Consumer Law Library

T&M Protection Resources, LLC

Volume 169 · 169 F.T.C. 213

Citation
169 F.T.C. 213
Docket
C-4709
Complaint
2020-03-16
Decision
2020-03-16
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
Security and investigative services
Outcome
consent order entered
Relief
cease_and_desist; compliance_reporting; recordkeeping
Order term (years)
20
Source
Original volume PDF
Original PDF
This decision as a PDF

privacy data securitydeceptive advertising

Cite this decision

T&M Protection Resources, LLC, 169 F.T.C. 213 (2020). Consumer Law Library, https://consumerlawlibrary.org/decisions/v169-0015

Report an error in this record (decision id v169-0015)

Order status: active_until:2040-03-16. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF T&M PROTECTION RESOURCES, LLC CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4709; File No. 192 3092 Complaint, March 16, 2020 – Decision, March 16, 2020 This consent order addresses T&M Protection Resources, LLC’s violation of Section 5 of the Federal Trade Commission Act by disseminating privacy policies and statements claiming Respondent participated in the EU-U.S. Privacy Shield framework. The complaint alleges that Respondent obtained Privacy Shield certification in 2017, but did not renew its participation after the certification expired in 2018, nor did it withdraw and affirm its commitment to protect any personal information it had acquired. After its certification lapsed, Respondent continued to claim it participated in the EU-U.S. Privacy Shield framework. The consent order requires Respondent must not misrepresent the extent to which Respondent participates in any privacy or security program sponsored by a government or any self-regulatory or standard-setting organization.

Participants For the Commission: Megan Cox and Andy Hasty.

For the Respondents: Eddie Holman and Lydia Parnes, Wilson Sonsini Goodrich & Rosati. COMPLAINT The Federal Trade Commission (“FTC”), having reason to believe that T&M Protection Resources, LLC, a limited liability corporation, has violated the Federal Trade Commission Act (“FTC Act”), and it appearing to the Commission that this proceeding is in the public interest, alleges:

1. Respondent T&M Protection Resources, LLC is a Delaware limited liability corporation with its principal office or place of business at 230 Park Avenue, Suite 440, New York, New York 10169.

2. Respondent provides background check, security and investigative services. In connection with providing services relating to background checks, Respondent obtained personal data about individuals in the EU.

3. The acts and practices of Respondent as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the FTC Act. 4. Respondent has set forth on its website, https://www.tmprotection.com/privacypolicy, privacy policies and statements about its practices, including statements related to its participation in the EU-U.S. Privacy Shield framework agreed upon by the U.S. government and the European Commission.

VOLUME 169 Complaint Privacy Shield 5. The EU-U.S. Privacy Shield framework (“Privacy Shield”) was designed by the U.S. Department of Commerce (“Commerce”) and the European Commission to provide a mechanism for U.S. companies to transfer personal data outside of the EU that is consistent with the requirements of the European Union data protection legislation. The EU General Data Protection Regulation, passed in May 2016 and enforced since May 2018 (replacing the 1995 EU Data Protection Directive), sets forth EU requirements for privacy and the protection of personal data. Among other things, it requires EU Member States to implement legislation that prohibits the transfer of personal data outside the EU, with exceptions, unless the European Commission has made a determination that the recipient jurisdiction’s laws ensure the protection of such personal data. This determination is referred to commonly as meeting the EU’s “adequacy” standard. Any company that voluntarily withdraws or lets its self-certification lapse must take steps to affirm to Commerce that it is continuing to protect the personal information it received while it participated in the program.

6. To satisfy the EU adequacy standard for certain commercial transfers, Commerce and the European Commission negotiated the EU-U.S. Privacy Shield framework, which went into effect in July 2016. The EU-U.S. Privacy Shield framework allows companies to transfer personal data lawfully from the EU to the United States. To join the EU-U.S. Privacy Shield framework, a company must self-certify to Commerce that it complies with the Privacy Shield Principles and related requirements that have been deemed to meet the EU’s adequacy standard. Any company that participates in Privacy Shield must verify, at least once a year, through self-assessment or outside compliance review, that the assertions it makes about its Privacy Shield privacy practices are true and that those privacy practices have been implemented. 7. Companies under the jurisdiction of the FTC, as well as the U.S. Department of Transportation, are eligible to join the EU-U.S. Privacy Shield framework. A company under the FTC’s jurisdiction that claims it has self-certified to the Privacy Shield Principles, but failed to self-certify to Commerce or failed to comply with the Privacy Shield Principles, may be subject to an enforcement action based on the FTC’s deception authority under Section 5 of the FTC Act. 8. Commerce maintains a public website, https://www.privacyshield.gov/welcome, where it posts the names of companies that have self-certified to the EU-U.S. Privacy Shield framework. The listing of companies, https://www.privacyshield.gov/list, indicates whether the company’s self-certification is current.

9. Respondent has disseminated or caused to be disseminated privacy policies and statements on the https://www.tmprotection.com/privacy-policy website, including, but not limited to, the following statements:

EU-U.S. Privacy Shield Framework T&M Protection Resources, LLC complies with the EU-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European T&M PROTECTION RESOURCES, LLC 215 Complaint Union to the United States. T&M Protection Resources, LLC has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern… 10. Although Respondent obtained Privacy Shield certification in 2017 to support its background check services, it did not complete the steps necessary to renew its participation in the EU-U.S. Privacy Shield after that certification expired one year later, in 2018, nor did it withdraw and affirm its commitment to protect any personal information it had acquired while in the program.

11. Commerce warned the company to take down its claims that it participated in Privacy Shield unless and until such time as it completed the steps necessary to renew its participation in the EU.-U.S. Privacy Shield framework. Respondent did not do so. 12. After its certification lapsed, Respondent continued to claim, as indicated in paragraph 9, that it participated in the EU-U.S. Privacy Shield framework. 13. The Privacy Shield Principles include Supplemental Principle 7, which requires any company that participates in Privacy Shield to verify, at least once a year, through self-assessment or outside compliance review, that the assertions it makes about its Privacy Shield privacy practices are true and that those privacy practices have been implemented. The verification statement must be signed by a corporate officer or the outside reviewer and is required to be made available on request to the FTC or Department of Transportation, whoever has unfair and deceptive practices jurisdiction over the company.

14. Respondent is under the jurisdiction of the FTC. During the 2017-18 period that Respondent was certified to participate in Privacy Shield, Respondent failed to comply with the requirement to obtain, through self-assessment or outside compliance review, an attested verification statement that the assertions it had made about its Privacy Shield privacy practices during the time it participated in the program were true and that those privacy practices had been implemented.

Count 1-Privacy Misrepresentation 15. As described in Paragraph 9, Respondent represented, directly or indirectly, expressly or by implication, that it was a current participant in the EU-U.S Privacy Shield framework.

16. In fact, as described in Paragraphs 10-12, after its certification lapsed, Respondent was not a current participant in the EU-U.S. Privacy Shield framework. Therefore, the representation set forth in Paragraph 15 is false or misleading. VOLUME 169 Decision and Order Count 2-Misrepresentation Regarding Verification 17. As described in Paragraph 9, Respondent represented that it complied with the EU- U.S. Privacy Shield principles.

18. In fact, as described in Paragraphs 13-14, Respondent failed to comply with the verification requirement during the time it participated in the program. Therefore, the representation set forth in Paragraph 17 is false or misleading. Count 3-Misrepresentation Regarding Continuing Obligations 19. As described in Paragraph 9, Respondent represented that it complied with the EU- U.S. Privacy Shield framework principles. These principles include a requirement that if it ceased to participate in the EU-U.S. Privacy Shield framework, it must affirm to Commerce that it will continue to apply the principles to personal information that it received during the time it participated in the program.

20. In fact, as described in Paragraph 10, Respondent did not affirm to Commerce that it will continue to apply the principles to personal information that it received during the time it participated in the program. Therefore, the representation set forth in Paragraph 19 is false or misleading.

Violations of Section 5 of the FTC Act 21. The acts and practices of Respondent as alleged in this complaint constitute deceptive acts or practices, in or affecting commerce, in violation of Section 5(a) of the Federal Trade Commission Act.

THEREFORE, the Federal Trade Commission this sixteenth day of March 2020, has issued this complaint against Respondent.

By the Commission.

DECISION The Federal Trade Commission (“Commission”) initiated an investigation of certain acts and practices of the Respondent named above in the caption. The Commission’s Bureau of Consumer Protection (“BCP”) prepared and furnished to Respondent a draft Complaint. BCP proposed to present the draft Complaint to the Commission for its consideration. If issued by the Commission, the draft Complaint would charge Respondent with violation of the Federal Trade Commission Act.

T&M PROTECTION RESOURCES, LLC 217 Decision and Order Respondent and BCP thereafter executed an Agreement Containing Consent Order (“Consent Agreement”). The Consent Agreement includes: 1) statements by Respondent that it neither admits nor denies any of the allegations in the Complaint, except as specifically stated in this Decision and Order, and that only for purposes of this action, it admits the facts necessary to establish jurisdiction; and 2) waivers and other provisions as required by the Commission’s Rules. The Commission considered the matter and determined that it had reason to believe that Respondent has violated the Federal Trade Commission Act, and that a Complaint should issue stating its charges in that respect. The Commission accepted the executed Consent Agreement and placed it on the public record for a period of 30 days for the receipt and consideration of public comments. Now, in further conformity with the procedure prescribed in Rule 2.34, the Commission issues its Complaint, makes the following Findings, and issues the following Order: Findings 1. Respondent T&M Protection Resources, LLC is a Delaware limited liability corporation with its principal office or place of business at 230 Park Avenue, Suite 440, New York, New York 10169.

2. The Commission has jurisdiction over the subject matter of this proceeding and over Respondent, and the proceeding is in the public interest. ORDER Definitions For purposes of this Order, the following definition applies: A. “Respondent” means T&M Protection Resources, LLC, a limited liability corporation, and its successors and assigns.

Provisions I. Prohibition against Misrepresentations about Participation in or Compliance with Privacy Programs IT IS ORDERED that Respondent and its officers, agents, employees, and attorneys, and all other persons in active concert or participation with any of them, who receive actual notice of this Order, whether acting directly or indirectly, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service must not misrepresent in any manner, expressly or by implication, the extent to which Respondent is a member of, adheres to, complies with, is certified by, is endorsed by, or otherwise participates in any privacy or security program sponsored by a government or any self-regulatory or standard-setting organization, including but not limited to the EU-U.S. Privacy Shield framework, the Swiss-U.S. Privacy Shield framework, and the APEC Cross-Border Privacy Rules.

VOLUME 169 Decision and Order II. Requirement to Meet Continuing Obligations Under Privacy Shield IT IS ORDERED that Respondent and its officers, agents, employees, and attorneys, and all other persons in active concert or participation with any of them, who receive actual notice of this Order, whether acting directly or indirectly, in connection with the advertising, marketing, promotion, offering for sale, or sale of any product or service, must: A. affirm to the Department of Commerce, within ten (10) days after the effective date of this Order and on an annual basis thereafter for as long as it retains such information, that it will 1. continue to apply the EU-U.S. Privacy Shield framework principles to the personal information it received while it participated in the Privacy Shield; or 2. protect the information by another means authorized under EU law, including by using a binding corporate rule or a contract that fully reflects the requirements of the relevant standard contractual clauses adopted by the European Commission; or B. return or delete the information within ten (10) days after the effective date of this Order.

III. Acknowledgments of the Order IT IS FURTHER ORDERED that Respondent obtain acknowledgments of receipt of this Order:

A. Respondent, within ten (10) days after the effective date of this Order, must submit to the Commission an acknowledgment of receipt of this Order. B. For five (5) years after the issuance date of this Order, Respondent must deliver a copy of this Order to: (1) all principals, officers, directors, and LLC managers and members; (2) all employees having managerial responsibilities for conduct related to the subject matter of the Order and all agents and representatives who participate in conduct related to the subject matter of the Order; and (3) any business entity resulting from any change in structure as set forth in the Provision titled Compliance Report and Notices. Delivery must occur within ten (10) days after the effective date of this Order for current personnel. For all others, delivery must occur before they assume their responsibilities.

C. From each individual or entity to which Respondent delivered a copy of this Order, Respondent must obtain, within thirty (30) days, a signed and dated acknowledgment of receipt of this Order.

T&M PROTECTION RESOURCES, LLC 219 Decision and Order IV. Compliance Report and Notices IT IS FURTHER ORDERED that Respondent make timely submissions to the Commission:

A. Sixty (60) days after the issuance date of this Order, Respondent must submit a compliance report, sworn under penalty of perjury, in which Respondent must: (a) identify the primary physical, postal, and email address and telephone number, as designated points of contact, which representatives of the Commission, may use to communicate with Respondent; (b) identify all of Respondent’s businesses by all of their names, telephone numbers, and physical, postal, email, and Internet addresses; (c) describe the activities of each business; (d) describe in detail whether and how Respondent is in compliance with each Provision of this Order; and (e) provide a copy of each Acknowledgment of the Order obtained pursuant to this Order, unless previously submitted to the Commission.

B. Respondent must submit a compliance notice, sworn under penalty of perjury, within fourteen (14) days of any change in the following: (1) any designated point of contact; or (2) the structure of Respondent or any entity that Respondent has any ownership interest in or controls directly or indirectly that may affect compliance obligations arising under this Order, including: creation, merger, sale, or dissolution of the entity or any subsidiary, parent, or affiliate that engages in any acts or practices subject to this Order.

C. Respondent must submit notice of the filing of any bankruptcy petition, insolvency proceeding, or similar proceeding by or against Respondent within fourteen (14) days of its filing.

D. Any submission to the Commission required by this Order to be sworn under penalty of perjury must be true and accurate and comply with 28 U.S.C. § 1746, such as by concluding: “I declare under penalty of perjury under the laws of the United States of America that the foregoing is true and correct. Executed on: _____” and supplying the date, signatory’s full name, title (if applicable), and signature.

E. Unless otherwise directed by a Commission representative in writing, all submissions to the Commission pursuant to this Order must be emailed to [email protected] or sent by overnight courier (not the U.S. Postal Service) to: Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue, N.W., Washington, D.C. 20580. The subject line must begin: In re T&M Protection Resources, LLC, FTC File No. 192 3092, Docket No. C-4709.

VOLUME 169 Decision and Order V. Recordkeeping IT IS FURTHER ORDERED that Respondent must create certain records for ten (10) years after the issuance date of the Order, and retain each such record for five (5) years. Specifically, Respondent must create and retain the following records: A. accounting records showing the revenues from all goods or services sold; B. personnel records showing, for each person providing services related to the subject matter of the Order, whether as an employee or otherwise, that person’s: name; addresses; telephone numbers; job title or position; dates of service; and (if applicable) the reason for termination;

C. all records necessary to demonstrate full compliance with each provision of this Order, including all submissions to the Commission; and D. a copy of each widely disseminated representation by Respondent making any representation subject to this Order, and all materials that were relied upon in making the representation.

VI. Compliance Monitoring IT IS FURTHER ORDERED that, for the purpose of monitoring Respondent’s compliance with this Order:

A. Within ten (10) days of receipt of a written request from a representative of the Commission, Respondent must: submit additional compliance reports or other requested information, which must be sworn under penalty of perjury, and produce records for inspection and copying.

B. For matters concerning this Order, representatives of the Commission are authorized to communicate directly with Respondent. Respondent must permit representatives of the Commission to interview anyone affiliated with Respondent who has agreed to such an interview. The interviewee may have counsel present. C. The Commission may use all other lawful means, including posing through its representatives as consumers, suppliers, or other individuals or entities, to Respondent or any individual or entity affiliated with Respondent, without the necessity of identification or prior notice. Nothing in this Order limits the Commission’s lawful use of compulsory process, pursuant to Sections 9 and 20 of the FTC Act, 15 U.S.C. §§ 49, 57b-1.

VII. Order Effective Dates IT IS FURTHER ORDERED that this Order is final and effective upon the date of its publication on the Commission’s website (ftc.gov) as a final order. This Order will terminate on T&M PROTECTION RESOURCES, LLC 221 Analysis to Aid Public Comment March 16, 2040, or twenty (20) years from the most recent date that the United States or the Commission files a complaint (with or without an accompanying settlement) in federal court alleging any violation of the Order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of:

A. any Provision in this Order that terminates in less than twenty (20) years; B. this Order’s application to any respondent that is not named as a defendant in such complaint; and C. this Order if such complaint is filed after the order has terminated pursuant to this Provision.

Provided, further, that if such complaint is dismissed or a federal court rules that Respondent did not violate any provision of the Order, and the dismissal or ruling is either not appealed or upheld on appeal, then the Order will terminate according to this Provision as though the complaint had never been filed, except that the Order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal.

By the Commission.

ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission (“Commission”) has accepted, subject to final approval, an agreement containing a consent order from T&M Protection Resources, LLC (“T&M” or “Respondent”).

The proposed consent order (“proposed order”) has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. This matter concerns alleged false or misleading representations that T&M made concerning its participation in the Privacy Shield framework agreed upon by the U.S. and the European Union (“EU”). The Privacy Shield framework allows for the lawful transfer of personal data from the EU to participating companies in the U.S. The framework consists of a set of principles and related requirements that have been deemed by the European Commission as providing “adequate” privacy protection. The principles include notice; choice; accountability for onward transfer; security; data integrity and purpose limitation; access; and recourse, enforcement, VOLUME 169 Analysis to Aid Public Comment and liability. The related requirements include, for example, securing an independent recourse mechanism to handle any disputes about how the company handles information about EU citizens. To participate in the framework, a company must comply with the Privacy Shield principles and self-certify that compliance to the U.S. Department of Commerce (“Commerce”). Commerce reviews companies’ self-certification applications and maintains a public website, https://www.privacyshield.gov/list, where it posts the names of companies who have completed the requirements for certification. Companies are required to recertify every year in order to continue benefitting from Privacy Shield.

T&M provides background check, security and investigative services. In connection with providing services relating to background checks, T&M obtained personal data about individuals in the EU. According to the Commission’s complaint, T&M published on its website, https://www.tmprotection.com/privacy-policy, a privacy policy containing statements related to its participation in Privacy Shield. However, T&M allowed its certification to lapse and continued to claim it participated in the Privacy Shield framework.

The Commission’s proposed three-count complaint alleges that Respondent violated Section 5(a) of the Federal Trade Commission Act. Specifically, the proposed complaint alleges that Respondent engaged in a deceptive act or practice by falsely representing that it was a certified participant in the EU-U.S. Privacy Shield Framework. The proposed complaint further alleges that Respondent engaged in deceptive acts or practices by representing that it complied with the framework when in fact it had failed to comply with certain Privacy Shield requirements. Part I of the proposed order prohibits the company from making misrepresentations about its membership or compliance with any privacy or security program sponsored by the government or any self-regulatory or standard-setting organization, including, but not limited to, the EU-U.S. Privacy Shield framework, the Swiss-U.S. Privacy Shield framework, and the APEC Cross-Border Privacy Rules.

Part II of the proposed order requires that the company affirm to Commerce that it will either continue to apply the Privacy Shield framework principles to any data it received pursuant to frameworks or protect the information by another means authorized under EU or Swiss law, or will delete or return such data within ten days after the effective date of the order. Parts III through VI of the proposed order are reporting and compliance provisions. Part III requires acknowledgement of the order and dissemination of the order now and in the future to persons with responsibilities relating to the subject matter of the order. Part IV ensures notification to the FTC of changes in corporate status and mandates that the company submit an initial compliance report to the FTC. Part V requires the company to create certain documents relating to its compliance with the order for ten years and to retain those documents for a five-year period. Part VI mandates that the company make available to the FTC information or subsequent compliance reports, as requested.

T&M PROTECTION RESOURCES, LLC 223 Analysis to Aid Public Comment Part VII is a provision “sun-setting” the order after twenty (20) years, with certain exceptions.

The purpose of this analysis is to aid public comment on the proposed order. It is not intended to constitute an official interpretation of the complaint or proposed order, or to modify in any way the proposed order’s terms.

VOLUME 169 Complaint

← 169 F.T.C. 198 · 169 F.T.C. 224 →