Showing posts with label Consumer Protection. Show all posts
Showing posts with label Consumer Protection. Show all posts

Wednesday, April 23, 2014

Buffalo Bills Alleged Over-Texting Results in Multi-Million Dollar Settlement

The National Football League’s Buffalo Bills, no strangers to disappointment on the field, are now a cautionary tale for mobile marketers. Last week, a federal judge in the Middle District of Florida approved a class settlement agreement over alleged violations of the Telephone Consumer Protection Act (“TCPA” 47 U.S.C. §227, et seq.), stemming from text messages sent by the Bills to fans who had explicitly signed up to receive texts from the team.

According to the complaint filed in October 2012, Bills fan Jerry Wojcik visited the Bills website to read news about the team and learned about the Bills text alerts program, under which fans could sign up to receive team news by text message. The program was explicitly opt-in; only fans who signed up would receive text messages. Further, subscribers could cancel their subscriptions at any time. The program description was quite specific, reading, in part: “You will be opted in to receive 3-5 messages per week for a period of 12 months. Text STOP to cancel.”

Mr. Wojcik signed up for the text program and began receiving texts. One week, he allegedly received 6 messages. Another week, he allegedly received 7. Noting that the program terms had stated that he would receive 3-5 messages per week, he sued, on behalf of himself and all others similarly situated, alleging a massive violation of the TCPA and seeking damages of up to $1500 for every text above the permitted 5/week. A year and a half later, the parties have agreed to a settlement potentially worth as much as $3 million (depending on the number of claimants who come forward), including approximately $500,000 in attorneys’ fees and costs for Wojcik’s lawyers.

Thursday, January 30, 2014

Traps for the Unwary: California’s Prop 65

In a previous blog post in our ongoing series about legal and regulatory challenges specific to the multichannel merchant, I indicated that I would next discuss quirky California laws that can create traps for unwary merchants. The first of these is one of the many voter-initiated statutes enacted by referendum in California. Popularly known as Prop 65, the Safe Drinking Water and Toxic Enforcement Act of 1986 requires the State of California to publish a list of chemicals known to cause cancer or birth defects or other reproductive harm. This list, which must be updated at least once a year, has grown to include approximately 800 chemicals since it was first published in 1987.

Many of the chemicals on the list are present in common, every day products, and would require massive doses every day for a lifetime to produce an observable effect. For example, acrylamide is a chemical found in many common food products such as potato chips, breads, coffee, tomato sauce, breakfast cereal, and fruit preserves.  See http://www.consumerfreedom.com/2009/11/4024-lawyer-math-1-1-prop-65 But an individual would have to consume massive quantities of any of these foods every day to create any kind of appreciably increased cancer risk.  See id.  Nevertheless, Proposition  65 requires businesses to notify Californians about the presence of acrymalide and hundreds of other chemicals in the products they purchase.

Friday, July 19, 2013

Report, Recall, or Both: Do You Know Your Obligations Under the Consumer Product Safety Act?

Manufacturers, importers, distributors, and retailers of consumer products have a legal obligation to report hazardous or dangerous products to the Consumer Product Safety Commission ("CPSC"). Failing to do so may result not only in large civil penalties, but also criminal prosecution. But, there are many common myths and misconceptions about this reporting requirement and how it relates to the separate question of whether a product recall ought to be commenced. Here are just a few:

Myth One: “I only need to report to the CPSC if someone is injured by a product I sell.”

In truth, a reporting obligation can arise if not a single consumer has been injured. The law requires the reporting of “unreasonably hazardous or dangerous” products that pose a risk to consumers—even if the risk of harm has never been realized. The possibility of harm, alone, triggers a reporting obligation.

Myth Two: “I can avoid the need to report simply by sending a communication to my customers telling them how to avoid being injured by the product.”

Tuesday, April 26, 2011

Commercial Privacy Bill of Rights Introduced in Congress

The introduction of the so-called Commercial Privacy Bill of Rights by Senators Kerry and McCain on April 12, 2011 suggests that we may be about to enter an era of robust regulation of information gathering regarding the online browsing and shopping habits of consumers. This type of data has come to be an important tool for online marketers to improve the efficiency of online advertising buys, and to improve other marketing techniques. At a minimum, this development presents a risk that online merchants will need to build out substantial new technical infrastructure to accommodate a welter of new rules under this bill. Beyond that, it may make it difficult even for highly respected and responsible merchants to engage in marketing activities that are an important part of their tool kit in the information age.

Among other things, the bill contains the following requirements:
  • Collectors of information must implement security measures to protect the information they collect and maintain.
  • Collectors of information must provide clear notice to individuals of the collection practices and the purposes of such collection. Additionally, collectors must provide the ability for an individual to opt out of any information collection that is unauthorized by the Act and to provide affirmative consent (opt-in) for the collection of sensitive personally identifiable information. Respecting companies’ existing relationships with customers and the ability to develop a relationship with a potential customers, the bill would require "robust and clear" notice to an individual of his or her ability to opt-out of the collection of information for the purpose of transferring it to third parties for behavioral advertising. It would also require collectors to provide individuals either the ability to access and correct their information, or to request cessation of its use and distribution.
  • Collectors must bind third parties by contract to ensure that any individual information transferred to the third party by the collector will only be used or maintained in accordance with the bill’s requirements. The bill requires the collector to attempt to establish and maintain reasonable procedures to ensure that information is accurate.

Monday, March 28, 2011

Update to eMarketers: Canada’s FISA Broader than US’s CAN-SPAM Act

Last late year, Canada enacted the Fighting Internet and Wireless Spam Act (FISA).  The framework established by FISA is fundamentally different from the United States’s CAN-SPAM Act.  First, while CAN-SPAM applies only to commercial email, FISA applies to any form of electronic message sent for marketing purposes (referred to as a “Commercial Electronic Message,” or “CEM”), including: email; SMS; instant messaging; and social media/networking. U.S. regulations have not to this point targeted communications with customers across social media.

Second, and perhaps more significantly from the standpoint of most U.S. firms, FISA requires affirmative consent from a potential recipient of a message before marketers can send a CEM.  This feature of the law stands in sharp contrast to CAN-SPAM, which permits at least “one free shot” at a recipient, provided that the message itself is CAN-SPAM compliant (ie. the message includes opt-out instructions, clearly identifies the sender, identifies itself as commercial email, etc.).

Accordingly, U.S. companies now will need to differentiate their approach to marketing to Canadian customers from their approach to marketing to U.S. customers in order to ensure compliance with both the Canadian and U.S. statutes.  Commonly utilized techniques for acquiring contact information, such as list rental, if used to market to Canadian customers, now have the potential to expose marketers to a violation of FISA.

Friday, July 2, 2010

B&I Files Constitutional Challenge to Colorado Notice and Reporting Law for The Direct Marketing Association

We've blogged frequently about Colorado's new notice and reporting law (see here and here).

Since our last posts on the topic, Brann & Isaacson's George Isaacson and Matthew Schaefer filed suit in federal district court in Colorado on behalf of The Direct Marketing Association in The Direct Marketing Association v. Roxy Huber.  Filed on June 30, the suit challenges the constitutionality of the new Colorado law.

The Colorado statute, which targets out-of-state retailers, purports to require those retailers to notify Colorado customers of their obligation to self-report use tax and to require those same retailers to turn over confidential purchasing information regarding Colorado customers to the Colorado Department of Revenue. In the complaint, the DMA, the leading global trade association of direct marketing businesses and nonprofit organizations, asserts that the Colorado statute discriminates against interstate commerce, exceeds the State’s regulatory authority over out-of-state businesses, violates the privacy rights of Colorado consumers, infringes the free speech and due process rights of retailers and consumers, and exposes confidential consumer information to the risk of unauthorized disclosure.

We'll continue updating you as developments arise.

Have a safe and happy Independence Day!

Friday, May 21, 2010

Colorado Enacts Law on Gift Cards; Update on Other States’ Cash Redemption Rules

Amidst the hullaballoo over Colorado’s recently enacted affiliate nexus and out-of-state vendor reporting requirements and its recent economic nexus regulation, Colorado also passed a new law regarding gift cards.

Under the new law, signed by Governor Ritter on April 29, issuers of gift cards, including actual cards and electronic cards, must redeem the remaining value of a gift card for cash if there is $5 or less remaining on the card and the holder of the card so requests. Additionally, sellers may not sell gift cards which contain a service fee, dormancy fee, inactivity fee, maintenance fee, or any other type of fee. The new law does not apply to gift cards which are useable with multiple sellers, unless the multiple sellers are affiliated sellers. Violations of the new statute are deemed deceptive trade practices under Colorado law.

Other states have similar laws and/or pending legislation regarding cash refunds for low balances on gift cards and certificates:

Friday, May 7, 2010

The "Draft" Federal Privacy Bill: Uniformity, But at What Cost?

On May 3, 2010, Representatives Rick Boucher, Democrat of Virginia, and Cliff Stearns, Republican of Florida introduced a “discussion draft” of a bill “[t]o require notice to and consent of an individual prior to the collection and disclosure of certain personal information relating to that individual.”  The bill seeks to provide uniform, national regulation of information collection and disclosure practices for a wide range of companies--governing not only the Internet, but all other channels of interaction between businesses and consumers--and it has already generated controversy.  Not only does it include a definition of private information that goes far beyond all existing laws, it contains strict notice and consent provisions that may be difficult and costly to implement.  It is unclear what triggered the drafting of the bill, nor what compelling public interest would warrant such a degree of intrusion into private business practices.

It is important to keep the draft bill in perspective.  Numerous privacy and security bills have been proposed over the years and Congress has, to date, been unable to pass anything coming close to comprehensive national legislation.  For example, repeated attempts to pass federal security breach legislation have failed, resulting in a plethora of state laws which are both confusing and inconsistent.  If Congress can't bring itself to pass uniform rules dealing with the very real issue of security breaches involving the theft or loss of sensitive personal information, the likelihood of it passing a comprehensive law governing the collection and use of personal information -- a far less serious matter -- seems limited, at best.

Nevertheless, it remains useful to examine the bill and how it addresses key issues that affect eCommerce companies.  Even if the bill fails to gather support in Congress, individual states may feel inspired to adopt some of its provisions.

Tuesday, May 4, 2010

Should You Be FACTA Compliant? -- June 1, 2010 Deadline for Compliance with the FTC’s Red Flags Rule Approaches

Under the Fair and Accurate Credit Transactions Act (“FACTA”), Congress in 2003 mandated that businesses which extend credit to consumers for personal, family or household purposes must adopt policies and procedures designed to identify instances of possible “identity theft” in connection with transactions/requesting such credit.  The regulations promulgated by the Federal Trade Commission (“FTC”) implementing FACTA’s provisions are referred to as the “Red Flags Rule,” because the procedures adopted by businesses are supposed to identify “red flags” that signal a risk of identity theft in connection with a consumer credit transaction.  After deferring the effective date of the Red Flags Rule four times, the deadline for affected businesses to comply is now June 1, 2010.

On its face, FACTA would not appear to apply to many direct marketers or Internet sellers, who most often do not extend credit, themselves, but instead rely on credit cards.  The requirements of FACTA, however, extend to those retailers that sell products or services on installment plans or otherwise extend credit to consumers.  In addition, retailers that offer private label or co-brand credit cards (i.e. the retailer’s name appears on the credit card) may also be affected, even if they do not act as the issuer of the card.  This is because the FTC’s Red Flags Rule also applies to service providers and others who assist creditors (the card issuer) in receiving or processing requests for credit.  Furthermore, FTC staff has indicated their intent to apply the Red Flags Rule very broadly, so that the rule may be applied even to transactions involving the extension of credit to sole proprietorships, on the theory that such transactions involve a risk of identity theft for the individual operating such a business.

Tuesday, April 27, 2010

Cybersquatting and the UDRP

Recently, I was a guest lecturer at the trademark law class at the University of Maine School of Law, invited by my colleague, Rita Heimes, director of the Maine Center for Law and Innovation.  I always enjoy an opportunity to discuss trademark law in an academic setting, and it is invigorating to meet aspiring young trademark lawyers.

The topic for my talk was the Uniform Dispute Resolution Policy (“UDRP”). For those unfamiliar with this policy, it helps protect businesses against “cybersquatting.”  For instance, if the owner of the Acme brand discovers that the domain name "acme.com" is registered by someone else, and is being used in bad faith, the UDRP is the most effective tool available for Acme to recover that domain name.  Prior to the creation of the UDRP, the prospects for success in a domain name dispute were uncertain, and the costs were potentially exorbitant.  In the mid to late 1990's, when widespread use of the Internet was first becoming prevalent, it was unclear whether existing trademark doctrine enabled the recovery of a domain name in this manner, and in any event, the only way to find out was to launch an expensive and time consuming lawsuit.  This time period was typified by a “gold rush” for ownership of domain names and many famous brand owners discovered to their dismay that their best option for securing the all-important “.com” domain name was to pay millions of dollars to the prescient person who had beaten them to the punch.

The UDRP was introduced at the insistence of brand owners by the Internet Corporation for Assigned Names and Numbers (“ICANN”), the entity that governs the allocation of Internet "real estate," in order to address the gap left by preexisting law.  Any person registering a domain name must consent to participation in the UDRP’s form of alternative dispute resolution, and agree to abide by the dispute resolution’s results. Typical costs to recover a domain name using this process are between $1500 and $3000, the success rate is very high (around 85%), and the process can be completed in a month or less.  The UDRP has been around for more than 10 years and has been used very effectively by brand owners to recover millions of improperly registered or used domain names.  Accordingly, it no longer qualifies for "cutting edge" status, although it is surprising how many brand owners remain unfamiliar with it.

In the course of preparing my remarks, however, I also had occasion to delve into some of the remaining challenges in this area, and to explore recent noteworthy developments. 

Wednesday, April 14, 2010

California Follows Colorado Down the Rabbit Hole

As we wrote last month, Colorado recently enacted legislation requiring retailers that do not collect Colorado sales tax to provide a list of their Colorado customers and the amount of Colorado purchases to the State Department of Revenue on an annual basis. Retailers must also inform purchasers of their duty to remit use tax and provide purchasers an annual statement of their purchases.

In that entry, Matt Schaefer wrote, “Voters in other states beware.” In fact, just days before Colorado’s bill was signed into law, the California Assembly introduced its own, similar legislation: AB 2078, as amended April 5, 2010. The bill is currently before the Assembly’s Committee on Revenue and Taxation. If passed in its current form, California would institute Colorado-type reporting requirements which, like Colorado’s law, are potentially in violation of Quill, discriminate against interstate commerce, and certainly invade consumers’ privacy.

Monday, April 12, 2010

Are You Selling "Children's Products"?

When Congress passed the Consumer Product Safety Improvement Act (the “CPSIA”) in 2008, it included a new definition of what constitutes a "children's product." Along with that new definition came a host of onerous testing, certification, and product design/composition standards. If the products you're selling fall into this category, your legal obligations expand dramatically to include third-party certification, substrate testing for lead, prohibitions on phthalates, product tracking labels, and more.  And so, the question of "What is a children's product?" becomes extraordinarily consequential for wholesalers, retailers, "private labelers," and importers.

As is traditionally the case with "age grading" of products, the CPSIA's definition generalizes things to the point of providing very little practical guidance on many products.  Under the new regime, a "children's product" is "a consumer product designed or intended primarily for children 12 years of age and under." While it is one thing to say roughly which products are intended for children who are two, or four, or six, or even eight, products of interest to many twelve-year-olds also appeal to older teens and even adults. Is a product primarily intended for twelve-year-olds if it broadly appeals to teenagers, for example? How closely must you parse the demographics of potential customers to figure out whether your audience is likely to be "primarily" twelve-year-olds? Coupling this with analysis of design aims and product "intentions" makes matters even more complex.

Into this analytical quagmire, the Consumer Product Safety Commission (“CPSC”) has now dropped 50 pages of industry guidance, including a brand new proposed regulation.  Once you dive in, it doesn't take long to realize that some of the products you thought were children's items may not be. Worse yet, some products that you reasonably might have concluded were "not designed or primarily intended for children 12 years" or younger may well be viewed very differently by the CPSC.  In other words, the CPSC has raised as many questions as it answers.

Thursday, March 25, 2010

What’s Next For Sales Tax (a/k/a Use Tax) On Direct Mail?

Direct marketers know that successful eCommerce strategies often depend upon reaching customers offline as well as online. Direct mail, including the distribution of catalogs, remains one of the most effective ways of driving traffic to a website. Indeed, given the reluctance of some consumers to give out their e-mail addresses, and the protections afforded consumers from unwanted solicitation under anti-SPAM, Do-Not-Call and other consumer privacy laws, traditional “snail mail” marketing techniques remain an important way for Internet sellers to communicate directly with customers.

Although several larger states (including California, New York, and Pennsylvania) provide exemptions from tax for certain types of direct mail, the vast majority of jurisdictions treat direct mail as taxable. And in all states, including those that provide exemptions, there are myriad other complex legal issues affecting taxability, including sourcing rules, taxability of postage, “direct mail” certificates, and nexus considerations, each of which make determining the proper sales tax treatment of direct mail transactions challenging. Add the fact that mailings go to recipients in many, if not all 50 states (and countless localities), each of which has its own tax law, and the difficulty of properly applying tax to any particular direct mail transaction multiplies exponentially.

Wednesday, March 17, 2010

Facebook: Not Just For Friends?

The Obama Administration is considering sending federal officers undercover on Facebook and other popular social networking sites. This effort raises a number of interesting questions, some legal, some not. For example, would the feds work with Facebook, or simply register, and silently patrol the social network looking for leads? If they went with the cooperative approach, just how much help could Facebook provide given its privacy policy and terms of use? Would it unlock the kingdom based upon an informal request, or would it require a subpoena or search warrant to comply? And, if the government decided to slip into the system without alerting Facebook, would it be required to follow Facebook's terms of use -- such as providing real names and contact information? What are the consequences if a person "tricks" someone into being their friend?

A confidential Department of Justice presentation obtained by the Electronic Frontier Foundation sheds some light on these issues, and also provides useful guidance in the crafting of privacy policies and terms of use by eCommerce companies, including those who provide social networks or online communities.

Tuesday, March 16, 2010

Think You’re Safe Storing or Releasing “Anonymized” Data? Think Again.

Anonymity is increasingly difficult to safeguard, and direct marketers that collect, maintain, share, and use customer information should take note of a recent class action settlement by Netflix than stemmed from the company's disclosure of an "anonymized" customer database.

Most federal and state privacy and data security statutes focus on the protection of "personally identifiable information," such as names, addresses, telephone numbers, financial account numbers, social security numbers, and email addresses. In response to such laws, many companies strip personally identifiable information from databases containing sensitive information. Once stripped of identifiers, the theory goes, the risks of identity theft or violations of consumer privacy rights resulting from disclosure of the data (whether purposeful or not) are eliminated. Some companies may even conclude that the data may be shared for marketing or "data mining" purposes without violating their privacy policies or applicable laws.

According to the Electronic Privacy Information Center, however, "computer scientists have revealed that this 'anonymized' data can easily be re-identified, such that the sensitive information may be linked back to an individual."

Gift Cards: The Sleeping Dog

Many of you may have read about the federal Credit Card Accountability, Responsibility, And Disclosure Act of 2009 (the “CARD Act”). While the CARD Act largely regulates the terms and conditions for credit cards, it also provides certain protections for purchasers of gift cards that will go into effect on August 22, 2010. But many people may not be aware that the CARD Act does not preempt or otherwise supersede state laws on gift cards, either before August 22 or afterwards.

There are many states that have gift card laws that bar the use of expiration dates on purchased gift cards, prohibit or set restrictions on imposing inactivity fees or other charges with regard to gift cards, and/or require disclosures regarding fees and expiration dates. Some of these laws are enforceable by the attorneys general of the states and/or through suits brought by consumers.

Thursday, March 11, 2010

Colorado's HB 1193 Risks Constitutional Violations and Threatens Consumer Privacy

The assault on eCommerce by short-sighted state legislators and tax officials continues. By now, many of you have heard or read about the new Colorado law (HB 1193) enacted in February, that imposes certain sales tax notice and reporting obligations upon each “retailer that does not collect Colorado sales tax.” Under the law, most non-collecting retailers are required:

(a) beginning effective March 1, 2010, to inform their Colorado purchasers of the purchaser’s duty to remit use tax on certain purchases under Colorado law;

(b) beginning in January 2011, to provide Colorado purchasers an annual statement of all of their Colorado purchases from the retailer; and

(c) beginning in January 2011, to file annually with the Colorado Department of Revenue a list of all purchasers and the amount of their Colorado purchases.

LifeLock: $12 Million to Settle Data Security False Advertising Claims

The company whose advertising campaign included displaying their CEO's social security number on the side of a truck has reached a settlement to pay $12 million to the FTC and 35 states who charged LifeLock, Inc. with false representations about the effectiveness of its services. In an official press release, FTC Chairman Jon Leibowitz said that “[w]hile LifeLock promised consumers complete protection against all types of identity theft, in truth, the protection it actually provided left enough holes that you could drive a truck through it.”

But the case against LifeLock didn't end there. The FTC and the states also charged LifeLock with making false claims about its own data security practices. According to the FTC, LifeLock failed to live up to the following representations:

The WISP Has (Finally) Landed: MA's Data Protection Law Now In Effect

After a seemingly unending series of delays and modifications, Massachusetts's data protection regulation finally went into effect on March 1, 2010. A copy of the regulation can be obtained here. Unlike the data protection laws of most states, the Massachusetts regulation requires holders of data to put in place a comprehensive set of written measures to protect confidential information (also known as a "WISP," or “written information security policy”), and to update their WISPs on an annual basis. The required contents of the WISP are outlined in the regulation, and cover topics ranging from encryption to vendor agreements.

Thumbnail: The new regulation applies to all persons and companies who either own or license personal information about residents of Massachusetts, and applies both to electronic and paper records. While the opening clause of the regulation appears to limit its coverage to "customer information" and "consumers," the balance of the regulation does not distinguish between information about customers, consumers, employees, or other categories of persons. If past experience with the administrative process in Massachusetts is any guide, it will be a long and winding road before we get any formal guidance as to the regulation’s scope.