Policy Beta details an appalling act of deception by Sears Holding Corporation (which also owns Kmart). According to the FTC settlement:
...the company failed to “adequately disclose” that it was collecting personal information using a spyware program secretly installed on consumers’ computers.
Between 2007 and 2008, 15 of every 100 visitors to sears.com or kmart.com were presented with a pop-up window that offered the opportunity to “talk directly to a retailer” and become part of “a place where your voice is heard and your opinion matters, and what you want and need counts!” No mention was made that this “opportunity” also installed detailed tracking software on the user’s computer.
Customers who asked for more information were offered a $10 coupon in exchange for downloading – and keeping on their computer for at least one month – software from Sears or K-mart that would allow them to become “part of something new, something different[.]” Consumers probably didn’t realize that by “new” and “different,” the advertisement meant “all-seeing” and “invasive.” Indeed, this software monitored both online and offline behavior, peering into online secure sessions and culling information from consumers’ email subject and recipients, online bank statements, drug prescription records, video rental records, and similar histories and accounts.
Now, somewhere in the bowels of Sears Holding Corporation, there are corporate loyalists gnashing their teeth about how unfair this is.
After all, they'd say - "we disclosed everything in our privacy statement!"
It clearly says (emphasis added):
Once you install our application, it monitors all of the Internet behavior that occurs on the computer on which you install the application, including both your normal web browsing and the activity that you undertake during secure sessions such as filling a shopping basket, completing an application form or checking your online accounts, which may include personal financial or health information.
We may use the information that we monitor, such as name and address, for the purpose of better understanding your household demographics; however we make commercially viable efforts to automatically filter confidential personally identifiable information such as UserID, password, credit card numbers, and account numbers.
Inadvertently, we may collect such information about our panelists [people who have downloaded the software]; and when this happens, we make commercially viable efforts to purge our database of such information.
Think about what they've just written there for a second.
We're going to monitor ALL your household internet use - including secure transactions. It MAY include your personal financial or health information. We may collect your UserIDs and passwords - but don't worry - we'll purge our database in a commercially viable way.
That's just breathtaking. Not only for the scope of how invasive it is, but that somebody was brazen enough to put that down in print.
Why did they do that? Because of this other little section of the document:
What are the other legal terms and conditions of participating in this program?
Governing Law: You agree that any dispute or claim arising out of this program or agreement shall be settled by binding arbitration in Cook County, Illinois under the American Arbitration Association Rules.
Yes, binding arbitration... corporate America's current attempt at de facto civil immunity.
The FTC was not impressed - partly because no one reads these privacy agreements, but largely because of the way in which the privacy text was displayed to users.
Wanna guess how they expected you to read their "disclosure" that agreement meant installing spyware and waiving your right to sue?
Yeah. That'd be the typical scrollable text box. Complete with boring intro text so nobody wants to read it.
Oh, there's a printable version link - but a link that starts with "print..." is going to get less traffic than one that says "View.." and they know that nobody has the staying power to read 11 pages of legalese.
And they offered people $10 to participate.
Ten bucks in exchange for people's private data and their right to sue.
The FTC has ordered the deletion of all the collected data - but I'm not seeing mention of a massive fine. There's also the typical "no admission of wrongdoing" langauge which is about as wimpy as it gets. What isn't wrong about what they did?
I know it's a question of emphasis and actual criminal intent was probably lacking. Odds are they were just arrogant enough to believe what they were doing was legal because of their "disclosure." But again, there was a clear expectation that people would not read/understand/consent to what was going to happen.
You pull crap like this on your customers - you should be paying a fine and wearing the corporate equivalent of a scarlet letter.
No comments:
Post a Comment