Privacycon 5 6 7 8 9 10 Tuesday, July 21, 2020 11 9:00 A.M
Total Page:16
File Type:pdf, Size:1020Kb
1 FEDERAL TRADE COMMISSION 2 3 4 PRIVACYCON 5 6 7 8 9 10 TUESDAY, JULY 21, 2020 11 9:00 A.M. 12 13 14 VIRTUAL EVENT 15 16 17 18 19 20 21 22 23 24 25 2 PrivacyCon 7/21/2020 1 FEDERAL TRADE COMMISSION 2 I N D E X 3 PAGE: 4 Welcome 3 5 6 Opening Remarks 6 7 8 Session 1: Health Apps 12 9 10 Session 2: Bias in AI Algorithms 74 11 12 Session 3: The Internet of Things 110 13 14 Session 4: Specific Technologies: 15 Cameras/Smart Speakers/Apps 156 16 17 Session 5: International Privacy 202 18 19 Session 6: Miscellaneous Privacy/Security 257 20 21 Closing Remarks 311 22 23 24 25 For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 3 PrivacyCon 7/21/2020 1 P R O C E E D I N G S 2 WELCOME REMARKS BY ELISA JILLSON 3 MS. JILLSON: Good morning. On behalf of my 4 colleagues at the Federal Trade Commission, I'm happy 5 to welcome you to our fifth annual PrivacyCon. My 6 name is Elisa Jillson. I'm an attorney in the 7 Division of Privacy and Identity Protection. My co- 8 organizer for today's event is Jamie Hine, a senior 9 attorney in the same division. 10 Before we get started with our program, I 11 need to review a few administrative details. We're 12 happy to welcome you via the webcast. We will make 13 the webcast and the other workshop materials available 14 online to create a lasting record for everyone 15 interested in these issues. That will include links 16 to the research discussed and, in a few weeks, a 17 written transcript of today's event. 18 As you may know, PrivacyCon is typically an 19 in-person event. If there are technological issues 20 with this webcast, we will work to address them 21 promptly and we ask in advance for your patience if 22 any such issues arise. 23 We will be leaving time at the end of each 24 panel to take questions from the audience. You can 25 email your questions to [email protected]. If you For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 4 PrivacyCon 7/21/2020 1 would like to ask a question by Twitter, you can tweet 2 your question using @FTC and #PrivacyCon20. Please 3 understand that we may not be able to get to all of 4 the questions. 5 Lastly, I wanted to thank all of the 6 researchers and the panelists for their participation 7 in today's event. We are very grateful for your work 8 in this important area. 9 This program would not be possible without 10 the great work done by many of our FTC colleagues. We 11 would like to thank our colleagues that assisted us in 12 reviewing all of the research submissions, including 13 Monique Einhorn and Patrick McAlvanah. We would also 14 like to thank those moderating panels today, including 15 Ellen Connelly, Phoebe Rouge, Daniel Wood, and Lerone 16 Banks. 17 Finally, this conference would not be 18 possible without the help of Kristal Peters, Aryssa 19 Henderson, James Murray, and Bruce Jennings; 20 paralegals, Leah Singleton and Alex Iglesias; June 21 Chang from our Division of Consumer and Business 22 Education; Somethea Mam from the FTC media team; 23 Juliana Henderson and Nicole Drayton in our Office of 24 Public Affairs; and Shawn Whitaker at Open Exchange. 25 Thank you all. For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 5 PrivacyCon 7/21/2020 1 It is now my honor to welcome the Director 2 of the Bureau of Consumer Protection at the Federal 3 Trade Commission, Andrew Smith. 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 6 PrivacyCon 7/21/2020 1 OPENING REMARKS BY DIRECTOR ANDREW SMITH 2 MR. SMITH: Thank you, Elisa. 3 Welcome to PrivacyCon 2020 and thank you all 4 for being here virtually. This is the fifth year that 5 we've held PrivacyCon, which brings together 6 researchers from around the country and around the 7 world to discuss cutting-edge issues related to 8 consumer privacy and security. I know that you will 9 all miss the opportunity to see each other face to 10 face, but the most important feature of PrivacyCon 11 remains the same, the spotlight on topnotch research 12 from a distinguished group of academics, physicians, 13 economists, and other practitioners. 14 Over the past few years, PrivacyCon has been 15 critical in keeping the FTC and other stakeholders up 16 to date on emerging technologies and related data and 17 privacy security risks. PrivacyCon informs all of the 18 work that we do here at the FTC, whether it be 19 enforcement, business or consumer education or 20 rulemaking and policy efforts. 21 In light of that influence, I'll start with 22 a few words about what the FTC has been doing to 23 protect consumers' privacy since the last PrivacyCon. 24 Vigorous enforcement is at the heart of what the FTC 25 does. And in the past year, we've brought privacy and For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 7 PrivacyCon 7/21/2020 1 security cases under the Fair Credit Reporting Act, 2 the Children's Online Privacy Protection Act, the 3 Gramm-Leach-Bliley Safeguards Rule, and our own FTC 4 Act. 5 Shortly after last year's PrivacyCon, we 6 announced settlements with Facebook, Equifax, and 7 YouTube last year that shattered prior records for 8 civil penalties or consumer redress for privacy and 9 security violations. These settlements also required 10 important structural changes with respect to how these 11 companies treat consumers' or children's information. 12 More recently, we brought a trio of cases 13 against operators of mobile apps that failed to 14 protect the privacy of children's information or 15 misled consumers about compliance with children's 16 privacy laws, the stalking app, Retina-X, the Swiss 17 mobile gaming company Miniclip, and the kid's app 18 purveyor HyperBeard. 19 In recent data security cases, like Tapplock 20 and InfoTrax, we've put a stop to misrepresentations 21 about smart lock security and also to the failure to 22 safeguard consumers' sensitive personal information. 23 In privacy cases like Unrollme and Mount 24 Diablo, we've challenged companies that made empty 25 promises about keeping sensitive information, like For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 8 PrivacyCon 7/21/2020 1 financial information and emails, away from prying 2 eyes. 3 We have also focused on educating business 4 and consumers about data-related risks. For example, 5 in recent months, we've issued guidance to businesses 6 on how to develop coronavirus-related technologies 7 that take privacy into account. We've offered advice 8 on secure cloud computing and tips for using 9 artificial intelligence and algorithms. 10 For consumers, we've put out guidance on how 11 to safely use videoconferencing services and how to 12 protect children's privacy while doing remote 13 learning. 14 Rather than talking about past 15 accomplishments, today's conversation needs to be 16 focused on what the FTC should be doing going forward. 17 Panelists today will discuss technologies ranging from 18 mobile health and disaster apps to interconnected 19 devices, such as smart speakers and cameras, to online 20 ad delivery systems. Economists will report on their 21 studies abroad to gauge the effects of privacy 22 legislation in Europe. And researchers will describe 23 mechanisms for consumer choice and how consumers 24 protect themselves from identity theft. 25 The papers presented today will highlight For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 9 PrivacyCon 7/21/2020 1 technological developments that could be a boon to 2 consumers, but that also present risks to privacy, 3 security, and, in at least one instance, equal 4 opportunity. 5 One final note before I turn the discussion 6 over to our first panel: In our call for research 7 papers, we specifically asked for research on mobile 8 health apps, and the first panel of the day will be 9 devoted to that important topic. Why health apps? 10 Industry reports show that consumers are increasingly 11 using a variety of health-related apps, including 12 fitness trackers, mood journals, smoking cessation or 13 addiction aids, heart rate or sleep monitors, 14 fertility trackers, diet guides, and more. Use of 15 contact-tracing apps during the COVID-19 pandemic 16 could add a whole new dimension to that trend. 17 Earlier this year, the Department of Health 18 and Human Services issued rules that will make it 19 easier for consumers to access medical records through 20 the app of their choice. This expanded access to 21 health information could be an enormous benefit to 22 consumers. But as we all know, wherever data flows 23 increase, the opportunity for data compromise 24 increases as well. 25 We, here at the FTC, have been active on For The Record, Inc. (301) 870-8025 - www.ftrinc.net - (800) 921-5555 10 PrivacyCon 7/21/2020 1 health privacy issues, with cases like Practice 2 Fusion, PaymentsMD, and Henry Schein.