Privacy Ref Blog

Don’t be too quick to publish a privacy notice

Having a privacy notice for customers to review is an essential part of any privacy program. When Delta Airlines added a privacy notice to their mobile app, “Fly Delta”,  to comply with California law, the policy did not reflect reality. When creating a privacy notice you need to say what you do and do what you say.

Delta’s mobile app and a privacy notice

California’s Attorney General,  Kamala D. Harris, has been very transparent in her plans for enforcement of the California Online Privacy Protection Act which requires an operator of a web site, including mobile apps, that collects personal information to conspicuously post a privacy notice. Last month AG Harris’s office gave Delta Air Lines (among other companies) 30 days to post a privacy notice in their mobile app; Delta did not comply.

In a press release last Thursday, AG Harris’s office announced that a lawsuit had been filed against Delta seeking to halt distribution of their app plus impose a fine of $2,500 for each violation of the California law. A copy of the complaint can be found here.

On Friday Delta responded by publishing a privacy notice for its mobile app. Ashkan Soltani, “an independent researcher and consultant focused on privacy, security, and behavioral economics” who was previously a technologist at the Federal Trade Commission, discovered that the app collected and shared an iPhone’s UDID, a unique identifier for each device, something that was not stated in the published privacy statement.

Did the development team understand the privacy notice requirements?

At a minimum it would be fair to say that there was a lack of understanding on the part of the privacy notice’s writer about how the app worked. Unfortunately this is not unusual as legally trained individuals may not be technology savvy and the technologists may not be legally knowledgeable.

There is often a disconnect in communications between a legal team and a technical team. The two disciplines have different priorities and use different terminology. What may be a viewed as a common practice by the technologists may be viewed as a legal problem by the attorneys. Without a “common language” the attorneys may not have known what to ask and the technologists may not know what to share.

Avoiding the problem – Privacy by Design

The publishing of a privacy notice with the mobile or any other application should be a business requirement of a project from the start. The same can be said of meeting any other privacy standards imposed by  an organization. Developers, business analysts, and project managers may not be completely versed in an organization’s internal and external privacy requirements; a privacy specialist must have a seat at the table when requirements are being defined.

Created by Ann Cavoukian, the Information and Privacy Commissioner for Ontario, Canada, Privacy by Design defines seven foundational principles that provide sound guidance in the construction of privacy program. In the recently published Operationalizing Privacy by Design: A Guide to Implementing Strong Privacy PracticesDr. Covoukian states four actions for embedding privacy into systems design:

  1. Make a Privacy Risk Assessment an integral part of the design stage of any initiative, e.g. when designing the technical architecture of a system, pay particular attention to potential unintended uses of the personal information. 
  2. Base identity metasystems on the “Laws of Identity,” intended to codify a set of fundamental principles to which universally adopted, sustainable identity architecture must conform. 
  3. Consider privacy in system development lifecycles and organizational engineering processes. System designers should be encouraged to practice responsible innovation in the field of advanced analytics. 
  4. Embed privacy into regulatory approaches that may take the form of self-regulation, sectoral privacy laws, omnibus privacy legislation and more general legislative frameworks, calling for an approach guided by “flexibility, common sense and pragmatism.”

In addition to an effective awareness program, the first three of these actions should be incorporated into the practices of any organization that is undertaking the implementation of a new system. In Delta’s case, this would have provided the necessary details and time to create a complete, accurate privacy notice.


Privacy Ref provides consulting and assessment services to build and improve organizational privacy programs. For more information call Privacy Ref at (888) 470-1528 or email us at

Posted on December 10, 2012 by Bob Siegel
Tags: , , , , ,

« »

No Responses

Comments are closed.

« »

Subscribe to our mailing list

Please fill out the form below.


Want to find out more?

Simply go to the contact page, fill out the form, and someone from Privacy Ref will be in touch with you. You can also send an email to or call (888) 470-1528.


April 16, 2018

IAPP Training Classes
Privacy Ref is proud to announce that we are an official training partner of the IAPP. You now have the opportunity to learn from one of our knowledgeable privacy professionals using the most respected training content in the industry. The robust interactive training offered, aids in the understanding of critical privacy concepts. The contents of the courses are integral to obtaining your privacy certifications and to educate your new team. Learn more here.

Latest Blog Posts

July 9, 2018

Don’t Forget Basic Communication
Most of us have been wrapped up in GDPR preparations for several months. While there are many organizations "not quite there yet", many others have made great strides towards compliance. As we continue to do assessments for clients, both GDPR and General Privacy,  I have been surprised at the frequency of the gap between a privacy official describing their organization's data subjects, information collected, and business processes  with the reality of what is happening. Continue reading this post...

California – The Next GDPR?
Starting January 1, 2020, if you are a for-profit company doing business in California, you may have new data privacy compliance obligations. Specifically, California just enacted the California Consumer Privacy Act of 2018 (the country’s strictest data privacy law to date), placing new privacy mandates on certain businesses with respect to the personal information of consumers (defined as natural persons who are California residents). Many aspects of the new law smack of EU-GDPR influences, such as a new and improved (in other words, broader) definition of personal information and the inclusion of guaranteed consumer rights with respect to such personal information. If your business is already in compliance with the EU’s GDPR, the California law will be nothing new to you. For other businesses, however, you have 18 months to get with the program. Continue reading this post...

Other Recent Posts