The Federal Trade Commission (FTC) recently approved a new method for website operators and mobile application developers (“operators”) to obtain parental consent to collect personal information from children.1 Under this new method, which is the first to use biometric identifiers to verify that a parent is providing consent for a child, the FTC will permit operators to use facial recognition technology to compare an image of the person providing consent with an image of verified photo identification, such as a drivers’ license or passport. If the two images match, the user is verified and can provide consent for the child to use the website or mobile application.
Continue Reading FTC Approves Facial Recognition as Method of Obtaining Parental Consent to Collect Children’s Information
Privacy
FAST Act Eases GLBA Compliance Burdens for Many Companies, Addresses Transportation and Infrastructure Privacy and Cybersecurity Issues
President Obama signed the Fixing America’s Surface Transportation Act (FAST Act) into law on December 4, 2015. The FAST Act not only provides long-term funding for highway and infrastructure improvements and other transportation projects, but also includes several privacy- and security-related provisions, including an important provision that may reduce consumer confusion and industry compliance costs by eliminating annual privacy notice requirements for financial institutions in certain circumstances.
Continue Reading FAST Act Eases GLBA Compliance Burdens for Many Companies, Addresses Transportation and Infrastructure Privacy and Cybersecurity Issues
HHS Ends 2015 with Three HIPAA Enforcement Settlements
In late 2015, the U.S. Department of Health and Human Services (HHS) announced three settlements in which the agency will collect over $5 million in collective penalties for alleged non-compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). In addition to the monetary penalties, each of the settlements requires compliance with a Corrective Action Plan (CAP), calling for the organizations to invest significant resources toward HIPAA compliance.
Continue Reading HHS Ends 2015 with Three HIPAA Enforcement Settlements
WSGR Alert: EU Data Protection Authorities Issue Statement Following Agreement on EU-U.S. Privacy Shield
On February 3, 2016, the body of European data protection regulators—the Article 29 Working Party (WP29)—issued a statement following the announcement of a political agreement regarding a new transatlantic data transfer scheme, the EU-U.S. Privacy…
Continue Reading WSGR Alert: EU Data Protection Authorities Issue Statement Following Agreement on EU-U.S. Privacy Shield
WSGR Alert: EU and U.S. Reach a Political Agreement on Transatlantic Data Transfer Deal
On February 2, 2016, the European Commission announced that a political agreement on a new legal framework for data transfers has been reached between the European Union (EU) and the U.S. Today’s agreement introduces the…
WSGR Alert: FTC Brings First Enforcement Actions Against Kids Apps Using Persistent Identifiers for Targeted Advertising
On December 17, 2015, the Federal Trade Commission (FTC) announced its first Children’s Online Privacy Protection Act (COPPA) enforcement actions challenging the use of persistent identifiers to engage in targeted advertising to children. The FTC…
Continue Reading WSGR Alert: FTC Brings First Enforcement Actions Against Kids Apps Using Persistent Identifiers for Targeted Advertising