“Internet” and “Operator” (COPPA Statute) InternetOperator Collectively the myriad of computer and telecommunications facilities, including equipment.

Slides:



Advertisements
Similar presentations
/0403 © 2004 Business & Legal Reports, Inc. BLRs Training Presentations Privacy Issues in the Workplace.
Advertisements

Family Educational Rights and Privacy Act (FERPA) Basics For Faculty and Staff.
PRIVACY CONSIDERATIONS Privacy for Children Under 13 1 February 2013.
Department of Highway Safety and Motor Vehicles Driver Privacy Protection Act.
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA – Privacy Rule and Research USCRF Research Educational Series March 19, 2003.
Increasing public concern about loss of privacy Broad availability of information stored and exchanged in electronic format Concerns about genetic information.
National Cancer Institute Cancer Therapy Evaluation Program (CTEP) presents: How to Obtain Protected Health Information (PHI) from an Outside Healthcare.
HIPAA Health Insurance Portability and Accountability Act.
1 HIPAA Education CCAC Professional Development Training September 2006 CCAC Professional Development Training September 2006.
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
Health Insurance Portability Accountability Act of 1996 HIPAA for Researchers: IRB Related Issues HSC USC IRB.
Silicon Valley Apps for Kids Meetup Laura D. Berger October 22, 2012 The views expressed herein are those of the speaker, and do not represent the views.
1 Office of the General Counsel FERPA  Family Educational Rights and Privacy Act (20 U.S.C § 1232g)
FERPA: WHAT YOU SHOULD KNOW ILASFAA April 18, 2008 Amy Perrin Director of Financial Aid Elgin Community College.
Family Educational Rights and Privacy Act What you need to know...
MINNESOTA GOVERNMENT DATA PRACTICES ACT How the law affects University employees and recordkeeping Susan McKinney Records & Information Management.
Phoenix Union High School District Governing Board Policy In-Service Technology Usage Electronic Information System (EIS) 2014/2015 School Year.
2/16/2010 The Family Educational Records and Privacy Act.
1 Children and Families. 2 Children & Families Focus on the Internet Children’s Needs –Education –Entertainment Families’ Needs –Education –Protection.
INTERNET and CODE OF CONDUCT
Office of Safe and Drug-Free Schools Advisory Committee Meeting February 21, 2007.
Tina Kraigher and Milena Podjed-Fabjančič 18 April 2010 Processing of Telephone Traffic Data of Employees ( a Case Study )
How It Applies In A Virtual World
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
HIPAA PRIVACY AND SECURITY AWARENESS.
HIPAA Business Associates Leadership Group Meeting June 28, 2001.
Indiana’s Access to Public Records Act Heather Willis Neal Public Access Counselor City and Town Court Conference City and Town Court Conference October.
Confidentiality, Consents and Disclosure Recent Legal Changes and Current Issues Presented by Pam Beach, Attorney at Law.
Acceptable Use Policies, Online Safety, and Photo Permission Forms Elizabeth White Tara Dykes Julie Howe.
Class 6 Internet Privacy Law Social Media Privacy.
Adam Soph, Alexandra Smith, Landon Peterson. Phishing is a way of attempting to acquire information such as usernames, passwords, and credit card details.
Arkansas State Law Which Governs Sensitive Information…… Part 3B
Federal Trade Commission required to issue and enforce regulations concerning children’s online privacy. Initial COPPA Rule effective April 21, 2000;
Data Protection Compliance Professor Ian Walden Institute of Computer and Communications Law, Centre for Commercial Law Studies, Queen Mary, University.
 Why is this important to you?  How do digital footprints connect with digital citizenship?  Does everyone have a digital footprint?
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
CONFIDENTIALITY TRAINING FOR CALLOWAY COUNTY SCHOOLS VOLUNTEERS SCHOOL YEAR
CYBERLAW Cyberlaw Meets Family Law: The Children’s Online Privacy Protection Act of 1998 (COPPA) Class of Nov. 11, 2002 Professor Susanna Fischer.
FAMIS CONFERENCE Mari M. Presley, Assistant General Counsel Florida Department of Education June 12, 2012.
LAW OF COMPUTER TECHNOLOGY FALL 2015 © 2015 MICHAEL I. SHAMOS Regulatory Law Michael I. Shamos, Ph.D., J.D. Institute for Software Research School of.
Can We Keep Our Kids Safe on the Internet? By Kim Hollingsworth - ETEC 562.
Indiana’s Public Access Laws Heather Willis Neal Indiana Public Access Counselor Columbus Police Department August 18, 2009.
Elected Officials and Health Department Records Indiana Public Health Foundation February 27, 2008.
INTERNET SAFETY Sergeant Karl Youngblood Barbara Burchard Information adapted from the
Indiana’s Access to Public Records Act Heather Willis Neal Public Access Counselor Brownsburg Police Department Brownsburg Police Department February 26,
CIPA (Children’s Internet Protection Act) Helping You Succeed Schools and Libraries Division Washington, DC Newark Atlanta Chicago Orlando.
Sharing Information (FERPA) FY07 REMS Initial Grantee Meeting December 5, 2007, San Diego, CA U.S. Department of Education, Office of Safe and Drug-Free.
CONFIDENTIALITY TRAINING FOR CALLOWAY COUNTY SCHOOLS VOLUNTEERS SCHOOL YEAR
An Overview of Legislation and Board Policy. Federal Legislation (CIPA, COPPA) WCPSS Board of Education ◦ Policy 2313, 3013, and 4013 Federally Mandated.
Indiana’s Public Access Laws Heather Willis Neal Indiana Public Access Counselor Indiana Association of Cities and Towns Red Flag and Sunshine Workshop.
COPPA: CHILDREN'S PRIVACY, YOUR GAME, AND THE CHANGING ONLINE LANDSCAPE MONA IBRAHIM SENIOR ASSOCIATE INTERACTIVE ENTERTAINMENT LAW GROUP
“Kids First, New Mexico Wins!” NMPED Data Conference Spring 2016 Dan Hill General Counsel, Public Education Department Randi Johnson General Counsel, State.
Final HIPAA Privacy Rule: The Research Provisions Julie Kaneshiro DHHS Office for Human Research Protections Phone: Fax:
Visibook is instant, simple, and dynamic appointment booking We're headquartered in San Francisco, California "Visibook is awesome. My entire studio was.
Somerset ISD Online Acceptable Use Policy. Somerset Independent School District Electronic Resources Acceptable Use Policy The purpose of this training.
FERPA Family Educational Rights and Privacy Act
Silicon Valley Apps for Kids: COPPA BASICS
Final Amended COPPA Rule
Emily Snyder, William Darras, Stephanie Berger
A Parent Guide to creating a student (under 13) Apple ID
Teaching Internet Safety
PERSONAL DATA PROTECTION ACT 2010
Family Education Rights and Privacy Act
Family Educational Rights & Privacy Act (FERPA)
Identity Theft Prevention Program Training
Government Data Practices & Open Meeting Law Overview
Government Data Practices & Open Meeting Law Overview
LEGAL OVERVIEW Board Governance
Confidentiality Training 2014
Presentation transcript:

“Internet” and “Operator” (COPPA Statute) InternetOperator Collectively the myriad of computer and telecommunications facilities, including equipment and operating software, which comprise the interconnected world-wide network of networks that employ the TCP/ IP, or any predecessor or successor protocols to such protocol, to communicate information of all kinds by wire or radio. Any person who operates a website located on the Internet or an online service and who collects or maintains personal information from or about the users of or visitors to such website or online service, or on whose behalf such information is collected or maintained...

It is unlawful for an operator of a website or online service directed to children, or any operator that has actual knowledge that it is collecting personal information from a child, to collect personal information from a child in a manner that violates the [COPPA Rule]. “Actual Knowledge” (COPPA Statute)

Individually identifiable information about an individual collected online, including: (a)A first and last name (b)A home or other physical address including street name and name of a city or town (c)An address or other online contact information, including but not limited to an instant messaging user identifier, or a screen name that reveals an individual’s address ** (d)A telephone number (e)A Social Security number (f)A persistent identifier, such as a customer number held in a cookie or a processor serial number, where such identifier is associated with individually identifiable information; or a combination of a last name or photograph of the individual with other information such that the combination permits physical or online contacting ** (g)Information concerning the child or the parents of that child that the website collects online from the child and combines with an identifier described in this definition ** COPPA statute permits the FTC to include “any other identifier that the Commission determines permits the physical or online contacting of a specific individual.” “Personal Information” (COPPA Rule)

Verified Parental Consent (COPPA Rule) General Standard: Methods that satisfy the Rule: Operators must make reasonable efforts to obtain verifiable parental consent, taking into consideration available technology. Any method to obtain verifiable parental consent must be reasonably calculated, in light of available technology, to ensure that the person providing consent is the child’s parent. (1) providing a consent form to be signed by the parent and returned to the operator by postal mail or facsimile (or scan) (2) requiring a parent to use a credit card in connection with a transaction (3) having a parent call a toll-free telephone number staffed by trained personnel (4) using a digital certificate that uses public key technology (5) using accompanied by a PIN or password obtained through one of the listed verification methods (6) “ plus” (for non-disclosures)

Exceptions to Parental Consent (COPPA Statute and Rule) No prior consent needed where the operator collects: (1) Name or online contact information of a parent or child to be used for the sole purpose of obtaining parental consent or providing notice. The operator must delete such information from its records if it has not obtained parental consent after a reasonable time from the date of the information collection. (2) Online contact information for the sole purpose of responding directly on a one-time basis to a specific request from the child, and where such information is not used to re-contact the child and is deleted by the operator from its records. (3) Online contact information to be used to respond directly more than once to a specific request from the child, and where such information is not used for any other purpose. The operator must make reasonable efforts, taking into consideration available technology, to ensure that a parent receives notice and has the opportunity to request that the operator make no further use of the information, immediately after the initial response and before making any additional response to the child. Mechanisms to provide such notice include, but are not limited to, sending the notice by postal mail or sending the notice to the parent’s address, but do not include asking a child to print a notice form or sending an to the child. (4) Child’s name and online contact information to the extent reasonably necessary to protect the safety of a child participant on the website or online service, and the operator uses reasonable efforts to provide a parent notice, where such information is used for the sole purpose of protecting the child’s safety, not used to re-contact the child or for any other purpose, and not disclosed on the website or online service. (5) Child’s name and online contact information and such information is not used for any other purpose, to the extent reasonably necessary: (i) to protect the security or integrity of its website or online service; (ii) to take precautions against liability; (iii) to respond to judicial process; or (iv) to the extent permitted under other provisions of law, to provide information to law enforcement agencies or for an investigation on a matter related to public safety.

Collection and Disclosure Disclosure (Statute)Collection (Rule) The term "disclosure" means, with respect to personal information— (A)The release of personal information collected from a child in identifiable form by an operator for any purpose, except where such information is provided to a person other than the operator who provides support for the internal operations of the website and does not disclose or use that information for any other purpose; and (B) Making personal information collected from a child by a website or online service directed to children or with actual knowledge that such information was collected from a child, publicly available in identifiable form, by any means including by a public posting, through the Internet, or through— (i) a home page of a website; (ii) a pen pal service; (iii) an electronic mail service; (iv) a message board; or (v) a chat room. Collects or collection means the gathering of any personal information from a child by any means, including but not limited to: (a)Requesting that children submit personal information online; (b)Enabling children to make personal information publicly available through a chat room, message board, or other means, except where the operator deletes all individually identifiable information from postings by children before they are made public, and also deletes such information from the operator’s records; or (c) The passive tracking or use of any identifying code linked to an individual, such as a cookie.