FTC settles with OpenX Technologies for $2 million for allegedly violating children's privacy law
Full article783 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The FTC also alleges that OpenX continued to collect geolocation data from some Android users even after they opted out of tracking.
Advertising platform OpenX Technologies will pay the Federal Trade Commission $2 million over allegations that it failed to comply with a federal rule requiring online services to obtain parents’ consent before collecting data about children under the age of 13.
OpenX offers automated ad buying that allows companies to reach a precise audience in real-time. The settlement effectively serves as a warning to digital advertising platforms, which funnel massive amounts of data through real-time advertising bids, often with little transparency.
“OpenX secretly collected location data and opened the door to privacy violations on a massive scale, including against children,” said Samuel Levine, director of the FTC’s Bureau of Consumer Protection. “Digital advertising gatekeepers may operate behind the scenes, but they are not above the law.”
A complaint from the Department of Justice filed on behalf of the FTC alleges that the company knowingly collected information from hundreds of apps that identified as “for toddlers,” “for kids,” “kids games,” or “preschool learning,” and included age ratings indicating they were aimed at users under 13.
“OpenX has received millions, if not billions of ad requests directly or indirectly from child-directed Apps, and transmitted millions, if not billions, of bid requests containing personal information of children” including location information, according to the complaint.
The FTC also alleges that OpenX violated FTC law by continuing to collect geolocation data from some Android users even after they opted out of tracking.
The order originally stipulated a $7.5 million penalty against OpenX but capped it at $2 million due to the company’s inability to pay.
OpenX called the collection an “unintentional error” in a blog post about the complaint. OpenX claims that “a relatively small number of apps were miscategorized” and that “more than 99% of those domains and apps were appropriately categorized.”
“We have reviewed and bolstered our policies and procedures to make sure we are fully COPPA compliant, and we will continue to follow strict criteria of both qualitative and quantitative attributes to determine a site’s or an app’s suitability for inclusion in our exchange,” the company wrote.
The settlement also requires OpenX to delete all the ad request data the company collected in violation of the federal children’s privacy law, Children’s Online Privacy Protection Act (COPPA). Members of Congress have in recent months introduced efforts to reform COPPA, which was passed in 1998, including raising the age of protection to 18.
More Scoops
The FTC wants to regulate AI for ideological bias
The commission is mulling whether to begin regulating bias in AI systems. Critics say they’re overstepping their legal authority and infringing on free speech.
House Republicans roll out national privacy bill
The FTC’s AI portfolio is about to get bigger
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ftc-openx-coppa/