Consumer Law LibrarySearchBy decadeBy respondentBy topicBy outcomeDataAbout

Pinger, Inc.

Volume 160 · 160 F.T.C. 516

Citation
160 F.T.C. 516
Docket
C-4550
Complaint
2015-09-29
Decision
2015-09-29
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
mobile apps
Outcome
consent order entered
Relief
cease_and_desist; recordkeeping; compliance_reporting
Order term (years)
5
Commission counsel
The respondent, its attorney, and counsel
Source
Original volume PDF
Original PDF
This decision as a PDF

privacy data securityonline internet

Cite this decision

Pinger, Inc., 160 F.T.C. 516 (2015). Consumer Law Library, https://consumerlawlibrary.org/decisions/v160-0010

Report an error in this record (decision id v160-0010)

Order status: active_until:2035-09-29. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF PINGER, INC.

CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATION OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket C-4550; File No. 152 3137 Complaint, September 29, 2015 – Decision, September 29, 2015 This consent order addresses Pinger, Inc.’s misleading representation of their participation in the Safe Harbor privacy framework agreed upon by the U.S. and the European Union (“EU”). Pinger, Inc. develops apps for mobile phones and devices. ‘Textfree’, is the proposed defendant’s most popular application. The Commission's complaint alleges that Pinger, Inc. falsely represented that it was a "current'' participant in the Safe Harbor Frameworks when, in fact, from March 2014 until April 2015, Pinger, Inc. was not a "current'' participant in the Safe Harbor Frameworks. The Commission’s complaint alleges that in March 2011, Pinger, Inc. submitted its self-certification to the Safe Harbor Frameworks. Pinger, Inc. did not renew its self-certification in March 2014 and Commerce subsequently updated Pinger, Inc.'s status to "not current" on its public website. In May 2015, Pinger, Inc. recertified with Commerce and is now a current participant in the Safe Harbor Frameworks. The consent order prohibits Pinger, Inc. from making misrepresentations about its membership in any privacy or security program sponsored by the government or any other self-regulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework. As well as, requiring Pinger, Inc. to supply and retain documents relating to their compliance with the Order for a five-year period. The proposed order mandates that Pinger, Inc. submit an initial compliance report to the FTC, and make available to the FTC subsequent reports.

Participants For the Commission: Monique Einhorn For the Respondent: Lydia Parnes, Wilson, Sonsini, Goodrich & Rosati COMPLAINT The Federal Trade Commission, having reason to believe that Pinger, Inc., a corporation, has violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges: PINGER, INC. 517 Complaint 1. Respondent Pinger, Inc. is a Delaware corporation with its principal office or place of business at 97 S. 2nd Street, Suite 210, San Jose, CA 95113.

2. Respondent develops apps for mobile phones and tablets. 3. The acts and practices of respondent as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act.

4. Respondent has set forth on its website, http://www.pinger.com/content/company/privacy_policy.html, privacy policies and statements about its practices, including statements related to its participation in the Safe Harbor privacy frameworks agreed upon by the U.S. and the European Union (“U.S.-EU Safe Harbor Framework”) and the U.S. and Switzerland (“U.S.-Swiss Safe Harbor Framework”). The Frameworks 5. The U.S.-EU Safe Harbor Framework provides a method for U.S. companies to transfer personal data outside of Europe that is consistent with the requirements of the European Union Directive on Data Protection (“Directive”). Enacted in 1995, the Directive sets forth European Union (“EU”) requirements for privacy and the protection of personal data. Among other things, it requires EU Member States to implement legislation that prohibits the transfer of personal data outside the EU, with exceptions, unless the European Commission (“EC”) has made a determination that the recipient jurisdiction’s laws ensure the protection of such personal data. This determination is referred to commonly as meeting the EU’s “adequacy” standard. 6. To satisfy the EU adequacy standard for certain commercial transfers, the U.S. Department of Commerce (“Commerce”) and the EC negotiated the U.S.-EU Safe Harbor Framework, which went into effect in 2000. The U.S.-EU Safe Harbor Framework allows U.S. companies to transfer personal data lawfully from the EU. To join the U.S.-EU Safe Harbor Framework, a company must self-certify to Commerce that it complies with seven principles and related requirements that have been deemed to meet the EU’s adequacy standard. VOLUME 160 Complaint 7. Companies under the jurisdiction of the U.S. Federal Trade Commission (“FTC”), as well as the U.S. Department of Transportation, are eligible to join the U.S.-EU Safe Harbor Framework. A company under the FTC’s jurisdiction that claims it has self-certified to the Safe Harbor principles, but failed to self-certify to Commerce, may be subject to an enforcement action based on the FTC’s deception authority under Section 5 of the FTC Act.

8. The U.S.-Swiss Safe Harbor Framework is identical to the U.S.-EU Safe Harbor Framework and is consistent with the requirements of the Swiss Federal Act on Data Protection. 9. Commerce maintains a public website, www.export.gov/safeharbor, where it posts the names of companies that have self-certified to the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework (“Safe Harbor Frameworks”). The listing of companies indicates whether their self-certification is “current” or “not current” and a date when recertification is due. Companies are required to recertify every year in order to retain their status as “current” members of the Safe Harbor Frameworks.

Violations of Section 5 of the FTC Act 10. In March 2011, respondent submitted to Commerce a selfcertification of compliance with the Safe Harbor Frameworks. 11. In March 2014, respondent did not renew its selfcertification to the Safe Harbor Frameworks, and Commerce subsequently updated respondent’s status to “not current” on its public website. In May 2015, respondent renewed its selfcertification to the Safe Harbor Frameworks and respondent’s status was changed to “current” on Commerce’s website. 12. Since at least March 2011, respondent has disseminated or caused to be disseminated privacy policies and statements on the http://www.pinger.com/content/company/privacy policy.html website, including, but not limited to, the following statements: Pinger complies with the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor PINGER, INC. 519 Complaint Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information from European Union member countries and Switzerland (the "Safe Harbor Frameworks"). Pinger has certified that it adheres to the Safe Harbor Privacy Principles of notice, choice, onward transfer, security, data integrity, access, and enforcement. To learn more about the Safe Harbor program, and to view Pinger's certification, please visit http://www.export.gov/safeharbor/ 13. Through the means described in Paragraph 12, respondent represents, expressly or by implication, that it is a “current” participant in the U.S.-EU Safe Harbor and U.S.-Swiss Safe Harbor Frameworks.

14. In truth and in fact, from March 2014 through April 2015, respondent was not a “current” participant in the U.S.-EU Safe Harbor and U.S.-Swiss Safe Harbor Frameworks. Therefore, the representation set forth in Paragraph 13 was false and misleading. 15. The acts and practices of respondent as alleged in this complaint constitute deceptive acts or practices, in or affecting commerce, in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission this twentyninth day of September 2015, has issued this complaint against respondent.

By the Commission.

VOLUME 160 Decision and Order DECISION AND ORDER The Federal Trade Commission (“Commission” or “FTC”), having initiated an investigation of certain acts and practices of the respondent named in the caption hereof, and the respondent having been furnished thereafter with a copy of a draft complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge respondent with violations of the Federal Trade Commission Act (“FTC Act”), 15 U.S.C. § 45 et seq.;

The respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), which includes: a statement by respondent that it neither admits nor denies any of the allegations in the draft complaint, except as specifically stated in the Consent Agreement, and, only for purposes of this action, admits the facts necessary to establish jurisdiction; and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the respondent violated the FTC Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, now in further conformity with the procedure prescribed by Commission Rule 2.34, 16 C.F.R. § 2.34, the Commission hereby issues its complaint, makes the following jurisdictional findings, and enters the following Order: 1. Respondent Pinger, Inc., is a Delaware corporation with its principal office or place of business at 97 S. 2nd Street, Suite 210, San Jose, CA 95113. 2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the respondent, and the proceeding is in the public interest. PINGER, INC. 521 Decision and Order ORDER DEFINITIONS For purposes of this Order, the following definitions shall apply:

A. Unless otherwise specified, “respondent” shall mean Pinger, Inc., and its successors and assigns. B. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. I.

IT IS ORDERED that respondent and its officers, agents, representatives, and employees, whether acting directly or indirectly, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, in or affecting commerce, shall not misrepresent in any manner, expressly or by implication, the extent to which respondent is a member of, adheres to, complies with, is certified by, is endorsed by, or otherwise participates in any privacy or security program sponsored by the government or any other self-regulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework and the U.S.-Swiss Safe Harbor Framework.

II.

IT IS FURTHER ORDERED that respondent shall maintain and upon request make available to the Federal Trade Commission for inspection and copying, a print or electronic copy of, for a period of five (5) years from the date of preparation or dissemination, whichever is later, all documents relating to compliance with this order, including but not limited to: A. all advertisements, promotional materials, and any other statements containing any representations covered by this order, with all materials relied upon in disseminating the representation; and VOLUME 160 Decision and Order B. any documents, whether prepared by or on behalf of respondent, that call into question respondent’s compliance with this order.

III.

IT IS FURTHER ORDERED that respondent shall deliver a copy of this order to all current and future principals, officers, directors, and managers, and to all current and future employees, agents, and representatives having responsibilities relating to the subject matter of this order. Respondent shall deliver this order to such current personnel within thirty (30) days after service of this order, and to such future personnel within thirty (30) days after the person assumes such position or responsibilities. Respondent must secure a signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons receiving a copy of the order pursuant to this section. IV.

IT IS FURTHER ORDERED that respondent shall notify the Commission within fourteen (14) days of any change in the corporation(s) that may affect compliance obligations arising under this order, including, but not limited to: a dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor corporation; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Unless otherwise directed by a representative of the Commission in writing, all notices required by this Part shall be emailed to [email protected] or sent by overnight courier (not the U.S. Postal Service) to: Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580. The subject line must begin: In re Pinger, Inc., FTC File No. 1523137.

V.

IT IS FURTHER ORDERED that respondent, within sixty (60) days after the date of service of this order, shall file with the PINGER, INC. 523 Decision and Order Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, it shall submit an additional true and accurate written report.

VI.

This order will terminate on September 29, 2035, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. any Part in this order that terminates in fewer than twenty (20) years;

B. this order’s application to any respondent that is not named as a defendant in such complaint; and C. this order if such complaint is filed after the order has terminated pursuant to this Part.

Provided, further, that if such complaint is dismissed or a federal court rules that respondent did not violate any provision of the order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order as to such respondent will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.

By the Commission.

VOLUME 160 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission ("FTC" or "Commission") has accepted, subject to final approval, a consent agreement applicable to Pinger, Inc. (“Pinger”).

The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement's proposed order. This matter concerns alleged false or misleading representations that Pinger made to consumers concerning its participation in the Safe Harbor privacy frameworks agreed upon by the U.S. and the European Union ("EU") and the U.S. and Switzerland (collectively, "Safe Harbor Frameworks"). The Safe Harbor Frameworks allow U.S. companies to transfer data outside the EU and Switzerland consistent with EU and Swiss law. To join the Safe Harbor Frameworks, a company must self-certify to the U.S. Department of Commerce ("Commerce") that it complies with a set of principles and related requirements that have been deemed by the European Commission and Switzerland as providing "adequate" privacy protection. These principles include notice, choice, onward transfer, security, data integrity, access, and enforcement. Commerce maintains a public website, www.export.gov/safeharbor, where it posts the names of companies that have self-certified to the Safe Harbor Frameworks. The listing of companies indicates whether their self-certification is "current" or "not current." Companies are required to re-certify every year in order to retain their status as "current" members of the Safe Harbor Frameworks. Pinger develops apps for mobile phones and tablets. According to the Commission's complaint, Pinger has set forth on its website, www.pinger.com/content/company/privacy_policy .html, privacy policies and statements about its practices, including statements related to its participation in the Safe Harbor Frameworks.

PINGER, INC. 525 Analysis to Aid Public Comment The Commission's complaint alleges that Pinger falsely represented that it was a "current'' participant in the Safe Harbor Frameworks when, in fact, from March 2014 until April 2015, Pinger was not a "current'' participant in the Safe Harbor Frameworks. The Commission’s complaint alleges that in March 2011, Pinger submitted its self-certification to the Safe Harbor Frameworks. Pinger did not renew its self-certification in March 2014 and Commerce subsequently updated Pinger's status to "not current" on its public website. In May 2015, Pinger recertified with Commerce and is now a current participant in the Safe Harbor Frameworks.

Part I of the proposed order prohibits Pinger from making misrepresentations about its membership in any privacy or security program sponsored by the government or any other selfregulatory or standard-setting organization, including, but not limited to, the U.S.-EU Safe Harbor Framework and the U.S.- Swiss Safe Harbor Framework.

Parts II through VI of the proposed order are reporting and compliance provisions. Part II requires Pinger to retain documents relating to its compliance with the order for a five-year period. Part III requires dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part IV ensures notification to the FTC of changes in corporate status. Part V mandates that Pinger submit an initial compliance report to the FTC, and make available to the FTC subsequent reports. Part VI is a provision “sunsetting” the order after twenty (20) years, with certain exceptions. The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the order’s terms in any way.

VOLUME 160 Complaint

← 160 F.T.C. 449 · 160 F.T.C. 526 →