Showing posts with label opt-out. Show all posts
Showing posts with label opt-out. Show all posts

Friday, January 04, 2008

CALPIRG does consumer study revealing that privacy laws are being ignored in California

Many believe that the reason behind the identity theft crisis is the irresponsible data mining and selling of people's personal and financial information. This information then gets stored in places, where it is obtained (bought or stolen) by people, who have more than a "marketing" interest in it.

The buying and selling of people's personal information is a multi-billion dollar business.

Given this, a lot of people and consumer groups now are questioning how this done and how the information is protected.

CALPIRG, the California Public Interest Research Group has just released an "interesting" report on this subject and is making some recommendations to the California legislature to make the practice of buying and selling people's personal information more transparent.

From the press release on the CALPIRG site:

California’s consumers are “Still in the Dark” when it comes to who has access to their personal information according to a privacy report released today by the California Public Interest Research Group (CALPIRG).

“This holiday shopping season millions of consumers surrendered their personal information to retailers across the country with no idea how or with whom that information is shared” said Pedro Morillas, CALPIRG Consumer Advocate. “Fortunately there is light at the end of the tunnel. California already has some good policies regarding this issue. A few additions to the existing policies will give consumers the tools they need to safeguard their personal information.”
Currently, California law requires that if a consumer requests to find out where their information went a company must reveal where the information went for the past calendar year, or provide a no cost "opt-out" opportunity.

The report -- which includes a survey of customers trying to to discover where their information went -- revealed that over one-third of the requests were ignored.

Even worse, in addition to not getting a response, many of the customers were given the run around by being sent to other places within an organization or getting responses that had nothing to do with their original request.

CALPIRG is now calling that the California Legislature make the laws stronger with additional measures. They are calling out that the following additions should be made to existing laws:

Companies that do business with California consumers to respond to privacy requests, regardless of whether they share information with third parties.

Companies to both disclose the personal informa¬tion shared, and the third parties with which it is shared, and provide consumers with an opportunity to opt out of future sharing.

Companies to place a box on their Web sites’ privacy pages allowing consumers to opt out of information sharing.

Companies to get an affirmative “opt-in” from consumers before sharing their information with third parties, as opposed to the current practice of requiring consumers to opt out in order to protect their privacy.

The full report from CALPIRG can be read, here.

Opting out and privacy notices with an abundance of fine print have been criticized as not being effective, or consumer friendly for awhile now. Here are two other posts, I've written on this subject:

How does a telemarketer get your unlisted number?

Not answering a Privacy Notice gives the sender permission to sell your personal/financial information

Tuesday, November 27, 2007

Facebook invokes the opt-out defense when accused of privacy violations!

FaceBook, the much talked about social networking site, has received a lot of bad publicity recently.

Despite their immense popularity, personal information published on the site has been used to commit everything from identity theft to abusing children.

Hackers are also using the site to drop malicious software on unsuspecting visitors. This leads to even more privacy violations and in many instances, identity theft and financial crimes, also.

Now they are under fire for a marketing scheme, which posts what their members just purchased all over the electronic universe (Internet).

Kimberly Palmer also known as the "Alpha Consumer" at U.S. News and World report recently documented her sister's frustrations with this practice.

In her own words:


This past weekend, after my sister found a great pair of Dansko clogs and ordered them online from Zappos.com, her Facebook friends received a newsfeed message that told them she had just "found something cool at Zappos.com." Since she hadn't planned on announcing her purchase to so many people, she quickly deleted the message but not before feeling that her privacy had been invaded.

It turns out Facebook has relationships with online retailers, including Zappos.com, Fandango.com, and Overstock.com, that allow the social networking site to post information when purchases are made. My sister isn't the only one upset by it; the liberal group MoveOn.org started a petition asking Facebook to respect users' privacy and stop the practice. The blog Binary Freedom has asked Facebook not to ruin the holidays by alerting people to their gifts ahead of time.

Facebook has defended their right to do this by saying that a member can opt-out from having their personal shopping habits disclosed in public.

I always chuckle when the words "opt-out" are used as a defense to justify a violation of privacy.

The financial services industry has been sending us snail mail for years that are called privacy notices. These notices, which are full of small print make a mockery of the meaning of privacy (my opinion). If you fail to respond to these letters, they can and will sell your information to the highest bidder.

Of course, in most of these instances, the institutions involved don't make it easy to respond to these notices.

The problem with opting-out is that the current laws make it too easy to opted right back in.

Opting out is like playing a game of "Whac a Mole," because whenever you conduct a transaction, you might be opting-in again.

Tom Fragala at the Truston blog recently chronicled his frustrations in a post entitled, "Opting-In After You Have Opted-Out." In this post, Tom writes about a personal episode where he was targeted by identity thieves and opted-out, only to be opted-in again.

He also did a follow-up post, "How Direct Marketers Get You to Opt-In After Opting Out," which shows how marketing people have gotten past opt-out legislation in general.

There is little doubt that opt-out laws need to be updated. I wonder if the law were changed so that people had to give their permission for a company to sell their information, we might see a marked decrease in criminal activity enabled by information that is too easy to access!

Sadly, the people making too much money by exposing it for marketing purposes don't seem to want to become more responsible. And as long as they have a lot of money to fuel special interests, the problem isn't going to disappear very quickly!

Kimberly Palmer article, here.

Wikipedia has an interesting article going into detail on all the privacy concerns with FaceBook, here.

12-2-07 (Update): It appears FaceBook is changing their policy on opt-out to make it more user friendly and transparent. Here is a story from the LA Times on the changes, which privacy advocates are claiming as a major victory:

Facebook adds safeguards on purchase data

Thursday, May 10, 2007

Does it really matter how well a bank protects their site?

Dark Reading had a story that caught my eye (courtesy of Bank Systems & Technology) stating that a 150 million people in the United States are scared of online banking.

For fear of becoming the next victim of identity theft, 150 million U.S. consumers don't bank online, according to experts. But the banking industry could improve profitability by as much as $8.3 billion per year if banks build consumers' confidence in online security, according to the TriCipher Consumer Online Banking Study, conducted by Javelin Strategy & Research (Pleasanton, Calif.) for TriCipher, a Los Gatos, Calif.-based authentication solutions provider.

One thing to consider is that in most instances, where an individuals banking or personal information is compromised -- it is because they downloaded malware (crimeware), or they gave it up by more social means -- often referred to as phishing.

A bank site might be well protected, but if your computer system is NOT, it's probably still at risk. There are also a lot of spoofed fake bank sites out there that look pretty convincing to the untrained eye.

If you are unfortunate to pick up a keylogger -- everything you "key" is logged and sent back to the person -- who dropped it on your system. If the crook gets your user name and password, no amount of security on the bank's site is going to stop you from being victimized.

Most keyloggers are dropped on a system, when the user clicks on a link they shouldn't have in a spam e-mail.

Perhaps, the key is to make sure your system is well protected, and learn to protect your information, personally.

I use online banking myself, but I'm not going to rely on the bank to protect me.

The best defense against identity theft is using common sense, which in the case of computer systems, should include current protection from a reliable computer security vendor. Of course, being aware of the more social ways information is stolen is highly recommended, also!

My own bank tries to sell me online banking as a means of preventing identity theft. They remind me (every time I log on) that it's a way to prevent my personal information (sent in snail mail marketing offers) from being stolen.

On a personal note, I remind myself, I'm saving a tree or two. It also reduces the amount of documents, I have to shred. Thinking of it that way, gives me more peace of mind.

The last time I asked a Postal Inspector, mail theft hasn't stopped, and still is a way identity thieves steal a LOT of information.

You can opt out from receiving this snail mail (highly recommended), here. If you do, the credit bureaus will stop marketing your personal information, and it will be less available to steal.

As long as corporations are making a lot of money by keeping the commodity (our information) easy to use, criminals are going to find ways to steal it. After all, it's become highly profitable for them, also.

Dark Reading article (courtesy of Bank Systems and Technology), here.

Wednesday, April 11, 2007

Warning if you don't open (and respond) to snail mail from American Express, they will sell your personal information!

I get snail (mostly junk) mail from credit issuers, daily. Being concerned about identity theft and my personal privacy, I try to shred all of them. But am I doing the right thing? As you will see, some of them probably hope I never do.

Here is what happened to someone, who is a lot more diligent than I am (he actually opens the mail). Christoper Null (ATT/Yahoo Tech blogger) got his most recent privacy notice from American Express, which informed him if he didn't want all of his personal and financial information sold, he needed to opt-out with them.

They gave him two methods to do so, snail mail and a 1-800 number. Chris selected the 1-800 number and here is what happened:

I call (800-297-8378 if you want to try it for yourself). I get a recording welcoming me American Express and notifying me that the call could be recorded... thenabruptly says: "The computer system needed to answer your questions is not available." And it hangs up.

Now I understand computers go down, but that was five days ago, and I'm still getting the recording. Will it ever come back online or is it all a scam? The paranoid side of me believes that there is no computer connected to this 800 number, and that it's designed to trick me into forgetting about the entire matter and being too lazy to fill out the paperwork so I'll remain opted in.

According to several comments on his post, the 1-800 was down for quite awhile.

He later (being the saavy tech guy he is) tried to go to their webstite to opt-out and was only able to opt out from electronic, not snail communication.

Very REVEALING post from Chris, here.

It is pretty scary that credit card companies require us to opt-out, and if we don't, they sell our information to, anyone and everyone. After all, selling information, is highly profitable.

The Personal Finance Blog did a post about how much personal information is worth (retail-value), here.

The post is about a year old, and the prices might vary, depending on who is selling it.

I guess the finance industry has found a way to get around recent privacy concerns, and they do it under the guise of a privacy notice!

It's no wonder there is so much identity theft!