Ch 11: Telecommunications and Marketing Flashcards

1
Q

What is the TCPA?

A

The Telephone Consumer Protection Act of 1991

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the TCPA do?

A

It places restrictions on unsolicited advertising by telephone and facsimile, and updated them in 2012 to address robocalls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the TSR?

A

The Telemarketing Sales Rule of 1995 which implemented the Telemarking and Consumer Fraud and Abuse Prevention Act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is Telemarking under the TSR?

A

A plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the US National DNC Registry?

A

The best known FTC TSR Requirement. It provides a means for U.S. residents to register residential and wireless phone numbers that they do not wish to be called for telemarketing purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Who enforces the DNC?

A

The FTC, the FCC and state attorneys general enforce the DNC Registry.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Violations of the DNC Registry can lead to what?

A

Civil penalties up to 40K per violation, nationwide injunctions, and payment of redress to injured customers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the DNC registry require sellers and telemarketers to do?

A
  1. To access the registry prior to making any phone-based solicitations
  2. To update their call lists every 31 days with the new registry information.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who do the DNC rules apply to?

A

For-profit organizations and charitable solicitations placed by for-profit telefunders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Who do the DNC rules not apply to?

A
  1. Nonprofits calling on their own behalf
  2. Calls to customers with an EBR
  3. Inbound calls, provided that there is no “upsell” of additional products or services
  4. Most business-to-business calls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the Existing Business Relationship (EBR) exception to the DNC rules?

A

Sellers (and telemarketers calling on their behalf) may call a consumer with whom a seller has an established business relationship (EBR), provided the consumer has not asked to be on the seller’s entity-specific DNC list.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

When is there an EBR?

A
  1. When the consumer has purchased, rented or leased the seller’s goods or services (or completed a financial transaction with the seller) within 18 months preceding a telemarketing call. The 18-month period runs from the date of the last payment, transaction or shipment between the consumer and the seller.
  2. When a prospect has made an application or inquiry regarding the seller’s goods and services. This EBR runs for three months from the date of the person’s inquiry or application.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Does the TSR allow sellers and telemarketers to call consumers who consent to receive such calls?

A

Yes, but the consent must be:

  1. in writing
  2. state the number to which calls may be made
  3. included the consumer’s signature
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the DNC Safe Harbor?

A

Guidance that if sellers and telemarketers follow will reduce their liability by not being subject to civil penalties or sanctions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is CAN-SPAM?

A

The Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does the CAN-SPAM Act do?

A

It created rules for how legitimate organizations send emails, including clear identification of the sender and a simple unsubscribe or opt-out.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

CAN-SPAM does not apply to:

A

Transactional or relationship messages.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What does the act provide to consumers who might sue?

A
  1. Injunctive relief

2. Damages up to $250 per violation, with a max of $2 million

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

CAN-SPAM prohibits senders from sending any MSCMs without…

A

the subscriber’s express prior authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What act governs the privacy of customer information provided to and obtained by telecommunications carriers?

A

Telecommunications Act of 1996

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is CPNI?

A

Customer Proprietary Network Information and is information collected by telecommunications carriers related to their subscribers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What are the opt-in and opt-out requirements of the 2007 CPNI order?

A

It requires customers to expressly consent, or opt in, before carriers can share their CPNI with joint venture partners and independent contractors for marketing purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What does the 2007 CPNI order require carriers to do?

A
  1. Carriers must notify law enforcement when CPNI is disclosed in a security breach within seven business days of that breach.
  2. Customers must provide a password before they can access their CPNI via telephone or online account services.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is the VPPA?

A

The Video Privacy Protection Act of 1988

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

Videotape are prohibited from what?

A

From disclosing customer PI unless an enumerated exception applies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

Does the VPPA preempt state law?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What is the CalOPPA?

A

The California Online Privacy Protection Act.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What does the CalOPPA do?

A

Requires operators of commercial websites to conspicuously post a privacy policy is the collect PII from those living in California. The policy must include information on how the operator responds to Do Not Track signals and to state whether 3 parties can collect PII about the site’s users.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What does the DNC registry require sellers and telemarketers to do?

A
  1. To access the registry prior to making any phone-based solicitations
  2. To update their call lists every 31 days with the new registry information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

Does the TSR allow sellers and telemarketers to call consumers who consent to receive such calls?

A

Yes, but consent must be:

  1. in writing
  2. state the number which calls may be made
  3. include consumer’s signature
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

Videotapes are prohibited from what?

A

From disclosing customer PI unless an enumerated exception applies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

California Online Privacy Protection Act (CalOPPA)

A
  • Requires operators of commercial websites to conspicuously post a privacy policy is the collect PI from those living in California
  • The policy must include information on how the operator responds to Do Not Track signals and to state whether 3 parties can collect PI about the site’s users
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

Does the Video Protection Privacy Act (VPPA) preempt state law?

A

No

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

Controlling the Assault of Non-solicited Pornography and Marketing (CAN-SPAM) Act of 2003 and its exceptions

A

It created rules for how legitimate organizations send email, including clear identification of the sender and a simple or unsubscribe or opt-out

Exceptions:
It does not apply to transactional or relationship messages

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

Who enforces the DNC?

A

The FTC, FCC, and the state attorney generals

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What does the 2007 Customer Proprietary Information (CPNI) order require carriers to do?

A
  1. Carriers must modify law enforcement when CPNI is disclosed in a security breach within 7 business days of that breach
  2. Customers must provide a password before they can access their CPNI via telephone or online account services
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is the TSR?

A

The Telemarketing Sales Rule which implemented the Telemarketing and Consumer Fraud and Abuse Prevention Act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

Who do the DNC rules apply to?

A

For-profit organizations and charitable solicitations placed by for-profit telefunders

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

CAN-SPAM prohobits senders from sending any MSCMs without . . .

A

the subscriber’s express prior authorization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What is the DNC Safe Harbor?

A

Guidance that if sellers and telemarketers follow will reduce their liability by not being subject to civil penalties or sanctions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

Violations of the DNC Registry can lead to what?

A

Civil penalties up to 40K per violation, nationwide injunctions, and payment of redress to injured customers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

When is there an established business relationship?

A
  1. When the consumer has purchased, rented, or leased the seller’s goods or services (or completed a financial transaction with the seller) within 18 months preceding a telemarketing call. The 18-month period runs from the date of the last payment, transaction or shipment between the consumer and the seller.
  2. When a prospect has made an application or inquiry regarding the seller’s goods and services. The EBR runs for 3 months from the date of the person’s inquiry or application
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What act governs the privacy of customer information provided to and obtained by telecommunications carriers?

A

Telecomunications Act of 1996

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What is the Existing Business Relationship exception to the DNC rules?

A

Selles (and telemarketers calling on their behalf) may call a consumer with whom a seller has an established business relationship, provided the consumer has not asked to be on the seller’s entity-specific DNC list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What does the act provide to consumers who might sue?

A
  1. Injunctive relief

2. Damages up to $250 per violation, with a max of $2 million

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

Intrusion Upon Seclusion

A
  • one of 4 traditional privacy torts
  • IOS ” imposes liability on “one who intentionally intrudes, physically or otherwise, upon the solitude or seclusion of another or his private affairs or concerns.”
  • To succeed in an intrusion tort claim, the plaintiff must show that “the intrusion would be highly offensive to a reasonable person.”
  • In contrast with intrusion tort requirements, telemarketing regulations in the United States address milder intrusions, which do not require a showing of “highly offensive” intrusion.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

Telephone Consumer Protection Act of 1991 (TCPA)

A
  • FCC issued regs that place restrictions on unsolicited advertising by telephone and fax. Updated in 2012 to address robocalls.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

Telemarketing Sales Rule (TSR): Background

A
  • FTC issued in 1995.
  • Implemented the Telemarketing and Consumer Fraud and Abuse Prevention Act
  • FCC has a counterpart rule
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

TSR: Do Not Call Registry, Background and Enforcement

A

The FTC, the FCC and state attorneys general enforce the DNC Registry.

  • Now contains over 220 million participating phone numbers—and is still growing.
  • $40,654 per violation.
  • In addition, violators may be subject to nationwide injunctions that prohibit certain conduct and may be required to pay redress to injured consumers.
  • Violation to call any number without checking registry first.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

Exceptions to DNC Registry

A
  • nonprofits calling on their own behalf
  • calls to customers with an existing biz relationship (EBR).
    EBR with customer - 18 mo. from last transaction
    EBR with prospect - 3 months from application or inquiry
  • inbound calls, provided no upselling.
  • Most BtoB calls
  • Consent - in writing, with signature, clear n’ conspicuous
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

DNC Registry: Safe Harbor

A

Safe Harbor = [I]f a seller or telemarketer can establish that as part of its routine business practice, it meets the following requirements, it will not be subject to civil penalties or sanctions for erroneously calling a consumer who has asked not to be called, or for calling a number on the National Registry:
• The seller or telemarketer has established and implemented written procedures to honor consumers’ requests that they not be called, [and]
• The seller or telemarketer has trained its personnel, and any entity assisting in its compliance, in these procedures, [and]
• The seller, telemarketer, or someone else acting on behalf of the seller . . . has maintained and recorded an entity-specific Do Not Call list, [and]
• The seller or telemarketer uses, and maintains records documenting, a process to prevent calls to any telephone number on an entity-specific Do Not Call list or the National Do Not Call Registry. This, provided that the latter process involves using a version of the National Registry from the FTC no more than 31 days before the date any call is made, [and]
• The seller, telemarketer, or someone else acting on behalf of the seller. . . monitors and enforces compliance with the entity’s written Do Not Call procedures, [then]
• The call is a result of error.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

TSR - How Calls Can be Made under Telemarketing Laws

A

The TSR requires covered organizations to:
• Call only between 8 a.m. and 9 p.m.
• Screen and scrub names against the national DNC list
• Display caller ID information
• Identify themselves and what they are selling
• Disclose all material information and terms
• Comply with special rules for prizes and promotions
• Respect requests to call back
• Retain records for at least 24 hours
• Comply with special rules for automated dialers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

TSR - Entity-Specific Suppression Lists

A
  • Consumers can put number on DNC Registry, or ask not be called again by the TMer/Seller. TMer/Seller required to maintain internal suppression lists to respect these DNC requests.
  • If distinction between 2 divisions of one TMer/Seller (operational structure wise and types of goods/services wise), then request not have to be honored by one division if made by consumer to other division.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

TSR Required Disclosures at Beginning of Call

A

The TSR requires that, at the beginning of the call, before delivering any sales content, telemarketers disclose:
• The identity of the seller
• That the purpose of the call is to sell goods or services
• The nature of those goods or services
• In the case of a prize promotion, that no purchase or payment is necessary to participate or win, and that a purchase or payment does not increase the chances of winning

Note that disclosures must be truthful.

Note: If made for multiple purposes, disclosures must be made for all SALES purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
55
Q

TSR : Broad Categories of Information that Must Always Be Disclosed

A
  1. Cost and quantity
  2. Material restrictions, limitations, or conditions
  3. Performance, efficacy, or central characteristics
  4. Refund, repurchase or cancellation policies
  5. Material aspects of prize promotions
  6. Material aspect of investment opportunities
  7. Affiliations, endorsements, or sponsorships
  8. Credit card loss protection
  9. Negative option features
  10. Debt relief services

Note: For newer payment methods must now meet higher standard for authorizing a payment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
56
Q

TSR: Other Requirements and Prohibitions

A
  • Must transmit accurate caller ID - TMer or Seller or Seller’s customer service number. TMer not liable if caller ID not reach cosumer if they arranged for it to be provided with carrier.
  • No call abandonment, i.e. hanging up or leaving dead air after 2 secs of consumer’s greeting. But is Abandonment Safe Harbor, if
    sales rep takes at least 97% of calls actually answered by consumer,

allows 4 rings/15 seconds before giving up on call

plays recorded message stating name/# of Seller when live sales rep not available w/i 2 secs

maintains documentation of these reqs.

  • To use pre-recorded message, must have consumer opt in.
  • No billing for any goods/services without express informed consent. If during call, can get then. If have account info from another source, getting consent is harder.
57
Q

Updates to FCC’s TCPA rules re. robocalls/autodialers

A
  • 2012 revision to match FTC TSR.
  • Even if have EBR, rquired to get express written consent for robocalls to residential lines.
  • Must allow consumer to opt out of robocalls during a robocall.
  • Robocalls subject to HIPAA are exempt.
58
Q

Updates to FCC Approach to Robotexts

A
  • FCC issued order in 2015 that text messages subject to same protections as voice calls under the TCPA. so robotexts require express consent also.
  • Also required consent to include clear and conspic. disclosure that calls/texts can be made using autodialer or artificial voice.
  • Consent not required for purchase.
  • Consent can be revoked

-

59
Q

TSR Record-keeping Requirements

A
  • Following records maintained for 2 years:
    • Advertising and promotional materials
    • Information about prize recipients
    • Sales records
    • Employee records
    • All verifiable authorizations or records of express informed consent or express agreement
  • Also - TMers and Sellers can decide how to keep records per contract.
  • sales records must include:
    (1) the name and last known address of each customer,
    (2) the goods or services purchased,
    (3) the date the goods or services were shipped or provided and
    (4) the amount the customer paid for the goods or services.
  • Similarly, for all current and former employees directly involved in telephone sales, records must include:
    (1) the name (and any fictitious name used),
    (2) the last known home address and telephone number and
    (3) the job title(s) of each employee.
60
Q

State Telemarketing Legislation

A
  • More than half the states require that telemarketers obtain a license or register with the state.
  • States can also create their own DNC lists, with differing exceptions, fines or methods of consumer enrollment from their federal counterpart.
  • Some states require that telemarketers identify themselves at the beginning of the call, or that the telemarketer terminate the call without rebuttal if the recipient of the call so desires.
  • Finally, states may require that a written contract be created for certain transactions.
61
Q

Fax Marketing

A
  • TCPA, enforced by FCC, prohibits unsolicited fax. up to $500 per fax penalty. PROA included.
  • Junk Fax Prevention Act - consent for commercial faxing from EBR, as long as opt-out provided.
62
Q

CAN-SPAM apples to?

A
  • to anyone who advertises products or services by electronic mail directed to or originating from the United States.
  • covers the transmission of commercial email messages whose primary purpose is advertising or promoting a product or service.
  • provides a mechanism for legitimate companies to send emails to prospects and respect individual rights to opt out of unwanted communications
63
Q

CAN-SPAM requirements and prohibitions

A
  • Prohibits false or misleading headers
  • Prohibits deceptive subject lines
  • Requires commercial emails to contain a functioning, clearly and conspicuously displayed return email address that allows the recipient to contact the sender
  • Requires all commercial emails to include clear and conspicuous notice of the opportunity to opt out along with a cost-free mechanism for exercising the opt-out, such as by return email or by clicking on an opt-out link
  • Prohibits sending commercial email (following a grace period of 10 business days) to an individual who has asked not to receive future email
  • Requires all commercial email to include (1) clear and conspicuous identification that the message is a commercial message (unless the recipient has provided prior affirmative consent to receive the email) and (2) a valid physical postal address of the sender (which can be a post office box)
  • Prohibits “aggravated violations” relating to commercial emails such as (1) address-harvesting and dictionary attacks, (2) the automated creation of multiple email accounts and (3) the retransmission of commercial email through unauthorized accounts
  • Requires all commercial email containing sexually oriented material to include a warning label (unless the recipient has provided prior affirmative consent to receive the email)
64
Q

CAN-SPAM enforcement

A
  • FTC primarily
  • Penalties up to 40,654 per violation.
  • also commercial email subject to laws banning false or misleading advertising
  • FTC issued rules in 2008
  • State AGs as well and other state officials-
  • ISPs can sue violators for injunction and damages if adversely affected. $250 per violation up to $2M.
    But otherwise no PROA.
  • Certain conduct is criminal - 5 years max
  • Treble damages for willful or aggratated.
  • Pre-empts other laws except deceptive/false advertising laws.
65
Q

CAN-SPAM distinction of “transactional or relationship messages”

A

Primary purpose:

  • Facilitate or confirm an agreed-upon commercial transaction
  • Provide warranty or safety information about a product purchased or used by the recipient
  • Provide certain information regarding an ongoing commercial relationship
  • Provide information related to employment or a related benefit plan
  • Deliver goods or services to which the recipient is entitled under the terms of an agreed-upon transaction
66
Q

Wireless messages under CAN-SPAM

A
  • FCC issued CAN-SPAM rules re. mobile service commerical messages (MSCMs), including commercial texts.
  • MSCM = a commercial electronic mail message that is transmitted directly to a wireless device that is utilized by a subscriber of a commercial mobile service.”
  • not cover phone to phone
67
Q

CAN-SPAM Express Prior Authorization

A
  • prohibits senders from sending MSCMs without subscriber’s “express prior authorization” - for each MSCM.
  • Detailed requirements:

Must be express, not negative option.

Must be prior to sending MSCMs.

No cost to consumer to the authorization or revocation process.

Each authorization must include disclosure stating that:

  • agrees to receive MSCM to device from specific sender
  • may be charged for receiving message
  • may revoke at any time

Sufficiently legible, large type, separate

Each sender - even affiliate and marketing partner - must get separate auths.

Can be written or oral

revocation allowed by same means as auth.

68
Q

Wireless Domain Registry

A

this is to help senders know whether they are sending MSCM or just regular commercial email.
Senders check the registry, and if where they want to send is on it, then they know MSCM rules apply.

Commercial mobile service providers must update list to FCC within 30 days.

69
Q

Telecommunications Act of 1996: Background and Definition of CPNI

A

-Covers telecom companies themselves, not marketing rules

Section 222 governs privacy of consumer information provided to telecom carriers.

  • Customer Proprietary Network Information = access, use, disclosure governed by TeleAct96
  • CPNI= information collected by telecommunications carriers related to their subscribers. This includes subscription information, services used, and network and billing information as well as phone features and capabilities. It also includes call log data such as time, date, destination and duration of calls. Certain PI such as name, telephone number and address is not considered CPNI.
70
Q

TeleAct96 Requirements/Prohibitions

A
  • carriers can use and disclose CPNI only with customer approval or “as required by law” or per an exception.
  • Carriers do not need approval to use, disclose or provide marketing offerings among service categories that customers already subscribe to.

Carriers can also use CPNI for billing and collections, fraud prevention, customer service and emergency services.

  • Carriers must notify law enforcement when CPNI is disclosed in a security breach within 7 days.
  • 2007 CPNI order requires customers to expressly opt-in before carriers share CPNI with joint venture partners and independent contractors for mkting purps.
71
Q

Cable Communications Policy Act of 1984 - Basics

A
  • regulates the notice a cable television provider must furnish to customers, the ability of cable providers to collect PI, the ability of cable providers to disseminate PI and the retention and destruction of PI by cable television providers.

It also provides a private right of action for violations of the aforementioned provisions, and allows for actual or statutory damages, punitive damages and reasonable attorney’s fees and court costs.

The act does not regulate the provision of broadband Internet services via cable because the act defines a “cable service” as “one-way transmission

72
Q

Cable Communications Policy Act - Required disclosure

A

At the time of entering into an agreement to provide cable services, and on an annual basis thereafter, cable service providers are required to give subscribers a privacy notice that “clearly and conspicuously” informs subscribers of: (1) the nature of the PI collected, (2) how such information will be used, (3) the retention period of such information and (4) the manner by which a subscriber can access and correct such information

73
Q

Cable Comm Policy Act Limits on Cable Providers

A
  • only collect PI that is necessary to render cable services or to detect the unauthorized reception of cable services
  • The act limits cable service providers’ right to disseminate PI without the “written or electronic consent” of the subscriber, unless the disclosure is subject to a specified exception.
    A number of exceptions (1) to the extent necessary to render services or conduct other legitimate business activities, (2) subject to a court order with notice to the subscriber or (3) if the disclosure is limited to names and addresses and the subscriber is given an option to opt out
74
Q

Video Privacy Protection Act

A
  • bork inspired
  • Applies to video tape service providers.
  • applies to pre-recorded tapes or similar audio visual materials - so Netflix comes under, eg.
  • prohibits disclosure unless exemptions apply - to consumer, with consumer consent, law enforcement pursuant to legal process, includes only names and addresses and subject matter descriptions if used for mkting, is for order fulfillment.
  • PI destroyed ASAP, no later than 1 year from date no longer necessary.
  • PROA - actual, statutory damages (2500)
  • No pre-emption
  • 2012 amendments allowed for consent to share movie viewing for up to 2 years

-

75
Q

Digital Advertising: Self-Regulatory Codes

A
  • Digital Advertising Alliance (DAA) principles
    important feature is consumer management of opt-outs

Network Advertising Initiative (NAI) code

  • org is exclusively 3rd party ad companies.
  • requires notice and choice
  • limits type of data used for ads
  • substantive limits on members collection, use and transfer re. online behavioral adv.
76
Q

Digital Advertising: FCC Broadband Privacy Rule

A
  • Until reently, companies involved in adv on internet faced reg and enforcement from FTC (see Ch 3).
  • In 2015 FCC reclassified broadband internet service as public utility - net neutrality
  • 2016 court upheld FCC’s authority in this regard.
  • FCC issued privacy rules for brband internet providers in 2016.
    1. required opt-in for uses of sensitive info
    2. allowed use of opt-out for non-sensitive.
    3. allowed inferred consent for providing underlying service and related uses.
    4. guidelines on data security and breach not.

2017 Congress voted under CRA to rescind these.

77
Q

Digital Advertising: California Do Not Track

A

CalOPPA rquire privacy policies to include

  • info on how operator responds to Do Not Track mechanisms
  • whether 3d parties can collect PI about site’s users.
  • The categories of PII collected through the site
  • The categories of third-party entities with whom the operator may share PII or other content
  • How the operator responds to web browsers’ Do Not Track signals or other mechanisms that provide consumers the ability to choose regarding collection of PII about an individual consumer’s online activities overs time and across third-party websites
  • Whether other parties may collect PII about an individual consumer’s online activities over time and across different websites when a consumer uses the operator’s website
78
Q

What is the FCRA?

A

The Fair Credit and Reporting Act. It mandates that accurate and relevant data collection, provides consumers with the ability to access and correct their information, and limits the use of consumer reports to defined permissible purposes.

79
Q

Who does the FCRA regulate?

A

Any consumer reporting agency (CRA) that furnishes a consumer report.

80
Q

Who is a CRA?

A

Any person or entity that compiles or evaluates personal information for the purpose of furnishing consumer reports to 3rd parties for a fee.

81
Q

What is a consumer report?

A
Any communication by a CRA related to an individual that pertains to the person's:
- Creditworthiness
- Credit Standing
- Credit Capacity
- Character
- General Reputation
- Personal characteristics
- Mode of living
and that is used as a factor in establishing a consumer's eligibility for credit, insurance, employment or other business purpose.
82
Q

What are the 4 main requirements under the FCRA that users of consumer reports must meet?

A
  1. Third party data for substantive decision making must be appropriately accurate, current and complete
  2. Consumers must receive notice when third-party data is used to make adverse decisions about them
  3. Consumer reports may be used only for permissible purposes
  4. Consumers must have access to their consumer reports and an opportunity to dispute them or correct any errors.
83
Q

What obligations are CRAs required to provide notice of to users of consumer reports?

A
  1. Users must have a permissible purpose.
  2. Users must provide certifications.
  3. Users must notify consumers when adverse actions are taken.
84
Q
  1. CAN-SPAM requires unsolicited email marketing messages to adhere to what rule regarding unsubscribe methods?

A. Every email must contain a working and visible unsubscribe link.
B. Every message must contain a self-destruct program.
C. Every message must contain a false subject line.
D. Opt-out requests must be met within 10 days of the request.

A

m

85
Q

According to CAN-SPAM, what must unsolicited marketing emails contain?

A. accurate “from” information
B. non-deceptive subject lines
C. a real address for the advertiser
D. pornography

A

l

86
Q

What is considered an “aggravated offense” under CAN-SPAM?

A. email address harvesting
B. Trojan horses
C. worms
D. unsubscribe methods

A

l

87
Q

Many of the telemarketing laws do not apply when the caller and the receiver have an EBR. What does EBR stand for?

A. Entity Building Residual
B. Existing Business Relationship
C. End Back Report
D. Earning Basis Residuals

A

l

88
Q

What is the TCPA?

A

The Telephone Consumer Protection Act of 1991

89
Q

What does the TCPA do?

A

It places restrictions on unsolicited advertising by telephone and facsimile, and updated them in 2012 to address robocalls.

90
Q

What is the TSR?

A

The Telemarketing Sales Rule of 1995 which implemented the Telemarking and Consumer Fraud and Abuse Prevention Act.

91
Q

What is Telemarking under the TSR?

A

A plan, program, or campaign which is conducted to induce the purchase of goods or services or a charitable contribution, by use of one or more telephones and which involves more than one interstate telephone call.

92
Q

What is the US National DNC Registry?

A

The best known FTC TSR Requirement. It provides a means for U.S. residents to register residential and wireless phone numbers that they do not wish to be called for telemarketing purposes.

93
Q

Who enforces the DNC?

A

The FTC, the FCC and state attorneys general enforce the DNC Registry.

94
Q

Violations of the DNC Registry can lead to what?

A

Civil penalties up to 40K per violation, nationwide injunctions, and payment of redress to injured customers.

95
Q

What does the DNC registry require sellers and telemarketers to do?

A
  1. To access the registry prior to making any phone-based solicitations
  2. To update their call lists every 31 days with the new registry information.
96
Q

Who do the DNC rules apply to?

A

For-profit organizations and charitable solicitations placed by for-profit telefunders.

97
Q

Who do the DNC rules not apply to?

A
  1. Nonprofits calling on their own behalf
  2. Calls to customers with an EBR
  3. Inbound calls, provided that there is no “upsell” of additional products or services
  4. Most business-to-business calls
98
Q

What is the Existing Business Relationship (EBR) exception to the DNC rules?

A

Sellers (and telemarketers calling on their behalf) may call a consumer with whom a seller has an established business relationship (EBR), provided the consumer has not asked to be on the seller’s entity-specific DNC list.

99
Q

When is there an EBR?

A
  1. When the consumer has purchased, rented or leased the seller’s goods or services (or completed a financial transaction with the seller) within 18 months preceding a telemarketing call. The 18-month period runs from the date of the last payment, transaction or shipment between the consumer and the seller.
  2. When a prospect has made an application or inquiry regarding the seller’s goods and services. This EBR runs for three months from the date of the person’s inquiry or application.
100
Q

Does the TSR allow sellers and telemarketers to call consumers who consent to receive such calls?

A

Yes, but the consent must be:

  1. in writing
  2. state the number to which calls may be made
  3. included the consumer’s signature
101
Q

What is the DNC Safe Harbor?

A

Guidance that if sellers and telemarketers follow will reduce their liability by not being subject to civil penalties or sanctions.

102
Q

What is CAN-SPAM?

A

The Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003.

103
Q

What does the CAN-SPAM Act do?

A

It created rules for how legitimate organizations send emails, including clear identification of the sender and a simple unsubscribe or opt-out.

104
Q

CAN-SPAM does not apply to:

A

Transactional or relationship messages.

105
Q

What does the act provide to consumers who might sue?

A
  1. Injunctive relief

2. Damages up to $250 per violation, with a max of $2 million

106
Q

CAN-SPAM prohibits senders from sending any MSCMs without…

A

the subscriber’s express prior authorization

107
Q

What act governs the privacy of customer information provided to and obtained by telecommunications carriers?

A

Telecommunications Act of 1996

108
Q

What is CPNI?

A

Customer Proprietary Network Information and is information collected by telecommunications carriers related to their subscribers

109
Q

What are the opt-in and opt-out requirements of the 2007 CPNI order?

A

It requires customers to expressly consent, or opt in, before carriers can share their CPNI with joint venture partners and independent contractors for marketing purposes.

110
Q

What does the 2007 CPNI order require carriers to do?

A
  1. Carriers must notify law enforcement when CPNI is disclosed in a security breach within seven business days of that breach.
  2. Customers must provide a password before they can access their CPNI via telephone or online account services.
111
Q

What is the VPPA?

A

The Video Privacy Protection Act of 1988

112
Q

Videotape are prohibited from what?

A

From disclosing customer PI unless an enumerated exception applies

113
Q

Does the VPPA preempt state law?

A

No

114
Q

Telemarketing Sales Rule (TSR) and the Telephone Consumer Protection Act of 1991 (TCPA)

A

The first enactment of laws limiting unsolicited and automated telemarketing for both telephone and fax communications. Most notably creates a private right of action for those receiving unsolicited faxes, carrying a $500 fine per violation and any damages sustained because of the fax.

115
Q

The Do-Not-Call Registry (DNC)

A

Best known TSR requirement. It provides a means for US residents to register residential and wireless phone numbers that they do not wish to be called for telemarketing purposes.

116
Q

What does the DNC require sellers and telemarketers to do?

A
  • Access the registry prior to making any phone-based solicitations
  • Update their call lists every 31 days with new registry information
117
Q

Who does the TCPA and DNC apply to?

A

For profit organizations and charitable solicitations placed by for profit tele-funders

118
Q

DNC Violations

A

Violations can lead to civil penalties up to $40,000 per violation, nationwide injunctions, and payment of redress to injured customers

119
Q

What does the TCPA not affect?

A
  • Political calls
  • Charitable gifts
  • Debt collectors
  • Surveys
120
Q

Telemarketing Safe Harbor

A
  • Have written procedures
  • Train personnel on those procedures
  • Monitor and enforce compliance
  • Maintain internal do not call list
  • Download the national registry every 31 days
  • Only violate by error
121
Q

Other TSR Requirements

A
  • Call only between 8 am and 9 pm local time to recipient
  • Display valid called ID information
  • Identify themselves and the purpose of their call
  • Connect to a live person within 2 seconds
  • Robocalls, auto dialers, and automated text messages are only permitted with the express consent of customers
122
Q

Combating the Assault of Non-Solicited Pornography and Marketing Act of 2003 (CAN-SPAM)

A

Created rules for how legitimate organizations send emails, including clear identification of the sender and a simple unsubscribe or opt-out.

123
Q

Categories of Email Messages

A
  1. Commercial - messages that advertise or promote a commercial product or service
  2. Transaction – Messages that facilitate or confirm a transaction the recipient has already agreed to
  3. Other – messages that are not commercial, transactional, or relationship
124
Q

Transactional/Relationship Messages

A
  1. Facilitates or confirm a transaction
  2. Provide warranty, recall, safety or security information
  3. Give information about changes in terms of an existing account
  4. Provide information about the employment relationship
  5. Deliver goods or services
125
Q

The Junk Fax Prevention Act of 2005

A

Summary:

i. Prohibits sending unsolicited advertisements by fac
ii. No exception for accidental transmissions
iii. Fines of $500 per page for violations
iv. Fines of $1,500 per page for knowing it is unlawful
v. Consent to receive faxes is implied by an existing business relationship

Detail:
Creates the EBR exception to the US Telephone Consumer Protection Act’s ban of fax-based marketing without consent but contains a requirement that all marketing faxes be accompanied by instructions on how to opt out of further unsolicited communications

126
Q

EBR Consent Requirements under JFPA

A

o Voluntary provision of fax number
o Opt out instructions
o Contact information
o Clear and conspicuous notice

127
Q

Telecommunications Act of 1996 and Customer Proprietary Network Information (CPNI)

A

Governs the privacy of customer information provided and obtained by the telecommunications carriers. Established Customer Proprietary Network Information (CPNI) restrictions. CPNI is information collected by telecommunication carriers related to their subscribers. The 2007 CPNI order established opt-in/opt-out requirements and requires carriers to (1) notify law enforcement when CPNI is discussed in a security breach within 7-days of that breach and (2) customers must provide a password before they can access their CPNI via telephone or online account services

128
Q

Customer Proprietary Network Information (CPNI)

A

Information related to a subscriber’s use of a telecommunications service

129
Q

Pre-Texting Security

A
  1. Require a password or ID

2. Notify customers of account changes

130
Q

Cable Communications Privacy Act of 1984 (CCPA)

A

Summary:

i. Cable operators may not collect PII without consent unless it is necessary to provide service
ii. Providers may not disclose information about consumers unless necessary to provide service
iii. CCPA Privacy Notices
iv. Cable operators must provide consumers with access to PII
v. PII must be destroyed when no longer needed for its intended purposes
vi. CCPA includes a private right of action

Detail:
Protects the personal information of customers of cable service providers. It incorporates the provisions of the OECD Privacy Guidelines (1980), thus providing a model of a comprehensive privacy statute. At the same time, it also represents an example of US sector-by-sector approach to privacy law.

131
Q

Video Privacy Protection Act of 1988 (VPPA)

A

Established that videotapes are prohibited from disclosing customer PI unless an enumerated exception applies.

Note: VPPA does not preempt state law

132
Q

VPPA Permitted Disclosures

A
  1. To the consumer
  2. With consumer’s consent
  3. Pursuant to court order or warrant
  4. To carry out normal business of the provider
133
Q

Video Privacy Protection Act Amendments Act of 2012 (H.R. 6671)

A

Amends provisions of the federal criminal code authorizing a video tape service provider to disclose personally identifiable information concerning any consumer to any person with the informed, written consent of the consumer to: (1) allow such consent to be provided through an electronic means using the Internet; (2) require such consent to be in a form distinct and separate from any form setting forth other legal or financial obligations of the consumer; (3) allow such consent to be given in advance for a set period of time, not to exceed two years or until consent is withdrawn by the consumer, whichever is sooner; and (4) require the video tape service provider to provide an opportunity for the consumer to withdraw such consent on a case-by-case basis or to withdraw from ongoing disclosures, at the consumer’s election.

134
Q

Digital Advertising Alliance

A

A non-profit organization that sets standards for consumer privacy, transparency, and control in online advertising.

135
Q

CARU (Children’s Advertising Review Unit) is an organization responsible for understanding how children are marketed to. It is part of the:

A. Federal Communications Commission
B. Better Business Bureau
C. Federal Trade Commission
D. Office of Consumer Protection

A

B. Better Business Bureau

136
Q

Existing EBR Exception

A
  • When the customer has purchased, rented, or leased the seller’s goods or services (or completed a financial transaction with the seller) within 18 months preceding a telemarking call. The 18-month period runs from the date of last payment, transaction, or shipment between the consumer and the seller
  • When a prospect has made an application or inquiry regarding the seller’s goods or services. This EBR runs 3 months from the date of the person’s inquiry or application
137
Q

CAN-SPAM Rules

A
  1. Don’t use false or misleading header information
  2. Don’t use deceptive subject lines
  3. Identify the message as an advertisement
  4. Tell recipients where you’re located
  5. Provide opt-out instructions
  6. Honor opt-out requests promptly
  7. Monitor what others are doing on your behalf
138
Q

CPNI permitted uses

A
  1. Communications with customers
  2. Billing and collections
  3. Customer service
  4. Fraud prevention
  5. Court order or emergency