United States: To Avoid Claims, Assess Privacy Impacts Of Marketing And CRM

Last Updated: November 15 2014
Article by Alan L. Friel

Editor's Note: We recently launched a graphic illustrating our Cyber Risk Mitigation Services. This week, our attorneys will be writing about specific examples of those services.

Big data and the interactivity of digital marketing are powerful tools for marketers, but consumer data protection laws have evolved in recent years, resulting in new and heightened compliance and risk management issues that need to be addressed when executing advanced advertising campaigns and consumer relationship management ("CRM") programs. This can be done effectively only if a company develops a privacy-by-design compliance culture that implements a process of conducting impact assessments before launching new products, services, campaigns or programs that could have an effect on consumer privacy or data protection. Such assessments can also incorporate analysis of traditional consumer protection impacts, such as compliance with advertising and sales laws, and analysis of intellectual property impacts (both third-party infringement risks and protection of company IP). We have developed forms for clients to use to help their legal and/or compliance professionals gather the relevant information from product and marketing teams to access legal impacts during the development process so that products and sales and marketing can be designed in a manner that minimizes potential liability while achieving business goals. This approach is fundamental to the BakerHostetler approach to helping clients be proactive and not just reactive to privacy and data protection and other consumer protection issues.

Companies are increasingly relying on innovative and edgy digital marketing campaigns to promote their products and services. Campaigns often include user-generated content, viral marketing, the brand's web site, a mobile application, and other social media and social networking elements. Companies are also looking to harness data through loyalty programs and consumer  tracking to better understand and serve their customers. However, the tech-savvy marketing professionals who are entrusted to implement these programs are often unaware of the complex patchwork of state and federal legal schemes, self-regulatory program obligations, and potential significant financial repercussions for their companies' failure to comply with applicable laws.

As a starting point for in-house counsel to assess the privacy impacts of their companies' marketing and sales activities, see the list below, which poses questions you should be asking. When you read the answers to the questions below, you will get guidance on the issues to help inform your diligence and counsel. There are an equal number of advertising law and intellectual property issues that relate to marketing campaigns and CRM programs, which will be addressed in subsequent blog posts.

The last decade has seen technology change how companies can target consumers in ways hardly imagined. The results can be beneficial to both brands and consumers, but consumers also face real risks and burdens as a result. Beyond the privacy issues discussed above, regulatory and intellectual property issues must be considered, both of which will be discussed in future blog posts and client advisories. Companies need to weigh the benefits and risks of proposed advertising, CRM, and sales schemes and be aware of the changing regulatory landscape that is evolving as technology advances. Further, the most important asset a brand has is its consumer goodwill. New marketing, CRM, and sales approaches that consumers appreciate build goodwill, but those that are perceived as misleading, unfair, or too intrusive can harm the brand. The role of legal counsel is to help marketers identify and evaluate the risks of novel promotional, consumer relationship management, and sales techniques from conceptualization though execution so that they may minimize risk while still achieving a compelling campaign that delivers the desired return on investment.

This post is based in part on TOP TEN PRIVACY CONSIDERATIONS FOR DIGITAL MARKETING, to be published in Promotion and Marketing Law, 8th Ed. (Brand Activation Assoc. Foundation, 2014).

1. Have you posted an appropriate privacy policy?

Not posting a privacy policy on a web site, mobile application, Facebook application or any other online service that collects personally identifiable information (e.g., first and last name, address, email address, telephone number) from a consumer violates not only Federal Trade Commission ("FTC") guidance but also California's Online Privacy Protection Act of 2003 ("CalOPPA"). Companies that collect personally identifiable information from California residents through any online service for commercial purposes, even if they are not themselves in California, must conspicuously post a privacy policy that informs individuals of this collection, including:

  • identifying the categories of personally identifiable information collected and third parties with which such information may be shared;
  • describing any process (if the site has one) for reviewing and requesting changes to collected information;
  • describing the process by which the operator notifies users regarding material changes to the policy; and
  • identifying the effective date of the policy.

Further, recent amendments to CalOPPA, effective January 1, 2014, require the privacy policy to additionally inform individuals of the following site practices:

  • disclosing how the operator responds to web browser "do not track" signals or other mechanisms that provide consumers the ability to exercise choice regarding the collection of personally identifiable information; and
  • disclosing whether third parties may collect personally identifiable information about an individual consumer's online activities over time and across different web sites when a consumer uses the operator's site or service.

As of January 1, 2015, privacy policies of services that allow user content postings will also have to provide in a specific manner a notice and a takedown process for minors to remove content they have posted about themselves.

CalOPPA requires privacy policies to accurately describe data practices and provides specifics as to how its requirement of "conspicuous posting" may be met, including with regard to placement, various types of font treatment, and word content. The California Attorney General has issued further guidance, particularly on how to deal with the small screens of mobile devices. The FTC has long used its deception authority to prosecute inaccurate or misleading statements in privacy policies as false advertising claims. In addition, certain regulated industries have specific privacy disclosure obligations, and online services directed to children have special regulatory requirements, outlined below. Accordingly, it is essential that companies annually audit their data collection, use, sharing, processing, storage, and security practices and ensure that their privacy policies completely and accurately explain all material practices and comply with applicable laws. Most companies will also need to meet the more stringent California requirements.

In 2013, the California Attorney General sent notices to hundreds of companies, many located outside of the state, that their sites or mobile apps did not include a privacy policy as required by CalOPPA, and where a company failed to comply within 30 days, filed suit under California's Unfair Business Practices Act. While CalOPPA requires such notice and opportunity to cure for failing to post a privacy policy, no notice and cure opportunity is necessary for a state or local prosecutor or for a consumer to bring a CalOPPA-based claim for false or misleading statements in a privacy policy.

2. Are you using third parties to collect information, or are you sharing information you collect with third parties?

In addition to the third-party tracking disclosure requirements of the CalOPPA amendment noted above, it is important to consider what information third parties may be directly collecting on your sites and what information you may be sharing with third parties such as co-promotional partners. With third parties you are working with on a campaign, you should consider whether you have addressed data ownership and control issues, properly disclosed information sharing practices, and imposed legally required security obligations where necessary. When addressing the sharing of information with third parties, don't forget that third parties can, under many laws, include your affiliate companies. Although it may feel to you like one big, happy family when you share information among affiliates, you may be creating the wrong impression if you say in your privacy policy, or at an information collection point, that you do not share information collected with any third parties. Companies should particularly take care to assess their obligations under California Civil Code Section 1798.83 (also known as California's "Shine the Light" law), which provides California residents with certain rights with respect to sharing certain consumer information collected online or offline with third parties (including affiliates) for the third parties' direct marketing purposes. Failure to comply with that scheme has spawned a number of class action lawsuits. Further, a bill in the California legislature would vastly expand the scope and effect of that law.

3. Does your campaign incorporate cookies, pixel tags, browser fingerprinting, web beacons, or other tracking technologies, and do you disclose these practices?

Undisclosed passive tracking is the stuff that media headlines are made of, and depending upon the scope of the information collected, it may now be required to be disclosed under the recent CalOPPA amendment discussed above. Cookies and other passive tracking practices are receiving increasing scrutiny domestically and globally (particularly in the European Union and Canada) from both the press and lawmakers. Even where passively tracked information is not linked to what we in the U.S. traditionally consider personally identifiable information, it can still raise privacy notice and consent issues. Also, almost every site now uses Google Analytics, and Google requires that certain disclosures be included in your privacy policy, as do other third-party vendors that most sites rely on to operate and serve ads. Thus, most companies engage dozens of vendors to help them operate their sites or services, and those vendors similarly contractually require that specific notices and opt-outs be followed by the companies. Third parties (government, media, consumer organizations, and site visitors) can use various browser add-ons (see http://www.ghostery.com) as a means to reveal whether a site's representations about passive tracking match up with actual practice. Misrepresentations and potentially material omissions are actionable as deceptive advertising claims. Revise your privacy policy to thoroughly address passive means of collecting information on your site or application. As part of a data practices assessment, talk with your IT staff and marketing staff to ensure that you cover all of your bases and get an accurate picture of what is going on with your site and in connection with your digital campaigns.

4. Has "privacy by design" been incorporated in your campaign development process?

In March 2012, the FTC released a set of recommendations for businesses regarding the collection and use of consumer personal information. (See FTC Issues Final Commission Report on Protecting Consumer Privacy.) A central tenant of this ("Privacy Framework") is the notion of "privacy by design ("PbD"), which is the philosophy of embedding privacy and data security considerations from the outset into the design development of information technologies and minimizing the collection and use of data to what is necessary under the circumstances. The goal of privacy by design is to minimize the privacy impact on consumers and maximize their informed choice. Companies that can "bake in" privacy protections for a new campaign in the conceptualization phase are more likely to avoid having to try to make changes right before launch or post-launch, when doing so may cause delay and additional cost. In order to effectively implement PbD, it is essential that a knowledgeable privacy professional evaluate the planned data practices to identify issues. For instance, the defendants in the recent flood of lawsuits relating to collection of consumer information as seemingly innocuous as mere zip codes in connection with credit card purchases, which violates California, Massachusetts, and other state laws, could have avoided those claims had they had compliance counsel involved in the development of the purchase flows. Such an impact assessment is essential when integrating loyalty programs with point-of-sale to avoid noncompliance with these credit card transaction privacy laws.

5. Do you offer choice regarding future marketing communications?

Companies with immature compliance programs may be surprised to find out that they can't send out marketing materials unless they have the proper permission to do so. The ability to communicate with consumers is increasingly subject to different legal requirements both in this country and internationally. Under the CAN-SPAM Act (Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003), email marketing to consumers is largely an "opt out" regime in the U.S. (other countries are "opt in"). Thus, companies are required to offer customers the ability to opt out from receiving future email marketing communications in any marketing email sent. Companies should also be mindful of special rules associated with marketing communications sent to mobile devices. The Telephone Consumer Protection Act ("TCPA"), telecom carrier rules, and Mobile Marketing Association Mobile Advertising Guidelines govern the sending of text messages and emails to mobile domain addresses. Companies must satisfy notice and express advanced written consent requirements before sending a commercial text message to a mobile device, though written consent may be electronic if certain requirements are met. A change, effective October 1, 2014, to Connecticut's version of TCPA seemingly expands the scope of the types of covered mobile messages beyond MMS and SMS to mobile app push notifications, a device marketers have been using to avoid the TCPA's express written consent requirements. Additional rules govern telemarketing and fax marketing. TCPA violations have spawned many class action lawsuits, resulting in tens of millions of dollars in settlements paid by advertisers that failed to fully comply.

To avoid problems with future marketing campaigns, companies must carefully consider when it is appropriate to take an opt-in versus an opt-out approach to the sending of future marketing communications. It is important to evaluate whether language is drafted appropriately to cover the additional communications that the company will send now and in the future, including who will send the communications (company only, affiliates, other third parties), how they will be sent (do not assume that "send me updates" means "call me at home during dinner"), and types of communications (about just one product, anything related to the company, anything related to a particular topic of interest, etc.). Recording of customer service calls is also regulated by various state laws regarding notice and consent, the violation of which has generated much recent litigation. Accordingly, companies should consider appropriate spam, do not fax, do not call, call recording, and broader communications policies

6. Have you and your vendors adopted a formal, written data protection compliance program?

Despite a sectorial approach to privacy and a state patchwork approach to data security regulation in the U.S., a growing number of companies are now subject to some form of legal obligation to adopt "reasonable" data security measures. Among the laws mandating some form of "reasonable" security are (i) the HIPAA security regulations applicable to the health care industry; (ii) the Gramm-Leach-Bliley Act ("GLB Act") "safeguards" regulations for financial institutions; (iii) state insurance law analogs to the GLB Act Safeguards Rule applicable to insurance companies; and (iv) state laws governing businesses that maintain personal information of residents (see Massachusetts, Nevada, and California). Even if your organization happens to operate outside the reach of these particular data security laws, there is a growing consensus that implementation of a formal, written security compliance program is a best practice. In Massachusetts, such a "Written Information Security Program" ("WISP") is required if a company has personal information of Massachusetts residents, even if the company itself is not present in the state. Most states also have data breach response and reporting laws, which require prompt action following a suspected compromise. Indeed, the FTC has been very active in exercising its unfairness authority to prosecute companies that have experienced data security breaches, under the theory that failure to take reasonable measure to protect data, even data that is not sensitive (e.g., Twitter account credentials) in an unfair business practice.

7. Does your company engage in behavioral advertising?

Online behavioral advertising ("OBA"), interest-based advertising, and targeted and retargeted advertising are terms used to describe this process of companies' tracking consumers' online activities to profile and target them for specially tailored advertising. Many companies advertise using OBA but may not be directly involved in collecting and using the OBA data because they employ vendors and ad servers to do this. However, an advertiser, even if engaging in OBA on a non-affiliated site (e.g., retargeting a user who has left your site with an ad on another site), is subject to self-regulatory rules and best practices guidance promulgated by the FTC.

Before engaging in any OBA, companies (both advertisers and publishers) should review the behavioral advertising self-regulatory guidance of the Digital Advertising Alliance ("DAA"). See http://www.aboutads.info/ . The DAA's guidance provides a self-regulatory framework for advertisers, agencies, publishers, and technology companies for engaging in OBA. The DAA provides an iconic form of notice that alerts consumers to OBA and provides a method to opt out. Though the opt-out method is currently browser-based and thus not effective for mobile apps, the DAA is currently beta testing a similar notice and opt-out program for OBA via mobile apps. While the DAA licenses the icon itself for $5,000 a year, it has three approved service providers that provide compliance and analytics services and can provide the license as part of their services. The DAA's enforcement division has brought a dozen or more actions against noncompliant advertisers, most recently against web site publishers that were dropping retargeting cookies on users, without the required notice on such web pages, to enable ads from that site to be served later when users visited other sites.

To identify and minimize risks, companies should take steps to (i) understand what tracking is taking place through their marketing campaigns as well as their web sites and mobile applications; (ii) include the requisite insurance and indemnity provisions in their agreements with vendors assisting them with OBA; and (c) include appropriate disclosures in their privacy policies, on their home pages, and on OBA ads to address what OBA activities may be occurring.

8. Is your marketing or sales targeted to children?

Children's privacy issues are lurking in many digital marketing campaigns, whether or not the campaigns are directed to children. On July 1, 2013, the FTC updated the Children's Online Privacy Protection Act ("COPPA"), which requires a company to obtain parental consent prior to collecting personal information from a child under the age of 13 online or via mobile apps, with limited exceptions. The updated COPPA regulations greatly expand what kind of data requires verified parental consent before being collected from a child under 13 years of age, and such information now includes persistent identifiers (an identifier used to recognize a user, browser, or device over time and across sites and services, such as an IP address). Also, COPPA now creates a new category of so-called mixed-use sites and apps that may in part be directed to children but not primarily so. These sites and services must now screen users for age in a neutral manner and treat them differently based on self-reported age. Mixed-use sites cannot block children under 13 completely but must offer them COPPA-compliant services. The FTC has made it clear that once any operator (even if directed to adults) has notice that a persistent identifier belongs to a child under 13, it must immediately take action to prevent a violation of COPPA. This includes ensuring that behavioral advertising is not served to them, that social media plug-ins and tools where they can submit publically available content are not made available to them, and that analytics providers and other vendors do not use their identifiers or other personal information except pursuant to certain narrow exceptions. Even if an operator could employ a cookie or other device to identify users it learns are under 13, given all the third parties affected (e.g., in the advertising ecosystem), real challenges remain to be solved before effective differentiation can become reality. In the meantime, other work-arounds can be employed to minimize risk. Digital marketing campaigns that are clearly required to comply with COPPA because they are targeted to children, even in material part, often make basic mistakes, such as not posting a COPPA-compliant privacy policy (or any privacy policy at all), making the policy hard to find, assuming that it is okay to collect information from children as long as the site does not do anything with it, or failing to properly secure parental consent before personal information from a child is collected.

9. Will your campaign collect location-based information from consumers or otherwise publicly share a consumer's location?

Location-based services ("LBS") have one thing in common regardless of the underlying technology — they rely on, use, or incorporate the location of a device to provide or enhance a service. For instance, a consumer may be able to "check in" at a location with his or her current location displayed to others using the LBS. Retailers are starting to employ in-store "iBeacons" that interact with consumers' mobile devices. Or users' locations can be tracked so that geographically relevant content or ads can be sent to them. Another popular location-based service is an application that enables users to locate other users who are near them. While such functionality can be valued by users, it is potentially intrusive, and companies should require that certain notices and consents be given and obtained before enabling such functionality on apps or other services. General caution should also be exercised. The San Francisco District Attorney recently sued a mobile app publisher that made teenagers' locations available to each other as an unfair business practice, alleging that it put minors at risk of becoming victims of sexual predators. A digital marketing campaign that incorporates LBS technology should give a user appropriate notice about how location information will be collected, used, shared, and disclosed and should consider age restrictions. With respect to location tracking and accessing certain device content or functionality, notice, opportunity to review, and consent are required by carrier and platform rules. User tracking also requires notice and consent in the European Union, and U.S. best practice is to give notice and a means to disable tracking (even if by uninstalling the entire app or service). For LBS technology, there should be a notice and opt-in permission to geo-location tracking that is displayed on a single screen, with links to a more detailed privacy policy, before LBS functionality is enabled. It will also be necessary to post a privacy policy on the app or service (which should be available at the point of registration, if applicable, and on an information page) that specifically addresses the collection of location-based or other sensitive data. The privacy policy should inform users of how they may terminate the collection of location-based information (which may be by uninstalling the software or by exercising privacy options) and of how to exercise any available privacy options (providing such options is recommended). Short-form notice is recommended at the point of consent.

10. Do you acquire or share content consumption data?

The Video Privacy Protection Act ("VPPA") and similar state laws prohibit disclosure of information that identifies a person as having requested or obtained specific video materials or services, without having first obtained consent from the user. Some companies wish to share video content consumption information with third parties and/or allow users to share what videos they watched on the company's site with a social networking site like Facebook. In order for a company to be able to share video viewing info with a third party social media site, the company first needs to obtain user consent to do so. Video service providers can obtain consent electronically over the Internet from a user for use of the video information for a maximum period of two years under the VPPA as it has been recently amended, though some state laws have more complex consent requirements. The form of VPPA consent requires that a separate, independent consent be obtained from the user (outside of consent obtained in a privacy policy/terms of use). Thus, companies wishing to share video content consumption information may need to post a separate "Video Privacy Policy" on their sites that complies with the requirements of the VPPA and state laws, and they may need to obtain consent to this document from users that is separate and apart from the consent obtained to typical privacy policies and terms of use before sharing a user's video consumption data, absent statutory exception.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

To print this article, all you need is to be registered on Mondaq.com.

Click to Login as an existing user or Register so you can print this article.

Authors
 
In association with
Related Video
Up-coming Events Search
Tools
Print
Font Size:
Translation
Channels
Mondaq on Twitter
 
Register for Access and our Free Biweekly Alert for
This service is completely free. Access 250,000 archived articles from 100+ countries and get a personalised email twice a week covering developments (and yes, our lawyers like to think you’ve read our Disclaimer).
 
Email Address
Company Name
Password
Confirm Password
Position
Mondaq Topics -- Select your Interests
 Accounting
 Anti-trust
 Commercial
 Compliance
 Consumer
 Criminal
 Employment
 Energy
 Environment
 Family
 Finance
 Government
 Healthcare
 Immigration
 Insolvency
 Insurance
 International
 IP
 Law Performance
 Law Practice
 Litigation
 Media & IT
 Privacy
 Real Estate
 Strategy
 Tax
 Technology
 Transport
 Wealth Mgt
Regions
Africa
Asia
Asia Pacific
Australasia
Canada
Caribbean
Europe
European Union
Latin America
Middle East
U.K.
United States
Worldwide Updates
Check to state you have read and
agree to our Terms and Conditions

Terms & Conditions and Privacy Statement

Mondaq.com (the Website) is owned and managed by Mondaq Ltd and as a user you are granted a non-exclusive, revocable license to access the Website under its terms and conditions of use. Your use of the Website constitutes your agreement to the following terms and conditions of use. Mondaq Ltd may terminate your use of the Website if you are in breach of these terms and conditions or if Mondaq Ltd decides to terminate your license of use for whatever reason.

Use of www.mondaq.com

You may use the Website but are required to register as a user if you wish to read the full text of the content and articles available (the Content). You may not modify, publish, transmit, transfer or sell, reproduce, create derivative works from, distribute, perform, link, display, or in any way exploit any of the Content, in whole or in part, except as expressly permitted in these terms & conditions or with the prior written consent of Mondaq Ltd. You may not use electronic or other means to extract details or information about Mondaq.com’s content, users or contributors in order to offer them any services or products which compete directly or indirectly with Mondaq Ltd’s services and products.

Disclaimer

Mondaq Ltd and/or its respective suppliers make no representations about the suitability of the information contained in the documents and related graphics published on this server for any purpose. All such documents and related graphics are provided "as is" without warranty of any kind. Mondaq Ltd and/or its respective suppliers hereby disclaim all warranties and conditions with regard to this information, including all implied warranties and conditions of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall Mondaq Ltd and/or its respective suppliers be liable for any special, indirect or consequential damages or any damages whatsoever resulting from loss of use, data or profits, whether in an action of contract, negligence or other tortious action, arising out of or in connection with the use or performance of information available from this server.

The documents and related graphics published on this server could include technical inaccuracies or typographical errors. Changes are periodically added to the information herein. Mondaq Ltd and/or its respective suppliers may make improvements and/or changes in the product(s) and/or the program(s) described herein at any time.

Registration

Mondaq Ltd requires you to register and provide information that personally identifies you, including what sort of information you are interested in, for three primary purposes:

  • To allow you to personalize the Mondaq websites you are visiting.
  • To enable features such as password reminder, newsletter alerts, email a colleague, and linking from Mondaq (and its affiliate sites) to your website.
  • To produce demographic feedback for our information providers who provide information free for your use.

Mondaq (and its affiliate sites) do not sell or provide your details to third parties other than information providers. The reason we provide our information providers with this information is so that they can measure the response their articles are receiving and provide you with information about their products and services.

If you do not want us to provide your name and email address you may opt out by clicking here .

If you do not wish to receive any future announcements of products and services offered by Mondaq by clicking here .

Information Collection and Use

We require site users to register with Mondaq (and its affiliate sites) to view the free information on the site. We also collect information from our users at several different points on the websites: this is so that we can customise the sites according to individual usage, provide 'session-aware' functionality, and ensure that content is acquired and developed appropriately. This gives us an overall picture of our user profiles, which in turn shows to our Editorial Contributors the type of person they are reaching by posting articles on Mondaq (and its affiliate sites) – meaning more free content for registered users.

We are only able to provide the material on the Mondaq (and its affiliate sites) site free to site visitors because we can pass on information about the pages that users are viewing and the personal information users provide to us (e.g. email addresses) to reputable contributing firms such as law firms who author those pages. We do not sell or rent information to anyone else other than the authors of those pages, who may change from time to time. Should you wish us not to disclose your details to any of these parties, please tick the box above or tick the box marked "Opt out of Registration Information Disclosure" on the Your Profile page. We and our author organisations may only contact you via email or other means if you allow us to do so. Users can opt out of contact when they register on the site, or send an email to unsubscribe@mondaq.com with “no disclosure” in the subject heading

Mondaq News Alerts

In order to receive Mondaq News Alerts, users have to complete a separate registration form. This is a personalised service where users choose regions and topics of interest and we send it only to those users who have requested it. Users can stop receiving these Alerts by going to the Mondaq News Alerts page and deselecting all interest areas. In the same way users can amend their personal preferences to add or remove subject areas.

Cookies

A cookie is a small text file written to a user’s hard drive that contains an identifying user number. The cookies do not contain any personal information about users. We use the cookie so users do not have to log in every time they use the service and the cookie will automatically expire if you do not visit the Mondaq website (or its affiliate sites) for 12 months. We also use the cookie to personalise a user's experience of the site (for example to show information specific to a user's region). As the Mondaq sites are fully personalised and cookies are essential to its core technology the site will function unpredictably with browsers that do not support cookies - or where cookies are disabled (in these circumstances we advise you to attempt to locate the information you require elsewhere on the web). However if you are concerned about the presence of a Mondaq cookie on your machine you can also choose to expire the cookie immediately (remove it) by selecting the 'Log Off' menu option as the last thing you do when you use the site.

Some of our business partners may use cookies on our site (for example, advertisers). However, we have no access to or control over these cookies and we are not aware of any at present that do so.

Log Files

We use IP addresses to analyse trends, administer the site, track movement, and gather broad demographic information for aggregate use. IP addresses are not linked to personally identifiable information.

Links

This web site contains links to other sites. Please be aware that Mondaq (or its affiliate sites) are not responsible for the privacy practices of such other sites. We encourage our users to be aware when they leave our site and to read the privacy statements of these third party sites. This privacy statement applies solely to information collected by this Web site.

Surveys & Contests

From time-to-time our site requests information from users via surveys or contests. Participation in these surveys or contests is completely voluntary and the user therefore has a choice whether or not to disclose any information requested. Information requested may include contact information (such as name and delivery address), and demographic information (such as postcode, age level). Contact information will be used to notify the winners and award prizes. Survey information will be used for purposes of monitoring or improving the functionality of the site.

Mail-A-Friend

If a user elects to use our referral service for informing a friend about our site, we ask them for the friend’s name and email address. Mondaq stores this information and may contact the friend to invite them to register with Mondaq, but they will not be contacted more than once. The friend may contact Mondaq to request the removal of this information from our database.

Emails

From time to time Mondaq may send you emails promoting Mondaq services including new services. You may opt out of receiving such emails by clicking below.

*** If you do not wish to receive any future announcements of services offered by Mondaq you may opt out by clicking here .

Security

This website takes every reasonable precaution to protect our users’ information. When users submit sensitive information via the website, your information is protected using firewalls and other security technology. If you have any questions about the security at our website, you can send an email to webmaster@mondaq.com.

Correcting/Updating Personal Information

If a user’s personally identifiable information changes (such as postcode), or if a user no longer desires our service, we will endeavour to provide a way to correct, update or remove that user’s personal data provided to us. This can usually be done at the “Your Profile” page or by sending an email to EditorialAdvisor@mondaq.com.

Notification of Changes

If we decide to change our Terms & Conditions or Privacy Policy, we will post those changes on our site so our users are always aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it. If at any point we decide to use personally identifiable information in a manner different from that stated at the time it was collected, we will notify users by way of an email. Users will have a choice as to whether or not we use their information in this different manner. We will use information in accordance with the privacy policy under which the information was collected.

How to contact Mondaq

You can contact us with comments or queries at enquiries@mondaq.com.

If for some reason you believe Mondaq Ltd. has not adhered to these principles, please notify us by e-mail at problems@mondaq.com and we will use commercially reasonable efforts to determine and correct the problem promptly.