Tuesday, February 19, 2013

Privacy

Shore Up Your Privacy Policy Before Disaster Strikes A typical Privacy Policy may state that the website will not use any PII without the user's express permission. The FTC will enforce that obligation if it learns that PII is being used without permission, such as to commercialize it. But if the website's Privacy Policy is silent about protecting PII, then the website may use the PII freely. Last month, I discussed, from the website owner's point of view, the critical importance of using Terms of Service (ToS) and Click Agreements suited to their business. Now I will address the need for appropriate consideration of your website's Privacy Policy. What Type of Information Do Privacy Policies Protect? Personally Identifiable Information (PII) may include many details such as name, address, email address, phone numbers, social security numbers, credit card numbers and the like. From a technology standpoint, every visitor to every website provides some PII about who they are and where they came from. When a visitor lands on a website, this is what the website owner can access: • the visitor's unique IP (Internet Protocol) address; • PII about the last website the visitor accessed; and • information from cookies it left on the visitor's hard drive from a previous visit to the site, perhaps including credit card information and passwords (usually encrypted). In addition, website visitors provide PII voluntarily when they register as users on sites such as Facebook and LinkedIn or for services like Gmail. Also, visitors provide credit or debit card information to facilitate website purchases. The critical issue about this volume of information presented to the website from the visitor is how that information is protected and what privacy the visitor is afforded. Website Privacy Regulation In the U.S., the Federal Trade Commission (FTC) regulates Internet privacy. Currently, the FTC does not require that websites have a Privacy Policy. However, if a website does have a Privacy Policy, it must adhere to its own terms. A typical Privacy Policy may state that the website will not use any PII without the user's express permission. The FTC will enforce that obligation if it learns that PII is being used without permission, such as to commercialize it. But if the website's Privacy Policy is silent about protecting PII, then the website may use the PII freely. Outside the U.S., privacy rules are very different. In the EU, Canada and Japan, for instance, there are very specific laws to restrict the use of PII on any computer, whether connected to the Internet or not. In Canada, the Personal Information Protection and Electronic Documents Act specifies the "...ground rules for how private sector organizations may collect, use or disclose personal information in the course of commercial activities. The law gives individuals the right to access and request correction of the personal information these organizations may have collected about them." In Japan the Personal Information Protection Act was enacted after conducting public surveys regarding privacy protection for individuals. The EU 1995 Data Directive (which started in 1989, in the pre-Internet era) regulates privacy for citizens and businesses that operate in the EU. The U.S. Department of Commerce established Safe Harbor rules that allow U.S. businesses to operate in compliance with the EU laws, so if your website allows users to conduct business with it in the EU, it makes sense to be in compliance under the Safe Harbor rules . TRUSTe (discussed in greater detail below) offers a specific service called EU Safe Harbor, which includes the following: TRUSTe can help you certify your compliance with the EU Directive on Data Protection. The Directive prohibits the transfer of European citizens' personal data to non-European Union nations that do not meet the EU's "adequacy" standard for privacy protection. Of course other companies offer similar EU services. What Should Your Privacy Policy Contain? Like ToS and Click Agreements, my informal surveys show that few individuals, at least in the U.S., take the time to review Privacy Policies. But that doesn't mean you should not have one. You have to consider your visitors' expectations, business issues and laws in countries where you operate. One approach to create your company's Privacy Policy is to find a website you think has similar issues to your own, and use that as a base for your company's policy (but you should be careful to not violate copyright laws when doing so). This might work, but if you guess wrong about what the Privacy Policy should be, your business may be a risk. Aggregate Data Many Privacy Policies say that they will not use visitor PII, but the website may aggregate visitor information for resale. Such information may include the percentage of visitors to the website who came from Google (Nasdaq: GOOG) or The New York Times (NYSE: NYT). The largest company in the data aggregation business is DoubleClick, which was purchased by Google a few years ago. Most website visitors do not feel that their privacy is violated by such aggregation since PII that is specifically identifiable is not being shared, but even where the law doesn't require disclosure, you should consider -- based on business reasons -- whether your Privacy Policy should let website visitors know whether your website aggregates such information. Consider Subscribing to Privacy Standards A number organizations promulgate Privacy Standards. Website owners may subscribe, pay a fee, and agree to adhere to the Privacy Standards of that organization. You often see the logos for these Privacy Standards on the front page of websites and embedded in Privacy Policies. You may be familiar with the TRUSTe logo. Since 1997, that company has offered a variety of online privacy services. This is what TRUSTe has to say about its services: The company offers a broad suite of privacy services to help businesses build trust and increase engagement across all of their online channels including websites, mobile applications, advertising, cloud services, business analytics and email marketing... Based upon the comprehensive privacy model of "Truth in Privacy," which is laid on a foundation of transparency, choice and accountability regarding the collection and use of personal information, TRUSTe's privacy seal is recognized and trusted by millions of consumers as a sign of responsible privacy practices. TRUSTe claims that more than 4,000 websites subscribe, including "...top companies like Apple (Nasdaq: AAPL), AT&T (NYSE: T), Disney (NYSE: DIS), eBay (Nasdaq: EBAY), Facebook, HP (NYSE: HPQ), Microsoft (Nasdaq: MSFT), Nationwide and Yelp." Among many services, TRUSTe offers website solutions for website privacy, EU Sage Harbor, Children's Privacy, Email Privacy, and downloads. Of course there are other Privacy Standards like those of the Better Business Bureau, which claims that more than 142,000 websites use its Privacy Standards, and also the Online Privacy Alliance and the CPA WebTrust Program. In Conclusion Website owners should make sure their Privacy Policies satisfy applicable legal requirements and also address business concerns, so as to give the website visitors comfort that PII will not be used wrongfully. Therefore, it is critical that each business review how it manages PII, and consider what it tells visitors to the website. Question: Is a policy important to your website? Discuss what you will do to incorporate a policy. Due Friday, February 22, 2013

8 comments:

  1. A policy is not important to my website, as there is no personal information withdrawn from the user. Although, my website will be linked to eBay, and will utilize thier policies, as well as Paypal for the payment process. eBay's policies incorporate rules for sellers and buyers to follow so eBay can protect their cusotmers and themselves. This also includes agreements when purchasing items. Paypal's policies incorporate privacy concerns to protect your personal and financial account information. Paypal's privacy policies are very important to users, and after years in business Paypal has gained that trust from millions of customers today.

    ReplyDelete
  2. Privacy policies over internet-based business are important for both the consumer and the business itself. To the consumer, this is a guarantee that their information is being protected and for the business, this creates the trust that you need with your clientele to establish the business.
    At U-Cakes, people will want to know that their payment methods are safe. This will be done through a link at the bottom of the web page and also shown again on the order page with a link to a full dislosure of the PIPEDA-complied policy that we have set forth in our business model. With this privacy policy agreement, we will also have contact information available so the client may be in touch with someone if they feel their privacy has been violated.
    At the bottom of the webpage,a Truste logo will be placed. This company will be in charge of our privacy policy for both the internet and mobile apps. I have chosen to go with this company becuase they inspect our policy to see if it matches our business and it used by many popular websites already, such as Oracle.

    ReplyDelete
  3. I believe that a policy is important because it gives the site a professional image. It gives the customers who are online shoppers a feeling of security. Furthermore, it ensures the private information of the customers will remain private. Certain guidelines must be made when creating a privacy policy. However looking at my business, a policy is not an important aspect to the business since there is not really any specific or personal/private information being shared. Although, my website will be linked to PayPal when doing the payment for the product the customer has purchased online. Therefore, my business will be following up with PayPal's privacy policy for the payment process.

    PayPal's policies incorporates terms and conditions that apply to users who uses their service. It ensures security protection on users personal information such as financial account as they will need to give their credit card information to proceed with the payment process.

    ReplyDelete
  4. Websites that are subscribed to privacy policies like TRUSTe always look more trustworthy and viable, and make you feel better about being on that site. Although I don't really think my site would need one because the only form of online transactions I'm using is PayPal (who looks after their own security), but it wouldn't hurt to state a brief policy to make customers feel safe and ensure their information won't be used wrongfully.

    ReplyDelete
  5. For my website, i will have a privacy policy in place to protect my consumers information, as i want them to be able to feel safe and that their information is protected and used for our use only. So to make sure of this i will use TRUSTe.

    ReplyDelete
  6. For my website i will be using Paypal and they have there own conditions that ensure security protection for financials and personal information. Although it is probably not necessary for my website to have a policy, the website is going to use eTrust to ensure security to consumers.

    ReplyDelete
  7. While a privacy policy may not be as important to my website as it is to a website that involves selling merchandise, I believe that it is always important to have some kind of policy in place to protect your self and your consumers. On my website consumers will have the option to participate in a group forum or send an email to the shop. This requires them to have to enter their name and e-mail. It is important that they feel safe giving that information and that it wont be used wrongly. That is why I think the privacy policy is important for my website. To incorporate a policy into my website I will develop a policy that works best with my e-business and make that policy available for consumers to view online. As well as implement protection from a company like TRUSTe or GeoTrust that shows consumers that the website is protected.

    ReplyDelete
  8. For my website I will be using eTRUST, the logo is placed on every page as to assure customers we are a safe and secure site. In the future Paypal would be a trusted payment options as I personally have used it for years and have confidence in it.

    ReplyDelete