Jose Felgueroso
Abogado | Attorney

  • Home
  • Blog


Summary of Two Recent Agreements of the United States Federal Trade Commission Regarding Privacy Policies

info@josefelgueroso.com

Versión en español

2021-05-18

In two recent agreements, the United States Federal Trade Commission settled complaints it had brought against two companies for misleading users and violating their own privacy policies. Flo Health is the developer of an app to track menstrual cycles and fertility, and the Commission alleged it had misled its users by sharing health information with third parties after promising it would not do so. Everalbum is the developer of a photo storage app, and the Commission alleged it had misled its users about its use of facial recognition technology and the deletion of data of users who deactivated their accounts.


Source: Mike MacKenzie

The Commission's Authority on Data Privacy

The Commission is the main federal enforcer of consumer protection laws. Under the Federal Trade Commission Act, it can investigate companies, bring actions against them, and order remedial actions if they engage in unfair and deceptive practices. The Commission can also impose civil penalties.

An act is unfair if it is likely to cause substantial injury to consumers who cannot reasonably avoid it, and the act is not outweighed by benefits to consumers or to competition. A deceptive act involves a material representation, omission or practice that is likely to mislead a reasonable consumer.

Since the 1990s, the Commission has taken hundreds of enforcement actions, creating precedents on privacy and security practices. It has used its authority to order companies to comply with their own privacy policies.

Flo Health

Facts

Flo Health developed a menstruation- and fertility-tracking app that has more than 100 million users, including more than 16 million in the United States and more than 19 million in the European Union. Users gave the Flo app detailed information about their menstruations and gynecological health with the expectation that the app would predict ovulation and aid during pregnancy. Although Flo Health stated in its privacy policies that it would not share health information with anyone, beginning in 2016 it shared users' health information with third parties, including Facebook and Google.

The Commission's complaint charged Flo Health with misrepresentations about the disclosure of health information and the company's compliance with the EU-US Privacy Shield framework.

Disclosure Misrepresentations

The Commission alleged that Flo Health communicated to its users it would not disclose to any third parties information related to menstrual cycles, pregnancy, symptoms, or notes in the application. In addition, the Commission alleged that Flo Health indicated to its users that it would only disclose device identifiers and similar data to specific third parties that would help Flo Health operate the app.

Many users entered their health information into the Flo app because they believed the company would treat it in accordance with its privacy policies.

The Commission alleged that Flo Health disclosed to various marketing and analytics firms records of users' interactions with the app that revealed information about the users' menstrual cycles, fertility, and pregnancies. The Commission also alleged that the information that Flo Health provided to the third parties that helped it operate the app went beyond device identifiers: it also disclosed app records that contained users' health information. For example, Flo Health provided these third parties app records that contained descriptive titles, such as P_ACCEPT_PUSHES_PERIOD and R_PREGNANCY_WEEK_CHOSEN.

Although Flo Health's privacy policies indicated it would restrict how third parties used users' personal data, Flo Health did not limit what these third parties could do with that information. As a result, they could use it for any purposes, including advertising and their own research.

Compliance Misrepresentations

The Commission alleged that Flo Health's privacy policies indicated it participated in the EU-US Privacy Shield Agreement and the US-Swiss Privacy Shield framework. Under this framework, a company must certify to the United States Department of Commerce it complies with requirements that meet the European Union's data privacy standards. In particular, a company participating in that framework must:

  • provide in clear and conspicuous language notice to individuals about the parties to which it discloses personal information and the purposes for doing so;
  • offer individuals the opportunity to choose whether their personal information is used for a purpose other than the one for which it was collected;
  • obtain from individuals affirmative express consent for disclosures of sensitive information, such as medical or health information;
  • transfer data to third parties only for limited and specified purposes;
  • ensure that any third parties that receive the personal data provide at least the same level of privacy protection; and
  • not process personal information in a manner incompatible with the purposes for which it was collected.

The Commission alleged that Flo Health:

  • failed to provide its users clear and conspicuous information about the purposes for which it disclosed health data to third parties, or that these third parties could use the health data for their own purposes;
  • failed to offer its app's users the opportunity to opt out of their health information being used by third parties for advertising or other purposes;
  • failed to obtain affirmative express consent for disclosures of health information to third parties;
  • did not transfer user data for limited and specified purposes, because the contracts between Flo Health and the third parties allowed use of the data for wide-ranging purposes;
  • failed to ensure that the third parties provide at least the same level of protection as the Privacy Shield framework; and
  • processed users' health information in a manner incompatible with the original purposes, because the contracts between Health Flo and those third parties authorized the latter to use the data for advertising and other purposes.

Remedial Measures

The agreement between Flo Health and the Commission prohibits the company from making false or deceptive statements about (1) the purposes for which Flo Health or any entity to which it discloses information collects or uses that information, (2) users' ability to control the health information they provide to the Flo app, (3) Flo Health's compliance with any privacy or security program, and (4) Flo Health's protection of users' personal information.

In addition, the agreement requires Flo Health to obtain a compliance review from an outside entity and to maintain certain records. The agreement will remain in effect for 20 years.

Everalbum

Facts

Everalbum operates Ever, an application for photo storage and organization available in mobile, web, and desktop formats. Users can upload photos and videos to Ever's servers.

In 2017, Everalbum launched a new feature called "Friends," which uses facial recognition to organize photos by the faces of the people who appear in them. Initially, this feature was enabled by default.

The Commission alleged that Everalbum used images it extracted from users' photos to develop its facial recognition technology. In addition, the Commission alleged that Everalbum did not delete the content of users who deactivated their accounts, contrary to what it had communicated to its users. In the Commission's view, the company misrepresented its practices, thus engaging in unfair and deceptive conduct.

Facial Recognition

An article posted on Everalbum's website in 2018 indicated that the company's facial recognition technology analyzed users' photos and videos to create a string of numbers it called "face embeddings." The Commission alleged that Everalbum combined facial images it extracted from its users' photos with publicly available datasets to create new datasets to develop its facial recognition technology. The Commission also alleged that Everalbum used this technology both in its app and to develop facial recognition services. These services were offered by the company's enterprise brand, which used it for purposes including security, access control, and facilitating payments.

Starting in May 2018, Everalbum disabled by default the Friends feature for users in jurisdictions with strict data privacy laws: Texas, Illinois, Washington, and the European Union. Users in these jurisdictions received a pop-up message asking whether they wanted the application to use facial recognition.

On the other hand, the settings for users in other jurisdictions were different. The Commission alleged that until 2019, Ever enabled facial recognition by default for users in most geographic locations, and users could not turn it off. This contradicted a help article from Ever that indicated that the Friends feature would not be active unless users enabled it.

Data Deletion

Ever users who sought to deactivate their accounts received a pop-up message indicating this would result in the deletion of their content, and the company's privacy policy included similar statements. The Commission alleged that until October 2019, Everalbum did not in fact delete the videos and photos of any users who had deactivated their accounts and instead retained them indefinitely.

As a result, the Commission alleged that the company's statements about content deletion were false or misleading.

Remedial Measures

As part of the agreement, the Commission ordered the following:

  • Everalbum must not make false statements about (1) its collection, use, or deletion of its users' personal data, content, and face embeddings; (2) its users' ability to control those actions; (3) the extent to which Everalbum permits access to its users' personal data; (4) the extent, purpose, and duration of its retention of users' personal data after deactivation; or (5) the company's protection of the privacy or security of users' personal information;
  • the company must clearly and conspicuously disclose and obtain users' affirmative express consent before using users' biometric information for its use or development of facial recognition technology;
  • the company must delete (1) the photos or videos of users who requested the deactivation of their accounts, (2) facial recognition data it created without users' affirmative express consent, and (3) models or algorithms it developed using images from users' photos; and
  • the company must keep records and provide information to the Commission for compliance monitoring.

The order will remain in effect for 20 years.

Final Comments

The Flo Health case stands out for the intimate nature of the personal data involved. "Disturbed," "outraged," and "appalled" were some of the terms the users of the app included in their complaints to the company after learning of the unauthorized disclosures of data about their menstruations and pregnancies. Another interesting aspect is that the Court of Justice of the European Union invalidated last year the European Commission's decision that was the basis for the EU-US Privacy Shield framework, but the Federal Trade Commission still considers its obligations binding for its participants.

The Everalbum case is significant for two reasons. First, for a time the company allegedly used different settings for users in different jurisdictions, depending on the strength of their data privacy laws. Second, one of the measures the Commission ordered was the deletion of facial recognition data and the algorithms developed based on users' photos. In the past, the Commission did not order the deletion of algorithms in cases involving illegally obtained data, such as in cases involving Google and Facebook.