Privacy Ref Blog

Don’t be too quick to publish a privacy notice

Having a privacy notice for customers to review is an essential part of any privacy program. When Delta Airlines added a privacy notice to their mobile app, “Fly Delta”,  to comply with California law, the policy did not reflect reality. When creating a privacy notice you need to say what you do and do what you say.

Delta’s mobile app and a privacy notice

California’s Attorney General,  Kamala D. Harris, has been very transparent in her plans for enforcement of the California Online Privacy Protection Act which requires an operator of a web site, including mobile apps, that collects personal information to conspicuously post a privacy notice. Last month AG Harris’s office gave Delta Air Lines (among other companies) 30 days to post a privacy notice in their mobile app; Delta did not comply.

In a press release last Thursday, AG Harris’s office announced that a lawsuit had been filed against Delta seeking to halt distribution of their app plus impose a fine of $2,500 for each violation of the California law. A copy of the complaint can be found here.

On Friday Delta responded by publishing a privacy notice for its mobile app. Ashkan Soltani, “an independent researcher and consultant focused on privacy, security, and behavioral economics” who was previously a technologist at the Federal Trade Commission, discovered that the app collected and shared an iPhone’s UDID, a unique identifier for each device, something that was not stated in the published privacy statement.

Did the development team understand the privacy notice requirements?

At a minimum it would be fair to say that there was a lack of understanding on the part of the privacy notice’s writer about how the app worked. Unfortunately this is not unusual as legally trained individuals may not be technology savvy and the technologists may not be legally knowledgeable.

There is often a disconnect in communications between a legal team and a technical team. The two disciplines have different priorities and use different terminology. What may be a viewed as a common practice by the technologists may be viewed as a legal problem by the attorneys. Without a “common language” the attorneys may not have known what to ask and the technologists may not know what to share.

Avoiding the problem – Privacy by Design

The publishing of a privacy notice with the mobile or any other application should be a business requirement of a project from the start. The same can be said of meeting any other privacy standards imposed by  an organization. Developers, business analysts, and project managers may not be completely versed in an organization’s internal and external privacy requirements; a privacy specialist must have a seat at the table when requirements are being defined.

Created by Ann Cavoukian, the Information and Privacy Commissioner for Ontario, Canada, Privacy by Design defines seven foundational principles that provide sound guidance in the construction of privacy program. In the recently published Operationalizing Privacy by Design: A Guide to Implementing Strong Privacy PracticesDr. Covoukian states four actions for embedding privacy into systems design:

  1. Make a Privacy Risk Assessment an integral part of the design stage of any initiative, e.g. when designing the technical architecture of a system, pay particular attention to potential unintended uses of the personal information. 
  2. Base identity metasystems on the “Laws of Identity,” intended to codify a set of fundamental principles to which universally adopted, sustainable identity architecture must conform. 
  3. Consider privacy in system development lifecycles and organizational engineering processes. System designers should be encouraged to practice responsible innovation in the field of advanced analytics. 
  4. Embed privacy into regulatory approaches that may take the form of self-regulation, sectoral privacy laws, omnibus privacy legislation and more general legislative frameworks, calling for an approach guided by “flexibility, common sense and pragmatism.”

In addition to an effective awareness program, the first three of these actions should be incorporated into the practices of any organization that is undertaking the implementation of a new system. In Delta’s case, this would have provided the necessary details and time to create a complete, accurate privacy notice.

 

Privacy Ref provides consulting and assessment services to build and improve organizational privacy programs. For more information call Privacy Ref at (888) 470-1528 or email us at info@privacyref.com

Posted on December 10, 2012 by Bob Siegel
Tags: , , , , ,

« »

No Responses

Comments are closed.


« »

Subscribe to our mailing list

Please fill out the form below.

Required

Want to find out more?

Simply go to the contact page, fill out the form, and someone from Privacy Ref will be in touch with you. You can also send an email to info@privacyref.com or call (888) 470-1528.

News

May 10, 2017

Predictive Breach Cost Model
Download our predictive breach cost modelhere.

Latest Blog Posts

October 30, 2017

PSR 2017 in Review
After a long trip from the northeast to San Diego, I finally made it to another exciting Privacy, Security, and Risk Conference from the IAPP. With GDPR on the horizon, the air was thick with discussion of this regulation in effect in May of next year. Even more so, a lot of questions received at the Privacy Ref booth were focused on this law, or preparing a privacy program through assessments data mapping. Overall, a great show with a few major themes. Continue reading this post...

The key to effective privacy training
I spend a lot of time facilitating privacy training. Whether it is directly for our clients or on behalf of the IAPP or their training partners, there are common elements to a successful educational event. Continue reading this post...

Other Recent Posts

PRIVACY REF