[00:03.180 --> 00:06.960] As you can see, Ben mentioned on this slide isn't here with me tonight. [00:07.240 --> 00:08.940] Unfortunately, his availability changed. [00:09.440 --> 00:16.920] Thankfully, we found time to pre-record our discussion, so the chat that we were going to have here live is going to be a part of this presentation. [00:17.140 --> 00:21.060] And I'm going to get through my slides as quickly as possible because that's really what you want to hear. [00:22.580 --> 00:25.320] Just briefly about me, I do product and privacy work. [00:25.420 --> 00:27.380] I'm the head of product at a small cybersecurity company. [00:27.640 --> 00:29.720] I do various things about privacy policy. [00:30.500 --> 00:33.020] And I'm here thanks to NYC Resistant. [00:33.700 --> 00:34.260] Check us out. [00:34.500 --> 00:34.860] We're in Brooklyn. [00:36.500 --> 00:50.040] Ben Wiseman is currently an associate director in the Division of Privacy and Identity Protection, and he's spent the past couple of years at the FTC and even longer working in the Attorney General's office in D.C. [00:50.320 --> 00:52.900] He's a lawyer with Education and Sociology. [00:53.040 --> 00:56.320] He has a wealth of experience in legal research, policy, and writing. [00:56.320 --> 00:57.580] As well as litigation. [00:57.980 --> 01:01.400] It's safe to say that he's been a consumer advocate for much of his career. [01:03.280 --> 01:11.660] Today's topics, I'm going to go through my slides again very quickly so we can get to the discussion, but I do want to kind of set the stage for it. [01:12.240 --> 01:15.500] And first, the central theme for our hour tonight. [01:15.880 --> 01:18.600] What can I do to help improve privacy for everyone? [01:18.840 --> 01:22.780] I want to ask everyone to take a moment to internalize this thought. [01:24.740 --> 01:31.600] Imagine... I imagine most people here do something to preserve their privacy, to help other people with privacy. [01:32.180 --> 01:37.400] And beyond that, you can also project into the future and come up with other things that you think you might want to do. [01:37.880 --> 01:45.500] Keep that thought in the back of your mind during this talk and please share your story so that we can learn and inspire each other and amplify our efforts together. [01:47.580 --> 01:56.960] I think about this a lot and I'll provide some examples of some of the things that I do and I've done and continue to do so that maybe it'll give you some ideas as well. [01:57.700 --> 02:13.220] So, between the constant leaks, so sorry AT&T users, news about companies constantly prioritizing profit over privacy and security, blatant overreach by businesses, new ways to track us and influence our choices and lives. [02:13.440 --> 02:32.460] From Wi-Fi signals being used as radar, to lasers being used to scan the insides of people's homes just using peepholes, to shoes being used to identify people, and machine learning being leveraged to detect various health conditions that should be assessed by very few people and not by everybody else. [02:34.160 --> 02:36.580] Many of us have fewer options to avoid surveillance. [02:37.220 --> 02:43.960] More automated systems that share data, whether accurate or not, with other parties that don't have our interests in mind. [02:44.880 --> 02:55.760] And we have a Congress that continues to fail to act on public policy needs even when the topic is a no-brainer, with national security implications and broad bipartisan support. [02:56.460 --> 02:59.200] While all of that is true, it's just information. [02:59.380 --> 03:00.160] We're not helpless. [03:00.360 --> 03:08.380] And again, I imagine many people here today and watching online are in fact doing something for privacy for themselves and for others. [03:08.880 --> 03:12.300] It's easy to lose hope, but I'm here to remind you that nothing is lost. [03:12.300 --> 03:15.140] You can make a difference today, and we need you in this movement. [03:15.580 --> 03:19.500] The point being is that it's easy to find issues and bad news. [03:19.960 --> 03:23.840] We can avoid feeling helpless by finding ways to contribute to the cause. [03:24.420 --> 03:25.760] And it's an ongoing process. [03:26.060 --> 03:28.320] Pretty much everything worthwhile ultimately is. [03:28.480 --> 03:32.140] I'm sure that HOPE 115 is going to be chock full of privacy talks too. [03:33.380 --> 03:35.680] We can spread awareness and share knowledge. [03:36.380 --> 03:40.160] You might be surprised at how many places would be happy to have you talk about privacy. [03:40.740 --> 03:52.040] Learning institutions, unfortunately, have pretty much at every level failed people... failed to provide people with the information they need to understand why this is important, what the risks are, and what they can do. [03:52.040 --> 03:56.420] That doesn't mean that there aren't people who realize this is an important topic. [03:57.140 --> 03:58.280] Just talk to people. [03:58.980 --> 04:04.660] Security professionals and hackers are a captive audience, and we have to reach out to other groups too. [04:05.220 --> 04:12.600] As much as I enjoy talking to you all, we need to make sure that HR, PR, marketers, and advertisers also have access to this information. [04:13.060 --> 04:15.360] We need them to care and to have this knowledge. [04:16.040 --> 04:20.220] We can also find ways to join groups working on the topic and help develop policy. [04:20.360 --> 04:22.700] It's often free beyond your own time commitment. [04:23.420 --> 04:28.560] I've had a chance, for instance, to contribute to the first NIST privacy framework through their public working sessions. [04:28.920 --> 04:34.900] In terms of local groups here in New York, you can follow and support STOP, the Surveillance Technology and Oversight project. [04:35.240 --> 04:41.160] You can check events out on the subject, including those at the People's Forum in Midtown Manhattan, as well as NYC Resistor. [04:41.340 --> 04:42.260] Just putting it out there. [04:42.920 --> 04:51.320] And then there's Amnesty International's Ban the Scan Task Force, focused on preventing the use of facial recognition technology in New York. [04:52.260 --> 04:55.720] Also, shout out to Atiyah, Anissa, and Kazi for their work on that. [04:58.060 --> 05:11.760] Staying aware of privacy and security risks, paying attention to business losses due to failures in product and process design, and general unethical behavior, and being even somewhat educated about regulations, helped me to push improvements in the companies where I work. [05:13.780 --> 05:22.820] To make better cases, to correct behaviors, to rally support, and design safer products, having that awareness can help you to make the case that you need with your leadership. [05:23.900 --> 05:35.280] And then further, I think that art is essential to nearly every social movement, and it gives us a way to quickly relate to people in ways that they may internalize, and can generate ideas and energy to take action. [05:35.580 --> 05:38.520] And of course, let's not forget about regulators. [05:41.200 --> 05:51.160] I found opportunities to speak with people who work at the Federal Trade Commission, submitted public comments, and attended a privacy conference that they put on in the past, which was a great source of information and inspiration. [05:52.040 --> 05:59.500] More recently, I got in contact with Ben Wiseman, an Associate Director in the Division of Privacy and Identity Protection. [06:00.060 --> 06:06.540] Again, we had plans to discuss his and his organization's work here tonight, but schedule conflicts got in the way, so this is what we have right now. [06:06.780 --> 06:17.280] I cut as much of myself as I could out of this discussion, so that he has the maximum time to tell you about what the agency has been doing, and how it's helping all of us. [06:17.760 --> 06:21.000] If you do, if he does, and what we can do to help. [06:21.280 --> 06:21.620] Sure. [06:21.840 --> 06:23.040] So, my name is Ben Wiseman. [06:23.160 --> 06:28.780] I'm the Associate Director of the Division of Privacy and Identity Protection at the Federal Trade Commission. [06:29.600 --> 06:37.440] Taking a step back, the Federal Trade Commission is an independent agency in the federal government. [06:37.640 --> 06:41.240] Its primary mission is to enforce the FTC Act. [06:41.440 --> 06:47.560] The FTC Act prohibits unfair methods of competition, as well as unfair and deceptive trade practices. [06:48.240 --> 06:58.120] Now, where we come in in the Division of Privacy and Identity Protection is we are really the primary and chief privacy law enforcers in the country. [06:58.520 --> 07:15.980] We enforce the FTC Act to ensure that companies are not engaging in deceptive and unfair trade practices when it comes to consumers' personal information, whether it's the privacy of sensitive information, or how companies are maintaining data from consumers. [07:16.100 --> 07:22.840] We also enforce a number of sector-specific statutes, or more narrowly tailored statutes. [07:23.040 --> 07:27.940] So, for example, the Children's Online Privacy Protection Act, which is known as COPPA. [07:28.140 --> 07:34.840] It's a law that provides protections and places parents in control of their kids' data. [07:35.020 --> 07:40.040] We enforce the COPPA rule, which is the rule that was promulgated from the COPPA Act. [07:40.320 --> 07:50.600] We also enforce the Graham-Leach-Biley Act, which applies to financial institutions, as well as the Health Breach Notification Rule, which applies to non-HIPAA-covered health entities. [07:50.900 --> 08:07.420] And so we have wide-ranging authority and jurisdiction that it really reaches nationwide across a number of markets and sectors, and use that jurisdiction and authority in ensuring that consumers are protected, their privacy is protected. [08:08.480 --> 08:13.620] We are in the division that I lead, and DPIP is what we call it. [08:14.420 --> 08:17.900] We're about 40 or so attorneys. [08:18.240 --> 08:29.600] We are a small and mighty group, but we've been able to accomplish a lot in the last several years that really advance privacy protections for consumers across the country. [08:29.760 --> 08:41.940] I work in product management, so I find regulators and compliance to be particularly helpful to helping to prioritize doing the right thing by consumers. [08:42.220 --> 09:05.440] And certainly, the work that the FTC has done has been extremely helpful in that, both in terms of being aware of the statutes that the FTC monitors and enforces, and not for nothing, but also the actions that the commission has taken, enforcement actions has taken against various businesses to make [09:05.440 --> 09:07.600] sure that people are protected. [09:08.180 --> 09:19.920] Nobody wants to be, let's say, on the FTC's agenda, knowing the activities that the FTC engages in, also helps avoid getting, essentially, on your radar in a negative way. [09:20.060 --> 09:29.280] In terms of what each of us can do to promote a safer society through better privacy protections, how does that idea express itself in your own life and work? [09:30.420 --> 09:40.920] So I think, you know, what we've seen over the past several decades has been an explosion of companies that collect and use consumers' data. [09:41.580 --> 09:58.460] Whether it was sort of the beginning of the commercial surveillance economy, where companies were incentivized to collect as much data as possible from consumers in order to provide advertising and other very targeted services to consumers, to what we're seeing now with AI advances, [09:58.460 --> 10:09.240] where machine learning models we know require increasing amounts of data to continue to work and to process and to develop. [10:09.720 --> 10:18.660] And that also leads companies to to a business model that really incentivizes, again, the over-collection of consumers' personal information. [10:18.920 --> 10:25.920] So I think in all of our lives, we've seen, you know, our phones have become sort of something that is attached to us at all times. [10:25.960 --> 10:27.300] And this is just one example. [10:27.880 --> 10:37.020] And many consumers, you know, might not realize that, you know, with that, with your phone, there's an incredible amount of data that companies are able to collect. [10:37.420 --> 10:47.260] And so what we have tried to do at the FTC is really address some of what we have seen as the failures over the last several decades to sort of rein in some of these privacy abuses. [10:47.700 --> 11:04.280] You know, there's this sort of notion that, you know, our senior leaders have talked about at the FTC, you know, 20 years ago or so, where, you know, companies would be able to self-regulate, that as long as consumers were provided notice of certain privacy practices, [11:04.580 --> 11:06.880] that they would be protected from them. [11:07.020 --> 11:19.700] And what we have seen over the last 20 years is that it hasn't happened, that, you know, the notice and consent regime that has really dominated privacy over the past several decades has really failed in a number of respects. [11:20.200 --> 11:27.740] And that's because, you know, notice is really a fiction if it requires reading thousands and thousands of pages of privacy policies. [11:28.340 --> 11:39.800] You know, I think research has shown that it's just not even possible for consumers to actually review all of the privacy policies of all the apps and websites that they visit every day. [11:39.880 --> 11:50.380] It just wouldn't be feasible for a consumer, even if they could understand the opaque terms in those policies, to actually read through them given just the nature of our interactions online. [11:50.560 --> 11:57.180] We rely on being online for most of our lives, whether it's for work or for school or just in our personal lives. [11:57.820 --> 12:06.540] And then, you know, consent is really, again, can be a fiction if it means that we don't have any information to make decisions. [12:06.700 --> 12:19.380] And also, again, when we have to live our lives online, again, for transportation, for school, for all these different purposes, where we really are forced to engage online increasingly and, you know, to receive healthcare. [12:19.860 --> 12:26.500] And so what we have been trying to do at the FTC is really provide substantive protections for consumers' privacy. [12:26.700 --> 12:35.980] And what I mean by that is in our cases, you know, we are looking to create, you know, we bring enforcement cases against companies. [12:35.980 --> 12:40.060] And when we bring those cases, we are looking to provide real protections for consumers. [12:40.280 --> 12:41.980] So I'll give you one example. [12:42.100 --> 12:55.300] We brought a series of cases against health apps that were transmitting users' personal health information to advertisers, contrary to the privacy promises that they made to those consumers. [12:55.900 --> 13:00.900] And we alleged that that was an unfair trade practice under the FTC Act that it violated the law. [13:01.280 --> 13:10.420] And in the orders we obtained from those companies, we didn't require the companies just to get consent from the consumers before sharing that information. [13:10.420 --> 13:15.520] We actually prohibited the sharing of sensitive health information with advertisers entirely. [13:15.980 --> 13:24.580] So those companies are now prohibited from sharing that type of app that are prohibited from sharing health information with third-party advertisers. [13:25.080 --> 13:39.360] So again, really looking to provide substantive protections, recognizing some of the failures that we've seen over the past several decades in I think we have all sort of lived through this on a day-to-day basis. [13:40.040 --> 13:53.500] And it's something that consumers are becoming even more aware of about how their privacy is being impacted by the number of applications and websites and companies that are constantly surveilling us and collecting information. [13:53.500 --> 14:08.660] The FTC is effectively the public's shield from abuse of our data, over collection, distribution, sale, and its use, of course, when it doesn't align with the consumer's own needs. [14:08.860 --> 14:10.980] And I also want to be careful about using consumer, right? [14:11.060 --> 14:21.000] Because you may not have a direct relationship with an organization, you may not be using their service, but you may still be impacted by their practices and be exposed to that risk. [14:21.000 --> 14:23.340] And, of course, you mentioned privacy policies. [14:23.640 --> 14:34.960] So, first of all, from my perspective, I think there's a general maybe misunderstanding that's pervasive in the public about what privacy policies are. [14:35.360 --> 14:41.220] Privacy policies generally protect the company from the consumer, not the other way around. [14:41.220 --> 14:51.260] Yes, they will note some of the things that they do to protect your data, but, ultimately, it's just saying, okay, this is what we do, and that's that. [14:51.500 --> 14:53.020] Do you think that's accurate? [14:53.400 --> 15:03.300] Yeah, I think what we've seen, again, is that consumers can't really absorb or fully understand the terms in privacy policies, let alone have the time to read them. [15:03.300 --> 15:09.540] So, you know, in that sense, you know, what protections are they really providing to consumers? [15:09.880 --> 15:12.480] Look, I'm someone who reads the privacy policies. [15:12.680 --> 15:19.280] I recognize that I'm probably an outlier because this is my job and this is what I do and I'm sort of immersed in this world. [15:19.280 --> 15:20.960] But most consumers don't. [15:21.240 --> 15:31.080] They sort of will click through and will, you know, continue to sort of use services without fully understanding how their data is being used. [15:31.180 --> 15:36.160] And many times they're surprised that their data is being used in certain ways that they didn't expect. [15:36.160 --> 15:48.080] So, you know, we are constantly looking at are these privacy policies, is this current framework, this notice and consent framework, really providing adequate protections for consumers? [15:48.420 --> 16:05.480] And the conclusion we've come to in a lot of our cases that we bring, and I'll step back and sort of explain our enforcement work sort of more generally, but the conclusion we've come to is that, no, there are a lot of failings and a lot of really problematic practices that we're seeing in this [16:05.480 --> 16:05.820] space. [16:05.820 --> 16:15.080] Circling back to sort of over-collection, I'll just like tick off a few of the items you raised because I'm happy to go into further detail on any of them and really enjoy talking about it. [16:15.580 --> 16:18.460] Well, you know, we have seen this sort of over-collection of data. [16:18.680 --> 16:27.500] And so one way we're trying to address that is in at least 17 cases now, we have required companies to implement data minimization provisions. [16:27.500 --> 16:32.660] So that means, and what we tell companies all the time is, collect less, delete more. [16:33.120 --> 16:35.880] Collect less data and delete it more often. [16:36.100 --> 16:46.520] And so we've required these companies to implement these types of data minimization principles into their sort of everyday or organic processes, into their governing practices. [16:46.520 --> 16:54.560] You know, the less data that companies have about consumers, the less likely it is to be misused or disclosed to third parties. [16:54.920 --> 17:01.680] But it's also the less likely it could be, you know, obtained through a cybersecurity incident or a hacking incident. [17:01.680 --> 17:13.320] You know, I think we're still seeing on a day-to-day basis, you know, very large companies having cybersecurity incidents where consumer data is being taken by third parties and malicious actors. [17:13.540 --> 17:23.940] And the less data companies have on consumers, the better they are at collecting less and deleting more of it, the less data there is for hackers and those malicious actors to obtain access to that data. [17:23.940 --> 17:28.360] And so, you know, the over-collection of data doesn't just invade our privacy. [17:28.520 --> 17:38.020] It doesn't just create more opportunities for companies to track consumers, whether it's to track their health, track their religious beliefs, track where they live and their movements every day. [17:38.140 --> 17:51.540] But it also creates the systemic risks of cyber incidents having a much greater impact on all consumers, where companies continue to collect and retain more data than they need to operate their businesses. [17:51.540 --> 17:51.740] So let's talk a little bit more to this. [17:51.900 --> 17:56.060] Let's talk a little bit more about over-collection of data. [17:56.380 --> 17:57.080] So what's appropriate. [17:57.320 --> 18:05.900] I recall reading relatively recently that there's been some thought about paying more attention to what car manufacturers are doing. [18:05.900 --> 18:09.400] And car rental companies, too, to some degree. [18:10.060 --> 18:26.900] In terms of tracking real-time and very granular, which we now realize, but maybe not, you know, common public knowledge, that location data can be used to make all kinds of inferences and make decisions. [18:26.900 --> 18:39.360] So potentially infer where the person lives, where they work, who they associate with, their wealth, and a whole slew of other factors. [18:39.360 --> 18:54.560] So from your perspective, how can the FTC get the message across to businesses that they need to operate in the space that their consumers believe that they operate in? [18:54.660 --> 19:05.680] And then more broadly, that they need to take care with any data that they collect and generate because it can have an impact beyond their business as well. [19:05.680 --> 19:11.440] Yes, let me just take a step back and sort of explain sort of all the tools that we have at our disposal at the Federal Trade Commission. [19:11.700 --> 19:26.620] So we are primarily a law enforcement agency in that we bring enforcement actions, lawsuits, and investigations against companies that we believe are violating the Federal Trade Commission Act, the FTC Act. [19:26.620 --> 19:29.400] And so those are cases that we would bring in court. [19:29.940 --> 19:40.960] Oftentimes, we reach negotiated settlements with those companies and obtain orders against those companies requiring them to abide by certain practices. [19:41.220 --> 19:43.620] It's what's called injunctive relief in our cases. [19:43.880 --> 19:55.760] In some cases, we're also able to obtain monetary relief, whether it be civil penalties where the law allows or also redress for consumers for harms that they have suffered. [19:55.760 --> 20:01.920] So that's our primary work we do at the agency is really focused on those law enforcement efforts. [20:02.120 --> 20:04.480] But we also have a number of other tools at our disposal. [20:04.960 --> 20:09.800] So for one, we also have rulemaking authorities so we can craft industry-wide rules. [20:09.980 --> 20:12.580] And we do that in cases for a number of reasons. [20:12.820 --> 20:22.320] One, you know, sometimes we recognize that case-by-case enforcement against particular individual companies might not be enough to address broader market-wide problems. [20:22.320 --> 20:27.560] So recently, the FTC has promulgated a number of rules to help better protect consumers. [20:27.840 --> 20:39.640] One example is the impersonator rule, which prevents, you know, makes it, you know, unlawful and allows the commission to obtain civil penalties where individuals are impersonating government officials. [20:39.960 --> 20:46.980] I mean, we've seen this, you know, as an unlawful practice for many years and now the FTC has promulgated a rule on that issue. [20:46.980 --> 20:49.700] We also have what's called 6B authority. [20:50.060 --> 20:58.980] It's an authority under the FTC Act that allows us to obtain information from companies to study business practices sort of at an industry-wide level. [20:58.980 --> 21:02.420] And we often generate reports from those studies. [21:02.440 --> 21:14.520] And we have a number of ongoing orders that are out to companies, particularly in the social media context, that were issued several years ago on those types of studies into particular companies. [21:14.520 --> 21:25.860] And another thing that we do that I'm really proud about is our consumer education and our business education guidance that we have on our website at FTC.gov. [21:25.860 --> 21:36.860] We have an entire division at FTC, Division of Consumer Business Education, that focuses on providing outreach to both the business and consumer communities. [21:37.160 --> 21:52.960] And that is a really powerful way that we can, one, provide helpful information to consumers so that they have the information they need to sort of understand practices that are going on and take steps and tips that we provide to consumers. [21:52.960 --> 21:59.560] But it also gives us an avenue to provide guidance to businesses about concerns we're seeing in the marketplace. [21:59.940 --> 22:08.660] And so just recently, we issued a post on consumer data in cars, in sort of the connected car space. [22:09.040 --> 22:13.680] This is a space that the FTC has been engaged in for quite some time. [22:14.180 --> 22:17.000] We had a workshop on this issue in 2013. [22:17.160 --> 22:20.660] We had a report on this issue in 2015. [22:20.660 --> 22:32.460] We did another workshop specific to connected cars in 2018, and we provided guidance to consumers about various issues, including sort of wiping data on your car before you sell them. [22:32.760 --> 22:39.820] Much as you would when you sell, you know, a phone or a computer or you're recycling those, you want to clear your data on that. [22:39.940 --> 22:41.320] We provided guidance about that. [22:41.320 --> 22:50.080] You know, you mentioned geolocation data specifically, and our recent post highlights geolocation data that cars can collect on consumers. [22:50.080 --> 22:57.460] And this year, what the commission has done, had a number of cases involving consumers' precise geolocation data. [22:57.800 --> 23:12.820] You know, geolocation data and precise geolocation data in particular, which can really track consumers' movements incredibly precise within meters to know exactly where they are, is so sensitive because it tells so much about us, right? [23:12.880 --> 23:19.660] It tells us, you know, where we go eat, where our kids go to school, where we pray, where we seek healthcare. [23:20.120 --> 23:24.180] It can be incredibly revealing information that you can obtain about consumers. [23:24.180 --> 23:39.260] And there have been numerous reports in media how this information can really impact consumers, how there can be sort of harms that come about when bad actors or others are able to obtain this type of information to track consumers' movements on a day-to-day basis. [23:39.460 --> 23:49.740] You know, there was a very popular expose from, I believe, the New York Times several years ago that was able to track members of the United States military to and from military bases from their homes. [23:49.740 --> 23:55.440] So this type of information is incredibly sensitive to consumers. [23:55.680 --> 24:00.320] And the collection and the use of this information can invade consumers' privacy. [24:00.620 --> 24:04.960] So earlier this year, we announced two cases against data brokers. [24:05.000 --> 24:20.640] These are companies that consumers don't interact with on a day-to-day basis, but collect an incredible amount of information and create profiles on consumers that include information about them, including geolocation on individuals. [24:20.880 --> 24:30.280] And in one case was selling that geolocation to third parties downstream, continuing sort of the flow of consumer-sensitive data onward. [24:30.380 --> 24:35.220] And we alleged that their practices were unlawful and unfair under the FTC Act. [24:35.340 --> 24:36.740] And we obtained orders. [24:36.740 --> 24:44.000] And importantly, the orders that we obtained in those cases ban the companies from selling precise geolocation. [24:44.480 --> 24:48.620] In one case, you know, a case against a company called XMODE. [24:48.620 --> 24:59.580] It was selling sensitive geolocation that could be tracked to sensitive locations, like religious facilities, like childcare centers, and other, you know, locations that are very sensitive. [24:59.580 --> 25:07.280] And the order we obtained in that case prohibits the company from selling precise geolocation data attached to those types of sensitive locations. [25:07.440 --> 25:17.940] Because we do really see that this type of information is incredibly sensitive and that consumers really want substantive protections of this type of information. [25:18.220 --> 25:20.240] And so let's discuss some specific actions. [25:20.420 --> 25:25.800] You mentioned a few of them, some that I personally feel are truly critical. [25:25.800 --> 25:35.740] And honestly, incredibly encouraging, because I think that oftentimes the people involved in privacy, unfortunately, take a somewhat negative view about what's possible. [25:36.160 --> 25:39.520] And this situation can improve. [25:40.060 --> 25:49.640] And there's evidence of that in some of the actions that you've taken and some of the reporting that you've done that helps us to make better decisions, to design better products, and so on. [25:49.880 --> 25:55.220] So let's highlight some recent cases and talk a little bit about the actions that the FTC has taken. [25:55.220 --> 25:58.460] And maybe you can help us to understand a little bit about each one. [25:59.060 --> 25:59.660] Yeah. [25:59.660 --> 26:02.100] So one was involving Avast. [26:02.320 --> 26:18.780] The case summary said that the FTC will require Avast to pay $16.5 million and prohibit the company from selling or licensing any web browsing data for advertising purposes to settle charges that the company and its subsidiaries sold such information to third parties after promising that its [26:18.780 --> 26:21.520] products would protect consumers from online tracking. [26:21.520 --> 26:24.840] Yeah, so Avast is the case that we brought earlier this year. [26:25.120 --> 26:33.160] You know, Avast was selling security products for consumers who wanted sort of enhanced security and providing these products. [26:33.320 --> 26:36.220] Consumers wanted advanced security for themselves. [26:36.460 --> 26:52.740] And advanced privacy was selling certain services like virus protection software and other privacy protective services that were purportedly to protect consumers from sort of the disclosure of their information that they didn't want to. [26:53.260 --> 26:56.460] And these were the services that the company was selling. [26:56.680 --> 27:10.940] When in fact, as our complaint alleges, the company had a subsidiary and it was sharing consumers' browsing information, the websites that they were visiting with the subsidiary that was then further selling that information to advertisers downstream. [27:11.440 --> 27:21.660] And so we realized that that disclosure of information, of web browsing information, which again, like geolocation, is sensitive information about a consumer. [27:21.820 --> 27:24.860] It tells us, you know, it can reveal a lot about a person. [27:24.860 --> 27:30.440] And a tiny, you know, we had a sampling of data that was transferred by Avast. [27:30.500 --> 27:33.160] And it showed just how sensitive some of the information was. [27:33.360 --> 27:35.020] It was people looking at political websites. [27:35.020 --> 27:39.720] It was individuals that were using Google Maps to map addresses. [27:39.720 --> 27:44.020] It was people filling out sensitive financial forms and financial aid documents. [27:44.180 --> 27:48.000] There's a lot of very sensitive information that can be revealed to web browsing data. [27:48.180 --> 27:53.740] And the company was selling that downstream to advertisers who were then using it to advertise to consumers. [27:53.740 --> 27:58.940] And we obtained an order in that case, a few prominent features of the order. [27:59.200 --> 28:07.460] One is a requirement that the company had to delete web browsing information of consumers, as well as any data products that were developed. [28:07.640 --> 28:13.700] So any models or algorithms that were developed from the data that was unlawfully disclosed. [28:13.880 --> 28:27.000] Also a requirement that the company would be akin to our cases in the healthcare context, prohibited from further selling web browsing information to third parties for advertising purposes. [28:27.440 --> 28:39.480] So again, not permitting sort of the company to continue to engage in this practice so long as consumers consented to it, but prohibiting the disclosure of that type of sensitive information for advertising purposes altogether. [28:39.480 --> 28:42.020] And also sixteen and a half million dollars. [28:42.620 --> 28:45.720] And that money is going to be used as redress to consumers. [28:46.080 --> 28:48.220] A lot of personal information is sensitive in general. [28:48.600 --> 28:54.040] But then there's a whole layer of risk that's added when we're talking about health-related information. [28:54.520 --> 28:59.000] And I just want to briefly mention three cases, one of which you already touched on. [28:59.000 --> 29:07.260] So there's the FTC versus Cachava Inc., Exmode Social Inc., and Monument Inc. [29:07.760 --> 29:08.860] Pick any of them you want. [29:09.160 --> 29:10.420] Combine them all into one. [29:11.140 --> 29:17.100] Can you talk to us a little bit about what was happening, what the risk was, and the outcomes? [29:17.480 --> 29:22.800] So Cachava is a case that's still in litigation, so I can't speak much about that, about that case because it's still ongoing. [29:23.060 --> 29:35.300] But let me touch on sort of Monument, which was sort of followed a series of cases we've brought in the healthcare space, including a case called BetterHelp, a case GoodRx, and a case PreMom. [29:35.760 --> 29:54.860] These were all companies, and I did touch on this a little bit, that were using certain advertising technologies, in particular tracking pixels, which are tiny pieces of code that are embedded on websites that consumers often have no idea exist, that transmit information from websites to third [29:54.860 --> 29:56.520] parties, often to advertisers. [29:56.940 --> 30:09.240] And in the case of these healthcare cases, the companies were sending via traffic pixels, consumers' health information that was being obtained by consumers' interactions with these websites. [30:09.660 --> 30:15.640] So BetterHelp is a mental health treatment service that is offered online. [30:15.780 --> 30:17.680] GoodRx is a prescription service. [30:18.140 --> 30:21.560] PreMom offers fertility services and ovulation tracking. [30:21.560 --> 30:26.940] And Monument is a substance abuse healthcare service. [30:27.400 --> 30:40.540] And all these companies were, as we alleged in our complaints, transmitting information about consumers' health via tracking pixels to these third-party advertisers like Facebook and Google. [30:40.540 --> 30:54.300] And we alleged that it was doing so contrary to the representations that it made to consumers about keeping their health information private and safe, contrary to representations they made in their privacy policies about not disclosing this information. [30:54.800 --> 31:06.080] And we alleged that these acts, that this disclosure was deceptive under the FTC Act, and also unfair, in that it harmed consumers. [31:06.800 --> 31:08.020] Consumers couldn't avoid it. [31:08.400 --> 31:13.220] And it caused more harm than the benefits that it provided, which is the standard for unfairness. [31:13.740 --> 31:16.280] So we brought cases against all four of these health providers. [31:16.440 --> 31:18.780] And we obtained orders in all of these cases. [31:19.180 --> 31:23.420] And again, the orders were really designed to provide these substantive protections for consumers. [31:23.420 --> 31:32.180] So it wasn't that the companies could continue to sell this information to advertisers, or provide this information to advertisers, as long as consumers consented. [31:32.200 --> 31:40.040] We have banned these companies from further disclosing health information to third parties for advertising purposes. [31:40.340 --> 31:46.460] And so really trying to make a bright-line rule that will protect consumers moving forward that use these services. [31:46.980 --> 31:52.880] In the BetterHelp case, we were able to obtain redress to provide monetary relief to consumers. [31:53.280 --> 31:57.760] There's another case, like a VAS, where we provided redress to consumers. [31:57.960 --> 32:15.200] But we've built in a number of other protections in these cases, including requiring privacy programs for the companies, so that they have to, again, embed in their normal practices a program designed to assess and test and ensure that their products and services are providing adequate protections [32:15.200 --> 32:16.380] for consumers' privacy. [32:16.800 --> 32:24.300] Can you talk a little bit about what the FTC is able to do to verify compliance after these actions are taken? [32:24.460 --> 32:33.360] Does the FTC maintain an active role in ensuring that these behaviors have stopped, that new policies have been implemented, and so on? [32:33.420 --> 32:33.780] It does. [32:33.880 --> 32:40.720] We build into our orders robust compliance provisions that require compliance reporting to the Federal Trade Commission. [32:40.720 --> 32:57.720] And so, you know, the companies are required to provide, you know, updated compliance reports to our offices, as well as if there are any sort of future incidents that occur, like an unauthorized disclosure, have to provide the FTC with information about this. [32:57.840 --> 33:04.520] And we have a division, Division of Enforcement, that works closely on ensuring that companies are in compliance with our orders. [33:04.520 --> 33:17.700] And so, yes, you know, we build into these orders, these compliance provisions that ensure that the FTC has an ongoing role into making sure that companies are really abiding by the orders that they agree to with the commission. [33:17.700 --> 33:20.680] Two more cases that I want to just touch on before we continue. [33:21.020 --> 33:21.260] Sure. [33:21.820 --> 33:22.400] Ring LLC. [33:23.320 --> 33:30.800] You know, Ring was a, you know, a fascinating case, and really shows some of the harms that can occur when there's overbroad [33:34.540 --> 33:43.480] The allegations in Ring was it had overbroad access, and it allowed, essentially, certain employees at Ring to have access to users, to cameras. [33:44.220 --> 33:47.540] Again, speaking about the sensitivity of information. [33:47.840 --> 33:52.940] You know, these were video cameras that were, you know, placed in people's houses and people's kids' bedrooms. [33:53.220 --> 33:59.560] And it exposed really, really harmful, you know, really sensitive information about consumers. [33:59.800 --> 34:05.120] And it went disclosed, and given the overbroad access, created some real harms for consumers. [34:05.120 --> 34:12.960] And so that was a case that we resolved with the company, I believe it was last year in 2023. [34:14.540 --> 34:21.900] And, you know, it was a really big case highlighting some of the harmful practices we had seen in that case. [34:21.900 --> 34:24.360] And then one more, Rite Aid Corporation. [34:24.360 --> 34:44.600] This one, in particular, just resonated with me because it touched on facial recognition, which, as again, we know can be abused, can be inaccurate, and trusting it can cause consumers significant harm. [34:45.060 --> 34:49.460] Can you talk a little bit about what happened with Rite Aid and what they can and can't do now? [34:49.460 --> 34:51.620] Yeah, absolutely. [34:52.060 --> 34:56.560] So, Rite Aid is a significant case in a number of respects. [34:56.860 --> 35:04.620] One, it's the first case the commission has brought alleging that the use of an AI product like facial recognition was unlawful. [35:05.120 --> 35:10.000] Not in sort of how it was advertised or what companies said about their AI products. [35:10.000 --> 35:11.580] We've brought cases like that in the past. [35:11.680 --> 35:16.640] This is the first case where he alleged the actual deployment of an AI system was unlawful. [35:16.640 --> 35:29.420] And, you know, the other reason Rite Aid is significant, it really crystallizes and really puts a fine point on some of the harms that can come when companies don't take reasonable measures when deploying these types of technologies. [35:29.420 --> 35:33.380] So, Rite Aid started to use facial recognition technology. [35:33.380 --> 35:35.460] This is what we have alleged in our complaint. [35:35.680 --> 35:43.920] Use facial recognition technology in its stores to try to identify shoplifters and other consumers that they had accused of wrongdoing. [35:43.920 --> 36:01.940] The way that the facial recognition system worked was that the company's employees would take pictures with their own phones or use CCTV footage of consumers that they suspected or were caught engaging in wrongful activity or shoplifting and upload those into a database. [36:01.940 --> 36:06.120] So, those would be uploaded into a facial recognition database. [36:06.760 --> 36:26.680] Then, when other consumers were walking in the store, cameras would analyze their faces, and if there was a match to the database, it would provide a notice to employees in the store and would offer a sort of, depending on sort of the severity of the person who was uploaded into the system, [36:27.020 --> 36:28.980] would provide a number of options for store employees. [36:28.980 --> 36:34.760] It could be just monitor the person around the store, stop them, search them, or call the police. [36:34.940 --> 36:36.860] So, there are a number of various sort of options. [36:37.620 --> 36:42.580] What we alleged is that the company failed to take reasonable measures before deploying the system. [36:42.800 --> 36:44.800] That it failed to do proper testing of the system. [36:45.420 --> 36:47.240] That it failed to train its employees. [36:47.540 --> 36:50.960] That it failed to keep tabs on how the system was working in real time. [36:50.960 --> 36:56.060] That it failed to use high-quality images when uploading images into the database. [36:56.440 --> 36:59.380] Which is, you know, something that's very important for facial recognition. [36:59.600 --> 37:03.220] That low-quality images when used in the systems create a lot of error rates. [37:03.600 --> 37:07.480] And so, you know, what happened was the system didn't work as intended. [37:07.480 --> 37:13.740] And thousands of people were falsely matched when they walked into Rite Aid stores. [37:14.040 --> 37:23.760] And the stories that we, you know, heard from consumers in complaints that the company had received were really just show the harms of some of these technologies. [37:23.960 --> 37:28.540] There was an 11-year-old girl who was stopped and accused of shoplifting with her mother. [37:28.780 --> 37:33.200] And her mother was so distraught by the experience, she had to take off time of work. [37:33.200 --> 37:38.000] There was a black woman who was shopping and had the police called on her. [37:38.220 --> 37:43.540] And when Rite Aid employees ultimately went back and looked at the match image that was supposed to... [37:43.540 --> 37:49.920] that had identified her, that had flagged her, the Rite Aid employees recalled saying, you know, that this wasn't... [37:49.920 --> 37:51.600] it was a white woman with blonde hair. [37:51.940 --> 38:07.620] And so there are all these stories of people who were just going about their, you know, day-to-day lives, picking up prescriptions, getting food or other supplies from the pharmacy, were accused of wrongdoing, were stopped, tracked around and monitored in a store, [38:08.360 --> 38:11.120] or had, in some cases, had the police called on them. [38:11.260 --> 38:13.380] And the system just, you know, failed spectacularly. [38:14.180 --> 38:23.840] We also alleged that the company had deployed this system in majority non-white areas, and that it had, you know, an impact on communities of color and on women. [38:23.840 --> 38:33.640] And so, you know, we brought this lawsuit against the company, alleging that they had failed to take these reasonable measures before deploying the system. [38:33.680 --> 38:35.480] And we obtained an order against the company. [38:36.500 --> 38:39.940] Importantly, the order prohibits the company for five years. [38:39.940 --> 38:44.380] There's a five-year ban on the use of any facial recognition surveillance system. [38:44.380 --> 38:51.880] So the company will not be able to deploy any facial recognition surveillance system of the kind it had previously deployed for five years. [38:52.240 --> 39:09.200] If, in the future, the company intends or decides to deploy any type of biometric system for surveillance purposes, that it has to develop a very robust program in doing so that requires testing and assessments. [39:10.060 --> 39:15.900] It requires notice to consumers when they've been subject to the system and when decisions have been made about the system. [39:16.320 --> 39:31.880] And significantly, it requires a kill switch, that if they identify that the system isn't working as intended or is causing specific risks to certain demographic groups, that they have to shut off the system if they're unable to fix it to implement safeguards that mitigate those risks. [39:31.880 --> 39:43.680] And so, you know, a few sort of big-picture takeaways is, one, that keeps really crystallize the harm that can come from some of these facial recognition technologies. [39:43.840 --> 39:54.200] And it also crystallizes, you know, the real cost to businesses if they fail to follow the FTC Act and deploy these types of technology responsibly. [39:54.400 --> 40:11.780] Again, there's a five-year ban on the use of these technologies, a comprehensive program before implementing them, and other significant provisions, including the deletion of all photos that were collected from the facial recognition system, as well as the deletion of any models or algorithms that were developed in those photos. [40:13.400 --> 40:15.260] So breaking the law can have a cost. [40:15.540 --> 40:16.740] I love that case. [40:16.940 --> 40:27.460] I want to spend hours dissecting it because it just ties together so many themes that are pervasive in application of technology in so many industries right now. [40:27.720 --> 40:35.480] And perfectly illustrates some of the real risks that people face, even when they don't have a relationship with that business. [40:35.700 --> 40:46.700] You may be in a Rite Aid because you're there with another person, not intending to do any business with them, but now you're part of their system, and however many other systems that are actually deployed. [40:46.920 --> 40:50.380] So that's, I think, a very, very interesting case. [40:50.540 --> 40:51.100] Thank you for that. [40:51.640 --> 40:54.480] Let's talk a little bit about how investigations typically start. [40:54.700 --> 41:07.040] And specifically, are there examples where people from the public sector, or generally outside of the FTC, have been involved in initiating investigations into things like inappropriate data collections, processing, and sales? [41:07.040 --> 41:07.760] Absolutely. [41:08.120 --> 41:12.460] We get cases and we sort of generate cases through a number of different means. [41:13.060 --> 41:16.200] One, we have a database of complaints. [41:16.360 --> 41:20.480] You can file complaints on the FTC website, reportfraud.ftc.gov. [41:23.320 --> 41:25.660] I like to say, we actually like complaints. [41:25.820 --> 41:27.340] Please send them our way. [41:27.600 --> 41:32.460] We want to hear from folks, you know, what you're experiencing, the privacy problems that you're experiencing. [41:33.100 --> 41:37.500] You know, I think we recently called for folks to tell us about connect to cars. [41:37.780 --> 41:39.320] How is that impacting you? [41:39.480 --> 41:43.540] And have you seen that sort of, the collection of data from cars impact you? [41:43.780 --> 41:45.100] Please report it to us. [41:45.280 --> 41:54.980] So please, you know, consumers, one thing that people can do, folks can do, is absolutely feel free to go to reportfraud.gov and fill out a complaint form. [41:55.200 --> 42:00.660] We get those, we read those, we analyze those, and cases are absolutely generated from our complaint database. [42:01.940 --> 42:11.960] Also, many advocacy groups and others will file complaints with the FTC where they've seen unlawful practices and file those directly with the FTC. [42:12.200 --> 42:15.380] And those are, we take those seriously and staff review them. [42:15.560 --> 42:20.660] And we can't talk about anything that is nonpublic or our investigative processes. [42:21.260 --> 42:32.320] But we receive those complaints, and there have been cases that have been generated out of complaints received from advocacy groups and other groups in the public who submit more formal complaints through the FTC. [42:32.320 --> 42:41.900] And so those are ways that we absolutely receive information and generate cases where we learn of unlawful practices. [42:42.300 --> 42:48.800] You know, another way we get cases is we work in close collaboration with states as well as other sister agencies. [42:49.380 --> 42:54.760] You know, state attorney generals across the country are sort of boots on the ground in those communities. [42:55.920 --> 42:59.640] They, you know, do incredible privacy work across the country as well. [42:59.780 --> 43:08.080] And we work closely with them, both on individual cases as well as collectively when looking at certain issues that are causing us concern in the marketplace. [43:08.700 --> 43:13.660] And then finally, you know, we learn about news concerning practices in the media as well. [43:13.660 --> 43:28.760] There's been great investigative journalists exposés in recent years on certain privacy practices that have, you know, that have caused us to take a closer look at things and really see if we're seeing problematic practices will take further action. [43:29.040 --> 43:36.520] I appreciate you specifically clarifying that the fraud reporting mechanism is in fact rather broad. [43:36.520 --> 43:42.060] It's not just about specific fraud that has happened, but also unfair and unreasonable practices. [43:42.060 --> 43:46.600] And I think that's very, very good for people to keep in mind. [43:46.740 --> 43:54.380] And I think that leads us into the final bits of this discussion and specifically about ways that we can help. [43:54.740 --> 43:56.580] So you mentioned fraud reporting. [43:56.760 --> 43:58.400] You've mentioned public comments. [43:58.520 --> 44:00.420] I've submitted public comments before as well. [44:00.640 --> 44:19.320] I think that it's always encouraging to see them published because you get a sense for kind of the commission's agenda and priorities and gives us an opportunity to weigh in on these subjects in a meaningful way and hopefully help the regulators at the FTC. [44:19.680 --> 44:25.740] Any other things that you want to bring up in terms of ways that people can help to further the cause by supporting your work? [44:25.740 --> 44:29.320] Yeah, I'll just reiterate, you know, reportfraud.ftc.gov. [44:29.580 --> 44:31.260] File complaints in our database. [44:31.480 --> 44:35.740] Complaints about privacy will be directed to us and we will closely look at them. [44:36.060 --> 44:37.180] Follow our website. [44:37.180 --> 44:38.660] You can get updated alerts. [44:38.860 --> 44:40.620] You know, follow our consumer blog. [44:41.400 --> 44:46.340] That will also sort of provide alerts when we do issue items for public comment. [44:46.340 --> 44:50.980] We want to hear public comment when we issue proposed rules. [44:51.300 --> 44:54.960] We often issue sort of RFIs or request for information. [44:55.280 --> 44:59.420] And so we do really want the public to engage and hear from the public on these issues. [45:00.140 --> 45:03.520] And so please provide your comments and stay engaged. [45:04.460 --> 45:13.300] It's incredibly helpful to hear how certain companies' practices are really impacting communities and individuals on an individual level. [45:13.300 --> 45:21.480] And, you know, one thing I would say that the commission has also called for, for several years now, is comprehensive federal privacy legislation. [45:22.520 --> 45:29.360] Baseline protections that would provide privacy protections for all consumers across the country. [45:30.120 --> 45:38.340] It has been encouraged by, you know, states have, I think there's now 18 or 19 state laws on the books, privacy laws on the books. [45:38.340 --> 45:54.120] But the commission has, you know, strongly urged Congress to act on comprehensive privacy legislation, which would address, you know, a lot of the concerns we talked about about the over collection of data, including some of the new collection techniques we're seeing with generative AI and other AI type products. [45:55.100 --> 45:56.300] Do you have any final thoughts? [45:56.440 --> 46:04.880] Is there anything that's coming up on your agenda that we should be keeping an eye on that you want to share before we wrap up? [46:04.880 --> 46:06.740] No, I just say, please stay engaged. [46:07.020 --> 46:08.860] We want to hear from, from communities. [46:09.060 --> 46:09.960] We want to hear from people. [46:10.240 --> 46:23.380] It's really important to understand how these types of privacy practices, whether it's AI, whether it's connected cars, whether it's your personal location information, how that is impacting your lives and where you're seeing problematic practices. [46:23.380 --> 46:31.540] So please use reportfraud.ftc.gov and engage in when we're issuing proposed rules in the comment process. [46:31.540 --> 46:33.060] We really do want to hear from folks. [46:33.220 --> 46:35.280] It's really important to our mission and the work that we do. [46:36.020 --> 46:39.520] Thank you so much for your time and for your work and everyone at the commission. [46:39.800 --> 46:40.740] Thanks for having me, Gene. [46:40.900 --> 46:42.860] It was fun to talk about these issues. [46:44.180 --> 46:45.260] So how about that? [46:46.000 --> 46:49.920] There's a lot they can do, even with the current laws, right? [46:50.120 --> 46:58.260] Law enforcement agency, they can take specific actions against companies and they have investigative authority and they're willing to listen to us. [46:58.700 --> 47:00.380] Just look at that Rite Aid case. [47:00.620 --> 47:02.380] They had to delete all of the data. [47:02.780 --> 47:03.920] They had to make this right. [47:04.020 --> 47:08.220] Right now, probably Rite Aid is the safest large pharmacy for you to go shop at as a result. [47:08.940 --> 47:15.020] So, be an advocate at work, be an advocate in your social circle, and help regulators do their work, right? [47:15.300 --> 47:18.240] They actually do this job and they do it quite well. [47:18.720 --> 47:21.180] And like us, they want the same things. [47:21.320 --> 47:26.460] They want the same things from Congress, they want the same things from businesses, and they have the ability to do this. [47:27.780 --> 47:32.080] So, huge thanks to Ben and Doug Farrar who made this possible. [47:32.380 --> 47:34.580] Thanks to everyone at HOPE and all the volunteers. [47:34.580 --> 47:36.880] Again, please join us at NYC Resistor. [47:37.020 --> 47:39.920] We like privacy there too, and all kinds of other hackery things. [47:40.520 --> 47:45.440] And I think we're just about at time, but I will have time after this discussion if you want to catch up. [47:45.560 --> 47:52.300] And you can also email me at privacychat at pm.me if you want to discuss anything that you might want to do together. [47:53.180 --> 47:53.980] Thank you for that. [47:57.720 --> 47:58.400] You got it.