Do social network acquisitions run roughshod over privacy? |
Connect with TechFlash on our Facebook page for all the latest technology news headlines and commentary, plus information and access to special events, photos from events, promotions and more.
Venkat Balasubramani
Venkat Balasubramani: Did Facebook’s acquisition of FriendFeed comport with FriendFeed’s privacy policy? In arguing this point, lawyers may debate the nuances of the policy, but consumers are largely left in the dark.
Most observers pegged the recent acquisition by FriendFeed of Facebook and by Mint of Intuit as at least partially – if not totally – driven by FriendFeed’s and Mint’s user base.
Are the resulting transfers of user information in line with consumer expectations as far as privacy? Do the transfers comply with the privacy policies of these companies? From the consumer standpoint, the answer is “no,” and probably “don’t know.” Privacy policies are increasingly filled with vague legalese.
As a result, lawyers and regulators may argue about the effect of technical language in these policies, but consumers are left without a clear idea as to what to expect.
In addition, the privacy practices of a company often vary from the stated policy.
The FriendFeed and Mint acquisitions received little attention from a privacy standpoint, but given the stakes, privacy advocates and regulators are sure to take notice in the long term.
Background: With the exception of certain specific industries or categories of information, few laws expressly regulate the transfer of user information between entities in the context of an acquisition.
Whether a transfer of user information is appropriate is typically left to the privacy policy of the selling company. Initially, many privacy policies provided that consumer information would not be transferred at all, or would only be transferred to another company that has the same policy.
One famous example in the wake of the first dot-com collapse involved Toysmart.
When Toysmart shuttered, and attempted to transfer its user information, the Federal Trade Commission intervened.
The FTC argued that the transfer of user information was not permitted under Toysmart’s privacy policy.
Ultimately, a settlement was reached that would have allowed Toysmart to sell to a bidder but with certain restrictions set by the FTC.
Online retailer eToys faced a similar situation when it wound down and tried to transfer its user information – it was only allowed to transfer information about consumers who opted in.
Privacy Policies Are Vague to the Point of Being Useless
Since the days of Toysmart and eToys, most companies tend to draft policies that leave plenty of room when it comes to transferring user information.
But privacy policies are so filled with legalese and vague assurances to consumers that it’s tough to tell what the policies really say.
For example, here’s FriendFeed’s policy:
The policy provides that if personal information is transferred in the context of an acquisition and becomes subject to a “different privacy policy,” FriendFeed will provide advance notice. So, when Facebook acquired FriendFeed, did the information become subject to a “different privacy policy?'
Apparently Facebook and FriendFeed didn’t think so. As a FriendFeed user I don’t recall receiving any notice.
Mint: Here’s what Mint’s privacy policy says:
The first paragraph makes an emphatic statement that the user’s privacy is “not for sale.”
But the policy goes on to state that a user’s information may be transferred in the context of an acquisition, but if such a transfer occurs, Mint will: use [their] best efforts to require that the new combined entity follow this Privacy and Security Policy with respect to your personal information, as and to the extent required by applicable law and to require that you receive prior notice if your personal information could be used contrary to this Policy. “Best efforts?" "As and to the extent required by applicable law?"
I’m not sure what this language means really. Again, lots of open ended language surrounded by legalese.
When coupled with Mint’s contradictory but emphatic assurance that the consumer’s “privacy is not for sale,” the consumer is left with little idea as to what to expect from a privacy standpoint.
Twitter’s policy follows a similar pattern in that it allows for an acquisition, but requires notice if the transfer is to a company that has a “materially” different policy.
It also contains a potential gotcha for Twitter (and any potential suitor ) – Twitter’s policy states that it will give users the opportunity to opt-out of any transfer to an entity that has a “materially” different privacy policy.
It’s tough to deny that the stakes have increased significantly for consumers.
Whether it’s Facebook or Google (Gmail; Google docs), consumers store an increasing amount of personal, intimate, and in some cases professional information on these networks.
An acquisition allows networks to combine data, and round out “profiles” of users. The cost in privacy terms to the consumer is undoubtedly higher than they were in the late nineties. An acquisition means that the information is often subject to a different privacy regime without any choice on the part of the consumer.
Additionally, there’s the discrepancy between what a company’s privacy policy says and what its actual privacy practices are.
Think of beacon and other Facebook privacy snafus in light of the assurances that are in Facebook’s privacy policy. Companies such as Facebook and Google also face threats from third party hackers. Facebook’s acquisition of FriendFeed allowed Facebook to gain access to user information for users who may have never trusted Facebook with their information in the first place.
The current climate of acquisitions present challenges for consumer privacy. Vaguely drafted privacy policies filled with legalese leave companies plenty of wiggle room, but consumers are left in the dark. It’s only a matter of time before privacy advocates and regulators focus on these issues.
Venkat Balasubramani is one of the founding lawyers at Focal PLLC , a Seattle-based law firm focused on technology, Internet and media clients. He blogs on technology and internet-related legal issues at Spam Notes. Opinions expressed in guest posts are those of their authors, and don't necessarily reflect the views of TechFlash or its staff.
If you are commenting using a Facebook account, your profile information may be displayed with your comment depending on your privacy settings. By leaving the 'Post to Facebook' box selected, your comment will be published to your Facebook profile in addition to the space below.
Who's creating today's energy efficient buildings? Find out at the BetterBricks Awards, Feb. 16
BetterBricks Awards salute the individuals leading the way for high performance commercial buildings with an emphasis on energy efficiency. Join us as we recognize these standout green building professionals.
Award categories include: Advocate; Architect/Designer; Facility Manager/Operator; and Owner/Developer.
Keynote Speaker: Kevin Kampschroer, Director of U.S. GSA's Office of Federal High Performance Buildings. Kevin leads the U.S. General Services Administration's efforts in building sustainability and accelerating industry adoption of sustainable principles across all aspects of a building's life.
Register here by February 10!
If you are interested in buying a table, email Monica Alquist or call her at 206-876-5404.
The Triple Door Presents: The Atomic Bombshells "J'ADORE!: A Burlesque Valentine"
Seattle's reigning Burlesque super-troupe delivers a gorgeous and glittering VALENTINE featuring some of the Bombshells' most exhilarating acts to date. J'Adore! promises to celebrate l'amour with good humor, style, and a healthy dose of dazzle! Bring a friend, a lover, a family member, or a secret crush, and celebrate with the Valentine's Burlesque spectacular that will leave you shouting: "J'ADORE......The Atomic Bombshells!" The incomparable Jasper McCann emcees with high style and charm.
Please visit www.thetripledoor.net for a full schedule of future performances.
The Triple Door Presents: Bob Mould – See A Little Light: An Evening of Reading and Music
"Bob Mould. Those two words are synonymous with integrity. From Husker Du in the last century to right at this moment, Bob is the real deal, writing and playing music for music's sake. He's a great songwriter and performer. I have been a fan of Bob's for thirty years now with no end in sight." -Henry Rollins
Please visit www.thetripledoor.net for a full schedule of future performances.
Why Choose BDO for your SOC (previously SAS 70) Reports?
BDO’s experience in providing attestation services (SAS 70/SSAE 16, AT 101, AT 201, AT 601, etc.) to a broad range of industries, and our team of skilled professionals distinctly qualifies us to serve as your company’s Service Auditor. By leveraging the BDO global network of control specialists, we are poised to provide global services in more than 1,000 offices and across 119 countries. Many organizations find that investing in reports on controls may result in benefits, including:
• Increased client confidence
• Improved competitive advantage
• Minimization of frequent audits
• Streamlined business processes and controls
• Enhanced risk management
For detailed information contact Paul Martini at pmartini@bdo.com.