FTC Takes Action against Companies Falsely Claiming Compliance with the EU-U.S. Privacy Shield, Other International Privacy Agreements

The Federal Trade Commission reached a settlement with a background screening company over allegations it falsely claimed to be a participant in the EU-U.S. Privacy Shield program. In separate actions, the FTC also sent warning letters to more than a dozen companies for falsely claiming participation in other international privacy agreements.

In its complaint, the FTC alleges that SecurTest, Inc., falsely claimed on its website that it participated in the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield frameworks, which establish processes to allow companies to transfer consumer data from European Union countries and Switzerland to the United States in compliance with EU and Swiss law, respectively.

While the company initiated a Privacy Shield application in September 2017 with the U.S. Department of Commerce, SecurTest did not complete the steps necessary to be certified as complying with the frameworks. By failing to complete certification, SecurTest was not a certified participant in the frameworks, despite representations to the contrary on its website. The Department of Commerce administers both frameworks, while the FTC enforces the promises companies make when joining those programs.

As part of its proposed settlement with the FTC, SecurTest is prohibited from misrepresenting its participation in any privacy or security program sponsored by a government or self-regulatory or standard-setting organization, including the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield frameworks.

FTC Warns Other Companies

The FTC also sent warning letters to 13 companies that falsely claimed they participate in the U.S.-EU Safe Harbor and the U.S.-Swiss Safe Harbor frameworks, which were replaced in 2016 by the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield frameworks, respectively. These Safe Harbor agreements are no longer in force, and the last valid self-certifications for either agreement have expired.

The FTC called on the 13 companies to remove from their websites, privacy policies, or any other public documents any statements claiming they participate in either Safe Harbor agreement. If the companies fail to take action within 30 days, the FTC warned it would take appropriate legal action.

The FTC also sent warning letters to two companies for claiming in their privacy policies that they are participants in the Asia-Pacific Economic Cooperation (APEC) Cross-Border Privacy Rules (CBPR) system even though they are not certified participants. The APEC CBPR system is an initiative to enhance the protection of consumer data that moves among the APEC member economies through a voluntary but enforceable code of conduct implemented by participating businesses. To become a certified participant, a designated third party, known as an APEC-recognized Accountability Agent, must review and certify that the company is compliant with the CBPR program requirements.

The FTC’s letter instructed the companies to remove from their websites, privacy policies, or any other public documents or statements that might be construed as claiming participation or involvement in the APEC CBPR system unless they prove that they have undergone the requisite review and certification. The FTC warned it would take appropriate legal action if the companies fail to provide a timely and satisfactory response.

The Commission vote to issue the administrative complaint and to accept the proposed consent agreement with SecurTest was 5-0. The FTC will publish a description of the consent agreement package in the Federal Register soon. The agreement will be subject to public comment for 30 days after publication in the Federal Register, after which the Commission will decide whether to make the proposed consent order final. Once processed, comments will be posted on Regulations.gov.

NOTE: The Commission issues an administrative complaint when it has “reason to believe” that the law has been or is being violated, and it appears to the Commission that a proceeding is in the public interest. When the Commission issues a consent order on a final basis, it carries the force of law with respect to future actions. Each violation of such an order may result in a civil penalty of up to $42,530.

The Federal Trade Commission works to promote competition, and protect and educate consumers. You can learn more about consumer topics and file a consumer complaint online or by calling 1-877-FTC-HELP (382-4357). Like the FTC on Facebook, follow us on Twitter, read our blogs, and subscribe to press releases for the latest FTC news and resources.

IR Press

Share
Published by
IR Press

Recent Posts

Acting Comptroller Issues Statement on Notice of Proposed Rulemaking on Incentive Compensation

WASHINGTON—Acting Comptroller of the Currency Michael J. Hsu today issued the following statement supporting an…

14 hours ago

Agencies Issue Proposal on Incentive-Based Compensation

Washington, D.C.— The Federal Deposit Insurance Corporation (FDIC), the Office of the Comptroller of the…

14 hours ago

Remarks by Secretary of the Treasury Janet L. Yellen at East Valley American Job Center in Mesa, Arizona

As Prepared for DeliveryI. IntroductionThank you to everyone for being here. It’s good to be…

3 days ago

Agencies Issue Guide to Assist Community Banks to Develop and Implement Third-Party Risk Management Practices

Federal bank regulatory agencies today released a guide to support community banks in managing risks…

4 days ago

MEDIA ADVISORY: Under Secretary for Terrorism and Financial Intelligence Brian Nelson to Travel to Singapore and Malaysia

WASHINGTON – From May 6th to May 9th, Under Secretary of the Treasury for Terrorism…

4 days ago

Remarks by Secretary of the Treasury Janet L. Yellen on the Economic Case for Democracy

As Prepared for DeliveryI. IntroductionGood afternoon. Thank you to the McCain Institute for the invitation…

4 days ago