Showing posts with label California Privacy. Show all posts
Showing posts with label California Privacy. Show all posts

Friday, December 13, 2013

Song Beverly Strikes Again: Email Address Collection Added to Potentially Worrisome Activity

As we've previously blogged, retailers who sell products to consumers in California and Massachusetts, as well as a number of other states, run the risk of costly class action lawsuits if they collect customer zip codes in connection with purchase of goods by credit card.  The prohibitions in those states, as we've explained, often go beyond zip codes, and can include -- in California, for example -- any information that does not appear on the face of the credit card.

A recent decision by the United States District Court in California involved the collection of e-mail addresses in credit card transactions, and found against a retailer on a motion dismiss -- propelling the case to trial.  That decision adopted what some might call an inordinately expansive interpretation of the underlying law by the Supreme Court of California, and made things far worse by adding an apparent misreading of the statute to the mix.  Not for the faint of heart, but certainly important for the prudent direct marketer who hopes to avoid costly and sometimes bogus lawsuits, the decision helps underscore the risks faced by even the most diligent companies -- risks high enough that companies are often forced to settle when they know in their heart of hearts that they're right.

Friday, October 25, 2013

California Ups the Ante On Privacy Policy Disclosures

For the past decade, California law has set the template for commercial website privacy policies.  With the passage of a new law, set to take effect January 1, 2014, the state has updated the disclosures required of any commercial website operator who collects personally identifiable information from California residents.

California’s Online Privacy Protection Act.   In 2003, California became the only state to require all websites that collect personal information (“PII”) from visitors – in this case, California residents – to post a privacy policy.   Until then, there was no generally applicable privacy policy requirement under either state or federal law, and, to this day, neither the other states nor the federal government have imposed such a requirement.  Federal privacy policy requirements have been limited to specific kinds of information (such as under Children’s Privacy Protection Act) or industries (under the Health Insurance Portability and Accountability Act).  Under the 2003 law, Internet sites need to identify the “categories” of personally identifiable information collected about “individual consumers”; describe the “categories” of third parties with whom the information may be shared; disclose (if there is one) any process for individuals to review or request changes to their personal information; explain how notice is given to consumers of changes in the privacy policy; and post the policy’s effective date. The definition of PII is more expansive than encountered in data breach statutes, and includes email addresses, partial addresses (including street names and towns), and first and last names.  The privacy policy also must be “conspicuously” posted, as defined by the statute.

Now, however, the law has been significantly expanded.