Application 2 – Annotated Bibliography
California has enacted extensive legislation in the pri-vacy, security, anti-spam, and anti-spyware areas that effectively molds the national agenda for fighting identi- ty theft, protecting personally identifiable information (especially for direct marketing purposes) and regulating the Internet. This article highlights the most important legislation, primarily focusing on privacy and security statutes that have recently taken effect.
While these new bills apply only to California resi- dents or their personally identifiable information, for the following reasons all businesses, regardless of loca- tion, should take heed:
• Several of the statutes specifically address out-of-state businesses that do business with, or collect or store in- formation from, California residents.
• The borderless nature of the Internet means that many businesses with an online presence will need to com- ply with California’s requirements.
• California is an enormous market with cutting-edge consumer protection laws that already are serving as a model for legislation by other states and the federal government.
• National and multi-regional businesses desiring to cre- ate a comprehensive privacy and security policy may need to conform to the most restrictive state require- ments in the country, which are California’s.
• California law increasingly favors private causes of ac- tion, so a business that unwittingly violates these new requirements could face onerous litigation as well as any enforcement penalty.
SB 1436: Restrictions on Installation of “Spyware” on California Consumers’ Computers
Senate Bill 1436, the Consumer Protection Against Computer Spyware Act, (CPACSA) prohibits the unau-
thorized installation of software on a California con- sumer’s computer. CPACSA also forbids the use of that software to deceptively modify that computer’s settings that may affect the computer’s access to or use of the Internet, including altering the consumer’s homepage, default search page, or bookmarks; sending viruses; or taking control of an infected system as part of a distrib- uted denial-of-service attack. CPACSA also outlaws the collection, “through intentionally deceptive means,” of “personally identifiable information” (such as user names and passwords) through keystroke-logging, tracking Web site visits, or extraction of such informa- tion from a consumer’s hard drive.
Those seeking to install software on a California consumer’s computer must notify the consumer regard- ing what the software will do (for example, if it is a pro- gram that will collect information, the consumer must be told what type of information will be collected and what will be done with the information) and obtain the user’s consent to the installation. Consent can be ob- tained in various ways, including through an on-screen dialogue box advising the consumer that clicking “OK” will install the program.
CPACSA defines a consumer as “an individual who resides in [California] and who uses the computer in question primarily for personal, family or household purposes.” It does not require a software provider to ob- tain consent from every employee of a business when installing information-gathering software on the busi- ness’ computer system or network.
CPACSA also bans software that cannot be uninstalled or disabled or that makes it seem as though the software has been uninstalled or disabled when it has not been. It also prohibits the installation of software that would re- move or render inoperative security, anti-spyware, or anti-virus software on the consumer’s computer.The law allows affected consumers to bring a lawsuit against the offending party and, if successful, recover damages of $1,000 per incident or violation, as well as attorney’s fees.
AB 1950: Security Requirements for Personal Information about a California Resident
Assembly Bill 1950 mandates that owners or licen- sors of unencrypted personal information about
California Privacy and Security Legislation Affects Entire Nation By Barbara L. Delaney, Sharon R. Klein, Charles S. Marion, Dana T. Nguyen, and Tracey S. Pachman
Barbara L. Delaney, Sharon R. Klein, Charles S. Marion, Dana T. Nguyen, and Tracey S. Pachman are attorneys with Pepper Hamilton LLP.
Volume 17 • Number 3 • March 2005 Intellectual Property & Technology Law Journal 21
ipt0503_Final.qxd 3/7/05 3:04 PM Page 21
California residents implement and maintain reasonable security procedures to protect personal information from unauthorized access, destruction, use, modifica- tion, or disclosure.
To the extent that personal information about a California resident is disclosed to a nonaffiliated third party, a contract with such third party must mandate se- curity and protect the personal information from unau- thorized access, destruction, use, modification, or disclosure. “Personal information” is defined as a per- son’s name combined with a Social Security number, driver’s license number, or California identification card number, account number and password, or medical his- tory, treatment, or diagnosis.
This bill supplements other California legislation re- garding notice of breaches of security of personal infor- mation (SB 1386) but does not preempt federal or state legislation protecting personal financial or medical in- formation, such as the California Financial Information Privacy Act, the Confidentiality of Medical Information Act, and the Health Insurance Portability and Accountability Act (HIPAA).
Additionally, the bill excludes entities subject to the confidentiality requirement of the Vehicle Code and any other business regulated by state or federal law pro- viding greater protection to personal information than that provided by this bill.
SB 27: Restrictions on the Disclosure of Personal Information to Direct Marketers
Senate Bill 27 imposes stringent new disclosure and notice requirements on entities that collect and share personal information about their California customers. Informally referred to as the Golden State’s Shine the Light law, SB 27 was drafted to address the growing pri- vacy concerns of California residents and to combat in- creasing incidents of identity theft.
Under the new statute, a business that discloses a California customer’s personal information to a third party for direct marketing purposes must either provide the customer a free opt-out procedure that will prevent sharing of that customer’s information or, upon request, identify the recipients of the information and describe the categories of information disclosed during the pre- vious calendar year.
SB 27 specifically covers business relationships creat- ed over the Internet and through mail order activities, so it does not just affect businesses located in California. Entities outside the state that collect personal informa- tion on California residents using Web sites and other alternative marketing channels and then disclose that information also are subject to the statute’s provisions.
“Personal information” is defined expansively to in- clude a wide range of customer data, including name, address, phone number, email address, physical descrip- tion, products purchased, payment history, and credit- worthiness. Similarly, the definition of “third parties” is far-reaching and includes entity affiliates if the affiliates are separate legal entities.
Fortunately, the statute applies only to situations in which a business knows or reasonably should have known that a third party would use the personal infor- mation disclosed for its own direct marketing purposes. If a business shares customer information with inde- pendent contractors, service providers, or other third parties acting on its behalf, these disclosures do not trig- ger the requirements of the statute, as long as the third parties receiving the information don’t use the infor- mation for their own direct marketing efforts.
A business subject to SB 27’s disclosure requirements must adopt one of two compliance procedures.The first is to provide its California customers with a free method for opting out of its information-sharing prac- tices. In that case, the company must provide notice of a customer’s opt-out rights using one of several speci- fied methods.
In the alternative, an entity must provide, upon cus- tomer request, a detailed disclosure of its information- sharing activities during the previous calendar year.The disclosure need not list the recipients of the particular customer’s information, but it must list the categories of information shared and the names and addresses of the recipients. It also must describe the recipient’s business, if that is not obvious from the recipient’s name.
If a covered business fails to comply with SB 27’s re- quirements, a California customer has a private right of action.The customer may recover actual damages, costs, attorneys’ fees, and a civil penalty of $500 (increased to $3,000 if the court finds that the violation was reckless, willful or intentional).
SB 1633: Restrictions on Obtaining Medical Information for Direct Marketing Purposes
Senate Bill 1633 prohibits obtaining medical infor- mation directly from an individual for marketing pur- poses without providing certain disclosures and obtaining that person’s consent. “Direct marketing pur- poses” means the use of personal information for mar- keting or advertising products, goods, or services but does not include use to effect charitable or political contributions.
Consent may be oral or in writing. Oral requests to use medical information for direct marketing purposes must be accompanied by an oral disclosure of the pur-
22 Intellectual Property & Technology Law Journal Volume 17 • Number 3 • March 2005
ipt0503_Final.qxd 3/7/05 3:04 PM Page 22
Volume 17 • Number 3 • March 2005 Intellectual Property & Technology Law Journal 23
pose to obtain information to market or advertise prod- ucts, goods, or services, and the individual must con- sent.The entire conversation must be recorded and kept for two years.
If consent is in writing, it must be accompanied by a disclosure of the direct marketing purpose in clear and conspicuous manner, and the written consent must per- mit medical information to be used or shared to mar- ket or to advertise products, goods, or services to the individual.
The bill exempts businesses that are already subject to the Confidentiality of Medical Information Act, cer- tain telephone companies, and insurance companies.
AB 68: California Online Privacy Protection Act of 2003
Assembly Bill 68, or the Online Privacy Protection Act of 2003 (OPPA), imposes requirements for the content and placement of privacy policies on Web sites or online services if they collect the personally identifi- able information of consumers residing in California. Web site operators, wherever located, that collect per- sonally identifiable information about individual con- sumers who reside in California via the Internet for commercial purposes must conspicuously post on their Web sites a privacy policy that meets the requirements of OPPA.
OPPA requires that such privacy policies describe:
1. The categories of personally identifiable information collected about individual consumers;
2. The categories of third parties (individuals or entities) with whom the personally identifiable information may be shared;
3. How an individual may review and request changes to his or her personally identifiable information;
4. How consumers using or visiting a Web site or online service will be notified of material changes to the pri- vacy policy; and
5. The effective date of the privacy policy.
Be cautious in how you address each of these ele- ments in your privacy policies, as you could face civil suits for unfair business practices under OPPA, as well as deceptive or unfair trade practices charges by the Federal Trade Commission, if you fail to comply with your posted privacy policies.
OPPA describes several ways to “conspicuously post” a privacy policy:
• Post an icon on your Web site’s homepage or first sig- nificant page that contains the word “Privacy” and is a contrasting color from your Web page or is otherwise distinguishable, and is linked to your privacy policy.
• Post a text link to your privacy policy on your home- page that contains the word “Privacy” and is written in capital letters or in contrasting type, size, font, or color.
• Use any other hyperlink to the privacy policy that is displayed so “that a reasonable person would notice it.”
• Post the entire text of the privacy policy on your homepage.
Based on these guidelines, the common practice of placing a miniscule text link at the bottom of a long scrolling homepage is likely insufficient to meet the OPPA standards.
SB 1457: Unlawful Commercial Email Advertisements
California’s original CAN-SPAM legislation was preempted by the federal CAN-SPAM Act of 2003. Undeterred, California passed subsequent legislation in September 2004 to add teeth to the SPAM legislation by re-introducing private cause of action and damages provisions, which California had in its original legisla- tion.
Under California law, the attorney general, electron- ic mail service provider, or recipient of unsolicited commercial email advertisements may sue for SPAM violations. Sanctions of $1,000 for each unlawful adver- tisement transmitted, not to exceed $1 million per inci- dent, are available as damages for such SPAM violations; however, if sound practices and procedures were imple- mented, such sanctions would be reduced to $100 per unlawful transmission not to exceed $100,000 per inci- dent. Prevailing party attorneys’ fees also are allowed.
AB 2840: Electronic Surveillance Technology in Rented Vehicles
Don’t mess with Californians and their cars! That is the message sent when California signed into
law in August 2004 legislation prohibiting vehicle rent- ing companies from using, accessing, or obtaining in- formation obtained through technological means relating to the renter’s use of the vehicle.
This bill was prompted by rental companies fining customers thousands of dollars if the GPS system tracked that a rental car was used outside a designated driving area. Information on a renter’s use of the car by electronic surveillance technology is prohibited except
ipt0503_Final.qxd 3/7/05 3:04 PM Page 23
to locate a stolen, abandoned, or missing car after the rental agency has notified law enforcement or one week after the contracted return date.
Additionally, electronic technology can be used for such things as remote locking/unlocking of a car, to provide roadside assistance, to calculate the total mileage and fuel consumption, as long as the informa- tion collected by the technology is not used for other purposes. No fines or surcharges may be imposed based on tracking technology. The renter may file a private cause of action and prevailing party attorneys’ fees are allowed.
AB 1733: Cell Phone Numbers Protection Act
Assembly Bill 1733 allows cell phone owners to pro- tect their privacy and the confidentiality of their cell phone numbers and gives them control over whether their cell phone number gets published in a directory and sold to telemarketers.
Cell phone companies are now required to get sep- arate written permission from users before adding their cell phone numbers to a directory or directory data- base. Because cell phone users pay for all incoming calls, either on a per-minute basis or a fixed rate, this legisla- tion aims to prevent telemarketers from forcing un- wanted sales pitches and text message spam into users’ cell phones.
Most cell phone companies already have included in their standard contracts a specific clause that gives them the right to publish numbers. For example, T-Mobile’s service contract reads:“Unless you make other arrange- ments with us and pay any required fee, we may list your name, address, and number in a public directory.” With this new law, cell phone companies are required to get separate written consent to include subscribers’ numbers in a directory.
SB 1618: Social Security Numbers on Paychecks
Effective January 1, 2008, California Senate Bill 1618 gives employers the option of showing only the last four digits of the employee’s Social Security number on wage statements or an existing employee identification number that is other than the employee’s Social Security number.
Existing law in California requires that the employ- ee’s name and social security number be printed on each pay stub provided to employees at the time that wages are paid. Because the amended legislation states that “by January 1, 2008 only the last four digits of his or her social security number . . . may be shown on the check,” it is ambiguous whether an employer who makes this change now will be considered in violation of the current law. Although it may be safer practice to continue displaying the employee’s entire social securi- ty number until January 1, 2008, employers should begin considering the logistics (e.g., timing, cost, com- plexity) involved in implementing such changes by January 1, 2008.
What Companies Should Do If a company transacts business with California resi-
dents, it should implement the following steps to com- ply with the new laws and avoid potential liability:
• Increase understanding of these new requirements;
• Immediately revise policies and procedures, for online and offline business, as needed;
• Provide seminars to train employees on new policies and procedures;
• Update contracts, including information-sharing agreements;
• Update employee handbooks;
• Educate customers on the new requirements; and
• Consult with an attorney to ensure compliance.
Businesses failing to comply could face monetary sanctions, private causes of action, and damage to busi- ness reputation.
Even if a business does not transact business in California, it should consider implementing company- wide policies that comply with California law. Compliance with those more stringent standards should make it unnecessary to adopt multiple policies to meet the varying requirements of different jurisdictions.
24 Intellectual Property & Technology Law Journal Volume 17 • Number 3 • March 2005
ipt0503_Final.qxd 3/7/05 3:04 PM Page 24