Enforcment Of US Privacy And Security Laws Flashcards
Civil litigation
Occurs in the courts
Plaintiff sues the defendant
Plaintiff usually seeks money or injunction ( mandating the defendant to stop engaging in certain behaviors)
What are important categories of civil litigation?
Contracts - suing someone for breach of contract
Torts - suing someone for invasion of privacy
Criminal litigation
Lawsuits brought by the government for violations of criminal laws
Can lead to imprisonment or fines
Criminal litigation is prosecuted by who in the federal government and state?
Federal - department of justice
State - attorney general or district attorneys
What is the FTC enforcement process and consent decrees?
When the Respondent of a FTC privacy enforcement action does not admit fault but promises to change its practices and avoids further litigation on the issue
Deceptive trade practices
Must involve a material statement or omission that is likely to mislead consumers who are acting reasonably under the circumstances
Examples - false promises, misrepresentations, failure to comply with representations made to consumers
Unfair trade practices
Failing to implement adequate protection measures for sensitive personal information or when they provided inadequate disclosures to consumers
Unfair claims can exist even when the company has not made any deceptive statements The injury must be - substantial - lacks offsetting benefits - cannot be easily avoided by consumers.
What is the GPEN?
Global privacy enforcement network
Promotes cross border information Shari g as well as investigation and enforcement cooperation among privacy authorities around the world
How can Self regulatory enforcement occur?
Can occur through 3 separation of power components
Some self regulatory systems engage in all 3 roles without the enforcement of a government agency (PCI)
Section 5 of the FTC act can bring enforcement actions and adjusticstion
Administrative enforcement actions
Actions carried out pursuant to the statutes (COPPA, TSR) that create and empower an agency (FTC and FCC)
When may a person sue based on a violation of law?
When a law create a private right of action
Example: fair credit reporting act (FCRA) allows individuals to sue a company if their consumer reports have been used inappropriately
What acts give the FTC power to govern privacy issues?
FTC act section 5
Fair credit reporting act (fcra)
Children’s online privacy protection act (COPPA)
Controlling assault of non-solicited pornography and marketing (CAN-SPAM)
Telemarketing sales rule
Administrator procedure act
In the federal government the basic rules for agency enforcement actions occur under this act.
Sets forth basic rules for adjudication within an agency where court like hearings may take place before an administrative law judge
What incentives does a company and the FTC have to negotiate a consent decree rather than proceed with full adjudication?
Company avoids a long trial, avoids having the details of its business practices exposed to the public and negative publicity
FTC - achieves a consent decree that incorporates good privacy and security, avoids the expense and delay of a trial, gains an enforcement advantage because monetary fines are easier to access in court if a company violates a consent decree than if one is not in place
What are the consumer privacy bill of rights under the White House report by Obama?
Individual control Transparency Respect for context Security Access and accuracy Focused collection Accountability
What is in the FTC privacy report?
Privacy by design
Simplified consumer choice
Transparency