SlideShare a Scribd company logo
1 of 22
Old COPPA, New COPPA
“Get Out of Jail Free”
500 Startups – MamaBear Conference
Presented by Shai Samet
May 10, 2013
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Basic COPPA equation
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
2
personal
information
collected from
child under 13
via the web
(site, app, tablet, etc.)
Verifiable Parental Consent
(plus other requirements)
User acquisition costs
(kidSAFE survey – Jan 2013)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
3
Companies polled: AOL, Fantage, Gaia Online, Highlights for Kids, Pearson, TBS, WebKinz, many others
Penalties for non-compliance
• Up to $16,000 per violation
• Over 20 FTC lawsuits and $8.4 million in fines since 2000
• Recent fines for COPPA violations:
– Path (app developer) – $800,000
– Artist Arena (various music artist sites) – $1,000,000
– RockYou (social game site) – $250,000
– Disney’s Playdom (for violations by acquired company) – $3,000,000
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
4
Old COPPA vs. New COPPA
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Key information and features
regulated under new COPPA
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
6
CONTACT INFO
First and Last Name
Home/mailing address
Email address
Phone numbers
Social Security Number
“personal information”
SCREEN/USER NAME
“personal” in some scenarios
(email, AIM, Skype name, etc.)
THIRD PARTY PLUG-INS
Integration with no VPC
means strict liability
GEOLOCATION
“personal” unless location is
not detailed enough
BEHAVIORAL ADS/PROFILES
“personal” if tracking across
multiple services & over time
PHOTOS, VIDEOS, AUDIO
“personal” if contains
image or voice of child
Photos, videos, audio files
(SnapChat, Faces iMake illustrations)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
7
temporary viewing by others = “collection/disclosure”
faces alone (with no other PI) = VPC
Geolocation information
(News-O-matic illustration)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
8
Opt-in prompt not enough under new COPPA
Consider coarse location or not uploading the data
Behavioral ads and social plugins
(WebKinz, NeoPets illustrations)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
9
Behavioral ads no more (contextual ads OK)
FB Connect needs VPC (link to fan page OK)
Verifiable Parental Consent
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Current options for parental consent
Method Providers Limitations
• Email Plus consent
Internally-
implemented
• Requires parent to activate via email comm’s
• Not sufficient if info will be shared/publicized
• Signed consent form N/A
• Manual
• Requires access to printer and scanner/fax
• Not mobile friendly
Monetary transaction
Payment
processors
• Requires credit card entry and payment
• Payment via PayPal also sufficient
• [Collection of iTunes password not sufficient]
• Phone call or video
conference
N/A
• Manual
• Requires live and trained personnel
• Video-conference requires device with camera
• Govt-issued ID Various
• Requires sharing of highly-sensitive information
• Not ideal for foreign users
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
11
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
12
Likelihood of industry adoption
(kidSAFE survey – Jan 2013)
Penalties for non-compliance
(just a reminder)
• Up to $16,000 per violation
• Over 20 FTC lawsuits and $8.4 million in fines since 2000
• Recent fines for COPPA violations:
– Path (app developer) – $800,000
– Artist Arena (various music artist sites) – $1,000,000
– RockYou (social game site) – $250,000
– Disney’s Playdom (for violations by acquired company) – $3,000,000
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
13
Considerations for Startups and Investors
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Scaling user growth
(COPPA techniques and loopholes)
• Anonymize child-directed features
– Limit sign-up process to anonymous info (username, password, etc.)
– For interactive features (chat, UGC), filter on the back-end to avoid upfront consent requirement
– For mobile features (geo-location, photos), keep data local to the device (do not upload/share)
– Utilize COPPA’s parental consent exceptions for other features
• Direct your account sign-up process to older users (when allowed)
– If kids under 13 not your “primary audience”, you can limit registration to users 13 and older
– On sites/apps directed to preschoolers, collect registration info from parents/adults
– Put behavioral ads and social plug-ins behind special parents section (or 13+ section)
• When parental consent is required, use least burdensome method
– Avoid collection of payment solely for consent purposes
– Avoid collection of govt-issued ID (last 4 of SSN, driver’s license)
– Consider email-based consent as first option
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
15
Parent-directed registration
(StoryBots illustration)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
16
Messaging on the page and within data fields must be clearly directed to parents
Parent lock for social features
(StoryBots, TocaBoca app illustrations)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
17
Math problem before access to web or social sharing features
Swipe to access parents section or apps for sale
Most viable revenue streams
(under new COPPA)
• E-commerce and retail (tied to compelling content or experience)
– Virtual goods, subscriptions, premium content/features (e.g., Wizard 101)
– Game/app downloads, in-app purchases (e.g., Minecraft, Toca Boca)
– Tablets, toys, offline merchandise (e.g., Nabi, Skylanders, Moshi Monsters)
– Brands/stories with TV or licensing potential
• Contextual ads
– Display, text, or video ads (all OK)
– NOT behaviorally-targeted or retargeted ads
• NOT models dependent heavily on social sharing/connections
– Hard to scale with current COPPA restrictions
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
18
Distribution ideas
• Kid-directed platforms
– Popular gaming portals (e.g., Miniclip)
– Kids’ tablets (e.g., nabi, Kurio)
– Other curated environments (e.g., Zui.com, Magic Desktop)
• Schools
– For properties with educational, nutritional, or creative utility (e.g., myNutratek, Minecraft)
– Schools/teachers can provide consent in lieu of parents
• Participation in kidSAFE
– Get noticed by users visiting our site from other popular sites/properties
– Reach our growing database of parents
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
19
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
20
About kidSAFE Seal Program
• Leading safety “seal of approval” program
– Certifying kid-directed sites, apps, software, tablets, and other technologies – GLOBALLY
– Over 100 seal holders since public launch in April 2012
– Fast becoming the industry standard for “online safety”
• kidSAFE+ membership offers full COPPA audit
– Qualifiers receive prestigious kidSAFE+ Seal and many other benefits
– Application for FTC approval coming soon
• Business-friendly, responsive, and highly knowledgeable
– Founder is former attorney and long-time COPPA expert
• For more info, visit kidsafeseal.com or email shai@kidsafeseal.com
Some of our customers
WEBANDPC
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
21
MOBILE
Collectively, these few sites alone account for over 15M unique visitors a month in the US alone (Source: Compete.com)
Questions?
(happy to share the deck)
CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY
MUST NOT BE SHARED WITHOUT PERMISSION
Upcoming kidSAFE Webinar on COPPA – May 30, 2013
(featuring open Q&A session with the FTC)
REGISTER HERE

More Related Content

Viewers also liked

Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20500 Startups
 
Fast Company, SMASH summit Presentation
Fast Company, SMASH summit PresentationFast Company, SMASH summit Presentation
Fast Company, SMASH summit Presentation500 Startups
 
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20500 Startups
 
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013500 Startups
 
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....500 Startups
 
Enchanted Diamonds
Enchanted DiamondsEnchanted Diamonds
Enchanted Diamonds500 Startups
 
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013500 Startups
 
Customer Acquisition on Facebook
Customer Acquisition on FacebookCustomer Acquisition on Facebook
Customer Acquisition on Facebook500 Startups
 
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013500 Startups
 
Aaron Batalion, LivingSocial, Lean Startup SXSW
Aaron Batalion, LivingSocial, Lean Startup SXSWAaron Batalion, LivingSocial, Lean Startup SXSW
Aaron Batalion, LivingSocial, Lean Startup SXSW500 Startups
 
unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid 500 Startups
 
Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013500 Startups
 

Viewers also liked (20)

Givesurance
GivesuranceGivesurance
Givesurance
 
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
Whitney Moss w/ Rookie Moms @ MamaBear Conference, Mt. View 4/20
 
Timbuktu
TimbuktuTimbuktu
Timbuktu
 
Dropifi
DropifiDropifi
Dropifi
 
Fast Company, SMASH summit Presentation
Fast Company, SMASH summit PresentationFast Company, SMASH summit Presentation
Fast Company, SMASH summit Presentation
 
Ohmconnect
OhmconnectOhmconnect
Ohmconnect
 
Luca prasso
Luca prassoLuca prasso
Luca prasso
 
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
Startup Pitch by Anya Shapina w/ PixOwl @ MamaBear Conference, Mt. View 4/20
 
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
Daron Akira Hall, Tapastic – Startup Pitch, WarmGun 2013
 
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
Startup Pitch by Chandini Ammineni w/ ActivityHero @ MamaBear Conference, Mt....
 
Enchanted Diamonds
Enchanted DiamondsEnchanted Diamonds
Enchanted Diamonds
 
Dylan Arena
Dylan Arena Dylan Arena
Dylan Arena
 
Reesio
ReesioReesio
Reesio
 
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
Dan Greenberg, Sharethrough, SXSW Lean Startup 2013
 
Customer Acquisition on Facebook
Customer Acquisition on FacebookCustomer Acquisition on Facebook
Customer Acquisition on Facebook
 
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
Tappsi > Apps.co Demo Day in Bogota, GOAP LatAm 2013
 
Aaron Batalion, LivingSocial, Lean Startup SXSW
Aaron Batalion, LivingSocial, Lean Startup SXSWAaron Batalion, LivingSocial, Lean Startup SXSW
Aaron Batalion, LivingSocial, Lean Startup SXSW
 
unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid unSEXY Conf 2013: Isaac Saldana, SendGrid
unSEXY Conf 2013: Isaac Saldana, SendGrid
 
Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013Federico Holgado, Designing for Your Redesign, WarmGun 2013
Federico Holgado, Designing for Your Redesign, WarmGun 2013
 
CultureAlley
CultureAlleyCultureAlley
CultureAlley
 

Similar to Shai samet

Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...- Mark - Fullbright
 
Trending Topics in Data Collection & Targeted Marketing
Trending Topics in Data Collection & Targeted MarketingTrending Topics in Data Collection & Targeted Marketing
Trending Topics in Data Collection & Targeted MarketingcdasLLP
 
The FTC’s Revised COPPA Rules (Stanford Presentation)
The FTC’s Revised COPPA Rules (Stanford Presentation)The FTC’s Revised COPPA Rules (Stanford Presentation)
The FTC’s Revised COPPA Rules (Stanford Presentation)WilmerHale
 
Children Online Privacy Komal Bansal
Children Online Privacy Komal BansalChildren Online Privacy Komal Bansal
Children Online Privacy Komal BansalKomal Bansal
 
Legislation That Internet Marketers Need to Know
Legislation That Internet Marketers Need to KnowLegislation That Internet Marketers Need to Know
Legislation That Internet Marketers Need to KnowKaley Perkins, MA
 
6: privacy terms
6: privacy terms6: privacy terms
6: privacy termsCOMP 113
 
Moochies presentation
Moochies presentationMoochies presentation
Moochies presentationkauepgarcia
 
E safety-slide-presentation
E safety-slide-presentationE safety-slide-presentation
E safety-slide-presentationCandice Wimbles
 
E safety-slide-presentation
E safety-slide-presentationE safety-slide-presentation
E safety-slide-presentationCandice Wimbles
 
Protect Privacy to Protect Your Startup
Protect Privacy to Protect Your StartupProtect Privacy to Protect Your Startup
Protect Privacy to Protect Your StartupDrexelELC
 
Thinking Outside the App: How Real World Forces Inform Kids' Media Development
Thinking Outside the App:  How Real World Forces Inform Kids' Media Development Thinking Outside the App:  How Real World Forces Inform Kids' Media Development
Thinking Outside the App: How Real World Forces Inform Kids' Media Development Robin Raskin
 
Privacy and Security in Mobile E-Commerce
Privacy and Security in Mobile E-CommercePrivacy and Security in Mobile E-Commerce
Privacy and Security in Mobile E-CommerceNow Dentons
 
Digital Coupons: How & Why
Digital Coupons: How & WhyDigital Coupons: How & Why
Digital Coupons: How & WhyM-Dot Network
 
Data Compliance Updates in the US and EU
Data Compliance Updates in the US and EUData Compliance Updates in the US and EU
Data Compliance Updates in the US and EUVbout.com
 
Social Media for School Districts - OTA 15
Social Media for School Districts - OTA 15Social Media for School Districts - OTA 15
Social Media for School Districts - OTA 15Diana Benner
 
Monetization Still A Mystery
Monetization Still A MysteryMonetization Still A Mystery
Monetization Still A MysteryPraveen Alavilli
 
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...iof_events
 

Similar to Shai samet (20)

Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
Children’s Online Privacy Protection Rule- A Six-Step Compliance Plan for You...
 
Business COPPA 6 Steps
Business COPPA 6 StepsBusiness COPPA 6 Steps
Business COPPA 6 Steps
 
Trending Topics in Data Collection & Targeted Marketing
Trending Topics in Data Collection & Targeted MarketingTrending Topics in Data Collection & Targeted Marketing
Trending Topics in Data Collection & Targeted Marketing
 
The FTC’s Revised COPPA Rules (Stanford Presentation)
The FTC’s Revised COPPA Rules (Stanford Presentation)The FTC’s Revised COPPA Rules (Stanford Presentation)
The FTC’s Revised COPPA Rules (Stanford Presentation)
 
COPPA
COPPACOPPA
COPPA
 
Children Online Privacy Komal Bansal
Children Online Privacy Komal BansalChildren Online Privacy Komal Bansal
Children Online Privacy Komal Bansal
 
Legislation That Internet Marketers Need to Know
Legislation That Internet Marketers Need to KnowLegislation That Internet Marketers Need to Know
Legislation That Internet Marketers Need to Know
 
6: privacy terms
6: privacy terms6: privacy terms
6: privacy terms
 
pig-e-bank
pig-e-bankpig-e-bank
pig-e-bank
 
Moochies presentation
Moochies presentationMoochies presentation
Moochies presentation
 
E safety-slide-presentation
E safety-slide-presentationE safety-slide-presentation
E safety-slide-presentation
 
E safety-slide-presentation
E safety-slide-presentationE safety-slide-presentation
E safety-slide-presentation
 
Protect Privacy to Protect Your Startup
Protect Privacy to Protect Your StartupProtect Privacy to Protect Your Startup
Protect Privacy to Protect Your Startup
 
Thinking Outside the App: How Real World Forces Inform Kids' Media Development
Thinking Outside the App:  How Real World Forces Inform Kids' Media Development Thinking Outside the App:  How Real World Forces Inform Kids' Media Development
Thinking Outside the App: How Real World Forces Inform Kids' Media Development
 
Privacy and Security in Mobile E-Commerce
Privacy and Security in Mobile E-CommercePrivacy and Security in Mobile E-Commerce
Privacy and Security in Mobile E-Commerce
 
Digital Coupons: How & Why
Digital Coupons: How & WhyDigital Coupons: How & Why
Digital Coupons: How & Why
 
Data Compliance Updates in the US and EU
Data Compliance Updates in the US and EUData Compliance Updates in the US and EU
Data Compliance Updates in the US and EU
 
Social Media for School Districts - OTA 15
Social Media for School Districts - OTA 15Social Media for School Districts - OTA 15
Social Media for School Districts - OTA 15
 
Monetization Still A Mystery
Monetization Still A MysteryMonetization Still A Mystery
Monetization Still A Mystery
 
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
Digital fundraising the legal bits - Augustus Della-Porta - Bates, Wells and ...
 

More from 500 Startups (20)

Get on Board
Get on BoardGet on Board
Get on Board
 
Connected Analytics
Connected AnalyticsConnected Analytics
Connected Analytics
 
Sira Medical
Sira MedicalSira Medical
Sira Medical
 
The Atlas
The AtlasThe Atlas
The Atlas
 
Trash Warrior
Trash WarriorTrash Warrior
Trash Warrior
 
Thematic
ThematicThematic
Thematic
 
Shiplyst
ShiplystShiplyst
Shiplyst
 
Renetec
RenetecRenetec
Renetec
 
Predina
PredinaPredina
Predina
 
Pluto
PlutoPluto
Pluto
 
Plant an App
Plant an AppPlant an App
Plant an App
 
Pilota
PilotaPilota
Pilota
 
Mero Technologies
Mero TechnologiesMero Technologies
Mero Technologies
 
Omnitron Sensors
Omnitron SensorsOmnitron Sensors
Omnitron Sensors
 
Juked
JukedJuked
Juked
 
GamerzClass
GamerzClassGamerzClass
GamerzClass
 
eino
einoeino
eino
 
Cenos
CenosCenos
Cenos
 
Bliinx
BliinxBliinx
Bliinx
 
Butlr
ButlrButlr
Butlr
 

Recently uploaded

A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observabilityitnewsafrica
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxfnnc6jmgwh
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Nikki Chapple
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesKari Kakkonen
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch TuesdayIvanti
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Strongerpanagenda
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...itnewsafrica
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Mark Goldstein
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersNicole Novielli
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxLoriGlavin3
 
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesMuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesManik S Magar
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfLoriGlavin3
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxLoriGlavin3
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentPim van der Noll
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 

Recently uploaded (20)

A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptxGenerative AI - Gitex v1Generative AI - Gitex v1.pptx
Generative AI - Gitex v1Generative AI - Gitex v1.pptx
 
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
Microsoft 365 Copilot: How to boost your productivity with AI – Part one: Ado...
 
Testing tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examplesTesting tools and AI - ideas what to try with some tool examples
Testing tools and AI - ideas what to try with some tool examples
 
2024 April Patch Tuesday
2024 April Patch Tuesday2024 April Patch Tuesday
2024 April Patch Tuesday
 
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better StrongerModern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
Modern Roaming for Notes and Nomad – Cheaper Faster Better Stronger
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
Arizona Broadband Policy Past, Present, and Future Presentation 3/25/24
 
A Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software DevelopersA Journey Into the Emotions of Software Developers
A Journey Into the Emotions of Software Developers
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptxUse of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
Use of FIDO in the Payments and Identity Landscape: FIDO Paris Seminar.pptx
 
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotesMuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
MuleSoft Online Meetup Group - B2B Crash Course: Release SparkNotes
 
Moving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdfMoving Beyond Passwords: FIDO Paris Seminar.pdf
Moving Beyond Passwords: FIDO Paris Seminar.pdf
 
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptxPasskey Providers and Enabling Portability: FIDO Paris Seminar.pptx
Passkey Providers and Enabling Portability: FIDO Paris Seminar.pptx
 
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native developmentEmixa Mendix Meetup 11 April 2024 about Mendix Native development
Emixa Mendix Meetup 11 April 2024 about Mendix Native development
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 

Shai samet

  • 1. Old COPPA, New COPPA “Get Out of Jail Free” 500 Startups – MamaBear Conference Presented by Shai Samet May 10, 2013 CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 2. Basic COPPA equation CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 2 personal information collected from child under 13 via the web (site, app, tablet, etc.) Verifiable Parental Consent (plus other requirements)
  • 3. User acquisition costs (kidSAFE survey – Jan 2013) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 3 Companies polled: AOL, Fantage, Gaia Online, Highlights for Kids, Pearson, TBS, WebKinz, many others
  • 4. Penalties for non-compliance • Up to $16,000 per violation • Over 20 FTC lawsuits and $8.4 million in fines since 2000 • Recent fines for COPPA violations: – Path (app developer) – $800,000 – Artist Arena (various music artist sites) – $1,000,000 – RockYou (social game site) – $250,000 – Disney’s Playdom (for violations by acquired company) – $3,000,000 CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 4
  • 5. Old COPPA vs. New COPPA CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 6. Key information and features regulated under new COPPA CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 6 CONTACT INFO First and Last Name Home/mailing address Email address Phone numbers Social Security Number “personal information” SCREEN/USER NAME “personal” in some scenarios (email, AIM, Skype name, etc.) THIRD PARTY PLUG-INS Integration with no VPC means strict liability GEOLOCATION “personal” unless location is not detailed enough BEHAVIORAL ADS/PROFILES “personal” if tracking across multiple services & over time PHOTOS, VIDEOS, AUDIO “personal” if contains image or voice of child
  • 7. Photos, videos, audio files (SnapChat, Faces iMake illustrations) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 7 temporary viewing by others = “collection/disclosure” faces alone (with no other PI) = VPC
  • 8. Geolocation information (News-O-matic illustration) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 8 Opt-in prompt not enough under new COPPA Consider coarse location or not uploading the data
  • 9. Behavioral ads and social plugins (WebKinz, NeoPets illustrations) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 9 Behavioral ads no more (contextual ads OK) FB Connect needs VPC (link to fan page OK)
  • 10. Verifiable Parental Consent CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 11. Current options for parental consent Method Providers Limitations • Email Plus consent Internally- implemented • Requires parent to activate via email comm’s • Not sufficient if info will be shared/publicized • Signed consent form N/A • Manual • Requires access to printer and scanner/fax • Not mobile friendly Monetary transaction Payment processors • Requires credit card entry and payment • Payment via PayPal also sufficient • [Collection of iTunes password not sufficient] • Phone call or video conference N/A • Manual • Requires live and trained personnel • Video-conference requires device with camera • Govt-issued ID Various • Requires sharing of highly-sensitive information • Not ideal for foreign users CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 11
  • 12. CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 12 Likelihood of industry adoption (kidSAFE survey – Jan 2013)
  • 13. Penalties for non-compliance (just a reminder) • Up to $16,000 per violation • Over 20 FTC lawsuits and $8.4 million in fines since 2000 • Recent fines for COPPA violations: – Path (app developer) – $800,000 – Artist Arena (various music artist sites) – $1,000,000 – RockYou (social game site) – $250,000 – Disney’s Playdom (for violations by acquired company) – $3,000,000 CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 13
  • 14. Considerations for Startups and Investors CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION
  • 15. Scaling user growth (COPPA techniques and loopholes) • Anonymize child-directed features – Limit sign-up process to anonymous info (username, password, etc.) – For interactive features (chat, UGC), filter on the back-end to avoid upfront consent requirement – For mobile features (geo-location, photos), keep data local to the device (do not upload/share) – Utilize COPPA’s parental consent exceptions for other features • Direct your account sign-up process to older users (when allowed) – If kids under 13 not your “primary audience”, you can limit registration to users 13 and older – On sites/apps directed to preschoolers, collect registration info from parents/adults – Put behavioral ads and social plug-ins behind special parents section (or 13+ section) • When parental consent is required, use least burdensome method – Avoid collection of payment solely for consent purposes – Avoid collection of govt-issued ID (last 4 of SSN, driver’s license) – Consider email-based consent as first option CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 15
  • 16. Parent-directed registration (StoryBots illustration) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 16 Messaging on the page and within data fields must be clearly directed to parents
  • 17. Parent lock for social features (StoryBots, TocaBoca app illustrations) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 17 Math problem before access to web or social sharing features Swipe to access parents section or apps for sale
  • 18. Most viable revenue streams (under new COPPA) • E-commerce and retail (tied to compelling content or experience) – Virtual goods, subscriptions, premium content/features (e.g., Wizard 101) – Game/app downloads, in-app purchases (e.g., Minecraft, Toca Boca) – Tablets, toys, offline merchandise (e.g., Nabi, Skylanders, Moshi Monsters) – Brands/stories with TV or licensing potential • Contextual ads – Display, text, or video ads (all OK) – NOT behaviorally-targeted or retargeted ads • NOT models dependent heavily on social sharing/connections – Hard to scale with current COPPA restrictions CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 18
  • 19. Distribution ideas • Kid-directed platforms – Popular gaming portals (e.g., Miniclip) – Kids’ tablets (e.g., nabi, Kurio) – Other curated environments (e.g., Zui.com, Magic Desktop) • Schools – For properties with educational, nutritional, or creative utility (e.g., myNutratek, Minecraft) – Schools/teachers can provide consent in lieu of parents • Participation in kidSAFE – Get noticed by users visiting our site from other popular sites/properties – Reach our growing database of parents CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 19
  • 20. CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 20 About kidSAFE Seal Program • Leading safety “seal of approval” program – Certifying kid-directed sites, apps, software, tablets, and other technologies – GLOBALLY – Over 100 seal holders since public launch in April 2012 – Fast becoming the industry standard for “online safety” • kidSAFE+ membership offers full COPPA audit – Qualifiers receive prestigious kidSAFE+ Seal and many other benefits – Application for FTC approval coming soon • Business-friendly, responsive, and highly knowledgeable – Founder is former attorney and long-time COPPA expert • For more info, visit kidsafeseal.com or email shai@kidsafeseal.com
  • 21. Some of our customers WEBANDPC CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION 21 MOBILE Collectively, these few sites alone account for over 15M unique visitors a month in the US alone (Source: Compete.com)
  • 22. Questions? (happy to share the deck) CONFIDENTIAL AND PROPRIETARY TO SAMET PRIVACY MUST NOT BE SHARED WITHOUT PERMISSION Upcoming kidSAFE Webinar on COPPA – May 30, 2013 (featuring open Q&A session with the FTC) REGISTER HERE