Today’s AP story, Privacy Options limited for Net services, highlights TRUSTe as an advocate for consumer choice, and mentions one exemplary sealholder, E-LOAN as offering exceptional choice when it comes to personal privacy. TRUSTe has reviewed tens of thousands of privacy policies, and E-LOAN’s is simply one of the best. One reason why they won our award for being a Most Trusted Company for Privacy this year.
Transparency, ensures that consumers are informed of the bargain. Accurate disclosure of practices also empowers consumers to encourage service providers to change thier practices. Facebook, another TRUSTe sealholder, is an excellent example of the importance of good disclosure and responsiveness to privacy issues. They handled customer concerns quickly and responsively - that’s also building trust.
- Posted by Carolyn Hodge
October 13th, 2006
As a result of investigating the HP Board pretexting scandal, CNET reporter/blogger David Berlind suggests to powers that be, that CNET/ZDNet should disclose outbound clear .gif tracking in thier email newsletters. And guess what, they agreed!
“So, sometime this week, once we’ve had a chance to adjust our newsletter templates, you will begin to see a text disclosure (probably at the bottom) that mentions the usage of trackable elements in the HTML versions of the daily and weekly editions of Tech Update.”
Bravo! We’ll be interested to see if subscribers, notice or comment on the disclosure.
October 2nd, 2006
If there was any confusion about what TRUSTe meant when we said we look at different things than SiteAdvisor, things got a tad clearer today when they announced they “don’t do phishing.”
This is only significant because in the previous post on this blog TRUSTe defends itself in a side-by-side comparison with SiteAdvisor, conducted by Ben Edelman, an expert reviewer and advisory board member to Site Advisor.
To repeat our previous posting, “TRUSTe views Site Advisor as a potentially useful monitoring tool, but not an accreditation program or an authority on privacy. Both approaches have strengths and shortcomings.”
Apples to oranges comparisons only become problematic when you come out on the losing end.
September 28th, 2006
In a recent study, the efficacy of our program and our standards has been called into question. TRUSTe disagrees with the study and its conclusion that TRUSTe certified websites are less trustworthy than non-certified web sites. TRUSTe requires its sealholders to adhere to a strict set of standards for consumer privacy based on informed choice for the use of personal information. Our processes are rigorous – on average 12% of applicants do not earn certification, and 100% of certified websites need to make changes to their policies, practices or websites prior to receiving certification. Notable companies with TRUSTe certification include Apple, Avis, Disney, eLOAN, Nationwide, NFL, and Pfizer. Consumers can be confident that TRUSTe certified sites comply with the disclosed privacy policy and offers them informed notice and choice.
The study does not present a full or accurate review of TRUSTe’s program requirements, monitoring processes and enforcement tools. The TRUSTe Web Seal Program Requirements represent a leading edge of privacy practices requiring disclosure of the uses of personal data, informed choice (as well as specifics for third-party sharing), and commitment to the Watchdog Dispute Resolution program. TRUSTe uses a number of tools, from user complaints to email seeding, to ensure continued compliance with our standards for informed notice and choice. Consumer generated Watchdog complaints have resulted in severe sanctions against licensees, including TRUSTe’s public termination of Gratis Internet - a company that the New York Attorney General has sued subsequent to TRUSTe’s actions.
In addition to several inaccuracies and misstatements, the study’s conclusions are based on an underlying set of assumptions, without exposition the methodology, definitions, and approach giving rise to such assumptions. TRUSTe views Site Advisor as a potentially useful monitoring tool, but not an accreditation program or an authority on privacy. Both approaches have strengths and shortcomings. As an accreditation program TRUSTe will err on the side of rating companies as trustworthy, conversely SiteAdvisor has been shown in some cases to err on the side of untrustworthy.
As for the four sites called out on Mr. Edelman’s blog, Direct-Revenue and MaxMoolah (and all WinHundred related companies) are no longer in the TRUSTe program. FunWebProducts, was, by an error in our database listed on our customer list, but it has never been certified, and has never displayed any seals or reference to TRUSTe to consumers. The fourth, Webhancer is certified by TRUSTe and will be required to submit its software for certification to Trusted Download program which is launching imminently. The Trusted Download program was designed specifically to address notice and choice and control issues with software that go beyond our website requirements. Like the Website Privacy Seal program, it will offer companies incentives to provide notice and choice while prohibiting intrusive behaviors.
We welcome this opportunity for regulators and others to closely review certification programs and for consumers to pay closer attention to seal and ratings programs and their requirements. We invite the public to closely look at the rigorous requirements of the TRUSTe web seal program, email privacy seal program, as well as our recently announced Trusted Download Program.
September 25th, 2006
By John Tomaszewski
The response in the commercial space to the Xanga.com settlement with the FTC has raised some interesting speculation/interpretation on FTC enforcement of the Children’s Online Privacy Protection Act (COPPA). One assumption is that the FTC doesn’t consider End User License Agreements (EULAs) to be worth the paper they are printed on, from a compliance perspective. If a EULA is going to be a legitimate mechanism to inform consumer consent to be bound by the terms, the FTC is looking for a EULA that a consumer can read and reasonably understand the implications without completing a law degree.
All of these EULAs are non-negotiable (the legal term for this is an adhesion contract). Most of the contracts that I sign are adhesive (my apt. lease, my claim check at a parking lot, my airline tickets, etc). I do have the choice not to do business if the contract is draconian. In the Xanga case, the FTC isn’t saying that EULAs are useless and not enforceable. They recognize EULAs non-negotiability but if they are going to be the mechanism for informing consent, they cannot require the average consumer to go through 10 pages of 8 point type to find that they can’t use the site if they are under the age of 13. If you are going to rely on a EULA for notice you had better make sure you are comfortable with your ten-year-old’s ability to understand the bargain it requires.
The answer to the child protection burden for many general audience Web sites has been simply to avoid collecting birthdates. This may allow these sites a safe harbor of plausible deniability, but it completely skirts the intent of the law, which is to protect children. Children these days are growing up privacy and security aware. Avoiding age collection also misses an opportunity to build trusting relationships with kids and their guardians about their online choices. Companies marketing to children should follow the golden rule to keep their audience in mind whether they are promoting products or providing choices.
September 20th, 2006
TRUSTe is very excited about a new resource issued by the Chief Marketing Officer Council (CMO Council) - emphasizing the importance of data protection on brand trust. This survey and forthcoming report entitled Secure the Trust of Your Brand, assesses the security mindset of consumers and calls marketer’s attention to the critical issues of privacy and security.
Read the Report & Share with Your Marketing Colleagues
TRUSTe is partnering with the CMO Council to provide our privacy and security best practices as key resources for addressing the consumer concerns raised in this survey and the forthcoming Fall 2006 report. We hope that you will participate in the CMO Council Secure the Trust of your brand program by taking the business executive survey (at right).
Secure the Trust of Your Brand(TM) is a major thought leadership initiative undertaken by the Chief Marketing Officer (CMO) Council to raise awareness and influence thinking about security among leading corporate marketers, brand managers and other senior corporate business executives. This global initiative includes six individual research components, and when published, will provide the first 360 degree view of the extent to which security now influences customer consideration, acquisition and retention.
Among the key findings from the consumer audits:
- Security concerns among consumers are rising-particularly among those who have experienced breaches firsthand.
o 65 percent of European and U.S. respondents, on average, have experienced computer security problems such as viruses and spyware
o One in six respondents have had their personal information lost or compromised
- Consumers aren’t taking these incidents lying down.
o 40 percent of respondents have actually stopped a transaction online, on the phone or in a store due to a security concern
o Over a third say they would strongly consider taking their business elsewhere if their personal information were compromised
o 25 percent would definitely take their business elsewhere if their personal information were compromised
We think this report and program are a good sign that marketers are getting the message that data security in privacy can strengthen brand value. We hope our sealholders find this a useful tool in supporting privacy and security initiatives within your organization.
August 24th, 2006
CDTupdated its adware report with “Follow the Money II - The Role of Intermediaries in Adware Advertising” with the novel finding that 55% of ads used no intermediaries at all, where CDT had previously found more frequent use of multiple intermediaries. The update focuses on 380 ads collected from only two adware makers Zango and Direct Revenue, and states that the previous study focused on higher-profile marketers. So the conclusion drawn is that higher profile marketers typically end up in these types of adware through multiple intermediairies (the “lose track” of ads) whereas many of the less high-profile marketers seen in these ads have direct relationships with the adware makers.
August 10th, 2006
Great article about everyday privacy on Reuters Today called “Product Returns: Consumers balk at giving personal info”
I recently tried to exchange sizes on a cash purchase at the Children’s Place here in San Francisco. Upon the exchange I was walked through a series of questions requiring my name, address, telephone number, etc. All of which I refused, requiring store manager intervention.
There are two issues arising in these situations:
1) Retailers do not provide adequate notice and information about any type of personal data collection at the point of sale. Combined with woefully undertrained and unknowledgeable store clerks, who give misinformed or inadequate answers — how can you blame customer unease at handing over personal information? I can guess more accurately why my personal data is being collected than the store clerk who may or may not have been instructed to respond.
2) At least in cases where your infomation is collected for marketing purposes consumers can see potential value in coupons or special offers. In this case you are asking law-abiding individuals to potentially expose thier personal information to a data breach because retailers have a 9% fraudulent returns problem.
So it doesn’t surprise me at all that individuals lie about thier information when asked, or that they balk at giving thier driver’s licenses to retailers. I encourage consumers to speak up about non-essential data collection, and demand reasonable disclosure about why and how the information is being used.
August 3rd, 2006
In a recent turn heralding growing advertiser acccountability, advertiser Warner Bros. decided to sever its relationship with adware maker Zango for advertising in adware & through affiliate relationships. And in a subsequent article over at MediaPost,
Warner Bros. said it ended the relationship because Zango had not provided a third-party certification that its business practices met Warner Bros. standards. “While we respect Zango’s effort to change its business model, we also take our responsibility to children and parents very seriously. Unfortunately, despite the initial assurance we sought and received from Zango, they have been unable to provide the third party certification we require to continue the relationship,” the company said Friday in a statement.
The Trusted Download whitelist scheduled for launch this Fall will be a useful tool for advertisers and brands such as WB to consult to evaluate appropriate partners. Of particular interest to the WB-Zango partnership are Trusted Download specific requirements for children in addition to the standard program requirements:
X. SPECIAL PROTECTIONS FOR CHILDREN
Program Participants with Certified Adware or Certified Trackware must take the following steps:
A. Prevent the distribution of their Certified Adware or Certified Trackware on Children’s Websites, including by prohibiting their Distribution Partners and Affiliates from such distribution.
B. Engage in commercially reasonable monitoring to determine where advertisements promoting the installation of their Certified Adware or Certified Trackware appear.
C. Disclose in Reference Notice that their Certified Adware or Certified Trackware should be installed only by Users age 18 and over.
D. If their Certified Adware delivers pornographic advertisements or advertisements for online gambling, alcohol, tobacco, firearms or other weapons, Program Participants must disclose the IP addresses of the server sending such ads to Net Nanny and other similar services, as prescribed by TRUSTe.
E. Follow the branding steps in Section VI to make sure that each time Users of Certified Adware see a Covered Advertisement, they have an obvious means of understanding why they received the Covered Advertisement and easy-to-find information on how to stop getting Covered Advertisements from the Certified
Adware.
Currently in a private alpha, TRUSTe is taking the certification process through the paces, and expects to open public Beta soon. Until then adware and trackware companies will have to get in line and make sure thier software is ready for certification and meets our program requirements.
August 1st, 2006
While privacy and piracy have been in the news quite a bit in the past few months as separate ideas, David Holtzman’s Viewpoint in Business Week Online - July 24, 2006, took the interesting step of combining them. Recent debate about privacy has been engulfed by repeated high profile breaches and the subsequent focus on data protection and security. Mr. Holtzman moves the discussion about privacy back to where it belongs – the value of personal data and how it is used.
The focus on “ownership” however, may be a red herring.
The concept of ownership bundles rights that a person can 1) assert around a thing, and 2) can restrict anyone else from asserting around such thing. This works well with physical objects (film, cars, CDs, etc.) but becomes more problematic when addressing data about such things. A person actually does not own personally identifiable data in many instances. For example, I don’t “own” my bank account number. While this may be counterintuitive, I cannot restrict my bank from changing or even reusing my account number. Because the bank has more rights over who can and how that number can be used, I can’t be said to “own” that number. Much personally identifiable data is subject to this quandary – the data is about me, but I don’t “own” it.
Control versus Ownership
This difficulty with “ownership” exposes Holztman’s red herring. Most of us aren’t as concerned with the technicality of ownership of our data, as much as asserting control over our data. Jim Harper of the Cato Institute articulates the definition of privacy like this:
“Privacy is the condition that people enjoy when they are given the opportunity to control information about themselves, and they exercise that control in a manner consistent with their interests and values.”
A privacy policy is supposed to do exactly that — to allow you to exercise of control over data about yourself. Without mentioning “ownership” this definition works well with how consumers interact with their data in the marketplace.
TRUSTe’s program requirements around what must go into a privacy policy expressly require this option of control. According to TRUSTe, a consumer must be given the option of limiting use beyond the transaction for which data was collected, and a company may not eliminate this requirement through privacy policy disclosures. (There is an exception for complying with legal disclosure requests from the government, as recently seen with the nation’s telecommunications firms.)
Further, where a website collects personally identifiable data from a third party, as in a gift delivery, the consumer must affirmatively opt-in to any other use by the same company that isn’t for the primary purpose of the collection. This means that if a friend sends you flowers, that flower shop shop is not able to send you offers for additional services unless you opt-in. . These requirements give control to the consumer regardless of who “owns” the data. A company, at least one certified by TRUSTe, can hardly do what ever it wants with data about an individual.
Mr. Holtzman and I do not greatly disagree. He offered our shared viewpoint with the statement:
“As consumers, we should be entitled to only give out our information when we want, and maintain some control over its subsequent disposition, including mandatory erasure when our business relationship is terminated.”
TRUSTe requirements, and all the regulatory environments which address personally identifiable data (e.g. Gramm-Leach-Bliley Act, HIPAA, Fair Credit Reporting Act, etc.) are in alignment with this concept of control versus ownership. Compliant policies restrict how personally identifiable data about an individual is used and disclosed regardless of who “owns” the data.
Commerce versus Stealing
Which brings us to the second privacy issue raised by Mr. Holtzman – the value of data. Mr. Holtzman makes a fascinating assertion that a privacy statement is a “…license to steal consumer information, wrapped up in legal tinsel.”
First, stealing is taking from a person, without their consent, something they “own” (which may or may not be the case with personally identifiable information.). Consequently, there are two elements in play here: 1) ownership of the data in question, and 2) lack of consent. If a person gives you something, that isn’t stealing. Further, if a person gives you something in exchange for something else, not only is that not stealing, that is called commerce.
So, putting aside the first threshold issue of “ownership,” let’s discuss the second issue of “bargained-for exchange,” which seems to be at the root of Mr. Holtzman’s complaint – “why can’t I get paid for data about me?”
A consumer interacts with a company (which would be the reason for a privacy policy to even apply) when the individual perceives a value to the interaction. Perceived value could come from information the individual receives from the company, or from the services that the company offers. I pay my bills at CheckFree because I perceive value when I don’t have to pay 37 cents to mail my bill. Further, when CheckFree personalizes communication with me, I perceive value in knowing I am not getting phished or spammed. So, for the disclosure of my information, I receive value in reducing my cost of paying bills, increased security in communication from Checkfree, and increased convenience of paying bils online.). All this for a service I don’t have to pay for. That looks a lot like bargained for exchange.
Regardless of “ownership”, the individual’s engagement with the business provides at least perceived, if not actual, benefit for the consumer. This is not stealing.
Now, a larger question lies in what kinds of companies actually do follow TRUSTe or GLB-like requirements? And additionally, is the benefit given to consumers actually realized to the level that the consumer wants? I think these are excellent questions and should be fully explored. However, these questions do not really lend themselves to the sensationalization that sells newspapers.
Regardless of how sexy the topic may not be, it is fundamentally the first principle of the privacy debate – can individuals control information about themselves in a way that is consistent with their interests and values; or is commerce placing a lower value on the bargained for exchange than the consumer might? This is a question of market motivations and consumer values. However, before any of this can happen in a meaningful way, commerce must adopt the business models that provide informed choice to the individual. TRUSTe is one way the marketplace does this.
July 26th, 2006
Previous Posts