Showing posts with label regulation. Show all posts
Showing posts with label regulation. Show all posts

Wednesday, June 27, 2018

GDPR Data Regs Hit U.S. Marketers in Europe

Starting this May, any U.S. marketer targeting customers in the European Union (EU) countries must navigate a changed data landscape thanks to the new General Data Protection Regulation (GDPR). It doesn't matter if the brand, marketer or data processor is based in the U.S.; strict compliance is mandatory. And shrugging off new data rules is a very costly mistake. Noncompliance can mean a fine equal to 4% of global annual revenue! The regulation's intended purpose is protection of non-anonymized personal data, and compliance is required of any company (or organization) that stores or processes that personal information about individuals ("data subjects"), who are defined as European citizens residing in an EU state. The protected personal data includes: Name, address, and phone number; IP address and cookies; racial identity; religion and religious affiliation; health and genetic data; biometric data; and sexual orientation and gender preference. GDPR's regulated "data controllers," who determine data processing, or "data processors," who handle data on behalf of data controllers, must respect key rights with regard to personal information. For example, there is an individual's right to access, to knowing what personal data has been collected and how that data has been processed. There is a right to accuracy, and restriction of data processing in the case of inaccuracy. There is a right to "freely given" and "explicit" consent for processing and storage of personal data. Plus, consent may not be regarded as "freely given" where performance of a contract is made conditional on consent, or is unnecessary to performance of a contract. The data subject also has the right to data portability, meaning the ability to request and receive personal data in a format easily transferred to another data controller. Finally, there is erasure or "a right to be forgotten," which allows individuals to withdraw their consent for data use or storage and demand that personal data be erased and no longer processed. Not sure it applies to you, direct marketer? Consider this GDPR wording: "Where personal data are processed for the purposes of direct marketing, the data subject should have the right to object to such processing, including profiling to the extent that it is related to such direct marketing, whether with regard to initial or further processing, at any time and free of charge." In terms of strategic response, 64% of executives at U.S. corporations reported that their top strategy for reducing GDPR exposure is centralization of data centers in Europe, according to a report released by PricewaterhouseCoopers (PwC). Just over half (54%) told PwC they plan to anonymize European personal data to reduce exposure. A significant minority are cutting European efforts, with 32% of respondents planning to reduce their presence in Europe, and 26% intending to completely exit the EU market. For more, see our website blog post: http://www.acculistusa.com/u-s-marketers-in-europe-wrestle-gdpr-data-compliance/

Tuesday, September 8, 2015

Protect Your Marketing From Costly Lawsuits

Marketing missteps that blossom into costly lawsuits make daily headlines, but many marketers still assume it's a risk only for the "big guys" or the "other guys." A recent Target Marketing magazine article by Alex Baydin, CEO of PerformLine Inc., a marketing compliance company, brought home the increasing scrutiny and pain of regulatory enforcement for all sizes and types of marketers. He notes that the Consumer Financial Protection Bureau alone reported $19.4 million in remediation for noncompliant marketing practices in the last six months of 2014. Penalties for marketing violations can be onerous. Baydin cites a recent CFPB complaint against PayPal over online credit sign-ups for $15 million in consumer redress and $10 million in penalties, plus a recent $11 million judgment by the Federal Trade Commission against Ashworth College for deceptive marketing. Before you shrug off the noncompliance threat because you aren't a high-dollar player, Baydin also reports recent action by the Federal Trade Commission to punish two auto dealers in Alabama and California for deceptive advertising. He lists five basic steps to protect your marketing from similar suits and fines: understanding of existing and new regulations; tracking of marketing messages across channels; a dedicated compliance team; clear and enforceable marketing guidelines for employees and affiliates; and close attention and timely response to customer complaints. For details, read http://www.targetmarketingmag.com/article/marketing-campaign-going-get-sued/

Tuesday, December 10, 2013

Marketers Wrestle Robocall, Texting Consent Rules

Telemarketers opened a troublesome gift from regulators going into the holiday season. Marketers using prerecorded or auto-dialed calls, as well as mobile texts, to reach consumers now must meet the Federal Communications Commission's stricter consent rules. Updating of the Telephone Consumer Protection Act, which went into effect Oct. 16, requires marketers to get prior written consent from consumers before delivering auto-dialed or prerecorded calls, or mobile texts. Unfortunately, this means that many companies' current opt-in databases do not comply with the new consent rules. Companies also can't claim an exemption due to a prior business relationship with a consumer, as they could in the past. In the consent agreement, companies must ask consumers to agree to receive automated or prerecorded messages and must make clear that a purchase is not a condition of the agreement. This creates a wording quandary for companies delivering a coupon or announcing a sweepstakes since no purchase is involved. It is also unclear whether a company can seek written agreement by asking a consumer to text back using a short code to receive a confirmation message that will ask for a "yes" reply to consent language. In a comment to Adweek magazine, Marc Roth, a partner in the advertising, marketing and media practice of Manatt, Phelps & Phillips, concluded that the courts will likely end up deciding how much latitude companies have in seeking consumer consent: "No one is concerned about the FCC, because they do little enforcement. The big fear is class actions. It's going to be the courts that decide what is necessary and what is not in terms of consent." For more discussion in the Adweek article, see http://www.adweek.com/news/technology/are-marketers-ready-new-telemarketing-rules-153079

Thursday, November 21, 2013

Fundraisers Face New HIPAA Opt-out Obligations

Health care fundraisers face important new obligations under the Health Insurance Portability and Accountability Act (HIPAA), including opt-out provisions. A new Omnibus Rule, which went into effect Sept. 23, did not take away the ability of a hospital or health care organization, or its institutionally related foundation or fundraising vendor, to contact patients for fundraising purposes, but it did make important changes in the type of patient information that can be used or disclosed, and it provides for greater patient control--notably new opt-out obligations for fundraisers. Fundraising efforts now must include an opt-out provision, written or oral, with each fundraising communication or material delivered to former patients, including telephone solicitations. In describing how the former patient can discontinue receiving fundraising materials and solicitations, the opt-out statement must be a clear and conspicuous part of the materials sent to the patient; must be written in clear, plain language; and must describe a simple, not unduly burdensome means to opt-out from receiving any further fundraising materials or communications. For details on changes to what patient information can be used for fundraising without prior authorization, the required notice of privacy practices, fundraising opt-out rules, and Business Associate Agreements covering fundraising vendors, go to http://www.ahp.org/advocacy/us/HIPAA/Analysis/Pages/default.aspx.

Tuesday, June 25, 2013

FTC Chair Calls for Better 'Do Not Track' Solution

New Federal Trade Commission Chairwoman Edith Ramirez shocked attendees at the American Advertising Federation’s annual advertising day on Capitol Hill by calling for a universal solution for Do Not Track (DNT), implying dissatisfaction with the Digital Advertising Alliance (DAA) self-regulatory program, reported a recent Adweek story. "Consumers await a functioning Do Not Track system, which is long overdue," Ramirez said. "We advocated for a persistent Do Not Track mechanism that allows consumers to stop control of data across all sites, and not just for targeting ads." The chairwoman poured salt in the wound by urging the advertising industry to work with the W3C (World Wide Web Consortium) to develop a DNT standard that is browser-based, championing Microsoft's Do Not Track browser and Mozilla’s plan to block third-party cookies. The advertising industry has been at odds with Microsoft and Mozilla policies, and the DAA put out a policy statement last year that advertisers would not honor the Microsoft browser because its default setting did not give advertisers choice. Ad industry members thought their DAA program had responded to the FTC’s DNT call two years ago. For more comments, see the story at http://www.adweek.com/news/technology/ftc-chair-stuns-advertisers-148644

Thursday, May 16, 2013

Updated Child Online Privacy Rule Starts in July

Despite pleas for delay from the Direct Marketing Association (DMA) and 18 other trade associations, the Federal Trade Commission (FTC) has rejected any extension on implementation of the updated Children's Online Privacy Protection Act (COPPA). The updated rule goes into effect this July 1. The trade associations are concerned about compliance with changes, such as an expanded definition of "personal information," which they hold will require more time to overhaul products and services. The DMA also expressed concern over an amendment holding companies legally responsible for third-party data services providers' compliance failures. The FTC responded that the trade groups have been on notice since the beginning of the rule-making process more than three years ago and have had six months to implement changes since the final December 2012 COPPA amendments. Changes affect parental notice, obtaining parental consent, confidentiality of personal information, safe harbors, and expanded definitions of "personal information," "website or online service directed to children," and "operator" of children-directed sites or services. For more on the updated COPPA, go to http://www.mondaq.com/unitedstates/x/239632/Data+Protection+Privacy/FTCs+Revised+COPPA+Rules+Go+Into+Effect+July+1+2013

Thursday, May 9, 2013

FTC Keeps Data Brokers in Regulatory Crosshairs

Federal officials are keeping the data brokerage industry in their regulatory crosshairs, and another warning shot has been fired. The Federal Trade Commission (FTC) just issued formal letters to 10 companies, alerting them that they may be violating federal restrictions on the collection and sale of consumers' personal information, reported The Washington Post. The targeted data brokers ranged from firms that compile consumer lists for credit offers to a website helping parents screen potential nannies. The list also includes well-known names in the direct marketing business. The FTC letters follow a broader inquiry into 45 data brokers appearing to market information whose use is restricted by the Fair Credit Reporting Act, which regulates how private companies can use personal information. Individuals are supposed to know when data reports affect their eligibility for insurance, credit or employment, and they are supposed to have the opportunity to correct errors. The FTC last year urged Congress to pass a law forcing the data brokerage industry to disclose its practices. The Post could not confirm whether any of the data brokers receiving letters face a full FTC investigation. Letter recipients were 4Nannies, Brokers Data, Case Breakers, ConsumerBase, Crimcheck.com, People Search Now, U.S. Information Search, US Data Corporation and USA People Search. The story did not name the tenth pending confirmation. For more, see the news story at http://www.washingtonpost.com/business/technology/ftc-warns-data-brokers-on-privacy-rules/2013/05/07/2e152c16-b748-11e2-92f3-f291801936b8_story.html

Thursday, March 28, 2013

Big Retailers Are Backing Internet Tax Bill

Change is in the wind for Internet sales. Major retailers are applauding recent Senate passage of a bill to impose sales taxes on all online orders in the United State, arguing that it is needed to "level the playing field" between brick-and-mortar and online retailers. The appeal to cash-strapped governments is clear: The bill's sponsors claim states collectively lose $23 billion a year by not taxing online purchases. The House has its own bill to allow states to levy taxes on online orders from major retailers (sparing small sellers), but the Senate bill would cover all online sellers. The Senate bill is backed by the National Retail Federation and Retail Industry Leaders Association, representing major businesses such as Best Buy, Target, and Wal-Mart. It is opposed by Internet giants like eBay, which argues that the Senate act would unfairly hamper small businesses. The Senate bill has some caveats that might initially ease the fears of small online retailers: It would be non-binding, so states could choose to simply not enact it. But opponents argue that this loophole is just a ruse to woo basic support for a more stringent Senate bill in the wings, dubbed the “Marketplace Fairness Act of 2013.” For more, see the news report at http://ivn.us/2013/03/28/major-retailers-want-internet-tax-law-to-level-playing-field/

Thursday, March 14, 2013

DMA Lobbies to Deflect Attacks on Data Marketing

Legislative and regulatory champions of privacy are redefining "data broker" to include any firm that collects, uses, analyzes, aggregates, shares, or compiles data for third parties -- literally all direct marketers -- warns the Direct Marketing Association (DMA). "The threats to what we do are looming large, both in Washington, across the ocean and in state legislatures," declared Linda Woolley, president and CEO of the DMA, in a recent "AdWeek" report. DMA lobbyists hurried to Washington, D.C., in March to warn House and Senate commerce and judiciary committees about the potential adverse impact on the whole economy of restrictions on marketing data. Rachel Thomas, DMA vice president of government affairs, is quoted as stressing that direct marketers "are responsible for 8.7% of the GDP, $168 billion in spending, $2.05 trillion in sales, 9.2 million jobs." What alternative approach does the DMA offer for guarding consumer privacy? It's talking up the Digital Advertising Alliance's self-regulation program giving consumers the ability to opt-out of online behavioral tracking, along with initiatives to craft mobile guidelines. Meanwhile, it's using its Data Driven Marketing Institute, formed last year, in a campaign to educate and advocate on the benefits of data-driven marketing. It remains to be seen whether self-regulation and education are enough to calm politicians' fears about the new era of Big Data. For the complete story, see http://www.adweek.com/news/advertising-branding/direct-marketers-crank-lobbying-campaign-147872

Thursday, December 27, 2012

'Big Brother' Redux? Now TVs May Watch Viewers

In future, while you are watching your television set, it may be busy watching you -- capturing conversations and moods from its surroundings and then delivering customized ads. Verizon has filed a patent application for targeting ads to TV viewers based on information collected from TVs equipped with infrared cameras, microphones and other devices that detect viewers' conversational keywords, moods and activities, well as information about objects and even animals near the TV. For example, if the TV sensors detect that a couple is arguing in the "Verizon Detection Zone," the system could send an ad for marriage counseling to the TV or a mobile phone in the room. If the system detects that the viewer is playing with a dog, a dog food commerical could be transmitted, and so on. It will be interesting to hear the privacy arguments generated by this proposed data-gathering! For more on the story, go to http://broadcastengineering.com/company-news/verizon-patents-targeted-advertising-watches-tv-viewers

Thursday, October 18, 2012

Senders of Free But Unsolicited Texts Can Be Sued

Senders of unsolicited text messages, even when the texts are free, can be sued. According to a July 20 decision by the U.S. District Court for the Northern District of California in Smith v. Microsoft Corp., text senders can be sued because text messages fall under the Telephone Consumer Protection Act (TCPA) and may violate the "right of privacy." TCPA already bans unsolicited advertising faxes and telemarketing calls to cell phones. The district court ruled plaintiffs could bring claims against Microsoft for unsolicited text messages even if a carrier didn't charge for receiving the message; harm to a plaintiff’s abstract "right of privacy" was sufficient to support legal claims. For more details, see http://www.abmassociation.com/News/2819/Ruling%3A-Senders-of-unsolicited-free-texts-can-be-sued

Tuesday, August 7, 2012

Privacy Legislation Debate Continues to Simmer


Privacy legislation to limit business information collection is a sword of Damocles for marketers. It hasn't fallen, but it won't go away either. This year's first privacy hearing by the Senate Committee on Commerce, Science, and Transportation sounded familiar themes as witnesses from the Federal Trade Commission advocated Do Not Track legislation and increased FTC enforcement authority. Democratic committee members leaned toward baseline privacy legislation, while Republicans looked to industry incentives for privacy protection. That political logjam may continue through the end of the year, but then watch for the debate to revive in 2013, warns the Association of Business Information and Media Companies (ABM). ABM lobbyists are continuing efforts to advocate self-regulation and a business capacity exemption so b-to-b companies can gather data on individuals in a business capacity. To learn more, see the ABM report at http://www.abmassociation.com/News/2767/Senate-Commerce-Committee-holds-privacy-hearing

Monday, June 18, 2012

Canadian Regulators Get Tough on Spam

In a drive to block spam, Canada has erected higher hurdles for e-mail and text-message marketing. The Canadian Radio-Television and Telecommunications Commission has now released regulations on how marketers can comply with Canada’s new anti-spam act. Unlike the U.S. CAN-SPAM act, which allows electronic marketers to send unsolicited messages to consumers provided they include a way for recipients to opt-out, the Canadian regulations require a marketer to have received express written or verbal consent from a recipient before sending an e-mail or text message. The regulations also require commercial messages to include the name of the sender, a mailing address, either the e-mail/web address of the sender or a phone number that connects to an agent or voice mail system, and a “consumer-friendly” unsubscribe option. If you ignore the regulations, you risk a maximum monetary penalty per violation of $1 million for an individual and $10 million for business entities, like e-tailers. If U.S. anti-spam efforts emulate their northern neighbor's, it will definitely be a game-changer for electronic marketing. For more detail, see http://www.internetretailer.com/2012/03/30/canada-gets-serious-about-combating-spam