Political ads face tougher targeting restrictions in EU if MEPs get their way

Europe has moved a step closer to having dedicated rules on online political ad targeting and transparency after the European Parliament fixed its negotiating position — paving the way for talks to start between MEPs and Member States to agree a final compromise text that can be passed into pan-EU law.

MEPs said they hope agreement can be reached in time to have the regulation in place for the next elections to the EU’s Parliament — in 2024.

Parliamentarians voted for a series of changes to the Commission’s original (rather weak) proposal which was presented back in November 2021— saying they’ve beefed up the draft so that only data “explicitly provided” for online political advertising can be used by advert providers for this purpose.

MEP Patrick Breyer, a co-negotiator on the file in the parliament’s civil liberties (LIBE) committee, dubbed it “a good day for democracy” — highlighting some of the agreed amendments parliamentarian want to see, including a stipulation that refusing consent for political ads targeting must be as simple as giving it (so no consent dark patterns); another that ‘do not track’ browser settings must be respected without hassling the user with more consent prompts (so no forcing consent by tiring web users who’ve already refused with fresh pop-ups); and a requirement that users who refuse consent should still be allowed access to the platforms (so no forcing consent, period).

MEPs backed the negotiating mandate on the file by a large majority — of 433 votes in favour, 61 against (and 110 abstentions).

“Platforms would be banned from running opaque ad delivery algorithms to determine who should see a political ad; they would only be able to select recipients randomly in the pool of people delineated by the targeting parameters chosen by the sponsor,” Breyer added in a press release rounding up key changes MEPs have proposed.

These also include a proposal for a 60 day pre-election (or referendum) period — during which there would be further limits on political message targeting, with MEPs wanting to restrict this to only a voter’s language and the constituency they live in to avoid the hyper-segmention of voters that’s possible thanks to ‘personalized’ political ads which has been shown to be so toxic to democratic accountability.

“Microtargeting, a strategy that uses consumer data and demographics to identify the interests of specific individuals, will therefore not be possible,” the parliament suggests in a press release.

In other changes, MEPs have also taken aim at foreign money seeking to influence EU elections — and proposed that non-EU based entities should be banned from financing political advertisements in the EU.

Although how effectively such a ban would or could be policed is another matter. (“To determine where such an entity is established, the relevant authorities should take into account where the ultimate controller of this entity is located,” is what the parliament says on that.)

MEPs have made other changes they say are aimed at improving transparency around political ads — such as pushing for the creation of an online repository for “all online political advertisements and related data”.

“It should be easier to obtain information on who is financing an advert, on its cost, and the origin of the money used,” they write. “Other pieces of information which should also be published include whether an advertisement has been suspended for violating the rules, on the specific groups of individuals targeted and what personal data were used for this, and the views and engagement with the advertisement. MEPs aim to give journalists a specific right to obtain such information.”

The Commission’s original proposal had proposed transparency labels for political ads, as well as some restrictions on microtargeting — but the vast majority of MEPs want to see tougher regulation of an arena where tech has gained a toxic reputation as a cheap, powerful and largely consequence-free tool for fiddling with democracy.

Hence they’ve also proposed the possibility of having periodic penalties levied for repeat violations — and the obligation for large ad service providers to suspend their services for 15 days with a particular client in the case of serious and systemic infringements. They also want the Commission to be able to introduce EU-wide “minimum sanctions”.

MEPs look keen to avoid any risk of forum shopping at the Member State level from undermining the rules by creating fresh workarounds — saying their adopted text both strengthens the powers of national data protection authorities (which will be expected to oversee compliance) but also empowers the European Data Protection Board (EDPB) to “take over an investigation into an infringement and enforce the rules”, i.e. if a DPA is finding it hard to do their duty and crack down on violators.

Breyer even directly names the (much criticized) Irish Data Protection Commission as a risk in this context, writing: “If a data protection authority such as the Irish DPA fails to enforce the rules against large online platforms, the EDPB would be able to take over.”

“In cases of illegal political ads targeting [the EDPB[] will not only be able to impose financial sanctions but also to temporarily suspend the targeting of ads by advertisers who seriously and systematically violated the rules. This ensures that more affluent sponsors are not able to simply factor-in the price of financial sanctions in their budget,” he adds.

Commenting in a statement, MEP and rapporteur for the file, Sandro Gozi, also said:

There is too much undue interference in our democratic processes. As legislators we have a responsibility to fight this but also to ensure debate remains open and free. This law will not kill political advertising, despite rumours spread by large online platforms. Nor will it stymie our freedom of expression. It will only limit abusive political advertising.

The European Council agreed its negotiating mandate on the regulation back in December — saying then that it wants to build on the Commission’s proposal by providing “greater legal certainty” re: the scope of the regulation; and around some of the key definitions, including in areas such as what is to be considered political advertising and how to identify a political ad.

It also sought to claim credit for proposing stronger transparency measures. Although the Council largely aligned with the Commission’s more limited approach on restricting political microtargeting — saying it wanted to ban targeting and amplification techniques using “sensitive” personal data, including inferred data, unless an adult “explicitly consents”; or is “a member or former member of a specifically defined not-for-profit body processing the sensitive data, or is in regular contact with it”. (But agreeing that the processing of minors’ data for political ads should be entirely banned.) 

While the parliament’s amendments propose to go further in restricting behaviorally targeted political ads there could still be scope for loopholes — as Breyer points out that limiting the application of the restrictions to “political advertising services” could, for instance, open a loophole for circumventing the rules if campaigns elect to directly send personally targeted letters, emails, or text messages “systematically and at large scale”.  Though he suggests MEPs may push to try to address such a scenario in the forthcoming trilogue talks.

Another gap the regulation does not address is organic, self-posted political content — which is (currently) excluded from the proposed targeting restrictions. So there’s also a risk that election fiddlers could fly under the radar by using fake social media accounts to post and amplify political propaganda — something that already happens at scale of course. So that looks like another major weak point.

That said, MEPs previously pushed forand won — some softer but more general limits on behavioral targeting via the Digital Services Act (which applies to digital intermediary services and platforms) — including a ban on the processing of minors’ data for targeting ads; and a ban on the use of sensitive data for ad targeting of adults. So the scope for tracking-and-profiling web users in order to target them with ‘personalized’ content is facing a growing range of restrictions in the EU — where adtech platforms are also seeing an increase in enforcements of breaches of existing data protection and ePrivacy rules.

Political ads face tougher targeting restrictions in EU if MEPs get their way by Natasha Lomas originally published on TechCrunch


from https://ift.tt/XJ2ohOR
via Technews
Share:

Car-sharing platform Getaround gets delisting warning from NYSE

The New York Stock Exchange has issued a delisting warning to peer-to-peer car rental company Getaround for trading too low, according to the company.

Getaround debuted on the public markets in December after merging with a special purpose acquisition company (SPAC). The combined company’s stock began trading at around $10 per share and promptly lost 65% of its value. Today, Getaround’s shares dropped 1.3% and are going for $0.64.

Getaround has six months to cure its stock price deficiency and regain compliance with the NYSE’s continued listing standards. The stock exchange issues such warnings to companies whose stock prices are less than $1 over a consecutive 30 trading-day period.

It seems a bit early in Getaround’s time on the public markets for the company to be dancing with a potential delisting, but the warning isn’t entirely unsurprising if you look at Getaround’s balance sheet. The company has scaled somewhat aggressively over the past couple of years and claims to have a network 20x larger than its nearest competitor. That scale has come at the cost of negative growth and rising losses. In fact, revenue declined and operating costs increased in the first three quarters of 2022 compared to the year prior. By September 30, 2022, Getaround’s operating cash burn was $63.2 million, compared to $53.3 million in the same period in 2021.

Getaround closed out Q3 2022 with free cash flow of $27.2 million. Merging with InterPrivate II Acquisition Corp. brought the company $228 million of gross proceeds to help keep it afloat, but that money came with a sharp reduction in its value that may partially explain the tanking stock price.

The somewhat beleaguered company will report its fourth-quarter and full-year earnings soon — Getaround has yet to set a date — which should shed some light on whether Getaround can turnaround and bring itself back up to compliance.

Car-sharing platform Getaround gets delisting warning from NYSE by Rebecca Bellan originally published on TechCrunch


from https://ift.tt/SrexgCh
via Technews
Share:

The Biden administration says Apple and Google’s app stores are stifling competition

The Biden administration is calling out Apple and Google’s app stores for stifling competition. A new report, issued on Wednesday by the Commerce Department’s National Telecommunications and Information Administration (NTIA), said it had investigated the competitive conditions in the mobile app ecosystem and found that it’s “not a level playing field, which is harmful to developers and consumers.” The report also made several policy suggestions that could improve the ecosystem and open up competition.

The investigation had been initiated as part of a 2021 Executive Order on competition and involved consultations with various industry stakeholders in the private industry, civil society, and academia, NTIA said. It also included a review of over 150 comments filed in response to a request for public comment last April.

The report summarizes what industry watchers already know: that the innovations made possible by mobile phones and downloadable apps have begun to be overshadowed by the barriers to entry to the market facing developers, the excessive and restrictive rules, the overcomplicated app review process, and the sizable commissions that developers are forced to pay for access to consumers’ devices.

“Our review suggests that the mobile app store model has provided a range of benefits to both app developers and users, but has also created conditions of competition that are suboptimal,” the report states. “The policies that Apple and Google have in place in their own mobile app stores have created unnecessary barriers and costs for app developers, ranging from fees for access to functional restrictions that favor some apps over others. These obstacles impose costs on firms and organizations offering new technology: apps lack features, development and roll-out costs are higher, customer relations are damaged, and many apps fail to reach a large number of users.”

Both Apple and Google took issue with the report’s findings. (The AP printed their comments here.) Largely, Apple’s position was the same as always — that its rules are focused on providing consumer safety and security. Google, meanwhile, points out it offers more competition and choice. (Android, for instance, already allows sideloading.)

In addition to summarizing the state of the market, the new report makes a variety of recommendations as to how various areas can be improved to boost competition. The report suggests, for example, there should be a more transparent app review process; limits on pre-installed apps and self-preferencing; bans on rules that restrict other means of installing apps, like sideloading; support for third-party payments; support for links to developers’ websites from apps; and more.

It also said tech giants should be restricted from using confidential business data acquired from third-party developers to help launch their own competing apps — a practice so common at Apple, it’s even been dubbed “sherlocking” after a famous example.

The recommendations, however, are just that — ideas, not policy. The report only helps to solidify and clarify the Biden administration’s position on app store competition. As the report points out, “Congress should enact laws” and “relevant agencies should consider measures” to limit anticompetitive conduct. It also suggests there are areas that warrant further study, like “choice screens” (which some argue only offer the perception of choice), and whether or not laws should ban preinstallation of apps or other agreements between Apple and Google and device manufacturers and carriers.

In other words, any real action is still in the hands of regulators and lawmakers, as it was in the months before the report’s release.

The Biden administration, so far, has seen mixed success in actually holding tech giants accountable. On the one hand, the Department of Justice is now suing Google over its digital ad monopoly, while on the other, Meta is winning against the FTC to move forward with its latest acquisition. The DoJ has yet to sue Apple, though it has been building a case and weighing in on Epic Games’ antitrust lawsuit. In the meantime, record lobbying spending from tech giants, including Apple and Google, has helped to block bipartisan bills that would curb anti-competitive behavior from advancing in Congress.

President Biden, of course, already made his position on big tech abuses known, in an op-ed published in The Wall St. Journal earlier this month. With regard to competition, he stated there was still more than needed to be done.

“When tech platforms get big enough, many find ways to promote their own products while excluding or disadvantaging competitors—or charge competitors a fortune to sell on their platform,” he wrote. “My vision for our economy is one in which everyone—small and midsized businesses, mom-and-pop shops, entrepreneurs—can compete on a level playing field with the biggest companies.”

The Biden administration says Apple and Google’s app stores are stifling competition by Sarah Perez originally published on TechCrunch


from https://ift.tt/KmnWbOA
via Technews
Share:

Google Fi hack victim had Coinbase, 2FA app hijacked by hackers

On January 1, a technologist who goes by the nickname regexer received an email saying he had successfully reset his account at the crypto exchange Coinbase.

Unfortunately — and worryingly — he had actually not requested a password reset. Regexer, who asked to be referred to by his online moniker for fear of being targeted by hackers again, quickly realized he was being hacked, and his attempts to log into his Coinbase to regain control were unsuccessful.

Soon after, he noticed he had no cell phone service. Then, his two-factor app, Authy, notified him that a new device was added to his account. After the hackers took control of regexer’s cell phone service, the hackers were able to reset the passwords on his accounts and intercept two-factor SMS messages. That allowed the hackers to take control of Authy, giving them the ability to use the 2FA codes created by the app, according to regexer.

This gave them a chance to break into even more accounts owned by regexer.

“Now I don’t know what the hell is going on. I am totally owned,” regexer told TechCrunch, recalling the incident.

Unsure what to do, regexer started changing passwords on his other important accounts that had apparently not been compromised yet. Then, on a whim, he started turning airplane mode on and off on his iPhone. Somehow, after a few attempts, his cellphone service was restored.

Regexer isn’t sure if turning airplane mode on and off is what stopped the attack but he is glad that happened.

For weeks, regexer had no idea how he had been hacked. Then, on Monday, he received an email from his cell phone provider, Google Fi, informing him and all other customers that hackers had stolen some customers’ information, likely connected to the recent breach at T-Mobile.

Unlike for other customers, the email regexer received contained more detailed information about the hack he suffered weeks prior.

“Other data related to your Google Fi account also may have been accessed without authorization, such as a zip code, and the service/emergency address associated with your account,” read the email, which regexer shared with TechCrunch. “Additionally, on January 1, 2023 for about 1 hour 48 minutes, your mobile phone service was transferred from your SIM card to another SIM card. During the time of this temporary transfer, the unauthorized access could have involved the use of your phone number to send and receive phone calls and text messages. Despite the SIM transfer, your voicemail could not have been accessed. We have restored Google Fi service to your SIM card.”

Regexer said he has talked to two Google Fi customer representatives trying to figure out more details about what happened, but neither of them told him anything. And, interestingly, regexer didn’t see any evidence that his Google account, which is tied to the Google Fi account, was compromised. It’s unclear how the hackers were able to perform the SIM swap.

Google has not responded to a request for comment. And it’s not yet known if there were other people, or how many, specifically targeted by hackers the way regexer was.

Once he regained control of this online life, regexer investigated the hack and found out the hackers had also taken over his Outlook email account, and — smartly — in an effort to hide their actions, deleted the emails informing of the password reset.

Even though nothing else happened since January 1, regexer is still worried and is calling on Google to disclose more information.

“The main thing I’d like to know is whether I and others are still vulnerable, and if there’s anything we can do to protect ourselves. I’d love to know more details about the mechanisms that were used for the phone number takeover because that will shed light on the level of ongoing vulnerability and methods for defense, as well as whether SMS two-factor remains better than no two-factor at all. (I can replace SMS for some online accounts, but not all. Many banks and others only allow two-factor via SMS.) I’d also love to know how many people had their phone numbers hijacked in connection with the breach, and, if it was a small subset, was there any reason that we in particular were targeted,” regexer said.

“So unless Google sheds more light on the attack there is a big open question about how vulnerable people’s phone numbers now are.”


Are you a Google Fi subscriber that was also a victim of a similar attack? Did you also get a personalized notification from the company about the hack against you? We’d love to hear from you. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Wickr, Telegram and Wire @lorenzofb, or email lorenzo@techcrunch.com. You can also contact TechCrunch via SecureDrop.

Google Fi hack victim had Coinbase, 2FA app hijacked by hackers by Lorenzo Franceschi-Bicchierai originally published on TechCrunch


from https://ift.tt/IApF2NK
via Technews
Share:

The biggest names in D&D are going independent on ‘Worlds Beyond Number’

“If you could open this article sort of Rolling Stone style…” Brennan Lee Mulligan suggests, then without changing his tone, pitches his lede: “In a Corvette, racing down the 5, [podcast producer] Taylor Moore swerves, then bites right into a massive wheel of brie cheese…”

It’s what you’d expect from Mulligan, who got his start as an improv comic at College Humor, which spun off Dropout, a subscription-based comedy hub known for its particular flavor of clever, quick-on-its-feet humor. In recent years, Mulligan began professionally orchestrating tabletop roleplaying games (TTRPGs) as the game master on Dropout’s ultra popular “Dimension 20” web series, ascending to something like Dungeons & Dragons royalty in the process.

Of course, we are not actually in a Corvette — as they say in Dungeons & Dragons, this is all in the “theater of the mind.” But for anyone who follows TTRPG actual play media, the unfortunately brie-free Zoom meeting on my laptop screen is probably more thrilling than a sports car.

Mulligan is part of a new powerhouse crew of TTRPG creators teaming up to introduce “Worlds Beyond Number,” a new audio fiction podcast that will launch in March with a Dungeons & Dragons campaign. He’s joined by ubiquitous video game voice actor Erika Ishii, Dimension 20’s Lou Wilson and Aabria Iyengar, who has spun imaginative original stories with Dimension 20 and Critical Role in recent D&D campaigns.

“There’s just something about the chemistry of this group that feels special,” Ishii told TechCrunch. “When you find people to create with, you gotta grab onto them and just keep doing that for the rest of your lives together. So, we figure we might as well put a ring on it.”

“Oh, a podcast is a new ring for creators!” interjected Iyengar.

If you’re of a particular generation, you could say that “Worlds Beyond Number” is to TTRPG podcasting as Boygenius is to indie music. And if that reference makes no sense, well… does Crosby, Stills, Nash & Young ring a bell?

Aside from its all-star cast, “Worlds Beyond Number” is unlike anything that the four performers have done before — and that’s because they actually own the project.

“We get to decide our own fate,” said Ishii. “We are not beholden to anybody else except for ourselves, and our creative sensibilities, and to the fans that are the ones supporting us.”

Iyengar is also looking forward to the creative freedom. “There is something so freeing in having the moment where you look at the table and go like, this is going to be whatever I want it to be, whatever we decide it’s going to be, and that feels so beautiful.”

At the stroke of midnight on February 1, more than 2,500 people watched the cast livestream on Instagram as they launched the Patreon page for the podcast. While the show will be available for free on standard podcast apps, fans can sign up for $5 per month to get behind-the-scenes, bonus content for the show, including a prequel campaign known as “The Children’s Adventure.”

Within thirty minutes of going live on Patreon, “Worlds Beyond Number” reached 3,500 patrons. By about 1:30 PM the following day, they hit 9,400 patrons. That means the show will already rake in over $47,000 per month, minus Patreon’s cut (around 10% depending on the creator’s choice of tier) and taxes.

Image Credits: Worlds Beyond Number

“There’s something about the simplicity of people saying like, ‘I love these creators, I want to support what they’re doing, so I’m going to come support it.’ And we get to share a bunch of that behind-the-scenes stuff with them as a result of that,” said Mulligan. “It just feels like the firm handshake of a square deal. It feels so pleasing. There’s no weird element.”

By making an independent podcast, the cast doesn’t have to jump through the corporate and bureaucratic hoops that are ever-present in the creative arts.

Three years ago, IAC sold CH Media, the parent company of CollegeHumor and streaming service Dropout, where “Dimension 20” airs. The company’s chief creative officer Sam Reich bought the company from IAC and took over as CEO, but had to lay off more than 100 staff, since CollegeHumor was not profitable. Against all odds, the company survived these harsh changes — but it’s not so easy to make the numbers shake out when you’re running a subscription-based streaming platform. Just look at Netflix.

“Worlds Beyond Number” producer Taylor Moore is no stranger to the woes of forging a creative life under the tyranny of the corporate world. Once the head of comedy and podcasts at Kickstarter, Moore was fired in 2019 while playing an instrumental role in forming the crowdfunding company’s historic labor union. About a year later, the National Labor Relations Board found merit to Moore’s complaint that Kickstarter illegally retaliated against him for participating in protected organizing activities; the company settled with him via a payment of about $36,000.

“I’ve dedicated my entire career to getting independent artists paid, and helping them make their stuff,” Moore told TechCrunch. “For thousands of years, the only way to make culture for many people was to either be born rich, so you have money to make it, or to knock on the door of a rich person’s house and a guy opens it in his bathrobe, and you have to make him happy […] Now you don’t have to do that.”

Meanwhile, Wilson and Ishii came up as Hollywood actors, making their way in an industry in which performers have very little creative freedom.

“Financially, we knew that this was something we could do, and we wouldn’t have to be doing self-tapes at midnight, trying to secure the bag,” Wilson said. “This could be something we did for ourselves, and we wouldn’t be futzing with lights while quietly weeping and saying, ‘I just want to play Bear Number Two in the Country Bears reboot for Disney Plus.’ Which is not something that happened last night.”

In other words: This crew of creators has the fan base necessary to make going independent possible, so why burn the midnight oil to audition for “Bear Number Two” when thousands of people want to pay you $5 a month to make up stories with your friends?

Of course, there’s a whole legion of talented creators who don’t have platforms as large as the “Worlds Beyond Number” cast, making it harder to venture out on their own. But some smaller independent shows can still manage to make a living if they are smart about how they structure fan memberships, advertisements and other income streams.

TTRPG actual play podcasts have exploded in popularity over the last several years, propelling franchises like Dungeons & Dragons out of fringe nerd culture and into the mainstream. Wizards of the Coast, the Hasbro-owned publisher of Dungeons & Dragons, recently tried to change the gaming license that allows third-party creators to make a living off of the game. In the end, the publisher took a massive step back after coordinated fan backlash, deciding to permanently license the game under Creative Commons.

Podcasts and other actual play content is covered under a separate fan content policy, but the controversy over these proposed license changes reverberated through the community, making content creators reconsider whether they wanted to continue platforming this game.

“People have been sitting around fires and making up stories with each other since before civilization, and we’re gonna keep doing it after civilization falls… probably in the next 20 to 30 years,” Moore said, throwing in what’s hopefully a joke. “The companies, the legal stuff, all this other stuff, the shape of the logs you sit on, the tech, the RSS feed that you use to do it… all that’s just waves on the surface that we can safely ignore because we are down here like the Kraken in the great deep sea, doing the fundamental thing of just hanging out and doing make-them-ups.”

“Worlds Beyond Number” will start with a Dungeons & Dragons campaign, with Mulligan as dungeon master. But Ishii said they already have ideas of other games they want to run, including some systems that don’t even involve dice.

Though these games contain spellcasting and sorcery, the real magic is watching a group of creative people work together to tell improvised, collaborative stories, guided by the structure of game systems and dice rolls.

“When I improvise or act, I’m on a stage, and I know that I’m on a stage. I’m aware that I’m standing up here on this platform, and you’re down there watching,” Wilson told TechCrunch. “Through games, the characters I create are often myself. The writing that we’re doing, that is improvised, is us. And so the art we make is a much more intimate experience, since all of my characters are pieces of myself.”

The biggest names in D&D are going independent on ‘Worlds Beyond Number’ by Amanda Silberling originally published on TechCrunch


from https://ift.tt/BnVfzCF
via Technews
Share:

Rivian to cut another 6% of its workforce

Rivian, the buzzy EV automaker that had one of the biggest IPOs in 2021, is cutting 6% of its workforce for the second time in less than a year, according to an internal memo sent to employees today by founder and CEO RJ Scaringe.

Reuters was the first to report about the cuts. TechCrunch has also viewed the leaked memo. A Rivian spokesperson confirmed the layoffs.

The memo comes six months since Rivian initiated its first layoffs. In July, Rivian cut 6% of its roughly 14,000-person workforce as the company attempted to get ahead of macroeconomic headwinds caused by rising inflation, interest rates and commodity prices.

Manufacturing jobs at the company’s Normal, Illinois factory will not be impacted, according to memo sent Wednesday. The cuts are aimed at lowering Rivian’s operational costs amid a weakening economy and pricing pressure from Tesla and other automakers.

“To deliver over the long-term, we must focus our resources on ramp and our path to profitability while ensuring we have the right set of future products, services and technology that will continue to challenge convention,” Scaringe wrote in the memo. “In 2022, we took steps to focus our product portfolio and drive a lower cost structure. Continuing to improve our operating efficiency on our path to profitability is a core objective and requires us to concentrate our investments and resources on the highest impact parts of our business. This includes the continued ramp of R1 and EDV production as well the launch of our high-volume R2 platform. The changes we are announcing today reflect this focused roadmap.”

Tesla, the EV sales leader that has one of the higher profit margins in the sector, has discounted its vehicles, or offered credits, at least four times in the past several months, kicking off what many in the industry have dubbed an EV price war. Ford recently followed Tesla’s lead, forcing other automakers to consider making the same move or risk seeing a drop in sales.

Sales of Rivian’s premium all-electric R1T truck and R1S SUV could drop if consumers turn to other lower priced options. Ford has not lowered the price of its F-150 Lightning truck giving Rivian a reprieve for now.

Rivian to cut another 6% of its workforce by Kirsten Korosec originally published on TechCrunch


from https://ift.tt/Mrjb1Ja
via Technews
Share:

FTC slaps $1.5M fine on GoodRx for sharing users’ health data with Facebook and Google

Online pharmacy GoodRx has agreed to pay $1.5 million in civil penalties for years of sharing the health information of consumers with third parties like Facebook, Google, and Criteo for advertising purposes, the Federal Trade Commission said Wednesday.

In a complaint filed in a California federal court, the FTC accused the healthcare and telemedicine giant of failing to notify consumers that their personal health information — collected while using its website and services — would be shared with third parties.

The FTC said GoodRx “deceptively promised its users that it would never share personal health information with advertisers or other third parties,” but “repeatedly violated this promise,” including by monetizing the data it collected to target its own users with targeted health and medication-specific ads. The FTC said that GoodRx has been doing this “for years.”

TechCrunch reached out to GoodRx for comment and will update this story as and when we get a response.

This is the first enforcement action taken under the FTC’s Health Breach Notification Rule — a decade-old guideline that had not been previously used until today.

GoodRx is a prime example of how the rules might be violated, but with the proliferation of online healthcare services in recent years — which got a boost in particular with the arrival of the COVID-19 pandemic — there are signs that we may start to see more enforcements of the rule.

The FTC warned as recently as 2021 (and laid out that warning more formally a year ago) that the rule also applies to app developers and fitness device makers, and that it would take action against companies that fail to tell consumers that their health data would be shared for advertising or user analytics.

The rule is particularly important in light of the fact that there are ever more healthcare services coming online. Just last week, Amazon launched RxPass, a Prime add-on that lets people fill all of their prescriptions for a set of conditions using generic prescription drugs for one flat monthly fee. TechCrunch reached out to Amazon to specify its own policies with customer data and will update this post with any responses.

‘Do not cash in on extremely sensitive health information’

According to the FTC’s complaint, GoodRx was sharing the names of medications and associated health conditions that users were searching on GoodRx with adtech players like Meta, Google and Criteo, which manage billions of dollars of advertising not just on platforms like Google.com, Facebook and Instagram, but on other sites and apps as well.

An FTC official told reporters on a call Tuesday that some of this information contained sensitive details about people’s health conditions.

The FTC also said GoodRx compiled lists of its users who bought certain medications — heart disease and blood pressure, specifically — and uploaded their email addresses, phone numbers, and pseudonymized device advertising IDs to Facebook so that GoodRx could identify who they were and target them with health-related advertisements.

The agency also accused GoodRx of “falsely suggesting” to consumers that the company was compliant with the U.S. health privacy law, Health Insurance Portability and Accountability Act, or HIPAA. The FTC official said consumers were misled into thinking their data was protected when much of GoodRx’s business was not covered by the law.

Under the order, GoodRx will be banned from disclosing users’ health information with third parties for advertising purposes. It will also be required to limit how long it can retain personal and health information “according to a data retention schedule” and it needs to detail to users what it collects and why. It also needs to implement a privacy program to protect consumers’ data in the future.

The FTC will also require GoodRx to seek the deletion of data by contacting the companies it shared users’ data with. But the FTC official conceded that its enforcement action binds GoodRx, and does not compel the companies who received the data to comply with the deletion request. GoodRx must also establish a comprehensive privacy program and “conspicuously” detail what data it will disclose to third-parties.

“Digital health companies and mobile apps should not cash in on consumer’s extremely sensitive and personally identifiable health information,” said Samuel Levine, the director of the FTC’s consumer protection bureau, in a statement. “The FTC is serving notice that it will use all of its legal authority to protect American consumers’ sensitive data from misuse and illegal exploitation.”

Some 55 million consumers have visited GoodRx’s website since 2017.

The FTC’s order is subject to approval by the federal court.

FTC slaps $1.5M fine on GoodRx for sharing users’ health data with Facebook and Google by Zack Whittaker originally published on TechCrunch


from https://ift.tt/5UbNYIJ
via Technews
Share:

Popular Post

Search This Blog

Powered by Blogger.

Labels

Labels

Most view post

Facebook Page

Recent Posts

Blog Archive