Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Privacy Self-Regulation.

Slides:



Advertisements
Similar presentations
Data Privacy and Security in the Cloud Presented by Robert J. Scott Managing Partner Scott & Scott, LLP
Advertisements

EU Privacy Directive. What is a directive? A piece of European legislation, passed by bureaucrats, addressed to member states Member states must ensure.
Rosemarie Day Deputy Director and Chief Operating Officer Thursday, May 8, 2008 Operations Report Current Priorities and Future Plans.
Accessibility Awareness Training for Customer Service Representatives © 2014, T-Base Communications Inc. Welcome to Accessibility Awareness Training for.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2005 Lorrie Cranor 1 Privacy Authorization Languages.
Privacy Laws & Higher Education. Agenda 1.Five Privacy Laws a.FERPA b.HIPAA c.GLB d.FACTA Disposal Rule e.CAN-SPAM 2.Overview of the Laws a.What does.
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
CHAPTER 4 E-ENVIRONMENT
Consumer Privacy and Information Access Professor Matt Thatcher.
Surviving a Privacy Exam Barbara B. Fitch 2 nd VP–Market Conduct & Compliance National Life Insurance Company October 3, 2005.
Protecting Yourself Against Identity Theft TSCPA Member Name, CPA Firm/Company Name.
The Internet industry’s privacy seal program Silicon Valley Web Guild.
Minding Your Own Business The Platform for Privacy Preferences Project and Privacy Minder Lorrie Faith Cranor AT&T Labs-Research
The Platform for Privacy Preferences Project (P3P) Lorrie Faith Cranor AT&T Labs-Research P3P Interest Group Co-Chair October 1998.
BGS Customer Relationship Management Chapter 13 Privacy and Ethics Considerations Chapter 13 Privacy and Ethics Considerations Thomson Publishing 2007.
Chapter 20 Additional Assurance Services: Other Information
Internet Privacy Policies Presented by: Paul Frenken President, COLAIP.
1 The End Of The Privacy Policy As We Know It Fran Maier President TRUSTe.
Usable Privacy and Security Carnegie Mellon University Spring 2008 Lorrie Cranor 1 Introduction to Privacy January.
Usable Privacy and Security Carnegie Mellon University Spring 2007 Cranor/Hong 1 Introduction to Privacy January.
Privacy in Ontario Brian Beamish Office of the Information and Privacy Commissioner/Ontario Presentation to Security Canada Central 2002 International.
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
© Oklahoma State Department of Education. All rights reserved. 1 Beware! Consumer Fraud Standard 9. 1 Fraud and Identity Theft.
Principles of Marketing
Computers and Society Carnegie Mellon University Spring 2006 Cranor/Tongia/Farber 1 Intellectual Property.
Privacy as an International Information Issue MD823 October 18, 2004.
Usable Privacy and Security Carnegie Mellon University Spring 2006 Cranor/Hong/Reiter 1 Introduction to Privacy.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Privacy Policy.
Taking Steps to Protect Privacy A presentation to Hamilton-area Physiotherapy Managers by Bob Spence Communications Co-ordinator Office of the Ontario.
The Privacy Tug of War: Advertisers vs. Consumers Presented by Group F.
Privacy Policy, Law and Technology Carnegie Mellon University Fall 2004 Lorrie Cranor 1 Privacy Self-Regulation.
Information Privacy Dr. Heng Xu Privacy Assurance Lab (PAL) Penn State 03/31/2010.
Quick Discussion – based on:
Marketing - Best Practice from a Legal Point of View Yvonne Cunnane - Information Technology Law Group 30 November 2006.
Internal Auditing and Outsourcing
Final Rule – Secondary School Students – Published October 27, 2010 Effective Date: 30 days from publication Implementation: 2011/12 academic cycle o 1698.
LAW SEMINARS INTERNATIONAL New Developments in Internet Marketing & Selling November 13 & 14, 2006 San Francisco, California Moderator : Maureen A. Young.
ADB Project TA 3696-PAK, Regulation for Corporate Governance 1 REGULATION FOR CORPORATE GOVERNANCE IN PAKISTAN CAPITAL MARKETS.
Day 2 – Marketing Research…
Privacy, P3P and Internet Explorer 6 P3P Briefing – 11/16/01.
7-Oct-15 Threat on personal data Let the user be aware Privacy and protection.
Policy Review (Top-Down Methodology) Lesson 7. Policies From the Peltier Text, p. 81 “The cornerstones of effective information security programs are.
The European influence on privacy law and practice Nigel Waters, Pacific Privacy Consulting International Dimension of E-commerce and Cyberspace Regulation.
INDUSTRY COMMITMENT TO INNOVATION IN NOTICE AND CHOICE AAAA, ANA, CBBB, DMA, IAB Convene Task-Force (April 2008) Coalition begins drafting industry principles.
Privacy Issues In Market Research Duane L. Berlin, Esq. General Counsel, CASRO Principal, Lev & Berlin, P.C. PL&B Annual Conference Cambridge, MA 22 August.
The DoubleClick controversy and other related issues pertaining to privacy on the Internet.
Your Trade Mission Certified by the U.S. Department of Commerce Certified Trade Missions offer a proven cooperative approach for putting U.S. businesses.
1 Ethical Issues in Computer Science CSCI 328, Fall 2013 Session 15 Privacy as a Value.
Electronic Marketing: Integrating Electronic Resources into the Marketing Process, 2e 11/5/2015  2004 Joel Reedy and Shauna Schullo Electronic Marketing.
U.S. Department of Commerce Web Advisory Group Minding Your Own Business The Platform for Privacy Preferences Project.
C MU U sable P rivacy and S ecurity Laboratory 1 Privacy Policy, Law and Technology Privacy Self-Regulation and the Privacy Profession.
Sears Privacy Policy & Security information Shaina Lacher.
ECT 455/HCI 513 ECT 4 55/HCI 513 E-Commerce Web Site Engineering Legal Issues.
The Protection of Personal Information Bill 13 February
1 Privacy Lessons from Other Industries Chris Zoladz, CIPP, Vice President, Information Protection Marriott International, President, International Association.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
Protecting Yourself Against Identity Theft A Financial Literacy Presentation by.
SAS No. 70, Service Organizations A standard for reporting on a service organization’s controls affecting user entities' financial statements. Only for.
Consumer Information Federal Trade Commission Act grants Federal Trade Commission (FTC) responsibility regarding unfair methods of competition and unfair.
Regulation models addressing data protection issues in the EU concerning RFID technology Ioannis Iglezakis Assistant Professor in Computers & Law Faculty.
E tail d E tails Primer on Privacy Dana B. Rosenfeld Bureau of Consumer Protection Federal Trade Commission.
"Our vision is to be earth's most customer-centric company; to build a place where people can come to find and discover anything they might want to buy.
Service Organization Control (SOC)
Protecting Your Identity:
Current Privacy Issues That May Affect Your Credit Union
GDPR (General Data Protection Regulation)
The Platform for Privacy Preferences Project
Presentation transcript:

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 1 Privacy Self-Regulation and the Privacy Profession September 18, 2007

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 2 Privacy self-regulation Since 1995, the US FTC has pressured companies to “self regulate” in the privacy area Upcoming FTC town hall on behavioral advertising Self regulation may be completely voluntary or mandatory (or somewhere in between) Self-regulatory programs and initiatives Seals CPOs Privacy policies P3P Industry guidelines

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 3 Voluntary privacy guidelines Direct Marketing Association Privacy Promise dma.org/privacy/privacy_promise.pdf dma.org/privacy/privacy_promise.pdf Network Advertising Initiative Principles CTIA Location-based privacy guidelines Generally Accepted Privacy Principals rally+Accepted+Privacy+Principles/ rally+Accepted+Privacy+Principles/

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 4

5 Chief privacy officers Companies are increasingly appointing CPOs to have a central point of contact for privacy concerns Role of CPO varies in each company Draft privacy policy Respond to customer concerns Educate employees about company privacy policy Review new products and services for compliance with privacy policy Develop new initiatives to keep company out front on privacy issue Monitor pending privacy legislation

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 6 Seal programs TRUSTe – BBBOnline – CPA WebTrust – Japanese Privacy Mark

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 7 Seal program problems Certify only compliance with stated policy Limited ability to detect non-compliance Minimal privacy requirements Don’t address privacy issues that go beyond the web site Nonetheless, reporting requirements are forcing licensees to review their own policies and practices and think carefully before introducing policy changes

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 8 Privacy policies Policies let consumers know about site’s privacy practices Consumers can then decide whether or not practices are acceptable, when to opt-in or opt-out, and who to do business with The presence of privacy policies increases consumer trust What are some problems with privacy policies?

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 9 Privacy policy problems BUT policies are often difficult to understand hard to find take a long time to read change without notice

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 10 There is lots of information to convey -- but policy should be brief and easy-to-read too! What is opt-in? What is opt-out? Privacy policy components Identification of site, scope, contact info Types of information collected Including information about cookies How information is used Conditions under which information might be shared Information about opt-in/opt-out Information about access Information about data retention policies Information about seal programs Security assurances Children’s privacy

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 11 Short Notices Project organized by Hunton & Williams law firm Short version (short notice) of human-readable policy for web and paper Also called a “layered notice” - refer to long notice for more detail Now being called “highlights notice” Focus on reducing privacy policy to at most 7 boxes Standardized format but only limited standardization of language Proponents believe they may eventually be mandated by law A work in progress - not yet in use Alternative proposals from privacy advocates focus on check boxes Interest Internationally Interest in the US for financial privacy notices

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 12 Acme Company Privacy Notice Highlights For more information about our privacy policy, write to: Consumer Department Acme Company 11 Main Street Anywhere, NY Or go to the privacy statement on our website at acme.com. We collect information directly from you and maintain information on your activity with us, including your visits to our website. We obtain information, such as your credit report and demographic and lifestyle information, from other information providers. PERSONAL INFORMATION We use information about you to manage your account and offer you other products and services we think may interest you. We share information about you with our sister companies to offer you products and services. We share information about you with other companies, like insurance companies, to offer you a wider array of jointly-offered products and services. We share information about you with other companies so they can offer you their products and services. USES You may opt out of receiving promotional information from us and our sharing your contact information with other companies. To exercise your choices, call (800) or click on “choice” at ACME.com. YOUR CHOICES You may request information on your billing and payment activities. IMPORTANT INFORMATION HOW TO REACH US This statement applies to Acme Company and several members of the Acme family of companies. SCOPE NY142510v1 5/28/2002 Dated: May 28, 2002 Template prepared by the Notices Project, a program ofthe Center for Information Policy Leadership at Hunton &Williams © 2002 Center for Information Policy Leadership Privacy Notice Highlights Template

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 13 Checkbox proposal WE SHARE [DO NOT SHARE] PERSONAL INFORMATION WITH OTHER WEBSITES OR COMPANIES. Collection: YESNO We collect personal information directly from you   We collect information about you from other sources:   We use cookies on our website   We use web bugs or other invisible collection methods   We install monitoring programs on your computer   Uses: We use information about you to:With YourWithout Your ConsentConsent Send you advertising mail   Send you electronic mail   Call you on the telephone   Sharing: We allow others to use your information to:With YourWithout YourConsent Maintain shared databases about you   Send you advertising mail   Send you electronic mail   Call you on the telephoneN/AN/A Access: You can see and correct {ALL, SOME, NONE} of the information we have about you. Choices: You can opt-out of receiving fromUsAffiliatesThird Parties Advertising mail   Electronic mail   Telemarketing  N/A Retention: We keep your personal data for:{Six Months Three Years Forever} Change:We can change our data use policy {AT ANY TIME, WITH NOTICE TO YOU, ONLY FOR DATA COLLECTED IN THE FUTURE} Source: Robert Gellman, July 3, 2003

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 14 Highlights notice on IBM web site

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 15 Highlights notice on P&G web site

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 16 Is industry self-regulation working? What are the arguments for and against privacy self-regulation? What are the arguments for and against privacy laws?

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 17 IAPP International Association of Privacy Professionals

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 18 Privacy organizations (and organizations that work on privacy issues as part of their larger mission)

Privacy Policy, Law and Technology Carnegie Mellon University Fall 2007 Lorrie Cranor 19 Privacy policy project ch-fa07/policy_project.html ch-fa07/policy_project.html