EU-U.S. Privacy Shield Review Report Outlines Steps To Improve Enforcement and Monitor Compliance

The Privacy Shield – a mechanism by which U.S. companies can legally transfer data to the European Union, continues to draw the attention of regulators and policymakers. On December 19, 2018, the European Commission (the Commission) announced the publication of its report on the second annual review of the EU-U.S. Privacy Shield. The report offers companies insight into what aspects of the Privacy Shield officials find most important and what steps are planned to strengthen enforcement and oversee compliance. Background The EU-U.S. Privacy Shield is a framework for transatlantic exchanges of personal data for commercial purposes between the European Union and the United States. Companies must self-certify that they meet the requirements of…

READ MORE

U.S. Federal Trade Commission Begins Hearings on Competition and Consumer Protection in the 21st Century

On September 13 and 14, the Federal Trade Commission (FTC), together with Georgetown University Law Center, will co-sponsor the first in a series of Hearings on Competition and Consumer Privacy in the 21st Century. These public forums will consider whether changes in the economy, technology, and emerging business practices warrant changes to law, enforcement and policy. Specifically, they will consider whether these changes require expansion of the FTC’s enforcement power over corporate privacy practices. At a House of Representatives subcommittee meeting on July 18, FTC Chairman Joseph Simons’ stated that the FTC’s current authority to do so, under Section 5 of the FTC Act, is inadequate. A Federal…

READ MORE

FTC Settles Complaint Against Venmo

On February 27, the Federal Trade Commission (FTC) reached a settlement with Paypal, Inc. relating to the privacy and security practices of Venmo, Paypal’s peer-to-peer payment service. The FTC alleged that Venmo failed to adequately disclose to its users that transfers of funds from their Venmo balances to external bank accounts were subject to review, and such funds could be frozen or removed in cases of suspected fraud. The FTC’s complaint also charges that Venmo misled users about the scope of Venmo’s “bank grade security systems,” as well as the extent to which users could control the visibility of their transactions. Venmo allows individuals to send and receive…

READ MORE

U.S. Regulators Convene Workshop on Privacy Risks and Harms

Compliance with the European Union’s General Data Protection Regulation (GDPR), scheduled to take effect in May 2018, has taken center stage for companies. But it is important to remember that regulators in the U.S. continue their own work to protect the privacy interests of consumers. The Federal Trade Commission (FTC) took the spotlight on December 12, 2017, when it hosted a one-day workshop titled “Informational Injury” in Washington DC. The event brought together a variety of stakeholders – including industry representatives, consumer advocates, academics and government researchers – to discuss issues related to the injuries consumers suffer when information about them is misused. In opening remarks, Acting FTC Chairwoman…

READ MORE

U.S. Federal Trade Commission Announces Settlement of First Privacy Shield Enforcement Action

On September 8, 2017, the Federal Trade Commission (FTC) announced settlement of its first enforcement action involving the terms of the Privacy Shield. Three companies – Decusoft, LLC, Tru Communication, Inc., and Md7, LLC were alleged to have violated the Federal Trade Commission Act (FTC Act) by falsely claiming that they were certified to the EU-U.S. Privacy Shield. In fact, they had not completed the certification process required. One of the companies, Decusoft, falsely claimed not to be certified to the Swiss-U.S. Privacy Shield. As part of their settlements with the FTC, the companies are prohibited from misrepresenting the extent to which they participate in any privacy or…

READ MORE