Websites selling abortion pills are sharing sensitive data with Google

Package of Mifeprestone

This story originally appeared on ProPublica.

Online pharmacies that sell abortion pills are sharing sensitive data with Google and other third parties, which may allow law enforcement to prosecute those who use the medications to end their pregnancies, a ProPublica analysis has found.

Using a tool created by the Markup, a nonprofit tech-journalism newsroom, ProPublica ran checks on 11 online pharmacies that sell abortion medication to reveal the web tracking technology they use. Late last year and in early January, ProPublica found web trackers on the sites of at least nine online pharmacies that provide pills by mail: Abortion Ease, BestAbortionPill.com, PrivacyPillRX, PillsOnlineRX, Secure Abortion Pills, AbortionRx, Generic Abortion Pills, Abortion Privacy and Online Abortion Pill Rx.

These third-party trackers, including a Google Analytics tool and advertising technologies, collect a host of details about users and feed them to tech behemoth Google, its parent company, Alphabet, and other third parties, such as the online chat provider LiveChat. Those details include the web addresses the users visited, what they clicked on, the search terms they used to find a website, the previous site they visited, their general location, and information about the devices they used, such as whether they were on a computer or phone. This information helps websites function and helps tech companies personalize ads.

But the nine sites are also sending data to Google that can potentially identify users, ProPublica’s analysis found, including a random number that is unique to a user’s browser, which can then be linked to other collected data.

“Why in the world would you do that as a pharmacy website?” said Serge Egelman, research director of the Usable Security and Privacy Group at the International Computer Science Institute at the University of California, Berkeley. “Ultimately, it’s a pretty dumb thing to do.”

Representatives for the nine sites did not respond to requests for comment. All were recommended on the popular website Plan C, which provides information about how to get abortion pills by mail, including in states where abortion is illegal. Plan C acknowledged that it does not have control over these sites or their privacy practices.

While many people may assume their health information is legally protected, US privacy law does little to constrain the kind or amount of data that companies such as Google and Facebook can collect from individuals. Tech companies are generally not bound by the Health Insurance Portability and Accountability Act, known as HIPAA, which limits when certain health care providers and health plans can share a patient’s medical information. Nor does federal law set many limits on how companies can use this data.

Law enforcement can obtain people’s data from tech companies such as Google, whose privacy policies say the companies reserve the right to share users’ data with law enforcement. Google requires a court order or search warrant, which law enforcement can obtain with probable cause to believe a search is justified. The company received more than 87,000 subpoenas and search warrants in the US in 2021, the most recent year available; it does not provide a breakdown of these requests by type, such as how many involved abortion medication.

In a statement, Steve Ganem, product director of Google Analytics, said: “Any data in Google Analytics is obfuscated and aggregated in a way that prevents it from being used to identify an individual and our policies prohibit customers from sending us data that could be used to identify a user.”

https://arstechnica.com/?p=1911084




Bill Would Force Period Tracking Apps to Follow Privacy Laws

When the Supreme Court last June stripped away constitutional protections for abortion, concerns grew over the use of period tracking apps because they aren’t protected by federal privacy laws.

Privacy experts have said they fear pregnancies could be surveilled and the data shared with police or sold to vigilantes.

Some Washington state lawmakers want to change that and have introduced a bill related to how consumer data is shared, KUOW reported.

Democratic Rep. Vandana Slatter represents Washington’s 48th legislative district, which covers much of Redmond, Bellevue, and Kirkland. She is sponsoring House Bill 1155, which focuses on the collection, sharing, and selling of consumer health data.

“Someone can actually track you, and target you, in some way that can be really harmful,” Slatter said.

HIPAA, the 1996 Health Insurance Portability and Accountability Act, protects medical files at your doctor’s office but not the information that third-party apps and tech companies collect about you. Nor does HIPAA cover health histories collected by non-medical “crisis pregnancy centers, ” which are run by anti-abortion groups. That means the information can be shared with, or sold to, almost anyone.

The Supreme Court’s decision to overturn abortion rights piqued Slatter’s interest in health data privacy, she said. Her proposed measure would make it illegal to sell any type of health data.

Rep. Jim Walsh of Aberdeen said he supports protecting a person’s privacy, but said the bill focuses too much on what he called hot button issues.

“Why do we need to use incendiary language, like about abortion?” Walsh said.

The bill is set to be presented to the state House Civil Rights and Judiciary Committee. Its companion bill in the state Senate, SB 5351, is sponsored by Sen. Manka Dhingra, D-Redmond.

Related: The Potential and Pitfalls of a Federal Privacy Law

Related: EU Tells TikTok Chief To Respect Data Privacy Laws

view counter

Previous Columns by Associated Press:
Tags:

https://www.securityweek.com/bill-would-force-period-tracking-apps-follow-privacy-laws




NSA Director Pushes Congress to Renew Surveillance Powers

A top U.S. intelligence official on Thursday urged Congress to renew sweeping powers granted to American spy agencies to surveil and examine communications, saying they were critical to stopping terrorism, cyberattacks and other threats.

The remarks by Army Gen. Paul Nakasone, director of the National Security Agency, opened what’s expected to be a contentious debate over provisions of the Foreign Intelligence Surveillance Act that expire at year’s end. The bipartisan consensus in favor of expanded surveillance powers in the years after Sept. 11 has given way to increased skepticism, especially among some Republicans who believe spy agencies used those powers to undermine former President Donald Trump.

The new GOP majority in the U.S. House has already formed a panel on the “weaponization of the federal government.” And progressive Democrats have pushed for more curbs on warrantless surveillance.

The NSA and other spy agencies use authorities under FISA’s Section 702 to collect huge swaths of foreign communications, which also results in the incidental collection of emails and calls from Americans. The law prohibits spy agencies from targeting Americans and requires the FBI to seek a court order to access a U.S. citizen’s communications.

Section 702 was first added to FISA in 2008 and renewed for six years in 2018, when Trump originally tweeted opposition to the program but then reversed himself.

Nakasone argued the law “plays an outsize role in protecting the nation” and generates “some of the U.S. government’s most valuable intelligence on our most challenging targets.”

He gave several broad examples of that work, including the discovery of attempts to steal sensitive U.S. technology, stopping the transfer of weapons components, preventing cyberattacks, and “understanding the strategic intentions” of China and Russia.

“We have saved lives because of 702,” Nakasone told a virtual meeting of the U.S. Privacy and Civil Liberties Oversight Board.

The general said he could not publicly share more details about the impact of that surveillance, acknowledging that also limited his ability to make his case. Civil liberties advocates have long criticized the secrecy of intelligence court proceedings and the power agencies have to collect years of incidental data on Americans.

Cindy Cohn, executive director of the Electronic Frontier Foundation, said Congress had created an effective “national security exception to the U.S. Constitution.”

“The American people and indeed people all around the world have lost the ability to have a private conversation over digital networks,” she told the board. Section 702, Cohn said, “was a mass monitoring infrastructure that subjects people’s communications to NSA review.”

Republicans on the House Intelligence Committee and other national security hawks are expected to push GOP colleagues to support a renewal this year accompanied by still-unspecified changes.

“We’ve got to have a discussion within our own caucus, but I feel good about the groundwork we’ve laid,” said Rep. Mike Gallagher, a Wisconsin Republican who will lead the House’s new select committee on China, in an interview this week. “There’s serious and legitimate concern. And so part of the process of getting renewal is to put in place reform that gives people confidence that there won’t be abuses in the future.”

In December 2019, the Justice Department’s inspector general found the FBI had withheld key information from the Foreign Intelligence Surveillance Court as it applied for warrants to monitor the communication of Carter Page, a Trump campaign aide. But the inspector general did make clear the extent to which agents relied during that process on uncorroborated allegations compiled by a former British spy.

The chief judge of that court would issue an unusual rebuke to the FBI, saying it had made “unsupported” representations as it submitted the eavesdropping applications and had failed to provide other information that would have weakened the government’s case for surveillance.

Responding to the scrutiny, the FBI announced a series of changes designed to ensure that its applications to the court, which approves warrants to eavesdrop on American soil on people suspected of being agents of a foreign power, are more accurate.

Congress in 2020 let expire three provisions of the Patriot Act that the FBI and Justice Department had said were essential for national security, including one that permits investigators to surveil subjects without establishing that they’re acting on behalf of an international terrorism organization. A bill renewing those authorities passed the Senate, but Democrats pulled legislation from the House floor after Trump and House Republicans turned against the measure and ensured its defeat.

Related: NSA Outs Chinese Hackers Exploiting Citrix Zero-Day

Related: European Lawmaker Targeted With Cytrox Predator Surveillance Spyware

view counter

Previous Columns by Associated Press:
Tags:

https://www.securityweek.com/nsa-director-pushes-congress-renew-surveillance-powers




Corte di Giustizia Ue: tutti hanno diritto di sapere a chi sono stati comunicati i loro dati personali

Un cittadino ha chiesto all’Österreichische Post, il principale operatore di servizi postali e logistici in Austria, di comunicargli l’identità dei destinatari a cui essa aveva comunicato i suoi dati personali. Il richiedente si fondava sul regolamento generale sulla protezione dei dati UE (il RGPD). Tale regolamento prevede che la persona interessata abbia il diritto di ottenere dal titolare del trattamento le informazioni relative ai destinatari o alle categorie di destinatari a cui i suoi dati personali sono stati o saranno comunicati.

Poste austriache a giudizio

In risposta alla richiesta del cittadino, l’Österreichische Post si è limitata ad affermare che essa utilizza dati personali, nei limiti consentiti dalla legge, nell’ambito della sua attività di editore di elenchi telefonici e che fornisce tali dati ai partner commerciali a fini di marketing.

Il cittadino ha allora citato l’Österreichische Post dinanzi ai giudici austriaci. Nel corso del procedimento giudiziario, l’Österreichische Post ha inoltre informato il cittadino che i suoi dati erano stati trasmessi a taluni clienti, tra cui inserzionisti attivi nel settore della vendita per corrispondenza e del commercio tradizionale, imprese informatiche, editori di indirizzi e associazioni quali organizzazioni di beneficienza, organizzazioni non governative (ONG) o partiti politici.

L’Oberster Gerichtshof (Corte suprema, Austria), investito della controversia in ultima istanza, intende sapere se il RGPD lasci al titolare del trattamento dei dati la libera scelta di comunicare o l’identità concreta dei destinatari o unicamente le categorie dei destinatari, oppure se offra all’interessato il diritto di conoscere la loro identità concreta.

Titolare del trattamento obbligato a fornire su richiesta l’identità dei destinatari

Con la sua sentenza pronunciata in data odierna, la Corte di giustizia risponde che qualora i dati personali siano stati o saranno comunicati a destinatari, il titolare del trattamento è obbligato a fornire all’interessato, su sua richiesta, l’identità stessa di tali destinatari. Solo qualora non sia (ancora) possibile identificare detti destinatari, il titolare del trattamento può limitarsi a indicare unicamente le categorie di destinatari di cui trattasi.

Ciò vale anche qualora il titolare dimostri che la richiesta è manifestamente infondata o eccessiva. La Corte sottolinea che tale diritto di accesso dell’interessato è necessario per consentirgli di esercitare altri diritti che gli sono riconosciutigli dal RGDP, vale a dire il diritto di rettifica, il diritto alla cancellazione («diritto all’oblio»), il diritto di limitazione di trattamento, il diritto di opposizione al trattamento o, ancora, il diritto di agire in giudizio nel caso in cui subisca un danno.

https://www.key4biz.it/corte-di-giustizia-ue-tutti-hanno-diritto-di-sapere-a-chi-sono-stati-comunicati-i-loro-dati-personali/430749/




Suit accusing YouTube of tracking children is back on after appeal

Kids looking at a laptop

An appeals court has revived a lawsuit that accuses Google, YouTube, DreamWorks, and a handful of toymakers of tracking the activity on YouTube of children under 13. In an opinion released Wednesday, the Ninth US Circuit Court of Appeals ruled that the Children’s Online Privacy Protection Act does not bar lawsuits based on individual state privacy laws.

Passed in 1998 and amended in 2012, COPPA requires websites to obtain parental consent for the collection and dissemination of personally identifiable information of children under the age of 13. COPPA gives the FTC and state attorneys general the ability to investigate and levy fines for violations of the law.

Several states across the US have laws similar to COPPA on the books. The revived lawsuit cites laws in California, Colorado, Indiana, and Massachusetts to argue that Hasbro, DreamWorks, Mattel, and the Cartoon Network illegally lured children to their YouTube channels in order to target them with ads.

A federal judge in San Francisco dismissed the original lawsuit, ruling that COPPA bars individuals from suing companies for privacy violations. In a unanimous decision, the Ninth Circuit judges hearing the appeal disagreed with the district court’s reasoning. COPPA is not, in fact, the only route to enforcement, according to the ruling.

“Since the bar on ‘inconsistent’ state laws implicitly preserves ‘consistent’ state substantive laws, it would be nonsensical to assume Congress intended to simultaneously preclude all state remedies for violations of those laws,” wrote Judge Margaret McKeown.

This is not the first time YouTube has faced legal problems for how it handles children’s data. The Alphabet subsidiary was fined $170 million by the FTC and the New York state attorney general in 2019 for COPPA violations.

The case, which seeks damages for a seven-year time period between 2013 and 2020, now heads back to district court.

https://arstechnica.com/?p=1906948




PPC 2022 in review: Performance Max, Apple Search, chaos at Twitter, and more

2022 was a wild ride and we’re not just talking about NyQuil chicken or the slap heard ‘round the world at the Oscars. The digital marketing world was inundated with a new Chief twit, old platforms making comebacks (enter Microsoft), and more campaign automation features then we really care for.

As the year comes to a close, let’s take a look at some of the most headline-worthy, controversial, biggest-impacting changes that rocked the PPC world over the last 12 months.

The bigger picture

We asked and you answered. This year marketers told us that although the adoption of Google Ads automation is high, it’s their least favorite part of PPC. The gradual loss of control, as well as forcing automation and broad targeting on marketers, doesn’t give us that warm and fuzzy feeling after all. Who knew? 

But automation and economic uncertainty aside, search advertising is thriving and spending in 2023 could hit $112 billion (nearly double the spend in 2019). Google dominates that spend, holding over 56% of ad revenue. Even Black Friday and Cyber Monday hit record numbers this year. So it’s no surprise that digital marketing ranks in the top 3 hottest skills Americans are learning in 2022. 

Speaking of skills, our Search Engine Land PPC Award winners were announced. NP Digital was the big winner this year, taking home Agency of the Year along with 2 other awards. Streamline Results took Small Agency of the Year, and Workshop Digital blew us away with Best B2B Search Marketing Initiative. And who can forget Melissa Liu from RPA taking home Search Marketer of the Year. Congrats to all of our winners! 

Security concerns and legal woes

Google had to tighten their policies surrounding explicit content after Reuters found illicit ads advertising liquor, sex toys, and high-risk investments. Large brands are even leaving Twitter after finding their ads next to adult, harmful, or violent content. More about Twitter later. 

Google security remained in the spotlight when Senator Richard Blumenthal (D-Conn) wrote a letter to CEO Sundar Pichai claiming that Google wasn’t doing enough to crack down on deceptive ads originating from their platform. The claim was citing an investigation from last year claiming that Google advertisers are impersonating government websites and purchasing ads in an effort to scam consumers. 

Location data concerns also plagued Google and they were sued by Washington D.C. attorney general Karl Racine. Lawsuits were also filed in additional states. 

But Google users concerned about privacy and security may be happy to know that Google updated their My Ad Center features to allow for more control. 

TikTok, though making aggressive moves toward a more secure and safe platform, isn’t a stranger to security flaws. The FCC even told (recommended?) that Google and Apple remove it from their app stores for breaching user data. The request claims that U.S. data had been accessed by China and that “TikTok poses an unacceptable national security risk due to its extensive data harvesting being combined with Beijing’s apparently unchecked access to that sensitive data.”

Speaking of TikTok, in an effort to play nice, the social media platform banned political fundraising and started requiring accounts that belong to U.S. government departments, politicians, and political parties to be verified. 

We can’t talk about safety and security without talking about Meta. From 12:01 AM PT on Tuesday, November 1, 2022, through 11:59 PM PT on Tuesday, November 8, 2022, no new ads about social issues, elections, or politics were allowed to be published, and most edits will be prohibited. This policy runs every year and is likely in response to the 2016 presidential election. 

Hot topics

Russia declared war in Ukraine. In response, Google and Microsoft Bing halted ad sales in Russia. A smart, necessary move to protest Russia’s actions in Ukraine, but they also help search engines avoid brand safety debacles like misinformation campaigns making it through their automated systems and showing to users.

In July Google eased ad restrictions for at-home abortion providers, making it easier for at-home abortion providers to distinguish themselves from other services that try to discourage the practice. Telemedicine providers who mail FDA-approved medications to people looking for at-home abortions previously weren’t allowed to label themselves as abortion providers. But in the aftermath of the Supreme Court overturn of Roe v. Wade, Google has amended its policies.

Gmail, YouTube, Smart Shopping updates; and is Google Search getting worse?

Freakonomics podcast asked us if Google Search was getting worse. What do you think? According to their research, maybe. 

Gone but not forgotten

Automation & Performance Max

New & improved

YouTube

Cookies

Cookies will remain active on Chrome until 2024. In July, Google announced that their Sandbox initiative has been delayed and developers are aiming for a Q3 2023 launch. Google developers also predict that it will start phasing out third-party cookies in the second half of 2024 – not 2023 like originally planned.

Microsoft is making a giant comeback

Microsoft isn’t new to PPC. But over the years it’s become third, fourth, or even fifth string to Google, Meta, twitter, LinkedIn, and even TikTok. But 2022 impressed us with just the sheer volume of new, improved, and updated features that Microsoft released. 

One of the biggest announcements this year was the acquisition of AT&T’s Xandr. By joining forces, Microsoft hopes to combine their audience intel and technology with Xandr’s powerful platform. This could allow Microsoft to leverage their audience network and provide additional inventory such as native video and digital TV.

Microsoft even announced plans to double the size of its ad business to $20 billion. I’d say they’re on the right track, since they also launched in 29 more countries in Europe and Africa. 

As if this year couldn’t be any more busy, they also won the bid to partner with Netflix for their ad supported tier. The deal gives Microsoft access to a quality streaming video inventory – something they previously lacked. 

New launches

Housekeeping

Meta takes a backseat

Meta stayed pretty quiet in 2022. With Zuck focusing so much time and resources on the Metaverse, they didn’t launch as many new products or features as Google or Microsoft. That said, there were still a few new developments. 

Twitter – where do we even begin

Twitter has had an interesting year. It’s not even over and new Chief twit Elon Musk is still making headlines. As always, we try our best to keep you updated with the latest news, as it happens. But Twitter updates are happening faster than we can report, so thanks for sticking around while we try to navigate what’s post-worthy and what’s too ridiculous to even mention. 

After the Musk takeover, security policies seemed to loosen and 30+ brands suspended their marketing campaigns after finding their ads next to child pornography accounts. 

But despite all the drama, Twitter has released a few new useful tools and features. Let’s take a look.  

TikTok shopping debacle, longer videos, and unhappy creators

TikTok continued to compete against Facebook and Instagram to gain an edge over the short form video market. In doing so, they extended the length of their videos to 10 minutes, and updated the description character limit to 2,200.

But the longer videos and descriptions wasn’t enough to keep creators happy. In July we reported that TikTok’s history of low Creator Fund payouts were forcing some influencers to leave the platform for good. Some creators claim they’re paid between $0.02 – $0.03 per one thousand video views. Yikes!

Shopping confusion

You would think that TikTok would be doing everything they could to get a leg up on other social and ad platforms. So it was surprising when Meta announced their plans to scale back on shopping, TikTik followed suit with its own announcement to abandon plans to bring shopping into the US. Though, understandably after a disastrous launch in the UK

But just one month later, TikTok announced three new shopping ad features, including video, catalog, and LIVE ads. So what gives?

For their LIVE feature, they aimed at enhancing the experience and promoting greater brand safety, something that the app has been accused of neglecting in the past.

They did this by introducing:

  • The introduction of Multi-Guest
  • Increasing the LIVE minimum age from 16 to 18
  • Introducing safety reminders for all LIVE guests

I think they were hoping that brands that saw features being cut on Meta would abandon the platform and move to TikTok. But has that happened? We shall see. 

And to further compete with Meta, TikTok also launched Photo Mode as well as 7 other photo editing features including:

  • Edit clips: Stack, trim, and split video clips
  • Edit sounds: Cut, trim, and set the duration for sounds
  • Edit and position text: More easily edit, position, and set the duration for text
  • Add overlays: Add photo and video overlays for picture-in-picture (or video-in-video) stacking
  • Adjust video speed: Speed or slow the pace of video clips
  • Frame content: Rotate or zoom in and out of frame of individual clips
  • Add sound effects. Add musical soundtracks to videos and photo carousels

Look familiar?

Competing with Amazon, too?

But Meta isn’t the only media giant TikTok is going after. In November, they launched TikTok Shop, where users can now make purchases directly through the app. At the time of this publishing, TikTok is currently inviting select U.S. businesses to participate in the initiative. That means live streamers from places where the feature is not live will need to continue directing shoppers to third-party websites.

Apple

Apple is trying its hardest to join the ad game, but unless you’re a publisher or game developer, there aren’t a ton of options for you right now. But nevertheless, Apple made some noteworthy changes and updates this year. Let’s take a look. 

Apple is expanding ads on iPhone and iPad.  Display ads are currently shown in the search tab. But soon Apple will expand the ads to the main Today tab as well as in third-party app download pages, according to Bloomberg. For search ads in the app store, developers can pay to have their apps featured in the results when users search terms related to the app.

Four new Apple Search Ad placement options. Apple released four new options for advertisers to drive visibility and downloads in the App Store. The new placements are:

  • Today tab
  • Search tab
  • Search results
  • Product pages — while browsing

Apple could be building an ad network for live TV. In November we reported that Apple was holding discussions with advertising partners and MLS sponsors with the plan to launch next February.

Apple Search campaigns shifting to cost-per-tap (CPT) pricing model. Starting in June, Apple shifted their model to Cost-per-Tap, or CPT. CPT is Apple’s version of CPC, or cost per click. It is calculated by dividing your total spend by the number of taps your ad received. 

Other platforms making headlines

We would be remiss if we didn’t mention that there are plenty of other platforms that made waves in 2022. Although these may not have been big enough to deserve their own category, they definitely deserve mentioning. 

Best Buy

Best Buy to sell search ads under its own in-house media company. Best Buy has launched Best Buy Ads, its own in-house media company. Best Buy Ads offers paid search ads and sponsored product listings on Best Buy’s website, among other ad offerings.

Instacart

Walmart

  • Walmart is expanding their self-service Marketplace platform. Search Brand Amplifier gives products listed in the Walmart marketplace higher visibility by boosting advertised products to the top of search results. Walmart says this benefits newer and smaller brands that haven’t achieved high organic listings within the Walmart platform.
  • Walmart is now selling ads on TikTok, Roku, and Snap. For the first time ever, Walmart has expanded its ad reach beyond its own ecommerce platform by powering ads on TikTok, Roku, and Snap. They’ll also have the capability to measure any sales that come from those ads.

LinkedIn

  • A podcast network aimed at professional audiences. The LinkedIn Podcast Network is a pilot program that will include shows about topics such as technology, recruiting and mental health, from external experts as well as its own in-house news team.
  • LinkedIn announces Business Manager. Finally! The new Business Manager will aim to simplify how marketers keep track of their accounts by offering their Campaign Manager and Pages options easily visible from a central location.

Pinterest

Pinterest is doubling down on Shopping by adding 4 new features. Pinterest introduced four new merchant features to help retailers promote their stores. 

  • Product Tagging on Pins
  • Video in Catalog
  • Shop Tab on Business Profiles
  • The API for Shopping

Reddit

Uber

Uber ads are coming, and they’re already raising privacy concerns. Ubers’ new journey ads will be shown in the Uber app at least three times during the riders’ journey. The new feature will let brands place ads using data drawn from riders’ travel history and their precise geographic destinations, according to Uber. 

SMX Advanced and SMX Next

We can’t wrap up our 2022 year in review without talking about SMX. We had 2 epic virtual conferences this year with expert speakers discussing topics such as how to leverage automated bidding to finding success with an audience-first strategy. Let’s take a look back. 

SMX Advanced

SMX Next

Did you miss SMX Next, or wanna watch it again? You still can. Registration is free

  • SMX Next PPC kicked off with an incredible keynote from Google’s own Ads Liaison (and former Search Engine Land Editor in Chief) Ginny Marvin. 
  • Melissa Mackey taught us how to make automation work for lead gen.
  • Navah Hopkins gave us the guide to permission based audience targeting.
  • Anthony Tedesco showed us how to level up our analytical skills using Excel.

Well that’s a wrap on 2022. What a year it’s been. Looking forward to 2023 I think we’re going to see more automation, a bigger push into GA4 as Universal Analytics gets sunsetted, big moves from Microsoft and other smaller platforms like Walmart and Instacart, and privacy-first strategies as third-party cookies finally retire.


Related stories

New on Search Engine Land

@media screen and (min-width: 800px) { #div-gpt-ad-3191538-7 { display: flex !important; justify-content: center !important; align-items: center !important; min-width:770px; min-height:260px; } } @media screen and (min-width: 1279px) { #div-gpt-ad-3191538-7 { display: flex !important; justify-content: center !important; align-items: center !important; min-width:800px!important; min-height:440px!important; } }

About the author

Nicole Farley

Nicole Farley is an editor for Search Engine Land covering all things PPC. In addition to being a Marine Corps veteran, she has an extensive background in digital marketing, an MBA and a penchant for true crime, podcasts, travel, and snacks.

https://searchengineland.com/ppc-2022-in-review-performance-max-apple-search-chaos-at-twitter-and-more-390608




Meta to pay $725 million to settle Cambridge Analytica lawsuit

facebook logo next to cambridge analytica sigh

Meta, the parent company of Facebook, will pay $725 million to settle a class-action lawsuit filed in 2018. The lawsuit came in the wake of Facebook’s revelation that it had improperly shared data on 87 million users with Cambridge Analytica, a British political consultancy tied to former President Donald Trump’s election campaign.

Cambridge Analytica got its access to Facebook user data via an app developed by a third party. While only around 270,000 Facebook account-holders used the “This is Your Digital Life” app, the app’s permissions allowed it access to data on those users’ friends. The end result was a dataset covering 87 million users that the developer than passed on to Cambridge Analytica, in contravention of Facebook’s terms of service. The vast majority of those in the dataset had not given the consultancy firm permission to access their data.

The unauthorized data sharing came to light in 2018, when reporters from The New York Times and The Observer informed Facebook that Cambridge Analytica still had copies of the data, even though the UK-based firm had promised the social network back in 2015 that the data would be deleted.

Cambridge Analytica filed for bankruptcy in May 2018 after determining it was “no longer viable to continue operating the business.”

The lawsuit against Meta continued on, and other instances of problematic data-sharing practices by Facebook were added to the complaint. Indeed, the lawsuit accused Facebook of giving “numerous third parties access to their Facebook content and information without their consent, [and alleged] that Facebook failed to adequately monitor the third parties’ access to, and use of, that information.”

Meta is admitting to no wrongdoing or illegal activity by settling the case. Instead, the company says the $725 million agreement, which must still be approved by a judge, is “in the best interest of our community and shareholders,” a Meta spokesperson told Reuters.

Up to 280 million Facebook users are covered by the settlement, which means that $725 million is going to be spread awfully thin after the plaintiffs’ attorneys take their 25 percent cut.

https://arstechnica.com/?p=1906625




Flussi dati Eu-Usa, Gay: “Bisogna accelerare la procedura di adeguatezza, in gioco la crescita europea”

Lo scorso 13 dicembre la Commissione europea ha avviato la procedura per adottare una decisione di adeguatezza in tema di privacy per rendere più sicuri i flussi di dati tra Unione europea e Stati Uniti. Tale iniziativa segue l’emanazione dell’Executive order del Presidente Biden che ha recepito “in principle” l’accordo dello scorso 25 marzo 2022 sottoscritto da UE e Usa per l’adozione di un nuovo Trans-Atlantic Data Privacy Framework, a tutela dei dati personali dei cittadini europei trasferiti negli Stati Uniti. 

Si tratta di un passaggio fondamentale tenuto conto che i trasferimenti di dati sono essenziali per la crescita dell’economia europea. Il flusso di dati transfrontalieri, infatti, permetterebbe all’Europa di conseguire 720 miliardi di euro di crescita in più entro il 2030, di generare 60 miliardi di euro di esportazioni all’anno, oltre la metà provenienti dal settore manifatturiero e creare di 700.000 posti di lavoro, molti dei quali altamente qualificati ove approvata.

“I flussi di dati transfrontalieri sono forieri di apertura di nuovi mercati e di opportunità per le aziende, vitali per la cooperazione transatlantica e rafforzano il partenariato economico USA-UE. Per questo motivo è essenziale che la decisione di adeguatezza venga adottata in tempi brevi”, ha commentato Marco Gay, Presidente Anitec-Assinform, l’Associazione di Confindustria che raggruppa le principali aziende ICT. “Il processo avviato nei giorni scorsi dalla Commissione europea costituisce un importante passo in avanti per assicurare, in questo difficile contesto economico, alle aziende europee di poter sfruttare tutte le opportunità del digitale in un contesto di regole chiare, certe e a tutela dei cittadini europei.”

A partire da oggi dunque, si prevedono ulteriori passaggi quali l’ottenimento del parere dal Comitato europeo per la protezione dei dati (EDPB) e il voto favorevole di un comitato dei rappresentanti degli stati membri.

Una volta concluso l’iter, la decisione obbligherà le aziende USA a osservare regole sulla privacy stringenti, tra le quali l’eliminazione dei dati personali non più necessari al loro scopo e il mantenimento della protezione dei dati quando condivisi con terze parti.

Con il provvedimento verrà, tra l’altro, limitato l’accesso ai dati da parte delle agenzie di intelligence statunitensi nei casi di sicurezza nazionale secondo criteri di proporzionalità e necessità e verranno introdotti alcuni meccanismi che consentiranno di presentare un ricorso indipendente da parte dei cittadini europei in caso di violazioni.

Vista la portata dei cambiamenti, l’auspicio è che la decisione venga adottata velocemente al fine di garantire un quadro di regole chiaro e certo applicabile al flusso di dati tra UE e USA che consenta alle imprese di superare lo stato di incertezza attuale così da agevolare lo svolgimento dell’attività economica e i processi di trattamento dei dati.

https://www.key4biz.it/flussi-dati-eu-usa-gay-bisogna-accelerare-la-procedura-di-adeguatezza-in-gioco-la-crescita-europea/429373/




Impronte digitali, Garante Privacy: “No alla rilevazione senza specifici requisiti”

Il trattamento di dati biometrici sul posto di lavoro è consentito solo se necessario per adempiere gli obblighi ed esercitare i diritti del datore di lavoro previsti da una disposizione normativa e con adeguate garanzie.

Lo annuncia il Garante Privacy dopo aver sanzionato per 20mila euro una società sportiva che aveva introdotto un sistema di rilevazione delle impronte digitali per accertare la presenza dei dipendenti presso i club in gestione.

L’Autorità è intervenuta a seguito di una segnalazione di un’organizzazione sindacale, che lamentava l’introduzione del sistema biometrico da parte della società, nonostante la richiesta del sindacato di adottare mezzi di rilevazione meno invasivi.

Nel corso dell’istruttoria e degli accertamenti ispettivi, effettuati dal Nucleo speciale tutela privacy e frodi tecnologiche della Guardia di Finanza, è emerso che la società aveva effettuato, per quasi quattro anni, la rilevazione delle impronte digitali dei 132 dipendenti senza un’adeguata base normativa.

E, violando i principi di minimizzazione e proporzionalità, aveva trattato per scopi di ordinaria gestione (consentire maggiore velocità e snellezza dell’attività di rilevazione delle presenze) una tipologia di dati protetta dal Regolamento europeo con particolari garanzie. La società aveva inoltre fornito ai lavoratori informazioni del tutto carenti sulle caratteristiche dei trattamenti biometrici.

Riscontrate le numerose violazioni della normativa posta a tutela dei dati personali dei lavoratori, il Garante, nel definire la sanzione di 20mila euro, ha tenuto conto della natura, della gravità e della durata degli illeciti, che si sono protratti fino al 2 maggio 2022, data in cui il sistema di rilevazione delle impronte digitali è stato sostituito da un sistema non biometrico.

https://www.key4biz.it/impronte-digitali-garante-privacy-no-alla-rilevazione-senza-specifichi-requisiti/429327/




Epic Games dovrà pagare 520 milioni di dollari per aver violato la privacy dei giocatori di Fortnite

Epic Games sarà costretta a pagare una sanzione record di 520 milioni di dollari dopo aver patteggiato con l’organo antitrust FTC per la violazione della privacy dei giocatori di Fortnite.

Lo sviluppatore di videogiochi è stato accusato di aver raccolto i dati degli utenti minori di 13 anni e averli indotti a effettuare degli acquisti fortuiti, e per questo motivo dovrà pagare una sanzione record da 520 milioni di dollari per aver violato la legge federale Children’s Online Privacy Protection Act.

Epic Games ha scelto di patteggiare, accettando di pagare due 275 milioni di dollari per la violazione della privacy dei minori, e ulteriori 245 milioni di dollari per aver spinto i consumatori ad acquistare oggetti attraverso l’uso di testi poco comprensibili e pratiche volutamente “manipolative” con cui ingannare gli utenti e spingerli ad acquistare oggetti virtuali.

Da tempo, infatti, alcuni genitori lamentano la difficoltà di ottenere un rimborso attraverso i canali ufficiali preposti da Epic Games dopo l’acquisto di skin, emote e altri contenuti con cui personalizzare il proprio personaggio di Fortnite, e così nella manovra studiata dall’organo antitrust statunitense sarà avviato un programma di rimborso che, attraverso il sito ufficiale dell’ente FTC, sfrutterà i succitati 245 milioni di dollari per restituire il denaro a coloro fossero stati colpiti dalla scarsa chiarezza di Epic Games.

“Nessuno sviluppatore crea un videogioco con l’intenzione di arrivare a questo punto”, ha dichiarato un portavoce dell’azienda sul sito ufficiale di Epic Games. “L’industria dei videogiochi è un luogo d’innovazione che continua a evolversi rapidamente, un’industria in cui le aspettative dei giocatori sono sempre più alte e le nuove idee sono assolutamente fondamentali. Le leggi scritte decenni fa non specificano come gli ecosistemi videoludici debbano operare: le leggi non sono cambiate, ma la loro applicazione si è evoluta e le pratiche industriali di vecchia data non sono più sufficienti”.

Epic Games spiega perché abbia accettato di patteggiare: “Abbiamo accettato questo accordo perché vogliamo che Epic Games sia un’azienda all’avanguardia nella protezione dei suoi consumatori e fornisca la migliore esperienza ai giocatori”, si legge in una nota ufficiale. “Negli ultimi anni abbiamo apportato modifiche per garantire che il nostro ecosistema soddisfi le aspettative dei giocatori e delle autorità di regolamentazione, che speriamo possano essere una guida utile per altri studi nel nostro settore”.

Lo studio statunitense sottolinea come il funzionamento della monetizzazione nei videogiochi e la gestione dei dati per la privacy sia cambiata drasticamente con l’avvento delle moderne piattaforme “live service” e che, pur condividendo le preoccupazioni dell’ente FTC, le accuse dell’organo antitrust non rispecchiano il modo in cui Epic Games opera per lo sviluppo, arricchimento ed evoluzione dell’ecosistema di Fortnite.

Ciò non toglie, tuttavia, che l’azienda voglia migliorare nei punti in cui ritiene di non offrire un’esperienza cristallina nei confronti del suo pubblico: “Continueremo a essere chiari su ciò che i giocatori possono aspettarsi quando sono effettuati degli acquisti, a garantire che le cancellazioni e i rimborsi siano semplici e a creare tutele che aiutino a mantenere il nostro ecosistema sicuro e divertente per il pubblico di tutte le età”.

https://www.key4biz.it/epic-games-dovra-pagare-520-milioni-di-dollari-per-aver-violato-la-privacy-dei-giocatori-di-fortnite/428976/