Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Privacy Lessons Learned From the Borders Group Bankruptcy

By Tracy Marshall on October 12, 2011
Email this postTweet this postLike this postShare this post on LinkedIn

The privacy implications of the sale of the bankrupt Borders Group’s consumer database to Barnes & Noble have been a focus of the Federal Trade Commission (“FTC”), state Attorneys General, and lawmakers, and the transaction highlights the need for companies to carefully draft and periodically review their privacy notices to consumers.

Privacy notices should not only accurately reflect current practices regarding the collection, use, sharing, and security of personal information, but also cover possible future transactions, such as a dissolution, merger, or sale of assets or the sharing of personal information with service providers.

In an e-mail sent to Borders customers and a notice on the Barnes & Noble website, customers were advised that they can opt-out of having their contact information (which includes names, addresses, and e-mail addresses) and purchasing history shared with Barnes & Noble.  This came about because Borders reportedly had at least three different privacy policies since 2006 that limited how personal information collected from customers could be shared; earlier policies stated that Borders would not share information without express consent, and a later policy indicated that information could be transferred if Borders was sold, merged, or reorganized, but the company would seek appropriate protections in such cases.  The FTC questioned whether the later policy covered dissolution and the sale of assets in bankruptcy, and the later policy only applied to information collected after the date it was adopted, so customers’ consent to the transfer was required.

Recent privacy enforcement actions by the FTC and lawsuits have focused on companies’ deceptive or unfair practices in failing to adhere to their stated privacy policies, applying a material change in a privacy policy to personal information collected under a prior policy without an affected individual’s consent, and failing to adequately secure personal information.  In light of this, it is important to ensure that privacy policies accurately describe the company’s current practices and are comprehensive enough to cover possible future transactions involving personal information.  In addition, personal information collected from consumers should always be appropriately secured from unauthorized acquisition or use.

Photo of Tracy Marshall Tracy Marshall

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She …

Tracy Marshall counsels international and domestic for-profit and non-profit clients on a range of privacy, data security, advertising, promotions, and intellectual property matters. She also advises on general corporate and transactional matters.

Tracy assists clients with compliance and advocates on their behalf. She is a Certified Information Privacy Professional (CIPP/US) through the International Association of Privacy Professionals (IAPP) and helps clients implement privacy, data security, and security breach response programs, develop internal and public-facing privacy policies to comply with applicable laws, respond to cyber and data security incidents, and manage relationships with service providers and third parties. Tracy advises on structuring and conducting email and text messaging campaigns, sweepstakes, contests, and other promotions, and she helps clients protect and enforce their intellectual property rights.

In addition, Tracy counsels clients on corporate matters and assists with structuring and negotiating a variety of transactions, including licensing, marketing, and outsourcing arrangements.

Tracy is frequently invited to speak at privacy, data security, telecommunications, and advertising conferences and is a contributor to Keller and Heckman’s Consumer Protection Connection blog and Beyond Telecom Law Blog.


To learn more about Tracy’s practice areas, click here.
Read more about Tracy MarshallEmailTracy's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Beyond Telecom Law Blog
  • Organization:
    Keller Heckman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo