January 28, Re: Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework Comment, Docket No.
|
|
|
- Basil Watts
- 10 years ago
- Views:
Transcription
1 475 Anton Boulevard Costa Mesa, CA January 28, 2011 Via National Telecommunications and Information Administration U.S. Department of Commerce 1401 Constitution Avenue, NW, Room 4725 Washington, DC Re: Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework Comment, Docket No Dear Internet Policy Task Force: Experian appreciates this opportunity to provide comments on the Department of Commerce Internet Policy Task Force s ( Department ) report titled Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework ( Commerce Report ). 1 As steward of some of the leading consumer information databases all of which are regulated by federal and state law and industry self-regulatory standards Experian has unique insight into how third-party data is collected, and how it is used by commercial, non-profit, and government entities. In addition, Experian also provides many services directly to consumers, including leading products to help provide consumer financial literacy and education directly to millions of Americans. We believe robust industry self-regulation coupled with existing sectoral privacy laws and enforcement of unfair and deceptive trade practices continues to be the most effective way to balance consumer privacy interests with business ingenuity. Experian is committed to ensuring that a self-regulatory framework succeeds that fosters consumer trust, spurs innovation, and secures consumer data. We urge the Department to support the self-regulatory initiatives that are currently underway and to encourage businesses to participate in such efforts. I. Background on Experian Products and Services. Experian is a leading global information services company, providing analytical and marketing services to organizations and consumers to help manage the risk and reward of commercial and financial decisions. Experian is well known in the United States as one of the three national crediting reporting agencies, but credit reporting is only one aspect of our business. For more than fifty years, Experian has compiled consumer data and used the information to help facilitate direct marketing, primarily through the U.S. Mail. Over these years, there have been many changes in technology and the manner in which organizations 1 Department of Commerce Internet Policy Task Force, Commercial Data Privacy and Innovation in the Internet Economy: A Dynamic Policy Framework (December 2010) (hereinafter Commerce Report ).
2 communicate and advertise to their current and prospective members or customers. Experian uses its compiled databases to facilitate multi-channel marketing and advertising through the mail, telephone, and . The emergence of Experian s Digital Advertising Services brings the same compiled marketing information and direct marketing principles to television, online, and mobile advertising. Experian serves large and small corporations and non-profit organizations around the world, and in doing so, has adopted five global information values that guide our use of marketing data. These values balance, accuracy, security, integrity, and communication align with the Fair Information Practice and Principles ( FIPPs ) embraced by the Department, the Organization for Economic Cooperation & Development, the European Union, and the Asia- Pacific Economic Corridor. These information values form the foundation of our belief that information use must benefit both businesses and individuals, while simultaneously meeting the privacy expectations of consumers. Because Experian has operations in 90 countries, we must apply these information values according to the laws, customs, and consumer expectations of the nations and regions in which it operates and/or serves customers. In turn, information policies, built upon our values, more specifically define how information may be used. For example, our privacy and compliance team works closely with Experian s business units to perform a proactive risk assessment prior to all data sourcing and product development launches. This self-regulatory audit incorporates subject matter experts from every relevant functional area of the company, including product development, technology, legal, compliance, information security, risk management, and data acquisition. In addition, Experian has demonstrated a commitment to providing consumers notice, choice, and education about the use of personal information through our collateral materials and information available on each of our public-facing websites. We also allow consumers to easily exercise choice with respect to the use of their personal information and provide our clients with the ability to utilize available suppression files. II. Third-Party Sharing of Data Provides Significant Benefits to Consumers and Businesses. The collection and sharing of third-party consumer data, which is at the heart of Experian s consumer databases, provides numerous significant benefits to consumers and businesses. Our market research and analysis services help businesses identify the common characteristics of their customers, which allows them to plan better media campaigns, determine the best retail or branch site locations, develop new product offerings, tailor their editorial content, and ensure adequate product inventory. The result is lower prices, enhanced competition, and increased consumer convenience. Third-party data also facilitates the relevancy of first-party marketing efforts, especially for small businesses and start-ups, which rely heavily on marketing to prospective customers. Even large first-party marketers with extensive customer databases depend on third-party data to provide better services and relevant marketing offers to existing customers. Marketers cannot rely solely on their own transactional and experience data to effectively make offers that are 2
3 tailored to specific individual or household preferences. This reduces the total number of advertising impressions that are produced, thus reducing the delivery of irrelevant advertising, which benefits consumers. We further believe that the U.S. approach for protecting personal data built on strong sectoral laws and voluntary enforceable codes of conduct that have been in place for decades is instrumental to the success and growth of the U.S. economy. The exchange of information among affiliated organizations, third parties, and consumers fuels innovation and product development, which in turn drives the United States economy. Breakthroughs in information technology that enable, for example, the ubiquity of social networking and e-commerce, simply would not have been possible without the collection and sharing of data. The existing approach to data security and consumer privacy is key to ensuring U.S. businesses continue to lead the world in the development of cutting-edge and transformative products and services. Because of this, and as addressed further below, Experian would urge the Department to present and support the existing U.S. framework as the best model for other nations to adopt in any effort to reach a global, harmonized regime. Any privacy framework should carefully balance restrictions on the collection and sharing of third-party information with the significant benefits that these uses of information provide to consumers, businesses, and the economy at large. Unlike static laws and regulatory regimes that cannot keep pace with rapidly developing technologies, we believe that selfregulatory systems are inherently adaptive and thus best suited to respond to new, emerging technologies and consumer needs while maintaining the competitive edge of the United States in the global economy. III. A FIPPs-Based Framework Could Serve as a Useful Tool for Companies to Evaluate Their Practices, But Not as a Legislative or Regulatory Framework. The Department has recommended the development of a full set of FIPPs as a foundation for commercial data privacy policy enacted either by industry, the Executive Branch, or Congress. While Experian believes that a FIPPs-based framework could be used by companies to evaluate their privacy and data security practices at various stages of the development of their products and services, we do not believe a new legal regime governing consumer privacy is needed. Ultimately, consumers are adequately protected by the existing system of U.S. sectoral laws (federal and state), multiple regulations promulgated and enforced there under, robust yet flexible self-regulatory codes of conduct, and strong enforcement by the Federal Trade Commission of unfair and deceptive trade practices. There is therefore not a demonstrated need for nor any evidence supplied by the Department in its report to justify adopting new legal requirements to protect consumer privacy given the established multi-layered system our nation has developed over the past forty years. Financial and health information is already afforded substantial privacy protections under existing laws, including the Fair Credit Reporting Act, the Fair Debt Collection Practices Act, the Fair Billing Act, the Health Insurance Portability and Accountability Act, and the Wall Street Reform and Consumer Protection Act. Similarly, data related to children is subject to strong legal protections under the Children s Online Privacy Protection Act. Moreover, data collected 3
4 for marketing purposes has been effectively regulated by standards promulgated by industry groups, such as the Direct Marketing Association ( DMA ), for over forty years. Second, the codification of a FIPPs-based framework through legislation or governmentdriven regulation that broadly applied to all data practices would inevitably produce a set of inflexible top-down prescriptions. This outcome would unnecessarily hamper the business community s ability to drive innovation and address rapidly evolving consumer preferences. We agree with the Department that a comprehensive baseline set of FIPPs must maintain the flexibility for each industry sector to develop tailored implementation plans and allow companies to direct resources to the principles that matter most for protecting privacy in a particular context in order to succeed. 2 However, we do not believe any government law or regulation, however carefully drafted, could retain those principles and simultaneously provide meaningful, enforceable guidance over time given the ever-developing and highly dynamic nature of business operations in the information age. Experian strongly believes self-regulation is the most effective way to regulate commercial data used for marketing purposes. Such self-regulatory codes of conduct are most effective when developed by the businesses to which the standards would apply, and not by government agencies or other groups. For over forty years, industry has taken the lead in developing and enforcing responsible codes of conduct. The guidelines and standards of the DMA, for example, provide individuals and organizations involved in direct marketing with a comprehensive set of principles that cover all marketing practices, including the collection, use, and maintenance of marketing data. 3 To enforce these guidelines, the DMA has established a committee which examines promotions and practices of members and nonmembers that may violate DMA s guidelines. The committee successfully works with individuals and companies to gain voluntary cooperation in adhering to the guidelines and to adopt good business practices for direct marketers. The DMA Guidelines for Ethical Business Practice have been applied to hundreds of direct marketing cases concerning deception, unfair business practices, personal information protection, and other ethics issues. In the last two years, the business community has demonstrated its deep commitment to effective self-regulation online. In July 2009, a coalition of industry organizations released the Self-Regulatory Principles for Online Behavioral Advertising ( Principles ) and then launched a self-regulatory program covering these practices in early fall These successful initiatives, which serve as models for further self-regulatory efforts, are a testament to the industry s dedication to the principles of self-regulation and its ability to deliver. We agree with the Department that the federal government has a significant role to play in harmonizing data security standards across state lines and international borders. That is why we support the adoption of a national standard for security breach notification that applies only to data that constitutes sensitive personally identifiable information. By simplifying business 2 Commerce Report at Direct Marketing Association, Guidelines for Ethical Business Practice (revised January 2010), available at, 4 American Association of Advertising Agencies, Association of National Advertisers, Direct Marketing Association, Interactive Advertising Bureau, and Council of Better Business Bureaus, Self-Regulatory Principles for Online Behavioral Advertising (July 2009), available at, 4
5 compliance processes and reducing costs, the adoption of a single, preemptive standard would increase and strengthen compliance. IV. The Department Should Facilitate the Development of Global Interoperability and Harmony of Data Security Standards Across Countries. Experian operates in more than 90 countries around the world and thus faces the challenges caused by the multiplicity of foreign data protection rules and regulations on a daily basis. We support the Department s call for the U.S. government to increase its efforts to develop a framework for mutual recognition of international data security standards. We do not, however, believe that the goal of such a framework should be a one-size-fits-all universal privacy standard. A country s cultural norms define the level and type of privacy rights expected by its citizens. A global standard of privacy detached from U.S. privacy norms and consumer preferences should not be imposed on American consumers. We instead urge the Department to advocate for a global framework that that recognizes each country s unique approach to privacy. While we believe privacy standards are local, information security should be global. Entities that maintain personal data should meet international standards of data security. Data should be able to be processed anywhere in the world, so long as appropriate data security standards are in place and the use of such data does not violate the privacy laws of the country in which the consumer resides. Better reconciliation of global security standards, coupled with adherence to country-specific privacy rights, would quell concerns about international transfers of information or the use of cloud computing. As such, we encourage the Department to lead international efforts to develop a framework that harmonizes data security standards across countries. * * * Experian thanks you for the opportunity to engage in dialogue with the Commission on these important matters. Should you have any questions, please do not hesitate to contact me at (202) Sincerely, Tony Hadley Senior Vice President Government Affairs 5
The DMA Guidelines for Ethical Self-Regulation
Before the NATIONAL TELECOMMUNICATIONS AND INFORMATION ADMINISTRATION, U.S. DEPARTMENT OF COMMERCE Washington, DC 20230 COMMENTS of the DIRECT MARKETING ASSOCIATION, INC. on the Multistakeholder Process
PRIVACY & DATA PROTECTION ANNUAL REPORT
2012 2013 PRIVACY & DATA PROTECTION ANNUAL REPORT CONTENTS 2 Leading the Way 4 A Strong Privacy Advocate 7 Protecting Our Customers 16 The Mobile Revolution PREFACE by Dr. Larry Ponemon Chairman & Founder,
Privacy and Data Protection
Hewlett-Packard Company 3000 Hanover Street Palo Alto, CA 94304 hp.com HP Policy Position Privacy and Data Protection Current Global State of Privacy and Data Protection The rapid expansion and pervasiveness
WRITTEN TESTIMONY OF JENNIFER BARRETT-GLASGOW GLOBAL PRIVACY OFFICER ACXIOM CORPORATION
WRITTEN TESTIMONY OF JENNIFER BARRETT-GLASGOW GLOBAL PRIVACY OFFICER ACXIOM CORPORATION BEFORE THE UNITED STATES HOUSE COMMITTEE ON ENERGY AND COMMERCE SUBCOMMITTEE ON COMMERCE, MANUFACTURING AND TRADE
Re: Big Data Request for Information
March 31, 2014 Attn: Big Data Study Office of Science and Technology Policy Eisenhower Executive Office Building 1650 Pennsylvania Avenue NW Washington, D.C. 20502 Ladies and Gentlemen: Re: Big Data Request
ICC RESOURCE GUIDE FOR SELF-REGULATION OF ONLINE BEHAVIOURAL ADVERTISING (OBA)
ICC RESOURCE GUIDE FOR SELF-REGULATION OF ONLINE BEHAVIOURAL ADVERTISING (OBA) Highlights Explanation of global framework available for OBA self-regulation Checklist from existing OBA self-regulatory mechanisms
Re: Big Data: A Tool for Inclusion or Exclusion? Workshop Project No. P145406
October 30, 2014 Federal Trade Commission Office of the Secretary Room H 113 (Annex X) 600 Pennsylvania Avenue NW Washington, DC 20580 Re: Big Data: A Tool for Inclusion or Exclusion? Workshop Project
RE: ITI Comments on Korea s Proposed Bill for the Development of Cloud Computing and Protection of Users
August 19, 2012 Korean Communications Commission Via e-mail to: [email protected] RE: ITI Comments on Korea s Proposed Bill for the Development of Cloud Computing and Protection of Users Dear Director Yang:
RE: Study Regarding Obligations of Brokers, Dealers, and Investment Advisers, File No. 4-606, 75 Federal Register 44996 (July 30, 2010).
Sarah A. Miller Senior Vice President Center for Securities, Trust and Investments 202-663-5325 [email protected] By electronic delivery August 30, 2010 Ms. Elizabeth Murphy Secretary Securities and Exchange
S7 08 11 / Clearing Agency Standards for Operation and Governance (the Clearing Agency Proposed Rule ) 1
Ms. Elizabeth Murphy Secretary Securities and Exchange Commission 100 F Street NE Washington, DC 20549 Re: S7 08 11 / Clearing Agency Standards for Operation and Governance (the Clearing Agency Proposed
How To Respond To The Nti'S Request For Comment On Big Data And Privacy
Submission to the National Telecommunications and Information Administration (NTIA), U.S. Department of Commerce Docket No. 140514424 4424 01 RIN 0660 XC010 Comments of the Information Technology Industry
U.S. DEPARTMENT OF COMMERCE
U.S. DEPARTMENT OF COMMERCE National Telecommunications and Information Administration --------------------------------------------------------------------------------- Information Privacy and Innovation
Re: Request for Comment: Big Data and Consumer Privacy in the Internet Economy
Microsoft Corporation Tel 425 882 8080 One Microsoft Way Fax 425 936 7329 Redmond, WA 98052-6399 http://www.microsoft.com/ August 5, 2014 Mr. John Morris National Telecommunications and Information Administration
AN INTRODUCTION TO THE EU DIRECTIVE ON THE PROTECTION OF PERSONAL DATA
AN INTRODUCTION TO THE EU DIRECTIVE ON THE PROTECTION OF PERSONAL DATA By Peter K. Yu Introduction The Internet and new communications technologies have made shopping more convenient than ever. Online
(U) Appendix E: Case for Developing an International Cybersecurity Policy Framework
(U) Appendix E: Case for Developing an International Cybersecurity Policy Framework (U//FOUO) The United States lacks a comprehensive strategic international policy framework and coordinated engagement
Guide to Internal Control Over Financial Reporting
Guide to Internal Control Over Financial Reporting The Center for Audit Quality prepared this Guide to provide an overview for the general public of internal control over financial reporting ( ICFR ).
DATES: Comments must be submitted on or before [INSERT DATE 60 DAYS AFTER PUBLICATION IN THE FEDERAL REGISTER].
This document is scheduled to be published in the Federal Register on 06/23/2015 and available online at http://federalregister.gov/a/2015-15412, and on FDsys.gov FEDERAL RESERVE SYSTEM Proposed Agency
Docket No. R-14 19, RIN 7100-AD76 Electronic Fund Transfers
MasterCard Worldwide Law Department 2000 Purchase Street Purchase,NY 1 0 5 7 7-2 5 0 9 tel 1-9 1 4-2 4 9-2000 www.mastercard.com July 22, 2011 By E-mail: [email protected] Jennifer J. Johnson
FEDERAL-POSTAL COALITION
FEDERAL-POSTAL COALITION September 15, 2011 The Honorable Barack Obama President of the United States The White House 1600 Pennsylvania Avenue, NW Washington, DC 20500 Dear Mr. President: On behalf of
Unlocking the opportunity with Decision Analytics
Unlocking the opportunity with Decision Analytics Not so long ago, most companies could be successful by simply focusing on fundamentals: building a loyal customer base through superior products and services.
Accountability: Data Governance for the Evolving Digital Marketplace 1
Accountability: Data Governance for the Evolving Digital Marketplace 1 1 For the past three years, the Centre for Information Policy Leadership at Hunton & Williams LLP has served as secretariat for the
Jan Philipp Albrecht Rapporteur, Committee on Civil Liberties, Justice and Home Affairs European Parliament
September 5, 2012 Jan Philipp Albrecht Rapporteur, Committee on Civil Liberties, Justice and Home Affairs European Parliament Lara Comi Rapporteur, Committee on Internal market and Consumer Protection
Importance of the Consumer Financial Protection Bureau
Importance of the Consumer Financial Protection Bureau The aftermath of the financial crisis affected millions of Americans. The U.S. economy was devastated as companies crumbled, homeowners lost their
Office of Inspector General Evaluation of the Consumer Financial Protection Bureau s Consumer Response Unit
Office of Inspector General Evaluation of the Consumer Financial Protection Bureau s Consumer Response Unit Consumer Financial Protection Bureau September 2012 September 28, 2012 MEMORANDUM TO: FROM: SUBJECT:
UNFAIR, DECEPTIVE, OR ABUSIVE ACTS OR PRACTICES (UDAAP)
UNFAIR, DECEPTIVE, OR ABUSIVE ACTS OR PRACTICES (UDAAP) EXAMINATION PROCEDURES Examination Objectives To assess the quality of the credit union s compliance risk management systems, including internal
EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update. By Stephen H. LaCount, Esq.
EU Data Protection Directive and U.S. Safe Harbor Framework: An Employer Update By Stephen H. LaCount, Esq. Overview The European Union Data Protection Directive 95/46/EC ( Directive ) went effective in
A Best Practice Guide
A Best Practice Guide Contents Introduction [2] The Benefits of Implementing a Privacy Management Programme [3] Developing a Comprehensive Privacy Management Programme [3] Part A Baseline Fundamentals
VIA OVERNIGHT MAIL, FACSIMILE TRANSMISSION: (2 0 2) 4 5 2-3 8 1 9 & E-MAIL: [email protected]
WEINER BRODSKY SIDMAN KIDER PC 1 3 0 0 19th Street N W 5th Floor Washington DC 2 0 0 3 6-1 6 0 9 office: 2 0 2 6 2 8 2 0 0 0 facsimile: 2 0 2 6 2 8 2 0 1 1 www.wbsk.com July 19, 2011 VIA OVERNIGHT MAIL,
ANA believes a number of points deserve emphasis at the outset:
March 31, 2014 Big Data Study Office of Science and Technology Policy Eisenhower Executive Office Building 1650 Pennsylvania Avenue, NW Washington, DC 20502 SUBJECT: Request for Information on Big Data
SUMMARY OF THE CFPB NOTICE
COMMENTS OF THE TAX PROBLEM RESOLUTION SERVICES COALITION TO THE BUREAU OF CONSUMER FINANCIAL PROTECTION IN CONSIDERATION OF DOCKET NUMBER CFPB-HQ-2011-2 FOR DEFINING LARGER PARTICIPANTS IN CERTAIN CONSUMER
Subject: Category Management Policy 16-1: Improving the Acquisition and Management of Common Information Technology: Software Licensing
January 21, 2016 Anne E. Rung Administrator, Office of Federal Procurement Policy Office of Management and Budget 725 17 th Street, NW Washington, DC 20503 Tony Scott Administrator and Federal CIO Office
We will not collect, use or disclose your personal information without your consent, except where required or permitted by law.
HSBC Privacy Notice HSBC's Privacy Principles HSBC Bank Canada is a subsidiary of HSBC Holdings plc which, together with its subsidiaries and affiliates, is one of the world s largest banking and financial
ConsumerViewSM. Insight on more than 235 million consumers and 113 million households to improve your marketing campaigns
ConsumerViewSM Insight on more than 235 million consumers and 113 million households to improve your marketing campaigns Learn how Experian s ConsumerView SM database enables better segmentation for brands
COMMISSION AUTHORIZED
V900033 UNITED STATES OF AMERICA FEDERAL TRADE COMMISSION WASHINGTON. D.C. 20S80 COMMISSION AUTHORIZED April 17, 1990 Bruce Hamilton Executive Director State Bar of Arizona 363 North First Avenue Phoenix,
Initial All Disclosures listed under the Client Obligations & Agreement on page 6 of the Client Retainer and Service Agreement;
WELCOME TO THE CREDIT PROS!! Enclosed you will find the Client Retainer and Service Agreement for your services with The Credit Pros. I have begun setting up your file and I am excited to see you on your
Re: Notice and Request for Comments - Determinations of Foreign Exchange Swaps and Forwards (75 Fed. Reg. 66829)
ISDA International Swaps and Derivatives Association, Inc. 360 Madison Avenue, 16th Floor New York, NY 10017 United States of America Telephone: 1 (212) 901-6000 Facsimile: 1 (212) 901-6001 email: [email protected]
Organisation de Coopération et de Développement Economiques Organisation for Economic Co-operation and Development
Organisation de Coopération et de Développement Economiques Organisation for Economic Co-operation and Development RECOMMENDATION OF THE OECD COUNCIL CONCERNING GUIDELINES FOR CONSUMER PROTECTION IN THE
The Sharing Economy: Issues Facing Platforms, Participants, and Regulators A Federal Trade Commission Workshop
The Sharing Economy: Issues Facing Platforms, Participants, and Regulators A Federal Trade Commission Workshop The Federal Trade Commission ( Commission or FTC ) will hold a workshop to explore issues
May 17, 2011. Comment on Proposed Interpretive Order, Antidisruptive Practices Authority ; 76 Fed. Reg. 14943 (March 18, 2011)
Mr. David A. Stawick Secretary U.S. Commodity Futures Trading Commission Three Lafayette Centre 1155 21 st Street, NW Washington, DC 20581 Via agency website May 17, 2011 Re: Comment on Proposed Interpretive
A FRAMEWORK FOR PROTECTING ENFORCEMENT IN THE GLOBAL DIGITAL ECONOMY
2011 CONSUMER U.S. INTELLECTUAL DATA PRIVACY PROPERTY ENFORCEMENT IN A NETWORKED COORDINATOR WORLD: COVER ANNUAL TITLE REPORT HERE ON A FRAMEWORK FOR PROTECTING PRIVACY INTELLECTUAL AND PROMOTING PROPERTY
RE: RIN 2900 AO65 Loan Guaranty: Ability-to-Repay Standards and Qualified Mortgage Definition under the Truth in Lending Act
June 9, 2014 Mr. John Bell Assistant Director for Loan Policy and Valuation Veterans Benefits Administration, Department of Veterans Affairs 810 Vermont Avenue, NW Washington, DC 20420 RE: RIN 2900 AO65
Re: FINRA Regulatory Notice 13-42: FINRA Requests Comments on a Concept Proposal to Develop the Comprehensive Automated Risk Data System
Ms. Marcia E. Asquith Office of the Corporate Secretary FINRA 1735 K Street, NW Washington, DC 20006 Re: FINRA Regulatory Notice 13-42: FINRA Requests Comments on a Concept Proposal to Develop the Comprehensive
Case 3:14-cv-00675-H-JMA Document 1 Filed 03/24/14 Page 1 of 11. UNITED STATES DISTRICT COURT SOUTHERN DISTRICT OF CALIFORNIA Case No.
Case :-cv-00-h-jma Document Filed 0// Page of 0 ERIC H. HOLDER, JR. Attorney General STEWART F. DELERY Assistant Attorney General Civil Division MAAME EWUSI-MENSAH FRIMPONG Deputy Assistant Attorney General
