Having a privacy notice for customers to review is an essential part of any privacy program. When Delta Airlines added a privacy notice to their mobile app, “Fly Delta”, to comply with California law, the policy did not reflect reality. When creating a privacy notice you need to say what you do and do what you say.
California’s Attorney General, Kamala D. Harris, has been very transparent in her plans for enforcement of the California Online Privacy Protection Act which requires an operator of a web site, including mobile apps, that collects personal information to conspicuously post a privacy notice. Last month AG Harris’s office gave Delta Air Lines (among other companies) 30 days to post a privacy notice in their mobile app; Delta did not comply.
In a press release last Thursday, AG Harris’s office announced that a lawsuit had been filed against Delta seeking to halt distribution of their app plus impose a fine of $2,500 for each violation of the California law. A copy of the complaint can be found here.
On Friday Delta responded by publishing a privacy notice for its mobile app. Ashkan Soltani, “an independent researcher and consultant focused on privacy, security, and behavioral economics” who was previously a technologist at the Federal Trade Commission, discovered that the app collected and shared an iPhone’s UDID, a unique identifier for each device, something that was not stated in the published privacy statement.
At a minimum it would be fair to say that there was a lack of understanding on the part of the privacy notice’s writer about how the app worked. Unfortunately this is not unusual as legally trained individuals may not be technology savvy and the technologists may not be legally knowledgeable.
There is often a disconnect in communications between a legal team and a technical team. The two disciplines have different priorities and use different terminology. What may be a viewed as a common practice by the technologists may be viewed as a legal problem by the attorneys. Without a “common language” the attorneys may not have known what to ask and the technologists may not know what to share.
The publishing of a privacy notice with the mobile or any other application should be a business requirement of a project from the start. The same can be said of meeting any other privacy standards imposed by an organization. Developers, business analysts, and project managers may not be completely versed in an organization’s internal and external privacy requirements; a privacy specialist must have a seat at the table when requirements are being defined.
Created by Ann Cavoukian, the Information and Privacy Commissioner for Ontario, Canada, Privacy by Design defines seven foundational principles that provide sound guidance in the construction of privacy program. In the recently published Operationalizing Privacy by Design: A Guide to Implementing Strong Privacy Practices, Dr. Covoukian states four actions for embedding privacy into systems design:
In addition to an effective awareness program, the first three of these actions should be incorporated into the practices of any organization that is undertaking the implementation of a new system. In Delta’s case, this would have provided the necessary details and time to create a complete, accurate privacy notice.
Posted on December 10, 2012 by Bob Siegel
April 16, 2018
September 21, 2018Continue reading this post...