SlideShare a Scribd company logo
1 of 13
Download to read offline
Data Protection Strategies for
Both Sides of the Atlantic
AppLift Summer Academy, Lisbon
August 27, 2015
Today’s Discussion
1. Importance of the EU-US relationship
2. Mobile players and data obligations
3. Proposed EU regulation (GDPR)
4. US-EU/Swiss Safe Harbor Status
5. US developments (including COPPA)
6. Best Practices for both sides of the Atlantic
1. Importance of EU-US relationship
● The EU & the US are each other’s largest trading partner, forming the
world’s largest integrated commercial artery - worth over $5.5 trillion
● The EU & the US are each other’s primary source and destination for
foreign direct investment - since 2000, the EU has received over 55%
of US investment dollars
● Since 2000, the EU has accounted for over 58% of the income from
foreign subsidiaries of US companies.
Source - The Transatlantic Economy 2015
2. Mobile Players & Data Obligations
Publishers
● Typically an advertiser
who is interested in
monetizing its traffic
● As a data controller or
first party, still holds
primary responsibility for
data protection & privacy
compliance
Networks
● Usually classified as a data
processor (EU) or third
party (US)
● Can be viewed as a data
controller if it determines
“purpose and means” of
data processing (Art. 29 WP
opinion 1/2010)
Advertisers
● Classified as a data
controller (EU) or a first
party (US)
● As a data controller or
first party, holds primary
responsibility for data
protection & privacy
compliance
3. Proposed EU Data Protection Regulation
● Trilogue - EU Council, EU Commission & EU Parliament must agree on
final version of the Regulation or “GDPR”
● Trilogue currently in process; hope to have agreement by end 2015.
● Per EU Council, implementation will be 2 years after final version is set
EU Council EU Parliament
3. GDPR - Big Issues for Ad Ecosystem
● Technical identifiers likely categorized as “personal data”
● Affirmative consent and opt out requirements for personal data collection
● Advertisers, publishers and networks would be viewed as data controllers
● “Right to be forgotten”
● Watered down version of “one-stop shop”
● Fines - between 2-5% of global “turnover”
4. Safe Harbor Negotiations….
Is the Safe Harbor still
credible after the
Snowden revelations
suggesting a “back
door” between US
companies and NSA?
● The Safe Harbor is the primary means by which
companies collect and share data from EU citizens
● Alternatives to Safe Harbor are costly and lengthy
● The Safe Harbor is under review in Europe vs. Facebook -
EU’s largest privacy class action. The EU’s Court of Justice
may declare Safe Harbor “inadequate.”
4. Why do we care about the Safe Harbor?
5. US Developments
● FCC* has recovered over $500 million for telco privacy violations
● FTC**, advocacy community unhappy with “Consumer Privacy Bill of Rights.”
● FTC’s right to regulate data security affirmed by Third Circuit (Wyndham)
● FTC continues its investigation into ad practices – cross device tracking is
next (November 2015).
* FCC - Federal Communications Commission
** FTC - Federal Trade Commission
5. Childrens Online Privacy Protection Act
● COPPA requires that you get “verified parental consent” when collecting
personal data from kids under 13 for targeting purposes
● COPPA requires an age gate for “mixed audience” sites
● Ad IDs and other persistent identifiers are “personal data” under COPPA
● Attribution and contextual advertising are COPPA exceptions
Advertisers and Publishers are
responsible for COPPA compliance on
their apps
Networks are responsible for COPPA
compliance only if they have actual
knowledge that they are targeting ads
to kids under 13.
6. Best Practices for both sides of the Atlantic
● The basics are a must - notice, consent, opt-out, security
● In the EU
○ Consider certification evidencing your compliance (EU)
● In the US
○ Consider participation in an industry framework (US)
○ Make sure you are COPPA compliant. FTC fines are significant because
COPPA is a law, not a best practice.
● Doing business in the EU and US?
○ Make sure your data transfers are “adequate” (Safe Harbor, BCR)
Regulatory
Art. 29 Working Party on Smart Mobile Devices: http://ec.europa.eu/justice/data-protection/article-
29/documentation/opinion-recommendation/files/2013/wp202_en.pdf
Privacy on the Go (CA privacy rules): http://oag.ca.gov/sites/all/files/agweb/pdfs/privacy/privacy_on_the_go.pdf
FTC Marketing Guidelines (US - advertising and privacy): https://www.ftc.gov/tips-advice/business-
center/guidance/marketing-your-mobile-app-get-it-right-start
FTC “Start with Security” (US - data security guidelines for mobile apps): https://www.ftc.gov/tips-
advice/business-center/guidance/mobile-app-developers-start-security
Industry
FPF-CDT Best Practices (for Mobile App developers): http://www.futureofprivacy.org/best-practices-for-mobile-
app-developers/
DAA Mobile Guidelines (behavioral /targeted advertising OBA):
http://www.aboutads.info/DAA_Mobile_Guidance.pdf
NAI Code (1st & 3rd parties engaged in ad delivery): http://www.networkadvertising.org/code-enforcement/code
MMA Advertising Guidelines: http://www.mmaglobal.com/files/mobileadvertising.pdf
6. Additional Resources
Thank You!
Saira Nayak
Chief Privacy Officer
saira@tune.com

More Related Content

What's hot

Compliance and risk management in ebanking
Compliance and risk management in ebankingCompliance and risk management in ebanking
Compliance and risk management in ebankingHubert Van de Vyver
 
2010 US Congress on pirate states
2010 US Congress on pirate states2010 US Congress on pirate states
2010 US Congress on pirate statesIlya Ponomarev
 
Sif14 How Trade Agreements Mess Up with Internet Freedoms
Sif14 How Trade Agreements Mess Up with Internet Freedoms Sif14 How Trade Agreements Mess Up with Internet Freedoms
Sif14 How Trade Agreements Mess Up with Internet Freedoms Carolina Rossini
 
The archived Canadian US Patent Competitive Intelligence Database (2015/6/2)
The archived Canadian US Patent Competitive Intelligence Database (2015/6/2) The archived Canadian US Patent Competitive Intelligence Database (2015/6/2)
The archived Canadian US Patent Competitive Intelligence Database (2015/6/2) Muchiu (Henry) Chang, PhD. Cantab
 
International Business Transaction - Exporting and Importing: The Documentary...
International Business Transaction - Exporting and Importing: The Documentary...International Business Transaction - Exporting and Importing: The Documentary...
International Business Transaction - Exporting and Importing: The Documentary...Mariske Myeke Tampi
 
20170624-Track or be tracked? The challenges of the ePrivacy Regulation
20170624-Track or be tracked? The challenges of the ePrivacy Regulation20170624-Track or be tracked? The challenges of the ePrivacy Regulation
20170624-Track or be tracked? The challenges of the ePrivacy Regulationyasoiler
 
The archived Canadian US Patent Competitive Intelligence Database (2014/9/16)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/16) The archived Canadian US Patent Competitive Intelligence Database (2014/9/16)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/16) Muchiu (Henry) Chang, PhD. Cantab
 
Should European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot ActShould European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot Actfrjennings
 
The archived Canadian US Patent Competitive Intelligence Database (2016/5/17)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/17) The archived Canadian US Patent Competitive Intelligence Database (2016/5/17)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/17) Muchiu (Henry) Chang, PhD. Cantab
 
International Business Transaction - Sale of Services
International Business Transaction - Sale of ServicesInternational Business Transaction - Sale of Services
International Business Transaction - Sale of ServicesMariske Myeke Tampi
 
The archived Canadian US Patent Competitive Intelligence Database (2014/9/9)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/9) The archived Canadian US Patent Competitive Intelligence Database (2014/9/9)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/9) Muchiu (Henry) Chang, PhD. Cantab
 
GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!WEBBED STAR
 
The archived Canadian US Patent Competitive Intelligence Database (2016/7/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/7/19) The archived Canadian US Patent Competitive Intelligence Database (2016/7/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/7/19) Muchiu (Henry) Chang, PhD. Cantab
 
The archived Canadian US Patent Competitive Intelligence Database (2014/9/23)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/23) The archived Canadian US Patent Competitive Intelligence Database (2014/9/23)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/23) Muchiu (Henry) Chang, PhD. Cantab
 
The archived Canadian US Patent Competitive Intelligence Database (2016/5/31)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/31) The archived Canadian US Patent Competitive Intelligence Database (2016/5/31)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/31) Muchiu (Henry) Chang, PhD. Cantab
 
The archived Canadian US Patent Competitive Intelligence Database (2016/6/21)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/21) The archived Canadian US Patent Competitive Intelligence Database (2016/6/21)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/21) Muchiu (Henry) Chang, PhD. Cantab
 
The archived Canadian US Patent Competitive Intelligence Database (2016/4/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/4/19) The archived Canadian US Patent Competitive Intelligence Database (2016/4/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/4/19) Muchiu (Henry) Chang, PhD. Cantab
 
The archived Canadian US Patent Competitive Intelligence Database (2016/6/7)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/7) The archived Canadian US Patent Competitive Intelligence Database (2016/6/7)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/7) Muchiu (Henry) Chang, PhD. Cantab
 
The Transatlantic Trade and Investment Partnership: The Intersection of the I...
The Transatlantic Trade and Investment Partnership: The Intersection of the I...The Transatlantic Trade and Investment Partnership: The Intersection of the I...
The Transatlantic Trade and Investment Partnership: The Intersection of the I...Patton Boggs LLP
 
The archived Canadian US Patent Competitive Intelligence Database (2016/3/1)
The archived Canadian US Patent Competitive Intelligence Database (2016/3/1) The archived Canadian US Patent Competitive Intelligence Database (2016/3/1)
The archived Canadian US Patent Competitive Intelligence Database (2016/3/1) Muchiu (Henry) Chang, PhD. Cantab
 

What's hot (20)

Compliance and risk management in ebanking
Compliance and risk management in ebankingCompliance and risk management in ebanking
Compliance and risk management in ebanking
 
2010 US Congress on pirate states
2010 US Congress on pirate states2010 US Congress on pirate states
2010 US Congress on pirate states
 
Sif14 How Trade Agreements Mess Up with Internet Freedoms
Sif14 How Trade Agreements Mess Up with Internet Freedoms Sif14 How Trade Agreements Mess Up with Internet Freedoms
Sif14 How Trade Agreements Mess Up with Internet Freedoms
 
The archived Canadian US Patent Competitive Intelligence Database (2015/6/2)
The archived Canadian US Patent Competitive Intelligence Database (2015/6/2) The archived Canadian US Patent Competitive Intelligence Database (2015/6/2)
The archived Canadian US Patent Competitive Intelligence Database (2015/6/2)
 
International Business Transaction - Exporting and Importing: The Documentary...
International Business Transaction - Exporting and Importing: The Documentary...International Business Transaction - Exporting and Importing: The Documentary...
International Business Transaction - Exporting and Importing: The Documentary...
 
20170624-Track or be tracked? The challenges of the ePrivacy Regulation
20170624-Track or be tracked? The challenges of the ePrivacy Regulation20170624-Track or be tracked? The challenges of the ePrivacy Regulation
20170624-Track or be tracked? The challenges of the ePrivacy Regulation
 
The archived Canadian US Patent Competitive Intelligence Database (2014/9/16)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/16) The archived Canadian US Patent Competitive Intelligence Database (2014/9/16)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/16)
 
Should European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot ActShould European Businesses Really Fear The Usa Patriot Act
Should European Businesses Really Fear The Usa Patriot Act
 
The archived Canadian US Patent Competitive Intelligence Database (2016/5/17)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/17) The archived Canadian US Patent Competitive Intelligence Database (2016/5/17)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/17)
 
International Business Transaction - Sale of Services
International Business Transaction - Sale of ServicesInternational Business Transaction - Sale of Services
International Business Transaction - Sale of Services
 
The archived Canadian US Patent Competitive Intelligence Database (2014/9/9)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/9) The archived Canadian US Patent Competitive Intelligence Database (2014/9/9)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/9)
 
GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!GDPR. Don't Leave It To Lawyers!
GDPR. Don't Leave It To Lawyers!
 
The archived Canadian US Patent Competitive Intelligence Database (2016/7/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/7/19) The archived Canadian US Patent Competitive Intelligence Database (2016/7/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/7/19)
 
The archived Canadian US Patent Competitive Intelligence Database (2014/9/23)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/23) The archived Canadian US Patent Competitive Intelligence Database (2014/9/23)
The archived Canadian US Patent Competitive Intelligence Database (2014/9/23)
 
The archived Canadian US Patent Competitive Intelligence Database (2016/5/31)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/31) The archived Canadian US Patent Competitive Intelligence Database (2016/5/31)
The archived Canadian US Patent Competitive Intelligence Database (2016/5/31)
 
The archived Canadian US Patent Competitive Intelligence Database (2016/6/21)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/21) The archived Canadian US Patent Competitive Intelligence Database (2016/6/21)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/21)
 
The archived Canadian US Patent Competitive Intelligence Database (2016/4/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/4/19) The archived Canadian US Patent Competitive Intelligence Database (2016/4/19)
The archived Canadian US Patent Competitive Intelligence Database (2016/4/19)
 
The archived Canadian US Patent Competitive Intelligence Database (2016/6/7)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/7) The archived Canadian US Patent Competitive Intelligence Database (2016/6/7)
The archived Canadian US Patent Competitive Intelligence Database (2016/6/7)
 
The Transatlantic Trade and Investment Partnership: The Intersection of the I...
The Transatlantic Trade and Investment Partnership: The Intersection of the I...The Transatlantic Trade and Investment Partnership: The Intersection of the I...
The Transatlantic Trade and Investment Partnership: The Intersection of the I...
 
The archived Canadian US Patent Competitive Intelligence Database (2016/3/1)
The archived Canadian US Patent Competitive Intelligence Database (2016/3/1) The archived Canadian US Patent Competitive Intelligence Database (2016/3/1)
The archived Canadian US Patent Competitive Intelligence Database (2016/3/1)
 

Similar to DP on both sides of the Atlantic - august 2015

Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKSally Hunt
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterTrustArc
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementGACC_Midwest
 
C8-Ethical, Social, & Political Issues in Ecommerce.PPT
C8-Ethical, Social, & Political Issues in Ecommerce.PPTC8-Ethical, Social, & Political Issues in Ecommerce.PPT
C8-Ethical, Social, & Political Issues in Ecommerce.PPTSyazwaniYa
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyKate Chan
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?EngageHub
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborGayle Gorvett
 
Data Protection Scotland Summit 2019
Data Protection Scotland Summit 2019Data Protection Scotland Summit 2019
Data Protection Scotland Summit 2019Ray Bugg
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationGhostery, Inc.
 
Companies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsCompanies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsThe Economist Media Businesses
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...Feroot
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Meteringnuances
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...TrustArc
 
IT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestIT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestLilian Edwards
 
Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)Kwanko
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issuesStefan Schippers
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownAgile PR
 

Similar to DP on both sides of the Atlantic - august 2015 (20)

GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016GDPR - Applift firstscreen june 2016
GDPR - Applift firstscreen june 2016
 
Data_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UKData_Privacy_Protection_brochure_UK
Data_Privacy_Protection_brochure_UK
 
PL&B _UK_80
PL&B _UK_80PL&B _UK_80
PL&B _UK_80
 
EMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years LaterEMEA Quarterly Update: GDPR Two Years Later
EMEA Quarterly Update: GDPR Two Years Later
 
EU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor ReplacementEU-US Privacy Shield - Safe Harbor Replacement
EU-US Privacy Shield - Safe Harbor Replacement
 
C8-Ethical, Social, & Political Issues in Ecommerce.PPT
C8-Ethical, Social, & Political Issues in Ecommerce.PPTC8-Ethical, Social, & Political Issues in Ecommerce.PPT
C8-Ethical, Social, & Political Issues in Ecommerce.PPT
 
No Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data PrivacyNo Man is an Island: The Battle for Data Privacy
No Man is an Island: The Battle for Data Privacy
 
GDPR: Are you Ready?
GDPR: Are you Ready?GDPR: Are you Ready?
GDPR: Are you Ready?
 
PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?PECB Webinar: The End of Safe Harbour! What happens Next?
PECB Webinar: The End of Safe Harbour! What happens Next?
 
Data Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe HarborData Privacy vs. National Security post Safe Harbor
Data Privacy vs. National Security post Safe Harbor
 
Data Protection Scotland Summit 2019
Data Protection Scotland Summit 2019Data Protection Scotland Summit 2019
Data Protection Scotland Summit 2019
 
The Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection RegulationThe Practical Impact of the General Data Protection Regulation
The Practical Impact of the General Data Protection Regulation
 
Companies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next stepsCompanies, digital transformation and information privacy: the next steps
Companies, digital transformation and information privacy: the next steps
 
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
EXPERT WEBINAR: GDPR One Year Later — What Can We Learn from Investigations a...
 
EU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart MeteringEU General Data Protection: Implications for Smart Metering
EU General Data Protection: Implications for Smart Metering
 
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
The Court Speaks: Privacy Shield, Standard Contractual Clauses and Cookie Con...
 
IT law : the middle kingdom between east and West
IT law : the middle kingdom between east and WestIT law : the middle kingdom between east and West
IT law : the middle kingdom between east and West
 
Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)Infographic : What's going to change with the GDPR (2018)
Infographic : What's going to change with the GDPR (2018)
 
Gdpr and usa data privacy issues
Gdpr and usa data privacy issuesGdpr and usa data privacy issues
Gdpr and usa data privacy issues
 
Jowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens ScownJowanna Conboye - Stephens Scown
Jowanna Conboye - Stephens Scown
 

DP on both sides of the Atlantic - august 2015

  • 1. Data Protection Strategies for Both Sides of the Atlantic AppLift Summer Academy, Lisbon August 27, 2015
  • 2. Today’s Discussion 1. Importance of the EU-US relationship 2. Mobile players and data obligations 3. Proposed EU regulation (GDPR) 4. US-EU/Swiss Safe Harbor Status 5. US developments (including COPPA) 6. Best Practices for both sides of the Atlantic
  • 3. 1. Importance of EU-US relationship ● The EU & the US are each other’s largest trading partner, forming the world’s largest integrated commercial artery - worth over $5.5 trillion ● The EU & the US are each other’s primary source and destination for foreign direct investment - since 2000, the EU has received over 55% of US investment dollars ● Since 2000, the EU has accounted for over 58% of the income from foreign subsidiaries of US companies. Source - The Transatlantic Economy 2015
  • 4. 2. Mobile Players & Data Obligations Publishers ● Typically an advertiser who is interested in monetizing its traffic ● As a data controller or first party, still holds primary responsibility for data protection & privacy compliance Networks ● Usually classified as a data processor (EU) or third party (US) ● Can be viewed as a data controller if it determines “purpose and means” of data processing (Art. 29 WP opinion 1/2010) Advertisers ● Classified as a data controller (EU) or a first party (US) ● As a data controller or first party, holds primary responsibility for data protection & privacy compliance
  • 5. 3. Proposed EU Data Protection Regulation ● Trilogue - EU Council, EU Commission & EU Parliament must agree on final version of the Regulation or “GDPR” ● Trilogue currently in process; hope to have agreement by end 2015. ● Per EU Council, implementation will be 2 years after final version is set EU Council EU Parliament
  • 6. 3. GDPR - Big Issues for Ad Ecosystem ● Technical identifiers likely categorized as “personal data” ● Affirmative consent and opt out requirements for personal data collection ● Advertisers, publishers and networks would be viewed as data controllers ● “Right to be forgotten” ● Watered down version of “one-stop shop” ● Fines - between 2-5% of global “turnover”
  • 7. 4. Safe Harbor Negotiations…. Is the Safe Harbor still credible after the Snowden revelations suggesting a “back door” between US companies and NSA?
  • 8. ● The Safe Harbor is the primary means by which companies collect and share data from EU citizens ● Alternatives to Safe Harbor are costly and lengthy ● The Safe Harbor is under review in Europe vs. Facebook - EU’s largest privacy class action. The EU’s Court of Justice may declare Safe Harbor “inadequate.” 4. Why do we care about the Safe Harbor?
  • 9. 5. US Developments ● FCC* has recovered over $500 million for telco privacy violations ● FTC**, advocacy community unhappy with “Consumer Privacy Bill of Rights.” ● FTC’s right to regulate data security affirmed by Third Circuit (Wyndham) ● FTC continues its investigation into ad practices – cross device tracking is next (November 2015). * FCC - Federal Communications Commission ** FTC - Federal Trade Commission
  • 10. 5. Childrens Online Privacy Protection Act ● COPPA requires that you get “verified parental consent” when collecting personal data from kids under 13 for targeting purposes ● COPPA requires an age gate for “mixed audience” sites ● Ad IDs and other persistent identifiers are “personal data” under COPPA ● Attribution and contextual advertising are COPPA exceptions Advertisers and Publishers are responsible for COPPA compliance on their apps Networks are responsible for COPPA compliance only if they have actual knowledge that they are targeting ads to kids under 13.
  • 11. 6. Best Practices for both sides of the Atlantic ● The basics are a must - notice, consent, opt-out, security ● In the EU ○ Consider certification evidencing your compliance (EU) ● In the US ○ Consider participation in an industry framework (US) ○ Make sure you are COPPA compliant. FTC fines are significant because COPPA is a law, not a best practice. ● Doing business in the EU and US? ○ Make sure your data transfers are “adequate” (Safe Harbor, BCR)
  • 12. Regulatory Art. 29 Working Party on Smart Mobile Devices: http://ec.europa.eu/justice/data-protection/article- 29/documentation/opinion-recommendation/files/2013/wp202_en.pdf Privacy on the Go (CA privacy rules): http://oag.ca.gov/sites/all/files/agweb/pdfs/privacy/privacy_on_the_go.pdf FTC Marketing Guidelines (US - advertising and privacy): https://www.ftc.gov/tips-advice/business- center/guidance/marketing-your-mobile-app-get-it-right-start FTC “Start with Security” (US - data security guidelines for mobile apps): https://www.ftc.gov/tips- advice/business-center/guidance/mobile-app-developers-start-security Industry FPF-CDT Best Practices (for Mobile App developers): http://www.futureofprivacy.org/best-practices-for-mobile- app-developers/ DAA Mobile Guidelines (behavioral /targeted advertising OBA): http://www.aboutads.info/DAA_Mobile_Guidance.pdf NAI Code (1st & 3rd parties engaged in ad delivery): http://www.networkadvertising.org/code-enforcement/code MMA Advertising Guidelines: http://www.mmaglobal.com/files/mobileadvertising.pdf 6. Additional Resources
  • 13. Thank You! Saira Nayak Chief Privacy Officer saira@tune.com