Compete, Inc.
Volume 155 · 155 F.T.C. 264
deceptive advertisingprivacy data securityonline internet
Cite this decision
Compete, Inc., 155 F.T.C. 264 (2013). Consumer Law Library, https://consumerlawlibrary.org/decisions/v155-0004
Report an error in this record (decision id v155-0004)
Cited by 0 later FTC decisions
Cites
Text (OCR of the scan at left; may contain errors)
IN THE MATTER OF COMPETE, INC.
CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SEC. 5(A) OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4384; File No. 102 3155 Complaint, February 20, 2013 – Decision, February 20, 2013 This consent order addresses allegations that Respondent Compete, Inc. utilized its web-tracking software to collect personal data in violation Section 5(a) of the Federal Trade Commission Act. Compete is a market research company that collects data from consumers through two products: (1) the Compete Toolbar, which consumers install to gain “instant access” to information about websites as they browse the Internet; and (2) the Consumer Input Panel, which allows the consumers to win rewards from sharing their opinions regarding products and services. Compete represented to consumers that the information it collected would be anonymous and would be limited to browsing behavior and web page addresses. The complaint alleges that Compete misrepresented the extent of its data collection efforts. In fact, Compete captured personal consumer data, including credit card numbers, financial account numbers, security codes, usernames, passwords, and Social Security numbers. The complaint further alleges that Compete failed to implement reasonable and appropriate measures to protect consumer information, and this failure was likely to cause substantial injury to consumers. The consent order requires Compete to disclose fully the information it collects and obtain consumers’ express consent before collecting any personal data. The order further requires that the company delete or anonymize the consumer data it has collected; and that it provide directions to consumers for uninstalling the software. Finally, the order bars Compete from misrepresenting its privacy and data security practices, and requires that it implement a comprehensive information security program with biannual independent third-party audits for the next 20 years. Participants For the Commission: Jamie Hine and Ruth Yodaiken. For the Respondent: Stuart Friedel and Gary Kibel, Davis & Gilbert LLP; Michelle A. Kisloff and Christopher Wolf, Hogan Lovells US LLP.
COMPLAINT The Federal Trade Commission, having reason to believe that Compete, Inc. (“Compete” or “respondent”), a corporation, has COMPETE, INC. 265 Complaint violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges:
1. Compete is a Delaware corporation, with its principal place of business at 501 Boylston Street, Suite 6101, Boston, Massachusetts.
2. The acts and practices of respondent, as alleged herein, have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.
RESPONDENT’S BUSINESS PRACTICES AND REPRESENTATIONS TO CONSUMERS 3. Compete is a market research company that collects data from consumers so that it can, among other things, develop and sell analytical reports about consumer behavior on the Internet. 4. Starting in January 2006, Compete collected data about consumers through two products. The first was the Compete Toolbar (“Toolbar”), which consumers installed to get “instant access” to information about websites as they surfed the Internet, such as the popularity of the websites they visited. (See Compete Toolbar, Exhibit 1, formerly available from www.compete.com). The second product was the Consumer Input Panel, which allowed consumers to win rewards while expressing their opinions to companies about products and services. (See Consumer Input Panel, Exhibit 2, formerly available from www.consumerinput.com).
5. In addition, Compete licensed its data collection software for third parties for their use, including incorporating into their own toolbars or rewards programs. In all cases the data gathered through Compete’s data collection software was sent to Compete. 6. As of the end of October 2011, Compete had collected data from more than 4 million consumers. VOLUME 155 Complaint Compete’s Tracking of Consumers’ Activities 7. When consumers installed the Toolbar, they were prompted to either leave enabled or to disable a feature the company referred to as “Community Share.” (See Exhibit 3). Compete provided the following description of the “Community Share” option:
By joining Community Share, the web pages you visit will be anonymously pooled with the Compete community to provide site trust rankings and analytics.
See Compete Toolbar Setup, Exhibit 3.
Enabling “Community Share” activated Compete’s ability to collect data about the consumer. 8. When consumers signed up for the Consumer Input Panel, Compete made statements such as the following: [W]e measure your behavior as well as your opinions. Consumer Input utilizes a piece of software stored on your computer that anonymously transmits aspects of your Internet browsing behavior so that we can understand the sites, products and services you interact with. See, e.g., Consumer Input Panel Registration, Exhibit 4.
Compete always collected data about consumers who participated in the Consumer Input Panel.
9. In addition, in its general privacy policy, Compete made the following statement about “click-sharing,” which refers to the consumers’ sharing of data with Compete: When you download Compete software, including the Compete Toolbar, you will be given the option of enabling click-sharing. Should you opt-in to COMPETE, INC. 267 Complaint click-sharing you will begin to anonymously share the addresses of the web pages you visit online. See General Compete Privacy Policy, Exhibit 5. 10. In fact, Compete collected more than browsing behavior or addresses of web pages. It collected extensive information about consumers’ online activities and transmitted the information in clear readable text to Compete’s servers. The data collected included information about all websites visited, all links followed, and the advertisements displayed when the consumer was on a given web page. The captured data included details about consumers’ online behavior to the extent that, for example, Compete knew whether a consumer abandoned or completed a purchase after placing an item in an online shopping cart. 11. Moreover, as far back as January 2006, Compete also captured some information consumers communicated on secure web pages (e.g., https), such as credit card numbers, financial account numbers, security codes and expiration dates, usernames, passwords, search terms, or Social Security numbers. 12. Compete’s data capture occurred in the background as a consumer used the Internet; there was no way for consumers – without special software and technical expertise – to discover the extent of the data collection.
Compete’s Filtering of Consumer Data 13. Compete made statements in its general privacy policy about filtering of personal information such as the following: All data is stripped of personally identifiable information before it is transmitted to our servers. Our data collection techniques have been designed to purge personally identifiable information wherever we find it. In addition, as a member of Compete you are assigned a randomly generated user ID ensuring your anonymity.
See General Compete Privacy Policy, Exhibit 5. VOLUME 155 Complaint 14. Similarly, Compete made statements in its Consumer Input Panel privacy policy and Frequently Asked Questions such as the following:
Inadvertently, the URL information we collect and license sometimes contains personal information about Internet users. Potentially, a name, address, email address, or similar information that an Internet user enters into a Web page can become part of the URL that is transmitted to us and stored in our databases. While we have no control over what information third party websites put into their URLs or where they put it, we make every commercially viable effort to purge our databases of any personally identifiable information. The data collection software uses a proprietary rules engine to search through all URLs, before transmitting them to its database, to strip out any such personally identifiable information. We do not disclose the contents of individual URLs stored in our databases so we will not release or use this information. Further, we aggregate data on hundreds of thousands of users before supplying data to our clients, thereby ensuring that an individual’s privacy remains intact at all times.
See Consumer Input Privacy Policy, Exhibit 6. In addition, the data collection software uses a proprietary rules engine to search through all URLs, before transmitting them directly to its database, to strip out any such personally identifiable information, thus ensuring your privacy. See Consumer Input Panel, Frequently Asked Questions, Exhibit 7.
15. Compete used data filters to prevent the collection and use of some sensitive data. However, those filters were too narrow and improperly structured to avoid collecting such data. For instance, a filter was designed to prevent the collection of COMPETE, INC. 269 Complaint personal identification numbers for financial accounts, and would have prevented collection of that data if a website used the field name “PIN.” However, the filter would not have prevented such collection if a website used similar field names such as “personal ID” or “security code.” In addition, Compete failed to implement a simple, commonly used, algorithm to screen out credit card numbers, and Compete filtered some types of information only after that information had been transmitted in clear text via the Internet to its servers.
Compete’s Data Security Practices 16. In addition to the representations made about the collection of data, Compete made statements about the security of user data such as the following:
We take reasonable security measures to protect against unauthorized access to or unauthorized alteration, disclosure or destruction of personal information. These measures include internal reviews of our data collection, storage and processing practices and security practices. See General Compete Privacy Policy, Exhibit 5. 17. Respondent engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for consumer information collected and transmitted by Compete. Among other things, respondent:
a. created unnecessary risks of unauthorized access to consumer information by transmitting sensitive information from secure web pages, such as financial account numbers and security codes, in clear readable text over the Internet;
b. failed to design and implement reasonable information safeguards to control the risks to customer information; and VOLUME 155 Complaint c. failed to use readily available, low-cost measures to assess and address the risk that the data collection software would collect sensitive consumer information that it was not authorized to collect.
18. These security failures resulted in the creation of unnecessary risk to consumers’ personal information. Compete transmitted the information it gathered – including sensitive information – over the Internet in clear readable text. Tools for capturing data in transit over unsecured wireless networks, such as those often provided in coffee shops and other public spaces, are commonly available, making such clear-text data vulnerable to interception. The misuse of such information, particularly financial account information and Social Security numbers, can facilitate identity theft and related consumer harms. 19. After flaws in Compete’s data collection practices were revealed publicly in January 2010, Compete upgraded its filters, added new algorithms to screen out information such as credit card numbers, and began encrypting data in transit. The company stopped distributing the Compete Toolbar to new customers, and began to distribute its Consumer Input Panel software to new customers through third parties rather than directly. It continued to collect and use consumer data, however. VIOLATIONS OF THE FTC ACT COUNT 1 20. Through the means described in Paragraphs 7-9, respondent has represented, expressly or by implication, that its products would collect and transmit information about the websites consumers visited.
21. Respondent failed to disclose that its products would also collect and transmit much more extensive information about the Internet behavior that occurs on consumers’ computers, and information consumers provided in secure sessions when interacting with third-party websites, shopping carts, and online accounts – such as credit card and financial account numbers, security codes and expiration dates, and Social Security numbers consumers entered into such web pages. These facts would be COMPETE, INC. 271 Complaint material to consumers. Respondent’s failure to disclose these facts, in light of the representations made, was, and is, a deceptive act or practice.
COUNT 2 22. Through the means described in Paragraphs 13-14, respondent has represented, expressly or by implication, that it stripped all personal information out of the data it collected before transmitting it from consumers’ computers. 23. In truth and in fact, Compete did not strip all personal information out of the data before transmitting it from consumers’ computers. As described in Paragraph 15 the consumer-side filters were too narrow and improperly structured to effectively scrub personal data before transmission to Compete’s servers. Therefore, the representation set forth in Paragraph 22 was, and is, false or misleading and constitutes a deceptive act or practice. COUNT 3 24. Through the means described in Paragraph 16, respondent has represented, expressly or by implication, that it employs reasonable and appropriate measures to protect data obtained from consumers from unauthorized access.
25. In truth and in fact, as described in Paragraphs 10-11, 15 and 17-18, respondent did not implement reasonable and appropriate measures to protect data obtained from consumers from unauthorized access. Therefore, the representation set forth in Paragraph 24 was, and is, false or misleading and constitutes a deceptive act or practice.
COUNT 4 26. As described in Paragraphs 10-12, 15 and 17-18, respondent’s failure to employ reasonable and appropriate measures to protect consumer information – including credit card and financial account numbers, security codes and expiration dates, and Social Security numbers – caused or was likely to cause substantial injury to consumers that was not offset by VOLUME 155 Complaint countervailing benefits to consumers or competition and was not reasonably avoidable by consumers. This practice was, and is, an unfair act or practice.
27. The acts and practices of respondent as alleged in this complaint constitute unfair or deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act.
THEREFORE, the Federal Trade Commission this twentieth day of February, 2013, has issued this complaint against respondent.
By the Commission.
COMPETE, INC.
Complaint EXHIBIT 1 Compete Toals Cue compete Toolbar , Browser Comearuon Moogle /Wetviloes fhodule Potasaa Horkapage icpet 4 Site Protite Extension i | A Bowne Companies Compete Toolbar Tha Compete Tecdber automatically creates threw alerts fer ewery web slike you wisi: ! parepelt~ soprded soaheas te Hist Stes Ap eu aepetience a caler web by warning you of potentially etabeiaie. yi pare, phishing) ae sibes.
Hike Peofiies tell you haw popular the wah dite, 9s rant, ancihow feet if a growing Geabt ight automatically tghba up if tare ara ary spacial promotions oc coupons thar Can save you money on the web ste GES o ee jee Fe TE Gs warnioty dlr availa manera 1 “UNO ony first ory ang fie comeee Tobe, J saved 20% at one of ery Greate citing stores and recever Free STARR or ey ata > Anes, Barion, USA “ie.no hoe Swe Seg nore conidoet anc’ sieving ans panwaee Abtrpevice tae aT apres ee bea Sat aT ae eo Doe Thad items e frosted fsend.” - Call, Ontario, Cenate "The Comumanie: Teathay 1e fascaneling, IPs dai PET aci to bare arated aecess fo fas evornepen es Ubrgerse Whe abteniel,”
Mickwel, Chranpe Couity, Lisa VOLUME 155 Complaint EXHIBIT 2 COMPETE, INC. 275 Complaint EXHIBIT 3 ie omni. leenbar Setup mp dete Select Preferenmes Please review the advanced features options explained below. | tay sane. Ceanenla aN chisi, heb Peigla val le wl bu ancien ccied at | the Compete community to provide ste trust rankings and analytics, To learn more about privacy and the Toolbar, read the Toolbar Privacy Statement Comenunity Share is currently enabled, os, leave Community Shara enabled (0) Na, switch Community Share to disabled VOLUME 155 Complaint EXHIBIT 4
VOLUME 155 Complaint EXHIBIT 5 COMPETE, INC. 279 Complaint EXHIBIT 5 a Third-Party Web Beacoms: We use third-party web beacona fren Yahoo! to help analyze where visitors go and what they de while visiting our website. Yahoo! may aleo use anonymous information about your visits to thia and other websites in order to improve its products and services and provide advertisements about goods and services of interest to you. If you would like more information about thia practice and to know your choices about not having thia information uged by Yahoo!, click here, Conkies and IF Addregsos To serve you Faster and with better quality, we uae “‘ecckiee’ technology. Cookies are amall bite sf coeds, usually etored on a user's computoe hoed dedse, which canble a Webaite to "personalize" itaelf for each user. We generally use cookies to reduce the time it takes for pages to load on your computer and to agsist with customer tracking. Customer tracking (or "click-#tream") date collected by us is used te optimize your experience by learning whether or not you successfully used Compete.com, Cookies are not tied to your personal information.
Clear Gita Me enploy a software technology called clear gifa@a la.k.a. Web Beacons) that help us Retl@r manage SOnbene on cur Bite by informing us what content is effective. Clear gifs are tiny graphics with a unique identifier, similar in function te cookies, and are used to track the online movement of Web usera. Clear gife are mot tied to users’ permonally identifiable information, We aleq wee clear gifs in our HTML-based ¢-maile to let us know which ¢-mails the recipdenta have opemed. This allows us to gauge the effectiveness of eattain communications.
Leg information When you use Compete services, cur servers automatically record infermation thar your brovaer genda whenever you visit 4 webaite, These server logs may include information such ae your web request, [Internet Proterol addraga, browser type, browser language, the date and time of your request and ome or more cookies that may uniquely identify your browser, Click-sharing When you download Compete software, including the Compete Toolbar, you will be given the option of enabling click-sharing. Should you opt-in to click-sharing you will begin co anonymously share the addresses of the web pages you vieit online. All data is stripped of pereonally identifiable inforwation before it if tranamitted to cur servers, Our data collection techniques have been designed to purge personally identifiable infermation wherever wo find it, In addition, aa a member of Compate you are agaioned a randomly generated user ID ensuring your anonymity. The only contact information aaseclated with your user ID ig your registration e-mail, which we only use to send you service updates and other requested communications that you have signed up to receive from us. We do not control what information third party websites put into thedr URLs or where Ehey put it. The URL information wa collect amd license may sometimes contain personal information about users, However, we make every commercially viable effort to purge persomally identifiable information wherever we find it. Compete's software application uses A proprietary rulea engine to search through all Urbs to strip out any such personally identifiable information before tranamitting the data to cur databases. To pretect your privacy, it's our policy never te disclose or release the contents of individual URL stored on our gerverg, Further, a11 our services aggregate data acroaa 411 ugera thereby enzuring that your privacy i# protected at all times 4s such information does mot identify you individually. To calculate more robust metrica for our users, we alao license URL and demographic data lage, gender, household income, geographical lecarian, ate.) fram multiple scurces including [Spa and ASPs. We hemor the privacy of our Members and the privacy policies of our licensors and do mot knowingly collect or license personally idencifiablea information Erom merbere of licensors. Again, Compete aggregates data on multiple users before supplying any data, thereby ensuring an individual's privacy. VOLUME 155 Complaint EXHIBIT 5 COMPETE, INC. 281 Complaint EXHIBIT 6 Ors Tera . My Account « Log In Home Member Services FAQ Benetits of Joining Privacy Statementregistration for Effective date: October 7, 2008 Protecting your privacy is our highest priority, Consumer Input is designed to be an anonymous research forum. As such, we go to great lengths to ensure that your anonymity will remain intact. Qur data collection techniques have been designed to purge personally identifiable information from our databases. Your email address will be used to contact you if you've wom a prize or to alert you to additional research opportunities. We will never sell your email address to a third party, nor will we ever solicit you for sales purposes of any kind.
Other than your email address, we will not collect information that can be tied to you as an individual. In fact, we will only require your name if you are selected as a winner in one of our cash drawings. We will not license, publish, or sell any information collected from our panelists that can be tied to an individual user. Nor will we use such information as part of a targeted marketing program. We offer our clients aggregate data conceming online consumer behavior by collecting information from the panel and, also, by licensing URL and demographic data (age, pender, household income, geographical location, ete.) from sources such as ISP's and browser companions. We honor the privacy of our panelists and the privacy policies of our licensors and do not knowingly collect or license personally identifiable information from our panelists of licensors, Inadvertently, the URL information we collect and license sometimes contains personal information about Internet users. Potentially, a name, address, email address, or similar information that an [nternet user enters into a Web pave can become part of the URL that is transmitted to us and stored in our databases. While we have no control over what information third party websites put into their URLs or where they put il, we make every commercially viable effort to purge our databases of any personally identifiable information. The data collection software uses a proprietary rules engine to search through all URLs, before transmitting them to its VOLUME 155 Complaint EXHIBIT 6 COMPETE, INC. 283 Complaint EXHIBIT 7 Consumer Input * What are the system requirements for the Consumer Input Software? * How can | be removed from your mailing list? * How can! remove the Consumer Input Software from my machine? *How do! address any technical problems | encounter during a survey? How do | change my e-mail address or update my profile? To update your profile, change your e-mail address, or be removed from our mailing list, Click Here top Why am | having trouble logging in? The most common Issue with logging in relates to web browser cookies. Consumer Input site requires that your browser accept cookies. Please enable cookies in your browser and attempt to log in again. Hf you still cannot log In, you can e-mail Consumer Input at [email protected]. top How does the panel work? In conjunction with traditional opinion and research surveys, Consumer Input uses proprietary software to anonymously record web browsing patterns. These patterns are merged with the patterns of thousands of Internet users and analyzed in aggregate to understand the trends that will influence major marketing decisions in a variety of industries. We will not license, publish, or sell any information collected from our panelists that can be tied to an individual user. In addition, the data collection software uses a proprietary rules engine to search through all URLs, before transmitting them to its database, to strip out any such personally identifiable information, thus ensuring your privacy. For more information, please consult the privacy statement, top VOLUME 155 Complaint EXHIBIT 7 COMPETE, INC. 285 Complaint EXHIBIT 7 Consumer Input Consumer Ingut allows participation by those in the United States who are 18 years of age or older. Our registration process denies membership to underage panelists. top What are the system requirements for the Consumer Input Software? Windows:
* Windows XP Service Pack 2 or Windows Vista * Internet Explorer Version 6.0 or greater, or Mozilla Firefox Version 2.0 or greater Macintosh:
* Mac OS X Version 10.2 or greater * Mozilla Firefox Version 2.0 or greater. top How can! be removed from your mailing list? To update your profile, change your e-mail address, or be removed from our mailing list, Click Here top How can | remove the Consumer Input Software from my machine? Microsoft Internet Explorer:
1, From the Windows control panel, select "Add / Remove Programs” 2. Select the "Consumer Input Software” entry. 3. Select the "Remove" button.
VOLUME 155 Decision and Order DECISION AND ORDER The Federal Trade Commission having initiated an investigation of certain acts and practices of the respondent named in the caption hereof, and the respondent having been furnished thereafter with a copy of a draft Complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge the respondent with violation of Section 5 of the Federal Trade Commission Act, 15 U.S.C. § 45, et seq.; The respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), an admission by the respondent of all the jurisdictional facts set forth in the aforesaid draft Complaint, a statement that the signing of said Consent Agreement is for settlement purposes only and does not constitute an admission by respondent that the law has been violated as alleged in such Complaint, or that the facts as alleged in such Complaint, other than jurisdictional facts, are true, and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it has reason to believe that the respondent has violated the Federal Trade Commission Act, and that a Complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such Consent Agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, and having carefully considered the comments filed by interested persons, now in further conformity with the procedure described in Commission Rule 2.34, 16 C.F.R. § 2.34, the Commission hereby issues its Complaint, makes the following jurisdictional findings, and enters the following Order: 1. Compete, Inc., is a Delaware corporation with its principal place of business at 501 Boylston Street, Suite 6101, Boston, Massachusetts.
2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of respondent, and the proceeding is in the public interest. COMPETE, INC. 287 Decision and Order ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:
1. “Affected Consumers” shall mean persons who, prior to the date of issuance of this order, downloaded and installed any Data Collection Agent, including but not limited to the Compete Toolbar and Consumer Input Panel software.
2. “Clearly and prominently” shall mean as follows: a. In textual communications (e.g., printed publications or words displayed on the screen of a computer or a mobile device), the required disclosures are of a type, size, and location sufficiently noticeable for an ordinary consumer to read and comprehend them, in print that contrasts highly with the background on which they appear; b. In communications disseminated orally or through audible means (e.g., radio or streaming audio), the required disclosures are delivered in a volume and cadence sufficient for an ordinary consumer to hear and comprehend them;
c. In communications disseminated through video means (e.g., television or streaming video), the required disclosures are in writing in a form consistent with subparagraph (A) of this definition and shall appear on the screen for a duration sufficient for an ordinary consumer to read and comprehend them;
d. In communications made through interactive media, such as the Internet, online services, and software, the required disclosures are unavoidable and presented in a form consistent with VOLUME 155 Decision and Order subparagraph (A) of this definition, in addition to any audio or video presentation of them; and e. In all instances, the required disclosures are presented in an understandable language and syntax; in the same language as the predominant language that is used in the communication; and with nothing contrary to, inconsistent with, or in mitigation of the disclosures used in any communication of them.
3. “Collected Information” shall mean any information transmitted, on or before the date of issuance of this order, from a computer by a Data Collection Agent to any computer server owned by, operated by, or operated for the benefit of respondent. 4. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. 5. “Computer” shall mean any desktop, laptop computer, tablet, handheld device, telephone, or other electronic product or device that has a platform on which to download, install, or run any software program, code, script, or other content and to play any digital audio, visual, or audiovisual content.
6. “Data Collection Agent” shall mean any software program, including any application; created, licensed or distributed, directly or through a Third Party, by respondent; installed on consumers’ computers, whether as a standalone product or as a feature of another product; and used to record, or transmit information about any activity occurring on that computer, unless: (a) the activity involves transmission of information related to the configuration of the software program or application itself; (b) the transmission is limited to information about whether the program is functioning as intended; or (c) the activity involves a consumer’s interactions with respondent’s websites and/or forms. The Compete COMPETE, INC. 289 Decision and Order Toolbar and the Consumer Input Panel software, for example, are both Data Collection Agents. 7. “Personal Information” shall mean individually identifiable information from or about an individual consumer including, but not limited to: (a) a first and last name; (b) a home or other physical address, including street name and name of city or town; (c) an email address or other online contact information, such as an instant messaging user identifier or a screen name; (d) a telephone number; (e) a Social Security number; (f) a driver’s license number or other government-issued identification number; (g) a bank account, debit card, or credit card account number; (h) a persistent identifier, such as a customer number held in a “cookie” or static IP address; or (i) a biometric record.
8. “Third Party” shall mean any individual or entity other than respondent, except that a third party shall not include a service provider of respondent that: a. Only uses or receives information collected by or on behalf of respondent for and at the direction of the respondent and no other individual or entity; b. Does not disclose the information, or any individually identifiable information derived from it, to any individual or entity other than respondent; and c. Does not use the information for any other purpose.
9. Unless otherwise indicated, “respondent” shall mean Compete, Inc., and its successors and assigns, and its officers, agents, representatives, and employees. VOLUME 155 Decision and Order I.
IT IS ORDERED that respondent, directly or indirectly, including through any contract, agreement, license, sale, or arrangement with any Third Party, is prohibited from: A. Collecting any information from any Data Collection Agent made available to consumers directly by respondent after the date of service of this order, unless prior to such collection respondent has: 1. Disclosed to the consumer clearly and prominently, and prior to the display of and on a separate screen from, any “end user license agreement,” “privacy policy,” “terms of use” page, or similar document: a. all the types of information that will be collected, including, but not limited to, if applicable, a statement that the information includes consumer transactions (both completed and incomplete) or communications in forms, online accounts, web-based email accounts, or search engine pages, and whether the information includes personal, financial or health information; and b. how the information is to be used, including if it is shared with any Third Party; and 2. Obtained express affirmative consent from the consumer to the collection, use or sharing of the information.
B. Collecting any information from any Data Collection Agent made available to consumers by a Third Party after the date of service of this order, unless prior to such collection respondent has provided the disclosures and obtained the consent described in subpart A(1-2), or has both required the Third Party by contract to do so, and monitored compliance with such contractual provisions.
COMPETE, INC. 291 Decision and Order C. Collecting any information from any Data Collection Agent that was made available to consumers before the date of service of this order, unless it has made the disclosures and obtained the express affirmative consent described in subpart A(1-2) or: 1. It has made the disclosure required by Part II(A)(3); and 2. It does not use information collected from an Affected Consumer by a Data Collection Agent, except in an aggregate and/or anonymous form that does not disclose, report, or otherwise share any individually identifiable information.
D. Using any Collected Information gathered on or after February 1, 2010, unless it has obtained express affirmative consent from the consumer to the use of the Collected Information, or 1. It does not use the Collected Information, except in an aggregate and/or anonymous form that does not disclose, report, or otherwise share any individually identifiable information; and 2. It does not otherwise access any Affected Consumer’s personal information that was collected by a Data Collection Agent.
E. Making any material change from stated practices about collection, use or sharing of such information, unless it has obtained express affirmative consent from the consumer.
Provided, however, this Part will not apply to the collection, use or sharing of information as reasonably necessary: 1) to comply with applicable law, regulation, or legal process; 2) to enforce respondent’s terms of use; 3) to detect, prevent, or mitigate fraud or security vulnerabilities; 4) for configuration of the software program or application itself; or 5) to determine whether the program is functioning as intended.
VOLUME 155 Decision and Order II.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns, shall:
A. Notify Affected Consumers: 1) that they have or had a Data Collection Agent installed on their Computers, and that this software collected and transmitted information to or on behalf of respondent, listing the categories of personal information that were, or could have been, transmitted by a Data Collection Agent; and 2) how to permanently disable and/or uninstall the Data Collection Agent. Notification shall be by each of the following means:
1. On or before thirty (30) days after the date of service of this order and for two (2) years after the date of service of this order, posting of a clear and prominent notice on the websites of Compete, Inc., and its successors and assigns;
2. On or before thirty (30) days after the date of service of this order and for three (3) years after the date of service of this order, informing Affected Consumers who complain or inquire about the privacy or security of a Data Collection Agent; and 3. Beginning only once notification described in both subparts II(A)(1) and (2) above have commenced, and completed on or before sixty (60) days after the date of service of this order, providing clear and prominent notice to consumers via Affected Consumers’ computers on which a Data Collection Agent is operating, through the browser, software upgrade or similar technology, that:
a. is visible until the consumer has taken action in response to the notice;
b. includes a hyperlink and/or the address for a website of Compete, Inc., and its successors or assigns; and COMPETE, INC. 293 Decision and Order c. includes the name of the company from whom the consumer obtained the Data Collection Agent, or the brand name (as marketed to the consumer) of the software or application containing the Data Collection Agent, and an explanation that Compete provides technology for the specific Data Collection Agent. B. Provide prompt and free support with clear and prominent contact information to help consumers disable and/or uninstall a Data Collection Agent. For two (2) years after the date of service of this order, this support shall include toll-free, telephonic and electronic mail support.
III.
IT IS FURTHER ORDERED that before entering into any contract, agreement, license, sale, or arrangement with any Third Party in connection with any Data Collection Agent made available to consumers by such Third Party, Compete, Inc., and its successors and assigns, shall serve the Third Party with a copy of this order. For any existing contract, agreement, license, sale, or arrangement with any Third Party in connection with any Data Collection Agent made available to consumers by such Third Party, respondent shall serve the Third Party with a copy of this order within 30 days of service of this order. IV.
IT IS FURTHER ORDERED that respondent, directly or through any corporation, subsidiary, division, website, or other device, in connection with the offering of any service or product in or affecting commerce, shall not make any representation, in any manner, expressly or by implication, about the extent to which respondent collects, maintains and protects the security, privacy, confidentiality, or integrity of any information collected from or about consumers, unless the representation is true, and non-misleading.
VOLUME 155 Decision and Order V.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns; directly or through any corporation, subsidiary, division, website, or other device; in connection with its advertising, marketing, promotion, or offering of any product or service, in or affecting commerce; shall no later than the date of service of this order, establish and implement, and thereafter maintain a comprehensive information security program that is reasonably designed to protect the security, privacy, confidentiality, and integrity of personal information collected from or about consumers. Such program, the content and implementation of which must be fully documented in writing, shall contain administrative, technical, and physical safeguards appropriate to respondent’s size and complexity and the nature and scope of respondent's activities, and the sensitivity of the personal information collected from or about consumers, including:
A. The designation of an employee or employees to coordinate and be accountable for the information security program;
B. The identification of material internal and external risks that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of personal information and an assessment of the sufficiency of any safeguards in place to control these risks. At a minimum, this risk assessment should include consideration of risks in each area of relevant operation, including, but not limited to: (1) employee training and management; (2) information systems, including network and software design, information processing, storage, transmission, and disposal; and (3) prevention, detection, and response to attacks, intrusions, account takeovers, or other systems failures;
C. The design and implementation of reasonable safeguards to control the risks identified through risk assessment, and regular testing or monitoring of the COMPETE, INC. 295 Decision and Order effectiveness of the safeguards' key controls, systems, and procedures;
D. The development and use of reasonable steps to select and retain service providers capable of appropriately safeguarding personal information such service providers receive from respondent or obtain on respondent's behalf, and the requirement, by contract, that such service providers implement and maintain appropriate safeguards; and E. The evaluation and adjustment of respondent’s information security program in light of the results of the testing and monitoring required by subpart C, any material changes to respondent's operations or business arrangements, or any other circumstances that respondent knows or has reason to know may have a material impact on the effectiveness of its information security program.
VI.
IT IS FURTHER ORDERED that, in connection with its compliance with Part V of this order, Compete, Inc., and its successors and assigns, shall obtain initial and biennial assessments and reports (“Assessments”) from a qualified, objective, independent third-party professional, who uses procedures and standards generally accepted in the profession. Professionals qualified to prepare such Assessments shall be: a person qualified as a Certified Information System Security Professional (CISSP) or as a Certified Information Systems Auditor (CISA); a person holding Global Information Assurance Certification (GIAC) from the SysAdmin, Audit, Network, Security (SANS) Institute; or a similarly qualified person or organization approved by the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580. The reporting period for the Assessments shall cover: (1) the first one hundred and eighty (180) days after service of the order for the initial Assessment, and (2) each two (2) year period thereafter for twenty (20) years after service of the order for the biennial Assessments. Each Assessment shall:
VOLUME 155 Decision and Order A. Set forth the specific administrative, technical, and physical safeguards that respondent has implemented and maintained during the reporting period; B. Explain how such safeguards are appropriate to respondent's size and complexity, and the nature and scope of respondent's activities, and the sensitivity of the personal information collected from or about consumers;
C. Explain how the safeguards that have been implemented meet or exceed the protections required by Part V of this order; and D. Certify that respondent's security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of personal information is protected and has so operated throughout the reporting period. Each Assessment shall be prepared and completed within sixty (60) days after the end of the reporting period to which the Assessment applies. Respondent shall provide the initial Assessment to the Associate Director for Enforcement, Bureau of Consumer Protection, Federal Trade Commission, Washington, D.C. 20580, within ten (10) days after the Assessment has been prepared. All subsequent biennial Assessments shall be retained by respondent until the order is terminated and provided to the Associate Director of Enforcement within ten (10) days of request.
VII.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns, shall, within fourteen (14) days after the date of service of this order, delete or destroy, Collected Information in respondent’s custody or control that was collected prior to February 1, 2010, unless otherwise directed by a representative of the Commission.
COMPETE, INC. 297 Decision and Order VIII.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns, shall, for a period of five (5) years after the last date of dissemination of any representation covered by this order, maintain and upon request make available to the Commission for inspection and copying:
A. All advertisements, labeling, packaging and promotional material containing the representation; B. All materials relied upon in disseminating the representation;
C. All tests, reports, studies, surveys, demonstrations, or other evidence in its possession or control that contradict, qualify, or call into question the representation, or the basis relied upon for the representation, including complaints and other communications with consumers or with governmental or consumer protection organizations; and D. All acknowledgments of receipt of this order, obtained pursuant to Part IX.
E. All notices related to service of the order on Third Parties, pursuant to Part III.
F. All materials demonstrating compliance with Part I(B), including all contracts and measures to monitor compliance.
Moreover, for a period of three (3) years after the date of preparation of each Assessment required under Part VI of this order, respondent shall maintain and upon request make available to the Commission for inspection and copying all materials relied upon to prepare the Assessment, whether prepared by or on behalf of the respondent, including but not limited to all plans, reports, studies, reviews, audits, audit trails, policies, training materials, and assessments, for the compliance period covered by such Assessment.
VOLUME 155 Decision and Order IX.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns, shall deliver a copy of this order to: (1) all current and future principals, officers, and directors; and (2) all current and future managers who have responsibilities with respect to the subject matter of this order, and shall secure from each such person a signed and dated statement acknowledging receipt of the order, with any electronic signatures complying with the requirements of the E-Sign Act, 15 U.S.C. § 7001 et seq. Respondent shall deliver this order to current personnel within thirty (30) days after the date of service of the order, and to future personnel within thirty (30) days after the person assumes such position or responsibilities.
X.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns, shall notify the Commission at least thirty (30) days prior to any change in respondent that may affect compliance obligations arising under this order, including but not limited to, a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor company; the creation or dissolution of a subsidiary (including an LLC), parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in respondent’s name or address. Provided, however, that with respect to any proposed change about which respondent learns less than thirty (30) days prior to the date such action is to take place, respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a representative of the Commission, all notices required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, DC 20580, with the subject line FTC v. Compete. Provided, however, that, in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of such notices is contemporaneously sent to the Commission at [email protected]. COMPETE, INC. 299 Decision and Order XI.
IT IS FURTHER ORDERED that Compete, Inc., and its successors and assigns, shall, within sixty (60) days after service of this order, and at such other times as the FTC may require, file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form in which respondent has complied with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, respondent shall submit additional true and accurate written reports.
XII.
This order will terminate on February 20, 2033, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part of this order that terminates in less than twenty (20) years;
B. This order’s application to any respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.
Provided, further, that if such complaint is dismissed or a federal court rules that the respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as though the complaint had never been filed, except that this order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal. By the Commission.
VOLUME 155 Analysis to Aid Public Comment ANALYSIS OF THE CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, an agreement containing a consent order applicable to Compete, Inc. (“Compete”).
The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. Compete develops software for tracking consumers as they shop, browse and interact with different websites across the Internet. As alleged in the Commission’s complaint, Compete offered one version of its tracking software as the Compete Toolbar, which would provide consumers with information about websites as they surfed the web, such as information about the popularity of the websites they visited. Separately, Compete offered consumers membership in its Consumer Input Panel: consumers could win rewards while participating in surveys about products and services. As part of the registration process for the Consumer Input Panel, consumers would install tracking software. In addition, Compete licensed its tracking software to third parties, such as Upromise, Inc., which was the subject of a recent FTC enforcement action. (See Upromise, Inc., at http://www.ftc.gov/os/caselist/1023116/index.shtm.) The Commission’s complaint involves the advertising, marketing and operation of tracking software. According to the FTC complaint, while Compete represented to consumers that the various forms of software would collect information about the web sites consumers visited, its failure to disclose the full extent of data collected through tracking software was deceptive. The complaint alleges that Compete’s tracking software collected the names of all websites visited; all links followed; advertisements displayed when websites were visited; and information that consumers entered into some web pages (e.g., credit card and COMPETE, INC. 301 Analysis to Aid Public Comment financial account numbers, usernames, passwords, and search terms), including secure web pages.
According to the FTC complaint, Compete misrepresented its privacy and security practices, including that: 1) it stripped all personal information out of the data it collected before transmitting it from consumers’ computers; and 2) it employed reasonable and appropriate measures to protect data gathered from consumers from unauthorized access. The complaint alleges that these claims were false and thus violate Section 5 of the FTC Act. In addition, the FTC complaint alleges that Compete engaged in a number of practices that, taken together, failed to provide reasonable and appropriate security for the personal information it collected and maintained. The complaint alleges that, among other things, Compete: 1) transmitted sensitive information from secure web pages, such as financial account numbers and security codes, in clear readable text; 2) did not design and implement reasonable safeguards to control risks to consumer information; and 3) did not use readily available, low-cost measures to assess and address the risk that its software would collect sensitive consumer information it was not authorized to collect. The complaint alleges that Compete’s failure to employ reasonable and appropriate measures to protect consumer information – including credit card and financial account numbers, security codes and expiration dates, and Social Security numbers – was unfair. Tools for capturing data in transit, for example over unsecured wireless networks such as those often provided in coffee shops and other public spaces, are commonly available, making such clear-text data vulnerable to interception. The misuse of such information – particularly financial account information and Social Security numbers – can facilitate identity theft and related consumer harms.
The complaint alleges that after flaws in Compete’s data collection practices were revealed publicly in January 2010, Compete upgraded its filters, added new algorithms to screen out information such as credit card numbers, and began encrypting data in transit.
VOLUME 155 Analysis to Aid Public Comment The proposed order contains provisions designed to prevent Compete from engaging in future practices similar to those alleged in the complaint. For purposes of the proposed consent order, we call such tracking software a “Data Collection Agent.” Part I applies to collection and use of data from any Data Collection Agent, whether already downloaded or to be downloaded in the future, and is tailored to address distribution by both Compete and third parties. Specifically Parts I.A. and B. of the proposed order apply to Data Collection Agents installed after the date of service of the order. Part I.A. prohibits Compete from collecting data through a Data Collection Agent unless a consumer has given express affirmative consent to such collection, after being provided with a separate, clear and prominent notice about all the types of information that will be collected, as well as a description of how the information is to be used, including any sharing with third parties. Part I.B. ensures these same protections apply when a Data Collection Agent is made available by a third party, and requires that Compete must either provide notice and obtain consent, or require the third party to do so and monitor the third party’s compliance. In addition, Parts I.C. and D. of the proposed order limit the collection and use of data from consumers who already have downloaded a Data Collection Agent (i.e., before the date of service of the order) to aggregate and anonymous data, absent notice and affirmative express consent. Part I.E. requires Compete to obtain express affirmative consent before it can make any material changes to its practices for collection or sharing of personal information. Part II.A. of the proposed order requires Compete to provide corrective notice to consumers who had previously installed a Data Collection Agent. Compete must inform consumers about the categories of personal information collected and transmitted by the software, and how to uninstall it. Part II.B. requires the company to provide for two years phone and e-mail support to assist consumers who seek to disable or uninstall a Data Collection Agent.
Part III of the proposed order requires Compete to provide a copy of the order to third parties with whom it has now, or will have in the future, any agreement in connection with any Data Collection Agent made available by the third party. COMPETE, INC. 303 Analysis to Aid Public Comment Part IV of the proposed order prohibits the company from making any misrepresentations about the extent to which it maintains and protects the security, privacy, confidentiality, or integrity of any information collected from or about consumers. Part V of the proposed order requires Compete to maintain a comprehensive information security program that is reasonably designed to protect the security, confidentiality, and integrity of information (whether in paper or electronic format) about consumers. The security program must contain administrative, technical, and physical safeguards appropriate to Compete’s size and complexity, the nature and scope of its activities, and the sensitivity of the information. Specifically, the proposed order requires Compete to:
• designate an employee or employees to coordinate and be accountable for the information security program; • identify material internal and external risks to the security, confidentiality, and integrity of personal information that could result in the unauthorized disclosure, misuse, loss, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks;
• design and implement reasonable safeguards to control the risks identified through risk assessment, and regularly test or monitor the effectiveness of the safeguards’ key controls, systems, and procedures;
• develop and use reasonable steps to select and retain service providers capable of appropriately safeguarding personal information they receive from Compete or obtain on behalf of Compete, and require service providers by contract to implement and maintain appropriate safeguards; and • evaluate and adjust its information security programs in light of the results of testing and monitoring, any material changes to operations or business arrangements, or any other circumstances that it knows or has reason to know VOLUME 155 Analysis to Aid Public Comment may have a material impact on its information security program.
Part VI of the proposed order requires Compete to obtain within 180 days after service of the order, and biennially thereafter for 20 years, an assessment and report from a qualified, objective, independent third-party professional, certifying, among other things, that: 1) it has in place a security program that provides protections that meet or exceed the protections required by the proposed order; and 2) its security program is operating with sufficient effectiveness to provide reasonable assurance that the security, confidentiality, and integrity of personal information is protected and has so operated throughout the reporting period. Part VII requires Compete to destroy all consumer data collected by a Data Collection Agent before February 2010. Part VIII requires Compete to retain documents relating to its compliance with the order. Part IX requires that it deliver copies of the order to persons with responsibilities relating to the subject matter of the order. Parts X, XI, and XII of the proposed order are further reporting and compliance provisions. Part X ensures notification to the FTC of changes in corporate status. Part XI mandates that Compete submit a compliance report to the FTC within 60 days, and periodically thereafter as requested. Part XII provides that the order will terminate after 20 years, with certain exceptions.
The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the proposed order’s terms in any way.
PPG ARCHITECTURAL FINISHES, INC. 305 Complaint