#Mobile #Privacy Continues to Challenge Marketers, Developers & Lawmakers

The rapid growth and expansion in the mobile market presents a number of privacy and security issues for mobile software and hardware developers, platform operators, advertisers and marketers who collect, store, use and share consumer information. As awareness of privacy risks grow among consumers, legislators and regulators are increasing scrutiny of mobile privacy and privacy policies in mobile apps.

Businesses operating in the mobile industry are facing a widening array of Regulatory compliance issues. Staying abreast of legal risks and issues can be daunting. How can mobile operators and application developers spot trends and adjust strategies to start competitive? First, keep an eye on FTC activity. Second, monitor new bills coming up in Congress. Third, follow this blog, adlerlaw.wordpress.com.

FTC Privacy Enforcement Actions

Earlier this year, the FTC expanded mobile privacy obligations beyond software to include hardware makers when it announced a settlement with HTC America over charges that HTC failed to use adequate “security by design” in millions of consumer mobile devices. As a result, the company is required to patch vulnerabilities on the devices which include #Smartphones and #Tablets. The settlement, the first action involving a mobile device manufacturer and the new “Privacy By Design” guidelines, sheds some light on the legal risks for mobile device manufacturers and, to some extent, mobile application developers.

Congressional Privacy Laws, Bills & Initiatives

Not surprisingly, federal legislators are taking up the mantle of Consumer Privacy in the area of Mobile Applications. In January 2013, U.S. Rep. Hank Johnson, introduced his mobile privacy bill, The Application Privacy, Protection and Security Act of 2013, or the “APPS Act,”. The bill focuses on transparency, user control and security, mandating that an application 1) provide the user with notice of the terms and conditions governing the collection, use, storage, and sharing of the personal data, and 2) obtain the consent of the user to the terms and conditions. Significantly, the privacy notice is required to include a description of the categories of personal data that
will be collected, the categories of purposes for which the personal data will be used, and the categories of third parties with which the personal data will be shared.

The Bill also requires that application developers have a data retention policy that governs the length for which the personal data will be stored and the terms and conditions applicable to storage, including a description of the rights of the user and the process by which the user may exercise such rights in addition to data security and access procedures and safeguards.

App developers unaware of the data protection requirements may face significant risks and potential harm to their reputation among users of smart devices. If you have concerns about what key data protection and privacy legal requirements apply to mobile applications and the types of processing an app may undertake contact us for a mobile app legal audit. Vague or incomplete descriptions of the ways which a mobile app handles data or a lack of meaningful consent from end users before that processing takes place can lead to significant legal risk. Poor security measures, an apparent trend towards data maximisation and the elasticity of purposes for which personal data are being collected further contribute to the data protection risks found within the current app environment.

Learn more David M. Adler here.

Four #Mobile #Privacy Take-Aways From FTC Settlement With HTC

Intel Mobile Device
Intel Mobile Device (Photo credit: Frank Gruber)

On February 22, 2013, the FTC announced a settlement with HTC America over charges that HTC failed to use adequate “security by design” in millions of consumer mobile devices. As a result, the company is required to patch vulnerabilities on the devices which include #Smartphones and #Tablets. The settlement, the first action involving a mobile device manufacturer and the new “Privacy By Design” guidelines, sheds some light on the legal risks for mobile device manufacturers and, to some extent, mobile application developers.

The FTC alleged that HTC failed to take reasonable steps to secure the software it developed for its smartphones and tablet computers, introducing security flaws that placed sensitive information about millions of consumers at risk. The resulting vulnerabilities posed risks to sensitive functionality, including the possibility that malware could send text messages, record audio, and install additional malware onto a consumer’s device.

Here are four key take-aways for mobile device manufacturers and application developers from the FTC’s complaint:

  1. provide your engineering (programming) staff with security training
  2. review or test your software on mobile devices for potential security vulnerabilities
  3. follow well-known and commonly accepted secure coding practices
  4. establish a process for receiving and addressing vulnerability reports from third parties

Smartphones and tablets are powerful, popular, and continue to find their ways into our personal and business lives. New mobile apps hit the market each day. In this fast-moving era of entrepreneurship and creativity, mobile device and app developers need to keep up with evolving privacy and security. Apps and mobile devices that tap into consumer data — including contact information, photos, and location to name a few — pose a heightened risk to digital snoops, data breaches, and real-world thieves.

Please contact us if you are interested in learning how to evaluate your mobile security and privacy risk or to help develop a “Privacy By Design” approach mobile app security.

Please comment, tweet and forward!

Three Things I Learned About Personal Cybersecurity At RSAConference That You Should Be Doing Right Now

Image representing CloudFlare as depicted in C...
Image via CrunchBase

I just returned from RSAConference 2013 where I had the privilege and honor of giving a presentation of the legal risks caused by social media in the workplace. As a speaker-attendee, I had the priceless benefit of access to all the other speakers and programs held during the conference.

One such program I attended was “We Were Hacked: Here’s What You Should Know”. The speakers, Matthew Prince (@eastdakota) CEO of CloudFlare, and Mat Honan (@mat) writer for Wired Magazine, shared their common experience as targets of high profile hacks. Hearing the details from them first hand, including information from interviews with the hackers themselves, I learned how easy it is to be the victim of hacking and how it’s the little things that create exploitable seams in our information security barriers.

Rather than rewrite their stories, I thought I would share three simple lessons I learned that I’ve already implemented and you should too. Besides, Matt does a better job telling his own story which can be found here.

Here are the three things I learned about how you can protect yourself and others in your organization.

First, security attacks go after the “low hanging fruit” and that often means figuring out a way to exploit your personal email address. With so many web-based services and so much login information to remember, many of us use our personal email as our username for everything from the web sites on which we comment, to our online photo gallery, to our online banking service. Unfortunately, this is probably the address we use for password recovery if we forget. Given that our digital lives are easily mapped, hackers already have one piece of the two-piece login puzzle: they know your user name.

TIP NO. 1: Use a private, obscure email address for your more sensitive information.

Second, once a hacker has accessed your accounts, your computer and your files, the fun has just begun for them. As Matt Honan described, these often adolescent script kiddies simply don’t understand the value of your stored memories and other information. In his case, all the photos of his children were permanently deleted. Regardless of a hacker attack, stuff happens and you don’t want to lose everything because you we’re too lazy to back up.

TIP NO. 2: Back Up your digital life, early and often.

Third, today’s’ Internet is an interdependent ecosystem. Just because you or your organization takes security seriously, doesn’t mean that other do as well. Your internal systems are not enough. Like it or not, the seams of your security perimeter are intertwined and permeated by the services and systems of customers and vendors. For most consumers, the there is a Hobbesian choice of Security v. Convenience. Multiple login usernames and super long passwords are difficult to remember and tedious to use. As a result, most people choose the least secure means of authentication on the assumption that using astringent password is enough. Unfortunately, some people don’t even bothers with that. A recent ZoneAlarm study found that “password” was the fourth most commonly used password by consumers.

Google, Facebook and others have started using two-factor authentication. Two-factor authentication requires that one enter a code after entering the username/password combo. The code is sent via, text message, voice call or email. This greatly reduces the chances of unauthorized access because hackers would need to have your phone, in addition to your username/password combo.

TIP NO. 3: Whenever possible enable two-factor authentication.

Please understand that there is no “magic bullet” when it comes to Cybersecurity. Taking these precautions does not guarantee that you won’t be attached or that your account information won’t be accessed. However, these are important and easy steps that you can take to improve your personal data security.

Please comment and follow!

 

Whose Social Media Account Is It Anyway?

As a result of the rapid shift in marketing from unilateral one-to-many communications, to the multilateral, many-to-many or many-to-one conversations enabled by Social Media, employees and employers are struggling to manage accounts that are used for both work and personal purposes.

This new phenomenon has benefits, but it also creates a number of legal challenges. For employees, it may result in greater efficiency, more opportunities for authentic customers engagement and the ability to stay on top of the most current grands and business issues. For employers, it presents opportunity to reap substantial benefits from lower communications and customer support costs. For in-house counsel, it raises a host of legal and practical issues with few easy solutions and significant liability and regulatory risks.

First, there are hardware issues. Smartphones, tablets and other personal electronics often have social networking capabilities built in. in addition, they contain contain both personal and business data. Because these devices are always on and always connected, they are more than just personal property. They have become essential business tools. For both sides of the workplace equation, employers and employees must understand where the privacy lines fall between personal versus work-related information.

Second, there are data issues. Employers must balance their needs to monitor employee usage, employees’ privacy concerns, and the risk of liability for theft or exposure of data if a device is lost or stolen, or from lack of proper safeguards on account usage. For in-house counsel tasked with drafting policies to address these risks, , Prior to implementation of any policy, the legal team needs to educate front line employees and management on reasonable expectations of privacy and security and the harms that the organization seeks to prevent.

Lastly, recent cases such as the Cristou v. Beatport litigation, highlight the struggle to define and control the beginning and end of employee social media accounts, ownership and protection of intellectual property and the post termination risks that arise from the absence of appropriate policies.

As we prepare to start a new year, the time is ripe to establish security and privacy policies governing creation, maintenance and use of employees’ social media accounts for work functions. In-house counsel must lead the charge to educate, inform and train employees about privacy, security and evidence-recovery implications associated with use of social media.

Outrageous! Seven Rent To Own Firms Used Nefarious Software to Spy on Customers in Their Homes

On September 25, 2012, the Federal Trade Commission announced a settlement with seven rent-to-own companies that secretly installed software on rented computers, clandestinely collected information, took pictures of consumers in their homes (WTF?!) and tracked these consumers’ locations.

If you haven’t vomited on your computer from the sickening outrage, you can read the FTC press release here.

Software design firm DesignerWare, LLC licensed software to rent-to-own stores ostensibly to help them track and recover rented computers. The software collected the data that enabled rent-to-own stores, including franchisees of Aaron’s, ColorTyme, and Premier Rental Purchase, to track the location of rented computers without consumers’ knowledge

According to the FTC, the software enabled remote computer disabling if it was stolen, or if the renter failed to make payments. It included an add-on purportedly to help stores locate rented computers and collect late payments. Alarmingly, the software also collected data that allowed the rent-to-own operators to secretly track the location of rented computers, and thus the computers’ users.

When activated, the nefarious feature logged key strokes, captured screen shots and took photographs using a computer’s webcam, according to the FTC. It also presented a fake software program registration screen that tricked consumers into providing their personal contact information.

“An agreement to rent a computer doesn’t give a company license to access consumers’ private emails, bank account information, and medical records, or, even worse, webcam photos of people in the privacy of their own homes,” said Jon Leibowitz, Chairman of the FTC. “The FTC orders today will put an end to their cyber spying.”

“There is no justification for spying on customers. These tactics are offensive invasions of personal privacy,” said Illinois Attorney General Lisa Madigan.

World Social Media Legal News Roundup

Newsmakers Q&A | Law slow to address workers’ social-media privacy
Columbus Dispatch

Colorado shooting: Public calls on Christian Bale to swoop in
Los Angeles Times

July 21, 2012, 12:04 p.m.. People are calling upon the caped crusader in the wake of the Colorado theater shooting with the 21st century bat signal: social media.

Afghan social media war steps up with new campaign
Reuters UK

And with the government mulling a media law to tighten its grip over the fledgling but lively Afghan press corps, Nai hoped social media could help safeguard political and social freedoms, as occurred during the wave of uprisings across the Middle East.

A social media win on merger
Philadelphia Inquirer

It’s a bracing lesson, on a local stage, in the power of social media to create community around an issue and ratchet up pressure on key players – in this case, the members of the Abington board and its president and CEO, Laurence Merlis. “It’s amazing to me just how fast word spread,” …. A community-conscious and activist community, with a high concentration of concerned, committed people who work in industries such as law, medicine, public relations, and journalism.

Valley reacts via social media regarding Colorado shooting
KGBT-TV

Once new information began streaming in about the shooting, over 100 viewers began responding to the Action 4 News Facebook page and Twitter feed. As the day progressed, over 500 comments came into valleycentral.com andAction 4 social media

Media Wise Parents to the rescue
Windsor This Week
Media Wise Parents helps parents, educators and churches become more aware with social media and the internet. Tweet · Bookmark and … It’s certainly in my background with law and marketing, it’s always something that interests me.

We Want To Hear From You: Take This Two-Minute Social Media Survey
Business Insider

This Is The Gun Used In The Colorado Shooting That Everyone Can’t Believe Is Actually Legal

In Focus: Social Media & Law Enforcement

Busted! Police Turn to Social Media to Fight Crime
CNBC.com (blog)

Law enforcement is taking to social media because criminals are changing their behavior and using social media to facilitate crime. In response, law enforcement officials are using it to track down criminals and as a predictive policing tool, said Haywood.

Role of Social Media in Law Enforcement Significant and Growing
Business Wire (press release)

WASHINGTON–(BUSINESS WIRE)–LexisNexis® Risk Solutions today announced the results of a comprehensive survey focused on the impact of social media on law enforcement in criminal investigations.

Police Make Wide Use Of Social Tools
InformationWeek (blog)

The survey, of more than 1200 law enforcement professionals with federal, state, and local agencies, found that 83% of the respondents are using social media, particularly Facebook and YouTube, to further their investigations.

Crime Busters Embrace Social Media
BusinessNewsDaily

It’s not just prospective customers, partners or employers who may be scanning the social media landscape to glean information about you and your organization. The long arm of the law has joined the party as well, a new survey shows.

How Law Enforcement Is Using Social Media (Infographic)
Law enforcement officials are using social media to solve crimes and will continue to do so in greater numbers. In an online survey conducted by LexisNexis Risk Solutions, four out of five law enforcement officials used social media.

Social Media Legal News Roundup

Into the data jungle – in association with Huron Legal
The Lawyer
Technological developments such as cloud computing, social networking and mobile apps mean EU law is no longer fit for purpose. The EU claims current laws often conflict and cost businesses a total of nearly £2bn a year.

Saudi Arabia considers law against insulting Islam
Bangladesh News 24 hours
JEDDAH, Saudi Arabia, July 16 (bdnews24.com/Reuters) – Saudi Arabia is studying new regulations to criminalise insulting Islam, including in social media, and the law could carry heavy penalties, a Saudi paper said on Sunday.

Mind the missteps in online job dance
Lawyers Weekly
With some background check firms specializing in social media searches (U.S.-based Social Intelligence Corp. for one), how do third-party recruiters use social media when screening or finding clients for law firms in Canada?

Saudi Arabia looking to criminalize Islam insults on social media
Bikya Masr
DUBAI: The Saudi Arabia government is looking to ensure users on social media networking sites do not insult Islam or the Prophet Mohamed, al-Watan newspaper reported on Sunday, citing officials who said a new law could bring “heavy” penalties.

Watching the detectives: the case for restricting access to your social media data
Delimiter
That debate tells us something about how Australians and the media conceptualise privacy and business-government relationships in a world where mobile phones and social network services such as Facebook are ubiquitous.

10 Tactics for Integrating Photographs into Content Marketing
Business 2 Community
Acquire digital rights for images. Remember when using images, especially photographs, your legal team is your best friend. Ensure that you’ve got the right to use the photos by incorporating outtakes and additional shots for social media.

Syracuse Neighborhood Watch plans to increase social media outreach
CNYcentral.com
New program coordinator plans more email, social media contact. … CNY Biz Central – Legal. Helpful advice about finding the right attorney for your legal needs. CNY Biz Central. Get information from our team.

Reasonable Expectations of Privacy in the Digital Age
Mondaq News Alerts (registration)
In this digital age of smart phones, global positioning systems, cloud computing, and social networking, determining what constitutes private information and what lengths our legal system will go to protect it is increasingly challenging.

Sale Of Digg Reminder Of Potential Risks To Facebook And Other Social Media …
Seeking Alpha
In 2011, social media watchers may recall reading in Bloomberg that Myspace, which had been purchased by News Corporation (NWS) for $580 million in 2005 had reportedly been sold for just $35 million to private investors, including Justin Timberlake. In …

Your Social Media Tweeting & Posting Legal Rights. TV … – YouTube
Find out how legally liable you are for your Twitter Tweets and Facebook postings.

Learn more about me here: www.ecommerceattorney.com and follow me here

Perfect Pitch: Who Am I? What Am I? Why Am I? Why You Merit Investment

Perfect Pitch™ A Strategy For Concise And Effective Communication Of The Idea Behind Your Business And Why You Merit Investment

©David M. Adler, All Rights Reserved

My recent attendance at TechWeek Chicago 2012 reminded me of advice that I used to provide to start-up and technology entrepreneurs. I have spent the last 15 years of my law practice advising entrepreneurs and businesses in varying stages of development. At some point, all growing businesses will need an infusion of capital. Sometimes this comes from “friends, family and fools.” Just as often it comes from professional investors such as Angels or Venture Capitalists. If you or your business needs additional capital to get to the “next level” whether that be development of a “proof of concept,” execution of the go-to-market strategy or strategic investment in new people or technology, you will need to convince the investor that your idea or business is relevant to the target market, achievable by the people and intellectual capital behind it, and likely to result in a substantial increase in value.

It has been my experience that many entrepreneurs or CEO pitch-men lose sight of the forest for the tress. All too often, the “pitch” or presentation only focuses on one thing. Usually, it focuses too heavily on the idea or the market and not enough on the people and strategy. On the other hand successful presentations seem to incorporate three basic, yet distinct concepts, what I call the tri-partite “Perfect Pitch.” In a nutshell the Perfect Pitch answers three questions: Who Am I? What Am I? Why Am I?

Who Am I? 

Answering this question tells investors about the people behind the idea. Every presentation should begin with a short, pithy and relevant description of the people and company, their history together and their qualifications for successfully commercializing this idea. For example: “John Doe, Jane Smith and Mary Jones each graduated in 2006 with a MBA from the Whoopity School Of Business. John has 5 years experience managing operations for a national retail chain. Jane has a 4 years experience as an assistant human resources manager for a Fortune 500 Company. Mary operated a small consulting business for 3 years before shutting down operations to pursue her MBA. Last year, they formed National Widget Sales Consultants (NWSC) as a Delaware LLC to capitalize on the emerging/growing/widening need for retailers to leverage the growing list of retail sales technologies.”

What Am I?

Answering this question tells the investor about the specific product or service offered and the revenue model. Put another way, answering this question tells investors what you do, how you do it and how you plan to make money. It never ceases to amaze me how many entrepreneurs forget the making-money part. They simply assume that advisors, investors and strategic partners will intuitively “get it.”

We won’t unless you tell us in plain and simple terms. If it is a product, does it stand alone or will it be incorporated into an end-product? Will it be sold wholesale, at retail, through VARs, through an inside sales team, or through an outside sales team, e.g. commissioned sales reps? How will the product be distributed? Will you have your own distribution? Will you piggy-back on another’s? Will you use a traditional courier, e.g., UPS or FedEx?

If it is a service, how will you market it? How will customers acquire it? Will it be licensed? How do you plan to keep customers coming back?

Continuing our previous example, “NWSC has created a proprietary and highly-customizable system that will be marketed and sold by an inside sales force. We will place consultants within our clients’ businesses to dissect their retail operations, identify operational and sales goals and evaluate which of the many technologies in the marketplace are the best fit for achieving those goals. NWSC generates revenue through consulting fees, commissions on technology sales and licensing the system to third-party business consultants.”

This is also the part of the presentation where you want to highlight the existence and commercial viability of any Intellectual Property including, Patents, Trademarks, Copyrighted content and Trade Secrets as well as proprietary technology or systems and methods.

Why Am I?

Now that you have convinced us that you are qualified to run this business and that you know how it will make money, you need to convince us how or why your idea meets existing or potential needs in the marketplace. Another common mistake I see is a focus on market size, penetration and growth. Yes, it’s true that VCs want to see Billion Dollar markets. But, more importantly, they want to know why your idea is going to penetrate that market and capture sales.

For example, is the market fragmented with no dominant provider? Are there segments of the market that are underserved by existing products/services? Put another way, what is your value proposition? Why will customers choose your product or service over their existing, entrenched ways of doing business? Again, don’t assume your audience will instinctively understand this. The more sophisticated the product or service, the more you will have to flesh out this value proposition.

The Bottom Line. 

While following the method outlined above is not guaranteed to land you that round of financing that you are after, it will no doubt help. Paying attention to answering these three simple questions will help keep you focused, keep you on message and provide a framework for answering the types of questions that your advisors, investors and strategic partners will be asking themselves. Good Luck!

PLEASE Forward, comment and follow me!

World Social Media Legal News Roundup

Law professor says social media can pose legal problems in Courtroom
Winnipeg Free Press
SASKATOON – The dean of law at the University of Saskatchewan says using social media can have negative consequences in the Courtroom – Business – Winnipeg Free Press.

Eight Ways Your Employee Social-Media Policy May Violate Federal law
AdAge.com (blog)
All employees have certain rights under federal law that social-media policies can’t restrict.

New Law to Force Identification of Trolls Set to be Unveiled
Technorati
Home / Social Media / Articles / New Law to Force Identification of Troll. … is behind the attacks on them online without having to resort to expensive legal action.

A blue wave of change Cleveland County law enforcers join move toward social media alerts
Norman Transcript
Lauri Stevens, a social media strategist at LAwS Communications, a Boston-area company, said law enforcement agencies nationwide are beginning to embrace social media.

Social media helped, hurt in hunt for suspect in triple shooting
Washington Post
Social media at times was a help, other times a hindrance in the search and eventual arrest of a suspect in the triple fatal shooting at an Alabama apartment complex.

Use social media, but use it responsibly, UAE conference hears
gulfnews.com
He said, “We do not monitor social media networks. People have the freedom to speak within the legal framework. There is no law specifically for twitter, but …

Police: Street gangs embrace social media, too
Kansas.com
Beard gave a presentation on gangs, the Internet and social media at last week’s Midwest Law Enforcement Conference on Gangs and Drugs, held in Wichita.

And…don’t forget to check out my presentation on the Law & Social Data panel at #TechWeek Chicago 2012.

The past few years have witnessed an explosion of legal and regulatory activity involving social and other new media. This session will examine several key areas, including copyright, trademark and related intellectual property concerns; defamation, obscenity and related liability; false advertising and marketing restrictions; gaming; data privacy issues presented by social media; and impacts of social media on employees and the workplace. Attendees will learn how to identify legal risks and issues before they become full-scale emergencies and how to develop appropriate policies and guidelines covering social media activity.

If you can’t make it, check out the Slideshare presentation here.