In the popular television program Sing Along with Mitch, the late Mitch Miller encouraged his audience to sing along as a “bouncing ball” kept rhythm with the lyrics scrolling across the screen. “Follow the bouncing ball” became a popular mantra that was used in many television programs over the years to keep viewers in sync with the program.
Fast-forward to the age of iTunes, cloud computing, and ecommerce. The digital age has spawned an explosion in data creation, collection, storage, and analysis. To stay in sync with the new digital world, businesses of all sizes must now keep their eyes on a different ball – data. To understand your market, your competitors, and your customers, a business owner must “follow the data.”
Below are several legal developments in data privacy law from 2012 that may affect your business:
Significant rules apply to the collection of personal data from the European Union: On Jan. 25, 2012, the European Commission proposed an overhaul of its data-protection rules. These rules will apply to U.S.-based companies that collect the personal information of residents located in the European Union. Examples of new provisions include a requirement that service providers delete personal information if it is no longer needed by the company; a mandate that corporations assist customers in the transfer of information to a new service provider; a condition that users must now opt-in to cookies and customer-tracking data before that data can be used; and a new rule holding website operators accountable for third-party dissemination of personal information that an individual has requested be removed from the operator’s database. In the event of noncompliance, the new rules allow for assessment of fines of up to 2% of the annual worldwide gross revenues of the offending company.
Beware of new rules governing data from mobile applications: California Attorney General Kamala Harris recently released recommendations for mobile carriers, mobile device application (app) developers, app platform providers, and mobile ad networks to minimize consumers’ confusion regarding the accessibility of their private information. The recommendations focus on increased transparency of procedures, development of easy-to-understand policies, collecting as little information as possible, and making the highest level of protection possible part of the default settings of newly developed apps. While many of these recommendations reach beyond current laws, Harris’ goal is to balance the protection of personally identifiable information with the growth of an emerging mobile app industry, especially in California.
Use extra caution in collecting data from children: Through adjustments to the Children’s Online Privacy Protection Act (COPPA) that will take effect on July 1, the federal government is also working to protect the online privacy of children while encouraging new technological development. The changes give parents greater control over their children’s personal information by expanding several key terms, closing loopholes, and extending liability to third parties. For example, the definition of “personal information” under COPPA has expanded, and now includes geolocation information; photos, video, and audio files that contain a child’s voice or image; and data that is used to recognize users across different websites, like IP addresses and mobile device IDs.
Violations will lead to more class-action lawsuits: In September 2012, the U.S. Court of Appeals for the 11th Circuit held that clients of a health insurance company were harmed when unencrypted laptops were stolen, even if no personal data was actually accessed, because the clients paid premiums to the company to keep their data secure (Resnick v. AvMed, Inc.). The combination of class-action suits involving potentially millions of people and a specified amount of damages per plaintiff allowed by privacy statutes has the potential to raise awards for privacy suits into the billions.
How to protect your business
Every company should have a data security plan in place. Plans should appoint data privacy officers, evaluate current use of consent in company-gathered personal information, and audit how and where data is used or transferred, in addition to noting how to respond to a breach and how to update practices in response to changing privacy laws.
Emerging data privacy laws will affect every business, especially if the business’s online content is mobile-accessible, is targeted toward children, or involves third-party advertisers. Further, American companies that transfer personal data from Europe to the United States, who target European consumers, or whose online presence is accessed by Europeans may also be responsible for ensuring compliance with the new EU rules.
Attorney Andrew J. Schlidt is a shareholder with the law firm Whyte Hirschboeck Dudek S.C., where he is co-chair of the firm’s Corporate Practice Group and is leader of the Technology Law Team. Ariane C. Strombom, a law clerk at WHD and a law student at Marquette University, assisted with this article.
Sign up for the free IB Update – your weekly resource for local business news, analysis, voices, and the names you need to know. Click here. If you are not already a subscriber to In Business magazine, be sure to sign up for our monthly print edition here.
