Showing posts with label CAN-SPAM. Show all posts
Showing posts with label CAN-SPAM. Show all posts

Tuesday, April 26, 2011

Commercial Privacy Bill of Rights Introduced in Congress

The introduction of the so-called Commercial Privacy Bill of Rights by Senators Kerry and McCain on April 12, 2011 suggests that we may be about to enter an era of robust regulation of information gathering regarding the online browsing and shopping habits of consumers. This type of data has come to be an important tool for online marketers to improve the efficiency of online advertising buys, and to improve other marketing techniques. At a minimum, this development presents a risk that online merchants will need to build out substantial new technical infrastructure to accommodate a welter of new rules under this bill. Beyond that, it may make it difficult even for highly respected and responsible merchants to engage in marketing activities that are an important part of their tool kit in the information age.

Among other things, the bill contains the following requirements:
  • Collectors of information must implement security measures to protect the information they collect and maintain.
  • Collectors of information must provide clear notice to individuals of the collection practices and the purposes of such collection. Additionally, collectors must provide the ability for an individual to opt out of any information collection that is unauthorized by the Act and to provide affirmative consent (opt-in) for the collection of sensitive personally identifiable information. Respecting companies’ existing relationships with customers and the ability to develop a relationship with a potential customers, the bill would require "robust and clear" notice to an individual of his or her ability to opt-out of the collection of information for the purpose of transferring it to third parties for behavioral advertising. It would also require collectors to provide individuals either the ability to access and correct their information, or to request cessation of its use and distribution.
  • Collectors must bind third parties by contract to ensure that any individual information transferred to the third party by the collector will only be used or maintained in accordance with the bill’s requirements. The bill requires the collector to attempt to establish and maintain reasonable procedures to ensure that information is accurate.

Monday, March 28, 2011

Update to eMarketers: Canada’s FISA Broader than US’s CAN-SPAM Act

Last late year, Canada enacted the Fighting Internet and Wireless Spam Act (FISA).  The framework established by FISA is fundamentally different from the United States’s CAN-SPAM Act.  First, while CAN-SPAM applies only to commercial email, FISA applies to any form of electronic message sent for marketing purposes (referred to as a “Commercial Electronic Message,” or “CEM”), including: email; SMS; instant messaging; and social media/networking. U.S. regulations have not to this point targeted communications with customers across social media.

Second, and perhaps more significantly from the standpoint of most U.S. firms, FISA requires affirmative consent from a potential recipient of a message before marketers can send a CEM.  This feature of the law stands in sharp contrast to CAN-SPAM, which permits at least “one free shot” at a recipient, provided that the message itself is CAN-SPAM compliant (ie. the message includes opt-out instructions, clearly identifies the sender, identifies itself as commercial email, etc.).

Accordingly, U.S. companies now will need to differentiate their approach to marketing to Canadian customers from their approach to marketing to U.S. customers in order to ensure compliance with both the Canadian and U.S. statutes.  Commonly utilized techniques for acquiring contact information, such as list rental, if used to market to Canadian customers, now have the potential to expose marketers to a violation of FISA.