Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

FTC Resolves Allegations Against Three U.S. Based Companies Involving Misrepresentations of International Privacy Program Certifications

By Kathleen Porter on April 20, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

Privacy laws in Asia-Pacific countries such as Japan, Australia, New Zealand and Singapore restrict the export of personal information except when the exporter meets certain qualifying conditions. One qualifying condition is if the exporter is in compliance with the Asia-Pacific Economic Cooperation’s Cross-Border Privacy Rules System (CBPR). Under the CBPR, the exporting company would have its data privacy policy and practices reviewed and certified by a third party to confirm the policy and practices are consistent with the applicable domestic law. For example, if an exporting company desired to export personal information of Japanese citizens, its privacy policy and practices would need to be consistent with Japanese law in order for the third party to certify the exporter was CBPR compliant. A company promoting compliance with CBPR on its website would be representing, directly or indirectly, expressly or by implication, that it was certified by a third party to participate in APEC’s CBPR system.

The U.S.’s data protection scheme does not require a third party to review a company’s privacy practices and policy prior to its export of personal information from the U.S. However, the U.S. scheme does prohibit a company from making false statements about its privacy practices and policy. Acting Federal Trade Commission (FTC) Chairman Maureen K. Ohlhausen recently reinforced the importance of this U.S. requirement, stating that companies “must live up to the promises they make to protect consumer data.”

Recently, the FTC charged three U.S. companies with violating Section 5(a) of the FTC Act on the grounds they falsely represented in their privacy policy that they were compliant with the APEC’s CBPR. In representing they were compliant with CBPR, these companies implied a third party had reviewed their privacy policy and privacy practices for compliance with the applicable domestic law. In fact, the FTC alleged, none of these companies had ever had their privacy policy or practices reviewed by a third party. The FTC claimed these false representations constituted deceptive acts or practices, which are prohibited under Section 5(a) of the FTC Act. The three companies charged by the FTC were Sentinel Labs, Inc. (endpoint protection software to enterprise customers), SpyChatter, Inc., (SpyChatter private message app), and Vir2us, Inc. (cyber security software distributor).

The FTC also claimed Sentinel Labs falsely stated in its privacy policy that TRUSTe reviewed Sentinel’s privacy policy and practices for compliance with TRUSTe requirements regarding transparency, accountability and choice regarding the collection and use of personal information. By claiming it had been awarded the TRUSTe Privacy Seal, the FTC claimed, Sentinel represented it met TRUSTe’s requirements. In fact, the FTC showed TRUSTe had never even reviewed Sentinel’s privacy policy or practices. The FTC claimed Sentinel’s misrepresentations regarding TRUSTe compliance constituted deceptive acts or practices, which are prohibited under Section 5(a) of the FTC Act.

The three companies decided to settle with the FTC, and the FTC entered into consent orders with each of them. The consent orders prohibit the companies from misrepresenting their participation, membership or certification in any privacy or security program sponsored by a government or self-regulatory or standard-setting organization. The companies are subject to monitoring and recordkeeping requirements. Notably absent is any material penalty or fine.

Because none of the companies had ever been certified under TRUSTe or APEC’s CBPR, it is possible the misrepresentations in the companies’ privacy materials were the result of simply cutting and pasting other policies and practices and just changing names, without reviewing the wording. The better practice when adopting a privacy policy or practice is for a company to draft its own wording based on its collection, use, security and transfer practices, rather than copying another policy and simply changing the names. A company should also carefully review the draft wording to confirm whether there are any incorrect statements. It is also helpful to periodically review a policy and set of practices to see whether changes are needed because of changes in the way the company handles personal information.

For additional information click here, here, and here.

Photo of Kathleen Porter Kathleen Porter

Kathy Porter’s practice straddles the areas of intellectual property, business transactions, trade regulation, and Internet law and includes import/export control issues, such as compliance and enforcement, competition, privacy, and data security. She counsels businesses on the development and implementation of data security and…

Kathy Porter’s practice straddles the areas of intellectual property, business transactions, trade regulation, and Internet law and includes import/export control issues, such as compliance and enforcement, competition, privacy, and data security. She counsels businesses on the development and implementation of data security and privacy practices to comply with the patchwork of laws and rules applicable to the collection, use, safeguarding, sharing, and transfer of protected or personal data. She regularly structures arrangements with promoters, marketers, website exchanges, and other third parties for the purchase, sale, sharing, and safeguarding of personal data. Kathy prepares and negotiates representations, warranties, and indemnities regarding personal or protected data and privacy and data practices. She also assists clients with privacy audits and works with third-party certification organizations to obtain certification of companies’ privacy practices. She guides clients through internal investigations to assess and address notice and other obligations regarding privacy breaches. Kathy often works closely with our litigation attorneys to manage external investigations such as those by federal or state regulators. Read her rc.com bio here.

Read more about Kathleen PorterEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo