Consumer Law LibrarySearchBy decadeBy respondentBy topicBy outcomeDataAbout

DDC Laboratories, Inc.

Volume 157 · 157 F.T.C. 1734

Citation
157 F.T.C. 1734
Docket
C-4467
Complaint
2014-06-19
Decision
2014-06-19
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
DNA testing
Outcome
consent order entered
Relief
cease_and_desist; recordkeeping; compliance_reporting; notice_to_customers
Order term (years)
20
Commission counsel
The respondent, its attorney, and counsel
Source
Original volume PDF
Original PDF
This decision as a PDF

deceptive advertisingprivacy data security

Cite this decision

DDC Laboratories, Inc., 157 F.T.C. 1734 (2014). Consumer Law Library, https://consumerlawlibrary.org/decisions/v157-0048

Report an error in this record (decision id v157-0048)

Order status: active_until:2034-06-19. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF DDC LABORATORIES, INC.

D/B/A DNA DIAGNOSTICS CENTER CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4467; File No. 142 3024 Complaint, June 19, 2014 – Decision, June 19, 2014 This consent order addresses DDC Laboratories, Inc.’s alleged false or misleading representations that DDC made to consumers concerning its participation in the Safe Harbor privacy framework agreed upon by the U.S. and the European Union. The complaint alleges that DDC, through its statement, falsely represented that it was a “current” participant in the Safe Harbor when, in fact, from November 2011 until November 2013, DDC was not a “current” participant in the Safe Harbor. The consent order prohibits DDC from making misrepresentations about its membership in any privacy or security program sponsored by the government or any other self-regulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework.

Participants For the Commission: Jessica Lyon, Katie Race Brin, and Katherine White.

For the Respondent: Jim Fishkin, Dechert LLP. COMPLAINT The Federal Trade Commission, having reason to believe that DDC Laboratories, Inc. (“Respondent” or “DDC”), a corporation, has violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges:

1. Respondent DDC Laboratories, Inc., also doing business as DNA Diagnostics Center, is an Ohio corporation with its principal office or place of business at One DDC Way, Fairfield, OH 45014.

DDC LABORATORIES, INC. 1735 Complaint 2. Respondent is a leading provider of private DNA testing and focuses primarily on testing to establish paternity and other familial relationships.

3. The acts and practices of Respondent as alleged in this Complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.

4. Respondent has set forth on its website, www.dnacenter.com, privacy policies and statements about its practices, including a statement related to its adherence to the Safe Harbor privacy framework agreed upon by the U.S. and the European Union (“U.S.-EU Safe Harbor Framework”). The Safe Harbor Framework 5. The U.S.-EU Safe Harbor Framework provides a method for U.S. companies to transfer personal data outside of Europe that is consistent with the requirements of the European Union Directive on Data Protection (“Directive”). Enacted in 1995, the Directive sets forth European Union (“EU”) requirements for privacy and the protection of personal data. Among other things, it requires EU Member States to implement legislation that prohibits the transfer of personal data outside the EU, with exceptions, unless the European Commission (“EC”) has made a determination that the recipient jurisdiction’s laws ensure the protection of such personal data. This determination is referred to commonly as meeting the EU’s “adequacy” standard. 6. To satisfy the EU adequacy standard for certain commercial transfers, the U.S. Department of Commerce (“Commerce”) and the EC negotiated the U.S.-EU Safe Harbor Framework, which went into effect in 2000. The U.S.-EU Safe Harbor Framework allows U.S. companies to transfer personal data lawfully from the EU. To join the U.S.-EU Safe Harbor Framework, a company must self-certify to Commerce that it complies with seven principles and related requirements that have been deemed to meet the EU’s adequacy standard. 7. Companies under the jurisdiction of the U.S. Federal Trade Commission (“FTC”), as well as the U.S. Department of VOLUME 157 Complaint Transportation, are eligible to join the U.S.-EU Safe Harbor Framework. A company under the FTC’s jurisdiction that claims it has self-certified to the Safe Harbor principles, but failed to self-certify to Commerce, or subsequently renew its Safe Harbor certification, may be subject to an enforcement action based on the FTC’s deception authority under Section 5 of the FTC Act. 8. Commerce maintains a public website, www.export.gov /safeharbor, where it posts the names of companies that have selfcertified to the U.S.-EU Safe Harbor Framework. The listing of companies indicates whether their self-certification is “current” or “not current” and a date when recertification is due. Companies are required to re-certify every year in order to retain their status as “current” members of the Safe Harbor Framework. Violations of Section 5 of the FTC Act 9. In November 2007, Respondent submitted to Commerce a self-certification of compliance to the Safe Harbor Framework. Respondent subsequently renewed its self-certification in November 2008, November 2009, and November 2010. 10. In November 2011, Respondent did not renew its selfcertification to the Safe Harbor, and Commerce subsequently updated Respondent’s status to “not current” on its public website. In November 2013, Respondent renewed its selfcertification to the Safe Harbor Framework and Respondent’s status was changed to “current” on Commerce’s website. 11. Since at least November 2007, Respondent has disseminated or caused to be disseminated a privacy policy and statement on the www.dnacenter.com website, including the following statement:

DDC and its subsidiaries, branches, divisions, and business units in the United States adhere to the Safe Harbor Principles published by the U.S. Department of Commerce with respect to all such data. DDC LABORATORIES, INC. 1737 Decision and Order 12. Through the means described in Paragraph 11, Respondent represents, expressly or by implication, that it is a “current” participant in the U.S.-EU Safe Harbor Framework. 13. In truth and in fact, from November 2011 until November 2013, Respondent was not a “current” participant in the U.S.-EU Safe Harbor Framework. Therefore, the representation set forth in Paragraph 12 was, false and misleading. 14. The acts and practices of Respondent as alleged in this Complaint constitute deceptive acts or practices, in or affecting commerce, in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission this nineteenth day of June, 2014, has issued this Complaint against Respondent.

By the Commission, Commissioner McSweeny not participating.

DECISION AND ORDER The Federal Trade Commission (“Commission” or “FTC”), having initiated an investigation of certain acts and practices of the respondent named in the caption hereof, and the respondent having been furnished thereafter with a copy of a draft complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge respondent with violations of the Federal Trade Commission Act (“FTC Act”), 15 U.S.C. § 45, et seq.;

The respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), which includes: a statement by VOLUME 157 Decision and Order respondent that it neither admits nor denies any of the allegations in the draft complaint, except as specifically stated in the Consent Agreement, and, only for purposes of this action, admits the facts necessary to establish jurisdiction; and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the respondent violated the FTC Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, and having duly considered the comments received from interested persons pursuant to section 2.34 of its Rules, now in further conformity with the procedure prescribed Commission Rule 2.34, 16 C.F.R. § 2.34, the Commission hereby issues its complaint, makes the following jurisdictional findings, and enters the following Order: 1. Respondent DDC Laboratories, Inc., also doing business as DNA Diagnostics Center, is an Ohio corporation with its principal office or place of business at One DDC Way, Fairfield, OH 45014. 2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the respondent, and the proceeding is in the public interest. ORDER DEFINITIONS For purposes of this Order, the following definitions shall apply:

A. Unless otherwise specified, “respondent” shall mean DDC Laboratories, Inc., and its successors and assigns.

B. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. DDC LABORATORIES, INC. 1739 Decision and Order I.

IT IS ORDERED that respondent and its officers, agents, representatives, and employees, whether acting directly or indirectly, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, in or affecting commerce, shall not misrepresent in any manner, expressly or by implication, the extent to which respondent is a member of, adheres to, complies with, is certified by, is endorsed by, or otherwise participates in any privacy or security program sponsored by the government or any other self-regulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework.

II.

IT IS FURTHER ORDERED that respondent shall maintain and upon request make available to the Federal Trade Commission for inspection and copying, a print or electronic copy of, for a period of five (5) years from the date of preparation or dissemination, whichever is later, all documents relating to compliance with this order, including but not limited to: A. all advertisements, promotional materials, and any other statements containing any representations covered by this order, with all materials relied upon in disseminating the representation; and B. any documents, whether prepared by or on behalf of respondent, that call into question respondent’s compliance with this order.

III.

IT IS FURTHER ORDERED that respondent shall deliver a copy of this order to all current and future principals, officers, directors, and managers, and to all current and future employees, agents, and representatives having responsibilities relating to the subject matter of this order. Respondent shall deliver this order to such current personnel within thirty (30) days after service of this VOLUME 157 Decision and Order order, and to such future personnel within thirty (30) days after the person assumes such position or responsibilities. For any business entity resulting from any change in structure set forth in Part IV, delivery shall be at least ten (10) days prior to the change in structure. Respondent must secure a signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons receiving a copy of the order pursuant to this section.

IV.

IT IS FURTHER ORDERED that respondent shall notify the Commission at least thirty (30) days prior to any change in the corporation(s) that may affect compliance obligations arising under this order, including, but not limited to: a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Provided, however, that, with respect to any proposed change in the corporation(s) about which respondent learns fewer than thirty (30) days prior to the date such action is to take place, respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a representative of the Commission in writing, all notices required by this Part shall be emailed to [email protected] or sent by overnight courier (not the U.S. Postal Service) to: Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580. The subject line must begin: In re DDC Laboratories, Inc., FTC File No. 1423024. V.

IT IS FURTHER ORDERED that respondent, and its successors and assigns, within sixty (60) days after the date of service of this order, shall file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of DDC LABORATORIES, INC. 1741 Decision and Order receipt of written notice from a representative of the Commission, it shall submit an additional true and accurate written report. VI.

This order will terminate on June 19, 2034, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. any Part in this order that terminates in fewer than twenty (20) years;

B. this order’s application to any respondent that is not named as a defendant in such complaint; and C. this order if such complaint is filed after the order has terminated pursuant to this Part.

Provided, further, that if such complaint is dismissed or a federal court rules that respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order as to such respondent will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.

By the Commission, Commissioner McSweeny not participating.

VOLUME 157 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission (“FTC” or “Commission”) has accepted, subject to final approval, a consent agreement applicable to DDC Laboratories, Inc. (“DDC”). The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. This matter concerns alleged false or misleading representations that DDC made to consumers concerning its participation in the Safe Harbor privacy framework (“Safe Harbor”) agreed upon by the U.S. and the European Union (“EU”) (“U.S.-EU Safe Harbor Framework”). It is among several actions the Commission is bringing to enforce the promises that companies make when they certify that they participate in the Safe Harbor Framework. The Safe Harbor framework allows U.S. companies to transfer data outside the EU consistent with European law. To join the Safe Harbor framework, a company must self-certify to the U.S. Department of Commerce (“Commerce”) that it complies with a set of principles and related requirements that have been deemed by the European Commission as providing “adequate” privacy protection. These principles include notice, choice, onward transfer, security, data integrity, access, and enforcement. Commerce maintains a public website, www.export.gov/safeharbor, where it posts the names of companies that have self-certified to the Safe Harbor framework. The listing of companies indicates whether their self-certification is “current” or “not current.” Companies are required to re-certify every year in order to retain their status as “current” members of the Safe Harbor framework.

DDC is a leading provider of private DNA testing and focuses primarily on testing to establish paternity and other familial relationships. According to the Commission’s complaint, since at DDC LABORATORIES, INC. 1743 Analysis to Aid Public Comment least November 2007, DDC has set forth on its website, www.dnacenter.com, a privacy policy and statement about its practices, including a statement related to its participation in the U.S-EU Safe Harbor Framework.

The Commission’s complaint alleges that DDC, through its statement, falsely represented that it was a “current” participant in the Safe Harbor when, in fact, from November 2011 until November 2013, DDC was not a “current” participant in the Safe Harbor. The Commission’s complaint alleges that in November 2007, DDC submitted a Safe Harbor self-certification. DDC subsequently renewed its self-certification in November 2008, November 2009, and November 2010. DDC did not renew its self-certification in November 2011 and Commerce subsequently updated DDC’s status to “not current” on its public website. In November 2013, DDC renewed its self-certification to the Safe Harbor and its status was changed to “current” on Commerce’s website.

Part I of the proposed order prohibits DDC from making misrepresentations about its membership in any privacy or security program sponsored by the government or any other selfregulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework. Parts II through VI of the proposed order are reporting and compliance provisions. Part II requires DDC to retain documents relating to its compliance with the order for a five-year period. Part III requires dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part IV ensures notification to the FTC of changes in corporate status. Part V mandates that DDC submit an initial compliance report to the FTC, and make available to the FTC subsequent reports. Part VI is a provision “sunsetting” the order after twenty (20) years, with certain exceptions. The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the order’s terms in any way.

VOLUME 157 Complaint

← 157 F.T.C. 1722 · 157 F.T.C. 1744 →