privacy framework, to the extent they have not already

done so. For its part, the FTC will focus its policy efforts on the five areas identified above, vigorously

enforce existing laws, work with industry on self-regulation, and continue to target its education efforts on

building awareness of existing data collection and use practices and the tools to control them.

ix

x

I. INTRODUCTION

In December 2010, the Federal Trade Commission (“FTC” or “Commission”) issued a preliminary

staff report to address the privacy issues associated with new technologies and business models.1 The

report outlined the FTC’s 40-year history of promoting consumer privacy through policy and enforcement

work, discussed the themes and areas of consensus that emerged from the Commission’s “Exploring

Privacy” roundtables, and set forth a proposed framework to guide policymakers and other stakeholders

regarding best practices for consumer privacy. The proposed framework called on companies to build

privacy protections into their business operations (i.e., adopt “privacy by design”2), offer simplified choice

mechanisms that give consumers more meaningful control, and increase the transparency of their data

practices.

The preliminary report included a number of questions for public comment to assist and guide

the Commission in developing a final privacy framework. The Commission received more than 450

comments from a wide variety of interested parties, including consumer and privacy advocates, individual

companies and trade associations, academics, technologists, and domestic and foreign government agencies.

Significantly, more than half of the comments came from individual consumers. The comments have helped

the Commission refine the framework to better protect consumer privacy in today’s dynamic and rapidly

changing marketplace.

In this Final Report, the Commission adopts staff’s preliminary framework with certain clarifications and

revisions. The final privacy framework is intended to articulate best practices for companies that collect and

use consumer data. These best practices can be useful to companies as they develop and maintain processes

and systems to operationalize privacy and data security practices within their businesses. The final privacy

framework contained in this Report is also intended to assist Congress as it considers privacy legislation. To

the extent the framework goes beyond existing legal requirements, the framework is not intended to serve as

a template for law enforcement actions or regulations under laws currently enforced by the FTC.

The Report highlights the developments since the FTC issued staff’s preliminary report, including the

Department of Commerce’s parallel privacy initiative, proposed legislation, and actions by industry and

other stakeholders. Next, it analyzes and responds to the main issues raised by the public comments. Based

on those comments, as well as marketplace developments, the Report sets forth a revised privacy framework

and legislative recommendations. Finally, the Report outlines a series of policy initiatives that FTC staff will

undertake in the next year to assist industry with implementing the final framework as best practices.

1

FTC, Protecting Consumer Privacy in an Era of Rapid Change, A Proposed Framework for Businesses and Policymakers,

Preliminary FTC Staff Report (Dec. 2010), available at http://www.ftc.gov/os/2010/12/101201privacyreport.pdf.

2

Privacy by Design is an approach that Ann Cavoukian, Ph.D., Information and Privacy Commissioner, Ontario, Canada, has

advocated. See Information and Privacy Commissioner, Ontario, Canada, Privacy by Design, http://privacybydesign.ca/.

1

II. BACKGROUND

A. FTC ROUNDTABLES AND PRELIMINARY STAFF REPORT

Between December 2009 and March 2010, the FTC convened its “Exploring Privacy” roundtables.3

The roundtables brought together stakeholders representing diverse interests to evaluate whether the FTC’s

existing approach to protecting consumer privacy was adequate in light of 21st Century technologies and

business models. From these discussions, as well as submitted materials, a number of themes emerged.

First, the collection and commercial use of consumer data in today’s society is ubiquitous and often invisible

to consumers. Second, consumers generally lack full understanding of the nature and extent of this data

collection and use and, therefore, are unable to make informed choices about it. Third, despite this lack of

understanding, many consumers are concerned about the privacy of their personal information. Fourth, the

collection and use of consumer data has led to significant benefits in the form of new products and services.

Finally, the traditional distinction between personally identifiable information and “anonymous” data has

blurred.

Participants also pointed to shortcomings in existing frameworks that have attempted to address

privacy concerns. The “notice-and-choice model,” which encouraged companies to develop privacy policies

describing their information collection and use practices, led to long, incomprehensible privacy policies

that consumers typically do not read, let alone understand.4 The “harm-based model,” which focused on

protecting consumers from specific harms – physical security, economic injury, and unwarranted intrusions

into their daily lives – had been criticized for failing to recognize a wider range of privacy-related concerns,

including reputational harm or the fear of being monitored.5 Participants noted that both of these privacy

frameworks have struggled to keep pace with the rapid growth of technologies and business models that

enable companies to collect and use consumers’ information in ways that often are invisible to consumers.6

Building on the record developed at the roundtables and on its own enforcement and policymaking

expertise, FTC staff proposed for public comment a framework for approaching privacy. The proposed

framework included three major components. It called on companies to treat privacy as their “default

setting” by implementing “privacy by design” throughout their regular business operations. The concept of

privacy by design includes limitations on data collection and retention, as well as reasonable security and

data accuracy. By considering and addressing privacy at every stage of product and service development,

3

The first roundtable took place on December 7, 2009, the second roundtable on January 28, 2010, and the third

roundtable on March 17, 2010. See FTC, Exploring Privacy – A Roundtable Series, http://www.ftc.gov/bcp/workshops/

privacyroundtables/index.shtml.

4

See, e.g., 1st Roundtable, Remarks of Fred Cate, Indiana University Maurer School of Law, at 280-81; 1st Roundtable, Remarks of

Lorrie Cranor, Carnegie Mellon University, at 129; see also Written Comment of Fred Cate, 2nd Roundtable, Consumer Protection

in the Age of the ‘Information Economy,’ cmt. #544506-00057, at 343-79.

5

See, e.g., 1st Roundtable, Remarks of Marc Rotenberg, Electronic Privacy Information Center, at 301; 1st Roundtable, Remarks of

Leslie Harris, Center for Democracy & Technology, at 36-38; 1st Roundtable, Remarks of Susan Grant, Consumer Federation of

America, at 38-39.

6

See, e.g., 3rd Roundtable, Remarks of Kathryn Montgomery, American University School of Communication, at 200-01; 2nd

Roundtable, Remarks of Kevin Bankston, Electronic Frontier Foundation, at 277.

2

companies can shift the burden away from consumers who would otherwise have to seek out privacyprotective practices and technologies. The proposed framework also called on companies to simplify

consumer choice by presenting important choices – in a streamlined way – to consumers at the time they are

making decisions about their data. As part of the call for simplified choice, staff asked industry to develop

a mechanism that would allow consumers to more easily control the tracking of their online activities, often

referred to as “Do Not Track.” Finally, the framework focused on improving consumer understanding of

commercial data practices (“transparency”) and called on companies – both those that interact directly

with consumers and those that lack a consumer interface – to improve the transparency of their practices.

As discussed below, the Commission received a large number of thoughtful and informative comments

regarding each of the framework’s elements. These comments have allowed the Commission to refine the

framework and to provide further guidance regarding its implementation.

B. DEPARTMENT OF COMMERCE PRIVACY INITIATIVES

In a related effort to examine privacy, in May 2010, the Department of Commerce (“DOC” or

“Commerce”) convened a public workshop to discuss how to balance innovation, commerce, and

consumer privacy in the online context.7 Based on the input received from the workshop, as well as related

research, on December 16, 2010, the DOC published for comment a strategy paper outlining privacy

recommendations and proposed initiatives.8 Following the public comment period, on February 23, 2012,

the Administration issued its final “White Paper” on consumer privacy. The White Paper recommends that

Congress enact legislation to implement a Consumer Privacy Bill of Rights based on the Fair Information

Practice Principles (“FIPPs”).9 In addition, the White Paper calls for a multistakeholder process to determine

how to apply the Consumer Privacy Bill of Rights in different business contexts. Commerce issued a Notice

of Inquiry on March 5, 2012, asking for public input on both the process for convening stakeholders on this

project, as well as the proposed subject areas to be discussed.10

Staff from the FTC and Commerce worked closely to ensure that the agencies’ privacy initiatives are

complementary. Personnel from each agency actively participated in both the DOC and FTC initiatives,

and have also communicated regularly on how best to develop a meaningful, effective, and consistent

approach to privacy protection. Going forward, the agencies will continue to work collaboratively to guide

implementation of these complementary privacy initiatives.

7

See Press Release, Department of Commerce, Commerce Secretary Gary Locke Discusses Privacy and Innovation with

Leading Internet Stakeholders (May 7, 2010), available at http://www.commerce.gov/news/press-releases/2010/05/07/

commerce-secretary-gary-locke-discusses-privacy-and-innovation-leadin.

8

See Department of Commerce Internet Policy Task Force, Commercial Data Privacy and Innovation in the Internet Economy:

A Dynamic Policy Framework (Dec. 16, 2010), available at http://www.ntia.doc.gov/files/ntia/publications/iptf_privacy_

greenpaper_12162010.pdf.

9

White House, Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation

in the Global Digital Economy (Feb. 2012), available at http://www.whitehouse.gov/sites/default/files/privacy-final.pdf. The

FIPPs as articulated in the Administration paper are: Transparency, Individual Control, Respect for Context, Security, Access,

Accuracy, Focused Collection, and Accountability.

10 See National Telecommunications and Information Administration, Request for Public Comment, Multistakeholder Process

to Develop Consumer Data Privacy Codes of Conduct, 77 Fed. Reg. 13098 (Mar. 5, 2012).

3

C. LEGISLATIVE PROPOSALS AND EFFORTS BY STAKEHOLDERS

Since Commission staff released its preliminary report in December 2010, there have been a number of

significant legislative proposals, as well as steps by industry and other stakeholders, to promote consumer

privacy.

1. DO NOT TRACK

The preliminary staff report called on industry to create and implement a mechanism to allow consumers

to control the collection and use of their online browsing data, often referred to as “Do Not Track.” Bills

introduced in the House and the Senate specifically address the creation of Do Not Track mechanisms, and,

if enacted, would mandate that the Commission promulgate regulations to establish standards for a Do Not

Track regime.11

In addition to the legislative proposals calling for the creation of Do Not Track, staff’s preliminary

report recommendation triggered significant progress by various industry sectors to develop tools to allow

consumers to control online tracking. A number of browser vendors – including Mozilla, Microsoft, and

Apple – announced that the latest versions of their browsers permit consumers to instruct websites not to

track their activities across websites.12 Mozilla has also introduced a mobile browser for Android devices

that enables Do Not Track.13 The online advertising industry has also established an important program.

The Digital Advertising Alliance (“DAA”), an industry coalition of media and marketing associations,

has developed an initiative that includes an icon embedded in behaviorally targeted online ads.14 When

consumers click on the icon, they can see information about how the ad was targeted and delivered to them

and they are given the opportunity to opt out of such targeted advertising. The program’s recent growth

and implementation has been significant. In addition, the DAA has committed to preventing the use of

consumers’ data for secondary purposes like credit and employment decisions. The DAA has also agreed to

honor the choices about tracking that consumers make through settings on their web browsers. This will

provide consumers two ways to opt out: through the DAA’s icon in advertisements or through their browser

settings. These steps demonstrate the online advertising industry’s support for privacy and consumer choice.

11 See Do-Not-Track Online Act of 2011, S. 913, 112th Congress (2011); Do Not Track Me Online Act, H.R. 654, 112th

Congress (2011).

12 See Press Release, Microsoft, Providing Windows Customers with More Choice and Control of Their Privacy Online with

Internet Explorer 9 (Dec. 7, 2010), available at http://www.microsoft.com/presspass/features/2010/dec10/12-07ie9privacyqa.

mspx; Mozilla Firefox 4 Beta, Now Including “Do Not Track” Capabilities, Mozilla Blog (Feb. 8, 2011), http://blog.mozilla.

com/blog/2011/02/08/mozilla-firefox-4-beta-now-including-do-not-track-capabilities/; Nick Wingfield, Apple Adds Do-NotTrack Tool to New Browser, Wall St. J., Apr. 13, 2011, available at http://online.wsj.com/article/SB1000142405274870355

1304576261272308358858.html. Google recently announced that it will also offer this capability in the next version of its

browser. Gregg Kaizer, FAQ: What Google’s Do Not Track Move Means, Computerworld (Feb. 24, 2012), available at http://

www.computerworld.com/s/article/9224583/FAQ_What_Google_s_Do_Not_Track_move_means.

13 See Mozilla, Do Not Track FAQs, http://dnt.mozilla.org.

14 See Press Release, Interactive Advertising Bureau, Major Marketing/Media Trade Groups Launch Program to Give Consumers

Enhanced Control Over Collection and Use of Web Viewing Data for Online Behavioral Advertising (Oct. 4, 2010),

available at http://www.iab.net/about_the_iab/recent_press_releases/press_release_archive/press_release/pr-100410.

4

Finally, the World Wide Web Consortium (“W3C”)15 convened a working group to create a universal

standard for Do Not Track. The working group includes DAA member companies, other U.S. and

international companies, industry groups, and consumer groups. The W3C group has made substantial

progress toward a standard that is workable in the desktop and mobile settings, and has published two

working drafts of its standard documents. The group’s goal is to complete a consensus standard in the

coming months.

2. OTHER PRIVACY INITIATIVES

Beyond the Do Not Track developments, broader initiatives to improve consumer privacy are underway

in Congress, Federal agencies, and the private sector. For example, Congress is considering several general

privacy bills that would establish a regulatory framework for protecting consumer privacy by improving

transparency about the commercial uses of personal information and providing consumers with choice about

such use.16 The bills would also provide the Commission rulemaking authority concerning, among other

things, notice, consent, and the transfer of information to third parties.

In the House of Representatives, Members have introduced bipartisan legislation to amend the

Children’s Online Privacy Protection Act17 (“COPPA”) and establish other protections for children and

teens.18 The bill would prohibit the collection and use of minors’ information for targeted marketing and

would require websites to permit the deletion of publicly available information of minors. Members of

Congress also introduced a number of other bills addressing data security and data breach notification in

2011.19

15 The W3C is an international standard-setting body that works “to lead the World Wide Web to its full potential by

developing protocols and guidelines that ensure the long-term growth of the Web.” See W3C Mission, http://www.w3.org/

Consortium/mission.html.

16 See Commercial Privacy Bill of Rights Act of 2011, S. 799, 112th Congress (2011); Building Effective Strategies To Promote

Responsibility Accountability Choice Transparency Innovation Consumer Expectations and Safeguards Act, H.R. 611, 112th

Congress (2011); Consumer Privacy Protection Act of 2011, H.R. 1528, 112th Congress (2011).

17 Children’s Online Privacy Protection Act of 1998, 15 U.S.C. §§ 6501-6506.

18 See Do Not Track Kids Act of 2011, H.R. 1895, 112th Congress (2011). In September 2011, the Commission issued

a Notice of Proposed Rulemaking, proposing changes to the COPPA Rule to address changes in technology. See FTC

Children’s Online Privacy Protection Rule, 76 Fed. Reg. 59804 (proposed Sep. 27, 2011), available at http://www.ftc.gov/

os/2011/09/110915coppa.pdf.

19 See Personal Data Privacy and Security Act of 2011, S. 1151, 112th Congress (2011); Data Security and Breach Notification

Act of 2011, S. 1207, 112th Congress (2011); Data Breach Notification Act of 2011, S.1408, 112th Congress (2011); Data

Security Act of 2011, S.1434, 112th Congress (2011); Personal Data Protection and Breach Accountability Act of 2011, S.

1535, 112th Congress (2011); Data Accountability and Trust Act, H.R. 1707, 112th Congress (2011); Data Accountability

and Trust Act of 2011, H.R. 1841, 112th Congress (2011); Secure and Fortify Electronic Data Act, H.R. 2577, 112th

Congress (2011).

5

Federal agencies have taken significant steps to improve consumer privacy as well. For its part, since

issuing the preliminary staff report, the FTC has resolved seven data security cases,20 obtained orders against

Google, Facebook, and online ad networks,21 and challenged practices that violate sector-specific privacy

laws like the Fair Credit Reporting Act (“FCRA”) and COPPA.22 The Commission has also proposed

amendments to the COPPA Rule to address changes in technology. The comment period on the Proposed

Rulemaking ran through December 23, 2011, and the Commission is currently reviewing the comments

received.23 Additionally, the Commission has hosted public workshops on discrete privacy issues such as

child identity theft and the use of facial recognition technology.

Other federal agencies have also begun examining privacy issues. In 2011, the Federal Communications

Commission (“FCC”) hosted a public forum to address privacy concerns associated with locationbased services.24 The Department of Health and Human Services (“HHS”) hosted a forum on medical

identity theft, developed a model privacy notice for personal health records,25 and is developing legislative

recommendations on privacy and security for such personal health records. In addition, HHS recently

launched an initiative to identify privacy and security best practices for using mobile devices in health care

settings.26

20 See In the Matter of Upromise, Inc., FTC File No. 102 3116 (Jan. 18, 2012) (proposed consent order), available at http://www.

ftc.gov/os/caselist/1023116/index.shtm; In the Matter of ACRAnet, Inc., FTC Docket No. C-4331 (Aug. 17, 2011) (consent

order), available at http://www.ftc.gov/os/caselist/0923088/index.shtm; In the Matter of SettlementOne Credit Corp., FTC

Docket No. C-4330 (Aug. 17, 2011) (consent order), available at http://www.ftc.gov/os/caselist/0823208/index.shtm; In

the Matter of Ceridian Corp., FTC Docket No. C-4325 (June 8, 2011) (consent order), available at http://www.ftc.gov/os/

caselist/1023160/index.shtm; In the Matter of Lookout Servs., Inc., FTC Docket No. C-4326 (June 15, 2011) (consent order),

available at http://www.ftc.gov/os/caselist/1023076/index.shtm; In the Matter of Twitter, Inc., FTC Docket No. C-4316 (Mar.

2, 2011) (consent order), available at http://www.ftc.gov/os/caselist/0923093/index.shtm; In the Matter of Fajilan & Assocs.,

Inc., FTC Docket No. C-4332 (Aug. 17, 2011) (consent order), available at http://www.ftc.gov/os/caselist/0923089/index.

shtm.

21 See In the Matter of Google, Inc., FTC Docket No. C-4336 (Oct. 13, 2011) (consent order), available at http://www.ftc.gov/

os/caselist/1023136/index.shtm (requiring company to implement privacy program subject to independent third-party audit);

In the Matter of Facebook, Inc., FTC File No. 092 3184 (Nov. 29, 2011) (proposed consent order), available at http://www.

ftc.gov/os/caselist/0923184/index.shtm (requiring company to implement privacy program subject to independent thirdparty audit); In the Matter of Chitika, Inc., FTC Docket No. C-4324 (June 7, 2011) (consent order), available at http://

www.ftc.gov/os/caselist/1023087/index.shtm (requiring company’s behavioral advertising opt out to last for five years); In

the Matter of ScanScout, Inc., FTC Docket No. C-4344 (Dec. 14, 2011) (consent order), available at http://www.ftc.gov/os/

caselist/1023185/index.shtm (requiring company to improve disclosure of its data collection practices and offer consumers a

user-friendly opt out mechanism).

22 Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq.; COPPA Rule, 16 C.F.R. Part 312; see also, e.g., United States v. W3

Innovations, LLC, No. CV-11-03958 (N.D. Cal. Sept. 8, 2011) (COPPA consent decree); United States v. Teletrack, Inc., No.

1 11-CV-2060 (N.D. Ga. filed June 24, 2011) (FCRA consent decree); United States v. Playdom, Inc., No. SACV-11-00724AG (ANx) (C.D. Cal. May 24, 2011) (COPPA consent decree).

23 See Press Release, FTC Extends Deadline for Comments on Proposed Amendments to the Children’s Online Privacy

Protection Rule Until December 23 (Nov. 18, 2011), available at http://www.ftc.gov/opa/2011/11/coppa.shtm.

24 See FCC Workshop, Helping Consumers Harness the Potential of Location-Based Services (June 28, 2011), available at http://

www.fcc.gov/events/location-based-services-forum.

25 See The Office of the National Coordinator for Health Information Technology, Personal Health Record (PHR) Model

Privacy Notice, http://healthit.hhs.gov/portal/server.pt/community/healthit_hhs_gov__draft_phr_model_notice/1176.

26 See HHS Workshop, Mobile Devices Roundtable: Safeguarding Health Information, available at http://healthit.hhs.gov/portal/

server.pt/community/healthit_hhs_gov__mobile_devices_roundtable/3815.

6

The private sector has taken steps to enhance user privacy and security as well. For example, Google and

Facebook have improved authentication mechanisms to give users stronger protection against compromised

passwords.27 Also, privacy-enhancing technologies such as the HTTPS Everywhere browser add-on have

given users additional tools to encrypt their information in transit.28 On the mobile front, the Mobile

Marketing Association released its Mobile Application Privacy Policy.29 This document provides guidance

on privacy principles for application (“app”) developers and discusses how to inform consumers about the

collection and use of their data. Despite these developments, as explained below, industry still has more

work to do to promote consumer privacy.

III. MAIN THEMES FROM COMMENTERS

The more than 450 comments filed in response to the preliminary staff report addressed three

overarching issues: how privacy harms should be articulated; the value of global interoperability of different

privacy regimes; and the desirability of baseline privacy legislation to augment self-regulatory efforts. Those

comments, and the Commission’s analysis, are discussed below.

A. ARTICULATION OF PRIVACY HARMS

There was broad consensus among commenters that consumers need basic privacy protections for

their personal information. This is true particularly in light of the complexity of the current personal data

ecosystem. Some commenters also stated that the Commission should recognize a broader set of privacy

harms than those involving physical and economic injury.30 For example, one commenter cited complaints

from consumers who had been surreptitiously tracked and targeted with prescription drug offers and other

health-related materials regarding sensitive medical conditions.31

At the same time, some commenters questioned whether the costs of broader privacy protections were

justified by the anticipated benefits.32 Relatedly, many commenters raised concerns about how wider privacy

protections would affect innovation and the ability to offer consumers beneficial new products and services.33

27 See Advanced Sign-In Security For Your Google Account, Google Official Blog (Feb. 10, 2011, 11:30 AM), http://

googleblog.blogspot.com/2011/02/advanced-sign-in-security-for-your.html#!/2011/02/advanced-sign-in-security-for-your.

html; Andrew Song, Introducing Login Approvals, Facebook Blog (May 12, 2011, 9:58 AM), http://www.facebook.com/

note.php?note_id=10150172618258920.

28 See HTTPS Everywhere, Electronic Frontier Foundation, https://www.eff.org/https-everywhere.

29 See Press Release, Mobile Marketing Association, Mobile Marketing Association Releases Final Privacy Policy Guidelines for

Mobile Apps (Jan. 25, 2012), available at http://mmaglobal.com/news/mobile-marketing-association -releases-final-privacypolicy-guidelines-mobile-apps.

30 See Comment of TRUSTe, cmt. #00450, at 3; Comment of Berlin Commissioner for Data Protection & Freedom of Information,

cmt. #00484, at 1.

31 See Comment of Patient Privacy Rights, cmt. #00470, at 2.

32 See Comment of Technology Policy Institute, cmt. #00301, at 5-8; Comment of Experian, cmt. #00398, at 9-11; Comment of

Global Privacy Alliance, cmt. #00367, at 6-7.

33 See Comment of Facebook, Inc., cmt. #00413, at 1-2, 7-8; Comment of Google, Inc., cmt. #00417, at 4; Comment of Global

Privacy Alliance, cmt. #00367, at 16.

7

The Commission agrees that the range of privacy-related harms is more expansive than economic or

physical harm or unwarranted intrusions and that any privacy framework should recognize additional harms

that might arise from unanticipated uses of data. These harms may include the unexpected revelation

of previously private information, including both sensitive information (e.g., health information, precise

geolocation information) and less sensitive information (e.g., purchase history, employment history) to

unauthorized third parties.34 As one example, in the Commission’s case against Google, the complaint

alleged that Google used the information of consumers who signed up for Gmail to populate a new social

network, Google Buzz.35 The creation of that social network in some cases revealed previously private

information about Gmail users’ most frequent email contacts. Similarly, the Commission’s complaint against

Facebook alleged that Facebook’s sharing of users’ personal information beyond their privacy settings was

harmful.36 Like these enforcement actions, a privacy framework should address practices that unexpectedly

reveal previously private information even absent physical or financial harm, or unwarranted intrusions.37

In terms of weighing costs and benefits, although it recognizes that imposing new privacy protections

will not be costless, the Commission believes doing so not only will help consumers but also will benefit

businesses by building consumer trust in the marketplace. Businesses frequently acknowledge the

importance of consumer trust to the growth of digital commerce38 and surveys support this view. For

34 One former FTC Chairman, in analyzing a spyware case, emphasized that consumers should have control over what is on

their computers. Chairman Majoras issued the following statement in connection with the Commission’s settlement against

Sony BMG resolving claims about the company’s installation of invasive tracking software: “Consumers’ computers belong to

them, and companies must adequately disclose unexpected limitations on the customary use of their products so consumers

can make informed decisions regarding whether to purchase and install that content.” Press Release, FTC, Sony BMG

Settles FTC Charges (Jan. 30, 2007), available at http://www.ftc.gov/opa/2007/01/sony.shtm; see also Walt Mossberg, Despite

Others’ Claims, Tracking Cookies Fit My Spyware Definition, AllThingsD (July 14, 2005, 12:01 AM), http://allthingsd.

com/20050714/tracking-cookies/ (“Suppose you bought a TV set that included a component to track what you watched, and

then reported that data back to a company that used or sold it for advertising purposes. Only nobody told you the tracking

technology was there or asked your permission to use it. You would likely be outraged at this violation of privacy. Yet that

kind of Big Brother intrusion goes on everyday on the Internet . . . [with tracking cookies].”).

35 See In re Google Inc., FTC Docket No. C-4336 (Oct. 13, 2011) (consent order), available at http://www.ftc.gov/os/caselist/10

23136/110330googlebuzzcompt.pdf.

36 See In re Facebook, Inc., FTC File No. 092 3184 (Nov. 29, 2011) (proposed consent order), available at http://www.ftc.gov/os/

caselist/0923184/111129facebookagree.pdf.

37 Although the complaint against Google alleged that the company used deceptive tactics and violated its own privacy promises

when it launched Google Buzz, even in the absence of such misrepresentations, revealing previously-private consumer data

could cause consumer harm. See Press Release, FTC, FTC Charges Deceptive Privacy Practices in Google’s Rollout of its Buzz

Social Network (Mar. 30, 2011), available at http://www.ftc.gov/opa/2011/03/google.shtm (noting that in response to the

Buzz launch, Google received thousands of complaints from consumers who were concerned about public disclosure of their

email contacts which included, in some cases, ex-spouses, patients, students, employers, or competitors).

38 See, e.g., Statement of John M. Montgomery, GroupM Interaction, The State of Online Consumer Privacy: Hearing Before

the S. Comm. on Commerce, Sci., and Transp., 112th Cong. (Mar. 16, 2011), available at http://www.iab.net/media/file/

DC1DOCS1-432016-v1-John_Montgomery_-_Written_Testimony.pdf (“We at GroupM strongly believe in protecting

consumer privacy. It is not only the right thing to do, but it is also good for business.”); Statement of Alan Davidson,

Director of Public Policy, Google Inc., Protecting Mobile Privacy: Your Smartphones, Tablets, Cell Phones and Your Privacy:

Hearing Before the S. Subcomm. on Privacy, Tech., and the Law, 112th Cong. (May 10, 2011), available at http://www.

judiciary.senate.gov/pdf/11-5-10%20Davidson%20Testimony.pdf (“Protecting privacy and security is essential for Internet

commerce.”).

8

example, in the online behavioral advertising area, a recent survey shows that consumers feel better about

brands that give them transparency and control over advertisements.39

Companies offering consumers information about behavioral advertising and the tools to opt out of

it have also found increased customer engagement. In its comment, Google noted that visitors to its Ads

Preference Manager are far more likely to edit their interest settings and remain opted in rather than to

opt out.40 Similarly, another commenter conducted a study showing that making its customers aware of

its privacy and data security principles – including restricting the sharing of customer data, increasing

the transparency of data practices, and providing access to the consumer data it maintains – significantly

increased customer trust in its company.41

In addition, some companies appear to be competing on privacy. For example, one company offers

an Internet search service that it promotes as being far more privacy-sensitive than other search engines.42

Similarly, in response to Google’s decision to change its privacy policies to allow tracking of consumers across

different Google products, Microsoft encouraged consumers to switch to Microsoft’s more privacy-protective

products and services.43

The privacy framework is designed to be flexible to permit and encourage innovation. Companies can

implement the privacy protections of the framework in a way that is proportional to the nature, sensitivity,

and amount of data collected as well as to the size of the business at issue. For example, the framework does

not include rigid provisions such as specific disclosures or mandatory data retention and destruction periods.

And, as discussed below, the framework streamlines communications for businesses and consumers alike by

requiring consumer choice mechanisms only for data practices that are inconsistent with the context of a

particular transaction or the business relationship with the consumer.44

B. GLOBAL INTEROPERABILITY

Reflecting differing legal, policy, and constitutional regimes, privacy frameworks around the world vary

considerably. Many commenters cited the value to both consumers and businesses of promoting more

consistent and interoperable approaches to protecting consumer privacy internationally. These commenters

stated that consistency between different privacy regimes reduces companies’ costs, promotes international

competitiveness, and increases compliance with privacy standards.45

39 See RESEARCH: Consumers Feel Better About Brands That Give Them Transparency and Control Over Ads, Evidon Blog (Nov.

10, 2010), http://blog.evidon.com/tag/better-advertising (“when advertisers empower consumers with information and

control over the ads they receive, a majority feels more positive toward those brands, and 36% even become more likely to

purchase from those brands”).

40 See Comment of Google Inc., cmt. #00417, at 4.

41 See Comment of Intuit, Inc., cmt. #00348, at 6-8 (“The more transparent (meaning open, simple and clear) the company is,

the more customer trust increases. . . .”).

42 See DuckDuckGo, Privacy Policy, https://duckduckgo.com/privacy.html.

43 See Frank X. Shaw, Gone Google? Got Concerns? We Have Alternatives, The Official Microsoft Blog (Feb. 1, 2012, 2:00

AM), http://blogs.technet.com/b/microsoft_blog/archive/2012/02/01/gone-google-got-concerns-we-have-alternatives.aspx.

44 See infra at Section IV.C.1.a.

45 See Comment of AT&T Inc., cmt. #00420, at 12-13; Comment of IBM, cmt. #00433, at 2; see also Comment of General Electric,

cmt. #00392, at 3 (encouraging international harmonization).

9

The Commission agrees there is value in greater interoperability among data privacy regimes as

consumer data is increasingly transferred around the world. Meaningful protection for such data requires

convergence on core principles, an ability of legal regimes to work together, and enhanced cross-border

enforcement cooperation. Such interoperability is better for consumers, whose data will be subject to

more consistent protection wherever it travels, and more efficient for businesses by reducing the burdens of

compliance with differing, and sometimes conflicting, rules. In short, as the Administration White Paper

notes, global interoperability “will provide more consistent protections for consumers and lower compliance

burdens for companies.”46

Efforts underway around the world to re-examine current approaches to protecting consumer privacy

indicate an interest in convergence on overarching principles and a desire to develop greater interoperability.

For example, the Commission’s privacy framework is consistent with the nine privacy principles set forth in

the 2004 Asia-Pacific Economic Cooperation (“APEC”) Privacy Framework. Those principles form the basis

for ongoing APEC work to implement a cross-border privacy rules system to facilitate data transfers among

the 21 APEC member economies, including the United States.47 In 2011, the Organization for Economic

Cooperation and Development (“OECD”) issued a report re-examining its seminal 1980 Privacy Guidelines

in light of technological changes over the past thirty years.48 Further, the European Commission has recently

proposed legislation updating its 1995 data protection directive and proposed an overhaul of the European

Union approach that focuses on many of the issues raised elsewhere in this report as well as issues relating

to international transfers and interoperability.49 These efforts reflect a commitment to many of the highlevel principles embodied in the FTC’s framework – increased transparency and consumer control, the need

for privacy protections to be built into basic business practices, and the importance of accountability and

enforcement. They also reflect a shared international interest in having systems that work better with each

other, and are thus better for consumers.

46 White House, Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation in

the Global Digital Economy, ii, Foreword (Feb. 2012), available at http://www.whitehouse.gov/sites/default/files/privacy-final.

pdf.

47 The nine principles in the APEC Privacy Framework are preventing harm, notice, collection limitations, uses of personal

information, choice, integrity of personal information, security safeguards, access and correction, accountability. Businesses

have developed a code of conduct based on these nine principles and will obtain third-party certification of their compliance.

A network of privacy enforcement authorities from participating APEC economies, such as the FTC, will be able to take

enforcement actions against companies that violate their commitments under the code of conduct. See Press Release,

FTC, FTC Welcomes a New Privacy System for the Movement of Consumer Data Between the United States and Other

Economies in the Asia-Pacific Region (Nov. 14, 2011), available at http://www.ftc.gov/opa/2011/11/apec.shtm).

48 See Organization for Economic Co-operation and Development, The Evolving Privacy Landscape: 30 Years after the OECD

Privacy Guidelines (Apr. 2011), available at http://www.oecd.org/dataoecd/22/25/47683378.pdf.

49 European Commission, Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General

Data Protection Regulation) (Jan. 25, 2012), available at http://ec.europa.eu/justice/data-protection/document/review2012/

com_2012_11_en.pdf.

10

C. LEGISLATION TO AUGMENT SELF-REGULATORY EFFORTS

Numerous comments, including those from large industry stakeholders, consumer and privacy

advocates, and individual consumers supported some form of baseline privacy legislation that incorporates

the FIPPs.50 Business commenters noted that legislation would help provide legal certainty,51 serve as a key

mechanism for building trust among customers,52 and provide a way to fill gaps in existing sector-based

laws.53 Consumer and privacy advocates cited the inability of self-regulation to provide comprehensive

and long-lasting protection for consumers.54 One such commenter cited the fact that many self-regulatory

initiatives that arose in response to the Commission’s 2000 recommendation for privacy legislation were

short-lived and failed to provide long-term privacy protections for consumers.55

At the same time, a number of commenters raised concerns about government action beyond providing

guidance for self-regulatory programs.56 Some cautioned the FTC about taking an approach that might

impede industry’s ability to innovate and develop new products and services in a rapidly changing

marketplace. Others noted that a regulatory approach could lead to picking “winners and losers” among

particular technologies and business models and called for a technology-neutral approach.57 Commenters

also argued that it might be impractical to craft omnibus standards or rules that would apply broadly across

different business sectors.58

The Commission agrees that, to date, self-regulation has not gone far enough. In most areas, with the

notable exception of efforts surrounding Do Not Track, there has been little self-regulation. For example,

the FTC’s recent survey of mobile apps marketed to children revealed that many of these apps fail to provide

any disclosure about the extent to which they collect and share consumers’ personal data.59 Similarly, efforts

50 See, e.g., Comment of eBay, cmt. #00374, at 2; Comment of Intel Corp., cmt. #00246, at 3-7; Comment of Microsoft Corp., cmt.

#00395, at 4; Comment of Intuit, Inc., cmt. #00348, at 13-14; Comment of Center for Democracy & Technology, cmt. #00469,

at 1, 7; Comment of Gregory Byrd, cmt. #00144, at 1; Comment of Ellen Klinefelter, cmt. #00095, at 1.

51 See Comment of Microsoft Corp., cmt. #00395, at 4.

52 See Comment of Intel Corp., cmt. #00246, at 3.

53 See Comment of Intuit, Inc., cmt. #00348, at 13.

54 See Comment of Electronic Privacy Information Center, cmt. #00386, at 2; Comment of World Privacy Forum, cmt. #00376, at

2-3, 8-17.

55 See Comment of World Privacy Forum, cmt. #00376, at 2-3, 8-17.

56 See Comment of Consumer Data Industry Ass’n, cmt. #00363, at 4-5; Comment of American Catalog Mailers Ass’n, cmt. #00424,

at 3; Comment of Facebook, Inc., cmt. #00413, at 13-14; Comment of Google Inc., cmt. #00417, at 8; Comment of Verizon,

cmt. #00428, at 2-3, 6-7, 14-17; Comment of Mortgage Bankers Ass’n, cmt. #00308, at 2; Comment of National Cable &

Telecommunications Ass’n, cmt. #00432, at 3, 5, 7-13; Comment of CTIA – The Wireless Ass’n, cmt. #00375, at 15.

57 See Comment of National Cable & Telecommunications Ass’n, cmt. #00432, at 32-37; Comment of USTelecom, cmt. #00411, at

5-7; Comment of Verizon, cmt. #00428, at 4-6; Comment of Direct Marketing Ass’n, Inc., cmt. #00449, at 5-6.

58 See Comment of Consumer Data Industry Ass’n, cmt. #00363, at 4-6; see also Comment of CTIA - The Wireless Ass’n, cmt.

#00375, at 8-11; Comment of Direct Marketing Ass’n, Inc., cmt. #00449, at 13.

59 FTC Staff, Mobile Apps for Kids: Current Privacy Disclosures are Disappointing (Feb. 2012), available at http://www.ftc.gov/

os/2012/02/120216mobile_apps_kids.pdf; FPF Finds Nearly Three-Quarters of Most Downloaded Mobile Apps Lack a Privacy

Policy, Future of Privacy Forum, http://www.futureofprivacy.org/2011/05/12/fpf-finds-nearly-three-quarters-of-mostdownloaded-mobile-apps-lack-a-privacy-policy/.

11

of the data broker industry to establish self-regulatory rules concerning consumer privacy have fallen short.60

These examples illustrate that even in some well-established markets, basic privacy concepts like transparency

about the nature of companies’ data practices and meaningful consumer control are absent. This absence

erodes consumer trust.

There is also widespread evidence of data breaches and vulnerabilities related to consumer information.61

Published reports indicate that some breaches may have resulted from the unintentional release of consumer

data, for which companies later apologized and took action to address.62 Other incidents involved planned

releases or uses of data by companies that ultimately did not occur due to consumer and public backlash.63

Still other incidents involved companies’ failure to take reasonable precautions and resulted in FTC consent

decrees. These incidents further undermine consumer trust, which is essential for business growth and

innovation.64

The ongoing and widespread incidents of unauthorized or improper use and sharing of personal

information are evidence of two points. First, companies that do not intend to undermine consumer

privacy simply lack sufficiently clear standards to operate and innovate while respecting the expectations of

consumers. Second, companies that do seek to cut corners on consumer privacy do not have adequate legal

incentives to curtail such behavior.

To provide clear standards and appropriate incentives to ensure basic privacy protections across all

industry sectors, in addition to reiterating its call for federal data security legislation,65 the Commission calls

60 See Comment of Center for Democracy & Technology, cmt. #00469, at 2-3; Comment of World Privacy Forum, cmt. #00376, at

2-3. Discussed more fully infra at Section IV.D.2.a.

61 See Grant Gross, Lawmakers Question Sony, Epsilon on Data Breaches, PC World (June 2, 2011 3:40 PM), available at http://

www.pcworld.com/businesscenter/article/229258/lawmakers_question_sony_epsilon_on_data_breaches.html; Dwight

Silverman, App Privacy: Who’s Uploading Your Contact List?, Houston Chronicle (Feb. 15, 2012 8:10 AM), http://blog.

chron.com/techblog/2012/02/app-privacy-whos-uploading-your-contact-list/; Dan Graziano, Like iOS apps, Android Apps

Can Secretly Access Photos Thanks to Loophole, BGR (Mar. 1, 2012 3:45 PM), http://www.bgr.com/2012/03/01/like-ios-appsandroid-apps-can-also-secretly-access-photos-thanks-to-security-hole/.

62 CEO Apologizes After Path Social App Uploads Contact Lists, KMOV.com (Feb. 9, 2012 11:11AM), http://www.kmov.com/

news/consumer/CEO-apologizes-after-Path-uploads-contact-lists--139015729.html; Daisuke Wakabayashi, A Contrite Sony

Vows Tighter Security, Wall St. J. May 1, 2011, available at http://online.wsj.com/article/SB10001424052748704436004576

296302384608280.html.

63 Kevin Parrish, OnStar Changes its Mind About Tracking Vehicles, Tom’s Guide (Sept. 29, 2011 7:30 AM), http://www.

tomsguide.com/us/OnStar-General-motors-Linda-Marshall-GPS-Terms-and-conditions,news-12677.html.

64 Surveys of consumer attitudes towards privacy conducted in the past year are illuminating. For example, a USA Today/Gallup

poll indicated that a majority of the Facebook members or Google users surveyed were “very” or “somewhat concerned”

about their privacy while using these services. Lymari Morales, Google and Facebook Users Skew Young, Affluent, and Educated,

Gallup (Feb. 17, 2011), available at http://www.gallup.com/poll/146159/facebook-google-users-skew-young-affluenteducated.aspx.

65 The Commission has long supported federal laws requiring companies to implement reasonable security measures and to

notify consumers in the event of certain security breaches. See, e.g., Prepared Statement of the FTC, Data Security: Hearing

Before the H. Comm. on Energy and Commerce, Subcomm. on Commerce, Manufacturing, and Trade, 112th Cong. (June

15, 2011), available at http://www.ftc.gov/os/testimony/110615datasecurityhouse.pdf; Prepared Statement of the FTC,

Protecting Social Security Numbers From Identity Theft: Hearing Before the Before the H. Comm. on Ways and Means, Subcomm.

on Social Security, 112th Cong. (April 13, 2011), available at http://www.ftc.gov/os/testimony/110411ssn-idtheft.pdf; FTC,

Security in Numbers, SSNs and ID Theft (Dec. 2008), available at http://www.ftc.gov/os/2008/12/P075414ssnreport.pdf;

President’s Identity Theft Task Force, Identity Theft Task Force Report (Sept. 2008), available at http://www.idtheft.gov/reports/

IDTReport2008.pdf.

12

on Congress to consider enacting baseline privacy legislation that is technologically neutral and sufficiently

flexible to allow companies to continue to innovate. The Commission is prepared to work with Congress

and other stakeholders to craft such legislation.

In their comments, many businesses indicated that they already incorporate the FIPPS into their

practices. For these companies, a legislative mandate should not impose an undue burden and indeed, will

“level the playing field” by ensuring that all companies are required to incorporate these principles into their

practices.

For those companies that are not already taking consumer privacy into account – either because of

lack of understanding or lack of concern – legislation should provide clear rules of the road. It should

also provide adequate deterrence through the availability of civil penalties and other remedies.66 In short,

legislation will provide businesses with the certainty they need to understand their obligations and the

incentive to meet those obligations, while providing consumers with confidence that businesses will be

required to respect their privacy. This approach will create an environment that allows businesses to

continue to innovate and consumers to embrace those innovations without sacrificing their privacy.67 The

Commission is prepared to work with Congress and other stakeholders to formulate baseline privacy

legislation.

While Congress considers such legislation, the Commission urges industry to accelerate the pace of its

self-regulatory measures to implement the Commission’s final privacy framework. Over the course of the

next year, Commission staff will promote the framework’s implementation by focusing its policymaking

efforts on five main action items, which are highlighted here and discussed further throughout the report.

xx Do Not Track: As discussed above, industry has made significant progress in implementing Do Not

Track. The browser vendors have developed tools that consumers can use to signal that they do not

want to be tracked; the DAA has developed its own icon-based tool and has committed to honor the

browser tools; and the W3C has made substantial progress in creating an international standard for

Do Not Track. However, the work is not done. The Commission will work with these groups to

complete implementation of an easy-to use, persistent, and effective Do Not Track system.

xx Mobile: The Commission calls on companies providing mobile services to work toward improved

privacy protections, including the development of short, meaningful disclosures. To this end, FTC

staff has initiated a project to update its business guidance about online advertising disclosures.68

As part of this project, staff will host a workshop on May 30, 2012 and will address, among other

issues, mobile privacy disclosures and how these disclosures can be short, effective, and accessible to

66 Former FTC Chairman Casper “Cap” Weinberger recognized the value of civil penalties as a deterrent to unlawful conduct.

See Hearings on H.R. 14931 and Related Bills before the Subcomm. on Commerce and Finance of the H. Comm. on Interstate

and Foreign Commerce, 91st Cong. 53, 54 (1970) (statement of FTC Chairman Caspar Weinberger); Hearings on S. 2246,

S. 3092, and S. 3201 Before the Consumer Subcomm. of the S. Comm. on Commerce, 91st Cong. 9 (1970) (Letter from FTC

Chairman Caspar W. Weinberger) (forwarding copy of House testimony).

67 With this report, the Commission is not seeking to impose civil penalties for privacy violations under the FTC Act. Rather,

in the event Congress enacts privacy legislation, the Commission believes that such legislation would be more effective if the

FTC were authorized to obtain civil penalties for violations.

68 See Press Release, FTC, FTC Seeks Input to Revising its Guidance to Businesses About Disclosures in Online Advertising

(May 26, 2011), available at http://www.ftc.gov/opa/2011/05/dotcom.shtm.

13

consumers on small screens. The Commission hopes that the workshop will spur further industry

self-regulation in this area.

xx Data Brokers: To address the invisibility of, and consumers’ lack of control over, data brokers’

collection and use of consumer information, the Commission supports targeted legislation – similar

to that contained in several of the data security bills introduced in the 112th Congress – that would

provide consumers with access to information about them held by a data broker.69 To further

increase transparency, the Commission calls on data brokers that compile data for marketing

purposes to explore creating a centralized website where data brokers could (1) identify themselves to

consumers and describe how they collect and use consumer data and (2) detail the access rights and

other choices they provide with respect to the consumer data they maintain.

xx Large Platform Providers: To the extent that large platforms, such as Internet Service Providers

(“ISPs”), operating systems, browsers, and social media, seek to comprehensively track consumers’

online activities, it raises heightened privacy concerns. To further explore privacy and other issues

related to this type of comprehensive tracking, FTC staff intends to host a public workshop in the

second half of 2012.

xx Promoting enforceable self-regulatory codes: The Department of Commerce, with the support

of key industry stakeholders, is undertaking a project to facilitate the development of sector-specific

codes of conduct. FTC staff will participate in that project. To the extent that strong privacy codes

are developed, the Commission will view adherence to such codes favorably in connection with its

law enforcement work. The Commission will also continue to enforce the FTC Act to take action

against companies that engage in unfair or deceptive practices, including the failure to abide by selfregulatory programs they join.

69 See Data Accountability and Trust Act, H.R. 1707, 112th Congress (2011); Data Accountability and Trust Act of 2011, H.R.

1841, 112th Congress (2011); Data Security and Breach Notification Act of 2011, S. 1207, 112th Congress (2011).

14

IV. PRIVACY FRAMEWORK

In addition to the general comments described above, the Commission received significant comments

on the scope of the proposed framework and each individual element. Those comments, as well as several

clarifications and refinements based on the Commission’s analysis of the issues raised, are discussed below.

A. SCOPE

Proposed Scope: The framework applies to all commercial entities that collect or use consumer data

that can be reasonably linked to a specific consumer, computer, or other device.

A variety of commenters addressed the framework’s proposed scope. Some of these commenters

supported an expansive reach while others proposed limiting the framework’s application to particular types

of entities and carving out certain categories of businesses. Commenters also called for further clarification

regarding the type of data the framework covers and staff’s proposed “reasonably linked” standard.

1. COMPANIES SHOULD COMPLY WITH THE FRAMEWORK UNLESS THEY HANDLE ONLY

LIMITED AMOUNTS OF NON-SENSITIVE DATA THAT IS NOT SHARED WITH THIRD PARTIES.

Numerous commenters addressed whether the framework should apply to entities that collect, maintain,

or use limited amounts of data. Several companies argued that the burden the framework could impose on

small businesses outweighed the reduced risk of harm from the collection and use of limited amounts of

non-sensitive consumer data.70 These commenters proposed that the framework not apply to entities that

collect or use non-sensitive data from fewer than 5,000 individuals a year where the data is used for limited

purposes, such as internal operations and first-party marketing.71 As additional support for this position,

these commenters noted that proposed privacy legislation introduced in the 111th Congress contained an

exclusion to this effect.72

Although one consumer and privacy organization supported a similar exclusion,73 others expressed

concern about exempting, per se, any types of businesses or quantities of data from the framework’s scope.74

These commenters pointed to the possibility that excluded companies would sell the data to third parties,

such as advertising networks or data brokers.

The Commission agrees that the first-party collection and use of non-sensitive data (e.g., data that is not

a Social Security number or financial, health, children’s, or geolocation information) creates fewer privacy

70 See Comment of eBay, Inc., cmt. #00374, at 3; Comment of Microsoft Corp., cmt. #00395, at 4.

71 Id.

72 See BEST PRACTICES ACT, H.R. 5777, 111th Congress (2010); Staff Discussion Draft, H.R. __ , 111th Congress (2010),

available at http://www.nciss.org/legislation/BoucherStearnsprivacydiscussiondraft.pdf.

73 Comment of the Center for Democracy & Technology, cmt. #00469, at 1.

74 See Comment of the Electronic Frontier Foundation, cmt. #00400, at 1; Comment of the Consumer Federation of America, cmt.

#00358, at 2.

15

concerns than practices that involve sensitive data or sharing with third parties.75 Accordingly, entities that

collect limited amounts of non-sensitive consumer data from under 5,000 consumers need not comply with

the framework, as long as they do not share the data with third parties. For example, consider a cash-only

curb-side food truck business that offers to send messages announcing when it is in a given neighborhood

to consumers who provide their email addresses. As long as the food truck business does not share these

email addresses with third parties, the Commission believes that it need not provide privacy disclosures to

its customers. This narrow exclusion acknowledges the need for flexibility for businesses that collect limited

amounts of non-sensitive information. It also recognizes that some business practices create fewer potential

risks to consumer information.

2. THE FRAMEWORK SETS FORTH BEST PRACTICES AND CAN WORK IN TANDEM WITH

EXISTING PRIVACY AND SECURITY STATUTES.

The proposed framework’s applicability to commercial sectors that are covered by existing laws

generated comments primarily from representatives of the healthcare and financial services industries. These

commenters noted that statutes such as the Health Insurance Portability and Accountability Act (“HIPAA”),

the Health Information Technology for Economic and Clinical Health Act (“HITECH”), and the GrammLeach-Bliley Act (“GLBA”) already impose privacy protections and security requirements through legal

obligations on companies in these industries.76 Accordingly, these commenters urged the Commission to

avoid creating duplicative or inconsistent standards and to clarify that the proposed framework is intended

to cover only those entities that are not currently covered by existing privacy and security laws. Another

commenter, however, urged government to focus on fulfilling consumer privacy expectations across all

sectors, noting that market evolution is blurring distinctions about who is covered by HIPAA and that

consumers expect organizations to protect their personal health information, regardless of any sector-specific

boundaries.77

The Commission recognizes the concern regarding potentially inconsistent privacy obligations and

notes that, to the extent Congress enacts any of the Commission’s recommendations through legislation,

such legislation should not impose overlapping or duplicative requirements on conduct that is already

regulated.78 However, the framework is meant to encourage best practices and is not intended to conflict

with requirements of existing laws and regulations. To the extent that components of the framework exceed,

but do not conflict with existing statutory requirements, entities covered by those statutes should view the

framework as best practices to promote consumer privacy. For example, it may be appropriate for financial

institutions covered by GLBA to incorporate elements of privacy by design, such as collection limitations, or

75 See infra at Sections IV.C.1.b.(v) and IV.C.2.e.(ii), for a discussion of what constitutes sensitive data.

76 See Comment of the Confidentiality Coalition c/o the Healthcare Leadership Council, cmt. #00349, at 1-4; Comment of Experian,

cmt. #00398, at 8-10; Comment of IMS Health, cmt. #00380, at 2-3; Comment of Medco Health Solutions, Inc., cmt. #00393,

at 3; Comment of SIFMA, cmt. #00265, at 2-3.

77 Comment of The Markle Foundation, cmt. #00456, at 3-10.

78 Any baseline privacy law Congress may enact would likely consider the best way to take into account obligations under

existing statutes.

16

to improve transparency by providing reasonable access to consumer data in a manner that does not conflict

with their statutory obligations. In any event, the framework provides an important baseline for entities that

are not subject to sector-specific laws like HIPAA or GLBA.79

3. THE FRAMEWORK APPLIES TO OFFLINE AS WELL AS ONLINE DATA.

In addressing the framework’s applicability to “all commercial entities,” numerous commenters discussed

whether the framework should apply to both online and offline data. Diverse commenters expressed strong

support for a comprehensive approach applicable to both online and offline data practices.80 Commenters

noted that as a practical matter, many companies collect both online and offline data.81

Commenters also listed different offline contexts in which entities collect consumer data. These include

instances where a consumer interacts directly with a business, such as through the use of a retail loyalty card,

or where a non-consumer facing entity, such as a data broker, obtains consumer data from an offline thirdparty source.82 One commenter noted that, regardless of whether an entity collects or uses data from an

online or an offline source, consumer privacy interests are equally affected.83 To emphasize the importance

of offline data protections, this commenter noted that while the behavioral advertising industry has started

to implement self-regulatory measures to improve consumers’ ability to control the collection and the use of

their online data, in the offline context such efforts by data brokers and others have largely failed.84

By contrast, a financial industry organization argued that the FTC should take a more narrow approach

by limiting the scope of the proposed framework in a number of respects, including its applicability to

offline data collection and use.85 This commenter stated that some harms in the online context may not exist

offline and raised concern about the framework’s unintended consequences. For example, the commenter

cited the significant costs that a requirement to provide consumers with access to data collected about them

79 There may be entities that operate within covered sectors but that nevertheless fall outside of a specific law’s scope. For

instance, a number of entities that collect health information are not subject to HIPAA. These entities include providers

of personal health records – online portfolios that consumers can use to store and keep track of their medical information.

In 2009, Congress passed the HITECH Act, which required HHS, in consultation with the FTC, to develop legislative

recommendations on privacy and security requirements that should apply to these providers of personal health records and

related entities. Health Information Technology (“HITECH”) Provisions of American Recovery and Reinvestment Act of

2009, Title XIII, Subtitle D (Pub. L. 111-5, 123 Stat. 115, codified in relevant part at 42 U.S.C. §§ 17937 and 17954).

FTC staff is consulting with HHS on this project.

80 See Comment of the Center for Democracy & Technology, cmt. #00469, at 2; Comment of the Computer & Communications

Industry Ass’n, cmt. #00434, at 14; Comment of Consumers Union, cmt. #00362, at 4-5; Comment of the Department of Veterans

Affairs, cmt. #00479, at 3; Comment of Experian, cmt. #00398, at 1; Comment of Google Inc., cmt. #00417, at 7; Comment of

Microsoft Corp., cmt. #00395, at 4.

81 See Comment of the Department of Veterans Affairs, cmt. #00479, at 3 n.7; Comment of the Computer & Communications

Industry Ass’n, cmt. #00434, at 14; Comment of Consumers Union, cmt. #00362, at 1.

82 See Comment of the Department of Veterans Affairs, cmt. #00479, at 3 n.7; Comment of the Computer & Communications

Industry Ass’n, cmt. #00434, at 14.

83 Comment of Center for Democracy & Technology, cmt. #00469, at 2.

84 Comment of Center for Democracy & Technology, cmt. #00469, at 2-3.

85 Comment of the Financial Services Forum, cmt. #00381, at 8-9.

17

would impose on companies that collect and maintain data in paper rather than electronic form. Another

commenter cited the costs of providing privacy disclosures and choices in an offline environment.86

The Commission notes that consumers face a landscape of virtually ubiquitous collection of their data.

Whether such collection occurs online or offline does not alter the consumer’s privacy interest in his or her

data. For example, the sale of a consumer profile containing the consumer’s purchase history from a brickand-mortar pharmacy or a bookstore would not implicate fewer privacy concerns simply because the profile

contains purchases from an offline retailer rather than from an online merchant. Accordingly, the framework

applies in all commercial contexts, both online and offline.

4. THE FRAMEWORK APPLIES TO DATA THAT IS REASONABLY LINKABLE TO A SPECIFIC

CONSUMER, COMPUTER, OR DEVICE.

The scope issue that generated the most comments, from a wide range of interested parties, was the

proposed framework’s applicability to “consumer data that can be reasonably linked to a specific consumer,

computer, or other device.”

A number of commenters supported the proposed framework’s application to data that, while not

traditionally considered personally identifiable, is linkable to a consumer or device. In particular, several

consumer and privacy groups elaborated on the privacy concerns associated with supposedly anonymous

data and discussed the decreasing relevance of the personally identifiable information (“PII”) label.87 These

commenters pointed to studies demonstrating consumers’ objections to being tracked, regardless of whether

the tracker explicitly learns a consumer name, and the potential for harm, such as discriminatory pricing

based on online browsing history, even without the use of PII.88

Similarly, the commenters noted, the ability to re-identify “anonymous” data supports the proposed

framework’s application to data that can be reasonably linked to a consumer or device. They pointed to

incidents, identified in the preliminary staff report, in which individuals were re-identified from publicly

released data sets that did not contain PII.89 One commenter pointed out that certain industries extensively

86 Comment of National Retail Federation, cmt. #00419, at 6 (urging FTC to limit privacy framework to online collection of

consumer data because applying it to offline collection would be onerous for businesses and consumers).

87 See Comment of the Center for Democracy & Technology, cmt. #00469, at 3; Comment of Consumers Union, cmt. #00362, at 4-5.

In addition, in their comments both AT&T and Mozilla recognized that the distinction between PII and non-PII is blurring.

Comment of AT&T Inc., cmt. #00420, at 13; Comment of Mozilla, cmt. #00480, at 6.

88 Comment of Center for Democracy & Technology, cmt. #00469, at 3 (citing Edward C. Baig, Internet Users Say, Don’t Track

Me, USA TODAY, Dec. 14, 2010, available at http://www.usatoday.com/money/advertising/2010-12-14-donottrackpoll14_

ST_N.htm); Scott Cleland, Americans Want Online Privacy – Per New Zogby Poll, The Precursor Blog (June 8, 2010),

http://www.precursorblog.com/content/americans-want-online-privacy-new-zogby-poll); Comment of Consumers Union,

cmt. #00362, at 4 (discussing the potential for discriminatory pricing (citing Annie Lowery, How Online Retailers Stay a Step

Ahead of Comparison Shoppers, Wash. Post, Dec. 12, 2010, available at http://www.washingtonpost.com/wp-dyn/content/

article/2010/12/11/AR2010121102435.html)).

89 For a brief discussion of such incidents, see FTC, Protecting Consumer Privacy in an Era of Rapid Change, A Proposed

Framework for Businesses and Policymakers, Preliminary FTC Staff Report, at 38 (Dec. 2010), available at http://www.ftc.gov/

os/2010/12/101201privacyreport.pdf.

18

mine data for marketing purposes and that re-identification is a commercial enterprise.90 This adds to the

likelihood of data re-identification.

Some industry commenters also recognized consumers’ privacy interest in data that goes beyond what

is strictly labeled PII.91 Drawing on the FTC’s roundtables as well as the preliminary staff report, one such

commenter noted the legitimate interest consumers have in controlling how companies collect and use

aggregated or de-identified data, browser fingerprints,92 and other types of non-PII.93 Another company

questioned the notion of distinguishing between PII and non-PII as a way to determine what data to

protect.94 Supporting a scaled approach rather than a bright line distinction, this commenter noted that all

data derived from individuals deserves some level of protection.95

Other commenters representing industry opposed the proposed framework’s application to non-PII

that can be reasonably linked to a consumer, computer, or device.96 These commenters asserted that the

risks associated with the collection and use of data that does not contain PII are simply not the same as the

risks associated with PII. They also claimed a lack of evidence demonstrating that consumers have the same

privacy interest in non-PII as they do with the collection and use of PII. Instead of applying the framework

to non-PII, these commenters recommended the Commission support efforts to de-identify data.

Overall, the comments reflect a general acknowledgment that the traditional distinction between PII and

non-PII has blurred and that it is appropriate to more comprehensively examine data to determine the data’s

privacy implications.97 However, some commenters, including some of those cited above, argued that the

proposed framework’s “linkability” standard is potentially too open-ended to be practical.98 One industry

organization asserted, for instance, that if given enough time and resources, any data may be linkable to an

90 Comment of Electronic Frontier Foundation, cmt. #00400, at 4 (citing Julia Angwin & Steve Stecklow, ‘Scrapers’ Dig Deep for

Data on Web, Wall St. J., Oct. 12, 2010, available at http://online.wsj.com/article/SB100014240527487033585045755443

81288117888.html); Sorrell v. IMS Health Inc., 131 S. Ct. 2653 (2011).

91 Comment of Mozilla, cmt. #00480, at 4-5; Comment of Google Inc., cmt. #00417, at 8.

92 The term “browser fingerprints” refers to the specific combination of characteristics – such as system fonts, software, and

installed plugins – that are typically made available by a consumer’s browser to any website visited. These characteristics can

be used to uniquely identify computers, cell phones, or other devices. Browser fingerprinting does not rely on cookies. See

Erik Larkin, Browser Fingerprinting Can ID You Without Cookies, PCWorld, Jan. 29, 2010, available at http://www.pcworld.

com/article/188161/browser_fingerprinting_can_id_you_without_cookies.html.

93 Comment of Mozilla, cmt. #00480, at 4-5 (citing FTC, Protecting Consumer Privacy in an Era of Rapid Change: A Proposed

Framework for Businesses and Policymakers, Preliminary FTC Staff Report, at 36-37 (Dec. 2010), available at http://www.ftc.

gov/os/2010/12/101201privacyreport.pdf ).

94 Comment of Google Inc., cmt. #00417, at 8.

95 Comment of Google Inc., cmt. #00417, at 8.

96 Comment of Direct Marketing Ass’n, Inc., cmt. #00449, at 13-14; Comment of National Cable & Telecommunications Ass’n, cmt.

#00432, at 13-17.

97 See Comment of AT&T Inc., cmt. #00420, at 13-15; Comment of Center for Democracy & Technology (Feb. 18, 2011), cmt.

#00469, at 3-4; Comment of CTIA - The Wireless Ass’n, cmt. #00375, at 3-4; Comment of Consumers Union, cmt. #00362, at

4-5; Comment of Electronic Frontier Foundation, cmt. #00400, at 1-4; Comment of Google Inc., cmt. #00417, at 7-8; Comment

of Mozilla, cmt. #00480, at 4-6; Comment of Phorm Inc., cmt. #00353, at 3-4.

98 Comment of AT&T Inc., cmt. #00420, at 13; Comment of CTIA - The Wireless Ass’n, cmt. #00375 at 3-4; Comment of Google

Inc., cmt. #00417, at 8; Comment of Phorm Inc., cmt. #00353, at 4.

19

individual.99 In addition, commenters stated that requiring the same level of protection for all data would

undermine companies’ incentive to avoid collecting data that is more easily identified or to take steps to

de-identify the data they collect and use.100 Other commenters argued that applying the framework to data

that is potentially linkable could conflict with the framework’s privacy by design concept, as companies

could be forced to collect more information about consumers than they otherwise would in order to be

able to provide those consumers with effective notice, choice, or access.101 To address these concerns,

some commenters proposed limiting the framework to data that is actually linked to a specific consumer,

computer, or device.102

One commenter recommended that the Commission clarify that the reasonably linkable standard means

non-public data that can be linked with reasonable effort.103 This commenter also stated that the framework

should exclude data that, through contract or by virtue of internal controls, will not be linked with a

particular consumer. Taking a similar approach, another commenter suggested that the framework should

apply to data that is reasonably likely to relate to an identifiable consumer.104 This commenter also noted

that a company could commit through its privacy policy that it would only maintain or use data in a deidentified form and that such a commitment would be enforceable under Section 5 of the FTC Act.105

The Commission believes there is sufficient support from commenters representing an array of

perspectives – including consumer and privacy advocates as well as of industry representatives – for the

framework’s application to data that, while not yet linked to a particular consumer, computer, or device,

may reasonably become so. There is significant evidence demonstrating that technological advances and the

ability to combine disparate pieces of data can lead to identification of a consumer, computer, or device even

if the individual pieces of data do not constitute PII.106 Moreover, not only is it possible to re-identify nonPII data through various means,107 businesses have strong incentives to actually do so.

In response to the comments, to provide greater certainty for companies that collect and use consumer

data, the Commission provides additional clarification on the application of the reasonable linkability

standard to describe how companies can take appropriate steps to minimize such linkability. Under the final

99 Comment of GS1, cmt. #00439, at 2.

100 Comment of AT&T Inc., cmt. #00420, at 13-14; Comment of CTIA - The Wireless Ass’n, cmt. #00375, at 4; Comment of

Experian, cmt. #00398, at 11; Comment of National Cable & Telecommunications Ass’n, cmt. #00432, at 16.

101 Comment of United States Council for International Business, cmt. #00366, at 1; Comment of Phorm Inc., cmt. #00353, at 3.

102 Comment of Retail Industry Leaders Ass’n, cmt. #00352, at 4; Comment of Yahoo! Inc., cmt. #00444, at 3-4; Comment of GS1,

cmt. #00439, at 3.

103 Comment of AT&T Inc., cmt. #00420, at 13.

104 Comment of Intel Corp., cmt. #00246, at 9.

105 Comment of Intel Corp., cmt. #00246, at 9.

106 FTC, Protecting Consumer Privacy in an Era of Rapid Change: A Proposed Framework for Businesses and Policymakers,

Preliminary FTC Staff Report, 35-38 (Dec. 2010), available at http://www.ftc.gov/os/2010/12/101201privacyreport.pdf;

Comment of Center for Democracy & Technology, cmt. #00469, at 3; Comment of Statz, Inc., cmt. #00377, at 11-12. See supra

note 89.

107 See FTC, FTC Staff Report: Self-Regulatory Principles for Online Behavioral Advertising, 21-24, 43-45 (Feb. 2009), available at

http://www.ftc.gov/os/2009/02/P0085400behavadreport.pdf; Paul M. Schwartz & Daniel J. Solove, The PII Problem: Privacy

and a New Concept of Personally Identifiable Information, 86 N.Y.U. L. Rev. 1814, 1836-1848 (2011).

20

framework, a company’s data would not be reasonably linkable to a particular consumer or device to the

extent that the company implements three significant protections for that data.

First, the company must take reasonable measures to ensure that the data is de-identified. This means

that the company must achieve a reasonable level of justified confidence that the data cannot reasonably be

used to infer information about, or otherwise be linked to, a particular consumer, computer, or other device.

Consistent with the Commission’s approach in its data security cases,108 what qualifies as a reasonable level

of justified confidence depends upon the particular circumstances, including the available methods and

technologies. In addition, the nature of the data at issue and the purposes for which it will be used are also

relevant. Thus, for example, whether a company publishes data externally affects whether the steps it has

taken to de-identify data are considered reasonable. The standard is not an absolute one; rather, companies

must take reasonable steps to ensure that data is de-identified.

Depending on the circumstances, a variety of technical approaches to de-identification may be

reasonable, such as deletion or modification of data fields, the addition of sufficient “noise” to data,

statistical sampling, or the use of aggregate or synthetic data.109 The Commission encourages companies and

researchers to continue innovating in the development and evaluation of new and better approaches to deidentification. FTC staff will continue to monitor and assess the state of the art in de-identification.

Second, a company must publicly commit to maintain and use the data in a de-identified fashion,

and not to attempt to re-identify the data. Thus, if a company does take steps to re-identify such data, its

conduct could be actionable under Section 5 of the FTC Act.

Third, if a company makes such de-identified data available to other companies – whether service

providers or other third parties – it should contractually prohibit such entities from attempting to re-identify

the data. The company that transfers or otherwise makes the data available should exercise reasonable

oversight to monitor compliance with these contractual provisions and take appropriate steps to address

contractual violations.110

FTC staff’s letter closing its investigation of Netflix, arising from the company’s plan to release

purportedly anonymous consumer data to improve its movie recommendation algorithm, provides a good

illustration of these concepts. In response to the privacy concerns that FTC staff and others raised, Netflix

revised its initial plan to publicly release the data. The company agreed to narrow any such release of data

to certain researchers. The letter details Netflix’s commitment to implement a number of “operational

108 The Commission’s approach in data security cases is a flexible one. Where a company has offered assurances to consumers

that it has implemented reasonable security measures, the Commission assesses the reasonableness based, among other things,

on the sensitivity of the information collected, the measures the company has implemented to protect such information, and

whether the company has taken action to address and prevent well-known and easily addressable security vulnerabilities.

109 See, e.g., Cynthia Dwork, A Firm Foundation for Private Data Analysis, 54 Comm. of the ACM 86-95 (2011), available at

http://research.microsoft.com/pubs/116123/dwork_cacm.pdf, and references cited therein.

110 See In the Matter of Superior Mortg. Corp., FTC Docket No. C-4153 (Dec. 14, 2005), available at, http://www.ftc.gov/os/

caselist/0523136/0523136.shtm (alleging a violation of the GLB Safeguards Rule for, among other things, a failure to ensure

that service providers were providing appropriate security for customer information and addressing known security risks in a

timely manner).

21

safeguards to prevent the data from being used to re-identify consumers.”111 If it chose to share such data

with third parties, Netflix stated that it would limit access “only to researchers who contractually agree to

specific limitations on its use.”112

Accordingly, as long as (1) a given data set is not reasonably identifiable, (2) the company publicly

commits not to re-identify it, and (3) the company requires any downstream users of the data to keep it in

de-identified form, that data will fall outside the scope of the framework.113

This clarification of the framework’s reasonable linkability standard is designed to help address the

concern that the standard is overly broad. Further, the clarification gives companies an incentive to collect

and use data in a form that makes it less likely the data will be linked to a particular consumer or device,

thereby promoting privacy. Additionally, by calling for companies to publicly commit to the steps they take,

the framework promotes accountability.114

Consistent with the discussion above, the Commission restates the framework’s scope as follows.

Final Scope: The framework applies to all commercial entities that collect or use consumer data that

can be reasonably linked to a specific consumer, computer, or other device, unless the entity collects

only non-sensitive data from fewer than 5,000 consumers per year and does not share the data with

third parties.

B. PRIVACY BY DESIGN

Baseline Principle: Companies should promote consumer privacy throughout their organizations

and at every stage of the development of their products and services.

The preliminary staff report called on companies to promote consumer privacy throughout their

organizations and at every stage of the development of their products and services. Although many

companies already incorporate substantive and procedural privacy protections into their business practices,

industry should implement privacy by design more systematically. A number of commenters, including

those representing industry, supported staff’s call that companies “build in” privacy, with several of these

commenters citing to the broad international recognition and adoption of privacy by design.115 The

Commission is encouraged to see broad support for this concept, particularly in light of the increasingly

global nature of data transfers.

111 Letter from Maneesha Mithal, Assoc. Dir., Div. of Privacy & Identity Prot., FTC, to Reed Freeman, Morrison & Foerster

LLP, Counsel for Netflix, 2 (Mar. 12, 2010), available at http://www.ftc.gov/os/closings/100312netflixletter.pdf (closing

letter).

112 Id.

113 To the extent that a company maintains and uses both data that is identifiable and data that it has taken steps to de-identify as

outlined here, the company should silo the data separately.

114 A company that violates its policy against re-identifying data could be subject to liability under the FTC Act or other laws.

115 Comment of Office of the Information and Privacy Commissioner of Ontario, cmt. #00239, at 2-3; Comment of Intel Corp., cmt.

#00246, at 12-13; Comment of CNIL, cmt. #00298, at 2-3.

22

In calling for privacy by design, staff advocated for the implementation of substantive privacy protections

– such as data security, limitations on data collection and retention, and data accuracy – as well as procedural

safeguards aimed at integrating the substantive principles into a company’s everyday business operations.

By shifting burdens away from consumers and placing obligations on businesses to treat consumer data in

a responsible manner, these principles should afford consumers basic privacy protections without forcing

them to read long, incomprehensible privacy notices to learn and make choices about a company’s privacy

practices. Although the Commission has not changed the proposed “privacy by design” principles, it

responds to a number of comments, as discussed below.

1. THE SUBSTANTIVE PRINCIPLES: DATA SECURITY, REASONABLE COLLECTION LIMITS,

SOUND RETENTION PRACTICES, AND DATA ACCURACY.

Proposed Principle: Companies should incorporate substantive privacy protections into their

practices, such as data security, reasonable collection limits, sound retention practices, and data

accuracy.

a. Should Additional Substantive Principles Be Identified?

Responding to a question about whether the final framework should identify additional substantive

protections, several commenters suggested incorporating the additional principles articulated in the 1980

OECD Privacy Guidelines.116 One commenter also proposed adding the “right to be forgotten,” which

would allow consumers to withdraw data posted online about themselves at any point.117 This concept has

gained importance as people post more information about themselves online without fully appreciating the

implications of such data sharing or the persistence of online data over time.118 In supporting an expansive

view of privacy by design, a consumer advocacy group noted that the individual elements and principles of

the proposed framework should work together holistically.119

In response, the Commission notes that the framework already embodies all the concepts in the 1980

OECD privacy guidelines, although with some updates and changes in emphasis. For example, privacy by

design includes the collection limitation, data quality, and security principles. Additionally, the framework’s

simplified choice and transparency components, discussed below, encompass the OECD principles of

purpose specification, use limitation, individual participation, and openness. The framework also adopts the

116 Comment of CNIL, cmt. #00298, at 2; Comment of the Information Commissioner’s Office of the UK, cmt. #00249, at 2;

Comment of World Privacy Forum, cmt. #00369, at 7; Comment of Intel Corp., cmt. #00246, at 4; see also Organisation for

Economic Co-operation & Development, OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal

Data (Sept. 1980), available at http://www.oecd.org/document/18/0,3343,en_2649_34255_1815186_1_1_1_1,00&&enUSS_01DBC.html (these principles include purpose specification, individual participation, accountability, and principles to

govern cross-border data transfers). Another commenter called for baseline legislation based on the Fair Information Practice

Principles and the principles outlined in the 1974 Privacy Act. Comment of Electronic Privacy Information Center, cmt.

#00386, at 17-20.

117 Comment of CNIL, cmt. #00298, at 3.

118 The concept of the “right to be forgotten,” and its importance to young consumers, is discussed in more detail below in the

Transparency Section, infra at Section IV.D.2.b.

119 Comment of Consumers Union, cmt. #00362, at 1-2, 5-9, 18-19.

23

OECD principle that companies must be accountable for their privacy practices. Specifically, the framework

calls on companies to implement procedures – such as designating a person responsible for privacy, training

employees, and ensuring adequate oversight of third parties – to help ensure that they are implementing

appropriate substantive privacy protections. The framework also calls on industry to increase efforts to

educate consumers about the commercial collection and use of their data and the available privacy tools.

In addition, there are aspects of the proposed “right to be forgotten” in the final framework, which calls on

companies to (1) delete consumer data that they no longer need and (2) allow consumers to access their data

and in appropriate cases suppress or delete it.120

All of the principles articulated in the preliminary staff report are intended to work together to shift

the burden for protecting privacy away from consumers and to encourage companies to make strong

privacy protections the default. Reasonable collection limits and data disposal policies work in tandem

with streamlined notices and improved consumer choice mechanisms. Together, they function to provide

substantive protections by placing reasonable limits on the collection, use, and retention of consumer data to

more closely align with consumer expectations, while also raising consumer awareness about the nature and

extent of data collection, use, and third-party sharing, and the choices available to them.

b. Data Security: Companies Must Provide Reasonable Security for Consumer Data.

It is well settled that companies must provide reasonable security for consumer data. The Commission

has a long history of enforcing data security obligations under Section 5 of the FTC Act, the FCRA and

the GLBA. Since 2001, the FTC has brought 36 cases under these laws, charging that businesses failed

to appropriately protect consumers’ personal information. Since issuance of the preliminary staff report

alone, the Commission has resolved seven data security actions against resellers of sensitive consumer

report information, service providers that process employee data, a college savings program, and a social

media service.121 In addition to the federal laws the FTC enforces, companies are subject to a variety of

120 See In the Matter of Facebook, Inc., FTC File No. 092 3184 (Nov. 29, 2011) (proposed consent order), available at http://

www.ftc.gov/os/caselist/0923184/index.shtm (requiring Facebook to make inaccessible within thirty days data that a user

deletes); see also Do Not Track Kids Act of 2011, H.R. 1895, 112th Cong. (2011).

121 In the Matter of Upromise, Inc., FTC File No. 102 3116 (Jan. 18, 2012) (proposed consent order), available at http://www.

ftc.gov/os/caselist/1023116/index.shtm; In the Matter of ACRAnet, Inc., FTC Docket No. C-4331(Aug. 17, 2011) (consent

order), available at http://ftc.gov/os/caselist/0923088/index.shtm; In the Matter of Fajilan & Assocs., Inc., FTC Docket

No. C-4332 (Aug. 17, 2011) (consent order), available at http://ftc.gov/os/caselist/0923089/index.shtm; In the Matter

of SettlementOne Credit Corp., FTC Docket No. C-4330 (Aug. 17, 2011) (consent order), available at http://ftc.gov/os/

caselist/0823208/index.shtm; In the Matter of Lookout Servs., Inc., FTC Docket No. C-4326 (June 15, 2011) (consent order),

available at http://www.ftc.gov/os/caselist/102376/index.shtm; In the Matter of Ceridian Corp., FTC Docket No. C-4325

(June 8, 2011) (consent order), available at http://www.ftc.gov/os/caselist/1023160/index.shtm; In the Matter of Twitter, Inc.,

FTC Docket No. C-4316 (Mar. 11, 2011) (consent order), available at http://www.ftc.gov/os/caselist/0923093/index.shtm.

24

other federal and state law obligations. In some industries, such as banking, federal regulators have given

additional guidance on how to define reasonable security.122

The Commission also promotes better data security through consumer and business education. For

example, the FTC sponsors OnGuard Online, a website to educate consumers about basic computer

security.123 Since the Commission issued the preliminary staff report there have been over 1.5 million

unique visits to OnGuard Online and its Spanish-language counterpart Alerta en Línea. The Commission’s

business outreach includes general advice about data security as well as specific advice about emerging

topics.124

The Commission also notes that the private sector has implemented a variety of initiatives in the security

area, including the Payment Card Institute Data Security Standards for payment card data, the SANS

Institute’s security policy templates, and standards and best practices guidelines for the financial services

industry provided by BITS, the technology policy division of the Financial Services Roundtable.125 These

standards can provide useful guidance on appropriate data security measures that organizations should

implement for specific types of consumer data or in specific industries. The Commission further calls on

industry to develop and implement best data security practices for additional industry sectors and other

types of consumer data.

Because this issue is important to consumers and because businesses have existing legal and selfregulatory obligations, many individual companies have placed great emphasis and resources on maintaining

reasonable security. For example, Google has cited certain security features in its products, including default

SSL encryption for Gmail and security features in its Chrome browser.126 Similarly, Mozilla has noted that

122 See, e.g., Federal Financial Institutions Examination Council (“FFIEC”), Information Society IT Examination Handbook (July

2006), available at http://ithandbook.ffiec.gov/it-booklets/information-security.aspx; Letter from Richard Spillenkothen,

Dir., Div. of Banking Supervision & Regulation, Bd. of Governors of the Fed. Reserve Sys., SRO1-11: Identity Theft and

Pretext Calling (Apr. 26, 2011), available at http://www.federalreserve.gov/boarddocs/srletters/2001/sr0111.htm (guidance

on pretexting and identity theft); Securities & Exchange Commission, CF Disclosure Guidance: Topic No. 2, on Cybersecurity

(Oct. 13, 2011), available at http://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm; U.S. Small Business

Administration, Information Security Guidance, http://www.sba.gov/content/information-security; National Institute

of Standards & Technology, Computer Security Division, Computer Security Resource Center, available at http://csrc.nist.

gov/groups/SMA/sbc/index.html; HHS, Health Information Privacy, available at http://www.hhs.gov/ocr/privacy/hipaa/

understanding/coveredentities/index.html (guidance and educational materials for entities required to comply with the

HIPPA Privacy and Security Rules); Centers from Medicare and Medicaid Services, Educational Materials, available at http://

www.cms.gov/EducationMaterials/ (educational materials for HIPPA compliance).

123 FTC, OnGuard Online, http://onguardonline.gov/.

124 See FTC, Protecting Personal Information: A Guide for Business (Nov. 2011), available at http://business.ftc.gov/documents/

bus69-protecting-personal-information-guide-business; see generally FTC, Bureau of Consumer Protection Business Center,

Data Security Guidance, available at http://business.ftc.gov/privacy-and-security/data-security.

125 See PCI Security Standards Council, PCI SSC Data Security Standards Overview, available at https://www.

pcisecuritystandards.org/security_standards/; SANS Institute, Information Security Policy Templates, available at http://www.

sans.org/security-resources/policies/; BITS, Financial Services Roundtable BITS Publications, available at http://www.bits.org/

publications/index.php; see also, e.g., Better Business Bureau, Security and Privacy – Made Simpler: Manageable Guidelines to

help You Protect Your Customers’ Security & Privacy from Identity Theft & Fraud, available at http://www.bbb.org/us/storage/16/

documents/SecurityPrivacyMadeSimpler.pdf; National Cyber Security Alliance, For Business, http://www.staysafeonline.org/

for-business (guidance for small and midsize businesses); Direct Marketing Association, Information Security: Safeguarding

Personal Data in Your Care (May 2005), available at http://www.the-dma.org/privacy/InfoSecData.pdf; Messaging Anti-Abuse

Working Group & Anti-Phishing Working Group, Anti-Phishing Best Practices for ISPs and Mailbox Providers (July 2006),

available at http://www.antiphishing.org/reports/bestpracticesforisps.pdf.

126 Comment of Google Inc., cmt. #00417, at 2-3.

25

its cloud storage system encrypts user data using SSL communication.127 Likewise, Twitter has implemented

encryption by default for users logged into its system.128 The Commission commends these efforts and calls

on companies to continue to look for additional ways to build data security into products and services from

the design stage.

Finally, the Commission reiterates its call for Congress to enact data security and breach notification

legislation. To help deter violations, such legislation should authorize the Commission to seek civil penalties.

c. Reasonable Collection Limitation: Companies Should Limit Their Collection of Data.

The preliminary staff report called on companies to collect only the data they need to accomplish a

specific business purpose. Many commenters expressed support for the general principle that companies

should limit the information they collect from consumers.129 Despite the broad support for the concept,

however, many companies argued for a flexible approach based on concerns that allowing companies to

collect data only for existing business needs would harm innovation and deny consumers new products

and services.130 One commenter cited Netflix’s video recommendation feature as an example of how

secondary uses of data can create consumer benefits. The commenter noted that Netflix originally collected

information about subscribers’ movie preferences in order to send the specific videos requested, but later

used this information as the foundation for generating personalized recommendations to its subscribers.131

In addition, commenters raised concerns about who decides what a “specific business purpose” is.132

For example, one purpose for collecting data is to sell it to third parties in order to monetize a service and

provide it to consumers for free. Would collecting data for this purpose be a specific business purpose?

If not, is the only alternative to charge consumers for the service, and would this result be better for

consumers?

As an alternative to limiting collection to accomplish a “specific business purpose,” many commenters

advocated limiting collection to business purposes that are clearly articulated. This is akin to the Fair

Information Practice Principle of “purpose specification,” which holds that companies should specify to

consumers all of the purposes for which information is collected at the time of collection. One commenter

supported purpose specification statements in general categories to allow innovation and avoid making

privacy policies overly complex.133

127 Comment of Mozilla, cmt. #00480, at 7.

128 See Chloe Albanesius, Twitter Adds Always-On Encryption, PC Magazine, Feb. 12, 2012, http://www.pcmag.com/

article2/0,2817,2400252,00.asp.

129 See, e.g., Comment of Intel Corp., cmt. #00246, at 4-5, 7, 40-41; Comment of Electronic Frontier Foundation, cmt. #00400, at

4-6; Comment of Center for Democracy & Technology, cmt. #00469, at 4-5; Comment of Electronic Privacy Information Center,

cmt. #00386, at 18.

130 See, e.g., Comment of Facebook, Inc., cmt. #00413, at 2, 7-8, 18; Comment of Google Inc., cmt. #00417, at 4; Comment of

Direct Marketing Ass’n, Inc., cmt. #00449, at 14-15; Comment of Intuit, Inc., cmt. #00348, at 5, 9; Comment of TRUSTe, cmt.

#00450, at 9.

131 Comment of Facebook, Inc., cmt. #00413, at 7-8.

132 See Comment of SAS, cmt. #00415, at 51; Comment of Yahoo! Inc., cmt. #00444, at 5.

133 Comment of Yahoo! Inc., cmt. #00444, at 5.

26

The Commission recognizes the need for flexibility to permit innovative new uses of data that benefit

consumers. At the same time, in order to protect consumer privacy, there must be some reasonable limit on

the collection of consumer data. General statements in privacy policies, however, are not an appropriate tool

to ensure such a limit because companies have an incentive to make vague promises that would permit them

to do virtually anything with consumer data.

Accordingly, the Commission clarifies the collection limitation principle of the framework as follows:

Companies should limit data collection to that which is consistent with the context of a particular

transaction or the consumer’s relationship with the business, or as required or specifically authorized by

law.134 For any data collection that is inconsistent with these contexts, companies should make appropriate

disclosures to consumers at a relevant time and in a prominent manner – outside of a privacy policy or

other legal document. This clarification of the collection limitation principle is intended to help companies

assess whether their data collection is consistent with what a consumer might expect; if it is not, they should

provide prominent notice and choice. (For a further discussion of this point, see infra Section IV.C.2.) This

approach is consistent with the Administration’s Consumer Privacy Bill of Rights, which includes a Respect

for Context principle that limits the use of consumer data to those purposes consistent with the context in

which consumers originally disclosed the data.135

One example of a company innovating around the concept of privacy by design through collection

limitation is the Graduate Management Admission Council (“GMAC”). This entity previously collected

fingerprints from individuals taking the Graduate Management Admission Test. After concerns were raised

about individuals’ fingerprints being cross-referenced against criminal databases, GMAC developed a system

that allowed for collection of palm prints that could be used solely for test-taking purposes.136 The palm

print technology is as accurate as fingerprinting but less susceptible to “function creep” over time than the

taking of fingerprints, because palm prints are not widely used as a common identifier. GMAC received a

privacy innovation award for small businesses for its work in this area.

d. Sound Data Retention: Companies Should Implement Reasonable Data Retention and

Disposal Policies.

Similar to the concerns raised about collection limits, many commenters expressed concern about

limiting retention of consumer data, asserting that such limits would harm innovation. Trade associations

and businesses requested a flexible standard for data retention to allow companies to develop new products

134 This approach mirrors the revised standard for determining whether a particular data practice warrants consumer choice

(see infra at section IV.C.1.a.) and is consistent with a number of commenters’ calls for considering the context in which a

particular practice takes place. See, e.g., Comment of CTIA - The Wireless Ass’n, cmt. #00375, at 2-4; Comment of Consumer

Data Industry Ass’n, cmt. #00363, at 5; Comment of TRUSTe, cmt. #00450, at 3.

135 See White House, Consumer Data Privacy in a Networked World: A Framework for Protecting Privacy and Promoting Innovation

in the Global Digital Economy, 15-19, (Feb. 2012), available at http://www.whitehouse.gov/sites/default/files/privacy-final.pdf.

For a further discussion of this point, see infra at Section IV.C.1.a.

136 See Jay Cline, GMAC: Navigating EU Approval for Advanced Biomterics, Inside Privacy Blog (Oct. 15, 2010), https://www.

privacyassociation.org/publications/2010_10_20_gmac_navigating_eu_approval_for_advanced_biometrics (explaining

GMAC’s adoption of palm print technology); cf. Kashmir Hill, Why ‘Privacy by Design’ is the New Corporate Hotness, Forbes,

July 28, 2011, available at http://www.forbes.com/sites/kashmirhill/2011/07/28/why-privacy-by-design-is-the-new-corporatehotness/.

27

and other uses of data that provide benefits to consumers.137 One company raised concerns about

prescriptive retention periods, arguing that retention standards instead should be based on business need,

the type and location of data at issue, operational issues, and legal requirements.138 Other commenters

noted that retention limits should be sufficiently flexible to accommodate requests from law enforcement

or other legitimate business purposes, such as the need of a mortgage banker to retain information about a

consumer’s payment history.139 Some commenters suggested that the Commission’s focus should be on data

security and proper handling of consumer data, rather than on retention limits.140

In contrast, some consumer groups advocated specific retention periods. For example, one such

commenter cited a proposal made by a consortium of consumer groups in 2009 that companies that collect

data for online behavioral advertising should limit their retention of the data to three months and that

companies that retained their online behavioral advertising data for only 24 hours may not need to obtain

consumer consent for their data collection and use.141 Others stated that it might be appropriate for the

FTC to recommend industry-specific retention periods after a public consultation.142

The Commission confirms its conclusion that companies should implement reasonable restrictions on

the retention of data and should dispose of it once the data has outlived the legitimate purpose for which it

was collected.143 Retention periods, however, can be flexible and scaled according to the type of relationship

and use of the data; for example, there may be legitimate reasons for certain companies that have a direct

relationship with customers to retain some data for an extended period of time. A mortgage company will

maintain data for the life of the mortgage to ensure accurate payment tracking; an auto dealer will retain

data from its customers for years to manage service records and inform its customers of new offers. These

long retention periods help maintain productive customer relationships. This analysis does not, however,

apply to all data collection scenarios. A number of commenters noted that online behavioral advertising

data often becomes stale quickly and need not be retained long.144 For example, a consumer researching

hotels in a particular city for an upcoming vacation is unlikely to be interested in continuing to see hotel

advertisements after the trip is completed. Indefinite retention of data about the consumer’s interest in

finding a hotel for a particular weekend serves little purpose and could result in marketers sending the

consumer irrelevant advertising.

137 See Comment of CTIA - The Wireless Ass’n, cmt. #00375, at 2-4, 14; Comment of American Catalog Mailers Ass’n, cmt.

#000424, at 5; Comment of IBM, cmt. #00433, at 4; Comment of Intuit, Inc., cmt. #00348, at 9.

138 Comment of Verizon, cmt. #00428, at 10-11.

139 See, e.g., Comment of CTIA - The Wireless Ass’n, cmt. #00375, at 14.

140 Comment of Yahoo! Inc., cmt. #00444, at 6; see also Comment of American Catalog Mailers Ass’n, cmt. #00424, at 3-4.

141 Comment of Consumer Federation of America, cmt. #00358, at 4 (citing Legislative Primer: Online Behavioral Tracking and

Targeting Concerns and Solutions from the Perspective of the Center for Digital Democracy and U.S. PIRG, Consumer Federation

of America, Consumers Union, Consumer Watchdog, Electronic Frontier Foundation, Privacy Lives, Privacy Rights Clearinghouse,

Privacy Times, U.S. Public Interest Research group, The World Privacy Forum (Sept. 2009), available at http://www.consumerfed.

org/elements/www.consumerfed.org/file/OnlinePrivacyLegPrimerSEPT09.pdf ).

142 Comment of Center for Democracy & Technology, cmt. #00469, at 6 (“Flexible approaches to data retention should not,

however, give carte blanche to companies to maintain consumer data after it has outlived its reasonable usefulness.”).

143 In the alternative, companies may consider taking steps to de-identify the data they maintain, as discussed above.

144 See Comment of Consumers Union, cmt. #00362, at 8.

28

In determining when to dispose of data, as well as limitations on collection described above, companies

should also take into account the nature of the data they collect. For example, consider a company that

develops an online interactive game as part of a marketing campaign directed to teens. The company should

first assess whether it needs to collect the teens’ data as part of the game, and if so, how it could limit the

data collected, such as by allowing teens to create their own username instead of using a real name and email

address. If the company decides to collect the data, it should consider disposing of it even more quickly

than it would if it collected adults’ data. Similarly, recognizing the sensitivity of data such as a particular

consumer’s real time location, companies should take special care to delete this data as soon as possible,

consistent with the services they provide to consumers.

Although restrictions may be tailored to the nature of the company’s business and the data at issue,

companies should develop clear standards and train its employees to follow them. Trade associations and

self-regulatory groups also should be more proactive in providing guidance to their members about retention

and data destruction policies. Accordingly, the Commission calls on industry groups from all sectors – the

online advertising industry, online publishers, mobile participants, social networks, data brokers and others –

to do more to provide guidance in this area. Similarly, the Commission generally supports the exploration of

efforts to develop additional mechanisms, such as the “eraser button” for social media discussed below,145 to

allow consumers to manage and, where appropriate, require companies to delete the information consumers

have submitted.

e. Accuracy: Companies should maintain reasonable accuracy of consumers’ data.

The preliminary staff report called on companies to take reasonable steps to ensure the accuracy of the

data they collect and maintain, particularly if such data could cause significant harm or be used to deny

consumers services. Similar to concerns raised about collection limits and retention periods, commenters

opposed rigid accuracy standards,146 and noted that the FCRA already imposes accuracy standards in certain

contexts.147 One commenter highlighted the challenges of providing the same levels of accuracy for nonidentifiable data versus data that is identifiable.148

To address these challenges, some commenters stated that a sliding scale approach should be followed,

particularly for marketing data. These commenters stated that marketing data is not used for eligibility

purposes and that, if inaccurate, the only harm a consumer may experience is an irrelevant advertisement.149

Providing enhanced accuracy standards for marketing data would raise additional privacy and data security

concerns,150 as additional information may need to be added to marketing databases to increase accuracy.151

145 See infra at Section IV.D.2.b.

146 See Comment of Experian, cmt. #00398, at 2.

147 See Comment of SIFMA, cmt. #00265, at 4.

148 Comment of Phorm Inc., cmt. #00353, at 4.

149 Comment of Experian, cmt. #00398, at 11 (arguing against enhanced standards for accuracy, access, and correction for

marketing data); see also Comment of Yahoo! Inc., cmt. #00444, at 6-7.

150 Id.

151 Cf. Comment of Yahoo! Inc., cmt. #00444, at 7 (arguing that it would be costly, time consuming, and contrary to privacy

objectives to verify the accuracy of user registration information such as gender, age or hometown).

29

The Commission agrees that the best approach to improving the accuracy of the consumer data

companies collect and maintain is a flexible one, scaled to the intended use and sensitivity of the

information. Thus, for example, companies using data for marketing purposes need not take special

measures to ensure the accuracy of the information they maintain. Companies using data to make decisions

about consumers’ eligibility for benefits should take much more robust measures to ensure accuracy,

including allowing consumers access to the data and the opportunity to correct erroneous information.152

Final Principle: Companies should incorporate substantive privacy protections into their practices,

such as data security, reasonable collection limits, sound retention and disposal practices, and data

accuracy.

2. COMPANIES SHOULD ADOPT PROCEDURAL PROTECTIONS TO IMPLEMENT THE

SUBSTANTIVE PRINCIPLES.

Proposed Principle: Companies should maintain comprehensive data management procedures

throughout the life cycle of their products and services.

In addition to the substantive principles articulated above, the preliminary staff report called for

organizations to maintain comprehensive data management procedures, such as designating personnel

responsible for employee privacy training and regularly assessing the privacy impact of specific practices,

products, and services. Many commenters supported this call for accountability within an organization.153

Commenters noted that privacy risk assessments promote accountability, and help identify and address

privacy issues.154 One commenter stated that privacy risk assessments should be an ongoing process, and

findings should be used to update internal procedures.155 The Commission agrees that companies should

implement accountability mechanisms and conduct regular privacy risk assessments to ensure that privacy

issues are addressed throughout an organization.

The preliminary staff report also called on companies to “consider privacy issues systemically, at all

stages of the design and development of their products and services.” A range of commenters supported

the principle of “baking” privacy into the product development process.156 One commenter stated that this

approach of including privacy considerations in the product development process was preferable to requiring

152 See infra at Section IV.D.2. The Commission notes that some privacy-enhancing technologies operate by introducing

deliberate “noise” into data. The data accuracy principle is not intended to rule out the appropriate use of these methods,

provided that the entity using them notifies any recipients of the data that it is inaccurate.

153 See, e.g., Comment of The Centre for Information Policy Leadership at Hunton & Williams LLP, cmt. #00360, at 2-3; Comment

of Intel Corp., cmt. #00246, at 6; Comment of Office of the Information & Privacy Commissioner of Ontario, cmt. #00239, at 3.

154 Comment of GS1, cmt. #00439, at 3; Comment of Office of the Information & Privacy Commissioner of Ontario, cmt. #00239,

at 6.

155 Comment of Office of the Information & Privacy Commissioner of Ontario, cmt. #00239, at 7.

156 Comment of Intel Corp., cmt. #00246, at 6; Comment of United States Council for International Business, cmt. #00366, at 2;

Comment of Consumer Federation of America, cmt. #00358, at 3.

30

after-the-fact reviews.157 Another argued that privacy concerns should be considered from the outset, but

observed that such concerns should continue to be evaluated as the product, service, or feature evolves.158

The Commission’s recent settlements with Google and Facebook illustrate how the procedural

protections discussed above might work in practice.159 In both cases, the Commission alleged that the

companies deceived consumers about the level of privacy afforded to their data.

The FTC’s orders will require the companies to implement a comprehensive privacy program reasonably

designed to address privacy risks related to the development and management of new and existing products

and services and to protect the privacy and confidentiality of “covered information,” defined broadly to mean

any information the companies collect from or about a consumer.

The privacy programs that the orders mandate must, at a minimum, contain certain controls and

procedures, including: (1) the designation of personnel responsible for the privacy program; (2) a risk

assessment that, at a minimum, addresses employee training and management and product design and

development; (3) the implementation of controls designed to address the risks identified; (4) appropriate

oversight of service providers; and (5) evaluation and adjustment of the privacy program in light of regular

testing and monitoring.160 Companies should view the comprehensive privacy programs mandated by these

consent orders as a roadmap as they implement privacy by design in their own organizations.

As an additional means of implementing the substantive privacy by design protections, the preliminary

staff report advocated the use of privacy-enhancing technologies (“PETs”) – such as encryption and

anonymization tools – and requested comment on implementation of such technologies. One commenter

stressed the need for “privacy-aware design,” calling for techniques such as obfuscation and cryptography

to reduce the amount of identifiable consumer data collected and used for various products and services.161

Another stressed that PETs are a better approach in this area than rigid technical mandates.162

The Commission agrees that a flexible, technology-neutral approach towards developing PETs is

appropriate to accommodate the rapid changes in the marketplace and will also allow companies to

innovate on PETs. Accordingly, the Commission calls on companies to continue to look for new ways to

protect consumer privacy throughout the life cycle of their products and services, including through the

development and deployment of PETs.

Finally, Commission staff requested comment on how to apply the substantive protections articulated

above to companies with legacy data systems. Many commenters supported a phase-out period for legacy

data systems, giving priority to systems that contain sensitive data.163 Another commenter suggested that

157 Comment of Intel Corp., cmt. #00246, at 6.

158 Comment of Zynga Inc., cmt. #00459, at 2.

159 Of course, the privacy programs required by these orders may not be appropriate for all types and sizes of companies that

collect and use consumer data.

160 In the Matter of Google Inc., FTC Docket No. C-4336 (Oct. 13, 2011) (consent order), available at http://www.ftc.gov/os/

caselist/index.shtm.

161 Comment of Electronic Frontier Foundation, cmt. #00400, at 5.

162 Comment of Business Software Alliance, cmt. #00389, at 7-9.

163 Comment of The Centre for Information Policy Leadership at Hunton & Williams LLP, cmt. #00360, at 3; Comment of the

Information Commissioner’s Office of the UK, cmt. #00249, at 2; Comment of CTIA - The Wireless Ass’n, cmt. #00375, at 14.

31

imposing strict access controls on legacy data systems until they can be updated would enhance privacy.164

Although companies need to apply the various substantive privacy by design elements to their legacy data

systems, the Commission recognizes that companies need a reasonable transition period to update their

systems. In applying the substantive elements to their legacy systems, companies should prioritize those

systems that contain sensitive data and they should appropriately limit access to all such systems until they

can update them.

Final Principle: Companies should maintain comprehensive data management procedures

throughout the life cycle of their products and services.

164 Comment of Yahoo! Inc., cmt. #00444, at 7.

32

DATA COLLECTION AND DISPOSAL CASE STUDY: MOBILE

The rapid growth of the mobile marketplace illustrates the need for companies to implement

reasonable limits on the collection, transfer, and use of consumer data and to set policies for

disposing of collected data. The unique features of a mobile phone – which is highly personal,

almost always on, and travels with the consumer – have facilitated unprecedented levels of data

collection. Recent news reports have confirmed the extent of this ubiquitous data collection.

Researchers announced, for example, that Apple had been collecting geolocation data through

its mobile devices over time, and storing unencrypted data files containing this information on

consumers’ computers and mobile devices.1 The Wall Street Journal has documented numerous

companies gaining access to detailed information – such as age, gender, precise location, and the

unique ID associated with a particular mobile device – that can then be used to track and predict

consumer behavior.2 Not surprisingly, consumers are concerned: for example, a recent Nielsen

study found that a majority of smartphone app users worry about their privacy when it comes

to sharing their location through a mobile device.3 The Commission calls on companies to limit

collection to data they need for a requested service or transaction. For example, a wallpaper app or

an app that tracks stock quotes does not need to collect location information.4

The extensive collection of consumer information – particularly location information – through

mobile devices also heightens the need for companies to implement reasonable policies for purging

data.5 Without data retention and disposal policies specifically tied to the stated business purpose

for the data collection, location information could be used to build detailed profiles of consumer

movements over time that could be used in ways not anticipated by consumers.6 Location

information is particularly useful for uniquely identifying (or re-identifying) individuals using

disparate bits of data.7 For example, a consumer can use a mobile application on her cell phone to

“check in” at a restaurant for the purpose of finding and connecting with friends who are nearby.

The same consumer might not expect the application provider to retain a history of restaurants she

visited over time. If the application provider were to share that information with third parties, it

could reveal a predictive pattern of the consumer’s movements thereby exposing the consumer to

a risk of harm such as stalking.8 Taken together, the principles of reasonable collection limitation

and disposal periods help to minimize the risks that information collected from or about consumers

could be used in harmful or unexpected ways.

With respect to the particular concerns of location data in the mobile context, the

Commission calls on entities involved in the mobile ecosystem to work together to establish

standards that address data collection, transfer, use, and disposal, particularly for location

data. To the extent that location data in particular is collected and shared with third parties,

entities should work to provide consumers with more prominent notice and choices about

such practices. Although some in the mobile ecosystem provide notice about the collection

of geolocation data, not all companies have adequately disclosed the frequency or extent of

the collection, transfer, and use of such data.

33

NOTES

1

See Jennifer Valentino-Devries, Study: iPhone Keeps Tracking Data, Wall St. J., Apr. 21, 2011, available at

http://online.wsj.com/article/SB10001424052748704570704576275323811369758.html.

2

See, e.g., Robert Lee Hotz, The Really Smart Phone, Wall St. J., Apr. 22, 2011, available at http://online.wsj.com/

article/SB10001424052748704547604576263261679848814.html (describing how researchers are using mobile

data to predict consumers’ actions); Scott Thurm & Yukari Iwatane Kane, Your Apps are Watching You, Wall St. J.,

Dec. 18, 2010, available at http://online.wsj.com/article/SB10001424052748704368004576027751867039730.

html (documenting the data collection that occurs through many popular smartphone apps).

3

Privacy Please! U.S. Smartphone App Users Concerned with Privacy When It Comes to Location, NielsenWire Blog

(Apr. 21, 2011), http://blog.nielsen.com/nielsenwire/online_mobile/privacy-please-u-s-smartphone-app-usersconcerned-with-privacy-when-it-comes-to-location/; see also Ponemon Institute, Smartphone Security: Survey of U.S.

Consumers 7 (Mar. 2011), available at http://aa-download.avg.com/filedir/other/Smartphone.pdf (reporting that

64% of consumers worry about their location being tracked when using their smartphones).

4

Similarly, the photo-sharing app Path faced widespread criticism for uploading its users’ iPhone address books

without their consent. See, e.g., Mark Hachman, Path Uploads Your Entire iPhone Contact List By Default, PC

Magazine, Feb. 7, 2012, available at http://www.pcmag.com/article2/0,2817,2399970,00.asp.

5

The Commission is currently reviewing its COPPA Rule, including the application of COPPA to geolocation

information. See FTC, Proposed Rule and Request for Public Comment, Children’s Online Privacy Protection

Rule, 76 Fed. Reg. 59,804 (Sept. 15, 2011), available at http://www.gpo.gov/fdsys/pkg/FR-2011-09-27/pdf/201124314.pdf.

6

See ACLU of Northern California, Location-Based Services: Time for a Privacy Check-In, 14-15 (Nov. 2010), available

at http://dotrights.org/sites/default/files/lbs-white-paper.pdf.

7

Comment of Electronic Frontier Foundation, cmt. #00400, at 3.

8

Cf. U.S. v. Jones, 565 U.S. 132 S. Ct. 945, 955 (2012) (Sotomayor, J., concurring) (noting that “GPS monitoring

generates a precise, comprehensive record of a person’s public movements that reflects a wealth of detail about her

familial, political, professional, religious, and sexual associations”).

34

C. SIMPLIFIED CONSUMER CHOICE

Baseline Principle: Companies should simplify consumer choice.

As detailed in the preliminary staff report and in submitted comments, many consumers face challenges

in understanding the nature and extent of current commercial data practices and how to exercise available

choices regarding those practices. This challenge results from a number of factors including: (1) the

dramatic increase in the breadth of consumer data collection and use, made possible by an ever-increasing

range of technologies and business models; (2) the ability of companies, outside of certain sector-specific

laws, to collect and use data without first providing consumer choice; and (3) the inadequacy of typical

privacy policies as a means to effectively communicate information about the privacy choices that are offered

to consumers.

To reduce the burden on those consumers who seek greater control over their data, the proposed

framework called on companies that collect and use consumer data to provide easy-to-use choice

mechanisms that allow consumers to control whether their data is collected and how it is used. To ensure

that choice is most effective, the report stated that a company should provide the choice mechanism at

a time and in a context that is relevant to consumers – generally at the point the company collects the

consumer’s information. At the same time, however, in recognition of the benefits of various types of

data collection and use, the proposed framework identified certain “commonly accepted” categories of

commercial data practices that companies can engage in without offering consumer choice.

Staff posed a variety of questions and received numerous comments regarding the proposed framework’s

simplified consumer choice approach. Two trade organizations argued that the framework should identify

those practices for which choice is appropriate rather than making choice the general rule, subject to

exceptions for certain practices.165 The majority of commenters, however, did not challenge the proposed

framework’s approach of setting consumer choice as the default.166 Instead, these commenters focused on

the practicality of staff’s “commonly accepted” formulation.167 For example, several commenters questioned

whether the approach was sufficiently flexible to allow for innovation.168 Others discussed whether specific

practices should fall within the categories enumerated in the preliminary staff report.169 In addition,

numerous commenters addressed the appropriate scope of the first-party marketing category and how to

165 Comment of Direct Marketing Ass’n, Inc., cmt. #00449, at 16; Comment of Interactive Advertising Bureau, cmt. #00388, at 8-9.

166 Several commenters expressed support for consumer choice generally. See, e.g., Comment of Center for Democracy &

Technology, cmt. #00469, at 11-12; Comment of Consumer Federation of America, cmt. #00358, at 6-12. One governmental

agency, for instance, expressly supported a general rule requiring consumer consent for the collection and any use of

their information with only limited exceptions. Comment of Department of Veteran Affairs, cmt. #00479, at 5. Another

commenter, supporting consumer choice, emphasized the importance of offering opportunities for choice beyond a

consumer’s initial transaction. Comment of Catalog Choice, cmt. #00473, at 10-18.

167 Comment of Center for Democracy & Technology, cmt. #00469, at 8-11; Comment of Consumer Federation of America, cmt.

#00358, at 6-10.

168 Comment of Computer and Communications Industry Ass’n, cmt. #00434, at 16; Comment of BlueKai, cmt. #00397, at 3-4;

Comment of Retail Industry Leaders Ass’n, cmt. #00352, at 5-7; U.S. Chamber of Commerce, cmt. #00452, at 5; Comment of

National Cable & Telecommunications Ass’n, cmt. #00432, at 23-24; Comment of Yahoo! Inc., cmt. #00444, at 9-10.

169 Comment of Phorm Inc., cmt. #00353, at 5; Comment of Verizon, cmt. #00428, at 11-13.

35

define specific business models. With respect to those practices that fall outside the “commonly accepted”

categories, commenters also addressed the mechanics of providing choice at the relevant time and what types

of practices require enhanced choice.

Consistent with the discussion and analysis set forth below, the Commission retains the proposed

framework’s simplified choice model. Establishing consumer choice as a baseline requirement for companies

that collect and use consumer data, while also identifying certain practices where choice is unnecessary, is

an appropriately balanced model. It increases consumers’ control over the collection and use of their data,

preserves the ability of companies to innovate new products and services, and sets clear expectations for

consumers and industry alike. In order to better foster innovation and take into account new technologies

and business models, however, the Commission is providing further clarification of the framework’s

simplified choice concept.

1. PRACTICES THAT DO NOT REQUIRE CHOICE.

Proposed Principle: Companies do not need to provide choice before collecting and using

consumers’ data for commonly accepted practices, such as product fulfillment.

The preliminary staff report identified five categories of data practices that companies can engage in

without offering consumer choice, because they involve data collection and use that is either obvious from

the context of the transaction or sufficiently accepted or necessary for public policy reasons. The categories

included: (1) product and service fulfillment; (2) internal operations; (3) fraud prevention; (4) legal

compliance and public purpose; and (5) first-party marketing. In response to the comments received, the

Commission revises its approach to focus on the context of the consumer’s interaction with a company, as

discussed below.

a. General Approach to “Commonly Accepted” Practices.

While generally supporting the concept that choice is unnecessary for certain practices, a variety of

commenters addressed the issue of whether the list of “commonly accepted” practices was too broad or too

narrow.170 A number of industry commenters expressed concern that the list of practice categories was too

narrow and rigid. These commenters stated that, by enumerating a list of specific practices, the proposed

framework created a bright-line standard that freezes in place current practices and potentially could harm

innovation and restrict the d

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.