FTC Still Seems More Interested In Making Headlines Than Really Protecting Privacy

from the picking-on-the-headline-winners dept

So, the FTC got some press today for announcing a high profile “settlement” with social networking startup Path. You might think that this is entirely about the news that came out a year ago, about Path uploading entire user address books to its server. If you don’t recall, that story got a lot of press coverage. Basically, Path, like tons of social networks and mobile apps, had a feature which was “see if your existing friends already use this app and connect to them.” But, to do that, it needed to know who your friends are. The process it used to do this was to upload your address book in the background and then compare it to their user base. This was, certainly, a somewhat questionable practice on privacy grounds, but it was something that lots of companies did, because it was a simple way to use the “find your friends” feature.

Of course, as soon as the story about Path went viral, most companies who were doing this very, very quickly dropped the practice, and figured out other, less privacy-invasive ways to connect you to your friends. That’s a good thing. So, does the company need to be punished? It seems like negative publicity and the market took care of everything.

Well… if you look at the details of the Path “settlement,” it wasn’t even really about that issue at all. Yes, Path agreed to have outside privacy audits for the next 20 years (which is the FTC’s go to “punishment” plan), but the hyped up $800,000 payment actually had nothing whatsoever to do with the uploading address books. Instead, it dealt with a different issue. During the investigation, the FTC also found that Path likely violated COPPA, the silly and misguided law that basically means most sites put in their terms that they don’t allow anyone under 13 to use it. Of course, in practice this has significant unintended consequences, including not letting perfectly reasonable services be available to kids and (more likely) parents teaching their kids to lie about their age.

It turned out that for a brief period of time, Path did not exactly follow the COPPA rules, and actually let a few thousand kids under the age of 13 sign up. So, they may have violated the rule. But… Path had discovered and fixed this well before the FTC investigation began. The company claims it was just an oversight that their system did not automatically reject users under the age of 13.

So… the company made a mistake, caught it and fixed it, without having the FTC get involved at all. And there’s no evidence, at all, that it misused the data it collected here. And yet it needs to pay $800,000? Why? For a big company, $800,000 may be small beans, but for a startup, that’s significant money.

Oh, and even more bizarre: as noted earlier, lots of companies did similar things to Path, but the FTC only went after Path. When asked why they only went after Path, outgoing FTC boss Jon Leibowitz gave a non-answer, saying that they’re just a small agency and so they have to “pick and choose which malefactors you want to go after.” So they chose the one most likely to create headlines — and forced them to cough up $800,000 over a “violation” that was the result of an accident, which the company had already discovered and fixed, and for which no abuse was found. That doesn’t seem like good policy. It seems like vindictive choices by the FTC focused on the maximum potential to create headlines, rather than actually protect people’s privacy.

Filed Under: , , , ,
Companies: path

Rate this comment as insightful
Rate this comment as funny
You have rated this comment as insightful
You have rated this comment as funny
Flag this comment as abusive/trolling/spam
You have flagged this comment
The first word has already been claimed
The last word has already been claimed
Insightful Lightbulb icon Funny Laughing icon Abusive/trolling/spam Flag icon Insightful badge Lightbulb icon Funny badge Laughing icon Comments icon

Comments on “FTC Still Seems More Interested In Making Headlines Than Really Protecting Privacy”

Subscribe: RSS Leave a comment
That Anonymous Coward (profile) says:

Well its nice to see that the FTC is kept small enough to not chase large corporations… well unless someone needs Google to pay a whiner because they have money that they should pay to them.
Look over here everyone! See we got $800,000 for these people violating your privacy… now stop worrying about the Government or large corporations doing it.

Add Your Comment

Your email address will not be published. Required fields are marked *

Have a Techdirt Account? Sign in now. Want one? Register here

Comment Options:

Make this the or (get credits or sign in to see balance) what's this?

What's this?

Techdirt community members with Techdirt Credits can spotlight a comment as either the "First Word" or "Last Word" on a particular comment thread. Credits can be purchased at the Techdirt Insider Shop »

Follow Techdirt

Techdirt Daily Newsletter

Techdirt Deals
Techdirt Insider Discord
The latest chatter on the Techdirt Insider Discord channel...