December 2017ENTERPRISE SECURITY| | 9be very confident that their permission is implicit in the action they're taking, before collecting and storing it.COPPAShort-hand for the Children's Online Privacy Protection Act, the important thing to know here is that the U.S. Federal Trade Commission treats the personal information of children under the age of 13 very differently from that of adults.Just ask Yelp. When it created a streamlined process for subscribers to sign up via a mobile app, the company neglected to ask for an applicant's date of birth. As a result, children signed up, Yelp didn't get parental approval for those signups, and the FTC delivered a $450,000 fine for a violation of COPPA.If you're working with children's data, be very explicit that you are getting parental permission to collect the data, offering parents a choice as to whether children's data will be shared with third parties and provide parents access to their children's data should they want to delete that data.Or better yet: Make sure you and your team is very familiar with the entirety of COPPA.LocationOh, sure, real estate professionals have always told you that it's all about location, location, location, but the digital age is radically changing the way we think about location data.Researchers have shown that just four data points can be enough to identify an individual person and regulators are increasingly protective of location data, especially when it's being collected without a user's knowledge.Case in Point Golden shores, which created a very popular flashlight app, in order to generate revenue served ads through this free download. And to serve targeted ads, the company gathered location data of its users. Unfortunately, they didn't tell users they were doing this. One consent decree with the Federal Trade Commission later, Golden shores finds itself being audited by a third party for the next 20 years.Sure, this is about that consent thing we were talking about earlier, but it's also an emphasis that location data is now very much sensitive and personal data and your organization needs to make sure everyone involved knows when it's being collected. Trans Border Data Flow I don't have to tell you that we live in a global market place, but many businesses don't realize their obligations for dealing with data collected from citizens of other countries. Particularly Europe, but also Canada, Australia and many Asian, African and Latin American countries have privacy laws and regulations that are different from the U.S. regime.Do you have a business relationship with that Canadian to whom you're sending an email? Can you document that it's been active within the last six months? Getting the answer wrong could result in $1 million or more in fines. Are you able to produce the data you have about an EU citizen upon request? Failing to do so could lead to regulatory headaches even if you are a US-based business.These are questions even small companies need to be able to answer with confidence when doing business nowadays. It's vital that you and your staff understand the global data privacy regulatory environment if you want to do business around the world.There are, of course, a host of other terms a smart business operating in the digital economy needs to know as well transparency, hashing, pseudonymity, unique identifier and more. As a CIO, terms like these that get at the heart of privacy must begin to enter your vocabulary and the questions you ask of your teams in product development, HR, marketing, IT and all the other departments in your organization that work with data.Learning them now, and spreading the word, will prepare your organization to take advantage of the many opportunities offered by the digital age. ESYour familiarity with these terms might be the difference between a successful product launch and an FTC investigationTrevor Hughes
<
Page 8 |
Page 10 >