Your Money or Your Life: Mobile Marketing & Privacy (Part 1 of 3)

Free content is not without a cost.

As our lives have become more digitally enmeshed with content, immersive entertainment and devices, the economic bargain that makes it possible has gone largely unnoticed. Simply put, the collection, analysis and sharing of personal data is driving the digital economy. Mobile applications (Apps), digital content and entertainment – from TV shows to games – are available for “free” but subsidized by income from online ads that are customized using data about customers. Vendors, advertisers and platforms compete for “eyeballs” based, in part, on the quality of the information they possess about users to whom the ads are targeted.

Across this interconnected landscape of users, content providers and devices, the issue of online privacy has become a major talking point for app developers, marketers, consumers and legislators. Recently, a wide range of stakeholders, from large institutions to smaller developers, have been accused of mishandling personal data. As the volume of public debate has increased, legislators have introduced a raft privacy initiatives. The Obama administration has called for a Privacy Bill of Rights, an industry consortium of leading web sites and search engines has proposed its own privacy best practices and the Electronic Frontier Foundation has published a consumer-oriented Mobile User Privacy Bill of Rights.

Part 1 of this article looks at several recent and high-profile revelations about how personal information is collected and used, often without the user’s knowledge and consent. Part 2 discusses the legal risks faced by vendors that don’t take adequate precautions to protect consumer privacy and Part 3 concludes with strategies and tactics that help leverage the power of personalization while avoiding the pitfalls of privacy and data security.

1. The current state of information gathering

The scope of personal information gathered is unprecedented and largely unknown. For years, “free” web-based content has been available because of the implicit compromise between content providers and content consumers. Advances in technology have made it easier to track a user’s web browsing habits, mobile browsing habits, and even real-time geospatial location (check in apps and GPS). In the last few months, we have learned that some apps not only gather this mostly non-personally-identifiable data, but also upload a user’s address book contacts and even photos.

On Wednesday Feb. 2012, software Developer Arun Thampi “outed” Path, the purveyor of a self-titled journaling app, for sending users’ address book contents to the company. Path lets users share what they’re doing with a select group of friends and gives users the option to find friends on the app through contacts or other social networks. Thampi disclosed the clandestine data transfer in a blog post after discovering that his phone’s entire address book, including full names and e-mail addresses, was being sent to Path without his explicit consent. According to Path, this data was necessary to in order to quickly notify users when people they know join Path.

Not too long ago, Google earned itself a similar PR (and legal) black eye when it launched its social network, Google Buzz, in 2010 through its Gmail web-based email product. At launch, users were not informed that the identity of individuals they emailed most frequently would be made public by default. Google Buzz automatically disclosed the email addresses of a user’s contacts by default. Google settled with the FTC over allegations that Google used deceptive practices and violated its own privacy policies.

On Feb 17 2012, WSJ reported that Google Inc. and other advertising companies have been bypassing the privacy settings of millions of people using Apple Inc.’s Web browser on their iPhones and computers—tracking the Web-browsing habits of people who intended for that kind of monitoring to be blocked. The companies used special computer code that tricks Apple’s Safari Web-browsing software into letting them monitor many users. Safari, the most widely used browser on mobile devices, is designed to block such tracking by default.

A major topic for discussion just this week is the “Target Snafu.” As originally reported in the New York Times, Target used customer data and predictive analytics to determine that one of their customers was pregnant, and even her specific trimester. The girl’s father learned of the pregnancy when the retailer emailed her promotional material and coupons.

It used to take days or even weeks to gather, synthesize and extrapolate data about a customer’s buying habits and receptiveness to particular products or services. Now it takes milliseconds. A targeted ad can be sourced and served in the time it takes to hit “refresh” on a web browser. Companies are using massive amounts of data to predict what their customers are going to want next. More importantly, gathering that data is getting easier, cheaper and more ubiquitous as the source of that data moves from the desktop to mobile devices.

So where is the middle ground between privacy and targeted advertising? Is it spying simply because the user doesn’t know what data is being collected even though the user accepted a broad and ambiguous Terms of Use agreement? Is knowingly contributing data without boundaries sufficiently transparent?

Five Social Media Legal Mistakes That Your Business Is Making

Image representing Facebook as depicted in Cru...
Image via CrunchBase

Seemingly overnight, Social media has moved from a business curiosity to an invaluable tool for customer engagement, brand positioning and employee empowerment. For example, social media use for 18-29 year olds has grown from 16% in 2005 to 89% in 2010. A recent survey, now in its third year, found that Social Media is imperative and effective to stand out in a crowded market: 88% of all marketers found that it helped increase exposure and 76% found that it increased traffic and subscriptions.

Faced with the rapid adoption of social media services and platforms, companies find themselves in a dilemma: move quickly to adapt to new technologies, or put policies in place that support marketing goals. Finding the right balance between taking appropriate business risks and minimizing legal ones is a dilemma shared by all businesses, and it can be particularly tricky in the rapidly changing realm of social media. A social media snafu could pull a business into a range of legal imbroglios, involving employment law, intellectual property rights, advertising, defamation, libel, antitrust, and privacy protection.  What follows is a list of five common social media legal mistakes that businesses are making.

1. Your Company does not have a social media policy.

Social media is going through an evolution from social media to social business. Yet In the rush to avoid being left behind, some 79% of companies do not have social media policies in place. Companies and employees are becoming deep users of Twitter, LinkedIn, Facebook, blogs, private-label platforms, and the like. Absence of a policy has led to lawsuits over basic issues such as ownership of LinkedIn profiles and Twitter followers. Lack of a policy could also lead to awkward situations that require a response, but may not rise to the level of a legal quandary such as public criticism by a volunteer or advisor.

Having a social media policy cannot prevent the occurrence of unintended consequences. However, it can address most risks that businesses will face and provide an informal framework for addressing issues that will inevitably arise before they become full-fledged emergencies that require a legal solution.

2. Your Company’s social media policy is unenforceable.

Not surprisingly, one of the most active legal areas of social media for business has been in the context of Employer-Employee relations. In 2011, the U.S. Chamber of Commerce released a report stating that the National Labor Relations Board (NLRB) had received 129 cases involving social media. The majority of claims concerned overly-restrictive employer social media policies or employee discipline and even termination based on use of social media.

More recently, the NLRB released updated guidance discussing 14 such cases in particular. Significantly, the NLRB criticized five employers’ social media policies, as  “unlawfully overly broad” (e.g., too restrictive). In four cases, an employee’s use of Facebook to complain about their employer was held to be “protected concerted activity.” The benefit for employers is that the report frames the discussion for the appropriate scope of an enforceable social media policy.

3. Your employees don’t understand your social media policy.

For companies who have drafted a social media policy, another risk is that the employees who are engaged in social media on behalf of the company or brand do not understand the policies. Training employees about what it is, how it works and what’s expected is just the beginning.

For example, Australian telecomm company Telstra is an excellent example of social media transparency. This 40,000+ employee company mandates social media training built around a manageable policy focused on “3Rs” – responsibility, respect and representation. To promote awareness and understanding, the comic book-styled policy answers simple questions like “what is Facebook?” and more complex issues like employer criticism on personal blogs. Taking it a step further, the company published their entire social media training guide online for others to study and critique.

4. Your privacy policy is out of date.

Back in the early days of the Internet “Gold Rush,” companies raced to create an online presence complete with ecommerce storefronts. Partly due to the length of time it took to get a web site up and partly due to the fear of risks associated with ecommerce, companies made sure to implement comprehensive Terms of Use and Privacy Policies. Many have not revisited those policies since.

The risks of an outdated privacy policy are twofold. First, it may be unenforceable for any number of reasons. For example, the company has changed the way it gathers and stores information about site visitors, has changed the platforms from which it gathers such data and potentially with whom it shares such data, even unwittingly.

More importantly, the dynamics of online usage and marketing have changed. The availability of GPS data and commonly used technologies for targeted advertising and related services pose new privacy risks such as leaking personally identifiable information including usernames, email addresses, first names, last names, physical addresses, phone numbers, and birthdays. A recent series of articles by the Wall Street Journal analyzed the tracking files installed on people’s computers by the 50 most popular U.S. websites, plus WSJ.com and found that some sites like dictionary.com had over 200 such tracking cookies.

Second, an outdated privacy policy may subject a business to scrutiny and even penalties from the Federal Trade Commission (FTC). On October 12, 2011 the FTC announced a settlement with a file-sharing application developer over allegations that it used deceptive default privacy settings, which would lead consumers to unintentionally and unknowingly share personal files from their mobile device or computer with the public.

5. Your Company is Not Engaging In The Conversation.

Lastly, social media enables instantaneous, ubiquitous, electronic social interaction using highly accessible and scalable publishing techniques. The platforms and services that enable this interaction also provide an unfettered medium for defamatory statements about individuals, disparaging remarks about a companies’ products and services and inaccurate or misleading remarks by over-enthusiastic employees.

The legal risk is that a company often does not control such conversations which can quickly spiral out of control. Many web sites and blogs allow comments and invite participation by unrelated third parties. Having a strategy for when, how, and why to engage is critical to mitigate the legal risks since this area of law is notoriously fact and circumstances dependent and varies by jurisdiction.

Contact Us For a Consultation.

Is your business making one of the mistakes described above? Do you want to learn how to use social media to market and communicate with existing and prospective clients and do so in a way that minimizes potential risks and pitfalls? Hopefully, the guidance outlined above can serve as a good starting point for discussions about how best to use social media as well as suggestions regarding factors that firms may wish to consider in strengthening their compliance and risk management programs. We invite you to contact us with comments and requests about how we can help you educate your employees, prevent fraud, monitor risk, and promote compliance. We can be reached at lsglegal.com, 866-734-256, @adlerlaw and dadler@lsglegal.com.

RSA 2012 Conference Podcast: Social Media Legal & Regulatory Compliance

The past few years have witnessed an explosion of legal and regulatory activity involving social and other new media. This session will examine several key areas, including copyright, trademark and related intellectual property concerns; defamation, obscenity and related liability; false advertising and marketing restrictions; gaming; data privacy issues presented by social media; and impacts of social media on employees and the workplace. Attendees will learn how to identify legal risks and issues before they become full-scale emergencies and how to develop appropriate policies and guidelines covering social media activity.

The RSA® Conference 2012 is coming up: February 27 – March 2, 2012 at the Moscone cEnter in San Francisco, CA.

Can’t make the Conference? Listen to the podcast here to get a sense of what you need to know.

FTC Puts an End to Facebook’s Freewheeling Privacy Ways

The social networking service Facebook has agreed to settle Federal Trade Commission charges that it deceived consumers by telling them they could keep their information on Facebook private, and then repeatedly allowing it to be shared and made public. The proposedsettlement requires Facebook to take several steps to make sure it lives up to its promises in the future, including giving consumers clear and prominent notice and obtaining consumers’ express consent before their information is shared beyond the privacy settings they have established.

Read the FTC update here.

Social Media Legal Risks: Seven Ways to Maintain Social Media Marketing Legal Compliance

Seal of the United States Federal Trade Commis...
Image via Wikipedia

In October 2009, the Federal Trade Commission released it’s updated “FTC’s Guides Concerning the Use of Endorsements and Testimonials in Advertising.” The purpose of the update was to address the increasing use of endorsements by consumers, experts, organizations and celebrities in online marketing. The update is particularly relevant to the explosive growth of social media as a marketing tool.

The updated FTC Guides contain two notable areas of concern for marketers. First, the Guides removed the safe harbor for advertisements featuring a consumer’s experience with a product or service, the so-called “results not typical” disclosure. Second, the FTC Guides underscored the longstanding principle of disclosing “material connections” between advertisers and the consumers, experts, organizations, and celebrities providing reviews and endorsements of products and services.

Even with the illustrations provided within the FTC Guides themselves, it is still confusing for advertisers, marketers, bloggers and social media users to know how to comply with the guidelines. The purpose of this article is to provided simple, concrete standards to determine (1) when to make certain disclosures and (2) the type of disclosures required by the situation. I have grouped the disclosures into seven categories: Personal Opinion, Free Samples & Free Gifts, Promotional Relationship, Employment Relationship, Affiliate Relationship, Healthcare Disclosures, and Financial Guidelines & Disclosures. The key requirement to keep in mind is the obligation to disclose any relationship that may have influenced you.

1. Personal Opinion

If you write a review or blog post and your post contains only your own opinions, you haven’t received any compensation for the review or post, and you otherwise have no material connection to the topic of your post, you have nothing to disclose.

2. Free Sample/Free Gift

If you have been given a free copy, sample, or gift of a product or service and you write a review or blog post, you must disclose the facts and circumstances of how you received the item or service, even if you have not been paid to review or post on that topic. You do not run afoul of the disclosure rules if you receive payment unrelated your content. This disclosure is useful to keep in mind when your content relates to product previews, reviews of samples, services, gifts, books, software, music, movies, etc.

3. Promotional Relationships

If you write a review or blog post and your post is based upon an advertising relationship, and you have received compensation (cash, free services, product samples for personal use or a gift) for the review or post, you must disclose the nature of the relationship, whether you received anything of value, and information about relationships with advertisers or endorsers that would have a material impact about how a prospective consumer would view the message. This disclosure is useful to keep in mind when your content relates to paid posts, sponsored messages, tweets, fan page postings, etc.

4. Employment Relationships

If you write a review or blog post and your post is based upon an employment relationship, e.g. you are an employee or shareholder of a related company, you have a “material business relationship” to disclose, even if you are not being directly compensated for the message. You may post on behalf of a business or brand. In fact, it may even be part of your job description. Again, be mindful of the requirement to disclose any “connections” that may have influenced you, including both direct and indirect relationships.

5. Affiliate Relationships

If you write a review or blog post and your post is based upon an affiliate relationship, e.g., you have included affiliate links on your page, you must disclose the fact that the relationship exists and that you will be paid for referrals from your page.

6. Healthcare Disclosures

If you write a review or blog post and your content is based upon a connection to a pharmaceutical or healthcare product or program, you need to include relevant healthcare-related disclosures or information safety warnings, side effects, or official links with information.

7. Financial Guidelines & Disclosures

If you write a review or blog post and you work for a financial services company, you may be making investor-relations communications and your communications are subject to regulation by the NASD, SEC, FINRA and potentially state and federal regulatory agencies. The FINRA Guidance on Blogs & Social Networking Sites” can be found here. Record Retention: ensure that you can retain records of those communications. Suitability: a particular communication a “recommendation” for purposes of NASD Rule 2310 and is it suitable for potential recipients. Public Appearances: determine whether  your post part of an “interactive online forum” and whether supervision is required. Third-Party Posts: If your firm created or “sponsors” and online forum, be aware that, under certain circumstances, a customer’s or other third party’s content on a social media site may become attributable to the firm. Whether third-party content is attributable to a firm depends on whether the firm has (1) involved itself in the preparation of the content or (2) explicitly or implicitly endorsed or approved the content.

Clearly, legal and regulatory compliance for social media remains a minefield. Although this article is intended to give you a working knowledge of the types of risks created by, and disclosures required for, the use of Social Media, it is NOT LEGAL ADVICE. Each situation is unique and you should consult with qualified legal counsel regarding your specific circumstances.

ABOUT THE AUTHOR

David M. Adler, Esq. is an attorney, author, educator, entrepreneur and partner at the boutique intellectual property, entertainment & media law firm LEAVENS, STRAND, GLOVER & ADLER, LLC based in Chicago, Illinois. My responsibilities include providing advice to business units and executives on copyright, trademark, ecommerce, software/IT, media & entertainment and issues associated with creating and commercializing innovations and creative content, drafting and negotiating contracts and licenses, advising on securities laws and corporate governance and managing outside counsel. Learn more about me here: www.ecommerceattorney.com and here: Leavens Strand Glover & Adler, LLC.

US bank consortium develops social media framework

BITS, the technology policy division of US bank-backed The Financial Services Roundtable, has released “Social Media Risks and Mitigation,” a framework for financial institutions adopting social media and a guide to managing related security risks.

Social media issues span legal, compliance, marketing, communications, IT and human resources departments. “Financial services customers are using social media and demanding that institutions have a secure and prudent presence there,” said Andrew Kennedy, BITS’ social media lead. The bits paper provides an enterprise-wide view of policies, practices, communications and risk management strategies.

Read the full article here: http://tinyurl.com/44rntx2

ABOUT ME

David M. Adler, Esq. is an attorney, author, educator, entrepreneur and partner at the boutique intellectual property, entertainment & media law firm LEAVENS, STRAND, GLOVER & ADLER, LLC based in Chicago, Illinois. My responsibilities include providing advice to business units and executives on copyright, trademark, ecommerce, software/IT, media & entertainment and issues associated with creating and commercializing innovations and creative content, drafting and negotiating contracts and licenses, advising on securities laws and corporate governance and managing outside counsel. Learn more about me here: www.ecommerceattorney.com

Facebook Marketing: Legal & Regulatory Compliance By David M. Adler, Esq.

Image representing Facebook as depicted in Cru...
Image via CrunchBase

AllFaceBook Presents AF Expo San Francisco June 27-29, 2011

COMMERCE & MONETIZATIONFacebook Marketing: Legal & Regulatory Compliance

The use of social media for marketing and advertising purposes is one of the fastest growing areas for business and marketers. The advent of social media sites like Facebook provides the opportunity for authentic interaction and engagement with customers. Therefore, it is no surprise that it is being used as a marketing tool by companies large and small to help them achieve their strategic goals. But with every technological development and opportunity, new legal and business risks present themselves. Understanding and minimizing these risks will help you maximize the opportunities. A best practices approach to social media marketing involves having the company’s philosophy, methodology, and guidelines captured in a comprehensive written policy that is clearly and regularly communicated to the employees, and regularly updated to keep abreast of new developments, opportunities and evolving legal guidance. Attendees will learn how to identify the legal issues and develop policies and procedures to keep informed about the current technology, marketing strategies and regulatory compliance.

Everyone at AF Expo shares a belief that the Facebook experience represents a paradigm shift in the way that marketing professionals identify, engage and convert customers. In the past, marketers had to conduct research to locate customs and to determine their wants and needs. Once these were identified, you needed to convince your customers to value your brand, understand your product/service and ultimately purchase what you were selling.
Facebook changes all of these assumptions. It offers an interactive platform where customs are actively engaged in seeking out the brands they are interested in – whether individually or through trusted networks, tell brand owned what they do and do not like about their brand and tell marketers whether they are open to receiving more information. Interestingly, the platform allows marketers to continue the conversation even when the customer has nominally disengaged (through trusted networks).
Like everything else, with great power comes great risks. Facebook marketing that is thoughtful, respectful and legally compliant is extremely effective. [give examples] However, marketing efforts that fail to understand and account for the requirements to maintain legal compliance can be a fixated.
In the beginning one could poke, like and comment. But what happens when you can purchase? Facebook is rapidly becoming a platform to identify, locate, contact and transact business with consumers of goods and services, both physical and virtual, using currency that is both physical and virtual.
My presentation will identify and explain the risks for Facebook marketers, grouped  into three risk categories, “The Three Cs” of Facebook marketing:
Content
Connecting
Commerce