Final Amended COPPA Rule

Slides:



Advertisements
Similar presentations
NAU HIPAA Awareness Training
Advertisements

2014 HIPAA Refresher Omnibus Rule & HIPAA Security.
Silicon Valley Apps for Kids Meetup Laura D. Berger October 22, 2012 The views expressed herein are those of the speaker, and do not represent the views.
I.D. Theft Alaska’s New Protection of Personal Information Act Ed Sniffen Senior Assistant Attorney General Alaska Department of Law.
OSEP QUARTERLY CALL WITH PARENT CENTERS PART B FINAL REGULATIONS RELATED TO PARENTAL CONSENT FOR THE USE OF PUBLIC BENEFITS OR INSURANCE Office of Special.
Children's Online Privacy Protection Act and the Video Privacy Protection Act By: Alana Rushing.
PRIVACY A Consumer Reporting Agency Perspective. Collect and Sell Information on People Credit Bureaus – Equifax, Experian & TransUnion – are CRA’s But.
CIPA Update. FOR SCHOOLS – By July 1, 2012, amend your existing Internet safety policy (if you have not already done so) to provide for the education.
Recently Issued OHRP Documents: Guidance on Subject Withdrawal and Draft Revised FWA Secretary’s Advisory Committee on Human Research Protections October.
Hong Kong Privacy Code on Human Resource Management
FARMINGTON AREA PUBLIC SCHOOLS SUMMER TECHNOLOGY ACADEMY AUGUST 18TH, 2010 Web 2.0 Tools.
Version 6.0 Approved by HIPAA Implementation Team April 14, HIPAA Learning Module The following is an educational Powerpoint presentation on the.
Microsoft Passport Waldemar Swiercz.
Chapter 9 Information Systems Controls for System Reliability— Part 2: Confidentiality and Privacy Copyright © 2012 Pearson Education, Inc. publishing.
Data Privacy: Third Parties, Vendors, & Nonprofits Baron Rodriguez (PTAC), Michael Hawes (DoED), & Mike Tassey (PTAC)
FAMILY EDUCATIONAL RIGHTS AND PRIVACY ACT Electronic Signatures This work is the intellectual property of the author. Permission is granted for this material.
HIPAA Health Insurance Portability & Accountability Act of 1996.
Per Anders Eriksson
Data Protection Paul Veysey & Bethan Walsh. Introduction Data Protection is about protecting people by responsibly managing their data in ways they expect.
“Internet” and “Operator” (COPPA Statute) InternetOperator Collectively the myriad of computer and telecommunications facilities, including equipment.
HIPAA PRIVACY AND SECURITY AWARENESS.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Marketing Systems Group Southern California MRA Education Seminar Presentation September 17, 2005 Privacy and Current Issues.
Privacy and Security Laws for Health Care Organizations Presented by Robert J. Scott Scott & Scott, LLP
Federal Trade Commission required to issue and enforce regulations concerning children’s online privacy. Initial COPPA Rule effective April 21, 2000;
NEW FERPA REGULATIONS: ARE YOU IN COMPLIANCE? Presented by Cristi Millard.
Technology Supervision Branch Interagency Identity Theft Red Flags Regulation Bank Compliance Association of CT Bristol, CT September 3, 2008.
The right item, right place, right time. DLA Privacy Act Code of Fair Information Principles.
CYBERLAW Cyberlaw Meets Family Law: The Children’s Online Privacy Protection Act of 1998 (COPPA) Class of Nov. 11, 2002 Professor Susanna Fischer.
Serving the Public. Regulating the Profession. CANADA’S ANTI-SPAM LEGISLATION (CASL) Training for Chapters Based on Guidelines for Chapters First published.
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
CONFIDENTIALITY TRAINING FOR CALLOWAY COUNTY SCHOOLS VOLUNTEERS SCHOOL YEAR
CONFIDENTIALITY. Three Confidentiality Laws 1.FERPA-Family Education Rights and Privacy Act (State Policy 4350: Procedures for the Collection, Maintenance.
COPPA: CHILDREN'S PRIVACY, YOUR GAME, AND THE CHANGING ONLINE LANDSCAPE MONA IBRAHIM SENIOR ASSOCIATE INTERACTIVE ENTERTAINMENT LAW GROUP
“Kids First, New Mexico Wins!” NMPED Data Conference Spring 2016 Dan Hill General Counsel, Public Education Department Randi Johnson General Counsel, State.
Juvenile Legislative Update 2013 Confidential Records and Protected Disclosures.
The Apple Privacy Policy zakiya mitchell
FERPA Family Educational Rights and Privacy Act
Denise Chrysler, JD Director, Mid-States Region
Nassau Association of School Technologists
Health Insurance Portability and Accountability Act of 1996
Voice Signature Process
Student Privacy in an Ever-Changing Digital World
Prepared by Kris Twomey Law Office of Kristopher E. Twomey, P.C.
Silicon Valley Apps for Kids: COPPA BASICS
Privacy & Confidentiality
The E-Rate Program CIPA Update Fall 2011 Applicant Trainings.
GDPR – What’s it all about???
Obligations of Educational Agencies: Parents’ Bill of Rights
Shavonne Henry, Nikia Clarke, David Heymann, Brandon Knight
Whistleblower Program
PERSONAL DATA PROTECTION ACT 2010
Privacy & Access to Information
Refuah Community Health Collaborative (RCHC) PPS
2016 Annual CPNI Training CPNI & PI Awareness Beth Slough,
ABA Privacy and Data Security Update May 14, 2013
Current Privacy Issues That May Affect Your Credit Union
Spencer County Public Schools Responsible Use Policy for Technology and Related Devices Spencer County Public Schools has access to and use of the Internet.
General Data Protection Regulations
The HIPAA Privacy Rule and Research
GDPR (General Data Protection Regulation)
FERPA For New Faculty Lawrence F. Glick Sr. Associate General Counsel
Enforcement and Policy Challenges in Health Information Privacy
Online Safety: Rights and Responsibilities
Student Privacy in the age of big data
Colorado “Protections For Consumer Data Privacy” Law
Privacy Principles Melinda Clarke.
Mobile Registration App Training Guide for OPO Staffers
Confidentiality Training 2014
Presentation transcript:

Final Amended COPPA Rule effective July 1, 2013

Disclaimer The views expressed in this presentation are my own and are not necessarily those of the Commission or any individual Commissioner.

COPPA Enforcement Agency has filed 21 federal court actions, and has obtained over $8.4 million in civil penalties; FTC is authorized to seek up to $16,000/violation in penalties; Deletion of personal information collected without parental consent; Employee education and written acknowledgement; Written compliance report to FTC; and Consumer education.

July 2013 Changes Definitions Online and Direct Notices Parental Consent Mechanisms Confidentiality and Security of Children’s PI Data Retention and Deletion New Voluntary Processes for FTC Approval Safe Harbor Programs

“Operator” Personal information is collected or maintained on behalf of an operator when: it’s collected or maintained by the operator’s agent or service provider; or the operator benefits by allowing another person to collect PI directly from its users. Applies to 1st party child-directed sites/services that embed 3rd party content

Who must comply? Operators of a commercial website or online service directed to children (CDS) that collect, maintain, or provide the opportunity to disclose personal information (PI). Operators of general audience site or service with actual knowledge that they collect kids’ PI. Operators of a CDS that allow another person to collect PI directly from its users A cite or service with actual knowledge it’s collecting PI from users of a CDS.

“Website/Online Service Directed to Children” Reorganized definition sets out criteria for site/service directed to children upfront Adds provision that a service collecting PI directly from users of child-directed site/service is covered where it has actual knowledge of such collection; Applies to 3rd party services embedded on child-directed sites/services Adds provision allowing child-directed site/service, which doesn’t target children as its primary audience, to age- screen to provide COPPA protections only to users under 13

“Personal Information” Updates to the Definition of PI: Persistent identifiers (e.g., cookie strings, user IDs, IP addresses, processor or device serial numbers, unique device identifiers) used to recognize a user over time and across different websites or online services; Geolocation information sufficient to identify street name and name of city/town; Screen/user names where they function in the same manner as online contact information; and Photos, videos, or audio files containing a child’s image or voice.

“Support for Internal Operations” Includes use of persistent identifiers to: Maintain/analyze functioning site/service Perform network communications Authenticate users/personalize content on site/service Serve contextual advertising, cap frequency of ads Protect security/integrity of site/service Ensure legal/regulatory compliance Excludes use of persistent identifiers for behaviorally targeting or amassing a profile on a child or for any other purpose

“Support for Internal Operations” (cont’d) Persistent identifiers may be collected without VPC if used to support internal ops of EITHER the child-directed site OR the third-party plug-in; Analytics does fall into support for internal ops, BUT you should ensure analytics company is not using for impermissible purpose (e.g., behavioral advertising); “Personalization” is for user-driven preferences not behavioral advertising.

“Collects or Collection” Modifies part (b) of definition to: Replace the “100% deletion standard” with a “reasonable measures” standard. Let operators provide interactive communities for children without parental consent as long as they take reasonable measures to delete all or virtually all children’s PI before it’s made public.

Notices Improves the “direct notice” to: Ensure that key information is presented to parents in a succinct “just-in-time” notice; Provide a clear roadmap for operators as to content of direct notice depending upon its collection and use practices. Streamlines the privacy policy by requiring a simple statement of: The information the operator collects from children, including whether the website/online service enables a child to make PI publicly available; How the operator uses such information; and The operator’s disclosure practices for such information.

Mobile phone and direct notice The collection of a mobile phone number from a child is not permitted without first obtaining verifiable parental consent. Once you have collected a parent’s online contact information, you may request a mobile phone number for further contact with the parent.

Parental Consent New approved VPC methods in Rule: Electronic scans of signed parental consent forms, Video-conferencing; Use of government-issued identification checked against a database, provided that the parent’s ID is deleted promptly after verification; Use of debit card or other online payment system, if it provides notification of each transaction; Retains “email plus” for internal uses of PI.

Exceptions to Parental Consent Adds 3 new exceptions: Where site/service collects parent’s online contact information (but no other PI from child) to keep parent informed of a child’s activities; Where site/service collects persistent identifier (but no other PI from child) for sole purpose of providing “support for internal operations”; Where plug-in collects persistent identifier on a child- directed site/service (but no other PI) from a 13+ previously registered user who affirmatively interacts with it.

Data Security Strengthens the Rule’s confidentiality, security, and integrity provision by: Adding a requirement that operators take reasonable steps to release children’s PI only to parties capable of maintaining its security. Adds a data retention and deletion provision to: Retain children’s PI for only as long as is reasonably necessary to fulfill the purpose for which it was collected; and Properly delete PI by taking reasonable measures to protect against unauthorized access to or use in connection with its deletion.

Voluntary Approval Processes Parental consent methods: Request for Commission approval of new mechanisms Support for internal operations of the website or online service: Request for Commission approval to add new activities to the definition of support for internal operations All requests published for public comment Commission determination within 120 days of request Safe Harbor approval of parental consent methods: Operators participating in FTC- approved safe harbor can use a method permitted by that program.

Safe Harbor Programs Strengthens COPPA safe harbors by requiring them to: Detail their business models and technological capabilities and mechanisms to assess and insure members’ COPPA compliance; Audit members at least annually; Report to the Commission (July 1, 2014 and annually thereafter) on the aggregated results of internal audits.

A few key issues The FAQs and other guidance Mixed Audience Sites/Services Third Party Content Actual Knowledge Push Notices Schools Safe Harbors, VPC, and Internal OPs

FAQs and Other Guidance FTC staff publish COPPA FAQs. Since amendments, we have updated and added new FAQs to provide guidance regarding the new rule. Not a static document; we will continue to adding new FAQs as we receive questions. COPPA Hot Line. Outreach.

Mixed Audience Sites Allows child-directed site/service that doesn’t target children as its primary audience to age-screen and provide COPPA protections only to users under 13. What kinds of sites are mixed audience? Can I block kids from my mixed audience site? How do I know whether I am a mixed audience site?

Mixed Audience cont’d Sites with parents corners are not mixed audience sites – children are still the primary audience. May continue to treat parents corner as general audience so long as it is not enticing to children.

Third Party Plug-ins Do I have to provide notice and get consent if I put third party plug-ins on my site? Generally, first party is responsible for all collection through site including where done by a third party. First party operator gets benefit from having plug-in on site. Fills a gap.

Exceptions to Third Party Collection Rule Section 312.5(c)(7) Persistent ID for internal ops Section 312.5(c)(8) Persistent ID with previous interaction Only apply to notice and consent requirements.

Actual Knowledge How does a third party plug-in obtain actual knowledge that it is collecting personal information from users of child-directed sites? Where child-directed content provider directly tells the plug-in. Where representative recognizes child directed nature of content. List of URLs from consumer group will not provide actual knowledge or duty to investigate.

Actual Knowledge Who from my company can get actual knowledge? Use of a first party “child-directed site” signal.

Push notifications How does COPPA treat push notifications? Information you collect for push notification is online contact information and requires consent. BUT, you may rely on multiple contact exception (provide notice and opt out). Cannot combine with other personal information.

Schools Can operators get consent from schools instead of parents to collect personal information from students? Teacher, school, district? Yes if for the use and benefit of the school and no other commercial purpose. Best practice is go through school or district.

Safe Harbors and other Approval Processes Amendments strengthen Safe Harbor program by requiring them to: Detail their business models and technological capabilities and mechanisms to assess and insure members’ COPPA compliance; Audit members at least annually; and Report to the Commission (July 1, 2014 and annually thereafter) on the aggregated results of internal audits.

VPC and Internal OPs Request approval of new VPC method. Analysis of how proposed method will meet standard. Request approval of additional activities to include within definition of internal ops. Analysis of potential effect on children’s privacy.

Questions? FAQs available at http://business.ftc.gov/documents/0493- Complying-with-COPPA-Frequently-Asked- Questions Email at CoppaHotLine@ftc.gov General website at www.FTC.gov