FTC Testifies On New Framework For Protecting Consumer Privacy

The Federal Trade Commission testified Wednesday before Congress on its new privacy framework, which defines best practices for companies to protect consumer privacy.

Processing Content

The framework also reemphasizes the agency's support for implementing a "Do Not Track" mechanism to allow consumers to control the tracking of their online activities across Web sites. Essentially consumers would be able to choose whether they want to allow sites to collect information about their Internet activity.

FTC Chairman Jon Leibowitz said it is a "decisive moment" for consumer privacy. The testimony before the House Committee on Energy and Commerce Subcommittee on Commerce, Manufacturing, and Trade, outlined the FTC's new privacy report, issued Monday. The report recommends consumers be granted greater access to information about them that is held by data brokers.

"While more work remains to be done on Do Not Track, the Commission believes that the developments to date are significant and provide an effective path forward," the testimony states.

The report, titled "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers," advocates three main principles for protecting consumer privacy.

First, companies should adopt a "privacy by design" approach by building privacy protections into their everyday business practices.

Second, companies should provide simpler and more streamlined choices to consumers about their data practices.

Third, companies, particularly those that don't deal directly with consumers, such as data brokers, should take steps to make their data practices more transparent by, for example, improving their privacy disclosures and giving consumers reasonable access to the data that companies maintain about them. 



The privacy report also recommends that data brokers that compile information for marketing purposes make their operations more transparent by exploring creation of a centralized Web site to identify themselves, and that they disclose how they collect and use consumer data. The Web site would detail the choices that these data brokers provide consumers about their own information.

The FTC recommends Congress consider enacting general privacy legislation, and that it enact data security and breach notification legislation and targeted legislation to address data brokers, the testimony states. It also urges individual companies and self-regulatory bodies to accelerate the adoption of the principles contained in the privacy framework, to the extent they have not already done so.

The testimony describes how the FTC has undertaken substantial efforts to promote privacy in the private sector through education, policy initiatives and enforcement.

Earlier this week, for example, the FTC announced an enforcement action against RockYou, a social media service (see story). RockYou collected information from about 179,000 children without obtaining the required parental consent under the Children's Online Privacy Protection (COPPA) Rule.  

The FTC is in the midst of a review of COPPA because of rapidly evolving technology and changes in the way children use and access the Internet. The agency hosted a workshop in December 2011 exploring facial recognition technology and the privacy and security implications raised by its increasing use.

Also, according to the testimony, the FTC intends to examine the practices of large platforms – such as Internet browser companies, mobile operating system providers, Internet service providers, and social media services – that can collect data from across the Internet to build extensive profiles about consumers.

FTC staff will host a workshop in the second half of 2012 to examine questions about the scope of such data collection practices, the potential uses of the collected data and related issues.


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More