TRUSTes EU Safe Harbor Seal Program Compliance and Enforcement Update Conference on Cross-Border Data Flows & Privacy October 15-16, 2007 Martha K. Landesberg.

Slides:



Advertisements
Similar presentations
Damon Greer Safe Harbor Program October 15, 2007
Advertisements

Privacy and the Internet Professor Peter P. Swire Ohio State University National Press Foundation February 14, 2001.
EU Privacy Directive. What is a directive? A piece of European legislation, passed by bureaucrats, addressed to member states Member states must ensure.
REQ Enrollment in Demand Response Programs Process Flow Engineering Firm Retail Customer Demand Response Service Provider (DRSP) Distribution Company.
1 1 Medicare Marketing Danielle R. Moon, J.D., M.P.A. Director, Medicare Drug & Health Plan Contract Administration Group National Association of Health.
Yukiko Ko Binding Corporate Rules – Global Implications Conference on Cross Border Data Flows and Privacy October 16, 2007.
606 CMR 14.00: Background Record Checks What you need to know!
IBM Corporate Environmental Affairs and Product Safety
EMS Checklist (ISO model)
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL DATA PROTECTION AND PRIVACY COMMISSIONERS.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
Checking & Corrective Action
Copyright 2007 Thomson South-Western Chapter 7 Buying Decisions.
The EU self-regulation of online behavioural advertising May 2014.
Offsite Storage RAF/2013/00023 Compulsory Briefing Session 16 August 2013 The Road Accident Fund.
Top 10 Checklist to Protect Your Personal Privacy Online Teens 1.
Advancing Trust Together. The Birth of BBB BBB Accredited Businesses… > Build Trust > Advertise Honestly > Tell the Truth > Are Transparent > Honor.
Page 1 AT&T Billing Solutions Anti-Cramming Policy Overview May 11, 2011.
NARUC/NIGERIA REGULATORY PARTNERSHIP Peer Review Presented by Elijah Abinah Assistant Director Public Utilities Division Arizona Corporation Commission.
Silicon Valley Apps for Kids Meetup Laura D. Berger October 22, 2012 The views expressed herein are those of the speaker, and do not represent the views.
29e CONFÉRENCE INTERNATIONALE DES COMMISSAIRES À LA PROTECTION DES DONNÉES ET DE LA VIE PRIVÉE 29 th INTERNATIONAL CONFERENCE OF DATA PROTECTION AND PRIVACY.
The Internet industry’s privacy seal program Silicon Valley Web Guild.
Self-Regulatory Approaches to Cross-Border Transfers of Personal Data: The APEC Experience The Privacy Symposium August 2007 Fran Maier Executive Director,
1 The End Of The Privacy Policy As We Know It Fran Maier President TRUSTe.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
Privacy as an International Information Issue MD823 October 18, 2004.
SEMINAR NAIC/ASSAL/SVS REGULATION & SUPERVISION OF MARKET CONDUCT © 2014 National Association of Insurance Commissioners Complaint Handling.
TS16949 requirements Subjects –Audit planning –Recertification audit requirements –Auditing Remote supporting functions.
Per Anders Eriksson
The U.S.-E.U. Safe Harbor Framework The U.S.-E.U. Safe Harbor Framework New Developments in Data Flows, Standards, & Compliance Damon Greer U.S. Department.
Transborder dataflows Flow of information across national borders Much of this data involves personal information.
Protecting information rights –­ advancing information policy Privacy law reform for APP entities (organisations)
A SOUND INVESTMENT IN SUCCESSFUL VR OUTCOMES FINANCIAL MANAGEMENT FINANCIAL MANAGEMENT.
Carmichael Centre for Voluntary Groups Implementing the Guiding Principles for Fundraising Sheila Nordon Executive Director 9 th November 2010.
House Committee on Business and Industry House Bill Implementation of Closed Account Notification System Texas Department of Banking April 22, 2008.
1 Click to Check Public FTAA.ecom/inf/122 February 13, 2002 Original: English.
1 SAFE HARBOR FRAMEWORK Barbara S. Wellbery Morrison & Foerster LLP 2000 Pennsylvania Avenue Washington, DC /
E-commerce Vocabulary Terms. E-commerce Buying and selling of goods, services, or information via World Wide Web, , or other pathways on the Internet.
1 April 2014 EU Consumer Summit 2014 Study on online hotel reviews Tobe Nwaogu Principal Consultant.
11 The OAS-ODR Proposal: Functional Case Flows Colin Rule Director of Online Dispute Resolution, PayPal UNCITRAL ODR Meeting Vienna March 30, 2010.
Delivering transparency, choice and control for European citizens.
2006 SISO Executive Conference Legal Issues in Using Mailing Lists: The CAN-SPAM ACT The Junk Fax Prevention Act The National Do Not Call Registry.
Privacy in computing Material/text on the slides from Chapter 10 Textbook: Pfleeger.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
What are the rules? Information technology is available to every student, faculty and staff member in support of the essential mission of the University.
The Basics of the Effort Certification and Reporting Technology (ECRT) System.
Avoid Disputes, Not Complaints Presented by: Stuart Ayres and Derek Pullen Stuart Ayres, Scheme Manager Derek Pullen, Scheme Adjudicator.
Privacy Advisory Services … … A Best Practices, Integrated Approach Insert Firm Name Here.
1 Copyright © International Security, Trust & Privacy Alliance -All Rights Reserved Making Privacy Operational International Security, Trust.
Essentials Of Business Law Chapter 27 Conducting Business In Cyberspace McGraw-Hill/Irwin Copyright © 2007 The McGraw-Hill Companies, Inc. All rights reserved.
May l Washington, DC l Omni Shoreham Web Hosting Potentials and Pitfalls David Snead Attorney W. David Snead, P.C.
Protecting Yourself from Fraud including Identity Theft Personal Finance.
Civil Rights in the Child Care Food Program (CCFP) Updated
Introduction: Introduction: As technology advances, we have cheaper and easier ways to stay connected to the world around us. We are able to order almost.
Purchasing Cards. What is a Purchasing Card? It is a type of commercial credit card, used by organizations for payment of goods and services. This tool.
Yes, it’s the holidays... A time of joy, a time of good cheer, a time of celebration... From the Office of the Chief Human Capital Officer (CHCO ) Privacy.
Presented by: David Reid, DBA International
Data Minimization Framework
APP entities (organisations)
Current Privacy Issues That May Affect Your Credit Union
NORTHEASTERNERS, INC. IRS 990 filing instructions presentation
activistpost Being connected to the largest information.
GDPR (General Data Protection Regulation)
Protecting Yourself from Fraud including Identity Theft
Protecting Yourself from Fraud including Identity Theft
Presentation to The Fourth National HIPAA Summit
CA Transperancy in Supply Chains Act
Protecting Yourself from Fraud including Identity Theft
in the Child Care Food Program (CCFP)
Anatomy of a Common Cyber Attack
Presentation transcript:

TRUSTes EU Safe Harbor Seal Program Compliance and Enforcement Update Conference on Cross-Border Data Flows & Privacy October 15-16, 2007 Martha K. Landesberg Director of Policy and Counsel, TRUSTe

About TRUSTe Independent non-profit headquartered in San Francisco Mission: Advancing Privacy and Trust for the Networked World –Build on widely-accepted privacy best practices –Elevate responsible players –Help consumers identify who they can trust –Supplement legislation and regulation –Address emerging privacy vulnerabilities and threats Celebrating 10 th Anniversary

TRUSTe: 10 Years of Impact Web Privacy Seal –2,400 Websites –1,500 companies –22 of Top 50 most visited websites –1 Million click-to-verify pageviews monthly –Thousands of consumer complaints resolved annually EU Safe Harbor Seal by authority of the US Department of Commerce Childrens Online Privacy Protection Act Safe Harbor by authority of the US Federal Trade Association Privacy Seal beyond legal requirements for legitimate mail Trusted Download Program (beta) –Certifying consumer downloadable software (not Spyware)

TRUSTe E.U. Safe Harbor Seal Program Launched in licensees with 317 websites 14 new Sealholders in 2007 Millions of consumers Notable EU Sealholders: Adobe Systems Audible Apple Computer Best Buy Carlson Companies Facebook Harris Interactive Logitech McAfee, Inc. Microsoft Monster Oracle Sybase Verisign

TRUSTe International Services Foreign language privacy statement translation is certified by TRUSTe Click to Verify seal on certified privacy statement links to validation page in foreign language Watchdog Dispute Resolution services provided in languages other than English

TRUSTe EU Safe Harbor Program Certification Process Improves Licensee Practices 1.Online Application 2.Enforceable Contract 3.Payment 4.Strong Commitment Over 90% required to make changes to business practices –Notice at Point of Collection –Privacy Policy disclosures esp. cookies and third-party sharing –HTTPS for sensitive data (e.g. credit card)

TRUSTe EU Safe Harbor Program Certification Process 1.Strict Standards Incorporate all Safe Harbor Privacy Principles 2.Self-Assessment + Rigorous TRUSTe Review Web Site Audit Access Reputation and other data Revision of policy and practice 3.Transparent Privacy Statement -Sealholder states adherence to Principles -Clear notice of complaint mechanism 4.Seals Awarded and Displayed 5.Ongoing Monitoring & Dispute Resolution 6.Annual Recertification Required

TRUSTe Privacy Seal Certification Prospective sealholder submits completed 67-question self-assessment to TRUSTe TRUSTe reviews the prospective member's website, privacy practices and privacy statement against our program requirements TRUSTe team delivers a Site Findings Report (SFR) to the prospective member with required changes for improvement and compliance with program requirements Prospective member makes necessary corrections to comply with TRUSTe program requirements TRUSTe Compliance team does quality check of prospective members Web site and practices against TRUSTe program requirements TRUSTe issues license to display seal New member implements TRUSTe seals per TRUSTe seal implementation requirements TRUSTe monitors members website for proper implementation throughout the year TRUSTe checks compliance with new requirements and regulations during recertification

TRUSTe Validation Page Foreign language privacy statement translation is certified by TRUSTe Click to Verify seal on certified privacy statement links to validation page in foreign language

Evaluate websites from many angles: proactive and reactive approach Ongoing Monitoring Technological scans seeding Reputation monitoring Ongoing reviews Watchdog monitoring Other reviews of blogs, press, consumer postings Approximately 50% of scans discover problems

TRUSTe E.U. Safe Harbor Seal Program Watchdog Dispute Resolution Online independent recourse mechanism Free of charge to consumers Easy-to-use online form Transparent, fair and equitable Complaints for offline data can be submitted by mail or fax

TRUSTe Watchdog Complaints We receive complaints of all sorts per year –Resolve privacy complaints –Forward non-privacy issues to sealholder as a courtesy –Refer out-of-scope complaints to appropriate resources We work with consumer and sealholder to resolve issues Complaints provide critical input to monitoring process We also offer self help through web site and newsletters Note: for all TRUSTe Watchdog Complaints

TRUSTe EU Safe Harbor Program Complaints from EU Citizens 200 Privacy Complaints in past 12 months –All resolved –Typical issues: Spam Cant unsubscribe Cant close account Unauthorized sharing with third parties –New issue trends: Phishing Spyware Unauthorized profile posted Access: unable to correct personal information

Consumer files complaint with the TRUSTe Watchdog Dispute Resolution Program watchdog_complaint.php TRUSTe reviews all complaints for jurisdiction and responds to consumer within five (5) business days TRUSTe forwards complaint to TRUSTe licensee who is required to respond within five (5) business days Licensee provides restitution to consumer directly or via TRUSTe at consumer request Consumer is given 10 business days to accept or reject proposed restitution When consumer responds, TRUSTe mediates resolution satisfying both consumer and licensee and then TRUSTe closes the complaint record When consumer does not respond, TRUSTe considers the resolution accepted and closes the complaint record Steps to Resolve a Watchdog Complaint Working with Consumer and Sealholder to reach satisfactory resolution

Types of Investigations Process (65%): –Unsubscribe me –Close account –Cant reach licensee Technical (20%): –Interface disclosures –TRUSTe seeding of client lists to check unsub link, unauthorized third-party mail Privacy Statement Analysis (14%): –Notice about data sharing, cookies etc. Legal/Policy Analysis: –Legal status of unusual business models or practices –Potentially deceptive notice May be triggered by Watchdog complaints or on TRUSTe initiative

Severity Scorecard: Early Warning System Used to analyze Watchdog complaints by company and provide early warning Weighting helps assess: –severity of complaint(s) –trends in complaint type –trends in complaint volume Color/letter process map reflect: type of follow-up and sealholder changes required: –type of investigation –privacy policy change –notice at opt-in –type of information collected –data spill assistance to Licensee –level of escalation within TRUSTe TRUSTe Watchdog Diagnosis (Complaints per Month) Increasing Offenses weight ed score 123+ Unable to unsubscribeDEG Unauthorized profile with my information DEG Unwanted DEG Excessive DEG sent without permissionDEG Unable to close accountDEG Unable to change/delete personal information DEG Shared personal informationABC Violated privacy policyABC Unable to contact licenseeABC Children's information (under 13)ABC Inconsistent Unsubscribe Instructions ABC Inaccurate Disclosure: POCABC Inaccurate Disclosure: PSABC

Enforcement Options Suspend Certification –Notified on Verification Page –Seal still on Website –Timeframe for Resolution Terminate –Termination for Convenience (non-public) - other issues not directly related to contract and/or reputation issues –Terminate and Rehabilitate –Termination for Cause (publish on website) –Terminate and refer case to law enforcement/regulators Process must be transparent, consistent, fair, and lead to positive consumer outcomes –Usually result in company coming back into compliance Independent Non-Profit Status Important

Compliance and Enforcement Toolbox Certification: –90% improve practices Watchdog Dispute Resolution –100% resolution –Small # of terminations Proactively monitor –Scanning – Seeding Enforcement Options –Decline to Recertify –Suspend –Terminate

Safe Harbor is Working Licensees demonstrate their ongoing commitment to Safe Harbor Privacy Principles Keeping companies compliant is a win-win for consumers and marketplace Measure of success: number of companies that have made commitment and are staying compliant Referral to FTC has not been necessary – a testament to our sealholders commitment

Contact Information Martha Landesberg Director of Policy and Counsel TRUSTe 1750 K Street, Suite 1229 Washington, DC