Internet tracking is an unfortunate reality in the cyber world. However, the way companies create these cookies has recently been brought under increased scrutiny. Various data collection laws both in the US and internationally continue to push for any data to be collected via websites or other means be secured or removed up request with various concerning what information that they could have access to.
When it comes to data collection, in the US, like many things it is state by state. One of the most comprehensive and oldest is the California Consumer Privacy Act of 2018. The California Consumer Privacy Act of 2018 (CCPA) gives consumers more control over the personal information that businesses collect about them and the CCPA regulations provide guidance on how to implement the law. This landmark law secures new privacy rights for California consumers, including:
Internationally, the General Data Protection Regulation or GDPR is the standard. Among its various provisions concerns that websites operating in their jurisdiction must tell their customers that the cookies they are pushing through are only to collect relevant data and must give an option to either accept or reject additional data collection. This is why when you go to these websites there's a prompt right before you get into the website about cookies and other data collection. If there is a breach, that company is on the hook for mishandling any data they collect. In general, individuals must affirmatively accept the cookie and privacy policies of the related company prior to any data being captured. No longer is it acceptable to simply list your privacy policy on a website.
In California, this type of data collection has seen a rise in the number of consumer lawsuits. In a recent class action lawsuit, Call-On-Doc violated California’s Invasion of Privacy Act (CIPA) by using tracking pixels (cookies) on its website. These tracking pixels allegedly allowed third parties to access and collect information about users without their consent.
The plaintiffs in the case argue that Call-On-Doc’s actions violated CIPA, which requires businesses to get the consent of individuals before recording or sharing their communications.
Call-On-Doc has not admitted any wrongdoing but agreed to pay $1.8 million to resolve the class action allegations.(2)
While some of these lawsuits are legitimate claims, there is also the rise of more scrupulous actors. According to Lannak and Hanna, there were over 1000 such CIPA related lawsuits that have been filed in California alone. Most of these stem from plaintiffs finding websites that don’t automatically have the opt out option as required by CIPA resulting in thousands of dollars in payouts and website redesign. These sites often share information with analytics sites such as google analytics, hubspot, salesforce and other similar CRM and analytics programs. The issue with some sites is that allow these third parties to collect data prior to receiving authorization.
They recommend talking to your Managed Service Provider, Internet Provider or IT personnel about what to do. Although, possibly not all inclusive, among the steps they recommend:
Cookies and data collection have become part of the everyday internet life. But there is a limit to these collections and as a result, government regulation has stepped in. California as well as many other states along with the EU have come out to protect data from being used unnecessarily. Your company should take steps to protect your clients' data and anyone visiting the website.
For more information feel free to reach out to our team to discuss best practices and on how to insure this risk. Many cyber policies do not extend coverage to the unlawful collection of such data. One should consult your broker for the best advice on properly insuring this.