Kids, Connected Toys and Devices, and Privacy

At FPF, we recognize the benefits that connected home technologies can provide to individuals, families, and kids.  We also know that privacy issues can make or break adoption of connected home tech – particularly questions about whether kids’ privacy and security are sufficiently safeguarded.   Families are using voice controlled devices to search the web, play games, and order products. Kids are playing with dolls that listen and talk, interactive animals, and apps that link toys to digital services.  Parents are using smart home technology to keep their families safe – connected tech can warn of fires or alert parents when a child falls into a backyard pool.

These technologies and many others are generating opportunities for interactive play and education, but also creating new challenges. Toys that can become a child’s closest friend, collect intimate information, and provide advice are raising questions about how to ensure families can make appropriate choices about how data is collected and used.

I think there are 5 key questions we need to answer about kids, connected homes, and privacy.

First: does COPPA apply to connected toys? Yes. Nearly all connected toys connect to online services or interact with apps that do.  This means that they are subject to COPPA protections.

Second: Do connected toys require a legislative update to COPPA because toys often lack screens and keyboards for parents to use to grant parental consent?  No. COPPA requires companies to provide notices and obtain consent from parents when online technologies collect personal data from kids.  Although many connected toys do not have built-in screens, toymakers are able to interact with parents through app-based or web-based interfaces.  And the COPPA rule allows for a range of alternative ways to verify parental permission and gives the FTC leeway to assess new methods as they become technically feasible.

Third: Are general home devices that serve families covered by COPPA? They are not and should not be. General purpose home devices like alarm systems, security cameras, smart TVs and home assistants are not targeted at children and don’t have actual knowledge of personal information about children.  Today, connected devices aren’t able to distinguish between an adult and a child.   This is similar to general purpose websites, search engines and other services that serve families – COPPA was designed to avoid placing its burdens on all users interacting with a service, simply because some children are using it.  The services that can understand speech are relying on speech recognition, not unique voice recognition, as we explain in a recent FPF whitepaper.

Fourth: Do parents have appropriate controls in light of kids’ interactions with the connected home? Sometimes they do, sometime they do not.  Law is a blunt tool, offering binary choices, on or off, legal or illegal.  But, as connected devices are becoming more integrated in our lives, parents must be able to have nuanced options to aid in their decision making.  More sophisticated and more usable design is going to be needed to help us manage the increasing number of options.  Carnegie Mellon’s Norman Sadeh and his team point the way to what is possible, with an app that uses artificial intelligence to learn what a user wants and then makes the hundreds of choices needed to fully configure the privacy options on a typical smartphone.

We will need technology and policy that allows parents to make choices consistent with their goals and values and that recognizes that not every household looks the same.  In some households, the child is the only English speaker, an elderly grandparent is the primary caregiver, no one has a credit card needed for age verification and the service needed is increasingly essential for school, work or play.

Finally: Are all connected home products sufficiently secure? No. Many digital devices have security vulnerabilities, and connected home systems are no different.  Does COPPA’s security requirement provide an adequate incentive for companies to work hard to provide reasonable security? Starting August 1, 2016, the maximum civil penalty for violating COPPA will more than double from $16,000 to $40,000 per violation. A violation is defined as each child an operator collects personal information from in violation of COPPA.  A connected toy directed at children under 13 with only 1000 users would face a potential civil penalty of as much as $40,000,000.  The FTC has super hero powers here – but it will take more than penalties.  Getting home security right requires education of device makers, software providers, home routers, and consumers who end up configuring these items.  Too hard to set up or use, the consumer turns the security off. Too easy, the hacker gets in.  The research needed to ensure useable security must be a priority.

We aren’t just thinking about toys and entertainment when we talk smart home. We are talking about inclusion of people with disabilities, the elderly, the underprivileged.  We are talking safety and education and health.

Some examples:

And of course people are familiar with the Nest and its money saving, environmental and safety benefits. For people with mobility-related disabilities, smart home technology allows users to control things in the home that can be physically challenging to access such as lights, door locks, or security systems.

It is true that these services are collecting detailed information about our day-to-day activities within our most private places, our homes.  But it is important not to lose sight of the fact that for adults and for kids, many of these smart devices are critical for health and wellness and security and sometimes just for fun.

Podcast: Lauren Smith Speaks with Bloomberg Law

Lauren Smith, Policy Counsel, spoke with Bloomberg Law today about connected cars and the legal implications of data collection. Lauren discussed the importance of privacy and highlighted many principles that are covered in the our report, “The Connected Car and Privacy: Navigating New Data Issues.” You can listen to the interview beginning at 5:50.

LISTEN

 

Big Data and Elections

Brenda Leong, FPF Senior Counsel and Director of Operations, contributed to a story in CSO about big data and elections. She explained:

Big data analytics offers, “great new ways to engage with voters on the things that really matter to them, which results in more motivated, and hopefully better informed, participants in the electoral process, and likely higher turnouts on election day.”

“Every campaign needs to treat security and privacy needs seriously, and have meaningful training for workers. We strongly recommend that every campaign have a chief privacy officer to monitor just these issues,” she said.

Read the full article in CSO

Future of Privacy Forum Statement Regarding Finalization of the US-EU Privacy Shield Agreement

In response to today’s finalization of the US-EU Privacy Shield agreement, FPF CEO Jules Polonetsky issued the following statement:

“Today’s finalization of the US-EU Privacy Shield agreement preserves an important data transfer mechanism that is supported by robust privacy safeguards. But for the long term EU-US relationship, it is important to see Privacy Shield as the beginning of a process, not the end.  Data flows between the US and EU economies and the services used by individuals across the Atlantic are too important to be strained by constant uncertainty.  It will be essential for companies, policymakers, regulators and civil society to build on the legal documents by seeking ongoing efforts to build trust and support responsible data practices.”

EU Approves Privacy Shield: The Agreement Will Benefit Companies and Individuals in the US and Europe

Today, EU member states strongly supported finalization of the EU-US Privacy Shield, a renewed framework for transatlantic data flows that replaces the EU-US Safe Harbor arrangement.  The Privacy Shield agreement enables member companies to transfer data between the EU and US, subject to privacy safeguards and commitments.

“Approving the Privacy Shield preserves a key legal mechanism for EU-US data flows,” stated FPF Vice President of Policy John Verdi.  “There are, of course, challenges ahead.  Surveillance reform must continue on both sides of the Atlantic.  But today’s approval provides much needed certainty for American companies that rely on the EU-US framework to pay and manage their EU-based employees, as well as for the 150+ EU companies that use the framework to transfer data to US subsidiaries.”

The Safe Harbor agreement was struck down last year amid concerns regarding US government surveillance programs – concerns that were amplified by the 2013 Snowden revelations.  The Privacy Shield approval comes in the wake of surveillance reforms and additional commitments by the US government.  FPF and Professor Peter Swire previously detailed the more than two dozen significant reforms to US surveillance law and practice since 2013. A previous FPF study revealed that Safe Harbor included 152 companies who are headquartered or co-headquartered in European countries, which span across a wide range of industries and countries.

July 20th Event: Kids & The Connected Home

Join us for a discussion on kids, connected toys and devices, and privacy.

The debate over the relationship between children and technology has been heated and complex. Issues ranging from the right amount of screen time, online privacy, safety and security have occupied policymakers, parents, and advocates for quite some time. New technologies such as dolls that listen and talk, interactive teddy bears, smart home devices, virtual reality, and artificial intelligence have intensified the debate. As new types of data are collected, these technologies will generate both opportunities for interactive play and education, but also new challenges.

Security concerns around outsiders accessing children’s information or accessing a parent’s home are already in the news. The nature of dolls and toys that become a child’s best friend – that can discuss intimate information, provide advice, and be a buddy – are raising questions about the right balance. When artificial intelligence enters the mix, the debate will only be intensified.

This talk is free and open to the public though space is limited. Doors open at 9:30 am for networking.

Follow the conversation on Twitter via the hashtag #InternetOfToys and follow @csmpasscode, @FOSI, and @futureofprivacy.

REGISTER

WATCH

WHEN


Wednesday, July 20, 2016 from 10:00 am to 12:00 pm (EDT)

WHERE


Microsoft I & P Center – 901 K Street NW, 11th Floor, Washington, DC 20001

FPF Advisory Board Member William McGeveran Publishes Privacy and Data Protection Law

Privacy and Data Protection LawWe are pleased to share that FPF Advisory Board member William McGeveran published Privacy and Data Protection Law on June 24, 2016. The textbook covers statutory and regulatory structures including FTC enforcement, medical privacy, and the Patriot Act, as well as standard topics like Torts and the Fourth Amendment.

William teaches courses in Data Privacy Law, Internet Law, Trademark Law, Civil Procedure I and II, and Law in Practice at the University of Minnesota Law School. He is an affiliated professor at the School of Journalism and Mass Communications. Order your copy of Privacy and Data Protection Law today!

Protecting privacy and promoting inclusion with the 'Internet of Things'

To technologists and innovators, the “Internet of Things” (IoT) represents a world of exciting new benefits that will solve important technical and social problems. To critics, IoT represents a world of pervasive surveillance, with toys that spy on kids and microphone-enabled devices recording and retaining our most personal data. As a think tank focused on helping chief privacy officers of companies both large and small navigate privacy challenges, as well as advocating for ethical data practices in support of emerging technologies, we believe they are both right. From traffic management to healthcare improvements, there is a wide range of possible benefits that will be derived from information networks created by the IoT. There is the potential to improve personal safety, improve public safety, increase consumer convenience, provide environmental benefits and promote business innovation. However, if we do not have the right guiding principles or necessary privacy safeguards, consumers will lose trust in the evolving technologies. We need to address security and privacy issues to ensure that the IoT achieves its full potential.

Recognizing this need, Samsung recently hosted a conference bringing together leaders from both government and industry to discuss the future of IoT. In his opening remarks, Oh-Hyun Kwon, vice chairman and CEO at Samsung Electronics, emphasized that the conversation around the possibilities of IoT should shift from focusing on smart homes, offices and factories, to smart communities, smart nations and a smarter world with better living standards for everyone, everywhere. In comments we filed recently for input into a new Department of Commerce green paper on shaping the future of IoT, we discussed ways IoT technologies are improving the day-to-day quality of life for people with low income, people with disabilities and traditionally underserved populations, among others. For example:

It is important that we do not lose sight of the broad hope that IoT technology will not simply be more gadgets for the affluent, but also a platform for improving quality of life for the traditionally underserved. As government policymakers and regulators examine, understand and embrace emerging IoT technologies, they must encourage strategies that benefit everyone, while at the same time apply commonsense privacy protections that build trust in IoT technologies to help ensure that consumers enjoy the full benefits of IoT sensors and devices.

This piece was originally published on June 29, 2016, 11:16 AM ET, by The Hill. 

W&L Law Review Publishes First-ever Disclosure of Facebook Internal Review Process

Today, Washington and Lee University (W&L) published a piece about a recent study titled “Evolving the IRB: Building Robust Review for Industry Research.” The study was authored by Molly Jackman and Lauri Kanerva of Facebook.

W&L explains:

“According to the authors, companies increasingly conduct research in order to decide what products to build and to improve customers’ experience with those products. But they say that existing ethical guidelines for research do not always completely address the considerations that industry researchers face, and they argue that companies should develop principles and practices that take into account the values set out in law and ethics. In Facebook’s case, this means maintaining a standing committee of five employees, including experts in law, ethics, communications, and policy to vet research proposals and identify ethical concerns.”

Read the full piece on W&L’s wesbite

FTC Settles with Major Ad Platform for Deceptive Location Tracking via Wi-Fi

The FTC announced a settlement today with InMobi, a major advertising platform provider, for engaging in deceptive location tracking practices. As explained below, InMobi used alternative methods to collect location data from users, even after the users had chosen not to share their location in apps via Location Services. But InMobi’s major mistake—misrepresenting the fact that they were collecting location data anyway via Wi-Fi networks—is one that many companies need to pay close attention to. There are many ways that location is collected about mobile devices and describing the options correctly can be difficult, especially if a partner’s practices are not transparent.

As the Future of Privacy Forum staff have explained in filings to the FTC and FCC as well as in a 2015 report on cross-device tracking, there are many ways that consumer devices are tracked. In this summary, we explain what exactly was happening, and how controls over various methods of location sharing are often misunderstood.

InMobi collected location information regardless of the common Location Services permission provided by users

InMobi provides a mobile advertising platform; by partnering with InMobi and integrating their software development kit (SDK), app developers can monetize their apps through targeted advertisements, and advertisers can target consumers via any apps which have integrated InMobi’s SDK.

Much of this advertising is geo-targeted—InMobi gives advertisers the ability to target ads based on the user’s precise location, as well as the patterns of locations of where the user had been over the previous two months. In iOS and Android phones, the operating system requires that an app has to ask your permission before it shares your location via Location Services, so consumers (and app developers) assumed that this geo-targeting was based on opt in consent. And in fact, InMobi told developers that geo-targeted ads were based on opt in consent. So far, so good.

The big problem—and the reason they were just penalized by the FTC—was that prior to December 2015, even when a user had declined to provide their location by selecting “no” in response to the app’s request (or turning it off manually in the phone Settings), InMobi used an alternative method to infer their location via the information collected about the Wi-Fi network to which the user was connected; and/or the Wi-Fi networks in range of the device. By compiling this information into a geo-location database (along with the more detailed information from users who had opted in to Location Services), InMobi could match Wi-Fi networks to specific locations. Despite this practice, the company told developers that geo-targeting was only available if users gave their permission via Location Services, thus opening the door to an injunction and civil penalties from the FTC for deceptive practices.

No Surprise: Many Alternative Methods for Location Targeting Exist

InMobi’s behavior was deceptive because they misrepresented their data collection—that is, they told the public and app developers that geo-targeting required opt-in consent, stating that they would respect users’ choices, and then didn’t respect those choices. However, the use of Wi-Fi itself to infer location is not new, and comes as no surprise. We have explained, in filings to the FTC and FCC, as well as in a report on cross-device tracking, that it is easier than ever to gather location data through smartphones using a variety of methods.

Of the methods by which apps can determine location, users are often most familiar with Location Services, the service controlled by the mobile operating system (OS). This is the primary way apps request location permission, and it’s usually optimal because it aggregates data from different sources—including GPS, cellular triangulation, nearby Wi-Fi signals, and Bluetooth positioning—to pinpoint the device’s location more accurately than any individual system.

But most users are not familiar with the range of other methods that can be used to determine a device’s location. These include cell tower location (cell towers broadcast unique Cell IDs, which are compiled in publicly available databases); carrier triangulation (uniquely, mobile ISPs can analyze signals from multiple surrounding cell towers); Wi-Fi networks (as explained below); beacons (small radio transmitters that broadcast one-way Bluetooth signals to apps that can receive them to infer proximity); and mobile location analytics (passive detection of devices’ Wi-Fi MAC addresses or Bluetooth addresses to determine things like airport or retail traffic).

How does an app determine location through Wi-Fi?

Even without access to Location Services, apps can infer geo-location through the device’s routine scanning for nearby Wi-Fi networks. Large databases exist of the unique identifiers (MAC addresses and SSID) of wireless routers and their known locations, which are continuously updated in a variety of ways, including by the mobile operating system itself (with permission during set-up). An early report in 2014 specifically documented the use by InMobi of this method of using local and previously logged Wi-Fi networks to capture location information.

wifi track

Mobile devices can infer geo-location by scanning for the MAC addresses and SSIDs of nearby publicly broadcasted Wi-Fi access points.

Deception via Misrepresentation to App Developers

It’s particularly interesting to note that in addition to making certain public statements in their own marketing campaigns, InMobi also misrepresented their geo-targeting practices in their statements to app developers. The FTC’s Complaint focuses on the fact that the InMobi SDK integration guides for Android and iOS developers contained inaccurate statements. As a result, the FTC states:

“. . . numerous application developers that have integrated InMobi SDK have represented to consumers in their privacy policies that consumers have the ability to control the collection and use of location information through their applications, including through the device location settings. These application developers had no reason to know that Defendant tracked the consumer’s location and served geo-targeted ads regardless of the consumer’s location settings.” FTC Complaint para. 37 (emphases added).

This focus is especially interesting in light of the fact that most FTC enforcement actions for deceptive business practices focus on misrepresentations in a company’s own privacy policy.

Going Forward

Apps can provide great value to consumers by using location for a wide range of services and geo-targeted ads can often provide useful relevant information. But app developers need to understand and demand transparency from their partners so that they can be accurate and honest with their consumers.

 

 

Read the FTC’s Complaint and Settlement here.

Read FPF’s Cross-Device Tracking report here.

 

For media inquiries, contact:

Melanie Bates

[email protected]